CISOs play an important role in implementing the zero-trust strategy, but what are their responsibilities?
According to Veeam Software CISO Gil Vega, it's a combination of two things: strategy and simplicity.
“Primarily for me, the role of the CISO is about setting the strategy [with a simple statement such as] 'We are going to implement a cybersecurity program that assumes a perpetual state of compromise that we have people in our environment that shouldn't be there,'" Vega told SDxCentral.
By starting with a simple statement, it’s much easier to threat-profile the changing attack methods, implement zero-trust architecture, and understand the company’s business requirements and resources that employees need to gain access to, Vega noted, adding, "We can use zero-trust technologies like encryption, multi-factor authentication (MFA), identity and access management schemes that depend on network segmentation and point control."
Vega has been with Veeam for about two years. He previously worked for CME Group as CISO and managing director, and served as CISO and senior cybersecurity leaders in various federal agencies, including U.S. Department of Energy and U.S. Department of Homeland Security.
At Veeam, he is responsible for policy oversight, reporting to the CEO, and works with a team of security architects and the IT team to implement zero-trust architecture and other security strategies.
Retired Synchrony Financial CTO and Zscaler executive advisor Greg Simpson echoed that the best CISOs he has worked with are the ones who care about technologies and helping businesses move forward.
“I've been blessed to work with great CISOs who aren't just concerned with implementing the perfect security strategy, they're concerned with how do we implement the business strategy in a manner that is secure?” Simpson said. “That's a big difference.”
It doesn't make any sense if a CISO prevents everyone from logging into the company’s system just to keep the malicious actors out, he pointed out.
“The CISO has to really understand the technology to be able to understand what the company is trying to accomplish, so they can help deliver the business value in a secure way, rather than delivering the security strategy independent of the business needs, and independent of the business strategy,” Simpson said.
Education is Key for Zero-Trust AdoptionWhen it comes to actually implementing a zero-trust strategy, Simpson says, “The first step is education, second step is finding the right partners, third step is to have a great team."
Education should cover all layers of the organization starting with the board members and C-level executives. It’s important that the board and C-suite understand education is a critical initiative and support it “because there's going to be some changes and users don't always like changes,” he said.
Additionally, a CISO needs to make sure the board of directors understand the threat environment that the company faces and the implications of a significant breach, Vega pointed out. “It's not about spreading fear amongst our executives, or CEO, or our board, but it's bringing them along on the journey.”
If a CISO works for an organization where "there isn't a culture laid down by the CEO and the board around the expectations that the company should take on cybersecurity, then that's an untenable position to be in,” he said. “So for me, the communication is most important at the top of the food chain.”
Comments