Operationalize the NIST Cybersecurity Framework Without Pulling All Your Hair Out (Part 2 of 3)

This is the Part 2 of a 3-part blog on how to use the NIST cybersecurity framework without getting bogged down and lost in the minutia of the specification documents. Part 1 can be found here, and we recommend you read this piece first if you have not… Continue reading Operationalize the NIST Cybersecurity Framework Without Pulling All Your Hair Out (Part 2 of 3)

5 Mistakes CISOs Make in Their Board Presentations

As a cybersecurity leader, you generally receive only a short time window in the board meeting for your update. During this time, you need to communicate key risks and remediation tactics, explain your strategic goals and plan, and answer questions; a… Continue reading 5 Mistakes CISOs Make in Their Board Presentations

What NOT to Do in Your First 90 Days as a CISO

Recently, Daniel Hooper, CISO at Varo Bank asked his LinkedIn network what their recipe for the first 90 days as a CISO would be. The post got 50+ responses but one that really stood out to me (and resonated with the whole group) was what NOT to do. T… Continue reading What NOT to Do in Your First 90 Days as a CISO

Security Awareness Training: How Often Should Your Employees Get Retrained?

Almost every company has some sort of security training, along with several other training prompts to complete during the new hire process. But once initial training is complete, how often should you revisit? With the ever-changing cybersecurity lands… Continue reading Security Awareness Training: How Often Should Your Employees Get Retrained?