Related Posts
It’s Friday who’s partying
Can someone guide on this?

Has anyone here tried pregmune?
Additional Posts in Cyber Security Bowl
Any tips or tricks for CSX certification?
Anyone ever heard of or worked for Sygnia?
Anyone working in Pharma industry?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.




Grc will always be needed across any department in any industry, not only cyber
Over-commoditized
Good PMOs are invaluable. Always need someone to effectively communicate asks to technical team members and translate results in business value to leadership. I say this as a technical person
I’ve seen consulting firms get rid of PMO resources and replace with AI for orchestration. EY might be different though.
Depends on what you consider niche specialists but yes they are in demand and will continue to be in demand. Most of the time the issue comes down to pay and location.
Not a fan on paper grc, i think we are heading fast into automated controls and risk management
Soc /dfir are always hot but subject to burn out
Zero trust and security architecture bubble still but traction feels slow still
I’ll do quantitative risk analysis. But risk only looked at periodically is not going to help any business long term.
Embedding controls should be done based on the paper side i agree but also based on business context and risk. This should be moving to near real time risk and compliance reporting based on controls, exceptions, what is happening in the system.
I also acknowledge this is more advanced.
I don’t agree that we should wait to put some controls in place based on assessments etc. i would rather build controls into a cloud environment from day 1 based on threat models, risk assessments etc than wait for someone to assess it before it goes live as that ignores everything up to then like leaving my api keys in my code on a public GitHub repo ( pls don’t do that).
The hottest topic in Cyber right now is PQC
🥱