معلومات عن هذه الحلقة
What should we be focusing on? It’s an essential question for all of us… but for those in the cybersecurity game, it’s critical. Focusing on the wrong things here can be *costly.* Or so says Neatsun Ziv, Co-Founder and CEO of OX Security, in this *#CybersecurityByDesign* conversation with Sam Rehman, EPAM’s CISO and SVP.
Ziv says that, when it comes to fixing code, “95% of the things” that organizations work on have “zero risk impact,” adding: “That is an insane amount of money that the organization should have spent creating a bigger gap between them and the competitors.”
Managing risk is indeed a major challenge for contemporary organizations. “There's no such thing as one single application anymore,” says Rehman, who wonders: “How do you manage the inherent risk from all these components?”
Ziv says the answer is about getting clients to focus on what’s critical to them. There’s a need to distinguish between vulnerability, theoretical risk and actual practical risk. What is a practical risk? It means getting clients to recognize, as an organization: “This is what I'm concerned about.”
“I always tell people the risk is managed,” adds Rehman, who says that approach is underpinned by asking questions such as “What's your security posture?” and assessing a client’s risk tolerance.
“You need to be smart about the investment,” says Ziv. He notes that this is where experienced leaders become practical. He gets them to answer questions like: What's exposed? What's internal? What do you want to replace first? How do we do it?
Ultimately, he says, it’s getting clients to be mature enough to say that they’d focus on the “5% [of efforts] that would actually make a difference in the first year or the second year.” The trick is taking a balanced approach, and the guys bring the idea of balance into the realms of supply chain and open source.
We leave you with a warning: Listening might have a serious impact on your own security posture. Click play now!
Host: Kenji Ross
Engineer: Kyp Pilalas
Producer: Ken Gordon
Ziv says that, when it comes to fixing code, “95% of the things” that organizations work on have “zero risk impact,” adding: “That is an insane amount of money that the organization should have spent creating a bigger gap between them and the competitors.”
Managing risk is indeed a major challenge for contemporary organizations. “There's no such thing as one single application anymore,” says Rehman, who wonders: “How do you manage the inherent risk from all these components?”
Ziv says the answer is about getting clients to focus on what’s critical to them. There’s a need to distinguish between vulnerability, theoretical risk and actual practical risk. What is a practical risk? It means getting clients to recognize, as an organization: “This is what I'm concerned about.”
“I always tell people the risk is managed,” adds Rehman, who says that approach is underpinned by asking questions such as “What's your security posture?” and assessing a client’s risk tolerance.
“You need to be smart about the investment,” says Ziv. He notes that this is where experienced leaders become practical. He gets them to answer questions like: What's exposed? What's internal? What do you want to replace first? How do we do it?
Ultimately, he says, it’s getting clients to be mature enough to say that they’d focus on the “5% [of efforts] that would actually make a difference in the first year or the second year.” The trick is taking a balanced approach, and the guys bring the idea of balance into the realms of supply chain and open source.
We leave you with a warning: Listening might have a serious impact on your own security posture. Click play now!
Host: Kenji Ross
Engineer: Kyp Pilalas
Producer: Ken Gordon
الإنجليزية
الولايات المتحدة
النص 🔗
Are you the producer of this podcast?
Add a podcast transcript
Need Audio-to-Text?
Transcribe with Listen411 in Just 60 Seconds
البحث في الحلقات الماضية
البحث في الحلقات السابقة من The EPAM Continuum Podcast Network.
حلقات أخرى في هذا البودكاست
“Can we use generative AI in a way that teaches us something that we might not have known otherwise, and in that learning… create something that actually has the potential to increase agency for all inside of the system?”
Good question, Angela Stockman! It is, in fact, one of many good questions t…
What does the phrase “aquatic corporate community” mean to you? A school of fish in business suits holding an underwater meeting around a table of coral? Well, for our guests on the latest episode of *The Resonance Test,* it’s all about plunging into a strategic social responsibility program called…
How are CISOs holding up in the era of AI?
According to Tim Ramsay, Managing Director of Mandiant Client Advisory (now part of Google Cloud), and our guest on *Silo Busting*: “You have a number of parts of the organization that may be embracing AI without any involvement from central IT, and more…
“If you want to know the future, look at the past.” While no one in their right mind would claim Einstein was giving any thought whatsoever to the future of the financial services industry, history would have once again proven him right if he had. Once upon a time, one’s choice of bank was based on…
إخلاء المسؤولية: البودكاست والأعمال الفنية المضمنة في هذه الصفحة مأخوذة من EPAM Continuum، وهي مملوكة لمالكها وليست تابعة لشركة Listen Notes, Inc أو معتمدة منها.
تعديل
شكراً على مساعدتنا في الحفاظ على قاعدة بيانات البودكاست مُحدَّثة.