As the fallout from the Capital One data breach continues, new lessons are being learned. Although technical failings were at the heart of the breach, a recent article in the The Wall Street Journal points to a series of overlooked issues that produced perfect storm conditions for the attack.
Notably, the Capital One hack did not come out of the blue. Before the breach, “…employees raised concerns within the company about what they saw as a high turnover in its cybersecurity unit and a failure to promptly install some software to help spot and defend against hacks.” The unit has also cycled through senior leaders and staffers, with about a third of its employees leaving in 2018 alone.
This kind of attrition is increasingly commonplace in security practices and has emerged as one of the biggest threats to corporate security. Studies show that, burnout and attrition in the security operations center (SOC) — often due to alert overload, long hours, and incomplete visibility into systems and threats — is contributing to a growing cybersecurity skills shortage. But, as the Capital One case proves, other factors are often at play.
Prior to the breach, Capital One “stood out among banks as a place where top technology talent wanted to work,” was generous with its cybersecurity funding, and had a game plan for anticipating hacks. Despite this, in recent years routine cybersecurity measures apparently began to fall by the wayside. Meanwhile the CISO, who came to Capital One from the public sector, clashed with employees, many of whom left for comparable jobs elsewhere.
With cybersecurity skills in high demand and companies ready to poach top-tier talent, poor leadership and a toxic culture can quickly lead to employee retention issues. Employees hold the upper hand; they can go wherever they like and name their price — and take their security expertise with them. That’s a risk that no company striving for top-tier cybersecurity can afford to take.
Great technology skills won’t solve cyber problems
The Capital One case shines a spotlight on a pervasive problem in security organizations — that people and cultural problems can compound cyber risk.
The role of a security leader carries enormous responsibility and requires expansive thinking that goes beyond the tactical nuts and bolts of IT. The most sought after CISOs aren’t just high technical performers (or, at least, they shouldn’t be). As security becomes more of a business and less of a technical function, leadership and management skills have become increasingly valuable attributes that aspiring CISOs need to develop as they look to advance their careers.