CISO Lens is the premier information sharing & analysis community (ISAC) for cyber security executives from the largest organisations in Australia & New Zealand
ICYMI: We've published Nadia Yousef's Incident Response Template. If you're a mid-sized organisation, before your staff start going on leave, use this template as a check list to review your existing IR plan.
https://t.co/pCsAvWbxVJ
This week saw our New Zealand roundtable in Auckland. Key topics included:
* Lack of satisfaction with third party SOCs
* Passwordless solutions
* Various approaches to cyber issues on risk registers
* Lack of board maturity
* lessons learned from Cyclone Gabrielle & floods.
We have published the CISO Lens Benchmark 2022, and it is available for download (no registration required). The information in this benchmark is shared to support evidence-based decision making around strategy and resource allocation. #securityleadership https://t.co/xkZawZNtlX
CISO Lens would like to share some positive news as the work year comes to a close for many.
We are delighted to acknowledge Richard Johnson, Group CISO @Westpac, as the CISO Lens Most Valuable Player for 2022. https://t.co/vMpgWyohl0
Yesterday in Christchurch was our last roundtable for the year. Topics included:
- Boards are maturing and asking better questions.
- The CEOs that "really get it".
- Vendor management.
- Legal, tax, and HR ripples from "work from anywhere" policies.
Our end of year Sydney harbour cruise is a wrap! We had a powerful roundtable, and topics included:
* mental health,
* the destructive impact of board whisperers who do not know as much as they claim,
* IT needs more budget,
* deep concerns over knee jerk legislation
ICYMI: Nadia Yousef's "Deep breaths and lean the f**k in. A user’s guide to Incident Response" presentation at @kawaiiconNZ it has been recorded and stored for the ages on YouTube.
#IncidentResponse#securityleadership
https://t.co/ol5MV0X063
A new phone scam method CERT NZ has been seeing is ‘spoofing’: Scammers using software to change their numbers to look like their calls are from a bank’s phone number to try and trick people into giving access to their bank accounts. Learn more here: https://t.co/l3RcG5JMxi
The dearth of independent experts with nothing to sell, who understand the issues, and can talk to the non-technical means that the vast majority of the ecosystem is getting left behind and being sold flimflam.
Yesterday's Melbourne gathering had big conversations:
* the new government & implications for joint Home Affairs + Cyber accountability,
* security operating models,
* crisis management & cyber,
* inconsistent auditor interpretations of CPS234,
* Microsoft & security.
We're delighted to share Cloud Governance Framework from the CISO Lens community. Thank you @iAshutoshKapse & Vasant Rao
Download is free, no registration required. #securityleadership#governance#cybersecurity
https://t.co/3GtkbYDUOw
“Cybercrime is predicted to cost the world $7 trillion USD in 2022, according to Cybersecurity Ventures. If it were measured as a country, then cybercrime would be the world’s third largest economy.” #infosec
https://t.co/XQTYBU6MGy
We're delighted to publish this report from the CISO Lens community. Standardised Executive Reporting by Andy Chauhan is an enormous piece of work that will save many security and technology executives from starting with a blank piece of paper. https://t.co/g50OKz9sei
Wonderful gathering yesterday in Auckland!
A big topic was the skills crisis, and how consulting firms & body shops are responding:
1) They are starting to raise fees &
2) Sending in less qualified people with bigger titles