The Circle of Cybersecurity
Ted recently wrote about the pain of rewarding performance with promotion and the purported death of the entry-level CS job. This got me thinking about the actual CS jobs that I have seen in the wild.When looking at actual CS jobs, size matters so we will start with that dimension.
Small Organizations
In very small organizations there isn't a Cybersecurity Program (CSP) so much as there is a guy or gal in IT who moonlights as The Person Who Keeps Us From Doing Dumb Stuff. This is a part-time Cybersecurity Engineer (CSE) even if they don't call it that. There is no formal communication channel between leadership and the valiant part-time CSE. The disaster-recovery aspect of the job is folded into the system administration duties.
Medium-Sized Organizations
In medium-sized organizations you have a CSP with a few people in it, mostly refugees from IT who Secure The Network. This is often a supervisor and two helpers who sort of communicate with senior management on an ad hoc basis. The disaster-recovery aspect of the job is still mostly a system administrator function.
Large Organizations
In larger organizations you have a CSP with a leader, one or more managers and three or more CSEs. The leader has a formal channel to the C-Suite if not a seat at that table. There should be a NIST CSF-level rigor to the CSP even if they don't use the NIST CSF. This is the level of operation that Pythia Cyber views as our main market.
Communication & Culture
In my long and idiosyncratic career I have worked at all three of these levels, sometimes working at the top and the bottom simultaneously as a consultant. In all the years of doing that I have been struck by the twin realizations that communication and culture play huge roles in how well a CSP protects the organization and that people don't really want to talk about that. Some leaders are instinctively good at these human behavioral factors and so they don't have to think about them. Some leaders are unaware that these factors are being handled by the managers and CSEs. Some leaders are vaguely aware that the CS people are weird and get pissed off sometimes about who-knows-what, but that's just life.
The Circle of Cybersecurity
This being a blog post I can't write endlessly about all the various permutations I have encountered and the various levels of utility that each permutation possessed. Instead I will write in a nice, short abstraction: the Circle of Cybersecurity.
Team Sport
The first point is that cybersecurity is a team sport. Some leaders feel that the CSP should be like a good janitorial service: invisible and something you only have to worry about if they screw up. This model is dying, thank God, but you still see it out there. The "circle" part of The Circle of Cybersecurity is that priorities flow from leaders to managers to be interpreted as action items by managers to CSEs but equally importantly, evidence of effectiveness flows upward from CSEs to managers to be interpreted as system status to leaders.
Different Skill Sets
Each role in this circle has its own separate and distinct requirements which is why it is such a bad idea to promote people as a reward for performance. There are unicorns: engineers who are great at interpretation and handling people, so you can promote them to manager without making a mess (assuming that you can replace them at the engineering level). There are managers who are great at the value judgments and strategic planning required of leaders, so you can promote them to leadership without risking disaster (assuming that you can replace them at the manager level). But most of the time promoting an excellent employee in order to reward them for their excellence is a lose-lose proposition: you lose them as excellent in their original role and you gain them as mediocre at best in their new role.
No Role Is An Island
The second point is that each level requires input from above or below in order to do their job. Leaders, contrary to popular lore, cannot sit alone atop the mountain and expound. Their vision has to be based on something. It is hard enough to make good decisions and future plans with good information. It is almost impossible to do with bad information.
Managers are in the middle: they must interpret in both directions. Nice, clear, simple directives from above--for example, "secure all network devices"--must be translated into procedures that can actually be followed, including all the boring edge cases that plague engineers but are invisible to leaders. Similarly detailed evidence of CSP activity has to be translated into terms that leaders have time to digest without the summary become distortion.
CSEs have the unenviable job of facing relentless opponents--entropy and cyberscriminals--and so bearing the burden of never slacking off and never taking their eye off the very tedious ball.
Promotion Isn't Always A Good Idea
The attributes which allow one to excel at each of these roles don't help much at any other level, so excellence at any specific level doesn't imply excellence at the next step along the promotion pipeline.
How We Can Help
What can you do about this? You can broaden and deepen your picture of your staff with one of Pythia Cyber's unique talent assessments. How likely is that CSE to make a good manager? We can give you a good idea of that. Would that manager be a good bet to promote to leadership? We can give you a good idea of that. Would this internal candidate be as good or better a fit for CSE than whatever their current job is? We can give you a good idea of that.
Would this outside candidate be a good fit for any of these roles? We can definitely help you with that.
Human factors are huge in cybersecurity. Data on human factors is almost non-existant. You already know how important it is to be data-driven in cybersecurity. You can help data on human factors.
Comments
Post a Comment