What is Leadership?

Join Us Now

Leadership. Itโ€™s a misunderstood word. In corporations all over the world, people use the term to connote a certain job title, like โ€œCISOโ€ or โ€œCTOโ€ or โ€œCEO.โ€ We see it all over company websites: About Us: Leadership Team. 

But the anointment of a title does not equal leadership. In truth, one of the main problems with the word โ€œleadershipโ€ is that it implies a certain set of skills or personal attributes, yet I would bet everyone reading this short rant knows of some person who has risen through the ranks to a โ€œleadershipโ€ position without the possession of any leadership skills whatsoever. After nearly three decades as a codified discipline, cyber security practitioners still talk about how CISOs typically come into the roleโ€”that is, some very technically skilled practitioner takes on more and more responsibility until he/she/they are the security expert in the company. As the resident expert, they are promoted to a VP or C-level position and are deemed a โ€œleader,โ€ someone who may even have a proverbial โ€œseat at the table,โ€ who reports into boards, and has numbers of employees working for them. 

Too often, though, these same people have received no leadership, never mind basic management, training. Their acquiredโ€”and very valuable skillsโ€”are focused on security and technology. But the lack of experience with and training in leadership can be detrimental to the organization. 

Cyber security is a business risk. Straight up, no chaser. It has become a critical business risk which can impact the productivity of entire organizations, jeopardize peopleโ€™s identities, and cost companies significant ARR. In more extreme situations, cyber security risk threatens lives.  

This is not meant to be hyperbolic, but we are seeing in real life how lack of leadership costs lives. 

While people are not dying every day from a data breach of PII, the impacts of such a breach are significant. At present. weโ€™re watching a former CISO face potential jailtime and half a million dollars in fines for allegedly covering up a breach and failing to report the breach properly. This is not playtime. 

And as such, we need leaders in security. We need people who are more than technicians. One hundred percent we need experts who can reverse engineer malware, analyze packets, and properly implement encryption/access controls/pick-your-functional-area-of-interest. But we need leaders who learn, understand, and practice communication skills. We need leaders who learn, understand, and practice empathy. We need leaders who do whatโ€™s right rather than whatโ€™s popular or that which gains them speaking invitations. We need leaders who can make tough calls when a security incident is in question, but who can execute with humility and respect. 

These are the so-called โ€œsoft skills,โ€ yet I posit that this is a misnomer. These โ€œsoft skillsโ€ are, in fact, extremely hard to acquire. And it takes training and practice and the ability to look outside oneself. A true leader isnโ€™t someone who seeks glory and tries to be a hero. How far will that get you in the aftermath of a breach? A true leader doesnโ€™t conceal information to save face, because theyโ€™re afraid of repercussions, or because they want to orchestrate the response at a personal level rather than doing whatโ€™s right.  

Being a leader is hard work, and in security, covering up information or holding back information about vulnerabilities or exploits has substantive impacts on peopleโ€™s lives. Perhaps not in the same way as Covid-19, but without a doubt cyber breaches of confidentiality, availability, and integrity have downstream effects on peopleโ€™s abilities to work, earn money, obtain credit to rent or buy a home, take out a loan to attend college, and many other real-life situations. 

So if youโ€™re a CISO or want to be a CISO, I implore you to work just as hard on becoming a better listener, better communicator, and better conduit for empowering those around you. These are just some of the attributes that make the best leadersโ€”and we have some great examples in the security community! But do not, for one second, think that a title makes you a leader. Your actions can harm people and threaten their livelihood; it is leadersโ€™ responsibilities to be truthful and to make difficult decisions, but do it with an understanding that the role is in service of a larger pictureโ€”one that dwarfs whether you left your RDP exposed to the internet or didnโ€™t encrypt your customersโ€™ credit card information.  

Join Us
Register to join our Executive Leadership Network & Newsletter.








Powered by
Verified by MonsterInsights