The Secrets of Cybersecurity Consulting

John McCumber

John McCumber is a cybersecurity executive, retired US Air Force officer, and former Cryptologic Fellow of the National Security Agency. In addition to his professional activities, John is a former Professorial Lecturer in Information Security at The George Washington University in Washington, DC and is currently a technical editor and columnist for Security Technology Executive magazine. John is the author of the textbook Assessing and Managing Security Risk in IT Systems: a Structured Methodology

Related Post Roulette

3 Responses

  1. InMD says:

    Actually consultants don’t accept any risk. It always says so right in their contracts.Report

  2. JS says:

    Another sensible reason to bring in an outside security consultant for occasional reviews is for the same reason it’s good sense to let someone else proof-read your work.

    Outside eyeballs help.

    Your internal experts know what they know — bringing in a fresh set of eyes that might know something ELSE is useful! And your internal folks are so used to the problems they routinely face, that they might not see other lurking dangers.

    Not that anyone ever listens. Security is expensive and a hassle to employees, so nobody cares until they’re burned.Report