{"id":4341,"date":"2024-07-05T09:00:30","date_gmt":"2024-07-05T14:00:30","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/why-cyber-teams-should-invest-in-strong-communicators"},"modified":"2024-07-05T09:00:30","modified_gmt":"2024-07-05T14:00:30","slug":"why-cyber-teams-should-invest-in-strong-communicators","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/05\/why-cyber-teams-should-invest-in-strong-communicators\/","title":{"rendered":"Why Cyber Teams Should Invest in Strong Communicators"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte74972ce4eeb272c\/667c7409f84d4a6ca82e3ccc\/communicate-Jacob_Lund-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity is a discipline filled with hard problems. Cybersecurity professionals are charged with protecting a rapidly evolving technology landscape from adversaries that are not constrained by profitability, productivity or employee privacy \u2014 and they need only a single security control to fail for them to be successful.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Today&#8217;s cyber landscape requires an organization that can swiftly discover, discuss, and mitigate risks while also driving a culture of security that ensures every employee understands their role in protecting the organization. Curating a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/creating-a-security-culture-where-people-can-admit-mistakes\" rel=\"noopener\">security culture<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that swiftly abates risk requires a cybersecurity team of excellent communicators.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Effective communication is foundational for fostering a security-conscious culture within an organization. Cybersecurity staff must possess the ability to clearly articulate complex technical issues in a manner that is understandable even to nontechnical stakeholders, including executives, managers, and employees across various departments. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/how-cisos-can-craft-better-narratives-for-the-board\" rel=\"noopener\">Simplifying technical language<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> without losing the essence of the message ensures that everyone is on the same page regarding the nature of threats and the importance of security measures. Clear, concise, and jargon-free explanations help demystify cybersecurity, making it more accessible and less intimidating to the average employee.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security teams must be adept at active listening. This involves not only understanding the concerns of and feedback from different organizational units, but also identifying underlying issues that may not be immediately apparent. By actively listening, security professionals can gain valuable insight into potential vulnerabilities and areas where security protocols may need reinforcement. This two-way communication fosters a sense of collaboration and trust, which is critical for a security culture to thrive.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity teams must also communicate effectively with external stakeholders, including clients, partners, and regulatory bodies. Transparent communication about the organization&#8217;s security posture, incident response capabilities, and compliance with industry standards builds trust and confidence. In the event of a security breach, clear and honest communication is crucial for managing the situation, maintaining customer trust, and fulfilling legal and regulatory obligations.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Clear Communication Is a Human Skill\">Clear Communication Is a Human Skill<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Communicating effectively about security topics absolutely requires a base level of technical knowledge. Understanding the output of a vulnerability scan requires understanding the packages involved, the systems impacted, their external exposure, and the necessary mitigation steps to assess the effort it will take to resolve a vulnerability.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, when facing a hiring decision between two candidates, both of whom have the requisite technical skills to interpret the output, choosing the one who can more effectively communicate the impact of the vulnerability scan will mitigate the risk at hand better than the candidate who can execute the remediations. Additionally, the ability to articulate complex technical concepts in clear and understandable language is crucial for fostering collaboration among various customers and stakeholders, ultimately enhancing the organization&#8217;s overall security posture.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Advancements in technology have also lowered the technical requirements within a number of cybersecurity disciplines. Continuing with the vulnerability management example, validating findings used to be a massive time sink, requiring deep technical knowledge of an infrastructure. However, with recent disruptors in the vulnerability-scanning space, some scanning platforms can now discover network topology, access controls, secrets management, and more without the need for manual control. This has resulted in technology platforms being able to contextualize vulnerability findings, prioritizing those that <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/choices-for-stronger-vulnerability-management\" rel=\"noopener\">pose the most risk<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> based on Internet adjacency and other factors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This has lowered the technical requirements for people tasked with managing vulnerabilities within an environment. It is now more important for them to be able to explain the risk of a vulnerability to the engineering team responsible for patching than to rank the risk of a vulnerability themselves. A solid communication of risk, in a language that the system engineer responsible for patching will understand, will result in lower times for vulnerabilities to live.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/why-cyber-teams-should-invest-in-strong-communicators\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY Cybersecurity is a discipline filled with hard problems. Cybersecurity<\/p>\n","protected":false},"author":12,"featured_media":4342,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4341","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/why-cyber-teams-should-invest-in-strong-communicators.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4341"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4341\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4342"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}