CISO
CISOs are now risk managers, argues Qualys' CEO. This means prioritising what threatens the business and thinking about windows of weaponisation, as well as...
“This is among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package."
Ubuntu: "Our recommendation is that you apply both userspace mitigations and Linux kernel security updates"
"We're really aspiring to be very much a business-focused function, rather than just a risk management one..."
"Risk management is about 'how much' -- and 'how much' is about money"
Insider risk is a huge headache for CISOs. These two frameworks may help, industry leaders say.