A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Sanne Group (SNN: LON)

The Importance Of Scrutinizing Established Processes

How has your journey been as an industry leader?

I'm the Group Head of Information Security for Sanne Group, which is a FTSE 250 alternative asset manager and fund administrator. We manage about 500 billion dollars in assets. We are in the process of merging with Apex Group. Together, we'll be the world's largest fund administrator with 2.3 trillion of assets.

In terms of my career trajectory, I started off as a self-taught policy writer. My published papers got picked up first by the United Nations, which I went out to delegate for. Subsequently, I went to work as a cyber-advisor at the Ministry of Defense. I also worked at the Cabinet Office and a few other places in Whitehall. After various policy jobs there, I moved into research, which had a really significant impact on my approach to information security.

Whilst I was there, I helped design a threat intelligence technology for the industry. I was also involved in developing and publishing the UK's first framework for quantitatively modeling cyber risk. That's probably been the biggest part of my career in the last five years and something that I am a passionate advocate for, which I drive in every aspect of information security work that I do.

“Surround yourself with people who challenge the norm, like I try to do. We should try and come up with a methodology that delivers value “

After leaving research, I went to work for State Street and it was about 10 months ago that I moved to Sanne Group. Very briefly when I joined Sanne, it was a brownfield site that had a comprehensive security toolset but it wasn't really a defined function. I was brought in to develop a five year strategy to build that function out. I now look after an internal security operation center along with technology risk management and am very closely aligned with the risk management and control architecture programs as well.

I didn't have a very conventional path in cyber security but I think that's only been a benefit.

What would you say are some of the trends or the changes that have come about in the industry and how can a particular organization or individual best cope with these changing times or the trends that you've observed?

In the decade that I've been working in information security, there have been various changes across people, process, and technology. The biggest change in technology is perhaps the adoption of cloud infrastructure. The fact that it exists now for organizations, but didn't really exist at the time when I started out, is a good way of seeing change in a paradigm shift from all aspects of people, process, and technology. My view is that information security exists solely to enable the business to achieve its objective. If a business wants to move to the cloud or wants to adopt a new way of work, our job is to make sure there are no blockers. Being able to work out that strategy of the business for cloud adoption brings a huge boost to them.

Interestingly, ‘people’ would be the last strand of how that's changed. It segues onto your next point in that there's been a huge shift in terms of the skillset that’s sought. When I started, I had no certification or any prior experience in cybersecurity. That has been beneficial because I got to start understanding the question of ‘why are we doing this?’ then understanding what should be done and deliver. This kind of structure and my unusual experience around my career has enabled me to focus on particular skills and attributes that were well outside of the information security paradigm and arena previously.

Neuro-cognitive diversity is absolutely fundamental to my approach to hiring a skilled staff. It ties closely to a well-known trope that's spotted out a lot in this industry – skill shortage. The reality is that we just haven't focused on the right skills. Hiring from different industry backgrounds and various diverse careers enriches the profession. It challenges the well-known concepts and methodologies and places them under fresh scrutiny.

Over the last 10 years, that encroaching shift to opening up a whole new set of technologies, processes, behaviors, and skills has been significant. Cloud's been one of the biggest wholesale drivers of that change.

When trying to cope with the ever-evolving processes in the industry, what would you say are some of the roadblocks that arise? And, how can you identify the right kind of partner to walk you through or navigate these issues or challenges?

The biggest blocker or inhibitor to people being able to adeptly tackle the challenges is measurement. In information security, so many of the approaches whether it is control frameworks, technologies used or established processes have remained static for a very long time.

This is a good example where thinking outside the box or leveraging other skills is incredibly valuable. When I designed the framework for quantitative modeling in information risk, it was the biggest step change as it enabled me to learn the practices that are used day to day in operational risk, health and safety, oil and gas, among several other industries and risk profiles.

95 percent of the time, most of an organization’s loss exposure is derived from people making mistakes, user error, misconfiguration, which fall under the very basic accidental threats within the organization. That is what's causing the business to lose money. Whereas information security, because it doesn't use a framework to measure loss in that way, it avoids that issue. But then you have to ask yourself, “Why do we even bother with risk management, if we aren't trying to earn back our losing money?” It becomes an exercise of selfvolley. We're doing it for its own sake.

 That methodological, psychological process-driven barrier to adopting a more effective approach and measuring the single biggest blocker I think is causing people to redirect the security effort to investments area.

For your peers in the marketplace today, or somebody who's looking to venture in the same arena like yourself, what is that one piece of advice that you'd like to give them?

There is a great phrase in the military, “Ask yourself so often, ‘why do I care?’” There's so much established thought and thinking in information security that so many of the fundamental principles that we operate by are never challenged. That is the biggest thing, the selfscrutiny. Surround yourself with people who challenge the norm, like I try to do. We should try and come up with a methodology that delivers value.

In the 12 principles of battle in the UK military doctorate, there is a brilliant principle of battle called the Economy of Effort, which goes, “If there’s a quicker and easy way of doing something, do it.” Information security is terrible, culturally and historically, at looking at the most effective way to doing things, and simply accepts that those are the ways of doing things because of the various challenges. But having that scrutiny is so important. It would really help the information security functions, and also help understand where value is actually being driven.

Being able to scrutinize established processes and measure the value and the efficacy of what you are doing in information security, is an area that's not given any attention. Yet it's the area that I think would yield the greatest value in terms of where people will get the biggest bang for their buck when they invest in certain security initiatives.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
Top