SESSION ID:SESSION ID:
#RSAC
The Five Secrets of High-
Performing CISOs
CXO-T10
#RSAC
Helping shift the balance of power
in the cyber war since 2001
Institute for Applied Network Security
2
#RSAC
SearchingforMyParents
HuangXiangjian,circa1656
3
#RSAC
Lead your organization
to adopt safe business practices
4
#RSAC
You have to Lead
WITHOUT Authority
pssst!
#RSAC
CISO Impact Data: Leading Without Authority
“With key allies
we have finalized
risk stewardship
policies for
business leaders.”
#RSAC
7
Big Idea for Infosec Leadership
CISO Impact™
#RSAC
Technical Excellence
CISO Impact™
8
Big Idea for Infosec Leadership
#RSAC
Technical Excellence AND
Organizational Engagement
CISO Impact™
9
Big Idea for Infosec Leadership
#RSAC
Why Technical Excellence?
cloud
NIST
ISO
visibility: SIEM, SOC
incident response
insider threat
advanced threat
Pen testing
active defense
safecoding
endpoint protection
Threat
intelligence
talent desert
malware
10
#RSAC
Why Organizational Engagement?
policy
audit
risk profile
board presentation
difficult conversations
communication
stakeholders
accountability
assessments
and the CISO reports to…
security
awareness
businessskills
budgets
Negative employment
rate
11
#RSAC
Focus on: 7 Factors of Organizational Engagement
12
#RSAC
Factor 1:
Gain Command of
the Facts
13
#RSAC
Factor 2:
Get the Business to
Own Risk
14
#RSAC
Embrace the
Change Agent Role
pssst!
#RSAC
Data: Embrace the Change Agent Role
Our team has quarterly
“engagement” goals that
involve face-to-face
meetings with all lines of
business and IT teams, and
the CISO has a goal to
“engage up” in the
organization.
3 of 4 High Performers
1 in 20 Low Performers
“We
systematically
and proactively
engage
stakeholders at
all levels…”
#RSAC
Factor 3:
Embed into
Key Processes
17
#RSAC
Don’t Wait to be
Invited to the Party
pssst!
#RSAC
CISO Impact Data: Don’t Wait to Be Invited In
“…we’ve run
simulations and
mock attacks at
executive offsites.”
#RSAC
Factor 4:
Run InfoSec Like a
Business
20
#RSAC
Factor 5:
Technical & Business
Capable Team
21
#RSAC
Build a Cohesive
Cyber Cadre – Not
Just a Team
pssst!
#RSAC
CISO Impact Data: Build a Cyber Cadre
84% of High Performers
1.4% of Low Performers
“…got the right
people, on the
path to a
cohesive team.”
#RSAC
Factor 6:
Communicate
the Value
24
#RSAC
Factor 7:
Organize for
Success
25
#RSAC
Two Models – Two Diagnostics
8 Domains of
Technical Excellence
7 Factors of
Organizational Engagement
25 Question
Diagnostic
50 Question
Diagnostic
26
#RSAC
CISO Impact Quotient (CIQ)
TechnicalExcellence
Organizational Engagement
27
What’s Your CIQ?
Foundational High
Foundational
Transitional High
Transitional
Executive
Foundational
High
FoundationalTransitional
High
TransitionalExecutive
#RSAC
It’s a 5 to 7 Year
Journey to
High Impact
pssst!
#RSAC
Organizational Engagement – Next Practices
Foundational
Program
29
#RSAC
High
Foundational
Program
30
Organizational Engagement – Next Practices
#RSAC
31
Organizational Engagement – Next Practices
Transitional
Program
#RSAC
32
Organizational Engagement - Dataset
High
Transitional
Program
#RSAC
33
Organizational Engagement - Dataset
Executive
Program
#RSAC
34
Technical Excellence – Next Practices
Foundational
Program
2.Softwareand
VendorSecurity
#RSAC
35
Technical Excellence – Next Practices
High
Foundational
Program
2.Softwareand
VendorSecurity
#RSAC
36
Technical Excellence - Dataset
Transitional
Program
2.Softwareand
VendorSecurity
#RSAC
37
Technical Excellence - Dataset
High
Transitional
Program
2.Softwareand
VendorSecurity
#RSAC
38
Technical Excellence - Dataset
Executive
Program
2.Softwareand
VendorSecurity
#RSAC
39
Technical Excellence + Organizational Engagement
Softwareand
VendorSecurity
#RSAC
Five Secrets of High Performing CISOs
You Must Lead
Without Authority
Embrace the Change
Agent Role
Don’t Wait to Be
Invited to the Party
Build a Cohesive
Cyber Cadre Not Just
a Team
It’s a 5-7 Year
Journey to High
Impact
#RSAC
Lead your organization
to adopt safe business practices
41
#RSAC
Action Plan
Invest 60 minutes (30 + 30) and take both diagnostics at:
Get YOURTechnical Excellence and Organizational Engagement reports
Embark on your data-driven journey to information security leadership
https://rsa2017.iansresearch.com
42
#RSAC
Questions?
Phil Gardner, Founder and CEO
pgardner@iansresearch.com
Stan Dolberg, Chief Research Officer
sdolberg@iansresearch.com
43

The five secrets of high performing cisos