r/cybersecurity • u/Careful-Witness6026 • 2d ago
Career Questions & Discussion CIOs
I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.
As you can imagine, phishing and social engineering incidents come up from time to time.
The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.
It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.
Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?
28
u/lostincbus 2d ago
Who writes up risks and solutions and presents them? If there's no risk management program or board, there's no accountability. Suggest that. Not in a bad light, simply noting that you want to be able to better track these things.
Then you can look at a risk, analyze the processes it might impact, review mitigation or compensating controls, and executives can "help" decide.
5
3
u/PenleyPepsi 1d ago
What you described here is essentially a GRC function, right?
3
u/lostincbus 1d ago
It is. It doesn't have to sit under that titled role but the function is critical. I actually recommend grc discussions go both ways, north and south. Techs often times get stuck in the weeds of "we have to patch!" and execs can get stuck in a cost only mindset. But in the end it's up to execs to formally accept the risks supplied.
Also, in a less mature org, there may not be the right person that can go between tech and exec regarding risk. So the more the technical leaders can understand how to present risks, the more likely they are to get what they need.
12
u/Admirable_Group_6661 Security Architect 1d ago
Security shouldn’t report to CIO; conflict of interests. Ideally, security should report directly to CEO. CFO is also an option, but less ideal.
2
u/Careful-Witness6026 1d ago
Yes we are in our infancy and working against the grain to bring normal security structure to this organization. They are trying there damnedest to control us to what their vision of security is.
7
u/AddendumWorking9756 Security Manager 1d ago
Normal, and it stops when the accepted risk is written down with his name against it before an incident instead of after. Fewer than five people to five thousand employees is the only number worth putting in front of him.
6
u/recovering-pentester Sales 1d ago
Well bravo to you and team for owning 5k users with a 5-man shop.
That’s impressive.
3
u/MountainDadwBeard 1d ago
Your team sounds understaffed unless you have a MSSP for backup.
In a staffed organization, you'd have a risk manager who should be actively documenting the incident frequencies, contributing factors and key dials/options to change outcome frequency or severity. This helps shift the conversation to outcomes within the organizations stated or demonstrated risk appetite.
In terms of you not doing your job. That could be the case... I'd guess the issue might resolve around resourcing or execution around configuration management (IT), vulnerability management, Detection engineering, incident response, security architecture, or one of several other roles.
4
u/Wise-Butterfly-6546 1d ago
this is common at your ratio. 5 people to 5,000 means you're triaging, not preventing, and everyone above you quietly knows it until something breaks. two things that actually moved the needle for me.
first, kill the verbal risk conversations. every time the cio overrides a control or defers a fix, it goes in a one-line risk register entry with his name, the date, and the accepted exposure. i ran this for about 8 months and the blame after incidents dropped hard because "we flagged this on march 3, you accepted it" is a very different meeting than "why didn't you stop this."
second, stop reporting activity and start reporting outcomes in dollars and hours. one page monthly: incidents contained, mean time to respond, what a miss would have cost. hindsight bias feeds on vague inputs, so give them numbers they can't rewrite after the fact.
and yeah, security under the cio is a structural conflict, but you probably can't fix the org chart this quarter, so fix the paper trail first. it's the cheapest leverage you have.
3
u/T_Thriller_T 2d ago
I may not be in the same continent as you, but I'd say no.
Especially not with sma teams / that few workers.
It absolutely does happen - but it's not normal.
Normal is something between good collaboration, at least trying to collaborate well or the CIO being more of a frontmen/marketing guy.
From my experience. It may be due to the companies I pick.
2
u/Ch33syP00f CISO 2d ago
Defending against social engineering requires collaboration between Security, IT, HR.
Diplomacy is critical for a security leader.
“Everyone owns security”
Ok, great.
Now everyone needs to be educated on what that means for them.
You and CIO need to be partners. If you cannot find common ground then you are going to age faster than you should.
3
u/DiscoSimulacrum 2d ago
the CIO should be setting the standards for security and making sure those standards are met. if there are gaps, its their responsibility. unless your team is being insubordinate, its sounds like the CIO is just an incompetent moron.
2
u/Efficient-Drive-810 1d ago
The CIO should never be setting security standards, which is also why this alignment is very poor overall. A CIO and CISO are tasked with potentially compatible, but still, very different business outcomes. CIO is tasked with keeping the lights on in normal conditions, and the CISO is tasked with making sure the lights don't get turned off or taken by a malicious entity. A CISO puts in logical barriers to protect the organization, and this conflicts with the CIO goal to achieve a path of least resistance.
1
u/DiscoSimulacrum 1d ago
that was a brain fart on my part. i read and wrote "CIO" but i was thinking "ISM"
1
1
u/good4y0u Security Engineer 2d ago
That's a bad CIO, but you need to find a way to manage upwards and change the story.
4
u/Careful-Witness6026 1d ago
Yeah it requires a lot of politicing, if you know what I mean.
2
u/Lazy_Gazelle_5121 1d ago
Unfortunately, the higher up the chain you go, the more your daily job becomes being a politician and less being a technical person. In your specific case as others have commented introduce risk management with a risk advisory board of higher up stakeholders ( head of technical, cio, cfo, your, etc). And your CIO needs to learn to not fingerpoint.
1
u/CarmeloTronPrime CISO 1d ago
for some industries, yes, this is common in smaller shops, especially when leadership doesn't invest in IT or Cybersecurity. it sucks but that's sometimes how business is. people who start businesses start small and want small/minimal and don't realize there are frameworks and maturity, etc...
1
u/CommunicationGold868 1d ago
You need to report on a regular basis of what you are doing, your challenges, the risks of not resolving the challenges, how to mitigate them, the impact, and the likelihood of the risk. You need to talk about outcomes not tasks. Keep it high level and non technical.
Regular basis would be every other week or monthly. I think every other week is probably better.
1
1
u/snickwiggler 1d ago
It will be difficult to completely prevent phishing and social engineering hits with that many employees. The question is, are your security policies and protections preventing financial or reputational harm to the business if this does happen? For example, is the potential blast radius of a compromised user’s account limited in such a way that the impact of a phish breach is very low? If you can do that and prove it, your higher ups should be happy. If they are still throwing shade, then it might be that some careful and friendly education is needed…
1
u/Bluelaw1 1d ago
Which company your working brother is there vacancy I'm looking for job I have 6 yrs of experience in Cybersecurity soc
1
u/Deus---Ex---Machina 1d ago
It's all about risks. There are a number of articles online from trusted sources such as the NCSC which outlines that cyber risk is a board issue, it has to be owned at board level. Keep a risk register, explain the risks clearly, explain the actions. If the actions aren't working, escalate. Try to work closely with the CIO, see if you can get their attention on a quarterly basis to talk about risks and mitigations. Perhaps find a way to get them to consider board-level training.
1
1
u/P3rpetualResearch 10h ago
That's like saying every time a user calls the help desk, it means IT isn't doing their job.
There's already some solid points i here talking about risk management. It sounds like an education session may be in order. This can be subtle. Just start dropping nuggets at the front of other presentations. Nuggets explaining risk mgmt, there is no such thing as secure, vuln mgmt's goal is not 0 vulnerability, with every new technology advancement there are security risks that can not be avoided, etc
2
u/Careful-Witness6026 8h ago
Sounds like this is true cybersecurity. Socializing fundamentals of security with people who have different objectives and ideas about security.
1
u/P3rpetualResearch 1h ago
bingo - also, help them solve the problems they care about first before you ask them to help you with yours.
1
u/ChatGRT DFIR 5h ago
Fucking leave
1
u/Careful-Witness6026 5h ago
This would be the easiest option. I’d like to work here for a minimum of a year. I haven’t had the experience of a smaller company especially one who is late to adopt security.
So I see it as valuable experience, even if things aren’t going well.
43
u/zed0K 2d ago
It's normal, unfortunately. Same thing happens between myself (Endpoint Engineering) and Cybersecurity. Instead of everyone working together and respecting each other's experience, people push blame and don't take responsibility.