AI-powered
podcast player
Listen to all your favourite podcasts with AI-powered features
Howdy, y’all, and welcome to The Cyber Ranch Podcast! That’s Tim Rohrbaugh, Founder/Principal at DefaultDenySec, former CISO for JetBlue Airways, advisor, investor: yup! Another Cyber Ranch guest with an awesome history! Tim and Allan were chatting a while back about budgeting cybersecurity programs, and they found out that they disagreed on a rather key point. In true Cyber Ranch fashion, Allan immediately asked Tim to come back to the show and to dig into the issue with him. They are starting with disagreement, which always makes for a better show...
NOTE: Allan is cheating here with this simplification. Run rate matters. Our existing tech stack is already in play before we address specific risks. So there is accretion there that must be acknowledged. And the question is also begged: How much does the already established run rate actually tackle specific risks vs. broad strokes? EDR, for example, should already be present. Do we say that EDR addresses the ransomware risk or the data leakage risk of HR data or the data theft risk of customer data, and/or… You get the point. Allan's model is not perfect. But what Allan has ALWAYS stood against is the idea that the cyber budget should simply be expressed as percentage of revenue or percentage of IT budget or percentage of anything external to cybersecurity, really.