Skip to content
    
Cybersecurity Insights with Contrast CISO David Lindner | 04/18/25

Insight No. 1 — CVE program’s near-death exposes security's single point of failure

The recent near-halt of the CVE program due to funding issues highlights a critical vulnerability in our industry's reliance on single points of failure. While CISA's extension averted immediate crisis, it exposed the potential for security's foundational elements to be disrupted. As security leaders, we must advocate for more resilient, diversified support systems for essential security programs and proactively address systemic issues like the Common Vulnerability and Exposure (CVE) backlog. This situation demands we revisit our single points of failure and reinforces the need for contingency plans to ensure the continued stability of our security ecosystem.

Insight No. 2 — Does your cyber policy have your back?

You've got to really know your cyber insurance policy. Just having one isn't enough. Make sure it's a solid fit for your specific risks, what the regulators expect and what you've promised in contracts. Regular check-ups on your policy are key: Understand exactly what's covered (and what's not), and ascertain that your policy will actually have your back if things go south.

Insight No. 3 — Speak their ROI language to unlock board buy-in for security

When talking to the board, skip the tech jargon and doom-and-gloom scenarios. They want clear, concise updates on the actual business risks we're managing and how our security strategy supports the company's goals. Focus on the ROI of security investments, use metrics they understand (think financial impact) and be upfront about what keeps you up at night – but always with a plan for how you're tackling it. Basically, speak their language, be transparent and show them security is a business enabler, not just a cost center.

David Lindner, Chief Information Security Officer

David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.