How I Became a vCISO
I have a lot of passion for my role as a Virtual Chief Information Security Officer (vCISO) for financial institutions, and I am always happy to tell...
3 min read
Chris Bedel : Mar 6, 2020
“You're trying to take our jobs.”
I think the comment was half joking, but also half serious.
It was four years ago, and I was presenting to a group of bank technology officers on the concept of the virtual Information Security Officer (vISO). I get to the end of my presentation where there's comments and questions. And the very first one that flies out from the group was just that:
“You're trying to take our jobs.”
I look around the room and there were a lot of head nods in agreement. “Ok. This isn’t going to be easy…” I say to myself. The thing is, it wasn’t true back then and it’s definitely not the case now.
BankDirector.com did their Annual Risk Survey in 2019 and found that of the participants surveyed, 53% of banks don't have a dedicated information security officer and 33% don't have one at all.
If you’re in the 33%, you can stop reading this now and go directly here: https://www.bedelsecurity.com/the-cyspot-program
But if you're in the 53%. This, this blog post is for you.
You might be saying yourself: “But Chris. Do we really need a dedicated information security officer? Why do they have to be dedicated?”
That's a great question.
In this case, the term dedicated means that your ISO or CISO aren’t dual purpose. They aren’t wearing multiple hats. And that can be hard for most community banks and credit unions. That’s why going virtual for this role can be extremely beneficial in a lot of circumstances.
So I've come up with five reasons why, even if you have a named information security officer, you should consider a virtual information security officer (vISO) or virtual chief information security officer (vCISO) at your financial institution:
So I think from those five items you can see, we're not trying to take anybody's jobs. This is about being a resource and providing help where help might be needed. This is about making people's lives easier.
And I hope this blog post is open your perspective to what the possibilities are of engaging with a vISO or vCISO, or at least find at least finding out more about it.
If you'd like to know more, shoot me an email at chris@bedelsecurity.com and we can set up a 10 or 15 minute chat.
I have a lot of passion for my role as a Virtual Chief Information Security Officer (vCISO) for financial institutions, and I am always happy to tell...
While the definition of a partner is fairly broad, its principles apply to a very broad spectrum of relationships. In the cybersecurity realm, this...