{"id":48982,"date":"2014-07-28T00:00:00","date_gmt":"2014-07-28T00:00:00","guid":{"rendered":"https:\/\/www.techopedia.com\/cisos-why-companies-need-them-more-than-ever\/"},"modified":"2014-07-28T13:18:23","modified_gmt":"2014-07-28T13:18:23","slug":"cisos-why-companies-need-them-more-than-ever","status":"publish","type":"post","link":"https:\/\/www.techopedia.com\/2\/30507\/it-business\/it-careers\/cisos-why-companies-need-them-more-than-ever","title":{"rendered":"CISOs: Why Companies Need Them More Than Ever"},"content":{"rendered":"
Businesses are being targeted by cyberattacks<\/a> at an alarming rate. Major breaches at Target in December 2013 and Neiman Marcus in January of 2014 shined a great big spotlight on the inadequacies that a lot of retail outlets have in their security infrastructure. As a result, more and more companies, both big and small, are feeling the need to ramp up their efforts and have a dedicated security team.<\/p>\n According to a report released by Reuters in May 2014<\/a>, a number of large corporations, such as Pepsi and JPMorgan Chase & Co., are on the hunt for new chief information security officers<\/a> (CISOs) in a bid to bolster security practices. What this reflects is a greater awareness of security and its importance at business’s executive level.<\/p>\n CISOs, and chief cybersecurity officers, are immersed in the security of their technology, both for employer and client, but their roles and responsibilities are becoming more pronounced and imperative in the eyes of the general public, not just among the security community.<\/p>\n "Five years ago, information security<\/a> barely cracked the top 10 concerns of boards. A year ago, it was No.2. Interestingly it\u2019s now data security<\/a> and not just information security," says David Boehmer, regional managing partner at recruitment firm Heidrick & Struggles, in a YouTube video produced by the company<\/a>.) <\/p>\n The role of a CISO can be quite broad, and they often find themselves wearing many different hats. The job involves everything from internal security, such as managing the security of intellectual property, to being responsible for customer security. <\/p>\n "I also do work with our product team and engineering team to implement features in the product that might be interesting to security buyers," says Joan Pepin, a CISO at Sumo Logic.<\/p>\n While the Target breach last year certainly got a lot of people talking, Pepin explains that she wasn\u2019t all that surprised – and neither was most of the security community. That\u2019s not to say the security community hasn\u2019t had its "watershed moments" though, where everyone needed to reinforce their work moving forward.<\/p>\n The RSA breach in 2011<\/a>, in which hackers breached the information security company’s servers and stole authentication tokens that provided access to sensitive government and corporate data, had many security professionals abuzz. How could a security company fall prey to hackers like that? Only two years later, that concern would shift to a target that had previously flown under the radar: retail customers. Attacks like those seen at Target and Neiman Marcus shifted attention to security for the everyday customer.<\/p>\n "Clearly when you have a massive retail operation with thousands and thousands of employees, all of these different sites, point-of-sale machines, that is the very poorest kind of system and the fact that those types of attacks did not happen on that type of scale sooner is actually bit of a surprise to me," Pepin said.<\/p>\n The issue stems from security being seen as simply a check box for companies to tick and leave be rather than a constantly policed aspect of their business. This doesn\u2019t mean that cybercriminals<\/a> are lax and can just walk in. In fact, cybercriminals are becoming increasingly skilled.<\/p>\n "[Target] was a pretty sophisticated breach, [the attackers were] able to impersonate the BMC agent, and those types of stealthy things. To engage in lateral movements throughout the Target network was pretty clever, Pepin said. <\/p>\n "I don\u2019t want to take away from that but in terms of difficulty in target, no pun intended, I would never place any retail chain on a list of hard targets. Security companies are hard targets, the government is a hard target. Some retail chain whose business is selling socks, I wouldn\u2019t expect them to be a super secure shop." <\/p>\n In June 2014, Target hired its first CISO, Brad Maiorino, a former General Motors executive who will be overseeing an overhaul of the company\u2019s security practices.<\/p>\n Businesses, regardless of their field or their size, will need to take note and enhance their security game in response to ever-growing threats with greater awareness and more authority to act on potential breaches. <\/p>\n "It was clear … in the Target case that alerts were generated that no one responded to and that, in my experience coming from managed security, is extremely typical, Pepin said.<\/p>\nWhat a CISO Does<\/span><\/h2>\n
The Landscape for Security Professionals<\/span><\/h2>\n