Chairman & Founder, Ponemon Institute

Joined March 2009
Photos and videos
15 Jul 2014
Thank you for a lovely chat! I look forward to Tweeting again. Be well! #infosecchat
2
15 Jul 2014
A7 Enterprise risk management should own the BCM and the CISO roles. BCM and CISO should be joined at the hip. #infosecchat
3
15 Jul 2014
@PaulRob35443448 @IBMSecurity Good point. The planning for physical incidents is likely to be 80% of what you need for cyber #infosecchat
2
15 Jul 2014
If you don't have a structured remediation plan, get one. Consultants can help. #infosecchat
3
3
15 Jul 2014
A5 The best way to reduce recovery time is to have a structured remediation plan in place. #infosecchat
1
15 Jul 2014
A4 The CISO needs to lead the CSIRT. The CIO should be supportive of the process, but not the leader. #infosecchat
3
3
2
15 Jul 2014
Companies that engage BCM in CSIRT tend to have fewer silos and silo thinkers! #infosecchat
1
15 Jul 2014
A3 BCM improves the incident response process. #infosecchat
15 Jul 2014
Mega breaches like Target are difficult to measure because they are rare events. #infosecchat
1
1
15 Jul 2014
A2 In general, you need smart people, good technologies and good luck! #infosecchat
1
15 Jul 2014
@gwbdmcReputation-related costs are important, but often overlooked by security leaders. #infosecchat
15 Jul 2014
A1 ABC requires the allocation costs against specific activities. The activity centers we look at totals 181 categories. #infosecchat
1
15 Jul 2014
A1 The best approach is Activity Based Costing. Thanks for asking. #infosecchat
1
15 Jul 2014
@IBMSecurityHowdy folks! Great to be here! #infosecchat
1
15 Jul 2014
@poore27Welcome to the discussion! #infosecchat
15 Jul 2014
Hello everyone! #infosecchat
1
1
15 Jul 2014
Good morning! I look forward to today's chat #infosecchat
2
1
15 Jul 2014
Greetings! Any interest in seeing our latest study on critical infrastructure? If so, send your request to research@ponemon.org.
15 Nov 2012
Did you see the Edelman Privacy Risk Index, which we helped develop? See edelman.com/privacy-risks/ for more info.

1
1
2
24 Aug 2012
One follower said "People are the greatest security risk for organizations." Do you agree?
2
2
2