SUBSCRIBE

SecTor 2015: Take advantage of changing threat landscape, CISOs told

A rapidly worsening threat landscape should be leveraged by CISOs to justify overhauling their operations centres, a Canadian security conference has been told.

Kristin Lovejoy, keynote speaker at the The CISO of Bombardier on Target, Sony and the changing nature of risk

For example, she said IT security shouldnโ€™t fear cloud computing, which allows organizations to create a pattern of infrastructure, wrap security controls around it and then replicate in a centralized way.

โ€œYour job is not to stand in front of cloud butย  to figure out how to enable the organization to rapidly and radically adopt the cloud not just for economics but to improve the overall security posture,โ€ she said.

Similarly, CISOs need to embrace agile software and business development processes by making sure security teams are advising on risk.

Donโ€™t waste time worrying about millennials who seem to ignore security policies, she said. Instead use them โ€œas an opportunity to radically change the way you approach security.โ€ For example, divide employees into blocks of users, each with a separate security policy: Privileged users have to use corporately-supplied devices, general users can bring their own.

But arguably her central message is that IT security teams have to create a better brand. โ€œYou donโ€™t want to be โ€˜The House of No.โ€™ You want to be known for innovation. โ€˜My job as a security team is to participate in the creation of innovation with confidenceโ€™ โ€” Something hokey like that. Define a mission statement. Define yourselves as partners and advisors and sources of dependable and simple information.

โ€œThe reality is business folks want you to be your partner but donโ€™t know how to talk to you.โ€

Also, she urged CISOs to talk about risk in business terms to managers and executives. So, for example, let them know there is a risk of forced code compromise in an application that will steal customer information. Or in a medical device that could kill a patient.


Related Download
Can we save the open web? Sponsor: Acquia
Can we save the open web?
Join the creator of Drupal, Dries Buytaert, in a discussion about the webโ€™s evolution, how we can put the power of the internet back into the hands of the people, and how you can prepare your organization.
Register Now


Tech Jobs

Categories