#1 Trending Cybersecurity News & Magazine
Monday, September 18, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    AraĆŗjo e Policastro Advogados Breach

    AraĆŗjo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    • Ā Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    AraĆŗjo e Policastro Advogados Breach

    AraĆŗjo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

    TransUnion cyber attack

    USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

    Dymocks Cyber Attack

    Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

    Retool Data Breach

    Retool Data Breach Linked to Google Authenticator Vulnerability

    Cybercrime competitions

    Inside Cybercrime Tournaments: Players, Incentives, and Impact on Security

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Anime About Hacking

    Get Your Hack On: Top 10 Anime About Hacking for Cybersecurity Buffs

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Ransomed Interview: Operator Speaks About No Mercy and All Gain

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    Cyble Partner Network

    Cyble Revolutionizes Cybersecurity Collaboration With Launch of Global Partner Program ‘Cyble Partner Network’

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    • Ā Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Features

A CISO’s First 90 Days: The Ultimate Action Plan and Advice

Having an action plan in place for early days can help CISOs prioritize steps that need to taken, based on what they learn about an organization's existing systems and data.

Editorial by Editorial
September 3, 2023
in Features, Firewall Daily
0
new CISO
595
SHARES
3.3k
VIEWS
Share on LinkedInShare on Twitter

by Maheswaran Shamugasundaram, Country Manager – India, VaronisĀ 

Many organizations seek a Chief Information Security Officer (CISO) who possesses a mix of technical proficiency and leadership abilities.

You might also like

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

AraĆŗjo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

While this is no longer a purely technical role, CISOs need to be able to communicate effectively with technical teams, understand evolving security risks and data protection technology, and be able to articulate complex security matters and solutions to non-technical executives and board members.

For CISOs starting at a new organization that has unknown data governance and security systems, the first 90 days can be challenging, to say the least.

Challenges faced by new CISOs

Over the last 10 years, the role of the CISO has become pretty complex, and this has become even more pronounced since the onset of COVID.

From a relatively straightforward office job that involved protecting devices and files where data is stored, CISOs today have to do a lot of heavy lifting due to the world of remote work and the progressive shift of data into the cloud.

Employees and applications now need to be connected to each other 24/7, around the world. Not to mention the abundance of third-party applications that require access to your sensitive data and often don’t get the security team’s seal of approval prior to activating.

This means dealing with new threat vectors and additional gaps that can be exploited for fraud and theft, such as employees working from unsafe locations and wifi networks.

Spare a thought for CISOs who have ended up with tons of extra tasks and risk management problems from remote work.

On the flip side, with advanced technology such as Data Security Posture Management (DSPM) platforms, CISOs can easily locate and tag more sensitive data, apply access permissions, and track usage and movement. This means they can quantify risks and analyze what went wrong in the event of a breach so they can prevent future attacks.

For organizations that rely on endpoint and perimeter solutions for security, CISOs can bear the brunt of any attacks by the latest developments in ransomware, such as threats that seek to monetize their malicious access.

These breaches can result in your data being held for ransom and locked down until payment is made. Payment demands are often made with crypto as the currency, which makes it hard to track, and almost impossible to recover once a payment is sent.

From a team perspective, the role of CISO is a disabler, not an enabler—so new CISOs need to develop a thick skin early on.

They’ll need to build out a team of SecOps, GRC, and Sec Architects, and ensure that everyone is productive whether they’re on-site or working from home.

Plus, they will need to ensure that security initiatives put in place are understood and adhered to by everyone – from the CEO to the R&D teams and non-technical board members.

The challenges faced by a new CISO can also manifest in other ways, like stress from a lack of resources and technology available to help them succeed in their role. A single, centralized platform can positively impact their work, reduce the risk of mistakes, and improve stress levels.

Why the first 90 days are critical for a new CISO

It’s a CISOs responsibility to establish a solid security foundation as rapidly as possible, and there are many mistakes that can be made along the way. This is why the first 90 days are the most important for new CISOs.

Without a clear pathway to success in the early months, CISOs can lose confidence in their ability as change agents and put their entire organization at risk of data theft and financial loss. No pressure!

Here’s our recommended roadmap for CISOs in the first 90 days of a new role.

CISOs’ action plan for the first 90 days

Having an action plan in place for the early days can help CISOs prioritize the steps they need to take, based on what they learn about an organization’s existing systems and data. This means they can reduce the feeling of overwhelm and work strategically toward business goals.

Implement measures to ensure data is protected

For a new CISO, it can be challenging trying to locate and classify all the sensitive data across an organization, not to mention ensuring that it’s also safe from a variety of threats.

Data protection technology is often focused on perimeters and endpoints, giving internal bad actors the perfect opportunity to slip through any security gaps in files, folders, and devices. For large organizations, it’s practically impossible to audit data activity at scale without a robust DSPM.

It is important to have a customized Data Risk Assessment that causes zero disruption to your IT environment, and can help new CISOs quickly:

  • Pinpoint vulnerabilities.
  • Simplify compliance.
  • Prioritize risks and act on them according to business requirements.

By implementing a DSPM tool, CISOs can automatically build a baseline, or ā€œpeace-time profileā€ over hours, days, and weeks for every user and device in your organization, enabling them to:

  • Easily spot unusual behavior in the cloud or on-prem.
  • See what kinds of accounts exist and who they belong to.
  • Understand who uses which devices and accesses certain data.
  • Monitor when users are active and where they are located.

Develop a system to detect and respond promptly to any potential breaches.

Most security solutions can only fix breaches after they’ve happened, not before or during a threat event. In many cases, affected data can’t be restored—so an ā€œafter the factā€ solution isn’t enough.

Focusing on data and insider threats, allows CISOs to secure files, folders, drives, and permissions far beyond the abilities of simple backup or perimeter solutions. This includes insider risk-management tools and automatic detection at any sign of compromise.

Alongside automated threat detection and mitigation, organisations should have a dedicated incident response team who can help with:

  • Proactive alert monitoring and threat investigation.
  • Customized threat model development.
  • Automated response configurations.
  • Regular updates to review security findings.

Ensure there are robust security measures in place.

Organizations create and send a stunning amount of data every day across their cloud and internal networks. As cloud service adoption increases, CISOs need to know where the risks are at every touchpoint so they can prioritize each risk and put the necessary security in place.

This includes thinking about factors such as:

  • Enhanced monitoring of external and guest users.
  • Privileged account monitoring.
  • The ability to spot risky configuration changes and deviations from service best practices.
  • Stale identity removal.

Establish procedures to demonstrate that data is handled responsibly.

CISOs should establish procedures and reporting that can help them demonstrate to stakeholders and board members that data is being classified and handled appropriately.

They need to prove that:

  • Sensitive data is labeled correctly.
  • Users can have access granted or revoked as appropriate.
  • The data lifecycle is being managed.
  • Unauthorized or suspicious activity is flagged and dealt with at speed.

Reports should be able to be generated as needed to provide updates to stakeholders, and enable their organization to make smarter, faster decisions about their data security.

Maximize the value of the tools and technology.

Having best-in-class tools and technology won’t make any difference to your security unless there’s widespread adoption and usage.

Adopting powerful data security solutions within a single, user-friendly platform, which ensures optimal adoption with little to no learning curve is imperative.

The views expressed in this content are solely those of the author and do not necessarily reflect the opinion, belief, or position of The Cyber Express. The author’s views are presented for informational and discussion purposes only. Readers are encouraged to form their own opinions and make their own informed decisions based on a variety of sources and perspectives.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Tags: CISOCISO action planCISO first 90 days
Previous Post

The Cybersecurity Risks of Smart Home Devices

Next Post

Fraud Alert: Students at Risk of Deceptive Free Laptop Scam

Editorial

Editorial

The Cyber Express is a publication that aims to provide the latest news and analysis about the information security industry. The news comes from a variety of sources and is updated regularly so that readers can stay up to date with the latest happenings in this rapidly growing field.

Related Posts

Ministry of Public Works and Housing Cyber Attack
Firewall Daily

OpIndonesia: Ministry of Public Works and Housing Faces DDoS Attack by Garnesia Team

by Vishwa Pandagle
September 18, 2023
AraĆŗjo e Policastro Advogados Breach
Firewall Daily

AraĆŗjo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

by Ashish Khaitan
September 18, 2023
TransUnion cyber attack
Data Breach News

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

by Vishwa Pandagle
September 18, 2023
Dymocks Cyber Attack
Firewall Daily

Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

by Editorial
September 18, 2023
Retool Data Breach
Data Breach News

Retool Data Breach Linked to Google Authenticator Vulnerability

by Ashish Khaitan
September 18, 2023
Next Post
Free Laptop Scam

Fraud Alert: Students at Risk of Deceptive Free Laptop Scam

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

AraĆŗjo e Policastro Advogados Breach
Firewall Daily

AraĆŗjo e Policastro Advogados Breach Claimed by 8BASE Ransomware Group

September 18, 2023
TransUnion cyber attack
Data Breach News

USDoD Quits RansomedVC a Week After Joining, Leaks TransUnion Data

September 18, 2023
Dymocks Cyber Attack
Firewall Daily

Dymocks Cyber Attack: Over 1 Million Customer Records Exposed on Dark Web

September 18, 2023
Retool Data Breach
Data Breach News

Retool Data Breach Linked to Google Authenticator Vulnerability

September 18, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber ExpressĀ  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco,Ā Atlanta,Ā Rome,
Dubai,Ā Mumbai,Ā Bangalore, Hyderabad, Ā Singapore,Ā Jakarta,Ā Sydney, andĀ Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

Ā© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    • Ā Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

Ā© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance