Skip to main content

Part three of Play Your Position, a Cyberleaf series on the lessons in Ken Dryden's The Game. This one takes on "don't put JV in a pro game" from the buyer's side.

Don't Put JV in a Pro Game, with Cory Brasel →Why Orchestration Matters More as You Grow, with Cory Brasel →

My job at Cyberleaf is to take what a good security program should look like and figure out how we deliver it. Prior to Cyberleaf, I was a CIO. Bringing together people, processes, and technology is what I've been good at, understanding the technical parts well enough to cut through the noise and get something done.

Earlier this month our CEO, Jeff Buss, wrote a piece on what Ken Dryden taught him about defending the net. One of the lessons, “don't put JV in a pro game,” got me thinking about how that looks to the person doing the buying.

The businesses we work with tend to have IT staff covering a lot of ground. Security sits on a list with everything else competing for their time. Meanwhile the business grows and keeps adding tools. Given daily competing priorities, the teams don't have enough time to see how all the pieces play together, or to look across all the tools to make sure they have the cybersecurity gaps covered. It's worth taking the time to understand where there may be gaps in your cybersecurity posture and what risks those create. Then clear out the tech debt as needed and ensure you're orchestrating what you have.

When I get on a call with a customer, the questions are usually about their stack and what tools contribute to the overall picture. Cost is part of it, but what matters more is who's managing each one and whether it's doing what you bought it to do.

Funny enough, I rewrote one of my own slides a while back. It used to list the tools we support, and I took them off. Vendors will tell you that if you buy this one thing, you'll be good, but it's never one tool. It's the orchestration of the tools to accomplish the overall objectives, and the people who help you wield them.

JV puts the endpoints on and says, “we're good, the tools are protecting us.” A pro takes those same tools and adds governance and policies, then keeps looking at the posture and asking, “What could we do better?” Some of that is unglamorous work, like data pipelines, deep analysis of the data, constant SIEM tuning, reviewing and updating asset lists, vulnerability scans, and more. It's a chore, and it often gets skipped due to time.

If I were looking at my own setup, I'd want to know how much I'm hearing from whoever handles my security. I'd want the visibility that the people, processes, and technology are all working together harmoniously. Communication and constant vigilance with your security team are key. There's never an “okay, we're good” moment. You're always managing risk. Kind of like when you clean the house, right? You keep on going, you get done, and you start over again.

– Cory

Originally published on LinkedIn by Cory Brasel, Chief Product Officer at Cyberleaf.