6 ms·
The reason for that is I'm the CTO, responsible for building out the tech / engineering team. Hiring people is difficult as there is lack of supply of talented
by artellectual 6y ago
The reason for that is I'm the CTO, responsible for building out the tech / engineering team.
Hiring people is difficult as there is lack of supply of talented people. We hire InfoSec on contract basis not full-time and they don't join such meetings due to the nature of the contract. So all the responsibility fell on me to defend our technical decisions at that point in time.
I'm working on building out the engineering culture / awareness within management now, to ensure these things do not happen, and I don't have to be questioned as to why we cannot install "google tag manager" in our front-end.
It all comes down to creating awareness, and making people understand. Fortunately for me our CEO gets it, he ended up siding with me.
- ahmedfromtunis 6y agoHonest question: how can a financial services company not have an in-house infoSec team? To me, this is an even more concerning issue. But then, I have no idea how the finance services world works, so maybe this is more common than I think?
- Narkov 6y agoFinTech doesn't always mean global mega bank. There's lots of small scale start-ups that fit into the financial services category that wouldn't/couldn't afford full time InfoSec roles. Outsourced CISO/InfoSec is a valid and reasonable thing for some companies.
- deleted 6y ago[deleted]
- yellowapple 6y agoI feel like a small scale startup needs internal infosec and audit teams even more. Unlike the incumbents, who are "too big to fail" and therefore are able to get away with blatant insecurity, a startup's in a much more vulnerable position, and any security breach is significantly riskier in terms of corporate longevity. If I was running a financial services startup, those groups would be near the front of my list in terms of internal hiring.
- rasz 6y agoWhy would they? There are still to this day no downsides to a customer data leak here and there.
- artellectual 6y agoThere are huge repercussions. We are governed by PDPA (our GDPR equivalent) law where penalties are extreme. Thailand takes Data Privacy as seriously as EU. But again, since it's not always easy to find the right people I end up having to fill in for everything we don't have a team member to execute on.
- rasz 6y agoDid anyone ever went to jail over a data breach? Though so.
- caffeine 6y agoWorth sharing this thread around your company, maybe? Could help with convincing people that there are negative marketing consequences to careless and seemingly harmless decisions.
- intricatedetail 6y agoI am guessing they don't join such meetings due to IR35 concerns?
- artellectual 6y agoNo has nothing to do with tax. Usually contractors have very fixed scope, they focus on doing what is in the contract. Sometimes things that come up ad-hoc like marketing requesting installation of Google tag Manager, is outside the scope of the contract. It would require a lot of giving them context, amending contract etc... It's not necessarily convenient to have to ask them to come in every time there is a problem. Usually I try to reason with management first. If it can be resolved internally we would not include outside consultants, however if it gets serious beyond something we can handle internally we would ask outside consultant to come in.