{"id":91654,"date":"2020-08-04T09:00:06","date_gmt":"2020-08-04T16:00:06","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=91654"},"modified":"2023-05-26T14:16:30","modified_gmt":"2023-05-26T21:16:30","slug":"ciso-stressbusters-post-4-highly-effective-security-operation","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2020\/08\/04\/ciso-stressbusters-post-4-highly-effective-security-operation\/","title":{"rendered":"CISO Stressbusters: 4 tips for running a highly effective security operation"},"content":{"rendered":"
Rebecca Wynn<\/em><\/a>, <\/em>Global CISO & Chief Privacy Officer<\/em> (CISO) of [24]7.ai\u00a0, shares her advice for relieving stress in today\u2019s CISO Stressbuster post.<\/em><\/p>\n In many organizations, CISO is held accountable for security breaches, yet they don\u2019t have control over all the decisions and systems that impact cyber risks. They need to continuously prove that they are making the company safer while persuading others to change behaviors.<\/p>\n Building a security culture can be stressful, but it helps if people know they can count on you. As a senior information and security risk officer who has served as a CISO at several technology companies, I\u2019ve learned that one way to increase influence is to get things done. Running a tight ship helps you prove value and gain allies. In the fourth blog in the CISO Stressbuster series, I\u2019ve outlined four tips that will help you build a highly effective security organization.<\/p>\n The most important part of your security operation is your people. A strong team that works well together will help you deliver on your goals and prove the value of cybersecurity to the board. To ensure your team has the right skills for your organization, start by identifying your strengths and weaknesses. For example, you may need people with more experience in cloud or automation technologies. It\u2019s also essential to think about diversity. People with different backgrounds help you avoid group-think and generate new ideas.<\/p>\n Training and apprenticeship programs are a great way to build skills within your existing staff. When done well, you can encourage a continuous learning culture that keeps people engaged. This is incredibly valuable because it isn\u2019t just CISOs who are stressed. Our teams are also under a lot of pressure. Helping them grow and acquire new skills can reduce burnout.<\/p>\n You won\u2019t be able to fulfill all your needs with training, but it can be challenging to find senior people with specialized backgrounds. When you do need to fill a new position, be intentional about which skills are required and which can be trained. Expand your criteria to include people with non-traditional backgrounds who can offer new insights. To encourage participation from everyone, build an inclusive culture.<\/p>\n Whether you work at a huge enterprise or a startup, there will always be a limit to your budget. Make smart investments to stretch those dollars farther. A great example is software and cloud services. There are many great security products available, but if they don\u2019t work well with your current solutions, you may not get as much value out of them. Find ways to expand the usage of existing products. Make sure new tools align with your long-term strategy and that teams are well trained. Audit your technology regularly and stop paying for services that no longer meet your needs.<\/p>\n Strategic staffing decisions can also help you do more with your budget. For highly specialized skills or irregular tasks, it can sometimes be more efficient to outsource. On the other hand, you may need to invest in your own team to prepare for a changing business climate, such as hiring analysts with cloud expertise.<\/p>\n Demonstrating a proven track record of managing your budget well, builds trust with the board and other executives. This gives you more credibility when you ask for increases in the future.<\/p>\n Your goal as a CISO is to improve the security of the company by effectively managing cybersecurity risk. To evaluate how well you are doing, you need to track the right metrics. The number of tickets opened and closed each month won\u2019t tell you much, but the context of those tickets can.<\/p>\n Set up reporting that will help you measure how well your team and tools are protecting the organization. Some possible examples include:<\/p>\n Making things happen as a CISO requires that you influence others. Whether that is encouraging different behavior from your team, persuading the board to approve a budget increase, or convincing other business leaders to take security seriously, communication is key.<\/p>\n Effective communication starts with good relationships. When I first join a company, I immediately work on building partnerships with other business leaders. If they have issues with the security team, I work on getting those ironed out. This paves the way for me to have conversations about how we can work together to improve security.<\/p>\n As you work with colleagues to make progress on security objectives, it helps to be agile. Listen during meetings to try to understand what\u2019s working and what\u2019s not. Flex your language depending on who\u2019s in the room. When people understand how they will benefit from security, they are more likely to get on board.<\/p>\n Safeguarding your company against cyber threats is rewarding work, but it also comes with a lot of pressure. To help you manage the stress, the CISO Stressbusters blog series will feature advice from CISOs from a variety of different companies and industries. S<\/em>tay tuned for the next CISO Stressbuster post for more advice from others in the trenches.<\/p>\n Did you find these insights helpful? What would you tell your fellow CISOs about overcoming obstacles?\u00a0 What works for you? Please reach out to Diana Kelley on LinkedIn<\/a> if you\u2019re interested in being interviewed for one of our upcoming posts.<\/p>\n Bookmark the\u00a0Security blog<\/a>\u00a0to keep up with our expert coverage on security matters. Also, follow us at\u00a0@MSFTSecurity<\/a>\u00a0for the latest news and updates on cybersecurity.<\/p>\n <\/p>\n","protected":false},"excerpt":{"rendered":" CISO Stressbusters provides peer to peer guidance and support on how to alleviate stressful situations in the SOC and on the team.<\/p>\n","protected":false},"author":96,"featured_media":91661,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[3659],"topic":[3684],"products":[],"threat-intelligence":[],"tags":[3822],"coauthors":[2371,1916],"class_list":["post-91654","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-best-practices","topic-security-operations","tag-microsoft-security-insights"],"yoast_head":"\n1. Cultivate your team<\/h3>\n
\n
2. Be a good fiduciary with your budget<\/h3>\n
3. Measure metrics that matter<\/h3>\n
\n
4. Adapt your communication for your audience<\/h3>\n
Looking ahead<\/h3>\n
\n