T O P

  • By -

LiferRs

I talk with my CISO every week for a F100 company. Trust me, he’s just another human with his wife, problems at home like having a contractor come in during a meeting to patch the roof, and walks his dog outside while on the phone. Just ask the person about what the career path was to be where they are today.


throwaway96wa

100%. I know that I’m not going to be bothering them bunch of work related question. I’m sure they are busy as it is. But, it would be interesting to hear their opinion on certain topics. Could be an eye-opener.


Odd-Condition7752

Most CISO's like to talk, so if you have a handful of things you want to talk to them about, you're golden!


BlacknWhiteMoose

Tits or ass?


DarkKooky

Thighs


throwaway96wa

After tits


throwaway96wa

Tits all the way


Academic-Skill-9923

Ass


brandeded

Now a question of etiquette: As I pass do i give you the ass or the crotch?


eew_tainer_007

Are you a grabber ?


brandeded

"*The* grabber." Always use the indefinite article.


GreyBar0n86

If you had an unlimited budget, which country or state would you attack ? How and why ?


he_who_breaks_things

Interesting question. Much more of a political opinion based question but a good one none the less.


GreyBar0n86

It's that or what do they look for in cyber operative exactly ? How can I become one ?


throwaway96wa

That’s a question for google


GreyBar0n86

True enough


throwaway96wa

That’s a good question. But, they will probably not going to answer that.


Ssyynnxx

probably tits or ass


throwaway96wa

Tits gang


-Zunfix-

What are you most worried about in the upcoming years? (So I know what to prepare for and skills I can build) What skills are the most valuable to grow to be in upper level positions like yours? Which zero day attack are you most worried about?


BooneTumbleweed

How could someone know in advance what zero day attacks to be worried about?


hexdurp

Firewall attacks. It’s been popping off lately


BooneTumbleweed

If I had to pick a subset of zero days to be concerned about it would either be VPN (like with ivanti) or RCE for obvious reasons.


-Zunfix-

Was meant as a slight joke lol, I’d have the confidence to ask them if the conversation was upbeat and positive to see their reaction


throwaway96wa

Noted! I will ask about the zero day to see their reaction 😂


-Zunfix-

I’d be curious to hear what the answers are for them as well. Would you be willing to say who it is or if they are military?


throwaway96wa

When/if I ask, I will post an update with the answers. I don’t want to say who because we just play sports together, but they work at the pentagon.


-Zunfix-

Gotcha that’s super cool. So you are in cybersecurity and play sports with them and just wanna see if you can pick their brain sometime? Tbh I don’t hear of many people that high up having personal time for hobbies or stuff like that so I’m impressed they just go out and do that for fun


mildlyincoherent

Presumably it's another log4j style event - - a RCE on ubiquitous software. Something that is used / embedded everywhere, tied to systems that process user input, and can be triggered past the ingress point.


olderby

Where do you need help?


throwaway96wa

Do you mean like which areas in cyberspace?


olderby

Yes where can practitioners focus to better improve cyber security nationally? What initiatives is the government taking to protect citizens?


Sportsfun4all

Do you guys have nice racks?


throwaway96wa

Now I have to ask this question 😂


SupermarketCool6965

Why do they not give a damn about cybersecurity? When asked why do you mean , ask why are they not offering better salaries to retain talent. As a ctr they are bleeding on the civilian side and mil side , and I’ve seen alot of CTR cap out and plan to leave as well . If not for salary it’s def bc there are so many holes they are over worked, plenty of people saving -and investing and more interested in building an escape plan from working vs being able to enjoy the field as much as they used to.


SupermarketCool6965

Also why are they not actually hiring by 8140 ? Its almost two years old


AmIAdminOrAmIDancer

Why public service for you? What has been your worst day in security? How are you doing, honestly? If this is an informal chat you’d be surprised how much the last one can endear them to you and you’ll see their demeanor change. If it’s an interview whether job or media/school id keep it as professional as possible.


throwaway96wa

It’s more on personal setting. I keep it informal with them, but every now and then, I’m itching to ask them cyber related questions.


WOTDisLanguish

Assuming I hadn't had anything planned, which I don't - it's a reddit post: * What got you into cyber? * What are some things you've worked on? * What are the threats to look out for in 2024-2025? * How is your organization working towards addressing them? * What is the most pressing issue in the industry? * What's the most memorable finding you've come across in your career? * What is your dream scenario for cybersec? * What's your favourite RFC? * What, and who do you think the threat of the future (5-10 years out) is? * How can we prepare for it? * Where do you plan on bringing your organization in 5 years time? * What are your thoughts on people using cybersecurity as a shield to justify non-security-related actions?


shavedbits

What's up with burnout in cyber security? Something something Artificial Intelligence something something? Have you ever regretted or questioned going into the field? Has anything in cyber security ever scared you? Why can't we secure our power grid and other public infrastructure? What's one thing people misunderstand about CISOs?


Revandir

Since you said a gov official, I'd say, what's your plan to keep up with current market trends for policy and security? AI is a catch up game, there are hundreds of iterations of policies that reference themselves in a cyclical manner, how do we stay ahead? I know I'd get a bs answer, but there's always a hope.


throwaway96wa

Noted!


reignbowmagician

How thin is the line between harrassment and research?


Just-the-Shaft

How quickly do you respond to CISA RFIs, and why is it so slow?


WackSnackAttack

Depends on the agency. If DoD, I’d ask what they’re doing to get China out of our shit. If treasury, I’d ask why they aren’t banning more China and Russia products used for espionage. If CISA, I’d ask what the hell they’re thinking with CIRCIA (total fedgov overreach, in my opinion). If DOE, I’d ask when they’re going to fund the much needed backbone upgrades for our fractured energy grid.


throwaway96wa

It’s DoD. I’ll ask about our “fragile” energy grid.


Weekly_Opposite_1407

I would ask the how I saw someone else’s phone UI in a pop up window that instantly disappeared. The only reason I know it exists is because I had a screen recording and went frame by frame and took a screenshot


throwaway96wa

On your computer or on your phone?


Weekly_Opposite_1407

On my phone.


knister7

Boobs or back


throwaway96wa

Dont forget elbows and ankles


maidata

Would you hire me if i can showcase my skills


throwaway96wa

Apply online


YT_Usul

My first and only question would be: May I speak to one of your engineers, please? You can discover almost everything a leader knows in a 60 minute chat with an engineer reporting under them, as well as determine how healthy the organization is (and likely where most of the risk is). Any leader that hides their team is instantly suspect of being a fraud. Now, the questions to ask that engineer could get pretty spicy! Those are the interesting ones. First question: Talk to me about data.


throwaway96wa

I like this!


bzImage

since 95% of the ransomware enters via email.. what security measures are in place to prevent that ?


LionGuard_CyberSec

Hello there!


MaskedPlant

What has the government done to help prevent the next Crackas With Attitude type of doxing?


peteherzog

I'd ask why does your government let ICANN profit off of criminals rather than remove domain names from obviously fraudulent domains? Why not put pressure on them to address this?


Derpolium

Bourbon or pepto?


throwaway96wa

You mean bourbon AND pepto


Derpolium

Preach


VicTortaZ

Do I need to introduce myself or do you know more about me than I know about myself?


StringLing40

It was like talking to Spider-Man because they had a lot of responsibility.


throwaway96wa

That’s funny. What would you ask Spider-man then?


StringLing40

Where is your safe place where you don’t need to worry about anything? Jesus would go off alone, almost like he was hiding from the overwhelming pain of the world he was bombarded with. Monks and religious people do the same it seems as do famous people, very clever people and very powerful people….if they care that is.


wijnandsj

Why the fuck are you guys always using such weird contracting procedures? Why are you afraid of anyone actually doing something new?


throwaway96wa

I can answer your second question. New innovations are out there. You just have to go and find it. What do you have in mind in terms of doing something new?


wijnandsj

let me give you two examples from my own work the past few years. Example 1. Public transport company is looking for onboard firewalls and puts out an RFP. We submit an offer. We've found an equipment manufacturer who makes a device with all the necessary ratings and approvals and some to spare. We've got a reference dealing with firewall management in industrial environments, another in vehicle security and a substantial software development team for a similar company in a neighbouring country. Turned down because we had no previous experience in this. Well duh! They were at that time one of only a handful of companies worldwide looking to do this. Went to a company who makes and implements the boxes. Example 2. SOC for a utility company. We've got a multitenant SOC, including industrial companies and a utility company (different sort but still a utility company) in a neighbouring country as a reference. We submit two dozen CVs of engineers and consultants with relevant industrial experience. Turned down because we did not have any experience in-country with that kind of utility. So this one went to the company that already had a majority share on the market. That's what I mean. Governments tend to give the contracts to parties that are already doing it regardless of creating a monopoly, regardless of quality


Playful-Shock5174

Looking to get into this where should I start


throwaway96wa

Get into what?


Playful-Shock5174

Overall cyber security


Nightpain9

Just tell him I said thank you!


throwaway96wa

Will do!


eew_tainer_007

Why are you so complacent ? Is the assurance and guarantee of government job security, health insurance, pension one of the reasons behind such complacency ? What are you doing about this malaise ?


young--geezer

Will you hire and train me, please?


hackedhitachi

Bobs or vagen?


throwaway96wa

They seemed like the vagen type


barefacedstorm

What’s the point if you know we turn on our own so easily?


throwaway96wa

Care to elaborate?


barefacedstorm

Not without seeing some serious money.


throwaway96wa

I will you give time. Time is gold.


barefacedstorm

I’ve been through those circles already, what good is time unless you have the things you want already. Need seed capital at some point in some situations.


Feisty_Potato_7365

Did biden poop his pants?