Reactive vs Proactive Security – A Balancing Act for CISOs

No ratings

Presented at CISOExchangeEast 2019 by

Reactive and proactive security methods do not have to be mutually exclusive — we must plan how to respond when an intrusion does occur, whether it comes from worms and viruses, DDOS attacks, social engineering or even from disgruntled employees with insider knowledge of the network. For comprehensive defense, a reactive security strategy should be paired with a proactive strategy and effective tools for uncovering, identifying, and responding to potential threats before they have the chance to damage a company. Every business needs to decide the appropriate mix of resources to devote to proactive security measures (to deter attacks), and reactive measures (to respond to attacks that get through).