4 ms·
It's hard to imagine anyone being that bad of a CISO. No CISO is going to say "shut down the business while we figure out security", not one who's been a CISO m
by staticassertion 5y ago
It's hard to imagine anyone being that bad of a CISO. No CISO is going to say "shut down the business while we figure out security", not one who's been a CISO multiple times at least. And then for them to not back down or discuss things? Unlikely.
More likely they just weren't getting things done fast enough. CISOs come and go - they're a very short lived position.
- tyingq 5y ago>More likely they just weren't getting things done fast enough I'd be surprised if that warranted the “nature of this situation” language.
- staticassertion 5y agoIt could mean so many things tbh. It's true though, it's a very odd way to phrase it. It certainly doesn't feel like a typical CISO exit, but idk.
- tptacek 5y agoIf it's a straight-up termination, that's what you'd expect the company to say (it's extremely unusual for a company to provide backstory for why they're firing senior management, even if the reason is really boring, like "we've lost confidence in the current path the organization is on and feel like we need to take a new direction").
- aerostable_slug 5y agoI find it odd the CISO gets two weeks to transition things while the Head of Security (does that get an acronym?) got shown to the door. The latter doesn't seem as much like a straight-up termination for ordinary performance reasons. Then again, I was at a large company where the CISO managed to get insta-fired in a 1:1 with the CIO. I actually saw the person about two minutes after it happened while they were grabbing their jacket and heading for the door — I don't know what was said, but judging by appearances things got really heated and the CIO had enough. Corporate security appeared shortly to begin boxing things up.
- tptacek 5y agoI don't know what the "head of security" role is. I have no inside knowledge here. But if he wasn't on many people's reporting chain, and a big part of his role was talking to external people and selling Twitter's security program --- not an unusual portfolio for a CSO! --- then there might have been no reason to ask him to hang around. You tend not to have your outgoing CSO do high-profile meetings to sell your security programs exsternally.
- willcipriano 5y ago> No CISO is going to say "shut down the business while we figure out security" I understand why they wouldn't from a personal perspective, however I can imagine situations where this is the right call. For Twitter perhaps not, but I hope the CISO who works at my bank would make this choice if things got bad enough.
- staticassertion 5y agoThe only situations I could see myself saying that are situations where I'd likely be getting authorities involved anyways. For example if the company is covering up an ongoing breach.
- bitexploder 5y agoAvg tenure of a CISO is low. I read one figure that put it at 18-24 months. Something will happen. CISO gets the heat. Rinse repeat. This is only a little shorter than usual, assuming it was performance related.
- michaelcampbell 5y agoThe old yarn of security; when things are great they ask, "What do we pay you for?", when things are bad they ask, "What do we pay you for?"
- jrockway 5y agoSecurity is also something that's pretty hard to "bolt on". The best posture is for every engineer writing code to be aware of potential security problems, and design the system to avoid them. But there aren't enough developers with that skillset to fill the open positions, so instead, they throw it over the wall to another team that improves the security. That makes the security team always one step behind, which is probably annoying to everyone. (People try this with testing and operations as well, with similarly poor results.)
- rendall 5y ago> But there aren't enough developers with that skillset to fill the open positions, so instead, they throw it over the wall to another team that improves the security. The best- run companies I've seen with respect to this have regular and frequent security audits and assign tickets to the team who wrote the code, sometimes even to the developer who wrote it. Also, security is built into the continuous integration as much as possible.
- bitexploder 5y agoA good security engineering function as an organization goes a long way. As does security engineering having a good relationship with dev teams. It starts with developers believing in security and knowing how to transform that belief into action with appropriate change agents. There is always a lot more than audits for places with good security practices and developers who deal well with frequent audits.