How To Build An InfoSec Program From Scratch

How To Build An InfoSec Program From Scratch

🎙 Prabh Nair 👥 184K 📅 December 1, 2025 ⏱ 30 min 👁 1K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

InfoSecCISORisk AssessmentSecurity ProgramGRC

Summary

In this podcast-style video, Prabh Nair and guest Rahul Kokcha discuss a practical approach to building an information security program from scratch. They emphasize starting with understanding the organization, its people, and culture before diving into strategy. The conversation outlines a phased approach: first, building relationships and understanding business context; second, conducting a risk assessment using a service-based model; third, developing a strategy and roadmap aligned with business objectives; fourth, implementing and validating controls; and finally, continuous improvement. They highlight the importance of being a security enabler, not a roadblock, and provide real-world examples, such as a password reset tool vulnerability. The video is aimed at new CISOs, first security hires, and GRC professionals, offering a mental model rather than a rigid framework.

123 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable practical insights from an experienced CISO, emphasizing the importance of understanding the business and building relationships before implementing security measures. The argumentation is coherent, with a clear logical flow from initial stakeholder engagement to risk assessment and strategy development. The use of a real-world example (the password reset tool) illustrates the points effectively. However, the advice is largely anecdotal and lacks empirical evidence or references to industry standards, which limits its generalizability.

85 words

Title / Content Match

The title accurately reflects the content, which is a step-by-step guide to building an InfoSec program from scratch.

Quality & Reliability

7/10

The video provides a practical, experience-based approach to building an information security program, with clear phases and real-world examples. The advice is grounded in the guest's extensive career, but it lacks formal citations or references to standards, and the methodology is presented as opinion rather than evidence-based.

Chapters

Cited Sources

Concurring Sources

  • ISO/IEC 27001 — The video's emphasis on compliance and governance aligns with ISO 27001 requirements.
  • NIST Cybersecurity Framework — The phased approach in the video is consistent with NIST CSF's Identify, Protect, Detect, Respond, Recover functions.

Contribution & Novelties

The video offers a practical, experience-based framework for building an InfoSec program, emphasizing the importance of understanding the business and building relationships before technical implementation. It provides a clear phased approach that is often missing in theoretical discussions. The service-based risk assessment model is a useful alternative to traditional asset-based approaches.

Pour aller plus loin :

  • ISO/IEC 27001 — International standard for information security management, relevant to the video’s discussion of compliance and governance.
  • NIST Cybersecurity Framework — Framework for improving critical infrastructure cybersecurity, useful for structuring security programs.
  • Risk Assessment — General concept of risk assessment, applicable to the video’s methodology.

102 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the video's rich practical content. The technical level is moderate, suitable for a broad audience. Overall reliability is good, though the lack of formal citations slightly reduces the score.

Reliability 7/10