Stop Boiling The Ocean! How To Succeed With Small Gains

No ratings

Presented at GrrCon2018 2018 by

Trying to do to much in infosec will actually wind up causing harm, because your attention gets diverted and important things wind up aging. Infosec is also a very complex set of problems and solutions. It’s typical for managers and practitioners to get caught up in everything and try to do it all at once. This means spreading yourself too thin, and very likely your efforts are falling short. For organizations with small security staff or budgets, a proper information security program can seem like a very daunting task, and it is. Whether you are large or small, improvements over time can also help bolster the security posture of organizations. This is called aggregation of marginal gains, and it’s been used successfully in many situations. It’s harder to see, but easy to measure, and in information security any improvement is a good improvement. The cool thing is you don’t have to stop at just infosec. There is power in small wins and slow gains. This talk will discuss the small improvements organizations can make to improve a security program, whether it is in inception or fully in gear. We will focus the importance of making better decisions on a daily basis. Find out ways to manage and measure progress, and discuss how to benefit from incremental improvement. The core of this talk seeks to address one simple question: how can I do better each day?