Paul Proctor

Paul Proctor
address becoming data detection enables management proactive providers risk support system systems trouble
Workflow system support by vulnerability management system providers is becoming more important as the need for proactive risk management and remediation grows, ... Integrating prioritized vulnerability and risk data with trouble ticketing systems enables enterprises to more effectively address the vulnerability management lifecycle from detection through remediation.
active associated bigger both businesses community complex dependent digital environment external greater information internet level managers risk risks social technical understand
The bigger the organization, the greater the level of external connectivity, and the more heavily IT dependent it is, the more complex the digital risk environment becomes. Sophisticated digital businesses need sophisticated information risk managers who understand both the technical and social risks associated with being an active participant in the Internet community and the risk-oriented imperatives of their employer's business.
business needs potential returns security understand
The CISO needs to be able to understand the business, and the potential returns on any security investment,
ability activity communication decision determine excellent executive good highly information knowledge lacking oral political report requiring risk security skills written
The ability to determine what constitutes risk, and the requirement to report that risk to executive decision makers, can be a highly political activity requiring excellent written and oral communication skills with a good knowledge of business. Generally, these skills have been lacking in traditional technically-oriented information security specialists,
affect bottom business operations people risks security speak talking tend unit weigh whereas
In some companies, operations and the business unit not only speak a different language, but have no way of talking about risks. Security people tend to think 'It's a risk, we can't have it,' whereas business people weigh risks and how they could affect the bottom line.
business days experience handled school security seeing spare stepping time
The days of security being handled by the 'network person' who did security in their spare time are over and increasingly we are seeing seasoned professionals with real business experience and business school qualifications stepping into the security space.
board change ultimately
Ultimately the change has to come from the board down.