THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Kate Silverman, Head of Security Architecture and Consultancy, Direct Line Group [DLG: LON]It’s no secret that businesses want to move faster to reduce the time to market for new ideas and initiatives and ensure they keep relevant to their new and existing customer base. To facilitate this, technologies such as cloud native services, machine learning and agile methodologies are being utilised. With more digital journeys, new technologies and faster product iterations, security is more important than ever – so how can security be leveraged to support a scaling business? It could be as simple as; education, innovation and automation.
We need to start speaking the same language and drive the message that security is everyone’s responsibility, and this is where education is key. We should be tailoring education to specific user groups and personas across organisations - to ensure relevance and to keep up levels of engagement. Let’s educate our developers in the importance of secure coding and drive learnings off the back of automated security tooling reports. But most of all let’s make it relevant and interesting. The same needs to be true for the entire business, front and back-office teams, system designers, developers and architects all need to be taken on the journey as to why we have certain security processes and tooling in place. Spoiler alert – it’s not to make life difficult!
As a member of a security team, I recognise that we all have a responsibility to keep up to date with the latest trends and technologies. Businesses must innovate to stay relevant, and they need security to be ready to support. This was demonstrated at the start of the pandemic across multiple industries. Most companies had to review their office working patterns overnight - collaboration platforms were spun up; computer bundles were pulled together, and multiple teams worked together to achieve this - including security.
Security must be willing and ready to support Minimal Viable Products to ensure speed to market, however, the business needs to be aware that there will be some redlines. It’s security’s responsibility to be transparent about the rationale for these, so the business understands why these are in place and the necessity to work within them.
“Security must be willing and ready to support Minimal Viable Products to ensure speed to market, however, the business needs to be aware that there will be some redlines.”
Finally, there is automation. We need to move fast and integrate where possible with existing business processes. By thinking about security from the start of a project, we can be aware of threats from the outset, resulting in a reduction to risks and associated remediation costs. Increasing early engagement can be achieved a variety of ways. One method I have seen successfully work multiple times before, is through aligning security Subject Matter Experts (SMEs) to specific business areas. This enables the business and SME to build trust and continue the security education and awareness across multiple projects and initiatives.
Security should constantly collaborate with the business to identify opportunities to reduce the time the business spends worrying about security. Some examples include the use of infrastructure as code and defining reusable patterns and building blocks for repeatable activities. This not only drives consistency but increases speed and reduces the possibility of tooling federation.
None of this is new. Trust and understanding is key to any partnership, and it’s the responsibility of both the business and security to work together to drive success.
Strong cyber security fosters trust and with trust brings an increased customer base, greater engagement and enables business growth. It’s time to change the narrative and ensure security is a key part of a business’s strategy.