As cybersecurity has reached the top management agenda in more organizations, they are faced with new pressures and challenges in the role of cyber leader. In a short period of time, many are not yet trained or educated to deal with the heightened attention and stakeholders in the company.
Not to underestimate the pressure on their cybersecurity teams.
In this new arena, mastery of the technical cyber discipline is no longer sufficient.
Cybersecurity has become an integral part of the enterprise, becoming part of a new corporate language, logic, and landscape of key decision makers. In addition, cyber leaders’ ability to maintain, build, and develop teams of highly focused and diverse specialists has become central to their responsibilities as their organizations grow—and yet an increasingly difficult task.
Leadership skills are therefore becoming more critical than ever for cyber leaders to succeed in leading downwards, upwards and outwards. Here are three good reasons why:
1. Cybersecurity is not a one-man army
As cyber teams grow, people management becomes a key responsibility. Leading a group of high-performing specialists (and introverts) working under pressure to protect the company from unknown threats requires presence, but also direct and present leadership.
The ability to not only build, but nurture and develop cyber teams will also be critical to retaining key talent, as the talent market is highly competitive. This is a group of people who receive job offers almost daily. Studies also show that 'cultures' are climbing the list of CISOs' top responsibilities, with them expected to spend more time on people issues than on technology-related matters.
2. Cybersecurity has reached top management
This has exposed cyber leaders to the boardroom, senior management and corporate political arena, which require strong communication and persuasive skills. Reporting cybersecurity at the executive level requires more than just the individual’s ability to convey the message – “a message is only as good as its messenger”.
It is up to the cyber manager to define the KPIs, and translate complex and extensive information into clear points and business risks. The ability to present and communicate becomes the key to the understanding of the board and directors.
3. Cybersecurity is an interdisciplinary discipline
As digitalization increases, cybersecurity is becoming a cross-functional part of all business functions – impacting processes and users at all organizational levels, which is why cyber leaders now work with project and change management. This cross-disciplinary discipline requires leadership skills when involving stakeholders or external partners, especially given the lack of direct authority in the process. Navigating different stakeholder agendas becomes necessary to gain the necessary mandate with key decision makers. This is an underestimated challenge for cyber leaders. Especially since cybersecurity has long been associated with being a cost, limiting, or controlling.
What transformation are cyber leaders facing today?
Because cybersecurity is a multifaceted and integrated part of the entire business, its leaders must be too. The challenge is that they are not all there yet. Morten Dichmann Hansen, CISO at Copenhagen Airport, points out the need for cyber leaders to excel in disciplines that go beyond their deep professional knowledge:
It is not enough to be competent in the cybersecurity field. Being a cyber leader involves human resource management to understand the different profiles of your team, budgeting, stakeholder management, navigating communication towards leaders – the importance of these surrounding tasks should not be underestimated.
Morten Dichmann Hansen, CISO CPH Airport
As Cyber Talent Builder & Broker and co-founder of the new cyber leadership training CISL, Camilla Treschow Schrøder also sees that the real transformation for the individual cyber manager moves beyond this specialist mindset. The pitfall for new leaders and leaders with a specialist background is that they end up in micro-management. Instead, they must empower and trust their people to do the work. This transformation is also crucial in communication:
Cyber leaders are both enriched and burdened by their specialist knowledge. They must learn to communicate the essence to achieve impact – this discipline is one of their greatest challenges
Camilla Treschow Schrøder, Cyber Talent Builder & Broker & Co-founder CISL
The focus on developing communication skills is also recognized within consulting, where Ebbe Petersen, Director for Cybersecurity & Compliance Consulting at NNIT, highlights the increasing need to build bridges between cybersecurity and business:
The biggest transformation lies in their ability to select and translate technical information into what it means for the business. The most important thing is to understand your audience. Communication at the management level is about sticking to the facts and getting straight to the point based on a balance of the company's business goals and digitalization strategy, risk profile, existing security budget and investment willingness – and that is a big challenge for many…
Ebbe Petersen, CISO, DSB.
It is Camilla's experience that many managers with a consulting background find it easier or more natural to enter the management discipline, as being a good consultant requires strong communication skills. This is also the reason why the management consulting company Kopenhagen Konsulting plays a central role in the CISL management education. Read more here (www.cisl.dk).