Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I get to speak to a masters in cyber security class at a major university on Monday.

I get to speak to a masters in cyber security class at a major university on Monday.

Scheduled Pinned Locked Moved Uncategorized
39 Posts 29 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jerry@infosec.exchangeJ jerry@infosec.exchange

    I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

    pesky_warlock@ioc.exchangeP This user is from outside of this forum
    pesky_warlock@ioc.exchangeP This user is from outside of this forum
    pesky_warlock@ioc.exchange
    wrote last edited by
    #19

    @jerry For high-level Corp. mgmt., communication governance in an incident is key. They may have to manage confidentiality while allowing the investigation to proceed, and they shouldn't allow info to propagate, even though high-ranked officials will demand access to the info. The story could get out before they could control this, which (obvs) will be detrimental to the stock price.

    1 Reply Last reply
    0
    • jerry@infosec.exchangeJ jerry@infosec.exchange

      I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

      jerry@infosec.exchangeJ This user is from outside of this forum
      jerry@infosec.exchangeJ This user is from outside of this forum
      jerry@infosec.exchange
      wrote last edited by
      #20

      I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

      da_667@infosec.exchangeD wendynather@infosec.exchangeW 0x58@infosec.exchange0 krypt3ia@infosec.exchangeK hotsoup@infosec.exchangeH 7 Replies Last reply
      0
      • jerry@infosec.exchangeJ jerry@infosec.exchange

        I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

        so1arp0wer@mastodon.socialS This user is from outside of this forum
        so1arp0wer@mastodon.socialS This user is from outside of this forum
        so1arp0wer@mastodon.social
        wrote last edited by
        #21

        @jerry ROI , risk management, and throw in whaling examples. Have them think of a DFIR budget as insurance.

        1 Reply Last reply
        0
        • R relay@relay.an.exchange shared this topic
        • jerry@infosec.exchangeJ jerry@infosec.exchange

          I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

          da_667@infosec.exchangeD This user is from outside of this forum
          da_667@infosec.exchangeD This user is from outside of this forum
          da_667@infosec.exchange
          wrote last edited by
          #22

          @jerry cybersecurity means being both the problem and the solution. ducks

          1 Reply Last reply
          0
          • jerry@infosec.exchangeJ jerry@infosec.exchange

            I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

            wendynather@infosec.exchangeW This user is from outside of this forum
            wendynather@infosec.exchangeW This user is from outside of this forum
            wendynather@infosec.exchange
            wrote last edited by
            #23

            @jerry Nah. I didn’t, and it went fine.

            1 Reply Last reply
            0
            • jerry@infosec.exchangeJ jerry@infosec.exchange

              I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

              0x58@infosec.exchange0 This user is from outside of this forum
              0x58@infosec.exchange0 This user is from outside of this forum
              0x58@infosec.exchange
              wrote last edited by
              #24

              @jerry Call it Super Security.

              1 Reply Last reply
              0
              • jerry@infosec.exchangeJ jerry@infosec.exchange

                I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                sensorlock@infosec.exchangeS This user is from outside of this forum
                sensorlock@infosec.exchangeS This user is from outside of this forum
                sensorlock@infosec.exchange
                wrote last edited by
                #25

                @jerry This is broader than just risk, but my advice on talking to top leadership is to pay very close attention to the questions they ask. They are trying to make decisions about what the company should do, and if you are talking to them, it's likely because someone thinks you have information that could help them make that decision.

                Have understandable answers and plan for the follow-up questions. Identify the key points you think the leaders need to know but may not know to ask.

                1 Reply Last reply
                0
                • jerry@infosec.exchangeJ jerry@infosec.exchange

                  I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                  pesky_warlock@ioc.exchangeP This user is from outside of this forum
                  pesky_warlock@ioc.exchangeP This user is from outside of this forum
                  pesky_warlock@ioc.exchange
                  wrote last edited by
                  #26

                  @jerry Also, it absolutely has to be established that Infosec runs the investigation, and can be allowed to turn things off. I once ran an incident communications workshop where the PR dept. said flatly: we will be running the investigation, as if they knew anything about systems. They wanted to govern the story completely.

                  1 Reply Last reply
                  0
                  • sempf@infosec.exchangeS sempf@infosec.exchange

                    @da_667 @Viss @DamonHD @jerry I have 7/8 of a music degree.

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote last edited by
                    #27

                    @Sempf @da_667 @DamonHD @jerry sure, its totally possible for people to be nerds and that not match their major. ive just encountered so many people with a 'masters in cybercyber' that dont have even basic experience, like installing an os or configuring a linksys its tainted the whole degree for me

                    1 Reply Last reply
                    0
                    • sempf@infosec.exchangeS sempf@infosec.exchange

                      @da_667 @Viss @DamonHD @jerry I have 7/8 of a music degree.

                      damonhd@mastodon.socialD This user is from outside of this forum
                      damonhd@mastodon.socialD This user is from outside of this forum
                      damonhd@mastodon.social
                      wrote last edited by
                      #28

                      @Sempf @da_667 @Viss @jerry An education and a time signature! B^>

                      1 Reply Last reply
                      0
                      • jerry@infosec.exchangeJ jerry@infosec.exchange

                        I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                        krypt3ia@infosec.exchangeK This user is from outside of this forum
                        krypt3ia@infosec.exchange
                        wrote last edited by
                        #29

                        @jerry It’s when you “cyber” securely, e.g. door closed, lights off, all alone.

                        1 Reply Last reply
                        0
                        • jerry@infosec.exchangeJ jerry@infosec.exchange

                          I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                          kevinflynn@c.imK This user is from outside of this forum
                          kevinflynn@c.imK This user is from outside of this forum
                          kevinflynn@c.im
                          wrote last edited by
                          #30

                          @jerry
                          Risk, as a cost

                          1 Reply Last reply
                          0
                          • da_667@infosec.exchangeD da_667@infosec.exchange

                            @jerry relating any recommendations to financial impact is all they care about. How much it will cost to implement, vs. how much it'll cost if we don't implement it.

                            jan@social.eden.oneJ This user is from outside of this forum
                            jan@social.eden.oneJ This user is from outside of this forum
                            jan@social.eden.one
                            wrote last edited by
                            #31

                            @da_667 @jerry Walk the fine line between fearmongering and allowing the BoD to snooze.

                            1 Reply Last reply
                            0
                            • jerry@infosec.exchangeJ jerry@infosec.exchange

                              I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

                              hotsoup@infosec.exchangeH This user is from outside of this forum
                              hotsoup@infosec.exchangeH This user is from outside of this forum
                              hotsoup@infosec.exchange
                              wrote last edited by
                              #32

                              @jerry I put on my robe and wizard hat… securely

                              jerry@infosec.exchangeJ cali@infosec.exchangeC 2 Replies Last reply
                              0
                              • hotsoup@infosec.exchangeH hotsoup@infosec.exchange

                                @jerry I put on my robe and wizard hat… securely

                                jerry@infosec.exchangeJ This user is from outside of this forum
                                jerry@infosec.exchangeJ This user is from outside of this forum
                                jerry@infosec.exchange
                                wrote last edited by
                                #33

                                @hotsoup I doubt anyone there will be old enough to understand that reference

                                jjbaumgartner@infosec.exchangeJ 1 Reply Last reply
                                0
                                • jerry@infosec.exchangeJ jerry@infosec.exchange

                                  I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                                  pesky_warlock@ioc.exchangeP This user is from outside of this forum
                                  pesky_warlock@ioc.exchangeP This user is from outside of this forum
                                  pesky_warlock@ioc.exchange
                                  wrote last edited by
                                  #34

                                  @jerry Also generally, security risk frameworks don't align with financial risks. To quote Jacquith, how do controls relate to business value? This is the problem they're going to have to solve.

                                  1 Reply Last reply
                                  0
                                  • jerry@infosec.exchangeJ jerry@infosec.exchange

                                    I get to speak to a masters in cyber security class at a major university on Monday. They are learning about interacting with senior leadership/BoD on topics of cyber risk. I have many stories to share with them, but curious if y’all have any ideas on what you thank that group should know

                                    noplasticshower@infosec.exchangeN This user is from outside of this forum
                                    noplasticshower@infosec.exchangeN This user is from outside of this forum
                                    noplasticshower@infosec.exchange
                                    wrote last edited by
                                    #35

                                    @jerry have you read the CISO Report?

                                    https://www.garymcgraw.com/wp-content/uploads/2018/01/CISO-2017.pdf

                                    1 Reply Last reply
                                    0
                                    • jerry@infosec.exchangeJ jerry@infosec.exchange

                                      @hotsoup I doubt anyone there will be old enough to understand that reference

                                      jjbaumgartner@infosec.exchangeJ This user is from outside of this forum
                                      jjbaumgartner@infosec.exchangeJ This user is from outside of this forum
                                      jjbaumgartner@infosec.exchange
                                      wrote last edited by
                                      #36

                                      @jerry @hotsoup Damn it, that means I'm the same age as old people.

                                      1 Reply Last reply
                                      0
                                      • jerry@infosec.exchangeJ jerry@infosec.exchange

                                        I should probably figure out what cyber security means before I go speak to a masters class about cyber security.

                                        kwayk42@sechtor.socialK This user is from outside of this forum
                                        kwayk42@sechtor.socialK This user is from outside of this forum
                                        kwayk42@sechtor.social
                                        wrote last edited by
                                        #37

                                        @jerry going all philosophical

                                        1 Reply Last reply
                                        0
                                        • hotsoup@infosec.exchangeH hotsoup@infosec.exchange

                                          @jerry I put on my robe and wizard hat… securely

                                          cali@infosec.exchangeC This user is from outside of this forum
                                          cali@infosec.exchangeC This user is from outside of this forum
                                          cali@infosec.exchange
                                          wrote last edited by
                                          #38

                                          @hotsoup @jerry “I cast lvl 3 eroticism..”

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups