How to assess your organization's security maturity
Jun 13, 2024
auto_awesome
Diana, Lisa, and Robin discuss their security maturity model, focusing on shifting security conversations to business terms. They explore the benefits of the model, leadership engagement, and cross-country collaboration. The podcast emphasizes the importance of empowering organizations to address security threats through open communication and continuous improvement.
Implementing a security maturity model fosters a strong security culture within organizations.
The Security Maturity Model shifts security conversations towards a business-centric perspective empowering leaders in decision-making.
Deep dives
Evolution of the Business Security Maturity Model
The podcast delves into the development of the Business Security Maturity Model by Diana, Lisa, and Robin, highlighting the journey from its inception to its prestigious recognition as winners of the CSO 50 award. Robin describes the dimensions and sub-dimensions comprising the model, emphasizing its focus on fostering a strong security culture. The team's shift towards visualizing the model to aid comprehension among business leaders resulted in more effective communication and strategic planning across global business units.
Value and Impact of the Security Maturity Model
The podcast discusses the significance and value of the Security Maturity Model, as articulated by Lisa. The model's innovative approach at the nexus of business and security, aligning strategic focus and risk management, emerges as a key driver for its recognition. Lisa underscores the model's capacity to shift security conversations towards a business-centric perspective, emphasizing the empowerment of business leaders in making informed security decisions and fostering a more comprehensive security culture.
Motivation and Design Evolution of the Model
The podcast explores the motivations behind the Business Security Maturity Model's creation and its evolution over time. Diana shares insights into the model's evolution, reflecting on the initial challenges of complexity and the subsequent shift towards a more user-friendly conversational framework. The team's collaborative approach and adaptability in design led to an improved model structure that facilitated effective communication and progress tracking for business units.
Global Adoption and Adaptation of the Model
The podcast reveals how the Business Security Maturity Model was adopted and adapted across global business units, surpassing initial expectations. Robin discusses the diverse implementation approaches undertaken by regions, showcasing the model's flexibility and capacity to evolve organically. The model's transition from a rigid assessment format to a more collaborative workshop partnership indicated a shift towards tailored and effective security planning strategies across different organizational contexts.
One of the fundamentals of security is self-awareness: knowing where you may be vulnerable, the practices and processes that aren't yet quite in place and what actions you need to prioritize are essential if your organization is to excel at security. But how can that be done? In complex and distributed teams, surfacing such knowledge can be incredibly difficult. One solution, though, is something called a security maturity model.
In this episode of the Thoughtworks Technology Podcast, Thoughtworks alumnus Diana Adorno and current Thoughtworkers Lisa Junger and Robin Doherty speak to host Alexey Boas about a security maturity model they've developed that was recognized by the prestigious CSO50 Awards. They explain the purpose of developing and using one, how theirs works and why it should matter to any organization that wants to get serious about the way it does security.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode