Cybersecurity Infrastructure & Operations Leadership Talent Development

How to Build an IT Security Team

How to Build an IT Security Team

As threats from APTs and other attackers continue to rapidly morph, the CISO faces an uphill battle of getting his or her team up to speed on the dangers that face an organization. The traditional model of waiting for a breach and then reacting has changed to be preemptive and preventative, and with that comes a score of new skills and strategies the CISO must develop among his or her team. What challenges are CISOs facing in this regard, and how can they address them? Where can they look for help, talent and added resources?

Contributor

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript

Sanjog Aul [00:00:25]:

Hello, and, welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. As always, we invite you to join the discussion on Twitter, #CTR live and #IT security. Today’s topic is How To Build An It Security Team, and our guest for today’s show is Adam Rice, who is a Chief Information Security Officer for ATK, and he’s a member of the CIO Executive Council. So, Adam, how are you doing?

 

Adam Rice [00:00:55]:

I am doing fine. Thank you.

 

Sanjog Aul [00:00:58]:

Great. Now we’ve always talked extensively on past shows about, new threats that may be facing the enterprise and things like APT, which is advanced persistent threats, and they are continually, morphing, but the question is, how can anyone keep up? We have spoken to quite a few CISOs online and offline, and we have seen that people are becoming one of the bigger, or most more, chronic challenge, if you will. So, Adam, what we wanted to do today is to look at what the landscape is, how is it morphing, and how is it going to be impacting what type of crew that is built or how is that going to change as the time goes by? So with that said, the first question is, is there a specific pattern that you see in the way the challenges and threats that organizations are facing and the way they’re morphing? Can you kinda sit, and watch it and kinda give it a definition or a pattern?

 

Adam Rice [00:01:56]:

I think that’s exactly correct. I think that cybersecurity is probably one of the more dynamic professions in the IT field. The threats, the people we work against, are changing their methods, their means, and I think that as those threats change and morph, which they do all the time, it is hard to back that up with a staff with skills and experiences that match those threats.

 

Sanjog Aul [00:02:35]:

So if you look at the changing pattern, do you think this is basically becoming a race against people with far more resources, or is that more of our inability to cope and then so that’s why we say that, okay. The other people have more resources there, have bigger institutions which are supporting the intrusion.

 

Adam Rice [00:02:57]:

So I think it’s a little of both. I think that your traditional cybersecurity team was a firewall guy, a policy guy, and leaned heavily on the vendor paradigm of signature-based security, and I think as the APT has really exploded in the last 5 years, it’s become pretty obvious to me anyway that that traditional paradigm of signature-based doesn’t work very well, and we are moving more towards a threat intelligence based defense, and this is true across especially my industry where our threat is very, very understood, and so when you staff against that kind of model, you have to understand that your adversaries are capitalized to millions and millions of dollars if it’s a nation state for instance, and they certainly seem to have the advantage. So it can be a challenge to convince management that you do need to retool your team to be more effective against these adversaries.

 

Sanjog Aul [00:03:56]:

And one is to say that APTs or any of these more sophisticated security issues or challenges we are facing are pervasive, but when you talk to quite a few people, there is a significant percentage who really are not as threatened by APTs because they are not above the radar as much.

 

Adam Rice [00:04:17]:

Well, I think it’s industry based. I think that a CISO has to really have an understanding of what their threat model is. I’m lucky in some ways. I work for a defense and aerospace company. So our threat is described on the front pages of The New York Times, but if you don’t work for an obvious target like finance or defense and aerospace, it can be a bit more difficult to really ascertain what your threat is, I think.

 

Sanjog Aul [00:04:52]:

And so suppose we take the ones we’ll perhaps during the show, talk about both sides and see how the people side can be handled or can be structured. So starting with the type of organizations such as yours, which can make the headlines in The New York Times in case there is a breach. So you definitely have to be sensitive, but how much sensitivity is enough?

 

Adam Rice [00:05:18]:

Well, I think that for a company like ours with an obvious threat, I think that we do have the advantage of leadership from the Board of Directors to the CEO to the CIO who understand that this is not something that is ambiguous or ethereal. It is real and it has a consequence if our adversaries are successful. So they understand that and it makes a part of their leadership statement that they don’t want that to happen, and that flows through the organization and it allows me to be able to staff up with the skills and within my organization what I think are the most effective ways of directly confronting our threat.

 

Sanjog Aul [00:06:07]:

Now let’s come to the people side. So as any organization which wants to have their people understand the business and having lived the environment for a little bit, they always will be more comfortable in that incremental change that may be coming down the pike. So take the, for example, the security team. Would you think a security team will comprise of specific roles that you had envisioned and identified and actually hired for 10 years ago? Is that relevant today, or would you think that has significantly changed? And if that’s the case, do you think the people who were hired with that old mindset, a 10-year-old mindset, is relevant today?

 

Adam Rice [00:06:44]:

You know, I would say that if the bad guys that are coming after your network are the advanced adversaries that you read about, if you structured your team even how most cybersecurity teams are structured five years ago, I think that you would be woefully unprepared to deal with the adversary. I think that over the last probably five years, there has been a big shift in what’s considered critical skills to go after the advanced adversary. Now if somebody is in an industry that perhaps doesn’t have the APT issue then perhaps the more traditional security staffing model would be more appropriate, but for organizations that have an advanced threat, I would say that the old paradigm does not work.

 

Sanjog Aul [00:07:36]:

So let’s compare the two. So when you originally started by saying that maybe, the traditional security team might have someone from policy, someone who is taking care of the firewalls and other type of, preliminary things. Could you draw a parallel or maybe a difference between five years ago team makeup and the kind of team we need today?

 

Adam Rice [00:08:02]:

Yes. So 5 years ago, you would have just speaking to what you just said, you would have your network appliance or device team and these would be your security engineers that would take care of your IPSs, your firewalls, your AV, your signature-based tools, and then you would have a governance risk and compliance team that would handle your compliance requirements, your policies, your more softer skills, and then they would combine under the CISO to kind of drive a security practice that was based on reactive security, signature-based security and then the policy side. So those two jobs are still relevant, but perhaps not as important. I think that the change is the addition of a CERT, a computer incident response team that is staffed with a job called a security analyst, and this is a relatively new kind of career.

 

Sanjog Aul [00:09:07]:

And could you define the security analyst role? What are we analyzing? Something which we don’t know enough about?

 

Adam Rice [00:09:14]:

Well, I think that everybody will uniformly agree that signature-based security doesn’t work. I mean, if it did, the vendors would underwrite their products with a guarantee that if there was a breach, they would pay for the remediation, and when I ask my vendors that question, of course, they just laugh at me, but so the shift has gone from signature-based security and a reactive stance to a proactive stance that is based primarily on threat intelligence, right? Understanding the MOs, the means and the indicators of compromise that our advanced adversaries use and then spending time on your network perimeter and inside your network to look for indicators of compromise because traditional security, signature-based tools will not detect it.

 

Sanjog Aul [00:10:07]:

Now come to the type of skills that you say for the advanced, where the organizations are facing some advanced level of threats. Are they always supposed to be by design? We are almost saying, oh, APT, it’s something new. Is APT a default type of threat, which is, like, almost fear of the unknown, and then we start filling up our team with the people who would be able to effectively handle it, but even that flavor of threat that they are expected to save us from, that’s also morphing. So how relevant is that incremental skill staff going to be from today to tomorrow?

 

Adam Rice [00:10:49]:

Right. So it is kind of an arms race. As we get better at seeing and preventing the APT, the APT in turn will try new strategies and campaigns using new indicators of compromise to get in. So the security analyst is a person that understands some of the probably the required tools that an enterprise would need beyond just firewalls to be able to use threat intelligence, but they have to spend their day really finding the proverbial needle in the haystack. They look for that trace of the bad guy, that indicator of compromise, and it’s not like doing a firewall rule where it’s source, destination, port and enter. These people have to work with very little information trying to find that one little unusual signature and then be able to walk the dog back and see where it came from and what it’s been doing.

 

Sanjog Aul [00:11:52]:

If you took APT out of the equation for a second, would you think there has been any fundamental shift in the way the network and firewall was handled, the way the governance compliance was handled, the way the risk was handled, and the other three, four areas that you had mentioned, which each of them had to be staffed by appropriately skilled people?

 

Adam Rice [00:12:11]:

Well, I think that, since the advanced threat has kind of crept into our paradigm, I’m finding that some of the very commodity skills that are needed to run a security practice fit that outsourcing model pretty well. So I would certainly hire a more senior firewall engineer or network engineer. I would see that as a critical task, but to hire also a bevy of very junior firewall engineers to do kind of that commodity firewall rule changes and just that kind of work, I would probably see that as an opportunity to outsource, if it made sense.

 

Sanjog Aul [00:12:57]:

Now if you’re saying that the outsourcing is basically a standard approach to how people handle security, then there are quite a few organizations, maybe not organizations such as ATK, who do not feel that APT is a threat. So they could very well either keep the status quo or start looking at outsourcing their security and take a 2-week vacation and life is good.

 

Adam Rice [00:13:24]:

Well, you know, outsourcing the work is fine, but what you can’t outsource is your corporate risk. So if you think that just writing a check to a managed security service provider is going to anyway decrease your risk, you’re probably wrong. In some ways, it actually increases your risk and that risk has to be managed regardless who’s taking care of the front door, either the managed security service provider or an internal team. So the decision to go with an MSSP has to be a deliberate one typically based on just ROI. If you want to watch the front door 24×7, it’s typically cheaper to go with an MSSP, but you have to go into that relationship with 2 eyes open. There are positives, but there are certainly negatives that need to be managed.

 

Sanjog Aul [00:14:15]:

Let’s take a quick break, listeners. When we come back, let’s specifically start identifying the challenges that CISOs, may be facing when they are trying to build a strong IT security team, and along with being strong, a team which can actually come hit the ground running at the same time has the DNA to be able to morph and expand their skill set as the landscape, the security landscape is morphing as well. So please stay tuned listeners. We’ll be right back and explore.

 

HP [00:14:57]:

HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner.

 

Bosch Software Innovations [00:15:27]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch connected manufacturing.

 

HP [00:15:59]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:16:44]:

Welcome back. So, Adam, what do you think are the top challenges organizations are facing fundamentally in building a strong IT security team to meet these newer challenges?

 

Adam Rice [00:16:58]:

Well, I think that number one, organizations need to be able to articulate what their threats are and what their risks are and do that comprehensively and then design their team around those threats. I think that as more and more industries are being hit by the APT and advanced adversaries and those aren’t just nation states, criminals are picking up their MOs. I mean the success of your usual suspects has been noticed by also more criminal elements. So the advanced threat is certainly broadening its repertoire. So as organizations sadly typically discover they have a problem when they’re told they have a problem. So if you don’t have a good handle on what your threat is and what your risks are, you usually make that discovery with a victim notification from the FBI or a notification from somebody that your stuff is out in the wild, and then there is this reactive approach to throwing money at the problem and trying to fix something quickly. So if you understand your threats and you understand your risks and you can structure your team deliberately, I think is probably a more sound approach, though I don’t think it happens that often. Usually people change security when there’s been a problem, but the biggest challenge I think is finding the skills. There is, at least from where I sit, a real lack of available talent.

 

Sanjog Aul [00:18:38]:

Could you further inventory the specific competencies and skills that you’re looking for in a certain mix, which is not available readily or we are not able to attract?

 

Adam Rice [00:18:50]:

So I think it’s kind of across the spectrum. It’s not just the security analyst role that I described, although experienced security analysts with experience working with the APT are hard to find, but even when you come to more traditional security roles like an advanced firewall engineering team or security architect, people with deep skills and knowledge across that vendor palette, even those roles there is a shortage of experienced skills. So if I were to have a senior position open where I wanted somebody with real mid- to late-career experience in some of these skills, it would be hard to find, both in the security analyst roles as well as the traditional security engineering roles. There are more jobs than there are people it seems.

 

Sanjog Aul [00:19:46]:

And where is the expected source from where these people will get the training? Or like we spoke sometime back about big data teams. So they had the same issue where they’re saying, we want a lot more people than they’re available. So then the question is, who’s gonna churn those people out? There is no degree at the engineering level. Even if they are taught certain things, how qualified are the folks who are teaching because they themselves don’t have the experience, and if you don’t have the experience, then you will never fill the role. So what is the source? Because you and us can be sitting here two years from now, and we could have the same issue to a larger degree because more and more people are gonna face the issue, and supply is less than demand.

 

Adam Rice [00:20:30]:

I agree. I think that universities and technical schools are woefully poor at turning out graduates that actually have skills that are usable on day one without additional training. I don’t think that we do a good job at that at all. I think that where people gain their skills is when they do have a job or get an entry level job, they acquire training through their current employer and build up their skills with the investment their employer has made, and then when they move, they move with those skills. So most of the experience that is gained is when somebody has worked in progressively greater roles within a security organization, and that pipeline is tight right now.

 

Sanjog Aul [00:21:25]:

And what is the hope? Because as I mentioned, if this is a choke point for most of us and on the other side the people who are intruders or the ones who are causing us the pain, they are actually enjoying the fact that we are becoming more and more helpless, but can we live like this? Can we plan our organizational risk mitigation like this? Who’s coming to the forefront to be able to take this lead role and say, okay, I’m going to as an organization work towards it or we are a bunch of organizations who are going to work towards building these skills and share those skills in some form. What’s happening at your end?

 

Adam Rice [00:22:00]:

So I think that the responsibility to train, hire and retain security professionals at least in my organization stays within my organization. One thing that does work collaboratively is the threat intelligence and other processes that are shared and enjoyed probably across many organizations. The defense and aerospace industry figured out a long time ago that there was no competitive advantage to not sharing your threat intelligence, and so across several industries, a lot of that threat intelligence is shared and techniques and methods of detecting the APT and certainly our security analysts learn tons from that broader collaborative environment than they would if they did not have that. So probably if I could point to any single thing that moves the ball forward for us beyond just having the skills is being able to collaborate in that larger environment to get that threat intelligence.

 

Sanjog Aul [00:23:14]:

So if you get threat intelligence, would you think you’re better off getting people who may not have that level of experience and expertise that you will ideally want instead get someone who is semi to a limited degree there and then take them under your wings and arm them with the threat intelligence and the training and education and mentoring that you could offer so that you got a little brighter light at the end of the tunnel?

 

Adam Rice [00:23:43]:

So I think that’s absolutely it. I think that the way that most organizations have to approach this is try to hire junior staff that look bright and are eager to learn and have the competencies to learn the skill and then bring them into the organization at the bottom, and then over time, probably in 1 year or so, they will have absolutely gained their feet and can do the job well. I think that that is probably the smartest approach is to hire low in the organization and then train them yourself.

 

Sanjog Aul [00:24:25]:

And if you were to train yourself, would you say that we have enough people within our respective organizations who have the level of experience and can mentor those junior? Because then we are limiting what our people know.

 

Adam Rice [00:24:42]:

No. I think that in most cases, if an organization has a CERT that is up and running, you do have that legacy skill within the CERT if you do bring in younger people. We do this deliberately. We hire junior staff and then we go through a deliberate process to get them trained up.

 

Sanjog Aul [00:25:07]:

If you’re a rock star in terms of security management and risk and other skills and competencies needed, where does that person go to learn? Do they expect some outside resource to be available or the maximum exposure they can get to what’s happening next is just by trial and error within the environment they are?

 

Adam Rice [00:25:28]:

So I think they learn within their peer group. I mentioned to you that we collaborate a lot within our industry on emerging threats and methods and so on, and within that same forum, there are workshops and there are symposiums and there are training opportunities, and we leverage those to their fullest extent to make sure that people are going out because the emerging threat or the advanced threat, as I mentioned, is dynamic with new MOs, and so it is a continuous learning process to be able to be effective as a security analyst.

 

Sanjog Aul [00:26:09]:

Would you have a benchmark of sorts which you would expect your people to be able to live up to? And then is there a way to measure that they have reached that level of scale? And if not, then the delta could be met by some external third party expertise who would come and help fill the gaps in terms of what their experience level and expertise and competencies are?

 

Adam Rice [00:26:33]:

Well, I think that a scientist from Lockheed Martin described the APT and they called it a kill chain. From left to right, it went from the initial reconnaissance of the advanced threat to the far right side of the kill chain, or to the bottom of the kill chain, was the exfiltration of data from the network. To stand on the ground and say we will not have an APT problem, we will stop it at the front door, I think is not a realistic goal. I think that there are a lot of ways to stop it within the kill chain, but you need to measure your success by stopping the APT or recognizing it and putting proactive blocks in early within that kill chain. So during the initial reconnoitering of your networks by the adversaries or their social engineering campaigns or their spear phishing campaigns, if you can see those coming over the horizon before they land on your users’ desktop, then you are certainly on the right side of the curve. It’s the organizations that don’t even realize they have a problem until they get the victim notification from the FBI, and then what they will typically do is rush for outside help to come in and leverage commercial threat intelligence databases to look at their networks, to figure out where the problem is and then how to clean it up. The problem with those companies is that their business model is for people to show up at their front doorstep fully on fire with a checkbook at hand and a boot mark in their butt from the board saying fix this now. So those outside organizations tend to be very expensive. So if you have a problem and you find out about it late, this is where this high cost of remediation comes in, I think.

 

Sanjog Aul [00:28:29]:

Now would you agree that when you look for people with those not commonly found skills and that unusual amount of experience and expertise, they recognize it, and a demand supply gap allows them to encash it by being in consulting versus joining somebody on their payroll. Do you think then you could perhaps have people with that stable set of skills who are more likely to stay with you? You create that type of an organization and maintain that stability, and for the special needs, you keep people at an arm’s length who are really specialized, but they choose not to join your organization. Do you think that’s a safer way of handling your ongoing needs?

 

Adam Rice [00:29:10]:

I think it all comes back to what your organizational threats are and what your risks are. I would say that if a company does not have a real compelling story to defend against an advanced threat, then that might work. I mean, there might be real sound business logic around that approach and save on OpEx and headcount, but I think that if you are in organizations that have that bull’s eye spray painted on your back, I think that is a necessary and critical skill to have in house.

 

Sanjog Aul [00:29:44]:

So you will try to buy that skill, whatever the cost is. Is that what the message you’re sending out?

 

Adam Rice [00:29:50]:

Well, you have to hire the skill, and then you have to train them and retain them.

 

Sanjog Aul [00:29:56]:

Let’s take a quick break. Listeners, we’ll be right back, and let’s talk about the crown jewels. Every organization can definitely identify the crown jewels because you cannot try to be boiling the ocean and trying to secure any and every asset that may be out there, and that’s why prioritization and rationalization is important. So in the security context, which are the crown jewels? How does an organization come to know, and how do you prevent distraction for your security team to try to go after any and every asset that any and every business user says is important to them and eventually have a finite number of items that you’re going to work towards securing? How do you create a method to this madness? Please stay tuned. We’ll be right back and explore.

 

HP [00:30:45]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud.

 

Bosch Software Innovations [00:30:57]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch Connected Manufacturing.

 

HP [00:31:28]:

HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:32:31]:

Welcome back. So, Adam, we have heard quite a bit about organizations identifying their crown jewels and focusing their energies to secure those crown jewels, but the challenge comes when either the business unit leaders are sometimes not able to or they don’t take the time to identify those crown jewels so that we can focus our energies. Or in many cases, a CISO’s team is invited to talk to business unit leaders or other users, and everybody gives their own priority, and suddenly, you could have a long laundry list of items which somebody would like to see secured, and everybody is gonna pull their own influence to get that be given the right priority. How do you handle the distraction that could come because you cannot be everywhere and have that leadership conversation at your level alone?

 

Adam Rice [00:33:31]:

Well, we kind of approach this in a few ways. The first thing that we look at when it comes to finding out where the family jewels are as it were is what are our regulatory and compliance requirements? In our industry a lot of the stuff that we make is protected under federal law and statute. So our data is actually a violation of the rules for our data to leave the United States or go to non U.S. persons. So we leverage, I think foremost we look at our regulatory burden and our compliance burden to kind of set our standard on what is the precious stuff and what is not, and in our industry, a lot of our data is covered under EIR and ITAR, the two rules. So it’s not really even a discussion with the business units at that point. The law is what it is and we have this fiduciary responsibility to kind of protect that data, and if the data does become loose or lost, we have to disclose that to the Department of Commerce, the Department of State and our customers, and that’s all embodied in the regulation. Where it comes to more kinds of intellectual property questions, what I like to do is rely on policy or data categorization policy that describes data in several flavors all the way from restricted to public, and the responsibility is on the owners of that data to appropriately categorize their data within four or five general categories, and then each one of those categories in turn have a commensurate kind of IT security approach all the way to our ITAR control data or our very proprietary data, financial data. That stuff is protected in a certain way all the way to our public website and other publicly facing information have different security controls. So we publish these policies and then we get support of leadership to enforce them, and then if the business units fail to categorize or lose control of their data that turns out to match one of these categories, then the responsibility falls back on them.

 

Sanjog Aul [00:36:04]:

So your environment definitely, and that’s why I say you’re blessed that you have regulations helping you out. In many cases, there are organizations who may not have such a clear cut definition of what crown jewels are and their definitions, how to identify which ones those are, and how are they changing? How is that priority changing? So should the CISO’s team be chasing the business to be able to extract from them, or is it somehow to be put in the governance structure that the business unit leaders are sharing the current state as well as how things change so they send us a delta report, if you will? And CISOs then know exactly how to prioritize their people’s activities so that appropriate family jewels, as you said, could be safeguarded.

 

Adam Rice [00:36:53]:

So I think that it has to be driven by policy. I think that if the CISO in any organization is trying to chase down that sum total of all data that’s produced within the organization at any moment and be able to stuff those into the appropriate buckets and then make sure those appropriate controls are in place, I don’t think it would ever work. I think that there has to be policy that is either an information security policy or an information technology policy that is endorsed and enforced from above that puts that governance responsibility directly on those data owners that the corporate policy says that if the data looks like this and you describe it fully and you put a categorization on it, that it has to be controlled like this, and this doesn’t need to be data that is managed through regulation or compliance. This can be anything the organization wishes it to be, and then the CISO’s role goes from chasing that into just internal audit and compliance to the policy, policy compliance checks, and then if there is a problem, they work to remediate it, and if there is data lost or inappropriately handled, then it becomes a question of policy violation, and then you just work with HR or however the organization deems to deal with that issue.

 

Sanjog Aul [00:38:26]:

So one is to create a policy. When we see examples of this particular strategy that you mentioned where I’m sure CISOs and their team may have tried to enforce a policy, but somehow even that policy is not driving the kind of change and the visibility that CISO’s team wants, what do you think could be going wrong?

 

Adam Rice [00:38:45]:

Well, then, probably you don’t have enough buy in from senior management. They’re not seeing it as a problem. They’re not seeing it as an imperative, and if that’s the case, then a CISO probably needs to make it very clear what they think the risks that complacency is bringing to the organization, make sure that everybody understands what that risk is, but in the end, organizationally, if there is a cultural resistance to doing it, I don’t think a CISO is going to be able to make it happen.

 

Sanjog Aul [00:39:24]:

But will they not lose their job if there is an actual threat which converts into damage? And he or she cannot say, I told you so, because now the damage is done and that policy was not enforced and nothing was put in place to save those jewels and now the jewels are lost or damaged and there you go. So who should be left holding the bag in this case?

 

Adam Rice [00:39:48]:

Well, I think it should be the data owners completely, and although I’ve never been in that position, I’ve heard of CISOs that have been in the position where they have all this responsibility and no authority at all to make people change the way they’re behaving and nor do they get the backing of their management to help enforce the policies, and if you’re a CISO in that position, then my first thought would be maybe you’re not in an organization that’s ready for a real CISO.

 

Sanjog Aul [00:40:21]:

And do you think there is something to be said about CISO perhaps trying to do the best job, but their own people coming back to the team that they have put in place? They are not able to go out and evangelize it effectively for business unit leaders or other users to be able to take it seriously. Do you think there is some sell job that has to be done at all levels within the CISO team and we have to have that competency built into each member of the team?

 

Adam Rice [00:40:47]:

No. Absolutely. I think that the CISO has to understand that their position exists, the organization exists to support the business. That to look at risks and risk management purely from a cyber technology point of view is myopic. I think that what the CISO’s message has to be back to the business has to be couched in the terms of risk to business, right? Either violation of regulation and compliance or NDAs or contracts and also the loss of proprietary data. So if the CISO has the ability to be able to make that risk statement with a business flavor to it, then you’re speaking the same language as the business managers, and even though they might not necessarily agree with your conclusions, they certainly are speaking the same language rather than if you come up to a business manager and say you have this Heartbleed vulnerability on your OpenSSL servers on this stuff and I have to take it down and that is going to result in a loss of the business, they’re not going to understand really what’s going on and you’re communicating past each other. So I think a big part of the new CISO kind of skill is to be able to take a big step out of just the basic technology realm and be able to work within the business units of an organization and that is a sell job, right? You have to have a traveling road show, you need to have security awareness training for managers as well as technicians, and a number of other things.

 

Sanjog Aul [00:42:25]:

So if you were to look at the type of mindset we need in the team, so there are two schools of thought here. One is saying that now we’ve got things like APT looming, so we have to become in that proactive mindset, and we have to start looking under the hood everywhere to see if there’s any thread, and that should be the mindset of a team. Second is after having worn that hat for a number of years with this APT being out there already, they say it’s simply not possible. Instead, we should have the team focus on how to react better when there is a threat which is evident. So in your view, based on where you sit and the way you see overall industry, what type of mindset would you promote and manage your team to adopt for it to be effective?

 

Adam Rice [00:43:20]:

So I don’t want to be in the business of incident response. I don’t want to be in the business of picking up the pieces after the incident happens. It’s costly. It’s damaging to the business. So I would say that you have to get in front of the threat and actually do your best to stop it before it becomes a problem. I think that you have to be able to respond to those problems effectively and have a tried and tested incident response process, but I think that remaining reactive is going to put you too far behind the power curve. You’re going to know there’s a problem after it has occurred. So fool me once, shame on you, fool me twice, shame on me. So if the bad guys are stealing your data and you’re just trying to react after the fact, I think that you’re on the wrong side of the issue.

 

Sanjog Aul [00:44:20]:

So what you just mentioned is one school of thought, and I’m bringing you back to that school of thought where they say they tried staying proactive and spend a lot of their energy into being proactive, but it’s still because things like APT start much earlier in a much more stealth manner than you and I or our team could envision. So we invariably end up seeing one or the other incident happening, one or the other holes getting created. So if we put most of our energies there, maybe our response ability to respond slacks because there are limited resources. You got limited number of people. So what’s that balance then? So if you say you’re gonna be proactive, would you be 100% proactive and not put that much attention to reactive? And if yes, then what is that mix?

 

Adam Rice [00:45:15]:

So, again, it comes back to what does your organization do. What is your compliance burden? What’s your regulatory burden? And what’s your threats? In the industry that I work in, we don’t want any APT in the house, and we focus a lot of our resources at preventing that, and it takes skills and tools that an organization typically would not invest in, and some of the tools are quite expensive, but in the case of the aerospace and defense industry, it is typical to take that approach because we understand what our threats are and what our regulatory burden is. Now on the other side of the spectrum, if you don’t have anything that is worth that kind of protection and if you look in the mirror and you say to yourself, well, who cares if they take it really, who cares, then probably it’s not a good business decision to spend the money on trying to get in front of an advanced threat and be more reactive. It’s a business decision really.

 

Sanjog Aul [00:46:25]:

Let’s take a quick break, listeners. We’ll be right back and come back to the actual skill and competency and management, management skill development that is required for the security team members to be able to do the job. So the process is only limited to collaboration among the peer group or there is some way to start grooming them with the right mindset, which will allow them to effectively serve the purpose for which they were even hired in the first place. Please stay tuned, listeners. We’ll be right back.

 

Bosch Software Innovations [00:47:08]:

Bosch Software Innovations is proud to sponsor this program. Visit www.bosch-si.com/connectedmanufacturing to find out how Bosch can help you improve your operational performance and become a manufacturing industry leader in a connected world. Change the way you predict, manage, and produce outcomes. Bosch Connected Manufacturing.

 

HP [00:47:40]:

HP is proud to sponsor this program. Tap into our expertise, innovation, and services to bring your most important workloads to the cloud. HP is proud to sponsor this program. Find out how the HP as a service solution for SAP HANA can help you gain instant impactful business results without capital investment by logging on to hp.com. Transform information into intelligence and a competitive advantage with a full spectrum of SAP HANA products and services from HP, a global SAP hosting partner. You are listening to CIO Talk Radio with Sanjog Aul. To learn more about the show, please visit www.ciotalkradio.com. If you have a question or comment, call toll free at +1 (866) 472-5790. That number again is +1 (866) 472-5790. Now back to the show. Here’s Sanjog Aul.

 

Sanjog Aul [00:48:55]:

Welcome back. So, Adam, in any organization when you try to develop, you want to have the appropriate quality, quantity, and cost attached to the workforce in such a balanced way so that it most effectively meets the business objectives, and that is very true for whether it’s a regular IT team or a security team. Is there some sort of a mapping done between the risks that are outlined by the business and of course you as a leader? And then there is a mapping done for workforce or is it rather a fluid calculation?

 

Adam Rice [00:49:36]:

Well, I think that it’s a little of both. I think that when a strategy is formulated to stop the APT and the advanced threat that will come with an organizational structure that is considered effective, and out of that will come a budget, your operational charge, your headcount and then tools and maintenance and so on, and that budget needs to be negotiated against the business with the CISO as the expert saying that no, if we want to accomplish the task, we really need to have this kind of organization, that organization cost that, and then once the organization is established and running year to year, then obviously you have your budget challenges like anywhere else where there is an expectation that you’ll grow your OpEx by a certain percentage or keep it flat or your CapEx at a certain percentage, and then you have to come in and just like all managers negotiate your budget to be as effective as you can be. Now if there is a new threat or a new issue comes over the horizon that is extraordinary then you would have to go up to your management and be able to describe what the issue was, and then if the fix cost money or people or tools be able to articulate that, convince them that it was important and needed, and then move from there.

 

Sanjog Aul [00:51:09]:

Is there a current ability for CISO and their teams to recognize specific connection between what the current state is and to what degree are they meeting the needs and then how the changes are happening and correspondingly what changes we’ll have to bring about in terms of, again, quantity and quality of skills and competencies within the team to meet the business objectives.

 

Adam Rice [00:51:34]:

Right. So I think that that speaks to being able to put key success indicators or key indicators of success on the table as part of your business statement that you will have no APTs, you will do this, you will do that and you will do this, and it has to be something that you can look back at and compare your performance against, and then within the organization, security is a kind of an odd one. Many organizations have a deeply matrix structure when it comes to security. Many of the network based tasks for security could be done by the network team with a dotted line back up to a security organization that is lighter in technical skills. Those skills could be outsourced or in some cases those skills could be kept within an autonomous security organization. It’s different everywhere, but I think that whatever the way that it is done, there has to be a lot of deliberate analysis done that you have the skills and the structure to meet what you are trying to protect against and not the other way around, if that makes sense.

 

Sanjog Aul [00:52:52]:

What kind of culture what are the tenets of a culture which will allow a security team to thrive and effectively meet the security needs which are already heavily demanding plus they are getting worse?

 

Adam Rice [00:53:07]:

I think that the most important thing organizationally or culturally is that the security team has got to be trusted by the leadership, that they are doing a job that is important to the organization, and that job unfortunately also creates a certain degree of inconvenience for the employees of that organization. Inevitably, there is some of that, but if senior management at the CEO, Board and CIO level recognize that what the security team is doing is critical in this day and age and provides that air cover for the team, within a very short time, it’s understood throughout the organization that the IT security team is not negotiating. They are there as an arbitrator of policy, and that if you don’t like the policy, there is always a way to get an exception, but the rule is that you do not violate the security policy.

 

Sanjog Aul [00:54:18]:

What’s the subculture that you recommend should exist within security? Because while you would like to have an organizational culture support security as a function, what culture would you like to see exist within that security team so that they make everyone proud?

 

Adam Rice [00:54:33]:

So I try to get away from being the team of contrarians, right, the team that just says no, the team where people are frustrated with dealing with where the security team is just the group of contrarians. I think that by leaning on policy and having your team be sensitive to business issues and making sure that they realize the reason why we have our jobs is to support business success and that our policies can’t describe every contingency all the time and that there is always an exception to policy as long as the risk is understood and accepted at the appropriate level within the organization. So the subculture would be to have some business acumen and respect the business.

 

Sanjog Aul [00:55:21]:

One final question for you. When you look in the mirror as a security leader, what do you think at all times you should have at top of your mind and which areas do you think you have to continually evolve as a leader to shoulder this huge responsibility?

 

Adam Rice [00:55:38]:

So the thing that keeps me awake at night is the advanced threat. They are the proverbial boogeyman. What I really judge my success on is stopping the unauthorized exfiltration of data from our network, and really that is where everything else revolves around that cornerstone. So the thing that I always try to tell my team is that every decision that we make and everything that we do has to be within one or two degrees of separation from that goal. Right? That is why we are here to stop the unauthorized exfiltration of data.

 

Sanjog Aul [00:56:18]:

On behalf of the show and our listeners, I’d really like to thank you, Adam, for sharing your thoughts on how to build an effective IT security team, and, listeners, please like us on Facebook, search for CIO Talk Radio, and be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.

 

 

Contributors

Adam Rice

Adam Rice, CISO, ATK

Adam Rice is the Chief Information Security Officer for ATK Adam Rice has 17 years of established experience in information technologies and information security. Adam is responsible for establishing the information security strategy a... More   View all posts
Add Comment
Click here to post a comment

Advertisement

MTECH - MSUMMARY - MPU - 02 -300x250
Adam Rice