Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

πŸ‘€ Speaker
414 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

We can't control the decision.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I mean, ultimately, we have a risk if we approach it with that mindset of the old thou shalt and office of no and everything.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But you can control the environment like what you were saying, Andy.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Yeah, I think why I have a visceral reaction to that is some of the faux pas that some CISOs out there make is if they bring something and an executive has a higher risk tolerance and they don't follow that exactly, there's this like, yeah, they get offended and get upset.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But the reality is we're a partner and we're going to work together to find what that right decision is.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

That's okay.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I mean, risk is a business decision at the end of the day.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Some companies are going to have a high risk tolerance, some aren't.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Your job as a CISO and as a business leader ultimately is to figure that out and to meet those goals within that risk tolerance.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Yeah.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And I think, I think you've got to have the framework where you can fail quickly, right?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Like the companies that are taking a risk are not doing transformational level risk that is going to cost the company billions of dollars.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

It's AB testing, different marketing concepts.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

It's trying this new technology, et cetera.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So it's not big bang risk.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

It's, it's small risk.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

That's tolerable.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

think the last thing david that you asked was about executives that want certainty i have encountered so many board meetings and executives that say like can you tell me we won't get hacked and as we know that's super dangerous to promise things so we got to be really careful there and

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Be transparent that there's no sure things, but immediately pivot that conversation to how we're managing that risk to give them that comfort, right, to really enable that business goal that they're trying to do and achieve that right balance.