Skip to content

Cybersecurity Insights with Contrast CISO David Lindner | 11/17

Cybersecurity Insights with Contrast CISO David Lindner | 11/17

Insight #1

Organizations are continuing to pay more for top cybersecurity talent, and with the Securities and Exchange’s (SEC’s) most recent lawsuit against SolarWinds and its former Chief Information Security Officer, those numbers are only going to go up.

Insight #2

Where did the SBOM talk go? Yes, Software Bills of Materials (SBOMS) are still a thing, and the National Telecommunications and Information Administration (NTIA) has very specific recommended elements (PDF) for what has to be in an SBOM. In my opinion, even if you don't fully conform, it's still good hygiene to have an SBOM for your software

Insight #3

A recent Synopsis report says software vulnerabilities are on the decline, yet Common Vulnerabilities and Exposures (CVEs) continue to be discovered at an alarming rate. I think the general consensus is that if you have an established Application Security (AppSec) program and track your mean time to respond/remediate (MTTR) and vulnerability escape rate (VER), vulnerabilities will decrease over time. Unfortunately, the majority aren't doing this.

David Lindner, Chief Information Security Officer

David Lindner, Chief Information Security Officer

David is an experienced application security professional with over 20 years in cybersecurity. In addition to serving as the chief information security officer, David leads the Contrast Labs team that is focused on analyzing threat intelligence to help enterprise clients develop more proactive approaches to their application security programs. Throughout his career, David has worked within multiple disciplines in the security field—from application development, to network architecture design and support, to IT security and consulting, to security training, to application security. Over the past decade, David has specialized in all things related to mobile applications and securing them. He has worked with many clients across industry sectors, including financial, government, automobile, healthcare, and retail. David is an active participant in numerous bug bounty programs.