Cybersecurity Culture Governance Leadership

Steps To Making Security Forethought

Steps To Making Security Forethought

CXOs are getting fired. Companies are losing credibility and billions in revenue. But many CISOs still have a hard time making security forethought in their organizations. How can CISOs get everyone to embrace security as a forethought for the benefit of all involved?
Contributors

    • Bharat Soni, Chief Information Security Officer (CISO) and Group Head Information Security Group, Guaranty Trust Bank (GTBank).
    • Robert Jamieson, Chief Information Security Officer, Mallinckrodt Pharmaceutics.

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

Transcript

Sanjog Aul [00:00:22]:

Hello, and welcome to this segment on CTN, and to learn more, please visit ciotalknetwork.com, and the topic for today is Steps To Making Security Forethought, and our guests are Bharat Soni, who’s the chief information security officer with Guaranty Trust Bank. Hey, Bharat. How are you?

 

Bharat Soni [00:00:39]:

I’m fine, Sanjog Aul. How are you? Good afternoon.

 

Sanjog Aul [00:00:41]:

Good afternoon to you. Good morning to you. I’m from Chicago. You’re from Nigeria.

 

Bharat Soni [00:00:44]:

So that’s one of your friends. Yes.

 

Sanjog Aul [00:00:47]:

So life is good.

 

Bharat Soni [00:00:48]:

Good morning.

 

Sanjog Aul [00:00:50]:

Alright. Great, and we also have Robert Jamieson, who’s the chief information officer and chief information security officer with Belling Crowd Pharmaceutics. Hi, Robert. How are you?

 

Robert Jamieson [00:01:00]:

Good morning to you. I’m over on the East Coast.

 

Sanjog Aul [00:01:03]:

Alright. So we got the three different time zones talking here, which is awesome, and, the topic the reason we picked it up, it actually stems from this challenge, a constant challenge that I hear from top security leaders from around the globe that while it’s important, there are some situations we have all seen and heard in media about people losing jobs because there were some breaches or revenue was lost or credibility was lost, but at the same time, there is an internal battle for the security leaders to be able to make a case for everyone to think about security as a forethought. We wanted to see why is this happening, why is this still a chronic issue, and what is possible for us to turn this problem into something which is a thing of the past and we don’t have to worry about it. So that said, Bharat, I’ll start with you. We know that, we have this challenge, but what is the current perception and the perceived importance of security in the minds of business stakeholders and users?

 

Bharat Soni [00:02:16]:

Yeah. So, I would say that I was expecting this question, but not so quick. So I will start with the thought process that what happens, Sanjog Aul, these days, as technology evolves, the evolvement of technology also comes with challenges, and it provides opportunities to do more business around it. Business nowadays are technology-driven businesses. They want quick and agile solutions. So in that business, I believe more or less the business users think that we want the solution because that’s a target attached to it, the business target or the revenue generation. Now the perception about security, I believe, was lagging behind. I will not say in my own scenario, but a few years back what I faced is the perception of security was not in the front row. Now the mindset of the business users is shifting that security is not protecting companies or the organization just from risk. Security is also being considered as a source of new competitive advantage. I will give you my own example. I’m from a financial sector. I’m from a bank. So in my bank, GT Bank, security is taken very seriously from top to bottom, and I will say that it’s not something which comes overnight into the business user’s mind. It’s a process which we have gone through, everyone has gone through. Because if, for example, in the financial sector, if there is a breach or there is a financial fraud, it’s not only the loss of money, it comes with branding risk, it comes with losing our customers. On top of it, there will be some regulatory risk around it. So, for me, the business mindset is changing around security, but the old saying that security is not my responsibility is changing to that security is everyone’s responsibility, and it covers the whole aspect of the business, business people at all. When I say this, I’ll give one example of my own self that this is not just talk. When I started my journey with GT Bank five years back, we started the journey around getting awareness, getting security, how it can be imbibed into the business and the culture. Sooner or later, I started seeing the impact of this. Just for example, one of my senior management guys received a spoofed or a phishing email stating that I’m the MD of the company and kindly initiate the transaction. This was unusual behavior, but that transaction created a lot of opportunity for the business. However, being an unusual behavior of the email, he immediately alerted and triggered. So coming from the point that the mindset of the business stakeholders is changing, it’s what you consider — an organization is as strong or powerful as its weakest person. For example, just one single compromise in the bank can compromise the whole network and increase the fraud. So there should be, for me, the business stakeholders’ mindset has been changing because of the current business requirement that demands. We need to have a good handshake between the business and the customer convenience. Business needs customer convenience, and on top of it, we as security experts need to provide proper security. Everywhere you see, that’s the one-click solution kind of thing, but is it secure? So that’s a win-win situation if that’s been established.

 

Sanjog Aul [00:06:29]:

So, Robert, based on Bharat’s response, he definitely mentions a couple of good points of how someone at the business level should be staying alert or how the security leaders should keep pushing the agenda of making security a priority, but we’ve been at it for a little bit, right? I mean, we have been trying it, but we are not making the type of dent we expected. Is the tactic missing? Is the finesse of how the messages are created missing? Where are we missing the boat because we are not able to really reach a desired level? And for that matter, I’d love for you to give your benchmark of what you would say is the right level of importance, which is which you can somehow measure, and if you reach that level, you’ll be happy.

 

Robert Jamieson [00:07:19]:

So I’d like to build on the last comments. I think the current perception is that cybersecurity is a technical problem and that we just throw some technical solutions at it and we’ll take care of it. There’s not the understanding that fundamentally cybersecurity is not a technical problem, it’s a strategic problem. As we have morphed into more of a digital business, and that was just brought out in the last comment, cybersecurity is front and center, and that shift has happened in a very short period of time so it’s not forefront in people’s consciousness. The reason it’s not forefront in people’s consciousness is for the most part, most people on planet Earth don’t understand digital. So there’s just a basic lack of understanding of what’s happening in our world and how it’s happening. My thought here is to get it in the forefront of business stakeholders, you have to change how they think about you and you have to do that by talking in their terminology. So the shift is really upon us and we as cybersecurity professionals tend to be far more technical in our discussions with the boards and with our senior executives than we should be. We should be talking about the strategic objectives they have and how we support, not just support those strategic objectives, but actually enable those strategic objectives, which gets into the measurement piece. When you think about measurement, we have measurements that we use internally, but we’ve got to translate those measurements into things that make sense from a business standpoint, which usually is either top line or bottom line, profitability or efficiencies. It’s got to be in terminology they can understand. So digitization means X to a business person. Digital innovation means Y to a business person. We have to be able to speak that language and say, look, our cybersecurity program, our strategy, not only eliminates risk for you, but it allows you to innovate. It allows you to digitize. It allows you to save money on the bottom line, and it allows you, as you do innovation, to get new monies on the top line that you never saw before, but we’re able to do it in a secure fashion where we’re not going to be attacked and lose that competitive advantage. So this enables us to do something that maybe nobody else has ever done before, but do it in a way that we’re structured so that we’re not going to lose that ability as attackers try to look at our weaknesses. From a measurement standpoint, the measurements I use with our senior executives and the board are all about our maturity, how well we’re controlling the risk and what the risks mean, and then measuring how we’re contributing to the overall organization through either bottom line or top line improvement. How we’re adding contribution actually significantly changes both the perception by the senior leadership and the board and makes it a perception that stays in place. It changes the conversation so they welcome your presence and they welcome your contribution to the organization.

 

Sanjog Aul [00:10:59]:

So what you mentioned, Robert, is you go ahead and change the verbiage, if you will, the vocabulary you’re using to talk to the business, and taking that as a baseline, Bharat, I would like to ask you, when you were talking, yes, you can claim that, yes, we will be able to use simpler language to explain how security is important, but if I sit in CEO shoes or anyone who is on the revenue side or business side, they may only see security as something which is slowing them down. How do you get someone over that? Because they want to drive a Ferrari, and you’re trying to apply brakes. Nobody likes that.

 

Robert Jamieson [00:11:46]:

Yes. That’s true, but again it gets into how we say things. Typically, cybersecurity is the office of the no. The shift is we have to be the office of yes and here’s how. When our CEO is looking for digital innovation, he’s looking for it quick. The shift with him is don’t select the solution. Let us be engaged in the solution set. You tell us what the requirements are. You tell us where you want to go. You tell us how fast you want to go. You tell us the things you want to accomplish. We’ll work on those details. So instead of having the CEO say, hey, I want you to get the AWS xyz solution or I want you to do something similar in a particular SaaS application, change the dialogue to say, what do you want to accomplish? And oh, by the way, I’m the guy, and the CIO, the combination of us, we’re the people who can accomplish that for you, but accomplish it in a way that minimizes your risk, maximizes the protection of your intellectual property, maximizes your competitive advantage. That allows them to drive the Ferrari, but they drive the Ferrari that’s got our safety features embedded inside it.

 

Sanjog Aul [00:13:16]:

yeah. Bharat, go ahead.

 

Bharat Soni [00:13:17]:

Just to add what Robert mentioned here is this is a tough question. When business wants, as you mentioned, to drive a Ferrari, and you want to apply the brakes, it should be a win-win situation for both. That’s the threshold on which you will apply the brakes. Now, let me give you the same: when we talk business, we talk in numbers. From a risk perspective or a security expert, if the business wants to continue an initiative which can generate revenue of, for example, $1,000,000, if we are not looking into this risk, the loss can be $1,000,000 or until the time we actually realize there is a loss or fraud happening. The scenarios with me and Robert may be different because I’m in the financial sector. So my losses can be calculated quickly. Now when I speak to business, the efforts are always in talking the same language. I will talk in numbers that these are the probable causes which should be realized and remediated now. Otherwise, we’ll see a bitter taste of driving the Ferrari at the end of the road. For example, if I say implement a data leakage prevention solution, from a security perspective I will say we need to implement it, and this is the cost. The business will talk in numbers. Based on past experience or current global practices, for example, if there is a data leakage fraud somewhere in the world, when I assess it, I will say that the typical cost of preventing it post facto will be somewhere in the range of $10 to maybe $90. That conversation starting from that particular point will eventually end up in some better solution for the organization. That’s what I would tell you, sir.

 

Sanjog Aul [00:15:49]:

So let’s take a quick break. Listen, we’ll be right back, and let’s talk about the language we will use. So, you both gave some example, but should we always front end with the possible losses that you may incur and that’s what you’re telling to your business if you don’t heed our advice and you don’t think about security or should we be talking about the possibility of generating revenue which you may or may not be able to impact as working in security, but at the same time, you don’t want to come across as the messenger of doom every time you talk. How do you prevent being seen as someone who’s going to be a messenger of doom so that they cringe even talking to you? And you create a positive spin, which essentially will make you their best friend, and that’s when they will start listening. Please stay tuned listeners. We’ll be right back and explore, and this question, please, Robert, you take it when we come back.

 

Speaker 0 [00:16:55]:

Predict your company’s future by creating it. Is your workforce able to connect, exchange ideas, and share brilliance simply and securely? Create tomorrow, today. Empower your people to innovate anytime and anywhere with secured BlackBerry Enterprise Mobility Management and document sharing solutions. To learn more, visit blackberry.com/enterprise.

 

Speaker 0 [00:17:23]:

Patient centered care requires a connected enterprise. Are you ready? If you’re looking to scale your health care IT efforts, visit Redmane.com/health today. Whether it’s to connect data from multiple partner solutions or developing software for unique needs, Redmane can help. To find out how Redmane can help your company deliver on the patient centered care promise, visit Redmane.com/help or call (773) 693-3919. Visit today.

 

Speaker 0 [00:17:56]:

Your growing business needs a highly productive workforce, effectively communicating and collaborating without exposing corporate data to cyber attacks. Are you looking to balance security and workforce productivity? Move beyond short term measures and securely scale your business with BlackBerry Enterprise Mobility Management Solutions. To learn more, please visit blackberry.com/enterprise. You are listening to CTN, CIO Talk Network with Sanjog Aul. To learn more about our program, please visit ciotalknetwork.com. Now back to the show.

 

Sanjog Aul [00:18:45]:

Welcome back. So, Robert, we don’t want CISOs to come across as the messengers of doom. What’s the other way of handling this?

 

Robert Jamieson [00:18:54]:

Well, you know, before I launch into that, just on that last conversation that we had where we were talking about Ferraris and braking. The reason brakes were invented was to make cars go faster. I talk about that sometimes when people say, hey, you’re putting a brake on this or you’re slowing things down. It’s really to enable people to go far faster. There’s a thing about FUD and we call it fear, uncertainty and doubt. FUD initially was used by our industry extensively. It’s still being used as a sales technique for the sky is falling. We’ve just recently had a related area which is GDPR with Europe where the sky is falling. May 25 is coming up. Are you prepared? Fines will be heavy and so on. There’s a lot of that FUD associated with it. I think that’s counter to trying to get a message across and engage with people. Eventually, people really don’t want to talk to you if you’re always about fear and you’re adding uncertainty and doubt. To me, it’s about flipping the conversation. It’s about saying we can cause you to succeed. We can cause you to not have the problems that you see in the outside world. You have a ransomware problem, that’s alarming. You’re hearing about it in the news. Our focus is to minimize that to the greatest extent possible. If it does happen, to attack it very quickly and resolve it very quickly, but that’s just what’s happening in the outside world. The big picture is about establishing a system that has a strategy behind it. Instead of just thinking about one-offs and the symptoms of cybersecurity, think about the root causes. Phishing email isn’t the problem really; it’s email and the control of email. If you look at the problem statement appropriately, you can say here’s how we can enable the use of email inside our organization and significantly minimize the downside of attacks from the outside. Here’s how we can address that problem, and oh, by the way, this is how we can do it and add value to our corporation. Our ecosystems as we evolve are consistently looking for partners to be more mature from a cyber standpoint. If you’re doing business with other businesses, they’re looking for that maturity. We’re seeing push for the entire world to become more mature in this space. As you become more mature, you become more valuable to your partner and to the community at large. So shift our conversations from yes, there are bad things out there, to here’s what we need to do about it, be proactive, and then shift to here’s how we can actually create greater value. Cybersecurity has always been very isolated. It needs to be far more broad. It has to be part of service management, asset management, controls, audit, all the different processes in the organization. Doing that, you can start adding tangible value to the product you have out there. Make that shift in the conversation and say, here’s some digitization we can do in a secure fashion which eliminates a significant amount of risk we have today from papers floating around or from people having things in their wallets or briefcases. We’ve eliminated a significant amount of risk. We put in multi-factor authentication so somebody from the outside can’t hack into it. We’ve increased security and eliminated 30% of waste in the organization. That 30% can be reapplied to top line growth. Looking ahead, in 6 years we’re going to have artificial intelligence. Right now we’re 32nd of the way there but it’s Moore’s Law, every year we’re doubling capability. In 6 years most people’s expectations are we’ll have artificial intelligence. If we start building our systems to that future 6-year mark, but understand that today they’re not there, then the innovation we could reach will put us far ahead of competitors with secure, smart machines that are not hackable or a liability. That conversation means our organization can be far ahead of our competitors. Think the long game and talk about the long game with executive leadership and the board so you’re looking at winning ahead of competitors while avoiding being damaged.

 

Sanjog Aul [00:25:22]:

So, Bharat, based on Robert’s response to this question, what do you think that we should try to make security a forethought in the first place? That’s the ideal, right? Where everyone in the business is thinking, oh, yeah, I gotta see what security is thinking. Is there a happy medium, or are we going to keep chasing something we would never achieve?

 

Bharat Soni [00:25:48]:

Okay. So to start with, these days connectivity and digitization are growing faster than information security. You will see initiative before you come with security solutions. The assets that in old days were physically protected are now accessible online. Cloud, emails, HR solutions are online, and those channels are vulnerable to disruption, and hackers are finding new opportunities. For example, with the cloud, the bomb of the cloud, hackers focus highly on the cloud environment because that’s a single source of more information. So when you look into security aspects, leadership or management needs to be aligned with this thought process. What we are speaking should be their primary line of thought because business is going there. From a security-forethought perspective, the information security department still struggles to maintain relationship with the board and senior management team. The links need to build and maintain trust relationships not only with the board and senior management but across the organization. If they are not maintaining it, it’s virtually meaningless. Security should be in the culture and in the blood of everyone in the organization. Bring security to life and make it an integral part of the company’s business practice. It’s not an overnight effort; it requires much more. When I look into my environment, I look at what Robert mentioned: new standards, frameworks, and regulations like GDPR. In old days information security was only about CIA — confidentiality, integrity, and availability. My thought process is we need to change that. The first thought should be around data and about data usability. If we define usability of data and concentrate CIA around that and make management and users aware, that is what needs to be looked at. If I’m not an authorized or authenticated user of data, I should not access it. Security is not one directional or purely top-down or bottom-up. CIO’s role nowadays is no more just securing the business. It’s becoming more strategic. The CIO role requires pivoting the conversation in mindset and language from business perspective to security and compliance and change it to risk strategy and management angle. Rather than using scary techniques to make it happen, we need to boost understanding of risk in terms of potential effect, competitive advantage. Use competitive advantage to take risk and grow revenue. That is easily understandable by business leaders and then becomes culture in the organization.

 

Sanjog Aul [00:30:26]:

Let’s take a quick break, listeners. When we come back, let’s talk about the staff, the other people who are not the leaders because what we are seeing is while the business leaders at the top may be more mature, they may understand revenue and growth and also potential loss, but when you come to middle management or the staff, frankly, they are a little removed from both of those areas. They’re the ones who end up adopting or ignoring security in the way they function, and when an individual person who is supposed to create data or be a custodian of their own data doesn’t really have any incentive to put that special effort to support security and make that a forethought, then it is actually a bigger problem than dealing with business leaders. How do we deal with it? We’ll discuss more. Please stay tuned listeners. We’ll be right back.

 

Speaker 0 [00:31:35]:

Your growing business needs a highly productive workforce, effectively communicating and collaborating without exposing corporate data to cyber attacks. Are you looking to balance security and workforce productivity? Move beyond short term measures and securely scale with BlackBerry Enterprise Mobility Management solutions. To learn more, please visit blackberry.com/enterprise.

 

Speaker 0 [00:32:06]:

Patient centered care requires a connected enterprise. Are you ready? If you’re looking to scale your health care IT efforts, visit Redmane.com/health today. Whether it’s to connect data from multiple partner solutions or developing software for unique needs, Redmane can help. To find out how Redmane can help your company deliver on the patient centered care promise, visit Redmane.com/help or call (773) 693-3919. Visit today.

 

Speaker 0 [00:32:38]:

Predict your company’s future by creating it. Is your workforce able to connect, exchange ideas, and share brilliance simply and securely? Create tomorrow, today. Empower your people to innovate anytime and anywhere with secured BlackBerry Enterprise Mobility Management and Document Sharing Solutions. To learn more, visit blackberry.com/enterprise. You are listening to CTN CIO Talk Network with Sanjog Aul. Now back to the show.

 

Sanjog Aul [00:33:19]:

Welcome back. So, Robert, business leaders could be spoken with. They would understand perhaps the growth and the losses and they may mend their behavior and maybe come on board, but most of the time when we have tried to get adoption going, we have seen the middle management and the staff who truly don’t have any incentive or they are not paid to think security. Their performance evaluation is not based on how securely they behaved, how much ownership they kept of their data, and what they do every day. How do you tackle that problem? Because that has been pulling us down for years.

 

Robert Jamieson [00:34:00]:

Yeah. So in my last 2 shops over the last 6–7 years, we’ve really focused in on that piece. In fact, in my last shop, we called it people-centric security. What we discovered is people like to be engaged with. The CISO sending out notes on a frequent basis translating what’s going on in the big world of cybersecurity and here’s what it means to you and here’s how you can be safer — there’s a personal piece, but the secret we found was we always follow those communications with a test. We’ll send out a phishing email or something like a phishing email as a test. The important part is if people respond, they have two responses: one is to forward the phishing email to the security operations center we operate, or if they click on the email, they get a response saying, hey, you’ve been phished, here’s how you could have detected that phishing email. If they forward it, we do a congratulatory note. More importantly, if people detect a phishing email or an anomaly and report that beyond the test, we congratulate them. I send an email congratulating them and I send a copy to their boss’s boss and a copy to the CEO. That usually generates another congratulatory message from either the CEO or their boss’s boss, which causes people to feel good. Engagement is the critical element when you think about getting the rank and file with really no other incentives. Engage with them, get them to respond, and have a conversation about how they can help improve security of the overall organization.

 

Sanjog Aul [00:36:20]:

So, Bharat, in your organization, given that it’s financial services, I assume the individual users who are handling data could be at a totally different level of sensitivity and that has to be protected far more.

 

Bharat Soni [00:36:35]:

So you’re right.

 

Sanjog Aul [00:36:36]:

So what is it that you’ve been able to do to incentivize an individual business user to take ownership and remain a custodian of the data and information that they manage?

 

Bharat Soni [00:36:50]:

Okay. It’s a broad question, Sanjog, and I will cover a few of the points Robert mentioned. First, humans are complex. We have our own agenda, influences, beliefs, priorities, and it depends on the environment where we are working. Sometimes we trust too much; sometimes we don’t trust anyone. One point Robert mentioned is personalization; people should have a personalized touch because they are the weakest link in any organization. Technically you can do anything and harden systems, but one single person behind that hardened infrastructure is the weakest link. For example, a phishing compromise can lead to disaster. In our environment, we use a full year plan focused on awareness. We carry awareness on a monthly basis. To measure awareness effectiveness, we carry out a quarterly social engineering test. In the quarterly social engineering test we send phishing emails to targeted staff. We record who has clicked, who has opened, who has submitted passwords, and then to ensure it does not repeat we sometimes take stringent controls like publishing compromised staff names on the organizational intranet. When people see that, two messages come out: one, be careful about information security duties and know whom to contact if you have doubts about an email. Apart from security applications, if people know where to contact, it resolves half the problem. In my experience this yields very good results. Apart from this, we have an annual information security week in which we send questionnaires to staff and put scenario-based questions with no objective answer; staff must respond in detail explaining how they would apply it. Names of defaults are published and winners are celebrated with management-approved gifts and pictures. It’s a two-way seesaw: sometimes staff are seen as stumbling blocks, other times security isn’t taken seriously. We build initiatives that involve security as important as your business role. These things go hand in hand when we talk about awareness.

 

Sanjog Aul [00:41:05]:

Robert, if you look at your own journey, I’m sure it’s not been all successes. Are there any learnings in the process of making security forethought? Are there areas that are chronic and you’re still struggling with in the journey?

 

Robert Jamieson [00:41:22]:

Yeah. I was thinking about this in context to the last comment. Early in my career I attended a Gartner conference. One of the executives, Andrew Walls, talked about phishing education. He said you have 3 reasons to do cybersecurity education: compliance, punitive, or for behavioral modification. Early in my journey we were more compliance-oriented when engaging people. He said if telling people to do the right thing worked, there would be no prisons. It’s not just telling people; it’s about behavioral modification. One learning I had: we had a significant cybersecurity issue caused by human error. I learned you have to modify behavior because most people don’t understand digital change; their behavior is based on an analogue world versus a digital world. You have to help them along the way, engage with them, and be in a space where they feel comfortable telling you they did something wrong so you can quickly fix it. My mistake was starting with a compliance-driven program and not leaving room for people to be engaged if they did something wrong, so they tried to hide it, which caused a significant external attack. We pivoted and it worked. Now if somebody does something wrong they feel comfortable that there will be nothing punitive and they report it, which allows our security operations to quickly isolate the machine or problem and minimize damage. Another learning was how I communicate to senior executives. Fundamentally I’m a geek like all cybersecurity people. I learned to change my conversation to be non-geek. My conversations internally with my team are geeky, but externally from the CIO on up it’s about the business: how we help the business grow and succeed and address external issues hampering the business. My first board conversation was a flop, but I learned and now I talk in metrics understandable by the board and they desire those conversations because they can ask about things, feel free, comfortable, and safe to ask about things they don’t understand.

 

Sanjog Aul [00:45:24]:

Bharat, Robert mentioned behavior change, which is important. The question is, do you have to keep hammering the people you want to change or once you change behavior is it permanent? Is your job ever done for those people?

 

Bharat Soni [00:45:51]:

I disagree with the notion that the job is done. The job is never done. It’s a continuous process, a continuous journey. When I started my career in information security there were many failures. As Robert mentioned, you cannot do things perfectly at first. Learning comes daily from users and leadership. As a CISO, it’s virtually impossible to protect every piece of data in any organization. What a leader can do is work with the business to understand what data is critical to the enterprise, where it resides, and the impact if that data is compromised or lost so both business and security speak the same language. That’s one learning. Another is creating security as a strategic, integrated part of the business. In my organization, when a business initiative is carried out, information security is one of the stakeholders from the start. Typical advice or recommendations for risk are provided early so business aligns because we are a partner in the continuous process rather than acting at the end. Behavior will change with this partnering initiative and it’s ongoing. Also, staff turnover means new people come in; that’s when you must pitch security to the new hires so they align with organizational culture where security is imbibed in the blood of the organization. The job continues.

 

Sanjog Aul [00:48:48]:

Robert, one last question: if you had a playbook to develop a culture of security and strive to make it a forethought, could you make it sustainable so it’s not dependent on you? How would you do it so it’s a legacy and continues even though you’ve left, versus every new leader changing direction?

 

Robert Jamieson [00:49:34]:

Yes. The key is structure. I did a presentation in London 2 weeks ago and it’s about having a strategy that informs people, process, procedures and documentation necessary to carry out that strategy, and then a technology component. I think technology is the last component. Think of this from a behavioral science standpoint more than a technological standpoint. Have the people, processes, documentation, procedures, policy documentation, get that framework in place with people responsible for each element, and then a strong change management program. Change management is the hardest part: change the mindset of your cybersecurity team from firefighter to proactive. Institutionalize the new paradigm and create that legacy so it survives after you leave, and the next person can assess, improve, and have a structure that creates security as forethought for business leaders, rank and file, and the cybersecurity unit.

 

Bharat Soni [00:51:43]:

Yeah. Sanjog, Bharat here. I totally agree with Robert. People and processes are the key which should be fixed first. First things first: have the culture in place. Processes will define culture because people will follow a process. If the process is modified such that information security or cybersecurity has high importance at every level, then it will work. In my case, security process starts from the point staff join the bank. From there, there are regular trainings and awareness sessions. This does not only apply to staff; we also coach lower level staff like cleaners and service staff on how to behave with information security practices. To continue this culture, processes must evolve. As Robert mentioned, someone will take over from a baseline and there may be modifications or more robust implementations, but there is at least a baseline for how security is to be taken care of in the organization whether you are there or not. That’s how organizational culture must be modified.

 

Sanjog Aul [00:53:36]:

On behalf of the show and our listeners, thanks so much, Bharat and Robert, for sharing your views on how organizations can start rethinking, take a step back, and look at how security is viewed in the organization, work with the business leaders, and also the staff members to make sure that it becomes a forethought. Thanks so much again, folks.

 

Bharat Soni [00:53:54]:

Thank you, Sanjog Aul. Thank you, Robert.

 

Robert Jamieson [00:53:56]:

Thank you. Thank you, guys. Appreciate it.

 

Sanjog Aul [00:53:59]:

Hope you enjoyed listeners. Please like us on Facebook. Search for CTN CIO Talk Network and be sure to follow us on Twitter and LinkedIn. I’d love for you to listen to us and follow us on iTunes, TuneIn, Spotify, iHeart. There are a number of places where you can download the podcast, and please rate us so that more people learn about us and benefit. Thank you again for listening to the segment on CTN. This is Sanjog Aul, your talk show host. Till next week, take care and God bless.

Contributors

Bharat Soni

Bharat Soni, Chief Information Security Officer (CISO) and Group Head Information Security Group, Guaranty Trust Bank (GTBank)

Result oriented seasoned Information, Cyber Security and Risk Management professional with experience of over 21 year in this domain. Strong acumen in implementation of Governance, Risk and Compliance in complex environments. Adept at creat... More   View all posts
Robert Jamieson

Robert Jamieson, Chief Information Security Officer, Mallinckrodt Pharmaceutics

Dr. Robert (Bob) Jamieson is currently the Chief Information Security Officer for Mallinckrodt Pharmaceutics and is responsible for leading a global effort to provide a secure information/digital environment for Mallinckrodt’s clients and... More   View all posts
Add Comment
Click here to post a comment

Advertisement

PRESISTENT - CONSUMERTECH - MPU - 01 - 300x250
Bharat Soni