Cybersecurity Digital Transformation Innovation Leadership

Transforming Security Programs to Become Digital Business Enablers

Transforming Security Programs to Become Digital Business Enablers

Business typically views security programs as inducing caution, restrictions, and restraints. As a security leader, how do you change perception, create alignment, engage constituents, and demonstrably catalyze innovation to transform such programs into practical digital business enablers?

Contributor

    • Dee Young, Chief Information Security Officer, UNC Health Care

Download Podcast

Apple PodcastGoogle PodcastSpotifyiHeartRadioSoundCloudTuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.

Explore More

 

Transcript 

Sanjog Aul [00:00:00]:

Hello, and welcome to CTN. To learn more about this show, please visit ciotalknetwork.com. And today’s topic is Transforming Security Programs To Become Digital Business Enablers. What do I mean by that? So businesses say typically view the security programs as some sort of a restriction or say a restraint or something that might be a word of caution or inducing caution. When we are as security leaders, we have a big job in front of us that is to secure the crown jewels that we have in the organization, but then it is not gonna be as easy because the programs that you’re trying to put out there, they could be, if not perceived properly, then there is rejection and or resistance to adoption. So what do we need to do as security leaders? We have to change perception. We have to perhaps create an alignment. We have to get engaged both business and IT and even security constituents, employees and management both, and somehow demonstrate that, hey security is not just brake on a fast moving car. It is actually something which could be a source of innovation. It can actually be a catalyst to innovation. And how do we go about transforming such program could actually help make it a better business, a better digital business. So that means a security program could actually turn out to be a digital business enabler. Is that even possible? Is it a pie in the sky or have leaders try to do it and they’ve had success? So to discuss this, we have Dee Young, chief information security officer with UNC Health Care. Hey, Dee. How are you?

Dee Young [00:01:43]:

I’m great. How are you today?

Sanjog Aul [00:01:45]:

Very good. Very good. So as you might have heard me kinda laying the context painting the context and laying the groundwork for this discussion, Let’s talk about this whole security program. So when you talk to people, is still in today’s day and age when people know security is going to play a whole rather a critical role in the organization? Do they still have this knee-jerk reaction to say, nah. You’re gonna be slowing me down.

Dee Young [00:02:10]:

I think that can be the case. I don’t think it’s with all users or all business leaders, but I do think there are pockets that still view security as you said, a brake, someone that’s gonna slow down the process or not allow it. And so what I found in my career is that’s an opportunity to really work with them and show them that we can align and be a trusted partner if we are given the chance.

Sanjog Aul [00:02:42]:

So when you see that there are pockets of people, some people are totally on board and others not as much. Is that because it’s a herd mentality because the rest of the world is thinking? Or where would you say most organizations lean? Do they wait for others or somebody to say no, it’s good or bad, and then they follow them? Or is it a bunch of people who have kinda made up their mind that security is not gonna help me? So I’m gonna always resist no matter how beautiful it looks.

Dee Young [00:03:12]:

Good question. I really feel and what I hear from my peers, that’s a historical view of security. And it’s something that security kinda had a bad rap for a while of just being the no police. I think we’ve all heard that. And I think more and more CSOs and security leaders understand that we have to help enable the business, but we have to help them do it safely. And I think as more and more wins occur and more and more trust can be established within an organization, I think that’s when you see the shift and the tide change. Then it becomes almost like what you talked about. You can trust them. They’re not gonna derail your project. They’re not gonna tell you no; they’re gonna help us figure out how to do this and be able to do it securely, safely, and sometimes hopefully have some really good ideas to bring to the table as well. So to add some value.

Sanjog Aul [00:04:15]:

So if I were to deconstruct this resistance, where would you say is the most resistance? At the top when you go into the Oval Office or the Corner Office, not Oval Office, Corner Office, and ask for the money or ask for the blessing that can I do a sweeping change within the organization with respect to security? Or when you try to get the security program explained to the business unit leaders and the staff of various groups and get them to adopt it?

Dee Young [00:04:46]:

I think it’s more of the latter. I think with, we all know the threat landscape right now and our leadership understands the risk that we face every day. I think in health care, those frontline workers, those frontline leaders, especially in the last two years, they’re so stressed and working so hard just to take care of the patients that I’m not sure they really understand that we won’t slow them down because they’ve had to go at a pace that, frankly, I don’t know too many security organizations have been able to keep up and have had to change the way they’ve done things. So our example is in health care, we have a lot of medical devices that are connected, IoT or medical device on the network. And a lot of times these devices can be purchased even prior to a security review. And then that’s when we’re kind of on the back of our heels trying to figure out if it’s safe and secure to put on our network. And I think a lot of times, the end users or the requesters might think that we’re gonna slow down the process and not let them buy because we wanna put a security review in prior to purchase. And it’s really to save them angst because the last thing we wanna do is to tell them they can’t put a device on the network after they purchased it. So I

Sanjog Aul [00:06:24]:

Go ahead.

Dee Young [00:06:25]:

Well, and I think it’s an ongoing challenge. With COVID, we were doing so many new and innovative things that most health care security really had to even change those security reviews to be able to be more agile and understand the true risk and figure out what we needed to do to mitigate the risk.

Sanjog Aul [00:06:50]:

Now with what you just mentioned, so there is a mixed bag, right, as you mentioned. If I were to spend 5 more years, do you think it’s gonna still remain a mixed bag because there will be people of all sorts? So what would you say is your holy grail in terms of the perception that you would like realistically to prevail in an organization for security to truly be able to add value, which enable, like, in the end, the mindset that will truly enable what security function can indeed deliver to the business.

Dee Young [00:07:22]:

I think it’s two fold. So I think in the last 2 years, I’ve seen a dramatic shift. The threat landscape, cybersecurity is now a kitchen table discussion whether we like it or not. And so I think everyone understands the risk that every organization faces. And I don’t think anyone wants to put their organization under that risk or added risk. So I think that’s helped us badly. But I think as far as the digital or the business enabler, I kinda see that being a shift as well. I think more and more security leaders are having to almost become proactive in reaching out to the business and saying, what are your strategic initiatives? What are your business drivers? What are your stressors? And I know that’s something I have done every organization I’ve gone into is sit down with key leaders and ask them, tell me about your concerns. Because once I’m able to do that and really hear them and listen and learn and make sure I understand how our business works, then I feel that I can be ahead of the curve and I can help with making sure that I align our security program and our posture so that we’re able to pivot whether it’s telehealth, virtual visits, whether it’s home care, more and more hospitals being able to pivot and being able to have our security footprint be ready for that change, growth, or innovation, I think is critical. And then that really inspires trust with our business and clinical leaders because then we are adding value. And we’re not telling them the fear, uncertainty, doom. We’re actually aligning with the business so that our goals are their goals. And we’re just looking at it in a different way, but it’s the same goals. Our goal is simple. We wanna take care of patients. We wanna provide safe and secure ways for our clinicians and our business leaders to do that. That’s easy. The hard part is how do we achieve that in a dynamic business environment and regulatory and, you know, payer environment. And so I think we all have to be bearing them.

Sanjog Aul [00:09:54]:

So when I use the word catalyst, is that a stretch when it comes to security? Can security by the very function of it, it is supposed to prevent harm, but can it enable growth truly?

Dee Young [00:10:08]:

That might be a little stretch for me. I think we sure are not a deterrent, but I think going back to that trusted partner in the path and the journey with our businesses is important. But I do think in some areas we might be able to become the catalyst. And I think it’s that proactive approach. Again, I go back to the medical device security and just being able to help enable our clinical staff to use the tools that are coming out so quickly to make sure that they’re safe and secure, but we’re able to adopt them in a manner that they need.

Sanjog Aul [00:10:51]:

So now with that said, if I were to ever get an organization to change its perception about security, what would you do? What would be your playbook? Or maybe instead of asking a theoretical question, what did you do, and what worked and what did not work to change the perception for the better?

Dee Young [00:11:16]:

So, again, I go back to that trust, but I think it’s really a longer game, a longer relationship. It’s really, again, understanding the business, understanding the drivers, and then building on those successes and those wins. It’s also showing the business that your organization is maturing as well. So, again, with those security reviews or our metrics or our measurables, making sure that we have good outcomes, that we close. It sounds silly. We close tickets. We resolve incidents. We work with them. We understand that they have deadlines that we can impact adversely if we’re not careful. So it’s really kind of making sure that we’re a good teammate within the organization. And then I think it’s also explaining and teaching in nontechnical terms, the impacts of what we’re doing and why we’re doing it. And helping them understand that we might not be able to allow a certain way, but we can help them achieve the goal in other ways. And finding that way to help them understand. The example would be maybe file sharing sites or blocking certain applications, understanding what they need to do and seeing if there’s a way that we can achieve that safely and securely either with what they’re asking for or another option.

Sanjog Aul [00:13:07]:

So when you talk about trust and you will talk about perception and you said about smaller wins, security function like IT is seen as best serving the business when they don’t hear from you. And unfortunately, it is not that you have made that situation or created that situation where they hear from you. They’re not very excited to go to talk to business, but there are way too many threats coming from all over. Or even if the threats are not coming, you’re supposed to go and keep training these people not to fall for a phishing attack or things of that nature. So the perception is not going to change for the better if they keep getting these attacks, but you cannot prevent them either. So how do you eat the cake and have it too?

Dee Young [00:13:55]:

I think it’s multichannel, multipath engagement. It’s the education and awareness. It’s the communication. It’s the projects. It’s working with them and understanding the business and explaining why those threats or risks or issues came up and what we’re doing to mitigate them and learning from them. I don’t think anyone necessarily faults security if it does not work, but I do think the fault can be easier if you don’t communicate well. So the example would be if something did happen, really communicating with your business and your stakeholders to explain what happened, what we’re doing about it, what we’re mitigating. Here’s what we’re gonna do, and we’re gonna move on and get better. And I think all of those together help, but it’s a ongoing challenge. Again, we go back to security kinda had a bad rap for a really long time of being no, and it’s gonna take all of us to really continue to work with the business.

Sanjog Aul [00:15:15]:

So what would be your specific response to a question which could be from a hallway conversation or from management, employee, or business unit leader? They’ll say, hey, why do I keep having these issues with security? When will this go down? What are you guys doing about it? What’s your response to that? Because you’re not allowed to, I mean, you don’t have a way to control what the attacks are happening. I mean, of course, you can put the tools in place, but they keep getting emails. The external environment is way too strong a force for you to ever be able to tame. What’s your response to a question like that? Because your response is going to also make or break the perception that you’re working so hard to reduce the stigma that you’re so hard to reduce?

Dee Young [00:15:57]:

I think personally for me, I would empathize and try to understand their frustration. Try to see if there’s a certain area that they’re most concerned about or an issue that is really driving that. And I think the reality is this is where we are right now. The threat landscape nationwide has increased. And so I don’t think we’re the only organization that’s running into any of these issues and kind of relaying that. But it’s a challenge. I’m not gonna lie. I think it’s difficult and those are hard questions.

Sanjog Aul [00:16:44]:

Say so? I mean, I totally understand it’s difficult, but that guy will say you get paid a million dollars to be a CISO and your team is handling this. What response do you think? I mean, it’s almost like listeners who are gonna listen to this podcast are going to be wondering. I am being asked this question as a security guy all the time. What’s a good answer?

Dee Young [00:17:03]:

I think for me, the way I would answer it is I’m not sure when the threats are gonna go down. I think we have to be ready. We have to do everything we can, and it takes everyone with security. It’s not just me. It’s not just my team. It’s every decision. It’s every software that we use as an organization, and it takes all of us to secure our environment. And I don’t know if I really have a great

Sanjog Aul [00:17:42]:

No. But in fact, what you just said gives me an idea. Do you think it would make sense that you don’t counter question but instead you say it actually depends on all of us. How do we keep the security risks down and use that as an opportunity to make that more of an inclusiveness pitch. I agree. Because anyone trying to say that it is somebody else’s problem, perhaps is not thinking it right.

Dee Young [00:18:04]:

And I think that’s one of the taglines we have is security, it takes all of us, and it does. And I give examples. I think the other thing you mentioned a minute ago. I think the other thing is really helping people to understand that security isn’t just a business risk. That in your personal life, your social media, anything that a person does outside of work can also increase our risk. So it’s educating those people to understand their Gmail account can cause an issue with our work account if you’re using the same passwords. And so it’s really kind of educating them that they have a role in our security posture as much as I do and my team does. And it does take all of us, and it takes all of us to understand and to create a culture of security.

Sanjog Aul [00:19:02]:

So when you are talking about okay. So one is you’re kind of managing perception, but another is now that you’ve built with all the data that you could have collected a good promising security program, and now you’re trying to get that executed and adopted. Now think about starting from how would you lay that out in front of people, how would you approach kicking it off? And then how would you, as the program has been kicked off and you’re trying to introduce various aspects of it, how do you keep all of them engaged where they don’t feel you’re bugging them down? At the same time, they don’t think it’s ever somebody else’s problem or they just kind of think that they can wing it.

Dee Young [00:19:47]:

So coming into this role, one of the first things I did was align us to NIST because I felt NIST would help us align to the business goals and to show business value with our security program. It would also help us understand where we are within our maturity level. Once we did that, then we were able to identify which goals we felt were most important to mature and again, align to the business. And then I think communicating, getting the buy-in. I have a very supportive CIO, deputy CIO, CTO, making sure that they agreed that this was the direction and it aligned with our IT initiatives and then to the larger business initiatives. And then it’s really communicating and getting that stakeholder agreement and alignment. And even within our IT group, security is in every goal as far as every team has some kind of role with security in their maturity efforts. And then moving that forward and then continuing to communicate and bringing it back and showing them where we’ve achieved, where we’re moving, what our next goals are, and just continuing to refine that process and communicating back.

Sanjog Aul [00:21:31]:

So what’s realistic and measurable KPI or measure of success for any security program? How would you kinda lay that out? Because only then you say, this is what we are aiming to do. And as you go along, as you show progress, that progress cannot be shown in hazy terms. It has to be, this is the holy grail, and this is how we’ve reached this far, and this is how it’s changed. So when people see progress, they are willing to join hands with you or evangelize what you’re trying to do. So what would you do in terms of giving it the required KPIs or metrics, something measurable or measurably how do you make it measurably impactful?

Dee Young [00:22:14]:

I think this is my fourth health care organization. And what I’ve seen is different KPIs for different organization based on the maturity of the organization and also what really matters to the business. Metrics just to have metrics don’t help you if you have issues and can’t support the business. And I think you can always talk about click rate or phishing failure, or you can talk about how email messages that you blocked or malware remediation within certain minutes or, you know, investigations. But those are internal to security in my view. I think a lot of those how many breaches have we had? How much data have we lost? Have we had to report to regulators, our constituents? I think those metrics are worth working with your business and really working with your leadership to really understand what matters to them is very important with the KPIs. Because again, I’ve seen KPIs just to do them, and I’m not sure that really enables business. I’m not sure it really transforms unless you’re able to tie it back to a reason that it matters. I can tell you how many millions of emails we get, we block, how many connections we’re working on, data points. None of that matters to a business leader or a clinical leader unless you can tie them back to understandable reasons why that’s important to them.

Sanjog Aul [00:24:05]:

Let’s take a quick break, listeners. We’ll be right back. And let’s talk about the people side of security, which is not the people outside of the security group who you’re trying to help stay secure and keep doing what they’re supposed to do, but the people within the security group. When we are saying that we want to make security programs to become digital business enablers, there has to be something that should change in the DNA of how security function is run. So what changes are required in the people culture and the very DNA and the mindset of people within the security group? Please stay tuned listeners. We’ll be back.

 

Sanjog Aul [00:25:31]:

Welcome back. So, Dee, when we look at any organization, whether it’s a security function by itself or the organization as a whole, people is what makes them. And since we’re talking about almost transforming the security programs and the security function itself to become a digital business enabler, which is not the traditional role that people expect, I mean, for this whole department, which means you got to take a step back and fundamentally see if I need to rewire. Rewire the mindset, the DNA, the job roles, the work structure, the mindset, you name it. So step like, maybe it’s a 2 part question. Are you working towards making your security department or the security programs to convert into a digital business enabler or that is too far fetched an idea?

Dee Young [00:26:27]:

I think for us now, we’re not to that degree, but I do think we’re on that path. So what I mean is I have multiple hospitals and with each hospital, we have a security person assigned. And that person is really that security lead and hopefully working with the business and the clinical leaders to understand and to partner with them. And I think as we develop those relationships, we’re able to then work with them on the projects and initiatives that each hospital or each business unit would have. And I think having that person assigned really helps everyone to trust and understand that we are part of the business as much as we are security. I think down the road, I don’t know if I would use the terms you did. I think it’s more we want to be ahead of the curve is what I always say. We want to be in the room where it happens. What I mean by that is we want to be in front of the decisions to help influence and impact good, wise, safe decisions if we can. And so the example would be again, we go back to the medical device or even one of the things we enabled and I think most health care did over COVID is some of the chat bots on the website and being involved sooner rather than later on which vendors we’re selecting and what we’re doing and how we’re deploying this and what measures are in place helps us to be able to make sure that we’re safe and secure. And I think having those relationships and those kind of conversations help us to hopefully transform and to become that transformational group. But I do think it’s a longer journey for most in health care from the security side now.

Sanjog Aul [00:28:45]:

So when you have a heart to heart or a pep talk with your team, what do you say as a way to represent where we are and where we are going? Like a pied piper. Right? They need to follow you, not blindly, but they should in a way, they should lead you. That’s the epitome of a good team.

Dee Young [00:29:04]:

So what I normally tell my team is several fold. Number one, I tell them to do their jobs because one of the things they’re entrusted to do is to follow our standards and our policies. And so when they’re looking at software, when they’re looking at devices, no one else in the organization is gonna have the eye like they are. So a lot of times, things can get political or there are certain drivers. And that’s one of the things I reinforce because I think we lose credibility if we don’t adhere standards and policy across the board. But what I also tell them is we need to find ways if we can to mitigate the risk and communicate that to the requester so that they understand what we’re doing. So again, I’m reestablishing that trust. The other conversations I have are really about remembering our why. Remembering that we serve the business and we serve security. And what I mean by that is we don’t work if we don’t have a business. So we can’t tighten down security to the degree where we can’t function. That would be very secure, but of course that doesn’t allow us to really run a business. So they have to walk a fine line. And I think a lot of it is coaching them to have that customer service, to understand what our rules and our processes are, and also to make sure that we communicate clearly and we’re professional in what we’re doing with the business. But I think it’s a longer journey where I want to go is kind of that transformational leader. Again, I want each entity that they’re assigned to or each business unit really see them as the leader within security to help guide them and to kinda give them those navigational buoys of where they can go within their decisions that are green lights that are safe and secure. These are applications we know. These are vendors that we know. These are products or technologies that we know that work, that are safe, they’re secure. They’re the green lights. And then communicate what the yellow lights are and then educate what those red lights are. And that’s what I really try to inspire and communicate with our team and it’s a collaborative effort. They also explain back to me their struggles, challenges, what they hear because again, I might be a little further removed than they are and I think it’s important to have that two way dialogue so that I can understand it and not have unrealistic expectations or not understand really what’s going on.

Sanjog Aul [00:32:22]:

How do you ensure when you’re trying to make each of your programs from the very design level all the way to getting it adopted that these people who are working with you within the security group, while they do their job, but they create by design some space on their plate versus having a spilling plate all the time and versus thinking how on earth will I get this pile that I have on my plate ever get done, but instead say, I have this breathing room. What next can I do to evolve myself and my team and the overall department to take it to the next level? What do you do for that?

Dee Young [00:33:03]:

I try to have those conversations of where do we want to go. What do they envision? How do we mature our program? Where do we want to go? And to block out whether it’s once or twice a month in a staff meeting or a one on one where we elicit and we kinda brainstorm together because I find that that’s what inspires me. So I’m sure it inspires other people. And what I find is they have brilliant ideas. They’re very good at what they do. In many cases, have done it much longer than I have, especially at this organization. And so I think all of them kinda know where they want to take it. It’s just finding the time. And I think while this last couple of years have been a challenge, I think we are kind of turning the corner and we’re able to start looking a little more forward. I think it’s also in involving other teams and groups. I try to reach out to other CSOs, other organizations internal to healthcare and external to try to get ideas on how to help us transform. And so it might be having another group come in and just show us what their program looks like, whether it’s the questionnaires that we ask vendors to assess risk, whether it’s processes or procedures. I think all of that helps all of us to be inspired of where we can go. I think it’s important also to kind of show them that I have ideas and plans and to kind of help them see what the next 6 months, 9 months, 1 year looks like. It’s not rigid, but it helps them to see that we do have some key deliverables that we want to achieve, and it’s gonna take all of us to do it.

Sanjog Aul [00:35:10]:

Any specific pet peeves or challenges that your team repeatedly brings up, which kind of in their view holds them back from being the best they can do to help the business and become or make the security function as a digital business enabler? Are you seeing certain patterns in the regular pet peeves, etcetera, that they share with you?

Dee Young [00:35:32]:

I think one of the biggest challenges for all of health care are those legacy devices. And I think it’s probably all a business. So devices running older outdated OSes that are either end of life, end of support, I think those are stressful for myself and my team because we know they’re so much better. I think the thing that frustrates them the most is vendors who sell us products that are outdated before they come to our loading dock. And while we work on our contractual requirements and our reviews, those are frustrating. Those are hard. I think also the problems that never die. Those issues that we think we’ve put to bed, we think we’ve found a solution, and they rear their ugly heads over and over again because something’s changed with the vendor or something’s changed with the requirements. And I think just reminding them that we don’t get the easy things. The easy things don’t come to us. We get the hard things. We get the complex things. And that’s where we really add the most value is taking those complexities, trying to simplify, trying to mitigate the risk and help the business achieve what they need to.

Sanjog Aul [00:37:01]:

Now when it comes to the you mentioned about the toolset, etcetera. Right? And there are so many emerging technologies. There are so many emerging tool sets or tool stacks, whatever you may want to call that. Are they really helping make the job easier? Is the complete solution provider community really making it easier so that whatever security program you create and the execution of that on the ground, is it getting any easier?

Dee Young [00:37:31]:

I think there are some areas that, yes, the tools have been dramatically helpful. Again, I go back to medical device security. I go to IoT. I think there are some innovative solutions and tools that have filled in large gaps for most healthcare organizations or most organizations especially with IoT. I think our philosophy and most organizations our size that I interact with is we’d rather go deeper on our tool stack than go wider. So what I mean by that is we would rather really learn the tools we have, utilize them to the best ability, and then see if there’s any gaps then to add 10, 15, 20, continue to have the tool sprawl and have to be masters at so many. I hope that as we all mature in the security technologies, these can become even more integrated and the tool stack can help each other. But, we’re not looking to add many technologies. We try to stick with our core offerings and our core vendors to make sure that we know the tools really well.

Sanjog Aul [00:39:08]:

When you are looking at the support that you need from business, so if you go to them, help me help you. What is the kind of support you should get as a security function so that you can turn around and become the enabler?

Dee Young [00:39:24]:

I think number one, helping us understand their strategic direction. I think also the things that I feel we need is what I think I’ve seen or other organizations and I know in my current organization, a seat at the table, whether it’s with the CIO, the CTO, really having security be there so that we can be engaged and we can add value from the get go. I think with our business leaders, it’s really engaging us. I always say early and often, let’s have those quick conversations instead of those hard discussions after the fact. And, hey. What do you think? We’re thinking of doing this. We’re gonna go with this. We’re thinking of this vendor. We’re thinking of this technology. And for us to be able to kind of do a quick review or quick assessment and be able to tell them off the bat is so much easier than having them have this long involved, contracting or relationship and then find out we have issues and then be brought in the table. So I think just having that dialogue is really what helps. And then, of course, for any incident response being pulled in as soon as someone knows something so that we can mitigate the risks.

Sanjog Aul [00:41:00]:

And from a leader’s perspective, so you as you mentioned that you’ve been in 4 health care organizations. Where do you feel a security leader needs to evolve him or herself? And so that they are basically at par with the complexity and the pace and the demands that the business is gonna place. What do you think is a good holy grail for a security leader to aspire for as a leader?

Dee Young [00:41:31]:

You mean the

Sanjog Aul [00:41:32]:

Qualities that they should have or the muscles they should create, the emotional intelligence, whatever. I mean, you take your pick because leader is an animal in itself. Every leadership is a big animal.

Dee Young [00:41:43]:

I think the biggest challenge I’ve had is just being able to communicate in the business terms back to the business and feel like I understand that. So what I mean by that is I really wanna understand the business, but to be able to communicate and add value, I think that’s a ball I’m a great technologist. I think I’m a pretty good security person getting better every day, but it’s that executive presence and it’s really being able to understand the viewpoint of those senior leaders. And the perspective that they have is obviously much different than a technician or even a director. I think a CISO, the role is evolving. I think having that understanding to be able to present to the board in nontechnical terms in no geek speak is critical, and I think that’s something we’re all working to do as our role becomes more and more visible within the organizations.

Sanjog Aul [00:43:04]:

So if the resources were to be offered to a security leader to be able to take the security function, its programs to the next level? What resources would you like to be available to be made available to you in that role so that there is no so called constraint which could be holding you back from being the best?

Dee Young [00:43:31]:

I think it’s both personal and the business. I think I take responsibility for my development, whether it’s additional courses or personal development or coaching. I think that’s important and that’s my responsibility. I think from the organizational perspective, it’s allowing me to be in the room, allowing me to engage with leadership, not just during a security event, but during those other discussions, whether we’re talking about budget or strategy, or we’re talking about technology or even some of the business, just keeping the lights on, I think helps us be at that table so that we have those relationships when we are able and we’re able to really leverage those, especially if we have a crisis situation or we have those hard decisions that need to be made. So it’s really having that relationship and that dialogue and trust outside of the security function. You mentioned at the get go that people don’t wanna hear from security, and I think that’s true. And I think the way you change it is being involved even if it’s not a security issue. Example would be maybe there’s a technology outage, and it has nothing to do with security. I try to be on those calls. I wanna support the IT group and be there even if it’s nothing to do with security and it’s a vendor issue or an outage. Number one, because I want that visibility in case it is a security issue and no one’s noticed or they’re worried about the outage. But second, I wanna be part of the team. I don’t wanna be an outsider. And I think that’s true with our executives and our business, whether it’s a go live, whether it’s a new hospital, whatever it is, I think it’s important for us to be visible at times that are important to the business so that they can be supported when it’s important to security.

Sanjog Aul [00:45:51]:

Once again, thank you so much, Dee, for sharing your thoughts and insights about how organizations can transform security programs to become digital business enablers. Thank you.

Dee Young [00:46:05]:

Thank you so much.

Sanjog Aul [00:46:07]:

And listeners, hope you enjoyed rather probing conversation. Please connect with us on social media. Subscribe to our podcast. And once again, thank you for listening to CTN. This is your host, Sanjog Aul. Till next week. Take care and God bless.

Contributors

Dee Young

Dee Young, Chief Information Security Officer, UNC Health Care

Dee Young is currently the Chief Information Security Officer for UNC Health system for the growing enterprise including 13+ hospitals an academic medical center and over 800+ clinics and physician practices, In this role, Dee leads the UNC... More   View all posts

Advertisement

Persistent - HiTech- MPU - 300x250
Dee Young