CISO

Cybersecurity in the “When-Not-If” Era by Jean-Christophe Gaillard

The “When-Not-If” paradigm around cyber-attacks is changing the deal completely around cybersecurity.

Many large organisations now assume that breaches are simply inevitable, due to the inherent complexity of their business models and the multiplication of attack surfaces and attack vectors which comes with it.

The Two Factors Killing GRC Practices by Jean-Christophe Gaillard

Many CISOs complain of communication problems with their business. They are not being listened to. They are not getting the budget they think they should get. They feel their business prioritises against security too often.

It has been a recurring theme amongst information security professionals for the best part of the last 15 years, and it is rooted in a wide range of factors, amongst which the profile of the CISO is often a dominant limitation.

Who wants to be a CISO? by Jean-Christophe Gaillard

Who wants to be a CISO these days? And at which stage in your career should you consider the move? What balance of managerial and technical experience do you need to have? And where do you go from there? (what’s the step after next? … always the most important question in terms of career development)

Those would be valid questions for many executive positions but when it comes to the role of the CISO, they seem to acquire a different meaning.

Large Firms: What role for the Group CISO? by Jean-Christophe Gaillard

The same title often hides a large diversity of roles, positioned differently across their respective organisations. It often reflects the maturity of each firm towards the appreciation of the threats it faces, the need for business protection, and its appetite for controls.

For large groups, in particular where business units or geographies manage their own bottom line and have a significant degree of autonomy in real terms, it can result in a large population of security practitioners across the group with very diverse approaches, objectives and priorities.

The First 100 Days of the New CISO: Expectations vs. Reality by Jean-Christophe Gaillard

A painfully recurrent complaint among Chief Information Security Officers (CISO) is the disconnect between what they were promised during the recruitment process, and the actual situation they find upon starting the job.

Indeed, it is quite common to hear freshly-hired CISOs blame their less-than-smooth transition into the role on “broken promises” (some explicit and some simply assumed) such as inadequate resources or insufficient attention dedicated to cybersecurity by key stakeholders.

Why are we still talking about the reporting line of the CISO? By Jean-Christophe Gaillard

The right reporting line is the one that works. Period.

Why are so many organisations and security professionals still worried about the reporting line of the CISO? This is one of the oldest and most consistent debate agitating the security industry, and it looks far from resolved.

Three factors marginalising the historical role of the CISO by Jean-Christophe Gaillard

The last SASIG meeting in London on 8th May 2018 examined the role and career of the CISO. It is hard to walk out of an event like this one not feeling that a number of things are seriously going round in circle in the security industry.

GDPR: Where are we now? And what happens next? by Jean-Christophe Gaillard

So … May 25th came and went, quickly followed by the football world cup and a heatwave which wrecked most of Europe and many other parts of the world …

Around GDPR, bureaucracy claimed birthrights over the act and things went back to normal: Snake oil vendors packed their stalls and alleged experts headed for the beach … The anti-climax was predictable, and we are still going through that phase where all players are expecting regulators to set their first fines and wondering “where the big one is going to come from”.

The Shifting Debate around Security Metrics by Jean-Christophe Gaillard

Driving security transformation is becoming key; not justifying investments

The age-long debate around security metrics and dashboards seems very much alive within the CISO community. But it is often positioned in an outdated historical perspective.
For many CISOs, it seems to be still about “justifying investments” or articulating some form of “return on security investment”.