39 min

Properly Prioritizing Cybersecurity with Melanie Ensign The Cyber Ranch Podcast

    • Technology

Melanie Ensign is a communications strategist and corporate anthropologist for cybersecurity, privacy, and risk organizations.  She is founder and CEO of Discernible, a multi-disciplinary Center of Excellence for security, privacy, & risk teams. Her team includes experts in communications, product development and management, compliance, security and privacy engineering, and behavioral science.
Melanie is here at the 'Ranch to talk specifically about the fact that so many CISOs feel they are in organizations that simply don’t care about cybersecurity.  She’s got some good insights into this one, and it’s the perfect topic for her expertise.
Allan asks Melanie:
Allan put up a LinkedIn poll asking folks “Do you feel organizations properly prioritize cybersecurity?” The results were pretty sobering.  What are your thoughts?
Is the problem really the organization or is it us? Probably a mix of the two, or maybe one or the other depending upon the environment and the individual CISO?
Assuming it’s the organization, how can a CISO avoid such organizations in the first place? How do you vet a company for its commitment to cybersecurity?
If you find yourself in a company that does not seem to care about cybersecurity, what should be your next steps?
Allan has emphasized over the years that all CISOs are salespeople times two. We sell the problem, then we sell the solution.  Is that a fair perspective in your mind?  How many other leaders have to sell their mission in general?  I think we all end up selling specifics…
What communication skills can improve the situation for CISOs?

Melanie Ensign is a communications strategist and corporate anthropologist for cybersecurity, privacy, and risk organizations.  She is founder and CEO of Discernible, a multi-disciplinary Center of Excellence for security, privacy, & risk teams. Her team includes experts in communications, product development and management, compliance, security and privacy engineering, and behavioral science.
Melanie is here at the 'Ranch to talk specifically about the fact that so many CISOs feel they are in organizations that simply don’t care about cybersecurity.  She’s got some good insights into this one, and it’s the perfect topic for her expertise.
Allan asks Melanie:
Allan put up a LinkedIn poll asking folks “Do you feel organizations properly prioritize cybersecurity?” The results were pretty sobering.  What are your thoughts?
Is the problem really the organization or is it us? Probably a mix of the two, or maybe one or the other depending upon the environment and the individual CISO?
Assuming it’s the organization, how can a CISO avoid such organizations in the first place? How do you vet a company for its commitment to cybersecurity?
If you find yourself in a company that does not seem to care about cybersecurity, what should be your next steps?
Allan has emphasized over the years that all CISOs are salespeople times two. We sell the problem, then we sell the solution.  Is that a fair perspective in your mind?  How many other leaders have to sell their mission in general?  I think we all end up selling specifics…
What communication skills can improve the situation for CISOs?

39 min

Top Podcasts In Technology

Acquired
Ben Gilbert and David Rosenthal
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Lex Fridman Podcast
Lex Fridman
Hard Fork
The New York Times
TED Radio Hour
NPR
Darknet Diaries
Jack Rhysider