[Opinion] Its High Time ….

The recent spate of cyber-attacks has served as an eye-opener for many organizations and individuals. Organizations that were using unpatched software had no security teams, no incident response policy, and procedures, etc. clearly were the ones who had to bear the maximum brunt of such attacks. There were many who did not get affected as they took the right steps at the right time and gave due importance to security and security teams in their organization. Lots of points mentioned below have been long debated in organizations. But it’s high time that they are taken seriously and religiously implemented. CISO/CSO should be a part of Board Meetings In most organizations, security is still considered an IT job. The CSO reports to either the CIO or admin's head or some senior business person. The organizations mostly appoint a CSO just to ensure that regulatory compliance (in some countries) is taken care of. They are really not interested in consid