What are organizations lacking in their cybersecurity posture?

768 views1 Upvote3 Comments
Sort By:
Founder/Chairman/CTO in Telecommunication2 years ago
I view cybersecurity as an 80/20 problem overall. 80% of it is hygiene and things that we've seen before — things that we can automate, in cases where automation is a viable and economic solution. It’s within the remaining 20% that the bad stuff happens. So how do you address both at the same time? It's always been interesting to have this conversation in the context of Bugcrowd, because people assume that I'm all about humans coming in to solve everything. But that's not true.

There's always going to be a gap that's created by the innovation of the adversary, which only has human creativity and human adoption of process as its solution. But you should automate wherever you can. The companies that we work for weren't started just to fight Russia or China, so this is not our main game.
SVP in Finance (non-banking)2 years ago
I refer to my approach as brilliance and basics, and the latter is what's lacking. There are hundreds of NIST and CIS recommendations out there. But the reality is, you only need 20 basic things. If everyone did those 20 basic things, they would be way ahead of where they are today. The general challenge that I find is that people get caught in the minutiae of all the other recommendations without realizing that they haven't even locked the doors or closed the windows.
1 Reply
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Founder/Chairman/CTO in Telecommunication2 years ago

Exactly. It’s simple hygiene, just like making sure you wash your hands after you use the restroom.

Content you might like

Yes - one person46%

Yes - multiple people46%


View Results
VP of IT in Retail3 days ago
My previous organization implemented a strict one-strike policy for lost or damaged devices. While the first incident was considered an accident, repeat offenders were required to reimburse the company for the lost or damaged ...read more
82 views1 Comment
IT Manager in Constructiona month ago
the topic is so broad, what are you focused on?
Read More Comments
4.8k views2 Upvotes5 Comments

Implementation complete23%

Implementation in progress54%

Planned within the next 12 months12%

Not planned7%

Not enabling O365 on mobile2%

View Results
2.4k views2 Upvotes