THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


As security and privacy professionals, we face the enormous challenge of creating, maintaining, and enhancing information security and privacy programs (from now on referred to as a 'Program') that proactively address the genuine needs of our organizations. While aiming to succeed in that task, we may overemphasize the technical aspect of it without thoroughly considering critical factors that can make or break our Programs. Thus, this article addresses pivotal considerations for implementing effective Programs.
● Understanding Our Work, Organization, and Team
There is an intrinsically humane side to the work we do. Security and privacy are functions that, beyond all technical standards, legal requirements, and business defense capabilities, fulfill a role aimed at protecting the rights and freedoms of individuals. It involves proactively working to safeguard information from getting into the wrong hands and causing severe damage to people. For an organization, this may translate into financial or reputational losses; for individuals, a failure to protect their information can cost them everything, even their lives.
Before developing a Program, we should consider whether our organization understands the inherent value provided by security and privacy teams instead of mere compliance checkboxes. If these functions are seen as burdensome compliance items at the organizational level, we may assess the appetite for change and improvement and undertake efforts to refocus the culture. For example, it includes highlighting the benefits of good security and privacy practices in connection with sustainability criteria (Environment, Social, and Governance -ESG- factors).
At the team level, we need to understand team dynamics as they play a fundamental role in the Program's success. Therefore, managers need to keep team members motivated by emphasizing the relevance of the work they do so that they remain focused on safeguarding the organization by protecting its most valuable asset: customer trust. A strategy to accomplish this is by using active listening to prove that we care about our team members' opinions and want to seek ways to implement justifiable security and privacy measures. Teammates' input will prove even more valuable if we encourage them to listen to and track business areas' concerns, as those records will provide actionable intelligence about security and privacy gaps or patterns that we should address in our Program.
● Understanding Risk Tolerance Levels and the Crucial Role of Communication in Risk Management
Before effecting change through the Program, security and privacy teams must understand the industry in which the organization operates, the organizational approach to risk, and the applicable legislation. Understanding legal requirements is crucial for developing a compliance baseline and it is helpful to select the most suitable security and privacy framework. In addition, it is relevant for determining whether the business areas' risk tolerance aligns with their compliance requirements. Identified deviations will impact security and privacy functions regarding risk acceptance and implementation of administrative and technical controls. Furthermore, understanding the organizational approach to risk will provide insights about the types of responses security and privacy teams should expect from the organization when deploying key items of the Program.
“A core component of managing risk for security and privacy is comprehending that, largely, the value provided by our Program will be tied not only to addressing technical issues and relevant risks but how we convey our findings.”
A core component of managing risk for security and privacy is comprehending that, largely, the value provided by our Program will be tied not only to addressing technical issues and relevant risks but how we convey our findings. As such, our teams must take the right approach to target the audience in every case by communicating in a way that is not overly technical or legal, unless we are talking to experts in these fields, and, where feasible, providing multiple alternatives to manage the risks identified. An efficient tactic to achieve a good level of communication is working with other business areas to create a process that enables us to share risks proactively and allows them to make informed choices to manage said risks.
● Increasing the Effectiveness of the Program Through Adequate Communication and Avoidance of Generic References
Other than knowledge, fostering curiosity or generating interest in security and privacy calls for dedicated teams to demonstrate our eagerness and provide value to the business areas. We need to understand where the problems are before trying to fix them, and that requires communication. It is common for security and privacy professionals to attempt to reuse policies from previous organizations they have worked in without considering how the organizations differ. While there are elements that will undoubtedly be transferable, a very different thing is meeting with every single business area to talk about their business activities, systems in use, processed data, their challenges, and known or unknown risks, using the inputs of these business analyses to inform our Programs. This process involves a significant time commitment still, but the benefits are worth the time invested, as you are guaranteed to identify issues that wouldn't have come across your desk otherwise. Gradual change happens when we connect with people to let them know that we are there to assist them and that they can reach out when they have doubts. Once we establish that rapport, people will start questioning their decisions about data and systems, which will translate into a positive culture switch regarding security and privacy.
To further promote the Program and increase its effectiveness, we should explicitly target the incidents, risks, and types of information processed by different business areas within our organization. Based on experience, people pay attention to little snippets of content relevant to their work because they can relate to and apply that content. Thus, consider the significance of tailoring your training.
Finally, a way to maintain a mutually beneficial relationship between security and privacy and other business areas is by keeping your team's response times in check. The longer you take to reply to random questions, contract reviews, or to finalize your security and privacy impact assessments, the more likely it is that business areas will see your function as a blocker rather than an enabler. Consequently, it is essential to set expectations upfront by explaining that the longer they take to follow up with service providers, obtain feedback, or make decisions, the longer the security and privacy assessments will take.
In essence, the value of our Program surpasses technical measures and policy wording. Its value lies in consistent and efficient communication and a flexible approach purposely implemented to safeguard the organization while enhancing customer trust. Such an approach can be achieved through the active engagement of our team and the different business areas from the outset to build a Program designed to target the organization's unique needs, culture, and risk tolerance.
During the development phase of the Program, rather than mindlessly focusing on writing a policy, we should use our interactions with the different teams to identify risks and create learning opportunities, helping to reshape organizational culture around privacy and security. We must also create avenues for input from our team and other stakeholders to improve the Program continuously. When training employees, we should prioritize content specific to the organization rather than generic. Finally, security and privacy should not be "blockers"; we also demonstrate the value we provide through our precise way of setting upfront expectations and efficient process management. A future-proof value-focused Program should consider all of the above.