RISK & CYBERSECURITY

Thoughts from the Field
  • HOME

  • ABOUT

  • RECENT EVENTS & PUBLICATIONS

  • More

    Use tab to navigate through the menu items.
    • Instagram - White Circle
    • All Posts
    • Leadership
    • Risk
    • Cybersecurity
    • Technology
    Search
    • May 8
    • 9 min

    Regulatory Relationships

    For some reason there have been a few people already in or moving into highly regulated industries, like finance or healthcare, that have...
    1,114 views
    • Apr 21
    • 3 min

    The Stress and Joy of Security Jobs - Updated

    There’s a lot going on in the world from conflict, crime, economic and many other pressures. Many of these matters have security...
    2,767 views
    • Feb 12
    • 18 min

    Organizational Politics

    At every stage in your career and in every part of your role you are going to have to deal with organizational politics. By this, I don’t...
    6,441 views
    • Jan 29
    • 16 min

    Secrets of Successful Security Programs - Part 2

    As introduced in the last post, a successful security program is made up of two distinct elements: A series of episodic big bets that...
    4,929 views
    • Jan 15
    • 11 min

    Secrets of Successful Security Programs - Part 1

    A successful security program (although I imagine this advice could apply to any discipline) is made up of two distinct elements: A...
    8,421 views
    • Jan 1
    • 7 min

    The Obvious CISO : Don’t Overlook the Simple

    There is a great little book I read recently, “Obvious Adams - The Story of a Successful Businessman", it’s available on Amazon, but it’s...
    1,458 views
    • Dec 4, 2021
    • 8 min

    How is the Security Profession Doing?

    I spoke on a CIISEC panel a few months ago about the state of the information security profession. This post is based on remarks I made...
    2,217 views
    • Nov 20, 2021
    • 4 min

    Security Program Tactics - Updated

    When starting or reinvigorating a security program, focus on a small number of meta-objectives that can have sustained outsize effects in...
    2,095 views
    • Nov 6, 2021
    • 6 min

    Slipstreaming : Business Tactics for Security & Control Implementation

    One of the most frequent cybersecurity binary thinking curses is that just because senior leadership in organizations won’t do every...
    1,299 views
    • Oct 22, 2021
    • 4 min

    Conferences and the Wider Security Eco System Culture - Toxic or Not?

    This could be part of another whole series on the curse of binary thinking so please read this in that tone. In other words, I’m trying...
    865 views
    • Aug 14, 2021
    • 9 min

    Risk = Hazard + Outrage

    There are four major insights that, above all others, have influenced my approach to security and risk management over the past decades....
    3,386 views
    • Jul 16, 2021
    • 8 min

    Cybersecurity - The Board's Perspective

    How Boards, especially public company Boards, oversee cybersecurity is a crucial but difficult topic. This previous post discussed how...
    6,766 views
    • Jul 3, 2021
    • 6 min

    Cybersecurity and the Curse of Binary Thinking

    Working in information/cybersecurity and technology risk is a fascinating and challenging career, as I’ve covered here. There is, mostly,...
    21,613 views
    • Jun 19, 2021
    • 7 min

    The Actual Cybersecurity Workforce Challenge

    We continuously hear about the millions of unfilled cybersecurity roles, although I’ve yet to see a study that actually supports that...
    5,252 views
    • Jun 5, 2021
    • 6 min

    Relationship Management for the InfoSec Program

    A key part of any security leader's role is relationship management. In my experience this is another one of those leadership skills that...
    1,981 views
    • Apr 24, 2021
    • 1 min

    Leadership, Business, Security and Risk Reading List

    This is my list of favorite books across the various professional disciplines I’m interested in. I have a set of favorite books that are...
    2,368 views
    • Feb 27, 2021
    • 3 min

    "Hell Yes, or No" vs. "Soft Yes, and Fast Quit"

    I am a big fan of the concept of saying, “Hell Yes, or No” to decide whether to do something or not. Derek Sivers has written well about...
    2,721 views
    • Dec 6, 2020
    • 6 min

    The Seat at the Table: Integrating Security into your Business

    The success of a security program is largely determined by how well it is integrated into the fabric of the organization, in terms of...
    1,853 views
    • Nov 29, 2020
    • 3 min

    Simple Rules of (InfoSec) Career Success - Updated

    Over the years I've noted the behaviors I’ve seen from consistently successful people. In this context I define success as a balance of...
    1,424 views
    • Nov 15, 2020
    • 6 min

    12 Step Guide on Escalating Risk and Security Issues 

    Escalating issues is part of the foundation of any good risk and security program. Unfortunately, human nature is such that most people...
    2,097 views
    1
    23
    Subscribe for updates.

    Thanks for submitting!

    © 2020 Philip Venables.