This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

The 5 Obstacles Organizations Forget when Designing their Cybersecurity Program

Download resources

About this session

Victor De Luca, a sales engineer at Zscaler with a background as an independent security consultant and army veteran, delivers a bilingual talk (mostly French) on five patterns he sees holding back cybersecurity programs across Canada. He argues the classic three-year plan-build-run cycle cannot keep pace with technology change and should give way to agile, risk-based budgeting; that most security teams cannot actually quantify risk in dollar terms and recommends combining the FAIR model with MITRE ATT&CK mapping to size and justify specific controls, illustrating the approach with a data-exfiltration scenario. He cites labor-shortage statistics (roughly 3.5 million unfilled cyber roles, workers holding multiple jobs) to argue for embracing SOAR-style automation for repetitive response work, stresses that tools without trained staff who understand the business are ineffective, and closes by arguing cybersecurity now underpins business continuity, illustrated with a rough cost estimate of what a serious breach could have cost Shopify. An extended French-language Q&A covers translating risk into board-level language and reconciling agile security budgeting with multi-year vendor contracts.

Key takeaways

  • Move away from fixed three-to-five-year security roadmaps toward agile, ad hoc budget requests tied to quantified risk reduction rather than tool purchases.
  • Combine a quantitative risk model like FAIR with MITRE ATT&CK control mapping to translate a specific attack scenario into a dollar-denominated risk-reduction case for leadership.
  • Expect the cybersecurity labor shortage to persist; adopt SOAR-style automated workflows for repetitive response tasks (e.g., auto-disabling an account after a password spray) rather than counting on hiring alone.
  • Invest in training security staff on the business itself, not just the tools; analysts who don't understand normal business behavior can't reliably tell risk from noise.
  • Frame security investment around overall business risk exposure (a target dollar reduction) rather than accounting-style ROI on individual tools, and expect vendor contract cycles to be a bigger drag on agility than the tools themselves.

Speakers

Victor De Luca
Victor De Luca
Sales Engineer · Zscaler
Having started his career in the Canadian Armed Forces, Victor has worked in the security field for over 10 years and has specialized in information security for the last 8. He holds an M.Eng. in cybersecurity and an MBA. In the private sector, he… Read moreRead less

Having started his career in the Canadian Armed Forces, Victor has worked in the security field for over 10 years and has specialized in information security for the last 8. He holds an M.Eng. in cybersecurity and an MBA. In the private sector, he has assisted numerous organizations in recovering from information breaches and improving their internal controls to reduce information leakage. Victor is primarily focused on helping organizations protect critical systems and sensitive information from attackers. In his spare time, Victor enjoys writing blog posts on Medium and learning about new technologies.

Resources

Tags

More from GoSec 2023

Also from Victor De Luca

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.