Honest question: how can a financial services company not have an in-house infoSec team?
To me, this is an even more concerning issue. But then, I have no idea how the finance services world works, so maybe this is more common than I think?
To me, this is an even more concerning issue. But then, I have no idea how the finance services world works, so maybe this is more common than I think?
Outsourced CISO/InfoSec is a valid and reasonable thing for some companies.
If I was running a financial services startup, those groups would be near the front of my list in terms of internal hiring.
But again, since it's not always easy to find the right people I end up having to fill in for everything we don't have a team member to execute on.