Bolstering Federal Cyber Resilience and Demonstrating ROI with Gerald Caron, Former CIO at U.S. Department of Health and Human Services (HHS), Office of the Inspector General (OIG)
Mar 1, 2023
auto_awesome
Former CIO Gerald Caron discusses managing operational risk, data mapping in Zero Trust, and demonstrating ROI. Topics include aligning Zero Trust with business strategy and understanding the political aspects of risk decisions. Caron highlights the cultural shift required for successful Zero Trust adoption and the importance of communication within an organization.
Managing operational risk involves understanding the political and mission aspects, not just IT.
Successful Zero Trust strategies require data mapping integration for enhanced security posture.
Demonstrating ROI in security investments involves aligning initiatives with business impact for tangible benefits.
Deep dives
Jerry Caron's Transition and Unique Journey to IT Leadership
Jerry Caron, with over 24 years of IT experience and a background in the US Army, shares his unique journey from a help desk position at the Department of State to becoming the Chief Information Officer at the Office of Inspector General at the Department of Health and Human Services. His transition highlights the diverse experiences and positions he held within the federal government over the past two decades.
Centralized vs. Federated IT Environments: Security Challenges
Jerry discusses the security challenges faced in centralized and federated IT environments, drawing parallels between his role at the Department of State managing 110,000 users to his current position at HHS managing 2,000 users. He contrasts the autonomy and varied IT needs in both environments, highlighting the opportunities for flexibility and agility in a fully-owned and centralized network.
Integration and Operational Risk Management in Cybersecurity
Jerry emphasizes the importance of integrating data sources in cybersecurity to manage operational risk effectively. He describes a tool called iPost that consolidates patch data, vulnerability assessments, and system configurations into a unified dashboard, providing real-time operational risk scoring. By streamlining data integration and risk assessment, organizations can enhance their security posture and respond proactively to evolving threats.
Zero Trust Strategy and Foundation Projects for Improved Security
Jerry outlines his approach to implementing Zero Trust principles, focusing on data mapping, microsegmentation, and identity management. He stresses the significance of aligning zero trust strategies with business objectives and creating a culture of proactive security measures. By investing in foundational projects centered around data protection, network security, and identity management, organizations can fortify their cybersecurity posture and mitigate potential risks.
Measuring Effectiveness and ROI in Security Investments
Jerry delves into the challenges of measuring the effectiveness and return on investment (ROI) in security investments. He advocates for quantifying the cost of security incidents and leveraging this data to demonstrate the value of proactive security measures. By aligning security initiatives with business impact and focusing on preventative strategies, organizations can showcase the tangible benefits of their security investments and enhance overall cyber resilience.
In this episode, host Raghu Nandakumara and Gerald Caron, Former Chief Information Officer for the Office of the Inspector General at the US Department of Health and Human Services, unpack how to manage operational risk, the role of data mapping in any successful Zero Trust strategy, and demonstrating ROI.
--------
“Because when you're managing risk, it's not just an IT thing. It's also a mission thing as well. What are the political aspects of the risk and the decisions that you're making? That informs the IT risk as well. But I think it has to be well understood that this is, going back to the ROI, this is why this is a good investment. This is gonna help mitigate this risk… [Zero Trust] is a cultural thing for an organization and it needs to be communicated.” - Gerald Caron
--------
Time Stamps
* (5:00) Understanding your operational risk posture as a CIO
* (9:52) What peanut butter, the cinema and Zero Trust have in common
* (14:10) Demystifying Zero Trust: Driving the adoption of ZT at the OIG
* (18:40) Measuring progress and effectiveness
* (25:53) Aligning Zero Trust with your company’s business strategy
--------
Sponsor
Assume breach, minimize impact, increase resilience ROI, and save millions in downtime costs — with Illumio, the Zero Trust Segmentation company.