Mike Lockhart, Chief Information Security Officer at EagleView, delves into the nuances of information security versus cybersecurity. He explains how terminology shapes public perception and emphasizes the importance of effective communication in aligning security strategies with client understanding. The conversation also highlights the diverse career paths in the security field, including red teaming and penetration testing. Lockhart discusses the crucial role of security leadership in fostering collaboration and managing stakeholder expectations to enhance organizational security.
The role of a CISO extends beyond cybersecurity, incorporating governance, risk management, and data protection into their responsibilities.
There is a significant confusion between cybersecurity and information security, which can hinder effective communication and influence security strategies within organizations.
Deep dives
The Expansive Role of the CISO
The role of a Chief Information Security Officer (CISO) is often narrowly framed within the context of cybersecurity, but it encompasses a much broader spectrum of responsibilities. Key areas include governance, risk management, data protection, and physical security, beyond just cybersecurity concerns. This misconception arises, in part, because the term cybersecurity has been heavily marketed and simplified, leading to a lack of understanding regarding the full range of information security duties. A more holistic view is essential, as it allows organizations to communicate effectively with stakeholders and better manage risk across all facets of the business.
The Confusion Between Cybersecurity and Information Security
There is a considerable disconnect in how the general public and industry professionals differentiate between cybersecurity and information security. Many believe that cybersecurity represents the entirety of security efforts, often focusing on the 'hacker' mentality, while information security is a more encompassing term that includes various domains and risk management practices. This confusion can hinder effective communication within organizations and impact their security strategies. It is crucial to clarify this distinction and reset expectations, as many new entrants to the field are eager to pursue roles that they mistakenly believe are solely centered around penetration testing or red teaming.
Influencing Organizational Security Strategy
A significant part of a CISO's role is to influence and guide the organization’s overall security strategy through effective communication. This involves not only educating the executive leadership and board but also empowering team members to understand and manage risks. Mentoring emerging professionals within the industry highlights the need for broader awareness of various security roles beyond just cybersecurity. Ultimately, success may hinge on the ability to provide the necessary support and resources, allowing teams to operate effectively and securely while driving meaningful conversations surrounding risk management.
All links and images for this episode can be found on CISO Series.
Check out this post for the discussion that is the basis of our conversation on this week’s episode co-hosted by me, David Spark (@dspark), the producer of CISO Series, and John Underwood, vp, information security, Big 5 Sporting Goods. Joining us is our guest, Mike Lockhart, CISO, EagleView.
In this episode:
Marketing versus strategy
A distinction without a difference?
Terminology follows function
Security convergence
Thanks to our podcast sponsor, Scrut Automation
Scrut Automation allows compliance and risk teams of any size to establish enterprise-grade security programs. Our best-in-class features like process automation, AI, and 75+ native integrations reverse compliance debt and help manage risk proactively as your business grows. Visit www.scrut.io to learn more or schedule a demo.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode