Posts tagged CISOs

6 min CISOs

CISOs: Do you have enough locks on your doors?

In a previous blog post [/2015/07/09/ciso-in-residence-series-shocked-but-not-surprised], I referenced some research on how people plan for, or rather how they fail to plan for, natural disasters like floods. At the end of the blog post I mentioned that people who have poor mental models about disasters fail to prepare fully. I keep coming back to the idea of mental models because it starts to explain why we have such a gap between security practitioners and senior executives. I asked one CISO

5 min CISOs

Insiders and Outsiders in Security

“Those fools. They didn't even bother to do X. And everyone knows you have to do X.” If you've been in Infosec for even a short time, you've seen this sort of statement, whether explicit or implicit, about something in the news. It comes up often after a company has suffered a breach. And it's often true. The company should have done X. Everyone knows you need to do X. Even my dad knows that. But then again, the security people making these comments often work at companies that really should be

2 min CISOs

Introducing the CISO in Residence

At the start of 2010 I started as Twitter's first security hire. You may recall a number of security challenges we were facing at that time. We had to build out a number of teams to deal with the entire spectrum of security issues. Today Twitter has what I believe to be some of the best security people and teams in the industry. Today I'm very excited to be joining the Rapid7 team as its first CISO in Residence. What does a CISO in Residence do? Well, there aren't a lot of examples to go by. T

2 min CISOs

Top 3 Takeaways from "CyberSecurity Awareness Panel: Taking it to the C-Level and Beyond"

Hi, I'm Meredith Tufts. I recently joined Rapid7 and if you were on the live Oct. 30th's webcast, “CyberSecurity Awareness Panel: Taking to the C-Level and Beyond” – I was your moderator. It's nice to be here on SecurityStreet, and this week I'm here to provide you with the Top 3 Takeaways from our CyberSecurity Awareness month webcast where we were joined by a panel of experts: Brian Betterton - Director, Security, Risk and Compliance at Reit Management & Research Trey Ford - Global Security

3 min PCI

Cyber Security Awareness Month: Data Custodianship

By now, you know that October is Cyber Security Awareness Month in the US [http://www.staysafeonline.org/ncsam/] and across the European Union [http://www.enisa.europa.eu/activities/stakeholder-relations/nis-brokerage-1/european-cyber-security-month-advocacy-campaign] . We know many SecurityStreet readers work in information security and are already “aware” - so this year we're equipping you for executive tier cyber security discussions. We kicked this off last week with a piece on why security

2 min Cloud Infrastructure

A CISOs Cloudy Reality

An Overview For many organizations, especially fast-paced hyper growth companies like Rapid7, the appropriate use of Cloud services can be the difference between success and failure.  As these products and solutions revolutionize the way we do business, CISOs must contemplate what constitutes appropriate use. In the past five years we have watched Human Resource, Customer Management, Learning Management, and other major business functions move into the Cloud. This has forced CISOs to push their