They hired a bureaucrat, not an engineer, to be their CISO.
They hired a bureaucrat, not an engineer, to be their CISO.
Hiring an engineer to be a CISO would be like choosing a biologist to give you surgery instead of a surgeon. Yes, a biologist probably knows a lot about the nitty-gritty of how bodies work, but knowing how the body works and knowing how to perform surgery on a body are two very, very different things.
That guy's LinkedIn looks more than qualified to be a CISO, and is certainly more qualified than the vast majority of CISOs I worked with in my career as a security consultant. And on top of all that, he has a degree in computer engineering and has prior experience as an engineer, so I have no idea why you're claiming he isn't an engineer.
To use your analogy no surgeon is allowed to cut until he or she does have a solid grounding in biology.
Maybe a better analogy would be choosing someone to represent you in a lawsuit about programming patents. You would want a lawyer representing you, not a programmer. Ideally the lawyer would have some previous experience with these kinds of cases and would lean on programming experts for their knowledge. Maybe they are even a former programmer turned lawyer! But I certainly wouldn't hire "a programmer" to represent me no matter how experienced in programming they are. Linus Torvalds would be a great expert witness, but he isn't going to be my general counsel.
>I think it's easier for the right kind of engineer to get into management rather than a lifelong manager to gain competence in engineering
IME, it's the opposite. It depends on your specific goal (are we trying to train someone to be CISO or are we training them to be a SOC team leader?), but it's ridiculously easier (and more effective) to take a person with existing management abilities and teach them about security than it is to take an engineer and teach them security management skills.
>Having someone with no background in engineering running a department is suspect.
It's really not, because again, engineering != security. It's no more suspect than the CFO not having a background in engineering.
I take it you're unfamiliar with the content of the MCAT exam, which is a prerequisite to admission to American medical schools.
Think about it this way: publications are telling you that ~92% of Cyber attacks start from an end users device. Probably true, but are we talking about a device being owned here or just are we discussing actual PII data loss?
More importantly, whilst Gartner and co is telling you what products you need to buy to defend against this, what they aren't telling you is the best product only has a 52% attack detection rate. And this only accounts for known attack vectors.
So you're a CISO, you're 15 million down on products, 5 million down on risk people, without a Software Developer, Sysadmin or Release Engineer on your team. The actual Engineering team ignores you because you keep raising stupid concerns.
Would this have happened if you were technical? Maybe, you'd have a different set of problems.
This guy was only a bureaucrat in the thinnest interpretation of the word.
Even then, security is an illusion. Eventually something or someone will find a way to get through. Zero trust needs to be embraced. Assume every employee, partner, developer and vendor is going to have full internal access and abuse it...then defend from there.
I would any day put my money in a bank who has a CISO with such credentials as that of Michael Johnson. He has been an engineer, done R&D, does have the right chops too I guess. And CyberSec has multiple layers - mostly the people, which is the weakest one. And that, my friend, cannot really be solved just by tech.
The issue is that fundamentally that's what managers and executives do. Their profession is politicking and manipulation rather than solving problems.
https://www.marketwatch.com/story/equifax-ceo-hired-a-music-...