Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

David Spark

πŸ‘€ Speaker
1577 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Quote, every point of friction has a cost.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

If it doesn't earn its place, it shouldn't exist.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

End quote.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

This is Brett Conlin.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

He's over at American Century Investment, and he frames it as deceptively simple.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Friction doesn't just slow teams down.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

It changes their behavior.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Extra approvals, redundant tools, processes that exist, quote, just in case.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

These all feel defensible in isolation, but collectively they push people off the intended path and onto workarounds that introduce the exact risks the controls were meant to prevent.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

The real tell is that controls get added faster than they're removed.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Most security programs never ask if an existing process meaningfully reduces risk or improves outcomes.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Is it, I'm going to ask you, Mike Johnson, as simple as asking that for your controls and processes?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

I mean, can you just ask this question?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And if so, how much extra process baggage are we all sort of holding on to?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

All right.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Mike, I'm going to throw this to you.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Have you done this exercise?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And I'm interested, have you actually removed or controlled?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Yeah, great question.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

The answer is yes and yes.