A recent conversation in LinkedIn was suggesting that the role of the CISO needs to be recreated since the role has evolved and the magnitude of the changes means that expectations of the CISO are hampered by the legacy of the past. I do not necessarily agree with the idea that the CISO (Chief Information… Read More
Security Operations: The Right Way to Manage Your SOC Part 1 (Reality check on what it takes to have a SOC)
To do this, let’s just step back briefly and look at what it takes to run an IT security operations team. The first thing you need is a security infrastructure. A set of tools and integrated solutions that allow you to monitor, hopefully automatically detect and block bad things. You need to buy the hardware,… Read More
What is the Right Sized IT Security Budget?
At this time of year the vexing challenge of trying to establish the appropriate IT security budget for next year rears its ugly head. The chief information security officer has to keep enhancing the security services portfolio capabilities and at the same time maintain his budget spending on people and vendors. This is a challenge… Read More