Skills Required for CISO Success with Optiv’s Max Shier
Max Shier, CISO at Optiv, discusses the skills CISOs need in 2024 to be successful, including being business-focused, communicating to the Board and executive officers in a way they’ll understand, and possessing the ability to define metrics that demonstrate the business value of security, including how security is enabling the business, reducing operational risk and providing a positive ROI.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Textron tv.
Our next guest today is Max Shire. Max is the ciso, CISO at Optiv, and we're gonna hear all about that. Hey, max, welcome to Textron's.
Good to see you. Yeah, thanks for having me. I appreciate it.
Uh, my pleasure. So Max, why don't we start off with, maybe, you know your CISO now, but, you know, how'd you come to become CISO there and, and, uh, a little bit of your journey? Yeah, thanks, I appreciate it.
So, my name is Max Farer. I'm Vice President, chief Information Security Officer for Optiv Security Inc. Optiv Security is really a pure play cybersecurity company.
We sell cybersecurity services that would be managed services, so soc uh, managed identity. We manage different parts of your security program, but we also sell software or other services that you may need all the way up until, you know, security awareness, training and education, or if you just need say, um, you know, endpoint software such like CrowdStrike, we provide that as well. So any cybersecurity services, um, and we run the gamut.
So for me, um, I've been at Optiv for about 18 months. My background is actually primarily in the federal space. Uh, so very atypical, I suppose, for a CISO coming into the, the commercial space.
Um, retired Air Force, as you can see behind me, very proud of that. Did 23 years, nine years active in the rest in the reserve. Um, I actually came from the military police background, uh, where I was, yeah, I did that for nine years and then crossed over to cybersecurity when I exited the military.
And, uh, so I've been in cybersecurity for, you know, coming on 18 years now, and, uh, love it. Um, and like I said, most recently coming from the federal space, so it's a little bit different, but I think also very relevant. Cybersecurity is, you know, I, although I, I think the threats differ between verticals, um, you know, cybersecurity, the concepts and the implementation are very similar across, across all verticals, right?
So, uh, it was a pretty, pretty easy transition for me to come over to commercial. But I think, you know, coming to a pure play cybersecurity company has been very interesting for me. Uh, being CSO and a company of, of security experts has been very eye-opening.
I learn something every day and, uh, and I love it. And also it makes my job, uh, I don't wanna say easy, but let's just say easier, where I can tap into hundreds of experts across the board, you know, running the running def, uh, several different verticals and several, several different, uh, backgrounds. So for me, uh, I love having the capability to be able to tap into experts like that.
Absolutely. So, you know, max, you are actually a great poster child for the topic of our discussion today, which is, you know, what skills are required for CSO success. And, and I, you know, let's talk about, I mean, so look, you're, you're an, you're an MP in the Air Force, right?
I'm assuming not a lot of, you know, you're not working a cyber desk there. I know. Um, you know, how did you acquire, well, first of all, how did you decide what skills you needed to have?
And then how did you go about acquiring them, you know, to help? Yeah, very interesting. You arise.
Yeah. Yeah, yeah. And you know, I, I think when I came into cyber, you know, almost 20 years ago now, I, I think the focus was a lot different.
It was still a very immature career field, and, you know, the focus was on metrics and compliance, and it was, you know, are you checking the box? Are you, you know, do you have the right paperwork in place? And I think cybersecurity has really transitioned over the last couple of decades to, um, a, a much more mature space.
Long gone are the days where a CISO can go to a board and say, you know, we're being attacked 10,000 times a day. We need to increase spending. Um, the board now wants to see a return on their investment.
And really, what does that mean? I mean, you need to quantify it for them in dollars, essentially, right? Are you getting your money's worth out of your investment?
And I think there's a lot of pressure now on CISOs today to really leverage the money that they're spending, uh, increase efficiency and really show what they're getting for their, for their spend. And, you know, there's a big push for tech rationalization right now where you're leveraging platforms of tools or making sure that the integration of your tools are maximized, et cetera. So that way you're, you're getting a bigger ROI on your investment.
And I think, you know, the platform plays are still gonna be there. Best of breed is still gonna be there. But I think, you know, it's the CISOs job to really determine what tools are best for their environment and to really mitigate risk in a cost, cost, uh, effective manner.
And, you know, I, I think that's really where the CISO skills have transitioned from the old days of compliance and scare tactics to really, um, being able to quantify where the money is going, and then developing metrics that really show risk mitigation and business effectiveness of those security controls in today's environment. Absolutely. Absolutely.
Um, now look, I was never a cso, let me say that on the, out from the outset. But you know, recently, I, you know, I, I guess maybe it started with the Uber case, right? And then SolarWinds and some of the other things, all of a sudden, you know, being a CISO has become a, uh, somewhat more hazardous, right?
Maybe you qualify for hazard pay, right? Because of all the legal ramifications, both criminal and civil and career wise that, you know, know, it's funny, I, I've been involved in security 25 years and look, a lot of security vendors always, so f always sold fud, fear, uncertainty, and doubt. And part of that FUD was, look, I, I remember friend of mine unfortunately passed away, which started a very famous security consulting, very well-known security consulting company outta Colorado.
And, you know, his, his line was, he'd go into the board and to the C level and say, how do you look in stripes? Right? Because if you guys, you know, don't toe the line here, back then it was Graham Leach Bliley, you know, before we had some of the other stuff.
We have now some of the other regulations. But really that's become true for CISOs now, right? You know, criminal charges, uh, and and so forth for, for what, you know, they don't have complete control over, quite frankly.
And, you know, I know a lot of friends who say, I wouldn't take that job with a 10 foot pole. Now what, what skill sets you need to navigate this new landscape, max? Yeah.
And I, you know, there is a lot of risk now being a ciso. And to your point, I think, you know, we're starting to see, especially with the SolarWinds, um, incident, right? That people are now being held accountable, not just the company, but individuals.
And I think that is a very marked change in how we dealt with these in the past, right? And, but I think there's, you know, there's things that CISOs can do to help mitigate that. And, and really it's, it comes back to transparency and communication and understanding what your company is doing.
So if you turn a blind eye to everything, are you responsible? If you sign the piece of paper that goes to the SEC that says, yes, we're compliant, but really you're not, and you know about it, then yeah, I think you should be held accountable, right? Um, but I think there are, you know, obviously it's a touchy subject.
Um, but, you know, I think personally transparency, communication, making sure that if there are issues that you do bring it up, and if there are things that are gonna prevent you from signing an attestation that says that you're compliant, you better bring it up as soon as possible. And that type of direct line of communication to the powers that be within your company is extremely important, right? So if you're buried within several levels of management and that never bubbles up to the top, you are gonna be at risk because your name is the one that's on the dotted line that says, yeah, we are compliant.
So, um, you know, I don't know the details really of the SolarWinds case. Uh, you know, I think that's gonna come out in court, but at the same time, you know, there was, um, rumors of negligence, et cetera, right? And I think the, the key word there is negligence.
If the CISO is negligent in their duties and they aren't digging into issues, and they're not raising up those issues, then yeah, I think they are gonna be at risk. Um, so really transparency, communication, just making sure that you're raising their, that red flag if there is one. Uh, that's extremely important, right?
And yep. You know, for me it's, it's, I'll tell you, signing on that dotted line is stressful, right? Did I cross all the t's?
Did I dot all the, i's am I making sure that I'm doing everything that I'm supposed to? Am I doing my due diligence? Really?
Yeah. And, um, and that's what's important. I think.
So before I got into tech, you know, I went to law school, I practiced law even for a few years, not one of my favorite things. Um, but you know, another, the, the bar for negligence is what they call a reasonableness test, right? So are you doing what a reasonable person in your situation or position would do or be expected to do?
And, you know, and then I mean, what we saw, I, again, I don't know the whole SolarWinds case either. We'll have to see how that plays out. But you know, certainly with the Uber case, you know, I call it the Nuremberg Defense, I'm just following orders, right?
I, I reported it to the CEO and they just said, okay, right. Just go along and don't make waves and you're part of a team here, but you know, and I get it, right? No one wants to walk away from a lucrative job or, or have to answer that down the road.
Why did you leave this CSO position? Well, because the place was, you know, asking me to do something I considered immoral or unethical or illegal. And, um, you know, I think, I think most CISOs, or I'd like to think most CISOs though, would walk away from the job, they'd come up with a reason why, right?
My Yep. You know, they wouldn't necessarily say I'm leaving because I think you're a crook, or I think you're doing something wrong, but they'd come up with a good reason. I was offered my dream job.
Mm-Hmm. And I'm leaving. Um, but there are some people who that job's really important to, and, and they, you know, especially if it's their first CISO gig.
Yeah. And so, again, skills required for CISO success, if you're a first time ciso, I think it's harder to, it is, you know? Yeah.
And I think, you know, navigating those waters is definitely difficult, but if you've been in the security career field any length of time, right? You're gonna have to deal with adversity in that, in that job. And, and I think that runs the gamut from entry level all the way up through CISO roles, if not higher, right?
Mm-Hmm. Um, and again, you know, communication and transparency, but to your point, if, if you are being put at risk, your own brand and your own reputation, and you think that you're at risk personally because of the, uh, the acts of those above you, or the acts of the company as a whole, and it's just not a good environment, then to your point, I would, I would definitely leave. And I will say that the job market is going to support you changing jobs.
That's not, that's not difficult right now, I think in this environment. However, the skills though, you gotta deal with adversity in this role, um, you know, cybersecurity or security in general, they're, you're always gonna get pushback. And I think it's important that if you have a difficult time dealing with adversity, you have to learn real quick to, to get with it and learn how to deal with it.
And a lot of what this job entails is really a negotiation, right? It's communication. It's making sure you understand what the business requirements are, what the business use cases are, making sure that you're coming back with adequate controls.
And I say adequate because there's gonna be a compromise there too, right? Right. Reasonable.
Are you enabling the business reasonableness, right? Yeah. And, uh, and making sure that you're talking to folks.
And, and I think that's the most important thing as a CISO or anywhere in cybersecurity, is are you working in a silo or are you working across party lines, so to speak, to make sure that everybody's voice is heard, that you're hearing all the use cases, and that you're adequately supporting those. And even if the business is pushing back on what you need, if you feel that strongly to where it's that high of a risk and you're quantifying it and you're still not getting feedback, uh, that they wanna change it, then you better get a risk management council in place or something to where the company can accept that risk and you have coverage from the business, whether through process or otherwise, to ensure that that is documented, that is accepted by the business, and that the business is well aware of what the risk and the consequences are if they don't implement those types of controls. Excellent.
That's really the CISO's job, right? It's not my job to accept the risk. It's my job to identify it, mitigate it appropriately.
And if we can't mitigate it appropriately, and there's, you know, residual risk that's, uh, severe, that the business is the one that accepts that risk. And it's really, again, all about that transparency and communication I keep on mentioning here, it's gonna be a recurring theme throughout this discussion. Yep.
We're running low on time. I've got one more kind of area, it's not really a question, but it's an area that needs to be covered. Again, I'm, I'm a bit of an insider when it comes to security and CISO and stuff like this.
Look, I think one of the primary jobs of the CISO is to be the translator between security talk and business talk, right? The rest of the board doesn't know what an IDS does or what a, a static analysis scan versus a dynamic scan versus software composition analysis. You know, they just wanna know, am I vulnerable?
Right? And talk business to me, and what's my exposure, what's my risk? That's right.
And so I, I think it raises the, the issue though is how technical does the CSO have to be today, right? How much, what kind of technical chops do they have to have for success versus business chops? Because look, it's a rare dude who, and I don't mean it's men, but all too often it is, but it's a rare person who has, you know, uber skills on both sides of the house there.
Yeah. Yeah. And this is, uh, it's, it's a debatable question, right?
You, you have the train of thought where really the CISO is more of a business function. They really don't have to be technical anymore. And then you have the other side where maybe at a smaller company where the CISO is more hands-on, they have to be more technical.
And so I think it depends, but at the same time, I, I think the ideal CISO should be a little bit of both, right? Leaning towards the business side, in my opinion. Because, you know, the CISO is there, to your point, to interpret between the team that's actually doing, and the board and the team that's actually doing, you still have to be there to ensure that your team is doing what they're supposed to.
You still have to understand in theory, best security practice implementation of such documentation of such and managing that program, right? And I think, um, you know, say in my, in my role right now, a lot of it is I have a, you know, a smaller team. I don't have a team of 200 like, like I've had at, at other positions.
And so for me, yeah, I do need to understand what the team is doing at a technical level, um, so that way I can help collaborate with them and be, you know, a valuable member of the team still and be able to manage that program appropriately. But at the same time, yes, I still need that business acumen. Um, albeit in my situation it's a little bit different because the board does know cybersecurity in this case as a pure play cybersecurity company, right?
You're, you're Not being cyber. Yeah. Yeah.
And so for me it's, you know, it's a little bit, bit different, but if you're talking about the board of a bank or something like that, um, or even healthcare for that matter, they may not know cybersecurity parlance. And so yeah, you do have to be more of a business person, more on the business side to be able to communicate that better to the board and to the EO for ex, you know, for that matter. Um, for me, my metrics look totally different than say somebody that's gonna be in a healthcare company, right?
I can dive a little bit deeper into the technical side of things because I'm gonna get those questions that are more technical from the EO because they're all cybersecurity SMEs or came up in the cybersecurity space, um, board, maybe not so much, but they are gonna have questions that are very specific to cybersecurity, the types of threats that we get and how I'm mitigating those. And so I do have to be a little bit more technical when speaking to the board, at least in my instance, right? Um, but I'm a unique case being in the cybersecurity industry.
So, um, but to your point, I, I think ideal ciso to your point, has to be both. Um, but I think it's gonna depend on the situation on where you're at too. A smaller team.
Yeah. Definitely gonna have to be more technical. If it's a larger company, maybe not so much.
Yep. Agreed. Hey, max, we are out of time.
We're probably over time. People wanna get more information on Optiv. com?
That's correct. Yep. com.
And, uh, feel free to reach out to me on LinkedIn too, if they have any questions. I'll feel free to, to move them to the right people. All righty, max Shire, CSO at Optive here on Tech Drunk tv.
We're gonna take a break. We'll be back. Thank you, Matt.
Max, it's great to have you on. We're gonna take a break. We'll be back here in a minute with more tech drunk tv.
Bye-Bye.