{"id":555,"date":"2020-08-13T16:02:00","date_gmt":"2020-08-13T15:02:00","guid":{"rendered":"https:\/\/fatbuzzhosting.com\/brim\/?p=555"},"modified":"2024-06-18T16:05:43","modified_gmt":"2024-06-18T15:05:43","slug":"guest-blog-dr-juliette-summers-on-the-threats-posed-by-ciso-identity-threat","status":"publish","type":"post","link":"https:\/\/fatbuzzhosting.com\/brim\/guest-blog-dr-juliette-summers-on-the-threats-posed-by-ciso-identity-threat\/","title":{"rendered":"Guest Blog: Dr. Juliette Summers on the threats posed by CISO Identity Threat"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"740\" height=\"530\" data-src=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog.webp\" alt=\"\" class=\"wp-image-556 lazyload\" data-srcset=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog.webp 740w, https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog-300x215.webp 300w\" data-sizes=\"auto, (max-width: 740px) 100vw, 740px\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" style=\"--smush-placeholder-width: 740px; --smush-placeholder-aspect-ratio: 740\/530;\" \/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"740\" height=\"530\" src=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog.webp\" alt=\"\" class=\"wp-image-556\" srcset=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog.webp 740w, https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/guest-blog-300x215.webp 300w\" sizes=\"auto, (max-width: 740px) 100vw, 740px\" \/><\/noscript><\/figure>\n<\/div>\n\n\n<div style=\"height:60px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-4ecqb\">Cyber security has an identity issue. While some data breaches are driven by hackers, research shows that most breaches of cyber security are staff related, resulting from employees\u2019 inadvertent use of technology (through either not understanding risks, mistakes, or lack of compliance with organisational policies) or deliberate actions by disgruntled employees.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-89gn5\">The information security risks of a proliferation of communications and information technologies and devices, coupled with testing peoples\u2019 understanding of complex and dynamic environmental changes and compliance, challenges accepted norms and definitions of the CISO professional role. While the professional status of CISOs is of ongoing academic and practitioner interest, what has been less well understood are the identity consequences of a rapidly changing IS ecosystem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"viewer-5jj8j\">We were lucky enough to talk to Dr Juliette Summers, University of St. Andrews for her expert insights on how CISO identity threat could be leading us towards organisational vulnerability.<\/h2>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>there is a risk of CISO exit if organisations do not fully understand the remit creep CISOs are experiencing.<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-b8l33\">Professional status and identity come with a considerable amount of sunk investment in terms of time, emotional ties and self-esteem. Any changes to role and context can threaten professional identity, which can result in reductions in performance, wellbeing and mental health, among other things. Identity threat can lead professionals to devalue the source of the threat and, if the threat is the increasing focus on HR in cyber security, this may lead to a lack of collaboration and an increased cyber security vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-6uakf\">With an ever-expanding cyber security sphere of activity, CISOs are under pressure to cover every aspect, including HR and not just an information security remit. Where demands on CISOs are increasingly outwith their traditional expertise domain, this can challenge accepted norms and definitions of their role. Such a discrepancy between desired CISO actions on the one hand (i.e., effectively dealing with cyber security) and constraints on those actions (i.e., other Senior Managers and Directors failing to understand these pressures and constraints), can threaten CISO effectiveness and reputation. Operating within this complex, challenging and dynamic environment brings with it the threat of credibility loss when CISOs\u2019 responsibility involves those outwith IT. This can be experienced as a threat to professional role and identity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-8r8co\">Theory tells us that where a professional identity is affirmed and supported, it can also be dynamic and responsive to contextual changes in conditions. Therefore, while cyber security training and policy are necessary, they are not sufficient, and CISO identity is often overlooked leading to organisational vulnerability. To facilitate CISO effectiveness, and to manage cyber security with appropriate resilience, companies need to offer and support new and positive dimensions to the CISO role. If not, there is a risk of CISO exit if organisations do not fully understand the remit creep CISOs are experiencing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-9duts\"><strong>About the author<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\" id=\"viewer-r87l\">Dr Juliette Summers is a lecturer in Management at the <a href=\"https:\/\/www.st-andrews.ac.uk\/maintenance\/schools\/jcs27\" target=\"_blank\" rel=\"noreferrer noopener\"><u>University of St Andrews<\/u><\/a>, with a research focus on points of identity transition for individuals and groups within organisations. Her work informs private sector businesses, including the legal sector, accountancy, human resource management and academia. She is a Director of the Centre for Research in Equality, Diversity and Inclusion at University of St Andrews, and <a href=\"https:\/\/www.journals.elsevier.com\/european-management-journal\/editorial-board\" target=\"_blank\" rel=\"noreferrer noopener\"><u>Associate Editor of the European Management Journal<\/u><\/a>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"350\" height=\"525\" data-src=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers.webp\" alt=\"\" class=\"wp-image-557 lazyload\" data-srcset=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers.webp 350w, https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers-200x300.webp 200w\" data-sizes=\"auto, (max-width: 350px) 100vw, 350px\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" style=\"--smush-placeholder-width: 350px; --smush-placeholder-aspect-ratio: 350\/525;\" \/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"350\" height=\"525\" src=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers.webp\" alt=\"\" class=\"wp-image-557\" srcset=\"https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers.webp 350w, https:\/\/fatbuzzhosting.com\/brim\/wp-content\/uploads\/2024\/06\/juliette-summers-200x300.webp 200w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/noscript><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The contents of this website are provided for general information only and are not intended to replace specific professional advice relevant to your situation. To find out more, <a href=\"https:\/\/www.brimcentre.com\/legal-disclaimer\" target=\"_blank\" rel=\"noreferrer noopener\">please click here.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber security has an identity issue. While some data breaches are driven by hackers, research shows that most breaches of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":556,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised"],"acf":[],"_links":{"self":[{"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/posts\/555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/comments?post=555"}],"version-history":[{"count":1,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/posts\/555\/revisions"}],"predecessor-version":[{"id":558,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/posts\/555\/revisions\/558"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/media\/556"}],"wp:attachment":[{"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/media?parent=555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/categories?post=555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fatbuzzhosting.com\/brim\/wp-json\/wp\/v2\/tags?post=555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}