To Kill a Security Program
CIOREVIEW >> Security >> NEWS

Cyber and Information Security Director at Inteva Products

Ahmeed Ahmeed

To Kill a Security Program

Ahmeed Ahmeed
Ahmeed Ahmeed, Cyber and Information Security Director at Inteva Products

Let me sell you this pen. It is more expensive than others, less convenient to use, and writes slower. But it’s the safest pen in the world. Are you interested?

Security groups, whether Cyber Security or Information Security, can be significantly different in structure and operation across organizations. However, most security groups share a common ground. Structurally, Security teams are usually understaffed for multiple different reasons. This forces leaders to either take a minimal approach, leaving gaps in their environment or to pressure their analysts to wear multiple hats and run at the edge of burnout. On the Operational side, the common ground is about security groups being somewhat accountable for everything and owning almost nothing, making it dependent on all other functional areas to deploy its own initiatives.  Such dependency puts security at the mercy of those functions’ priorities, schedules, resource availability, and motivations. Getting other functions to adopt a security initiative is a pretty tough sell; after all, most security initiatives are not going to save them money, time, resources, nor will make their job more convenient, but we will get to that later.

Taking all those challenges into consideration, it is obvious that undertaking a security program or initiative is extremely difficult. But that’s not the main reason why security initiatives fail. Most initiatives fail due to self-inflicting wounds turning the exciting challenges into resume-generating events.

Here are the top five mistakes new security leaders make when deploying an Information or Cyber Security program, or large-size security initiative:

Seeking the magic wand

The most common mistake is the “magic wand” or “Silver bullet” trap. In many cases, cyber security personnel come from an IT background, and most of the successful ones have grown their careers to design, develop, or configure a system that considers all possibilities (outages, bugs, anomalies, etc.,). What-if scenarios dominate the design processes and trigger many design-changing test results. Unfortunately, that engineering mentality, the desire to fully control or eliminate an issue, is not successful with security.

While most security professionals live their lives by Risk Management principals, many still funnel into the magic wand trap either by nature or through the influence of the resisting audience. The resisting audience will usually point out the imperfections in control points, the ways that a security control can be evaded, and the gaps that control will not cover. These arguments soon escalate to “Do we really need to do this? It’s not really solving the issue.”

The best approach to stop the resistance is to consider Risk Management principals. Risk is comprised of two dimensions, the potential impact a threat causes, and the probability that it will take place. Risk treatment rarely resolves the risk, and in most cases just mitigates it by reducing the impact or probability or both.

There is no silver bullet, focus on risk treatment.

Boiling the Ocean

Security covers a massive landscape and affects all functions (similar to other SG&A, a horizontal element in Porter’s value chain). Organizations that are starting an information security program are often overwhelmed by the vastness of the program's surface as well as its depth. Dissecting the elephant, which is the usual answer, is also tricky because all of the pieces of information security programs are highly interconnected with each other. The lines of separation are blurry, and leaders can easily fall into the trap of trying to make everything happen at once, again.

 A successful security leader will assume the role of a business consultant in the information security area, taking on the process of getting the executive suite onboard through education, not just providing information 

The best approach here is to follow the discipline of focus (referencing Sean Covey’s four disciplines of execution) and keep the scope of work in check. As for how to dissect the elephant, it’s done by picking a framework that works for your organization such as NIST800 (or ISO27001 if your organization is an international entity) to help set lines between the areas. 

Do less, do it better.

Doing it for the sake of doing it

Another common mistake is to lose sight of the objective and do something because it exists. There is a great difference between deploying a security control for the sake of checking a box in a compliance audit versus mitigating a critical risk. Not everything in the security framework has equal weight. these different areas have different risk levels from one organization to another, one department to another, and even from one type of data to another. Remember your objectives.

Eyes on the ball.

Keeping it to Yourself and Keeping it Technical

While IT can deploy a new system that helps the business, finance changes accounting structure and reporting, HR updates its code of conduct with new policies. Security is unique in the sense that its initiatives are deployed by others and the products of the work are typically not desired by its receivers. 

Security programs without management support will get nowhere. A successful security leader will assume the role of a business consultant in the information security area, taking on the process of getting the executive suite onboard through education, not just providing information. By providing them the ability to make sound decisions through quantifying and qualifying risk in business terms, not technical terms. Once the board is “on board” next is a marketing campaign. A successful security leader educates the organizational culture to be security aware and oriented. This is a long-term process, that involves educating the audience on how the controls work, as well as how they mitigate risks (represented by their terms). This requires training, persuasion, developing a mindset, and making a culture change. While a program won’t get anywhere without management support, a program won’t get far without middle management and workforce support. If a leader is patient enough in this process, the resistors will eventually turn into allies. This is the longest and most difficult part of starting an information security program.

Evangelize security in the audience’s language.

Run and Done

“A ship that sails without a compass will get lost at sea” - Matshona Dhliwayo. The last point worth mentioning here is to measure as much as possible. Leaders who fail to measure the effectiveness and efficiency of their initiatives are more likely to cost the organization more than benefit it. 

Measure, measure, cut.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.