Stacy Hughes, Voya Financial CISO, discusses the art and science of cybersecurity with Ann Johnson. They explore informing stakeholders, balancing frameworks, continuous learning, and advice for security leaders.
Combining business and technology expertise is crucial for establishing a strong cybersecurity program as a CISO.
Integration of frameworks like MITRE ATT&CK and business partnerships enhances threat detection and cybersecurity talent development.
Deep dives
Journey to CISO Role at Voya Financial
Stacey Hughes shares her path to becoming a Chief Information Security Officer at Voya Financial, highlighting her diverse background in internal audit and accounting, her transition into technology, and the experiences that led her to the CISO role. By combining business and technology expertise, she has established a strong cybersecurity program, emphasizing the importance of enjoying and being passionate about one's work in the CISO role.
Evolving Risks and Attacks in Financial Sector
As an enterprise financial sector CSO, Stacey discusses the evolving risks and attacks in the industry, noting trends such as social engineering, phishing, ransomware, and vulnerabilities. She highlights the impact of new technologies like cloud, artificial intelligence, and chat on security practices, emphasizing the need for strong security awareness, cyber hygiene, and compliance to counteract evolving threat actor tactics.
Art and Science of Cybersecurity, Leadership Development, and Board Engagement
Stacey explains the integration of the art and science of cybersecurity, emphasizing the use of frameworks like MITRE ATT&CK alongside business partnerships to enhance threat detection. She delves into talent development, advocating for mentorship, skill-building, and leadership progression to address the cybersecurity talent shortage. Stacey also shares insights on engaging with senior leaders, boards, and the importance of elevating cybersecurity within organizational goals and success criteria.
Stacy Hughes, Voya Financial Senior Vice President and Chief Information Security Officer, joins Ann on this week's episode of Afternoon Cyber Tea. Stacy has over 20 years of experience leading complex IT initiatives within Fortune 500 financial technology organizations. Prior to her role at Voya, she was CISO at Global Payments Inc. and has held leadership positions across governance, compliance, accounting, and audit functions. Stacy and Ann discuss her journey to being CISO at Voya, the art and science of cybersecurity, and advice for CISOs and other security leaders on how to effectively inform, educate, and influence stakeholders.