Building The Right Team For Strengthening Cybersecurity
CIOREVIEW >> Identity Governance and Administration >> NEWS

Motor Oil

Christos Syngelakis, Group Chief Information Security Officer

Building The Right Team For Strengthening Cybersecurity

Christos Syngelakis, Group Chief Information Security Officer
Christos Syngelakis, Group Chief Information Security Officer, Motor Oil

Christos Syngelakis has had an exemplified record of working in the oil & energy industry for over 35 years, 18 of which saw him serving as an IT infrastructure and operations manager for different industries. His work mainly concentrated on optimized data usage and augmenting cybersecurity strategies.

In an interview with Enterprise Security Magazine APAC, Christos Syngelakis sheds light on some of the prevailing challenges in enterprise security management and how setting up the right team, rather than ChatGPT and AI technologies, can play an instrumental role in strengthening cybersecurity dynamics.

How do you think current trends like ChatGPT will make a difference in the cyber security space in the future?

ChatGPT and all these AI-driven technologies are remote at this time, and by that, I do not mean that they will not be engaged soon. But in the security industry, the infrastructure is of prime importance. ChatGPT and other AI technologies would be instrumental in sharing knowledge about attack and defense strategies, but it is limited to novices. The experts already know how to work around their way in cyber security, and the present products in the market already use AI input for functioning.

The central aspect of cybersecurity space is an endless to-andfro of attack and defense between machines. However, it is not always true. You cannot decide the defense based on the machine input because the environment varies. Using the same motive to defend in one environment can be catastrophic in another. So yes, the presence of AI would boost our attack and defense strategies, but it is not the main aspect of cyber defense.

What are the current limitations faced by cybersecurity experts?

The limitations depend on the industry that one is in. If you are talking about the IT industry, the problems can be with regulations, compliances, or even with intellectual properties. To assess how safe the environment is, some robust solutions can be implemented if the company's mentality is appropriate and you have inside support.

 To implement these, you need to have a team in sight because these are very people besides the company who knows the latter inside out – the mentality and everyday activity of the company, the dayto-day problems, etc. Such teams set the right direction for the company to move on 

But suppose you take the other works of the core team, like industrial security and power computing. In that case, we see the need to always be connected and engage in information transfer between different segments like the customers and the management. There is a huge underlying issue in the industrial environment due to a lack of security. Let me divide the problem into two areas. The first is the office area. You can solve problems with the right mentality, money, and manpower. The other area is the industrial environment, with far too many problems. With multiple ongoing things and a dearth of solutions, it is not possible to hold one person responsible for the issues.

From the engineering perspective, industrial engineers are adept at running the infrastructure. But issues arise from the cybersecurity perspective. Such critical problems can have deep implications for the public.

What would be your word of advice for your peers in the industry?

The first piece of advice would be to remain true to your words when speaking with other guys. Do not give into fear and offer them the real picture since you have a problem. Even if you show them the real picture, admit that you have run into some problems, but they can be overcome easily. If you are not part of the solution, you are part of the problem. Overcoming your fear can help you achieve a lot of things. With too many tasks, you would require all the support you get.

Of course, it is not easy to discuss such topics with the upper management level. The upper management level does not only handle internal security problems. There are thousands of other problems and risks that they face. Even though you might not be the only one concerned about safeguarding the organization, you should not write that off as a risk.

How significant is it for companies to discover the right talent and expertise in cyber security?

There are two ways how you can access the work. The first would be strategic planning and architecturing. To implement these, you need to have a team in sight because these are very people besides the company who knows the latter inside out – the mentality and everyday activity of the company, the day-to-day problems, etc. Such teams set the right direction for the company to move on. So from my point of view, accounting and outsourcing CSOs will give you momentum as a company. Of course, it is not easy to find the right person. The ideal CSO would have the perfect technical knowledge and soft skills balance. It isn't easy to find a person with this kind of expertise in the market. Of course, too many novices are filling up the positions instead. It is up to the companies to debate the right team, but unfortunately, there is a huge shortage in the market.

What kind of team expertise are you fixating on?

First, you must have someone with strategic knowledge and the ability to speak before upper-level management. Besides, he must have someone in the internal team who can understand technical architecture and orchestrate outsourcing. He must be in a position to report to the CSO directly, and of course, there must be someone from the GRC perspective to run the risk-based approach, the risk assessments, and the compliances. In the end, all these must be in complete alliance with IT and end IT personnel.

Christos Syngelakis has had an exemplified record of working in the oil & energy industry for over 35 years, 18 of which saw him serving as an IT infrastructure and operations manager for different industries. His work mainly concentrated on optimized data usage and augmenting cybersecurity strategies.

In an interview with Enterprise Security Magazine APAC, Christos Syngelakis sheds light on some of the prevailing challenges in enterprise security management and how setting up the right team, rather than ChatGPT and AI technologies, can play an instrumental role in strengthening cybersecurity dynamics.

How do you think current trends like ChatGPT will make a difference in the cyber security space in the future?

ChatGPT and all these AI-driven technologies are remote at this time, and by that, I do not mean that they will not be engaged soon. But in the security industry, the infrastructure is of prime importance. ChatGPT and other AI technologies would be instrumental in sharing knowledge about attack and defense strategies, but it is limited to novices. The experts already know how to work around their way in cyber security, and the present products in the market already use AI input for functioning.

The central aspect of cybersecurity space is an endless to-andfro of attack and defense between machines. However, it is not always true. You cannot decide the defense based on the machine input because the environment varies. Using the same motive to defend in one environment can be catastrophic in another. So yes, the presence of AI would boost our attack and defense strategies, but it is not the main aspect of cyber defense.

What are the current limitations faced by cybersecurity experts?

The limitations depend on the industry that one is in. If you are talking about the IT industry, the problems can be with regulations, compliances, or even with intellectual properties. To assess how safe the environment is, some robust solutions can be implemented if the company's mentality is appropriate and you have inside support.

But suppose you take the other works of the core team, like industrial security and power computing. In that case, we see the need to always be connected and engage in information transfer between different segments like the customers and the management. There is a huge underlying issue in the industrial environment due to a lack of security. Let me divide the problem into two areas. The first is the office area. You can solve problems with the right mentality, money, and manpower. The other area is the industrial environment, with far too many problems. With multiple ongoing things and a dearth of solutions, it is not possible to hold one person responsible for the issues.

From the engineering perspective, industrial engineers are adept at running the infrastructure. But issues arise from the cybersecurity perspective. Such critical problems can have deep implications for the public.

What would be your word of advice for your peers in the industry?

The first piece of advice would be to remain true to your words when speaking with other guys. Do not give into fear and offer them the real picture since you have a problem. Even if you show them the real picture, admit that you have run into some problems, but they can be overcome easily. If you are not part of the solution, you are part of the problem. Overcoming your fear can help you achieve a lot of things. With too many tasks, you would require all the support you get.

Of course, it is not easy to discuss such topics with the upper management level. The upper management level does not only handle internal security problems. There are thousands of other problems and risks that they face. Even though you might not be the only one concerned about safeguarding the organization, you should not write that off as a risk.

How significant is it for companies to discover the right talent and expertise in cyber security?

There are two ways how you can access the work. The first would be strategic planning and architecturing. To implement these, you need to have a team in sight because these are very people besides the company who knows the latter inside out – the mentality and everyday activity of the company, the day-to-day problems, etc. Such teams set the right direction for the company to move on. So from my point of view, accounting and outsourcing CSOs will give you momentum as a company. Of course, it is not easy to find the right person. The ideal CSO would have the perfect technical knowledge and soft skills balance. It isn't easy to find a person with this kind of expertise in the market. Of course, too many novices are filling up the positions instead. It is up to the companies to debate the right team, but unfortunately, there is a huge shortage in the market.

What kind of team expertise are you fixating on?

First, you must have someone with strategic knowledge and the ability to speak before upper-level management. Besides, he must have someone in the internal team who can understand technical architecture and orchestrate outsourcing. He must be in a position to report to the CSO directly, and of course, there must be someone from the GRC perspective to run the risk-based approach, the risk assessments, and the compliances. In the end, all these must be in complete alliance with IT and end IT personnel.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.