CYBERSECURITY REVIEW8 APRIL, 2021IN MY OPINIONBECOMING A LEADER IN ENTERPRISE SECURITYMany readers of Enterprise Security are focusing on technical topics to increase knowledge and gain expertise. There is also an opportunity, and need, for those same individuals to learn about leadership. Many cybersecurity technicians are being asked for input and participation on a wider level in their organization, yet they lack the skills to effectively help their organization, and career, move forward.Let's spend a few minutes looking at some of the essentials of leadership for cybersecurity professionals. During this exploration, we will also look at a couple of key leadership principles that are important for everyone to know.The best way to begin is to look at how effective cybersecurity leaders are leading and determine the key characteristics of those leaders. In August of 2019, SecurityIntelligence.com published this data. In the article titled "The Many Dimensions of Effective CISO Leaders" https://securityintelligence.com/articles/the-many-dimensions-of-effective-ciso-leaders/ they identified 5 characteristics of successful CISOs (Table 1). While everyone may not aspire to reach the CISO level, studying this level of leadership will help anyone gain essential forward-movement techniques. There are several key takeaways from this study. First, CISOs are expected to have high strategic leadership qualities, followed by strong communication skills and relationship building capabilities. Notice that Technical skills lagged behind the skills often characterized as "soft skills". An effective CISO needs to have a strong set of interpersonal skills, in addition to technical skills, in order to be an effective leader.By delving even further into this phenomenon, the need to establish a clear vision becomes paramount. That vision incorporates both a vision for the Cybersecurity Program, and a vision for how Cybersecurity can be an enabler of business, not an inhibitor. The CISO has to be part of the department of K-N-O-W, not the department of N-O. This is where many Cybersecurity leaders fail.Cybersecurity leaders must think more like risk managers, acknowledging that some amount of risk is essential to keep business moving forward. If Cybersecurity says "NO" too frequently, the business leaders will stop asking for input and end-run the security program to get something out the door. The key is for the Cybersecurity leader to become a Trusted Advisor instead of a Subject Matter Expert (SME).The Subject Matter Expert is invited to the leadership table for the 10-15 minutes that executives want an SME. Then they are dismissed to go back to work, rather than being invited to stay and help make decisions. On the other hand, Trusted Advisors are invited for the entire decision-making process. Effective Enterprise Cybersecurity leaders move from being the SME to a Trusted Advisor through applying specific leadership principles. What are the key forward-movement leadership principles to Leadership, particularly strategic directionCommunicationManagement SkillsTechnical Skills54%49%44%33%21%Strong Relationship with Business ExecutivesBy RANDY RAW, VP of Information Security, Veterans United Home Loans
<
Page 7 |
Page 9 >