enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Global CISO at FIEGE

CISO 2022

Boris Awdejew, Head of Information Security, Global CISO at FIEGE

As you know, culture eats strategy for breakfast. When it comes to cyber security, the CISO must first change the way the board, senior management and other stakeholders think about cyber threats and how to deal with them. If you ask an executive not directly involved in information security what the CISO should do and what tools he uses to prevent cyber attacks, the most common answer is probably something about IT security technologies, something about firewalls and anti-viruses. The CISO in the public mind sits in front of his Linux laptop and chats incomprehensible characters on a black console ensuring the company's information security day and night.

In reality, the CISO's primary responsibility is to build processes and eliminate vulnerabilities in those processes. Companies do not break down because of vulnerable servers, they break down because of faulty processes. The consensus in CISO professional circles is that risk management is the key information security process. The implementation of professional risk management requires an accurate understanding of a company's primary and supporting assets, taking into account the criticality of any given asset, the definition of crown jewels, as well as the applicable threats. The Board should be regularly informed of existing risks and decide how to address them. However, it is all a well-known theory based on the ISO 2700x family of standards.

Over the years, I have developed four main areas of activity for the CISO in a large company.

First, the CISO has a duty to be a visionary. The CISO has to keep in mind the future landscape of information security processes and understand their interplay. The CISO shall understand what the rules of the game will be internally defined, what processes will be needed to implement those rules, and what technological solutions will be needed to make it happen. Last but not least: you have to understand the organizational structure and think about which competencies will be needed at the headquarters and which will be needed at the field offices.

Second, the cyber security vision must be communicated and integrated into the company's business processes. The CISO has to convince stakeholders of his vision, and his understanding of cyber security has to be shared by all the key players within the company. Of course, you can't build security without the support of the IT department, the quality department, the legal department and, less obviously, the sales department. Today, information security is no longer just a way to keep secrets (confidence) or maintain the availability of key IT systems, but also a way to strengthen your market position and make security your USP.

"Companies do not break down because of vulnerable servers, they break down because of faulty processes."

In Germany, the real information security boom started in 2015 with a law requiring all companies classified as critical infrastructure to build an ISO 27001-compliant ISMS. In those seven years, a secure cyberspace of certified companies was effectively created, which could act as contractors for each other and not threaten the security of their counterparties. Your business is probably also connected to critical infrastructures in one way or another. FIEGE itself is not subject to the law, but many of our customers in industries such as healthcare or food are very interested in FIEGE's ISO 27001 certification. This will help our customers comply with their internal regulation.

The challengefor the CISO is to identify such customers and certify the relevant company units. That is why it is important to engage with the Sales and Business Development departments, among others.

Once the CISO has articulated his vision for information security within the company and secured the support of all stakeholders, a Security Organization shall be created. The most important question to decide is which competencies will be intern and which will be extern. In addition, some functions should be carried out centrally (such as the development of risk management methodology) and some functions should be carried out locally, such as risk assessments in specific projects based on a centrally formulated risk management methodology.

The fourth key to success is operational process management, i.e. Governance, Project Management and classic People Management. Only this holistic approach to information security can ensure success in a world of growing cyber threats.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.