
Executive Cybersecurity with Dave Tyson
One of the industry's most decorated CISOs, Dave Tyson served at SC Johnson, Pacific Gas and Electric, and led eBay's security, all before taking on his role as president of Apollo Information Systems. Executive Cybersecurity is Dave's direct conversation with boards and executives about how to handle the challenges they face as an organization and their role in building a culture of security in everything they do.Short and practical, Executive Cybersecurity with Dave Tyson gives you direct access to the latest in cybersecurity thinking and strategy.
Executive Cybersecurity with Dave Tyson
Easy Cybersecurity Framework for Boards
•
Dave Tyson
•
Season 1
•
Episode 4
- By focusing on the Crown Jewels of the organization and adding robust security intelligence about real threats the appropriate metrics and measurements can be defined that enable a superior cyber security governance and decision-making framework.
- In many industry verticals now, good cyber security is considered “table stakes” but truly focused cyber security excellence is used as a business differentiator for many, and can provide business competitive advantage, which drives customer and employee trust.
- Cyber attacks are a business with typical business goals, understanding and monitoring these trends and changes is instructive for managing cyber security business risk. Measure risk by business unit in your framework.
- Build security metrics and performance dashboard based on crown jewels protection and business priorities, not IT activity.
- Most poor security circumstances are a result from a business decision made, either with or without risk understanding. Bring transparency to those business decisions and ensure the risk taken on aligns with executive guidance. Track decision-making performance versus risk over time.
- Track and measure risk creation and expected mitigation by the leader, align expected risk resource allocation and results to performance pay metrics.
- Disconnect from the idea that security tools by themselves will solve your problems, you need good processes, policies, communication, and aware employees and contractors to create an environment where security tools can create their value.
- Security capabilities are created every day that can greatly reduce business cyber risk but are rarely implemented because innovation dollars are assigned elsewhere, and risk strategy is stuck in traditional thinking. Real expertise can break the logjam.
- Much of the industry is, not surprising, invested in just selling you more……. recognize what this is and ensure your spend decisions are actually reducing risk specific to what matters the most.