Logo

    How To Optimize Your Security Budget

    enJune 19, 2020
    What was the main topic of the podcast episode?
    Summarise the key points discussed in the episode?
    Were there any notable quotes or insights from the speakers?
    Which popular books were mentioned in this episode?
    Were there any points particularly controversial or thought-provoking discussed in the episode?
    Were any current events or trending topics addressed in the episode?

    About this Episode

    In today’s DailyCyber Podcast I discuss two topics I keep hearing more about through my conversations with colleagues and through Cyber Security news:

     

     

    CISO Dialogue: How to Optimize Your Security Budget

     

    "There are many different approaches to managing a security budget, and CISOs organize and prioritize uniquely based on the company, industry, and threats. Three consistent areas of spending are identity and access management (IAM), global risk and compliance (GRC), and security operations,” Brett Wahlin CISO of Amazon Prime Video noting:

     

    * IAM is always a mess because no one wants to deal with access management, passwords, access sprawl, and so on.  

    * GRC is difficult because there are always new regulations to remain compliant with; privacy, in particular, is an ongoing challenge.

    * With security operations, levels of effectiveness vary. Wahlin posed several questions for consideration. "Is it in-house? Are you outsourcing to an MSSP? How are you measuring effectiveness? It's an area where I often have to retool from a people, process, and technology standpoint."

     

    Top Tips for New CISOs

    Brett Wahlin concluded with a breakdown of the most important things he would recommend a new CISO look at, both budgetary and beyond:

    * Look at the three most problematic areas: IAM, GRC, and SecOps. You can always find things to fix, and it will give you some quick wins.

    * Know your industry and how your security program can help the company grow.

    * You need to be able to constantly communicate the value you're bringing to the table — it's how you'll get budget and, more importantly, it's how you keep it.

    * "Partnering with the business" is not just a catch phrase batted around at security conferences. Learn what it means for your company and be a good partner.

    * Think like an architect: As you build a program, how do the different functions interact with each other? How do you plan to grow based on shared communication?

    * Don't be afraid to pull something out if it's not raising the security bar for your company.  

     

    https://www.darkreading.com/operations/ciso-dialogue-how-to-optimize-your-security-budget-/a/d-id/1338055

     

     

    76.36% Believe Cloud Service Provider is Responsible for Security: CISO MAG Market Trends Report

    From CISO Mag’s Cloud Security survey then found

    76.36% said that cloud service providers (CSP) is entirely responsible for the security of the cloud

    23.64% they said 40% in the article - stated the responsibility is on the cloud consumer  

    Looking at these numbers you can tell that the “Shared Responsibility” as Amazon refers to it. Is not truly understood just by this survey alone.  

    AWS defined a Shared Responsibility model that says “Security of the Cloud” is the responsibility of the CSP (Cloud Security Provider), but “Security in the cloud” is the responsibility of the customer. This model is gradually being accepted in the industry.

     

    https://www.cisomag.com/shared-responsibility-model/

     

    To learn more watch the video or listen to the podcast at www.DailyCyber.ca and comment below

     

    Recent Episodes from DailyCyber The Truth About Cyber Security with Brandon Krieger

    Ask Real Life CISO Mike Melo Your Cyber Security Questions | DailyCyber 265

    Ask Real Life CISO Mike Melo Your Cyber Security Questions | DailyCyber 265

    In today’s DailyCyber Podcast I am fortunate to have Mike Melo CISO of LifeLabs on my DailyCyber stream. He answers real life questions to give you insight into the real world of Cyber Security.  

     

    To learn more watch the video or listen to the podcast at www.DailyCyber.ca and comment below 

    Ask Real Life CISO Allan Alford Your Cyber Security Questions

    Ask Real Life CISO Allan Alford Your Cyber Security Questions

    Ask Real Life CISO Allan Alford Your Cyber Security Questions | DailyCyber 261 ~ Watch Now ~


     

    https://youtu.be/CSMuUkv7j-o


     

    In today’s DailyCyber Podcast I am fortunate to have Allan Alford as a guest to answer real life Cyber Security questions that Cyber Security professionals want to know. 


     

    https://allanalford.com/

    https://www.linkedin.com/in/allanalford/

    https://twitter.com/AllanAlfordinTX


     

    Recommended links we discuss through the stream: 

    https://hackervalley.com/cyberranch

    https://www.linkedin.com/in/naomi-buckwalter/

    https://podcasts.apple.com/us/podcast/breaking-into-cybersecurity/id1463136698


     

    To learn more watch the video or listen to the podcast at www.DailyCyber.ca and comment below 

    Advance Life Hacks for Cyber Security Professionals Part 2

    Advance Life Hacks for Cyber Security Professionals Part 2

    In today’s DailyCyber Podcast Brandon is going to share some advance Life Hacks for Cyber Security Professionals that he has learned over the years mentoring business professionals. 



    To learn more watch the video or listen to the podcast at www.DailyCyber.ca and comment below 


     

    #DailyCyber260, #BrandonKrieger, #Cybersecurity, #cybersecuritynews, #Cybersecurityawareness, #Cyberthreats, 

    What is Cyber Threat Intelligence with Jim McKee

    What is Cyber Threat Intelligence with Jim McKee

    In today’s DailyCyber Podcast I have the fortunate opportunity to interview Jim McKee who is an expert in Cyber Threat Intelligence. We are going to dive in deep why Cyber Threat Intelligence is important to protect your business. 


     

    Website:  https://www.wapacklabs.com

    Linkedin:  https://www.linkedin.com/in/jimckee/


     


     

    To learn more watch the video or listen to the podcast at www.DailyCyber.ca and comment below 

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io