In cybersecurity, each CISO steers the ship with their own particular compass. As I sat down with Leron Zinatullin, CISO of Constantinople, it was clear that in his roster of professional priorities, people come first.
But that isn’t to say things don’t get done: he believes that this particular order of operations is what makes the transformations he pushes for permanent and palatable.
In this interview, Leron opened up about what got him interested in helming a security team, how business environment dictates security culture, and how soft skills enable leadership to roll out the hard changes.
What Was Your Journey like to CISO?
I work now for an Australian-headquartered company, Constantinople, that delivers the first all-inclusive AI-native platform for running a bank. But before getting into fintech and finance, my formative professional experiences centers around critical national infrastructure, and in securing industrial control systems for operational technology.
I started my career as a consultant, where I had a chance to work across multiple industries and help companies solve their hardest security challenges. I developed the skills that led to my passion for strategizing security changes within a range of different organizations, but soon that wasn’t enough. Beyond developing the strategy, I wanted to stick around to help get it done. Becoming a CISO seemed like the logical next step.
As a CISO you can play the long-game and work for your changes, establishing the relationships that reach within other sectors of the business and that will eventually earn you trust and buy-in. These individual, personal-level changes are needed at the top for security initiatives to take effect and trickle down.
What Are the Essential Skills for the Modern CISO?
Technical skills are important, but there’s more to cybersecurity than these alone. Being a CISO means building a culture (of cybersecurity). That starts with understanding what drives the organization and its people.
The most important skills for CISOs to have are those of listening and observing. We need to understand the psychology of change.
Security culture is what people are doing when no one is looking. Observe that culture. Why are people doing what they do? Why are (or are they not) they jumping fences? What does the company value?
Values manifest in more than what they write, but in what they do on a daily basis. If we understand the business drivers, we can understand how to weave security culture in seamlessly among them, even boosting those drivers through security goals.
As a consultant, I learned to leverage the culture already in place within different sectors to build a security foundation. For example, in the energy sector, safety is key. They have recurring goals of zero injuries in the workplace and take physical safety metrics seriously.
Implementing security practices was a matter of making them an extension of employee safety: cybersecurity was protecting the employee, but in a digital context. This was something the embedded culture seemed to readily understand.
What Is Your Top Tip for Building a Security Culture?
You can’t build a security culture if you don’t understand the company you’re working with and what matters to them. Everything else will be tied to that.
I go over this in my book, The Psychology of Information Security, which was released several years ago but which I re-released as a second edition this year to address obvious new changes: AI being the first among them.
There are short-term and long-term goals. To build a foundation for long-term adoption, change management frameworks come into play. Summarized, this entails creating a vision, a sense of urgency around the change you want to make, then building a coalition to support that change and getting security buy-in from top leaders.
However, even here it is crucial to find out what makes key stakeholders tick. Understand what language works best for a certain set, and what is going to motivate them about the new behaviors. What do they stand to gain?
Get to know their pain points. One thing we forget is that most people in an organization are paid to do a job that is not cybersecurity. We are the only ones getting paid to do that. So, when they hit a security roadblock that prevents them from doing their job, they are going to find a workaround that is inevitably going to be more dangerous.
It is our job to work with their business needs, not be the no-person telling them what they can’t do. As we listen to them, we as CISOs can be better informed on how to create security policies and cultures that align with their goals, not negate them.
Do You Have Any Counterintuitive Advice on Cybersecurity and Being a CISO?
This first one may not seem out of the ordinary, but we want a security culture where failure is embraced - or at the very least, okay.
If employees feel safe admitting when they fell for a phishing scam, we are more likely to be able to find and respond to the problem faster. In a company where security infractions are punished, no one feels safe to grow.
It’s important to remember that everyone makes mistakes, even security professionals. If non-technical employees (or even your SOC analysts) don’t know that you know this, there will be a tendency to delay reporting vital security errors and a latency in responding to them.
People are going to make these mistakes anyway. Making it safe to come clean with them only helps the company. Punishing them only pushes things backwards.
What Is One Unexpected Role of a CISO?
Many times, CISOs find themselves – or need to find themselves – in conversations about business ethics. This may be one of the more non-traditional aspects of the job, but it is coming to the fore more often as more data becomes available.
For example, most businesses run on data, but that data can be collected without purpose if leadership isn’t careful. Often, CISOs discover that more customer information than is absolutely necessary is being gathered and held in databases that aren’t properly secured.
When asked why, non-technical stakeholders typically respond with something like “it can be sold, or used later, etc.” However, it is a CISOs job to explain the consequences of what could happen to the customer (and the company, for that matter) if that data were to get breached: personal lives ruined, compliance violations, reputational loss.
These are all textbook answers for anyone in cybersecurity, but surprisingly, things not all department heads are thinking about, or thinking about in-depth. The cost is that protecting that data can be expensive, and it takes an ethical CISO to push to do the right thing.
How Will AI Change the Role of a CISO?
AI forces us to be faster and adapt to the changes. For years, attackers have been operating at machine-speed. If defense is going to keep up, it is going to take more than technological upgrades to the security stack.
Getting people to adopt pro-security changes (like patching things faster) is going to be the real hard part, and that’s where the listening, the people skills, the emotional intelligence, and the relationship-building come into play.
Meet Our Thought Leaders
Fortra® subject matter experts share their real-world experiences, offer practical tips, and help organizations navigate the cyber threat landscape.