Reflecting on Davos: Responsible Leadership and Automation

Over the past week at the World Economic Forum Annual Meeting in Davos, Switzerland, I was fortunate enough to meet and participate in sessions with numerous leaders from business, government and academia from all over the world. As I mentioned in my last post, this year’s meeting focused on “Responsive and Responsible Leadership,” which I noticed took shape around two major themes: the promise of artificial intelligence (AI) and automation, and building and maintaining trust in these technologies.

AI and automation are poised to potentially upend industries; the research and development, and advancements, are staggering. While the stories of the application of AI are impressive, as one Davos participant noted, “We’re on the first rung of this ladder.” In the context of cybersecurity, we have long advocated for the need to have as automated an approach as possible to preventing breaches, and we are starting to see the transformative impact of automation on our industry, driving increasingly positive outcomes for organizations. The future of the digital age, from a technological perspective, is bright, so long as secure innovation continues.

However, the promise of a bright future is entirely contingent on trust in these technologies and the organizations that operate them. Consistently during discussions at Davos, it was clear that cybersecurity is being viewed at the most senior levels as a fundamental enabler of the innovations that hold great promise to improve health, productivity and communication for individuals and organizations everywhere.

What, then, does responsible leadership for cybersecurity look like? In my view, it means approaching cybersecurity as a math problem, in which the declining cost of compute power and commoditization of attack tools have made attacks cheaper than ever for adversaries. Security postures that focus solely on responding to attacks won’t solve that math problem – what will? Making attacks cost-prohibitive to attackers with automated next-generation technology, improved processes, and the education of people will.

The dialogue in Davos represents an excellent step toward broad recognition that the prevention of successful attacks lies at the heart of establishing and maintaining trust in the Fourth Industrial Revolution and, by extension, the digital age. As a next step, I encourage leaders looking for concrete advice to consult the editions of Navigating the Digital Age, executive-level cybersecurity guides we have put together with experts from a variety of fields for the U.S., U.K., Australia, France, Japan and Singapore, with more to come.

[Palo Alto Networks Research Center]

2016 Harold F. Tipton Memorial Scholarship Recipient

Cybersecurity professionals are in high demand and it’s projected to stay that way for the foreseeable future. Part of the mission of the Center for Cyber Safety and Education, (formerly the (ISC)² Foundation), is to provide scholarships to undergraduate and graduate students who are pursuing careers in the field of information security.

In 2016, the Center awarded scholarships to 44 students worldwide. The undergraduate recipients were invited to apply for the Harold F. Tipton Memorial Scholarship, which is awarded to an aspiring information security student, to help provide a pathway to the profession. The prestigious scholarship was named after the late information security industry pioneer and (ISC)² co-founder, Harold “Hal” F. Tipton, who is often referred to as “the grandfather of the CISSP®.”

The 2016 recipient of the Harold F. Tipton Memorial Scholarship is Erwin Karincic, an undergraduate student at Virginia Commonwealth University (VCU). Karincic’s passion for technology started when he was only seven years old, growing up in Bosnia. His computer broke and without anyone to fix it, Karincic bought a hard drive and operating system, then figured out how to fix it himself. Immigrating to the United States in 2014, he learned English and began excelling academically, enrolling in college-level courses as a high school student. He is currently studying computer engineering at VCU and plans to pursue a career in cybersecurity.

“The scholarship will help me to alleviate my financial burden during my studies and assist with research on new and improved ways to remove vulnerabilities with systems, and secure the entire infrastructure,” said Karincic. “In the near future, I plan to pursue CISSP certification in order to be globally recognized as one of the best information security leaders. This award will also allow me to spend more time mentoring other students, to help them grow and succeed in the cybersecurity field which all leads to the common goal of a safe cyberspace.”

Scholarships for undergraduate, graduate and post-graduate students are offered throughout the year through the Center for Cyber Safety and Education. Women’s Scholarship applications are now open. The application period for Undergraduate Scholarships begins February 15, and Graduate Scholarships on February 28.

For more information and to apply, please visit www.iamcybersafe.com/scholarships

[(ISC)² Blog]

Talking it Out: Millennials, Certifications and Careers (part two)

Editor’s note: ISACA Now recently moderated a conversation among a trio of millennials to discuss topics including professional development, networking, certification and how their generation differs from others when it comes to career priorities and workplace dynamics. The first portion of the conversation can be read here. The following is the second installment of the two-part conversation – edited for length and clarity – between Ashley Spangler, CISA, CISM, CRISC, SunTrust Banks, Inc., AVP Information Security; Leigh Ann Montgomery, CISA, Solutions Architect, and Mick Gomm, CISA, GWEB, PMP, Sr. Information Security Engineer and Board Member, ISACA Utah Chapter.

ISACA Now: Are there any perceptions or stigmas of millennials in the workforce that you think are unfair?
AS: I don’t think I’ve had anything in a negative light, but it’s almost like I can see the difference of how some other individuals who might be a peer to me are treated if they have certifications versus individuals who don’t have certifications. And it’s not necessarily negative, but I think it is solidifying the value that you’re bringing to the table. I think Mick used the word ‘clout.’ I had an instance where I had a manager who I think technically is a Gen Xer but a borderline Baby Boomer in age, and when we were having a 1-on-1 conversation about my career and my next promotion, the question was ‘Well, you’ve only been in your role about a year and a half or two years, why don’t you just stay in that role longer and really get to know what you’re doing?’ I don’t mean this in a bragging way, but I think there’s still some old-school thought that you have to put a certain amount of years into a job to master that position, or the monotonous day-to-day that you do in that position should be acceptable. I think one thing that I’ve experienced is there’s a little bit of a struggle when you challenge that generation’s way of thinking.

MG: I’ve definitely had that experience, too. One stigma is that millennials are impatient – we want to get to that next step, whatever that is, if it’s on a technical or management track. That’s because I think we have a better understanding of technology in general, especially in this space, and there’s a belief that we’re maybe a bit impatient about our career progression.

LAM: I think within the [Dallas-Ft. Worth] area, our local chapter has really great penetration into universities and colleges, and really makes a point to get out there and even go through different classes on manners and etiquette over the business table and stuff like that. We’ve learned how to do business in the business world but also how to impart our own values in ways that we think as millennials onto whatever topic that we’re covering. And I think that’s been really interesting to know how to embrace those challenges and not necessarily have to change your ways to match a previous generation. It’s just like Ashley said, we like to go about things at kind of a quicker pace, and I think lots of research has shown we want to change careers even a few times, whereas before that might not have been the natural pace of what people normally do. I think it’s neat to fit into the work environment that is already established and to try to make our mark on it as well.

ISACA Now: What are some other types of professional development opportunities that are important to you?
AS: Being a part of two different [ISACA chapter] boards of directors, I think it’s so interesting. I mean, I network all the time, and it’s not necessarily looking for that next person who might help me get another job. I’m more interested in everyone’s journey and how they get to where they are because there’s truly not a one-way path. Everyone’s path is different, which is intriguing to me and provides me insight on how I can potentially maneuver through my career personally. I think I take a passion in that because I really fell into information security. Both of my degrees are in accounting and information systems, and I had actually applied for a financial auditor position, but I was the fourth person in line, and they were only hiring three people, so they liked that I had an information systems degree, and they were like ‘Hey, why don’t you come join our team?’ I was like ‘I don’t know anything about what you’re doing.’ So, similar to what Leigh Ann had mentioned, I know the Nashville chapter, we had six local universities, and I was a part of building that ISACA local chapter academic program, and I made it a point when I would present to those universities to explain that it’s not just about being a developer or a programmer or a help-desk analyst. I tried to broaden their horizons on the different career options we have in our industry because truthfully curriculum is not up to speed to explain all of these different avenues and facets of our industry. I felt like even when I was in school, and that was only six years ago, there were only a few options, and the reality is that is not true. I mean, who knew about information security architect positions. I didn’t learn about that in college.

LAM: To tack onto that thought, it’s amazing being part of that ISACA community and seeing all the different career types – even just through CISA, all of the different ways people can use it. I think that’s probably why I was drawn to that CISA in the first place over the CISM or any of the others – you could really see security professionals, audit professionals, governance and risk and compliance professionals, a whole bunch of different facets with ultimately the same baseline. I think that’s why the networking events that we do, the college events, are really important, because you get to see all the different ways it can be used in all of these different areas. It’s really neat.

ISACA Now: There’s a notion out there that young people are especially resistant to the idea of the rat race, showing up at an office day in and day out. Obviously you all are committed, serious professionals, but how do you feel about incorporating your career into your overall lifestyles?
MG: At least for me in information security, I think the work-life balance is fantastic. I get a ton of autonomy of how I balance my workload and where I do it and everything. I’ll tell you, Leigh Ann, I actually grew up in the [Dallas-Ft. Worth] area, my parents live in Mansfield, so I am headed home in a couple weeks, and my company actually has an office in Arlington. I’m just going to work there for about a month while I’m down there, so I can avoid taking a lot of PTO by getting work done remotely. It’s an increasing trend that you’re able to work from home or another site. That’s something I try to tell people who are trying to get into information security or are wondering about career planning and work-life balance.

LAM: I actually work from home 100 percent of the time other than the travel expectations. It’s really great, I think, given that the work-life separation is the threshold of my office door. I know that like many millennials I really throw myself at work. I probably spend more time than necessary, but I know my company definitely backs me up and gives me a lot of options and time off. I feel like we’re really flexible where I work, and I really appreciate that. It really helps me get my work done in a comfortable way.

AS: It also depends on your industry. Working in consulting, they really had to sell you on what their version of work-life balance is. We had a lot of fun. We had a lot of parties and big events, and we got to travel to some really cool places. There are a lot of benefits they really had to tack on above and beyond what you probably get at a typical 8 to 5 kind of organization or industry, like financial services. So, I think it’s a difference in the roles that I’ve been in, and in consulting it was ‘We’re not here to count your eyeballs,’ you can work from wherever you want, just give us quality deliverables, which being fresh out of college, that was very nice. I really took a lot of pride in having that opportunity because I knew a lot of people I went to college don’t get to work from home, so I really appreciated if I had a doctor’s appointment at 9 a.m., I would just work an extra hour in the evening or make it up on the weekend. In the role that I’m in currently, we get certain days of the week that we can work remotely, so it’s not as free as the last job that I had but we still have freedom to work remotely. Kind of like what Leigh Ann and Mick said, it’s nice to be able to have those options so you can plan for things that don’t necessarily fit in an 8 to 5 time slot.

ISACA Now: Anything else that any of you would like to add?
LAM: I’ve probably said it a million times, but I’m very serious about it, is getting young people involved in local ISACA chapters. It’s important. I think all three of us probably benefited from that experience. It’s a neat way to give back to a larger organization that helped you get certified, helped you to network to find jobs and meet other individuals that you might lean on for one-off conversations or one-off problems in your normal day-to-day work. Beyond the certification, it’s really a community that we’ve all gained together.

[ISACA Now Blog]

Customer Spotlight: Law Firm Thwarts Ransomware with Traps Advanced Endpoint Protection

Pérez-Llorca, one of the premier law firms in Spain, was challenged with finding a solution that prevents the loss of sensitive client information, blocks ransomware and other cyberthreats, and avoids costs associated with remediating successful attacks. On several occasions, ransomware successfully infected the firm’s computers. While there was a robust backup system in place to rebuild the individual’s machine without paying the ransom and there was no loss of data due to encryptions, every successful attack was costly in terms of lost productivity for the lawyers and drained IT time.

It was in light of these costly incidents that Aitor Lasala, Chief Technology Officer at Pérez-Llorca, decided that the antivirus solution currently deployed on the firm’s endpoints was no longer adequate. Lasala consulted with Palo Alto Networks partner Grupo Antea, a firm Pérez-Llorca often relied on to assist in technology matters, for their opinion. After assessing Pérez-Llorca’s needs, Grupo Antea recommended Palo Alto Networks Traps advanced endpoint protection.

“The POC test convinced us that the Palo Alto Networks solution met all of our needs. Traps stopped every piece of known and unknown malware that had previously infected our endpoints. At the same time, Traps recognized our critical applications and allowed them to execute unimpeded.”

– Aitor Lasala, Chief Technology Officer at Pérez-Llorca

Find out how the firm was able to prevent successful ransomware attacks by deploying Palo Alto Networks Traps advanced endpoint protection by reading the Pérez-Llorca Customer Case Study.

[Palo Alto Networks Research Center]

Talking it Out: Millennials, Certifications and Careers

Editor’s note: ISACA Now recently moderated a conversation among a trio of millennials to discuss topics including professional development, networking, certification and how their generation differs from others when it comes to career priorities and workplace dynamics. The following is the first installment of the two-part conversation – edited for length and clarity – between Ashley Spangler, CISA, CISM, CRISC, SunTrust Banks, Inc., AVP Information Security; Leigh Ann Montgomery, CISA, Solutions Architect, and Mick Gomm, CISA, GWEB, PMP, Sr. Information Security Engineer and Board Member, ISACA Utah Chapter.

ISACA Now: Why did you decide to pursue certification at a relatively young age?
AS: Both of my degrees are in accounting and information systems. The firm I started to work for was creating this information security and assurance services group. I originally applied for a financial audit position and was not picked. However, they liked my background in information systems so they were like ‘Hey, why don’t you come join our team?’ Of course, I was completely green and didn’t really know what I was getting into. When I first got there, they said ‘You need to start working on certifications.’ I met an individual through ISACA, which is how I got intertwined with being a volunteer board member for the Nashville location, and I just started to learn more about the different certifications which were available in the information security industry. … I didn’t like being the only person that didn’t have a certification and especially when my name and bio would be listed on a statement of qualifications for bidding on work. CISA was most prominent in the information security assurance world that I was in at that point, so I made that my target for my first certification. So, I really looked at it, one, as validation for myself and what I was doing, and secondly for helping our group’s chances of winning engagements.

LAM: I was mentored by the president at the time of the North Texas ISACA chapter … He invited me to a meeting and talked about the different certifications, and mentored me through taking the CISA certification. Through that process, I really got to know my internal audit team of my company at the time. I took the test both to grow my knowledge of that type of audit and really understand what the terms were, and how to best get the information and pull evidence. It helped me in my day-to-day job and definitely added an acronym after my name, and got me exposed to a lot of really great people and networking in the process.

MG: I started out in audit consulting, and kind of the baseline or the bar to working in that space is an audit certification, and CISA is the most recognizable and known. I think the IT audit and information security industries really just look for that, especially in the past few years. Having multiple certifications is almost a barrier to entry. That’s why I got my third certification, the CISA, because starting in consulting, they were like ‘Alright, the first thing you need to work on is getting your CISA.’ Certifications like CISA are important, but I also think the industry is headed toward requiring additional specialization in specific technologies and spaces.

ISACA Now: How does your certification help you most on a daily basis?
LAM: On a day-to-day basis, part of my job is to build security programs and security awareness programs for other companies, and I always try to do that with audit principals in mind. Make a program metrics-driven, and seeing how we can improve year over year and clearly think about how, from an auditor’s perspective, how I can make my suggestions for other companies with those basic audit recommendation principles in mind. So, I go back to what I learned during my CISA certification studying. A lot of the language that I use for these types of recommendations are very similar to what I learned, so it definitely helps me communicate not only with security professionals, but audit professionals, and executives from both of those sides.

AS: It seems like there are so many moving pieces and parts within our enterprise, constantly dealing with different lines of business and their needs. I think having the CISA, CRISC and the CISM may have been most helpful in giving me those multi-faceted knowledge bases which I can leverage to solve problems for the various lines of business and segments of our bank. Overall, from a career perspective it helps solidify the knowledge that I use in solving those problems. I think people see my work in combination with the certifications as a justification of my value that I bring to the table, especially being a millennial.

ISACA Now: Can you elaborate on that?
AS: I don’t know if you’ve ever heard this, but the way I’ve heard it and thought about it is a lot of Baby Boomers and Gen Xers, they kind of have a strange feeling regarding millennials and how we impact the workforce. We’re essentially change agents and we’re ambitious and we want to impact our organizations in a positive way, and ultimately some of us want to be able to change the world. We don’t necessarily climb that ‘career leader’ that older employees or Gen Xers climb; we essentially just take the elevator. We don’t like the red tape. We don’t like the bureaucratic processes. We’re always looking for bigger and better ways to do things. In my situation, being as young as I am and having the certifications but not necessarily having extensive experience, it helps stabilize my footing when I’m interacting with more seasoned professionals.

LAM: I would absolutely agree with you, Ashley. Often I’m looked at as very young in the field and therefore very inexperienced. I think having the CISA and serving on my local ISACA board have really helped to get my name out there.

MG: I totally agree. When you meet face-to-face and people realize how young you are, they’re like ‘Oh, you’re not qualified.’ But when you have certifications, people pay attention more. You have more clout in those situations, especially when you’re interacting with other companies or vendors and you introduce yourself on a phone call, and somebody asks that question ‘What credentials do you have?’, it’s always nice to be able to respond that you have multiple certifications because people in the industry know what the certifications are and what they mean. I also think the industry is leaning toward the certifications being less book knowledge and more hands-on technical knowledge, which I think is really good.

AS: I can’t agree with you more about those times where, working in a larger organization, we have a little over 33,000 employees, and I speak with a lot of people on the phone, and when I meet them in person, they always say ‘Don’t take this wrong, but you sound so old’ or ‘I can’t believe how young you are.’ I’ve had that happen quite a bit.

LAM: My company works with many global organizations and currently we’re expanding into the Asia Pacific region. Especially with my age and length of experience, I find that when I speak to audit members or different security team members in that region about having CISA certification, they’re very impressed and willing to work with me when before they might not have been as willing. So, it definitely has helped me prove myself as a consultant trying to get into those types of deals. Despite any cultural differences, I have found that having a particular certification and serving on [an ISACA chapter board] has opened up a lot of communication with people who are very different from me. Being able to gain that common ground has been really interesting and has really opened a lot of doors.

[ISACA Now Blog]

English
Exit mobile version