• About
  • Subscribe
  • Contact
Thursday, May 8, 2025
    Login
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
No Result
View All Result
No Result
View All Result
Home Technology Security

PodChat for FutureCISO: Architecting security for an unknown future

Allan Tan by Allan Tan
April 17, 2023
PodChat for FutureCISO: Architecting security for an unknown future

PodChat for FutureCISO: Architecting security for an unknown future

Gartner says the endlessly expanding digital footprint of modern organisations is introducing new security challenges. The pandemic response has accelerated hybrid work and the digitalisation of business processes in the cloud.

2022 showed us what sustained big-game ransomware attacks, including multiple attacks on the digital supply chain, deeply embedded vulnerabilities, and increasing attacks on identity systems, can do to vulnerable organisations.

When coupled with the shortage of skilled security staff at all levels, in almost any part of the world, you have to ask: how did we survive 2022, and can we thrive in 2023?

Omer Grossman, global chief information officer for CyberArk, attended the 2023 Gartner Security And Risk Management Summit and shared three key learnings from the conference:

Cybercrime, specifically ransomware. Keeping up with regulations can be challenging. According to our CyberArk 2023 identity security threat landscape, over 70% of organisations surveyed have experienced ransomware attacks in the past year.

Supply chain, and third-party issues. Many cyber incidents happen through a third party. Our CyberArk survey shows that 62% of the organisations have done nothing to secure the software supply chain post the solar winds attack.

Cyber resilient. Organisations may suffer from loss of customers and revenue, pay compliance fines or even fail in an audit.

Go beyond security and technology

Grossman noted that to be effective in their role, including earning the trust of the Board and other members of the C-suite, CISOs need to understand business issues – and this is happening today.

Bryan Kissinger, author of CISO: How to Organise, Evangelize, and Operate an Enterprise-wide IT Risk Management Program, explains that the continued intensity of cyber terrorism attacks, regulatory and compliance requirements, and customer privacy concerns are driving the need for a business-minded CISO to lead organisational efforts to protect critical infrastructure and sensitive data.

He suggests that a CISO must be able to both develop a practical program aligned with overall business goals and objectives and evangelise this plan with key stakeholders across the organisation.

Source: Identity Security: Bridging the Executive Confidence/Reality Gap, CyberArk 2023
Omer Grossman

Grossman concurs adding that almost 70% of global C-levels said that they are making correct identity security-related decisions, compared to more than half of all other personnel.

"There is a gap. In the Asia Pacific region, the statistics are even lower, only 50% of C-level executives believe they are making correct identity security-related decisions."

Omer Grossman

Security is a team sport

Kissinger says that the modern CISO cannot sit in a bunker somewhere in the IT operations centre and expect to achieve buy in and support for the activities required to operate a program.

For his part, Grossman proposes that the secret sauce to a successful CISO career lies in “how do you govern not only with sticks but also with carrots. How do you balance the built-in tension between productivity and security?

He offers a few principles that work:
  1. Collaboration and trust are key: Wherever there is trust, you can convince others.
  2. Understanding the business process is a must.
  3. You must have clear communication around risk management: Security has to be seen as a key enabler for the business. Security isn't the enemy.

The influence of technology

According to the Capgemini Research Institute report, Reinventing Cybersecurity with Artificial Intelligence: the new frontier in digital security, 56% of executives participating in the survey say their cybersecurity.

To counter the threat, respondents accept AI as fundamental to the future of cybersecurity. For 64%, they expect it to lower the cost of breach detection while 74% it will enable them to respond faster.

“AI offers huge opportunities for cybersecurity,” says Oliver Scherer, CISO of Europe’s leading consumer electronics retailer, MediaMarktSaturn Retail Group. “This is because you move from detection, manual reaction and remediation towards automated remediation, which organisations would like to achieve in the next three

Grossman argues that the industry is reaching an inflexion point where technology’s growth becomes exponential.

"We have reached an inflexion point for AI lately, specifically with the derivative capability through ChatGPT. Cybercriminals are leveraging AI for cyberattacks. I see AI fighting AI in the near future and the good guys will win eventually."

Omer Grossman

He commented on being less concerned with quantum computing as he believes the technology is still years away from maturing. Still, he acknowledges quantum computing will be key to secure private and public encryption.

Futureproofing cybersecurity

Like many other technology practitioners, Grossman does not believe in a future-proof cybersecurity strategy. He suggests that organisations include identity security, as a crucial piece of the cyber security pie.

"Identity-based security controls are critical for detecting network attacks," he added "but they've already made their way inside organisations' infrastructure. With them in place, organisations can focus on protecting our most valuable assets to prevent data theft and disruption to their key risks in the cybersecurity world."

Omer Grossman

He opined that zero trust, supported by identity security is key. "Never trust, always verify every user's identity. Ensure that devices are validated and privileged access is intelligently limited to just what they need," he concluded.

Click on the PodChat player to listen to Grossman detail his recommendations for architecting security for an unknown future.

  1. You recently attended the Gartner Security & Risk Management Summit (2023). From your perspective what is the key to learning from the Summit?
    • What are the top 3 concerns of pre-occupying CISOs, heads of security and CIOs?
  2. In 2023, has the role of the CISO changed much? Can you identify if any – the most significant change (priority) in the role in 2023 compared to previous years?
  3. As your role at CyberArk is an internal one, how do you work with the security team and the CISO, the rest of the C-suite, and the Board when it comes to the security of CyberArk?
  4. AI is with us now (albeit still maturing) whereas quantum computing is still 5-10 years away. How are these two technologies impacting how cybersecurity technology and practices?
  5. Is there such a thing as futureproofed cybersecurity strategy?
Related:  90% of all security mistakes come from remote workers
Tags: CyberArkcybersecurityidentity securityPodchats
Allan Tan

Allan Tan

Allan is Group Editor-in-Chief for CXOCIETY writing for FutureIoT, FutureCIO and FutureCFO. He supports content marketing engagements for CXOCIETY clients, as well as moderates senior-level discussions and speaks at events. Previous Roles He served as Group Editor-in-Chief for Questex Asia concurrent to the Regional Content and Strategy Director role. He was the Director of Technology Practice at Hill+Knowlton in Hong Kong and Director of Client Services at EBA Communications. He also served as Marketing Director for Asia at Hitachi Data Systems and served as Country Sales Manager for HDS’ Philippines. Other sales roles include Encore Computer and First International Computer. He was a Senior Industry Analyst at Dataquest (Gartner Group) covering IT Professional Services for Asia-Pacific. He moved to Hong Kong as a Network Specialist and later MIS Manager at Imagineering/Tech Pacific. He holds a Bachelor of Science in Electronics and Communications Engineering degree and is a certified PICK programmer.

No Result
View All Result

Recent Posts

  • Agentic AI-powered AppSec platform launched for the AI era
  • IDC forecasts GenAI alone will grow at a 59.2% CAGR
  • Dataiku brings new AI capabilities to create and control AI agents
  • Microsoft reveals the rise of a new kind of organisation in the AI era
  • St Luke’s ElderCare enhances data security and user experience with Juniper

Live Poll

Categories

  • Big Data, Analytics & Intelligence
  • Business Applications & Databases
  • Business-IT Alignment
  • Careers
  • Case Studies
  • CISO
  • CISO strategies
  • Cloud, Virtualization, Operating Environments and Middleware
  • Computer, Storage, Networks, Connectivity
  • Corporate Social Responsibility
  • Customer Experience / Engagement
  • Cyber risk management
  • Cyberattacks and data breaches
  • Cybersecurity careers
  • Cybersecurity operations
  • Education
  • Education
  • Finance
  • Finance & Insurance
  • FutureCISO
  • General
  • Governance, Risk and Compliance
  • Government and Public Services
  • Growth Strategies
  • Hospitality & Tourism
  • HR, education and Training
  • Industry Verticals
  • Infrastructure & Platforms
  • Insider threats
  • Latest Stories
  • Logistics & Transportation
  • Management Leadership
  • Manufacturing
  • Media and Telecommunications
  • News Stories
  • Operations
  • Opinion
  • Opinions
  • People
  • Process
  • Remote work
  • Retail & Wholesale
  • Sales & Marketing
  • Security
  • Tactics and Strategies
  • Technology
  • Utilities
  • Videos
  • Vulnerabilities and threats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCIO is about enabling the CIO, his team, the leadership and the enterprise through shared expertise, know-how and experience - through a community of shared interests and goals. It is also about discovering unknown best practices that will help realize new business models.

Quick Links

  • Videos
  • Resources
  • Subscribe
  • Contact

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Management Leadership
    • Growth Strategies
    • Finance
    • Operations
    • Sales and Marketing
    • Careers
  • Technology
    • Infrastructure and Platforms
    • Business Applications and Databases
    • Big Data, Analytics and Intelligence
    • Security
  • Industry Verticals
    • Finance and Insurance
    • Manufacturing
    • Logistics and Transportation
    • Retail and Wholesale
    • Hospitality and Tourism
    • Government and Public Services
    • Utilities
    • Media and Telecommunications
  • Resources
    • Whitepapers
    • PodChats
    • Videos
  • Events
Login

Copyright © 2022 Cxociety Pte Ltd | Designed by Pixl

Subscribe