Building a Resilient Organization: Emphasizing Enterprise Security
CIOREVIEW >> Document Management >> NEWS

Pepperdine Graziadio Business School

Charla Griffy-Brown, Senior Associate Dean of Executive and Part-Time Programs

Building a Resilient Organization: Emphasizing Enterprise Security

Charla Griffy-Brown, Senior Associate Dean of Executive and Part-Time Programs
Charla Griffy-Brown, Senior Associate Dean of Executive and Part-Time Programs, Pepperdine Graziadio Business School

"In today's dynamic business landscape, it is crucial for organizations to build a proactive framework that equips them to address risks, rather than striving for risk elimination."

Charla Griffy-Brown began her carrier at Pepperdine Graziadio Business School as a Professor of Information Systems and has served for the last 24 years. She also holds the position of Associate Dean of Executive and Part-Time Programs, and prior to this, she was the chairperson at the Advisory Board Cyber Risk Professional Certification.  Charla has helped many executives and boards in privately and publicly traded firms leverage analytics, build cyber risk programs, and deploy technology to achieve greater efficiencies.

In an interview with CIOReview magazine, Charla discusses the challenges and trends that have reshaped enterprise security, emphasizing the need for a proactive, risk-based approach. Additionally, she provides industry leaders with valuable insights on navigating the evolving cybersecurity landscape while leveraging AI for a data-driven approach.

Please walk us through your background and the focus of your work at Pepperdine Graziadio Business School.

Over the last 20 to 30 years, my primary focus has been on emerging technologies, business innovation, cybersecurity and risk, analytics, and business strategy in rapidly changing and volatile markets. My journey in Pepperdine has revolved around working extensively in the cyber risk area with both large and small organizations, the Secret Service, Chief Information Security Officers, CIOs, and the FBI. Together, we have organized many conferences and worked with influential figures like Mayor Eric Garcetti , the mayor of Los Angeles, and Mayor Donald P. Wagner , the mayor of Irvine. With my global experience in countries like Japan, Australia, and various Asian countries, I am passionate about equipping our students with decision-making skills in today's dynamic business landscape.

Could you throw some light on the challenges or trends that have transformed the enterprise security space in recent years?

In recent years, enterprises have faced escalating challenges marked by significant growth in scale and complexity. One notable trend is the exponential increase in cybersecurity incidents globally. This trend is evident when visualizing the data, as illustrated in the Information is Beautiful website. It is a great site that provides an incredible visualization of what we have seen over the last few years. A thorough analysis of this data reveals a rapid surge in cybersecurity breaches, underscoring their profound global impact and increasing volume.

  ​To combat cyber threats, organizations must embrace a holistic approach that aligns people, processes, and advanced technologies on the same tangent.   

The interconnected nature of technology and the expanding attack surface contribute to these trends. As long as we continue to embrace technology without optimizing risk, this volume and acceleration of cyber threats will persist.

How do you see industry leaders pivoting their approach to address these challenges and ensure the security posture of their organizations?

Industry leaders are shifting their approach from solely relying on preventive and detective security measures to a more proactive and risk-based strategy. They recognize that in today's dynamic business landscape, it is crucial to build a proactive framework that equips them to address risks rather than striving for risk elimination. While traditional controls remain necessary, they have become inadequate in the face of evolving risks. To combat cyber threats, organizations must embrace a holistic approach that aligns people, processes, and advanced technologies on the same tangent. Cybersecurity is not just a technology problem. It involves vigilance, resilience, awareness, and effective priority-setting within the organization. Leaders must identify threats to their critical business assets, establish risk appetite, and allocate funding accordingly.

What advice would you give to industry leaders to navigate this changing landscape and leverage AI for a data-driven approach?

AI is a transformative technology, and cyber criminals are also well-versed in its use, necessitating different risk postures. However, it is essential to note that AI is just one element of the recommended approach, not the central piece.

First and foremost, leaders need to develop a comprehensive plan and actively practice its execution. Engaging senior executives and the board is vital to fully comprehend the implications of cybersecurity for the organization. Mapping threats to critical business assets and defining risk appetite will guide the development of effective cyber risk programs.

Organizations should prioritize behavior change by creating learning scenarios that foster awareness and emphasize the importance of questioning the type of risks that might be involved. Regular review of executives, consistent evaluation of focus areas, adherence to cyber hygiene practices, incentivizing collaboration, and adaptability to change are all vital for success.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.