The ability to influence
Depending on the definition of 'leadership', one could argue that the CISO role has evolved into a leadership role, rather than a specialist/staff function. If we work with the understanding of 'leadership' as having the ability to influence, either by inspiring a team of specialists, or by communicating the importance of information security to management and the board, then it seems that leadership skills are extremely important for a CISO's success. Stakeholder management, reporting to the board and executive management, the fight for resources, convincing decision-makers, change management, etc., are among some of the themes we hear, becoming a larger part of the CISO's everyday life and the focal point of their work. This also applies to those CISOs who are not organizationally placed in a management team, or have a team under them. Their challenges are the same, and require the same influence and communication power upwards and outwards in the organization.
Management skills have become more important
In 2016, Deloitte described and divided the CISO role into four different characteristics; the guard, the technology man, the strategist and the advisor. According to Deloitte, a CISO in 2016 would in most cases (approximately 77%) draw on the technical aspects of the role, such as the guard or the technology man. Even then, it was disputed that the other two roles – the strategist and the advisor – would play a more important role in the future. Deloitte describes the strategist as the person who ensures that IT security efforts are in line with the business strategy, and ensures innovation and long-term change and investment plans in the area. The advisor as the person who, in close cooperation with the business, trains and advises employees, and constantly influences IT security decisions with qualified knowledge of consequences and implications.
The above-mentioned characteristics are part of most leadership roles and support the thesis that the CISO role has evolved into a leadership role. From our daily dialogue with CISOs, it is our impression that what surprises and challenges them most is the amount of energy and time they are forced to spend; influencing and manipulating the organization, obtaining the necessary resources, creating the necessary peace of mind, ensuring the right reporting, getting management to recognize the actual maturity and risk picture, and in general ensuring that they are involved where their knowledge is needed, e.g. in business development and digitalization strategy.
In a previous article, we defined the CISO's responsibilities as follows:
______________
A CISO is responsible for establishing, securing and maintaining the company's vision, strategy and the programs and systems that ensure that the company's data and technologies are adequately protected at all times. The CISO is expected, alone or together with his team, to identify, develop, implement and maintain processes across the company's value chain that reduce risks related to technology.
The responsibility includes everything from incident response, establishing standards and controls, ensuring the right management systems, developing and implementing policies and procedures, and ensuring the necessary compliance.
_________________
But how much time and energy does the CISO actually spend on this central and important area of responsibility that they are hired to handle – and how much is actually focused on organizational elements that make these tasks accessible at all?
We have entered into dialogue with CISOs in Denmark to learn more about how much time you, as a CISO, spend working on the organizational elements of management, both formally and informally. Including which types of management tasks take up the most time.