1. Why CISOs Need To Teach Everyone To Own Risk

    “I identify certain types of risk — operations, privacy, availability — and the key stakeholders who either accept it or not,” said Paul Catalayud, CISO of Palo Alto Networks. “The goal is to reduce that risk to an acceptable tolerance."...

    1. When a CISO is assessing threats, that assessment must start with business alignment and an understanding of what drives the business.
    2. That's something organizations sometimes don't understand.
