In his talk “CISOs Talking SMAC (Social, Mobile, Analytics, Cloud)”, Jim Routh, CISO at Aetna recounted a lunch conversation that he shared with eight recently hired CISOs. Through the course of the lunch discussion, the CISOs ascertained the following three facts: 1) Each CISO was interviewed for their current position by the CEO, 2) they were all being very well compensated, and 3) the lowest amount of budget increase was double.
Routh’s lunch time anecdote makes it clear that the role of the CISO is evolving. The elevated importance of the CISO within the enterprise shows an increased enterprise awareness and focus on information security risk, but it also speaks to the new nature of the CISO’s role. Traditionally, the CISO was more a of a “back-office” manager focused on network and security operations. The role has evolved. The CISO is in many ways on par with other “C-level” executives. The new CISO is customer-facing and revenue-generating.
Security has been historically classified as a business expense with a very little calculable return on investment. Similar to insurance, companies would spend / invest in information security to avoid losses rather than to increase profits. According to the risk management executives at the summit, this philosophy is changing. Recent high-profile breaches have brought the potential consequences into stark relief (think the CEO of Target being fired). Organizations are realizing the consequences of poor performance, both within their own organization and within the organizations with which they share data and rely upon for critical business services. With increased scrutiny of 3rd party risk, companies are engaging with a potential business partner’s CISO. Effective risk management and detailed security plans are becoming selling points, making high performing information security a competitive differentiator.