Some might think that ‘no’ is the only word in the CISO vocabulary — the cybersecurity department has been notoriously characterized as a stifler of innovation.
But with the cybersecurity landscape growing ever more perilous, there are many legitimate instances where “no” is the right answer.
Industrious CISO, however, can use this to their advantage: While it may seem counterintuitive, measuring why — and just as importantly, how often — they say no can help them build out a strong security culture and bolster their department’s budget and initiatives.
Security leaders practicing this type of metric of no “want to be viewed as the ‘Department of Yes, and…’ where they are fully leaning in to support business objectives,” asserts Clarke Rodgers, director of enterprise strategy at Amazon Web Services (AWS).
Moving beyond the ‘department of no’The clichéd view of IT security personnel are teams sitting in a basement or tucked away in a back office, only called upon when bad things happen. The CISO, similarly, has been viewed as a firefighter rather than a proactive business leader that others listen to.
The reality is that C-suites and boards often don’t ask security questions — or if they do, they’re often quick, superficial ones, Rodgers pointed out. In these scenarios, if CISO do say no, there isn’t a strong enough culture in place to stop so-called shadow IT, when employees use tools without the security department’s knowledge.
But, as Rodgers noted, “you can’t blame security for wanting to protect the organization and mitigate risk, because that’s what they’re there for.”
The ‘metric of no’ requires, well, metricsTo mitigate — and ideally eliminate — this perception, CISO must provide tangible numbers. The metric of no must be a data-driven practice, Rodgers emphasized.
“Tracking is everything,” he said. “If you’re just pulling stuff out of the air, you’re not going to convince everybody.”
Security leaders must have mechanisms in place to collect and analyze how many times they are saying no and why. This can help them differentiate the good no’s (obvious scenarios such as shutting down firewalls and getting rid of passwords because it simplifies the software development process) from the bad no’s, said Rodgers.
Those bad no’s may be prompted because an organization doesn’t have adequate security capabilities and a strong security culture in place to mitigate risk.
Over time, this practice can help CISO quantify the dollar value of the no for senior leadership. This can help them build a stronger cybersecurity backbone, said Rodgers, and they might even be able to convince CEOs and CFOs to increase department funding because they have statistics to back up why they keep saying no to legitimate requests.
“It’s a risk-based conversation about dollars and cents,” said Rodgers. “It’s about PNL (profits and losses) versus a bits and bytes vulnerability conversation.”
Ideally, this can help CISO be viewed as active business leaders who mitigate risk, and functionalities and features can more quickly move into production.
Getting cybersecurity high on an organization’s agenda is increasingly a must-have imperative, with the Securities and Exchange Commission (SEC) passing new rules requiring public companies to outline their practices and mitigation strategies, as well as their board’s involvement in (and knowledge of) these processes.
“The first question an organization must have when thinking about a new piece of software or new service is ‘What is the security risk?”, said Rodgers. “If they think about it upfront, they will have a much easier time getting things built, released on time, and will be as secure as reasonably possible.”
Undoubtedly, it’s an iterative process, he points out: “This is not an overnight activity.”
Security and line of business owners working togetherSecurity leaders and developers have long butted heads. Line of business (LOB) owners want to increase the speed of code releases to achieve better time to market and meet revenues set by CEOs, considering security an afterthought or an annoying impedance.
On the other hand, when security teams discover issues in code, they block rollouts and force expensive reworks. Their directive is to securely release code and maintain that security throughout the product life cycle, Rodgers explained.
To move from that ‘‘no’’ to ‘‘yes,’’ CISO should show LOBs what the no actually costs in terms of potential lost revenue, he said. This makes security objectives clear (i.e, ‘‘we must do X, Y, and Z’’) but flexible (‘‘let's explore any options we can’’).
Metric of no data can then be used to get funding and buy-in for the following:
- Tooling teams that build and maintain continuous integration/continuous delivery (CI/CD) pipelines with security checks built in so that developers get security feedback at every stage of the software development lifecycle (SDLC).
- A security culture incubation program where everyone has responsibility.
- A training program a ‘security ambassador’ embedded into every product team.
This gives LOBs control over product ownership, speed of release and security, Rodgers said. Security is built in early, saving expensive rework and ‘night of product implementation’ security blocks. He emphasized that security should be addressed at ideation, when the first bits of code are being written.
“Progressive-leading CISOs are there to support the business,” said Rodgers, “not block the business from doing things that will support their growth.”
The ‘metric of no’ more important than everThis ‘‘metric of no’’ process is ever-critical with the rapid adoption of generative AI tools, Rodgers pointed out.
From a security standpoint, he compared AI to the introduction of cloud a decade or so ago. Business leaders wanted to migrate as quickly as possible, but many CISO blocked this process because they didn’t understand the cloud, and it seemed far too risky.
“There was a lot of friction there,” said Rodgers.
As a result, security was often circumvented, and teams had to “bolt on security after the fact.”
Other security leaders, however, took more objective stances, he pointed out. They learned the benefits of the cloud early on and supported their business throughout the process to ensure that anything built or deployed in the cloud met security standards.
“The new cloud is anything that has generative AI in it,” said Rodgers. As such, CISO must support its implementation and have risk-based conversations to get the resources needed to secure it.
If they take this stance, security departments can be seen as an asset, accelerator and risk mitigator.
“Saying ‘no’ and being the ‘department of no’ are two very different things,” said Rodgers. “But CISOs have an opportunity to use ‘no’ in terms of business risk and opportunities to justify increased security and resilience while maintaining the pace of innovation that modern businesses demand.”
Comments