Report herunterladen: Wie CIOs und CEOs im KI-Zeitalter in Einklang kommen

Schließen
Schließen
Ihr Netzwerk von morgen
Ihr Netzwerk von morgen
Planen Sie Ihren Weg zu einem schnelleren, sichereren und widerstandsfähigeren Netzwerk, das auf die von Ihnen unterstützten Anwendungen und Benutzer zugeschnitten ist.
Erleben Sie Netskope
Machen Sie sich mit der Netskope-Plattform vertraut
Hier haben Sie die Chance, die Single-Cloud-Plattform Netskope One aus erster Hand zu erleben. Melden Sie sich für praktische Übungen zum Selbststudium an, nehmen Sie an monatlichen Live-Produktdemos teil, testen Sie Netskope Private Access kostenlos oder nehmen Sie an Live-Workshops teil, die von einem Kursleiter geleitet werden.
Ein führendes Unternehmen im Bereich SSE. Jetzt ein führender Anbieter von SASE.
Netskope wird als Leader mit der weitreichendsten Vision sowohl im Bereich SSE als auch bei SASE Plattformen anerkannt
2X als Leader im Gartner® Magic Quadrant für SASE-Plattformen ausgezeichnet
Eine einheitliche Plattform, die für Ihre Reise entwickelt wurde
Generative KI für Dummies sichern
Generative KI für Dummies sichern
Erfahren Sie, wie Ihr Unternehmen das innovative Potenzial generativer KI mit robusten Datensicherheitspraktiken in Einklang bringen kann.
Moderne Data Loss Prevention (DLP) für Dummies – E-Book
Moderne Data Loss Prevention (DLP) für Dummies
Hier finden Sie Tipps und Tricks für den Übergang zu einem cloudbasierten DLP.
Modernes SD-WAN für SASE Dummies-Buch
Modernes SD-WAN für SASE-Dummies
Hören Sie auf, mit Ihrer Netzwerkarchitektur Schritt zu halten
Verstehen, wo die Risiken liegen
Advanced Analytics verändert die Art und Weise, wie Sicherheitsteams datengestützte Erkenntnisse anwenden, um bessere Richtlinien zu implementieren. Mit Advanced Analytics können Sie Trends erkennen, sich auf Problembereiche konzentrieren und die Daten nutzen, um Maßnahmen zu ergreifen.
Technischer Support von Netskope
Technischer Support von Netskope
Überall auf der Welt sorgen unsere qualifizierten Support-Ingenieure mit verschiedensten Erfahrungen in den Bereichen Cloud-Sicherheit, Netzwerke, Virtualisierung, Content Delivery und Software-Entwicklung für zeitnahen und qualitativ hochwertigen technischen Support.
Netskope-Video
Netskope-Schulung
Netskope-Schulungen helfen Ihnen, ein Experte für Cloud-Sicherheit zu werden. Wir sind hier, um Ihnen zu helfen, Ihre digitale Transformation abzusichern und das Beste aus Ihrer Cloud, dem Web und Ihren privaten Anwendungen zu machen.

The Modern CISO Role Needs to Evolve. Here’s Why.

Jun 06 2022

As I prepare for my upcoming presentation at RSA 2022, I’ve been reflecting on the role of information security in modern enterprises and how it is evolving like never before. Security will need to improve third-party oversight as organizations increasingly depend on outsourcing models for scale flexibility, efficiency, and cost savings. It will also need to do a better job of balancing security requirements (e.g., regulatory compliance, risk management) against business objectives (e.g., user experience, network performance, reducing costs).

To keep up with this shift, the role and responsibilities of the Chief Information Security Officer (CISO) need to evolve as well. But this shift is just as much about an evolving culture as much as it is about changing infrastructure and multiplying risks.

To get a better understanding of these changes, let’s start by airing out a few of the most common complaints from management teams and executive boards regarding the current tenure of today’s CISO:

  • Security teams don’t positively engage with business
  • Security strategy and spending doesn’t align with the organization’s business strategy
  • Security focuses on information protection at the expense of other corporate goals
  • Security is a roadblock to innovation and revenue growth
  • Security can’t articulate value to the business

To be fair, today’s CISOs face a much harder job today than they did even a few years ago. Their attack surface is sprawling as a result of remote workers, multi-cloud services, and unending cycles of business digitalization. Threat actors are launching increasingly sophisticated attacks that use advanced technologies like artificial intelligence (AI) and machine learning (ML). Attack volumes are on the rise—with things like a 450% increase in phishing downloads over the last 12 months. And there’s also more vulnerable information that is being collected and shared than ever before—with total the amount of data in the world projected to more than triple from 2020 to 2025. (On top of that, CISO mental health is of increasing concern, disproportionate to a wider understanding of why burnout occurs so often in CISOs.)

When I started security at Visa 25 years ago, it was my responsibility to secure the organization. Keep the bad guys out, let the good guys in. I thought it was complex at the time. But over the last decade, virtually every aspect of the security team’s responsibilities have become increasingly more complex. Securing the internal organization is still at the core, but now we also have to manage third-party risks as well risks with vendors and software-as-a-service (SaaS) applications. Regulatory compliance risks have also gone up a hundred fold since those days with the emergence of things like the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and strict Payment Card Industry (PCI) standards.

The security leader’s job has become exponentially difficult—while the potential for a successful attack that significantly impacts the business is also rising. And so for security matters to be taken seriously, we really need to change the executive team’s perception of security. It needs to become a value to the business. Just like any other department, it needs to create value in coordination with the broader trajectory of the organization. 

At the end of the day, the goal of the security leader is still to protect the business. But some critical skill limitations of the traditional CISO’s role are starting to interfere with that prime directive. The effects of business digitalization and shadow IT are widening the gap between the security team and the broader business, bringing executive leaders and boards to a breaking point. The modern security leader needs to be well versed in risk management, outstanding communication skills with the savvy and C-level acumen for proper business enablement. As a result, today’s CISOs must adapt—or face being replaced by a person with needed skills to lead security efforts in a modern organization.  

How do I get those skills? Interested to learn more about how the modern CISO needs to evolve their mindset to balance risk management and drive value for the broader business amid these changing times? I will be diving into this topic in-depth in my upcoming presentation at RSA 2022 on Thursday June 9 at 1pm PT, alongside Bobby Singh, CISO & CTO from the Toronto Stock Exchange. Click here for more information.

author image
James Christiansen
James Christiansen is Netskope’s VP of cloud security transformation and leader of the Global Chief Strategy Office. He is focused on enhancing Netskope’s global clients.
James Christiansen is Netskope’s VP of cloud security transformation and leader of the Global Chief Strategy Office. He is focused on enhancing Netskope’s global clients.
Verbinden Sie sich mit Netskope

Subscribe to the Netskope Blog

Sign up to receive a roundup of the latest Netskope content delivered directly in your inbox every month.