THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Urmas Aamisepp, Head of Information Security, EpirocEveryone seems to agree on Zero Trust being the way to go in the future, and it makes sense. There are so many attack vectors and potential adversaries out there, it’s really hard to trust anything these days.
“Just naming the project differently can make a huge difference because you put the focus on their day-to-day operations and what matters to them”
But agreeing on Zero Trust with your fellow security practitioners is one thing. How do you make your other colleagues understand that it’s a path we must take? In some areas, it may add to what they experience is the “burden” of security, like some users reacting badly to having to use two-factor authentication as they view it as a time thief. Not by many seconds, but still. You may meet resistance when you launch security projects just because they are security projects.
The job of being responsible for information security and/or IT security has many facets: Creating an Information Security Management System, enforcing those policies and guidelines, doing risk assessments etc. But actually – it’s largely a sales job! As soon as you have an initiative going, you need to sell it to the different parts of the organization. Rarely does a security project raise any excitement in the business as they just want to continue doing their business as painlessly as possible. And that’s where the selling part comes in.
Just naming the project differently can make a huge difference because you put the focus on their day-to-day operations and what matters to them. This, of course, requires that you have a good understanding of the business so you can sell it right.
As an example, a typical thing to do in a Zero Trust effort is to enforce “least access” policies for users, i.e., only give them the necessary permissions in different systems for them to do their jobs. This can be a sensitive thing to do in an organization where they’ve always had very generous access granted in systems, sometimes in order to be able to help each other but sometimes because “that’s how it’s always been”.
In this scenario – imagine you were responsible for a department or a division that isn’t involved in security on a daily basis. Which one of the below project descriptions would make you feel better about talking to the person presenting it?
1.This is a security project where we need to remove access rights for your staff in order to ensure no one is able to do anything outside of their specifically assigned work tasks. This is part of our Zero Trust initiative.
2.We are launching an initiative to minimize production disruptions where the goal is to have 99.5 percent uptime on all systems relevant for to conduct your business. It will bring about some changes in system access rights but it will stabilize the production environment.
The presentation of the security project will almost certainly lead to negative reactions, as the user’s rights are being limited and they feel that something is taken away from them. However, the project to minimize production disruptions is most likely to have a rather positive reaction, and you’ll be met with curiosity rather than animosity.
This is just one example (albeit very simplified) of how you can get a better relationship with the business by just selling security projects as business enablers. Because, if a project doesn’t enable the business, should you even be doing it?