Lenny Zeltser 09月29日 10:49
CISO活动赞助与参与
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

组织网络安全领导者会议需要大量努力和赞助。然而,一些会议和社区排除了为安全供应商工作的CISO。这种立场虽然出发点良好,但损害了行业并允许隐藏的利益冲突未受控制。本文探讨了这一问题及其解决方案,以改善此类会议和整个社区。

🔍 CISO尊重等级通常基于其雇主类型,大型企业和金融服务机构的CISO最受尊重,而安全供应商的CISO则处于较低位置,尽管所有类型的CISO都面临着相似的挑战并贡献重要价值。

🤝 赞助是CISO会议的主要资金来源,允许供应商展示产品、进行广告宣传和扩展品牌影响力。通常,会议会设立专门时段供赞助商发言,有时要求发言人非销售或市场人员,而CISO是理想人选。

🚫 某些会议禁止安全供应商的CISO参与,目的是维持收入来源、允许开放讨论和确保参与者是实际CISO而非销售人员。然而,这种“全有或全无”的方法无法解决潜在的利益冲突,例如参与者的投资或咨询关系。

🧱 更好的方法是实施透明行为准则,要求与会者避免在非指定论坛推广产品、披露利益冲突或退出相关讨论,并尊重不同意见和背景。这有助于建立包容且富有成效的社区。

🤝 所有公司都是某些人的供应商,我们希望供应商拥有强大的安全计划。允许所有类型的CISO参与,包括安全供应商的CISO,有助于促进行业增长和建立健康的关系。

Organizing events that gather cybersecurity leaders requires significant effort and sponsorships. Unfortunately, some events and communities exclude CISOs who work for security vendors. This stance, though well-meaning, harms the industry and allows hidden conflicts of interest to go unchecked. Here's why and how we can address this issue to improve such events and the community at large.

CISOs of All Types

Industry veteran Andrew Hay once posted a tongue-in-cheek "CISO hierarchy of industry respect." At the top were security leaders of Fortune 500 companies. Further down were CISOs at financial services or insurance firms. Lower, the CISOs at hardware vendors. Closer to the bottom were the CISOs working for a cybersecurity vendor; hi, that's me!

The respect hierarchy was meant as a joke, and CISOs took it as such. It was funny because there was something truthful about it. Some executives command more respect among their peers than others. CISOs who work at large organizations have to deal with more complexities and command larger budgets than those who work for smaller firms. Yet, no matter the type or size of the organization, CISOs are dealing with many challenges and have much to contribute to the community.

Sponsorship of CISO Events

Hosting events incurs costs for the venue, food, and organizer salaries. Typically, these costs are covered by vendor sponsorships, which allow vendors to present, advertise, and otherwise expand their brand equity.

Therefore, CISO gatherings sometimes include designated sessions where the sponsors discuss their commercial products. Sometimes, the organizers ask the sponsors to present "thought leadership" content that doesn't overtly pitch products. For such presentations, the organizers often require that the speaker not be in sales or marketing. If the vendor has a CISO, that person is often a good candidate.

When well-orchestrated, this approach to covering event costs benefits all stakeholders: the organizers, attendees, and vendors.

Excluding Security Vendors' CISOs from Events

Some events restrict CISOs from security vendors to only attend sessions sponsored by their employer. In doing this, the organizers aim to:

These are reasonable objectives; however, banning security vendors' CISOs from events is a poor way of achieving them.

This jackhammer, all-or-nothing approach creates the appearance of an environment that facilitates an unbridled exchange of ideas and opinions. Yet it doesn't address overt conflicts of interest and vendor relationships of attendees who might:

When events ban CISOs of cybersecurity vendors but allow the possible issues above unchecked, they merely create the appearance of establishing an environment free of vendors' involvement or other undesirable interference.

Moreover, all of us who work for commercial companies are somebody's vendors. And we want our vendors to have strong security programs with knowledgeable leaders. We often want to meet these leaders, establish relationships with them, and perhaps even learn from them. By failing to create an environment that allows CISOs of all organizations, even security vendors, to participate, organizers get in the way of our industry's growth.

How to Organize Events for All CISOs

There is another way. Many CISO communities successfully include all types of security leaders. How do they facilitate fruitful discussions while allowing security vendors' CISOs, such as me, to participate? They enforce transparent rules of conduct, which require attendees to:

Establishing these rules requires intentionality, but it is possible and effective. I've seen it create thriving communities that benefit all stakeholders and advance our industry. If you're a CISO attending a security event, ask whether security vendors' CISOs are allowed to participate in the entire event. If not, encourage organizers to adopt these rules or refer them to this article.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

CISO 网络安全 会议赞助 利益冲突 行业社区
相关文章