“A beloved child has many names” when it comes to titles and helps create confusion around the CISO role. Below are just a few examples of titles:
- Head of information security / IT security
- IT Security Director
- Cyber security executive
- Information security director
- Chief Security Officer (CSO)
- Vice President of information security
It's no wonder that there is confusion at all levels about the content, responsibilities, powers, references, as well as requirements and qualifications of a CISO role. Where previously we saw much narrower and more technical definitions of a CISO's responsibilities, today we would describe the responsibilities as much broader. Our version of a 2020 definition could be:
__________
A CISO is responsible for establishing, securing and maintaining the company's vision, strategy and the programs and systems that ensure that the company's data and technologies are adequately protected at all times. A CISO is expected, alone or together with his team, to identify, develop, implement and maintain processes across the company's value chain that reduce risks related to technology.
The responsibility includes everything from incident response, establishing standards and controls, ensuring the right management systems, developing and implementing policies and procedures, and ensuring the necessary compliance.
__________
In the real world, we see variations in the role depending on the company's industry, size, organizational structures and digital maturity level. In one place, a CISO may solely constitute the company's IT security function and thus work extremely technically and operationally. In another place, a CISO may lead a larger team of both specialists and generalists within operational IT security, GRC (Governance, Risk, Compliance), information security – and in some places even physical security.
In 2016, Deloitte described and divided the CISO role into four different characteristics: the guard, the technologist, the strategist and the advisor – which nicely illustrates the complexity associated with the role both then and now. According to Deloitte, a CISO in 2016 would in most cases (approximately 77%) draw on the technical aspects of the role, such as the guard or the technologist. Even then, it was disputed that the other two roles – the strategist and the advisor – would play a more important role in the future.
The strategist is the person who ensures that IT security efforts are in line with the business strategy, as well as ensuring innovation and long-term change and investment plans in the area.
The advisor as the person who, in close collaboration with the business, educates and advises employees, and constantly influences IT security decisions with qualified knowledge of consequences and implications.
We have just completed an analysis in which we have highlighted the organizational consequences of the development in the threat landscape. The analysis is based on interviews with 27 Danish CISOs. Analyses clearly show that Deloitte's assumption is correct and that today it is the strategist and the advisor who are needed. Digitalization is in most companies the focal point for strategy and business development. It is therefore expected that a CISO manages to support digitalization with solutions that do not limit, but support digitalization, thus that the CISO embraces both the technical and communicative aspects in order to be able to advise the business.
Based on the developments we see in the market in 2020, we believe that a fifth role should be added, which is the leader.
The manager is able to lead, inspire and develop a team of specialists as well as communicate and convey the importance of Information Security to management and the board of directors, thereby ensuring the right attention on the board's agenda. The manager has a sound technical foundation combined with good business understanding, which allows him/her to think about Information Security holistically, including in relation to KPI and reporting.
What type of CISO is needed?
Which type of CISO is specifically needed in your company depends of course on a number of parameters. This relates to industry, size, complexity, whether the company is part of the six sectors designated as critical infrastructure and thus covered by legislation and regulations, the maturity both in relation to the level of IT security and the general IT landscape, the specific threat landscape, the importance of digitalization for the company and much more.
As with all recruitment, success depends on how well you define (and delimit) the role and on your understanding of the journey the candidate will take the company on. It is relevant to ask how well you are at describing “AS IS” and “TO BE”. This is a challenging – and almost impossible – task when the threat landscape is constantly changing and at the same time defined by factors beyond your control. Few companies have a real picture of “AS IS”.
It is incredibly difficult for most people to describe the current IT security set-up, especially in a situation where you have not previously had a CISO, or had one who was unable to keep an overview, which is all too often the case in small and medium-sized companies. Ergo, you do not have a full and realistic picture of the situation.
Recommendations
Interim CISO: Depending on the size of the company, we have good experience with hiring an interim CISO during the employment period (3-6 months), who helps define the role and ensure the right qualifications for the future CISO. There are many extremely qualified CISOs at all levels who choose to work interim for a period of time. These are competencies that would normally be overqualified for the role, but who have the necessary overview and interest in maturing the company in the area.
Expert help for the professional assessment: Be 100% sure that the candidate has the right professional level in terms of both technology, organizational impact and possibly management. IT security is a broad area with many professional disciplines, which can be difficult to relate to. If necessary, seek external help for the professional assessment. If you have a technical consultancy firm affiliated with you, they will probably be happy to assist in the evaluation of the technical competencies. There are also a few specialized headhunters who will be able to give a second opinion of the candidates in terms of both technical level, leadership skills and impact.
The board should be involved in the hiring process: The CISO role has unfortunately become a distinctly revolving door position. One reason for this is, among other things, the lack of support from top management and the board. In recent years, IT security has been described as one of the central themes on the agenda for top management and boards - this should therefore also be reflected in the hiring process. The involvement in the process should help the board feel comfortable with the hiring process, that the new CISO and the board speak the same language, and give the candidate an impression of whether the necessary attention is being paid.
Set the bar high, possibly search abroad: Don't compromise. If there are not enough qualified candidates nationally, search internationally. Denmark is in many ways an attractive country with good opportunities to attract experienced candidates from abroad. Candidates who have experience from large and complex companies and who have "grown up" with a more skeptical and defense-based culture - than the one we have historically cultivated in Denmark.
Which role is needed?: Most importantly, it is important to assess where you as a company are on your maturity journey in relation to IT security. This has a decisive impact on which combination of the four roles is needed. As part of our analysis, it became clear that the majority of Danish companies can be divided into four categories, each with its own focus:
- Companies without a current IT security function. IT security is handled by the CIO/IT manager who purchases external consultants
- Companies subject to critical infrastructure
- Major global manufacturing companies
- Companies with a digital agenda
Re1. Companies without a current IT security function. The recommendation will be an interim CISO. The main task will be to review the technological platform and implement the necessary systems, as well as ensure processes and subsequent controls, and work with the change process in the organization and the behavior required to raise the level.
Ad2. Companies subject to critical infrastructure. This group is characterized by being subject to legislation and regulations and therefore by being well underway with the journey and by having a clear picture of where they are going. There is focus on the area, it is under construction, there are demands from management and the board, it may have political attention, which is why the strategy and the leader are in focus. The technology skills are / must be present, but the importance means that there must be strong technological skills in the team.
Ad3. Larger global manufacturing companies. This group is often challenged by expensive and old production systems and by working internationally and being subject to compliance requirements from large global customers. Security is on the agenda of management and there is a clear picture of the consequences of potential breakdowns. The IT security function is most often on a size of 5-6 headcounts. The technical aspects of IT security are often either outsourced or placed in operations. The challenge for the CISO is largely to get the business engaged and involved so that IT security is considered in R&D, production, sales, etc., which is why the advisory role and the watchdog role become the central ones - closely followed by the management role.
Ad4. Companies with a digital agenda. This group will have recently hired or replaced their CISO because they have learned that they need a CISO who can advise and consult with management on security in relation to their business development. Things are moving fast, and there is a need for someone who is visionary.
What does the market look like for CISOs in Denmark?
For companies that have not previously had a CISO
In this segment, there are many qualified candidates - especially candidates who have worked in management consultancies for a number of years. There is often a widespread desire among these candidates to try their hand at a CISO role after a few years as consultants.
Small and medium-sized enterprises
The biggest challenge in this segment is the high turnover among CISOs with a few years of experience. We now have a good base of experienced CISOs in this segment, who have moved from being technical to being able to function as advisors and strategists and who have the necessary business understanding. The CISO role has unfortunately become a revolving door position. It is our assessment that CISOs on average only last 18 months in the job and that the situation in DK right now matches this figure, combined with the fact that most CISOs have changed jobs within the last 12 months.
Larger companies
In this segment, the supply of candidates is limited. We have a structural challenge in Denmark with a business community that is primarily based on the SME segment. This means that we only have a small handful of CISOs who have built up experience from larger, complex companies and with a high level of maturity within Information Security and Cyber Security. It is primarily the financial sector where we find the really serious candidates with the serious experience.
Facts
21% of Danish companies have hired a CISO in the past year.
A CISO stays in the position for an average of 18 months. A LinkedIn search for CISOs in Denmark reveals approximately 274 profiles, of which 23 are women.
We have 168 CISO candidates in our database – of which 38 candidates have experience from interim CISO roles.
Salary level: This has increased by 18% in the last 2 years to a level of 85,000 - 150,000 DKK / month + pension.