Latest news
Make sure the organisation is compliant with all relevant and updated government, federal and international laws
This is becoming more and more important, particularly as organisations such as the European Union Commission plan to hit enterprises that suffer data losses with huge fines. The IT security landscape will soon be one where breaches are not purely just a PR disaster, but a financial disaster as well. Your job, as well as your promotion, depends upon steering clear of this elephant trap.
Be aware of your internal PR
Run your own internal PR campaign . This is not as bizarre as it sounds. If organisations have to run PR campaigns to get themselves known in the big wide world then you should do the same to get noticed within your own organisation. This means capitalising on every time you speak at a seminar, an internal event, a sales conference or a presentation in front of the company.
Also, keep your boss up-to-date about IT security trends with clippings and snippets from recognised news outlets — make sure you do this as they happen.
Talk to the marketing and public relations people in your organisation, learn from them and make sure they are aware of you and what you are doing. They may ask to use you as a spokesperson, but tactically you may want to put forward your boss as a spokesperson. It is important to build your profile outside of the organisation so make sure that you use LinkedIn and other business networking sites.
2. Make your boss look great
Keep to your budget
Budgets used to be more flexible. Today, in this era of extreme bean counting when accountants rule the world, budgets are absolutes. Quantify what you are delivering – how is IT security making a difference to the bottom line of the company. If IT security isn't seen as a strategic asset then you could face a battle for resources. More importantly, you will not be seen as a leader who has taken these questions into account.
If you can communicate how the IT security staff is delivering hard value your boss will look good to the bean counters and shareholders. There are no exceptions to this rule.
Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





