Logo

    A conversation with award-winning CISO, Andrew Rose

    enApril 28, 2020
    What was the main topic of the podcast episode?
    Summarise the key points discussed in the episode?
    Were there any notable quotes or insights from the speakers?
    Which popular books were mentioned in this episode?
    Were there any points particularly controversial or thought-provoking discussed in the episode?
    Were any current events or trending topics addressed in the episode?

    About this Episode

    A conversation with award-winning CISO, Andrew Rose

     

    ANDREW ROSE joins us for Series 3, Episode 12 of the Re-Thinking the Human Factor Podcast. Join us for this straight forward discussion with an award winning CISO who transformed security management for three major organisations.

     

    With his extensive background, Andrew is a strong relationship manager who is able to develop and lead teams, driving initiatives forward with a style that is facilitative, tenacious and positive. Able to communicate, co-ordinate and influence effectively at all levels and respond to challenges with dedication, enthusiasm and pragmatism. 

     

    Andrew Rose is strongly focussed on sensible, cost effective security solutions being used to enable a business to innovate and develop.

     

     

    AS YOU LISTEN TO THE EPISODE, IF YOU FIND YOURSELF WANTING TO IMPLEMENT SOME OF THE INSIGHTS YOU’RE GAINING BUT YOU FEEL YOU NEED A LITTLE HELP, PLEASE DO GET IN TOUCH WITH ME AT:

     

     

    bruce.hallas@re-thinkingthehumanfactor.com

     

     

    JOIN ANDREW ROSE AND BRUCE HALLAS AS THEY DISCUSS:

    • The early days of cyber security and how people almost gave up on the human factor.

    • How the idea of applying the knowledge of human awareness came into play.

    • Challenges today’s cyber security managers face.

    • How can you be safe if you are not secure?

    • The key indicators to a healthy security culture.

    • The influences that help to drive our decision-making and behaviour.

    • Designing cyber security awareness and training with the human in mind.
    • How to win over people to try something new.
    • How hackers think.

     

     

    RESOURCES AND TOPICS FOR FURTHER STUDY

     

    MORE ABOUT ANDREW ROSE:

     

     

    Please subscribe to the podcast in iTunes, and if you enjoyed this interview, please share with your friends and colleagues and leave a 5 star rating and review.

     

    Thanks for listening and sharing.

     

    Bruce & The Re-thinking the Human Factor Podcast Team

    Recent Episodes from Re-thinking The Human Factor with Bruce Hallas

    Insights from advertising for security awareness professionals.

    Insights from advertising for security awareness professionals.

    In this episode we are joined by a guest who has committed their career to the world of advertising agency work. Influencing target audiences awareness of products and stacking the odds in their clients favour, that the target audience will choose their product over their competitors. The challanges our guest has faced, over the years, are in many ways similar to those that education and awareness managers, for information security and data protection, now face.

    A Human Resource view on Information Security Awareness and Education

    A  Human Resource view on Information Security Awareness and Education

    The role of the human resources function, in the the overall process of employee awareness, behavioru and culture can't be under stated.

    In the early days of my research, at Re-thinking the Human Factor, it was very apparent that HR was a major stakeholder. From what I like to call KPI's clash, where stakeholders KPI's sometimes clash against each other, through to employee performance and development, and from HR processes such as starters, movers and leavers, through to organisational change. The HR department can add a lot of value to the process of delivering change in employee security awareness, behaviour and culture if you work on fostering a beneficial releationship. 

    With that in mind I wanted to invite a guest who excels in the area of organisational development, epople management and HR. Our guest, Anne Benedict, stepped right up and agreed to share some insights into the challange of employee awareness and education, from a HR perspective.

    Embracing Diverse Skills When Building an Effective Education and Awareness Team.

    Embracing Diverse Skills When Building an Effective Education and Awareness Team.

    When I first got involved in “information security” 20+ years ago, I found myself almost entirely surrounded by industry peers whose training and experience was in technology or technology disciplines. My training in law, marketing and finance, and my experience in business development, marketing, recruitment and even a stint in purchasing and supplies all seemed out of line with the world of IT security as it was called back then.

    As I came to understand, during my own research in human behaviour and culture, my lack of an education in technology meant I was culturally and even physically wired differently. This meant I looked at things through a different set of lenses. The result, was an approach that we would now call governance, risk and compliance. However, it was these very human disciplines, which led me to fundamentally think differently when it came to kicking off the Re-thinking the Human Factor research programme.

    Our guest Lana McGill, to me, enshrines the change in direction of an increasing number of forward thinking security professionals looking for a more mature approach to employee awareness, behaviour and culture. Lana believes that by diversifying their search for skills and experience, outside of the traditional industry expectations, you can bring new insights and energy to the challenge of influencing  employee behaviour and culture. Her role as a senior information security leader, in the finance sector, and her willingness to embrace other skills and experiences in the search for more effective interventions, gives hope that the industry inertia, when it comes to the human factor, may finally be shifting.

     

    ©Copyright Marmalade Box Limited

    The content of this podcast is the property of Marmalade Box Limited. Any use of the content of the podcast, either in full or partially, will be considered an infringement of Marmalade Box Limited rights as sole owners of this content. Any enquiries about the use of this content should be directed to Marmalade Box Limited. Contact information can be found at www.marmaladebox.com .

    The Science Behind Metrics

    The Science Behind Metrics

    Finding relevent metrics, for security awareness, behaviour and culture has been a long standing  challenge which the information security industry has struggled hard to address.

    Now, when I reflect on how I personally tackled metrics, around the human factor, before I kicked off my research programme here at Re-thinking the Human Factor, I recognise I had an in-mature approach. That approach focused on what data I knew I could get rather than what was useful. Some industry folks called this "vanity metrics." That's all changed now, and that change started off, with getting back to basics by looking at what the science of measurement had to say.

    In this episode our guest and I talk about the sceince of measurement, how it is has evolved to enable human kind to progress at every stage of human evolution and how this knowledge might shine a light on the challenge of finding effective metrics when it comes to employee awareness, behaviour and culture.

    If you want to know more about how we have used this and other insights into metrics to support information security professionals measure the effectiveness of their programmes to influence security awareness, behaviour and culture then visit www.re-thinkingthehumanfactor.com and register for the monthly webinar. 

     

    Insights from Educational Psychology for Information Security Professionals

    Insights from Educational Psychology for Information Security Professionals

    Educating employees on their roles and responsilities when it comes to information security and data protection, is common sense, and, even if you don't think that's the case, it is, without a doubt, a regulatory obligation for many. So, what is "education" and what is going on in the world of learning and development which might help us to re-think the human factor?

    In this episode our guest, Teisa Marshik, a respected educational psychologist and passionate educator, shares how her's and her colleagues approach to educating learners is changing. We cover everything from how the effectiveness and success of education is measured, through to how advances in our understanding of human behaviour and culture, mean we now recognise that students are consuming and responding to education content based on their own life experiences and situations and what this means for traditional best practices in L&D.

     

    Understand the forces at play.

    Understand the forces at play.

    Our guest, is Dr. Ben Evans. Ben is an aeronautical engineer, and he’s applying his understanding of the forces at play, to the seemingly insurmountable challenge of conquering the breaking a world record at the Bloodhound Land Speed Project.

    Ben talks about the laws of science and engineering which help him to find the marginal opportunities for improvement which are helping the team towards breaking the world record. But, in this interview, it’s also clear to me, that success is a matter of teamwork often with colleagues with different and sometimes conflicting priorities.

    Understanding the forces at play includes understanding science and nature, even when it comes to human awareness, behaviour and culture, but it’s also about understanding the forces at play across stakeholders, where often conflicting priorities and interests can arise. Getting the “Team” aspect right, you could argue is as important as the science which drives decision its self.

    Versace, Burberry and Lacoste. Thoughts from branding.

    Versace, Burberry and Lacoste. Thoughts from branding.

    In this episode we delve into the world of branding with the out standing Geraldine Michel and explore possibilities for security professionals responsible for the human factor.

    We draw on lessons from the world of fashion, by skirting through branding and how Brand Directors and Managers utilise this mammoth of the modern day commercial world to shape and influence behaviour and culture. 

    An internal communications perspective.

    An internal communications perspective.

    Internal communications is a major stakeholder in employee awareness, behaviour and culture. We often defer to their skills and experience as the specialists in communication strategy for reaching out to internal staff. However, there's something a foot in the industry. Traditional ideas of what makes "good internal communications" are being challenged and our good friend "behavioural science" has been a great influence on the thought leaders in the field of communications. In this episode  I talk with one such thought leader.

    The human factor in the middle of a major security breach.

    The human factor in the middle of a major security breach.

    In previous episodes of the podcast we have explored why human judgement and decision making, which drives our behaviour, is heavily influenced by the environment within which we make our decisions.

    In this episode we take this one step further and ask how employee awareness, behaviour and culture pans out, after all of the theorising and planning, when the tranquil environment of corporate learning is replaced by the rawness of a major security crisis.

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io