MichaelPeters.org

  • CRM
  • PMP
  • 0
  • 1
  • 2

MichaelPeters.org - Your Personal CXO, LLC

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

Buyer Beware

0

By Michael Peters on November 24th, 2012

Fact:

Companies are being breached seemingly at-will by hackers, malicious insiders, competing company entities, and nation states. Companies and consumers seem to be losing the battle.

Sources of this problem are:

  • 83 percent of organizations have no formal cyber security plan. (Source: National Cyber Security Alliance, 2012)
  • Thousands of breaches have occurred over the last 12 months. (Source: US Secret Service, 2012)
  • 48% of breaches were caused by insiders, which means employees and trusted business partners. (Source: US Secret Service, 2012)
  • 96% of breaches were avoidable through simple or intermediate controls. (Source: US Secret Service, 2012)
  • The average organizational cost of a data breach increased to $7.2 million and cost companies an average of $214 per compromised record. (Source: Ponemon Institute, 2011)
  • 67% of security professionals are unqualified to do the job. (HP Cyber-security study, 2012)

The corporation is in jeopardy with a successful breach from financial, brand and reputation damage; at times permanently. A company that does not take security seriously in our globally connected market will suffer; if not go out of business.

What advice is there for companies seeking to hire a Chief Information Security Officer or other information security professional that may increase their success and decrease their risks?

Solution:

Hire the security executive with verifiable credentials, recognition and industry impact. To name a few points of verifiable interest, look for the following:

  • Has that candidate earned any accredited academic degrees?
    • While a degree does not make-or-break a security professional, you should want your security executive to have great business and professional skills comparable to other executives so look for candidates with graduate degrees.
  • Does that candidate have current industry certifications that are appropriate for security?
    • It is pretty standard for security executives to have security certifications. Make sure they are still current and have not expired.
  • Is that candidate internationally recognized by the industry as an expert?
    • Organizations such as the Information Systems Security Association (ISSA), an international organization devoted to security award just a small percentage of security practitioners with the Hall of Fame, Distinguished Fellow, Fellow, and Security Person of the Year. Look for these and other reputable forms of recognition to help identify the best-of-the-best.
  • Is that candidate sought after for keynote speaking or other presentations for industry events?
  • Does that candidate have a verifiable track record of affecting business change?
    • You want a security and risk executive who can speak the same language as your other core group of business executives. Look for examples of how this has been accomplished. Don’t overlook published works that illustrate this potential.

Stay secure my friends!

If you are interested in contacting us for more information about the content and services offered by Your Personal CXO, LLC or for media interview inquiries or aggregation requests, please use the following contact methods:

By phone: 1-762-822-4174
By email: retainme@yourpersonalcxo.com

Share this:

  • Email
  • Print
  • Digg
  • Google +1
  • LinkedIn
  • Twitter
  • Tumblr
  • Pinterest
  • Reddit
  • StumbleUpon
  • Facebook
  • CXO, Your Personal CISO
  • Search

  • Your Personal CXO

  • The Security Trifecta

    Hire the experts to implement The Security Trifecta in your organization. Click for more information!

  • Louisville Metro InfoSec

    The Louisville Metro InfoSec is the premier ISSA information security conference!

  • External Services

  • Thousands of other great people can't be wrong! Enter your email address to subscribe to this blog. -

  • Affiliates

  • RSS SBN RSS

    • Microsoft Bounty Program: Katie Moussouris at FIRST
    • Do SOC2 Audits Even Matter?
    • Security Slice: Do You Know Where Your Contractors Are?
    • Microsoft Bug Bounties – Podcast interview with Katie Moussoris
    • SBN Sponsor Post
  • RSS The Register

    • That Microsoft-Nokia merger you've been predicting? It's no go
    • Microsoft caves on Xbox One DRM and used-game controls
    • Kim Dotcom victim of 'largest data MASSACRE in history'
    • Google preps wave of machine learning apps
    • Reg to Australia: Here's your chance to find NBN answers
  • Categories

    • Books
    • CXO
    • Featured
    • HORSE Project
    • HORSE Project V1
    • Kickback Cafe
    • Law
    • Lazarus Alliance
    • Life Learner
    • Obsolescence
    • Projects
    • Remember
    • Securing the C Level
    • Syndication
    • The Security Trifecta
    • Uncategorized
    • Your Personal CISO
  • Archives

    • March 2013
    • February 2013
    • January 2013
    • December 2012
    • November 2012
    • October 2012
    • September 2012
    • August 2012
    • July 2012
    • June 2012
    • May 2012
    • April 2012
    • March 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011
    • January 2011
    • December 2010
    • November 2010
    • September 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • May 2008
    • April 2008
    • January 2008
    • December 2007
    • July 2007
    • June 2007
    • May 2007
  • Get the app!

    Your Personal CXO now on Android!

  • Get the app!

    The HORSE Project now on Android!

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

More on Your Personal CXO, LLC

  • EXTERNAL

    • AppHappening
    • CheckSavvy
    • Dynamic Clinical Systems
    • eLance
    • HORSE Project
    • Maprehend
    • Quest for Tech
  • Meta

    • Register
    • Log in
    • Entries RSS
  • Recent Posts

    • The Policy Machine
    • Top 1% Most Viewed LinkedIn Profile
    • Reasonable Duty of Care: Data Security and Privacy
    • Security Overlooked: Weathering the DDoS Storm
    • Please Vote for this blog!
  • Top Links

    • clouds (70)
    • No Title Given (57)
    • mba-mdp (47)
    • site (30)
    • peters-wgu-sbit-infosec (25)
    • CISSP-MDP-2013 (23)
    • An Introduction (21)
    • http://michaelpeters.org/?page_id=336 (21)
    • LinkedIn.com (19)
    • CMBA-MichaelPeters-2007 (17)

Copyright © 2013 MichaelPeters.org - MICHAELPETERS.ORG - Your Personal CXO, LLC

 
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.