THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Mark Alvarado, Executive Director of IT Security & Compliance, Academy Sports + OutdoorsI have been in IT for over 20 years with a focus IT security for the last 12 years. The number one issue that I hear from my peers in the cyber security space is funding, by why? Why is funding for a cyber program hard to get when cyber-crime is at an all-time high. It’s difficult to read or watch the daily news without hearing about a ransomware attack or data breach event somewhere in the world. It’s also well known in the IT recruitment space that there is a shortage of qualified cyber professionals. Additionally, the pay for cyber professionals is also higher than most other IT roles. Which brings me back to my question “Who do cyber security leaders struggle to get their security initiates funded”?
In my opinion, there are to primary reasons why. First, the cyber security leader fails to effectively communicate to their senior leadership. Secondly, the cyber security leader fails to effectively explain the business need. I know that my opinion may upset a few people, so give me your patience for a bit and let me explain my points.
In my first point, I do believe that it is important and necessary for a cyber security leader to have a strong knowledge of IT security from an operational and GRC perspective, but it is equally important to have a strong knowledge of finance and the business. It’s important for a cyber security leader to understand what technical gaps exists in area, but he also needs to understand the cost measure the technical cost against the companies long-range-business-plan, known as the LRP. If the two do not line up, the cyber security leader needs to go back to the drawing board and find a plan-B. In fact, he or she should always have a plan A, B, and possible C to ensure the business that due diligence was done. In the cyber world its not just about technology it is also about cost, and both need to be weighed while building the cyber strategy and roadmap. The cyber strategy is not just about securing the data, it is also about data privacy and meeting the current and future cyber needs of the business. This will require the cyber security leader to have extensive knowledge of the current cyber landscape and what is potentially coming. This ultimately requires the cyber security leader to be re-active and proactive.
”IF TECHNOLOGY CAN BE USED BY ATTACKERS TO STEAL COMPANY DATA, THEN TECHNOLOGY CAN BE USED TO SECURE COMPANY DATA”
In my second point, good communication skills are essential in any role in life but is highly needed in a senior leadership role. Learning the preferred communication style and method for each senior leader is crucial to effective leadership. Also, learning what are the key business motivators will help the cyber leader determine if his or her strategy and roadmap are in alignment with the goals of senior leadership. Often, I see cyber security professionals who are focused on technology and miss the business side. This puts the cyber security leader at odds with his leadership. If all are not aligned, getting funding for the cyber security program becomes even more challenging. Each leader tends to have a topic or priority specific to their role, the cyber security leader should learn this and determine if his or her cyber strategy has any synergies. If it does, great, point it out in the presentation. If it does not, re-evaluate the cyber strategy and see if the senior leaders’ priorities can be added to the strategy. In learning to communication style of the senior leader, the cyber security leader can focus finetune his or her presentation. In my experience, some people like visual presentations such as power points. Some people like a lot of detail in a formal setting. Some people prefer to just to have a fluid conversation in a comfortable atmosphere. Most like a pre-read of the material a least a day before. Whatever the style or method, the cyber security leader needs to learn it.
I think that my points can and should be followed in any leadership position, but cyber professional are different bread. A good cyber security professional needs to be detailed oriented and have extensive knowledge in all areas of IT, criminal law, insurance and risk, data privacy, finance, regulations & compliance, and physiology in relation to crime. People with type of knowledge tend to be very logical and analytical, lots of times a little lite on people skills. In my opinion, social skills tend to be something we (cyber professionals) have to work on. If the cyber security leader learns how his leadership and peers prefer to communicate and takes the time to learn the companies LRP, he or she will be able to acquire the necessary funding to their security initiatives.