cybersecurity

BlackLine CISO Jill Knesek on Building Security Teams

Jill Knesek, BlackLine's CISO, discusses her experience in cyber threat mitigation and building security teams. She emphasizes a structured cybersecurity team with governance, risk, compliance, application security, and operations units. Knesek prioritizes soft skills and cultural fit in hires, alongside technical training. Effective communication with executives using risk management language and transparency builds trust. She identifies ransomware as a top threat, advocating strong security practices and employee training. Knesek acknowledges the potential of AI in enhancing security while remaining cautious of its risks. Her key advice is to focus on fundamental security hygiene to address the majority of attack vectors.

https://www.infosecurity-magazine.com/interviews/blackline-ciso-jill-knesek/

Zero Trust Network Access: Ending Implicit Trust in Cybersecurity

Zero Trust Network Access (ZTNA) replaces “trust but verify” with strict access controls for hybrid workforces, minimizing breaches and enhancing compliance in cloud environments. ZTNA denies implicit trust, isolates applications, restricts lateral movement, and enforces least privilege, making it essential in modern cybersecurity.

https://securityboulevard.com/2025/03/zero-trust-network-access-ending-implicit-trust-in-cybersecurity/

SolarWinds CISO Says Security Execs Are ‘nervous’ About Individual Liability for Data Breaches 

SolarWinds CISO Tim Brown highlighted growing anxiety among security executives about personal liability for data breaches, stemming from legal challenges following the company's notable cyberattack. This stress distracts CISOs from their core responsibilities, impacting their effectiveness. While individual executive liability raises concerns, some cybersecurity professionals argue it may enhance accountability. Brown emphasized the need for clearer guidelines to allow CISOs to manage cybersecurity without legal fears hindering their work.

https://cyberscoop.com/tim-brown-solarwinds-liability-cyberlawcon/

Cyber Resilience Redefined

UK Cyber Resilience Act (CRA) aims for stronger board accountability in cybersecurity, paralleling EU's NIS2. The CRA needs clearer guidelines on supply chain security, incident response, and penalties. Analysts urge proactive security strategies amid AI threats. Effective legislation should evolve with threats, incorporate stakeholder insights, and focus on business continuity and recovery post-breach. Final outcomes of the CRA could impact UK's cyber resilience and compliance landscape.

https://cybernews.com/security/c-suite-cybersecurity-breaches/

Center for Internet Security (CIS)

CIS: Non-profit focused on improving cybersecurity. Develops benchmarks, guidelines, and best practices. Offers tools like CIS Controls and CIS-CAT for effective security management. Provides resources for organizations to enhance defense against cyber threats.

CIS Benchmarks

CIS provides cybersecurity benchmarks for various platforms, aimed at helping organizations mitigate threats. These include configuration guidelines for over 25 vendor products, tools for assessing compliance, and a variety of resources like the CIS SecureSuite and webinars for implementation support. Membership benefits include access to exclusive tools and community development.

https://www.cisecurity.org/cis-benchmarks

What CISOs Need From the Board: Mutual Respect on Expectations

CISOs need mutual respect and understanding from their boards to effectively navigate cybersecurity challenges. Boards require CISOs to communicate risks clearly and ensure compliance with regulations while maintaining transparency. In turn, CISOs need strategic support, accountability, resources, and the board's involvement in shaping security culture and direction. A collaborative relationship enhances organizations' ability to address cybersecurity risks effectively.

https://www.csoonline.com/article/3829678/what-cisos-need-from-the-board-mutual-expectations-respect.html

Council Post: The Growing Cybersecurity Skills Gap: a Breach Waiting To Happen

Cybersecurity faces a severe talent shortage, risking sensitive data and systems as organizations struggle to find qualified professionals. Nearly 90% of leaders attributed breaches to this skills gap, with over 700,000 roles unfilled. Human error causes 88% of breaches, highlighting the need for effective training. To address this, companies should invest in enhanced education, role-based training, and automation. Utilizing gamified, hands-on training can engage potential talent and effectively prepare them for real-world threats, helping to bridge the skills gap and improve cybersecurity defenses.

https://www.forbes.com/councils/forbestechcouncil/2025/02/26/the-growing-cybersecurity-skills-gap-a-breach-waiting-to-happen/

Scroll to Top