What Makes a Good CISO

14
What makes a good CISO? Stephen Cobb, CISSP, MSc. Senior Security Researcher www.WeLiveSecurity.com www.eset.com

Transcript of What Makes a Good CISO

Page 1: What Makes a Good CISO

What makes a good CISO?

Stephen Cobb, CISSP, MSc.

Senior Security Researcherwww.WeLiveSecurity.com

www.eset.com

Page 2: What Makes a Good CISO

Why think about this?

Page 3: What Makes a Good CISO

What do they even look like?

Very few academic studies of cybersecurity professionals exist, relative to other IT roles and guardianship professions

Page 4: What Makes a Good CISO
Page 5: What Makes a Good CISO
Page 6: What Makes a Good CISO
Page 7: What Makes a Good CISO

We find hiring for cybersecurity positions to be:

Cobb, S. (2016) “Getting to know CISOs: Challenging assumptions about closing the cybersecurity skills gap” University of Leicester MSC dissertation

Page 8: What Makes a Good CISO

The skills gap is undermining security82% admit to a shortage of cybersecurity skills71% cite shortage as responsible for direct and measurable damage to organizations“A shortage of people with cybersecurity skills results in direct damage to companies, including the loss of proprietary data and IP”

James Lewis, CSIS, quoted by Intel Security

Page 9: What Makes a Good CISO

What are some key attributes, competencies,

and personality traitsof CISOs?

Page 10: What Makes a Good CISO
Page 11: What Makes a Good CISO
Page 12: What Makes a Good CISO

Yes, CISO’s have personality

Testing with IPIP NEO, Freed found that IT cybersecurity workers scored higher on Openness and Conscientiousness, lower on Neuroticism, than regular IT folks. Cobb found this difference was even greater in CISOs.

Page 13: What Makes a Good CISO

7 Top traits of good CISOs1.Broad in understanding2.With an open mind3.Conscientious4.Strong nerves5.Strong imagination 6.Good communication skills7.Humility

Page 14: What Makes a Good CISO

Thank you!» [email protected] » www.WeLiveSecurity.com