|
|
|
|
|
by toomuchtodo
926 days ago
|
|
It potentially plugs the contractual and liability risks, which might be more important (talk to your legal and compliance folks). None of your data is going to launch nuclear missiles, if it leaks it would be unfortunate, but not as much as the litigation and regulatory costs you could potentially incur. Everyone gets popped eventually. It's your job to show you operated from a commercially reasonable security posture (and potentially your third party dependency graph, depending on regulatory and cyber insurance requirements). (i report to a CISO, and we report to a board, thoughts and opinions are my own) |
|
That sounds like an interesting role. How did you get there? Did you start as a security analyst and work your way up?