How do you communicate risk in your enterprise?
I’m not IT security, I have a director that manages IT security. I'm enterprise risk. I'm a business person. And I try to dumb myself down by letting them know that I'm not going to say the word firewall, I'm not going to say fishing, I'm not going to say any of those words to you because I'm a business person. Now let's talk about how I could be your strategic partner to help you achieve your mission and goals. And so it's really trying to build trust, trying to make my services valuable to the businesses so they can say, "Hey, I can't deliver my product without the infosec team. I can't deliver my product and be successful without including the information security team." I'm getting it through agile processes of small wins, showing instant risk reduction of certain aspects of business and allowing those lessons learned to wrap back in and try to approach it again.
Don't let a good crisis go to waste when it happens, right? It sounds like you're doing all the things that you need to be doing. Making it real for them and all that
We've tried a lot of that and we've come to the realization that the business is just not mature enough to interpret that type of stuff. They want to know good vs bad, and they want to see yellow, green, red. That's just where we are. Keep in mind that people who run a County are representatives of the people, they're not necessarily business people. And so trying to have that conversation is a thin line., especially when they think that you're just IT security.
That’s an amazing skill set that you're gaining: heavy influencing at a level that's off the charts. Even in my world, when I try to influence decision makers, it comes down to what really motivates them. That's the front of your conversation. So you are assessing your stakeholders and immediately what's going to motivate them. And then you build your discussion off of that. I know it's probably frustrating but it's an amazing set of skills right there.
We tell ourselves all the time, once we conquer this, we can go wherever we need to go as far as career wise. But it's also learning. The State of Texas had to change the legislature and they had to change its legislation to enact security. They had to change the law. And you're dealing with people who have to decide between firewalls and making sure people's houses don't flood like they do in Austin, Texas. I definitely need to take stuff that hasn't been done before in government and try to apply it and try to make it fit because Texas politics is a unique animal that textbooks won't help satisfy.
Content you might like
Malicious use of AI algorithms for targeted cyberattacks20%
Unauthorized access to sensitive AI models and data68%
Adversarial attacks compromising the integrity of AI systems9%
Lack of transparency and explainability in AI decision-making processes3%
Yes28%
No, but we expect to be hit in the future.48%
No, and we don't expect to be hit by ransomware in the future.24%