Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Megan Samford

πŸ‘€ Speaker
157 total appearances
Voice ID

Voice Profile Active

This person's voice can be automatically recognized across podcast episodes using AI voice matching.

Voice samples: 1
Confidence: Medium

Appearances Over Time

Podcast Appearances

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

They're the dead body.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

I know that you're going to give me a horrible scenario and I'm going to have to choose between the lesser of two evils.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Sure, so I will also address point number one.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So what I heard there, the Reader's Digest notes was, we uncovered a lot of risk and we're aware of the gaps.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Great, that's every day on the CISO job.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Like this is great that we actually know what the gaps are.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

I mean, this almost felt like a softball question because we do this every single day.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So if you've identified all of your gaps, a CISO should never be owning risk, number one.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

They are a risk overseer.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So there should be other executives within the company that need to be aware of the risk and they would be responsible for either dispositioning that risk and coming up with a timeline for when remediation and everything else needs to happen, or they need to formally sign their name on the document that they are accepting the risk for a period of time.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

And that needs to be time bound, right?

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Like we can't perpetually accept risk that are a danger to the company or increasing risk to the board or anything like that.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

I think question number one is pretty softball.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

We disposition, assign, have people review, sign off on risk, escalate the risk or otherwise come up with a roadmap for how they're going to deal with it every single day.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

No one should be stumped by that question whatsoever.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

On question number two, with the thing you have going on there with the potential phishing and the mobile apps team, number one, I'm impressed that the CISO was notified quickly.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

I'm impressed that people have come to you with this.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Okay.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

So we're sitting in this reality again.

CISO Series Podcast
It's Not That We Don't Value Your Experience, We Just Don't Want to Pay for It

Then I would say you need to, number one, determine potential initial impact in that golden hour.