The CSO's failure to lead

Talk to any information security professional over the past decade about a number of their greatest perceived challenges when it comes to doing their job. More often than not you'll hear about how their organization's business leadership didn't provide them the support and space they need to secure their organizations properly. One way you'll hear this is when it comes to the lack of budget. Another way you'll often hear this expressed, is as security "doesn't get a seat at the table."

[How to optimize your security budget]

There's no doubt a large number of security teams often do feel left in the lurch. "Many businesses view cyber security as an IT problem and not a business problem,"says Brian Honan, CEO at Dublin, Ireland-based BH Consulting. "When you consider how dependent businesses are on IT, and more importantly on the information on those systems, businesses need to realize cyber security truly is a business issue,"Honan says.

But, ultimately, that convincing comes down to the responsibility of the IT security leaders. They are the ones, after all, responsible for convincing management of the investments that need be made. And those we interviewed tended to agree. "I reject the premise that a barrier to security is a 'lack of security leadership from business executives.' Business executives owe it to their organization to allocate resources in the best interests of the business. If the security team can't make the case that involves investment in security, then that's on them - not the business executives. I'm saying that's a total copout,"says Mike Rothman, an analyst at the IT security market research firm Securosis.

Many others agree, and echo the argument that in many cases it is the CSO's fault for providing a lack of security leadership. "I worry about CSOs who claim lack of security leadership is what is causing their security programs to fail. The CSO by definition is responsible for security leadership in the organization, they are the one responsible for ensuring senior business people, and indeed every user in the organization, understands the importance of information security. If the CSO finds the organization is not responding to his leadership, then that CSO is the wrong person for that organization or indeed that organization may be the wrong one for the CSO,"says Honan.

The deaf ear of the business

To be sure, some business leaders do turn a deaf ear to security risk management. Part of the issue may be due to the hierarchy in place. Recently, Javvad Malik, security Analyst at The 451 Group conducted a study analyzing shelf-ware and was surprised to discover that, consistently, CISOs feel they are, and often actually are, ineffectual at managing information security risks in their organization --and it's not all their fault. "The findings were rather consistent in stating that security leaders, like CSOs or CISOs or security directors are wholly ineffective in actually managing security within organizations. The general theme that surfaced was that these people are first not really true C-level executives in the majority of the cases. They actually report into a CIO or a CFO,"Malik says.

[The sorry state of cybercrime]

That's unfortunate, as it shows too often the CISOs don't get a seat at the table, and when reporting to CIOs there is a strong inherent conflict of interest between information security and IT projects.

Fortunately, the tide may be turning, as we reported in CSO magazine's annual State of the CSO survey, forty-six percent of the security decision-makers surveyed in the report believe that their own organizations have placed more value on risk management in the past year while sixty one percent expect company leaders to value risk management more in the year ahead. Survey results suggest the larger the organization the more value leadership places on risk management.

What's more, nearly three quarters (seventy four percent) of the security professionals we surveyed have seen an increase in the amount of time they spend advising senior executives and other top business decision makers on security-related matters and 79 percent expect their time spent in that area to increase during the next three years.

Now, with that attention, it's important the opportunity isn't squandered, and use this time to build credibility. "Security can help the business reach its goals, and part of building that credibility is not playing Chicken Little, and realize that not everything can be a top priority. Businesses look at specific issues, determine their potential impact on the bottom line, and what needs to be done to manage the issue, and whether or not it is actually worth dealing with the issue,"says Honan.

[Survey: execs clueless, security pros unsure in fighting cyberattacks]

And that's where the real value and CSO leadership comes into play --helping the business decide what areas need the most effort and risk reduction --and showing the way to get there.

Join the CSO newsletter!

Error: Please check your email address.

Tags managementBH ConsultingbudgetsNetworkingsecurityCISOCSOSecurity Leadership

More about CSOindeed

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by George V. Hulme

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts