The theme of the RSA Conference this year is resilience, which applies well to the security industry as well as society as a whole. Both had to adapt to previously unknown, persistent threats over the past year. Maybe it’s just the pandemic lens, but there seems to be more reflection about lessons learned at this year’s event.

Among these lessons-learned talks: Angela Weinman, VMware’s head of global governance, risk, and compliance, and Jimmy Sanders, who leads information security at Netflix DVD, tackled three cybersecurity “hard truths” in a joint keynote address, and discussed how these truths can lead to more resilient security.

“We’ve got to zoom out, throw out, and reach out,” Weinman said, summarizing the three lessons learned.

Lesson 1: Zoom Out

Or, as Sanders described the first hard truth: “The security risk picture is out of focus.”

To prepare for and recover from threats, security professionals first must accurately determine potential risk impacts. If risk doesn’t drive security strategy — and spending — “we’re initiating projects, we’re investing resources using the wrong priorities,” Weinman said.

Security professionals’ strong desire to accurately predict risk “can cause us to be too conservative when predicting risk impacts and necessary treatment,” she added. So the solution is to zoom out, and use a wider-angle lens. “Think of the spectrum of impact, rather than a narrowly-defined scenario,” Weinman said.

The speakers used the pandemic as an example. Before 2020, most companies’ disaster recovery or related worst-case scenario plans only focused on top executives and other “critical staff” working from an alternate location for a month or two. And then COVID-19 hit, sending almost everyone home to work and access corporate networks and data remotely for at least a year.

“It turns out those who could pivot fastest last year were the ones who had the broadest plans, or who could mitigate by being the furthest along their digital transformation journey,” Weinman said.

Sanders used a chess analogy. Losing a rook doesn’t mean game over. Instead of protecting organizations’ environments like pieces on a checkers board, where every piece has the same value, “we must broaden our views and prioritize environments so we ensure not all environments are protected and viewed the same,” he said. “See the entire board.”

Lesson 2: Throw Out

The second truth, throw out, means that just because an organization has always done security a certain way, this doesn’t mean it’s the best way. Security processes, products, and even compliance requirements should be questioned and tested. And if they don’t work, or have become too cumbersome over time, it’s OK to throw them out and replace them with something better.

“I spend my time railing against legacy security practices and the lack of diverse voices within our security community,” Sanders said. “Witnessing the rise and fall of companies, products, and best business practices throughout my career has imprinted a deep belief within my psyche. That belief is that we, the collective we, must create an environment where the best ideas win. And what happens is this improves our security posture overall.”

This requires inclusion, and “allowing every voice at the table to be heard” so that the best ideas win, he added. “My company and peers cannot be great at security by sticking to outdated security practices,” Sanders said.

To put this concept into practice, Netflix started doing a proof of concept on a new security tool or technique every month. “What transpired from that is our team developed a resilient and nimble mindset that does not get worried when change happens,” he said. “Change is just a matter of course.”

Lesson 3: Reach Out

And finally, the third truth, according to Weinman and Sanders, is that security is a team sport and requires information sharing. “This applies at all stages of having a career in security,” Weinman said. “It can be a common misconception that because of what we do, we must work in individual secrecy … Personally, I wouldn't have been anywhere near as successful without the help of others. I still vividly remember the first help I got from reaching out to a vendor, very early in my career.”

Network with other security professionals, join cyber organizations, share best practices — “but also what went wrong,” Sanders said. “I lead the Emerging Technology Group for ISSA International, and our charter is to explore, document, and distribute information to the security community,” he added. “We want to do that so we can illuminate leading-edge and effective security practices and controls.”