6 ms·
Somebody told me a few years back that the life time of a CISO in a larger organisation is not larger than 24 months. In my organisation that proved to be true
by kune 5y ago
Somebody told me a few years back that the life time of a CISO in a larger organisation is not larger than 24 months. In my organisation that proved to be true so far. Here the rule applies as well.
- Phlarp 5y agoIt really feels like the CISO role has become less about the security posture of an organization and more about being a corporate whipping boy-- Predesignated as the go-to sacrificial lamb for when a public leak or government investigation comes knocking. Hard to find longevity or stability in a role that exists to fail
- BeFlatXIII 5y agoOnce this is known throughout the industry, it also means that the whipping boys keep getting fired and then taking up their next tenure at the startup next door until they're fired again.
- tptacek 5y agoTo the extent that's true, it sure doesn't seem to stop high-profile people with lots to lose from taking that role.
- michaelcampbell 5y ago$$$, golden parachutes, quick vesting equity...
- hn_throwaway_99 5y agoCISO's get paid a ton of money to be that sacrificial lamb. At the same time, since it's widely known that the post is a sacrificial lamb post, there is really not that much to lose.
- MattPalmer1086 5y agoA CISO told me that the role was to beg for resources and then to get fired if something goes wrong.
- hn_throwaway_99 5y agoHaving seen how some CISOs "beg for resources", I pretty fundamentally believe most of this money is wasted anyway. The only way you can really get better security at a company is to have an ingrained security culture. I.e. developers are continually educated on secure coding practices and new threats, code reviews include security checklists, corporate security training includes continual social engineering tests and an atmosphere of continual improvement. And yes, that stuff does cost money, but that's rarely the resources I see CISO's fight for. Instead, they fight for lots of expensive software, things like useless, shitty WAFs or poorly built "network monitoring" software (which can be a huge threat vector in itself, just see the SolarWinds fiasco). Like many other comments here, I don't believe security is something you can "bolt on" at a company. Yes, there are specialized roles that a dedicated security team needs to fill, but unless everyone at the company has a true understanding of the value and importance of security vigilance, you're screwed.
- cutemonster 5y ago> code reviews include security checklists, Can I have a checklist please? Full stack web dev Edit: Here I found one https://www.michaelagreiler.com/security-code-review-checklist/ https://www.michaelagreiler.com/security-code-review-checkli...
- MattPalmer1086 5y agoThere are some bits phrased the wrong way around (e.g. are session parameters passed in URLs? Check!). You don't want to do that. But as list of things to consider, if you already understand what you're doing, its not too bad.
- MattPalmer1086 5y agoIt's a huge problem in security to know what money is wasted or not. Not hacked yet? Lucky or wise? It's probably like the old saw about advertising. Half of all it is useless, we just don't know which half!
- saagarjha 5y agoPerhaps they should check to see if they ever denied the position to Lord Voldemort.
- edmundsauto 5y agoI’ve been told similar for CMO - < 1 year tenure on average. The narrative was that CMO are weirdly in a mix of technical and creative and accounting, meaning they need to come up with answers and execution that satisfy CEOs. So either the company does well and the CMO stays, or not. And the default for most companies is to fail.