Evo Cyber Security #45 - Building a Culture of Security - From Awareness to Action
Aug 12, 2023
auto_awesome
Join host James Price as he discusses building a culture of security with David Kosorok, Sri Pulla, and Bruce Neuwirth. They emphasize the importance of education, communication, security champion programs, and mentorship. They also discuss ways to get involved in cybersecurity and opportunities in Boston area.
Building a security champion program is crucial for expanding security influence and mentoring potential security experts outside of the field.
The involvement of different teams, both technical and non-technical, in a security champions program fosters a shared responsibility and understanding of security beyond just technical roles.
Deep dives
Building a Robust Security Champion Program
Building a security champion program is seen as a necessity in order to expand security influence outside of engineering. The panel discusses the importance of leveraging influence by developing strong mentorship programs and adhering to security habits. They highlight the need to bring others into the security profession and spend regular blocks of time mentoring potential security experts. The goal is to help them gain education and experience and make a positive impact in the industry.
Identifying and Nurturing Security Talent
The panel shares examples of how organizations have successfully identified talent outside of the security field and mentored them to join the security profession. They discuss the effectiveness of running internal Capture the Flag (CTF) challenges where non-security employees can participate. By identifying top performers and offering mentorship and training, these individuals were able to transition into security roles, resulting in successful career growth. Encouraging interest and providing a clear path for progression fosters talent acquisition and development.
Engaging Different Teams in the Security Champions Program
The importance of involving different teams, both technical and non-technical, in a security champions program is emphasized. The panel highlights the benefits of building trust and communication between security and various departments by providing training, education, and incentives. They discuss the value of creating a sense of community through rewards and gamification, enabling everyone to be a part of the security culture. Inclusion of different teams fosters a shared responsibility and understanding of security beyond just technical roles.
Creating an Effective Security Awareness Program
The panel explores key factors and criteria for building an effective security awareness program. They discuss the importance of avoiding dry, lengthy training sessions and instead utilizing engaging approaches such as humor, storytelling, and gamification. By making training more personalized and relevant, there is increased awareness and understanding among employees. Feedback and assessment of the training program are also essential for measuring its impact and continuously improving it.
Join host James Price on the latest episode of Evo Cyber Security as he explores the critical topic of "Building a Culture of Security - From Awareness to Action." In this enlightening conversation, David Kosorok, Director of Application Security at Toast, Sri Pulla, Director of Application Security at Cloudflare, and Bruce Neuwirth, Manager of Application Security at Cengage Group, share invaluable insights. Dive into their expertise and perspectives on fostering a security-conscious environment. A must-listen for anyone seeking to enhance their understanding of cybersecurity culture and its practical implementation.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode