E D I T O R ' S Q U E S T I O N
Foremost , CISOs need to embrace their dependency on others – on the CIO to implement policies , on legal for coverage during an incident , and on the CEO to establish tone at the top . The CISO can accomplish very little unilaterally , and the ability to develop relationships matters more in the role than in any other skill set . If you want to manage risk , you ’ re going to need allies .
You need to find trusted authorities in the fields where you ’ re not an expert and listen to their concerns . Understand their perspective and see the world through their lens . You ’ ll likely uncover risks you didn ’ t even know to look for . We ’ re all unwitting occupants of a digital battlefield being contested by nation-states , criminal gangs and other bad actors . None of us succeed on our own – we ’ re strongest when we join with others for a collective defence .
We often hear that people are the weakest link in our chain – that they ’ re our greatest risk . But if that ’ s true , why don ’ t we hear about more CISO / HR collaborations ? Why aren ’ t more CISOs reaching out and having meaningful discussions about how they can partner with workforce leaders to incentivise good security behaviour ? Our field still defaults to technical solutions , but sometimes the best solution needs an uncommon partnership .
CISOs must ensure information sharing and collaboration flows through their organisation , to be one step ahead of cybercriminals . Everyone , enterprise-wide , must be educated right from day one on the potential risks . Security should ultimately enable the right people to do the right thing at the right time . But the flip side to that is preventing the wrong people from doing the wrong thing , too . Discussions need to centre around three key elements : identity , access and asset management .
Today ’ s workforce is complex , with non-employees making up nearly half of corporate identities . With identity often being the make or break of any type of attack , CISOs have a vital role to play in better safeguarding identities , both machine and human , employee and non-employee .
Enterprise complexity is quickly outpacing human capacity for understanding . Through the smart application of AIenabled identity security technologies , CISOs can put the right measures in place to ensure visibility . Having centralised visibility is crucial for organisations to deal effectively with any suspicious behaviour well ahead of a breach occurring .
One area that doesn ’ t regularly come up in discussion , but is increasingly becoming a frontline target , is HR . It ’ s not necessarily that attackers focus on HR-specific systems , they ’ re just looking for systems with sensitive information on them ¬– and HR holds plenty . Knowing they ’ ll be looking for data they can monetise , hold to ransom or use for intelligence , CISOs must work more closely with HR leaders to prevent and detect potential threats .
To stay ahead of cyberthreats , CISOs must ensure they collaborate and engage with all departments – especially those that they have traditionally placed less focus on . With the right technology in place , CISOs can work effectively with the wider business to implement a multi-layered approach to security . �
REX BOOTH CISO , SAILPOINT
www . intelligenthealth . tech 27