Security Culture

Episode 145 of Task Force 7

Add bookmark

As noted in our recent CISO Strategies & Tactics for Incident Response, establishing a security culture with clear communication is an imperative. Some say awareness is simply the first step and that infusing the organization with a cyber security culture and consciousness is an ultimate goal.
Jeff Campbell, Chief Information Security Officer, Horizon Power is one such executive, “It’s about making incident response part of an automatic reaction. Ensuring there is a cyber security culture. Making sure there’s a state of mind around what cyber security is - so when things happen you know what to do, and it’s almost natural. If a staff member accidentally clicks on an
email, and then realizes and has that, “Oh, s#!%,” moment,
then they automatically know what to do. That’s bringing
incident response forward.” This week's TF7 guest agrees.

Episode Overview:

How CISO's create an Information Security Strategy varies greatly from organization to organization. One particular challenge is creating a strategy for a tech startup with very little resources. The Vice President of Information Security for Daily Pay, Jeffrey Hudesman, talks about the biggest threats FinTech companies are facing, how they are combating these threats, how he works to establish a security culture in his organization, and how important are security certifications like ISO 27001 to smaller companies. Hudesman also comments on how important timely threat intelligence is, how he goes about implementing red teaming operations in a FinTech, and how he sees the role emerging technologies play in the security posture of a small startup. 

Listen Now:


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended