

We All Agree That Prevention Is the Best Advice We're Never Going to Follow
Sep 9, 2025
In this discussion, Jason Loomis, CISO at Freshworks and expert in IT service management, sheds light on the crucial yet often ignored topic of preventative cybersecurity measures. He emphasizes the cultural buy-in needed for effective security practices within organizations. The conversation also touches on the isolation CISOs face and the importance of peer support in navigating stress. Additionally, they explore the complexities of cybersecurity decisions and the future implications of quantum encryption, all delivered with a good dose of humor.
AI Snips
Chapters
Transcript
Episode notes
Sell Prevention With Stories
- Tell executives why a preventative control matters in business terms, not just technical terms.
- Use storytelling to turn security projects into demanded priorities for the company.
Shift Prevention Left
- Focus preventative controls on new systems and shift security left during development.
- Measure and tell the story of saved developer time and business impact after deployment.
Praise The Implementers
- Give credit to the teams that implemented controls, not just security leadership.
- Public praise makes other teams want to collaborate and repeat the behavior.