The article doesn't really say anything beyond "CTrO positions exist and think tanks think they're not a trend."
The article doesn't really say anything beyond "CTrO positions exist and think tanks think they're not a trend."
> Peake, a former CISO, said a lot of the skills from his previous role have translated into his current one. However, he said the CTrO role differs from the CISO role because it operates more on the “business level,” as the work done by a CTrO can directly impact revenue generation, contract negotiation, and onboarding new customers.
In my view, it's a role that sits between Sales and Security. A major part of the role is getting customers and prospects information about your business and security controls to validate their own needs (e.g. compliance requirements). It's still a semi-technical role, but isn't necessarily focused on the nut-and-bolts of ground-level security.
The Trust officer is an outward-facing role.
The corpos yearn for regulations
Always look at who is requesting more regulation. Make sure they’re doing it for the right reasons and not simply to build moats that small companies can no longer cross. It can be a form of regulatory capture to propose the regulations in the first place.
The nuts-and-bolts security still falls to a CISO. This role is more about bridging the gap between security teams and customers. The Trust officer might have influence over high level roadmap items ("our customers are asking about X"), but the actual implementation will still land with the CISO.
"We're really sorry it broke again, it wont happen again.. again"
(*requires healthy economy)
For one it’s always been easier to not get caught than to do the work. And even people who do the work will generally agree with that. It’s not about easy it’s about looking yourself in the mirror.