Sign in to view Mariano’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Mariano’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Boston, Massachusetts, United States
Sign in to view Mariano’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
11K followers
500+ connections
Sign in to view Mariano’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Mariano
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Mariano
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Mariano’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Articles by Mariano
-
Mythos & GPT-5.4-Cyber: The Upcoming AI-Driven Vulnerability Surge in SAP
Mythos & GPT-5.4-Cyber: The Upcoming AI-Driven Vulnerability Surge in SAP
Frontier AI models like Claude Mythos demonstrate an unprecedented capability to autonomously discover zero-day…
89
-
Built For and By SAP Defenders: Not a Tagline, But an Origin StoryMar 12, 2026
Built For and By SAP Defenders: Not a Tagline, But an Origin Story
There are defining moments that test whether a company’s positioning reflects real substance. For us, one of those…
84
9 Comments -
Innovating to Secure the Future of SAP: 2025 Year in ReviewJan 8, 2026
Innovating to Secure the Future of SAP: 2025 Year in Review
Key Takeaways from 2025: If 2024 brought SAP application security into the mainstream, 2025 was the year urgency…
96
1 Comment -
Our Enduring Impact: Protecting the Global Economy, One Enterprise Application at a TimeDec 3, 2025
Our Enduring Impact: Protecting the Global Economy, One Enterprise Application at a Time
Today, I’m thrilled to share that Onapsis has been recognized by Inc.’s Best in Business awards for three categories:…
153
10 Comments -
The SAP Cybersecurity BookMar 11, 2025
The SAP Cybersecurity Book
A much-needed resource is finally here. Onapsis CTO & Co-Founder Juan "JP" Perez-Etchegoyen and Guarav Singh have…
95
5 Comments -
SAP and Onapsis Partner to Help Customers Detect and Respond to Cybersecurity IncidentsDec 11, 2024
SAP and Onapsis Partner to Help Customers Detect and Respond to Cybersecurity Incidents
With cybersecurity data breaches and ransomware attacks on the rise, it is increasingly important to have a plan in…
127
8 Comments -
Accelerate Your RISE with SAP Transformation with the New Onapsis Secure RISE AcceleratorNov 19, 2024
Accelerate Your RISE with SAP Transformation with the New Onapsis Secure RISE Accelerator
As the CIO of a global organization turning to RISE with SAP to modernize your SAP environments in the cloud, you may…
106
5 Comments -
Time to Act: Safeguard Your SAP PlatformAug 20, 2024
Time to Act: Safeguard Your SAP Platform
As the CEO and Co-Founder of Onapsis, I have the privilege of leading a team dedicated to securing the critical…
61
-
New Threat Intelligence: Threat Actors Targeting SAP for Profit - Questions CIOs & CISOs Should Be AskingApr 17, 2024
New Threat Intelligence: Threat Actors Targeting SAP for Profit - Questions CIOs & CISOs Should Be Asking
With over 400,000 customers globally, including 99 of the 100 largest companies in the world, SAP is a foundational…
102
1 Comment -
SEC's New Regulations Impose SOX-like Urgency on ERP Systems, Now in the Cybersecurity DomainSep 12, 2023
SEC's New Regulations Impose SOX-like Urgency on ERP Systems, Now in the Cybersecurity Domain
Cybersecurity events have unfortunately become commonplace. However, the severity and the frequency of these attacks…
92
7 Comments
Activity
11K followers
-
Mariano Nunez shared thisFollowing the OpenAI / Hugging Face incident reports, there's a huge debate right now in AI and cyber circles about whether: - Better security measures in the eval environment would have helped to prevent this. - People are (over?)anthropomorphizing the behaviour of the agents behind the attacks. My take? Both discussions miss what's truly "urgent and important". Whether the agents should have been able to "escape" in the first place is irrelevant when real-world adversaries don't need to worry about safeguards. Are we attributing human-like intent and awareness to code that's simply optimizing to achieve an objective and reward-hacking? It's an exciting philosophical debate, but it's not the immediate threat we face. We should be spending all our time focused on how we tackle what the incident means in practice: agents can already autonomously coordinate the execution of highly sophisticated attack campaigns, persisted over days and executing at incredible velocity. The existing security paradigms protecting the critical infrastructure underpinning our society were already struggling to prevent and detect attacks that have been historically constrained by adversaries' human knowledge, resources, and intent. That constraint is no longer present. Understanding how we will *quickly* evolve our defenses against this new reality is the only thing that matters right now. This challenge is so huge that we should focus all our energy on it, and defer the finger-pointing and philosophical debates until after we solve this.
-
Mariano Nunez shared thisVery excited about this new CrowdStrike + Onapsis partnership. Great co-innovation and collaboration between our product teams to ensure customers can close a major blind spot in their Exposure Management programs: The world's leading SAP cybersecurity exposure, now 100% integrated and available within Crowdstrike. Learn more through the article below, and next week live at #Falcon! Álvaro Del Hoyo Manene Ansel Thomas Pablo R.as Pablo R. Sadik Al-Abdulla Alex Horan Pablo Müller Mark Francetic Lauren McKinneyMariano Nunez shared thisAdversaries weaponize SAP vulnerabilities in minutes. Enterprise SOCs can't afford ERP blind spots. That’s why Onapsis and CrowdStrike have deepened our partnership. We’ve integrated Onapsis Assess with CrowdStrike Falcon Exposure Management (FEM) to bring deep SAP intelligence into a single console. What are the key benefits? - Complete Visibility: Eliminate the gap between SAP and your SOC. - Smart Prioritization: Focus on real-world exploitability, not raw volume. - Rapid Response: Neutralize attack paths before business disruption. Mariano Nunez breaks it down in his latest blog linked below Plus, if you'are attending Fal.Con 2026, you'll have the chance to join Álvaro Del Hoyo Manene and Mariano Nunez for "Defending SAP Critical Systems in the Frontier AI Era" on Sept 2 @ 12:30 PM PDT. More info for the blog and around our Fal.con presence linked in the comments ⬇️
-
Mariano Nunez shared thisHow do cybercriminals jump from your SAP BTP instance to your private-cloud S/4HANA? How would they hijack your SAP Cloud Connector to steal login credentials? How can they pivot from your on-prem ECC to compromise your SAP Cloud data? Most importantly, how can you protect yourself? Get the answers - including live demos - tomorrow at 10am ET, learning directly from the only team that has been protecting SAP from threat actors in the trenches for 16+ years. 👇 Register through the link in the comments for the live or on-demand session.
-
Mariano Nunez shared thisWith adversaries are moving at machine speed to attack SAP applications, I’m glad for the invitation to help defenders learn how to protect themselves at CrowdStrike's #FalCon2026, alongside Álvaro Del Hoyo Manene. In our session, "Defending SAP Critical Systems in the Frontier AI Era," we'll share the latest on the SAP Threat Landscape and showcase how Onapsis and CrowdStrike are eliminating this critical enterprise security blind spot, powered by our integrations between Onapsis Assess and CrowdStrike Falcon Exposure Management (FEM), Onapsis Defend and Crowdstrike's NG-SIEM - and more! ;) Session Details: Wednesday, September 2 at 12:00 PM PT Looking forward to seeing you in Las Vegas! 👉 Register here: https://lnkd.in/eg54Axxj Ansel Thomas Chris Stewart Chris Kachigian Pablo R.an Pablo R.
-
Mariano Nunez shared thisThe volume of attacks against SAP applications over the last 18 months was nothing like we've ever seen before. And now, AI has created the perfect storm. I sat down at Black Hat with Michael Novinson from ISMG, and we dove into why threat actors have shifted focus to target SAP applications. In this 10min interview, we break down: - How attacker behavior around SAP business-critical applications has evolved. - Why an SAP zero-day was the most exploited vulnerability in 2025. - How AI is being used by threat actors to attack SAP applications at speed and scale. - Why traditional defenses (network, endpoint & IAM) fall short when protecting ERP landscapes. - Actionable steps Security and SAP teams must take together to gain real-time visibility, mitigate vulnerabilities, and secure internet-facing applications. - And more... Protecting your SAP digital core requires moving beyond standard InfoSec practices toward threat-informed ERP security. Check out the full discussion and video in the comments below.
-
Mariano Nunez shared thisFollowing the scheduled SAP Security Patch Day release yesterday, SAP issued 4 additional patches (and 1 updated one) later that day, which may have been missed by many defenders. The challenge is that this new batch includes a critical (CVE-2026-58231, CVSS 10) vulnerability in SAP Commerce Cloud, enabling remote, unauthenticated threat actors to take full control of vulnerable systems. The good news is that Commerce Cloud has a much lower footprint across the customer base compared to other SAP components, so your organization may not be affected. If you do have this component running (keep in mind, in many cases it's internet-facing), we strongly recommend to apply SAP Security Note 3771065 or workarounds if applicable. More info in the The Hacker News article below, and in the updated Onapsis Research Labs blog in the comments.Mariano Nunez shared this⚠️ Warning: SAP Commerce Cloud flaw could enable arbitrary code execution. CVE-2026-58231 carries a CVSS 10.0 score and can be triggered by an unauthenticated attacker abusing a default authentication client with crafted input. SAP has released a fix. Patch and redeploy. Read: https://lnkd.in/gkbSyUw7
-
Mariano Nunez shared thisThe SAP Security Patch Day for August is here. Our Onapsis Research Labs partnered with SAP to identify and mitigate 14 zero-day vulnerabilities, including 2/3rds of the new HotNews released this month. Kudos to SAP's Global Security & Cloud Compliance and Engineering teams for the diligent work to protect customers. Fortunately, none of this month's issues can be exploited without authentication, but there are still some serious zero-day vulnerabilities that need attention. Read the blog below to learn more. Marielle Ehrmann Siddhartha Rao Andreas Hauke Erin Hughes Gabriele Fiata Darryl Gray Erik Fischer Karl Fahrbach
-
Mariano Nunez shared thisWhat a great Black Hat. Another year of groundbreaking technical research, deep conversations and collaboration across the community. And, as always, a great opportunity to meet with Onapsis customers, partners, investors and friends. It was certainly 99.9% about AI, which is a reflection of the critical challenges we're seeing as defenders to ensure we can realize the benefits of AI while minimizing the risks. Of course, the OpenAI/HuggingFace talk was packed. If you've not watched it, you should (https://lnkd.in/gF9-FsU7). While the "covert" agent-to-agent communications and 0-day exploitation got everyone's attention, I'm still more fundamentally concerned about how we will solve the challenge of alignment. Agents don't "escape" - they just optimize for the goal they are given. And these are supposed to be the ones running in controlled environments with narrow goals... I'm long-term optimistic about the impact of AI for defense, but the next 18-24 months are going to be very challenging. I'm glad communities like Black Hat exist, helping defenders collaborate on how to solve this. Finally, huge kudos to my colleagues at the Review Board and the entire BH organization team; there's a lot that happens behind the scenes to deliver an event like this.
-
Mariano Nunez shared thisKudos to Dr. Philipp Herzig and SAP for leading from the front and joining the Open Secure AI Alliance. This is a great step forward to ensure SAP AI innovations and adoption can accelerate, securely.Mariano Nunez shared thisOpen source isn't just community. It's also critical infrastructure – and now we're building the alliance to protect it. Today, SAP joins NVIDIA and fellow industry leaders as a founding member of the Open Secure AI Alliance - a movement dedicated to making AI safer, more secure, and more trustworthy for everyone. This initiative is therefore a natural extension of how we think about secure, enterprise-ready AI at SAP. Together, we will develop new techniques and tools to safeguard software by rapidly and responsibly identifying and patching vulnerabilities as the technology evolves. Why this matters? Enterprise software already relies heavily on open source technologies. Open-weight AI models are now foundational to national AI leadership, cybersecurity, and enterprise innovation. Yet they have historically been underprotected. This alliance aims to change that. We need secure and trusted access to both closed and open models. For cybersecurity, open models and open harnesses are essential because they enable cyber defense while protecting data and complement closed frontier models with customizable, localized controls. Security harnesses go far beyond a pure LLM view of the world: they orchestrate agents, govern tool use, verify outputs, and enforce policies at runtime. In other words, they are the control plane for secure AI. For our customers, that’s where trust is won or lost – in how AI is tasked, constrained, and supervised end‑to‑end. This perspective aligns strongly with our strategy. We anchor AI in business context, processes, and domain knowledge. With SAP Business AI Platform, AI agents operate inside a governed business environment, with security, compliance, and context built in from the start. Joining the Open Secure AI Alliance lets us take that approach into an open ecosystem, co‑designing harnesses that combine NVIDIA AI Infrastructure with SAP’s deep enterprise semantics. The future of secure AI will only be built together. Kari Ann Briski Tricia Barr Justin Boitano Marielle Ehrmann Anirban Majumdar Jonathan von Rüden Marc-Oliver Klein Andreas Meider Anil Parekh
-
Mariano Nunez liked thisMariano Nunez liked thisMeet Harish Luthra, Chief Executive Officer of SAP NS2! Harish brings nearly three decades of experience helping public-sector and regulated organizations apply enterprise technology to their most complex missions. As CEO of SAP NS2, he leads customer engagement and strategy for secure, compliant SAP solutions serving national security and critical-infrastructure customers. Harish began his SAP career in 1997 and founded the company’s Federal Professional Services practice just two years later. He later served as National Vice President of SAP Public Services Consulting, leading teams supporting DoD, federal civilian, state and local, aerospace and defense, and higher-education clients. Harish joined SAP NS2 in 2011 and has helped guide its evolution through a range of senior leadership roles. Before becoming CEO in 2022, he was president of SAP NS2 Secure Cloud and managing director, leading operations and GTM across cloud, analytics, supply chain, and business technology. Today, Harish is helping SAP NS2 customers modernize legacy environments responsibly with secure, compliant cloud offerings that consolidate systems, automate workflows, and meet IL4/IL5 requirements. Harish’s career reflects a steady commitment to leadership, customer success and the secure adoption of emerging technology
-
Mariano Nunez liked thisMariano Nunez liked thisBack from Black Hat USA 2026. That was a really good week. The part that does not show up in any schedule: seeing people I only meet once a year, and only at this event. The other part: some members of the ERNW Education Team were along this year, and watching them work their way through the Briefings program for the first time was something special. The moment of the week for me, though, was seeing my colleagues Lorin Lehawany and Sven Nobis on that stage. "Breaking Multi-Tenancy Over and Over, and What We Can Learn From This" — a year of research with real consequences for enterprise networks. New vulnerabilities and working exploits in Kubeflow, Istio and Traefik, all breaking the apparent boundary between namespaces. Another talk I enjoyed a lot: "Root from Kilometers Away — Ubiquiti airMAX RCE" by Federico Kirschbaum and Gaston Aznarez. Extensive analysis of a proprietary protocol, and a really remote attack vector that is even more cool once you think about where these devices sit. Btw, Federico already spoke at TROOPERS Conference & Workshops 2008, and he is also one of the organisers of one of the oldest and coolest conferences in South America: Ekoparty! Links in the comments. #BlackHat #BHUSA #Kubernetes #Ekoparty #ERNW
-
Mariano Nunez liked thisMariano Nunez liked thisCrowdStrike and Snowflake have partnered to bring the CrowdStrike Falcon platform to the Snowflake Marketplace. This collaboration allows customers to apply pre-committed Snowflake capacity toward Falcon, creating a faster path to AI-powered cybersecurity. Breaking down critical data silos is essential for modern security. By bringing Snowflake data directly into Falcon investigations and routing security telemetry with Falcon Onum, this integration accelerates detection, investigation, and response times across the board. ❄️🦅 Learn more: https://lnkd.in/ehgzK7v6
-
Mariano Nunez liked thisMariano Nunez liked thisHay pocas historias empresariales que haya podido seguir tan cerca y por tanto tiempo como la de Ricardo Villadiego. Lo entrevisté por primera vez hace casi diez años, cuando lideraba Easy Solutions, una empresa que se había expandido por el mundo, que había fundado en 2002, y que luego vendió a Cyxtera. Desde que me comentó que iba a fundar Lumu Technologies, he contado su historia. Ahora, Lumu es la número 25 en ciberseguridad del Inc. 5000, con un crecimiento cercano al 300% en tres años, 1.543 clientes en 38 países y sede en Miami. Su tesis es que la ciberseguridad se construyó para las empresas gigantes, y el problema lo tienen millones de empresas pequeñas. Hablamos de eso, de por qué entró a Brasil y de por qué compró una empresa en España para llegar a Europa. Aquí pueden leer la entrevista: https://lnkd.in/ecq4A2yY Portafolio
-
Mariano Nunez liked thisMariano Nunez liked this🎉 Announcing one of our Top 10 Architecture Leaders of the Year Americas 2026: Paul Kurchina! Paul Kurchina has spent over 25 years improving business operations with SAP and other industry technologies, working as an Independent SAP Community Evangelist, Connector, Analyst, and Advisor. Today, he runs KurMeta, an SAP ecosystem development practice where he connects people across the globe to share business know-how and mutual experience. He also serves as Community Orchestrator and Evangelist for the Enterprise Architect SAP Community, supporting and growing the ecosystem globally through thought leadership and engagement. Paul is considered an IT visionary across both industry and technology, having worked in government, crown corporations, private companies, and consulting throughout his career, much of it spent in the utility sector. He's held leadership positions across multiple groups within the ASUG - Americas' SAP Users' Group' Group since 1993, including two terms on the ASUG Board of Directors, and has co-authored several books as an industry analyst focused on the utilities sector. As one of his peers put it: "Paul is leading his community of enterprise architects through an extremely complex change driven by SAP to move to be an AI company. This change impacts the world, as 8,000 of the 10,000 companies with $1B a year in revenue all use SAP. Paul has pulled together over 10,000 people who are watching and learning through 13 hours of webinars to understand what this huge change in SAP means." Another shared "Paul inspires us with decades of technology community building, all with the selfless intent and sprit of giving back and sharing knowledge to build the next generation of thought leaders" Congratulations, Paul Kurchina on the peer recognition as a top 10 Chief Architect Network leader - a well deserved honor!
-
Mariano Nunez liked thisMariano Nunez liked thisReimagine Payables with SAP Business AI Platform and SAP Invoice Management by OpenText. Join Hari Sharma (VP Global Technology Alliances, SAP) and Matthias Niessen (Senior Alliances Marketing Manager, OpenText) this Thursday as they break down how integrating SAP Invoice Management by OpenText with SAP Business AI Platform delivers end-to-end invoice lifecycle visibility. Attendees can expect practical insights around how zero-copy data integration between OpenText and SAP BAIP (SAP Business AI Platform) can unlock early payment discounts, improve DPO strategy, and strengthen supplier relationships, all without additional data replication or migration. Participation is free! Here are the details: Date: Thursday, September 3, 2026 Time: 10:00 – 11:00 AM EDT Register here: https://bit.ly/4h0NDRT #OpenText #SAP
Publications
-
Attacks on Crown Jewels: SAP Vulnerabilities and Exploits
RSA Conference
First SAP cyber-security crowsourced session to be accepted at the RSA Conference.
-
Cyber-attacks on ERP Systems
Datenschutz und Datensicherheit (DuD)
See publicationERP systems represent the world’s business-critical infrastructure. Large and medium companies, governmental and defense organizations rely on these platforms to process and store information regarding their business crown jewels. This article analyzes how the threat landscape has changed, why most of these platforms are vulnerable to cyber-attacks today and how to protect these critical assets.
-
Attacking the Giants: Vulnerabilities in SAP RFC Gateway
BlackHat 2007
See publicationThe first-ever presentation on SAP cyber security threats.
-
MS06-36: Remote Code Execution in Microsoft DHCP Client Service
See publicationDiscovered a vulnerability rated as CRITICAL in all Microsoft Windows versions. Remote code execution by setting up a malicious DHCP server.
Patents
-
Automated Security Assessment of Business-Critical Systems and Applications
Issued US 9009837
Courses
-
Harvard Business School
Endeavor Leadership
-
Stanford Graduate School of Business
Endeavor Leadership
Projects
-
Sapyto/Bizploit: First SAP/ERP Penetration Testing Frameworks
See projectDeveloped the first SAP Penetration Testing framework (sapyto), which was released under GPL license at Black Hat Europe 2007.
Bizploit is a fork of the sapyto project, expanding the framework with additional SAP security modules as well as support for other ERP applications
Honors & Awards
-
Boston Business Journal - 40 Under 40
Boston Business Journal
-
EY Entrepreneur of the Year 2018
EY
EY Entrepreneur of the Year 2018 New England
-
MIT TR35
MIT + Technology Review
Selected by MIT Technology Review as:
- "Innovator of the Year - 2012"
- One of the "Top-10 young innovators under 35"
(Argentina) -
Endeavor Entrepreneur
Endeavor
Selected by Endeavor as a high-impact entrepreneur in 2011.
Selected as "Emerging Entrepreneur of the Year" in 2012.
Languages
-
English
Native or bilingual proficiency
-
Spanish
Native or bilingual proficiency
Recommendations received
7 people have recommended Mariano
Join now to viewView Mariano’s full profile
-
See who you know in common
-
Get introduced
-
Contact Mariano directly
Other similar profiles
-
Max Yoder
Max Yoder
Every day, I am grateful that I got cut from the basketball team two years in a row.<br><br>In 2019, I published a book called Do Better Work, which explores eight ways anyone can bring clarity and camaraderie to a relationship or team.
4K followersIndianapolis, IN
Explore more posts
-
Nitin Bhatnagar
PCI Security Standards Council • 25K followers
The PCI Security Standards Council (PCI SSC) has released a new information supplement, PCI DSS v4.x: Guidance for Compensating Controls and the Customized Approach. The document provides practical guidance to help assessed entities and assessors navigate two options in PCI DSS v4.x that provide flexibility but are often misunderstood – the use of compensating controls and the customized approach. PCI SSC developed this guidance in collaboration with industry stakeholders, including the Global Executive Assessor Roundtable (GEAR) and the Board of Advisors (BOA). PCI Security Standards Council https://lnkd.in/dTV5EwB3
47
-
Roland Ong 王中華
Asperiq • 610 followers
The new standard for governance requires boards to see risk as strategy, not disruption. Those who integrate preparedness into decision-making will not just survive crises but emerge stronger. For today’s directors, strategic risk management isn’t optional, it’s the blueprint for resilience in an unpredictable world.
1
-
Darace Rose
Oppos • 13K followers
A PCI readiness assessment uncovers security gaps before the audit begins—from scoping to configuration errors and policy gaps. This pre-audit step helps you prioritize remediation, reduce surprises, and streamline the journey to compliance. Think of it as a dress rehearsal for your PCI audit. Make sure you're truly prepared before the QSA arrives. 👉https://lnkd.in/gUTksVtu #PCICompliance #AuditReadiness #Cybersecurity
11
-
Michael Goldstein
Entech • 32K followers
When security tools are overly inflexible, they can hinder innovation and expose your team to risks. The solution is adaptive security that meets your needs. 🔐 The eBook titled "The Decision-maker's Guide to Comprehensive Security" explores how Microsoft provides protection that balances flexibility and effectiveness. With advancements in AI and diminished breach risks, this guide aids leaders in crafting a strategy that safeguards the present and plans for the future. Get your free copy to learn how customized security can drive your success.
1
1 Comment -
Amar Thakare
Lumiverse Solutions • 19K followers
Your ISO 27001 certificate doesn't secure your organization. Your controls do. I’ve seen organizations put enormous effort into preparing for an ISO 27001 audit: Policies are updated Documents are organized Evidence is collected Teams prepare for auditor questions And then the audit is passed. . . . But here’s the real question leadership should ask: What happens to those controls the day after the audit? Common red flags: Risk assessments are updated only before an audit Access reviews happen only when auditors ask for evidence Security policies exist in documents but are not followed in daily operations The problem: ISO 27001 creates real value only when it becomes part of daily operations: not just something maintained for certification. A practical way to look at it: Risk → Control → Ownership → Evidence → Improvement Every important security risk should have: - A defined control - A clear owner - Evidence that the control is actually operating - A way to measure effectiveness - A process to improve when things change Key mindset shift: - The certificate should be the outcome - The security management system should be the asset Final leadership question: If the auditor disappeared tomorrow, would your security controls continue to operate? That’s where the real value of ISO 27001 begins. #ISO27001 #Cybersecurity #InformationSecurity #GRC #RiskManagement #CISO
7
2 Comments
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content