Several CISOs and security executives joined the Industry Leaders Forum CxO Round-Table discussion and shared their insights on the question: if there was a cybersecurity failure on the CISO's part, should the penalty be prison?
“Oftentimes as CISOs, we are trying to install the landing gear while the plane is flying,” said Ron Layton, VP of cyber fusion and asset protection at Sallie Mae Bank. “Responsibility is oftentimes spread out among the organization, but we have seen some very high-profile CISOs find themselves in hot water.”
Layton, who previously served as deputy assistant director for the United States Secret Service, noted that there were a number of notable cases where security leaders had been held accountable for breaches or response failures.
While CISOs do bear some responsibility and have, in some cases, paid a price, "the question is whether the criminal justice system will levy fines against that, I actually don't think so,” he added.
ServiceNow CISO Ben de Bont echoed that “a successful security program is not going to be solely dependent upon a CISO or security team.”
It depends on how the security enforces best practices and strategies across the whole organization, and also the technologists, developers, and others who are responsible for deploying those practices, he said. “If you take the approach of just blaming the security team, you're blaming the one group that is absolutely concerned about security all day long.”
He used Amazon as an example. If there was a breach in Kubernetes in AWS, the GM of Kubernetes would get fired but not the CISO, “because security needs to be everybody's responsibility,” de Bont said.
In addition, there is no criminal statute for cybersecurity negligence such as using a weak password, said John Kindervag, SVP of cybersecurity strategy and group fellow at ON2IT, who is the author of the original zero-trust research.
When punishing CISOs, “you're blaming the victims and not focusing on the actual people doing the criminal activity,” Kindervag said. “CISOs are generally trying to do their best. It's an incredibly difficult job.”
“There are things we can do to create friction for the attacker, and we want to do those things strategically. But to try to just hit everything over the head with a hammer is just counterproductive,” he added.
The proposal will make the cybersecurity skill gap even worse, Ciena CISO Ryan Hammer pointed out. “I think wanting criminal charges against a CISO or security organization is going to make it even more difficult to find folks who are willing and excited to take the job.”
Even if CISOs do their best or work 80 hours a week, breaches can still happen, “because we can never get these organizations 100% secure,” Hammer said. “The best we can do is reduce risk to a threshold that the company can tolerate and that we can do reasonable and appropriate efforts to protect the interests of our customers, of our shareholders, and all the other stakeholders.”
Comments