u/ConcertDependent8452

i have serious concern about corporate cybersecurity

is it just me or is the cybersecurity management in corporates are actually useless jobs ? i still didn't see a single ciso and his leadership advisors that actually prioritize fixing issues they all just ask "what tool should i purchase ", and in some jobs I've had the security leadership is doing actual unethical work by hiding issues from ciso because they don't want to be the bearer of bad news , cybersecurity job is full of delivering bad news that's just how it is and it drives me nuts when leadership doesn't understand that.

can someone please assure me and give me faith back in cybersecurity I've been working for more than 15 years and not a single CISO I've worked with actually pushs a roadmap towards fixing issues all i see is "what tool to change / what tool to add " meanwhile an smtp without authentication and whitlisted to bypass all security tools to avoid getting internal emails in spam and have a firewall with allow any/any is known for years but "too complicated to fix" ... my technical mind can't even start to understand the order of priorities in this , yes sure we want to expand the "build" of our scope , but shouldn't "what we need" be based on what are the areas we struggle in with risk on the "run" daily life ?

and if you are a CISO reading this can you tell me how are you making sure your direct reports are nto hiding bad news because they are afraid they wont get the promotion /bonus they wanted ?

reddit.com