A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Motor Oil
The First Hundred Years Are Difficult. Be Calm. Everything Is Fine


Christos Syngelakis
The Ever-Changing Battlefield of Cybersecurity
Working with Digital Security even in our time sounds like a challenge. I was involved since 89 with the first virus protection program in DOS and the transformation of a floppy disk to a hardware token for a copy prevention program in 93. First firewall in 96 and since then IT and security operations, in communications and data centers in various industries. The last decade with the roles of CISO and DPO.
The role of CISO needs a technical background, but it requires much more than that. It requires soft skills, many of which I did not have when I took it on. Experience comes with friction and over time, as long as you are given the luck and the opportunity to be able to rub without getting worn out. You will have to see security through the eyes of a Business enabler.
We chose a problematic science. What we learn constantly becomes useless. Technologies that come and replace others, leveling and erasing what we have learned. But this useless knowledge is what differentiates you from those who have not experienced it. In some magical way, all the useless knowledge helps in a useful way to understand how everything works. Because no matter how much everything has changed, they are based on basic principles. You stand on them and move more steadily even if the environment changes.
It is impossible to survive if you are not in a constant state of learning. We have reached the level of exhaustion. There are so many sources of information and it is so difficult to focus on anything. I really wonder how people who do not already have a large repository of knowledge from a wide range of the past will be able to cope with the needs for knowledge in such a labyrinthine environment.
Continuous learning about the basic and everyday risks, how they change, in what new aspects of activities and new technology they are lurking and what products or solutions may exist. It is invaluable if you can gain access to the thoughts, experiences and knowledge of capable colleagues. It requires a significant investment of time and targeted study and not just reading a few newsletters if one wants to be able to identify what the emerging threats are.
Obtaining a Professional Certification as an engineer is useful if one wants to pursue vertical knowledge. If you have the will to learn, the knowledge will come. The course framework that a certification offers will help if one cannot focus on the structure of a learning program on their own. However, there is also Certification for Certification. A series of an endless series of three or four letters next to the name. Certification marks are useful to a company when writing a proposal and wants to prove that it has knowledgeable engineers and to you on your CV when you are looking for a new job.
Artificial intelligence helps find solutions to situations where finding the right human resources to deal with them is problematic. It also promises a solution much faster than a team of people can provide. In the field of cyber defense we are forced to examine hundreds of situations with the effort focused on distinguishing one.
In such cases, any help is useful and the help that artificial intelligence can provide should not be ignored. But we must admit that not all AI are the same. A good AI product that will defend itself costs money and usually requires you to be connected to a whole ecosystem of cybersecurity solutions that are not necessarily suitable for your needs. Let's not look for products that are good and cheap because we will probably be fooled.
Also, a big problem is that AI will help the other side, which will exponentially multiply the possibility of creating problematic situations that will be founded by any of their successes. Even if in the positive scenario we manage to ward off any situations with corresponding AI systems, this will be a continuous financial blow that will cost more and more.
Building a culture of awareness among employees, must be inventive and I believe that probably the only way for someone to listen to you is to relate problematic situations to their own personal and not professional life. Someone will pay attention and learn what they need to do so that someone does not deceive them and their children, does not steal their money, does not drop their own photos and does not blackmail them with their own data, destroying their own life. If he gives them the basics, understands and uses them, then there is a good chance that he will reflexively transfer this culture into his working life relatively easily.
Cybersecurity leaders must be Swiss Army knife. With a need to know not only what technological risks the company has to face but also with knowledge of its culture, its strategy and the general way it runs. With the ability to compete with machines and people with the same comfort. With the ability to judge where he should insist and where to back off.
With given opportunity to be actively involved in nasty situations. If they are lucky there should be someone over there to support and help and not necessarily criticize. Continuous friction and involved in new technologies and continuous ability to learn. With every day collaboration with the company's people and external partners, participation in Project management and development of soft skills in people management and crisis management. With continuous sharpening of the Swiss Army knife.
Aiming to reach a CISO position needs persistence, patience, courage and a strong stomach. If you want to make a career, jump from company to company. You will never complete anything, but you will make a strong CV.