Slow Down and LEAD…So That You Can MANAGE

By Eric Noonan • January 14, 2013

…that’s my advice for managers and CISO’s who find themselves on the hamster wheel of incident response and day to day operations. It’s easy to get locked into a permanent schedule of daily meetings punctuated by operational crisis and mistakenly believe that security is different from anything else in your business and can’t be managed. Of course, it can, but like anything worth doing (dieting and exercise come to mind), it’s hard and results take time to materialize. To do it you have to lead so that you can manage.

CISO’s have to set the strategic direction for the organization and define success criteria that can be measured and shared with the business. One way to change the pace of your organization from frantic to controlled chaos, with a goal of getting to the point where you manage security like a business unit, is to define and implement a process for collecting, analyzing and reporting metrics. Take an incident response as an example:

How many incidents did you have this month?

Where were they (geography)?

What business units were impacted the most?

Did you lose any data?

On average how long did it take you to remediate an incident?

Is that better or worse than last month? Why?

By collecting and analyzing the data you force the organization to slow down and start analyzing what’s working and what’s not. Which tools are performing the best? Which business units need more focused attention because they are more often targeted? Is the peanut butter spread approach to security working or does it make sense to better focus your resources? If you are not taking the time to collect and analyze the data you will never know.

If you don’t lead, you will never be able to manage.

CyberSheath Blog

CyberSheath Opens Registration For CMMC CON 2022

RESTON, Va. — June 8, 2022 — Federal contractors have been searching for direction after seeing a flood of messaging about the future of Cybersecurity Maturity Model Certification (CMMC). The nation’s largest CMMC conference has returned to help contractors navigate their course through the evolving compliance landscape.   Hosted by…

5 Reasons to Partner with CyberSheath

The threat landscape is only becoming more complex. Offload the responsibility of navigating cybersecurity issues for your customers by taking advantage of CyberSheath’s new Partner Program.   As a pioneer and industry leader in the managed security service provider space, our new offering helps you achieve rapid results and deliver…

CMMC Compliance Training: How to Earn Your Black Belt

Contractors in the Defense Industrial Base (DIB) are looking for direction as Cybersecurity Maturity Model Certification (CMMC) 2.0 nears. Compliance with CMMC and Defense Federal Acquisition Regulation Supplement (DFARS) is your key to doing business with the Department of Defense (DoD) and we can help you navigate those requirements and…

Our Trusted Partners

Tenable Microsoft Siemplify KnowBe4 ConnectWise DUO

CMMC CON 2022 is here! Save your spot to hear the latest on CMMC from our expert speakers across the government and Defense Industrial Base.