enterprisesecuritymag

| | ENTERPRISE SECURITY8 JULY - AUGUST - 2021Former CSO at Facebook and Yahoo, Alex Stamos perhaps summed it up best when he said,"It's kind of a crappy job to be a chief security officer" because "it's like being a chief financial officer before accounting was invented".The absence of an executive playbook and lack of a universal language to communicate with the business can be overwhelming. But while working in cybersecurity I've observed a few structural differences that elevate some teams ahead of the rest; there are often things they do which have made them more successful.STRUCTUREThe first thing to say is structure isn't about job titles. Nor is it about technical specialists (more on that later), this is about some key roles in cybersecurity teams that I've seen deliver transformational effects.A cybersecurity leaderThis is the strategic cybersecurity leadership position in an organisation and is ultimately responsible for cybersecurity performance. The leader (usually the CISO) needs to think bigger than preventing ormanaging the next incident; they must formulate a plan that articulates where they are now, where they want to be and how to get there.They are responsible for building digital resilience across all critical business functions. With the average tenure of a CISO often less than 2 years, it appears many organisations areover-emphasising the operational aspects of cybersecurity and not placing enough value on retaining a custodian to look after the long-term interests of the organisation. The CISO needs to answer severalresilience and team performance areas such as:· Developing the organisation's digital resilience capabilities to a performant structure.· Continuously adopting the best from others while creating the team's own standards to achieve the vision.· Contributing back to the cybersecurity community and raising professional standards.The CISO reporting line is debated frequently and a lot has been said of the conflicts of interest reporting to a CIO. But the common success factor I've seen is whether messages reliably reach the board in terms that they can understand and objectively assess. In this sense, it is important that cybersecurity is effectively communicated in the context of business performance and other operational risks. At the same time, the importance of the board's role in performing oversight and challenge of the CISO and his team is critical (see Non-Executive Director). Strategy, intelligence&analyticsThis is someone responsible for promoting the use of facts to make better decisions. The role focuses on data and evidence, whether that is at the technical and tactical levels of security operations and application development, operational level of risk management or strategic level of governance, technology strategy and resilient business performance. Across all business levels, it is rare that non-security people care about security arguments and so this role needs to be expert at translating between data and technology specialists and business context. When collected, wrangled, and analyzeddata can provide tactical, operational and strategic benefits. Figure 1 illustrates how high-quality intelligence supports decisions by matching data and intelligence products to the complexity and time horizon of the decision-maker. Security architectAs Alex Stamos quote infers, cybersecurity is a field fraught with disorder. Intervening in this disorder requires sense-making and planning skills that cover the organisation's technologies HIGH PERFORMANCE CYBERSECURITYBy Simon Goldsmith, Senior Director Information Security APAC, adidasSimon GoldsmithIN MY OPINIONIN MY OPINION
< Page 7 | Page 9 >