惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
罗磊的独立博客
The GitHub Blog
The GitHub Blog
L
LangChain Blog
A
About on SuperTechFans
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
D
DataBreaches.Net
宝玉的分享
宝玉的分享
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
N
Netflix TechBlog - Medium
The Cloudflare Blog
Microsoft Azure Blog
Microsoft Azure Blog
H
Help Net Security
美团技术团队
大猫的无限游戏
大猫的无限游戏
雷峰网
雷峰网
爱范儿
爱范儿
酷 壳 – CoolShell
酷 壳 – CoolShell
MongoDB | Blog
MongoDB | Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
CISOs share their top 7 strategies for gaining C-Suite bu...
Wiz Team · 2024-03-08 · via Wiz Blog | RSS feed

Wiz recently had the privilege of hosting three insightful CISOs for the most recent episode of our monthly CISO webinar series: Adam Fletcher, Chief Security Officer at Blackstone; Carla Sweeney, Security Team Lead at Red Ventures, and Jeff Farinich, the SVP of IT and CISO at New American Funding. They shared insights on aligning priorities with the board and how the dynamics of collaboration changes the game. We share some of the key takeaways below.  

  1. Speak the C-Suite language. A CISO's role has always been to balance business needs with security needs. Panelists stressed the need for CISOs to align their own priorities with those of C-suite executives. Both Fletcher and Sweeney emphasized the need to articulate risk in business terms that outline potential financial and regulatory impacts, they agreed that it’s best practice to trade technical jargon for language that C-suite executives understand. 

  2. Focus on governance versus control. Carla Sweeney shares that at Red Ventures they organize security efforts among a wider group of stakeholders. Jeff Farinich of New American Funding added that his security team also works closely with developers, which creates “flexibility for enablement, but also governance.” Among all the panelists, having the right relationships in place across teams was a high priority to effectively execute their programs. 

  3. Don’t assume legal liability. Make a clear distinction between security professionals owning risks versus identifying and surfacing risks. “It’s very important that we work closely with the board leadership to understand that we’re not the only ones who are at risk. It’s also them; it is a partnership. But as of now the CISO are kind of the fall guys, and we’ve gotta change that,” Jeff Farinich explained. 

  4. Establish strong relationships with stakeholders. Sweeney explained the delicate balance of keeping stakeholders informed while also securing sensitive information in case of a potential breach. She recommended having strong relationships across security, privacy, legal, and communications teams to do this successfully. 

  5. Understand the regulatory environment. When disclosing information on a potential breach, Farinich highlighted the need to accurately communicate with an organization’s board about technical risks and real-world implications, alongside keeping abreast with the ever-evolving regulatory terrain commanded by the SEC. 

  6. Throw out benchmarks and set your own goals. Achieving objectives should take precedence over relying on benchmarks or expense metrics. Fletcher cited Phil Venables' thoughts on the potential pitfalls of benchmarking, emphasizing the importance of setting individual security goals. He succinctly concluded: "run your own security program." 

  7. Be a team player. The CISO's role is no longer confined to the realms of the IT department. Rather, CISO have emerged as strategic teammates who work with C-suite executives. To garner C-suite buy-in for prioritizing cloud security, CISOs must provide a clear understanding of the organization’s cloud environments and identify critical assets at risk. 

Driving C-suite buy-in requires a combination of thought leadership, awareness building, effective communication, and setting common objectives. Our panelists put the focus on the importance of setting up good governance, assessing risk tolerance, and building robust relationships across all organization levels. They also emphasized the need to streamline processes so your teams can address vulnerabilities quickly and continuously monitor controls for quick interventions. 

Watch the webinar for more valuable insights!