{"id":7003,"date":"2025-01-21T09:00:00","date_gmt":"2025-01-21T15:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-must-think-clearly-amid-regulatory-chaos"},"modified":"2025-01-21T09:00:00","modified_gmt":"2025-01-21T15:00:00","slug":"why-cisos-must-think-clearly-amid-regulatory-chaos","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/21\/why-cisos-must-think-clearly-amid-regulatory-chaos\/","title":{"rendered":"Why CISOs Must Think Clearly Amid Regulatory Chaos"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt81ea13eaf12d6b1c\/67506ba3c70df6502150eb3c\/Regulations_%281800%29_filmfoto_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><br \/><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the high-stakes world of cybersecurity, the ground is shifting beneath the feet of those charged with protecting our digital infrastructure. First came the new Securities and Exchange Commission (SEC) rules and lawsuits related to cybersecurity. More recently, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.google.com\/url?q=https:\/\/axios.com\/2024\/07\/02\/chevron-scotus-biden-cyber-regulations&amp;sa=D&amp;source=docs&amp;ust=1736459693434916&amp;usg=AOvVaw0AaGeWVpg6fUX_Z-Q-Ngpk\">a <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.google.com\/url?q=https:\/\/axios.com\/2024\/07\/02\/chevron-scotus-biden-cyber-regulations&amp;sa=D&amp;source=docs&amp;ust=1736459693434916&amp;usg=AOvVaw0AaGeWVpg6fUX_Z-Q-Ngpk\">US Supreme Court ruling<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> promises to reshape the regulatory landscape, compelling federal officials to rethink their approach to cyber governance.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Yet amid this whirlwind of change that has descended on the industry, it&#8217;s critical for chief information security officers (CISOs) to remain steadfast and not be deterred \u2014 or discouraged \u2014 by this shift.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">New public policies changing the field require security professionals to stay abreast of the regulatory landscape. More changes are undoubtedly on the horizon. But through all the turbulence, the CISO&#8217;s role remains unchanged: a vital player in the team sport of safeguarding an organization&#8217;s data and networks.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Therefore, my message, drawn from decades in the security field, resonates with the stiff-upper-lip slogan of Britain in the run-up to World War II: Keep calm and carry on.&nbsp;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Regulatory Tsunami\">A Regulatory Tsunami<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The SEC&#8217;s rules went into effect last December. Under the new rules, public companies must report any cyber incidents within four business days of determining that it was a material event. The SEC also requires that public companies disclose their strategies for handling cybersecurity risks.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Those in the security world apprehensive about these anticipated changes became downright frightened when the SEC \u2014 even before its new rules went into effect \u2014 sued a company, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/5-key-takeaways-from-the-solarwinds-breach\">SolarWinds<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, that had been going so far as to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/sec-charges-against-solarwinds-ciso-send-shockwaves-through-security-ranks\">single out its CISO in its filings<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Just weeks before its new cybersecurity laws were set to go into effect, the agency was sending a clear message to the country&#8217;s CISOs: Complacency is no longer an option.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When in July a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/application-security\/solarwinds-charges-tossed-out-of-court-in-legal-victory-against-sec\">federal judge dismissed most of the SEC&#8217;s case against SolarWinds and its CISO you could almost hear the sigh of relief among security professionals across the land.&nbsp;&nbsp;<\/a><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But the judge simply confirmed what those of us in the cybersecurity field already understood: Holding a CISO personally liable for a cyberattack won&#8217;t make systems more secure. While security professionals play a critical role in protecting a company, they cannot do so effectively without the collaboration and support of others. CISOs often have only partial visibility into an organization&#8217;s attack surface. That, of course, is a serious impediment to conducting a complete risk assessment.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To be clear, legislation can play a role in helping CISOs enhance an organization&#8217;s defenses. The Food and Drug Administration&#8217;s (FDA&#8217;s) implementation of cybersecurity requirements for medical devices illustrates this well. Those regulations empowered CISOs to join the conversation and secure the resources needed to safeguard additional areas of their organizations.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The SEC&#8217;s newest ruling provides a similar opportunity \u2014 and long overdue change \u2014 for today&#8217;s CISOs to be more involved in an organization&#8217;s fuller set of technology decisions.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"A Collective Responsibility&nbsp;\">A Collective Responsibility&nbsp;<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At their core, CISOs are truth sayers \u2014 akin to an internal audit committee that assesses risks and makes recommendations to improve an organization&#8217;s defenses and internal controls.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ultimately, though, it&#8217;s the board and a company&#8217;s top executives who set policy and decide what to disclose in public filings. CISOs can and should be a counselor for this group effort because they have the understanding of security risk. And yet, the advice they can offer is limited if they don&#8217;t have full visibility into an organization&#8217;s technology stack.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many oversee a company&#8217;s IT system, but not the products the company sells. That&#8217;s crucial when it comes to data-dependent systems and devices that can provide network-access targets to cyber criminals. Those might include medical devices, or sensors and other Internet of Things endpoints used in manufacturing lines, electric grids, and other critical physical infrastructure.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In short: A company&#8217;s defenses are only as strong as the board and its top executives allow it to be.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And if there is a breach, as in the case of SolarWinds? CISOs do not determine the materiality of a cybersecurity incident; a company&#8217;s top executives and its board make that call. The CISO&#8217;s responsibilities in that scenario involves responding to the incident and conducting the follow-up forensics required to help minimize or avoid future incidents.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even before the SEC got involved, though, liability was an underlying concern among security officers. Those whose job it is to protect our data systems invariably feel responsible when something goes wrong, whatever a federal agency might say.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ours is a business in which thwarting a bad actor 99 times will not make any difference if an intruder manages to breach defenses on the 100th try. That&#8217;s the burden that comes with the CISO title, and that&#8217;s why I&#8217;ve always recommended \u2014 long before the SEC&#8217;s new transparency rules \u2014 that a CISO understand the complex threat landscape as well as the evolving regulatory environment.&nbsp;&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Chevron Decision: A New Layer of Complexity\">The Chevron Decision: A New Layer of Complexity<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For cybersecurity professionals, the legal move potentially more significant than the dismissal of the SolarWinds suit was the Supreme Court&#8217;s decision in June to reverse the so-called Chevron doctrine. The Chevron doctrine, established by a previous case in 1984, required the courts to defer to a federal agency&#8217;s reasonable interpretation of ambiguous statutes.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Now, the wisdom of agencies \u2014 whether the SEC or other bodies \u2014 is no longer assumed. The overturning of this decades-old Chevron precedent has created uncertainty around the enforcement of cybersecurity regulations, making it even potentially harder for CISOs to navigate the regulatory landscape.&nbsp;&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even as the rule book may be in flux, though, the professional mission of the CISO remains unchanged: protecting their organization in a world of constant, continually evolving threats. That requires clear thinking and the ability to keep one&#8217;s head amid chaos.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In other words: Keep calm and carry on.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/cisos-must-think-clearly-amid-regulatory-chaos\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARYIn the high-stakes world of cybersecurity, the ground is shifting<\/p>\n","protected":false},"author":12,"featured_media":7004,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7003","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/why-cisos-must-think-clearly-amid-regulatory-chaos.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7003"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7003\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7004"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}