Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I get to speak to a masters in cyber security class at a major university on Monday.

I get to speak to a masters in cyber security class at a major university on Monday.

Scheduled Pinned Locked Moved Uncategorized
39 Posts 29 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jerry@infosec.exchangeJ jerry@infosec.exchange

    I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

    da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchange
    wrote last edited by
    #2

    @jerry relating any recommendations to financial impact is all they care about. How much it will cost to implement, vs. how much it'll cost if we don't implement it.

    damonhd@mastodon.socialD da_667@infosec.exchangeD jan@social.eden.oneJ 3 Replies Last reply
    0
    • jerry@infosec.exchangeJ jerry@infosec.exchange

      I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

      j4yc33@infosec.exchangeJ This user is from outside of this forum
      j4yc33@infosec.exchangeJ This user is from outside of this forum
      j4yc33@infosec.exchange
      wrote last edited by
      #3

      @jerry The importance of being able to marry technical jargon and precision with a layperson's understanding.

      I have had so many senior leadership/Board discussions and it always boils down to being able to have a depth of understanding that allows for that ELI5 type of communication.

      1 Reply Last reply
      0
      • jerry@infosec.exchangeJ jerry@infosec.exchange

        I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

        subm3rge@infosec.exchangeS This user is from outside of this forum
        subm3rge@infosec.exchangeS This user is from outside of this forum
        subm3rge@infosec.exchange
        wrote last edited by
        #4

        @jerry Knowing Corporate only gets you that far, at some point you must know the Individuals.

        Risk perception and appetite is a deeply personal trait.

        1 Reply Last reply
        0
        • jerry@infosec.exchangeJ jerry@infosec.exchange

          I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

          joriki@infosec.exchangeJ This user is from outside of this forum
          joriki@infosec.exchangeJ This user is from outside of this forum
          joriki@infosec.exchange
          wrote last edited by
          #5

          @jerry

          just enjoying the idea of referring to senior leadership as the blue screen of death 💀

          1 Reply Last reply
          0
          • da_667@infosec.exchangeD da_667@infosec.exchange

            @jerry relating any recommendations to financial impact is all they care about. How much it will cost to implement, vs. how much it'll cost if we don't implement it.

            damonhd@mastodon.socialD This user is from outside of this forum
            damonhd@mastodon.socialD This user is from outside of this forum
            damonhd@mastodon.social
            wrote last edited by
            #6

            @da_667 @jerry Yes, indeed. Especially the bean counters need to have an NPV waved at them!

            But the rest of the board should also care about reputational risk.

            So the lesson is that while CxO should care about data security and operational integrity - and the tech and training that that implies - it may need to be translated into money and shame to be salient...

            viss@mastodon.socialV 1 Reply Last reply
            0
            • damonhd@mastodon.socialD damonhd@mastodon.social

              @da_667 @jerry Yes, indeed. Especially the bean counters need to have an NPV waved at them!

              But the rest of the board should also care about reputational risk.

              So the lesson is that while CxO should care about data security and operational integrity - and the tech and training that that implies - it may need to be translated into money and shame to be salient...

              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.socialV This user is from outside of this forum
              viss@mastodon.social
              wrote last edited by
              #7

              @DamonHD @da_667 @jerry i dare you to ask them how many have any technical background whatsoever

              da_667@infosec.exchangeD 1 Reply Last reply
              0
              • jerry@infosec.exchangeJ jerry@infosec.exchange

                I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                vinterkarusell@infosec.exchangeV This user is from outside of this forum
                vinterkarusell@infosec.exchangeV This user is from outside of this forum
                vinterkarusell@infosec.exchange
                wrote last edited by
                #8

                @jerry ask if they are on this instance! 🤭

                1 Reply Last reply
                0
                • da_667@infosec.exchangeD da_667@infosec.exchange

                  @jerry relating any recommendations to financial impact is all they care about. How much it will cost to implement, vs. how much it'll cost if we don't implement it.

                  da_667@infosec.exchangeD This user is from outside of this forum
                  da_667@infosec.exchangeD This user is from outside of this forum
                  da_667@infosec.exchange
                  wrote last edited by
                  #9

                  @jerry this also relates to budgeting for new tools, and head count. Learn to create proposals for head count and/or tooling. Including cost figures in those figures. I worked tech support at Sourcefire for a number of years, and had team leads who were bitching that we didn't have all the tools we need to do the job. One of them would put a draft together, submit it, the boss would ask "where are the costs?" and it would NEVER progress. It all comes down to cost. If you don't mention cost, they don't care.

                  1 Reply Last reply
                  0
                  • viss@mastodon.socialV viss@mastodon.social

                    @DamonHD @da_667 @jerry i dare you to ask them how many have any technical background whatsoever

                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchangeD This user is from outside of this forum
                    da_667@infosec.exchange
                    wrote last edited by
                    #10

                    @Viss @DamonHD @jerry I had a music major as my datacenter ops manager.

                    I want you to understand, I know that sometimes, someone changing majors and/or professions sometimes happens and that these people can be quite good in a totally difference space (edit:clarification), but this dude paid for a cleaning service that does datacenters to come and clean the datacenter. It didn't really need it, and was genuinely a waste.

                    Now, us replacing all of our network fabric, and re-doing our cable management, which was another huge endeavor, was a big win.

                    sempf@infosec.exchangeS 1 Reply Last reply
                    0
                    • jerry@infosec.exchangeJ jerry@infosec.exchange

                      I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                      alister@hachyderm.ioA This user is from outside of this forum
                      alister@hachyderm.ioA This user is from outside of this forum
                      alister@hachyderm.io
                      wrote last edited by
                      #11

                      @jerry I'd suggest two things: a) Ethics - should you do something, or should you say something when you discover a problem?

                      b) A couple of stories about why security researchers/sysadmins can be like magicians - because we will spend an inordinate amount of time on doing some tiny thing to absolute perfection in order to find out something that is bugging us:

                      1/ Clifford Stoll found an unauthorized user who had apparently used nine seconds/75cents of computer time and not paid for it. It was a KGB Hacker. Oh, and "The Cuckoos Egg" had a nice cookie recipe too.

                      2/ The XZ Backdoor was found by a user, testing SSH, who saw that logins were taking too long.....

                      1 Reply Last reply
                      0
                      • jerry@infosec.exchangeJ jerry@infosec.exchange

                        I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                        avuko@infosec.exchangeA This user is from outside of this forum
                        avuko@infosec.exchangeA This user is from outside of this forum
                        avuko@infosec.exchange
                        wrote last edited by
                        #12

                        @jerry Understand what the personal risks are for the board. Usually it is tied to shareholder value and/or profit loss.

                        Play on that. In for-profits, nothing else will work.

                        Sorry to sound so cynical.

                        1 Reply Last reply
                        0
                        • jerry@infosec.exchangeJ jerry@infosec.exchange

                          I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                          simplenomad@rigor-mortis.nmrc.orgS This user is from outside of this forum
                          simplenomad@rigor-mortis.nmrc.orgS This user is from outside of this forum
                          simplenomad@rigor-mortis.nmrc.org
                          wrote last edited by
                          #13

                          @jerry Let them know that despite there being plenty of anti-AI sentiment out in the world, it is not only NOT going away but it is up to the security community to fix it. Just like we did with PHP when that came out spawning hundreds of vulnerable websites from non-HTML programmers. Just like we did when we moved from server rooms to the cloud. Before HTTPS. And on and on. Whether we like it or not, security pros have to fix things.

                          n_dimension@infosec.exchangeN joshbressers@infosec.exchangeJ 2 Replies Last reply
                          1
                          0
                          • jerry@infosec.exchangeJ jerry@infosec.exchange

                            I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                            n_dimension@infosec.exchangeN This user is from outside of this forum
                            n_dimension@infosec.exchangeN This user is from outside of this forum
                            n_dimension@infosec.exchange
                            wrote last edited by
                            #14

                            @jerry
                            #Ai is a new attack surface.

                            1 Reply Last reply
                            0
                            • jerry@infosec.exchangeJ jerry@infosec.exchange

                              I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                              manicpxisiemgrl@infosec.exchangeM This user is from outside of this forum
                              manicpxisiemgrl@infosec.exchangeM This user is from outside of this forum
                              manicpxisiemgrl@infosec.exchange
                              wrote last edited by
                              #15

                              @jerry relaying how their org is doing when compared with their peers. I get asked that on the weekly. Understanding the risk completely and how that impacts the org is really important too, and being able to explain that risk. Don't misspeak either, especially in consulting roles.

                              Don't be that nervous. They're just people at the end of the day who (hopefully) want to see their org mitigating future attacks. This one I notice a large difference between internal and consulting roles.

                              1 Reply Last reply
                              0
                              • simplenomad@rigor-mortis.nmrc.orgS simplenomad@rigor-mortis.nmrc.org

                                @jerry Let them know that despite there being plenty of anti-AI sentiment out in the world, it is not only NOT going away but it is up to the security community to fix it. Just like we did with PHP when that came out spawning hundreds of vulnerable websites from non-HTML programmers. Just like we did when we moved from server rooms to the cloud. Before HTTPS. And on and on. Whether we like it or not, security pros have to fix things.

                                n_dimension@infosec.exchangeN This user is from outside of this forum
                                n_dimension@infosec.exchangeN This user is from outside of this forum
                                n_dimension@infosec.exchange
                                wrote last edited by
                                #16

                                @jerry @simplenomad

                                GIVE THIS PERSON AN AWARD!!!
                                🎖️🏅🥇

                                1 Reply Last reply
                                0
                                • da_667@infosec.exchangeD da_667@infosec.exchange

                                  @Viss @DamonHD @jerry I had a music major as my datacenter ops manager.

                                  I want you to understand, I know that sometimes, someone changing majors and/or professions sometimes happens and that these people can be quite good in a totally difference space (edit:clarification), but this dude paid for a cleaning service that does datacenters to come and clean the datacenter. It didn't really need it, and was genuinely a waste.

                                  Now, us replacing all of our network fabric, and re-doing our cable management, which was another huge endeavor, was a big win.

                                  sempf@infosec.exchangeS This user is from outside of this forum
                                  sempf@infosec.exchangeS This user is from outside of this forum
                                  sempf@infosec.exchange
                                  wrote last edited by
                                  #17

                                  @da_667 @Viss @DamonHD @jerry I have 7/8 of a music degree.

                                  viss@mastodon.socialV damonhd@mastodon.socialD 2 Replies Last reply
                                  0
                                  • simplenomad@rigor-mortis.nmrc.orgS simplenomad@rigor-mortis.nmrc.org

                                    @jerry Let them know that despite there being plenty of anti-AI sentiment out in the world, it is not only NOT going away but it is up to the security community to fix it. Just like we did with PHP when that came out spawning hundreds of vulnerable websites from non-HTML programmers. Just like we did when we moved from server rooms to the cloud. Before HTTPS. And on and on. Whether we like it or not, security pros have to fix things.

                                    joshbressers@infosec.exchangeJ This user is from outside of this forum
                                    joshbressers@infosec.exchangeJ This user is from outside of this forum
                                    joshbressers@infosec.exchange
                                    wrote last edited by
                                    #18

                                    @simplenomad @jerry I just make all my prompts end with “and be sure you make it secure” and everything is fine

                                    1 Reply Last reply
                                    0
                                    • jerry@infosec.exchangeJ jerry@infosec.exchange

                                      I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                                      pesky_warlock@ioc.exchangeP This user is from outside of this forum
                                      pesky_warlock@ioc.exchangeP This user is from outside of this forum
                                      pesky_warlock@ioc.exchange
                                      wrote last edited by
                                      #19

                                      @jerry For high-level Corp. mgmt., communication governance in an incident is key. They may have to manage confidentiality while allowing the investigation to proceed, and they shouldn't allow info to propagate, even though high-ranked officials will demand access to the info. The story could get out before they could control this, which (obvs) will be detrimental to the stock price.

                                      1 Reply Last reply
                                      0
                                      • jerry@infosec.exchangeJ jerry@infosec.exchange

                                        I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                                        jerry@infosec.exchangeJ This user is from outside of this forum
                                        jerry@infosec.exchangeJ This user is from outside of this forum
                                        jerry@infosec.exchange
                                        wrote last edited by
                                        #20

                                        I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

                                        da_667@infosec.exchangeD wendynather@infosec.exchangeW 0x58@infosec.exchange0 krypt3ia@infosec.exchangeK hotsoup@infosec.exchangeH 7 Replies Last reply
                                        0
                                        • jerry@infosec.exchangeJ jerry@infosec.exchange

                                          I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                                          so1arp0wer@mastodon.socialS This user is from outside of this forum
                                          so1arp0wer@mastodon.socialS This user is from outside of this forum
                                          so1arp0wer@mastodon.social
                                          wrote last edited by
                                          #21

                                          @jerry ROI , risk management, and throw in whaling examples. Have them think of a DFIR budget as insurance.

                                          1 Reply Last reply
                                          0
                                          • R relay@relay.an.exchange shared this topic
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups