#CTODailyDose - Impact of Equifax on IT

4:43 · Watch on YouTube ↗

Transcript 607 words · about 4 min to read

Auto-generated captions from YouTube, not hand-corrected, so names and technical terms may be imperfect. The video is authoritative.

hey how's it going to skew bouncing from the CTO of Viacom with today's CTO daily dose again a high level technology conversation hopefully within the time that it takes us unless they take to drink your favorite caffeinated beverage so what does equal fax target sarbanes-oxley what does all three of those have in common when it comes to I T and I T governance the my argument is that all three have created the catalyst to have a business conversation that wasn't had prior to the onset of

those events so sarbanes and I clean created this overhead of compliance that went all the way up to the board of directors and we saw that at the board of directors at many companies we'd have a compliance officer or a compliance audit lead sitting on a board of director his primary responsibility was to ensure that the organization was represented accordingly when it comes to audist simply sauce main is Sarge maintenance actually that wasn't necessarily always the case some companies had had a audit representative on the

board and other companies didn't so a new role industry-wide for most publicly traded companies then the target hack the target had brought IT proper back into the purview of the board of directors that that was a very high-profile hack and board started to understand that this concept of cross system authentication was a issue that if a hacker got into a system sitting in a secured area they then have access to all the systems that will lateral to that system microsegmentation don't know exactly what that is

but microsegmentation is a solution and I'm speaking from the board's perspective is a solution to this problem so we saw massive investment in technologies such as VMware NSX and the ability to micro segments were closed from machine to machine and these were actually board driven initiatives VMware would tell you that board of directors are having conversations and initiatives around micro segmentation that's you can't get much geekier in the conversation there micro segmentation so what does this have to do with eco fix well this a hundred

and forty seven 147 million consumers impacted this is a big big deal week just controls if you think there is a room or something about admin admin been a username and password for secure database we're just gonna see board of directors helping and I'm using help and a liberal sense helping IT and information security technology by having security experts sit on the board of directors so you're gonna see a lot more intense involvement from the business I don't know if this is a good thing or

a bad thing I guess anytime the business pays its instant attention to security is always a good thing but we've get we've gotten help before from the business when it comes to ite IT security it is well intentioned but you know sometimes it can be a hammer trying to slice expect more help from the business when it comes to security as a result of these hacks just like we get budget and recommendations or directions to micro second maintained our networks will also get a lot of

external advice from the folks at like PwC the loading twos people we don't necessarily think of when we think about IT and IT security we'll start getting a lot of input from those folks whether we want to or not that's it for this CTO daily dose talk to you guys next episode follow the hashtag hashtag CTO daily dose to get more of the content