Security: Yes. Risk: Getting There. Breaches: Uh Oh. People: Aha! P RESENTATION Top 7 Issues for CISOs
Data Classification: SecureState Public S POTLIGHT ON THE P RESENTERS 2 Stephen Marchewitz President Steve has more than 15 years of experience in multiple aspects of information systems, security, management, and risk advisory services. Don Miller Manager of Cyber Security & IT Compliance at FirstEnergy Fulfilling the CISO role and building the security function from its infancy for over 10 years, Don has developed and implemented the enterprise cyber security, risk and compliance programs for First Energy. Don started his career at Bell Labs and was a Sr. Manager at both E&Y and Deloitte & Touche.
Data Classification: SecureState Public A UDIENCE D EMOGRAPHICS 3
Data Classification: SecureState Public S ECURE S TATE O VERVIEW 4 Management Consulting Firm Specializing in Information Security Established in 2001 By identifying the problem in a causal relationship we can provide tactical and strategic recommendations to position our clients in achieving their SecureState.
Data Classification: SecureState Public S ECURE S TATE P HILOSOPHY 5
Data Classification: SecureState Public What are CISOs Saying? 6
Data Classification: SecureState Public B ACKGROUND SecureState Research and Innovation Study Discussions with 20 CISOs Interviews ended Q Questions such as: – What are your top issues? – What things have the greatest impact to your success? – What trends are you seeing or dealing with? Some responses were formal interviews, others were anecdotal or compiled from our assessments 7
Data Classification: SecureState Public CISO I SSUE #1: M ARKETING AND S ELLING OF S ECURITY 8
Data Classification: SecureState Public CISO I SSUE #2: P RESENTING TO O THER E XECUTIVES AND THE B OARD 9
Data Classification: SecureState Public CISO I SSUE #3: U NDERSTANDING ( AND C ONVEYING ) HOW THE B USINESS M AKES M ONEY 10
Data Classification: SecureState Public CISO I SSUE #4: S PEAKING IN B USINESS L ANGUAGE, NOT T ECHNICAL 11
Data Classification: SecureState Public CISO I SSUE #5: H ELPING THE CEO ‘W IN ’ 12
Data Classification: SecureState Public CISO I SSUE #6: S ECURING N EW T ECHNOLOGY 13
Data Classification: SecureState Public CISO I SSUE #7: S TRATEGIC (R ISK ) M ANAGEMENT 14
Data Classification: SecureState Public “B ONUS ” CISO I SSUE #8: L OSING Y OUR J OB A FTER A B REACH 15
Data Classification: SecureState Public T HANK YOU FOR YOUR TIME ! A Q & Q U E S T I O N S A N S W E R S Stephen Marchewitz President