Skip to main content

The CISO Evolution: Business Knowledge for Cybersecurity Executives

Page 1

The CISO Evolution


The CISO Evolution Business Knowledge for Cybersecurity Executives

MATTHEW K. SHARP KYRIAKOS P. LAMBROS


Copyright © 2022 by Matthew K. Sharp and Kyriakos P. Lambros. All rights reserved. Published by John Wiley & Sons, Inc., Hoboken, New Jersey. Published simultaneously in Canada. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning, or otherwise, except as permitted under Section 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-­copy fee to the Copyright Clearance Center, Inc., 222 Rosewood Drive, Danvers, MA 01923, (978) 750-­8400, fax (978) 750-­4470, or on the web at www.copyright.com. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-­6011, fax (201) 748-­6008, or online at http://www.wiley.com/go/permission. Limit of Liability/Disclaimer of Warranty: While the publisher and author have used their best efforts in preparing this book, they make no representations or warranties with respect to the accuracy or completeness of the contents of this book and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives or written sales materials. The advice and strategies contained herein may not be suitable for your situation. You should consult with a professional where appropriate. Neither the publisher nor author shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages. For general information on our other products and services or for technical support, please contact our Customer Care Department within the United States at (800) 762-­2974, outside the United States at (317) 572-­3993 or fax (317) 572-­4002. Wiley also publishes its books in a variety of electronic formats. Some content that appears in print may not be available in electronic formats. For more information about Wiley products, visit our web site at www.wiley.com. Library of Congress Cataloging-­in-­Publication Data Names: Sharp, Matthew K., author. | Lambros, Kyriakos P., author. Title: The CISO evolution : business knowledge for cybersecurity executives / Matthew K. Sharp, Kyriakos P. Lambros. Description: Hoboken, New Jersey : Wiley, [2022] | Includes index. Identifiers: LCCN 2021044404 (print) | LCCN 2021044405 (ebook) | ISBN 9781119782483 (hardback) | ISBN 9781119782506 (adobe pdf) | ISBN 9781119782490 (epub) Subjects: LCSH: Chief information officers. | Computer security. | Management information systems—Security measures. Classification: LCC HD30.2 .S5325 2022 (print) | LCC HD30.2 (ebook) | DDC 658.4/038011—dc23 LC record available at https://lccn.loc.gov/2021044404 LC ebook record available at https://lccn.loc.gov/2021044405 Cover Design: Wiley Cover Image: © Wahyu Hermawan and Mark John N. Madriaga of 99Designs


This book is dedicated to: Matt’s wife and son, Luz and Aleco Rock’s wife, Mary They provided us with unlimited love and support in this journey.


Contents

Foreword

ix

Preface

xi

Acknowledgments

xv

Introduction

1

PART I Foundational Business Knowledge

7

CHAPTER 1

Financial Principles

9

CHAPTER 2

Business Strategy Tools

29

CHAPTER 3

Business Decisions

55

CHAPTER 4

Value Creation

91

CHAPTER 5

Articulating the Business Case

129

PART II Communication and Education

167

Cybersecurity: A Concern of the Business, Not Just IT

169

CHAPTER 7

Translating Cyber Risk into Business Risk

197

CHAPTER 8

Communication – You Do It Every Day (or Do You?)

239

CHAPTER 6

vii


viii PART III

Contents

Cybersecurity Leadership

CHAPTER 9

Relationship Management

273 275

CHAPTER 10 Recruiting and Leading High Performing Teams

307

CHAPTER 11 Managing Human Capital

339

CHAPTER 12 Negotiation

367

Conclusion

383

Index

385


Foreword

W

elcome to an incredible period of change in cybersecurity – what an amazing time to be in this field!

In the chapters that follow, two of the industry’s leading critical thinkers divulge the skills and knowledge a cybersecurity leader must acquire to successfully build a modern-­day cybersecurity program. To get the job done they combine personal stories, practical knowledge, and intimate case studies. My colleagues Rock Lambros and Matthew Sharp will challenge us to think about cybersecurity on a new level. They encourage us to contemplate managing our cybersecurity programs differently, through a business lens. What’s more, they offer us the tools to make that transition a reality. With 40 years combined industry experience across many verticals, I’m confident you’ll find the following pages rich with key insights about building, sustaining, and maintaining your cybersecurity program. I can’t think of two more qualified practitioners to lead the charge in shaping how we must evolve our approach to aligning cybersecurity programs with business objectives. Rock and Matt offer profound insights into how organizations should design, adapt, and embrace cybersecurity best practices to ensure business alignment. Gone are the days of selling your security program through Fear, Uncertainty, or Doubt (FUD). The era of digital business will require executive presence to claim your seat at the table. The success that has brought you to your current role is a good start. I’d like to disrupt your assumptions and inspire a deliberate review of

ix


x

Foreword

what you need to survive in the middle of the cybersecurity jungle. I would encourage you to consult this timeless, universally applicable reference in your journey forward. The CISO Evolution: Business Knowledge for Cybersecurity Executives is not only your survival guide – it’s a blueprint for the aspiring cybersecurity leaders of tomorrow. The concepts in this book are proven through multiple industries. As life learners, Rock and Matt hope to ignite a spark in you; meanwhile, their courage coupled with their commitment to give back to our community was the driving force that led to this seminal work. The only constant with our field is change, and the rate of change continues to intensify. If you think you’ve seen it all so far; I’m here to tell you we’ve not seen anything yet. The future holds boundless uncertainty! How do we stay current? More importantly, how do we embrace this change while ensuring alignment with the business? The answer is The CISO Evolution: Business Knowledge for Cybersecurity Executives. As you read this book, please keep in mind that most businesses are trying to move at the speed of innovation. We need something radically different. Rock and Matt are the industry experts prying open a new door to an unexplored path that will make us think differently about our cybersecurity programs. Demetrios Lazarikos (Laz) 3x CISO, 30+ Year Security Veteran Business and Technical Advisor Co-­Founder, Blue Lava


Preface

To know and not to do, is really not to know. —­Stephen R. Covey

G

o to enough conferences, and a clear pattern emerges. A few industry leaders have the courage and presence to impart wisdom. Yet, most of the industry is an echo chamber of platitudes. Maybe you’ve heard a hollow statement from a so-­called expert. These throwaway phrases reveal nothing, yet our colleagues masquerade behind them as thought leaders. The most insipid exam­ple, “Speak to the business in business terms.” For too long we have allowed one another to nod in agreement while behind the scenes we consistently fail to apply this wisdom and execute. This book provides a roadmap so that you can start asking the right questions, making the right investments, and delivering outcomes that matter. The first generation of CISOs learned that with confidence you can cast cybersecurity as a black art that cannot be measured. Eventually, the anecdotes and hopeful statements weren’t enough. Business leaders soon learned that cybersecurity knowledge is only part of the job. So, we have arrived at an inflection point. We can do better. We must do better. It’s time to evolve. The challenges of information sharing in our field are known, along with the talent crunch. To cultivate the future leaders of our profession we must exhibit the courage to be vulnerable, as people. Cryptocurrencies, IoT, and the public cloud will accelerate the demand for safe computing. Future economies will rise in cyberspace. The wars of the information age will be fought and won digitally. Competition is

xi


xii

Preface

no longer about company versus company. Instead, bundles of services and the most effective supply chains dictate the winners and losers of commerce. Courage is the path forward. It won’t be easy; it will require that we circumnavigate the legal constraints, licensing restrictions, fear, and self-­preservation that has prevented the requisite knowledge sharing and talent development. We fought back each of these dragons in the process of publishing this book. With the stakes higher than they have ever been, Rock and I hope to share our experience as builders, operators, and consultants. We are both experienced CISOs and MBA graduates. We have supported leaders who failed to convince their businesses of the importance of cybersecurity risk. We have lived these symptoms: Failure to garner trust from executive leadership ■■ Misaligned expectations around risk appetite and capital allocation ■■ Misperception of cybersecurity’s role in business ■■ Demoralization of your team in the face of cyber risk acceptance ■■ Increased stress and anxiety from managing an underfunded program ■■

As authors, we see the world through different lenses. We disagree in our politics, our management styles are varied, and we think this phase shift in values and approach will benefit you as the reader. Path dependence is when the decisions presented to people are dependent on historical experiences. So, we complement each other in the diversity of our experience and the order of our career transitions. Rock was an operator for years before starting his own consultancy. In contrast, I spent years in consulting before I was entrusted with the responsibility of operating a security program. Indeed, the world looks different from the vantage of a vendor versus that of an end user. You are treated differently, welcomed or not into circles of peers, and so the lessons you learn, the relationships you build, and soft skills you hone are a product of your path dependence. With this book, we created a streamlined business reference that is tailored to cybersecurity professionals. It will equip you with insights curated to develop your business acumen, communication, and


Preface

xiii

leadership skills. The chapters expand upon the content often delivered in MBA programs. Each of these capabilities is required by the modern CISO. We provide you with the tools you need to evolve from a technical leader into an effective cybersecurity executive. Each chapter is packed full of specific, practical advice and real-­life stories to help you communicate with business leaders, establish an executive presence, secure cybersecurity budgets, protect what matters, and not only enable, but also accelerate business outcomes. By contributing our mistakes and experience, we hope to fuel your success and stimulate more forthright dialogue in our industry. If you find value in this book, we’d love to hear from you. And if you disagree, take issue, or find room for us to improve, we’d love to hear from you too! You can find us at www.CISOEvolution.com, or on LinkedIn: Matthew K Sharp – https://www.linkedin.com/in/ciso-­mba/ ■■ Kyriakos “Rock” Lambros – https://www.linkedin.com/in/rock lambros/ ■■


Acknowledgments

W

e are grateful to all the people who helped us bring this project to life.

We thank our families that encouraged us and took on responsibilities we could not in the early mornings, long nights, and weekends spent to realize this book. Thank you for reviewing our early drafts, providing your guidance on the logo and cover, and creating space week after week. Thank you for your empathy through the challenges we faced and the mounting stress as the deadline for our final manuscript approached. Thank you for your reassuring words, patience, and believing in this book as we conquered each new surprise. Most of all, thank you for your hugs and for your loving support. Without them, this book would not have been possible. We thank the many individuals who invested their time to help review and refine the manuscript. The perspectives gained from CEOs, equity investors, industry analysts, consultants, MBA professors, and the many CISOs and cybersecurity professionals who contributed surely improved the accuracy and relevance of our content. We want to express specific gratitude to Kenneth Ziegler, Brian Ahern, and Lisa Xu, who helped in reviewing various chapters, offering revisions and insights and examining content from a CEO’s perspective. Karan Saberwal, Shaun Gordon, and Michael Lee were generous in extending their expertise as equity investors. Paul Proctor has been an inspiration for years. His work at Gartner continues to push the industry forward, and we were lucky enough to benefit from his passion and commitment to emphasize the most important ideas in our text. Timothy Galpin added his perspective with years in M&A consulting and more recently in academia xv


xvi

Acknowledgments

as a professor and academic director. Dave Hannigan and Caroline Wong were reviewers of our book proposal as we pursued a publisher and later contributed as valued reviewers. Their perspectives as cloud and application security pioneers, experienced operators, and mentors have been invaluable. Malcolm Harkins’s expertise as a successful Fortune 50 CISO and later entrepreneur has been a beacon, especially during our formative years in the profession. Marilyn Daly for her support in considering the impact of our words from a variety of unique perspectives. Demetrios Lazarikos for his generous time writing the foreword and being a dedicated mentor in cybersecurity and entrepreneurship. The Lean CISO group not already mentioned here: Philip Beyer, Russell Eubanks, Alex Kreilein, Sean Martin, and Jasper Ossentjuk for their friendship and for supporting physical and mental health throughout an unprecedented year. We thank them all for their guidance and the time each individual invested as it doubtlessly improved our book. We thank those who gave us permission to quote them, contributed graphics, extended our professional networks, and encouraged our work. Chris and Kristine Laping, Tage Tracy, Craig Fletcher, Stefan Peter Roos, Steven Martano, and Ryan Freilino: we thank you for your willingness to support this project. We thank the authors and experts who came before us. In many cases, we merely extended their theories, research, and formulated thoughts or shared our experience putting their ideas to work throughout our careers. In most cases, we are bridging other’s content into the world of cybersecurity. The Notes section at the end of each chapter does a great job capturing the people who inspired us in this regard. Without their deliberate contributions this body of work would not have been possible. Finally, we thank Richard Seiersen for his introduction to our publisher. And we thank our team at John Wiley & Sons for seeing the potential of this project: Susan Cerra, Sheck Cho, Samantha Enders, Michael Isralewitz, Beula Jaculin, and the countless others behind the scenes.


Introduction

I

n the foreword and preface we got aligned on the challenges our industry faces, our motivations for writing the book, and a bit about the authors. To help you use this book as reference in your day-­to-­day experience, we’ll now review the structure of the book and offer a summary of each chapter. First note that the book has three parts. So, if you plan to read the book front-­to-­back the flow is natural and the content is cumulative. Chapters at the back of the book assume you are capable of financial analysis, business cases, and other topics covered early on. In our view, it was important to first establish requisite Foundational Business Knowledge in Part I. That is where you will learn key vocabulary, basic financial formulas, and business strategy tools. We will also review business decision models, valuation methodologies, and business case development. Each chapter (or class) includes one or more case studies to apply the knowledge you’ve learned. That’s true throughout the book, and also true in any MBA program as well. What is different here is that our case studies are developed through the lens of the CISO, rather than a strict business perspective that surfaces in MBA curricula. Equipped with a common foundation of business knowledge and clear examples of how to apply the core concepts we move on to Part II – Communication and Education. Here you can expect a review of how to leverage COSO, an enterprise risk management framework, to ensure cybersecurity risk fits into the broader context of business risk management. Remember, cybersecurity risk is another risk that needs to be addressed along with financial, operational, strategic, legal, and compliance risk. Just as market, credit, and liquidity risks 1


2

Introduction

are types of financial risk, there are subcategories of cyber risk too. So, Part II is the connective tissue that ensures cybersecurity risk is properly framed and prioritized. Finally, assuming a foundation of business concepts and the proper governance structures for treating cybersecurity risk are in place, you need to lead a team and execute according to the priorities you have established and the projects you have funded. In Part III – Cybersecurity Leadership we review techniques for attracting and retaining talent, and finally negotiation skills that will help you navigate interactions with your employees, colleagues, investors, regulators, and outside vendors. Now that you know how the book is structured, it’s also important to understand how the chapters are structured throughout the book. Through personal stories we outline the opportunities we feel are most relevant at the very beginning of each chapter. Then we introduce theory or research in the Principle section. Next, each chapter extends theory with an Application section that features one or more illustrative case studies. In some cases, the names or details were adapted to protect the innocent. Finally, each chapter is summarized with a Key Insights section that draws out the salient lessons we hope you learn. There is also a Notes section provided at the end of each chapter that outlines supporting research and reference materials. We recommend that before you read a chapter, you read the Key Insights and examine the Table of Contents. Since we cover many high-­level frameworks quickly, this approach will be helpful to keep you oriented in the chapter and book. It’s also a speed-­reading technique. The following paragraphs provide a summary of each chapter.

Part I – Foundational Business Knowledge Chapter 1 – Financial Principles. This chapter builds your knowledge of financial statements, reviews connections between each statement, offers free resources for further study, and features two case studies that relate cybersecurity operations to accounting rules and financial statements. Read this chapter to solidify your understanding


Introduction

3

of EBITDA, CapEx, OpEx, Retained Earnings, and Net Income along with other fundamental vocabulary and accounting concepts. Chapter 2 – Business Strategy Tools. In the second chapter, we introduce business models, KPIs, and value chains. Other topics include board composition and systems theory. We provide a case study to demonstrate the use of the business model canvas. There are two additional case studies that feature value chain linkages to create competitive advantage. One case study features optimization while the second focuses on coordination. Read this chapter for tools that will help you dissect your business’s strategy, understand the supply and demand dynamics of your company operations, connect to primary business measures, and optimally position cybersecurity as a source of competitive advantage. Chapter 3 – Business Decisions. Our third chapter explores how business decisions are made. Decision-­making can be improved with an awareness of the biases and noise that commonly afflict us as human beings. We cover a lightweight application of the scientific method to enhance learning. From there, we dive into decision science and choice architecture frameworks. We briefly examine the use of an influence model, and then we finish the chapter with two case studies. The first case study examines various applications of the decision science framework in the context of a hypothetical new CISO scenario. In the second case study we apply choice architecture to phishing defense. Chapter 4 – Value Creation. The fourth chapter is all about business valuation. We naturally start by defining what we mean by value. Then, we examine the critical attributes of value. Next, we explore how those attributes surface in determining business valuations. Additionally, we examine investor types, means of return, valuation methodologies, and common value drivers. The application section covers the core concepts in a case study that applies security strategy in the context of business valuation for a hypothetical beverage manufacturer. Chapter 5 – Articulating the Business Case. To get the fifth chapter started, we review several important cost concepts including incremental, opportunity, and sunk cost. From there we explore a


4

Introduction

communication framework, and two financial analysis methods: cost benefit analysis and net present value. Finally, we close out the chapter with three case studies. The first examines a successful budget request for password management, and the second applies cost benefit analysis to the same project. The final case study leverages a Monte Carlo simulation to examine possible net present value outcomes of a revenue-­generating opportunity resulting from delivery of security services.

Part II – Communication and Education Chapter 6 – Cybersecurity: A Concern of the Business, Not Just IT. In Part II, we will build upon Part I and introduce additional tools that transform cyber risk issues into enterprise risk dialogue. This chapter starts to break down the COSO framework. It lays the foundation for elevating cyber risk conversations to enterprise risk by focusing on the first two guiding principles of COSO: ■■ ■■

Governance and Culture Strategy and Objective Setting

At the end of this chapter, the case study relives one of the author’s greatest regrets and warns of the consequences of failing to establish a robust governance structure. Chapter 7 – Translating Cyber Risk into Business Risk. Chapter 6 discussed establishing a cyber risk management program’s foundation using COSO’s first two guiding principles. This chapter expands upon those foundations and focuses on executing the cyber risk program and rolling up cyber risk into a portfolio view of enterprise risk that executive leaders, and the board, can use to make business decisions. To do this, we will align with the final three risk management components of COSO: Performance Review and Revision ■■ Information, Communication, and Reporting ■■ ■■


Introduction

5

The case study reveals how the author helped an organization align its cybersecurity program to its enterprise risk management efforts. This ultimately highlighted previously unknown risks and secured additional funding from its board of directors. Chapter 8 – Communication – You Do It Every Day (or Do You?). This chapter challenges you to examine how you communicate. It provides a structure to improve communication for the explicit purpose of advancing a cybersecurity program. We close this chapter by expanding upon the case study in Chapter 7. We take you into the boardroom to eavesdrop on the conversation between the author and the board of directors.

Part III – Cybersecurity Leadership Chapter 9 – Relationship Management. You cannot operate in a vacuum. A robust cybersecurity program relies on individual technical skills and interpersonal relationships. Read this chapter to master the four key skills of relationship management: maintaining trust, indirect influence, managing through conflict, and professional networking. We conclude with two case studies. The first demonstrates how some humble pie is the remedy to establishing greater trust. The second case study shows the importance of a professional network as the author transitioned from being an operator to an entrepreneur. Chapter 10 – Recruiting and Leading High Performing Teams. The cybersecurity skills gap is well documented yet hotly debated. However, as a leader, you must ensure you have the right people in the right roles at the right time. This chapter will dive into methodologies we utilized to attract, retain, and lead high-­performing teams. The case study walks through the perils of combining a bureaucratic hiring process with an inability to implement the hiring practices we advocate for in this chapter. The same case study then walks through what it was like to get “baptized by fire” in servant leadership. Chapter 11 – Managing Human Capital. Read this chapter for specific tools to baseline strengths, critical considerations in managing a multigenerational workforce, the importance of training, the criticality of


6

Introduction

diversity, and cognitive biases to be aware of that may rear themselves in our day-­to-­day jobs. The case study brings to bear a cost-­ benefit analysis technique outlined in Chapter 5 to demonstrate the actual value of training and the true cost of eliminating it from a constrained budget. Chapter 12 – Negotiation. In this penultimate chapter, we focus on adapting the skills from Chris Voss (a former FBI hostage negotiator) as featured in his book Never Split the Difference: Negotiating As If Your Life Depended On It. There are countless negotiations you perform every day. If you can be successful in your negotiations while preserving your relationships, you have what it takes to generate cultural change. The chapter concludes with a case study on building security culture and application security using the negotiation techniques introduced. Conclusion. We conclude the book with a heartfelt note of gratitude and an optimistic eye toward a brighter future. Engage us online at www.CISOEvolution.com


PART

Foundational Business Knowledge

I


CHAPTER

1

Financial Principles

Embrace Reality and Deal with It. — Ray Dalio

Opportunity It’s easy to get distracted by how you think things should be. Yet, it is critical to understand how they really are. Early in my career, I often identified ways that would make my work more efficient. When there was a dependency on resources I didn’t have, I usually stewed in frustration about how stupid the people were who designed such a flawed system in the first place. It wasn’t until years later that I learned optimizing all parts of a system does not necessarily optimize the system itself. You see, every organization has a mission and limited resources. Today, nearly all organizations in the modern economy deliver value through technology. However, not all organizations and leaders agree upon the importance of cybersecurity. As a cybersecurity leader, it’s your job to educate, build consensus, and secure necessary resources. Organizational mission and cybersecurity goals must be aligned. I think Malcolm Harkins said it 9


Turn static files into dynamic content formats.

Create a flipbook
The CISO Evolution: Business Knowledge for Cybersecurity Executives by TheDTE - Issuu