The CISO Job - Getting It, and Keeping It

Featuring Craig Shumard, Marcus Ranum, and Todd Bearman
A Politics of Information Security Webcast

Over the last decade, the Chief Information Security Officer (CISO) has emerged as the job in IT risk management. But for many, it's a high-risk career move. Average tenures in the role remain mired at just a few years. But success is possible — join our expert panel to learn how you can get, and keep, the CISO job.

You'll learn:

How to Get the CISO Job:
- Who gets to the top of the shortlist
- Whether certifications play a role
- How experience in other parts of the organization can help your bid

And Then, How to Keep It:
- How to deal with senior management
- Establishing governance frameworks to guide your activities
- Advice on balancing tactical vs. strategic efforts
- Positioning yourself as an enabler, not a blocker
- Staying ahead by meeting all important audit and regulatory requirements


Featured Speakers:
- Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
- Marcus Ranum, CSO, Tenable Network Security
- Todd Bearman, CISO, Towers Watson
May 31 2012
63 mins
The CISO Job - Getting It, and Keeping It
CISO Careers
More from this community:

Data Center Management

Webinars and videos

  • Live and recorded (1634)
  • Upcoming (64)
  • Date
  • Rating
  • Views
  • 70% of the success of an IT project relies on the effective user adoption of the new tool or solution implemented. Let us introduce HP ART - a solution which changes the way users adopt and learn enterprise software. The webinar includes analyst observations, HP customer use-cases and a highly visual tool demonstration.
  • Virtual environments are excellent at providing an elastic, scalable environment for a myriad of workloads to thrive. Unfortunately, it's often too easy to over-provision resources or leave discarded and unwanted workloads, fostering a constrained environment due to virtual sprawl. However, did you know that this can also negatively impact the performance and growth of your critical workloads? In this session, you will learn to:

    - Identify virtual sprawl using advanced technical methods
    - Dig into performance related issues that can be caused by imbalanced or top heavy provisioning
    - Understand how to translate real world sprawl data into a solid business case for change
    - Exercise recommended practices to avoid falling deeper into the virtual sprawl trap
  • Virtual environments are excellent at providing an elastic, scalable environment for a myriad of workloads to thrive. Unfortunately, it's often too easy to over-provision resources or leave discarded and unwanted workloads, fostering a constrained environment due to virtual sprawl. However, did you know that this can also negatively impact the performance and growth of your critical workloads? In this session, you will learn to:

    - Identify virtual sprawl using advanced technical methods
    - Dig into performance related issues that can be caused by imbalanced or top heavy provisioning
    - Understand how to translate real world sprawl data into a solid business case for change
    - Exercise recommended practices to avoid falling deeper into the virtual sprawl trap
  • On Premise? Outsourced? Dedicated? Cloud? Harness the Power of "Hybrid" for a True "All-of-the-Above" Approach to IT Infrastructure.

    With so much focus on – and hype around – the cloud, we seem to have forgotten that for most businesses IT infrastructure remains a mix of on-premise, outsourced, physical and virtual components that must be optimized into a seamless hybrid environment. Featuring IaaS experts from Latisys and HP, we'll look at how CIOs and CTOs are allocating workloads, applications and data across a diverse infrastructure today – using every tool in their arsenal in an effort to maximize legacy assets, optimize limited IT budgets and leverage technology advancements to make their business more effective and responsive.
  • With easy access to public cloud resources like Amazon EC2, end users are completely sidestepping corporate IT and spinning up their own mini-datacenters with only a credit card in hand. This grass roots migration is gaining speed, and industry experts predict 35% of enterprise IT expenditures will go to shadow IT services like AWS in under 3 years.

    If you are in Corporate IT, join this webinar to learn more about:
    - Strategies other IT teams are pursuing regarding public cloud services, both pro and con
    - Management options for IT shops who want to embrace AWS, whether a little or a lot
    - Easy ways for corporate IT to add value to the business units and engineering teams already using Amazon EC2
    - Practical techniques for assuming a public cloud leadership role, even when resources are non-existent

    About the Presenters:
    Lynn LeBlanc, CEO and founder of HotLink Corporation, has over 25 years of enterprise software and technology experience at both Fortune 500 companies and Silicon Valley start-ups. Prior to founding HotLink, Ms. LeBlanc was founder and CEO of FastScale Technology, an enterprise software company acquired by VMware, Inc.

    Oded Haner, CTO at HotLink Corporation, is an accomplished, strategic, collaborative technology leader with extensive experience in developing and implementing innovative IT technologies. Most recently, Mr. Haner was CIO at Monster Cable where he developed and deployed a multi-year roadmap to overhaul corporate architecture towards virtualization, private cloud and SaaS based technologies. As a direct result of his vision, Monster Cable became an early adopter and internal service provider using both on-premise and cloud-based infrastructure.
  • Companies are eager to adopt infrastructure-as-a-service services in both public providers and private datacenters because of the business agility that IaaS enables. Full IT automation, self-service provisioning, and metered usage billing helps companies accelerate the development of their products and services, and improves organizational efficiency. Unfortunately, many companies are struggling to accelerate the most important parts of their business due to the challenges of securing these highly dynamic environments. In this talk Rand Wacker, VP of Products for CloudPassage will describe the challenges of security and compliance in a truly automated cloud and critical topics that you need to be aware of when planning to adopt cloud services in either public or private environments.
  • Automating your data center is the easiest way to free up your IT department's time to work on more strategic projects. Tune in to this webinar as Jeff Hart from M2 Technology discusses how automation can be the key to increase efficiency while reducing your IT costs.
  • Zac Streelman, Manager, Information Technology at Leupold and Stevens was looking for a disaster recovery (DR) solution that would extend the flexibility of virtualization to his DR environment. The solution had to deliver enterprise-class support for his mission critical applications: Oracle, Microsoft SQL Server and SharePoint and various CAD programs. The board of directors was specifically asking what the current solution was and what service levels could the infrastructure deliver.
    Zerto Virtual Replication installed seamlessly into their existing infrastructure, did not require any data center updates and is fully integrated into VMware vCenter.

    With Zerto Virtual Replication he was able to:
    - Realize very aggressive service levels – recovery point objectives of seconds and recovery time objectives of minutes
    - Deliver a better ROI with a DR solution that is hardware agnostic
    - Increase team productivity with a very simple solution
    - Quickly cross-train additional staff on DR processes and procedures
    - Optimize flexibility as changes to the environment required changes to the DR strategy
    - Test and validate the DR failover process without taking primary production systems offline

    Join Zac Streelman, Manager, Information Technology at Leupold and Stevens and Jennifer Gill, Director of Product Marketing at Zerto, to hear from your peers and learn about Zerto Virtual Replication.
  • How to keep your head (and your job) when the worse case scenario happens.

    Due to the increasing frequency of security breaches, defining an action plan is critical for every security practitioner. Getting breached doesn’t determine whether or not you’ve got a good security program in place – but how you respond to one does.

    Join security expert Conrad Constantine of AlienVault, for an in-depth discussion on things you and your team should do today to prepare for information security breaches. You’ll get practical, lessons learned advice on:

    -The inevitability of security breaches
    -Preparing to survive security breaches
    -Threat identification and containment
    -Handling the aftermath so it’s not worse than the breach itself
  • As data continues to grow at an alarming rate, IT will need to be smarter on how they store their data as much as how much storage they purchase. In this panel, experts from HGST and Code42 will discuss how data growth is affecting the storage industry in regards to cold storage, HDDs, back up and archiving and best practices to developing a comprehensive storage strategy.
  • Channel
  • Channel profile
Up Down
  • Geeking Out with Marcus Ranum - Malware Response Jun 4 2013 6:00 pm UTC 60 mins
    Within the past five years, we have seen an escalating strategic use of malware and its negative impact on organizations. The TTPs (tactics, techniques, and procedures) of various threat actors have caused not only a demand for incident response capabilities, but also the need for in-house reverse engineering and malware response skills to aid incident response and forensic activities.

    Please join Marcus Ranum and special guest, Joel Yonts, on Tuesday, June 4 at 2PM EST for an interactive conversation on malware response programs and their importance and role in today’s enterprise security operations.

    Topics covered:
    •Strategy and objectives for developing a malware response process
    •How to build a malware analysis team
    •What tools to employ for malware response, and other related topics
  • Managing Vulnerabilities in Virtualized and Cloud-based Deployments May 30 2013 6:00 pm UTC 60 mins
    Technologies such as virtualization and cloud-delivered services offer organizations the benefits of hardware consolidation and rapid provisioning and deployment. However, they also bring security and compliance challenges that break traditional vulnerability management solutions by allowing un-scanned and unpatched systems to become active in any part of the organization. A new model that offers real-time identification and assessment of these technologies is required to mitigate the risks. Find out more about it in this webcast…
  • Cyber Threats News and APT Defenses - A Politics of Security Webcast May 23 2013 6:00 pm UTC 60 mins
    There has been a lot of press lately on the escalating cyber threats especially from China. A panel of security experts and practitioners will discuss focus on how this press coverage has changed how organizations think about these cyber threats and what countermeasures they need or plan to implement to address escalating crimes, espionage, or warfare cyber risks.
  • Is your Network Infrastructure Adequately Protected? Recorded: May 15 2013 63 mins
    Network devices including firewalls and routers are the gatekeepers to “endpoint” resources and are increasingly using complex software components. These devices are often remotely accessible and whose configuration changes regularly, making them susceptible to vulnerabilities and misconfigurations. To add to this, network and security teams are often separate parts of an organization often leading to incomplete understanding of vulnerable infrastructure. In this webcast, we examine how to identify vulnerable devices and communicate them across multiple teams and ultimately fortify these devices from configuration and security issues.
  • Increase Security Effectiveness with the 20 Critical Security Controls Recorded: May 1 2013 64 mins
    Automating the 20 Critical Security Controls has demonstrated reduction in risk by over 90%. Tenable is the first vendor to offer an integrated real-time risk management solution to help organizations easily implement these controls.
  • How Will CDM Impact Your Organization? Recorded: Apr 10 2013 59 mins
    DHS' CDM program combines the valuable lessons learned from the existing implementation of FISMA mandates, the strides made by the Cyberscope program, and the proven results of the State Department’s iPOST program. During this webinar, we will discuss:

    - Current challenges in enterprise continuous monitoring
    - How to move your program from periodic system state analysis to real-time monitoring
    - A glimpse into the future: DHS CDM and it's affect on security and regulatory compliance
  • Geeking Out with Marcus Ranum - Take 2 Recorded: Apr 3 2013 60 mins
    Defining "normal" is one of the hardest things we do in security (the other is trying to get people to write perfect code!), but there are a few tricks that work. In this second session, Marcus Ranum and Ron Dilley will be talking about detection algorithms and the problem of defining "normal" network activity.
  • Geeking Out with Marcus Ranum - Security Data Aggregation Recorded: Feb 19 2013 52 mins
    Big data and security analytics have become the buzz of the industry. It is true organizations are collecting more and more data each year with the intention of getting better network telemetry and enterprise-wide visibility to solve complex security problems. One of the main challenges is collecting the necessary data that lives dispersed across an organization to build an effective security model.

    The first part of this series is a lively discussion between Marcus Ranum, CSO of Tenable Network Security, and special guest, Ron Dilley.
  • The Politics of Stakeholders within the CISO world Recorded: Jan 31 2013 56 mins
    CISOs must deal with several stakeholders within the organization. These stakeholders range from BOD members, C-Level management, peer compliance stakeholders (e.g. Legal, Privacy Office), vendors, and the IT organization itself.

    This session will focus on critical success factors to dealing with this wide array of stakeholders and success case studies.

    Specifically, this session will discuss the politics of getting alignment and buy in with the many stakeholders within the organizations such as:
    •Board of Directors and C-Level management
    •Natural allies such as compliance, privacy, audit, enterprise risk management
    •Potential contentious relationships with line or business unit management
    •IT organization strategic and tactical delivery goals and objectives

    Speakers include:
    •Craig Shumard, Principal, Shumard and Associates, LLC, Emeritus CISO, Cigna
    •Tom Doughty, VP & CISO,Prudential
    •Larry Brock, CISO emeritus, Dupont
    •Bob Hillmer, Director, Enterprise Information Security and Directory Services
    •Marcus Ranum, CSO, Tenable Network Security
  • Outcome Based Security Monitoring in a Continuous Monitoring World Recorded: Jan 23 2013 57 mins
    Data from continuous monitoring is in turn enabling “Outcome based” security for identifying trends before they are problems, making better policies, and making asset owners more accountable for the systems they are managing.

    Register for this new webcast to learn about how data from continuous monitoring is enabling "Outcome Based" security.
  • The Politics of Risk Tolerance Recorded: Dec 13 2012 52 mins
    A Politics of Information Security Webcast.

    This webcast will focus on how risk tolerance is decided within an organization and the processes and politics of risks assumption. Topics to be covered include:

    - How risk tolerance is decided within an organization
    -- Informal to formal risk tolerance model
    - How and who can assume risk
    - Risk assessment and risk assumption linkages
    - Competing Drivers
    -- Business unit versus enterprise risk

    Presenters include:
    - Craig Shumard, Principal, Shumard and Associates, retired CISO, Cigna
    - Dennis Brixius, VP of risk management and CSO, McGraw Hill
    - Catherine Rees, CISO, Dow Jones & Company
    - Marcus J. Ranum, CSO, Tenable Network Security
  • IPv6 Requires Fundamental Change to Vulnerability Management Programs Recorded: Dec 4 2012 63 mins
    Learn how new upgrades to Tenable’s SecurityCenter CV™ identify vulnerabilities in devices that could be located in any of 18,446,744,073,709,551,614 (18 quintillion!) IPv6 addresses, the /64 space recommended for a “typical” organization.

    Register for Tenable’s webcast on Dec 4 at 2PM EST to hear about the Newest version of SecurityCenter Continuous View™ (SC CV). This is the first solution designed to manage risk across IPv6 networks, the next generation of Internet address spaces.

    Speakers include:
    - Ron Gula, Tenable Co-founder and CEO
    - Jack Daniel, Tenable technical product manager
    - Allan Carey, Tenable product marketing manager
  • The CISO Job - Getting and Keeping It Part II Recorded: Sep 25 2012 58 mins
    A Politics of Information Security Webcast
    Earlier this year, a panel of Chief Security Officers from some of the nation’s highest profile companies met to talk about how to get and keep the CISO job. The response was tremendous – over 1,000 people have participated in the session. But that talk only scratched the surface – our team of panelists has much more information to share. Join us for Part II of the discussion where we’ll dig into some of the questions that didn’t get answered in the initial discussion, and cover more ground on topics like working with senior management.
    You'll learn:
    How to Get the CISO Job:
    - How to deal with senior management
    - Establishing governance frameworks to guide your activities
    - Advice on balancing tactical vs. strategic efforts
    - Positioning yourself as an enabler, not a blocker
    - Staying ahead by meeting all important audit and regulatory requirements
    Featured Speakers:
    - Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
    - Marcus Ranum, CSO, Tenable Network Security
    - Todd Bearman, CISO, Towers Watson
    - Vas Rajan, CISO, ING Direct
    - John Masserini, Chief Security Officer of Miami International Holdings and the Miami International Securities Exchange (MIAX)
  • Malware Defenses for 2012 and Beyond Recorded: Jul 31 2012 60 mins
    Organizations everywhere are deep in the grips of “malware madness.” Industry estimates of the number of unique malware variants are pegged in the hundreds-of-millions, and it’s rapidly growing. Faced with increasing stealth and sophistication, and an ever-broadening selection of worthy targets, security teams must not only invest in dedicated anti-malware products, but also take advantage of every tool in their arsenal capable of helping combat the problem.

    Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO and CTO Ron Gula to learn:

    • What’s driving the malware problem and how extensive it is
    • Strategies for building effective, long-term malware defenses
    • The benefits of a next-generation vulnerability management solution with integrated malware defense capabilities
  • No More Checkboxes: Vulnerability Management Evolves Recorded: Jun 26 2012 67 mins
    Vulnerability management is growing in strategic importance as organizations seek to optimize the efficiency of their security teams, and to better understand and manage risk. As managers struggle to make sense of a deluge of vulnerability data, vulnerability scanners are evolving to address these needs. As a result, they’re emerging as a much more strategic component of the security infrastructure. Join Securosis analyst and president Mike Rothman as he discusses critical findings around this market shift – including an examination of underlying drivers and detailed insights into the capabilities and features you’ll need to move to next-generation vulnerability management and begin reaping the rewards. Mike will be joined by Jack Daniel, Tenable Network Security product manager and security blogger, who’ll provide insights into how organizations are achieving these gains today with Tenable products and technologies.

    Topics to be covered include:

    •What core features are essential in today’s more complex networking environments

    •The increasing importance of assessing the application layer

    •How to expand capabilities by incorporating value-add technologies to your deployment

    •The unique requirements of the enterprise

    •Deciding whether you can work with the tools you have – and how to replace them if new technologies are needed
  • The Case for Integral Attack Path Analysis Recorded: Jun 19 2012 63 mins
    Taking Vulnerability Management to the Next Level:
    The Case for Integral Attack Path Analysis

    Are your high-value servers and the data they contain really safe from attack, even with multiple countermeasures in place? Given today’s highly motivated attackers and the increasingly sophisticated threats they are generating it is not surprising that patching, firewalls, intrusion prevention systems and other commonly deployed defenses are no longer sufficient. Unfortunately, all it takes is a single, seemingly unimportant system to provide skilled attackers with a beachhead they can use to work their way through and around your defenses. Tenable’s next-generation vulnerability management, with integrated attack path analysis capabilities provides the answer, delivering the tools, insights, and intelligence organizations need to identify and close off otherwise overlooked attack paths – while simplifying infrastructure and streamlining operations in the process.

    Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO Ron Gula and learn:

    • Why traditional vulnerability management fails to measure up
    • What’s needed to efficiently identify and close common attack paths
    • Processes, tips and techniques for conducting attack path analysis
    • The benefits that can be derived from a next-generation vulnerability management solution with integral attack path analysis capabilities
  • The CISO Job - Getting It, and Keeping It Recorded: May 31 2012 63 mins
    A Politics of Information Security Webcast

    Over the last decade, the Chief Information Security Officer (CISO) has emerged as the job in IT risk management. But for many, it's a high-risk career move. Average tenures in the role remain mired at just a few years. But success is possible — join our expert panel to learn how you can get, and keep, the CISO job.

    You'll learn:

    How to Get the CISO Job:
    - Who gets to the top of the shortlist
    - Whether certifications play a role
    - How experience in other parts of the organization can help your bid

    And Then, How to Keep It:
    - How to deal with senior management
    - Establishing governance frameworks to guide your activities
    - Advice on balancing tactical vs. strategic efforts
    - Positioning yourself as an enabler, not a blocker
    - Staying ahead by meeting all important audit and regulatory requirements


    Featured Speakers:
    - Craig Shumard, Principal, Shumard and Associates, LLC, retired CISO, Cigna
    - Marcus Ranum, CSO, Tenable Network Security
    - Todd Bearman, CISO, Towers Watson
  • A Layered Approach to Mobile Security Recorded: May 22 2012 64 mins
    70% of security professionals agree mobile device vulnerability management is very important, but 67% of enterprises report they have no or few mobile controls deployed. Despite the bleak outlook, it is possible to reassert control over this rapidly growing security exposure. Join AimPoint Group Founder and Principal Analyst Mark Bouchard and Tenable CEO Ron Gula and learn how to apply a layered approach to mobile device security to regain control, evaluate risks, and establish essential policies.

    You’ll learn:

    •Why mobile devices are inherently difficult to track, evaluate, and assess
    •The four essential layers of an effective mobile device security strategy
    •How to prioritize mobile device security activities
    •Why scanning technologies need to change to assure effective vulnerability assessment of mobile devices
Industry-expert insights on overcoming critical security challenges
Tenable Network Security brings you critical, timely insights and advice on how to protect your IT infrastructure from the latest threats and ensure compliance and clean audits, while effectively understanding and communicating risk. With guests including renowned technical experts and specialists, senior executives, and industry leaders, you’ll gain multiple perspectives on how to address IT security challenges — along with the practical, hands-on advice you need to stay ahead of threats.

Embed in website or blog

Successfully added emails: 0
Remove all
  • Title: The CISO Job - Getting It, and Keeping It
  • Live at: May 31 2012 6:00 pm
  • Presented by: Featuring Craig Shumard, Marcus Ranum, and Todd Bearman
  • From:
Your email has been sent.
or close
You must be logged in to email this