Menu
Sign In Search Podcasts Libraries Charts People & Topics Add Podcast API Blog Pricing

Mike Mello

๐Ÿ‘ค Speaker
155 total appearances

Appearances Over Time

Podcast Appearances

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Yeah.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And the thing, it comes out once a year and it means so much to the industry.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

It's the equivalent of in the futures markets where there's like the annual farms report or the annual futures for mining.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Those things are very heavily watched out for.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

I think the most interesting point in here is about the introspection of your current controls.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

I mean, I got to imagine not a lot of people do this.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

You don't do it because it's too easy to leave that which is in place.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Leave it there.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Inertia is a powerful force.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And so people tend to leave those controls in place.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And there's also, as security professionals, we are also risk management professionals.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

There's an element of risk involved in removing an existing control.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

If you remove that and then there's a incident, it's not going to look very good.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Why did you do that?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

So I think people are very hesitant to look at those controls because if you're not going to remove them, then why are you spending the time even looking at them?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

But in terms of dealing with it, there are natural opportunities that occur all the time.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

Like if you get a new team member, just ask them, hey, what do you think of our controls?

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

New eyes definitely help.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

The new eyes really do help.

CISO Series Podcast
Our Data Security Policy Is Transparent in That It Doesn't Exist

And that's one of the opportunities that you have