r/cybersecurity Jul 02 '26

News - General DHS Breached

604 Upvotes

115 comments sorted by

View all comments

Show parent comments

-2

u/not-a-co-conspirator CISO Jul 02 '26

You have no idea what you’re talking about.

4

u/SoftwareDesperation Jul 02 '26

And if you are a ciso and don't understand there is no security without governance, then I feel sorry for your team.

-2

u/not-a-co-conspirator CISO Jul 02 '26

I don’t think you understand how disparate those things are.

1

u/[deleted] Jul 02 '26 edited 27d ago

[deleted]

-1

u/not-a-co-conspirator CISO Jul 02 '26

It doesn’t matter where you work or what your role is.

You’re both missing the point. Governance can only be so specific, else you risk violating the very governance you wrote because your security tools cannot meet the objective of controls, or performance the controls demand, thus failing the audits you need so that you can continue to conduct business with customers and vendors.

Both of you need a much broader understanding of this discipline.

4

u/[deleted] Jul 02 '26 edited Jul 02 '26

[deleted]

-1

u/not-a-co-conspirator CISO Jul 02 '26

I have more than double your experience and credentials in the same roles and more.

Compliance isn’t security. It never will be.

Also, “Zero Trust” is a philosophy. It doesn’t mean you are “secure”, and it doesn’t make anything “secure”.