SlideShare a Scribd company logo
1 of 16
Download to read offline
Conference2015
San Francisco | April 20-24 | Moscone Center
When your CEO asks,
“Are we secure?” what do you say?
“As secure as
we can be.”
- Chris Egaaen, Sycomp
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“We could be
more secure
if you give me
more money.”
- Jennifer Graham
SunTrust Banks, Inc.
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“We’re only
as secure as
the things we
know about.”
- Jay Schwitzgebel
HealthPlan Services
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“According
to our audits
we’re doing
a good job.”
- Steven Lodin, Sallie Mae Bank
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“I think we’re
pretty secure
but it’s always a
moving target.”
- Rhonda Simmon, New York Life
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“As good as it gets,
my friend. You’re
never as secure as
you can be. It’s about
risk management.”
- Tony Zirnoon, Global Security Strategy
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“Very secure, but we’re
only one incident away
from a problem as is
every other company.”
- Christina Critzer, SunTrust Banks, Inc.
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“The hackers are just as
good as we are, and we’re
constantly fighting. We
have to be right 100% of
the time. They have to be
right one.”
- David Rooker, Actian Corporation
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“We are as secure as we
can be today. We are
continuing to mature,
and we'll be more
secure tomorrow.”
- John Graham, Jabil
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“I’d first ask what
are our goals? How
do we define being
secure? How do we
define what we are
going to measure?”
- Bill Olson, Tenable Network Security
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“We have a number of
threat vectors that we
watch, and we have
made a number of
investments on those.”
- Alex Hutton, IANS
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“The key thing we do
is we go and look at
benchmarks and see
how we compare on
it. So, probably not
secure enough, but
trying to get there.”
- Kenneth Haertling, Telus
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“We are aiming for ‘secure
enough.’ Not ‘too secure’
because that means you
are spending money you
don't need to spend, and
‘not secure enough’
means you get owned.”
- David Mortman, Dell
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“Today we’re about
medium. Medium
means right now
we don't have any
active attacks, and
we're monitoring
the situation.”
- Greg Press, Munich Re
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?
“Based on industry practices,
we've done the best that we can.
Using something like
SecurityCenter makes it easy to
say you've done best practices
recommended by the government,
by the payment card industry, by
penetration testers, and the really,
really basic cyber hygiene things.”
- Ron Gula, Tenable Network Security
Watch the #RSAC video: bit.ly/how-secure
If your CEO asks, “How secure are we?” what do you say?

More Related Content

Viewers also liked

Viewers also liked (8)

What should I be scared about today?
What should I be scared about today?What should I be scared about today?
What should I be scared about today?
 
Nutanix and microsoft_webinar_oct_28
Nutanix and microsoft_webinar_oct_28Nutanix and microsoft_webinar_oct_28
Nutanix and microsoft_webinar_oct_28
 
Navigating the PCI Self-Assessment questionaire
Navigating the PCI Self-Assessment questionaireNavigating the PCI Self-Assessment questionaire
Navigating the PCI Self-Assessment questionaire
 
Shadow IT
Shadow ITShadow IT
Shadow IT
 
Technical debt in cyber ark [agile practitioners-2015]
Technical debt in cyber ark [agile practitioners-2015]Technical debt in cyber ark [agile practitioners-2015]
Technical debt in cyber ark [agile practitioners-2015]
 
CyberArk
CyberArkCyberArk
CyberArk
 
Managing privileged account security
Managing privileged account securityManaging privileged account security
Managing privileged account security
 
What was your worst day in IT?
What was your worst day in IT?What was your worst day in IT?
What was your worst day in IT?
 

Similar to When your CEO asks, "Are we secure?" what do you say?

How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
How to Communicate the Actual Readiness of your IT Security Program for PCI 3...How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
RedZone Technologies
 
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
Shawn Tuma
 
The 10 Secret Codes of Security
The 10 Secret Codes of SecurityThe 10 Secret Codes of Security
The 10 Secret Codes of Security
Karina Elise
 
Independent-Fall-2015-Edition
Independent-Fall-2015-EditionIndependent-Fall-2015-Edition
Independent-Fall-2015-Edition
Todd C. Schultze
 
Slides to the online event "Creating an effective cybersecurity strategy" by ...
Slides to the online event "Creating an effective cybersecurity strategy" by ...Slides to the online event "Creating an effective cybersecurity strategy" by ...
Slides to the online event "Creating an effective cybersecurity strategy" by ...
Berezha Security Group
 

Similar to When your CEO asks, "Are we secure?" what do you say? (20)

How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
How to Communicate the Actual Readiness of your IT Security Program for PCI 3...How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
How to Communicate the Actual Readiness of your IT Security Program for PCI 3...
 
Running with Scissors: Balance between business and InfoSec needs
Running with Scissors: Balance between business and InfoSec needsRunning with Scissors: Balance between business and InfoSec needs
Running with Scissors: Balance between business and InfoSec needs
 
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
SecureWorld Expo Dallas - Cybersecurity Law: What Business and IT Leaders Nee...
 
How to Secure America
How to Secure AmericaHow to Secure America
How to Secure America
 
The 10 Secret Codes of Security
The 10 Secret Codes of SecurityThe 10 Secret Codes of Security
The 10 Secret Codes of Security
 
Independent-Fall-2015-Edition
Independent-Fall-2015-EditionIndependent-Fall-2015-Edition
Independent-Fall-2015-Edition
 
AFCOM - Information Security State of the Union
AFCOM - Information Security State of the UnionAFCOM - Information Security State of the Union
AFCOM - Information Security State of the Union
 
The State of Safety Culture in Mining Webinar - Slides.pdf
The State of Safety Culture in Mining Webinar - Slides.pdfThe State of Safety Culture in Mining Webinar - Slides.pdf
The State of Safety Culture in Mining Webinar - Slides.pdf
 
CB Insights Live: Startups And Accelerating Corporate Innovation
CB Insights Live: Startups And Accelerating Corporate InnovationCB Insights Live: Startups And Accelerating Corporate Innovation
CB Insights Live: Startups And Accelerating Corporate Innovation
 
BIZGrowth Strategies Summer 2015
BIZGrowth Strategies Summer 2015BIZGrowth Strategies Summer 2015
BIZGrowth Strategies Summer 2015
 
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER VersionPCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
 
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER VersionPCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
 
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER VersionPCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
 
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER VersionPCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
 
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER VersionPCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
PCI DSS: Myths, Mistakes, Misconceptions 2009 - TEASER Version
 
Ken at Peaks
Ken at PeaksKen at Peaks
Ken at Peaks
 
CONFIDENCIALIDAD DE LA INFORMACION
CONFIDENCIALIDAD DE LA INFORMACIONCONFIDENCIALIDAD DE LA INFORMACION
CONFIDENCIALIDAD DE LA INFORMACION
 
Security Snake Oil Cycle 2019
Security Snake Oil Cycle 2019Security Snake Oil Cycle 2019
Security Snake Oil Cycle 2019
 
Cybercrime and the Developer Java2Days 2016 Sofia
Cybercrime and the Developer Java2Days 2016 SofiaCybercrime and the Developer Java2Days 2016 Sofia
Cybercrime and the Developer Java2Days 2016 Sofia
 
Slides to the online event "Creating an effective cybersecurity strategy" by ...
Slides to the online event "Creating an effective cybersecurity strategy" by ...Slides to the online event "Creating an effective cybersecurity strategy" by ...
Slides to the online event "Creating an effective cybersecurity strategy" by ...
 

Recently uploaded

Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
HyderabadDolls
 
Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
ranjankumarbehera14
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
wsppdmt
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
nirzagarg
 
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
gajnagarg
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptx
chadhar227
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
gajnagarg
 

Recently uploaded (20)

Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
Sealdah % High Class Call Girls Kolkata - 450+ Call Girl Cash Payment 8005736...
 
20240412-SmartCityIndex-2024-Full-Report.pdf
20240412-SmartCityIndex-2024-Full-Report.pdf20240412-SmartCityIndex-2024-Full-Report.pdf
20240412-SmartCityIndex-2024-Full-Report.pdf
 
Ranking and Scoring Exercises for Research
Ranking and Scoring Exercises for ResearchRanking and Scoring Exercises for Research
Ranking and Scoring Exercises for Research
 
Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1Lecture_2_Deep_Learning_Overview-newone1
Lecture_2_Deep_Learning_Overview-newone1
 
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book nowVadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
Vadodara 💋 Call Girl 7737669865 Call Girls in Vadodara Escort service book now
 
Discover Why Less is More in B2B Research
Discover Why Less is More in B2B ResearchDiscover Why Less is More in B2B Research
Discover Why Less is More in B2B Research
 
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
如何办理英国诺森比亚大学毕业证(NU毕业证书)成绩单原件一模一样
 
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
Top profile Call Girls In Hapur [ 7014168258 ] Call Me For Genuine Models We ...
 
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...Top Call Girls in Balaghat  9332606886Call Girls Advance Cash On Delivery Ser...
Top Call Girls in Balaghat 9332606886Call Girls Advance Cash On Delivery Ser...
 
Dubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls DubaiDubai Call Girls Peeing O525547819 Call Girls Dubai
Dubai Call Girls Peeing O525547819 Call Girls Dubai
 
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Vadodara [ 7014168258 ] Call Me For Genuine Models ...
 
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
5CL-ADBA,5cladba, Chinese supplier, safety is guaranteed
 
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptxRESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
RESEARCH-FINAL-DEFENSE-PPT-TEMPLATE.pptx
 
Gartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptxGartner's Data Analytics Maturity Model.pptx
Gartner's Data Analytics Maturity Model.pptx
 
Fun all Day Call Girls in Jaipur 9332606886 High Profile Call Girls You Ca...
Fun all Day Call Girls in Jaipur   9332606886  High Profile Call Girls You Ca...Fun all Day Call Girls in Jaipur   9332606886  High Profile Call Girls You Ca...
Fun all Day Call Girls in Jaipur 9332606886 High Profile Call Girls You Ca...
 
Digital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham WareDigital Transformation Playbook by Graham Ware
Digital Transformation Playbook by Graham Ware
 
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
Top profile Call Girls In dimapur [ 7014168258 ] Call Me For Genuine Models W...
 
Aspirational Block Program Block Syaldey District - Almora
Aspirational Block Program Block Syaldey District - AlmoraAspirational Block Program Block Syaldey District - Almora
Aspirational Block Program Block Syaldey District - Almora
 
Statistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbersStatistics notes ,it includes mean to index numbers
Statistics notes ,it includes mean to index numbers
 
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
Nirala Nagar / Cheap Call Girls In Lucknow Phone No 9548273370 Elite Escort S...
 

When your CEO asks, "Are we secure?" what do you say?

  • 1. Conference2015 San Francisco | April 20-24 | Moscone Center When your CEO asks, “Are we secure?” what do you say?
  • 2. “As secure as we can be.” - Chris Egaaen, Sycomp Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 3. “We could be more secure if you give me more money.” - Jennifer Graham SunTrust Banks, Inc. Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 4. “We’re only as secure as the things we know about.” - Jay Schwitzgebel HealthPlan Services Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 5. “According to our audits we’re doing a good job.” - Steven Lodin, Sallie Mae Bank Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 6. “I think we’re pretty secure but it’s always a moving target.” - Rhonda Simmon, New York Life Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 7. “As good as it gets, my friend. You’re never as secure as you can be. It’s about risk management.” - Tony Zirnoon, Global Security Strategy Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 8. “Very secure, but we’re only one incident away from a problem as is every other company.” - Christina Critzer, SunTrust Banks, Inc. Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 9. “The hackers are just as good as we are, and we’re constantly fighting. We have to be right 100% of the time. They have to be right one.” - David Rooker, Actian Corporation Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 10. “We are as secure as we can be today. We are continuing to mature, and we'll be more secure tomorrow.” - John Graham, Jabil Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 11. “I’d first ask what are our goals? How do we define being secure? How do we define what we are going to measure?” - Bill Olson, Tenable Network Security Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 12. “We have a number of threat vectors that we watch, and we have made a number of investments on those.” - Alex Hutton, IANS Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 13. “The key thing we do is we go and look at benchmarks and see how we compare on it. So, probably not secure enough, but trying to get there.” - Kenneth Haertling, Telus Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 14. “We are aiming for ‘secure enough.’ Not ‘too secure’ because that means you are spending money you don't need to spend, and ‘not secure enough’ means you get owned.” - David Mortman, Dell Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 15. “Today we’re about medium. Medium means right now we don't have any active attacks, and we're monitoring the situation.” - Greg Press, Munich Re Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?
  • 16. “Based on industry practices, we've done the best that we can. Using something like SecurityCenter makes it easy to say you've done best practices recommended by the government, by the payment card industry, by penetration testers, and the really, really basic cyber hygiene things.” - Ron Gula, Tenable Network Security Watch the #RSAC video: bit.ly/how-secure If your CEO asks, “How secure are we?” what do you say?