Télécharger le rapport: Comment aligner DSI et PDG à l’ère de l’IA

fermer
fermer
Le réseau de demain
Le réseau de demain
Planifiez votre chemin vers un réseau plus rapide, plus sûr et plus résilient, conçu pour les applications et les utilisateurs que vous prenez en charge.
Essayez Netskope
Mettez la main à la pâte avec la plateforme Netskope
C'est l'occasion de découvrir la plateforme Netskope One single-cloud de première main. Inscrivez-vous à des laboratoires pratiques à votre rythme, rejoignez-nous pour des démonstrations mensuelles de produits en direct, faites un essai gratuit de Netskope Private Access ou participez à des ateliers dirigés par un instructeur.
Un leader sur SSE. Désormais leader en matière de SASE à fournisseur unique.
Netskope est reconnu comme le leader le plus avancé dans sa vision pour les plateformes SSE et SASE.
2X est un leader dans le Magic Quadrant de Gartner® pour les plateformes SASE
Une plateforme unifiée conçue pour votre parcours
Sécuriser l’IA générative pour les nuls
Sécuriser l’IA générative pour les nuls
Découvrez comment votre organisation peut concilier le potentiel d'innovation de l'IA générative avec des pratiques robustes en matière de sécurité des données.
Prévention des pertes de données (DLP) pour les Nuls eBook
La prévention moderne des pertes de données (DLP) pour les Nuls
Obtenez des conseils et des astuces pour passer à un système de prévention des pertes de données (DLP) dans le nuage.
Réseau SD-WAN moderne avec SASE pour les nuls
SD-WAN moderne pour les nuls en SASE
Cessez de rattraper votre retard en matière d'architecture de réseau
Identification des risques
Advanced Analytics transforme la façon dont les équipes chargées des opérations de sécurité utilisent les données pour mettre en œuvre de meilleures politiques. Avec Advanced Analytics, vous pouvez identifier les tendances, cibler les domaines préoccupants et utiliser les données pour prendre des mesures.
Support technique de Netskope
Support technique de Netskope
Nos ingénieurs d'assistance qualifiés sont répartis dans le monde entier et possèdent des expériences diverses dans les domaines de la sécurité du cloud, des réseaux, de la virtualisation, de la diffusion de contenu et du développement de logiciels, afin de garantir une assistance technique rapide et de qualité
Vidéo Netskope
Formation Netskope
Grâce à Netskope, devenez un expert de la sécurité du cloud. Nous sommes là pour vous aider à achever votre transformation digitale en toute sécurité, pour que vous puissiez profiter pleinement de vos applications cloud, Web et privées.

The Modern CISO Role Needs to Evolve. Here’s Why.

Jun 06 2022

As I prepare for my upcoming presentation at RSA 2022, I’ve been reflecting on the role of information security in modern enterprises and how it is evolving like never before. Security will need to improve third-party oversight as organizations increasingly depend on outsourcing models for scale flexibility, efficiency, and cost savings. It will also need to do a better job of balancing security requirements (e.g., regulatory compliance, risk management) against business objectives (e.g., user experience, network performance, reducing costs).

To keep up with this shift, the role and responsibilities of the Chief Information Security Officer (CISO) need to evolve as well. But this shift is just as much about an evolving culture as much as it is about changing infrastructure and multiplying risks.

To get a better understanding of these changes, let’s start by airing out a few of the most common complaints from management teams and executive boards regarding the current tenure of today’s CISO:

  • Security teams don’t positively engage with business
  • Security strategy and spending doesn’t align with the organization’s business strategy
  • Security focuses on information protection at the expense of other corporate goals
  • Security is a roadblock to innovation and revenue growth
  • Security can’t articulate value to the business

To be fair, today’s CISOs face a much harder job today than they did even a few years ago. Their attack surface is sprawling as a result of remote workers, multi-cloud services, and unending cycles of business digitalization. Threat actors are launching increasingly sophisticated attacks that use advanced technologies like artificial intelligence (AI) and machine learning (ML). Attack volumes are on the rise—with things like a 450% increase in phishing downloads over the last 12 months. And there’s also more vulnerable information that is being collected and shared than ever before—with total the amount of data in the world projected to more than triple from 2020 to 2025. (On top of that, CISO mental health is of increasing concern, disproportionate to a wider understanding of why burnout occurs so often in CISOs.)

When I started security at Visa 25 years ago, it was my responsibility to secure the organization. Keep the bad guys out, let the good guys in. I thought it was complex at the time. But over the last decade, virtually every aspect of the security team’s responsibilities have become increasingly more complex. Securing the internal organization is still at the core, but now we also have to manage third-party risks as well risks with vendors and software-as-a-service (SaaS) applications. Regulatory compliance risks have also gone up a hundred fold since those days with the emergence of things like the EU’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and strict Payment Card Industry (PCI) standards.

The security leader’s job has become exponentially difficult—while the potential for a successful attack that significantly impacts the business is also rising. And so for security matters to be taken seriously, we really need to change the executive team’s perception of security. It needs to become a value to the business. Just like any other department, it needs to create value in coordination with the broader trajectory of the organization. 

At the end of the day, the goal of the security leader is still to protect the business. But some critical skill limitations of the traditional CISO’s role are starting to interfere with that prime directive. The effects of business digitalization and shadow IT are widening the gap between the security team and the broader business, bringing executive leaders and boards to a breaking point. The modern security leader needs to be well versed in risk management, outstanding communication skills with the savvy and C-level acumen for proper business enablement. As a result, today’s CISOs must adapt—or face being replaced by a person with needed skills to lead security efforts in a modern organization.  

How do I get those skills? Interested to learn more about how the modern CISO needs to evolve their mindset to balance risk management and drive value for the broader business amid these changing times? I will be diving into this topic in-depth in my upcoming presentation at RSA 2022 on Thursday June 9 at 1pm PT, alongside Bobby Singh, CISO & CTO from the Toronto Stock Exchange. Click here for more information.

author image
James Christiansen
James Christiansen is Netskope’s VP of cloud security transformation and leader of the Global Chief Strategy Office. He is focused on enhancing Netskope’s global clients.
James Christiansen is Netskope’s VP of cloud security transformation and leader of the Global Chief Strategy Office. He is focused on enhancing Netskope’s global clients.
Connectez-vous avec Netskope

Subscribe to the Netskope Blog

Sign up to receive a roundup of the latest Netskope content delivered directly in your inbox every month.