A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Banca Ifis

How Security and Operations will seamlessly work in future organisations

If someone tells you that technology or a tool will solve all of your problems, you already know it's a lie. Not because technology isn't a key enabler, but because technology only supports a specific need that must be clear to anyone, properly addressed and structured before a tool can even start being effective.

When it comes to security, this is even worse, not only because the number of tools is rocketing but because the threats are rapidly changing and becoming harder to cope with, considering that most of them come from within the organisation.

As seen in IT Development, the complexity nowadays is tremendously increasing with large implications; it is clear, though, that Security departments are not as scalable as they are structured today – largely proved by several burnout CISOs across the globe. Let’s focus on two of the main reasons:

1. Security is siloed between Governance and Operations

2. Responsibility is centralised in the SecOps team.

Security is siloed between Governance and Operations.

The division within organisations poses challenges in establishing complete security measures for an enterprise's infrastructure and systems.

When it comes to corporate Security, Governance and IT departments are typically split into different teams, but hackers do not focus solely on individual silos. They take advantage of weaknesses throughout the system, requiring comprehensive security measures. Realising this, companies need to work on dismantling silos and creating solutions that span across different silos in order to combat cyber threats efficiently.

"Maintaining an understanding of security concerns is essential for achieving maximum security."

In the field of data security, internal risks are equally important as external threats. Dishonest individuals within a company can lead to notable damage to the security and privacy of data. Therefore, addressing internal security risks is just as important as addressing external threats. Collaboration and cooperation among various teams can be difficult because of conflicting priorities and differing perspectives.

Introducing cross-silo security solutions may occasionally cause disagreements among different teams. IT and security governance teams may have varying methods, likes, or focuses, resulting in conflict and lengthening the decision-making procedure. Yet, when security and IT teams have shared objectives, trust can be established, resulting in enhanced collaboration and improved security strategies.

While security policies are crucial for protecting organisations, they may be inadequately executed in technology, causing friction between IT and security teams. Sometimes, security measures may hinder the efficient functioning of systems or limit the adaptability needed by IT teams. Maintaining a delicate equilibrium between strong security measures and operational efficiency is essential for the overall success of a company's security initiatives.

Maintaining an understanding of security concerns is essential for achieving maximum security. Nevertheless, an excess of information can occasionally result in a failure to comprehend the fundamental technology. Maintaining an equilibrium between being updated on security risks and flaws and having a thorough grasp of the technologies used by IT professionals is crucial. This aids in connecting security and IT teams and enables smooth cooperation in implementing security measures.

In order to tackle the issues caused by isolated IT departments and improve security, companies should think about implementing a more equitable strategy. This involves dismantling barriers through education, assistance, and an improved understanding of business requirements. Furthermore, the job responsibilities in IT departments need to change in order to emphasise the value of having expertise in multiple areas, promoting the development of well-rounded professionals with skills in networking, database management, and application development.

Organisations can attain a stronger and more extensive security position that matches business goals by promoting teamwork and breaking down barriers.

Break down silos; maximise communication, cooperation and efficiency!

Responsibility is centralised in the SecOps team.

Why Security responsibilities can't be centralised at all? Quite easy to understand, the vast majority of attack surface comes from End Users. Even though systems and Internet-exposed applications are commonly highlighted as the main threats, we all know that systems and applications are not the weakness – recently, social engineering has been reaching levels where it is really hard to understand whether it is real or not what you are seeing or listening to.

So why companies are still trying to centralise as much as possible the responsibilities instead of delegating and empowering people working with a security first approach?

Well, often, it is just a problem of culture. That's how it works if you want to structure responsibilities in a RACI matrix, for example. But the world is not moving in the same way. This phenomenon is well-known in other departments, considering how infrastructure culture has changed over the last decade. From centralising the responsibilities of provisioning, configuration management, capacity optimisation, and decommissioning to delegating as much as possible, creating a platform where everyone can consume Infra services in a standardised, secure, and optimised manner with ease.

Maybe you are now thinking ‘DevSecOps is there since years’ – why shift-left is something that is recently rocketing in the trends though. Of course delegating to Tech team is easier than trust that people won’t click on every single link in an e-mail but be honest: security is managed by security people that won’t scale up infinitely, threats will instead.

Who knows what will happen? What we know is that building a security platform should be on the agenda of every security executive. Standardise and industrialising all the security topics, commoditising them like infrastructure did, is a future everyone can predict.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top