Cybersecurity Digital Transformation Governance Leadership

Acing the Security Leadership Recipe for Digital

Acing the Security Leadership Recipe for Digital

Digital has forced security leaders to rethink their department’s strategy, people, processes, tools, governance, budgets, and culture. With the dynamic and volatile nature of digital, it isn’t easy to build a standardized, unified, and cohesive approach to making security forethought and implementing it in the very DNA of the organization. With unique organizational needs and constraints, how are security leaders developing their unique recipes and acing it?

Contributor

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript

Sanjog Aul [00:00:22]:

Hello, and welcome to the segment on CTN. To learn more, please visit ciotalknetwork.com, and the topic for today is Acing The Security Leadership Recipe For Digital. We wanted to cover this topic because, of course, digital is on everybody’s mind. Business wants to go at 100 miles an hour. CIOs and other IT leaders are, of course, trying to support the best they can, but when it comes to security, they have to make sure that nobody loses their shirt in the zeal to get to the next level of innovation and growth, and at the same time, we also have constraints, and we have digital morphing. So it’s not becoming any easier to deal with security, and it’s not going to be a standard playbook that you can pick up and build your program and go with it. So every security leader has to come up with their own recipe in context of their organization and also in context of what they’re doing for digital. So we wanted to cover that, and for that, I have with me Brandon Champion, who is the CISO of Syneos Health. Hey, Brandon. How are you?

 

Brandon Champion [00:01:31]:

I am awesome. How are you?

 

Sanjog Aul [00:01:32]:

Very good, sir. So since I have kinda set the stage on where we are going, we’re talking security leadership and in the context of digital where everything is moving. So let’s start with the first question I would have is we are trying to switch and fix and break and revamp everything possible when it comes to digital. We are purposely creating that flux because we want to rethink everything that we’re doing as a business, and because of it, it’s not getting any easier for the security leaders, but when it comes to someone having a breach, the seesaw gets fired. Should we be holding back for what problems are being created by others? And if we had to tackle this challenge, how will you do it? And how would you even start becoming proactive knowing that the rest of the executives and the team and the whole organization is working in a different direction and you’re supposed to try to control the environment, but you know you cannot?

 

Brandon Champion [00:02:40]:

That’s a very packed question. So let’s take a few bites out of this. Yeah, I mean, just the whole digital transformation, you definitely described it very well. I think it can be summed up in one word. It’s disruptive, and like any sort of disruptive business change or technology change, that’s just going to generate a lot of different moving parts in a lot of different directions. So, security has always been sort of a field of uncertainty, a field of constant change. I would argue that the digital side hasn’t changed that fundamentally. It’s just really exponentially increased that rate of change. So, I think as a CISO one of our primary duties is to remain calm under fire. This is just a great example of an increased stress level, but I think that the fundamental tenets of security haven’t changed dramatically. They’ve just been accelerated to the degree that we haven’t seen in a long time.

 

Sanjog Aul [00:03:50]:

Now, one is the word you used is fire. Now, the assumption is that whenever we’re gonna change things, even our intent is good, it is going to create fire or it’s gonna create bigger fires. Now we cannot say to the business, stop trying to grow or stop trying to disrupt, but if they are not keeping security at the top of their mind, how could you be just left dealing with the tail end of whatever comes out because even that becomes unpredictable, and no one can say they can handle all possible unpredictable situations and events.

 

Brandon Champion [00:04:33]:

Correct. I think it all comes down to credibility with the business. So, you’ve got to, if you’re not already in a position where you’re interacting with the business very frequently, you need to make that happen. Because at the end of the day, as you mentioned, the CISO is often the scapegoat. We can argue philosophically if that makes sense or not, but the reality is that when one breach has happened, the CISO is the one who takes the blame. So with that being said, it’s inherent on us as security professionals to embed ourselves as much as we can with the business, and build up that credibility, and I think once you establish that credibility, as you explain risk, as you explain in business terms what these different opportunities that the business is trying to do as they try to grow and accelerate, what those could potentially mean to the bottom line of the business. It’s a balance between not always the doom and gloom side of security. I mean, it’s really easy to do, but once people hear that enough times, they sort of tune it out. So, you’ve gotta selectively understand when to play your cards, when to really put your foot down on something that you know was a tremendous risk. It’s all about understanding the security side, being able to communicate that in business terms, and again, how you communicate, that’s gonna be directly unique to your individual business and their individual risk appetites.

 

Sanjog Aul [00:06:03]:

Let’s talk about credibility building for a second. Credibility by design whether, a new employee in a company or a leader or other different types of leaders in the organization. Everyone has to build their credibility. I totally get it, but when it comes down to you trying to go and say, okay, I will talk to you properly. I will give you a vision, and it will talk about all of that, but eventually, credibility is built when you have some wins. Unlike other roles where things could be given some structure and you can plan to have some small wins, you kind of control the environment, but with security, you can do all the good and the big talk with them that we should do this or that, but when it comes to really making it happen or to have some sort of win, first of all, you cannot predict it, but you could have a win today, but a big breach tomorrow. So what will you do to sustain that credibility for you to be able to charge ahead?

 

Brandon Champion [00:07:04]:

Yeah. I think you can get some wins even on the field security. So there are tangible projects that you can put in place that would have measured impacts on risk. So I think a good strategy, especially if you’re just coming into the role or just coming into a new organization, is to do something like a security maturity assessment. So that gives you a quantifiable score on where you sit, and then, you should have your 30, 60, 90, 180, 1-year plan. Look at sort of those low hanging fruit items that you can actually implement successfully, run another maturity assessment later on in that year towards the tail end of the year, and you could quite easily demonstrate an actual growth there. I think doing something like that will establish some modicum of credibility. We all know credibility is really difficult to earn, super easy to lose, and that’s where breaches could and probably will happen. I think that breaches, depending on what the root cause of it is, can be a great opportunity to actually increase your credibility depending on how you handle yourself and handle that entire incident flow during a breach.

 

Sanjog Aul [00:08:22]:

Let’s bring up this context of digital now. You mentioned about perhaps doing a security maturity assessment. Maturity is always done in context or in comparison to a benchmark we said that this is the environment we are playing in, and this is how much and how well have we handled or implemented the controls. So we have things, that we can tackle if they do come our way. Come digital, that whole so called static benchmark is thrown out of the window. So could you ever do a security assessment in a digital context where your benchmark is even shifting?

 

Brandon Champion [00:09:06]:

Yeah. I think you can. I mean, while digital is obviously disruptive and is obviously transformational, I think if you’re benchmarking across peer industries, companies of similar size, revenue, industry, etcetera, they’re all going through digital transformation as well. So I think benchmarking is not as static as people may assume that it is, it’s a point in time, but what that point looks like today and what it looks like in several months when more digital activity has happened are going to be different, but I think if you take that with context, the assessment score can still be something of value.

 

Sanjog Aul [00:09:50]:

So let’s hear from you. If you were to pick up, say, top 3 to 5 challenges, which would hold you back from developing a recipe for security leadership and then acing it, what would those be?

 

Brandon Champion [00:10:07]:

So I think the cloud adoption is definitely in my top things that keep me up at night. I would also, the mobile and, yeah, I could even throw the BYOD idea in there as a similar bucket, and then, the increased use of DevOps internally as a way that the company is trying to expand would be one, and then, we could do this in the cloud bucket, but I’m gonna separate it: just the increase, sort of, reliance on third parties. So, even outside of cloud environments, third party service providers would be probably my top four.

 

Sanjog Aul [00:10:52]:

So when you mentioned this, and, Sibin, I used the term digital. Of course, naturally, we will lean into looking from a technology lens, but digital also shifts quite a few things at a business level, at a process level, at a culture level. Where would you see the top challenges for the security leaders in those areas?

 

Brandon Champion [00:11:16]:

Yes. I mean, if we’re looking at it from the non-technology lens, you’re dealing with really people, processes, and culture, and I would argue that culture ultimately dictates your people and your processes. So, having an understanding of what that culture is from a digital standpoint, what senior leadership’s end goal is and how they’re gonna get there is important. Frankly, a challenge can be that a lot of times businesses see digital as a buzzword, as a demand, as something all their competitors are doing, but oftentimes, if you ask somebody to define what digital means, sometimes that’s a challenge. So I think a role of a leader, regardless of whether you’re in security or technology or anywhere in the business, is to help really tie those down and put those in clear attainable language. I think the culture is probably the biggest challenge because it’s going to really feed into all the sub items from there.

 

Sanjog Aul [00:12:25]:

So let’s take a quick break. Listeners will be right back, and when we come back, based on the challenges that you mentioned, so we are gonna build it in a in a flex mode this conversation. You mentioned the top challenges. Now in order to tackle them one by one, how are you putting or what is your foundation that you should build because of course you would have your own recipe but it’ll sit on top of some of those foundational elements you have to put in place so that anything that you try to execute on it is got a firm foundation. So that said, what would those elements be to tackle the technology challenges, to tackle the cultural challenges, and, of course, related processes and, people? What would you do? So please stay tuned listeners. We’ll be right back and explore.

 

Speaker 0 [00:13:19]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Sanjog Aul [00:14:14]:

Welcome back. So let’s talk foundational elements, the very foundation you will build based on which you will solve problems related to people, culture, technology, and everything else in context of digital. So you did mention some of those top challenges. Now let’s talk about solutioning.

 

Brandon Champion [00:14:31]:

Sure. So, I mentioned cloud first, which is obviously more of a technology type problem. So, foundational sort of blocking attacking elements here are gonna be something like a CASB. I hate to use overused terms, but you can’t protect what you don’t know about. With the ability for people to stand up software as a service without even using a corporate credit card in some cases is obviously an area of concern. Something like a CASB would let your security team understand at the very least what’s out there, what’s being used, what that usage looks like, and getting a handle on that. Taking a step away from purely technology standpoint, having good governance over your ability for users to purchase things on their own through a corporate credit card, for instance. We don’t allow any technology purchases over a corporate credit card unless it goes through our vendor management process, and then we have security gates within that vendor management process to ensure people aren’t standing up things that we’re not aware of and aren’t signing off on. Moving a little bit higher than the maturity level is when we start to talk about things like data loss prevention in the cloud. Having a good data classification program in place is a prerequisite to any successful data loss prevention program. If you don’t have a good solid data classification, defining what can be stored in the cloud is important. Are there certain things that can only be put in certain types of cloud environments? If you’re a global business, where the GDPR-related elements of the cloud apply. As you can see, there’s a lot of moving parts once we identify and sort of look at all the potential risk that the cloud offers, but obviously, the business sees the benefit of being able to quickly stand up servers, quickly stand up services, quickly share files across the world. So it is that balancing act that we’re always doing.

 

Sanjog Aul [00:16:44]:

Now you mentioned, about, this whole shadow IT or people using their corporate credit card. Now the solution that you gave, of course, can be seen as, in a traditional world, a way to control the situation, but the perception that goes out about security, and that’s what even IT did in the past, but then they got branded as “no” people. Meaning you’re stopping me from getting things done. If you guys are slow, I need to move at a warp speed. I need to turn on a dime. I wanna be able to do it. So this is the business talking, and if you also then, along with IT or security, do this, then the so called credibility gets a hit. Now there is actually a trend right now to figure out how to embrace this shadow IT or rogue IT, whatever the term that you wanna use, but allow the business to do whatever they need to do, without perceptibly chaining them down by saying you have to go through us. So there are some strategies being used and discussed today, which will allow you to eat the cake and have it too. Any thoughts on that collaborative yet getting to the same end goal approach?

 

Brandon Champion [00:18:11]:

Yeah. I mean, I think that is a distinct possibility, again depending on how mature some of your technology controls are. If you have good solid things that are essentially enforceable, you could tell people, hey, you can stand this up, but you’re not allowed to share our top secret confidential data out on the cloud for reasons x, y, and z, and then you have technology controls to enable that, but then you also say, if you do need to share this, here are the IT or BT approved means to do that. Whenever you say you can’t do something, you need to have some sort of alternative that you’re offering, and that alternative is one that you vetted and that you’re comfortable with. Most of the time, if people see that they can do it, it might not be ideal, but it’s a working option. Again, you’re not gonna have everybody 100% happy, but at the end of the day, you’re finding that balance. To your point, business does want to do things at the speed of business, and security has to run itself as a business likewise. So, when we’re doing these checks, when we’re doing this vetting, we have to be agile as well. Another sort of thing we haven’t hit on yet, but I think is gonna be interesting to discuss is how do we leverage AI and how do we leverage security orchestration and automation. Are those things that we can do as security professionals that are really gonna align our timeline with what the business is looking for?

 

Sanjog Aul [00:19:47]:

Now when you are looking at all of these different things where you want to see things change the way you want, are you just going and asking people to change and they change? Because your influence, it’s not easy for a security leader to exert influence on the rest of the organizations when they know they need you, but they don’t want you. Think about that position.

 

Brandon Champion [00:20:18]:

Yeah, and I think this comes down to individuals and their leadership styles and their leadership approaches. So, I don’t think that the CISO role is ever going to develop into one of pure positional or authoritarian leadership influence. In organizations that are more bound by compliance drivers and regulatory drivers, then, yeah, you could make that argument because the CISO can always point to a law and say, okay, we have to do it because it says this. Organizations that aren’t bound that way, that’s where, again, as a leader, you have to work on other means of influence, and it’s up to that individual or whatever fits the business culture to find that style that’s going to be effective. Because yeah, it’s gonna be really tough to influence people, because at the end of the day, you’re not driving profits per se. You’re obviously preventing loss, which you can spin into the economic benefit there, but end of the day, you’re essentially a call center.

 

Sanjog Aul [00:21:26]:

So should we say and I don’t want to make this claim for everybody, but should we say security leadership is a pipe dream or an oxymoron?

 

Brandon Champion [00:21:37]:

No. I would definitely not say it’s a pipe dream, and I wouldn’t say it’s an oxymoron. I think it’s definitely in its infancy and it’s honestly still figuring out where it belongs organizationally. I know there’s a lot of discussion on where the CISO role should sit organizationally. Should it be part of the IT organization? Should it be directly under the CIO? Should it report to the board? I think the fact that there’s not even a clear understanding of where the role lives organizationally speaks to the lack of maturity we still have in this industry and specifically in this role. I think in a few years from now, there’ll definitely be a more clearly defined understanding of the role’s importance and where it needs to live in the organization.

 

Sanjog Aul [00:22:34]:

So would you say the security leaders like yourself should—I mean, while your end goal is, of course, to help everyone, what should be the mindset or what should be the type of activity so that the rest of the world doesn’t see you as chaining people down or chaining processes or the organization down? Instead, setting them free, and freedom is connection to not having fear.

 

Brandon Champion [00:23:06]:

Again, it comes back to the whole idea of credibility where people see you as a credible resource, as that trusted adviser, as somebody who has that subject matter expertise on security, but is also tied in intimately with the business and what it’s doing. So again, being able to speak to the business, being very familiar with the business objectives, mission, KPIs that the business is describing. All of those things you can wrap security around, given the right level of communication skills, which we haven’t really hit on yet. Your role is to really be, at that level, a communicator. You’re almost the liaison between the business and the rest of your security staff—the ones who are actually going to be enforcing the controls and the technologies. As a security leader, you have to be able to make that translation. If you do a good job, the business will actually see you as an ally, as an enabler, as somebody who can view security as a business differentiator, which is a great end result that you should be striving for.

 

Sanjog Aul [00:24:19]:

So given your experience with dealing with security and being a security leader here at Syneos and also your peers across the industry, if you were to just inventory the specific type of messages or specific type of actions or projects which you did, which hit home, which allowed you to build your credibility, which allowed people to think that you’re there to set them free, which ones do you see top the list?

 

Brandon Champion [00:24:56]:

I’ve struggled to identify just one. A lot of it is really just making yourself available and placing yourself in the business. So, whether that’s in my role, I’ve talked to the audit committee once a quarter and the audit committee has several board members as well, and then we do some work with the board directly. Especially when you’re finding yourself in an organization, being able to use the board as a driving force there really helps because, if you’ve got the board support, that gives you a lot of credibility within the business, and once you have that, it’s up to you not to blow it. Originally, a lot of the work we were doing was around integration and migration. Syneos Health was the result of a merger of equals. I came in right as the first new hire orientation group of Syneos Health. So I was brought in to really help with some of those integration and migration issues. Being involved in the trenches during the chaos that is any sort of merger helps build a lot of credibility with the business too—that you’re in there with them, you’re dealing with the same problems, but you’re also helping them come up with solutions that are gonna make the combined company a more secure place, but more importantly, a better business.

 

Sanjog Aul [00:26:39]:

Let’s take a quick break, listeners. We’ll be right back, and let’s get into another area of delivering an outcome which is desirable with respect to making the fort secure, but keeping it keeping things simple for the other people while somehow figuring out how to manage complexity within the security department and then also even simplifying how you manage security. So it’s simplification all the way through because things fly when you simplify, but what is the devil in the detail which someone has to look for? So step one, immediately, if I could simplify security for the end users, they will love us for that. That builds credibility. That builds affinity, but if it’s gonna kill us internally, that doesn’t help either. So what’s that playbook? What are those action steps that you will take right up front to achieve both of these outcome? Please stay tuned, listeners. We’ll be right back.

 

Speaker 0 [00:27:51]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. Now back to the show.

 

Sanjog Aul [00:28:41]:

Welcome back. So we’re talking about the different kind of demands that are placed and digital is not making things any easier, and what the rest of the community needs, all the constituents needs, the user base, they want you to make it, like, simple and fun to do what they want to do with digital. They don’t care how complexity is bogging you down internally, but even that complexity should be handled in a timely manner so you do not implode as a security group. How do you achieve the two?

 

Brandon Champion [00:29:18]:

So, I think a reason why security and IT in general is fascinating is our role is really to make the complex simple for the end user. It’s to handle all of the things behind the scenes and then put something that’s going to have a great end user experience, enable the business to do what they’re doing. I honestly think that the business isn’t wrong by asking for a simple solution, and it’s not their job to consider the complexity. It’s our role as IT and security leaders to figure out that complexity, but also if there’s something that’s just not realistic, being able to communicate that effectively and impactfully.

 

Sanjog Aul [00:30:06]:

Now let’s talk about something you did mention as part of your previous responses. We spoke about how do you exert influence and build credibility and part of the response was that we got to be a resource to others and I totally agree with you. Now the challenge comes is there’s not only a help needed as someone asks for, and that’s where you act as a resource. There are things that you want them to, where you want them to follow you. You becoming the pied piper. That means you have to do something beyond being a resource so that they look up to you in a certain area and say, okay, we will follow your lead, and if you say to jump, we will ask how high. Not literally in a subservient way, but actually follow you. How does a security executive elevate themselves from just thinking or being a resource to becoming a leader?

 

Brandon Champion [00:31:01]:

Yeah. I mean, I think that’s where some people in the role may struggle with, especially if they’re coming directly from a purely technical perspective where they’re used to measuring success and their ability to execute complex projects, deliver, etcetera. To truly be a security leader, a security executive, that leadership side of the house is something where you’ve gotta take if you haven’t really actively been developing yourself in that manner, that is a key to success or could be the number one reason you fail in that position. We talked already about sort of the lack of your ability to probably have a level of tasking authority over people that you’re trying to do things for you. So that’s where other elements of leadership outside of just your positional authority become paramount to success. I think you can be both a leader and a resource. I think it’s easier to be a resource. Most people in security leadership at the very least have a very strong technical understanding of security, but being both a leader and that resource is something that separates people at a certain level in their career.

 

Sanjog Aul [00:32:26]:

Where have you seen it? There may be instances. Or not all throughout, but you yourself may have seen that a certain act or a certain set of words or something that you did working with others gave you that elevation even though temporary from being seen as a resource to people saying I’d like to follow you or they showed signs that they want to follow you.

 

Brandon Champion [00:32:48]:

Yeah. I mean, just not trying to pass the buck somewhere else or not saying it’s not my problem or not saying this is outside the scope of my role. I think people are drawn to leaders who embrace challenge, who are looking forward to taking something that’s very complex and very challenging and goes across different business units and owning it. So just being able to say, hey, I got this, and executing on that more importantly. I think that the confidence and the willingness to accept something challenging goes a great deal to at least the appearance of leadership, and again, your ability to deliver on those promises is really what’s gonna make or break you after that fact.

 

Sanjog Aul [00:33:41]:

Now let’s talk about your approach to the fundamental rethinking in a digital context about the people, the processes, the tools, and the culture. Now, of course, you are thinking about all of those regardless, with or without digital, but since we are talking in the digital context, how would people do things new, more, or different to achieve that optimum balance?

 

Brandon Champion [00:34:12]:

Right. So, I think one of the foundational elements of digitization is taking processes that weren’t digitally based and turning them into a digital approach or taking a solution and turning it digital. So anytime you’re making a transformation of that type, it’s a great opportunity for improvement overall. Improving the efficiency of a process, and our role in this is to improve the security of those processes. It all goes down to the culture changes needed in the business where if they embrace security and they see it as something that could differentiate their business, I think your success rate is gonna be much higher. Whereas people are baking in this idea of security as they’re revamping these processes and turning them into digital solutions, it just becomes part of the normal cadence of this transformation.

 

Sanjog Aul [00:35:14]:

Now one is to be able to influence people below. Another is for you to take charge and be seen as someone even executive management would be willing to follow or the board will be willing to follow. Different styles perhaps, managing up and managing down. What do you think has happened on the ground with you? What your actions, your words, your approaches have made people above you to see come and seek your advice or look up to you?

 

Brandon Champion [00:35:48]:

Yeah. I think your communication style is definitely going to be different depending on the level of organization you’re trying to communicate with. So, I do a lot of communication with technology leadership, and just the amount of detail that I’m gonna provide to them is tremendously more than the amount of detail that I’m providing to the audit committee or to the board. I’d take a 3-slide deck to the board. That same information, I would expand to maybe 12 slides for technology people because they’re interested in those details. They want to sort of see underneath the covers of what’s going on while the board is 100% interested in just risk, and being able to take that and articulate it to a risk level to the board and just speaking their language. Something that I did just for personal development, I went back to school and pursued an MBA because I specifically wanted to be able to speak business. I wanted to be able to understand the reports that they’re reading and they’re being evaluated on. I think being able to speak their language gives you almost that “he’s one of us” feeling versus going in with a technical approach.

 

Sanjog Aul [00:37:23]:

Now, I’ve seen dealing with quite a few leaders is the folks who really are able to get a patient ear from the executive management and, even taking to the next level, they start following that individual. These individuals create a cadence of innovation or innovative ideas which they take back to the leadership, invite them to a forum, discuss with them, and get their blessing maybe for some of them, have the team under this security leader, for example, or an IT leader, get them focused on execution and then they move on to the next 3 to 5 that they are gonna pitch the next quarter. Do you think that model of you always blazing a new trail, going and looking at what are possible, and staying ahead, and showcasing those things on a regular basis with a cadence, fly for a security leader.

 

Brandon Champion [00:38:25]:

Yeah. I would take that approach and modify it a little bit. I think we shouldn’t always be trying to put whatever the new shiny buzzword or new tool of the day is in place all the time. I think you want to be able to show demonstrated measurable improvement every time you’re coming in front of some sort of body that’s evaluating your work, but I think it’s important that we don’t lose sight of the fact that a lot of companies already have significant investments in tools that they bought in the past. We don’t want to just put something in place to check a box saying, hey, we have this. There’s an underappreciated amount of value in really optimizing your existing investments. I think that’s something you can also highlight when you’re doing these presentations: not only do we install new technology x, y, and z, but we also automated something we already have an investment in, and we’re seeing X% reduction in whatever that tool is designed to do. So optimizing existing investments as well as putting in new technology to stay ahead of the latest threat is a definitely good combination for success.

 

Sanjog Aul [00:39:53]:

So totally, point well taken about not trying to go after the shiny toy. What I was hoping to get validation on is that instead of being reactive—waiting for somebody to ask, “what are you worth?”—you take ownership of reaching out every quarter, setting up a steering committee or that sounding board comprised of executive management. Present to them that this is where we are going as a business, this is where the security landscape is going, and we are supposed to look at things a little differently or more broadly, and these are five opportunities that we can tackle. So we will not then be stopped or be disrupted by a breach. I cannot guarantee it, but at least it’ll reduce or minimize those chances, and we’ll be able to confidently move forward. So you’re no longer waiting for that call to be audited or be evaluated on your capability or your group’s capability. You are actually going back in front of them and saying every quarter, I’d like to bring these four ideas, out of which you may fund two of them, but at least we are making forward movement. Is this being done by security leaders at a cadence and proactively?

 

Brandon Champion [00:41:12]:

Completely agree. When I do my updates, it’s always a combination of, here’s what we did this quarter, here are the things in the works, here are the things that we want to fund, and we always share an updated 3-year roadmap where the detail in the current year is broken down into quarters. The next year it’s broken into halves, and the third year is a little more vague. We always want to be moving forward with an understanding of where the business is going. Is the business looking to expand internationally? Is it growing? Are we gonna do some acquisitions? What are the major digital transformations that are gonna be happening? What technologies are gonna change? Staying ahead means you’re not trying to bolt a security solution on after the fact. It’s a way to increase both your visibility and your credibility at the same time.

 

Sanjog Aul [00:42:19]:

Let’s take a quick break, listeners. We’ll be right back, and once we are back, let’s look at the leadership side itself, which means a good leader can be or should be confident but that person shouldn’t be afraid of showing their vulnerability that, hey, I do not have answers to all possible questions, so I need help. Is it okay for a security leader to show that vulnerability in front of people below and above them with an honest intent to get help to move or rather secure that organization, or are we supposed to always come across as a hero that nothing can phase us out? What should be the mindset and what should these security leaders be doing today in context of digital where things are truly not in their control. Please stay tuned, listeners. We’ll be right back and explore.

 

Speaker 0 [00:43:25]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. Now, back to the show.

 

Sanjog Aul [00:44:16]:

Welcome back. So imagine, Brandon, I’m driving or you’re driving with your family in a car and you’re not feeling the most comfortable in the region that you are or you’re not sure or you’re lost. If you tell the rest of the family, hey, I’m lost, that really doesn’t put your family at ease, but if you don’t announce that, then you don’t get possibly the help you need or ideas from the family for you to be able to take the whole family to the destination safely. Drawing that as a parallel to what you do as a security leader. Yes. They look up to you, the whole executive management, and people look up to you to keep the breaches away or basically reduce or minimize the damage, but you cannot play the hero. You cannot have that imposter syndrome overtaking your true abilities and actually taking your organization to a vulnerable position itself.

 

Brandon Champion [00:45:29]:

Yeah. It’s a pretty good analogy between business and family. Theoretically, your family’s there to work together for a common goal, and you hope that in business, your fellow leaders are doing the same thing. I think in both cases, as a leader both in the family and in the business, it’s really imperative that you’re transparent. Transparency in leadership helps with the overall viewpoint of how people are perceiving you. What you don’t want to do is not be honest. While not easy to do, you can be confident without having all the answers. There’s ways that you communicate while still maintaining your credibility and your confidence level to say, hey, I don’t know what the answer is. However, here are the steps I’m gonna do to come up with a solution and I’m gonna partner with this expert third party who is really good at this area that I’m unsure of. At the end of the day, we’re gonna come up with a solution that’s going to meet what the business is trying to do.

 

Sanjog Aul [00:46:46]:

So any suggestions for the listeners? Because this is not an easy question, and it also puts a security leader on a tough spot, and a lot of people struggle as I know because I talked to a lot of them.

 

Brandon Champion [00:46:58]:

Yeah. I think any individual leader needs to really take an honest inventory of their strengths and weaknesses. Nobody is perfect. Even the best leaders in the world have flaws, and it’s okay. We’re all human. We all have issues that we’re not the strongest at. Leaders that continue to develop themselves take that inventory of where they’re good, where they’re not, and take steps to address the areas of improvement. If you’re constantly developing yourself in areas where you’re not strong, you’re gonna become a better employee, but more importantly, a better person.

 

Sanjog Aul [00:47:42]:

And a good leader is supposed to basically build other leaders. That’s their legacy, and for that to happen, you got to give yourself the breathing room so that you have the time to help develop others versus just fighting fires, and also allow your people to have the breathing room so that they can work on themselves and evolve themselves with your help or otherwise. Is there something specific, intentional, and procedural or in a structured manner done by people like yourself in the security domain in context of digital where people have more than a spinning plate and literally there’s no time to breathe to make sure you reduce the workload on them?

 

Brandon Champion [00:48:36]:

Yeah. I think automation can help. There’s obviously a big push in the security space for orchestration technology, things that allow us to leverage things like AI to do a lot of the repeatable tasks that eat up a lot of the security team’s time. Freeing them to sort of do more interesting and more challenging work that is more tailored to individual development helps the team get results, but then also helps people to move into those areas of specialization that they’re really passionate about. When people are passionate and having that career development at the same time, it’s really a win-win for everyone involved.

 

Sanjog Aul [00:49:23]:

One final question I have for you, which is about going and trying to make sure that what happens with digital going forward, I mean, part of it we know, but many things which we don’t. The uncertainty, the volatility, the complexity, these things are not going to get any lesser. So this security leader who we have today, including yourself, you might have to shed the current skin and get a new skin, the thicker one, to be able to figure out what will you do in this particular madness, which is not going to get any less. What would you recommend for people who are trying to become the best security leader they can be so that they can say, yes, I am ready, and I will defend the fort.

 

Brandon Champion [00:50:20]:

Yeah. It’s all about embracing change. We can have a couple different reactions to change. We can resist it, or we can come to appreciate it and see it as the way that our business is working to remain competitive and to grow. If you see that and change your lens to see changes as something that you’re welcoming because it’s a sign that the business isn’t stagnant—the business is adapting to the future—you wanna be part of that. Security in general, most people got in the field because it is ever changing, because it is something different every day. See this as an opportunity to get more of that faster pace. How you deal with conflict, how you deal with challenges, it’s on yourself how your attitude sees it. It may take some effort, but if you frame your mindset around changes being positive and just embrace that and go with it, you’re gonna set yourself up for success.

 

Sanjog Aul [00:51:25]:

On behalf of our show and the listeners, thanks so much Brandon for sharing your insights about how all the security leaders can develop the security leadership muscle, a good recipe, which is very unique to their organization and the constraints and the goals that they have, and actually work towards acing it. Thanks so much. This was very, very valuable.

 

Brandon Champion [00:51:48]:

You’re very welcome. I enjoyed it.

 

Sanjog Aul [00:51:50]:

Thanks so much and hope listeners you got some good nuggets out of this conversation. Please like us on Facebook, search for CTN, and be sure to follow us on Twitter and join our LinkedIn group, and listen to our podcast on over 23 syndication channels. We are almost everywhere where you can find a podcast, so please listen and please rate us. Thanks so much again for listening to this segment on CTN. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.

Contributors

Brandon Champion

Brandon Champion, Chief Information Security Officer, Syneos Health

Brandon Champion has over 20 years of technology and security experience and joined Syneos Health as its Chief Information Security Officer in 2018. Syneos Health is a global $4B Contract Research Organization (CRO) with over 25,000 employ... More   View all posts
Add Comment
Click here to post a comment

Advertisement

Persistent - HiTech- MPU - 300x250
Brandon Champion