enterprisesecuritymag

APRIL 2023ENTERPRISE SECURITY| | 19By Ramón Serres, Information Security (CISO) and IT Quality Director, AlmirallA CONSTANTLY CHANGING CONTEXTThe CISO Role: What to Expect and How to Stay RelevantIntroductionThe CISO role is heterogeneously implemented across businesses and organizations. Its definition and organizational positioning depend to a great extent on the size and maturity of the business and organization, and its risk exposure, that is, to what extent critical or sensitive information may be at risk due to cyber-security threats, or to what extent critical business processes and operations are at risk. On top of all those factors, I would add that it also depends on what vision have the CISO and the C-level for the information security function. That said, the context is evolving for everybody, and as such, has to evolve the CISO role to stay relevant or, at least, to stay as relevant as it ought to in line with the current and future needs of that organization in particular.Many things change in our context, but let us point at four of them that are quite different versus the - The IT landscapes are changing the ratio between traditional on-premise infrastructure versus cloud infrastructure. This is a short headline that entails a whole set of different requirements in terms of governance (not only IT governance but also, more holistically, enterprise governance), and risk management.Ramón Serres is an Industrial Engineer who has led and transformed the Information Security function in the last 8 years in ALMIRALL, a medical dermatology leader in the pharmaceutical industry. He has an extensive background as an IT manager and has worked in several industries from consulting services to consumer goods and the pharmaceutical industry.CISO INSIGHTS
< Page 9 | Page 11 >