
Cyber Security Sauna · 2024-01-03 · 38 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
CISOs face a critical challenge: justifying continuous budget increases while paradoxically making themselves less visible through effective risk prevention. Matthew Rosenquist (Eclipse IO CISO) and Christine Beharazco (Secure CISO) explore how security leaders can bridge the gap between technical capabilities and C-suite business priorities. The key is audience-specific communication - discussing confidentiality with HR, data integrity with finance, and system availability with operations. Rather than adopting an adversarial compliance posture, successful CISOs build empathetic partnerships across departments by first understanding what each function needs to accomplish. Both guests emphasize that the traditional model of requesting 20% annual budget increases is unsustainable and will trigger organizational resistance. Instead, forward-thinking CISOs should identify opportunities where cybersecurity becomes a competitive advantage or revenue driver - from third-party vendor evaluation to product differentiation. The SEC's recent enforcement actions against Uber and SolarWinds signal that boards now hold CISOs and executives accountable for material cybersecurity disclosures, fundamentally changing how the role is valued and perceived. This shift requires CISOs to expand beyond attack prevention and regulatory compliance to become strategic business enablers.
Tailor your message to what each function cares about most: HR prioritizes data confidentiality, finance prioritizes data integrity (preventing unauthorized changes), operations prioritizes system availability. Show concrete examples of breaches in similar organizations within their sector to help them connect abstract risk to business impact.
If the CISO does their job exceptionally well, bad things don't happen, making it hard to justify continued large budget increases. Conversely, if breaches happen frequently, it raises questions about throwing more money at a failing function. This creates a structural sustainability problem that requires CISOs to shift from pure cost-reduction to value-creation models.
Yes. CISOs can partner with product and sales teams to identify market segments that value security, such as business travelers valuing VPN features, or vendors can be selected based on security posture, making security a differentiator. When security contributes to revenue, the CISO moves from cost center to profit center status.
The SEC investigates whether companies materially misrepresented cybersecurity risks to investors in required filings. While CISOs won't go to jail for simple mistakes, executives and boards are now accountable for disclosing material cybersecurity events and risk management capabilities, raising the stakes for how CISOs communicate security posture to leadership.
The CISO's role is to help the organization achieve its strategic goals - such as digital transformation - in the least risky way possible, not to block innovation. This requires understanding business objectives first, then designing security and resilience into transformation initiatives as an enabler, not a blocker.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely useful practitioner insights - particularly the 'if you do your job perfectly you can't justify the budget' paradox and the CISO-as-profit-centre framing - but most of the runtime is consumed by agreeable platitudes about speaking business language and aligning to goals, which any mid-career security leader already knows.
if we are really, really good at what we do, bad things don't happen. And if bad things don't happen, why am I investing more money in you?
every dollar made from that tier, that CISO can say that's attributed back to security
The airline VPN upsell anecdote as a lived illustration of CISO-as-profit-centre is the most original moment in the episode; the rest recycles well-worn CISO communication advice (speak their language, empathy, align to business goals) without genuinely challenging any of it or offering a contrarian frame.
CISOs who only focus on regulatory compliance and um, attack prevention, they're not going to survive
they had to have had the vernacular to be able to sell that. Right. They had to understand marketing strategies. They had to understand upsell and margins and good, better, best
Both guests are credible working CISOs who draw on real operational experience - Christine's CEO-background observation about how the CISO title signals 'what did I do?' is an authentic practitioner insight - but neither is identifiably operating at a recognisable company at scale, limiting the weight their claims carry.
I advise CISOs, and then I also get brought in by CEOs and boards to come in and evaluate security
when you ping people, they were like, okay, yeah, so let's talk about things now. When you ping people, they were like, what did I do?
A handful of real data points (the 9 - 20% annual budget growth figure, the SolarWinds/Uber SEC cases, the 40% time-allocation heuristic) give the episode some grounding, but the vast majority of advice is delivered without named organisations, internal metrics, or documented outcomes from the guests' own tenures.
it's typically between 9 and 20%. The uh, estimated for the next five years is about 20% increase year over year
two big cases, one for Uber and the one that was currently announced towards solar winds
The host makes a couple of smart pivots - flipping 'speaking their language' into 'listening their language' and pushing back lightly on the doom-and-gloom framing - but broadly accepts every claim without probing for evidence, and the SEC ruling thread is dropped quickly despite being the most substantive policy territory in the episode.
is there a component here of sort of listening their language as well?
you oversold the dark clouds there a little bit
Computed from the transcript - who did the talking, and the words that came up most.
CISOs find themselves at the forefront of safeguarding sensitive information, ensuring regulatory compliance, and protecting their organizations from constantly evolving cyber risks. Today, we are joined by Cybersecurity Strategist and Eclipz.io Inc. CISO Matthew Rosenquist and WithSecure CISO Christine Bejerasco to discuss why making senior leadership and the board clear on the value that CISOs bring to the table.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hi everyone, and welcome to the cybersecurity Sauna. My name is Janne Kauhanen and I will be your sauna Mayuri and the host of this podcast. Thank you for joining us for another session where we sweat out the hot topics in security. Welcome to our listeners and, uh, be sure to follow us on Twitter IberSauna. CISOs find themselves at the forefront of safeguarding sensitive information, ensuring regulatory compliance, and protecting their organizations from constantly evolving cyber risks. Today we're joined by security strategist and Eclipse IO CISO Matthew Rosenquist, and with secure CISO Christine Beharazco to discuss why making senior leadership and the board clear on the value that CISOs bring to the table, uh, not just in terms of organization cybersecurity, but in the broader context of its business success is more important than ever. Sprinkled, I hope with a few pain points. Welcome.
Speaker B: Thank you.
Speaker A: Thank you. So how do CISOs effectively communicate the value of security initiatives to non technical stakeholders?
Speaker C: Well, it's an interesting challenge, um, because it is important for CISOs to work with everyone in the C suite. And that could be, you know, your head of hr, your head of it, some head of a product or a service that the organization has. And often, um, cybersecurity is seen as an overhead, as a burden. The first axiom in our industry is cybersecurity is not relevant until it fails and then it's relevant and people are interested. But we need to have that cooperation well before that. And the way we do that is we need to communicate in terms they understand, in terms that they use in their business. And that conversation, the discussions about security risk have to be relevant to them. And I'll give you an example. If I sit down with the chief human resources officer, I'm going to be talking with that person about the confidentiality of their data. They've got data, they want to keep it very, very confident. That's their worry. And if I ask them, okay, would you rather have a data breach or your HR system down for two days? They'll say, take the HR system down for two days. I don't want a data breach. No, no, no, no, no, no. Okay, great. If I go to finance and I have the same conversation, I'm not going to really be talking about confidentiality as much. Sure, it's important to them. But the one thing that the finance people don't want, they don't want somebody to move a decimal somewhere. So it's the integrity of that data. Don't let anybody change my Numbers. So if I ask would you rather have a data breach or would you rather have your systems out or would you rather have somebody be able to modify. They know what they want. So that's the value security would bring to them. And every organization, including the board and the CEO, there is a different nuanced conversation that you can have about the value proposition cybersecurity brings to the table. And in reality we bring all those we do confidentiality, availability and integrity. But you got to speak to your audience if you want value to resonate. Resonate.
Speaker B: And I actually completely agree with that. I mean when it comes to the executive team m talking the language of business outcomes resonate a lot with them. Like on the level of reputational damage or on the level of um, availability system uptime that's valuable for them. When it comes to the non technical audience, um, like for instance HR or finance, as Matt mentioned, uh, speaking their language is very valuable and adding data when it comes to for instance incidents that happened to their area, that really hits the point home. I mean even if a breach hasn't happened yet, and then comparing that for instance to an external organization, maybe similar to us, for which a breach happened because of certain incidents, and showing them that these are actually also the incidents that are happening with us internally, it really opens up their eyes because there is already this internal thinking, for instance of different people that of course they want to do their job well and of course they want their jobs to be as de risk as possible. They just don't seem to be able yet to bridge that gap that okay, this cyber risk that you have is actually going to manifest into something that would really be bad for that area. And it's in speaking that language and showing to them like what is the reality of that on the ground and what are the data that we actually already see inside our organization that shows that that could potentially manifest. And it hits home every time. I mean the thing that they then ask is okay, but I have still this priority, but maybe this is something that we can do next. And then the work starts to cascade to other people in the organization. So that is quite effective.
Speaker C: And over the long term you really want to build that, that relationship with them. So it's important that they start to understand a little bit. They'll never be a security expert, but for them to start understanding some of the more nuanced aspects is really beneficial. Because if you go to that HR person, that executive, and they don't have an experience with cybersecurity, chances are in their Mind that they look at you and go, okay, your job is to prevent risk. All right, just keep me protected and do whatever you need to do. It's an opportunity at that point to go, yes, we are going to work to protect you. It will never be 100%, it would be so expensive or burden your people or system.
Speaker B: Mhm.
Speaker C: That's just not possible. So we're going to protect you as much as it makes sense, knowing that something might happen. But we're also going to have means to detect when bad things happen and we're going to make sure that you can recover quickly and get back up and running. And you know, as Christine said, being able to show, especially within your sector, to say, hey, you know, this HR group in your sector, they were hacked and data was released and they were down for two weeks and all this data got published. Being able to use those as examples to say we can help mitigate the risk of bad things happening and then we can also reduce the impact if something bad does happen. So there's going to be a plan. It's not just, we're just going to try and stop it. We're going to need your help as a partner to make sure we have this comprehensive plan in place so that we can manage the overall risk.
Speaker B: Hmm.
Speaker C: Mhm.
Speaker A: So you're talking about sort of speaking their language, but is there a component here of sort of listening their language as well? I mean, we're asking them to care about our stuff. Does that mean that we then sort of need to care about their stuff as well? Like sit them down and like, you know, what do you want? Like what are your concerns? What are you trying to accomplish in your sort of neck of the woods and then sort of try to figure out if there's anything you as a CISO can do to help that that
Speaker C: level of empathy is absolutely required.
Speaker B: Yes.
Speaker C: Right. If you're that ciso, that's just going to be that cop, the policeman, I'm going to tell you the rules and you just obey. And if you don't, I'm going to hit you with something sharp. Um, you're not going to get very far and you're not going to get that long term collaboration. They may fold the first time and do what you need to be, but there's going to be resistance down the road. It will not work out well.
Speaker B: And they might even hide from you,
Speaker C: they may work around you intentionally. Let's be very clear, they may, you know, completely, uh, undermine what you're trying to do. And I'VE seen that happen so many times with CISOs approaching it in a very antagonistic way. Whereas if it's empathetic and every CISO can learn something about HR and IT and finance and everything, it's an opportunity for us to learn. And we need to, if we're sitting in the big chair, which we've been asking for, right. To, uh, move up from that cybersecurity director to that CISO position. It comes with responsibility. Responsibility and understanding how the business works. You have an opportunity to learn from those executives. Learn it, because that will shape your ability to give even more value to the organization.
Speaker B: Because the thing with that building on top of what Matt said, uh, the moment you get the title of ciso, it's not actually a very pretty title. There's already something that you're the cop that whenever you ping somebody, I mean, I used to not be a ciso, so in my previous role I was a CEO. And when you ping people, they were like, okay, yeah, so let's talk about things now. When you ping people, they were like, what did I do? So, um, there is already that. That comes with a title. So I mean, the empathy. Exactly. That you will do. And it's really about understanding what the organization needs to do first. Because the organization doesn't exist for a cybersecurity function. The cybersecurity function exists to support the organization. And therefore we need to understand what are then the processes, the different areas, the different functions that the organization has and needs to do so that we can help de risk it, so that we can help secure the organization. And it's in understanding that as a ciso, that you can become successful and you can truly integrate yourself into these different functions.
Speaker A: Okay, Matthew, you're already talking about how, you know, CISOs are moving up in the world and they're, you know, getting those leadership, uh, team positions now, C level positions. Um, how else has the seesaw role evolved? Like, what are some of the new challenges that seesaws are facing these days?
Speaker C: Well, okay, I hate to be the bearer of bad news, but there are dark, dark days coming.
Speaker A: Are there?
Speaker C: Um, how dark, how dark can it get? The absence of all light? No. Um, you know, our industry, again, we're seen as an overhead, right. Um, and we create friction, we incur costs. We're not a cheap organization per se. And when you look at year over year, security isn't one time investment. You have to invest. Our industry is constantly dealing with better attackers. Um, new technology infrastructures that we then have to protect so the technology environment is constantly growing. You have a constant churn of new employees and third parties and vendors and suppliers that you have to deal with. So every year security organizations typically ask for a greater budget. And if we look back over the past few years, it's typically between 9 and 20%. The uh, estimated for the next five years is about 20% increase year over year. Okay, now if you think about it, you're the CEO and you've got your profit centers, right? They're the ones making money, they're the ones you love. You know, that's where you invest. But then you've got your cybersecurity that keep asking for 20% bonus budget increase every single year and they're not contributing anything to the bottom line. There's a cliff there that eventually the C suite will go, no, enough. We can't keep investing in this, right? And we almost are our worst enemy. And I'll say that because if we are really, really good at what we do, bad things don't happen. And if bad things don't happen, why am I investing more money in you? Bad things don't happen to us. So if we do our job really well, it's tough to justify, it's tough to see the value. But then again, on the other hand, if you're really, really bad at what you do and bad things are happening all the time, again, why would we throw good money after bad? So no matter where you on the spectrum, justifying the value of cybersecurity is very, very difficult. Especially when you're asking for more and more money and you are potentially impeding organizations more. We see a lot more organizations having to do post release patch management. Where do those engineering resources come from to do that? Well, it's the engineers that are working on the next version of the product and you pull those out of their work now you're delaying your next product, your next version, your next moneymaker, right? So again, we are in a tough position and we have to find a new gear, take it to the next level to be able to show or deliver more or better kinds of value. We have to, there is a cliff coming and companies will start to resist and not give you that money that you need. Um, and then it just goes downhill from there because you're going to start having incidents more and you're not going to be in a good position. Right. People are going to blame you.
Speaker B: But the beauty of that one though, this is a dark beauty. But um, the beauty of this one is that uh, since many different organizations are opening up to the need of having more cybersecure partners as well. Then when, for instance, like as a ciso, when I evaluate uh, third party organizations to become partners, for example, when it comes to vetting people, uh, in hr, for instance, or when it comes to payroll, when they end up in the shortlist, one of the things that we evaluate them for as well is that how secure is our data when it comes to their estate and it translates to their cybersecurity investments. And we have already said no to uh, vendors that actually don't make the cut. So as a ciso, if you think a little bit more strategic enough and then go towards a little bit more towards the sales part of your organization and maybe take a look at where are the areas that we are not able to sell so much more. Like we don't seem to have any competitive advantage because of xyz. And perhaps that's an area that cybersecurity could make a difference for the product or the service that um, your organization has. Maybe the conversation could start heading towards that direction. Because I have also heard from organizations where, um, the cybersecurity capability, uh, that they had became a competitive advantage and they were actually able to do even more business because they had a cybersecurity capability. I mean, obviously for us it's a mandatory requirement for many different things, especially when you're working with the finance sector. They are quite cutthroat when it comes to third party risk management. But there can definitely be advantages. Uh, but it needs investment. And once the C suite understands this and the CISO of course is able then to articulate what that translates into the cybersecurity investments, then perhaps that could potentially be the future.
Speaker C: I think it absolutely will be. In fact, that's part of my predictions for the next three to five years is we are going to see those CISOs who only focus on regulatory compliance and um, attack prevention, they're not going to survive. The CISOs that start to expand out and look for opportunities for competitive advantage, that's going to be important. Look for value add and even in some cases, right, you can add to the bottom line. We're talking organic revenue to the companies. Um, actually the last time I flew out here, uh, the last leg I was on one of the airlines here, one of the regional airlines and I was looking and they offer, you know, uh, you've got wireless on the plane and if you want to send text messages, it's free, just connect to the WI fi and then they had another tier and this is where they would sell you.
Speaker B: Right.
Speaker C: If you wanted high speed Internet and be able to watch videos and whatnot, you could pay. And then they had a third tier. And the only difference between that first paid tier and the third tier was a business vpn. So it would secure your data, but that was the only additional feature. Now, if you think about this, and it's catering towards business travelers. Right, okay, that kind of makes sense. But I had to start figuring out the conversations here, and I put myself in that ciso's position of that company, and I came to the determination. This person was brilliant because they went to their product team and said, listen, I can be part of your good, better, best strategy for upsell and we can target this segment. And. And they had to have had the vernacular to be able to sell that. Right. They had to understand marketing strategies. They had to understand upsell and margins and good, better, best and things of that sort. So they could articulate it to the point where they said, yeah, let's try it. And now every dollar made from that tier, that CISO can say that's attributed back to security. So now when they're going into those board meetings and they're sitting at that table with other profit centers, they're not there begging for money. I'm a contributor.
Speaker B: They are a profit center.
Speaker C: They are maybe small, but it fundamentally changes that conversation. Instead of, uh, okay, whatever scraps are left, maybe we can throw at you to. This is somebody that's working with my team that's elevating our products. Right. And generating revenue. Yeah, he's a partner. Or she's a partner. Right. Cybersecurity is a partner. And contributing to revenue. Not just are we compliant, you know, are we doing protection. You fundamentally change. And I think that's where the CISO will evolve in the next three to five years, because it simply is not sustainable to keep going in and saying, I need a 20% budget increase. I do not know of any organization that can do that year over year over year over year and maintain that you'll run the business out of money.
Speaker A: Okay, Yeah, I think you oversold the dark clouds there a little bit because I thought you were going to be talking about some recent rulings that apparently mean that all CISOs are going to go to jail for the slightest mistake.
Speaker C: No, but I think there will be a pruning, um, uh, think dinosaurs and cataclysmic events where potentially 90% of the ones doing this now won't survive in the next decade.
Speaker B: Those are serious dark Planets.
Speaker A: Absolutely. Yeah. Yeah. And, um, you know, well done for not touching the live wire. That is the SEC ruling.
Speaker C: Oh, we can talk about SEC rulings. This is my space. Right. I'm from the U.S. so, yeah, there's lots of talk and concerns about SEC rulings.
Speaker A: So does that mean that CISOs are going to go to jail for the slightest mistake?
Speaker C: Um, so the short answer is no. Um, the sec, for those who don't know, the Security and Exchange Commission, their charter is to make sure that investors and their rights, um, are properly respected and that security fraud does not occur, and if it does, for them to investigate and prosecute. So they focus on security fraud. And, you know, many companies have to fill out certain required forms on a quarterly basis and think about it, Right. If you're a public. And these are public companies. If, uh, you're a public company, you have to share with your investors what are your quarterly revenues, what is your quarterly profit, what's your margin levels, and if there's anything material that those shareholders should know, because they have a right to properly invest their money. And if you keep material information to yourself, that's insider information. And if you start trading your options or shares, you're now committing crimes, and shareholders have the right to know that. So you have to fill out, uh, S1s and S8s and 8Ks. If you intentionally mislead, deceive those shareholders in those formal forms, that is considered fraud. And it is doing it to the detriment of the shareholders. The SEC is the body that investigates and prosecutes it. And this year, we've had two big cases, one for Uber and the one that was currently announced towards solar winds. And my industry is going sideways. It's just bifurcating. You have two different groups, um, that are just going, going at it. So it's, it will just. The conversations alone will drive a change and a better understanding of what those roles and responsibilities are for the ciso.
Speaker B: Yeah.
Speaker A: And your personal opinion is fair enough.
Speaker C: Um, I've read the. Was it 86 page or 68 page? I can't remember. Um, complaint from the SEC. If. And again, you know, the people are innocent until proven guilty. So let's, let's make sure that's absolutely clear. They are innocent at this point in time, if even half of what's in that complaint are true, I think you're gonna find a conviction. A conviction against one or more of the company, uh, for fraud, sure. Okay. But it's up to a jury, it's up to a judge that's our form. They will determine guilt or innocence and the burden of proof is on the prosecution. So the SEC must prove it. All right, um, and that's where we're gonna go.
Speaker A: But there may be right to investigate anyway.
Speaker C: Yeah, that's our job. That's why we pay the tax dollars, go to them.
Speaker B: But having the burden of proof on the prosecution, it should be how it should be.
Speaker A: Absolutely.
Speaker B: Especially like with this role itself.
Speaker A: Right, okay, I see where you're coming from. Right, okay. So the, so the role of the CISO is evolving, but organizations are also like, um, organizations are embracing the digital transformation. The, you know, the business innovation is happening. The business is changing. How does the CISO sort of maintain balance, uh, with the security needs versus that ongoing innovation?
Speaker B: My take on this is to go back to the goals or the outcomes that the business would really want to go towards. So for instance, you mentioned digital transformation. If that's the outcome that the business would like to go towards, then it's the CISO's job to ensure that. How does the organization go towards that in as, uh, less risky way as possible, essentially. So the CISO's job is to enable the organization essentially to digitally transform securely and perhaps during that transformation, even provide more resilience for the organization. Like have the CIA triad like M have more confidentiality, availability, integrity of information as you move towards that area. So it's not really the CISO's role to say, let's not go there, because there's so many threats there. Because the CISO should help manage then the threats towards that outcome that the business would like to aim towards, as
Speaker A: we discussed optimally, even sort of enable new business or new outcomes.
Speaker C: I completely, 110% agree with everything which she's saying. It's got to come back to those goals. Those goals change. And if the company, uh, wants to expand to a new market, okay, great, The CISO should be looking at that. How can I help make the company successful?
Speaker B: Mhm.
Speaker C: And there's going to be lots of different conversations, but instead of being that traffic cop that says stop, you need to be part of that executive branch going, okay, this is the strategic future of our organization. We're all in it together. How do we in our individual disciplines help make that a reality? And cyber, you have to manage the cyber risk for that. Okay, great. You're part of that contribution.
Speaker A: Right? Okay. But at the same time, sort of the things we deal with, the things uh, we see face is, uh, cyber attacks, data breaches, uh, dangerous sort of big Ticket items. Um, uh, so you're thinking about that stuff. How can you then find the time and just presence of mind to contribute to ensuring business continuity and organizational resilience? Stuff like that. Is it like. I don't know, is there a. Are we talking about two different things here?
Speaker C: I don't think we are. And I'll go back to what Christine said. It all comes back to the goals.
Speaker A: Yeah.
Speaker C: And so if I'm sitting with the board, I've got a number of goals. Right. And those will be prioritized. And it's never. We will be 100% invulnerable to attack. It's never that. Right. If you do that, you shouldn't be a ciso. Um, it's typically, okay, we're going to accept a certain level of risk, and this is kind of the prioritized goals we will have. Okay, great. If a new business goal comes in, we're going to expand to a new market.
Speaker B: Great.
Speaker C: Let's talk about how that changes our current goals and prioritization, because it's important. Yes. So that may, uh, disrupt and, uh, the goals may have to be adapted, but that's fine as long as those who are accepting the risk, the board, the C suite, so on and so forth, understand it and are bought in.
Speaker B: Great.
Speaker C: And there may be tough discussions. Right. We may say, okay, based on our current risk posture, we may have a small data breach on average, every two years. Management would go, okay, we're willing to have that small data breach every two years, minimal. Okay, sure. But you bring in a new goal and, okay, during the time that we're acquiring this company or merging with or expanding our business to this new market, that may adjust that number. Right. We may. The. The likelihood may drop down to a breach every one year. Is that acceptable?
Speaker A: Right.
Speaker C: For the time that we're doing this, that. And they may go, yes, for the one year it's going to take to get into that market, we're willing to accept that risk. Great. We're going to document it, of course. And we're going to document that in the writing. Right. Um, and if it happens, that's the conversation you're going to have. Yeah. Hey, we agreed to this. And if they say no. Okay. Well, then there's additional resources and friction that I'm going to need to manage that risk to whatever acceptable level you want.
Speaker A: Yeah, I see what you mean. And certainly makes sense. Maybe what I'm asking is more like, uh, how do you find the time to do that? Because a lot of CISOs are in firefighting mode. They're just, you know, trying to stave off that next cyber attack. So how do you find the time to sort of be proactive and think ahead and have these, uh, conversations?
Speaker C: Well, you have to be part of the discussion to begin with. And if you're doing your job and you show that empathy and understanding, they want you as part of that discussion because they've got grandiose plans. They don't want some cyber attack to ruin it.
Speaker A: Right.
Speaker C: Make sure Christine's in the room. So cyber, you know, bad things don't happen. Right. So Christine's doing her job. She's got, um, uh, you know, the empathy and the coordination and the collaboration with these executives. She's a valuable part of the team. So having that conversation is just a natural extension of how am I going to prioritize these. Hey, I'm 100% saturated keeping at this goal. I've got to take some of those resources to help make this new project accessible. That adjusts my risk profile. And if you're not okay with that, well, then I need more resources.
Speaker B: Right. And you, you just really need to carve out the time and get out of the firefighting. Because a lot of the firefighting, um, that we see the impact of, those are actually not very vast like most of the incidents that we have every day. I mean, there are some that have bigger implications than the others, but most of them don't have that big implications. But when you go towards the upper levels of the company and really take a look at the strategy, that is one area that we need to take the time to spend on, because our cybersecurity program would need to work back from those. And if we don't take the time to understand those, to have conversations with the upper management when it comes to those, then we are completely isolated in what we're trying to do and securing the organizations out of different tiny incidents that may not have been the priority in the first place.
Speaker A: Okay, yeah.
Speaker C: And I think that is the unique role of the CISO is to be able to adjust those goals, communicate, to get that collaboration. But without the CISO there, the organization would continue to do the firefighting just as it did the day before. Nothing would change. So when there is a shift in business goals or management, that CISO is the key person to understand that and then adapt the organization, the security organization, to be able to meet those goals. So it's going to be different for the next day.
Speaker A: Okay, so what's changing in the industry right now? Um, uh, you know, we've established that CISOs want to be there, want to have those conversations, want to show the value of their work. But what are some of the emerging trends that you guys are keeping your eyes on that are going to impact, impact that the value that you're showing?
Speaker B: I mean, I, I can start with third party risk management. Mhm. I mean, third party risk management. Several CISOs that I have discussed with, there's really no one that has cracked this.
Speaker A: No, it's a biggie.
Speaker B: Yeah, this is quite big. Um, and third party risk management, it can start with cyber risk, but then it can easily go into just general supply chain risk. And uh, when you say confidentiality, availability and integrity, it could be like availability of materials for the business continuity of the organization as well, which could essentially go beyond cyber. So um, my thought on this is that, I mean CISOs, at some point, should they want to go towards higher and higher levels of the organization or go towards different areas, they could become masters of supply chain that just go beyond cybersecurity and really think about, let's say, for example, like a chief risk officer profile that you are thinking about generally the risk to the business, the risk to the strategy. Because the conversations that we have at times, they are not just about cyber risks anymore. When we talk about business outcomes, they could also be that, okay, if there's a shortage, for instance, in chips, how will our business continue tomorrow, the next month, what will we then protect? That's my take, at least on that.
Speaker C: Uh, supply chain is. It's an ugly monster that for the past probably five or six years, most CISOs have intentionally ignored because it was such a sleeping dragon that you didn't want to have to allocate all your time and resources to slay and nobody's figured it out. Uh, I would add a few more things to the list. Uh, we see regulations, more and more regulations that are coming in, whether it be for privacy or security or whatnot. Um, so that's going to fundamentally change some of the aspects of security and the responsibilities of security. I think there is a continuing elevation of expectations by executives, by the CEO, and definitely by the boards because they're starting to feel some of that accountability. But the expectations of what security will deliver is going up. Whenever there's expectations going up, that typically means you're going to need more resources or you're going to be more, need to be more efficient. That will change and be a major challenge. We've talked about how there needs to be empathy between CISOs and other, uh, frontline executives as well as the board. And there's a different language there. We see right now a chasm between CISOs that again, grew up from a technical perspective and managing security from a technical, uh, viewpoint, trying to be able to communicate with those other business partners with the board. They don't understand. Right? You take a highly technical CISO that's never talked to the board, and you throw them in front of a board or put them in a board meeting, you see them putting up 50 slides, right, with attack metrics, and there is zero communication actually happening. And they don't realize why it's a different language. So there's a chasm there that hasn't yet been crossed. And we're not training our CISOs to be able to speak business or listen business. So I think we've got many different changes, and we already talked about the last one where the CISO will have to transform. The CISO and the organization will have to transform to be able to show more value and be able to communicate that. Again, chasm to communicate that. But it also will have to explore areas to add business value, competitive advantage, and potentially even new revenue moving forward.
Speaker A: So we've discussed how there are these multiple demands for CISO's time and attention, uh, both things you should be doing and things you want to be doing. So what are some of your sort of personal tips or tricks in sort of deciding how to allocate your resources and budget and time?
Speaker B: Well, there is really no perfect answer to that. And I would go back to what are the needs of the organization? I, um, mean every single day in the organization, there are always pressing needs. But for instance, there are needs that are urgent. There are needs that are important, and there are needs that are important and urgent, and those like CISO should then be on top of that. But there are also needs that are urgent but are not really that much important. And, um, these are the areas that, as a ciso, if you have different people in the organization that you can delegate that to, it's probably better. I like to encourage CISOs actually to spend time on what is important and long term. Like, for instance, even the simple fact of how do you operationalize security in an organization to make it more sustainable? Because, I mean, fact of the matter is, as Matt mentioned, no matter how much of our budgets increase year on year, the demands for this function will continue to increase and it will never be enough. And therefore, it becomes a question of what does sustainability mean for this organization in the context of cybersecurity and how do I implement that? And this is the question that if you are thinking about this always at the back of your mind as a ciso, and then helping steering the organization towards that area, that is something that could even help longer term to lessen the firefighting m that you continuously do. And I mean, of course you can't avoid urgent and important. Those just need to get out of your table very quickly. So usually I try and uh, some weeks I don't always succeed, but I try as much as possible to spend 40% of the time to the important and not so urgent, and then the rest of the 60 go to the urgent and important matters.
Speaker A: Okay.
Speaker C: Yeah. Um, So I advise CISOs, and then I also get brought in by CEOs and boards to come in and evaluate security. Um, whenever I sit down with the CISO or many times when I sit down with the ciso, the first thing they want to talk about is, okay, well, we use these kinds of suites and these kinds of tools and they want to. And I'll stop them and go, what are your security goals? What have you committed to, to the board, to the CEO, to the president. Right. Um, and I'll get a funny look like, well, what do you mean? I protect against attacks. What are your specific goals? What are the metrics behind those? How do you show success versus failure? And for many, they have to take a step back. Well, I'm just here to stop bad things from happening. If you don't have.
Speaker A: You can only fail in that metric.
Speaker C: Yeah, exactly. That's exactly true. You can only fail in that metric. You are, well, you're a victim. Eventually you will be a victim.
Speaker A: Right?
Speaker C: You will be a scapegoat as well. Congratulations. You know, do you have your golden parachute? But if organizations don't have those goals and we've both been talking about, hey, it goes back to the goals. It goes back to the goals. If you don't have clearly defined and documented goals about risk, about attacks, about loss, about things of that sort, there's no way you'll win. There's no way you will have a long term successful program. It will continually evolve. Even if buckets of money are thrown at you, you will focus on the busy work. You will not be prioritizing what you can do. Um, and you're going to be distracted. And ultimately it's still going to bite you in the end. So again, for the first and foremost, the CISO is a strategic leader that has to work with other groups. And if you don't have common goals that everybody understands. This is success versus not success. You won't win.
Speaker A: Wow. That's, uh, a little bit bleak, but also, I think, very actionable. So with that, uh, I want to thank you guys for being with us today.
Speaker B: Thank you.
Speaker C: Thank you.
Speaker A: That was the show for today. I hope you enjoyed it. Please get in touch with us through Twitter with the hashtag Cybersauna with your feedback, comments and ideas. Thanks for listening. Be sure to subscribe.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.