Table of Contents
List of Tables
- Chapter 2
- Chapter 3
- Chapter 4
- Chapter 5
- Chapter 7
- Chapter 10
- Chapter 11
List of Illustrations
- Chapter 1
- Chapter 2
- Chapter 3
- Chapter 4
- Chapter 5
- Chapter 6
- Chapter 7
- Chapter 8
- Chapter 11
Guide
Pages
The CISO Evolution
Business Knowledge for Cybersecurity Executives
MATTHEW K. SHARP
KYRIAKOS P. LAMBROS
Copyright 2022 by Matthew K. Sharp and Kyriakos P. Lambros. All rights reserved.
Published by John Wiley & Sons, Inc., Hoboken, New Jersey.
Published simultaneously in Canada.
No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, electronic, mechanical, photocopying, recording, scanning, or otherwise, except as permitted under Section 107 or 108 of the 1976 United States Copyright Act, without either the prior written permission of the Publisher, or authorization through payment of the appropriate per-copy fee to the Copyright Clearance Center, Inc., 222 Rosewood Drive, Danvers, MA 01923, (978) 750-8400, fax (978) 750-4470, or on the web at www.copyright.com. Requests to the Publisher for permission should be addressed to the Permissions Department, John Wiley & Sons, Inc., 111 River Street, Hoboken, NJ 07030, (201) 748-6011, fax (201) 748-6008, or online at http://www.wiley.com/go/permission.
Limit of Liability/Disclaimer of Warranty: While the publisher and author have used their best efforts in preparing this book, they make no representations or warranties with respect to the accuracy or completeness of the contents of this book and specifically disclaim any implied warranties of merchantability or fitness for a particular purpose. No warranty may be created or extended by sales representatives or written sales materials. The advice and strategies contained herein may not be suitable for your situation. You should consult with a professional where appropriate. Neither the publisher nor author shall be liable for any loss of profit or any other commercial damages, including but not limited to special, incidental, consequential, or other damages.
For general information on our other products and services or for technical support, please contact our Customer Care Department within the United States at (800) 762-2974, outside the United States at (317) 572-3993 or fax (317) 572-4002.
Wiley also publishes its books in a variety of electronic formats. Some content that appears in print may not be available in electronic formats. For more information about Wiley products, visit our web site at www.wiley.com.
Library of Congress Cataloging-in-Publication Data
Names: Sharp, Matthew K., author. | Lambros, Kyriakos P., author.
Title: The CISO evolution : business knowledge for cybersecurity executives/Matthew K. Sharp, Kyriakos P. Lambros. Description: Hoboken, New Jersey : Wiley, [2022] | Includes index.
Identifiers: LCCN 2021044404 (print) | LCCN 2021044405 (ebook) | ISBN 9781119782483 (hardback) | ISBN 9781119782506 (adobe pdf) | ISBN 9781119782490 (epub)
Subjects: LCSH: Chief information officers. | Computer security. | Management information systemsSecurity measures. Classification: LCC HD30.2 .S5325 2022 (print) | LCC HD30.2 (ebook) | DDC 658.4/038011dc23
LC record available at https://lccn.loc.gov/2021044404
LC ebook record available at https://lccn.loc.gov/2021044405
Cover Design: Wiley
Cover Image: Wahyu Hermawan and Mark John N. Madriaga of 99Designs
This book is dedicated to:
Matt's wife and son, Luz and Aleco
Rock's wife, Mary
They provided us with unlimited love and support in this journey.
Foreword
Welcome to an incredible period of change in cybersecurity what an amazing time to be in this field!
In the chapters that follow, two of the industry's leading critical thinkers divulge the skills and knowledge a cybersecurity leader must acquire to successfully build a modern-day cybersecurity program. To get the job done they combine personal stories, practical knowledge, and intimate case studies.
My colleagues Rock Lambros and Matthew Sharp will challenge us to think about cybersecurity on a new level. They encourage us to contemplate managing our cybersecurity programs differently, through a business lens. What's more, they offer us the tools to make that transition a reality.
With 40 years combined industry experience across many verticals, I'm confident you'll find the following pages rich with key insights about building, sustaining, and maintaining your cybersecurity program. I can't think of two more qualified practitioners to lead the charge in shaping how we must evolve our approach to aligning cybersecurity programs with business objectives.
Rock and Matt offer profound insights into how organizations should design, adapt, and embrace cybersecurity best practices to ensure business alignment. Gone are the days of selling your security program through Fear, Uncertainty, or Doubt (FUD). The era of digital business will require executive presence to claim your seat at the table.
The success that has brought you to your current role is a good start. I'd like to disrupt your assumptions and inspire a deliberate review of what you need to survive in the middle of the cybersecurity jungle. I would encourage you to consult this timeless, universally applicable reference in your journey forward.
The CISO Evolution: Business Knowledge for Cybersecurity Executives is not only your survival guide it's a blueprint for the aspiring cybersecurity leaders of tomorrow. The concepts in this book are proven through multiple industries. As life learners, Rock and Matt hope to ignite a spark in you; meanwhile, their courage coupled with their commitment to give back to our community was the driving force that led to this seminal work.
The only constant with our field is change, and the rate of change continues to intensify. If you think you've seen it all so far; I'm here to tell you we've not seen anything yet. The future holds boundless uncertainty!
How do we stay current? More importantly, how do we embrace this change while ensuring alignment with the business?
The answer is The CISO Evolution: Business Knowledge for Cybersecurity Executives.
As you read this book, please keep in mind that most businesses are trying to move at the speed of innovation. We need something radically different. Rock and Matt are the industry experts prying open a new door to an unexplored path that will make us think differently about our cybersecurity programs.
Demetrios Lazarikos (Laz)
3x CISO, 30+ Year Security Veteran
Business and Technical Advisor
Co-Founder, Blue Lava
Preface
To know and not to do, is really not to know.
Stephen R. Covey
Go to enough conferences, and a clear pattern emerges. A few industry leaders have the courage and presence to impart wisdom. Yet, most of the industry is an echo chamber of platitudes. Maybe you've heard a hollow statement from a so-called expert. These throwaway phrases reveal nothing, yet our colleagues masquerade behind them as thought leaders. The most insipid example, Speak to the business in business terms. For too long we have allowed one another to nod in agreement while behind the scenes we consistently fail to apply this wisdom and execute. This book provides a roadmap so that you can start asking the right questions, making the right investments, and delivering outcomes that matter.