Showing posts with label CyberTruth. Show all posts
Showing posts with label CyberTruth. Show all posts

Tuesday, December 10, 2019

Security Connective Tissue Behind Digital Transformation


Digital transformation is what the business see and their customers experience. 


It’s the face of the transformation.

Exposing business value via APIs.

But there is also magic happening behind the scenes.

Thursday, December 5, 2019

The Conceptual Problem of Cyber Security Ownership


Effectively securing the IT and information assets of an organization is as much a problem in modeling the right approach as it is in having the right controls and technical solutions in place. 



For instance, wanting to distribute ownership of cyber security across the organization isn’t a technical problem to solve.  It’s a business model problem that begins with a conceptual change that then leads to process change. 


If we want to distribute cyber security ownership, we can conceptually view the relationship of a cyber security team and a cyber program in two ways.

Wednesday, December 4, 2019

Play To Win In Cyber Security

Close your eyes and think of the goals for your cyber program.  Think of what a win looks like.



In American football, a prevent defense almost always means the other team has a chance to win. 


Are your cyber goals preparing your organization to win? Or, is your program playing the cyber equivalent of a prevent defense?

Tuesday, December 3, 2019

Cyber Leaders, Critical Thinking, and Team Colors


Purple teams confuse me.



To be more precise, small cyber teams thinking that they need some separate purple capability is what actually confuses me.

Sunday, December 1, 2019

Servant Leadership In Cyber Security


Servant leadership seems to be a growing buzzword in cyber security.




Robert K. Greenleaf coined the words "servant-leader" and "servant leadership" in 1970 with the publication of his classic essay, The Servant as Leader.

Tuesday, November 19, 2019

Transforming Cyber News Into A Value Add


Retweeting or forwarding news articles about a cyber breach seems somewhat mindless.  A company made the headlines for being breached...again. It might be mildly interesting if the breached party is a technology vendor or a management consulting company with a cyber practice.The frequency is overwhelming.


That said, is there really any value left in being the 10,000th person to retweet or forward the link about that latest breach?


Perhaps there is a different way to think about cyber news. 

Wednesday, November 13, 2019

Rethinking Gaps In Cyber Security Programs


Think about cyber in business terms for a second. A description of a cyber security program without a clear statement of program gaps is like a balance sheet without a liabilities statement. 




And yet, somehow, gaps seem to be an often minimized part of our conversations with executives. 


Perhaps as cyber leaders, we choose to avoid hard conversations about program gaps because we want to be positive. Maybe we avoid them because we have some level of fear of executive reaction to hearing about gaps in the cyber security program in the context of past investments. 

Tuesday, November 12, 2019

Transforming Into A Cyber Security Culture Takes Guts


Sometimes, organizations confuse cultural transformation around security with security awareness training.



Making annual cyber security training mandatory doesn’t take much to implement. A little bit of coordination with the right people and perhaps some pointing at some cyber security framework language and it is done. 


Checkbox checked. 

Saturday, November 9, 2019

Cyber Security Shared Consciousness: A Primer


Cultural transformation defines successful cyber security. 


You have a concept. A change. Something necessary but perhaps not tangible….yet.

It might be some change to a focused activity or something broad like re-engineering the entire cyber security program. Either way, you’ll need to start with something.

Shared consciousness.

Wednesday, November 6, 2019

"A Teams" And Well Intentioned Mistakes In Cyber Security



Hiring an “A team” may seem like a difficult task to many cyber leaders. But retaining an entire team of As is even harder. 




We can begin with the common attribute of “A players” generally taking the initiative. Sometimes you’ll get great initiative and great results. Occasionally, you’ll get great initiative and poor judgment. Poor judgment that can lead to a mistake.


But, from a leadership perspective, a mistake made because of taking the initiative isn’t such a bad thing.

Saturday, November 2, 2019

What's Really Broken In Cyber Security


One might think that the common problems in cyber security programs are that teams aren’t resourced correctly and that the business doesn’t support the cyber security program. Could be but maybe we’ve confused the symptoms of being broken with the underlying root causes.



Some of those possible root causes? 

Non-committed leadership.
Vague security goals and objectives.
Lack of understanding and consensus by executives.
Solutions before analysis.
Poor execution.