For the upcoming year 2021, how are the CISOs enabling a business-driven cyber strategy, gearing up to take on the broader role, and planning budgets that directly tie to business growth and improved risk management? How are they planning to develop their talent pool and manage security services partnerships to deliver on their 2021 CISO agenda successfully?
Contributors
-
- Jake Margolis, Chief Information Security Officer, Metropolitan Water District of Southern California
Download Podcast
Apple Podcast, Google Podcast, Spotify, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More
Transcript
Sanjog Aul [00:00:24]:
Hello, and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com. So topic today is Delivering On The 2021 CISO Agenda. So for this new year, 2021, we have to look at things differently. Perhaps we will never go back to where we came from because of the pandemic, and things are still morphing. So what do CISOs need to do differently? Will they be able to enable a business driven cyber strategy? Will they be able to take on a broader role? How are they gonna gear up for it? Would the budgets really fit with what they need to achieve, and would that ever be justified to the business as something tied to the business growth and or improved risk management? How are they going to get very hard to find talent and then retain them and pay them the money that they want or, in other ways, motivate them to keep working alongside them as they help the business? A lot of questions here, but let’s dig in. So to discuss this, I have, Arun D’Souza, who is the CISO with NextGear Automobile. Hey, Arun. How are you?
Arun D’Souza [00:01:41]:
Good, Sanjog Aul. Thanks for having me.
Sanjog Aul [00:01:44]:
Great to have you, and Jake Margolis, CISO, Metropolitan Water District of Southern California. Hey, Jake. How are you?
Jake Margolis [00:01:51]:
I’m doing well. Thank you. How about yourself?
Sanjog Aul [00:01:53]:
Very good, sir. Thank you. So let’s set the stage. So, Arun, I’ll start with you. What new or different security challenges do you think we should expect to tackle in 2021? And from the ones which we are already tackling now, which ones will bleed in there into the new year? And they have been chronic, but what we’ll be dealing with and to what degree do you feel optimistic that you’ll crack those problems?
Arun D’Souza [00:02:24]:
Okay. Thanks, Sanjog. The following security challenges will continue to be critical in the manufacturing industry and the industry at large, and they can lead to production downtime, loss of revenue, customer trust, reputation, and so on. So it is important to monitor these risks and deploy proactive control strategies. In particular, phishing, ransomware, Internet of Things, supply chain and third party risk, and privacy concerns. Phishing is the one that probably is most easily controlled, if you have a good email security platform. The other ones will probably bleed over into next year and ongoing because they vary, in ransomware. There are variants of all kinds. The Internet of Things is a particular concern to me because those devices come without proper security controls, things like embedded security credentials. Patching is not up to date and very old firmware, and the supply chain and third party risk across the enterprise ecosystem is something that is always a concern, especially in manufacturing because there’s so many entry points and so many levels, and the last one, privacy concerns, I think that’s going to hang around now, and it’s going to actually expand the concern as a CISO, CFO, CIO because of regulations such as the GDPR. Some of the things that we have already seen in the recent past, stuff like the Garmin and Honda data breaches that affected them significantly with a lot of downtime, and I think ransomware is the one thing that I fear the most in manufacturing.
Sanjog Aul [00:04:07]:
So, Jake, what have you seen, which is maybe I’m sure some of the things which Arun mentioned, must be resonating, but what more have you seen which we should be concerned about or be getting up for?
Jake Margolis [00:04:20]:
Well, I think the phishing thing is a perpetual problem that’s never gonna go away. It’s always in the top five attack vectors, and part of that is because we have to accept this reality that we could spend billions of dollars on cybersecurity, and all it takes is an end user who has to have a wallpaper click on the wrong link. The secure email gateways get better, but I’ll take another step towards phishing and business email compromises and supply chain risk and tie those all together. Because I think that’s becoming more prevalent because it’s hard for an attacker to defeat some of these next gen securities that are out there. So they’re always looking for ways to sidestep them, and what’s interesting and what’s trending is that they compromise your supply chain, and then you get emails from your supply chain about things like, hey. We need to change your wire transfer instructions or go to this website to view this invoice, but you’re gonna have to use your Office 365 credentials to log in. Users fall for that, and partly because the attacker is exploiting a trust, and so I think there’s going to be an increase on social engineering, because it works, and they’re exploiting trust that users have developed with their third party vendors, and we’re gonna see more and more of that, because it’s lucrative and it’s easy, as long as they know your supply chain and how they can take advantage of that, and there’s a challenge with the supply chain as well is there’s no real technology we can deploy easily that’s going to stop or defend that. We can defend ourselves, but how do you defend somebody else’s network? And, really, it’s not your responsibility to. So when you’re talking about dealing with members in your supply chain, it really comes down to what legal teeth can I put into my agreements that can make the supply chain more pliable as far as my cybersecurity defensive posture goes? And I’m wondering if 2021 is gonna start having a little bit more of those mutual kind of arrangements, whereas we may say, hey. If you have a breach, I want you to tell me in 24 hours, but are the members of our supply chain gonna hit us back with the same conditions and contractual language? Like, well, if you have a breach, you need to let me know in 24 hours, and so I think we’re gonna see a lot more in the legal frontier in 2021 because there’s a lot of questions that come up on what can you do beyond the limits of your technological boundary when it comes to defending yourself? And I think that that’s the big one, and then the big questions to ask, and there’s a lot of people asking those right now, and as far as the other things that we’re seeing, I 100% agree. Ransomware is gonna continue because it works. So they’re gonna continue to use it, and then I think we’re gonna see more and more of a shift to cloud centric technologies, more of these EDR platforms that work in the cloud so that we don’t have to bring traffic back to our data centers for traffic inspection. So I think organizations that were traditionally on prem are more and more going to be shifting to cloud centric technologies for front facing applications, which is gonna present its own set of challenges for data security, data loss prevention, and end user support.
Sanjog Aul [00:07:35]:
So we have been covering this whole cybersecurity space since 2003, since the show started, and we saw the pendulum. Initially, it was swinging to the side where security leaders were fairly confident and said, you know what? I will not let these intruders come in, and I’m gonna secure the fort. After that, that confidence dwindled, and they said, you know what? I’m not sure if I can control them because this is getting out of hand, and I don’t have enough speed and power and the resources to be able to do that. Then it came back again because people said, oh, we have AI now. A human doesn’t need to do it, so maybe we will have AI help prevent phishing attacks. Maybe it’ll prevent ransomware, etcetera, and then people started talking about AI on the bad guy’s side and AI on the good guy’s side. They will both fight the war. So, Arun, coming to you, what I just mentioned as the different phases of evolution or confusion in some cases, what do you think is gonna happen in 2021? Are the bad people who are trying to cause us harm, are they gonna get smarter or will they have an edge over us, or are we looking at taking the AI and other tools and techniques that we are evolving, we will be at par with them or we’ll be ahead of them? What’s your crystal ball saying?
Arun D’Souza [00:09:01]:
I think we’ll probably battle them to a close to a draw, and the pendulum will shift from either side, but I wanted to just pick up on something that Jake said. Business email compromise is the number one threat vector, not only phishing. So companies need to do more with things like controls like DMARC, DKIM, recipient handling, and so on because that’s one way to make sure at the enterprise level we are validating the trust of different organizations. In response to your question, I think, basically, AI and ML all sounds very beautiful, but nothing is going to be running itself. AI, my particular concern is its predilection for bias. How do you neutralize that bias and make sure the AI is working correctly? So I think what it’s going to take is a broad based length, breadth, and depth collaboration and federation across the enterprise ecosystem. Just as in the case of phishing, like we’re talking earlier, where companies are gonna have to work together as allies, I’m already seeing that across different vendors actually banding together in these coalitions like the SkyTeam Alliance for frequent flyers and airlines. There’s something called the Spectra Alliance, which includes CrowdStrike, Okta, Proofpoint, and Octave, and what they’re trying to do is to complement the strengths of each other and share intelligence in real time, so as to help companies have the power of the coalition to whatever pieces you have. I think it’s going to take that to the first level, deeper control strategies. The second level, closer federation, and the third thing, I think, you know, as a CISO, we need to partner very closely with the business to align business strategy along with cyber strategy to mitigate the enterprise risks. Because at all times, CISOs are balancing the fulcrum between value protection and value creation, and it’s very, very important to maintain a proactive control stance because as technologies evolve, it’s incumbent on us on this side of the fence to use it to protect and repel the digital marauders, if you will. So I think you can’t rest on your laurels. The threats will keep coming. They’ll keep evolving, and they’ll keep finding threat vectors. You shut one door. They’ll find a chink elsewhere. So I think it’s really, at all times, developing adaptive proactive control strategies aligned with the business and with a larger federation, with your partners and service providers as well, and last of all, your partner service providers are close allies to you. Keep them close to you. Meet with them. Involve them in your strategy because many times they have resources and skills you do not have.
Sanjog Aul [00:11:56]:
So, Jake, when you look at what all we’re dealing with, and I’m sure it’s not gonna get any easier, but even at the business level, it’s morphing. It’s changing by the day. With that said, yes, we have an agenda, and we have that vision that the CISOs will be enabling a business driven cyber strategy. With that said, when the business is changing and the cyber security related landscape is changing, the way those intruders are changing their strategy when everything is so in flux. Can you truly build something which is business driven and please those executive management folks up there?
Jake Margolis [00:12:39]:
I don’t know that it’s our job to please them. I think it’s our job to advise them on risk and help them to make really good, risk based decisions, but rest assured that the decision rests with them. So we can say, hey. You probably shouldn’t enable this particular group of people to work remote because of what they work with or the intellectual property is gonna be at risk or whatever the case may be. Fill in the blank with the high risk item. What it really comes down to is they need to be informed, and I think sometimes, we need to not be timid. We need to be bold when we go to executive management and tell them honestly and frankly what the risk is that they’re looking at so that they can weigh it out because there’s no right or wrong decision. There’s the risk based decision, and coming from a military background, I think there’s a certain amount of truth to that. Because sometimes you’re presented with things that there’s just no right decision. You have to make the least risk impactful decision, and I think that’s true in business. I would say that we’re not there to make them happy. We’re there to be their trusted advisers, and we’re also not there to be roadblocks to innovation, and I know you mentioned 2003, when you first got into this talk on cybersecurity. Back then, there was also that we’re not gonna talk to the security guys because they’re just gonna tell us no, and that’s how we ended up with years of bad code that people put on the enterprise, and so I think we still need to be mindful that we don’t wanna go back to those dark days where people didn’t talk to security. The fact that they’re talking to us is a good thing, and we wanna continue to foster that relationship and that trust with the business, and I found that that works. With the organization I’m at now, and with previous organizations, just having those frank conversations and being willing to understand the financial and operational risk as well as the cyber threat risk that’s associated with any particular business transaction or process is really important, and it’s a composite of all of that risk mitigation that’s going to get us to that sweet spot where we feel like we can tolerate what it is we’re doing. I think to get ahead of the business processes to a certain degree too, cyber needs to learn how we can complement them. You know, I mentioned them just a few minutes ago. We need to start looking at stronger procurement language within our contracts. Stronger contracting language within our procurement processes on how to better mitigate risk that can be associated with potential business email compromises that start in our supply chain. Maybe we enforce a policy across the organization that says all email internally has to be digitally signed so that if you don’t get a digitally signed email, it’s not a legit email, to prevent somebody from pretending to be somebody within the organization so that there’s that visual indicator that it’s a legit email when an employee gets it. Maybe it’s a business process we help refine and say, hey. Anytime somebody tells you you’re going to change your wiring instructions by internal policy, you have to let them know that that’s a 10 business day transaction for cooling off plates before we all respond to those kind of transactions because those are financial transactions, and we want voice verification, and we need time for the dust to settle in that. Most attackers are only sitting on those fraudulent accounts for a couple of days, and so there’s a lot of things that we can implement that aren’t technology driven to a certain degree. So sometimes we can be friends with the business by saving money and looking at things that don’t cost a lot of money, and also by maximizing the value proposition with using those technologies that are in alliance packs with one another, because you’re getting more financial bang for your buck when you’re investing in that suite of technologies because they’re complementary, and they’re gonna provide you better results at the end when you’re talking about detections and remediation. So I think there’s a few things we can do, but it always boils down to advising on risk, helping them streamline the process. In a way, we’re still kind of pseudo IT professionals in what we’re trying to improve efficiency, but by applying security controls in that efficiency game, and then the last thing would be developing the value proposition for the services that we provide. One example I can give you that we’re doing is we do two factor authentication, and we’re pushing that out heavily with these tokens that we’ve issued to employees that use a PKI cert. At first, they’d say, well, this is costing us money, but now they see the value proposition because employees don’t have to use passwords anymore. They’re happier that they can just log in without a password. The more we get that deployed, the happier they are. So to me, that’s an example of a value proposition and efficiency gain that we can communicate easily to the business, and those are the kind of wins that we have to look for.
Sanjog Aul [00:17:32]:
So, Arun, Jake used this golden word risk. Right? And when you talk about risk, historically businesses’ view of risk and how a security leader looks at it has not always matched. So who wins in this tug of war of the risk propensity or rather the risk calibration or rich benchmarks, whose benchmarks prevail? Should it be a third party? And once you do come to certain terms, what you say is appropriate risk tolerance for business, can they be making a mistake that they may be taking too much liberty or you will say, okay. Business willing to take that much risk? It’s okay with me. Or would you fight back because you have the business’s best interest in mind? Think about it a little bit. Please stay tuned. Listeners will be right back, and Arun, this is a question for you when we come back.
Speaker 0 [00:18:33]:
Today, enterprise technology is both strategic and global. Each week on CTN, CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.
Sanjog Aul [00:19:29]:
Welcome back. So, Arun, the big r word, which is the risk. Business sees risk differently, and IT leaders, of course, like the security leaders here, CISOs, would look at it differently. Ideally, they should look at it the same way. First is there a common understanding of what risk is, and do we see eye to eye on that definition? And secondly, if business is trying to move it forward and just because of that, they become overzealous and they try to undermine what they feel is just about enough risk prevention or the levels that they’re playing, it is too liberal. Do you feel it is the duty of the CISO to push back, or risks should be seen as one benchmark. Once established, we just follow it and let business drive how much risk they’re willing to take, and we’ll follow orders.
Arun D’Souza [00:20:26]:
I think it’s incumbent on the CISO to drive the conversation in partnership with the business. Because I think as things have changed and the CISO has become more of a business leader than ever before, especially in the seat of distributed work, I think it’s very important for the CISO to lead that conversation, and the reason I say that is the field of enterprise risk, security, and privacy are converging now, and the only one who can see it clearly is like the ship’s captain, the CISO, and before I answer your question, so I can frame my answer properly, I submit to you some key tenets that are very, very important as a CISO going forward, to frame my answer. Number one, align cyber strategy with business strategy because you’ve got to be able to enable the business. Jake touched upon that. Baseline and track your program maturity. Coordinate with enterprise risk management because typically enterprise risk management works in a vacuum and they sort of throw darts, but you gotta work with them to make sure they understand and respect how CISOs are valuing the different risk parameters. Executive and cross functional support is very, very important because the thing is you cannot fight the battle alone. You’ve got to form an infosec council with executive leaders, meet with them from time to time, beginning of the year, every 3 or 4 months, so they can understand how you’re progressing, and actually, one of the things that I’ve done right in the very beginning is center my cyber strategy to enterprise risk assessment. I generate something like a Gartner quadrant or business risk quadrant and then tie those risks to business strategy so they can understand it and talk that language, and then actually having good processes like focusing on security across the systems acquisition development life cycle, having a playbook for cloud services. Jake touched upon that earlier, but most importantly, harnessing trusted partnerships across the enterprise. Because if you found in your cyber strategy on these key tenets, now you’re in a different position because you’ve become a partner to the business. You’ve extended that federation, and you’re having these regular conversations. So now to answer your question directly, I think, I see the role of the CISO evolving. Now back in the day, maybe 25 years ago, there was a technical CISO. Then this was a business CISO. Now we are more in the era of the risk based CISO, and there’s also transformational CISO, and I don’t want to get caught in the organizational reporting structure, but I’ll just say sometimes CISOs have to play across all levels, and it’s the CISO’s job now because they are the leader, like ship captains to manage risk and to partner with enterprise privacy and risk management to actually frame how risk can be used as an enabler and competitive advantage so that businesses can walk that fine balance between value protection and creation. So I think CISOs need to lead that conversation, and this is why I think in some companies now, the CIO even reports to the CISO because companies see that it’s all about cyber risk and the CISO has become a risk based and a transformation leader in some companies. Hope that helps, Sanjog. Did it resonate at any level?
Sanjog Aul [00:23:53]:
No. It did, and, Jake, I’d like to build on that. So Arun mentioned partnership. Right? So you could have the CISOs and the business leaders sing kumbaya and be all buddies, and they take a common definition of risk or a certain benchmark of risk tolerance, and run that business, but would it not be a good idea to look at risk outside in and establish benchmark based on what makes sense to a third party who is looking at that business and saying for this business type, this is the risk versus leaving it to human emotional decision on what risk should be for a given business at a given time?
Jake Margolis [00:24:36]:
I can give you a short answer to that. I would say yes, but that would lead to a lot more questions, but the short answer is yes. You want the outside in perspective. Because I think part of it gets down to as we assess risk, we do it fundamentally how we defend the enterprise. You’re always trying to think, what is somebody going to do to me? So that’s why I wanna analyze risk that way. How do I look to the outside world? More importantly, how do I look to my shareholders, the board, and in my case, the public, because I work for a public sector entity, how are we presenting ourselves as good stewards of the public trust? Those are important questions, and so I think part of that is in how we manage risk. We would think about it in terms of what would your stakeholders think of how you’re approaching this issue. I think that’s an important question to ask. I like the statement about Kumbaya with business because I would actually like to get to that place, but I don’t think any CISO is ever gonna get there, but we get close, and we do develop meaningful partnerships, but the biggest thing is treating risk as part of the business; there’s no way to get rid of it. People have to come down to that reality. Oftentimes, when people are trying to do something, I see in previous organizations people get really passionate about an initiative that they’re doing, and nobody’s ever asked the question of, what happens if you don’t do that thing? What happens if you don’t do that? Are we gonna lose money? Are we gonna lose productivity? Is it gonna affect our reputation? If we do this thing you’re talking about, is it gonna make us more money? Is it gonna improve our reputation? Sometimes that question is not asked, and I think one of the things that the CISO can really weigh in on, particularly when it comes to IT’s involvement with the business, is we can stop the tail from wagging the dog. IT has evolved over the last few decades to sometimes be the tail that’s wagging the dog. A lot of us have seen that in organizations where IT says, hey. We have a better way to do something. Nobody asked for that. Yet IT is presenting it as how we’re going to do it now. I’m not saying that’s not part of IT’s job, but that’s a little bit about how we’re engaging the process and how we engage the business processes determines how we assess the risk. So when IT says I have a way to make that process better, but you didn’t make the risk coefficient better for that process by introducing this new way of doing something. To a certain degree, it’s interesting that Arun mentioned how IT and cyber are divergent. In some instances, they’re having CIOs talk to CISOs a little bit more in that directed kind of relationship, but I think we’re approaching that era where a CISO is having to be holistically involved in leadership, and I think that’s how I would address that.
Sanjog Aul [00:28:58]:
So, Arun, based on the response that, Jake, he mentioned about the CISOs have to become leaders. So I have facilitated CISO level events, in person events globally. Yeah, and when I sit with them and hear them talk, they
Arun D’Souza [00:29:17]:
don’t.
Sanjog Aul [00:29:17]:
I mean, I’m not talking about both of you, but I’ve not seen many CISOs showing that confidence or even the intent to get to that role. They’re very happy and content in that cocoon, but they cannot stay there because that’s not gonna help them do their job, because it’s comfortable for them to stay geeky and talk about the security side or the technical side of security versus talking risk. So 2021 will require people to come out of their shells, whoever is in that shell, but how will they come out? Do they need external help? And if yes, how can they be helped? How can we enable them or empower them?
Arun D’Souza [00:30:05]:
Yeah. So it’s funny that you say that. The reason for that is a couple of things. On the one side, in many organizations, there is a lack of awareness that the CISO role is that of a business leader or a ship’s captain, as I said, and an all around leader, like Jake was saying. They just haven’t caught up to that, but another real challenge is, to your point about people being in the cocoon is that the majority of CISOs come from dedicated technical backgrounds, and they may need training and development to grow their business acumen. I started myself as a very pure technical CISO back in 2003. At some point in the mid of the last decade, I needed to grow my skills. So I enrolled and completed the CIO pocket MBA from Boston University School of Management. I took a class on contract management five days to expand my business chops, if you will. Over the years, I’ve joined a lot of seminars, conferences, and so on to learn from other people. Especially in this day and age, they need to be able to grow their skills and make the choice. Either make the choice themselves like I did, or companies need to provide them the training. Something that’s not as well done in organizations is that there’s no clear career development and succession planning strategy for interested people in CISO roles. We need companies to be able to give them opportunity to grow. It’s on us as we are early in a career to participate in cyber groups like the Cloud Security Alliance or ISACA and get mentors in the industry that can help you. I think it’s incumbent on both sides of the organizations to support high potential folks, but for people who are interested to take the bull by their horns and train themselves as well. It is a matter of choice, both on the organizational side as well as personal side, to grow and develop. Because on the other side, there is no choice — to be a ship’s captain, a CISO, you need to grow. There’s no choice. I hope that helped.
Sanjog Aul [00:32:30]:
It did. So, now with that said, Jake, have you tried something yourself, or have you seen some of your buddy CISOs trying something to improve their leadership muscle or come out of their cocoon? What has the journey been like? Because many people came from the technical background and growing into the CISO role. Not many business people came in there. So for them to suddenly drop many years of grooming or training or the specific mindset. What has that journey been like if you’ve seen someone being successful in doing this?
Jake Margolis [00:33:07]:
Well, I think that we have to accept that leadership is a separate skill set, first of all. I remember attending a class that was based on one of John Maxwell’s books, The 21 Irrefutable Laws of Leadership, and he tells a joke in this video that they used to have back when we used to watch VHS tapes. The joke was a Native American warrior is going from village to village, and he gets to this village and wants to talk to the chief. He asked the chief if any great men were born in this village. The chief says, no. No great men. Only babies. I think that’s important for us to realize: you’re not born to be a great leader. You don’t come into the world and you’re ready to set the world on fire. Certain people are charismatic and have those skill sets naturally, but you have to learn to be a leader, and you have to learn by trial and error. To a certain degree, what I would tell people is we say it all the time, fail early, fail fast, and fail often. You’re not going to learn from your successes. I’d rather be good than lucky. If it took me a long way to get there and it was difficult, I’d rather do that than be lucky because anybody can get lucky. If you deliberately plan something and seek to completion, that’s gonna develop you. I think we don’t spend a lot of time teaching people to plan and problem solve. People need to learn more about actual problem solving, actual planning. When you’re going to do something, you have to ask yourself fundamental questions. What is it you’re trying to accomplish? Defining a problem isn’t about answering a symptom. Sometimes people say, well, we’re gonna remediate this issue, so we’re putting x on our desktops. Got it, but what are you actually trying to accomplish? What is the threat vector we’re trying to mitigate against? Maybe we could get more bang for our buck if we actually try to deal with the root cause. Leadership is something that has to be taught more in leadership academies. You have to flex those leadership muscles and be willing to take personal risks, even if it means you may not be successful. People tend to be unforgiving. I’d look to other leaders in the business world and in the industry to not be so unforgiving. As long as you’re empowering people to learn, you have to accept that people are gonna make mistakes. If they can recover and learn from those mistakes, they’ve built enough skills that when a mistake that’s looming occurs, they’ve learned leadership skills to do proper planning, risk assessment, and have contingencies. I had training in uniform, and I was fortunate to work for officers that gave me those opportunities to fail, taught me along the way, and helped me pick myself back up. That’s what I try to do for other people in my organizations and those I mentor. Leadership is fundamentally a skill set that needs to be taught.
Sanjog Aul [00:37:10]:
Let’s take a quick break, listeners. We’ll be right back, and, Arun, when we come back, let’s try to come up with ways or maybe you have a way already to tie security budgets to risk management or improvement in risk management and business growth. That’s what business says you got to show. What kind of metric would that be? What kind of formula would you use for that? Please stay tuned listeners. We’ll be right back and explore.
Speaker 0 [00:37:35]:
Today, enterprise technology is both strategic and global. Each week on CTN CIO Talk Network, IT thought leaders from around the world share their experience with listeners as they discuss with Sanjog Aul how they are trimming costs and partnering with business to innovate and help IT become more competitive, better care for customers, and improve the corporate bottom line. If you want to keep up with IT thought leadership, listen to CTN, CIO Talk Network with Sanjog Aul at ciotalknetwork.com. You are listening to CTN CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.
Sanjog Aul [00:38:30]:
Welcome back. So, Arun, an interesting question for you. Security budgets that you are supposed to get, you gotta tie them to improved risk management and also value creation and business growth. What would that formula look like?
Arun D’Souza [00:38:51]:
So, just a little preamble. Security budgets, you’re right, are typically tied to either the IT budget or risk management, and the goal for many companies is to compare and benchmark expenditures within the company, peer group, or industry. This may be helpful to some extent, but in my opinion, it’s a limited and very myopic way to bracket the value to the business of the information security function in the modern era. A couple of things. Every year, we need to do an enterprise risk assessment and adapt your program maturity, know where you are. One of the things that I found very useful is a valuable framework developed by Intel Corporation called the Business Value Analysis Framework. It is a model tied to three dimensions: the functional fit, the organizational fit, and the financial value for any projects that you conduct. There are various choices you have to make on a scale of 1 to 5 and a variety of questions, but the end result is because embedded in the functional fit are elements linked to organizational strategy, culture, etcetera. The technical fit takes into account the architectural alignment, integration of existing security tools, and so on. Ultimately, potential investments are plotted in a bubble chart quadrant of business value versus functional value. What you want to know is how investments or potential projects are doing. If they come up in the top right hand corner, the quadrant, high business value and high functional value, those are investments you want. That’s a two parter because you do that when you’re going out to ask for funding, but you also go in after the fact and see if those investments that you made for the business have actually given the values that you had projected, where they are really at, how they’ve driven value to the business by decreasing risk and so on. I found this methodology very helpful to executive leaders because now they’re able to understand that behind this model it’s a three-dimensional model, and they see it better. That helps you to be seen as someone that understands that cyber and enterprise risk have to be aligned to the business strategy, and they’re able to see in a visual way something they can understand and trust as long as you do the due diligence every time. So that’s been helpful. I think the metric based view is somewhat limited, and that’s at least been my experience. Sanjog and Jake, hope that resonated.
Sanjog Aul [00:41:36]:
Sure. So, Jake, you want to chime in and then share your approach to how you came up with the magic formula?
Jake Margolis [00:41:43]:
Well, I’ll let you know when I do come up with the magic formula, but I will chime in. I think that we’re long since graduated past FUD, and I’m still shocked that in coming into 2020 and 2021 you’ll still run into CISOs every once in a while that will use fear, uncertainty, and doubt because they’ll prey on emotion to get what they want. As we know, that’s only good for maybe one fiscal cycle, if that. I do agree with Arun and the metrics point, especially when it comes to security, you are trying to figure out what metrics actually matter to people because things that matter to us as cybersecurity professionals often have very little meaning to the business. So that’s a tough one. You can’t really align it with IT centric metrics either because those aren’t the same things we’re looking at. I could really care less how many tickets are closed in a given month, for example. That has very little to do with my world. The types of tickets, sure. When we start looking at how to establish that value, I try to tie it to what’s important to the organization. For us at Metropolitan, for example, I look at things from a public sector perspective and say, hey. What is it that would be most impactful on us, that would be damaging to our image and the public trust? Let’s align our value based on that, but keep in mind what is the most important thing we’re doing — our core competency is to move water. Any efforts we put into cybersecurity have to be complementary to that. Is it going to help us gain better awareness? Is it going to help us have better stability of the system? Those are the kinds of questions I look at. When I was at the County, I looked at the same way. County was more complex because we had 26 different entities, each their own business with their own lines of business. It’s always a little bit of a challenge. So my perspective is unique because I look at it from the public trust perspective and what is impactful if something happened to us, and how that’s going to come out as far as what our investment was to prevent these things. I try to stay away from fear, uncertainty, and doubt. From a public sector perspective we don’t have the same financial goals as private sector. When we answer to our boards, it’s more about policy issues and how we’re maintaining stability and are we being good stewards of taxpayers’ dollars as opposed to how profitable we’re going to be. So that’s different, but what Arun is suggesting is applicable and something I’d want to add to our toolkit at Metropolitan, but the outcomes we’re looking for are a little different. The way we have to phrase what we’re doing is a little different. I try to tie it to strategic initiatives so I can communicate a strategic level plan when asking for more money because I can show where the money is going to be spent along a strategic roadmap over the next 5 to 7 years, adjusted every year or two based on how things are going. For me, it works because I keep the conversation about cybersecurity being a public safety issue, and when focusing our efforts we keep that in mind to improve public safety and cybersecurity. It becomes easier to drive the conversation.
Sanjog Aul [00:46:38]:
Absolutely. So Arun, building upon what we need to do in terms of the budgets, the next come is, okay. I give you the money. How would you be effective as a security group? That means you need the right culture, the right org structure, the right talent. What is your recipe for 2021 that you are cooking so that you’re ready and you’re effective?
Arun D’Souza [00:47:05]:
Yes. Absolutely. One of the things we read all the time is there’s like 3,000,000 open positions in cybersecurity worldwide. That number keeps going up, especially with the exponential growth of IoT. So we have to try to bridge that gap somehow. From a cultural perspective, start by leveraging partnerships with the business and across the enterprise to develop and communicate a unified vision. Collaborate and share information with them, but also focus on cost optimization and program execution, because you’ve gotta be able to fund your resources, especially in manufacturing. Build and embrace change management. We need to probably add security operations resources and other stuff, but it all depends. How are you going to determine what you need to do? The first step is to build out a detailed services and competency framework with the skill sets that you need to support the services you have today. Then determine the gaps between your current state services and your future state services to have a strategic hiring plan. This has to be done every six months or every year because the challenges keep increasing. How do you mitigate this risk given the shortfall of talent? Some strategies: define an appropriate mix of in house and outsource services because you can’t insource everything or your cost will get out of hand. For those services you have in house, conduct cross training across service tiers, like folks in identity management should be trained in security operations and so on. Managed services are key. Find the sweet spot at the appropriate scale to balance and deliver services economically and cost effectively. Leverage training and development succession plans. Whether organizations are asking you at a hierarchical level, you need to do it anyway. Once you know your gaps, you can negotiate some cost savings to self fund certain key roles to the extent you can. Also develop a grassroots talent pipeline by partnerships with universities with students and co-ops. Identify talent early and strengthen your pipeline. Last, build affiliation with industry groups and universities to identify interested talents and help get more young people into the industry from a diversity and skills perspective. It’s a multidimensional, layered strategy for talent management in this modern era.
Sanjog Aul [00:50:28]:
So one last question I’ll ask you, Jake, is about the specific leadership set of muscles you will build. If you had to fix something in you, Jake, what would you do to be better ready for 2021? And time permitting, I’ll ask Arun, you as well.
Jake Margolis [00:50:46]:
Other than lose the 25 pounds of COVID weight I put on, something I’d like to improve for 2021 is my relationships with units outside IT and continue to build relationships within IT. Sometimes in my work and how I build programs, I find myself at odds with fellow IT people just because we’re changing their world. When we come up with the solution and say, hey. We’re going to move this endpoint protection to a cloud centric service, the people that manage that AV server cluster that’s existed for time immemorial think you’re taking away their job. I want to improve how I do that. One thing I want to do in 2021 is adopt a training strategy that is cross training but broader: every IT professional is a cybersecurity professional first. We’re developing a training program that stems from the top all the way down across IT verticals, and that includes myself. What do I need to get better at in 2021? I have a couple educational goals on the horizon. I would like to look at some legal education in 2021. I’m not sure exactly how that’s going to manifest yet, but I am considering that because I need to improve those chops to better work with our general counsel and other lawyers when developing relationships. I also want to build this training model with the right matrices to show every IT professional can be a cybersecurity defender so we can develop depth in the organization to maybe address that 3,000,000 employee shortfall. If I have people already hardening servers because they manage our domain controllers and servers, then I don’t necessarily have to hire an IT security person to come in and…
Sanjog Aul [00:53:20]:
Thirty seconds?
Jake Margolis [00:53:22]:
So anyway, that’s what I’m looking at for 2021: improving that training and collaboration space.
Sanjog Aul [00:53:30]:
Alright. Total of fifteen seconds, maybe a couple of words in. Arun, which muscle are you gonna fix quickly?
Arun D’Souza [00:53:38]:
Yes. I would continue to strengthen my change leadership muscle because it’ll help in this modern era with all the threats out there. It’ll help me be a better business leader as a CISO by leveraging collaboration, communication, envisioning and storytelling, relationship management, program management, negotiation and vendor management, and strategic cost optimization.
Sanjog Aul [00:54:04]:
Once again, thank you so much, Arun and Jake, for sharing your insights and thoughts about how CISOs can gear up for 2021 and be seen as a business leader. Thank you.
Arun D’Souza [00:54:16]:
Thank you, Sanjog. Thank you, Jake.
Jake Margolis [00:54:18]:
Thank you.
Sanjog Aul [00:54:20]:
And listeners, hope you enjoyed it. Please connect with us on Facebook, LinkedIn, Twitter, and Pinterest, and subscribe to our podcast on Apple and Google Podcasts, as well as all other major channels where you listen to podcasts. Once again, thank you for listening to CTN. This is Sanjog Aul, your host. Till next week. Take care, and God bless.


