CISO
"Industry has gotten good at identifying vulnerabilities in the supply chain; SBOMs and so on [but not at] at insidious backdoors and logic issues that are built into software, and update mechanisms that could cause implants..."
"You have to be intentional about designing for real people who are not security experts."
"We operate with the assumption that a sophisticated nation state threat actor is always active inside the organisation"
'Do not state anything that is subjective and avoid adjectives (e.g., "state of the art," "mature," "advanced," "appropriate," "comprehensive," or "reasonable")' say experts.
Concern at IAM vendor Okta's response mounts as BeyondTrust details concerns, Cloudflare calls for customers to press harder on "further information regarding potential impact to your organization"
"We’re seeing CISOs getting elevated in the business, taking on a larger scope and being exposed to increased liability."
Multinational's Global CISO touts critical work being done by the OpenSSF and tools like its Security Scorecard...