Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Megan Samford

πŸ‘€ Speaker
157 total appearances
Voice ID

Voice Profile Active

This person's voice can be automatically recognized across podcast episodes using AI voice matching.

Voice samples: 1
Confidence: Medium

Appearances Over Time

Podcast Appearances

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Get a third-party independent report.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

If you're coming into a company, new to a program, new to a role, you want to make a big splash in the first six months, get a third-party report to baseline where your program's at.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And that's something that you can immediately hand off and present to your board.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And that's going to add a lot of credibility to whatever strategy you're trying to form.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Thank you so much.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

It's awesome to be here with you all.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Yeah, I think it's really more about achieving the balance between high alignment and high autonomy, right?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And for large organizations, what I've seen work successfully is this concept of a three lines of defense strategy.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So the first line of defense needs to be where the risk actually originates.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So if you're a company like mine that develops products and sells them to global markets, our first line of defense is typically considered developers and divisions and individual P&Ls unto themselves.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And so that's really where the risk originates.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

It's the best opportunity you have to mitigate that risk directly.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

The key thing with the first line of defense is that

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Anyone in the first line of defense, just like a factory floor from the 1970s, they should be empowered to have what's called stop the line capability.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

If anyone observes behavior that is out of bounds for the company's values, for their policies, what it clearly says we're going to do with our secure development lifecycle and the way that we make products,

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

anyone should be empowered to raise their hand and say, I don't agree with this behavior and this needs to be looked at more thoroughly.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

That being said, there's also the second line of defense.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

That's really where CISOs sit is the second line of defense.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We are risk overseers.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And so our job is to set policies, set successful governance structures, empower that first line of defense, make their lives easier, create clear escalation paths when we're not seeing behavior that we wanna see

← Previous Page 1 of 8 Next β†’