Accidental CISO Profile picture
I accidentally became the CISO. I didn't want this job, but the job chose me. I'm scared, and I want to go home.
Sep 14, 2021 12 tweets 2 min read
Shadows
There are flashes of forever
in the glintings of the past.
The shadows make predictions
through the images they cast.

By the eerie light of memories
glowing deep inside the heart.
Phantom silhouettes are dancing
ghosts of fears that will not part.

1/x I wrote this poem 22 years ago and it still haunts my memory today. A few years later, my wife painted this painting in school. As soon as I saw it, I associated it with this poem.
Sep 12, 2021 4 tweets 1 min read
While it is absolutely possible to prepare for a SOC-II audit without outside help, I recommend that startups without a CISO engage outside help as a part of that strategy. A vCISO or consulting company can help bring clarity to the roadmap and accelerate execution. Especially since most organizations don't decide to pursue SOC-II until there is customer pressure for it and sales are jeopardized. Timing and success become critical.
Sep 8, 2021 12 tweets 2 min read
Hiring for entry-level roles presents an interesting challenge that I hadn’t anticipated, though, in hindsight, I should have.

When prior experience isn’t required, and there is significant interest in the role, narrowing down candidates to interview is a real problem. 1/x With “senior” roles, we can look for specific experience or skills to compare resumes and test against some minimum bar. We can look at the types of that orgs candidates have worked for, and what achievements they choose to highlight.