Insight #2: Finding root cause doesn't always solve the problem
Root cause analysis is not just about figuring out the technical problems that may have occurred, as Forbes describes. Technical problems rarely exist in isolation. They often occur within the context of a larger process or workflow. If that process is inefficient, it can create conditions that make technical problems more likely to occur, or harder to detect and fix.
Insight #3: Fixing culture helps fix security
So many interesting interactions with peers over the last few months are making me realize that there is still a major disconnect between finding and fixing vulnerabilities and the culture that drives it. Too many security leaders don't care about culture and care more about resolving risk. But I would argue that creating a positive security culture will naturally help to address vulnerabilities faster (mean time to respond/remediate [MTTR]) and create less vulnerabilities as time goes on (vulnerability escape rate [VER]). Why can't we get over this hump?
David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.
Get the latest content from Contrast directly to your mailbox. By subscribing, you will stay up to date with all the latest and greatest from Contrast.