BSW #307 – Matt Radolec
Full Audio
View Show IndexSegments
1. It’s All About the Data: Understanding Your Blast Radius to Reduce Risk – Matt Radolec – BSW #307
You can rebuild infrastructure. But you can’t un-breach data – Data sits at the core of an organization and is often the most open and vulnerable. This is why data security is the most important and urgent security problem to solve right now. We’re joined by Matt Radolec, Senior Director of Incident Response and Cloud Operations at Varonis, to walk through the blast radius concept – from what it is and how to use it to understand your organization's risk, to how it can serve as a guide to securing data from insiders and external attackers.
Segment Resources: The Great SaaS Data Risk Exposure report: https://info.varonis.com/hubfs/Files/docs/research_reports/Varonis-The-Great-SaaS-Data-Exposure.pdf
The Forrester Wave™: Data Security Platforms, Q1 2023 https://reprints2.forrester.com/#/assets/2/1646/RES178465/report
Learn more about the Varonis Data Security Platform https://www.varonis.com/products/data-security-platform
This segment is sponsored by Varonis. Visit https://securityweekly.com/varonis to learn more about them!
Announcements
Security Weekly listeners: Identiverse is just weeks away! Register now and join the digital identity community at the ARIA Resort & Casino in Las Vegas, May 30 – June 2. The 14th annual Identiverse will bring together over 2,500 security professionals for 4 days of world-class learning, engagement, and entertainment.
As a community member, receive 20% off your Identiverse 2023 tickets using code IDV23-SW20!
Register today: securityweekly.com/identiverse2023
Guest
Matt Radolec, Senior Director, Incident Response and Cloud Operations at Varonis, leads a global team of security and cloud experts. His teams help organizations adopt a data-centric approach by securing data from the inside out.
The Varonis Incident Response Team, created and led by Radolec, routinely aids Varonis clients in thwarting insider threats and cyberattacks, including notable and publicized breaches initiated by Blackcat, Darkside, REvil, Trickbot, and many others.
Hosts
2. Do You Need a CISO, & Employee Contract May Keep CISO Out of Jail – BSW #307
In the leadership and communications section: Do You Really Need a CISO?, A CISO Employment Contract May Mean the Difference Between Success and Jail, When Your Employee Tells You They’re Burned Out, and more!
Announcements
Our teams from Security Weekly and SC Media were onsite at RSA Conference 2023 delivering in-depth reporting, analysis and interviews from the conference. If you were unable to join us in person, or didn't manage to catch our video livestream from Broadcast Alley, you can access all of our RSAC 2023 coverage at https://securityweekly.com/rsac.
Hosts
- 1. Do You Really Need a CISO?
A CISO is a senior executive in charge of an organization’s information, cyber and technology security. CISOs need a complete understanding of cybersecurity as well as the business, the board, the C-suite and how to speak in the language of senior leadership.
It’s a changing role in a changing world. But do you really need one?
- 2. A CISO Employment Contract May Mean the Difference Between Success and Jail
CISOs are responsible for the security of an organization’s information systems and data and they are often held accountable for any security breaches that occur. Both the Sullivan/Uber criminal case and the SolarWinds/SUNBURST civil case against the company’s CISO demonstrate the need for CISOs to have personal protection as part of their jobs. To protect themselves from civil and criminal liability, CISOs should ensure that they have the following:
- D&O or other liability insurance
- A duty of the company to indemnify and hold harmless
- Express whistleblower protections
- 3. CISO and board collaboration, driving better outcomes together
Your organization’s board has a unique role to play in managing cyber risks. Board members are not involved in the day-to-day cyber security strategy development and execution, but they are responsible for oversight and serve as fiduciaries.
Although it can be difficult for board members to engage around cyber risk, board members are expected to ensure that cyber risk remains on the agenda, as it can affect customer data, trade opportunities, and share prices, among other things.
Despite the fact that cyber risk became a board-level topic quite some time ago, boardroom stakeholders who drive the cyber security conversation can have misaligned viewpoints, translating to inconsistent corporate visions and weak decision-making.
- 4. CISO’s push for mental health support in cybersecurity
A new report hopes to challenge the way the industry deals with burnout, stress, and mental health problems. The immediate actions of the report will be:
- Professional and certifying bodies should include the awareness of the importance of mental health and stress issues into their knowledge domains, certifications, standards, frameworks, and best practices.
- Governments, professional and certifying bodies should make funding available for research on mental health in cybersecurity.
- Enterprises should actively include mental health in their strategic planning & measurable outcomes.
- Cybersecurity professionals should speak out about stress, raise awareness and identify signs and symptoms of stress in themselves and their colleagues, and explore ways to support their teams to address the root cause.
- 5. Cybersecurity risk could soon become buying criteria for CSCOs
A recent survey from Gartner finds just how important cybersecurity has become for businesses with fewer than 1,000 employees. According to the research firm, 60% of supply chain organizations plan to use cybersecurity risk as a “significant determinant” in conducting third-party transactions and business engagements by 2025.
This means chief supply chain officers (CSCOs) need to be on top of the latest threats in a quickly changing environment.
- 6. When Your Employee Tells You They’re Burned Out
Burnout is affecting both leaders and employees — and contributing to a talent shortage that’s challenging and costly to navigate. It can be challenging for even the most enlightened managers to have conversations about employee burnout while managing the needs of the business. The author offers five steps to take when an employee comes to you expressing burnout:
1) Treat their concerns seriously; 2) Understand their experience of burnout; 3) Identify its root causes; 4) Consider short- and long-term solutions; and 5) Create a monitoring plan.