Tag: virtual ciso

Tag: virtual ciso

Supply Chain Resilience – Who are your Backup Suppliers?
13/01/2020 CISO Blog, DPO Blog, Security Advisory Blog admin

Is your supply chain resilience programme reminiscent of the article image? Aged, poorly maintained, complex, hard-to-untangle. Do you carry out due diligence at the beginning of your engagements? More importantly, do you carry out ongoing governance and oversight? Even more importantly, does supply chain resilience form part of your wider operational resilience strategy or business

Read More
Security Incident Avoidance – Hackers know we’re away for Christmas…
23/12/2019 CISO Blog, Security Advisory Blog admin

It’s that time of year where many of us will be ensuring our organisations can still deal with a security incident whilst most of the workforce are at home watching Christmas movies like Die Hard – yes, it’s definitely a Christmas Movie. Hackers know businesses are running on skeleton staff during the holiday period so

Read More
Strategy – Can a CISO learn from the 2019 General Election?
13/12/2019 CISO Blog, Security Advisory Blog admin

Security Strategy – What lessons can CISOs learn from the UK Gerneral Election 2019 when devising and delivering a security strategy? Here are three…

Read More
Security Awareness Training Dies. My 2020 Prediction
11/12/2019 CISO Blog, Security Advisory Blog admin

My prediction is that 2020 will be the year security awareness training dies…and not before time…

Read More
Cybersecurity Strategy – Organise to Operate
07/12/2019 CISO Blog, Security Advisory Blog admin

Cybersecurity strategy is being “organised to operate”. A principle that is fundamental to developing an effective cybersecurity programme. Here’s why…

Read More
Security Audit – Are you a ‘Quiddler’?
26/11/2019 CISO Blog, DPO Blog, Security Advisory Blog admin

Are you a Quiddler? No, this is not some fanboi reference to Harry Potter (I’ll be honest I haven’t read one of the series, I’m a proper muggle!). Quiddling, however, is a very real problem in the world of Security Audit. If you want to know more, keep on reading. You could be one of

Read More
CISO role: All C and no IA, the 33% CISOs failing their organisations!
23/08/2019 CISO Blog admin

In the last (maybe…) of my three-part CISO rant series (See Part One and Part Two if you want to catch up) I am going to wrap up with a rant about the 33% CISOs not giving their organisations of a full CISO role. These are the CISOs who think their role is solely about

Read More
Security Strategy: If you want to run a SOC, you’re not ready to be a CISO
17/08/2019 CISO Blog admin

A CISO is a strategic role, not an operational role – if you still want to run a Security Operations Centre (SOC) then (attitudinally at least) you’re not ready to be a CISO…here’s why…

Read More
CISO Reporting Line: Your CISO should not report to the CIO or the COO or the CFO…here’s my rant as to why it’s bad Joo Joo!
16/08/2019 CISO Blog admin

The CISO reporting line is to 1 of 2 roles. The CRO if the CRO sits on the senior management team. If no CRO, then CISO should report to CEO directly.

Read More
InfoSec CPE: If you pay for your infosec specialists’ membership fees why aren’t you reviewing their annual CPE transcripts?
28/07/2019 CISO Blog, DPO Blog, Security Advisory Blog admin

I would strongly recommend periodically asking your staff for their current qualifications’ CPE transcripts. Not just your InfoSec or Risk specialists but all your specialists.

Read More