The Current State of the CISO with Nick Kakolowski
Nick Kakolowski, senior research director for IANS, dives into a survey done in conjunction with Artico Search on the current state of the CISO.
Transcript
This is Textron tv. Hey guys. Thanks Withrow.
We're here with Nick Klowski, he's the senior research director for Ryans. And we're talking about a new study that they did with AR that looks into, well just how the role of the CISO has expanded and what are the implications thereof. Hey Nick, welcome to the show.
Great to be here. Mike book, I think everybody we talk to will tell us that the CISOs playing a larger role in organizations. In fact, in some places the CISO now ones IT and security, but I don't think that's the standard operating procedure just yet.
But as it's clear that security is a bigger focus, what has been the impact on all this increased responsibility on these CISOs Elements of scope creep and what we see is kind of two forks happening. On one side you have the CISOs to kind of have the scope creep thrust upon them and are given extra responsibilities, extra functions and aren't necessarily given rewards, aren't necessarily given a bigger role and more influence within the business. And it's just kind of like, oh, all the problems are getting dumped on those CISOs and those folks are getting burnt out fast and looking for new jobs 'cause they just want to get out.
And then you have the CISOs who are being given real ownership of parts of the business, for example, the full ownership of it, given the opportunity to really have more influence at the executive level and real opportunities to grow the business and partner with other executives and those CISOs who are getting elevated with meco creep are finding it generally very rewarding to have all those extra opportunities and extra responsibilities because it's giving them a bigger role within the business. Is that emotional rewarding or financially rewarding? All of the above.
Uh, because a lot of times, you know, at least in my experience, so almost everybody gets added responsibilities to their job over the years. And it takes a while before anybody recognizes that maybe I have a different job but I need a different title. So we'll CISOs as they continue to get elevated and responsibilities evolve into something else.
Yeah, so for example, we see this dual IT and security ownership situation where you might have a CISO and CIO kind of role, the folks who are CISO and CIO see a substantial increase in compensation, substantial increase in satisfaction, and generally speaking more of an executive role within the business. Whereas if we see CISOs who just take on discrete functions of it but don't get the full CIO function, they could own as much as half or more of it. Their compensation stays pretty much the same as other CISOs.
Their satisfaction drops and they start getting frustrated with how they're just given all the problems to solve but not given commensurate rewards. The folks who are taking on more responsibility outside of traditional cybersecurity, are there common attributes? Are they, maybe they've got an MBA or something if they go do something different that their colleagues are not doing?
We do see some commonality in that the CISOs who are getting more opportunities have diversity of experience, whether that is working across multiple industries, whether that is making an effort to get involved in risk committees or AI committees or compliance committees within the organization kind of work cross-functionally and build relationships cross-functionally. But ultimately what we see happening is CISOs are just extremely strong problem solvers and as businesses have bigger digital risk problems, the CISO is the best person to solve 'em. They're the, they're the people who know enough about the compliance angle, enough about the technical angle and enough about the security angle to actually problem solve some of those risk issues.
And they're getting thrust into those roles. The key thing is figuring out how can I influence these decisions in partnership with other business leaders as opposed to how do I become the defacto owner of a whole bunch of risk that really needs to be owned by business units. And to that point, are they kind of, um, as they assume those responsibilities, um, are they engaging with business leaders more in terms that the business understands?
'cause I think part of the problem I've seen over the last year, and I think we've talked about it in the past, is that security people, they finally get access to the boardroom but the boardroom still doesn't know what they're talking about. Yeah, we are seeing about 50% of CISOs report to the board either quarterly or monthly and year over year just fewer and fewer CISOs are are never reporting to the board. Many CISOs are now starting to get active on subcommittees, which is where a lot of the board work really gets done.
And then in general we are hearing more and more about CISOs getting executive exposure and looking at the rest of the C-suite as their peers. We are planning to update next year's survey, which we're probably gonna launch in late March, early April with some really specific questions to get a sense of how frequently CISOs are meeting with executive peers and which ones they're connecting with more often When I do gain access to the board, I think one of the things that becomes quickly apparent is that the board cares a lot more about compliance than a lot of things 'cause compliance is where the fines are and that's part of the oversight. So is that driving more security people to take out responsibility for compliance because it's kind of like the path to the board?
To an extent I think compliance can work as a forcing mechanism to get the board to care about security. But more often, or I should say more substantially, I think what we see is a lot of compliance solutions end up being security. It ends up being figuring out how you're gonna protect and safeguard data once it's actually in your systems and where that data's living and how that data is rooting through your systems.
And that just requires security input. And so security is gonna have such a big stake in solving a compliance challenge then it makes sense that security is getting a larger stake in understanding what those compliance challenges are in the first place. One of the things that I've noticed is that sometimes when security people get exposed more to the business and the port, their appetite for risk starts to increase their actually start to think about things a little bit more in terms of well what is the impact of the business?
'cause the business leaders are always assessing risk and to them cybersecurity is just one more. Um, so does it change the way the security people think? Oh yeah, we see a strong correlation in our data between exposure to the board and satisfaction with the business' alignment to security priorities.
And we think two things are going on at the same time and they're kind of coming together to make that satisfaction high. And that is board members and business leaders are becoming more aware of cyber risk and more open to real conversations. And so CISOs are starting to feel heard and CISOs are becoming more aware of business risk and understanding the priorities and what level of financial risk within cyber is tolerable and more willing to take risks than they might be if they're kind of siloed in the back office thinking about all the threats and worrying about what happens if there's a breach.
But come to understand, okay, the business is aware of this risk, the business is choosing to take this financial risk. I have the backing of the rest of the organization. I can feel comfortable with this risk.
So do you think that the CISOs that understand that and have that level of conversation are arguably less stressed out than their other colleagues who are always kinda walking in every morning going, I don't know what's gonna come next, but it could be a disaster? In some ways they also tend to have a lot of executive presence and don't show that stress as much. Sometimes they actually are less stressed out or whether they're just good at showing it.
But also those CISOs tend to have been put in a position by the business to be less stressed and have more resources on the team below them so they can delegate more and focus on more strategic issues. A lot of CISOs are starting to elevate their executive presence and their wherewithal on business acumen, but they're still forced by the way the business regards the role into kind of a back office tech function and they're working to get the business to change too. One of the other things that I sometimes wonder about is when I see senior security or even IT people for that matter get closer to the business, they start to lose touch with the IT and the security teams underneath them.
So how do you kinda maintain that relationship while you're establishing these other relationships in a way that doesn't, you know, where they underlying folks who report to you start to uh, I don't wanna say they become suspicious, but they come a little more, um, negative. In some ways this can be easier for CISOs than what I've seen in practice because generally speaking, CISOs are such curious people who care a lot about doing good meaningful work. And when when you have that attitude, it's easier to kind of, you know, it's almost like we to talk CISOs into going out of being in the weeds and care about the strategic corporate stuff because they want to step in and help their teams.
They want to understand the technical problems, they want to go learn a new programming capability and they have to learn to monitor that part of their brain so they can do enough of that to stay plugged in, but not so much of it that they can't have that strategic influence over the business. Do you think there'll be more of a, a split, like when I see in the IT world there's a CIO in these larger companies frequently now as a CTO or somebody who's involved in the actual tech. So will security teams evolve where the CISO will be complimented by somebody who is really the security operations lead or somebody like that?
We see large security teams having functional department heads for SecOps, for architecture, for GRC, for AEC product sec, all kinds of assumptions depending on the specific needs of the org. It's really just a matter of scale. We're also seeing in those kind of dual CISO CIO roles, you might have a person who is a CISO and CIO and title who then has a head of IT reporting to them and the head of InfoSec reporting to them because it gives them the ability to be very strategic.
While those functional department heads are leading the technical execution, How do you perceive the relationship between CISOs and the CIOs then evolving? Because in some ways it feels like, you know, we want them to collaborate more, but you know, people start to get jealous of their resources and priorities. It's gonna vary a lot from organization to organization, but what I'm seeing in a lot of healthy situations is where even if the CISO is reporting to the CIO, that reporting is almost most clinical in nature.
It's about, you know, getting through the reviews and the formal HR things you have to do. And in function they operate more as peers within the business, both with access to the executive teams and they serve as partners and they both have a shared vision for where they want it and security to go. Those two units work extremely collaboratively and they are able to have a strong, healthy relationship where they are working toward common shared vision for how security and it can make the business better and deliver value.
In your experience, are there courses for security people to take to kind of get this kind of business acumen? 'cause I mean there's no shortage of technical courses for security folks, but I wonder if we need something that helps them understand the business and kind of have those conversations with people. Yeah, there are some emerging programs.
We at Ions have an executive competencies program where we offer coaching from recently retired or active CISOs and VSOs and a variety of asynchronous and synchronous learning opportunities to develop those business skills within a cyber context. We see programs at universities like Carnegie Mellon where some of our faculty are professors teaching business skills to CISOs and even like ORs, like the NACD will kind of help CISOs understand governance or help board members understand cyber. It's a growing need.
And of course there's always the option of pursuing an MBA or something like that if you want to get really deep in the business. I can't help but wonder if AI tools, whether it's chat GPT or whatever, is gonna make it easier for the security of people that understand a lot of these business rules. I mean, ultimately most of what we're doing in business is not rocket science.
It's been fairly well documented. There are tons of business courses and is that all just gonna become accessible content? I think a lot of it's accessible already.
The nuts and bolts side of it, CISOs are generally very smart and very curious and they can pick this stuff up fast. Generally what we see is the tricky part is all of the soft skills, the human interaction, the emotional intelligence, the relationship management and influencing where in most business functions, you gradually build those things up with other business leaders organically as you move up the ranks. Whereas in security, you're moving up the ranks due to technical achievement Often then you get thrust into this role where you're now meant to connect with other business leaders and you don't already have those relationships necessarily.
You don't already have the shorthand that the business is using for specific problems and you have to go and kind of build, other people might be building up over five or 10 years of osmosis vast. And that's where things get challenging. What relationships can you build to fast track that process?
One of the other things I've noticed is that more businesses today, when they all align with somebody else, there is a bigger concern about the security of the two firms and how that's gonna be maintained is they're more of an effort to, for the CISOs to kind of collaborate with the, with other CISOs from different organizations to kinda address those business concerns and that becomes part of the job. Yeah, we're seeing a growing trend, whether it's through ISACs or it's through organizations like us and all of the events that we host to bring CISOs together. There is a growing effort to create a stronger community among CISOs that folks can share and find that balance between how do we talk about our problems, whether it's the very real threats we're facing or whether it's the business challenges without losing the competitive advantage that we may gain through having an excellent security program.
It's just finding ways to open up lines of communication in a healthy, productive way for the CISO community. So ultimately, what's your best advice to aspiring CISOs out there? I mean, there's a lot of them.
I think they wind up, you know, being in the technical track, but at some point if they want to become the next generation ciso, they need to have some sort of business experience. So how should they go about getting that Find side projects that get you excited, that are adjacent to your technical areas of expertise, but not directly in them, whether that's an AI steering committee, whether that's a compliance committee, whether it's a customer trust initiative and volunteer for those kinds of programs. It'll get you exposure to other executives or business function leaders who will then see the kind of value you can offer and bring you in and sponsor you when business is trying to solve other problems.
And then gradually you're gonna get more exposure to the business. The business is gonna get more exposure to you and you're gonna demonstrate the value you can offer to the organization beyond simply the security nuts and bolts. All right, function.
You heard here, you wanna become a ciso, you gotta expand your reach beyond just the technical side of the job. And that all requires talking to business folks and ultimately you need to be seen. Hey Nick, thanks for being on the show.
Thanks for having me, Michael. It's great to be here. All right, and back to you guys in the studio.