How CEOs Think (2020)
blog.erratasec.com
blog.erratasec.com
There is a flaw in how CEOs think here.
One flaw is that "outside" consultants are steered by those skilled at corporate politics. The consultants know which faction hired them, and thus, tilt their "unbiased" advice toward that faction. Having been a consultant myself, it's the hardest ethical question I face: how do I maintain my own integrity in the face of the client trying to spin/tilt my reports?
The second flaw is that CEOs are measuring their companies against equally conservative peers. All of them resist some innovation that could reduce costs because none of them have tried it yet. Thus, there's obvious things that all the techies can see, and yet, the organization resists because none of their peers have tried it yet. Yes, CEOs don't want to excel at cybersecurity, to be the leader in their industry with the best cybersecurity, but this thinking stops them from being even slightly above average.
The third flaw is that consultants are dumb as rocks. They are just random people who have gone through some training who don't have to be responsible for the long term consequences of what they do. They don't reflect the best practices that the industry is doing so much as the dumbest. Most times an organization hires outside consultants there's smarter people inside the organization fighting against the dumb things the consultants are doing.
All this means that instead of getting the "average" or "slightly above average" out of these outside consultants, CEOs are getting the "below average". Their IT (and cybersecurity) is slowly sinking, except for the insiders who fight against this.
Thus, we have the fight the tweet describes above. The CEO has an extraordinarily broken view of cybersecurity.