The Cyber Security Review | Monday, January 02, 2023
AI and machine learning improve security while posing new challenges.
Fremont, CA: As the threat landscape evolves, so does the function of CISO (chief information security officer). Rather than having the greatest technical expertise, the capacity to be powerful leaders is critical to any CISO's success. When developing cybersecurity trends, having a high-performing staff surpasses having a detailed understanding of the current malware.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The emerging cybersecurity challenges stem from certain well-known sources. However, how the CISO responds to them should take a creative approach.
CISOs have been monitoring AI and machine learning as cybersecurity tools. There are several advantages to deploying them: upgrades that a CISO may use to showcase the benefits. However, there is a downside. Cybercriminals may also use these technologies to collect data, send realistic phishing emails, conceal malware, crack passwords, and distribute ransomware.
It may get used for good or harm, just like everything else. As a CISO, the response should contain the human element. AI vs. AI is a toss-up, but AI plus human knowledge allows a company to employ it more strategically. One cannot dwell on the bad, but users must know its implications.
• Shifting To Zero Trust Architecture
CISOs have been vocal supporters of zero-trust architecture, praising its "never trust, always verify" tenet. This is a strategy for modern organizations to streamline their architecture, and that may appear concerning to security-conscious individuals at first. In the world of cybersecurity, it does not imply inferiority.
The truth is that zero trust works and allows for more visibility and control over users and traffic in an environment. As CISO, the most important responsibility is to lead the way in embracing change. First, users will need to rally their troops, and they may object because it is novel and different from what they have been doing.
• Recruiting And Retaining Technical Talent
Cybersecurity has a challenge with recruiting and retention. The scarcity of candidates reflects the larger picture in hiring: low unemployment, a desire for more meaningful work, a refusal to work in toxic conditions, and career transfers due to the Great Resignation.
This may be the primary worry as a CISO. Different approaches should get taken to increase recruitment and retention. For example, only emphasize certificates if they are widely regarded. Instead, look for employees with the necessary talents since they can learn technology and develop their competencies in this area. An adaptive, communicative, and inquiring recruit is far more helpful than someone who is set in their ways with a stack of qualifications. Interviews should get treated as discussions, candidates should suit the culture, and no one should get hired out of desperation.
More in News