Personal tools
You are here: Home wikidblog On the short tenure of CISOs and low-frequency, high-impact events
« August 2008 »
Mo Tu We Th Fr Sa Su
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Recent comments
Re:Security and Oil admin Apr 25, 2008
Re:Security and Oil Paul feet Apr 24, 2008
Re:100% open source admin Apr 22, 2008
Re:100% open source Adam Apr 22, 2008
Re:Capital Gains Tax Rates and Entrepreneurs Lance Oct 23, 2007
 

On the short tenure of CISOs and low-frequency, high-impact events

I came across this post which pointed to this article on how to hedge funds can write a series of naked puts on low-probability events and look like geniuses. I have equated this to the information security market before and I have pointed out other posts about low-frequency, high-impact events.

This is an agency problem in many ways. What occurred to me was that this same logic is probably impacting the average tenure of CISO/CSOs. If you're a CISO and you have not had a high-impact event at your company, then chances are: 1. You will be viewed positively by potential employers; 2. The likelihood of a high-impact event that would be your responsibility at your current employer is getting higher; 3. Any high-impact event at a new job could be blamed on a predecessor for some time.

Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.