From months I have been going through a lot of tools
* Configuration/Mis Config Management tools for cloud - Internal Issues at high level
* External Attack Surface Management tools - Things outside your perimeter
* Internal Tools - SIEM, XDR, MDR, DLP...etc - which are managed by SOC Services
* Phishing simulation platforms
* Standards like DMARC, BIMI etc
* Compliance - ISO 27001, HIPPA, SOC2 blah blah....
* Did I miss anything ?
Regardless of all these - I have seen that there are breaches, there are misconfiguration that got me thinking what could be reason
* Orgs don't have budget to but all these cool stuffs - it's kinda luxury - though people are aware but they can't use
* Orgs don't have bandwidth - it's usually outsourced and outsourced stuffs are not under-contractual obligations to pay.
* There is lot to do in lot less time - every now & then things keep popping up.
What do you folks think - How much a CISO/CyberSec lead should do ? What is future of cybersec - form your POV ? What would be an ideal solution to these problems ?
or I am just being noob.
submitted by /u/EternalxIntern
[link] [comments]
http://dlvr.it/SyS3zY
Post Page Advertisement [Top]
Subscribe to:
Post Comments (Atom)
';
(function() {
var dsq = document.createElement('script'); dsq.type = 'text/javascript'; dsq.async = true;
dsq.src = '//' + disqus_shortname + '.disqus.com/embed.js';
(document.getElementsByTagName('head')[0] || document.getElementsByTagName('body')[0]).appendChild(dsq);
})();
No comments:
Post a Comment