Skip to content

Cybersecurity Insights with Contrast CISO David Lindner | 09/20/24

    
Cybersecurity Insights with Contrast CISO David Lindner | 09/20/24

Insight #1: Don't shrug off this internet plague!

Cross-site scripting (XSS) is the overlooked vulnerability plaguing the web. As Contrast’s recent attack data show, it's everywhere, yet it’s often dismissed as “'low risk.” The truth? This prevalence makes XSS more of a threat, and it's easily exploited. Fortunately, Application Detection and Response (ADR) is here to help you stop it!
 

Insight #2: Finding root cause doesn't always solve the problem 

Root cause analysis is not just about figuring out the technical problems that may have occurred, as Forbes describes. Technical problems rarely exist in isolation. They often occur within the context of a larger process or workflow. If that process is inefficient, it can create conditions that make technical problems more likely to occur, or harder to detect and fix.

 

Insight #3: Fixing culture helps fix security 

So many interesting interactions with peers over the last few months are making me realize that there is still a major disconnect between finding and fixing vulnerabilities and the culture that drives it. Too many security leaders don't care about culture and care more about resolving risk. But I would argue that creating a positive security culture will naturally help to address vulnerabilities faster (mean time to respond/remediate [MTTR]) and create less vulnerabilities as time goes on (vulnerability escape rate [VER]). Why can't we get over this hump?
David Lindner, Chief Information Security Officer

David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.