CISOs - BE LESS DISPOSABLE!
Over the past year or so I've seen a shift in what our members are taking on in their roles. While CISOs are already overwhelmed and under-resourced, I think these broader roles are even more important than ever.
I think this shift is partly because the traditional CISO role seems to be under attack. I've seen members lose their jobs when the CISO role is eliminated, not to be replaced. This is happening largely in un-regulated industries, often as companies downsize their staffs in an effort to cut cost.
While I think this is a risky move on behalf of the companies doing it, I can't fault them for trying to lower their overall costs. Nonetheless I think those companies will come to regret the elimination of the CISO role, in time.
The advice I've been giving to members to combat this trend is to "go broader" in their roles. I've suggested they take on parts of IT such as infrastructure, desktop, help desk, and more. I've also recently started suggesting they include "resiliency" in their role. If we took nothing more away from the CrowdStrike issue, we should have learned that outages cost money.
What is ultimately included in this resiliency role remains to be seen. I think it will include BC/DR and more to include resilient architecture and design.
I've made these suggestions to members because I think it makes them "less disposable".
What do you think? Are we wise to spread our wings and make the CISO role broader and less disposable?
This is so important to us that we are devoting a series of Regional Roundtables to it throughout the first half of next year.
If you are a cybersecurity product or services provider with solutions around cyber-resiliency, please consider participating in those regional roundtables in our sponsorship program. Our members want to better understand how we incorporate this important new areas into their roles. Contact me [email protected] to inquire about being a sponsor for this 2025 series.