{"id":61692,"date":"2022-07-25T17:11:18","date_gmt":"2022-07-25T13:11:18","guid":{"rendered":"https:\/\/techxmedia.com\/?p=61692"},"modified":"2025-04-18T00:13:34","modified_gmt":"2025-04-17T20:13:34","slug":"how-should-cisos-deal-with-pressing-cybersecurity-concerns","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/how-should-cisos-deal-with-pressing-cybersecurity-concerns\/","title":{"rendered":"How should CISOs deal with pressing cybersecurity concerns?"},"content":{"rendered":"\n<p><span style=\"color:#cf2e2e\" class=\"tadv-color\"><strong>Exclusive interview with Frank Kim, Fellow Instructor at the SANS Institute.<\/strong><\/span><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/techxmedia.com\/wp-content\/uploads\/2022\/07\/image-39.png\" alt=\"\" class=\"wp-image-61694\" width=\"451\" height=\"259\" srcset=\"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2022\/07\/image-39.png 902w, https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2022\/07\/image-39-300x172.png 300w, https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2022\/07\/image-39-768x441.png 768w\" sizes=\"auto, (max-width: 451px) 100vw, 451px\" \/><\/figure><\/div>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: What are the most pressing cybersecurity concerns faced today by organizations in the Middle East?<\/span><\/strong><\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">Frank<\/span><\/strong>: Cloud computing is transforming the way businesses work. Every large organization is now multicloud by choice or by chance. As a result, cybersecurity teams must be well versed in cloud computing, the corresponding threats, and how to appropriately secure cloud workloads.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: What are some of the best cybersecurity practices your company has adopted to ensure not only a secure working environment but also a simplified adoption process?<\/span><\/strong><\/p>\n\n\n\n<p><span style=\"color:#000000\" class=\"tadv-color\"><strong>Frank<\/strong><\/span>: Automation. To scale effectively, cybersecurity teams must automate to keep up with both the speed of modern attacks but also the speed of the business.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: Hybrid work culture is now a reality; how are you protecting your remote workforce from potential cyber threats?<\/span><\/strong><\/p>\n\n\n\n<p><span style=\"color:#000000\" class=\"tadv-color\"><strong>Frank<\/strong><\/span>: In many ways, the secure behaviors we want people to exhibit while working at the office are the very same secure behaviors we want them to exhibit working at home. However, there are additional behaviors expected of them when working at home as their home environment must be secure, for instance, securing their WiFI network, ensuring family members or children are not accessing work systems or perhaps the use of a VPN.<\/p>\n\n\n\n<p>The other challenge is reaching a remote workforce as all training is done virtually. In short, securing a remote workforce is similar to securing an in-office workforce, however, you need to expand your virtual training capabilities and add some additional, relevant topics.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: The human factor remains one of the most serious threats to an organization&#8217;s cybersecurity; in light of this, what kind of security training should employees receive?<\/span><\/strong><\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">Frank<\/span><\/strong>: Security training is moving from the world of compliance to the world of managing human risk. This means security awareness programs need to be closely aligned with the security team and identify the top human risks to the organization and the key behaviors that manage those risks. The awareness team is then responsible for continuously engaging and training their workforce on those key secure behaviors. Training is no longer a single, annual event but a continuous, regular process throughout the entire year that focuses on key behaviors. A big part of successful training is making security simple so it becomes easy and convenient for people to behave in a secure manner.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: What is the best and most immediate strategy for CSOs\/CISOs to implement if a data breach occurs in their organization?<\/span><\/strong><\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">Frank<\/span><\/strong>: As a CSO\/CISO, your primary role is to drive progress through coordination, understanding and communication. You can\u2019t unbreach an organization but you can inform and control the situation to a better place. Here are some measures that can be taken in the event of a breach \u2013<\/p>\n\n\n\n<p>1. Notify your organization\u2019s key team leads (Legal, IT Admin, Cyber Security, HR, PR), and set a time to meet and ensure that all are aware of \u201cwhat is known\u201d at that time. Set cadence for future meets.<\/p>\n\n\n\n<p>2. Enact your Incident Management (IM) plans invoking IR, BCP, PR and Legal Support contracts. Consider contacting Law Enforcement especially if you are large, critical infrastructure or supply your government.<\/p>\n\n\n\n<p>3. Identify the worst-case impact from what is known about the breach at this time. Get a timeline from IR to understand the scope of the breach and work to that timeline. Get frequent updates from your IM team.<\/p>\n\n\n\n<p>4. Prepare a press statement around what is known now, and get legal advice before release. Set a time when you need to release the press statement, ensuring it can be passed to all customer contact points.<\/p>\n\n\n\n<p>5. Listen to the IR update at each briefing and identify what that means to your business, your data and your customers. Plan, coordinate, lead the teams. Brief up \u2013 laterally internally and externally regularly as required.<\/p>\n\n\n\n<p>6. Look after your people (mentally, too), your customers and yourself.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: What do you consider to be the most important skills of a modern CSO\/CISO?<\/span><\/strong><\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">Frank<\/span><\/strong>: Modern CISOs need to go beyond traditional technical skills to build a security-aware and risk-aware culture. A big part of this is understanding how the business works and makes money. By identifying strategic business objectives, the CISO can focus on cyber risks<\/p>\n\n\n\n<p>that affect key business processes and crown jewels. Building strong technical capabilities is just a table stake. CISOs need to show the board and senior leadership teams that they are business leaders as well.<\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">TECHx: What advice or tips would you give to other CISOs in light of the current global cybersecurity landscape?<\/span><\/strong><\/p>\n\n\n\n<p><strong><span style=\"color:#000000\" class=\"tadv-color\">Frank<\/span><\/strong>: Spend more time building and cultivating business and personal relationships. Successful CISOs lead in three directions \u2013 up, across, and down. Focus on all three.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cloud computing is transforming the way businesses work. Every large organization is now multicloud by choice. Cybersecurity teams must be well versed in cloud computing, the corresponding threats, and how to appropriately secure cloud workloads.<\/p>\n","protected":false},"author":8,"featured_media":61695,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1595,9621],"tags":[7135],"contributor":[9732],"class_list":["post-61692","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-emerging-technologies","tag-sans-institute","contributor-news-desk"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2022\/07\/Featured-1-1-1.png","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/61692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=61692"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/61692\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/61695"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=61692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=61692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=61692"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=61692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}