Welcome to the KuppingerCole Analysts Chat. I'm your host. My name is Matthias Reinwarth. Today we are exploring some kind of critical evolution in cybersecurity leadership. So we're going far beyond technology. We're looking at leadership, at management and how to deal with people. We are joined by Jonathan Care to discuss how CISOs are transforming from security gatekeepers to business enablers through servant leadership principles. This is quite something to chew upon. First of all, welcome Jonathan. It's a pleasure to be on the Analysts Chat again. So I'm curious about this.
And the thing that sparked my curiosity is that CISOs, the role of the CISO has undeniably transformed. They used to be, well, as a doctor know, they used to be the security gatekeeper, the person who told you why you couldn't do what you wanted to do. And they transformed into business enablers, the person who would help you do what you want to do in a secure manner. And the transformation continues now with CISOs playing an active role in advising boards and indeed being a key part of executive management groups.
And I think the next evolution I see is the transformation of the CISO as a leader. And we are perhaps used to the very autocratic leader who says, you go and do this, you go and do that. And what I'm suggesting here is that the CISO transformed from being a highly directive leader into one who empowers their team to do the right thing. And so essentially, the CISO, through serving the needs of his team and helping the team to be highly effective, exercises an even greater domain of leadership. Right. And usually you say, if it ain't broken, don't fix it. So there's something to fix.
So let's look at the symptoms. Let's look at the current state. What are the challenges that CISOs face today with this traditional leadership approach?
Well, it's all in the mind. And that's indeed my first point. If you look at the lifetime of the traditional CISO, and we see this in the clients that we serve, we see this in the vendors that we advise, and we see this throughout the industry, CISO burn out quickly. The average lifetime of a CISO is about 18 months. That's an average. And I see an awful lot of extremely talented people on LinkedIn going, this was too much for me. I'm going to an alternative profession. I'm going to retire from the industry entirely. I'm going to downshift.
I'm going to do something less strategic, less stressful. And I think that point, and I am not a psychologist. I do have an interest in behavioral science. I do see that the friction caused by being the naysayer, being the person that says, you can't do this, you can't do that, creates a tremendous amount of friction. And dare I say it, cognitive dissonance in the CISO, who's ultimately tasked with being the accountable person for these no decisions. What's the consequence of security says no. We've all heard about it. And indeed, we're all seeing it.
Shadow IT, you can't put that information into chat GPT. We won't pay for you to have your a chat GPT instance.
Oh, okay. I'll just use my personal account.
Oh, I really need to have files accessible for anywhere while I'm traveling, whether it be a work or whether it be a working vacation, perhaps. And indeed, we see that people use cloud storage in highly unwise and highly insecure ways. And of course, once information is outside the domain of corporate control, it's out there, it's in the wind. So shadow IT is a challenge. Work around to the no culture challenge. The most excruciating example I can think of is the UK's tax service, Her Majesty's Revenue, or His Majesty's now, Revenue and Customs.
They, and this is in the public domain, I'm free to talk about it. They reported that they lost two DVDs containing the tax records of every adult taxpayer in the United Kingdom. They put the, they burned these DVDs, burned the data, put them into an envelope, consigned them to a courier who consequently lost them. Why did they do this?
Well, I strongly suspect that this is because they were unable to use the approved methods of government secure intranet to transfer this data in an approved secure manner. So they created a workaround and created the biggest breach in UK history. There is a disconnect between security teams and business units. And the big clue, it's a phrase that you and I, and everybody industry uses, oh yeah, I'm doing this for the business. The business want this.
Well, guess what? We're all part of the business. We're paid by the business. The business success reflects on us and vice versa. And so that disconnect is, again, an observable phenomenon. And the final one, as I mentioned, CISOs are in the enviable position now of being able to advise the board, which is excellent, and that's a great improvement.
However, it has brought into sharp relief the expectations a board will have versus operational reality. And this has seen a number of operational areas, especially obviously in the cybersecurity and identity domain, because we are one of the sharp edges. Right.
And when you say the balance that CISOs have to find between business demands and their security requirements, does the traditional command and control security approaches that we usually see and that many CISOs are still practicing and using on a daily basis, how does that even contribute to things getting worse or how can we change things then? I think you have to look at, yeah, again, human behaviors.
Humans, we go towards what we're motivated to go towards. And obviously in the business world, that traditionally means what do we bonus on? What are our pensions at risk if we do not do? So the question there is, well, how do we make sure that cybersecurity is part of the business demand? And of course, it's very challenging. And one example that occurred to me was I had a CISO who said to me, look, I have a real problem here. The board mandate, the CEO of a new business unit saying we must have the customer portal up in three weeks.
I am saying you can't put the customer portal live until it's done a security audit. So we know if it complies with our data privacy legislation. And so those kind of conflicts becomes a real problem. And there are many more scenarios. I mentioned shadow IT. We're seeing vendors out there now who are exploring what your identity is connected to. What cloud services are you authorizing with your identity? And of course, this is important because if you don't know that, then you have a whole underbelly of OAuth2 authorizations that you may not even be aware of. Right.
So when you've mentioned or suggested the topic of servant leadership as a topic for this podcast, I have to admit I had to read a bit. And the more I read into it, I realized that this is really an interesting topic because it changes the overall role of everybody and especially of the CISO. But for those of us who are not yet well introduced into the concept of servant leadership, can you give us a brief intro of what it is, why it matters, why it's so different and why we need it? Let's start with the one I mentioned as a CISO. And these are ideas.
And so for anybody in the audience who is strongly drawn towards or indeed strongly repelled by them, you should examine that motivation and why it is so. However, first of all, we as CISOs should empower our teams, not control them. We should empower operations teams, our architects, our application security specialists, our network security specialists to do the right thing. And what is that right thing? I hear you say. We need to demonstrate as CISOs that we serve the organization's mission while protecting it. Sounds simple? I hope so. Why do this?
Because the more we can demonstrate transparency, the more we can demonstrate our support for our teams, for the organization's mission, we build trust and therefore we are leading through influence rather than authority. So you're no longer doing something because you're afraid I'll fire you. You're doing something because you trust that I am leading you in the right direction. And that is far more powerful and is actually far more dynamic and agile and thus serves the needs of the organization, which can change, pivot and swivel very quickly indeed.
This is really a significant mind shift moving away from just giving orders to leading by example, by telling people, by educating them, by showing and by even enforcing them to do the right things themselves. How does this even look like practically for a CISO? How does that change their job description and how does a servant leader CISO work on a day-by-day basis?
One of the things that came to my mind when I was thinking about what this means, I remember back in my very, very younger day, and we're talking decades ago now, where I was involved in martial arts, used to teach jiu-jitsu, I noticed that my students would take on every one of my bad habits and perhaps 50 percent of the good habits that I was trying to teach them. I'm told that experience from my fellow teachers is not uncommon and indeed extends beyond martial arts to a number of domains. Sometimes it was very tempting to say, you know, honestly, JFDI, just fracking do it.
But if you can show people that you are collaborating with them on their risk assessment, rather than imposing a policy on them, so they feel they have intellectual and indeed emotional investment in the decisions that are being made. If you can try a principle of security champion, so rather than creating an ivory tower in the security operations center, which is still an important necessary function, you have capability spread across the business, you have security champions in operational business units, which is there I am doing in the business.
Across the company we all work for, we have people who are experts, who are points of advice, points of interaction and across the business, so they can participate in project development, product development. I've done this myself. I was one of the security champions in Visa and I spent time being embedded in development projects, working elbow by elbow with the dev teams, working on getting really rolling my sleeves up and getting into technicalities of risk of vulnerability management and so on. Which leads on to another point. What else can we do?
Well, if we can integrate security across functions, one of the challenges that we as a profession have been facing for a number of years is one of our most important client groups inside an organization are the development team. And we fail to speak the same language as the devs. We fail to speak the same language as the devs. Result being we fail to influence. We fail to collaborate on risk assessments. And so we can do better.
We can improve and change our behaviors so that we can involve transparent communication, ensure that threats and decisions are understood rather than sullenly complied with. You've mentioned this part of understood that security threats are understood. I'm curious about that balance. On the one hand, enabling business, as you've mentioned. On the other hand, still maintaining the core tasks of a CISO to make sure that security standards are understood and still being more collaborative, more together with your target groups and working with them in their language.
You've mentioned that example. For example, can I use JetJPT for my business? Can I use a cloud service for transferring the data of two DVDs from A to B because it does not work with the existing methods? But isn't there a risk of compromise when you allow this level of agency of autonomy also within your team? Absolutely there is. And I'm not suggesting that enablement means abrogation of responsibility. I'm not suggesting that the CISO becomes everyone's friend and gives them a hug and then everything will be all right. And that would be disingenuous to say the least.
An example I can give is, again, in my own career history in a very large payment cards company, which wasn't MasterCard. I think we even mentioned it already, but hey. We can go and look it up on LinkedIn.
Anyway, but in this company, I had a product owner who said, I presented a set of risks. He said, that's fine. I'll accept those risks. And the response was, with respect, these risks are too big for you to accept. We need to escalate this to a level of management above. In actual fact, that particular risk went in front of the executive management committee of that organization. It was a substantial risk. And so there is always a way. But nevertheless, note what we did. By being open, by working with people. In that case, I got the opportunity to speak to very senior management in Visa.
Very senior management. And I had the opportunity to influence them on the decisions that would enable good security practices rather than harm good security practices. So that's one example I would throw at why this worked. So I wasn't telling people, you can't do that. And thereby inviting people to find a workaround, find some way of doing what they went in, bending the rules. I was saying, let's work together. In this case, we need to go up and go up to quite a senior level in order that we can examine the risk in the appropriate context.
So from what I've read, so in the context of cybersecurity leadership, servant leadership is empowering teams while facilitating business success, building trust and collaboration, and leading with empathy. And I think all of this really sounds great for those who are just listening out there and try to put this into real life. So let's get specific. How can you actually start, initiate and actually live this transformation? How does that look like? Is there a case study or an example of a CISO who has done that?
You've mentioned that from your own perspective, but is there some visible case study that you can talk about? I think there is.
Yeah, there's an interesting one. I'm thinking of a quite large e-commerce business. They decided that, in fact, there's a couple, actually. There's another one. I'm thinking of a large broadcast media company. Decided that the approach to security management was not to have a central point of expertise, but to have operational advisors throughout the different business units. So through broadcast, through studios, through overseas. So all the different business units that the operating units of this business had.
And the result was, rather than saying, well, we need to go and refer this to security, project teams had the expertise to hand. Project teams could say, right, we can make decisions that we know will get through approval gates, that we know will not be blocked, will not require rework further down the project line. What does that mean?
Well, it means if you're following, for example, agile development, the technical debt that you're racking up is minimal or minimized at the very least. So there's two examples I can think of.
In fact, the third one is occurring to me now. A similar approach for a very large retail organization.
They, again, fed security expertise into project teams. The result being project teams, whether it's infrastructure, whether it's application development, whether it was rolling out the next gen of e-commerce, whether it was architectural design, had security expertise on tap. They knew where they were going and they knew what the right thing to do was. And what's the measurable outcome?
Well, one, as I say, is reduction in technical debt. The other one is expedited and indeed vastly improved project delivery time schedules. Resistance.
Well, part of the resistance actually is in us as security practitioners. As many of us have come to realize, there are a variety of mindsets that work in IT generally and indeed in cybersecurity and IAM. Some people are very outgoing, very communicative and will obviously fit well to this enabled empowered model. Other people are quite introverted. Other people are quite, yes, again, they have a rich inner dialogue, shall we say. And when asking them, hey, can you please be an outgoing introvert? I believe it's bordering on the physically painful for some people.
So we must, again, understand that different people have different mindsets, different ways of working. And so you can find when you say, there's no more Dr. No.
Well, unfortunately, some people say, well, actually, I quite like Dr. No, because that was my mental model that allowed me to keep the outside world at bay and stay in my rich internal dialogue. And so those things we need to be aware of. Yeah. If you look at, you've mentioned measurable outcomes and I want to get back to this because you've mentioned delivery time, which is great, but it's not as cybersecurity metrics. When we look at delegating more responsibility by leading through example, how can you measure that the success of this type of leadership actually is there?
How can you prove that? How can you demonstrate that to your leaders to say, okay, yeah, I did this new approach. It worked. One of the things about this, of course, is proof is a difficult and slippery word. I would suggest that it's quite difficult to run controlled studies in any business organization because business organizations are there to earn money.
However, we can detect, we can use a before and after measurement. So things we could measure, for example, our participation in security awareness.
Now, security awareness training is, as some people have said, a four letter word. It's not something that's welcomed. People are reluctant. And there's a considerable body of opinion to say that it lasts for at most 24 hours and possibly 24 minutes after the person finishes security awareness training. And there's a lot of thinking. There are a lot of people trying to do an awful lot in this space. And as you mentioned, some quite very smart and gifted psychologists are doing some things in this as well as obviously traditional security practitioners.
Everybody is trying to say, well, why is it so hard to change behaviors? Well, that's a question for another day. But that is one thing you can measure is the effectiveness and the retention and the change in behavior following a new model security awareness. People feel they are being enabled, empowered, and they are participating rather than being educated. Use a phrase that somebody used to me once. Another thing you can look at is the incident detection time. And obviously there's one measure where we can control this is during a penetration test or a red teaming exercise.
How long does it take before internal reports start filtering in about, hey, this is happening? That's actually a useful finding in itself. And it may be worth considering how we scope internal penetration tests. Should we actually scope it to do a covert entry, which of course is a traditional method, but then actually to make a bit of noise in the network as we traverse the network and see how long it takes for it to be reported. Because again, that's an important success metric. And I think it's also worth looking possibly harder to measure beyond simple, you know, bums on seats.
But what's the cross function project inclusion? How much do we see security expertise, security practitioners, and IAM practitioners being brought into projects? It's undeniable that any project will have a need for cyber security of some kind, even just to make sure they understand and develop within the architectural guidelines.
However, as you and I know, Matthias, identity is now front and center of every cyber security strategy on this planet anyway. And so the inclusion of IAM expertise, I think is also something to look for and note. If it's not mandated, but it happens organically as a result of program managers saying, we need this, that's a success metric there. Something we don't do very much, and I think we need to do more. And certainly post COVID, the idea of employee satisfaction has perhaps dipped down a little bit.
But one area that we could include on these satisfaction surveys is people's satisfaction with the cyber security function within the organization. Do you feel it helps you do your job? Do you feel it limits you? How many times have you asked for help or for a particular functionality? Was that help useful? Was it not useful?
So again, looking at outcomes, I think would be very useful there. And again, measuring these metrics.
And where, of course, we're getting to is there are a whole bunch of measurable activities where we can see whether we are truly acting in partnership or whether we are still acting in opposition. Right. And if you keep the values before and after and compare them, I think that's actually, that's measurable. You can prove success. And this is not a new approach. Do you have any insights into unexpected surprise benefits that organizations have experienced from this approach? So something that was not actually on the plan, but actually turned out to be an additional effect?
I think one of the interesting things, again, going back to the large retail organization, one of the technical infrastructure operation teams shyly took me aside one day and said, hey, you know, we've done something we think we'd like to show you. And what they presented was this really interesting and quite compelling thesis. They'd uncovered a flaw in the cash registers, which would have meant that pricing and between the shelf and the cash register would have been wrong. And that's a bad thing. And at scale actually means the retailer is trading unlawfully.
And this would be a problem at scale. And so they said, what do you think we could do about this? And I said, well, have you tried talking to the CIO and the IT board? And they said, well, we tried. And he handed me this great big thesis and said, here's my in sick report.
I said, I don't think they've read it. I thought, well, no, and that's why. But when I said, look, organize a demonstration, use the retail development lab that this organization had to demonstrate this, take a video, something we can show to the board. So we show, not tell. And the board went, yeah, got it. And the changes made forthwith. That sounds really good. I think we are telling a story here, or you are telling a story here, that might convince one or the other CISO to start making that shift. Where should they start? Is there a way that they can dip just one toe into the water?
What would be a first step to start to move towards more servant leadership in cybersecurity? I think the first step is self-assessment of one's own current leadership style. And certainly something I noticed is that when I first examined it, I thought, no, actually, I am quite autocratic.
I'm like, go and do this. And if you can't, please fold yourself up into a box and jump off, jump into the sea. I thought this is not the way to engage people. If they do what I ask, they will do so grudgingly and sullenly. They are more likely to find ways that they can do the bare minimum of what I ask and perhaps even skirt around what I am demanding. And so my self-assessment of my current leadership style was, I am overly directed, bordering on the autocratic. Look at some management development frameworks. A lot of these things are sitting on bookshelves around the world, gathering dust.
But look at Kenneth Blanchard's situational leadership, where you can start off being quite directive. As the team grows in confidence, grows in maturity, you can be delegate more and more and start handing things off.
Again, quick wins are always something we look for in pretty much any part of IT. We're looking for ways that we can demonstrate value, show that what we're doing is actually a good thing. And so what quick wins can we identify right now to improve our relationship? And for example, just as you know, just before this recording, Matthias, you and I were talking about, hey, here's a tool set I think would really help the advisory team.
Hey, here's something which I'm working, which I think is interesting. What am I doing there? I am relationship building with a colleague. I didn't plan that as a case study. It just didn't work out rather well. Willing partners and departments, as I did before this call, as you said, you're pushing an open door here. And I'm like, oh, well, that's good. Then that's a great place to start. I'm finding someone who has the same mindset.
But again, what are we doing? Well, we're changing, we're shifting our communication strategy. We're making ourselves easy to work with.
So yeah, but we are advisors. I'm an advisor. So on the one hand, we try to support organizations, CISOs to do the right stuff. On the other hand, they do not have to make each mistake for themselves. So maybe we can tell them what are the common pitfalls, resistant points that they should expect and maybe can avoid. Where would you put some recommendations? The big challenge, I think, and I think the one that everybody has secretly or no, perhaps, is if I present myself as overly flexible, overly cooperative, people will think I'm a pushover and they'll lose any authority.
So it's the fear of losing control is one of the big challenges here. And again, that's an internal challenge. That's an internal resistance point. The second challenge, I suspect, is actually when you get out into the field and you find actually people really will try and ignore you and so on.
Well, take my example to heart there. I had a product manager who did try and dismiss me.
He said, oh no. I said, this is a risk. This is a big risk. And he said, oh, well, I'll accept that risk. With respect, this risk is too big for you to accept. We need to escalate it. Involving the next level, if required, would be helpful. It's a bit pointing to the upper ranks, but sometimes it helps. Sometimes it helps. And of course, we need to be able to communicate at the level and in the mode that the upper ranks like to be communicating. And I would give that example back of the retail organization. These infrastructure operation group had created a beautiful inch thick report.
And I'm not exaggerating. It literally was an inch thick. Expecting CIOs and top management to read something is ambitious at best. It's highly unlikely that any senior manager is going to have the time to read through an inch thick report.
Therefore, the way we communicate, the modality, the level of information, the level of specificity that we should provide differs at a more senior level of management. And so again, as security practitioners, as CISOs, we need to have the flexibility. And that's a challenge. We can't communicate the same way with a bunch of engineers or devs that we would with the board, with the CIO. Right. So when you told me that we could do an episode on that topic, of course, I did my own research because I wanted to be prepared.
And once you ask your favorite search engine, your favorite AI about this topic, there is really a lot of stuff out there. So to drill this a bit down or to narrow it down, are there any specific tools, frameworks, books, resources that you would recommend for CISOs who are embarking on that journey that you would say, this is good?
Well, I'm a big fan and something I read many years ago of Kenneth Blanchard's work on situational management. I'm a big fan of behavioral approaches.
So again, I was, you know, again, the work that's being done on the different roles that people play in teams. And so we have, again, those colleagues who are extremely valuable, who are very bright, who are a source of ideas, but they are not the people who will drive a project to finish. They're not the people who will get the project team together and say, come on, guys, we're taking this to the finish line. And so understanding, again, things like Belbin team personality types, understanding situational leadership, all these things are useful. And none of it is, none of it's voodoo.
In fact, none of it's rocket science. It's an extension probably of skills that we have already. Can we expect some research from you in that area to be published at Kuping et al's website? I'm very interested in writing some research in this.
And yes, I'm planning to write research notes on this. I think it's important that we talk to our CISOs, our CISO members about how the role is changing and how they deal with that. Right.
Looking, really looking forward to that. So watch that space. We've only talked about the CISO. There are so many other cybersecurity roles. Do you expect that this evolution that you just described, moving to a different kind of leadership, different kind of teamwork approach, do you expect that to impact the broader cybersecurity landscape as well? Will that be infectious? So I used to work at Sun Microsystems and a long time ago, and frankly, it was one of the best jobs I ever had. And I guess now the company's dissolved. I probably won't be going back there. But I very...
Don't let your girl. I think now, yes, now I, now I was, Sun Microsystems is no more. But I remember coming back from a meeting and I said to my manager, gosh, I met with this guy. Why is he like that? And he said something that stuck with me.
He said, what you see from that person is actually reflective of what the attitude of their manager is when they're not putting on a front for partners across the organization, which was my role. And I thought that was incredibly insightful. And it goes to what I was saying about when I used to teach jujitsu before I became old and fat, that students or indeed your subordinates, your team, your colleagues, they will pick up on the behaviors you exhibit.
So if you want your team to be thinking more about enablement, thinking more about serving the organization, supporting organizational goals, then you have to demonstrate that behavior, which is why I said CISO, CISO, CISO three out, because behavior change at the top of a business unit at the top will percolate down through that, through that business unit, through that organization. Right. So that would be the advice that you also would give to boards and executive to support this evolution in their CISOs? I would. I would. I think boards obviously have different priorities.
Boards are not looking at operational goals. They are much more strategic. And so they are at least one or two levels of abstraction removed from where an operational role like a CISO would be. Nevertheless, being able to demonstrate those values and say, giving the hint to the CISO that this kind of behavior is the behavior that these are the values that the organization shares, I think is a great idea. And I think it does not make the CISO's job easier. It changes it. It makes it more responsible, leading away from this order mentality, more to a leadership, to a collaborative approach.
But I think it makes it more fulfilling to say, OK, let's steer a team. It's absolutely not easy.
We, if we follow this route, have to exercise a lot of control over our feelings. We have to be able to detach when a situation makes us emotional. We have to say, well, I detach from this and I'm sticking with my principles of what's the thing, what's the right thing to do. So it's not easy. I would say the easy thing to do is just to say, you know what, Matthias, I'm just too busy right now. Just go and do it. Right. We've got the security policy. Don't bother me with these details. That's not servant leadership. I'd say that's the opposite. That's going back to autocracy.
And the approach that this requires is to be more engaged, is to communicate, is to, you know, if you had a bad weekend and the dog ran away and all the rest of it, you have to put that behind you and say, I'm here now. I need to serve the principles of the organization. Absolutely fascinating. Thank you very much, Jonathan. This is really insightful and also sparked some really interesting ideas in me. So I want to follow up on that afterwards.
Before we wrap up, when there's one key takeaway that you want our audience to remember about servant leadership, even if they say it sounds good, but maybe not for me, what would be your recommendation? This one thing, this one takeaway that you would like to implant into those brains?
Well, I think probably like many people, I was drawn to cybersecurity because of the exciting technology. And then I discovered that I needed to write policies in order to establish governance over the exciting technology. What I'm actually saying here is that there's a third level of evolution, which is it's about people and culture. And that approach that we've outlined on this conversation today, I think offers a path to build both stronger security and stronger business relationships. That sounds good.
So my usual sentences at the end of such an episode, and especially for something that is really so, so much sparking conversation discussions. If you have any questions, if you have any comments regarding everything that Jonathan said, that I said, that we covered in this episode, please leave your comments below this YouTube video or wherever you watch or listen to this episode. We are really keen on hearing what you think of what we just presented.
We want to do a follow-up and I love these not so much technical episodes very much because all of this, as you described, these different levels are important and we want to cover that also in the analyst chat. If you have direct questions, reach out to Jonathan or to me on the platform of your choice. We are on LinkedIn, easy to find there. Communicate with us, send us a mail. We want to follow up on that. So please do and we will. Thank you very much, Jonathan, for being my guest today. That was really a great approach presented here.
So this servant leadership is something that could benefit many organizations. It's not an easy job to do. You mentioned that. If there are any more questions, reach out to us. There will be research, Jonathan has promised. So this will be there available and for the time being, looking forward to having you again as a guest, Jonathan. Thank you for your time. Thank you. Thank you. Bye-bye. Bye-bye.