This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

5 Mistakes I’ll never make again:

Download resources

About this session

Moshe Toledano, partner in PwC Canada's cybersecurity, privacy and financial crime practice and a former CISO of several Quebec organisations, returns to GoSec with five mistakes from his own career. He sets the scene first: attackers have become roughly 60 percent more efficient than defenders over six years, more than half of Canadian OT organisations surveyed by PwC reported a cyber incident, events such as the pandemic, SolarWinds and Log4j keep hijacking roadmaps, governments are legislating, and budgets rise faster than teams can spend them. The mistakes: boxing vendors into orders instead of sharing outcomes and budgets so they have skin in the game; presenting frameworks and gap charts instead of decrypting the message for operations, management and the board; lacking the courage to scrap a doomed upgrade project; carrying security alone rather than publishing incident counts by business unit with executives' names attached; and promising ISO 27001 in two years or a maturity score the CFO could not interpret, instead of a few standing objectives with yearly checkpoints. A live poll scores the room on each mistake, and questions cover executive-level awareness, banning ransom payments and risk-driven strategy.

The demand for cyber security expertise and services is continuing to accelerate faster than we can keep up. Threats are evolving, new regulatory requirements are on the horizon and, most importantly, management is demanding that their business services and corporate initiatives are cybersafe. As cybersecurity leaders and professionals, we need to deliver cybersecurity programs that are agile and effective at an accelerated pace. In this session we’ll talk about the evolving demands on cybersecurity organizations and how to avoid some of the pitfalls that can slow us down or erode our cybersecurity programs

Key takeaways

  • Give vendors the why, the outcome and the real budget, then demand that they challenge you; orders without context leave them no skin in the game.
  • Tailor every security message to its audience: metrics for operations, prioritised actions for management, evidence that you understand your risk for the board.
  • When the inside voice says a project is a dead end, bring in neutral outsiders and get out early rather than burn the team to a bad outcome.
  • Publish behavioural incident counts by business unit with the executive's name on each line; nobody wants to top that list, and engagement follows.
  • Replace end-state targets like a certification date or maturity score with three to five standing objectives and yearly checkpoints, because the game has no finish line.

Speakers

Moshe Toledano
Moshe Toledano
Assoc. - Cybersecurity, Privacy and Anti-Crime financière · PwC
Moshe Toledano est associé de PWC Canada. Il dirige l’équipe Cybersécurité, protection des renseignements personnels et lutte contre la criminalité financière du Québec, qui se compose de spécialistes dans les domaines suivants : cybersécurité… Read moreRead less

Moshe Toledano est associé de PWC Canada. Il dirige l’équipe Cybersécurité, protection des renseignements personnels et lutte contre la criminalité financière du Québec, qui se compose de spécialistes dans les domaines suivants : cybersécurité, protection des renseignements personnels, fraude, blanchiment d’argent, sanctions, juricomptabilité et gestion de crise. Moshe a également eu le privilège d’être chef de la sécurité de l’information pour plusieurs organisations québécoises de premier plan, ce qui lui a permis de développer une connaissance concrète des défis que doivent relever les organisations en matière de cybersécurité. Comme les organisations comptent sur les technologies numériques pour transformer leurs activités, il est plus important que jamais d’atténuer les risques liés à la cybersécurité. Moshe a à cœur d’aider les organisations à gérer les risques liés à la cybersécurité et à accélérer leur capacité de mettre en œuvre leurs programmes de cybersécurité. Moshe a conseillé des entreprises de divers secteurs, notamment la fabrication, les télécommunications et les services financiers, afin de les aider à résoudre des enjeux commerciaux et à mettre en œuvre des solutions complexes cadrant à la fois avec leurs objectifs de gestion des risques et leurs objectifs commerciaux. Face à la progression des cybermenaces et à leur impact sur la qualité de vie des citoyens et des entreprises du Canada, Moshe est fermement résolu à trouver des moyens efficaces de protéger nos collectivités et d’atténuer les risques pour la cybersécurité. Soucieux du succès de ses collègues et de ses clients, il demeure engagé à former des équipes efficaces.

Resources

Tags

More from GoSec 2022

Also from Moshe Toledano

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.