{"id":42219,"date":"2023-10-18T22:26:27","date_gmt":"2023-10-19T02:26:27","guid":{"rendered":"https:\/\/www.itworldcanada.com?p=549908"},"modified":"2023-10-18T22:26:27","modified_gmt":"2023-10-19T02:26:27","slug":"maplesec-how-to-stop-csos-from-saying-goodbye","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/maplesec-how-to-stop-csos-from-saying-goodbye\/","title":{"rendered":"MapleSEC: How to stop CSOs from saying, \u2018Goodbye\u2019"},"content":{"rendered":"<p>Increasing cyber attacks and the pressures COVID put on organizations is making chief security officers and their equivalents think of the unthinkable: Quitting.<\/p>\n<p>In fact, Gartner believes by 2025\/26, almost half of current CSOs will have left their job for another post, and of them, 25 per cent will leave cybersecurity.<\/p>\n<p>Some call this The Great Resignation. Gartner calls it The Great Reflection, as infosec leaders reflect on whether they can find a balance between work and their personal life. Sometimes they conclude the solution is walking out the door.<\/p>\n<p>With the current talent shortage, that&#8217;s not sustainable.<\/p>\n<p>At this week&#8217;s IT World Canada <a href=\"https:\/\/www.itworldcanada.com\/maplesec\">MapleSEC<\/a> security education event, two Gartner experts discussed what individuals and corporate leaders can to do halt this trend.<\/p>\n<p>&#8220;Part of the challenge CSOs face &#8230; is you feel like you&#8217;re pioneering what you&#8217;re doing while you&#8217;re executing it,&#8221; said<b> <\/b>Geoff Crampton, an Ottawa-based Gartner executive partner. That&#8217;s in part because the CSO role is relatively new. Also, many CSOs have risen through IT positions, but today the C-suite demands members be business leaders, which isn&#8217;t a competency many CSOs have.<\/p>\n<p>&#8220;You really have to sit down and figure out where are you going to invest your time, how are you going to invest your time, and what&#8217;s the most important place to put your time,&#8221; Crampton said.<\/p>\n<p>Satyamoorthy Kabilan, a senior executive partner at Gartner and former director of national security and strategic foresight at the Conference Board of Canada, said CSOs should take a page from research done on others who face high-stress periods: First responders, such as police and firefighters, as well as emergency managers. One lesson: In an emergency, you can&#8217;t run 24\/7 for a week, you need a team that can step in for you.<\/p>\n<p>So he advises CSOs to build a team that can share duties in a crisis.<\/p>\n<p>And sharing responsibility, he added, is a great motivation for others on the infosec team to stay with the company.<\/p>\n<p>Meanwhile, corporate managers need to help take the load off the backs of CSO, said Crampton. &#8220;That starts with the organization understanding that cybersecurity is everyone&#8217;s responsibility. This is not a technical issue, this is not for one person to have to carry on their shoulders.&#8221;<\/p>\n<p>The way senior management does that is by recognizing that cybersecurity issues are enterprise risk issues.<\/p>\n<p>Gartner calls this the organization&#8217;s cyber judgment: Its ability to make risk-based decisions on a number of factors, including cybersecurity.<\/p>\n<p>When an organization has good cyber judgment, Kabilan said, the CSO won&#8217;t be seen as &#8220;the blocker&#8221; of innovation. To do that, he added, the CSO has to understand the business&#8217;s needs.<\/p>\n<p>Ultimately, Kabilan said, it&#8217;s up to senior management to decide if they have a great CSO &#8212; or a potential CSO &#8212; to make sure the organization develops and keeps them.<\/p>\n<p>&#8220;We want CSOs to move from a role that prevents breaches to a leader that facilitates risk management,&#8221; Crampton concluded. &#8220;Second, we want to move from cyber risk being seen as a security problem to cyber risk as a business or organizational risk. Third, security can&#8217;t be seen as a roadblock. We want to re-frame that to &#8216;Security enables agile secure products and business operations.&#8217;<\/p>\n<p>&#8220;If we can find those three reframings happening over the coming years, these positions will become much more supported in our organizations and [infosec] people will feel supported.&#8221;<\/p>\n<p>The post <a href=\"https:\/\/www.itworldcanada.com\/article\/maplesec-how-to-stop-csos-from-saying-goodbye\/549908\">MapleSEC: How to stop CSOs from saying, \u2018Goodbye\u2019<\/a> first appeared on <a href=\"https:\/\/www.itworldcanada.com\/\">IT World Canada<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSOs need to find ways of not shouldering the entire burden of cybersecurity in their organizations, say experts &#8212; and senior leadership has a role i<\/p>\n","protected":false},"author":17,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16,1020],"tags":[391,489,393,275],"class_list":["post-42219","post","type-post","status-publish","format-standard","hentry","category-leadership","category-security","category-training-and-development","tag-di","tag-it-jobs","tag-security-strategies","tag-top-story"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/42219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=42219"}],"version-history":[{"count":0,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/42219\/revisions"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=42219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=42219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=42219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}