Well, I Think My Relationship With the CIO Improved When I Took Their Job
Aug 27, 2024
auto_awesome
In a lively conversation, Ty Sbano, the CISO at Vercel, shares his journey in cybersecurity and how taking on the CIO role helped improve relationships within the organization. He emphasizes the significance of employee well-being in managing insider threats and suggests coaching instead of shaming to foster a positive workplace culture. The discussion includes the value of phishing simulations and the evolving dynamics between CISOs and CIOs, alongside a cultural shift needed for integrating security practices into DevOps.
The relationship between CISOs and CIOs can be improved through collaboration and shared accountability for the organization's technological landscape.
Addressing employee morale is crucial for security, as a positive company culture reduces the likelihood of insider threats and misconduct.
Deep dives
Lessons from a Security Mishap
One significant mistake highlighted in the episode involves a previous experience of a security head who accidentally disabled G Suite access for an entire company. This incident rapidly escalated, eliciting panic from both employees and the CEO, ultimately leading to a lighthearted moment where the security head jokingly considered resigning. This example underscores the importance of thorough account management and the potential repercussions of miscommunication within an organization. It serves as a stark reminder that even minor oversights in IT can result in company-wide disruptions.
The Role of CISO in Employee Well-being
The podcast discusses the role of Chief Information Security Officers (CISOs) in addressing employee morale and discontent, emphasizing that these issues should not be sidelined as mere HR responsibilities. A healthy company culture directly relates to security, as happy employees are less likely to engage in malicious behavior. The conversation stresses the need for CISOs to be attentive to the emotional states of their employees, using feedback from engagement surveys and off-boarding assessments as vital tools for gauging workplace health. Engaging with employees respectfully, especially during difficult times such as layoffs, can significantly impact the overall security posture of an organization.
Approaches to Security Policy Violations
In addressing security policy lapses among employees, the podcast explores various lighthearted approaches taken by some organizations, such as sending humorous reminders or creating friendly competitions. There is a distinction made between these traditions and the more serious nature of phishing test results, suggesting that the latter can often lead to feelings of embarrassment or shame among employees. The discussion also cautions against escalation or punitive measures that can harm employee trust and morale, instead advocating for constructive conversations that nurture awareness of security protocols. Ultimately, fostering a supportive atmosphere where employees feel comfortable addressing lapses could strengthen the organization's security culture.
The Evolving Roles of CIO and CISO
The episode delves into the dynamics between Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs), noting that the relationship can often be fraught with tension due to diverging priorities. It's suggested that both roles share accountability for the organization’s technological landscape, yet a misalignment in goals can lead to conflicts. The conversation points out the need for these roles to collaborate effectively, with an emphasis on ensuring security within the broader objectives of the business. Moreover, as roles evolve, there is speculation about the future relevance of the CIO position in organizations where security leadership is increasingly critical.
Backslash Security is your modern AppSec solution, focusing on what truly matters—real risks. Gain clear visibility into your applications and fix only the code and open-source software that’s actually in use, making your AppSec smarter and more efficient. Learn more at https://www.backslash.security/.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode