THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


What challenges do you regularly confront in your role as Chief Information Security Officer at H&R Block?
Joshua Brown, Chief Information Security Officer, H&R Block
One of the semi-unique challenges is that we onboard and offboard around 80,000 tax professionals every year for tax season. The nature of the tax business is such that we generate a significant portion of our revenue over a relatively short period of time, and our field associate headcount is quite transitional. Therefore, the security needs of the business (as well as its risk profile) change dramatically based on geography and what phase of business operations we are in at any point in time. Because H&R Block sits at this interesting nexus of retail, financial and technology sectors, we must synthesize elements from all those sectors to deliver appropriate capabilities and protections to the business.
All facets of information security and data security fall under the purview of my team. As we built out and invested in our team, many of the capabilities that had been outsourced or purchased as services over time were then able to be delivered internally. Investing in our talent enabled us to deliver better and faster for the business. We built our own security operations center (SOC) and SIRT teams staffed 24/7. Almost all of our penetration testing and application security testing is done in-house. We manage our own compliance and security awareness programs. Therefore, depending on where we are in the tax season, a typical day for me involves meeting with my peers and perhaps senior leadership team members while also reviewing our different KPIs and dashboards. We closely monitor fraud as well as the security parameters surrounding the critical systems that provide services to both our internal clients and customers. We constantly review the company's risk profile and make any necessary adjustments, balancing urgency with patience. And of course, we are constantly striving to improve in everything we do.
How do you see the industry now that the pandemic is over?
In the past, we provided our clients with assisted services at our physical retail locations as well as offering web and software-based DIY capabilities. Now, we enable consumers to file their taxes in whatever manner is most comfortable for them: on their own, as well as hybrid services that let them meet with a tax expert in person or virtually. During Covid, clients wanted more choice in how they interacted with our company. For example, they wanted to be able to drop off their tax documents digitally rather than coming into an office. We also had to make changes to accommodate the demand for our staff members to be able to work from anywhere at any given time and that alters the company's risk profile. The sanctity of our customer’s data, and the trust that our customers have placed in us are of paramount importance to the company. Everything we do is in pursuit of safeguarding that trust.
"As we built out and invested in our team, many of the capabilities that had been outsourced or purchased as services over time were then able to be delivered internally. Investing in our talent enabled us to deliver better and faster for the business."
So, we had to make quick adjustments to enable the mobility that our tax professionals and customers demanded, while ensuring that we had the appropriate visibility and security controls in place. Being in a specific physical office was no longer sufficient as a risk mitigator. In other words, previously if you worked in an H&R Block-controlled office, how you accessed applications and data benefitted from the physical security of those locations. COVID forced us to re-imagine how we could ensure security without the protections of a physically-controlled location. Hence, we had to change and adopt a new strategy. That's where ”Zero Trust” or the ”Secure Service Edge” came into play for us.
The other massive change that happened during the pandemic was a reexamination of how our associates wanted to work. I lost nearly 60% of my team, including nearly my entire management team during the so-called “Great Resignation.” H&R Block adjusted rapidly and we offered our associates the flexibility and empowerment to construct their ideal work environment. This approach involved more than just technology, even though it was essential for accommodating this new way of working. I believe that the philosophy and the human side of how you treat and empower your associates to make decisions that improve their happiness and their connection to one another--without necessarily having to be in the same location anymore—was the most vital change in how we work. The global team I have now is unbelievably talented and motivated. They are deeply connected to the “why” of what we do, and they understand what each of them brings to the larger team. They are here because they truly want to be here, they want to work with and learn from each other. And that’s a pretty special thing to be a part of.
How do you see the future of the industry itself when it comes to the next 18 to 24 months?
Over the past several years, security technology has advanced to the point where the bad actors are increasingly not attacking the layers of technology security directly. Instead they are targeting the “carbon layer”: people. Phishing and social engineering attacks are the most prevalent and successful attack vectors, and in many ways those are the toughest things to stop. Security awareness is therefore important and will continue to be important. But, if your organization has 100,000 employees and a 1 percent failure rate for phishing, all you need is one person to click a bad link or open a malicious attachment. Hence, we cannot define a successful security strategy by mandating that our employees always make the right choice.
So, I believe that the effectiveness of real-time risk assessments of behaviors will continue to improve and people's ability to interact with technology will become more seamless. Risk assessment and mitigation will happen largely behind the scenes, only prompting the users for heightened challenges or interactions when indicated by situational awareness. Hence, in the past, you would get to sensitive systems via a jump box or a privilege access workstation. You can use zero-trust platforms, private internet access, or similar technologies to proxy applications directly to authorized and entitled users over the internet without the need for legacy technologies like VPN. More importantly, we can grant access directly to the things that employees need to do their jobs without granting them access to things that they don’t need. This helps contain the blast radius of any attacks without sacrificing efficiency or productivity, all while lowering risk.
Additionally, mobility will continue to increase among customers and employees. Now that every employee is mobile, the data follows them. Hence, rather than focusing on the physical location of data, we need to be more pragmatic about how we monitor, track and secure data movement. If your laptop is encrypted and I can ensure that you aren't moving data to unsecured areas or via insecure means, I don't really care if you have data on it. Identity-based security is the other significant component of the puzzle that we haven't fully discussed. Everything must revolve around who you are and what you require in order to perform your work effectively.
I believe many people overlook the fact that the use of passwords is finally beginning to decline somewhat, which is fantastic. I think we're going to see more movement in that direction. We'll be moving away from passwords and passphrases towards things that do not rely on people to remember them—things that you have, like certificates, keys or tokens; and things that are part of who you are, like biometrics. If businesses can master integrating these elements, we'll notably raise the bar for overall security while lowering the burden on our users and our customers.
What would be your piece of advice for your fellow peers and colleagues?
I believe that as an industry, we need to stop enforcing gatekeeping practices like college degrees and certifications; we have a shortage of several hundred thousand security professionals in the US alone, and millions worldwide. Without actively mentoring the next generation of security talent, whether they be leaders or individual contributors, we won't be able to hire our way out of this issue. Hence, we must consider mothers who are returning to the workforce. We need to consider people with second careers. We need to evaluate our hires based on aptitude and potential. A sizable portion of my staff is made up of former members of the armed forces, police enforcement, the medical field, and teachers.
We must embrace the idea of having a diverse range of backgrounds and experiences who can add something special to our workforce, such as those who are neurodiverse. They possess unique superpowers! They might not always feel at ease speaking in front of a crowd. They're amazing analysts, though. They also contribute a perspective and approach that neurotypical people might not have. We must quit imposing our own methods on others and let them discover what works best for them. The more different lenses we apply to tough problems, the more likely we will be able to solve them.
In the end, it really doesn't matter how many hours you put in; what matters is that you are delivering effective results and living up to the team's expectations, and that you are fulfilled with what you are doing. Our responsibility is to support the business in making well-informed risk-based decisions, not to be the place where good ideas go to die.
On the team-building and execution front, we must understand that when the situation shifts and our employees need new ways to deliver for customers who require different services, we must be adaptable enough to support those kinds of changes. This means that we want our associates to be able to access the information they require when they require it from the devices they prefer to use. As a result, we must be able to make risk-based decisions in real time using a range of factors. I believe there are valid privacy concerns because some of the monitoring we must conduct is much more behavioral than in the past. Yet by making innovations like the secure service edge a reality, we can simultaneously give people more freedom to accomplish the things they need to do and be much more adaptable in how they interact with technology.