<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CISO Conversations &#8211; CISO Forum</title>
	<atom:link href="https://www.cisoforum.com/category/ciso-conversations/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cisoforum.com</link>
	<description>An Exclusive Forum For Information Security Leaders</description>
	<lastBuildDate>Wed, 06 Mar 2024 10:22:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://www.cisoforum.com/wp-content/uploads/2025/04/cropped-apple-icon-152x152-1-32x32.png</url>
	<title>CISO Conversations &#8211; CISO Forum</title>
	<link>https://www.cisoforum.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CISO Conversations: Leading CISOs in the Healthcare Sector </title>
		<link>https://www.cisoforum.com/ciso-conversations-leading-cisos-in-the-healthcare-sector/</link>
					<comments>https://www.cisoforum.com/ciso-conversations-leading-cisos-in-the-healthcare-sector/#respond</comments>
		
		<dc:creator><![CDATA[CISO Forum]]></dc:creator>
		<pubDate>Thu, 04 Jan 2024 10:00:00 +0000</pubDate>
				<category><![CDATA[CISO Conversations]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Helthcare]]></category>
		<guid isPermaLink="false">https://www.cisoforum.com/?p=8418</guid>

					<description><![CDATA[Three CISOs discuss the role of security leadership: William Dougherty (Omada Healthcare), Barbee Mooneyhan (Woebot Health), and Mark Wochos (VEDA Data Systems).]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">(Kevin Townsend &#8211; SecurityWeek) &#8211; <em>SecurityWeek</em> discussed the role of security leadership with <strong>William Dougherty</strong> (Omada Healthcare), <strong>Barbee Mooneyhan</strong> (Woebot Health), and <strong>Mark Wochos</strong> (VEDA Data Systems). All three are CISOs in one of the world’s most attacked sectors: healthcare.</p>



<h1 class="wp-block-heading has-medium-font-size" id="h-the-route-into-cybersecurity">The route into cybersecurity</h1>



<p class="wp-block-paragraph">All three of our CISOs entered cybersecurity via IT. Dougherty had led the creation of an MSP where he became VP operations. He was recruited by one of the MSP’s customers and became corporate computing services manager.&nbsp;</p>



<p class="wp-block-paragraph">“We started having problems with people trying to break our systems. We didn’t really have a security function; so, I went to my boss and said, hey, I think we need a security department and I want to run it.”</p>



<p class="wp-block-paragraph">This is a recurring theme in this series of&nbsp;<a href="https://www.securityweek.com/category/ciso-conversations/" target="_blank" rel="noopener">CISO conversations</a>&nbsp;– career progression is often self-initiated: see an interesting gap, step up, and fill it.</p>



<p class="wp-block-paragraph">Barbee Mooneyhan had been in IT for almost 20 years, but never quite felt it was where she should be. She would often help members of the security team, and eventually asked if she could transfer. She did.</p>



<p class="wp-block-paragraph">“I just studied and studied and studied, and it took me over a year to get into security properly.” She moved to another company as a security team member, becoming the team manager about a year later. But now she had found where she should be. “I absolutely fell in love with security the moment I landed in it.”</p>



<p class="wp-block-paragraph">Mark Wochos was a systems and network engineer. This was in the days before cybersecurity evolved into a separate field of expertise. “So, it was automatically part of my duties. But it piqued my interest and I spent more of my time focusing on that area.” People focusing on cybersecurity so early tended to automatically become managers.</p>



<p class="wp-block-paragraph">So, see a gap and fill it; especially if it is one that attracts you.</p>



<h1 class="wp-block-heading has-medium-font-size" id="h-becoming-a-leader">Becoming a leader</h1>



<p class="wp-block-paragraph">A CISO differs in one major aspect from a manager. a CISO must also be a leader. Wochos draws an interesting distinction here: “Anyone can be a leader. You don’t necessarily need to be a manager to be a leader.” Most teams have a goto person that other members seek out for advice on tricky problems. That person is a leader, but he or she is probably not a manager; and may prefer to remain an engineer rather than become a manager.</p>



<p class="wp-block-paragraph">Being a manager requires a different skillset to being a leader. There are good managers who are not good leaders, and there are good leaders who are not good managers. A successful CISO must have both skills.</p>



<p class="wp-block-paragraph">In the early days of cybersecurity there was no existing organizational structure. A good and ambitious engineer could jump straight into a cybersecurity management position. That almost certainly cannot happen today. The route now is from team member to team leader to manager and – if you tick all the boxes – eventually to CISO. This process naturally teaches management skills – but the CISO also requires exceptional leadership skills.</p>



<p class="wp-block-paragraph">You can learn management skills from books. Most CISOs believe you can also learn leadership skills, but this comes from desire, the advice of mentors, observation of other leaders, and a smidgen of natural charisma. Mostly nurture, but a little bit of nature.</p>



<p class="wp-block-paragraph">Mooneyhan provides an example from her own career. Her task was to develop a threat hunting and incident response program. What she found was a non-team – just individuals doing their own thing and not generating any coordinated information. Her response was to fly everybody to a private summit – including her boss – in Nashville.&nbsp;</p>



<p class="wp-block-paragraph">“We sat in a room for three days, and we planned out everything that was going to happen. I think I just took the reins. The next year I did the same thing.” That showed the desire and charisma to lead, and demonstrated leadership.</p>



<p class="wp-block-paragraph">“I think most leaders make themselves, but no leader makes themselves alone,” says Dougherty. Leadership is a skill that must be learned, like any other skill. And the best way to learn that skill is through observation, and apprenticeship. You must have mentors and guides and leaders above you that are willing to help you learn. I don’t believe you come fresh out of school ready to be a leader. Leaders are made, not born.”</p>



<p class="wp-block-paragraph">The implication here is if you are a manager wishing to become a CISO, you must have the desire and willingness to learn leadership. But it can be learned.</p>



<p class="wp-block-paragraph">Wochos agrees with this. “It is something you can absolutely learn. Obviously, there are certain people who have natural charisma or natural leadership skills that they are born with, but a good leader must spend time focusing on those skills. Anyone who has the desire to move into a leadership role can do so if they’re willing to put the time in.”</p>



<h1 class="wp-block-heading has-medium-font-size" id="h-building-and-keeping-a-strong-security-team">Building and keeping a strong security team</h1>



<p class="wp-block-paragraph">Key to being a successful CISO is the ability to recruit and keep – gain and retain – a strong, well-balanced security team. Different CISOs develop their own methods for recruitment. Wochos, for example, prefers to recruit from within his company. “My preference is to find someone internal who has a desire to move into security, because that seems to be more effective.” That doesn’t mean he doesn’t recruit externally for specific roles, but he adds, “I think having an existing relationship and having people who already understand the company jumpstarts the whole process.”</p>



<p class="wp-block-paragraph">Mooneyhan notes a common problem for smaller organizations: “I don’t have the luxury of being able to recruit and train entry-level staff – I need people who can be effective from day one without requiring a lot of handholding.” This involves going through hundreds of resumes looking for people who might fit – and this much is fairly standard.</p>



<p class="wp-block-paragraph">What differs is the first interview. She talks about herself and her way of working, and about the company. She asks the candidate about passions and aspirations. By the end of the conversation, she knows whether the candidate wants to work for her, and whether they can work together. This process weeds out those who just wouldn’t fit into her culture, and it is only at the second technical interview does she investigate whether the candidate is qualified for the position.</p>



<p class="wp-block-paragraph">All three CISOs take the same approach to keeping a strong team. It involves taking a personal interest in each individual. Compensation is important, but not what makes people want to stay. Team members stay on the team if they are interested, engaged, have a sense of purpose and fulfillment, and a clear career path.&nbsp;</p>



<p class="wp-block-paragraph">“Every career is ad hoc,” comments Wochos. “In the short term, my approach is to have that conversation with everyone to understand what they’re doing, where they want to go – and then help create a plan to get there. In some cases, particularly with people who are newer to the industry or new to the role, that person might not know where they want to go. So, you use your intuition, some of your own expertise and wisdom, to try to push them in a direction you think they’ll be good – but that only works if they have a desire to want to walk with you.”</p>



<p class="wp-block-paragraph">The secret to retaining a strong security team is to make each member want to walk with you, but to train and mentor them so they are eventually capable of walking ahead on their own.</p>



<h2 class="wp-block-heading has-medium-font-size" id="h-the-importance-of-diversity">The importance of diversity</h2>



<p class="wp-block-paragraph">Diversity is an important ingredient in the team mix. “If I don’t have diversity of thought, I don’t have a fully functioning team,” says Mooneyhan.&nbsp;</p>



<p class="wp-block-paragraph">“I really focus on diversity of thought,” adds Dougherty. “I want to hire really smart people that are likely going to disagree with me, because that allows us to bring the best arguments forward.”</p>



<p class="wp-block-paragraph">For example, Dougherty is pleased he has team members that come from an arts rather than purely technical background. “I value that because when you have a diverse team, you have a number of different opinions, and it allows you to come to a more holistic answer.”</p>



<p class="wp-block-paragraph">Diversity goes way beyond gender diversity – which is difficult to achieve because of the smaller number of female applicants. It includes race, socio-economic background, culture and LBGT. Full diversity is difficult for smaller organizations because the security team isn’t large enough to include everyone – and CISOs must choose the best person regardless of background.</p>



<p class="wp-block-paragraph">Nevertheless, each of the CISOs would welcome&nbsp;<a href="https://www.securityweek.com/harnessing-neurodiversity-within-cybersecurity-teams/" target="_blank" rel="noopener">neurodiversity</a>&nbsp;into the mix. “We embrace that,” says Wochos. “In fact, I do have one or two neurodiverse people on my team.”</p>



<p class="wp-block-paragraph">Dougherty adds, “I’ve had the pleasure of working with a few people that would fit in that category and they’ve been fantastic people. Some of the neurodiverse people I’ve worked with have been incredibly good at data and math and statistics. So, if you put them in an analyst role, where they’re doing that sort of thing, they thrive.”</p>



<h2 class="wp-block-heading has-medium-font-size" id="h-maintaining-mental-health-in-the-team">Maintaining mental health in the team</h2>



<p class="wp-block-paragraph">The potential for&nbsp;<a href="https://www.securityweek.com/burnout-in-cybersecurity-can-it-be-prevented/" target="_blank" rel="noopener">burnout</a>&nbsp;is increasingly recognized. Dougherty explains part of the cause within the security team. “There’s a portion of the job that is… I don’t want to say boring, but it’s rote. Every day you must look at your SIEM and you must look at your log files. So, you review 1000 entries in a system looking for problems. And you clear them all and tomorrow morning, you wake up and you’ve got another 1000 entries, and a year from now you still have another 1000 entries to look at. That creates a tedium. But, in addition to that, you also have these moments of incredibly high stress. You find something, and you must figure out whether it’s a false positive or is the entire house on fire? And as soon as you’re done with that crisis, you have to go back to the tedium – and the cycle never ends; every day, you’re going to get another 1000 log entries.”</p>



<p class="wp-block-paragraph">Burnout is something that can happen to anyone in any profession, but including (and perhaps especially) the CISO. For the CISO, the buck stops here. There is generally less external company support available, and the CISO must be self-disciplined to prevent personal burnout.</p>



<p class="wp-block-paragraph">Wochos describes how he and many other companies manage burnout for the team. “We focus on our people’s mental health,” he explained. “We provide the opportunity for mental health days when people need to step away. We provide mental health benefits. If I see one of my engineers who has not taken time off for a while, I’ll force them to take a day off. ‘Hey, by the way, you’re not coming in on Friday. Goodbye, we’ll see you next week. Take a day off.’ We think that’s important to allow people to take time off to refresh and come back as their best self.”</p>



<p class="wp-block-paragraph">He believes the problem can be exacerbated by remote working, with staff working excessive hours. “We provide guidance and suggestions and try to enforce them where possible. “Separate your workspace from your living space. Find hours when you will not work, and step away from work in these periods.”</p>



<p class="wp-block-paragraph">The key to preventing burnout lies in the old adage: finding and, if necessary, enforcing a good work/life balance.</p>



<h1 class="wp-block-heading has-medium-font-size" id="h-advice">Advice</h1>



<p class="wp-block-paragraph">We ask all the CISOs in this series to tell us the best advice they ever received, and what advice they would now give. The former tells us how to become a good leader, while the latter tells us what has been learned after succeeding.</p>



<p class="wp-block-paragraph">Mooneyhan says the best advice she received comes from the Robert Frost quote: “The best way out is always through.” Frost has another similar quote: “Hope is not found in a way out but a way through.” For Mooneyhan, this translates as not trying to avoid difficulties, but confronting them and solving them.</p>



<p class="wp-block-paragraph">Dougherty cites two pieces of advice: never stop learning; and surround yourself with people you believe have the potential to be better than you while giving them the opportunity to be so.</p>



<p class="wp-block-paragraph">For the former, he says that technical learning is good, but you shouldn’t limit yourself. “Continuously expand your knowledge. Be a sponge. You won’t always know when you will be able to use that knowledge, but eventually you will. To be an effective CISO, you must be continuously learning.”</p>



<p class="wp-block-paragraph">For the latter, he comments, “Their success will reflect back on you as a leader. The ultimate value of success is 20 years down the road when they’re all leaders too.”</p>



<p class="wp-block-paragraph">For advice given, Mooneyhan points out the necessity to learn additional skill sets as you move up the career ladder. Management skills are different from engineers’ skills. And when you get to C-suite levels, you need to add leadership skills and business skills.</p>



<p class="wp-block-paragraph">Dougherty advises on the need to build strong trusting relationships. “It may be counterintuitive in the security world because our inclination is to trust no one – but the paradox is that to be effective, you have to surround yourself with people that you trust and that trust you.”</p>



<p class="wp-block-paragraph">Wochos simply says, “Be true to yourself. Don’t let a company mold you into someone you don’t want to be. Just be true to yourself. Be who you are, don’t lose yourself while you’re evolving into a good leader.”</p>



<h1 class="wp-block-heading has-medium-font-size" id="h-threats">Threats</h1>



<p class="wp-block-paragraph">A good CISO will lead a strong, diverse, and healthy team for one primary purpose: to prevent cyber threats impacting the company’s bottom line. Understanding those threats is imperative – especially in healthcare, one of the most attacked sectors.</p>



<p class="wp-block-paragraph">“I’ve been concentrating on buttoning down our public threat landscape in the expectation of more national threat actors,” commented Mooneyhan.</p>



<p class="wp-block-paragraph">“The media focus is on malware,” says Wochos, “and understandably so because it is interesting and challenging. But the greatest threat is, and will continue to be,&nbsp;<a href="https://www.securityweek.com/security-awareness-training-isnt-working-how-can-we-improve-it/" target="_blank" rel="noopener">social engineering</a>. Almost every attack goes through social engineering attack vectors. Getting your workforce to be alert with the proper level of paranoia and education, and the understanding to ask questions and not just do things… this is the greatest risk and will probably remain so for the foreseeable future.”</p>



<p class="wp-block-paragraph">Dougherty’s concern is on a similar theme. “I have long held that my number one threat is the insider. I’ll say this in an impolite way, and then I’ll try to make it more polite. I’m always fighting against malicious and stupid, and stupid is always stronger than malicious.”</p>



<p class="wp-block-paragraph">‘Malicious’ comprises the external actors that try to cause harm and steal data. ‘Stupid’ comprises the internal workers who are simply trying to do their job as efficiently as possible, but with a system that doesn’t preclude careless errors.&nbsp;</p>



<p class="wp-block-paragraph">“The biggest threat comes from the people inside who already have privileged access and are trying to do the right thing but just make a dumb mistake. They’re not trying to not circumvent your controls; they’re trying to get their job done. The hardest thing to do is to design systems that allow people to get their work done, while at the same time preventing them from making mistakes. Human error with the best intentions from people who were just trying to do the right thing and get their job done within a system that promotes productivity but doesn’t catch those errors – that’s the biggest threat.”</p>

    <div class="xs_social_share_widget xs_share_url after_content 		main_content  wslu-style-1 wslu-share-box-shaped wslu-fill-colored wslu-none wslu-share-horizontal wslu-theme-font-no wslu-main_content">

		
        <ul>
			        </ul>
    </div> 
]]></content:encoded>
					
					<wfw:commentRss>https://www.cisoforum.com/ciso-conversations-leading-cisos-in-the-healthcare-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CISO Conversations: Intel, Cisco Security Chiefs Discuss the Making of a Great CISO</title>
		<link>https://www.cisoforum.com/ciso-conversations-intel-cisco-security-chiefs-discuss-the-making-of-a-great-ciso/</link>
		
		<dc:creator><![CDATA[CISO Forum]]></dc:creator>
		<pubDate>Wed, 27 Jan 2021 00:12:57 +0000</pubDate>
				<category><![CDATA[CISO Conversations]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Intel]]></category>
		<category><![CDATA[Leadership]]></category>
		<guid isPermaLink="false">http://www.cisoforum.com/?p=504</guid>

					<description><![CDATA[SecurrityWeek talks to two veteran security leaders in the technology sector: Brent Conran, CISO at Intel, and Chris Leach, Senior CISO Advisor at Cisco Systems. The purpose is to understand what makes a successful modern CISO.]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" src="https://www.securityweek.com/sites/default/files/features/CISO_Conversations_Header_title.png" alt=""/></figure></div>



<p class="wp-block-paragraph"><em>In this installment of SecurityWeek’s CISO Conversations series, we talk to two veteran security leaders in the technology sector: Brent Conran, Chief Information Security Officer (CISO) at <a href="https://www.intel.com/" target="_blank" rel="noreferrer noopener">Intel</a>, and Chris Leach, Senior CISO Advisor at <a href="https://www.cisco.com" target="_blank" rel="noreferrer noopener">Cisco Systems</a>. The purpose, as always in this series, is to understand what makes a successful modern CISO.</em></p>



<p class="wp-block-paragraph"><strong>Organizational hierarchy</strong></p>



<p class="has-drop-cap wp-block-paragraph"><strong>The enduring question for many CISOs is where their role fits best in the organizational hierarchy. It’s an important question. Reporting to the CIO or CEO can be problematic because they have different priorities. Reporting to the CFO, Legal or Audit can be problematic because they don’t usually understand the nitty gritty, down-in-the-weeds function of cybersecurity.</strong></p>



<p class="wp-block-paragraph">Nearly every CISO has a personal view on the question, usually with some slight variation from others, depending on their own experiences. Brent Conran from Intel has a dramatically different view from most. “Well, I work for myself,” he said. He doesn’t mean it in the normal legal sense. He means it in the psycho-emotional sense. “Once you’ve got that part of the equation figured out – that you’re a going concern in your own right – where you report to doesn’t much matter.”</p>



<p class="wp-block-paragraph">But he admits it’s a vexed question. He’s been attending the RSAC Executive Security Action Forum each year for the last ten years. “They’ve asked that question every year. Ten years ago, 95% of CISOs reported to the CIO. Today, it’s probably about 55%, with the rest reporting to a range of offices.”</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><a href="https://register.securityweek.com/2020-securityweek-ciso-forum-registration?utm_source=CISOFORUM&amp;utm_medium=banner&amp;utm_campaign=article" target="_blank" rel="noopener"><img decoding="async" src="https://www.cisoforum.com/wp-content/uploads/2020/09/300x250-CISO-2020-Virtual-banner.png" alt="" class="wp-image-506"/></a><figcaption><a href="https://register.securityweek.com/2020-securityweek-ciso-forum-registration?utm_source=CISOFORUM&amp;utm_medium=banner&amp;utm_campaign=300x250" target="_blank" rel="noopener">Register for the 2020 CISO Forum (Free for Security Professionals)</a></figcaption></figure></div>



<p class="wp-block-paragraph">He thinks the solution depends upon a range of factors: the industry you’re in, what you want to achieve as a CISO, the relationships you have. “If you have a good relationship with the CIO, there’s often a lot of benefit in reporting to the CIO. But if you need a lot of independence to do what’s necessary as a CISO, then maybe you shouldn’t report to the CIO.”</p>



<p class="wp-block-paragraph">Cisco’s Chris Leach is in broad agreement. “When I first started as a CISO, some 20 years ago, I reported to the CIO – and that made sense. But as the CISO role and accountability have evolved, so the reporting structure needs to change as well. Whoever controls the security budget controls the security – and the CIO has different priorities.” CIOs want smooth computing; CISOs want secure computing – and the two concepts are not always fully compatible.</p>



<p class="wp-block-paragraph">But that leaves a problem, because other officers tend not to have a close understanding of security. “The best reporting relationship I’ve had has been with a COO. The worst was with a CFO – I don’t think CFOs really understand the issues. But in both cases, it was ultimately down to the personal relationships. I don’t think there’s an ideal place until you understand the individuals and the company concerned. But I can tell you this,” he added: “you should never report solely to a CIO. Maybe dual-reporting with somebody else.”</p>



<p class="wp-block-paragraph">All of this begs some interesting questions: what can a CISO who wants to shine do if the reporting structure prevents it? Well, this is where Conran’s initial comment comes in to play. By ‘working for yourself’, he effectively means it is your life, your career, so take responsibility for it.</p>



<p class="wp-block-paragraph">“A CISO has to be able to effect change,” he said, “and if you’re in a position where you cannot effect change, do something.” He gave a hypothetical example. If you report to the CFO and it isn’t working, there has to be other C-Suite officers you can talk to.”</p>



<p class="wp-block-paragraph">Leach takes a very similar view. “If you’re not getting through to the company and you’re having a reporting issue, I would talk to internal audit.” If the problem is reporting to the CIO, Leach doesn’t suggest bypassing the CIO and taking the complaint straight to the board, or even trying to exclude the CIO.</p>



<p class="wp-block-paragraph">“But I would begin with audit,” he said. “Get their view and see if they’ve had any discussions around this topic with the audit committee and/or the board. Audit understands conflicts of interest. As CISOs, we tend to beat up audit, but audit can be your best friend as well.”</p>



<p class="wp-block-paragraph">The second question raised by the reporting structure is ‘compliance’. Compliance cannot be ignored. It’s either the law (like CCPA and GDPR) or club rules that must be obeyed (like PCI). The main issues, however, are where should compliance live within the company, and who should own it.</p>



<p class="wp-block-paragraph"><strong>Compliance</strong></p>



<p class="wp-block-paragraph">“There’s nothing wrong with requiring compliance with standards per se,” said Leach. “The problem is that there are so many of them. Any single company will likely need to comply with multiple different state privacy regulations, multiple international privacy regulations, national and international finance regulations, PCI and more. There is no single audit that confirms compliance with all of them – and maintaining separate and consistent compliance is a burden.”</p>



<p class="wp-block-paragraph">But compliance is also a problem for the organizational structure of the company. “Take GDPR,” he said. “My argument is that privacy is a component of security. But we’re seeing a divergence of privacy and security with privacy going to the legal department. But the lawyers don’t do operations – they don’t understand 24/7 tickets and all those sorts of things we deal with.” So, privacy is taken away from security, but comes back to security to be handled.</p>



<p class="wp-block-paragraph">“I’ve seen some companies that have a whole separate compliance department,” he continued. “That department does what it has to do, that’s good – but they always have to come back to security for answers or to make any necessary changes. Security is always central to the functioning of compliance. So should compliance be under security and help security, or should it be on a level and make demands on security. I don’t know the answer to that.”</p>



<p class="wp-block-paragraph"><strong>Advice</strong></p>



<p class="wp-block-paragraph">Further insight into what Conran means by taking responsibility for your career comes from both the best advice he has ever received, and the advice he would give to new or prospective CISOs. The best advice came from his father. “Always work yourself out of a job, and you will always have a job.”&nbsp;</p>



<p class="wp-block-paragraph">He has applied this in different ways at different times. He always looks for people who are constantly seeking to improve their position. He mentors and prepares them. “So, there’s one, two, or three people always ready to take my job &#8211; if necessary. But that means that if something bigger or better comes along for me, I can just take it without worrying about my current company. Or if my world suddenly changes, like mainframes get dropped and we move to client/server, or office working gets dropped in favor of remote working, I’ve already worked myself and the company into a position of being able to handle it. Work yourself out of a job, and you’ll always be in one.”</p>



<p class="wp-block-paragraph">Leach’s best advice is different, but still related to taking responsibility. “The best advice I ever had was simple: never be afraid to vote with your feet.” He expanded on this. “If, as a CISO, you continually raise a hand to escalate issues – and assuming the reporting is to a CIO who has different priorities and ignores you – what can you do? If there is a subsequent breach, it is the CISO who bears the mark of that breach on his CV, forever. What can you do? For me, if I can’t get anything done, or I’m having roadblocks because of a bad reporting relationship, I would leave. And incidentally, I did leave&#8230; I did leave one company where I worked for that very reason – because I couldn’t get anything done because the CIO blocked everything I did.”</p>



<p class="wp-block-paragraph">The advice that Conran would give to newcomers is again related to his central theme of taking responsibility. “What I tell everyone,” he said, “is that you must continuously and constantly learn – and if you do that, you’ll be successful. I get a lot of people who come to me and say, ‘I’m top of class with 99% right.’ I tell them that means you’re 1% wrong, and it might be that 1% that gets you. If you have the personality and aptitude to continue learning, you’ll thrive. If 99% right is all you want, that’s OK, but we’ll find somewhere else for you.”</p>



<p class="wp-block-paragraph">Leach would simply recycle the advice he received: don’t be afraid to vote with your feet. It implies more than seems obvious. If the CISO is going to take the blame for a failure, he needs to be given the authority to prevent it. Without that authority, for the sake of your career, it might be better to move on.</p>



<p class="wp-block-paragraph"><strong>Personal attributes</strong></p>



<p class="wp-block-paragraph">At this point it is worth asking what it takes to be a top CISO. Conran has little doubt. “Agility,” he said, “and the self-confidence to use that agility. Look,” he continued, “we might be doing something one day, and the world suddenly changes under our feet.” Like the pandemic forcing an almost overnight switch from office working to home working. “We have to be able to pivot, and we have to be able to pivot today.”</p>



<p class="wp-block-paragraph">Or there might be a sudden and major incident. “A CISO must be able to talk at all levels – like from 40,000 feet and 20,000 feet, and sometimes right down to the ones and zeros – while keeping your hat on straight,” he said. “The agility to interact with all levels of that stack simultaneously is imperative to being successful.”</p>



<p class="wp-block-paragraph">There’s a related attribute: the ability to understand the business. “Security used to have a technical relationship to the business,” he said. “Discussions mostly came down to ‘yes’ and ‘no’ – mostly ‘no’. That doesn’t work anymore. The CISO must be able to sit down with business in a consultative manner, and say, ‘I understand where you’re trying to go – let me explain the best way to get there. ‘No’ must become ‘Yes, but like this’.”</p>



<p class="wp-block-paragraph">Asked outright whether the CISO needs to be a businessman or a techie, he replied, “I don’t understand the question. I don’t know how a CISO can do his job if he doesn’t understand technology, and I don’t know how he can do his job if he doesn’t understand the business. An understanding of both is part and parcel of being a CISO.”</p>



<p class="wp-block-paragraph">Leach has a slightly different emphasis. “It’s more important to be a businessman,” he said. “I’ve been saying this for 20 years. If you think about being a CISO, it’s like being a general in a big battle. You’ve only got a certain number of troops and a certain amount of resources. How can that work if you don’t know where it is most important to deploy them?”</p>



<p class="wp-block-paragraph">He gave the example of a Fortune 50 company. He asked the CIO, what were the company crown jewels that needed to be protected. The answer wasn’t this data, or that server or some intellectual property – it was the customers. The CEO gave exactly the same answer. “But if I went to Coca Cola and I asked the same question, I might be told their recipe or something like that. All businesses are unique. But if I don’t understand what each business is trying to achieve – what it’s best at – then I don’t know how I do my job. And most CISOs forget to ask the question.”</p>



<p class="wp-block-paragraph">Conran adds two other attributes that will benefit the modern CISO. The first is a thick skin. “I cannot make a decision,” he said, “that does not upset a portion of my workforce. Whatever I do, I’m either turning something on or turning something off. Whichever it is, it will mean change, and people simply aren’t wired for change – but you’ve just got to keep your mind focused on the goal.”</p>



<p class="wp-block-paragraph">The second attribute is a desire to learn. “I read for hours in the morning and hours at night – technical whitepapers, industry trends and developing themes. If you move to a new platform or different piece of technology, you must make the time to thoroughly understand it. Security is like a journey where you’ll never reach the destination. The good news is that you’re never going to finish learning about your job. The bad news is that you’re never going to finish learning about your job. You just have to keep up.”</p>



<p class="wp-block-paragraph"><strong>Future threats</strong></p>



<p class="wp-block-paragraph">With an understanding of what it takes to be a top CISO, it is worth asking where the future threats are likely to originate. Conran breaks it into tactical threats (immediate term), and strategic threats (longer term).</p>



<p class="wp-block-paragraph">“The tactical answer is ransomware and commodity malware. Ransomware is happening across the globe. It’s destructive and a huge problem, threatening trust in the internet. Security builds confidence in the internet. If people were to lose their confidence and no longer trust their bank or online retail shops, then rebuilding trust is something we’re going to have to work on.”</p>



<p class="wp-block-paragraph">For the longer term, he has a different concern. “If you look into the future, but not so far out, I think Quantum is going to be massive for this sector – and for the Internet. None of our encryption algorithms will work once we have Quantum. None of our security products will work once we have Quantum. And, whoever finally gets there first is going to throw this industry up in the air. We’ll have to work through that pretty quickly to ensure we maintain the integrity of our data and transactions.”</p>



<p class="wp-block-paragraph">Summing up, he said, “Tactically, it’s going to be ransomware and commodity malware that’s the problem. More strategically but within the foreseeable future, I think quantum computing is going to be very disruptive to the existing security products and standards that we have today.”</p>



<p class="wp-block-paragraph">Leach is as much concerned about security’s response to threats as to the precise type of threat faced. “I think the biggest problem is that innovation from the attackers is accelerating, and we are not. We cannot continue to do what we are doing – we have a cycle of a 3- to 5-year plan and strategy. If we don’t shorten this, if we don’t go faster, we are in danger of becoming obsolete as individuals. That’s not the role of CISO, but the existing crop of CISOs.”</p>



<p class="wp-block-paragraph">But there is another problem that stems from within, especially in the technology sector. “There’s an overwhelming number of security product vendors out there. Our constant chasing after the latest shiny object really detracts us from just getting the job done. It’s a difficult issue because we all quite rightly look for new emerging technologies, but there’s so many of them. I cannot operate a bunch of single-purpose solutions in my organization – I don’t have enough people, I don’t have enough budget, and I don’t have enough time. We need to start looking at the interconnectivity of devices, vendors, and what I really think of as a fabric. We need a better integrated security fabric.”</p>



<p class="wp-block-paragraph">It’s a question of communication between devices. “Take the SIEM,” he said, “which was supposed to solve so many problems. You add a new process, or whatever, and suddenly, you’re re-baselining all over again. So, my SIEM, which was bought to be a problem solver, becomes a millstone around my neck.” The problem, he suggests, is that the vendors are not working together.</p>



<p class="wp-block-paragraph">His third concern is that security needs to become more resilient. By this he means more than just recovery – for Leach, resiliency involves the anticipation of problems so that they can be avoided or better recovered from. “Resiliency is more than just recovery,” he said. “When we talk about resiliency, people often think it’s just recovery from backups. But no. We need to anticipate failures. The attacks are becoming better, stronger and more specific. We need to be in a position to anticipate and prepare for what the next attacks are going to be like.”</p>



<p class="wp-block-paragraph">Between them, Intel’s Brent Conran and Cisco’s Chris Leach have painted a picture of the major threats to expect over the next few years, and best practices on how to handle them.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><a href="https://register.securityweek.com/2020-securityweek-ciso-forum-registration?utm_source=CISOFORUM&amp;utm_medium=banner&amp;utm_campaign=article" target="_blank" rel="noopener"><img decoding="async" src="https://www.cisoforum.com/wp-content/uploads/2020/09/300x250-CISO-2020-Virtual-banner.png" alt="" class="wp-image-506"/></a><figcaption><a href="https://register.securityweek.com/2020-securityweek-ciso-forum-registration?utm_source=CISOFORUM&amp;utm_medium=banner&amp;utm_campaign=300x250" target="_blank" rel="noopener">Register for the 2020 CISO Forum (Free for Security Professionals)</a></figcaption></figure></div>



<p class="wp-block-paragraph"><strong>Related</strong>:&nbsp;<a href="https://www.securityweek.com/ciso-conversations-mastercard-ellie-mae-cisos-discuss-people-problem" target="_blank" rel="noopener">CISO Conversations: Mastercard, Ellie Mae Security Chiefs Discuss the People Problem</a></p>



<p class="wp-block-paragraph"><strong>Related</strong>:&nbsp;<a href="https://www.securityweek.com/ciso-conversations-verizon-att-cisos-talk-communications-sector-security" target="_blank" rel="noopener">CISO Conversations: Verizon, AT&amp;T CISOs Talk Communications Sector Security</a></p>

    <div class="xs_social_share_widget xs_share_url after_content 		main_content  wslu-style-1 wslu-share-box-shaped wslu-fill-colored wslu-none wslu-share-horizontal wslu-theme-font-no wslu-main_content">

		
        <ul>
			        </ul>
    </div> 
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
