Menu
Sign In Search Podcasts Charts People & Topics Add Podcast API Blog Pricing

Andy Ellis

๐Ÿ‘ค Speaker
182 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I absolutely love what you said there, Andy, about basically making him have an out, if you will, the great versus awful idea.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

David, to your question, I think we've got to serve as a risk advisor, but it's a trusted risk advisor.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And how you're going to establish trust is bring them realistic options, right?

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Not the invest $10 billion or I'm going to the street type of thing, or I told you so.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

So building that trust is a big part of it.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And you got to bring it to them with the proper business context, not the classic fear, uncertainty, and doubt.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Something they're going to understand, something with mitigations, and really something that you're going to bring an advisement, say, hey, here's what I suggest, but here's the other alternatives that we've considered as part of that.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

The only thing that gives me pause in that is the word control.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

We can't control the decision.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I mean, ultimately, we have a risk if we approach it with that mindset of the old thou shalt and office of no and everything.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But you can control the environment like what you were saying, Andy.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Yeah, I think why I have a visceral reaction to that is some of the faux pas that some CISOs out there make is if they bring something and an executive has a higher risk tolerance and they don't follow that exactly, there's this like, yeah, they get offended and get upset.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Right.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

But the reality is we're a partner and we're going to work together to find what that right decision is.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

That's okay.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

I mean, risk is a business decision at the end of the day.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Some companies are going to have a high risk tolerance, some aren't.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Your job as a CISO and as a business leader ultimately is to figure that out and to meet those goals within that risk tolerance.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

Yeah.

CISO Series Podcast
Our Theoretical Controls Work Great Against Hypothetical Attacks

And I think, I think you've got to have the framework where you can fail quickly, right?