CISO Stressed

SCYTHE

It’s dangerous to go alone! Evolving threat landscapes and shifting resources. CISOs need all the swords and unicorns available and at the ready - leveraging their team, time, and budget to focus on the adventure at hand. CISO Stressed - SCYTHE’s latest release focuses on the quests that CISOs face. Join Liz Wharton (Chief of Staff at SCYTHE) for conversations on what is top of mind with CISOs - what causes stress and what they’re stressing within their organization. New episodes released every month. Come join and listen in.

Episodes

  1. CISO Stressed Episode 5: Nick Andersen CISO for Public Sector at Lumen Technologies and Nonresident Senior Fellow with the Cyber Statecraft Initiative at the Atlantic Council.

    06/08/2021

    CISO Stressed Episode 5: Nick Andersen CISO for Public Sector at Lumen Technologies and Nonresident Senior Fellow with the Cyber Statecraft Initiative at the Atlantic Council.

    On this episode of CISO STRESSED, Elizabeth Wharton SCYTHE Chief of Staff is joined by Nick Andersen, CISO for Public Sector at Lumen Technologies and Nonresident Senior Fellow with the Cyber Statecraft Initiative at the Atlantic Council. Wharton and Andersen discuss the unpacking of Biden’s latest Executive Order with the Atlantic Council, and the importance of collaboration and sharing within the CISO role.     Show Notes:    Andersen shares his experience unpacking the most recent thirty-page executive order from the Biden Administration.  Andersen unpacked the executive order with the Atlantic Council people encapsulating the S Bomb initiatives that NTIA has been working on for a couple of years, to EDR Requirements, instant response playbooks, and cloud requirements there is a lot to unpack.    (4:28 – 7:17) Andersen shares that any time he has reached out to anyone as a CISO with questions or interest in something he read, he has never been turned away for help and he enjoys the collaborative nature of the community.    (5:31 – 6:58) Talking about the community of collaboration on the private sector side continuing as well as it did on the government side)   (12:52 – 14:17) Lumen sees a tremendous amount of traffic: ingesting about 190 billion net flow sessions and 771 million DNS queries per day. This creates a great opportunity for Lumen to pair up with other organizations and discuss what we are seeing, what is normal/abnormal, what we see in an adjacent sector, and within our customer segments. There are many opportunities for collaboration and taking advantage of the insights from a company like Lumen that sees so much traffic. Collaboration helps each party deepen their understanding of what is happening within a threat environment.    From the CISO perspective A huge difficulty is it to remind people of all the competing and compliance issues. There is a tremendous amount of intertwined nature between federal and state entities and opportunity there as well. States stand up and say they are going to model some of our compliance and procedures and policies based off the way the federal government has taken their approach. It is difficult to ask these tiny little county and city governments to meet these requirements when, in some cases, they are made up of just two people responsible for all that. It’s important for them to be able to leverage the knowledge base at the federal level, and then piggyback.    Subscribe to SCYTHE’s YouTube Channel and watch the latest CISO Stressed episode as well as Threat Thursday and other video releases. Questions or conversation ideas? Drop us an e-mail at info@scythe.io with “CISO Stressed” in the subject line.

    24 min
  2. CISO Stressed Episode 4: SCYTHE Chief of Staff Elizabeth Wharton interviews Dr. Pablo Breuer.

    05/11/2021

    CISO Stressed Episode 4: SCYTHE Chief of Staff Elizabeth Wharton interviews Dr. Pablo Breuer.

    On this episode of CISO STRESSED, SCYTHE Chief of Staff Elizabeth Wharton interviews Dr. Pablo Breuer. Breuer is currently a non-resident senior fellow at the Atlantic Council’s GeoTech Center and the CISO of Security BSides Las Vegas. They discuss what to change in a team’s response plan after a ransomware attack, ransomware and malware attacks going undetected for months at a time, and his response to stress and building better plans. KEY TAKEAWAYS  The military is more likely to plan out a few years in advance, and commercial companies normally only plan as far as one fiscal year ahead of time.   There is something to be learned from both the private and the public sector.    Get back to basics. Solarwinds could have been prevented from ever reaching a supply chain attack if people didn't’ gloss over the basics: Interns shouldn’t be allowed to do things that are public facing without a mentors supervision   Attacks are going to happen: It’s the nature of the beast, and there’s too much incentive.   Companies need to evaluate what risk they are currently accepting, if that risk is acceptable, and if not how do they get down to residual risk that is.   Depending on who’s map you follow, at the end of 2020 we had between fifteen or twenty times the number of devices on the internet than we had people on the planet.   A CISO is essentially a risk advisor, advising company risk. They don’t get to decide what’s acceptable, the company decides what risk is acceptable.

    23 min

About

It’s dangerous to go alone! Evolving threat landscapes and shifting resources. CISOs need all the swords and unicorns available and at the ready - leveraging their team, time, and budget to focus on the adventure at hand. CISO Stressed - SCYTHE’s latest release focuses on the quests that CISOs face. Join Liz Wharton (Chief of Staff at SCYTHE) for conversations on what is top of mind with CISOs - what causes stress and what they’re stressing within their organization. New episodes released every month. Come join and listen in.