Earlier quoted context omitted.
Seriously? It's not the 1990s. You will never convince me that Equifax could not have hired a CISO with decades of relevant IC and leadership experience and appropriate educational background. Perhaps Maudin at the time she was hired, I'm not sure the length of her tenure. But there was certainly no excuse for choosing an MBA without IC cybersecurity experience for her replacement. (Who, btw, is a man and also wildly…
>You will never convince me that Equifax could not have hired a CISO without decades of relevant IC and leadership experience and appropriate educational background. If it's so easy, surely you can name a couple of people with decades of relevant IC and leadership experience and appropriate educational background who they could have hired back when they went with Maudin? >1. Equifax majorly shit the bed on cybersecur…
Yes, I can name dozens of people who would have made excellent CISOs in 2017 and meet my (low) bar of (1) relevant IC experience and (2) some relevant formal training.
> The buck never stops at the CISO, just like it supposedly didn't at Twitter.
If the buck doesn't stop there, it certainly passes through.
Let me flip this around: should you hire a Software Engineer with decades of management experience at a bank to the Chief Financial Officer? What about lawyer who's worked at a hospital to be the Chief Medical Officer? Would you hire an MBA without any legal experience to be your Chief Legal Officer? No, no, and no. If a company did any of those things and shit hit the fan, people would be irate and the company would be rightly criticized.
So why is it okay to fill CTO and CISO roles with MBAs who have no technical training or experience?
It's not, and I don't think juries are going to put up with this over the next couple decades. The "new field" argument is increasingly implausible.