4 ms·
Avg tenure of a CISO is low. I read one figure that put it at 18-24 months. Something will happen. CISO gets the heat. Rinse repeat. This is only a little short
by bitexploder 5y ago
Avg tenure of a CISO is low. I read one figure that put it at 18-24 months. Something will happen. CISO gets the heat. Rinse repeat. This is only a little shorter than usual, assuming it was performance related.
- michaelcampbell 5y agoThe old yarn of security; when things are great they ask, "What do we pay you for?", when things are bad they ask, "What do we pay you for?"
- jrockway 5y agoSecurity is also something that's pretty hard to "bolt on". The best posture is for every engineer writing code to be aware of potential security problems, and design the system to avoid them. But there aren't enough developers with that skillset to fill the open positions, so instead, they throw it over the wall to another team that improves the security. That makes the security team always one step behind, which is probably annoying to everyone. (People try this with testing and operations as well, with similarly poor results.)
- rendall 5y ago> But there aren't enough developers with that skillset to fill the open positions, so instead, they throw it over the wall to another team that improves the security. The best- run companies I've seen with respect to this have regular and frequent security audits and assign tickets to the team who wrote the code, sometimes even to the developer who wrote it. Also, security is built into the continuous integration as much as possible.
- bitexploder 5y agoA good security engineering function as an organization goes a long way. As does security engineering having a good relationship with dev teams. It starts with developers believing in security and knowing how to transform that belief into action with appropriate change agents. There is always a lot more than audits for places with good security practices and developers who deal well with frequent audits.