The Circle of Cybersecurity: Managers to CSEs

A recent post of mine, The Circle of Cybersecurity,  was a bit dense so I am expanding pieces of it in separate posts.

This post examines the second downward arrow, what flows from Managers Cybersecurity Engineers (CSEs), the folks on the front lines. That arrow is labelled "Procedures" but that is a bit of shorthand for the many related kinds of information that travel that path.

In this post we are focusing on large organizations with a Cybersecurity Program (CSP) run by a dedicated staff. We assume that any such organization has a rigorous CSP, based on some formalized principles such as the NIST CSF.

Procedures

In theory all you need for your CSP is for procedures to be transmitted from Managers to CSEs. In practice, this is where the rubber meets the road. To stretch the analogy, this is where the tires of your Policies meet the road debris of previous decisions, the potholes of cyberattacks, the ice of accidents and the oil slicks of negligence. And, of course, the imperfect imaginations of whoever translated the policies into procedures in the first place.

So abandon all hope that the Manger / CSE relationship is like that of a manufacturing plant manager and assembly line worker. Sometimes things go that smoothly. Often they do not. 

Exceptions

When you hit the road debris, the potholes, the ice and oil slicks there are going to be questions that the procedures don't perfectly address. There are going to be communications which are not required but which are a good idea. There are going to be occasional instances where co-ordination is required. If your managers don't have that kind of relationship with their reports then you are going to wish that they did. The commitment has to be to the goal of cybersecurity, not the strict adherence to the procedure. You want your CSEs to follow procedure, yes, but you really want them to warn you about possible issues with doing that.

Communication & Culture

Cybersecurity cannot escape issues of communication and organizational behavior because cybersecurity rests largely on human beings and their daily decisions and actions. Managers need to foster an environment in which CSEs feel comfortable voicing concerns and making observations. It cannot be chaos, your CSEs can't feel free to do whatever they like, but having automatons mindlessly execute your procedures means that your procedures have to be perfect. That is...unlikely.

Ensuring that your managers are well-equipped to do the interpersonal aspects of their part in your CSP is hard. We can help. Ask us how.

Comments