SlideShare a Scribd company logo
1
proudly presents at
2
Hackers Are from Mars;
CxOs Are from Jupiter
Rob Havelt
Director of information Governance, Risk and Compliance (iGRC)
infoedge LLC
3
• A background as a packet monkey,
wireless geek and leader of a
pretty big pen test team
• A hacker and technologist who
bleeds ink from all those tested pens
• A director of iGRC for a management
consulting firm called infoedge LLC
Rob is decidedly from Mars
4
Denizens of the boardroom and the SOC
A rift often exists between the denizens of the boardroom and the SOC,
who each inhabit different worlds.
5
Denizens of the boardroom and the SOC
They don’t think, communicate or process information the same.
6
The title of this talk isn’t arbitrary; the
planet names are significant.
Beyond simple lexicon
7
• God of war
• Protector of agriculture
• Guardian of populace
M
ARS
8
• Lightning bringer
• Controlled the realm
• Father of Gods
JUPIT
ER
9
Why bother knowing this?
Fair question.
10
Why bother knowing this?
Fair question.
I’d rather be taking apart an ATM,
developing exploits or getting root.
11
As a director at
a technical firm
for many years,
I thought I knew
a decent amount
about the business
layer until I left
that bubble and
entered theirs.
12
Then everything
changed...
13
I realized that words
and concepts meant
completely different
things to a CPA
than an engineer.
14
Like any hacker,
I wanted to pull
things apart, see
exactly how it
worked and know
the rules.
15
What’s in it for hackers?
• Leave “the bubble”
• Communicate clearly to get your funding
• Hack “the rules” to get your way
16
Disregarding bold ideas
• Ideas for solving non-technology
problems are often non-starters
• They aren’t bad ideas but lack business
context (metrics, operationalization,
optimization, planning)
• They also lack visualization of how
they contribute to the company
(mission, vision, goals, objectives)
17
Don’t let good ideas stagnate
due to presentation.
18
All Other Business Levels
Board of Directors
Jupiter Players
Other Players
(CIO|CMO|CCO|CTO)
Company Management
(CEO|COO|CFO)
19
What about the CISO?
• Chief Information Security Officer (CISO)
or Chief Security Officer (CSO)
• Has the least secure position
in the organization
• Is the person who takes the fall
for the inevitable breach
• Knows heshe will take the fall
• Accepts impermanence as part
of the job description
CISO?
20
Keep the following in mind
when strategizing on how to
present to these players.
21
Executives have unique
expectations and priorities
• Do some homework to find out what those priorities are
• Prepare to cycle through a few
contexts to see what resonates
22
Executives have limited time
and demand clarity
• Deliver key messages up front
• Have a plan A, B, C and D in your pocket
23
Executives require
high-level communication
• Use graphical models whenever possible
• Use pre-reads and handouts
24
How do hackers align CISO/CSO
InfoSec expectations?
25
Align your message with
business risk strategy
• Understand the risk appetite of the organization
• Make a proposal that enables business decision-making
26
Satisfy cyber security
risk concerns
• Cyber risk is one of the top three boardroom
concerns, and therefore an executive concern
• Other concerns include current risks,
emerging trends and strategy
27
Use effective storytelling
• Know what impression you want to leave
behind/story you want to tell
• What outcome do you want?
28
Take the time to refine your message.
29
Tell a story that aligns
with your objective
• Facts and data are great, so use them
• Ensure your data can stand on its own
• Connect the dots to tell a compelling story
• Socialize your story ahead of time
30
Paint a complete picture
without raising alarms
• Risk management is about both opportunities and threats
• Don’t exaggerate and negatively impact your
credibility; expect counter information to exist
• Any counter information can destroy your credibility
31
Communicate risk and
provide clear parameters
• Terms like “high risk” are open to interpretation
• Use frequencies rather than percentages
• People respond differently when you allow a
comparison of how often an activity is undertaken
32
Constructs management loves
• Corporate dialogue
• Analytics
• Process flows
• Value propositions
33
Learn these constructs to help you
present your ideas more effectively.
34
Learn your corporate dialogue
• Technological talk actually makes sense to the initiated
• Terms have definitions, acronyms all stand
for something and they are defensible
• “Corpspeak” has to be made up; what do
words like “operationalization” even mean?
35
Analytics
• Measure everything...even if your approach
to measurement is unique
• Gather real, obtainable measurements
• If you can’t directly measure something on its own
scale, compare it to something similar, e.g. BSIMM
• Look to someone with “Auditor” in their title to
learn how to do this in your organization
36
Process flows
• Arrange into corresponding swim lanes
• Number all steps
• Have descriptions for all artifacts
• Include an input and output for each block
37
Value propositions
• Straightforward yet hard to do
• Must start with business issues
• Focus on threats and opportunities in a risk context
• Define what you want and the impact it will have
• End with what people will get out of it
38
Tying it all together
• Both sides have different concerns, focus and drivers
• People working towards the same objective
can approach it in vastly different ways
• Bridge the gap by taking an objective look
at your players and their risk drivers
• Frame the issues that are most critical
for the C-suite to understand
39
Questions?
40
Rob Havelt
Director
information Governance, Risk and Compliance (iGRC)
infoedge LLC
rob.havelt@infoedgellc.com
@dasfiregod
About infoedge LLC
infoedge helps you improve business strategy, accelerate innovation and manage
risk, so you can succeed in the information economy.

More Related Content

Viewers also liked

CaseStudy-Archway
CaseStudy-ArchwayCaseStudy-Archway
CaseStudy-Archway
Matthew Bonanno
 
Combinacion de correspondencia
Combinacion de correspondenciaCombinacion de correspondencia
Combinacion de correspondencia
lina carolina ramos zapata
 
Emplois du temps_2emes
Emplois du temps_2emesEmplois du temps_2emes
Emplois du temps_2emes
Chennoufi Med
 
School Stars Library Card Campaign
School Stars Library Card CampaignSchool Stars Library Card Campaign
School Stars Library Card CampaignEileen Cole
 
WalkMate Account Statement
WalkMate Account StatementWalkMate Account Statement
WalkMate Account StatementEileen Cole
 
cv liz2
cv liz2cv liz2
HabíA Una Vez Tres Cerditos Hermanos Que VivíAn
HabíA Una Vez Tres Cerditos Hermanos Que VivíAnHabíA Una Vez Tres Cerditos Hermanos Que VivíAn
HabíA Una Vez Tres Cerditos Hermanos Que VivíAn
Universidad Pontificia Comillas ICAI-ICADE
 
Lesson 9 show
Lesson 9 showLesson 9 show
Lesson 9 show
Greg
 
Building consTRUCTION
Building consTRUCTIONBuilding consTRUCTION
Building consTRUCTION
sahil saini
 
Analytics in-action-survey
Analytics in-action-surveyAnalytics in-action-survey
Analytics in-action-survey
Anjan Das
 
Digipack analysis
Digipack analysisDigipack analysis
Digipack analysis
Hollie15
 
17-02-14-UHPP ACA Update
17-02-14-UHPP ACA Update17-02-14-UHPP ACA Update
17-02-14-UHPP ACA Update
Utah Health Policy Project
 

Viewers also liked (12)

CaseStudy-Archway
CaseStudy-ArchwayCaseStudy-Archway
CaseStudy-Archway
 
Combinacion de correspondencia
Combinacion de correspondenciaCombinacion de correspondencia
Combinacion de correspondencia
 
Emplois du temps_2emes
Emplois du temps_2emesEmplois du temps_2emes
Emplois du temps_2emes
 
School Stars Library Card Campaign
School Stars Library Card CampaignSchool Stars Library Card Campaign
School Stars Library Card Campaign
 
WalkMate Account Statement
WalkMate Account StatementWalkMate Account Statement
WalkMate Account Statement
 
cv liz2
cv liz2cv liz2
cv liz2
 
HabíA Una Vez Tres Cerditos Hermanos Que VivíAn
HabíA Una Vez Tres Cerditos Hermanos Que VivíAnHabíA Una Vez Tres Cerditos Hermanos Que VivíAn
HabíA Una Vez Tres Cerditos Hermanos Que VivíAn
 
Lesson 9 show
Lesson 9 showLesson 9 show
Lesson 9 show
 
Building consTRUCTION
Building consTRUCTIONBuilding consTRUCTION
Building consTRUCTION
 
Analytics in-action-survey
Analytics in-action-surveyAnalytics in-action-survey
Analytics in-action-survey
 
Digipack analysis
Digipack analysisDigipack analysis
Digipack analysis
 
17-02-14-UHPP ACA Update
17-02-14-UHPP ACA Update17-02-14-UHPP ACA Update
17-02-14-UHPP ACA Update
 

Similar to Hackers are from Mars; CxOs are from Jupiter

bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
Anthony Melfi
 
Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?
Security Innovation
 
Conquering Chaos: Helix & DevOps
Conquering Chaos: Helix & DevOpsConquering Chaos: Helix & DevOps
Conquering Chaos: Helix & DevOps
Perforce
 
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon
 
Threat Modeling In 2021
Threat Modeling In 2021Threat Modeling In 2021
Threat Modeling In 2021
Adam Shostack
 
CS101- Introduction to Computing- Lecture 42
CS101- Introduction to Computing- Lecture 42CS101- Introduction to Computing- Lecture 42
CS101- Introduction to Computing- Lecture 42
Bilal Ahmed
 
Publishing Strategic Technology for Association of Catholic Publishers
Publishing Strategic Technology for Association of Catholic PublishersPublishing Strategic Technology for Association of Catholic Publishers
Publishing Strategic Technology for Association of Catholic Publishers
Craig Miller
 
Project professionals: Ready for the future? AI and Change Management, James ...
Project professionals: Ready for the future? AI and Change Management, James ...Project professionals: Ready for the future? AI and Change Management, James ...
Project professionals: Ready for the future? AI and Change Management, James ...
APMDonotuse
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017
Chad Hoffmann
 
Hit the ground running 2013 - Strategic Thinking
Hit the ground running 2013 - Strategic ThinkingHit the ground running 2013 - Strategic Thinking
Hit the ground running 2013 - Strategic Thinking
philpickford
 
Generative Analysis Overview
Generative Analysis OverviewGenerative Analysis Overview
Generative Analysis Overview
Jim Arlow
 
CS 101 Introduction to computer computing-profession.ppt
CS 101 Introduction to computer computing-profession.pptCS 101 Introduction to computer computing-profession.ppt
CS 101 Introduction to computer computing-profession.ppt
athar549116
 
One hundred rules for nasa project managers
One hundred rules for nasa project managersOne hundred rules for nasa project managers
One hundred rules for nasa project managers
Andreea Mocanu
 
NESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development PresentationNESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development Presentation
EnergySec
 
DevSecOps with Microsoft Tech
DevSecOps with Microsoft TechDevSecOps with Microsoft Tech
DevSecOps with Microsoft Tech
Darin Morris
 
CISO's first 100 days
CISO's first 100 daysCISO's first 100 days
CISO's first 100 days
MichaelSadeghiPhDABD
 
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptxSAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
hforhassan101
 
10 Observations from 10+ years in the Corporate UX Trenches
10 Observations from 10+ years in the Corporate UX Trenches10 Observations from 10+ years in the Corporate UX Trenches
10 Observations from 10+ years in the Corporate UX Trenches
Ario Jafarzadeh
 
Three Secret Ingredients To Recruiting Software Developers
Three Secret Ingredients To Recruiting Software DevelopersThree Secret Ingredients To Recruiting Software Developers
Three Secret Ingredients To Recruiting Software Developers
Michal Juhas
 
The Missing Link Between Governance and Agile Culture
The Missing Link Between Governance and Agile CultureThe Missing Link Between Governance and Agile Culture
The Missing Link Between Governance and Agile Culture
Jeremy Pullen
 

Similar to Hackers are from Mars; CxOs are from Jupiter (20)

bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
bsides NOVA 2017 So You Want to Be a Cyber Threat Analyst eh?
 
Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?Secure DevOps - Evolution or Revolution?
Secure DevOps - Evolution or Revolution?
 
Conquering Chaos: Helix & DevOps
Conquering Chaos: Helix & DevOpsConquering Chaos: Helix & DevOps
Conquering Chaos: Helix & DevOps
 
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting LeftDevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
DevSecCon Asia 2017 Shannon Lietz: Security is Shifting Left
 
Threat Modeling In 2021
Threat Modeling In 2021Threat Modeling In 2021
Threat Modeling In 2021
 
CS101- Introduction to Computing- Lecture 42
CS101- Introduction to Computing- Lecture 42CS101- Introduction to Computing- Lecture 42
CS101- Introduction to Computing- Lecture 42
 
Publishing Strategic Technology for Association of Catholic Publishers
Publishing Strategic Technology for Association of Catholic PublishersPublishing Strategic Technology for Association of Catholic Publishers
Publishing Strategic Technology for Association of Catholic Publishers
 
Project professionals: Ready for the future? AI and Change Management, James ...
Project professionals: Ready for the future? AI and Change Management, James ...Project professionals: Ready for the future? AI and Change Management, James ...
Project professionals: Ready for the future? AI and Change Management, James ...
 
CSA Fall Summit 2017
CSA Fall Summit 2017CSA Fall Summit 2017
CSA Fall Summit 2017
 
Hit the ground running 2013 - Strategic Thinking
Hit the ground running 2013 - Strategic ThinkingHit the ground running 2013 - Strategic Thinking
Hit the ground running 2013 - Strategic Thinking
 
Generative Analysis Overview
Generative Analysis OverviewGenerative Analysis Overview
Generative Analysis Overview
 
CS 101 Introduction to computer computing-profession.ppt
CS 101 Introduction to computer computing-profession.pptCS 101 Introduction to computer computing-profession.ppt
CS 101 Introduction to computer computing-profession.ppt
 
One hundred rules for nasa project managers
One hundred rules for nasa project managersOne hundred rules for nasa project managers
One hundred rules for nasa project managers
 
NESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development PresentationNESCO Town Hall Workforce Development Presentation
NESCO Town Hall Workforce Development Presentation
 
DevSecOps with Microsoft Tech
DevSecOps with Microsoft TechDevSecOps with Microsoft Tech
DevSecOps with Microsoft Tech
 
CISO's first 100 days
CISO's first 100 daysCISO's first 100 days
CISO's first 100 days
 
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptxSAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
SAL-DR-01-ELC 10 Understanding the SOC Audience.pptx
 
10 Observations from 10+ years in the Corporate UX Trenches
10 Observations from 10+ years in the Corporate UX Trenches10 Observations from 10+ years in the Corporate UX Trenches
10 Observations from 10+ years in the Corporate UX Trenches
 
Three Secret Ingredients To Recruiting Software Developers
Three Secret Ingredients To Recruiting Software DevelopersThree Secret Ingredients To Recruiting Software Developers
Three Secret Ingredients To Recruiting Software Developers
 
The Missing Link Between Governance and Agile Culture
The Missing Link Between Governance and Agile CultureThe Missing Link Between Governance and Agile Culture
The Missing Link Between Governance and Agile Culture
 

Recently uploaded

みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
名前 です男
 
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
Neo4j
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Speck&Tech
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
DianaGray10
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
Pixlogix Infotech
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
IndexBug
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
mikeeftimakis1
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
Adtran
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
Matthew Sinclair
 

Recently uploaded (20)

みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
みなさんこんにちはこれ何文字まで入るの?40文字以下不可とか本当に意味わからないけどこれ限界文字数書いてないからマジでやばい文字数いけるんじゃないの?えこ...
 
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
GraphSummit Singapore | The Future of Agility: Supercharging Digital Transfor...
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
Cosa hanno in comune un mattoncino Lego e la backdoor XZ?
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6UiPath Test Automation using UiPath Test Suite series, part 6
UiPath Test Automation using UiPath Test Suite series, part 6
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial IntelligenceAI 101: An Introduction to the Basics and Impact of Artificial Intelligence
AI 101: An Introduction to the Basics and Impact of Artificial Intelligence
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Introduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - CybersecurityIntroduction to CHERI technology - Cybersecurity
Introduction to CHERI technology - Cybersecurity
 
Pushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 daysPushing the limits of ePRTC: 100ns holdover for 100 days
Pushing the limits of ePRTC: 100ns holdover for 100 days
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
20240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 202420240609 QFM020 Irresponsible AI Reading List May 2024
20240609 QFM020 Irresponsible AI Reading List May 2024
 

Hackers are from Mars; CxOs are from Jupiter

  • 2. 2 Hackers Are from Mars; CxOs Are from Jupiter Rob Havelt Director of information Governance, Risk and Compliance (iGRC) infoedge LLC
  • 3. 3 • A background as a packet monkey, wireless geek and leader of a pretty big pen test team • A hacker and technologist who bleeds ink from all those tested pens • A director of iGRC for a management consulting firm called infoedge LLC Rob is decidedly from Mars
  • 4. 4 Denizens of the boardroom and the SOC A rift often exists between the denizens of the boardroom and the SOC, who each inhabit different worlds.
  • 5. 5 Denizens of the boardroom and the SOC They don’t think, communicate or process information the same.
  • 6. 6 The title of this talk isn’t arbitrary; the planet names are significant. Beyond simple lexicon
  • 7. 7 • God of war • Protector of agriculture • Guardian of populace M ARS
  • 8. 8 • Lightning bringer • Controlled the realm • Father of Gods JUPIT ER
  • 9. 9 Why bother knowing this? Fair question.
  • 10. 10 Why bother knowing this? Fair question. I’d rather be taking apart an ATM, developing exploits or getting root.
  • 11. 11 As a director at a technical firm for many years, I thought I knew a decent amount about the business layer until I left that bubble and entered theirs.
  • 13. 13 I realized that words and concepts meant completely different things to a CPA than an engineer.
  • 14. 14 Like any hacker, I wanted to pull things apart, see exactly how it worked and know the rules.
  • 15. 15 What’s in it for hackers? • Leave “the bubble” • Communicate clearly to get your funding • Hack “the rules” to get your way
  • 16. 16 Disregarding bold ideas • Ideas for solving non-technology problems are often non-starters • They aren’t bad ideas but lack business context (metrics, operationalization, optimization, planning) • They also lack visualization of how they contribute to the company (mission, vision, goals, objectives)
  • 17. 17 Don’t let good ideas stagnate due to presentation.
  • 18. 18 All Other Business Levels Board of Directors Jupiter Players Other Players (CIO|CMO|CCO|CTO) Company Management (CEO|COO|CFO)
  • 19. 19 What about the CISO? • Chief Information Security Officer (CISO) or Chief Security Officer (CSO) • Has the least secure position in the organization • Is the person who takes the fall for the inevitable breach • Knows heshe will take the fall • Accepts impermanence as part of the job description CISO?
  • 20. 20 Keep the following in mind when strategizing on how to present to these players.
  • 21. 21 Executives have unique expectations and priorities • Do some homework to find out what those priorities are • Prepare to cycle through a few contexts to see what resonates
  • 22. 22 Executives have limited time and demand clarity • Deliver key messages up front • Have a plan A, B, C and D in your pocket
  • 23. 23 Executives require high-level communication • Use graphical models whenever possible • Use pre-reads and handouts
  • 24. 24 How do hackers align CISO/CSO InfoSec expectations?
  • 25. 25 Align your message with business risk strategy • Understand the risk appetite of the organization • Make a proposal that enables business decision-making
  • 26. 26 Satisfy cyber security risk concerns • Cyber risk is one of the top three boardroom concerns, and therefore an executive concern • Other concerns include current risks, emerging trends and strategy
  • 27. 27 Use effective storytelling • Know what impression you want to leave behind/story you want to tell • What outcome do you want?
  • 28. 28 Take the time to refine your message.
  • 29. 29 Tell a story that aligns with your objective • Facts and data are great, so use them • Ensure your data can stand on its own • Connect the dots to tell a compelling story • Socialize your story ahead of time
  • 30. 30 Paint a complete picture without raising alarms • Risk management is about both opportunities and threats • Don’t exaggerate and negatively impact your credibility; expect counter information to exist • Any counter information can destroy your credibility
  • 31. 31 Communicate risk and provide clear parameters • Terms like “high risk” are open to interpretation • Use frequencies rather than percentages • People respond differently when you allow a comparison of how often an activity is undertaken
  • 32. 32 Constructs management loves • Corporate dialogue • Analytics • Process flows • Value propositions
  • 33. 33 Learn these constructs to help you present your ideas more effectively.
  • 34. 34 Learn your corporate dialogue • Technological talk actually makes sense to the initiated • Terms have definitions, acronyms all stand for something and they are defensible • “Corpspeak” has to be made up; what do words like “operationalization” even mean?
  • 35. 35 Analytics • Measure everything...even if your approach to measurement is unique • Gather real, obtainable measurements • If you can’t directly measure something on its own scale, compare it to something similar, e.g. BSIMM • Look to someone with “Auditor” in their title to learn how to do this in your organization
  • 36. 36 Process flows • Arrange into corresponding swim lanes • Number all steps • Have descriptions for all artifacts • Include an input and output for each block
  • 37. 37 Value propositions • Straightforward yet hard to do • Must start with business issues • Focus on threats and opportunities in a risk context • Define what you want and the impact it will have • End with what people will get out of it
  • 38. 38 Tying it all together • Both sides have different concerns, focus and drivers • People working towards the same objective can approach it in vastly different ways • Bridge the gap by taking an objective look at your players and their risk drivers • Frame the issues that are most critical for the C-suite to understand
  • 40. 40 Rob Havelt Director information Governance, Risk and Compliance (iGRC) infoedge LLC rob.havelt@infoedgellc.com @dasfiregod About infoedge LLC infoedge helps you improve business strategy, accelerate innovation and manage risk, so you can succeed in the information economy.