A call after the worst-case scenario # A company calls. Ransomware. Production has come to a standstill. The first question: “How could this happen?” A better question would have been: “Why didn’t we do anything about it before?”
Many companies still treat information security as a chore – something you do because you have to. It is regrettable that regulatory pressure is often needed to make this happen, but given human weaknesses in dealing with statistics and risk, it is hardly surprising.
Preparation # I started preparing in January and took the exam in mid-March. So it took me about two months in total, with a few interruptions. I spent about an hour a day during the week and two hours at weekends. Some weeks I did nothing at all – but I didn’t let that stress me out.
My technical background allowed me to repeat familiar content instead of starting from scratch. Nevertheless, the exam was no walk in the park. It was crucial that I identified my weaknesses early on and worked on them systematically. I focussed on continuity rather than perfectionism – it was okay to skip a chapter from time to time.
Introduction # I keep asking myself why simple, well thought-out and cost-effective ideas for improving corporate culture, safety or productivity fall on deaf ears. Not only in corporations with cumbersome bureaucracy, but also in small companies with flat hierarchies and seemingly short decision-making processes. Am I naive because I believe that people would write a LinkedIn article for a cup of coffee? Or because I believe in a positive reinforcement culture instead of disciplining employees with compulsory training or silent frustration?