Amit Megiddo
π€ SpeakerAppearances Over Time
Podcast Appearances
This is from Louis Zhang of AIA Australia.
They're both crappy and you have to decide which one is the worst scenario, the one you would like the least.
It is a risk management exercise.
All right.
Andy, you are a CISO of a high growth, budget tight company.
Here's the first scenario.
It's the beautiful security strategy that nobody follows.
You hire a strong enterprise security architect, clean target state architecture, standardized controls for technology stacks, clear security baselines, governance framework in place, an ambitious multi-year roadmap.
On paper, it's world-class.
Then the reality hits.
The business moves too fast.
Teams bypass design reviews.
Exceptions quietly become the norm.
Cloud environments drift within weeks.
Shadow IT and shadow AI thrive.
Nothing critical gets built the way it was designed.
You have a great strategy, but limited to no enforcement.
There you go.
Well, at least you have something polished to report to the board and the auditor.
So you have something that looks good.