Chapter 20
Ten Tips for Getting Security Buy-In
Dozens of key steps exist for obtaining the buy-in and sponsorship that you need to support your security testing efforts. In this chapter, I describe the top ten I find to be the most effective.
Cultivate an Ally and a Sponsor
Although recent breaches and compliance pressures are helping push things along, selling security to management isn’t something you want to tackle alone. Get an ally — preferably your direct manager or someone at that level or higher in the organization. Choose someone who understands the value of security testing as well as information security in general. Although this person might not be able to speak for you directly, he or she can be seen as an unbiased sponsor and can give you more credibility.
Don’t Be a FUDdy Duddy
Sherlock Holmes said, “It is a capital mistake to theorize before one has data.” To make a good case for information security and the need for vulnerability testing, support your case with relevant data. However, don’t blow stuff out of proportion for the sake of stirring up fear, uncertainty, and doubt (FUD). Managers worth their salt can see right through that. Focus on educating management with practical advice. Rational fears proportional to the threat are fine. Just don’t take the Chicken Little route, claiming that the sky is falling with everything all the time. That’s tiring to those outside of IT and security and will only hurt you over the long haul.
Demonstrate How the Organization ...
Get Hacking For Dummies, 5th Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.