Risk mitigation isn’t just about calculation, it’s about contemplation. In this episode of Cyber Security Inside, we speak with Malcolm Harkins, a Security Executive, Board Member, Advisor and Coach/Mentor whose thirty-year career in the tech industry gives him incredibly valuable insight into a whole host of key issues surrounding cyber security.

We covered many topics with an overarching question in mind - How can we collectively become better choice architects in the face of inevitable risk?

We discuss:

• The ideal skill set for a CISO/CSO, which should include a breadth of business, risk compliance and technical acumen

• The kinds of vital questions missing from board discussions, including moral and ethical concerns

• The importance of long-range planning when it comes to risk preparedness and damage mitigation

• What can be learned from a disaster like the recent Colonial Pipeline ransomware attack

... and more. Join us for this fascinating discussion, and become a better choice architect.

Here are some key take-aways:

• It’s physically impossible to completely eliminate risk, but you can ask better questions in board discussions to help manage it.

• Similarly, you can’t know everything, but with the right group of people and data, you can forecast a variety of different risk scenarios and become better prepared to minimize damage.

• Ethical and moral questions need to be coming up far more in board discussions - these issues can be a matter of life and death, and should not be ignored.

• When it comes to the language of board discussions, there should be more of an even playing field - non-technical members should begin to employ a basic understanding of security and tech nomenclatures, and vice versa.

• And while it’s important to train people to be on the lookout for ransomware attacks like phishing attempts, it’s not a sufficient strategy - accountability should ultimately be driven back to the security community across the vectors of risk, total cost, and control friction.

Some interesting quotes from today’s episode:

“I think it’s high time that we start expecting the non-technologist board members to at least be able to understand the basic nomenclatures in the security and technology space.”

“I think there’s an ethical and moral accountability that is missing in many of the discussions around risk; that’s a question that I can tell you has never come up in any of the board meetings I’ve ever been in, but one that should.”

“Before I had that dialogue with them, they were not looking at that data integrity with that lens, which would have potentially caused people to get sick or die, and it certainly would’ve had a substantial revenue brand or organizational implication if that were to occur.”

“I think we are doing bandaids, bubblegum and baling wire making up for dated security technologies and other technologies that don’t work.”

“We’ve got to start weeding and feeding our environment. Go look at the effectiveness and efficiency of control, and if it’s not effective and efficient, shut it off. Get rid of it and buy something better.”

“If technology companies spent more time making sure that every engineer who created code or developed technology understood security vs. just functionality, again, you would change the technology vulnerability dynamics by focusing on that training which we don’t do enough of.”

“I’ve always thought of my role as architecting choices for the business...if I architect choices the right way, we’ll make better business decisions.”