URL has been copied successfully!
CISOs reshape their roles as business risk strategists
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Evolving risks require a new CISO leadership profile: The shift to CISO as a risk position, and not one limited to technical and cybersecurity alone, has been years in the making. But it has accelerated since the arrival of ChatGPT in late 2022, as organizations embraced first generative AI and more recently agentic AI. That’s because AI melds with the business process, whereas prior technologies only enabled business processes. That melding raises the stakes and makes cyber, digital, and business risk nearly synonymous.That evolution has pushed the CISO deeper into risk assessment and management, and it requires a different type of CISO than those of the past.”CISOs cannot walk around and make decisions based on fear or compliance. They must now be able to talk about risk in business terms. They need to understand that risk is a business conversation,” says Leon DuPree, lecturer at Eastern Michigan University’s School of Information Security and Applied Computing.Leading CISOs do this by quantifying both risk and the ROI of their options to address those risks, DuPree says, noting that many use the Factor Analysis of Information Risk (FAIR) model to understand and position cyber and operational risk in financial terms.”That’s the direction that CISOs are trying to go, so they can facilitate change and innovation working from ROIs for all the dollars being spent on security assets and risk mitigation,” he adds.S-RM’s Caron sees more CISOs taking this approach.For example, he says more security chiefs are being tasked with assessing and modeling risks associated with the AI uses within their organizations and reporting how those risks impact business processes, not just data integrity and IT systems.To perform such duties, CISOs must use more of their executive skills than their cyber acumen, Caron says. They must identify risks that come with the deployment of AI and other technologies, quantify those risks in business terms, offer mitigation strategies, quantify how each mitigation option reduces business risks, and help prioritize risk-related tasks based on expected returns and business objectives.”It takes more of a business leader’s lens than a very technical lens. So CISOs now have to be the ones responsible for steering the conversation into directions that show they’re a partner with the business to accelerate growth,” he explains. “The businesses of today are demanding more and more a business CISO.”Caron acknowledges that it’s a significant demand, one that requires CISOs to expand their knowledge base beyond technical and even compliance to business operations, enterprise strategy, and market conditions.”I think that’s where CISOs needs to start going, not necessarily where they are today,” he adds. “Many do still struggle with the mental shift it takes.”

A question of appetite: Steve Martano, an IANS Research faculty member and a partner in Artico Search’s cybersecurity practice, says the majority of CISOs rise through the technical and engineering ranks, so many still find enterprise risk assessment and management novel tasks.But, like Caron, he says it’s now part of the gig.”I think understanding how emerging tech impacts the organization’s risk profile is something they must do, and I think the conversation around enterprise risk is always something security practitioners should be striving for when they communicate,” he says.But Martano, like others, also says CISOs do not have, nor should they assume, ownership over establishing the organization’s risk appetite.”It’s not the CISOs job to revisit the risk posture itself. It’s not the CISO’s job to say, ‘We’re operating too loose,’” Martano says.Instead, CISOs must possess “a good understanding of what the organization thinks is inbounds and out-of-bounds” so they can “flag how technologies, processes, and tools could have an effect on the risk posture,” he says. “The CISO is the adviser.”Boards expect CISOs to be capable of identifying and assessing current and future risks as well as advising on whether to mitigate, transfer, insure against or accept those risks, he adds.That may be more challenging now than ever, with technology, AI, and enterprise use of them swiftly evolving.”The best CISOs think about risks that are around the corner. They have to have a pulse on where things are going,” Martano adds. “They don’t have to be visionary; but they do need to be proactive by engaging more outside their four walls, engaging with vendors, information-sharing with their peers, having a pulse on the macro level. The more they diversify what they’re hearing, the better, so they can bring nuggets of information to their boards and executive teams to discuss and how those affect their own organization’s risk culture.”

First seen on csoonline.com

Jump to article: www.csoonline.com/article/4159317/cisos-reshape-their-roles-as-business-risk-strategists.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link