Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Megan Samford

πŸ‘€ Speaker
157 total appearances
Voice ID

Voice Profile Active

This person's voice can be automatically recognized across podcast episodes using AI voice matching.

Voice samples: 1
Confidence: Medium

Appearances Over Time

Podcast Appearances

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

How did the right folks get eyes on it?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And how is that risk disposition properly with escalations that hopefully don't need to have emotion about them, right?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

When things are going wrong, everyone should be free to say that this is something that we need to take a closer look at.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

But you're really running more like air traffic control.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And then your third line of defense, perhaps my favorite line, is that third-party internal audit, making sure that the risk overseers in that first line of defense are doing what they said that they were going to do and they're not accepting more risk than is appropriate at their level.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And that risk is being surfaced up to the board and all of that.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And then, of course, I'm also a fan, as I mentioned earlier, of third-party independent reports.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So that could come in the form of

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

like a 62443 certification or an independent consulting firm helping you out just to get an external view on what you're doing and making sure that everything is coming to light.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Sure.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

This is a topic, if you had eight hours, I could talk to you about this.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

But I think the first thing is you're going into the problem set, viewing it correctly, and that, yes, OT is different.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We say this every single day.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

But there's a term that's emerging called industrial realism.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Okay.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Yes.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And what this is, is recognizing that, yes, the controls are going to look very different within OT environments.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We have been adopting a lot of the good security practices from our friends on the IT side.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And this IT-OT convergence has been happening, I think, for the past decade.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

five, 10, 15 years, depending on who you ask.