# CISO

Published articles for CISO.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management

DevFeed: [Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management](<https://devfeed.tech/articles/australia-is-replacing-the-essential-eight-with-a-new-cyber-framework-here-s-how-exposure-management-can-help-you-get-ahead-of-it-26585.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management>)

Author: Ben Mudie

Published: 2026-09-15T13:32:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [australia](<https://devfeed.tech/tags/australia.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [essential-eight](<https://devfeed.tech/tags/essential-eight.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [identity](<https://devfeed.tech/tags/identity.md>), [operational](<https://devfeed.tech/tags/operational.md>), [organization](<https://devfeed.tech/tags/organization.md>)

### AI overview

The article describes Australia's replacement of the Essential Eight with an outcomes-focused cybersecurity framework covering enterprise IT, cloud, operational technology, and potentially agentic AI. It argues that organizations will need continuous evidence of their security posture, and presents exposure management as a way to identify and prioritize weaknesses and support current posture validation.

### Source excerpt

Australia's move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI. The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT. The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports. In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments. Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture. ASD's strategic shift to active security posture validation Can you prove your security posture is solid, right now, on demand? That's the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization's board, CISO, and C-suite. ASD's decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance. It's no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question: Ho

## EU DORA compliance for engineering teams

DevFeed: [EU DORA compliance for engineering teams](<https://devfeed.tech/articles/eu-dora-compliance-for-engineering-teams-12263.md>)

Original publisher: [Read original article](<https://www.port.io/blog/navigating-the-eus-digital-operational-resilience-act-eu-dora>)

Author: John Crowley

Published: 2026-06-02T13:42:24Z

Content type: article

Language: en

Sources: [Developer Experience & Platform Engineering Blog | Port](<https://devfeed.tech/sources/developer-experience-platform-engineering-blog-port.md>)

Topics: [Resilience](<https://devfeed.tech/topics/resilience.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [systems](<https://devfeed.tech/topics/systems.md>), [monitor](<https://devfeed.tech/topics/monitor.md>), [Software](<https://devfeed.tech/topics/software.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [eu](<https://devfeed.tech/tags/eu.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [operational](<https://devfeed.tech/tags/operational.md>), [operations](<https://devfeed.tech/tags/operations.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [software](<https://devfeed.tech/tags/software.md>), [systems](<https://devfeed.tech/tags/systems.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This article explains how the EU Digital Operational Resilience Act (DORA) affects engineering teams supporting financial services in the EU. It outlines requirements for ICT asset inventories, incident reporting, operational resilience testing, and third-party risk management, and describes the need for accurate software ecosystem information and automated workflows.

### Source excerpt

Understand how the EU Digital Operational Resilience Act (DORA) affects engineering teams, the four core compliance pillars, and how to streamline audit readiness.

## The Real Role of the Field CISO

DevFeed: [The Real Role of the Field CISO](<https://devfeed.tech/articles/the-real-role-of-the-field-ciso-39501.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/the-real-role-of-the-field-ciso>)

Author: phil7672

Published: 2026-04-04T13:32:43Z

Content type: article

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [reliability](<https://devfeed.tech/topics/reliability.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [reliability](<https://devfeed.tech/tags/reliability.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article discusses the role of Field CISOs and argues that security and reliability increasingly support sustainable, long-term customer success.

### Source excerpt

We all need to advance our businesses and that is in many respects about selling. We also need to recognize that security and reliability are increasingly the path to sustainable long term customer success - which is your success. This is where the Field CISOs come in. There are many more people that are becoming, so called, Field CISOs and many more organizations that are creating Field CISO teams under a variety of structures and names. Let's look at what Field CISOs are, why they exist,...

## The CISO's Craft: Watchmaker or Gardener?

DevFeed: [The CISO's Craft: Watchmaker or Gardener?](<https://devfeed.tech/articles/the-ciso-s-craft-watchmaker-or-gardener-39499.md>)

Original publisher: [Read original article](<https://www.philvenables.com/post/the-ciso-s-craft-watchmaker-or-gardener>)

Author: Phil Venables

Published: 2026-01-24T16:39:53Z

Content type: opinion

Language: en

Sources: [Risk and Cyber](<https://devfeed.tech/sources/risk-and-cyber.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [craft](<https://devfeed.tech/tags/craft.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [precision](<https://devfeed.tech/tags/precision.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article considers whether security leaders should operate more like precise watchmakers, adaptive gardeners, or both when leading organizational transformations. It also argues that cybersecurity benchmarking should focus on control effectiveness and outcomes rather than inputs such as budgets.

### Source excerpt

Some time ago I saw a comment about the distinction between acting like a "watchmaker" or a "gardener" when undertaking organization transformations. I misplaced the original reference so, unfortunately, I can't credit appropriately. But, I've been thinking a lot about what this would mean in the context of security leadership. Specifically, should the CISO be a watchmaker or a gardener, or both? The Watchmaker CISO: Precision and Control Imagine a master watchmaker, meticulously crafting...

## Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece

DevFeed: [Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece](<https://devfeed.tech/articles/seeking-symmetry-during-att-ck-season-how-to-harness-today-s-diverse-analyst-and-tester-landscape-to-paint-a-security-masterpiece-8340.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/seeking-symmetry-attck-season-harness-todays-diverse-analyst-tester-landscape-paint-security-masterpiece/>)

Author: Márk Szabó James Shepperd Ben Tudor

Published: 2025-12-10T15:03:51Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [incident](<https://devfeed.tech/tags/incident.md>), [industry](<https://devfeed.tech/tags/industry.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [practitioner](<https://devfeed.tech/tags/practitioner.md>), [report](<https://devfeed.tech/tags/report.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article explains how security practitioners can interpret and connect cybersecurity reports and tests from analyst firms and independent testing labs. It focuses on endpoint security, including product evaluations, feature testing, broader market analyses, and assessments against known advanced adversary attacks, to support more informed protection-stack and purchasing decisions.

### Source excerpt

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

## Empowering women in security: The impact of mentorship

DevFeed: [Empowering women in security: The impact of mentorship](<https://devfeed.tech/articles/empowering-women-in-security-the-impact-of-mentorship-7904.md>)

Original publisher: [Read original article](<https://snyk.io/blog/empowering-women-in-security-the-impact-of-mentorship/>)

Author: Erin Cullen

Published: 2024-11-27T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [career-development](<https://devfeed.tech/tags/career-development.md>), [career-growth](<https://devfeed.tech/tags/career-growth.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [community](<https://devfeed.tech/tags/community.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer](<https://devfeed.tech/tags/developer.md>), [industry](<https://devfeed.tech/tags/industry.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [security](<https://devfeed.tech/tags/security.md>), [series](<https://devfeed.tech/tags/series.md>), [snyk](<https://devfeed.tech/tags/snyk.md>)

### AI overview

This article explores how mentorship and allyship can help women enter and advance in cybersecurity. It highlights supportive leaders, non-traditional career paths, advocacy for promotions and raises, and the importance of confidence, collaboration, and professional networks in building a more inclusive security community.

### Source excerpt

In the Women Leading Security series, Snyk CMO Jonaki Egenolf spoke with influential leaders about challenges and opportunities in the journey toward a more inclusive cybersecurity industry.

## How Axel Springer National Media and Tech achieved continuous security with Snyk

DevFeed: [How Axel Springer National Media and Tech achieved continuous security with Snyk](<https://devfeed.tech/articles/how-axel-springer-national-media-and-tech-achieved-continuous-security-with-snyk-7838.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axel-springer-national-media-and-tech/>)

Author: Nina McClure

Published: 2024-09-03T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk-code](<https://devfeed.tech/topics/snyk-code.md>), [Static code analysis](<https://devfeed.tech/topics/static-code-analysis.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Development](<https://devfeed.tech/topics/development.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [customer](<https://devfeed.tech/tags/customer.md>), [customer-featured](<https://devfeed.tech/tags/customer-featured.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [iac](<https://devfeed.tech/tags/iac.md>), [interest](<https://devfeed.tech/tags/interest.md>), [megawatt](<https://devfeed.tech/tags/megawatt.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [security](<https://devfeed.tech/tags/security.md>), [shift-left](<https://devfeed.tech/tags/shift-left.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [snyk-code](<https://devfeed.tech/tags/snyk-code.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This customer story describes how Axel Springer National Media and Tech adopted Snyk after Log4Shell to help developers find and fix vulnerabilities earlier. It covers the implementation of Snyk Code and Snyk Open Source within existing development processes, alongside developer-managed IaC on AWS and security responsibilities shared across teams.

### Source excerpt

Find out how Axel Springer's National Media & Tech business division uses Snyk to empower its developers to find and fix vulnerabilities in their own code.

## Developer and CISO perspectives on software supply chain security

DevFeed: [Developer and CISO perspectives on software supply chain security](<https://devfeed.tech/articles/top-10-things-devs-want-their-ciso-to-know-13295.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/top-10-things-devs-want-their-ciso-to-know>)

Published: 2024-05-09T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [communications-gap](<https://devfeed.tech/tags/communications-gap.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [developers](<https://devfeed.tech/tags/developers.md>), [security](<https://devfeed.tech/tags/security.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [shared-responsibility](<https://devfeed.tech/tags/shared-responsibility.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

This article presents ten insights from Chainguard and Harris Poll's 2023 CISO & Developer Trends in Software Supply Chain Security Report. It describes developers' concerns about security tools, productivity, communication, shared responsibility, expertise, organizational priorities, and tensions between developers and CISOs.

### Source excerpt

Bridge the dev-security gap! Learn essential insights for fostering a collaborative, secure development environment.

## Day in the life of a food giant CISO

DevFeed: [Day in the life of a food giant CISO](<https://devfeed.tech/articles/day-in-the-life-of-a-food-giant-ciso-7882.md>)

Original publisher: [Read original article](<https://snyk.io/blog/day-in-the-life-food-giant-ciso/>)

Author: Vandana Verma Sehgal

Published: 2024-04-18T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [engineering-culture](<https://devfeed.tech/topics/engineering-culture.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [governance](<https://devfeed.tech/tags/governance.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [management](<https://devfeed.tech/tags/management.md>), [organizational](<https://devfeed.tech/tags/organizational.md>), [product-security](<https://devfeed.tech/tags/product-security.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [strategy](<https://devfeed.tech/tags/strategy.md>)

### AI overview

This developer-focused interview profiles Sherif Mansour, Just Eat's Director of Information Security, and discusses his career, Just Eat's three-line information security model, and his responsibilities across platform security, cloud and infrastructure, product security, application security, security engineering, culture, and awareness. It also describes organizational leadership principles and a themed weekly schedule for managing priorities.

### Source excerpt

Snyk's Vandana Verma Sehgal sat down with Sherif Mansour, the Director of InfoSec at JustEat, for a "Day in the life of a CISO" session to learn more about his day-to-day experience as a security leader.

## Reporting AppSec risk up to your CISO

DevFeed: [Reporting AppSec risk up to your CISO](<https://devfeed.tech/articles/reporting-appsec-risk-up-to-your-ciso-8067.md>)

Original publisher: [Read original article](<https://snyk.io/blog/reporting-appsec-risk-to-your-ciso/>)

Author: Kate Powers Burke; Ezra Tanzer

Published: 2024-02-13T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [blog](<https://devfeed.tech/tags/blog.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [security-tools](<https://devfeed.tech/tags/security-tools.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains how AppSec teams can report prioritized application security risk to CISOs. It emphasizes clear reports, concise risk summaries, holistic visibility across code-based assets and software supply chains, and contextual prioritization beyond vulnerability counts and scores.

### Source excerpt

Learn what information CISOs need to know about your application security program in order to have a clear understanding of risk.

## New report shows disconnect between developers and security teams on software supply chain security priorities and responsibilities

DevFeed: [New report shows disconnect between developers and security teams on software supply chain security priorities and responsibilities](<https://devfeed.tech/articles/new-report-shows-disconnect-between-developers-and-security-teams-on-software-supply-chain-security-priorities-and-responsibilities-13182.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-report-shows-disconnect-between-developers-and-security-teams-on-software-supply-chain-security-priorities-and-responsibilities>)

Published: 2023-11-08T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [developers](<https://devfeed.tech/tags/developers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [software-developer](<https://devfeed.tech/tags/software-developer.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [software-supply-chain-security-research](<https://devfeed.tech/tags/software-supply-chain-security-research.md>), [survey](<https://devfeed.tech/tags/survey.md>)

### AI overview

Chainguard and The Harris Poll released a 2023 survey of CISOs and developers about software supply chain security. The report found that both groups consider it important but differ in their views of security awareness, responsibilities, tooling, and associated risks.

### Source excerpt

Chainguard's new report reveals a crucial gap between developers and security teams on software supply chain priorities.

## Securing Diversity in Cybersecurity

DevFeed: [Securing Diversity in Cybersecurity](<https://devfeed.tech/articles/securing-diversity-in-cybersecurity-20345.md>)

Original publisher: [Read original article](<https://engblog.nextdoor.com/securing-diversity-in-cybersecurity-6aa83dafb850?source=rss----5e54f11cdfdf---4>)

Author: Kristen Beneduce

Published: 2023-05-02T13:01:51Z

Content type: opinion

Language: en

Sources: [Nextdoor](<https://devfeed.tech/sources/nextdoor.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [ciso](<https://devfeed.tech/tags/ciso.md>), [culture](<https://devfeed.tech/tags/culture.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [diversity](<https://devfeed.tech/tags/diversity.md>), [engienering](<https://devfeed.tech/tags/engienering.md>), [events](<https://devfeed.tech/tags/events.md>), [inclusion](<https://devfeed.tech/tags/inclusion.md>), [industry](<https://devfeed.tech/tags/industry.md>), [innovation](<https://devfeed.tech/tags/innovation.md>), [rsa-conference](<https://devfeed.tech/tags/rsa-conference.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Nextdoor discusses the representation gap in cybersecurity and its partnership with WiCyS Silicon Valley during an RSAC 2023 diversity event. The article highlights barriers affecting women in cybersecurity and argues that diverse teams improve problem-solving and innovation.

### Source excerpt

Panelists from Left to Right: Ronit Polak (Moderator), Kathy Wang* , Lea Kissner, Rupa Parameswaran, Olivia Rose, Jameeka Green Aaron *Correction: Kathy Wang is the former, not current CISO of Discord At Nextdoor we build technology that empowers resilient, safe, and kind neighborhoods all over the world. Securing a product that empowers global communities requires diverse and inclusive teams, reflective of the communities we support. Yet hiring and retaining the diverse talent needed to achieve our purpose remains an industry challenge. The gap is particularly evident in the cybersecurity field where 25% of the workforce and 16% of CISOs identify as female. According to the WiCyS State of Inclusion report 2023, women cite lack of respect and limited opportunities for growth in cybersecurity as top challenges accompanying lack of representation. We must keep working on it. That is why Nextdoor welcomed the chance to celebrate diversity, alongside RSAC 2023, in Nextdoor HQ's backyard this week and to partner with our neighborhood Women in Cybersecurity (WiCyS) Silicon Valley chapter. We are committed to building a diverse and inclusive workplace, and we are proud to work with organizations like WiCyS, who share the same values. Nextdoor's CISO TC Niedzialkowski kicked off with a warm welcome. CEO Sarah Friar framed the discussion by sharing how she launched her career by building a network at her first RSA conference as an equity analyst for Security Software at Goldman Sachs. She emphasized that diverse teams bring a variety of perspectives and experiences to the table, which ultimately leads to better problem-solving and innovation. Left to Right: Tanvi Kolte Tiwari (WiCyS Silicon Valley Events Chair) introducing the panel, Attendees soaking into a fantastic intro by Sarah Friar (Nextdoor CEO) , TC Niedzialkowski (Nextdoor CISO) cheering on the panel Moderator Ronit Polak, WiCyS Silicon Valley President, and CISOs Kathy Wang Lea Kissner Rupa Parameswaran Olivia Ros

## The Uber CSO indictment

DevFeed: [The Uber CSO indictment](<https://devfeed.tech/articles/the-uber-cso-indictment-37012.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-uber-cso-indictment/>)

Author: Adam

Published: 2020-08-28T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [infosec](<https://devfeed.tech/topics/infosec.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [disclosure](<https://devfeed.tech/tags/disclosure.md>), [ftc](<https://devfeed.tech/tags/ftc.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [law](<https://devfeed.tech/tags/law.md>)

### AI overview

An analysis of the Uber CSO indictment and Mark Rasch's essay on concealing and failing to report a data breach. The article emphasizes due process for Joe Sullivan and argues that the case may make organizations and lawyers more cautious about breach disclosures, potentially reducing their usefulness for learning from mistakes.

### Source excerpt

Thoughts on Mark Rasch's essay, Conceal and Fail to Report - The Uber CSO Indictment