Tag: metrics

  • Preview: How to CISO Volume 2: Risk Measurement

    Preview: How to CISO Volume 2: Risk Measurement

    As a CISO, you’re often going to be asked to measure risk. This has a lot of different meanings, depending on who is speaking, so you’re going to have to listen carefully to the speaker to understand what they’re actually asking for. It’s possible that you’re being asked to provide a quantitative answer to the…

  • Why assessing third parties for security risk is still an unsolved problem

    Why assessing third parties for security risk is still an unsolved problem

    A recent ranking of the most cyber-secure companies reveals weaknesses in current third-party risk management practices. A Forbes article is making the rounds right now about America’s most cyber-secure companies, and I can already see the cybersecurity outrage machine up in arms. Full confession: I haven’t yet read the article, but I’m about to. I’m writing this…

  • How to CISO Volume 1: The First 91 Days

    How to CISO Volume 1: The First 91 Days

    Ninety days is generally the grace period (or “honeymoon,” if you’d like) that a new executive has to get acclimated to a new environment. At the end of this time window, your employer is going to expect you to be executing on a plan, anyone you need to meet will expect you to have already…

  • Vulnerabilities don’t count

    Vulnerabilities don’t count

    No one outside the IT department cares about your vulnerability metrics (or they shouldn’t, anyway). They care about efficacy. And traditional stats don’t show that. I had a lovely chat with one of my favorite CISOs the other day, helping them think through the security metrics that they report upwards.  Front and center, as I…