Chief Information Security Officers (CISOs) face a complex network of demands and challenges, but five themes stand out to Dell'Oro Group Research Director Mauricio Sanchez as the most pressing issues on the modern CISO's plate.

First, CISOs understand that while the COVID-19 pandemic has been a crisis, it's also presented an opportunity. Both the shift to remote work and the acceleration of enterprise digital transformations have surfaced "thorny security problems to solve," Sanchez explained.

Pandemic-induced disruption has also paved the way for new ways of looking at security problems and has sparked post-pandemic security investments that wouldn't have been otherwise made, he added.

Enterprise Users Make Security Complex

CISOs are also conscious of the complexity brought by enterprise end users. Sanchez describes enterprise users as "humans that flourish off three Cs: curiosity, convenience, and comfort."

Curiosity can lead to users making unexpected moves that open security holes. Employees also have a tendency to work around security measures they view as an inconvenience. "Passwords on a post-it note, anyone?"

And the comfort of working at home is hard for employees to give up in a post-pandemic world, but remote work brings "enormous security implications compared to the traditional office environment," Sanchez explained.

But rather than trying to change user behavior, Sanchez recommends CISOs constantly evolve and look for new security controls "that match the current user landscape and behaviors."

The Threat Landscape Moves Fast

The third item on most CISOs' minds is that the threat landscape is not only growing more brutal every day, but it is innovating faster than enterprises can fight back.

"Not only has the internet threat landscape gone from being a tough neighborhood to open warfare, but the threat actors are moving at a blinding speed," he explained.

Part of the solution is focusing on security fundamentals, Sanchez suggested, such as understanding what exactly needs to be protected and building a strong security plan based on those needs.

Vendors Are a Double-Edged Sword

CISOs are justifiably weary of security vendors, according to Dell'Oro. There are hundreds of security products fighting for attention, but the flurry of new products creates "a dangerous pitfall," Sanchez said.

Oftentimes these vendors push flashy marketing to convince CISOs a product is necessary "even though the reality could be the opposite," he explained. "Unless a CISO is working off the knowledge of what needs to be protected in their enterprise and a robust security plan, a CISO can’t assign security value to any new product."

Despite caution toward security vendors, relationships with trusted vendors play an essential role in security strategy. "Bi-directional communication is vital to help vendors develop security controls and technologies that benefit the enterprise," Sanchez said.

Zero Trust Is a Strategy, Not a Product

Sanchez identified a consensus among CISOs that zero trust, arguably the hottest industry buzzword, is a valuable strategy and not a product. This theme is especially relevant considering the slew of security vendors applying that buzzword to their products in the hopes of selling a product inaccurately named after a strategy.

This issue showcases how easy it is to confuse strategy with tactics, Sanchez said. "A CISO that buys a “zero trust” product from a vendor may think they are covering all necessary security bases. But, the reality is that this CISO is stuck in the tactics that may or may not align with the strategy that the enterprise needs to follow."

To that point, he argues that CISOs without a coherent strategy are, at best, doing nothing more than blowing IT budgets on products that "minimally improve" the organization's security. At worst, they create an empty sense of security that will eventually lead to the enterprise being compromised, Sanchez said.