Does anyone feel like cyber strategy work is useful? I feel like most companies just throw out NIST assessments that my team does.

Most people know the issues or themes… it’s the implementation part and budget that’s tough. 99% of the executives don’t even listen.

Maybe we’re doing this wrong.

likefunny
Posting as :
works at
You are currently posting as works at

Being on the other side as a solo consultant, yes, strategy and advisory are still useful, but more enterprise clients are avoiding the implementation projects from the Big 4 because they are costly and don't work.

like

Big 4 consulting is changing at a rapid pace and they are going to lose a lion share of business to the doers over the next decade.

like

Answer: No, not really.

Few enterprises will actually go forward with a bug bounty program that pays enough to solve their problems. Frameworks are nice, but if you want to know where your cybersecurity concerns lurk, pay someone you don’t know to put some pressure on everything.

like

Yes, it's useful because it lowers the company's insurance premiums

likefunny

Curious to know what type of companies and how you are selling NIST assessments. It’s how you package your product at the end of the day.

Cyber strategy is useful for sure. If it’s a regulated company and sector, the executives can’t throw it out blatantly. They will need to have risk based strategies and best practice approach to align cyber goals with enterprise objectives. Every cyber solution implementation project supports NIST.

like

McKinsey

Disguised as proprietary crap

like

We don’t ignore it, but no one gets excited about audit results. It’s like doing your taxes and finding out you owe money. If you can spin it into your budget requests it gives you some leverage. Thats about as good as it gets. Executives like to point fingers and say I thought this was in place. I thought we were good here. Then we have to remind them it is in place but no one is following the standards.

like

They can point fingers all they want, but ultimately they own the problem and the fact that they didn’t know the gap exists.

An auditor would see right thru them if they attempted to shift blame. Right out of the CISM material, prob CISSP too.

funny

If you’re just doing a NIST assessment you’re not doing cyber strategy, you’re identifying cyber risk. Cyber strategy combines the business and technology aims of the organisation and cyber threats to define a 3 year plan that enables the business

like

The fact that you think a ‘strategy NIST-based maturity assessment’ is cyber strategy is the problem and it’s unlikely a roadmap based on this will be strategic, likely tactical and operational.

The general problem with cyber strategists is that we think working with a CISO to achieve a 3.5 or 4 maturity over 3 years is a strategy. Our actual role is to help a CISO to align his/her strategy to protect the technology strategy that enables the business strategy, specifically against current and future cyber threats

funnylike

Related Posts

Looking to connect with someone in a Supplier Compliance Manager role. What does your day-to-day look like? Favorite thing about your job? Worst thing about your job? Skills that are beneficial to touch-up on?

like

Any communication about when will perm office be open? I mean how many months.

like

When I started in this industry, it was all about radio and direct mail. Now, most are doing video content and influencer marketing. What do you think our children will be influenced by?

like

Angular vs React if rewriting apps for ADA Compliance?

like

Going from 165 as an ACD to 210 as a CD? Is that about right?

like

40 weeks pregnant and terrified to be induced. Any tips on how to manage the stress and pain? I’m getting an epidural but still very nervous.

like

I am so nauseous and have been eating straight carbs for over a week now.. Any healthy lunch/breakfast ideas that would be easy on my stomach?

like

My wife is around 3 months pregnant. Doctor has recommended Irospan. And my insurance says they don’t cover it. And it is coming aroun 695$ without insurance, I found good Rx coupon which comes around 200$. Does anyone have better suggestions to check for coupons? And is iron deficiency common during pregnancy? Any valuable suggestions are welcome. Thanks

To those who have delivered. Are they still doing photography at the hospital after you deliver?

like

When in your pregnancy did you (1) purchase life insurance and (2) have a will drawn up?

like

Citicorp Hi, How is WLB and job security in Citicorp ? I am a java developer with 5.5 years of experience and have joining in next month. Thanks in advance!

Citi

Earned Value Management

Post Photo
like

Which level is FJ09 ?

Anyone know of any good tax professionals in the area?

like

How many years did it take you to get promoted to senior software engineer?

like

How much Salary should a Senior project Manager working in localization industry should be getting.
Also what all courses would be beneficial for upskilling.

Hi Team,
I have worked in a project for more than 1.5 years now for a non scripting tool. Feel no learning and skill enhancement here.Can I get my project changed. QA Automation. Will there be any consequences if I do so?

Hi Sharks,

Today I had senior manger round for senior analyst
Deloitte.
What salary range I should be asking if I proceed.

Project Management Domain
Location Hyderabad
Year of experience - 3.5 years

Any advice??

like

Does anyone use their private car to drive to work from hebbal, thanisandra or places that are 20kms away? It may be an absurd question to ask considering the Bangalore traffic, but still checking if there's anybody driving down that distance?

M here. Where can I find slim tees with a slightly longer length? Not to the extent of longline tees where it’ll go past my ass but long enough that I don’t have to worry about it turning into a crop top when I raise my arms

like

Additional Posts in Cyber Security Bowl

Message me if you need a referral to PwC cybersecurity, financial crimes, or regulations. Please no noobs. Only experienced professionals with at least 1 YOE

likefunny

CohnReznick hiring for cyber/tech risk/privacy team. Looking for seniors and managers. Anyone interested?

funnylike

What cert to go for next? Currently have AWS-SAA and Security+. Thinking about CISSP but how difficult is it compared to the AWS-SAA?

likefunny

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Anyone ever heard of or worked for Sygnia?

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

How is Booz Allen cyber strategy and risk management consulting? Got a recruiter inquiry

like

Can anyone recommend a good book/materials to prep for the CIPP/CIPM? 🙏🏽

How did you decide your speciality in Cybersecurity? Did you naturally gravitate towards one area?

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

I have interviews coming up with BCG. Any BCG Platinion folks willing to discuss example case interview questions?

like

How to make a jump to cloud security when I just have SOC experience? Currently studying for Solutions Architect cert

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

On a phone call today, my client suggested our project team provide 24/7 coverage for scanning support. My team size is two, including myself.

Post Photo
likefunnysmart

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like
like

Thinking about getting the AWS Cloud Practitioner certification. Does EY have any amazon resources or training materials that they provide? Any advise from people who have taken it before? Thanks!

like

is CRISC worth it? dont see it coming up as much as others

like

Laterals to Deloitte Cyber from other B4: Can you describe your interview process and what each one entailed? TIA!

like

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal