{"id":3457,"date":"2024-05-07T14:46:02","date_gmt":"2024-05-07T19:46:02","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/what-s-the-future-path-for-cisos"},"modified":"2024-05-07T14:46:02","modified_gmt":"2024-05-07T19:46:02","slug":"whats-the-future-path-for-cisos","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/07\/whats-the-future-path-for-cisos\/","title":{"rendered":"What&#8217;s the Future Path for CISOs?"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8c9a87dc12741d38\/65f997fb6c9f9b040a4d58ca\/CISO_Kjetil_Kolbj%C3%B8rnsrud_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security professionals who rise through the corporate ranks and become chief information security officers (CISOs) often believe they have reached the pinnacle of their careers. But for some, the CISO role is a path to overseeing all of IT.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many CISOs mentored by Renee Guttmann-Stark aspire to advance to the chief information officer (CIO) or chief technology officer (CTO) role, for instance. Gutmann-Stark is among four former CISOs who will <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/ciso-role-changing-can-cisos-keep-up\" rel=\"noopener\">discuss the future of leading an enterprise security organization<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on Thursday during the closing session of this week&#8217;s RSA Conference in San Francisco.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In an interview before the session, entitled&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.rsaconference.com\/USA\/agenda\/session\/CISOs%20Unchained\" rel=\"noopener\">CISOs Unchained<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Gutmann-Stark acknowledged that she never aspired to rise above CISO, indicating her preference for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/ciso-role-changing-can-cisos-keep-up\" rel=\"noopener\">focusing on cybersecurity<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. &#8220;It is too exciting,&#8221; she says. &#8220;I really didn&#8217;t feel the need to explore doing anything else.&#8221;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, Guttmann-Stark says she&#8217;s seeing more <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/5-ways-cisos-can-navigate-new-business-role\" rel=\"noopener\">CISOs taking on CTO roles<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, such as Jamil Farschi of Equifax. After six years as Equifax&#8217;s CISO, Farschi was promoted to CTO last month. &#8220;There is an emerging trend in business: CISOs are expanding into technology,&#8221; Farschi&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/jamilfarshchi\/recent-activity\/all\/\" rel=\"noopener\">announced on LinkedIn<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Farschi pointed to other CISOs who have also become CTOs, such as Brian Minick of First Third Bank and Craig Froelich at Bank of America. He noted that, like the CISO, CTOs are immersed in an entire business, manage risk, and can lead technical teams.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Future of the CISO?\">Future of the CISO?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Despite some CISOs rising in the ranks, most face challenges says Guttmann-Stark, who is now principal of the&nbsp;advisory firm CisoHive. Before launching CisoHive, Guttmann-Stark held several CISO roles at companies such as Royal Caribbean, Time Warner, and Coca-Cola.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Among those challenges are <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cybersecurity-s-continued-shortfall-not-proof-against-layoffs\" rel=\"noopener\">ongoing job vacancies<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, challenges <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/new-regulations-make-d-o-insurance-a-must-for-cisos\" rel=\"noopener\">getting liability insurance<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and the difficulty of purchasing all their core tools from one vendor. People also want to know how the CISO role will evolve and how to handle the barrage of attacks.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">During her 30 years in cybersecurity, Guttmann-Stark says she never experienced a major headline-grabbing attack or breach, although there were plenty of routine incidents.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The reality is that you always have something going on or some event,&#8221; she says. &#8220;And I used to tell people that my job is to see if there&#8217;s a fire in a garbage can and make sure it doesn&#8217;t burn the building down.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The most notable incident that Guttmann-Stark can recall occurred when she was Coca-Cola&#8217;s CISO, and a service desk person of a non-wholly owned division took home a laptop with data that wasn&#8217;t fully encrypted. The company was compelled to have her organization check out all the laptops during the Christmas holiday.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We worked pretty much day and night going through these laptops to see if there was anything of interest there that would&nbsp;potentially&nbsp;need to be discussed outside the company,&#8221; she recalls.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Impact of AI\">Impact of AI<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The most significant opportunity for CISOs today could be leading the deployment and governance of technology that automates tasks using artificial intelligence (AI).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I believe there is a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/ai-gives-defenders-the-advantage-in-enterprise-defense\" rel=\"noopener\">lot of merit to AI<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, especially having it work on things that are just so mind-numbingly boring, or where it can do repeatable tasks much faster than&nbsp;any one person&nbsp;can do,&#8221; Guttmann-Stark says.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">She notes that she attended a recent conference where five CIOs on a panel discussed the importance of AI. &#8220;They basically said they wouldn&#8217;t even entertain talking with a vendor unless that vendor was contemplating&nbsp;the use of&nbsp;AI within their solution,&#8221; she says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Similarly, CISOs she mentors ask where they can gain more proficiency in AI. Guttmann-Stark says she took two-day cyber-risk classes offered by the National Association of Corporate Directors.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">She says CISOs should be aware of what their boards know, especially given the new <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/orgs-face-major-sec-penalties-failing-disclose-breaches\" rel=\"noopener\">SEC data breach reporting rules<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/what-s-the-future-path-for-cisos\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security professionals who rise through the corporate ranks and become<\/p>\n","protected":false},"author":12,"featured_media":3458,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=1813%2C1107&ssl=1",1813,1107,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=300%2C183&ssl=1",300,183,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=640%2C391&ssl=1",640,391,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=640%2C391&ssl=1",640,391,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=1536%2C938&ssl=1",1536,938,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=1813%2C1107&ssl=1",1813,1107,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=1024%2C625&ssl=1",1024,625,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/whats-the-future-path-for-cisos.jpg?fit=1813%2C1107&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3457"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3457\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3458"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}