How to Win the IT Advisory Talent Battle

Demand never has been higher for the IT advisory skill set. At our firm, we’re seeing more competition now than even existed in the SOX boom of the mid-2000s. Positions across the United States are re-maining open for months at a time. Your company wants to make sure it’s not settling on the first ap-plicant who knows the difference between CISA and COBIT and, instead, wants to attract the brightest talent that will really make a difference to your team.

We’ve seen some common themes among our clients who consistently attract the best candidates, and I’d like to share them with you so that you can win the talent war in 2017 and beyond.

Impact
The number one motivation for making a job change that I hear time and time again goes something like this: “I don’t feel like my position really makes a difference. I just check up on everyone else.” You need to make sure you’re marketing your position as one that allows the applicant to see the meaning and purpose of his or her work. Tell them success stories about your department and paint a picture for them about how you are perceived in the organization.

A recent example from one of our clients was a project where the business operations and IT security teams could not agree on the best way to move forward on a large product rollout. The IT audit team (through years of showing its value to the business) was instrumental in making sure both sides came to an agreement in order to release a workable product. Not only does this IT audit team now have the pride and satisfaction from helping shape one of the company’s most important initiatives, but is has also turned into a great recruiting story allowing them to attract top talent. That’s true impact.

Work/life balance
The rise of the Silicon Valley style corporations with unlimited vacation time, a whole year for paterni-ty/maternity leave and game tables in every conference room has made it difficult to win the talent war without offering an appealing work/life balance. At the management level, I know you’re not able to change large policies like I’ve mentioned above, but what you can do is make your department one that embraces technological advances that allows your employees to work when they can, where they can.

I realize that this is more easily said than done, but companies that are doing this are able to attract the best talent. Perks such as working a day a week from home, flexible work schedules (get in early/leave early, etc.,) and making sure on-site time is used to maximize face-to-face encounters with internal customers and team members while the rest of the work is done from a coffee shop, etc., will help you to be much more appealing to the generation that has grown up with information available any-where, on any platform.

Growth
Obviously, your goal is to retain the talent you are able to attract. The best way to do that is to make sure your employees are challenged, able to grow and never bored: “I want to make sure I’m not a (insert job title here) forever.”

It’s a common concern among candidates I speak with and human nature to not want to feel trapped. Candidates want to feel there is a career path for them and know that they won’t be doing the same thing every day. They crave variety, challenge, growth and advancement. If you plan to hire someone who already knows how to do everything in your job description, you’re setting yourself up to have someone leave your department early if there is no significant growth or challenge for them if they stay. In so far as possible, create opportunities for your employees to add to their skill sets, and enable them to advance within and eventually beyond your department. If you don’t have a compelling story about the growth opportunities you can provide for your new team members, you will continue to lose that talent to other companies who can show them a challenging career path.

Use what sets you apart
If you search for the term “CISA” on LinkedIn, Indeed, Monster and CareerBuilder, you’ll find thou-sands of available roles. On ISACA’s own job board, there are 500. With competition like that, you need to be sure your company and opportunity stands out from the rest.

What is special about your company that attracted you to work there? How do you address mentoring younger talent? What processes do you have in place to groom the candidate for future leadership roles? Also, make sure to allow the applicant to go to lunch with potential co-workers, not just manag-ers. Applicants who leave the interview believing they will enjoy working beside the people they meet will be much more inclined to want to work for you.

Highlighting smaller perks doesn’t hurt, either. Do you have a generous 401K match? Does your com-pany offer free lunches in the cafeteria? Have an onsite daycare? Make sure you advertise those.

My goal for this article was to provide value to you and help you identify some things you can do to attract the talent you need to succeed. If I can answer any questions to help you win the talent battle, write your questions in the comments below!

Brad Owens, Recruiting Director, Duval Search

[ISACA Now Blog]

Build Your (ISC)² Network through Chapters in EMEA and North America

Are you looking to start an (ISC)² Chapter in your area? The enrollment period for chapters in the Europe, Middle East and Africa (EMEA) and North America regions is now open through February 5. Through the chapter program, (ISC)² members and other information security professionals further advance the organization’s vision to inspire a safe and secure cyber world by sharing knowledge, raising security awareness and advancing information security in local communities around the world.

To be eligible to start a chapter, you will need to meet the following requirements:

  • Be an (ISC)² member in good standing for a minimum of three years.
  • Be a resident of the area in which you plan to start a chapter for at least one year.
  • Have proven leadership experience in a professional setting.
  • Not currently serving as an officer of another security chapter organization.
  • No previous convictions of criminal activity or conduct.

Since lifting the moratorium on chapters this month, we have already received several applications from the two regions, and we look forward to receiving more! The new chapter application process is streamlined and entirely online, making it easier to get started.

To submit a chapter application, visit https://isc2chapters.communityforce.com/

Open enrollment for the Asia-Pacific (APAC) and Latin America (LATAM) region chapters will begin in Q2 2017. Keep an eye on our blog for an announcement.

[(ISC)² Blog]

On Data Privacy Day, Keep Your Data Safe by Identifying the Threats

Saturday, January 28th was Data Privacy Day. We’re proud champions of the National Cyber Security Alliance’s focused effort on protecting privacy and safeguarding data. But at Code42, we know that one day isn’t enough. We dedicate an entire month each year to reaffirm our critical role in keeping our customers’ data safe.

This year, we initiated an annual Certified Information Systems Security Professional (CISSP) training program at Code42 and trained staff on the eight common bodies of knowledge defined by (ICS)2 to earn the coveted credential. We embedded a new tool in our email system for Code42 employees to report phishing attempts. And, we hosted a panel discussion with representatives from the FBI and Secret Service to learn more about how they combat cybercrime.

But we’re not here to talk about what we did to keep our data safe. We’re here to talk about what you can do to protect yours. The first step in any cybersecurity strategy: situational awareness.

Your Employees Are Being Targeted: Part One
Your end users, and their devices, represent a very large mobile attack surface. IT and InfoSec professionals spend far too much time cleaning up issues caused by employees who fall for phishing emails, click corrupt links, or engage in careless online behavior. These unintentional “user mistakes” are one of the biggest threats today, causing around 25 percent of data exfiltration events.

Why do users make so many mistakes? To put it simply, most don’t care. They believe that if IT is doing its job, no threats will reach them and they have nothing to worry about. They believe that if they have an error in judgment, or do something foolish, IT will always come to the rescue. They actively ignore security policies and find creative workarounds for security measures they view as an inconvenience.

Your Employees Are Being Targeted: Part Two
It’s one thing for your employees to make mistakes. It’s another for them to deliberately remove data from your organization. Unfortunately, that’s exactly what happens quite often, and it’s part of the reason why 78% of security professionals say insiders are the biggest contributors to data misappropriation.

With your company’s IP making up 80% of its value, the potential damage from malicious insider threat is enormous. To help spot vulnerabilities, look for “Shadow IT,” the tools and solutions your employees use without explicit organizational approval that often pose measurable risks. Many tools that are unapproved by your IT department also place the data they’re accessing at risk and often there’s no overall management of these tools.

The Solution: Backup and Real-time Recovery
I have often said that there are only two types of networks in this world, those that have been breached and those that are being attacked. The fact is, security breaches occur to varying degrees of severity at all Fortune 500 companies. If a breach results in being denied access to your data, the C-Suite expects IT to get them back up and running. What they are just now learning is that this can be accomplished in mere minutes, or hours without overwhelming support staff! The solution to protecting your company from inside threats, ransomware, or any other cybersecurity issue is real-time recovery on the endpoints.

This is what the FBI has been urging businesses to do for years: regularly back up data and verify the integrity of those backups. It’s equally important to ensure that backed-up files aren’t susceptible to ransomware’s ability to infect multiple sources and backups. Consider these key points:

  1. When endpoints are infected by ransomware, real-time recovery can roll back clean versions of every file, including system files.
  2. While other solutions such as File Sync and Share (FSS) programs can import ransomware to its mirror mate (as they are designed to do), enterprise endpoint recovery solutions can roll back all files to earlier dates (versions) and restore them.
  3. When a device gets stolen or damaged for whatever reason, or when an employee leaves with valuable company data, real-time recovery can roll back each and every file on the device. This keeps the business operational and provides options relative to how they want to deal with the departed employee.

There are many tools on the market that claim to protect your data, and many indeed do a good job. But a sound cybersecurity policy begins within. You can’t protect your data if you don’t understand where it is and the threats you’re up against.

Rick Orloff, Chief Security Officer, Code42

[Palo Alto Networks Research Center]

The First 90 Days Brings Both Unintended Consequences and Opportunities for the Federal Workforce

During its first few weeks, the Trump administration issued several executive orders that left heads spinning, with many federal personnel unclear of the implications. One particular order that is causing significant anxiety among federal cybersecurity personnel – including thousands of (ISC)² members — is the hiring freeze. How is the freeze impacting our U.S. government member community and the government’s overall cyber progress?

After numerous conversations with federal cybersecurity leaders, one thing is clear – there is an abundance of unknowns and a unanimous sentiment of unpredictability. Yet, when outcomes are hard to predict, sometimes it helps to know that you are not alone. We can confirm that the current tone among federal cyber leaders is that of uncertainty, bordering on anxiety. So far, the unintended consequences of the freeze include a pause on recruitment efforts, withdrawal of current applicants, the exodus of younger entrants who see greater promise in private industry and an increase in early retirement for those with seniority. For those in the federal government who struggle daily in a short-staffed environment, morale is certainly taking a hit.

For our U.S. government members trying to navigate the implications of the hiring freeze, and other cyber-related orders on the immediate horizon, I want to encourage you to think short-term and be cautious to draw conclusions within the first 90 days of the new administration. One thing that I can say with certainty is that the (ISC)² organization is doing our part to drive awareness of the issues, and we stand dedicated to continuing such efforts. As for (ISC)²’s immediate goals, we will be focused on the following:

  • Helping our members navigate the uncertainties. We will be regularly polling cyber experts and posting the community’s reactions to any new happenings in an effort to shed light on potential impact to our members. To this end, we are encouraging you to provide comments and/or questions in the comment section below, so that we can be a resource of information to assist in whatever challenges arise.
  • Continuing our efforts to advocate for the workforce. We will be presenting a set of recommendations to the transition team in the coming weeks with the intention of helping to move forward federal cyber workforce initiatives. In prior years, the government heeded our call to hire a Federal CISO, and we will continue pushing for the same from this administration. We will make it known that it is a top priority to fill the void of practical leadership for those of you on the front lines.

Finally, I want to encourage conversation. As the world’s largest body of cybersecurity professionals, we have an opportunity to drive progress over the next four years. With the greatest minds in cyber, together we can help solve the complex and continuing challenges of securing our nation and the world around us. Now, more than ever, our collective voice needs to be heard.

Dan Waddell, CISSP, CAP, PMP
Regional Managing Director, North America Region, (ISC)²

[ (ISC)² Blog]

Resilience and Security Risk Management in the Future of the IoT

The IoT, or “Internet of Things” (everyday objects and systems that have connections to a network to provide data-sharing and virtual control), is a fast-growing arena of technology growth. The potential uses of the IoT to build a “smart world” of connected devices is enormously convenient and brings a whole new level of mobile management to every aspect of consumer and business activities. We are now able to start our cars from our phone, lock our front doors from our PC, or turn on the crockpot in our kitchen from a tablet in the office. Who knows what we will be able to do in the very near future?

Unfortunately, the IoT brings with it not just convenient access for users of the “things” on the IoT, but also convenient access for those wanting to exploit those things. More access points mean more places for attackers to get in. More remote control means more ability to hijack that control. All that leaves big problems for the organizations that design, build, and sell, or buy, implement, and use these products.  With HVAC systems, point of sale systems, communications systems, manufacturing lines – entire organizations, in fact – tied into the connected world, the IoT is opening increasing risk (security and operational) every day to businesses whose operations are more and more often tied into the network, whether they are making or using IoT devices.

Dealing with Risks on the IoT
The key to dealing with the changes in the security risk environment brought about by the ongoing evolution of the IoT is to focus, not on a detailed plan for any specific risks (which are ever-changing), but more on organizational resilience and risk-principle-based security management in general. The protection and continuation of business operations in the risk environment of the IoT goes beyond the scope of just information security. The risks associated with these networked devices transcend technology and reach deep into the realm of overall business resiliency and, as such, must involve stakeholders from across the business.

Organizational resilience enables enterprises to respond nimbly, pivot on a dime to change focus and alter activities, and keep fulfilling their mission no matter what is happening around them. It’s a philosophy that relies more on an attitude of preparedness – on understanding that a crisis is likely to occur no matter how many mitigation plans you put in place – than on hard-and-fast rules for responding to a crisis event.  Organizational resilience is a team approach that allows the risk managers and business leaders to work together in a partnership to ensure that critical functions can continue no matter what. It’s an outlook that enables a quick response to events that can quickly escalate – exactly the type of events we can expect when dealing with a fast-changing environment like the IoT.

Enterprise Security Risk Management (ESRM) is a security paradigm that is gaining significant traction in the security world and is a perfect response to the kinds of changing risk environments associated with the IoT. It’s a risk-based security management philosophy that is based on building partnerships across the business to manage security risk and to ensure that business leaders are making educated risk decisions for their assets and critical functions. ESRM embraces risk identification and mitigation while at the same time recognizing that businesses need to sometimes take risks to succeed. It enables business owners and security practitioners to work together to find the best solution for protecting the company while not stifling its ability to get the job done.

Using the two complementary philosophies of enterprise security risk management and organizational resilience, the business organization is in a better place to both protect itself from harm and embrace positive change due to uncertainty in the business environment. Resilience works both ways in an enterprise, to flexibly adapt to good or bad risk outcomes – both are highly possible when dealing with the IoT universe.

These philosophies drive all parts of the business to recognize and proactively deal with security risk, not simply put the responsibility solely on the technology or security department. ESRM is a security management system that any organization can take and adapt to its needs to build out a flexible and business-based program that will help it along the path to true organizational resilience, no matter what risks it is exposed to in the present or the future. Now is the time for security leaders to embrace these philosophies and strengthen the resilience of their enterprises, because the future of the IoT is already here.

Rachelle Loyear, CISM, MBCP, AFBCI, PMP, Partner, Security Risk Governance Group

[ISACA Now Blog]

English
Exit mobile version