As Long as We Keep Moving the Goalposts, We Have a Great Security Culture (LIVE in Dallas, TX)
Jan 28, 2025
auto_awesome
Lamont Orange, CISO at Cyera and expert in data security, discusses key themes from a live conference in Dallas. He emphasizes the shift from a zero-incident mindset to building resilience in cybersecurity. The conversation highlights the importance of AI and automation in data security, and addresses the balance between security, integrity, and availability. Lamont also engages in lively debates on integrated platforms versus niche solutions, urging for better integration in response to evolving threats while promoting curiosity and innovation in the field.
A resilient cybersecurity culture emphasizes continuous improvement and crisis management, requiring collaboration across legal and communication teams for effective planning.
Data Security Posture Management (DSPM) is essential for improving data visibility and automating risk assessment, highlighting the importance of knowing data storage locations.
Deep dives
The Importance of Resilience in Cybersecurity
Emphasizing resilience in cybersecurity involves accepting the inevitability of breaches and focusing on minimizing their impact. Security professionals now prioritize continuous improvement of defenses, as well as integrating crisis management across various business functions. This shift requires a collaborative effort involving legal teams and communication departments to ensure effective crisis planning and testing. Security leaders are urged to think beyond traditional recovery methods and instead foster a culture that maintains business operations during incidents.
Data Security Posture Management (DSPM) Insights
DSPM is gaining attention as a critical framework for managing data security, aiming to enhance data discovery and classification. Notably, many security professionals remain unaware of their data's storage locations, highlighting significant implications for privacy and compliance. The introduction of DSPM technologies seeks to address these challenges by automating data visibility and risk assessment. Additionally, the integration of AI within DSPM solutions is believed to streamline processes and improve data security management.
Building a Security Culture
The evolution towards a positive security culture emphasizes collaboration and transparency between cybersecurity teams and employees. It is essential for security professionals to create platforms for self-reporting mistakes, enabling employees to feel comfortable addressing security concerns. By fostering champions across business units, organizations can build a culture where security is viewed as a partner rather than an adversary. Furthermore, regular communication and feedback loops can reinforce this culture, leading to a more resilient and engaged workforce.
Balancing Security and Usability
Achieving a balance between security measures and user experience is crucial for successful implementation. While some friction in security procedures is necessary, the goal should be to make security as invisible as possible to users. Innovations like YubiKeys exemplify how organizations can introduce usable security solutions that reduce user burden while maintaining strong protections. By focusing on the 'why' behind security policies and demonstrating their benefits, security teams can cultivate a more receptive environment towards necessary changes.
This episode was recorded in front of a live audience at Cyera’s first DataSec conference (November 2024) in Dallas. Thanks to Adam Holland, CISO, Wendy's, Farray Rahman of Vibrant Emotional Health and 988 Lifeline, and Biji John of USAA for our questions in the episode.
In this episode:
Shifting from traditional recovery
Do you know where your data is?
The science of tradeoffs
How do you measure security culture?
Thanks to our podcast sponsor, Cyera!
Cyera’s data security platform discovers your data attack surface, protects sensitive data, governs data access, monitors critical data events, and quickly responds to data risks. Cyera’s agentless design allows us to deploy within minutes across any environment and provide a 95% precision rate through our AI-powered classification engine. Learn more at Cyera.io
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode