Cyber Insights · Episode 10

Why CISOs Can't Fix Cybersecurity (And What Actually Works)

Dr Paul Guckian, Author, Systematic Cyber Risk
· 37 min
  • Why CISOs are snipers fighting a general's war
  • The difference between cyber knowledge and cyber understanding
  • How organisations reach tipping points where recovery becomes impossible

Prefer your own app? Spotify · Apple Podcasts

About this episode

“Just defend better and you won't need resilience.” It is a logic trap that is burning out CISOs, and the premise may be wrong.

Dr Paul Guckian, author of Systematic Cyber Risk: Why CISOs Can't Fix Cybersecurity, joins Ronan Murray and Ian Finlayson to explain why cybersecurity needs systemic answers. Drawing on research across financial services, fire safety and military cyber command, he challenges the perfectionist mindset common in security teams.

PG
Guest
Dr Paul Guckian
Author, Systematic Cyber Risk

Paul is the author of Systematic Cyber Risk: Why CISOs Can't Fix Cybersecurity.

In this episode

  • Why CISOs are snipers fighting a general's war
  • The difference between cyber knowledge and cyber understanding
  • How organisations reach tipping points where recovery becomes impossible
  • Why containment deserves its own pillar in security frameworks
  • What the contrast between Delta and United Airlines reveals about cyber resilience
  • Why compliance gets you to level 3 maturity, but rarely beyond
  • Why you have to assume your security will fail
Want to see where your gaps are?
Security Posture Review · Assessment
See the Security Posture Review
Ian Finlayson

Got a question about cyber resilience?

Talk to Ian. Ian Finlayson, Chief Security Services Officer at Edge7 Networks, is happy to talk through what this looks like for your environment.

ISO 27001:2022 · ISO 9001:2015 · Cyber Essentials · Networking and security specialists since 2018