THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


How Did Your Previous Roles And Responsibilities Epitomize Your Current Role At Denver Water? 
Tung Nguyen
I began my career in IT as an administrator, never expecting to end up in information security. However, my career path evolved organically. I spent a few years as an IT administrator at a university, learning the ropes of administrative tasks. Then, I had the opportunity to become a security administrator for another university in town, which marked my entry into the world of information security.
As time went on, I progressed from a security administrator to an architect and now hold the position of director of cybersecurity at Denver Water. Today, I am responsible for managing the cybersecurity of our enterprise, including both our IT and operational technologies, as well as the overall security of our organization.
How Do You Select The Right Cybersecurity Solution For Your Organization?
When I was offered the opportunity to become a security head, I wasn’t entirely sure where to start. Many people advised me to adopt a security framework as a starting point, so I looked into various frameworks and selected what I thought was the best cybersecurity framework. However, as I progressed on this journey, I learned that sometimes in information security, we focus on good things, but not necessarily the right things.
Therefore, as security leaders, we must ask ourselves whether we focus our efforts on the right things. It’s good to install and configure firewalls, but is it the right thing to do at this moment to protect our organization? That’s why organizations must assess risk profiles and identify the right priorities. We don’t have unlimited resources, so it’s essential to determine what we need to do today, this week, this month, or next year based on our risk profile.
The first step toward identifying the right priorities is conducting a thorough risk assessment that takes into account the organization’s risk profile and risk priorities. At Denver Water, where I work, we’re a major water utility that interfaces with customers through certain enterprise applications, processes credit cards, and has critical infrastructure. It’s essential to understand the business and the risk profile of the organization to conduct a suitable risk assessment.
Understanding the risk profile, prioritizing risks, and tailoring assessments to the organization’s risk profile are critical first steps to help identify the right things to work on. This approach will ensure that we’re making the best use of our resources and addressing the most critical risks.
Could You Please Explain How You Use Your Approach To Implement Various Security Projects At Denver Water?
In the past few years, Denver Water’s cybersecurity team has taken on more than a dozen projects. One of the essential things I’ve learned from these projects is that we must have clear objectives and goals. Without them, we may end up implementing technology and doing activities, but we’re unsure if we’re achieving the desired outcome.
"As security leaders, we must continually conduct assessments, understand our business, the risks we face, and how the external environment changes along with our risk profile."
For instance, we were implementing a segmentation project to divide our large internal network into smaller networks with appropriate security controls and protections for critical networks. Although we aimed to adopt a zero-trust model, we couldn’t go straight to 100% zero trust. Instead, we decided to break our network into four or five smaller networks and focus on protecting them based on the asset associated with each network. During implementation, we faced numerous technological challenges, and the technology we selected didn’t work as expected. This was mainly because we didn’t test it well enough, and we didn’t have a clear definition of what constituted success and the criteria for achieving our project goals.
To address these challenges, we gathered all stakeholders and discussed how we could clarify our project objectives and ensure success. We also examined what we did not understand to achieve the desired results. The bottom line is that we must understand what we’re trying to accomplish and the problem we’re trying to solve. It is essential to ensure that everyone involved in the project, from executive sponsors to technical personnel responsible for implementing the project, has a clear understanding of the objectives.
How Do You Envision The Future Of The Cybersecurity Space?
In today’s landscape, organizations generate vast amounts of data every day, and networks have become increasingly complex, not just in terms of technology, but also threats and vulnerabilities. I don’t believe relying solely on manual processes to handle the data and network complexity is sustainable. However, I also don’t think that AI and machine learning alone can solve all problems.
I believe that automation should be integrated into all aspects of our cybersecurity programs, including security controls, to effectively manage security threats in today’s landscape and the future. We need to consider all factors of people, processes, and technologies and determine where we can leverage our people and technology to solve problems effectively. Relying solely on people is not a viable solution, and technology alone cannot solve the problem because it lacks context and understanding of an organization’s business dynamics and culture.
Therefore, a balanced approach that integrates both automation and human decision-making is necessary. We need to use technology to support decision-making and automate repetitive and mundane tasks to free up time for people to focus on higher-level tasks that require human intervention. Ultimately, we need to strike a balance between the strengths of technology and human expertise to achieve optimal results.
What Is Your Advice To Your Peers?
As security leaders, we must continually conduct assessments as well as understand our business, the risks we face, and how the external environment changes along with our risk profile. This understanding allows us to develop and drive appropriate security roadmaps and programs. If we fail to keep our risk profile up-to-date, we might not react and respond quickly enough to the increasingly complex security threat landscape. It’s crucial to avoid knee-jerk reactions to the news and instead focus on identifying the right priorities to manage the risks effectively.
We must remain vigilant and regularly reassess our risk profile to identify new risks and challenges. This approach enables us to proactively identify and address security threats before they become serious issues. It also allows us to develop an agile security program that adapts to changing risks and threats, enabling us to prioritize our efforts effectively. In conclusion, risk management must remain at the core of our business, and we must ensure that we are continually assessing and updating our risk profile to address the dynamic and ever-evolving security landscape.