Quickbase’s Rebecca Harness: Securely engaging with technology partners and third-party vendors and overcoming the inevitability of human error
Aug 15, 2023
auto_awesome
Rebecca Harness, VP and CISO at Quickbase, discusses her career journey and building a strong security culture. She explores securely engaging with partners and vendors, combating human error with automation, and the evolving SecOps landscape. Rebecca also highlights the potential of generative AI in collaborating with SecOps teams.
Building a strong security culture involves emphasizing transparency, open communication, and partnerships with external vendors.
Automation and AI are crucial tools for enhancing efficiency, minimizing human errors, and improving incident response capabilities in security operations.
Deep dives
Building a Strong Security Operations Team with Rebecca Harness
Rebecca Harness, VP and Chief Information Security Officer at Quickbase, shares her journey in the security field and the importance of building a strong security operations team. Harness emphasizes the need to focus on individuals' interests and provide opportunities for growth and training. She highlights the significance of leading with transparency, fostering a culture of open communication, and building strong partnerships with external vendors. Harness also discusses the evolution of security operations, including the increasing role of automation and the potential of AI in the future. She emphasizes the need to prioritize targeted attacks, improve secure configurations, and leverage external resources to enhance organizational security.
The Role of Culture in Information Security
Harness discusses the importance of culture in information security. She emphasizes that culture is a crucial aspect of creating a secure and resilient organization. Harness highlights the significance of understanding diversity within departments and ensuring that security is a collective responsibility. She explains how Quickbase focuses on educating employees about security best practices, explaining the why behind each action, and providing continuous security awareness training. Harness emphasizes the need to be empathetic in approach and to establish partnerships that promote a security-conscious culture throughout the organization.
Managing Third-Party Risk in Security Operations
Harness discusses the challenges of managing third-party risk in security operations. She emphasizes the importance of understanding the internal owner of third-party relationships and ensuring accountability. Harness highlights the need to assess the risk associated with vendors and suppliers, including their access to sensitive data and systems. She emphasizes the value of building collaborative relationships with third parties and assessing their compliance with relevant security standards. Harness also discusses the significance of continuous risk management and the need to go beyond compliance to ensure robust security.
The Future of Security Operations and Automation
Harness shares her insights on the future of security operations, emphasizing the increasing role of automation. She highlights the benefits of automation in enhancing efficiency and effectiveness in security operations. Harness discusses the potential of AI as the next evolution in security operations. She also discusses the importance of focusing on targeted attacks and continuously improving security configurations. Harness envisions security operations teams evolving to become more focused on threat hunting and proactive defense, while leveraging automation tools to minimize human errors and improve incident response capabilities.
In this episode of The Future of Security Operations podcast, Thomas chats with Rebecca Harness, VP and Chief Information Security Officer at Quickbase. Quickbase is a no-code database and application development platform that enables anyone to safely build, iterate, and integrate their applications.
Rebecca has 25 years of experience in information technology and over 12 years of experience in security specifically. Over her career, Rebecca has launched two of her own companies; she’s led numerous high-performing cybersecurity teams through the challenges of supporting cloud-first digital transformation strategies; and she’s a board member of ISACA St. Louis. She also has a Master of Science in Information Security Engineering.
Topics include:
Rebecca’s career journey from her start in IT to founding her first company, to becoming VP and CISO at Quickbase.
The steps Rebecca takes to build a strong security culture within her teams.
Balancing empathy and velocity as a CISO.
The measures Rebecca feels best place SecOps teams to securely and safely engage with technology partners and third-party vendors.
The inevitability of human error and how automation can help combat this.
How Rebecca has seen SecOps evolve and the resource and skills gap being experienced across the industry and how this can be combated.
How generative AI can be a key collaborator for SecOps teams.
Where Rebecca sees the SecOps landscape going over the next five years.
Rebecca’s experience in the MSP space and how she feels MSPs will be affected by attacks becoming less commodified and more targeted.
The measures Rebecca takes to ensure her teams don’t burn out and remain passionate about their role.