enterprisesecuritymag

ENTERPRISE SECURITY| | 9JULY - AUGUST - 2021and anticipated threat activity. Through development of integrated frameworks,a security architect aligns all the cogs of organisational development. A word of caution, a significant part of cybersecurity is the chaos and complexity driven by both incidents and our organisations' pace of change - so what is known and what can be anticipated becomes less obvious. The best architects drive more of the cybersecurity team's work into ordered structure and automation for expected events while also increasing the organisation's potential to tolerate the unexpected.Figure 1 ­ Examples of Cybersecurity Risk Communications(@madplatt) Figure 2 ­ Varieties of human work (@safediff) People DevelopmentLeading teams recognise that behavioural psychology skills are crucial to cybersecurity as the systems we defend are both people and technology. This role shapes the way the team acquires, develops and maintains the right information security skills. A process and programme for learning and development is crucial - not just for the team members but other teams throughout the organization. Apart from embracing modern behavioural science, a common target of successful organisations is to resolve dissonance between work as imagined by the cybersecurity team and prescribed in policies and work as done by the business. There will be gaps (see figure 2), but with some humility and by aligning policy to business performance objectives and constraints, there is potential for transformational change. This in turn drives the culture and behaviour of the cybersecurity team, and their acceptance within the entire organisation. Non-Executive Director (Cybersecurity)Boards already appreciate the value of including someone who is expert at something they consider critical to their future success. The non-executive role is still rare in cybersecurity, but it makes sense to have someone who acts as an independent bridge between the board and the information security team. This role may involve:· Ensuring the board continually review how the cybersecuritystrategy is being delivered and looking for ways to help those tasked to deliver it.· Assembling acommittee to meet with the CISOandadvise on team and performance. The purpose being to support the CISO in navigating internal teams, regulators, suppliers and threats, not to put pressure on them.The benefit of this role is having someone grounded in disciplined cybersecurity fundamentals who is not embroiled in the politics of the organisation.A NOTE ON SPECIALISTSHow often have we seen cybersecurity job specifications with a long list of every possiblecyber skill set? High performing cybersecurity teams have technical depth. However, designing and implementing secure, resilient systems (infrastructure and applications) requires different technical know-how to efficiently and reliably detecting, triaging and responding to incidents (SecOps). These disciplines are supported bycybersecurity governance, risk analysis,stakeholder engagement and anticipation of threats, all of which should also be treated as specialist skills.FINALLY - LEADERSHIPWe can talk at length about structures and specialisms, but, ultimately, it's human relationships that count most of all. A common thread to a security team's success seems to bemindset, rather than the skillset. This mindset involves having an expansive view, understanding how relationships improve risk management and being eager to grow others and the cybersecurity community. Ultimately it is about being the relentlessly energetic force the enterprise needs for transformational change. ES
< Page 8 | Page 10 >