How to Communicate Risk to Executive Leadership

How to Communicate Risk to Executive Leadership

“I don’t get it!” said the CEO as he dropped the 300-page report on the conference table. Something was very wrong. It was 2010 and my team had just completed a large enterprise security risk assessment for a financial services company. We followed a traditional...

The Failure of the PCI-DSS?

Recent events have caused people all over the information security community to question the efficacy of the PCI-DSS. The Target breach has become a lightning rod for debate as to how well the PCI-DSS protects organizations. In a recent blog entry, Avivah Litan from...

We Are Privacy and Security Hypocrites

So, the NSA is spying on us without warrants, the Chinese are spying on us without consequences, criminals are spying on us without liability, and everybody is in an uproar over Edward Snowden leaking data.  2013 was a watershed year for information security and...