Cybersecurity Governance

Steps to Outcome-Driven Security

Organizations want their security investments to achieve intended results and drive significant positive ROI like any business function. For such clarity, how much security organizations need and how much they should pay must be calculated based on operations and technology costs, risks mitigated, and benefits realized. Also, explicit metrics must drive security effort evaluation, performance, and the required adjustments. So how can we move to such outcome-driven security?

Contributor

    • Bharat Soni, Chief Information Security Officer (CISO) and Group Head Information Security Group, Guaranty Trust Bank (GTBank)

Download Podcast
Apple PodcastGoogle PodcastSpotifyiHeartRadioSoundCloudTuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

Transcript 

Sanjog Aul [00:00:00]:
Hello and welcome to CTN, and to learn more about the show, please visit ciotalknetwork.com and the topic for today is Steps To Outcome Driven Security. What do I mean by that? So if you look at security investment that any organization is looking to make or is making, they want to achieve certain results and of course some ROI of positive ROI like it would do from any other business function, but typically that is not how we run security, and if you really wanted to go ahead and make it like a business function where you’re looking for clear ROI, you definitely have to have a way by which you totally understand what is it that it is supposed to be delivering to the business. What are the benefits and the risks and the cost and do you do your math to eventually show that positive result? But do we have such metrics, such explicit way of calculating what is the investment in security, how you to evaluate what is the current way you’re running security, the performance metric, and if you have to do the required adjustments, do you have the calibration approach to do so? If you had to go that route, what would it take for us to deliver an outcome driven security? That’s what we were here to discuss, and I have with me Bharat Soni, he’s the Chief Information Security Officer with Guarantee Trust Bank.

Sanjog Aul [00:01:39]:
Hey Bharat, how are you?

Bharat Soni [00:01:41]:
Hi Sanjog. I’m fine. How are you doing?

Sanjog Aul [00:01:43]:
Very good sir. Thank you so much for joining.

Sanjog Aul [00:01:46]:
So let’s. And so we know that business and technology landscape is changing quite a bit. If you were to assess based on what you’ve seen happening in your organization and many of your other industries and or other peers that you have, which areas within a business is becoming easy for you to measure. How security is performing and where is security or handling or managing security for business is becoming easier and where are they becoming complex? What’s the lay of the land right now?

Bharat Soni [00:02:25]:
Okay, so I will start with like really appreciate that this is the point

Bharat Soni [00:02:31]:
to is these kind of questions and

Bharat Soni [00:02:34]:
to have everybody having their thought process around this because the topic is very apt for the times. What we are into now business, what we have seen like I will not say that the rapid changes in terms of business what we have seen for last two years are like I’ve taken the businesses to rethink into their strategies, the way they are functioning to just tenure ahead of the time frame. This pandemic, when we always hear that pandemic is driving the, what you call technology towards the organization of the digitization is being driven by the technology pandemic. This it’s very apt because ultimately the businesses have to adopt to the new changes. Now when we talk about security and things, technology is changing every day. Same way with the change in technology, the security and the thought process around security is also changing. Let me, let me try to further explain this thing. When we see how we were communicating earlier and how we were sharing the information earlier, like three years back, four years back and let’s see where we are now.

Bharat Soni [00:03:51]:
Typically we have seen how mobile applications are being adopted. The rate they have been adopted. Every business you take, they’re going through mobile app. The way the information has been shared. Everyone is on social media, all channels. Business are tapping the channel of digitization.

Bharat Soni [00:04:07]:
Like anything, the faster it has been

Bharat Soni [00:04:10]:
adopted, the more the opportunities will be there. Enabling of remote working the way it’s been changing. Use of artificial intelligence and cloud computing,

Bharat Soni [00:04:23]:
collaboration and cross functional integration and things like that.

Bharat Soni [00:04:28]:
So these are the ways in this business have changed away. They are working on this thing, but with every buying frame you also see opportunities. How with these kind of investment business businesses are looking into, they have increased productivity, they have decreased downtime because of the infrastructure investment they are making, but when you ask that what has been easy, these are the easy part that every opportunity is coming. Then apart from the opportunities you will see complexities are increasing. There is when we talk about security, there’s no guarantee on security.

Bharat Soni [00:05:04]:
It’s a complex environment which is rapidly changing every day. Now let me give an example. Earlier we used to have Internet banking. With the adoption of mobile banking, are we doing seamless and omnipresent kind of customer experience which pull the customer to the new digital world to the mobiles. Everyone has a smartphone now how we are going to pull the customer to smartphone when they have more features on Internet banking platform. So on top of it, when we say customer experience. Now see the challenge over here is expectation to meet business requirement along with keeping security in place. Or you are embedding security in new channels without complicating things.

Bharat Soni [00:05:56]:
Username, password. Then we move token, then we move to OTP. Then we move to another level of security. So are we creating complexity around adoption? That is first question we need to ask and how we are going to reduce it by ways and means which can be more innovative. Then are we extremely accepting all new challenges? Because this is a world of first entrant kind of thing. The one who enter into a specific line of business or segmented the first instance itself is leading the way Vision mobile Adoption and alternate channels how we are doing it. I can give an example that in here in our bank we were the first one to introduce biometric ATMs so now you see once you have the biometric ATMs some of the competitors are still getting into that mode while we have move ahead from biometric ATM withdrawals and transactions within the bank to any other bank. Now you have moved a step ahead

Bharat Soni [00:07:00]:
while others are still to get into the setup. So who is accepting the new challenges? And obviously in all these things in place are we reducing the cost? That’s where the business will look into it from a security perspective. They will say okay let’s talk about zero trust framework, access control for stop, internal, external, how we are going to look into things. Then new regulations are coming like GDPR here in Nigeria we have same line as an entire sum. Other bills are on cable for privacy related issues. So things are getting more complex and due the third party risk, fourth party risk these are the things which are making things complex for the business and it’s a difficult situation to the security leaders to drive with lesser complexity and enabling business more. With challenges in technology business can look at plenty opportunities hire more security. Things are also getting challenging and complex with the day.

Bharat Soni [00:08:05]:
So that’s how I will look into things.

Sanjog Aul [00:08:08]:
Now. One is of course you gave a pretty comprehensive response on what you’re seeing and you are on a different continent than others and still you find some commonalities in the way security is being handled and or how complex it is. So back to the focus of the topic is we have to figure out what metrics and benchmarks should we even be using because what you cannot measure you cannot improve. So if I were to specifically say what measurable metrics does the management require from the security department to ensure and assess how effectively is security department doing to help meet the business goal, and if you are going to be asking your team and are talking internally to come up with those metrics and providing or are required to provide to the business that is a metric. How is that changing the way you run security and how it becomes strategic to the business? That’s what would my next question be, but please stay tuned listeners. We’ll be back and listen to Bharat share his insights.

Sanjog Aul [00:10:08]:
Welcome back. So Bharat Security department, if it had to work like any other business function, and if the management wanted it to work like any other business function, they are going to require it to provide some sort of metrics. What are those metrics that business is asking of you? Or what metrics should business ask you for you to literally be seen as parallel to any other business function like HR, marketing, finance, et cetera, and if they did ask you that for that metric, how is that changing the way you look at security, your team looks at security and how even the business and your counterparts look at security?

Bharat Soni [00:10:47]:
Okay, so let me try to tell or try to explain things in a very normal manner which is about metrics. Metrics typically what I understand is just like measurement data compared to baselines. It’s just a baselining thing. Now what metrics will do for a business. It determines what is working well, where we need improvement in terms of when we talk, when we take the context to the security side. Within my security policies, processes and technology, whether what is working well, whether I need to improvise on anything of these security policies, my processes, whether any lapses into the process are to be modified and it is a continuous process, infrastructure has been added. Technology has to be improvised and aligned with the new requirement. The first thing or the key is to find correlation on how it can apply to business as a whole.

Bharat Soni [00:11:44]:
Security is something you can People should not think that security is only typical to IT infrastructure. Now when whenever I talk about information security I give typical examples like even if I left a printout on a printer unattended, that’s a lapse of security. So whether I’m aligning myself to business as a whole, it’s all about the context. When we see and align ourselves to the business context, then it’s then it’s relevant. Like I can give an example. One of the metrics is to measure performance of security. Check the security against fraud reduction and compare with previous year, previous month or previous quarter.

Bharat Soni [00:12:26]:
What is the reduction in terms of internal fraud or external fraud. Another matrix example can be how many incidents becomes a problem or how many problem are been resolved kind of matrixes. So these will Help security department to what you call the to provide themselves or to prove themselves that they are another business function, not a cost center.

Bharat Soni [00:12:51]:
In terms of how security has been increased and interruptions are being reduced customer service time downtime of the infrastructure and what is the revenue impact. Like for example for any cyber attack. If my services to Internet banking is down, then there is a loss of the business. So in a security matrix I’ll put it as that these kind of attacks we have observed and these attacks are being eliminated. Like for example a DDoS attack has been eliminated, but while in the industry. Now I will compare my security metrics with what is available globally, maybe locally into the industry and in a local environment. So that gives me as a security person to say that yes.

Bharat Soni [00:13:37]:
Now look, I’m not a cost center. I’m giving a matrix which is like. Which you can compare around the peers around the industry. So what it gives me at the

Bharat Soni [00:13:49]:
as end result it will soften my executive fear. The top management fear that they will be feeling more easy where company is going in security. What is the security protocol status of the company? They answer their questions when I present to the board. The board is not really interested into. I have 10 security patches been released in this month and I applied all they want to be assured that all security patches are applied to my 100% system or what is my threshold? 95%, 98% are secured with the latest security patches. So the questions are being answered and then they also My metrics will also help me to continually prove that this is my worth of security. A security team has to earlier days has to fight for everything my budget, my approvals and everything, but this trend is changing with the adoption of new technology changing mindset at the top.

Bharat Soni [00:14:55]:
So these are the things which my metrics should allow me. However, I will also add that by providing metrics we should not overwhelm to try everything and put everything into metrics at the first go. It’s a. It’s the process. We can always grow into this thing and we have to develop a growth plan which it’s a. It’s a mature program and it always continues to optimize it because change in environment will make change in the program and the results has to be communicated very effectively. If results are not been communicated it’s of the matrix is of no use. Ultimately the use of data and this work with security team expert like for example the metrics should be based on approval track record of someone who is efficient into doing this thing and the last one is to what you call the plan which is to be approved and the top management should be accountable for execution or support of that plan.

Bharat Soni [00:16:01]:
Execution is with the security leader, but they should be the one who is going to govern and support the security leader. That’s how this metrics will become a strength for security department and feel like they’re also part of the business.

Sanjog Aul [00:16:17]:
So that’s a good response. Now what would you say is the level at which we are really able to carry out this cost benefit analysis for security currently? Because in many cases security says we want a million dollars to get something done, but we cannot promise that you’ll be foolproof. So it is to some extent subjective, but if you were to move towards becoming more precisely measuring the outcomes, more precisely measuring the performance and the way the security operations are run, where are we with it? I mean are we nearing the ideal, the way we could have done it? If not, then where are the gaps?

Bharat Soni [00:16:58]:
Okay, security. As I was mentioning earlier that security earlier was been looked as a cost center. Now the trend has been changing. However, as a security governance part when we talk about because cost benefit comes from the it is required by the top executives only from the secret leaders, but when it comes to security, if I’m into a business I can show that this is my product launch cost and I will do the cost benefit analysis and ultimately I’ll give you some revenue figures. When it comes to cybersecurity, there are no guarantees. I can even maybe we all are aware that even if I’m going into any agreement with any third party from I will get is 99.9% time, 99.9% response time and things like that. That 1.1% is the risk or the security which everyone has to bear in mind,

Bharat Soni [00:17:59]:
but cyber security is way, way beyond that. Uncertainty is natural and unavoidable. When we talk about cyber security the risk landscape because the game is changing every second, every minute it’s changing and we don’t know what’s happening.I am not even sure that

Bharat Soni [00:18:18]:
within 10 minutes I will not hear a news that there was cyber incident on this organization or there is a new zero day all been identified and everyone is running towards it. So and when you talk about cost benefit analysis in cyber or in larger sense the security the question we need to ask is whether we should pay now or we should pay later.

Bharat Soni [00:18:45]:
Why I’m going to pay now or why should I be paying later. Later will be the cost of incident plus the cost of investment. So are we going to take that risk? There’s a dilemma around it. So for me, when we do the

Bharat Soni [00:18:59]:
cost benefit analysis, we have to answer few questions like maybe I would identify my key most important assets like the key jewels of my organization. What is my organization collects and stores? Because it’s all about data ultimately am I going into direction or not? Where are my vulnerabilities? And when I talk about vulnerabilities it’s always internal and external, both sides. It’s not only external, you talk about security because threats are coming from everywhere. What specific threat? Like for example my organization is like being into financial industry. I look into the threats like internal, insider threat, external threat where we, where we look into malware, hackers, system not functioning at the right, I mean to branch then rest which is my operational risk kind of thing. So what we can face, those are my. What are my likelihood of falling victim to a cyber attack? Maybe for example, can my staff members be easily compromised to phishing or a square phishing email attack, and if it happens, whether I’m ready to sustain it or not, a cyber attack or data breach, how it’s, it’s affecting the business on.

Bharat Soni [00:20:14]:
On financial basis, on operational basis and ultimately my brand reputation, how it is impacting my brand reputation and what is the level of risk or threshold which my organization is going to accept? Because there is always a risk. So organization has to at the top, you have to accept the risk, something like that. Now apart from this questions, I need to also see if something happens, what is the cost of coming back to the business as usual. So in this term I will say like direct cost. There are some direct cost, there are some indirect cost. Direct cost is if I got a ransom attack, am I going to pay the ransom or I’m going to do the data, if I’m going to lose the data, whether I’m going to face some compliance issues or not. Then the remediation cost right after incident happened, security and time of getting back to business as usual. Apart from this indirect cost will be my downtime, my operational disruption, my reputational damage.

Bharat Soni [00:21:13]:
Because by, because the social media time, nothing is done. Everyone is, everyone is on to see that yes, I know this information on first hand compliance issues, the cost of businesses like the direct cost, productivity loss and everything. It’s, it’s what we have to look as a security person and try to see whether my organization is ready to answer or accept this risk or mitigate this risk, transfer this risk at the end of the day, at the End of the day, we should always be looking for most effective way to deliver the outcomes for the organization. Generally there is a cost benefit trade

Bharat Soni [00:21:56]:
off between you what is my risk and investment, and it’s not all about investment because investments are not all equally cost costly. It’s the risk versus the investment kind of thing. So that’s how I would say cost benefit will take me. If I am able to answer these questions and get a proper results, I will be move with the cost benefit analysis from a security perspective. Thank you.

Sanjog Aul [00:22:22]:
So the cost benefit analysis part you addressed. Now one thing which does come up is when you’re talking dollars and cents, while you don’t get budgets for department by department coverage of security, but if you were to look at different departments, Marketing, HR, Finance and many others, each of them may have their own assets which they want to secure and they would put different demands on the security department. Do you go down to that level to say hey, I’m going to ask you for $1 million because HR is asking me more versus marketing versus others. Do you go into that level of detail at the business function level so that it is truly, if you are a shared service, you are truly are able to tell business that this is where my money is going to get because this department is going to place more demands on security than others.

Bharat Soni [00:23:16]:
So means when we end up into the last question about cost benefit analysis, the answer to the risk and all those preliminary assessments are being done, we come back and say that this is what I’m going to invest. When I say I’m treating myself as a business function or another business enabler, I need to show the business what are my ROI calculations, but as I also mentioned earlier that cyber security or the security as a whole, information or cyber security is always a probability and that’s why the investment is hard to quantify. I cannot put a quantifiable thing values to cyber security in terms of it. The security investment should not be treated as profit. Like it will add into my profit that if I’m investing into security $1 million, it will add into my profit.

Bharat Soni [00:24:15]:
No, it should be seen as prevention for losses.

Bharat Soni [00:24:19]:
Here we are talk taking the back route of things. I will be investing so that my probable losses based on my previous cost benefit analysis can be seen what is maybe my potential losses or how much I will be saving out of it. So what is the amount an organization should invest in protecting information? I can say that it depends on how much we are going to do on these questions. How much I am saving, what Are my potential losses or how much can be the losses probable losses. So I would say ROSI which is return on security investment. I was reading this term and I really like this ROSI term rather than just putting it ROI kind of thing. Now when we say we are looking back as investment in proposing management this is what I want to invest and then distribute it amongst different departments, but overall ultimately what security is about, it’s about protecting my assets.

Bharat Soni [00:25:22]:
Process data. Ultimately the data should be not moving out anywhere. Unfortunately the way we implement the approvals are being taken. The threats moves very quickly and companies are of are often reluctant to reveal data on the security incidents as well. So we don’t know what’s happening around unless it comes as a compliance issue. So little statistical information on the cost of incident effectiveness of security measure will help us to say that this is what my investment should be. Now calculating the investment or the return is a process at this level. I will not say that what you call how grant how we can go and say that okay, this department will need this amount more.

Bharat Soni [00:26:13]:
This department will need this amount more to secure the assets, but I will say we have to go and mature and then we can go to a level where we can give answer to this question. Like for example first we’ll identify our crown jewels, the attached infrastructure and to the level of data identification. I don’t know how many organizations have defined the value to the data like if I if under GDPR we know there are clear rules that this is the sanction which an organization can have, but have we defined our own value of the data that if I am losing one data to cyber incident what is the value cost to me and what is the value cost to against 10,000 records. So these we need to answer this question during this process. Also we need to look which model best applies to the organization. We’ll see that we have to adopt a specific model or develop our own model to differentiate between the investments in cybersecurity and distributing it amongst different or different what you call departments.

Bharat Soni [00:27:16]:
When you talk about HR marketing HR is still a function where they are helping or they are the what you call cost centers. Typically they are the cost centers HR while they are comparing marketing with the revenue center. So between marketing and HR I cannot say that I am spending 20% of the implementation while I will take 100% out of marketing’s revenue. So that is a process, and then we need to also see how to measure the added value of expenses in incident handling. If incident happen, what is what for Example consulting charges, external support, remediation, cost of brand damage, reputation or reputation damage, all those things, and what are we going to include into the cost? As I mentioned, it’s a process and every organization need to start this general journey due to rapidly changing threats and the landscape in the current scenarios. So that’s how we need to look and take the journey and how to start somehow, somewhere.

Bharat Soni [00:28:19]:
Thank you.

Sanjog Aul [00:28:21]:
So with that said, what would you say in this journey of converting security, the regular security function to becoming outcome driven security which is driven by data, it’s driven by metric. What fundamental changes would you have to make in the processes, the people and the tools and even the organizational structure because the team itself is not used to it. The leadership itself is not used to that. Not a scrutiny but a data driven approach to security or security management function as if it was another business function.

Bharat Soni [00:28:59]:
Okay, so Sanjog, my thoughts this is as I mentioned this again when we talk about security or outcome driven function in terms of security it’s again a journey and an improvement or continuous process to drive through. Here when we talk about outcome driven functions organizations or a department we should not confuse ourselves between. Everybody talks about KPIs but KPI and matrix which are output driven function matrix I am putting it as output driven and business align function. KPI is very specific. They give you whether you achieved it or don’t achieve it. The results are being measurable somewhere. KPI doesn’t tell you what needs to

Bharat Soni [00:29:46]:
be changed or improved.

Bharat Soni [00:29:47]:
They will only give you the end results to drive the business growth. Whereas metrics driven organization are we would say output driven functions is aligned with organization, vision, mission, short and long range plans and how the output of that alignment gives a better view of the functioning. Now when we adopt an output or outcome focused approach what does it mean is we are orienting our organizations to achieve specific outcome which are the result of our activities. Now here I will go back again to the previous one where I say KPI is measurable where this becomes a more subjective one initially when the journey has been starting you have to be more subjective. Then looking for a broader side of things. Now focus on outcomes self organizations to prove to the stakeholders that because as I mentioned that it’s aligned to vision mission and my long range and short range goals. So the stakeholders they what they will get as an output is whether the organization is doing or working fine, moving in direction or not, whether my sticks into the organization say is safe or not. More importantly it also help organization improve

Bharat Soni [00:31:12]:
what they are doing so when they

Bharat Soni [00:31:13]:
will see divisions again. Go back to the process of remediating or coming out of the divisions and go back to the process which by being armed with better information because we are seeing the outputs are not going to direction what is working and what is not working. So all this has to come back and you that. That becomes a what you call a loop in which outputs are being measured. The output or metric driven organizations should maybe what you call focus on interconnected matrixes.

Bharat Soni [00:31:43]:
Because it’s.

Bharat Soni [00:31:44]:
It’s a single. When we talk about every business matrix or output for a department, everyone is aligned to the organization goals and missions. So it’s interconnected matrixes, future goals, proper definitions of expectation has to be there and the timely tracking we can set

Bharat Soni [00:32:03]:
workforce to achieve these goals.

Bharat Soni [00:32:05]:
What are the desired output has been communicated. We can involve all stakeholders, and from. If we involve all stakeholders from the start into achieving output driven strategy, the stakeholders or the staff member of the bank, they feel as part of this journey and they feel accountable, and their synergistic effort will definitely make it to improve more efficiency into the process in organization, increase employee morale so that I am a part of the journey and then establish the foundation, become an output driven organization. That that’s how we need to look into these things.

Bharat Soni [00:32:44]:
Thank you.

Sanjog Aul [00:32:45]:
Now, when you are looking at starting this journey, some people may be already on that journey or they may be thinking okay, this is where we need to get to. Would you say CISO should own it because they are the ones who are supposed to make it happen, but should it not be a business like executive management? Sponsorship needed and enough funding needed because you’re trying to transform a business function. So who should own it and who should fund it? Because you are not only at the executive management level supporting them, but now you’re also making this transformation directly impact the level of security and the trust you are able to offer to each department or each function.

Bharat Soni [00:33:26]:
Okay, so to answer this question, I would say that it’s a cultural change into the organization. Because organizational security culture requires care and

Bharat Soni [00:33:37]:
feeding at the top.

Bharat Soni [00:33:39]:
That’s how I would say, and we’ll come back to the question that who should own it and who should fund it, but before that, let’s see what is required. It’s not something that you always. Security is a function which grows into a very organic way or in a positive way. We have to invest in security culture when we talk about this thing where it becomes an accountability and responsibility issues. Sustainable security culture is bigger than just a single event because it goes into the process infrastructure and even I would say the blood of the employees. When a security culture is sustainable,

Bharat Soni [00:34:19]:
it transforms security from a single kind of event into a life cycle where the security is like a function or it becomes a responsibility of everyone into the organization. It has. In my this view, any security related cultural change should have few things maybe like it’s. It should be disruptive in nature and it should be very open as well. Now when we talk about disruptive, which means security culture is to foster change and better security should be there into the organization that becomes a security disruption into the organization’s ongoing way of working. Now it is also it also because when we talk about security, we don’t

Bharat Soni [00:35:05]:
expect that security team is an expert

Bharat Soni [00:35:08]:
person and we are talking our security

Bharat Soni [00:35:09]:
using our security words,

Bharat Soni [00:35:12]:
and everybody will understand in the same pace. It should be engaging with the employee. Like awareness has to be there and it should create fun into them. When you create awareness, it should not be too boring even that people will go away from the security thing and the people should participate into this thing, and the most important thing that the culture change should return should provide a ROSI return on investment of my thing. Now the As a security leader it is essential that we speak the language of business leadership to align security priorities with business outcomes, and when we have this kind of things, we can say that we are clearly connected to the business outcomes. When we say while security is important, for example, I can give an example where we say that what kind of system if I’m going and presenting it to organization leaders or someone else to say that my systems are tight, but what is the percentage of system types? What is the risk I’m giving or what is the assurance I’m giving to the leaders? That has to be done.

Bharat Soni [00:36:21]:
And then I have to provide appropriate context of things that what you call this is related to this concept. When we talk about funding ownership, obviously both things goes at the top. First, the CEO should be taking the ownership and should be responsible for the funding. Because when the security culture has been adopted into the organization, the ownership is always a governance issue. The CEO should. This is my view that the CEO should be taking the ownership to different stream leaders. Now, CEO is not into day to day operations, but he can ally. He can assign responsibilities like CSOs or CIOs to different leaders into their own business function and how to and he also should be or she also should be.

Bharat Soni [00:37:11]:
A CEO should be measuring it and should set clear expectation at how much budget is spent on new in like for example, he should say that your measurement will be done on I’m spending how much budget on regular functions and how much budget is being spent on new innovations based on my security things, and what’s the business benefit outcoming out of it?

Bharat Soni [00:37:33]:
What is the adoption rate of a new product and whether my security features are actually hampering my adoption of new product or they are making it very easy to increase into the revenue where my customers are moving to digital channels or they’re still going back to like for example in the bank, they are going back to banking halls to get their things done. Also a proper feedback has to be done that this customer needs these kind of features and things like that. So these ownership and funding has to be done in a manner where everyone is involved, and typically when you read about ownership and funding, obviously the organization will see and they will adopt certain plan which is based on talent acquisition performance is doing whether people are at the right or not, and ultimately it’s a combined responsibility between the security leaders and the top management of any organization. You cannot say that someone is solely responsible because these two has to infuse together and talk to each other in a business friendly manner. That’s what I will say about this thing.

Sanjog Aul [00:38:48]:
So one final question for you is while the business leaders can ask a lot of you and also the IT leaders can ask a lot of the security leaders, but what should they offer you as support so that you can establish a department and or transform your existing security department into an outcome driven entity?

Bharat Soni [00:39:13]:
Okay, so as I mentioned earlier that

Bharat Soni [00:39:16]:
when we talk about output driven department or output driven organization, typically the three most important consideration, and I mentioned it earlier, to ensure the successful change into the organization is mission, vision and the goals. So if this we consider all these things, organizations include the impact of change, the response to change and how emerge and this thing always emerge from your mission, vision and goal. Now from security leaders, that’s the support which has been needed from different stakeholders. That includes them giving the authority, accountability, leadership direction and the control of the departments and their alignment with the business thing. Now when we talk about support, business support and transforming into an output based entity, we have to what you call the governance program has to be in such a way we have

Bharat Soni [00:40:15]:
to adopt an effective security governance program.

Bharat Soni [00:40:18]:
And it should what you call include adoption from the top and should be spread along the organization. All leaders, whether it’s a security leader, technology, HR, whichever department, the leaders of those particular or the head of those department should be make accountable for this particular activities. It is viewed as a business requirement that cost of doing business and security should not be seen that what is it a cost of doing business or is it a sunk cost because it’s or I’m doing it just for the compliance.

Bharat Soni [00:40:54]:
So security should not be seen as

Bharat Soni [00:40:58]:
a sunk cost or expense or just doing it for compliance sake and it is addressed and enforced in all my organization, policies, strategies everywhere. Adequate resources because we need resources. As a security person professional I can tell you that resources requirement is heavy and people should be continuously trained on the activities to be done and should be continuously trained on the new or upcoming creds. Last but not the least, it is the process of support and adoption of

Bharat Soni [00:41:33]:
security into the culture should be treated

Bharat Soni [00:41:36]:
as a live process. It’s a live process and it’s a continuous process. It should not be seen as one time activity and after that nobody will talks about it. So those are the thing as security data I would say has been seeked in this kind of time from the management and other leaders of the business.

Sanjog Aul [00:41:56]:
Thank you and once again thanks so much Bharat for sharing your insight so that organizations and their security leaders can collaborate and actually develop what is a dream for everyone which is outcome driven security. Thanks so much.

Bharat Soni [00:42:12]:
Thank you Sanjog. Thank you.

Bharat Soni [00:42:13]:
Thank you so much.

Sanjog Aul [00:42:14]:
And listeners, please like us on social media, follow us on many of these different podcast channels that we are on and we look forward to keep getting some feedback from you so we keep improving. Thank you. So once again this is Sanjog Aul your host. Please take care. We will talk next week. God Bless.

Contributors

Bharat Soni

Bharat Soni, Chief Information Security Officer (CISO) and Group Head Information Security Group, Guaranty Trust Bank (GTBank)

Result oriented seasoned Information, Cyber Security and Risk Management professional with experience of over 21 year in this domain. Strong acumen in implementation of Governance, Risk and Compliance in complex environments. Adept at creat... More   View all posts

Advertisement

Citrix DaaS MPU 300X250
Bharat Soni