Why Vanta Wants Boards to Measure Cyber Risk in Business Terms
The Business of Cybersecurity by Neil C. Hughes
Episode notes
In this episode of The Business of Cybersecurity, I speak with Khush Kashyap, Senior Director of Governance, Risk, and Compliance at Vanta. Khush began her career as a software engineer before moving into cybersecurity, giving her a builder’s view of governance and operational resilience.
Our conversation begins with the UK Cyber Security and Resilience Bill and the demands it could place on managed service providers, data centers and designated suppliers. Proposed reporting windows could require an initial notification within 24 hours and a fuller incident report within 72 hours. Khush explains why organizations should map their supplier dependencies, define reporting responsibilities and rehearse those deadlines before a real incident tests them.
We then examine what Vanta calls security theater. Khush argues that teams have spent y ...