Digital Transformation Leadership Talent Development

CISO as a Digital Business Leader

CISO as a Digital Business Leader

As a CISO, how are you grooming your team to understand the goals of your digital business, identify and assess the risks, and recommend effective yet cost-efficient solutions in business terms? How are you helping your team members to become effective communicators and problem solvers while you hone your leadership skills?

Contributors

    • Leon Ravenna, Chief Information Security Officer, KAR Global
    • Harshal Mehta, Vice President, Chief Information Security Officer, Carlson Wagonlit Travel (CWT)
    • Eddie Borrero, Chief Information Security Officer, Robert Half

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript 

Sanjog Aul [00:00:23]:

Hello, and welcome to this segment on CTN. To learn more, please visit ciotalknetwork.com, and our topic for today is CISO As A Digital Business Leader. Who doesn’t know what a CISO does? A tough life for people who are living this role, and I have three of them here today. I’m gonna shortly introduce you to them, but the topic that we have picked up is because digital is making everyone crazy. Of course, business wants to see it as a good crazy where they want to grow their business and move it forward, but that doesn’t mean it takes away the risk and the volatility of what digital brings with it, and that’s where the CISOs are supposed to handle it all, or at least they are expected to handle it all. Are they ready for it? Is their team ready for it? What do they need to get to, or which level do they need to get to so that they can call themselves as a digital business leader who happens to be handling risk and security? That’s what we are here to discuss. So here, my first guest here is Harshal Mehta, who’s a CISO with CWT.

 

Harshal Mehta [00:01:31]:

Good, Sanjog Aul. It’s been a pleasure joining on the call and sharing perspectives today.

 

Sanjog Aul [00:01:37]:

Beautiful. Thanks so much, and Eddie Borrero, CISO of Robert Half. Hi, Eddie. How are you?

 

Eddie Borrero [00:01:42]:

I’m great. Thank you for the invite, and thanks for having me.

 

Sanjog Aul [00:01:46]:

Amazing, and Leon Ravenna, CISO of CardGlobal. How are you, sir?

 

Leon Ravenna [00:01:52]:

I’m doing great today.

 

Eddie Borrero [00:01:53]:

Thanks for having me.

 

Sanjog Aul [00:01:54]:

So, Harshal, let’s start with you since I announced your name first. We talk about digital, and it is no longer the digital new because it’s been around for a while. People are talking about it. People are living it. It’s gone mainstream. So when you talk about the journey that’s going on from an organization standpoint, they also have to be able to effectively handle the security and risk management function, and I’m assuming CISOs were given that back to hold and run with it. What do you think has happened to date when you tried to do it in your role? And what have been your learnings?

 

Harshal Mehta [00:02:33]:

Yes, I think an interesting perspective, especially when we are talking so much on digital, CWT just went in a few years back into the digital journey, and just to recap, CWT does a lot of business on the travel management side, and this is a space where it’s not a crazily fast world. We still have to make systems, legacy environment. So digital was something completely new on the blocks, and especially for a TMC to come on the block and make a difference, risk and security play such a big role, a massive role because what came up with the digital tag was to have faster to the market journey. We need to have our applications, our environment moving really quickly to give that free to our travelers and to our end users. So what that means to us from a risk and security means we need to be faster. We need to support these applications. We need to support these developers who need this faster world to accelerate and to grow means more responsibility, means we need to be more agile and more aware on how these environments would be talking in. Number one, covering from the legacy environment to the big world, and Number two, when we have so much PII data, so much of traveler information, the onus on us from risk and security more and more. So bringing that value out in this whole journey was of a key importance. I think the journey has been incredible, especially looking the way security and risk has evolved, just not in the TMC space, but even in the industry perspective, especially on the digital side is no longer security as being looked as a support function in an IT organization. It’s been looked as more of a function which makes a difference. A lot of the times I go into the customer’s call or calls with regulators, and the first question is how well is your security program? How well is your security program maturing? So it’s not an IT question anymore. It’s more of, I would say, a differentiator or a competitive advantage, especially for businesses and dealing with personal information or having so much, adherence on the e commerce side. So I would say, some of the key points the key points for us was how do we manage this whole transition, the business on the digital journey? How do we support them, especially on the security side, in making a difference? Because most of the times, we have to make sure that all the environment, all the applications are secure, and the third question is to wrap it up would be giving them a competitive advantage or giving them some of which they can go and talk and say, yes, from a security program perspective, this is what we are maturing.

 

Sanjog Aul [00:05:43]:

So, Eddie, when you look at what Harshal mentioned in his ecosystem, his organization does something different, totally different than what you do. When you looked at digital for your organization, what was the business looking for? How did they perceive before they started on the digital journey in terms of what the risk and security aspects would be? And how different did it turn out as you tried to support them as they started adopting digital?

 

Eddie Borrero [00:06:11]:

It’s an interesting question. I think my organization looks at digital as a transformative, differentiator. Right? So when we look at our business, 10, 20 years down the road, we’re looking at how do we transform through digitization to to be the leader in, , and that we are today 20 years from now. So we look at this as something that’s changing how we work end to end and how our customers experience us. So it’s big. When we say digital, it means we’re transforming our business, and so from a security perspective, our organization really values our brand. Our brand reputation is kind of number one in the space and we all know what happens to brand reputation when cyber breaches happen. This is a board level issue in my organization. It’s taken very, very seriously, and as you mentioned, a lot of the expectation falls on my shoulders, and so, I think the only couple things I would add to the conversation at hand thus far would be I think, we don’t look at moving fast. We look at integrating, and so how do we help our business understand their own risks and help them deal with it as well as do the traditional security work in a way that’s integrated into how the teams are working. I’ll give you a couple of examples. If you think about digital, it’s an agile type of model. Typically, moving fast, getting some minimal viable solutions in place as quickly as possible. To do so, you typically have a 3-pronged process. You have the design, you have the build, and you have the run space or the operate space. We start to put ourselves in the shoes of our business and our technology teams and we start to work with them very closely around how do we best support you without getting in the way and how do we best support you without having to keep up with you because it’s hard to scale, for lack of a better term, when your business is skyrocketing in a digital age and era, and so a couple examples are, as we do product development, we have security product owners in that conversation. We’re working with our teams, that type of thing, to where, we’re shifting left. We’re making sure that the business knows what our security requirements are upfront. We’re, as much as possible, integrating how security is done in the development cycle, and then we incentivize operations teams to make sure they’re doing all the traditional security controls that they need to be responsible for. On top of that, we practice excellence within our own world. How do we I have it I call it the leave no event behind scenario, where we’re capturing as much as we can. We’re actioning in a way that’s militant, for lack of a better term. So, there’s a lot to it, but in essence, we’re integrating as much as we can where we can. We’re educating as much as we can where we can, and we’re building excellence in our operations when it comes to security. So it’s kind of my tact where it’s now it’s not just the security organization’s problem. It’s everyone solving the problem together.

 

Sanjog Aul [00:09:35]:

Awesome. So that’s great. Eddie, based on your response, Leon, I’m gonna come to you given Harshal had his own take and Eddie did his own, and Eddie mentioned that we are gonna try whatever best we can. Now the question for you, Leon, is how does business see when they talk to security? Do they say take $1,000,000, do what you can, and I still want this port to be secured, and if it is not, then you’re fired. What is the business looking at? Because they want to run like a Ferrari 120 miles an hour, and they don’t want to be stopped. They just want you to be there as a brake, which say which gives them the assurance that you will not let them topple over, but they really don’t want you as security. Sure. So in that kind of a mode, what is the demeanor? What’s the mindset should CISO embrace for them to be able to be that brake for that Ferrari that they are building?

 

Leon Ravenna [00:10:32]:

Oh, thanks for letting me be the one that nobody wants to talk to. It’s been that way my whole life. Really as we look at it, my job is a little bit different than Eddie. He used the word militant and we try not to do that. We still end up doing it sometimes, but realistically, we’re trying to be more collaborative and set guardrails for people. You can operate within these bounds and go run as fast as you can as long as you adhere to the bounds I give you, and so to go back on that to a little bit of the other question that you had, it’ll probably help fill it out a bit. When you look at Car Auctions Services, we’ve recently changed our name and rebranded to Car Global because we have operations in Mexico, Canada and Europe, and if you look at what would be considered a legacy operation, an auction for us is 180 acres, 14,000 vehicles, heavy, heavy, heavy infrastructure. Making that move to run faster where there’s people who are trying to eat our lunch just on the technology side is huge, and so we look at a couple of things. 1 is we are doing a cultural piece to try and change how people think and how they act. So we can’t be, , and it’d be real easy to drop into talking about tech speak and IOPS and stuff like that, but we don’t.

 

Eddie Borrero [00:12:03]:

We try and keep it at

 

Leon Ravenna [00:12:04]:

a business level and what the risk is that we’re trying to address. So when you say, I’ll give you $1,000,000, well, it might not be $1,000,000. It might be $10 but it might be $10,000,000. So we look at it from a risk perspective on what we’re actually needing to defend against and what are the threats that we actually can defend against. So for instance, I can’t defend against China and I can’t defend against Russia, but we understand what our threat model is and build in with risk to that piece.

 

Sanjog Aul [00:12:37]:

So Harshal, if I were to ask you what are some of the Can I ask you

 

Eddie Borrero [00:12:40]:

real quick?

 

Sanjog Aul [00:12:42]:

Yes. Please go ahead.

 

Leon Ravenna [00:12:43]:

To that. Sure.

 

Eddie Borrero [00:12:44]:

Yeah. So this is Eddie. I just want to make sure I was clear because it seemed like maybe I came across wrong there, but when I used the word militant, it was more about in our security operations, how we handle events and incidents is a very structured approach. Right? And so I agree that collaboration is key, which is why, we really focus on integrating with the business and really teaching as much as we can so that as we develop tech, we’re not the only people in the room thinking security. Everybody’s thinking security, but I do think it’s important that, when it comes to thinking about information security, there’s multiple components to it. Operations, one, as well as integrating with how we help the business digitize is another. So I just wanted to be clear on that.

 

Sanjog Aul [00:13:35]:

Absolutely. So, Harshal, coming back to you. So we have issues as we deal with the business side, as you’re trying to help the business deal with security or you support security function so that digital can be best harnessed in terms of the value by the business, but then what are those top challenges that you face as a CISO and or your team faces as you’re helping with security? And to add to it, this question is, are most of these problems self inflicted because it is at least reported by some security leaders themselves or some technical people or business users that the security team in particular tries to or loves to stay very close to the tech versus understanding this answer to so what? Why am I doing it? I’m not laying a brick. I’m building a castle. So do they understand the castle if they don’t? And is that the reason why most of these challenges exist? What’s your thought on that?

 

Harshal Mehta [00:14:39]:

So, yes, I think it’s a great question. Let me put some perspective here. If you ask me this question maybe three or four years back, yes, traditionally, as I said, IT security was so closely linked in that security always came up with an IT organization. It was an extension of an IT organization, which used to do some kind of security monitoring, some security policies and so on. I think the gradual shift of the change, which happened over the last few years and we jumped onto that journey, is how do we collaborate with business? Continuing the same conversation, take the business collaboration hand in hand, make them understand that, security is the way you are going to operate. It’s not for you and me, it’s for everyone. Our customers, our regulators, everyone’s at stake. I think that cultural shift is what we did and that helped us in the whole journey. I think that was one of the challenge 6, 7 years back when IT and security were so closely linked in. I think let me give you an example of what are some of the changes which we have done over the last few years, which really helped in overcoming some of the specific challenges which we’re facing. Number 1, having something called Security Champions in place. So Security Champions is not an extension of my team, but it is a security designated person or nominated person from business, from the IT team, from the application team who has been trained on basic security stuff and who knows what security is. So when this person goes and talks to his business or he talks about Apple, he is our guardrail or he is our point of contact to spread the word about security. So it’s imbibing a culture of awareness, just not at a very high level by the basic mandatory, the security awareness training, but by a constant change by every organization starting from your board level to your application developers, to your business leaders, understand what security is. Again, the context and content can be different. The context for the application security guys would be training them on how do we code in secure applications; for the infrastructure would be totally different on the environment. For the cloud, it would be different, but I think one of the key areas and again, referencing a lot of industry, uploads, but Verizon Data Breach Report, a classic example of how many C suite executives get done day out. So educating them on basic security as well as imbibing security when they talk to their stakeholders is so critical. So I think that was one of the challenge which we are, again, I would not say we are perfectionists at this, but that’s a process of constantly working on imbibing security in the culture.

 

Eddie Borrero [00:17:49]:

As one

 

Harshal Mehta [00:17:49]:

of the example, security champions, designated business level, application, infra level, that breaks the chain that security is just so much tech focused or just IT focused. It’s across the organization. It’s for a change starting from physical security controls to a high level architecture control level. So that was number 2, which really helped us in overcoming some of the challenge. Sorry, you were supposed to add something.

 

Sanjog Aul [00:18:24]:

Yeah, no. So I was actually building upon what you just said, and, Eddie, coming to you based on what Harshal said is there are some of the challenges, but, of course, there are some solutions that were offered to that, and now coming to the very essence of the topic today is we got to become a CISO’s business leaders, good digital business leaders, and it also requires our own team members to step up their game and become better problem solvers and effective communicators. So my implied claim that are some of the security team challenges not understanding the business or not been able to come across as some people who understand business. What have you tried to do to solve that part? It’s not that they cannot talk in the language of business or, the plain English, if you will. Where are we missing, and what have you done to solve it?

 

Eddie Borrero [00:19:20]:

So I think you’ve described where we’re missing. It’s the understanding of the business. It’s taking the time to understand the business as well, and so we’ve done 2 things that I think have been extremely successful. The first is using kind of a FAIR assessment model where we’ve worked with the business to teach them about how to do risk management and had long, arduous conversations around their business process and had some actually start to come up with the risks that we actually prioritize and address, and, 9 times out of 10, the security team had a good understanding of what some of those risks are. Actually, that’s probably not true. I would say 50% of the time, we would understand what the risks are, but the other 50% of the time, everybody was surprised at what came out of those conversations, and so the first value of that is that the business themselves come to a conclusion around what risk they have, and they’re the ones who are now working with us to mitigate those risks instead of the other way around, and that makes a huge difference because the security team learns, but also the business begins to learn our craft and our trade as well, and then the other thing that we’ve done that I think has been the ultimate game changer is that we start to use what’s called design thinking to actually problem solve, and so, we actually leverage the LUMA practice here, quite a bit, and so what that does is it says, look, the security team is no longer gonna solve a problem on their own. We’re gonna actually build a process to where people come into a room, do some very structured design thinking around how to solve a problem, and come up with a prototype that we can actually then move forward with, and in that way, you have a ton of buy in, you have business sponsorship and support, but you also get a better understanding of how business processes are impacted when we do a project or we do an effort. Two things, just to summarize. One is leveraging FAIR to be a collaboration tool, which I think is really starting to shine, and then two, leveraging design thinking to actually solve problems in a collaborative way.

 

Sanjog Aul [00:21:38]:

So, Leon, when you are looking at what Eddie mentioned here, so he did what he could do. Do you think we are developing our people the wrong way and then you’re doing the break fix? Could there be a fundamental shift in the way we are grooming and incubating the security talent? Because that’s loss of good precious dollars at the education level, at the grooming level, and then trying to do the fixing, if you will.

 

Leon Ravenna [00:22:08]:

Yeah. Absolutely, and I think, Eddie’s got a great point in the design thinking. One of the things we’re doing to try and help that is we are engaged in PI planning. So we will work with the dev teams and infrastructure teams as they are going through their planning sessions, and part of our role is to just try and make security part of their normal work stream. So they may be fixing something and they may look at fixing a vulnerability at the same time they’re looking to update a field on something. So we’re trying to just build it into the normal part of work. So we engage them in the overall process, and where Eddie’s doing design thinking, we are doing more privacy by design. So we started with some of our new developments happening in Europe trying to build security in to anticipate what will come in the future from a regulatory standpoint. So we’re out ahead, and those teams are very engaged in seeking us out to make sure that they’re making good design decisions. So we’ve been able to, at least in part of the organization, be able to get people very engaged in trying to think ahead about what the security pieces are going to end up being, and so we are doing that. One of the things that my group does a little differently, Eddie and Harshal may be the same, but my group also does customer focused stuff. So my group will do about 400 customer audits a year, as a part of my group. So whereas we are intangibly ingrained with the business because we’re taken care of for answering customer questions. So we actually have opportunity to see what some of the customer pain points are before they even get to the business. From that standpoint, we have an advantage. So we understand what the issues are there.

 

Harshal Mehta [00:24:12]:

Okay. Can I just add in here? So, I’m partially here. I think perspective here, but the ways we are trying to understand business more and trying to deliver a value which the business really needs is every year or mid of the year, our business, enterprise wide level gets finalized, and that gets translated into our objectives that for the next year, what really matters to us? Is it just the transformation? Is it an application? A new region or so on? And that gets defined into our strategy and our priorities because then we are delivering something which makes a difference to the business rather than the fancy tool, which is just used and helps and makes things easier. So I think that is one which we do at the start of the program. The other which we really do and again, echoing what was mentioned is the customer. We do so many responses to the customers, just not based on the audits, but even on understanding and having those client meetings, they come back with, okay, our security program requires these requirements. How are you positioned to take that? So that is a direct input or a channel through our business facing teams that, okay, from a perspective, this may or may not become a priority for the coming years. So that way, business and security aligns and speaks the same language.

 

Sanjog Aul [00:25:49]:

Let’s take a quick break, listeners. We’ll be right back, and Harshal, I will jump back right to you in terms of the next question we have when we come back, is to look at tinkering. Should we just be tinkering with our existing people, processes, and tools within the security department? Or should we fundamentally reset and rethink how we go about even seeing our security group in context of digital and fix it so that we are not, , and kind of get hunted by the legacy approaches to handling security that we had pre digital. So what are you doing in that regard? What have you tried, if at all you’ve tried, and what have been the results? So please stay tuned, listeners. We’ll be right back.

 

Speaker 0 [00:26:42]:

Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul on how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN, CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Sanjog Aul [00:27:37]:

Welcome back. So, Harshal, the question for you is there are a lot of ways we will have to shift our approaches to people, processes, and tools when we talk about digital and in context of your security function or your department. One is to just keep incrementally tweaking what you do, and another is to fundamentally reset how you saw your security function. So what did you try doing? Did you do a fundamental reset and rethink and rebuild, or did you continue to tinker? What do you recommend as the ones for other people who are trying to do the same for security so that it becomes relevant for the digital world?

 

Harshal Mehta [00:28:22]:

I think, , and I can speak from my perspective, based on consulting experience and current with this organization. I think it’s very critical to understand the culture of the organization. I would not just say, a hard reset doing and start fresh would work, but, gradually, the things worked well for us was, imbibing and moving towards the digital journey by taking on steps or process changes, by aligning with the business, understanding where understanding what’s the digital focus for the organization, and in this whole journey adding in the security guardrails or touch points at individual to gather the trust and assurance. I think one of the key areas in this whole ecosystem is to gather trust both internally and externally. So it’s just not talking about your IT organization. It’s talk about your business, your legal functions, your privacy teams, your sales and marketing, your operations you have to take in lot of initial steps and process enhancement to gradually move into the environment. So this is what worked well for us.

 

Sanjog Aul [00:29:42]:

So, Eddie, when you look in your organization, what fundamentally different what all areas did you fundamentally rip apart and rebuild to make sure that you are not, left behind, if you will, at the pace and you you are at the you’re running at the pace of this digital craziness.

 

Eddie Borrero [00:30:08]:

That’s a really good question. I think a couple of things. We really focused in on trying to get people to uptick their skills in the areas that we needed them to, and so we spent a lot of time on creating security learning paths and forcing that, ensuring that, as part of your employment you would grow and learn from a skill perspective, and then we made a lot of hard choices around for those teams that were low skill, low value as a company changed, finding the right fit for those resources and really bringing in new blood that could help to uplift the security team, and then sometimes and in some ways and in some instances, we partnered with our business to bring in business folks and teach them security to kind of give us a jump start in certain areas, and so we’re constantly looking at how do we build up our team, how do we develop a pipeline of talent, and so we do a lot of different things, and I’ll give you a couple examples. We work with a very local community college that has what I think is a top notch security program. The college is Merritt College in Oakland. They have a 2 year degree that’s really based on job descriptions from places like Facebook and Google to create their curriculum, and so we find that we get some pretty good talent coming into the organization from that college.

We also work with a lot of different universities that are out there as far as internships go. We spend a lot of time, collaborating and communicating with various teams within the organization, which at times brings in talent from other teams, and vice versa, we send talent out. So as people grow, they sometimes grow into other departments, and sometimes that’s by design and sometimes it’s not, but the idea is to create an ecosystem that allows us to uptick our skills on a very regular basis and really make them relevant for the business, and so we look at it every year during our kind of business planning cycle. Do we have the right skills? Are we on the right path as far as filling out skill gaps? And it’s very difficult. I think one of the biggest challenges security organizations have is obtaining and maintaining good talent, especially in the Bay Area, and so in some cases we’ve created some very creative solutions to staffing and resourcing certain skills, but it’s not an easy thing, I think, is my message for everybody, but you really got to look at what is your business doing as far as the digitization and or additional business model goes and really begin to align how do you, , and we’ve used the word run fast with them. We’ve used the word integrate, and all that’s about having the right people, and sometimes those people are not security people. They’re business people that need to learn security.

 

Sanjog Aul [00:33:31]:

So, Leon, your company, CardGlobal, is, of course, as a business, trying to scale, and they are not expecting you to reveal the complexity you are going to be dealing with, and at the same time, the user community does not want to be bothered with additional hoops that they have to jump through to help you manage security better. What have you done, new, more, or different? What strategies, what approaches, which worked, and when did they push back and your strategies did not work as expected?

 

Leon Ravenna [00:34:17]:

Sure. Great question. I’ll give you the first one. I’ve been here now about 3 years and the second year, so, 2018. Our security awareness training was much, much, much too hard. Our organization is about 15,000 people, and there’s probably 10,000 people that are mechanics or detailers or drivers or things like that, and they don’t need to know the intricacies of security. However, they have an account. They have mail. So we need to train them. We purposely went out and picked new training that was much more targeted, and actually a little bit I won’t say funny, but it was more, we tried to bring the training to the people. So, again, collaborating, we heard that, you didn’t like it. Let’s go find something that works better, and that for 2019 worked very well, but a couple of things that we’re doing to help along the process. You talked about looking for unique skill sets or building those. We’re trying to train those up. Indianapolis is a small town and historically, we would steal each other’s people. I would steal somebody from Anthem. They would steal my person and we just kept trading people. We’re working on training people up. I have one of my guys that started working in the customer focused area who is now a security engineer. He went out and got a CISSP. He had that passion. He’s doing a great job. We talked to the local community colleges and I have an intern from Ivy Tech. We also are doing some mentoring and working with folks like Purdue on a nationwide apprentice program. There’s a training academy here that does kind of very focused building like SOC engineers and stuff like that. So trying to look for those skills in different places because quite frankly what we need is somebody who’s looking at things from a different perspective. You know? So they grew up differently. They have seen different things. So looking for those skills that are coming from the life challenge, not necessarily the classically trained, and the one other thing that we’re doing quite frequently now, I use the kind of the statement that, IT is driving digital transformation, and I’m watching their back. That’s how we’re kind of working hand in glove with IT to get stuff done. So it forces some of that collaboration.

 

Sanjog Aul [00:37:14]:

So, Harshal, a question for you. When you are looking at security as a function, there is some geek work to be done, pure technical. While I may say all I want that every person across your chain of command needs to demonstrate that effective communication and leadership, I’ve had some security leaders say, no, that’s not the case because I need an Uber geek as well to get some work done while I have some people who will do the communication. What are your thoughts on that front?

 

Harshal Mehta [00:37:55]:

So, yes, I think this is a very debatable question, and we get this a lot, especially when you’re looking at roles across the whole security program. So, , and security program, first of all, has various types of roles and it needs different kind of skill sets. I would not expect someone whose role is to just monitor logs and do the technical areas in the background to have best in class communication skills so he can talk to a business and explain the incident. So we have a lead or a manager or a director on top of him who can articulate and speak the techno manager language. So that’s why you would need, especially at that manager position or at that leader position, to break up those technical skill sets into something which is easily digestible at the business level, and the same goes with, especially when you’re representing security matrix or the risk at the board level or at the executive meetings level, they are not able to understand or they would not be able to articulate what you’re trying to speak on your technical terms. So this is where you have to break it down into a message which is easily digestible to them. So I would say, not every role needs communication skills to be off top notch, but that’s a growth area for the person if he’s an engineer who’s just monitoring logs, and if he needs a career for a lead or a manager, these are the core skills needed for his success. So, yeah, communication is a big skill, and we invest a lot, especially when we are driving up the job description or we are looking at promotions for the next level. How do we up skill the bare minimum skill sets so that person is able to break it up and talk? I think apart from communication, collaboration is something which is really needed, especially when security is a function which collaborates and relies so heavily on working with other functions to do the job. So collaboration is even more important and communication is more important, especially when you are at the techno manager or leadership roles.

 

Sanjog Aul [00:40:16]:

Eddie, if I were to request you to calibrate the role of the pure technical engineer, then a team lead or a manager, and then a leader like you with respect to the level of softer skills, if you will, whether problem solving, team, or other type of collaboration skills or leadership skills. What comes to mind and what have you instituted? Rather, what comes to mind, what have you instituted so that they are at right level? Like Harshal said, I could use some pure geeks. They don’t need to have comms skills to the degree, but what should that be in your view? If you were helping an organization recalibrate their roles with respect to those additional skills which will make them better suited for the digital transformation and play a good relevant role, what would that look like?

 

Eddie Borrero [00:41:13]:

That’s a really good question. I think it’s a complicated one because it, the traditional consulting answer, it depends, what the people are doing, what company you’re in, that kind of thing, but I do think it’s important that at a CISO level, you have the ability to do a couple of things. One, listen well. Two, learn the business quickly, and three, really learn how to speak business talk, and so what I mean by that is that a long time ago, what I’ve learned is that security is very complicated and people are skilled in their space, and I’ll give an example. So, , and a finance guy knows finance very well. So when you’re talking numbers and metrics, it’s compatible with their language, but as you start to deviate from those conversations and get into a little bit of a tech talk or conversations around risk, it’s really hard for them to learn without you teaching them and or understand without you teaching them. So that CISO really has to have executive acumen. I would say CISO really has to learn how to grow constantly. Executive coaching is a good way of doing that. Obtaining feedback about your performance outside of your direct chain of command is a good way of doing that. I think that’s really important to just stay abreast of how well are you integrating within the organization and how well are people understanding you. Because you can be a great CISO. You can communicate to the board. You can get a ton of head nods, but at the end of the day, you’re gonna have a lot of misunderstanding that’s out there. So that’s one. At the managerial level, I think it’s really, really important that people learn and focus on execution, and so building out an ability to be really clear on people’s goals and objectives, really clear on the work that they need to get done, really clear on what’s a priority for folks, and really clear on what the expectation of delivery is. I find that that’s muddy throughout my career, and so we have a really keen focus on how do we drive results. We call it do less to do more, and so doing less means spending a little extra time on planning and prioritizing and collaborating so that we can actually deliver against things that are meaningful, and then lastly, at the engineer level, at the individual contributor level, it’s really about executing your job effectively and learning. If you wanna grow, let us know. If you don’t, like, there’s some people, some roles that, it doesn’t require communication skills, but it does require a lot of analytics and or a lot of great tech skill, and so sometimes those two things aren’t found in one individual and that’s okay, but you’ve got to focus people, right, to make sure that the results that you expect are being driven. If I just recap, at the very top level is constant communication and understanding of how you are influencing the organization. At the managerial level, it’s really setting the right level of expectation, and making sure people understand what they need to do, when they need to do it, and how it aligns to our business goals and objectives, and then lastly, for people, it’s getting the work done.

 

Sanjog Aul [00:45:03]:

No. That was a pretty good rundown. So, Leon, while, of course, Eddie mentioned about the specific calibration we could do on the software things, etcetera, let’s go individual on each of you because we said you got to groom, as the title says, CISO as a digital business leader. If you had to do your performance appraisal and you had to look at where you could get better, Which all areas are you truly working on to get better or fill the gaps so that you would be the best at this game in the digital context? Sorry for throwing this tough question on you, but I guess this is an important one to ask.

 

Leon Ravenna [00:45:52]:

Yes. It’s fine. I wanted to first echo something that Eddie said. I have kind of a mantra that execution is the only thing that matters. It’s what are we actually getting done and helping the business. I’ve seen too many people that are happy to talk about the way things should be, not necessarily just get the work done, but to answer your question, I do my own review every year, and I just did one over Christmas. The first step, even though we’ve talked a lot about communication, it’s communicating better. It’s communicating more effectively. It’s very easy having a 30 year career in heavy infrastructure, building data centers, running data centers, and then moving into security to fall into, hey. Here’s bits and bytes, and I’m gonna talk about stuff. So, , and you guys will all think I’m smart. It doesn’t work that way. I’ve learned that the better thing for me is to be quiet. When I’m quiet, I don’t have to pull my foot out of my mouth, so it works better, but quiet and listening to what people are saying and understanding what the question is they’re really asking. Asking because a lot of times the question is not necessarily what needs to be done, but it’s more how are you going to get this done, and then one of the things that I have tried to work on for years is just making sure that my attitude is one of being humble and not necessarily, well, , and I’m gonna tell you how it is. Making sure that I am there and available because I want people to come to me with issues. So I am almost monotone no matter what. Highs, lows, good, bad. It’s the same person, and those are the things that I have consistently worked on over the last several years to make sure that people will are willing to approach me. So a lot of it is almost exclusively focused on communication, the technology and learning that stuff that stuff that I put in on my time, but it’s more about just making sure that I’m communicating as effectively as possible.

 

Sanjog Aul [00:48:31]:

Harshal, what about you? What are you trying to fix in you and what are you going to develop yourself? In which area would you like to develop yourself so that you feel more prepared for the interesting times ahead as a CISO?

 

Harshal Mehta [00:48:46]:

Yes. So I think there are a few areas which I would break in, echoing Eddie and Leon. I think fundamentally, from a CISO perspective, the entire organization and everyone is looking at you to deliver and operate on a security program, which is such a key priority. So I think the number 1 for me is trust. Trust across the organization, trust showing from a program perspective, from a maturity perspective, we are transparent. If there are areas which needs to be called out, let’s call spade a spade, but in the back, we also work and constantly evolve and make sure that it doesn’t get a big problem in the future. So trust is such a big component of CISO’s role. The other big portion is communication. As part of the whole ecosystem, how do we communicate and echoing everything on the call, listen well, understand and be the point of contact for all the stakeholders. You want to be the person people want to call up midnight, although you would hate for it, but at least you want to be the person where, in case of an incident, case breach, where people come and notify you or come up for a recommendation that what needs to be done in case of such incidents, and the third big criteria is have to be business focused. You have to understand and be part of the journey what business is driving or what business is attaining to do. So in this whole journey, you have that teaming along well with the business team and with the IT teams to make sure whatever they are delivering or whatever they are driving for completion, you are part of the journey. So I think these are the three areas, I would say, really as a process needs to be good on a constant basis.

 

Sanjog Aul [00:50:52]:

Eddie, one final question. You got just about a minute or less. You heard about the things that CISOs must fix in themselves or work on as individuals so that they become better digital leaders. What do you think CISOs need help in? The good leader is not just confident, but also someone who asks for help. Who and what help should we offer to CISO so that they can develop into a good business leader? One minute or less.

 

Eddie Borrero [00:51:23]:

Yeah. I would just say executive coaching is super important. I can’t overstate this. It is extremely important for people to get coaching. Everyone has an opportunity to grow and the best way to understand what their growth path is, especially within your line of business, is get some coaching. A lot of coaching comes with 360 degree feedback, which really gives you some insight into what’s working and what’s not working in your own style and in yourself and really just how you show up to work every day, and so, I think if we leave it to ourselves to self evaluate, nine times out of 10 we’re wrong or we’re missing something that’s really important. So go get some help. Go get some coaching. Get some feedback from your peers and from your management, and I think you’ll be surprised at how much better you become as an executive.

 

Sanjog Aul [00:52:25]:

On behalf of the show and our listeners, thanks so much, Harshal, Eddie, and Leon, for sharing your insights about how CISOs can groom themselves as business leaders and also groom their teams so that they become effective communicators and problem solvers and help all of them come together to support the business’s digital agenda. So thanks so much again.

 

Harshal Mehta [00:52:48]:

Thank you.

 

Leon Ravenna [00:52:49]:

Sure. Thank you very much.

 

Sanjog Aul [00:52:50]:

And listeners, please like us on Facebook. Search for CT and CIO Talk Network, and be sure to follow us on Twitter and join our LinkedIn group. Thank you again for listening to this segment on CIO Talk Network. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.

Contributors

Leon Ravenna

Leon Ravenna, Chief Information Security Officer, KAR Global

Leon Ravenna is Chief Information Security Officer at KAR Global. He leads KAR’s efforts in global security strategy, execution, and privacy and compliance services for the company’s more than 17,500 employees. A seasoned CISO, Leon has... More   View all posts
Harshal Mehta

Harshal Mehta, Vice President, Chief Information Security Officer, Carlson Wagonlit Travel (CWT)

Harshal is a seasoned information security leader with more than a decade of leadership experience spread across Risk Management, Security Governance, Compliance Management, Payment Security and Security Office. He has held various consulti... More   View all posts
Eddie Borrero

Eddie Borrero, Chief Information Security Officer, Blue Shield of California

Eddie Borrero is Vice President, Chief Information Security Officer at Blue Shield of California, a nonprofit health plan with $21 billion in annual revenue serving 4.6 million members in the state's commercial, individual, and government m... More   View all posts

Advertisement

Automate Everything - The New Cupid for BPOs 1 MPU 300X250
Leon Ravenna