Skip to content

Cybersecurity Insights with Contrast CISO David Lindner | 04/11/25

    
Cybersecurity Insights with Contrast CISO David Lindner

Insight No. 1 — How to survive without CISA

As CISA scales back, it’s time for enterprises to wake up to a harsh reality: You can’t rely on the government to secure your infrastructure. The safety net is shrinking, and those still waiting for public-sector handholding are falling behind. Smart orgs are already shifting to private-sector threat intel, red-teaming services, and collaborative alliances that move faster and hit harder. Security is no longer a shared responsibility — it’s yours, whether you’re ready or not.

Insight No. 2 — Team up for security: HR can’t go it alone

Delegating cybersecurity training solely to HR is a recipe for disaster. While HR handles compliance, they lack the technical expertise to combat sophisticated threats like phishing and social engineering. Security training isn't a checkbox exercise; it's a critical, ongoing process requiring collaboration between Security, IT, Governance and HR departments. Without this partnership, your employees are ill-prepared, and your organization remains vulnerable.

Insight No. 3 — No, the sky is not falling: It’s just cloud FUD

A 235% spike in high-severity cloud alerts sounds terrifying — until you realize it might reflect better detection, not worse security. Don’t let vendors use alert volume as a proxy for breach success. Focus on validated threats, not inflated dashboards. Cloud FUD is the new snake oil.

David Lindner, Chief Information Security Officer

David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.