Thread regarding Wells Fargo & Co. layoffs

Information Security Officers in Divisions Should Laid Off

The division ISOs are pretty useless many of them were recruited without security backgrounds and I knew some who were demoted into an ISO role or even hired with criminal records.

I understand they're all under Corporate Risk under Mandy Norton doing security planning using a risk based approach. But they're terrible at what they do and the bank should let most of them go to keep the jobs for the Frontline employees in the branches or call centers, it's only right.

by
| 2813 views | | 15 replies (last January 12, 2021) | Reply
Post ID: @OP+18PP9UkY

15 replies (most recent on top)

Honey what do you do? I work security plans babe. Wow so you protect the bank? No, we just check a box on some dumb risks that are admin related and it leads to no mitigation. Oh, but you’re still getting a bonus, right? Yes pumpkin.

by
| | Reply
Post ID: @3plo+18PP9UkY

What is corporate risk and why are they so useless? Sorry I’m new at WF

by
| | Reply
Post ID: @3ybh+18PP9UkY

Harassment is never acceptable. You have a legal, moral and ethical responsibility to guard against this inappropriate workplace conduct.

We know much of Management and HR are cowards, so you may be on your own. I faced this myself in my group. Not sure why the employees at WF have such low confidence in them self to do things like this.

by
| | Reply
Post ID: @2lpe+18PP9UkY

Please don't insult the Mexicans

by
| | Reply
Post ID: @1ekq+18PP9UkY

The bullying and harassment from the security plan people is new to me. Care to share more?

by
| | Reply
Post ID: @1lsb+18PP9UkY

If the security and risk teams as stated in this thread are worse than the Frontline emoyees when they should be held to a higher standard that explains why the bank is in serious trouble. Send the ISO and risk jobs to Mexico the Mexicans can do it better.

by
| | Reply
Post ID: @1pqa+18PP9UkY

Also as a Senior software engineer, they do not respect me, everyone should respect me all of the time.

Tech Secretaries run rampant here too

by
| | Reply
Post ID: @1zil+18PP9UkY

those aren't the only things they do, they bully, harass and discriminate

by
| | Reply
Post ID: @1few+18PP9UkY

I agree Corporate Risk is useless.

All those people only monitoring software and vulnerabilities, that can all be automated, they can go too. First company I have seen doing this manually.

by
| | Reply
Post ID: @1pqi+18PP9UkY

We could fire all of Corporate Risk and not feel any impact....

by
| | Reply
Post ID: @1zet+18PP9UkY

The ISOs in the company created security plans that were all wrong, thousands of them, each related to an application or infrastructure component. Also, some ISOs I knew were involved in widespread s-xual harassment and widespread embezzlement. No wonder all the work was corrupted their brains were crammed with filth.

by
| | Reply
Post ID: @1zvf+18PP9UkY

Every big company went bonkers over hiring for cyber security. The IT department ends up doing all the work.

Yeah buddy I’m sure our Logitech usb wireless keyboard dongles are going to get hacked just because hacker magazine payed some guy a $250,000 bonus to prove he could do it in a lab.

I’m sure the epson printer in Frank’s office that isn’t even on the network will be used to steal millions in secrets if we don’t disable that protocol on it.

How many millions in salaries can we spend for a team that gets to role play Cold War era spy game movies. Just like the “balloon boy” incident in 2009 these teams just love the attention. Ah ha- see we found the web server was hacked!
Oh sorry John’s security scanning tool accidentally reported itself as a malicious executable. Sorry for making you guys work all weekend.

by
| | Reply
Post ID: @ajd+18PP9UkY

They are actually “Security Plans” and not people?

Who knew...

by
| | Reply
Post ID: @ahp+18PP9UkY

Ok. Thanks. No one should have an ISO with a criminal record or was demoted into that role that explains why they're so bad.

by
| | Reply
Post ID: @rim+18PP9UkY

I agree that they are pretty useless. They’re security plans are check the box things. They’ve mitigated no risk and never stopped a security incident as a result of their assessment.

But get your facts straight Jack. They don’t report to Mandy. They report to Gary (CISO) who reports to pretty boy SVB , head of technology. In first line.

by
| | Reply
Post ID: @jrf+18PP9UkY

Post a reply

: