3 ms·
I would assume that a CSO at a F500 company is mostly responsible for things like budgeting, hiring, and high level strategy. I would think not knowing these sp
by nathantotten 9y ago
I would assume that a CSO at a F500 company is mostly responsible for things like budgeting, hiring, and high level strategy. I would think not knowing these specifics is reasonable. What isn’t excusable though is these companies ignoring advice from internal and external sources. Companies clearly make deliberate budget choices by weighing risk/reward and a CSO at a big company often rationally doesn’t make the right security choice because the risk is small. IMO, bills like this are needed in order to force companies to properly value the risk of bad security.
- alphonsegaston 9y agoThe idea that you can make high-level strategy choices about security without intimate knowledge of that domain is what needs to go away. That kind of thinking is the product of a business culture designed to keeping rich people with MBAs employed over making sane decisions.
- nathantotten 9y agoI think that's being a little extreme. I would guess that a CSO is typically somebody who has the experience, but has worked their way up. It is natural that as you progress in leadership in a company you become less knowledgeable about the details. A good executive is somebody who can hire the right people and listen to them. Somebody who has to know everything themselves is actually dangerous in my opinion - they are ignorant of what they don't know, could be unwilling to take advice, and may be inflexible about new ideas. To clarify, I am not talking about a CSO at a 100 person startup. I am talking about somebody like the CSO of equifax or Boeing which should have hundreds of people reporting to them. They cannot possible know the specifics of everything they secure.