Listen "Beyond the Blinky Lights: Why Security Governance Drives Technology with Bryant Tow"
Episode Synopsis
In this eye-opening episode of SecureTalk, host Justin Beals welcomes Bryant Tow, Chief Security Officer at LeapFrog Services, to discuss why technology alone can't solve cybersecurity challenges. Bryant reveals how the "Ring of Security" concept shows that up to half of your attack surface lies outside of technology—in governance, policies, people, and processes. The conversation explores real-world examples like the Change Healthcare breach, why security frameworks often fall short, and how building a culture of security requires connecting protection of company assets to personal security concerns.Key TopicsThe Change Healthcare breach: How a single oversight led to a $2.9 billion loss despite substantial technology investmentsWhy frameworks like CIS are great starting points but insufficient on their ownHow the "Ring of Security" approach addresses the complete attack surfaceBuilding a security culture that resonates with employees on a personal levelWhy a business impact analysis is critical but often missing from frameworksThe importance of understanding your data before implementing AI solutionsNotable Quotes"When you do the root cause analysis on headline breaches, nearly all of them started somewhere outside the technology." - Bryant Tow"Even if you do your technology perfectly, you're leaving half of your attack surface open." - Bryant Tow"Strategy drives governance. Governance drives operation." - Bryant TowAbout the GuestBryant Tow serves as Chief Security Officer at LeapFrog Services, where he assists clients with comprehensive security programs including strategy, governance, and operations. Previously, he owned Cyber Risk Solutions and served on the Department of Homeland Security Sector Coordinating Council. His "Ring of Security" concept emphasizes that cybersecurity is an organizational problem that uses technology as just one tool in the solution.Resources MentionedThe "Ring of Security" conceptCIS Framework limitationsBusiness Impact AnalysisAI Readiness AssessmentDepartment of Homeland Security Sector Coordinating CouncilSecureTalk is hosted by Justin Beals, focusing on cybersecurity strategy, governance, and best practices for organizations of all sizes.
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.