A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Motor Oil[Fra: Mhz]
Christos Syngelakis, Group Chief Information Security Officer
Evolving Role of the CISO


Information Security is a science which has emerged in recent years due to the accelerated use of technology and related risks. Every business now uses technology regardless of whether or not it is their main business pillar. We use it for development, planning, strategy and sales promotion, to prepare future moves etc.
It's nice to use technology. But it's problematic and creates huge anxiety when you realise that your gun can be turned on you. When you see that as easy as your life becomes with the fast access to digitised data, it becomes a nightmare when you no longer have this data because someone steals or destroys them. And you feel powerless when you realise that the whole approach of economical solutions through the digital revolution has a much greater cost than it seems at first if you decide to secure it from digital risks.
At this point, the role of the CISO appeared, which in recent years has developed and acquired a status that is in no way limited to involvement with technological measures, as it now has a role that is called upon to help the company operate in a blurred technological landscape.
And so the years passed, the professionals in the field relied on international practices are constantly improving. You can follow some steps that can be assumed that, in the office space, even though the risks have become more, you will have some significant improvement, and you can have a stable and secure environment.
So, everything is fine. Unfortunately, no. Because there are probably some problems that we haven't seen yet, the problems we have to face are not limited to the area of information management and the systems that do this management. We must face the fact that we are in a messy situation in the industrial environment, as well as in the environment of the use of smart small devices connected to the Internet. Yes, in recent years, a framework has been created in Europe, such as NIS2, that discusses the need for digital security in the industrial and critical infrastructure sectors.
But is there a real person responsible from the company's side who has the knowledge and the authority to intervene in the industrial environment? In the operational technology (OT) environment.
If we look at it bluntly, CISO focuses on information security, not digital security. Most CISOs I know are simply out of touch and unaware of OT security issues. Their company may have an industrial production environment, but their jurisdiction over it is small to non-existent. This is room for big kids. For production engineers who are responsible for continuous production.
Don't get me wrong. The problem is not just for CISOs. The same problem exists with most CIOs, who are disconnected from decisions about the technology infrastructure accompanying the production premises.
Why this gap exists and how big it is, is a big debate. The fact we have to deal with is that this gap exists. Because those who talk about investments in machines forget or want to forget that these are now based on computer systems, and these systems have great exposure to digital risks because, in their design, it is assumed that with a magic wand, these risks do not touch them. But this is not the case. There are no more disconnected devices living in their silos with the myth of airgap protection.
It is necessary to see the problem in its true dimension and not to hide behind excuses. Yes, there is a problem because the people, who know about information technology and related security in the business space, do not know the problems of operational technology and related security in industrial environments. Yes, finding someone with experience and knowledge of the whole is very difficult. But it is something that must be done. Someone needs to have the big picture of all the digital risks that the business is facing. To make strategic moves and make decisions based on the general picture and not the microcosm of an environment, ignoring and leaving to the essence, since we are talking about a company with industrial activity, the company's main production environment unprotected.
It is necessary to see the problem in its true dimension and not to hide behind excuses
Those large European companies that have not understood and have not already taken steps to meet the mentioned needs will be in for an unpleasant surprise as the regulatory framework of NIS2 defines in Europe requirements which are probably, for the first time, above what the ecosystem can cover. Because it requires solutions to problems that often do not have immediate solutions, and the need to continue to operate in a dangerous environment is a one-way street.
Dear, however, the title really fits, CISO or chief digital security officer or chief information & operation technology security officer. Your role becomes even more demanding.
Weekly Brief
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info


