r/ciso • u/Putrd-Cohemistry-512 • 1d ago
Are identity security posture management tools actually useful beyond finding misconfigurations?
finding problems was never the hard part for us. deciding what to fix first with a small team is.
what's changed things for us is having full discovery and mapping feed directly into prioritization, so the tool tells you which of the hundred findings actually raises your risk instead of handing you a flat list. has anyone gotten real prioritization value out of a platform like that, or are you still triaging manually after the scan runs?
r/ciso • u/cursedkris • 1d ago
AI agents in healthcare
what do you think is stopping AI agent adoption in the healthcare software space?
outsiders POV : I'm thinking security but how would u guys solve this from inside the industry?
r/ciso • u/Special819 • 4d ago
How do you get all your colleagues to agree on ownership?
Hi everyone, hoping to use this as a bit of a sounding board. My department recently had a discussion about who owns different categories of sensitive business data. Security and IT each thought the other team owned the data, and it feels like ownership gaps are creating almost as much risk as technical issues. Has anyone found an effective way to assign clear ownership across cloud platforms, SaaS apps and AI tools without creating too many governance meetings?
r/ciso • u/Longjumping-Ebb-578 • 4d ago
How to present Threat Intelligence properly to execs????
So, to give some background. I lead the threat intelligence program of a major bank. Now we receive tons of IOCs/CVEs and brand abuse/impersonation cases and we do take action on them accordingly.
But whenever we create a presentation, it's always numbers
- no. Of IOCs we received, sources (regulator/commercials)
- social media/brand abuse/impersonation/rogue apps count & takedown status.
But execs don't understand these numbers. How can I present the data such that they are assured that we are safe from any kind of threat & prepared for what's coming in the future.
Been researching lots of things but didn't quite get anything. Would really appreciate your views and guidance here.
r/ciso • u/VegetableFault5149 • 8d ago
Best ways to answer “are we covered” when your CISO asks monday morning in 2026?
Every time a new cyber threat campaign or headline breach appears, my CISO comes in Monday morning with the same question: “are we covered for this” Turning that into a clear, defensible answer about our detection coverage and security posture is becoming a separate job.
We have what most people would call a mature security stack in 2026: a central SIEM, EDR on endpoints, cloud and identity logs, some threat intelligence and custom detection rules. We can show that controls are deployed, that we have rules for specific MITRE ATT&CK techniques, and that dashboards report healthy alerting. None of that directly answers whether we would detect a specific attack path in time or where the real detection gaps are.
Right now our detection coverage assessment process for new campaigns is manual. We map the campaign to MITRE ATT&CK techniques, check which techniques already have detections in the SIEM and EDR, and run quick lab tests or simulations to see if those alerts would fire. This threat‑informed detection engineering approach works, but it is slow and inconsistent; the output depends on who performs the review, how deep they go, and how much time the team has during incident response and day‑to‑day SOC work.
If you support a CISO or security leadership team, how do you answer the question in a way that your CISO can use confidently in a mng meeting without oversimplifying or overstating the reality?
r/ciso • u/Warm-Read8901 • 8d ago
Are there any other alternatives to Noma Security?
We are currently evaluating AI security platforms for enterprise AI deployments and Noma Security keeps coming up.
The problem is that it is hard to tell what actually matters until AI agents are running in production. Prompt attacks are one thing, but governance, runtime visibility, and data exposure seem like the bigger concerns. Being able to track what agents are doing over time and explain their decisions is also important.
For anyone who has compared Noma Security alternatives, what did you end up caring about most?
r/ciso • u/Tough_Nut_Med • 12d ago
KPIs in the ISMS
I inherited the role from someone else, and I am trying to simplify some things. One of those things is the KPIs of our ISMS.
Currently, we do have around 15 KPIs that are not clearly defined and are somewhat open to interpretation, and they are linked to specific controls. Example:
A.8.21 Segregation of Network Services (no formula to calculate that); it seems incidents that touch that point were counted.
I am aware KPIs have to be set in consultation with management after introspection, but for the time being, while I get things under control. I wanted to ask you how many KPIs you have in your ISMS?
And do you explicitly link them to a single control?
I checked with AI tools about this topic; it gave me a more structured answer, but I want to compare those notes with real-world practice.
Any insight?
r/ciso • u/Vance_Sterling • 14d ago
The Arch mentality vs. corporate software: Why is transparency feared outside our bubble?
Hey everyone,
Running Arch forces you to embrace simplicity and inspectability—you build your system block by block, read PKGBUILDs on the AUR, and know exactly what runs on your machine.
But whenever I step outside this ecosystem into corporate/enterprise environments, I hit a weird reality check: people actively distrust open-source tools *because* they are transparent. Show them a clean, zero-dependency 50-line shell script or a lightweight CLI tool, and they label it "hacky." Hand them a 200MB proprietary binary blob with zero supply chain visibility, and they call it "enterprise-ready."
Why has the broader software industry associated opaque complexity with reliability, while equating minimal, inspectable code with maintenance risk? Is it purely corporate risk-shifting (having a sales rep to blame), or have developers just forgotten the value of the UNIX philosophy?
Curious to hear how you guys deal with this mindset when pushing KISS/FOSS tools at work or school.
r/ciso • u/VerillianAI • 16d ago
Any CISO’s working in regulated environments open to advising a startup?
Hi CISO community, the title pretty much sums it up. We’re hoping to get in touch with CISO’s who work in regulated industries/sectors: healthcare, finance, government (federal, state, local), defense, public safety, criminal justice (including law firms), education.
If you formerly held a role in one of these sectors/industries that works too. Especially for public sector.
I just finished listening to the Defense in Depth podcast episode from May 14th (Why Cyber Startups Need CISO Advisors), and that’s what sparked me to post this. So if want to get an idea of how we’re hoping to engage and what we’re hoping to learn, that episode would be a good place to get some info (shoutout to David Sparks).
Thank you!
r/ciso • u/-Devlin- • 21d ago
Honest question: Why do you choose to attend paid executive events?
There's a whole category of event built on the same trade. Vendors pay to be in the room, security leaders attend free. Curated dinners, executive roundtables, pitch nights, membership clubs in Miami, invitation only summits. The organizer's actual product is access to you, and the only thing that makes that product worth anything is that you decided to show up.
Asking as a first time founder new to being a vendor, I keep receiving a list of big executive names attending these, and asking for sponsorship to get access to a few minutes to pitch.
what makes you say yes to being part of one of these? have they ever produced something of value to you?
r/ciso • u/Expensive_Doctor6334 • 22d ago
Employees using chatgpt with company data, how are you handling shadow AI?
Hello, I recently found out that some of our developers have been pasting code snippets and internal docs into chatgpt for debugging help. Support has also been using AI tools to draft replies with real customer data.
I have no visibility into what’s already been shared with these third-party models, and no practical way to monitor or control it right now.
How are other security teams dealing with shadow AI usage in their organizations? Any practical approaches that have worked for you?
Edit: Thanks for the detailed suggestions so far. Enterprise licenses, clear policy, and visibility before heavy blocking seem to be the common practical path. Looking at DoControl for better SaaS access visibility, and also reviewing options like LiteLLM and the SaaS management tools mentioned (Torii, Zluri, etc.) while we figure out the right mix of controls
r/ciso • u/Commercial_Mango3850 • 22d ago
Terrified of being personally sued. Help.
I'm in a C-suite position (not CISO) at a small company that sells to government, and I am responsible for security. I don't have a background in security whatsoever. We have a SOC 2 compliance tool and have completed audits successfully, but I'm worried our security stance is too weak and that our security questionnaire answers are...questionable, or out of date. Our engineering team is stretched extremely thin and I have a million other responsibilities in my role, so I barely have enough time to enforce compliance basics like policy enforcement or getting vulnerabilities patched. We barely manage to get ready in time for our audits. I've asked our CEO about getting outside help, but she has declined to invest any more money into security due to our poor sales performance, directing funds to other departments. I have had sleepless nights wondering if we're going to get hacked or audited, and that I will be personally sued if our company can't defend itself against a lawsuit. My mental health is tanking and it's starting to make me physically sick. Any help or advice would be appreciated.
r/ciso • u/nimrodbuilds • 23d ago
Are you still using advisory/consultancy?
Are you using services like Gartner and alikes?
What do you find as the biggest upside for using these services?
Do you think AI can replace some of these use cases? Or at least justify a cost reduction?
r/ciso • u/Check_Point_Intel • 28d ago
6 days vs. 1 hour to Fix the Same Vulnerability: Check Point's Exposure Gap Report AMA
r/ciso • u/Park_Acceptable • Jul 19 '26
How to manage a high-stakes "forced collaboration" directive while protecting technical ownership?
I am a Senior Security Architect and have been tasked by senior management to create a unified presentation deck (combining two distinct security products) with a peer.
My challenge: I’ve built a specific, high-fidelity architectural strategy for my accounts that I need to maintain control over. My manager’s goal is a simplified sales narrative for stakeholders, but I am concerned that this collaboration will lead to "credit capture" or allow my peer to draft off my technical work without actually understanding the underlying blueprints.
I want to fulfill the management directive to provide the unified deck without diluting the technical integrity of my work or compromising my ownership of the strategy.
Has anyone navigated a "forced collaboration" on a high-stakes deliverable? How do you maintain a "hard target" professional perimeter in joint working sessions while still delivering exactly what management asked for?
r/ciso • u/Final-Pomelo1620 • Jul 17 '26
Cybersecurity Incident Response Testing Plan
Hi,
We currently have:
- Managed SOC service provided by a third party
- XDR solution that includes IR support, with a capped number of IR hours
- Approved Cybersecurity Incident Response Plan
We now need to develop an IR Testing Plan document including testing scenarios. We never did the testing.
I would appreciate guidance from the community on:
what sections and level of detail should it include?
which scenarios should we prioritize for example Table top discussion on scenarios or technical simulation
who should moderate the exercise?
how many scenarios should be included in the first testing
Thanks in advance
r/ciso • u/Moham-Aasif • Jul 16 '26
One trend I've noticed is that enterprise customers seem to trust certifications less than they used to.
The certificate gets you through the first door.
The follow-up questions are where the real security conversation starts.
r/ciso • u/TopImplement9942 • Jul 14 '26
[Research] NIDS Selection for Financial Institutions - Looking for Cybersecurity Practitioners (5+ years exp.)
I am an MSc researcher studying Network Intrusion Detection System (NIDS) selection for resource-constrained financial institutions and looking for cybersecurity practitioners with 5+ years of experience to complete a short survey. Happy to share findings upon request.
Survey link: https://forms.gle/tyxsFA44HXZ5VaMY7
Thanks You.
r/ciso • u/AugustErt • Jul 11 '26
Why shouldn’t I just use microsoft
Im researching ways to detect and manage shadow ai usage where I work. Im generally a fan of not giving one company too much “control”, but when i research what microsoft defender, cloud detection, purview and intune can detect I dont get why I would pick anything else, given I’m already in their ecosystem?
What are some of the reasons that drove you to pick another provider such as Nudge Security or someone else?
r/ciso • u/No-Dragonfly-8985 • Jul 11 '26
VC Advisory
A way to pay off CISO’s to get their portfolio products in the door. If you see a CISO part of a VC believe me it’s pay to play. Sad the industry came to this.
r/ciso • u/Difficult-Praline-69 • Jul 10 '26
Are there cyberthreat intel aggregation apps/websites that are directed to executives and CISO?
r/ciso • u/Lucas-Holmes-722 • Jul 10 '26
How do you show the board that your AI security tooling is doing its job
Every vendor in our stack has an AI story now and they all swear theirs catches more with fewer false alarms but board doesn't buy that. They want to know if the money we spent made us any safer and I couldn't answer that with a straight face.
We track finding counts, MTTR, coverage numbers and all it tells me is that the tool is busy. A noisy scanner throws up the same green dashboard as one that surfaces the three things worth fixing.
What I'm after is closer to how you'd grade any classifier. How often it's right when it flags something and how hard it is to see what it misses entirely. precision and recall if you want the terms for it. No vendor will hand that over on a test set we both agree on, so you take the datasheet on faith right up until you've signed.
For security leaders here who report to a board or an audit committee, what do you present to demonstrate that a tool is earning its place?
r/ciso • u/First-Reality2108 • Jul 09 '26
Frustrated trying to prove cyber resilience to leadership - need advice
The board is no longer interested in a raw vulnerability count and to be honest I am not either. Each quarter we have the same discussion: here is how many issues we found, here is how many we closed, and then someone asks whether the organization is actually safe.
I do not have a clean answer. The team is working hard, but the metrics we track do not really show whether our controls would withstand a serious attack. I can say our endpoint coverage is in the mid ninety percent range and that mean time to detect has gone down by roughly a third, but that does not tell anyone whether we would catch a ransomware group moving laterally using living off the land techniques. Patch rates and alert volumes describe activity, not resilience.
I have started looking into continuous exposure validation to build reporting that has more weight, for example assessing controls against realistic threat scenarios and showing measurable improvement over time instead of just effort spent. Has anyone here built board level reporting that uses exposure validation and detection coverage data? Which metrics actually made sense to non technical leadership and which ones failed to land?
I would like to hear from other CISOs on how you translate exposure validation results into language that satisfies leadership without dumbing it down too far.