← All talks

Overcoming Obstacles in Operationalizing Security

BSidesSF · 201836:29168 viewsPublished 2018-04Watch on YouTube ↗
Speakers
Tags
CategoryCareer
StyleTalk
About this talk
Rafae Bhatti - Overcoming Obstacles in Operationalizing Security: A Tale from the Trenches So you got an offer letter to manage or lead a security team at a startup. You create a lofty security strategy that encompasses all of the advice you got from your peers together with textbook security principles. As you roll up your sleeves and get going, you quickly realize that an ambitious strategy, even when combined with genuine security expertise and advice, won’t take you too far if it does not anticipate all the obstacles you are likely to face. And this is where the rubber meets the road. This talk will describe some of these obstacles, contrasting the textbook strategies often discussed or written about with the real world challenges faced by security teams, particularly at smaller startups. It is based on actual first few months of a startup CISO on the job, chronicling the experiences related to operationalizing the security strategy while battling limited budgets, vendor fatigue, and talent shortage. Using illustrative scenarios, it will guide security professionals on what challenges to anticipate when implementing their security strategy, and provide practical pointers on how and when to make sensible trade-offs.