Illustration: Anna Kim, Photos: Getty Images
What does it take for a CISO to successfully come out of a data breach without any dents in their reputation? One expert says it’s personal branding.
Headspace CISO Jameeka Green Aaron is a post-breach CISO. However, a quick Google search of Green Aaron—whose career spans over two decades with leadership roles at companies such as Nike and Okta—won’t immediately reveal this fact. Green Aaron told IT Brew that this is “intentional.”
“The reason that I have done that is that I want you to know that I’m a post-breach CISO,” Green Aaron said. “It means I’ve got some chops and that I can do this job really well and that I can take you through an incident and we can come out on the other side of it.”
She added that while the ability to successfully navigate a breach is often used as a “litmus test” to evaluate CISOs, that’s not the only value she brings to the table. Green Aaron has “an opinion about a myriad of subjects,” from non-human identities (think API keys and OAuth tokens) to being a Black woman in the industry—areas that have both become part of her personal brand.
“In many cases, CISOs hit the headlines when their companies have been breached,” Green Aaron said. “That’s not the only thing that you want the world to know about you, right?”
Read the rest here.—BM
|
|
In the SaaS world, data loss is inevitable. What really matters is how you get your data back.
But did you know your SaaS applications, such as Jira, Confluence, Azure DevOps, and GitHub, only protect their platform with system-wide disaster recovery?
Save engineering time and protect your user data with automatic backups and on-demand granular restores with Rewind.
Rewind can help you:
- Protect your workflows, IP, and profitability with both account-level and item-level backup coverage.
- Improve speed to recovery with on-demand restores, directly to your SaaS app in minutes.
- Meet compliance requirements faster with SOC 2, ISO 27001, and more.
Boost efficiency, save money, and cut down on wasted developer cycles when you protect your SaaS data with Rewind. Try Rewind for free today.
|
|
Jittawit.21/Getty Images
THIS IS NOT A BILL. But some bad actors are hoping you think it is.
A report from the API security platform Wallarm said fraudsters are using Docusign accounts to send invoices that appear “strikingly authentic.” Threat actors use the document-signing platform’s legitimate services to deceive users and to automate the process, according to the blog post released on November 5.
“Attackers found a way to confuse people using the basic concept of Docusign that allows you to send any documents to anyone,” Ivan Novikov, CEO at Wallarm, told IT Brew.
“It looks so real, because it is real,” he said.
The details:
- The scam used a realistic Norton Antivirus signature document, likely created by copying a genuine one, Novikov said.
- These fake invoices may include accurate pricing and additional charges, like an activation fee, according to the Wallarm report.
- The fraudster can then use an e-signed document to request payment from the organization outside of Docusign, the blog post said.
- Threat actors used the legitimate Docusign APIs to facilitate mass distribution.
2 Legit…Attackers have frequently employed legitimate services—URL shorteners, company mail servers, and popular file-sharing services, to name a few—to sneak past an organization’s security filters.
Read more here.—BH
|
|
Francis Scialabba
For some employees, failing a phishing test can feel like being on an episode of Punk’d. For others, the mistake can lead to not-so-staged consequences.
According to a recent Arctic Wolf report, more than one-third (34%) of IT and security decision-makers send phishing simulation tests at least every two weeks.
Repercussions for those who repeatedly fail these simulations vary. Some employees who miss the mark on these tests, which have garnered backlash in recent years, are offered short training sessions following their oversight. However, Joshua Crumbaugh, CEO of PhishFirewall, an AI-powered anti-phishing solution company that focuses on non-punitive phishing campaigns, told IT Brew that others face more serious penalties.
“I know of a number of our Fortune 50s that still implement what they call a three-strikes-and-you’re-out policy,” Crumbaugh said. “All that means is you fail three phishing tests and you get fired.”
Silverfort CISO John Paul Cunningham told us that he has seen other extreme examples of corrective action, such as requiring an entire department to take remedial training if a repeat offender fails or that the consistent failure has a one-on-one conversation with their company’s CISO or CEO.
Keep reading here.—BM
|
|
IT + business = BFFs. Okay, so maybe this equation isn’t always the reality. Silos between business and IT teams often cause delays, missed opportunities, and inefficiencies. That’s why Camunda’s guide explains how your organization can overcome common obstacles between these teams to foster stronger IT + business collabs. Get your copy. |
|
Francis Scialabba
Today’s top IT reads.
Stat: 4%. That’s how much of global headcount Advanced Micro Devices is cutting in layoffs. (the Wall Street Journal)
Quote: “City of Sheboygan employees with internet access can communicate with each other online as all cloud-based services are up and working.”—officials in Sheboygan, Wisconsin, on the extent of a ransomware hack that affected municipal services (The Record)
Read: A generative AI-built video game is weird—but fun. (Wired)
Beef up your security: If you don’t have a next-generation firewall (NGFW)—or don’t optimize the one you have—you’re missing an opportunity to increase your network security. Watch this webinar to learn why an NGFW matters.* *A message from our sponsor.
|
|
Break free from the job-board cycle. CollabWORK connects you with relevant job openings curated specifically for communities you’re already part of—like IT Brew. Find high-quality opportunities and land your next big break by joining CollabWORK today.
|
|
Share IT Brew with your coworkers, acquire free Brew swag, and then make new friends as a result of your fresh Brew swag.
We’re saying we’ll give you free stuff and more friends if you share a link. One link.
Your referral count: 2
Click to Share
Or copy & paste your referral link to others: itbrew.com/r/?kid=9ec4d467
|
|
ADVERTISE
//
CAREERS
//
SHOP
//
FAQ
Update your email preferences or unsubscribe
.
View our privacy policy
.
Copyright ©
2024
Morning Brew. All rights reserved.
22 W 19th St, 4th Floor, New York, NY 10011
|
|