SlideShare a Scribd company logo
1 of 10
W H Y T H E O R G
M A T T E R S
T H E R O L E O F P R I V A C Y A N D S E C U R I T Y I N O R G A N I Z A T I O N
D E S I G N
J U L I E T S A I , I N F O S E C P R O F E S S I O N A L
F O R R E S T E R ’ S P R I V A C Y & S E C U R I T Y 2 0 1 8
W A S H I N G T O N , D . C . S E P T E M B E R 2 5 - 2 6 , ‘ 1 8
T I M E L I N E A N D D I M E N S I O N
2 0 1 0 - 1 1
2 0 1 8 - N O W
2 0 1 0
O P E R A T I O N
A U R O R A
L A R G E -
S C A L E , N O T
U N D E R S T O O D
B Y N O N -
S E C U R I T Y
2 0 1 6 Y A H O O
D I S C L O S E S 2 0 1 3 -
1 4 B R E A C H E S ,
S A L E P R I C E
D R O P S $ 3 5 0 M
2 0 1 8 F A C E B O O K
2 0 1 6 E L E C T I O N
E V E N T S Q U E S T I O N
I N T E G R I T Y O F
P R O C E S S A N D
P R E S S
2 0 1 2 - 1 3 2 0 1 4 - 1 5 2 0 1 6 - 1 7
C L A S S O F C O M P R O M I S E I S
2 0 1 3
T A R G E T C C
B R E A C H
P L A Y S O U T O N
C - S P A N - N O W
U N D E R S T O O D
2 0 1 7 E Q U I F A X
C O N S U M E R P R I V A T E
V E R I F I C A T I O N D A T A
L E A K E D A T N E W
S C A L E
W I T H G R E A T K N O W L E D G E S H O U L D
C O M E G R E A T P O W E R …
T H I S I S H O W I T S H O U L D L O O K
R I S K C H I E F *T E C H C H I E F
S E C U R I T Y
* C E O , C O O , C A O ,
C G C , B O D ? ?
T H I S I S H O W I T M I G H T A L S O
L O O K
P R O D U
C T
* C E O , C O O , C A O ,
C G C , B O D ? ?
L E G A L
F I N A N
C E
C O M P L
I A N C E
A U D I T
S A L E S
M A R K E
T I N G
B U S .
O P S
H R
T E C H C H I E F
S E C U R I T Y
R I S K C H I E F *
T H E S E C U R E O R G A N I Z A T I O N A L
B O D Y
C E N T R A L I Z E D
I N T E L L I G E N C E
S T R O N G B A C K B O N E
D I S T R I B U T E D N E R V O U S
S Y S T E M — D E V S E C O P S :
A R E W E T H E R E Y E T ? D I D
W E S T A R T ? D E P L O Y M E N T
P I P E L I N E S ? C O N F I G M G M T ?
B E L I E F S ?
I N V I S I B L E U N T I L I T ’ S * T H E *
T H I N G
• Emergent startups have been slipstreaming Sec into
DevOps (or DevSecOps) pipelines - or ignoring it
• Enterprise orgs have matrixes departments - with Sec
being asked to report more frequently to the BoD
• One of hardest tech/exec roles to fill (scarcity etc.)
• Consequently…. all the movement pulling Sec up.
W E A R E A L L S E C U R I T Y P E O P L E
S T A T S
Huntsource: A 2015 Georgia Tech 40% of CISO’s were still reporting to CIO’s.
K Logix study 2015
>+50% -> CIO "Makes sense for early stage" - could be CTO too
15% -> CEO
+ -> COO/Risk leader
50% predicted reporting to CEO "in the near future"
In 2018, a PwC study concluded that this figure has dropped to around 24%, with
But the Financial Services Information Sharing and Analysis Center (FS-ISAC) co
Who’s pacesetting for this?
Israel, in some cases mandating Security report to CEO. SOX can cite reporting s
T H E M O D E R N S E C U R I T Y
L E A D E R
1. Be as technical as you can
2. And, build great teams
3. And, have partners throughout org
4. And, have friends outside
5. Paint the picture of where the technology is going and
be *there* to lead it
… I S A T E C H N O L O G Y L E A D E R
R E F E R E N C E S & I M A G E C R E D I T S
REFERENCES
https://securityintelligence.com/what-can-we-learn-from-the-global-state-of-information-security-survey-
2018/
https://www.cio.co.nz/article/600206/why-ciso-hardest-tech-role-fill/
https://www.darkreading.com/operations/top-infosec-execs-will-eventually-report-to-ceos-cisos-say/a/d-
id/1321980
https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy/
https://www.carbonblack.com/2017/07/31/cio-will-report-ciso-2/
https://huntsource.io/why-ciso-shouldnt-report-to-cio/
https://www.csoonline.com/article/3237675/data-protection/the-cio-should-report-to-the-ciso.html
https://www.f5.com/labs/articles/cisotociso/who-should-the-ciso-report-to
https://securityintelligence.com/is-the-ciso-reporting-structure-outdated/
IMAGE CREDITS
chart gif - http://chiefmartec.com/2013/07/with-big-technology-budget-big-cmo-responsibility/
prodigy gif - https://www.pri.org/stories/2014-12-08/meet-hacking-prodigy-you-definitely-want-your-side
cowboy - http://moziru.com/explore/Drawn%20cowboy/
prisoner - https://www.dreamstime.com/stock-illustration-cartoon-prisoner-behind-bar-illustration-image50839937
nervous system - https://www.takeda.com/newsroom/featured-topics/central-nervous-system-research--development-at-takeda/

More Related Content

What's hot

StoreMotion company profile 2015
StoreMotion company profile 2015StoreMotion company profile 2015
StoreMotion company profile 2015EMILE BLONDET
 
Online video Landscape
Online video LandscapeOnline video Landscape
Online video LandscapeQuid Inc.
 
Project Management & Innovation
Project Management & InnovationProject Management & Innovation
Project Management & Innovationmade4gov
 
ISDS: The European Proposal of an Investment Court System
ISDS: The European Proposal of an Investment Court SystemISDS: The European Proposal of an Investment Court System
ISDS: The European Proposal of an Investment Court SystemMartina F. Ferracane
 
Fab Labs: a global network for local entrepreneurship
Fab Labs: a global network for local entrepreneurshipFab Labs: a global network for local entrepreneurship
Fab Labs: a global network for local entrepreneurshipMartina F. Ferracane
 
The Ultimate Guide to Non-Coding Tech Jobs
The Ultimate Guide to Non-Coding Tech JobsThe Ultimate Guide to Non-Coding Tech Jobs
The Ultimate Guide to Non-Coding Tech JobsJeremy Schifeling
 
The Acquisitions Guide to Environmental Due Diligence
The Acquisitions Guide to Environmental Due DiligenceThe Acquisitions Guide to Environmental Due Diligence
The Acquisitions Guide to Environmental Due DiligenceNik Lahiri
 
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...JSchaus & Associates
 
Taipei – 加速、整合、自動化
Taipei – 加速、整合、自動化Taipei – 加速、整合、自動化
Taipei – 加速、整合、自動化Christina Lin
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Emanuel Souvairan
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Emanuel Souvairan
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Emanuel Souvairan
 

What's hot (20)

StoreMotion company profile 2015
StoreMotion company profile 2015StoreMotion company profile 2015
StoreMotion company profile 2015
 
Online video Landscape
Online video LandscapeOnline video Landscape
Online video Landscape
 
Angela Gary CV One Page
Angela Gary CV One PageAngela Gary CV One Page
Angela Gary CV One Page
 
ISDS in APEC region the record
ISDS in APEC region   the recordISDS in APEC region   the record
ISDS in APEC region the record
 
Project Management & Innovation
Project Management & InnovationProject Management & Innovation
Project Management & Innovation
 
Store motion company profile 2015
Store motion company profile 2015Store motion company profile 2015
Store motion company profile 2015
 
Tournament trends 2018
Tournament trends 2018Tournament trends 2018
Tournament trends 2018
 
ISDS: The European Proposal of an Investment Court System
ISDS: The European Proposal of an Investment Court SystemISDS: The European Proposal of an Investment Court System
ISDS: The European Proposal of an Investment Court System
 
Fab Labs: a global network for local entrepreneurship
Fab Labs: a global network for local entrepreneurshipFab Labs: a global network for local entrepreneurship
Fab Labs: a global network for local entrepreneurship
 
DATA FLOWS & NATIONAL SECURITY
DATA FLOWS & NATIONAL SECURITYDATA FLOWS & NATIONAL SECURITY
DATA FLOWS & NATIONAL SECURITY
 
Onyx Presentation
Onyx PresentationOnyx Presentation
Onyx Presentation
 
The Ultimate Guide to Non-Coding Tech Jobs
The Ultimate Guide to Non-Coding Tech JobsThe Ultimate Guide to Non-Coding Tech Jobs
The Ultimate Guide to Non-Coding Tech Jobs
 
The Acquisitions Guide to Environmental Due Diligence
The Acquisitions Guide to Environmental Due DiligenceThe Acquisitions Guide to Environmental Due Diligence
The Acquisitions Guide to Environmental Due Diligence
 
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...
Federal Government Contracting - LIVE Q&A - Topic: OTA Other Transaction Auth...
 
Scorecards
ScorecardsScorecards
Scorecards
 
Taipei – 加速、整合、自動化
Taipei – 加速、整合、自動化Taipei – 加速、整合、自動化
Taipei – 加速、整合、自動化
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...
 
FVR Portfolio v2
FVR Portfolio v2FVR Portfolio v2
FVR Portfolio v2
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...
 
Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...Practical Approaches to Managing International Development Projects in the Fa...
Practical Approaches to Managing International Development Projects in the Fa...
 

Similar to Why the org_matters_shorter.jzt.2018sept25

SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ Presentation
SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ PresentationSEO: A Crash Course | What is SEO in 2015? An Ethoseo™ Presentation
SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ PresentationDamien Wright
 
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investores
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investoresleihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investores
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for InvestoresAlireza Rezvani
 
Interactive media : information and libraries (#bobcatsss2017)
Interactive media : information and libraries (#bobcatsss2017)Interactive media : information and libraries (#bobcatsss2017)
Interactive media : information and libraries (#bobcatsss2017)Guus van den Brekel
 
Welcome to ICD-10 in-services
Welcome to ICD-10 in-servicesWelcome to ICD-10 in-services
Welcome to ICD-10 in-servicesAlicia Cooper
 
English project .pdf topic Test vs T20 cricket
English project .pdf topic Test vs T20 cricketEnglish project .pdf topic Test vs T20 cricket
English project .pdf topic Test vs T20 cricketDevSharma303884
 
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...Gerardo Sánchez Trejo
 
Should we have a pedagogy of technology?
Should we have a pedagogy of technology?Should we have a pedagogy of technology?
Should we have a pedagogy of technology?Ashley Casey
 
California Science Center (USC CSCI 588)
California Science Center (USC CSCI 588)California Science Center (USC CSCI 588)
California Science Center (USC CSCI 588)Sunny Chiu
 
Federal Government Contracting - LIVE Q&A - Topic: PRICING
Federal Government Contracting - LIVE Q&A - Topic: PRICINGFederal Government Contracting - LIVE Q&A - Topic: PRICING
Federal Government Contracting - LIVE Q&A - Topic: PRICINGJSchaus & Associates
 
Part 2: Leadership & Innovation Tactics
Part 2: Leadership & Innovation TacticsPart 2: Leadership & Innovation Tactics
Part 2: Leadership & Innovation TacticsDustin Haisler
 
Blancett group samples 2-lo-res
Blancett group samples 2-lo-resBlancett group samples 2-lo-res
Blancett group samples 2-lo-resMeloyde
 
Jonty Sharples - Arrogance & Confidence in ...Redux
Jonty Sharples - Arrogance & Confidence in ...Redux Jonty Sharples - Arrogance & Confidence in ...Redux
Jonty Sharples - Arrogance & Confidence in ...Redux uxbri
 
Competency-Based LMS
Competency-Based LMSCompetency-Based LMS
Competency-Based LMSFidelis
 
Inuka fragrances by Sue Leonard
Inuka fragrances by Sue Leonard Inuka fragrances by Sue Leonard
Inuka fragrances by Sue Leonard Suelette Leonard
 
Gamification World Congress 2015 - Resumen
Gamification World Congress 2015 - Resumen Gamification World Congress 2015 - Resumen
Gamification World Congress 2015 - Resumen Dassia Legorreta
 
I Quit. Next Steps to Take When Blinded by the Market.
I Quit. Next Steps to Take When Blinded by the Market.I Quit. Next Steps to Take When Blinded by the Market.
I Quit. Next Steps to Take When Blinded by the Market.David Aferiat
 
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...Simone Puorto
 

Similar to Why the org_matters_shorter.jzt.2018sept25 (20)

SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ Presentation
SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ PresentationSEO: A Crash Course | What is SEO in 2015? An Ethoseo™ Presentation
SEO: A Crash Course | What is SEO in 2015? An Ethoseo™ Presentation
 
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investores
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investoresleihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investores
leihdir.de "SMART & LOCAL RENTAL SEARCH ENGINE" Handout for Investores
 
Interactive media : information and libraries (#bobcatsss2017)
Interactive media : information and libraries (#bobcatsss2017)Interactive media : information and libraries (#bobcatsss2017)
Interactive media : information and libraries (#bobcatsss2017)
 
Welcome to ICD-10 in-services
Welcome to ICD-10 in-servicesWelcome to ICD-10 in-services
Welcome to ICD-10 in-services
 
English project .pdf topic Test vs T20 cricket
English project .pdf topic Test vs T20 cricketEnglish project .pdf topic Test vs T20 cricket
English project .pdf topic Test vs T20 cricket
 
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...
La movilidad en la Ciudad de México: Análisis y propuesta de rediseño de la s...
 
Quid - The Threat of AI
Quid - The Threat of AIQuid - The Threat of AI
Quid - The Threat of AI
 
Event Planning & Trends: Design, Technology & F&B
Event Planning & Trends: Design, Technology & F&BEvent Planning & Trends: Design, Technology & F&B
Event Planning & Trends: Design, Technology & F&B
 
Professional History
Professional HistoryProfessional History
Professional History
 
Should we have a pedagogy of technology?
Should we have a pedagogy of technology?Should we have a pedagogy of technology?
Should we have a pedagogy of technology?
 
California Science Center (USC CSCI 588)
California Science Center (USC CSCI 588)California Science Center (USC CSCI 588)
California Science Center (USC CSCI 588)
 
Federal Government Contracting - LIVE Q&A - Topic: PRICING
Federal Government Contracting - LIVE Q&A - Topic: PRICINGFederal Government Contracting - LIVE Q&A - Topic: PRICING
Federal Government Contracting - LIVE Q&A - Topic: PRICING
 
Part 2: Leadership & Innovation Tactics
Part 2: Leadership & Innovation TacticsPart 2: Leadership & Innovation Tactics
Part 2: Leadership & Innovation Tactics
 
Blancett group samples 2-lo-res
Blancett group samples 2-lo-resBlancett group samples 2-lo-res
Blancett group samples 2-lo-res
 
Jonty Sharples - Arrogance & Confidence in ...Redux
Jonty Sharples - Arrogance & Confidence in ...Redux Jonty Sharples - Arrogance & Confidence in ...Redux
Jonty Sharples - Arrogance & Confidence in ...Redux
 
Competency-Based LMS
Competency-Based LMSCompetency-Based LMS
Competency-Based LMS
 
Inuka fragrances by Sue Leonard
Inuka fragrances by Sue Leonard Inuka fragrances by Sue Leonard
Inuka fragrances by Sue Leonard
 
Gamification World Congress 2015 - Resumen
Gamification World Congress 2015 - Resumen Gamification World Congress 2015 - Resumen
Gamification World Congress 2015 - Resumen
 
I Quit. Next Steps to Take When Blinded by the Market.
I Quit. Next Steps to Take When Blinded by the Market.I Quit. Next Steps to Take When Blinded by the Market.
I Quit. Next Steps to Take When Blinded by the Market.
 
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...
Simone Puorto. 2024 Odissea nel Travel Il Ruolo della GenAI nell’Universo Tur...
 

More from Julie Tsai

pbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxpbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxJulie Tsai
 
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?Julie Tsai
 
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...Julie Tsai
 
Carrot hammer olivebranch.devopseast.20.2019nov08
Carrot hammer olivebranch.devopseast.20.2019nov08Carrot hammer olivebranch.devopseast.20.2019nov08
Carrot hammer olivebranch.devopseast.20.2019nov08Julie Tsai
 
Build It and They Will Come-Pliant
Build It and They Will Come-PliantBuild It and They Will Come-Pliant
Build It and They Will Come-PliantJulie Tsai
 
API Security: Assume Possible Interference
API Security: Assume Possible InterferenceAPI Security: Assume Possible Interference
API Security: Assume Possible InterferenceJulie Tsai
 
Dev ops and_infrastructure_immunology_v0.4
Dev ops and_infrastructure_immunology_v0.4Dev ops and_infrastructure_immunology_v0.4
Dev ops and_infrastructure_immunology_v0.4Julie Tsai
 
Puppet HackDay/BarCamp New Delhi Exercises
Puppet HackDay/BarCamp New Delhi ExercisesPuppet HackDay/BarCamp New Delhi Exercises
Puppet HackDay/BarCamp New Delhi ExercisesJulie Tsai
 
Automate your systems with puppet, and change your life
Automate your systems with puppet, and change your lifeAutomate your systems with puppet, and change your life
Automate your systems with puppet, and change your lifeJulie Tsai
 

More from Julie Tsai (9)

pbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptxpbc_devsecops_eastereggs.2022oct06.jt.pptx
pbc_devsecops_eastereggs.2022oct06.jt.pptx
 
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?
Building Towards the New Security & Privacy Landscape: Where Do We Go From Here?
 
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...
Everything you know is wrong: How Computer-Ing While Leading People Will Be Y...
 
Carrot hammer olivebranch.devopseast.20.2019nov08
Carrot hammer olivebranch.devopseast.20.2019nov08Carrot hammer olivebranch.devopseast.20.2019nov08
Carrot hammer olivebranch.devopseast.20.2019nov08
 
Build It and They Will Come-Pliant
Build It and They Will Come-PliantBuild It and They Will Come-Pliant
Build It and They Will Come-Pliant
 
API Security: Assume Possible Interference
API Security: Assume Possible InterferenceAPI Security: Assume Possible Interference
API Security: Assume Possible Interference
 
Dev ops and_infrastructure_immunology_v0.4
Dev ops and_infrastructure_immunology_v0.4Dev ops and_infrastructure_immunology_v0.4
Dev ops and_infrastructure_immunology_v0.4
 
Puppet HackDay/BarCamp New Delhi Exercises
Puppet HackDay/BarCamp New Delhi ExercisesPuppet HackDay/BarCamp New Delhi Exercises
Puppet HackDay/BarCamp New Delhi Exercises
 
Automate your systems with puppet, and change your life
Automate your systems with puppet, and change your lifeAutomate your systems with puppet, and change your life
Automate your systems with puppet, and change your life
 

Recently uploaded

CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLScyllaDB
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfAlex Barbosa Coqueiro
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 

Recently uploaded (20)

CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Developer Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQLDeveloper Data Modeling Mistakes: From Postgres to NoSQL
Developer Data Modeling Mistakes: From Postgres to NoSQL
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Unraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdfUnraveling Multimodality with Large Language Models.pdf
Unraveling Multimodality with Large Language Models.pdf
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 

Why the org_matters_shorter.jzt.2018sept25

  • 1. W H Y T H E O R G M A T T E R S T H E R O L E O F P R I V A C Y A N D S E C U R I T Y I N O R G A N I Z A T I O N D E S I G N J U L I E T S A I , I N F O S E C P R O F E S S I O N A L F O R R E S T E R ’ S P R I V A C Y & S E C U R I T Y 2 0 1 8 W A S H I N G T O N , D . C . S E P T E M B E R 2 5 - 2 6 , ‘ 1 8
  • 2. T I M E L I N E A N D D I M E N S I O N 2 0 1 0 - 1 1 2 0 1 8 - N O W 2 0 1 0 O P E R A T I O N A U R O R A L A R G E - S C A L E , N O T U N D E R S T O O D B Y N O N - S E C U R I T Y 2 0 1 6 Y A H O O D I S C L O S E S 2 0 1 3 - 1 4 B R E A C H E S , S A L E P R I C E D R O P S $ 3 5 0 M 2 0 1 8 F A C E B O O K 2 0 1 6 E L E C T I O N E V E N T S Q U E S T I O N I N T E G R I T Y O F P R O C E S S A N D P R E S S 2 0 1 2 - 1 3 2 0 1 4 - 1 5 2 0 1 6 - 1 7 C L A S S O F C O M P R O M I S E I S 2 0 1 3 T A R G E T C C B R E A C H P L A Y S O U T O N C - S P A N - N O W U N D E R S T O O D 2 0 1 7 E Q U I F A X C O N S U M E R P R I V A T E V E R I F I C A T I O N D A T A L E A K E D A T N E W S C A L E
  • 3. W I T H G R E A T K N O W L E D G E S H O U L D C O M E G R E A T P O W E R …
  • 4. T H I S I S H O W I T S H O U L D L O O K R I S K C H I E F *T E C H C H I E F S E C U R I T Y * C E O , C O O , C A O , C G C , B O D ? ?
  • 5. T H I S I S H O W I T M I G H T A L S O L O O K P R O D U C T * C E O , C O O , C A O , C G C , B O D ? ? L E G A L F I N A N C E C O M P L I A N C E A U D I T S A L E S M A R K E T I N G B U S . O P S H R T E C H C H I E F S E C U R I T Y R I S K C H I E F *
  • 6. T H E S E C U R E O R G A N I Z A T I O N A L B O D Y C E N T R A L I Z E D I N T E L L I G E N C E S T R O N G B A C K B O N E D I S T R I B U T E D N E R V O U S S Y S T E M — D E V S E C O P S : A R E W E T H E R E Y E T ? D I D W E S T A R T ? D E P L O Y M E N T P I P E L I N E S ? C O N F I G M G M T ? B E L I E F S ?
  • 7. I N V I S I B L E U N T I L I T ’ S * T H E * T H I N G • Emergent startups have been slipstreaming Sec into DevOps (or DevSecOps) pipelines - or ignoring it • Enterprise orgs have matrixes departments - with Sec being asked to report more frequently to the BoD • One of hardest tech/exec roles to fill (scarcity etc.) • Consequently…. all the movement pulling Sec up. W E A R E A L L S E C U R I T Y P E O P L E
  • 8. S T A T S Huntsource: A 2015 Georgia Tech 40% of CISO’s were still reporting to CIO’s. K Logix study 2015 >+50% -> CIO "Makes sense for early stage" - could be CTO too 15% -> CEO + -> COO/Risk leader 50% predicted reporting to CEO "in the near future" In 2018, a PwC study concluded that this figure has dropped to around 24%, with But the Financial Services Information Sharing and Analysis Center (FS-ISAC) co Who’s pacesetting for this? Israel, in some cases mandating Security report to CEO. SOX can cite reporting s
  • 9. T H E M O D E R N S E C U R I T Y L E A D E R 1. Be as technical as you can 2. And, build great teams 3. And, have partners throughout org 4. And, have friends outside 5. Paint the picture of where the technology is going and be *there* to lead it … I S A T E C H N O L O G Y L E A D E R
  • 10. R E F E R E N C E S & I M A G E C R E D I T S REFERENCES https://securityintelligence.com/what-can-we-learn-from-the-global-state-of-information-security-survey- 2018/ https://www.cio.co.nz/article/600206/why-ciso-hardest-tech-role-fill/ https://www.darkreading.com/operations/top-infosec-execs-will-eventually-report-to-ceos-cisos-say/a/d- id/1321980 https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy/ https://www.carbonblack.com/2017/07/31/cio-will-report-ciso-2/ https://huntsource.io/why-ciso-shouldnt-report-to-cio/ https://www.csoonline.com/article/3237675/data-protection/the-cio-should-report-to-the-ciso.html https://www.f5.com/labs/articles/cisotociso/who-should-the-ciso-report-to https://securityintelligence.com/is-the-ciso-reporting-structure-outdated/ IMAGE CREDITS chart gif - http://chiefmartec.com/2013/07/with-big-technology-budget-big-cmo-responsibility/ prodigy gif - https://www.pri.org/stories/2014-12-08/meet-hacking-prodigy-you-definitely-want-your-side cowboy - http://moziru.com/explore/Drawn%20cowboy/ prisoner - https://www.dreamstime.com/stock-illustration-cartoon-prisoner-behind-bar-illustration-image50839937 nervous system - https://www.takeda.com/newsroom/featured-topics/central-nervous-system-research--development-at-takeda/

Editor's Notes

  1. A. 2010 (2008-2009) - Operation Aurora - this is still more for the profess Goog, Adobe, Juniper, Rackspace, Yahoo, Symantec, Northrop Grumman, Morgan Stanley, Dow Chemical - codebases B. late 2013 - Target testifies in front of Congress $18.5M in damages to states C. September 2016 - Yahoo reporting breaches of 2013 and 2014 drops sale price to VZW from $350M to $4.48B, top-line exec changes D. Equinox now, this is personal - SSNs, driver’s IDs, verification information the internet can’t unsee this E. Now - Facebook Democracy turning point 2016? where is the Fourth Estate? Is there such a thing anymore? Walter Cronkite “a free press is not just essential for democracy. it *is* democracy.” Can we still get signal in widely universal mass media? If the means to publish is not understood, can it be trusted?
  2. With all of this, security professionals should be psyched/motivated/feeling valued, right? Right?!
  3. Centralized intelligence - one org Strong backbone - incentives, goals, workflow all reinforce the shared objective and authority Distributed nervous system - DevSecOps
  4. Stats Huntsource: A 2015 Georgia Tech 40% of CISO’s were still reporting to CIO’s. In 2018, a PwC study concluded that this figure has dropped to around 24%, with 40% of CISO’s now report directly to CEO’s, with another 27% reporting to the board of directors. But the Financial Services Information Sharing and Analysis Center (FS-ISAC) concluded that only 8% of CISO’s are reporting directly to a CEO. Who’s pacesetting for this? Israel. SOX can cite reporting structure as weakness. GDPR required Chief Data Protection Officer.
  5. 1. Be as technical as you can You can’t manage what you can’t understand. Tiny details can make or break a project. Consensus decisions can take years to arrive at and to back out again — too slow for yearly disruption markets. Tech is core, not peripheral. Why did you get into this in the first place?! 2. You must also build great teams Too many adversaries for SWAT team of heroes Talent is the differentiator - be human-centered Be able to truly manage, not just narrow down, the exceptions 3. You must also have partners throughout org. if you’re big enough, you need other groups to deliver and reinforce these priorities Understand where they’re coming from and be able to work across the org 4. You must also have friends outside. Circles of trust are even more important in this world. Reliant on landscape intel from many. And peers to sanity-check complex situations. 5. You must see where the technology is going and be there to meet it - and lead it. Have the vision, know what to say to whom when, relentlessly drive and support to get it done Run to where the ball is going. Help your org, partners, and customers see what they need to do and be before they do.