3rd Party Risk Management
,
Governance & Risk Management
,
Video
Kinly CISO Don Gibson on Overlooked Social Engineering Threats and Human Error
Supply chain attacks are a persistent risk for enterprises worldwide. Despite advances in technical defenses, attackers still succeed by taking advantage of social engineering, inadequate processes and poor verification practices. These factors often open backdoors into organizations, leaving them vulnerable to breaches.
See Also: From VPN to Hyperscale: Island Reimagines the Browser
Don Gibson, CISO at Kinly, said businesses should treat process resilience with the same criticality as compliance frameworks. Paper-based policies alone offer little protection if employees don’t know how to respond when pressured by malicious actors posing as trusted entities, he said.
“Trying to get that balance between the supplier and the customer … making sure that the system is actually secure by design, that it is built out from the beginning to make sure it fits the requirements – that’s the key,” Gibson said.
In this video interview with Information Security Media Group at the Cybersecurity Summit: London Financial Services, Gibson also discussed:
- Common missteps when designing resilient processes;
- Extending zero trust principles to supplier networks;
- Building trust through compliance and collaboration.
Gibson creates pragmatic security programs that mold strong, diverse and resilient teams and functions that help deliver business objectives. He also advocates for cyber mental health and previously served as head of cyber at the Department for International Trade in the U.K. government. He is a member of the CyberEdBoard.

