There are so many security tools for monitoring and detecting vulnerabilities for example DAST, SAST, IAST, network scan, agent scan , IDS, IPS, splint, DB monitoring, DLP etc. do you think a small company can afford all these expensive tools???

like
Posting as :
works at
You are currently posting as works at

It’s not about the tools but how you used them. A lot of cloud tools for example overlap, so you need to understand where the gaps are and define controls to address them. Understanding your risk posture is far better than buying a bunch of expensive tools.

like

A small company also very likely doesn’t need all of those. You probably aren’t employing hundreds of developers to write millions and millions of lines of custom code; instead, your tech stack is mostly, or all entirely the shelf software, or even fully SaaS. In those cases you don’t even need to bother with your own DAST, SAST, etc. - you can likely rely on your providers attestation. And you don’t have access to source code anyway, so static analysis isn’t even an option.

Similarly, smaller companies tend to be homogenous Microsoft shops, and with an E5 license now, you really have a powerful full-capability security stack. This doesn’t fit every large enterprise environment because they have so much tech complexity, but for small companies it’s great.

like

Eval risk and technical talent. Buy what’s outside of their ROI for TCO and build/ free tools for lower risk areas of your threat models that teams can self maintain . More importantly figure out mechanism of coverage needed when you threat model at the org level

Related Posts

Anyone want to grab a drink tn?

like

Hi everyone! I’ve been working as a product manager in an internal consulting department at Kaiser Permanente a on software product that maps and automates clinical workflows. Although my title is a consultant, my role entails the usual responsibilities of a PM (prioritizing builds and features, identifying business requirements, mapping user journeys and stakeholder management). Does anyone have any advice on ways to break into tech or suggestions of companies to look into?

like

Question for Sales leaders who’ve said “I did an analysis and concluded we just need more at bats”.

Does it feel like you’re saying something useful? Or are you also writing a book titled “In order to get rich you just need more money”?

likefunny

Why are properties in NYC so damn expensive? At this point should I just move elsewhere?

like

Is it worth doing MBA for breadth of knowledge and brand network if you already have 30LPA Ctc

I'm resistant because avg iim package is 25lpa. Please suggest (opportunity cost is also high -ie 2 years plus fees investment)

like

Newly promoted M1. Transaction advisory services (FDD). Seattle.


Am I off base to expect $115-120k? Given how crazy M&A market is and demand for staff

like

Ok! What would be the manager promotion increase and bonus this year for a National firm in the northeast region?? Any guesses?!

likehelpful

What is the take on firing at CVS Health? Given the high likelihood of recession, does CVS Health have a history of firing people? I have a feeling that they have hired a lot of people at high cost in the past year and are going to face pressure to justify productivity. Would be great to understand if there is history here in how CVS has reacted in the past to recession

like

Today no one came into our restaurant and my boss started crying. Do I... comfort them? Leave them be?

likefunnyupliftinghelpful

“Circumcision makes your dick look like it’s wearing a tailored suit. Circumcised is James Bond. Uncircumcised is James Out-On-Bond"

likefunny

Overheard on LinkedIn

Post Photo
likefunny

Can anyone please tell me what’s the expected salary range for Risk Analyst Role. Thank you.

like

Ping me for Siemens Referal. Good Company and WLB with decent package. #Openings. #SiemensBangaloreSiemens

likefunny

I'm panicking because I think I got hired in at a title that's too high for my day to day. I Am relatively new and I got hired to work on a speciality practice that required some unique skills.

like

Anyone else feel like as you move up, you have to work even harder to justify your value to your company as you grow “out of the weeds”? Especially with the fear of layoffs looming over everyone’s heads.

likehelpful

How big does an agency have to be to justify a CCO title?

like

How is John St these days for accounts?

like

Making a switch form Android to iOS. Whats the best way to get my backup messages on to the new device ?

like
like

Hi I am an Icwa with 15 years experience in accounts.i can do tally finalization tds and gst.I am looking for a job change

Additional Posts in Cyber Security Bowl

Anyone familiar with Istari-Global and their collective of cyber risk companies? What’s their perception in the market? Opportunity to join US team. Thanks!

like

Thinking of moving from Big4 cyber to Accenture cyber. Any major differences (other than no channel restrictions).

like

Anyone at Protiviti in their Cybersecurity consulting practice willing to chat? Looking to inquire about pay, culture, etc. Thanks!

like
like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

I have a younger family member (almost 13) who is very interested in cybersecurity. How can this person learn and grow in a safe manner if he/she isn’t near a city with youth clubs and etc? Idea is to reinforce ethics, but this material is far too advanced for the parents.

like

Hey Cyber friends! I’m a life long professional creative looking to get out. I’m fascinated by Cybersec/Infosec and have been learning a small amount. Tryhackme + YouTube + beginning to learn some python. However, I’m well aware that these baby steps don’t compare to the real job.

My questions: do you like what you do? Would you recommend the field or your discipline to a friend? What is the best and worst part of your job? Grateful for any and all responses. Thanks for letting me lurk! 🙏🏻🙏🏻

like

Anyone here do post-breach data mining? Being pursued to start a practice line doing this and trying to understand market value.

like

Any tips or tricks for CSX certification?

like

What’s a good taxonomy for defining requirements for logging & monitoring? (i.e., apps, db, infra, etc.)

likefunny

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

Currently working in an IT audit role, what is the best way to transition into cyber ?

like

Tired of your job and want to come to KPMG Cyber Services? Drop me a burner here.

likefunny

How much does Deloitte pay for cybersecurity or devops senior Deloitte roles

like

Wondering if anyone here got "provisional" CISSP --obtaining the cert before five years in the industry. Have Security+ and CIPP/US and aiming for BISO role in Fortune 100. Pivoted from consulting. 15+ YOE. Masters degree Management experience. Advice? Thanks.

like

Views on carbon black as a product?

helpful

How is Booz Allen cyber strategy and risk management consulting? Got a recruiter inquiry

like

I have interviews coming up with BCG. Any BCG Platinion folks willing to discuss example case interview questions?

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal