enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Chief Strategy Officer at the National Cybersecurity Center

From Silos to Synergy-Facilitating Three-Way Security Convergence

Mark Weatherford, Chief Strategy Officer at the National Cybersecurity Center

Mark Weatherford is the (virtual) Chief Information Security Officer at AlertEnterprise, the Chief Strategy Officer (and a Board member) at the National Cybersecurity Center, and the Founding Partner of Aspen Chartered Consulting, where he provides cybersecurity consulting and advisory services to public and private sector organizations around the world. 

Could you brief us on security convergence and how organizations can benefit from its implementation?

Security convergence involves the integration of various security disciplines. Specifically, it entails the merging of physical security, OT security, and cyber security (or IT security) into a unified and integrated security function within an organization.

It comprises three key elements. Firstly, the organizational component involves merging various security functions into a unified structure. Secondly, the technology component entails managing the distinct technologies employed in each discipline. Lastly, there is a cultural aspect to security convergence that should not be underestimated.

What are the current challenges in the industry?

Implementing a converged security program necessitates addressing the behavior and mindset of individuals from different security disciplines, some of which have longstanding histories and ingrained practices. Effective communication across departments and siloed domains can also prove challenging for organizations pursuing security convergence. Additionally, compliance issues arise as different regulatory and compliance requirements exist for each security discipline.

In security convergence, the integration of different security functions helps leveraging existing infrastructure in a synergistic manner. It offers a significant reduction in overlap of different training and technologies within most organizations. For instance, a company may already have security cameras installed for physical security purposes, and the data collected from these cameras can also be used for cybersecurity monitoring.

“We are currently witnessing an upward trend towards convergence, as companies recognize its value in terms of security, compliance, cost savings, and operational efficiency.”

By adopting a broader perspective on the security program and examining vulnerabilities across the entire organization, the number of security lapses can be reduced. This approach facilitates the identification and implementation of improved controls that address these vulnerabilities in the long run.

To illustrate the benefits of integration, consider a scenario where a security incident occurs at a remote substation. In the past, it was challenging to determine the appropriate response. However, by integrating different technologies, a more structured and disciplined approach can be established, enabling clear visibility into the nature of the incident. These efforts ultimately result in increased efficiencies by streamlining processes and enhancing communication between different parts of the organization.

Has the distinction between physical security and cybersecurity analysis widened in the recent past?

The convergence of these formerly disparate security disciplines has become a focal point for companies seeking increased efficiency. While some organizations have not yet appointed a unified security leader, efforts are underway to enhance communication and collaboration among these disciplines. The pandemic served as a catalyst for this shift, prompting organizations to adapt quickly to remote work scenarios and find ways to integrate physical security practices remotely. In recent years, the convergence gap between these disciplines has noticeably narrowed.

What are the potential difficulties for senior management and the individuals leading the IT-OT security convergence process?

The difficulties primarily stem from cultural factors rather than operational capabilities. The integration of different security disciplines often involves navigating human nature and potential concerns regarding diminished roles or titles.

However, despite these challenges, the long-term benefits and efficiencies far outweigh any initial concerns. When presenting a comprehensive security perspective to the board of directors, having a unified approach and a holistic security picture for the organization is far more effective and coherent than having multiple individuals with fragmented responsibilities.

Do you anticipate further security convergence in the near future?

We are currently witnessing an upward trend towards convergence, as companies recognize its value in terms of security, compliance, cost savings, and operational efficiency.

Looking ahead, one disruptive force in the field is AI, particularly ChatGPT. Many security technology companies are incorporating ChatGPT into their product offerings, enabling them to obtain real-time answers and insights on situations, vulnerabilities, and threats. By leveraging the power of AI and large language models, organizations can access and analyze vast amounts of data, expediting the decision-making process.

What is your advice to your peers looking to create a seamless security process in their organization?

Implementing incremental changes is a prudent approach in security convergence. One effective way to do so is by enhancing communication and collaboration among security leaders.

When considering the adoption of new security technologies, it is crucial to involve all security leaders in the decision-making process. This collaborative approach ensures a comprehensive understanding of the technology's capabilities and facilitates the procurement of versatile solutions that can serve multiple security functions across different organizational domains, avoiding siloed approaches and promoting efficiency.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.