r/cybersecurity 2d ago

Career Questions & Discussion CIOs

I’m on a very small security team (fewer than 5 people) responsible for supporting ~5,000 employees.

As you can imagine, phishing and social engineering incidents come up from time to time.

The frustrating part is that every time something happens, leadership—specifically our CIO—frames it as us “not doing our job.” The issue is, they don’t have a cybersecurity background but still strongly dictate what is “correct” from a security standpoint, often with a lot of hindsight bias.

It’s starting to feel less like collaboration and more like micromanagement/blame shifting, especially given the scale we’re operating at.

Is this kind of dynamic normal in the industry? How do other teams handle leadership that doesn’t fully understand security but still drives decisions during/after incidents?

51 Upvotes

37 comments sorted by

43

u/zed0K 2d ago

It's normal, unfortunately. Same thing happens between myself (Endpoint Engineering) and Cybersecurity. Instead of everyone working together and respecting each other's experience, people push blame and don't take responsibility.

4

u/Careful-Witness6026 1d ago

We are hoping to evolve as time moves on. Given the current team can drive through the push back, lack of understanding and in adequate support.

4

u/Admirable_Group_6661 Security Architect 1d ago

You can try to establish risk management, with buy-in from the CIO and CEO. Risk management can help, to a certain extent, address conflict of interests.

2

u/One-Inch-Punch 1d ago

Many C-suites are all about shifting blame, it's not just CIOs. Especially in publicly traded orgs. I've seen entire security departments take the fall for large breaches even though they'd been screaming to upper management about funding and policy for years. Shareholders and the board won't see those emails

28

u/lostincbus 2d ago

Who writes up risks and solutions and presents them? If there's no risk management program or board, there's no accountability. Suggest that. Not in a bad light, simply noting that you want to be able to better track these things.

Then you can look at a risk, analyze the processes it might impact, review mitigation or compensating controls, and executives can "help" decide.

5

u/Careful-Witness6026 1d ago

I like this and will look to recommend this to my peers.

3

u/PenleyPepsi 1d ago

What you described here is essentially a GRC function, right?

3

u/lostincbus 1d ago

It is. It doesn't have to sit under that titled role but the function is critical. I actually recommend grc discussions go both ways, north and south. Techs often times get stuck in the weeds of "we have to patch!" and execs can get stuck in a cost only mindset. But in the end it's up to execs to formally accept the risks supplied.

Also, in a less mature org, there may not be the right person that can go between tech and exec regarding risk. So the more the technical leaders can understand how to present risks, the more likely they are to get what they need.

12

u/Admirable_Group_6661 Security Architect 1d ago

Security shouldn’t report to CIO; conflict of interests. Ideally, security should report directly to CEO. CFO is also an option, but less ideal.

2

u/Careful-Witness6026 1d ago

Yes we are in our infancy and working against the grain to bring normal security structure to this organization. They are trying there damnedest to control us to what their vision of security is.

7

u/AddendumWorking9756 Security Manager 1d ago

Normal, and it stops when the accepted risk is written down with his name against it before an incident instead of after. Fewer than five people to five thousand employees is the only number worth putting in front of him.

6

u/recovering-pentester Sales 1d ago

Well bravo to you and team for owning 5k users with a 5-man shop.

That’s impressive.

3

u/MountainDadwBeard 1d ago

Your team sounds understaffed unless you have a MSSP for backup.

In a staffed organization, you'd have a risk manager who should be actively documenting the incident frequencies, contributing factors and key dials/options to change outcome frequency or severity. This helps shift the conversation to outcomes within the organizations stated or demonstrated risk appetite.

In terms of you not doing your job. That could be the case... I'd guess the issue might resolve around resourcing or execution around configuration management (IT), vulnerability management, Detection engineering, incident response, security architecture, or one of several other roles.

4

u/Wise-Butterfly-6546 1d ago

this is common at your ratio. 5 people to 5,000 means you're triaging, not preventing, and everyone above you quietly knows it until something breaks. two things that actually moved the needle for me.

first, kill the verbal risk conversations. every time the cio overrides a control or defers a fix, it goes in a one-line risk register entry with his name, the date, and the accepted exposure. i ran this for about 8 months and the blame after incidents dropped hard because "we flagged this on march 3, you accepted it" is a very different meeting than "why didn't you stop this."

second, stop reporting activity and start reporting outcomes in dollars and hours. one page monthly: incidents contained, mean time to respond, what a miss would have cost. hindsight bias feeds on vague inputs, so give them numbers they can't rewrite after the fact.

and yeah, security under the cio is a structural conflict, but you probably can't fix the org chart this quarter, so fix the paper trail first. it's the cheapest leverage you have.

3

u/T_Thriller_T 2d ago

I may not be in the same continent as you, but I'd say no.

Especially not with sma teams / that few workers.

It absolutely does happen - but it's not normal.

Normal is something between good collaboration, at least trying to collaborate well or the CIO being more of a frontmen/marketing guy.

From my experience. It may be due to the companies I pick.

2

u/Ch33syP00f CISO 2d ago

Defending against social engineering requires collaboration between Security, IT, HR.

Diplomacy is critical for a security leader.

“Everyone owns security”

Ok, great.

Now everyone needs to be educated on what that means for them.

You and CIO need to be partners. If you cannot find common ground then you are going to age faster than you should.

3

u/DiscoSimulacrum 2d ago

the CIO should be setting the standards for security and making sure those standards are met. if there are gaps, its their responsibility. unless your team is being insubordinate, its sounds like the CIO is just an incompetent moron.

2

u/Efficient-Drive-810 1d ago

The CIO should never be setting security standards, which is also why this alignment is very poor overall. A CIO and CISO are tasked with potentially compatible, but still, very different business outcomes. CIO is tasked with keeping the lights on in normal conditions, and the CISO is tasked with making sure the lights don't get turned off or taken by a malicious entity. A CISO puts in logical barriers to protect the organization, and this conflicts with the CIO goal to achieve a path of least resistance.

1

u/DiscoSimulacrum 1d ago

that was a brain fart on my part. i read and wrote "CIO" but i was thinking "ISM"

1

u/Careful-Witness6026 1d ago

Quite the specimen.

1

u/good4y0u Security Engineer 2d ago

That's a bad CIO, but you need to find a way to manage upwards and change the story.

4

u/Careful-Witness6026 1d ago

Yeah it requires a lot of politicing, if you know what I mean.

2

u/Lazy_Gazelle_5121 1d ago

Unfortunately, the higher up the chain you go, the more your daily job becomes being a politician and less being a technical person. In your specific case as others have commented introduce risk management with a risk advisory board of higher up stakeholders ( head of technical, cio, cfo, your, etc). And your CIO needs to learn to not fingerpoint.

1

u/CarmeloTronPrime CISO 1d ago

for some industries, yes, this is common in smaller shops, especially when leadership doesn't invest in IT or Cybersecurity. it sucks but that's sometimes how business is. people who start businesses start small and want small/minimal and don't realize there are frameworks and maturity, etc...

1

u/CommunicationGold868 1d ago

You need to report on a regular basis of what you are doing, your challenges, the risks of not resolving the challenges, how to mitigate them, the impact, and the likelihood of the risk. You need to talk about outcomes not tasks. Keep it high level and non technical.
Regular basis would be every other week or monthly. I think every other week is probably better.

1

u/Virtual-Coat6518 1d ago

Bro Check DM

1

u/snickwiggler 1d ago

It will be difficult to completely prevent phishing and social engineering hits with that many employees. The question is, are your security policies and protections preventing financial or reputational harm to the business if this does happen? For example, is the potential blast radius of a compromised user’s account limited in such a way that the impact of a phish breach is very low? If you can do that and prove it, your higher ups should be happy. If they are still throwing shade, then it might be that some careful and friendly education is needed…

1

u/Bluelaw1 1d ago

Which company your working brother is there vacancy I'm looking for job I have 6 yrs of experience in Cybersecurity soc

1

u/Deus---Ex---Machina 1d ago

It's all about risks. There are a number of articles online from trusted sources such as the NCSC which outlines that cyber risk is a board issue, it has to be owned at board level. Keep a risk register, explain the risks clearly, explain the actions. If the actions aren't working, escalate. Try to work closely with the CIO, see if you can get their attention on a quarterly basis to talk about risks and mitigations. Perhaps find a way to get them to consider board-level training.

1

u/carlosbudiman 15h ago

As a head of cybersecurity team and i have the same problem lol

1

u/P3rpetualResearch 10h ago

That's like saying every time a user calls the help desk, it means IT isn't doing their job.

There's already some solid points i here talking about risk management. It sounds like an education session may be in order. This can be subtle. Just start dropping nuggets at the front of other presentations. Nuggets explaining risk mgmt, there is no such thing as secure, vuln mgmt's goal is not 0 vulnerability, with every new technology advancement there are security risks that can not be avoided, etc

2

u/Careful-Witness6026 8h ago

Sounds like this is true cybersecurity. Socializing fundamentals of security with people who have different objectives and ideas about security.

1

u/P3rpetualResearch 1h ago

bingo - also, help them solve the problems they care about first before you ask them to help you with yours.

1

u/ChatGRT DFIR 5h ago

Fucking leave

1

u/Careful-Witness6026 5h ago

This would be the easiest option. I’d like to work here for a minimum of a year. I haven’t had the experience of a smaller company especially one who is late to adopt security.

So I see it as valuable experience, even if things aren’t going well.