Whether you're an aspiring cyber leader or looking to expand your current leadership role, The CISO Brief is here to provide you with a 'peek behind the curtain' into the dynamic world of cybersecurity. Join us as we explore essential strategies, tools, and leadership skills to help you lead in these rapidly shifting times.
In the fast-paced field of cybersecurity, new CISOs have a small window to demonstrate their credibility, articulate their strategy, and ultimately, demonstrate their value. Gone is the assumption that they are proficient in the day-to-day skills required for running a cybersecurity department, including managing operations, architecture, vendors, compliance, and risk, as well as keeping up with the latest technology.
To help you succeed in your role, we created a field guide based on insights gathered from 50 years of combined cyber experience and more than 28 CISO executive transition labs conducted across major industries, including banking, container, public sector, and energy and resources.
CISOs face a multitude of challenges that demand their attention. These challenges may include securing outdated IT systems, addressing disunity among staff within the cyber organization, and improving relationships with internal clients. CISOs may also need to focus on enhancing critical technologies that protect the company or managing vendor-related issues. It’s crucial to note that the extent of these demands may not be immediately evident when considering a CISO position.
The first 30 days are critical to getting to know your business. Act as a customer yourself and ask questions about your own purchasing behavior. Would you change anything as part of that experience? Talk to customers, store managers, and employees to gain insights into how your company makes money and why certain decisions are made.
In addition, meet with internal stakeholders across corporate functions such as IT, internal audit, human resources, and privacy. Show empathy for stakeholders, especially if you are joining an organization that may have underinvested in security. It's time to build relationships and learn. It's not yet the time to make recommendations and educate.
Show empathy for stakeholders, especially if you are joining an organization that may have underinvested in security.
Next, meet your team for insights into the current culture. A high-performing team is diverse, highly capable, and motivated to achieve a central purpose, and operates in an environment where they can thrive.
Meet with your team to understand roles, capabilities, and career aspirations.
Through these discussions, you will learn about unneeded meetings, underfunded projects without defined value or drivers, time-consuming reports that go unread, and underutilized technology that is expensive to license and run. This exercise can also help you identify a few quick wins that will drive immediate value to the business with nominal costs.
Focus on delivering initial projects and quick wins and, if required, rearchitect the CISO organization. During this period, it is important to connect strategy and funding to the overall review to assess the strengths and weaknesses of the cybersecurity function. Take the time to review the organizational structure and determine if the function is aligned to the organization's strategic plans. Assess if the team can lead that growth, and work with stakeholders to focus on what is most important.
During this period, the focus should be on resolving organizational issues that can be addressed within a year. This includes defining a strong three-year cybersecurity strategy and roadmap to deliver cybersecurity in the future, enabling the business, and establishing new organizational and governance models for security overnight. As a CISO, it is important to delegate tasks and responsibility so you can focus on strategic initiatives and manage risks.
In our next issue, we'll focus on the topic of talent, its challenges, and the crucial role it plays in early CISO success.