THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Bjorn R. Watne, Senior Vice President and Chief Security Officer at Telenor Group, [OTCMKTS: TELNY]Bjorn R. Watne is Senior Vice President and Chief Security Officer at Telenor Group, and an advisor to EUROPOL. He holds a bachelor’s degree in computer science from University of Agder in Norway and an Executive MBA from ESCP Business School in Paris, France. Watne has more than 20 years of professional experience with information security and cyber risk management in Europe and Asia – primarily within financial services, telecommunications, and critical infrastructure. Over the years he’s held numerous board and committee positions with different professional bodies and is a regular speaker at industry events. In 2021 Mr. Watne was named amongst the Global Top 100 Leaders in Information Security by Corinium Global Intelligence, and in 2022 he was one of the finalists for the Outstanding Chief Information Security Officer award, handed out by the OSPAs.
In the light of your experience what are the trends and challenges you’ve witnessed happening with respect to the Security Awareness space?
Coming into IT-security more than two decades ago, the biggest change I’ve witnessed over the years is how this discipline has transcended from server-room to boardroom. You will still find situations where information security is seen as an “IT issue”, but more and more people understand that beside technology one needs to address both processes and people.
There is a popular saying these days that “hackers don’t break in – they log in”, meaning that it’s a lot easier using valid credentials to enter a system than trying to find loopholes and bypass security measures. Credentials are usually a combination of multiple factors that can include both passwords and devices/tokens. Making sure that users don’t disclose information/passwords and that they manage their devices in a secure manner is therefore becoming more crucial to uphold adequate information security.
The trend is that more and more people are becoming more aware of risks and potential dangers as society is getting ever more digitalized. That’s a good thing. With more and more people turning into digital citizens, it is however also a trend that we see a rise in compromised credentials. Based on this, a continuous focus on improving Security Awareness is certainly becoming more important than ever.
How do you measure the effectiveness of your organization's Security Awareness program, and what metrics do you use to track progress?
Security Awareness programs are preventive controls, and measuring effectiveness of preventive controls is inherent difficult. What we’re trying to achieve is to prevent the occurrence of incidents, but whether or not an incident takes place is by large dependent on external factors like motivation, and capabilities of potential adversaries. Meaning you can still run a very successful security awareness program while at the same time experience multiple incidents.
“To get support and understanding for budgets and controls, one needs to be able to “sell the story” also outside the security organization.”
One way to measure maturity and effectiveness is to combine the awareness program with practical assessments – like phishing simulations. An organization can run annual awareness programs and measure completion rate, and then go on performing phishing simulations on the same workforce to see whether maturity is increasing following completion of training.
In my experience the program is more successful when it’s being tailored individually to different target groups and not pushed out as an enterprise-wide “one size fits all” module. Keeping it interesting and relevant to the recipient is key to make it stick.
What advice would you give to someone who is interested in pursuing a career in Security leadership, and what skills or experience do you think are most important for success in this field?
Security leadership isn’t different from leadership in general, but it is my strong belief and experience that if you want to succeed as a leader, manager, and mentor in any field you need to have a good understanding of the field you’re operating in. Cybersecurity today is a very complex discipline, covering everything from physical access to assets, through IT- and technical controls, all the way to the abovementioned training and awareness of people. To be an expert in everything is quite impossible for a single person, but to know which questions to ask and be equally able to digest/understand the response is important for a leader to make the right decisions.
Aside from the fundamental knowledge of the discipline, it would be very useful for a leader to be able to breach the gap between business and technology and to have the ability of explaining a technically difficult topic in business terms to external stakeholders. To get support and understanding for budgets and controls, one needs to be able to “sell the story” also outside the security organization. Some exploration into the business management area would greatly benefit an aspiring technologist and cybersecurity leader.
What are some of the most common misconceptions about Security Awareness, and how do you work to address them within your organization and the broader industry?
I am not aware there are too many misconceptions around Security Awareness specifically. Everyone you ask will typically always agree it’s important to address the issue. I have however from time-to-time encountered people being somewhat skeptical to awareness-training, claiming that people aren’t paying attention to what’s being taught and just “click through” to complete the assignment and move on.
Having been the “victim” of such trainings myself in the past I can somewhat relate to that, and as I mentioned before – that’s why it is very important to understand your audience. For most speakers, knowing who you’re addressing, what they know and what their concerns are is usually the basis for delivering a successful speech. Likewise, a security awareness program needs to be relevant and interesting to the audience it targets. One thing I have found useful in such regard is to target individuals in a private context – flagging issues like identity theft, fraud and blackmail or online bullying. People are in general concerned about these things, and if you can create awareness around secure online behavior areas a private citizen, chances are high the same behaviors will be brought along to the office.