National Cyber Warfare Foundation (NCWF) Forums


Cybersecurity Insights with Contrast CISO David Lindner | 09 20 24


0 user ratings
2024-09-20 19:12:24
milo
Blue Team (CND)

Insight #1: Don't shrug off this internet plague!




Cross-site scripting (XSS) is the overlooked vulnerability plaguing the web. As Contrast’s

recent attack data show, it's everywhere, yet it’s often dismissed as “'low risk.” The truth? This prevalence makes XSS more of a threat, and it's easily exploited. Fortunately,

Application Detection and Response (ADR) is here to help you stop it!


 


Insight #2: Finding root cause doesn't always solve the problem 




Root cause analysis is not just about figuring out the technical problems that may have occurred, as Forbes describes. Technical problems rarely exist in isolation. They often occur within the context of a larger process or workflow. If that process is inefficient, it can create conditions that make technical problems more likely to occur, or harder to detect and fix.




 


Insight #3: Fixing culture helps fix security 




So many interesting interactions with peers over the last few months are making me realize that there is still a major disconnect between finding and fixing vulnerabilities and the culture that drives it. Too many security leaders don't care about culture and care more about resolving risk. But I would argue that creating a positive security culture will naturally help to address vulnerabilities faster (

mean time to respond/remediate [MTTR]) and create less vulnerabilities as time goes on (

vulnerability escape rate [VER]). Why can't we get over this hump?






The post Cybersecurity Insights with Contrast CISO David Lindner | 09/20/24 appeared first on Security Boulevard.



David Lindner, Director, Application Security

Source: Security Boulevard
Source Link: https://securityboulevard.com/2024/09/cybersecurity-insights-with-contrast-ciso-david-lindner-09-20-24/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.