Live data from Hacker News

Equifax used records it collects from companies to fire employees with 2nd jobs

businessinsider.com

301–310 of 408 posts

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#301
post #298

Earlier quoted context omitted.

Seriously? It's not the 1990s. You will never convince me that Equifax could not have hired a CISO with decades of relevant IC and leadership experience and appropriate educational background. Perhaps Maudin at the time she was hired, I'm not sure the length of her tenure. But there was certainly no excuse for choosing an MBA without IC cybersecurity experience for her replacement. (Who, btw, is a man and also wildly…

>You will never convince me that Equifax could not have hired a CISO without decades of relevant IC and leadership experience and appropriate educational background. If it's so easy, surely you can name a couple of people with decades of relevant IC and leadership experience and appropriate educational background who they could have hired back when they went with Maudin? >1. Equifax majorly shit the bed on cybersecur…

> surely you can name a couple of people

Yes, I can name dozens of people who would have made excellent CISOs in 2017 and meet my (low) bar of (1) relevant IC experience and (2) some relevant formal training.

> The buck never stops at the CISO, just like it supposedly didn't at Twitter.

If the buck doesn't stop there, it certainly passes through.

Let me flip this around: should you hire a Software Engineer with decades of management experience at a bank to the Chief Financial Officer? What about lawyer who's worked at a hospital to be the Chief Medical Officer? Would you hire an MBA without any legal experience to be your Chief Legal Officer? No, no, and no. If a company did any of those things and shit hit the fan, people would be irate and the company would be rightly criticized.

So why is it okay to fill CTO and CISO roles with MBAs who have no technical training or experience?

It's not, and I don't think juries are going to put up with this over the next couple decades. The "new field" argument is increasingly implausible.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#302
post #298

Earlier quoted context omitted.

>You will never convince me that Equifax could not have hired a CISO without decades of relevant IC and leadership experience and appropriate educational background. If it's so easy, surely you can name a couple of people with decades of relevant IC and leadership experience and appropriate educational background who they could have hired back when they went with Maudin? >1. Equifax majorly shit the bed on cybersecur…

> surely you can name a couple of people Yes, I can name dozens of people who would have made excellent CISOs in 2017 and meet my (low) bar of (1) relevant IC experience and (2) some relevant formal training. > The buck never stops at the CISO, just like it supposedly didn't at Twitter. If the buck doesn't stop there, it certainly passes through. Let me flip this around: should you hire a Software Engineer with decad…

Okay, name one person.

I'm sure it's easy to find lots of qualified people with compsci degrees, but that's not a relevant degree.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#303

Earlier quoted context omitted.

No, the changes to it are going away, not the legislation. It'll be back on contractors to make the determination of IR35 status again

And it's not even certain that this is going away; even if it does, it won't be before the next tax year at the earliest.

By which point we might be onto the next PM. Or the one after that going by the current rate of attrition...

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#304
post #294

Earlier quoted context omitted.

It's not a valid criticism of anyone. Essentially zero people with that kind of work experience have infosec degrees. It's hard to get a formal degree on a subject which isn't taught anywhere! For example: HN loves Mudge, who also happened to just leave a CISO post, and also only holds a music degree from Berkelee.

Another data point, I was reading just yesterday on a HN post about fake qualifications about many male director level people without proper education. They were criticised too. I guess we all see the world as we wish.

We're specifically talking about a field where even a decade ago "proper education" was only offered by a couple of schools in the world.

Compsci is not an infosec-related degree.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#305
post #86

Earlier quoted context omitted.

Instead of paying $12,000/kid/year you could just send them to public school.

Having been through public school in the U.S., I would not send my own child to one if I had any other choice.

I on the other hand went to public school and would send my children to one. Anecdotally, some of the most successful people I know went to public school, many of which had parents that could easily afford to send them to private school.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#306
post #300

Earlier quoted context omitted.

The only person that made this about the CISOs gender is you. OPs point was about the lack of credentials, which would apply to anyone. I think it's a reasonable conclusion to draw, due to the nature of the very sensitive data at risk. Having professional accreditation that you should be overseeing the security of peoples most sensitive information is objectively a good idea. Muddying the conversation with virtual si…

>The only person that made this about the CISOs gender is you. OPs point was about the lack of credentials, which would apply to anyone. Except it seemingly doesn't apply to literally every other CISO. Does the CISO at Meta have a relevant degree? No. Did Mudge have a relevant degree while he was the CISO at Twitter? No, he also had a music degree. Does Coinbase CISO in charge of securing many billions hold a relevan…

The article is about Equifax.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#307

Earlier quoted context omitted.

Depends on the job. There’s a growing trend of people getting remote jobs then just hanging out in Slack/Zoom (camera off, never talking) collecting a check til they get fired. In some cases they’ll outsource some work overseas.

How many of these people can there possibly be? Are there really that many jobs with such low visibility, low expectations that someone can get away with Just Not Working for more than a few days before it’s obvious?

You know, I thought the same thing. Then I encountered 3 over the last month at 2 different companies I consult with.

Stuff is weird right now.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#308
post #304

Earlier quoted context omitted.

Another data point, I was reading just yesterday on a HN post about fake qualifications about many male director level people without proper education. They were criticised too. I guess we all see the world as we wish.

We're specifically talking about a field where even a decade ago "proper education" was only offered by a couple of schools in the world. Compsci is not an infosec-related degree.

Independent of if the criticism is valid, it isn't gender motivated.

I'll agree the criticism isn't valid.

I disagree about the invalid criticism being gender biased or motivated.

The subject just happens to be female. That doesn't exempt them from valid or invalid criticism.

This isn't difficult really.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#309
post #302

Earlier quoted context omitted.

> surely you can name a couple of people Yes, I can name dozens of people who would have made excellent CISOs in 2017 and meet my (low) bar of (1) relevant IC experience and (2) some relevant formal training. > The buck never stops at the CISO, just like it supposedly didn't at Twitter. If the buck doesn't stop there, it certainly passes through. Let me flip this around: should you hire a Software Engineer with decad…

Okay, name one person. I'm sure it's easy to find lots of qualified people with compsci degrees, but that's not a relevant degree .

> Okay, name one person.

My current employer's CISO or my former employer's equivalent of the CISO. Both were hired prior to 2017 and had relevant education and expertise. And no, I'm not going to risk doxing myself to someone accusing me of sexism for saying that CTO/CISO roles should be filled by people with relevant education.

> Compsci is not an infosec-related degree.

Are you kidding me? I am beginning to lose confidence in any ability to have a reasonable conversation with you.

Four years of CS cover a lot of material that is directly relevant to information security, even without any formal coursework in security. Most CS degrees require several years of programming, an Operating Systems course, and courses like Networking, Cybersecurity, and Cryptography are often offered as electives. Even the basic courses offer a lot of basic knowledge about the work being managed.

Is it everything you need? No, of course not! That's why the criteria -- from my first post -- is BOTH relevant education and also relevant IC experience.

What is inappropriate is a CISO who has never written or read a single line of code, never configured a piece of IT equipment, etc. It would be like a CLO who has never read a legal brief or a chief medical officer who has never treated a patient. They won't even have a basic high-level understanding of what's actually going on in the work they are managing. I've seen this, first hand, from a (male) executive who did not have a technical background.

Re: Equifax used records it collects from companies to fire employees with 2nd jobs

#310

Earlier quoted context omitted.

You get a lot of this up here in Canada. Companies hire you as a contractor, but prohibit you from working other roles.

I'm pretty sure this isn't legal in most provinces.

It isn't, but everyone does it, including the federal government.
Post reply on HN