cybersecurity dinner 2015



Similar documents
Goodbye Spokesperson, Hello Steward

Greater than the Sum of its Parts: Professionalizing the Supervisory Board

ROLE SPECIFICATION INTERNATIONAL FINANCE CORPORATION

The Real Supply Chain Challenge Leadership and Talent Management

Digital Infrastructure and Economic Development. An Impact Assessment of Facebook s Data Center in Northern Sweden executive summary

Human Resources Specialty Practice.

managing talent to meet pharma s next great challenge: global market access Life Sciences and Healthcare Services

Opportunities for Action. Achieving Success in Business Process Outsourcing and Offshoring

How CPG manufacturers and retailers can collaborate to create offers that will make a difference. Implications of the Winning with Digital Study

ROLE SPECIFICATION WORLD FOOD PROGRAMME

Opportunities for Action in Industrial Goods. Winning by Understanding the Full Customer Experience

Indian E-Retail Congress 2013

We should have started earlier.

DHL Global Energy Conference 2015 Outsourcing logistics Enhancing innovation or increasing risk?

What Makes Cities Successful Randstad on the World Stage

Eight Best Practices for Conducting a Successful General Counsel Search

Customer Relationship. Opportunities for Action in the Pulp and Paper Industry. Management in the Paper Industry

Opportunities for Action. Shared Services in Operations and IT: Additional Complexity or Real Synergies?

The Data Center of the Future: Creating New Jobs in Europe

Opportunities for Action in Industrial Goods. The Price Is Right: Optimizing Industrial Companies Pricing of Services

Coaching Executives: Building Emotional Intelligence

Real Estate. Expertise of a boutique. Reach of a global firm.

Freight Forwarders: Thinking Outside the Box

Danske Advokater Bestyrelsens dag, 2. maj 2014

Elements of an Organization That Can Work For the Police

Opportunities for Action in Financial Services. Growing Profits Under Pressure: Integrating Corporate and Investment Banking

2015 City RepTrak The World s Most Reputable Cities


Opportunities for Action in Operations. Working Capital Productivity: The Overlooked Measure of Business Performance Improvement

at the pace of business Leadership development In-house programs available! The Leadership Express Series Ottawa, ON

Opportunities for Action in Consumer Markets. To Spend or Not to Spend: A New Approach to Advertising and Promotions

Opportunities for Action in Financial Services. Sales Force Effectiveness: Moving Up the Middle and Managing New Prospects

Opportunities for Action in Financial Services. Transforming Retail Banking Processes

the leadership implications of saas

Cyber security: A major issue for Australian business

Cargo Sales & Service Presentation

Opportunities for Action in Financial Services. The Three Golden Rules of Cross-Selling

Redefining Security Leadership in a Riskier World

Denied Boarding Eligibility

Global Real Estate Outlook

The World s Most Competitive Cities. A Global Investor s Perspective on True City Competitiveness

Financial services regulation in Australia

seeing the whole picture HAY GROUP JOB EVALUATION MANAGER

Guide. Axis Webinar. User guide

India. Doorway to opportunities

Ken Favaro Ashish Jain Samuel Bloustein. Small Business Banking Customers An Attractive Segment for Organic Growth

board solutions litigation support services Executive compensation

Opportunities for Action in Industrial Goods. Asset Productivity: A Potent Lever for Competitive Advantage

Our top digital business and talent trend picks from the Mobile World Congress: The Connected Society Comes Into View

Opportunities for Action in Financial Services. Making the Most of Mortgage Markets

Opportunities for Action in Information Technology. IT Outsourcing Rediscovered: Getting Your Share This Time Around

Opportunities for Action in Financial Services. Untapped Riches: The Myths and Realities of Wealth Management

Denied Boarding Eligibility

Opportunities for Action in Consumer Markets. The Antidote to Mismanaged CRM Initiatives

Fact sheet DTZ Fair Value Index TM methodology

Aiming for Outsourcing Excellence

e-literacy: the need for leadership change in the business of higher learning Tech and Communications

CITY OF CHICAGO BUILDING ENERGY USE BENCHMARKING AND TRANSPARENCY

Alvarez & Marsal Global Forensic and Dispute Services Asia Pacific Regional Meeting (APRM) Tokyo, Japan April 2015

Opportunities for Action in Consumer Markets. Paying for Performance: An Overlooked Opportunity

Guide. Axis Webinar User Guide

Opportunities for Action in Consumer Markets. Fast Is Good, but Smart Is Better

Seamus McMahon Ashish Jain Kumar Kanagasabai. Redefining the Mission for Banks Call Centers Cut Costs, Grow Sales, or Both

big data doesn t make decisions: leaders do Six guiding principles to build organizational muscle in analytics

Internet of Things, a key lever to reduce CO 2 emissions

Opportunities for Action in the Automotive Industry. Winning in Today s Chinese Automotive Market

Opportunities for Action in Information Technology. Demonstrating the Value of IT: Mission Impossible?

SRM How to maximize vendor value and opportunity

Cuba Sanctions Update: Removal of Cuba from Terrorism List Will Result in Modest Easing of Trade Sanctions


SOCIAL MEDIA STRATEGY EXECUTION 10 STEPS DIGITAL SERIES

Opportunities for Action in Consumer Markets. Competitive Advantage from Mobile Applications

Private Equity Practice Group

How to Become a Procurement Champion

What it takes to succeed as a Multinational Company CEO in India

CRITICAL THINKING AT THE CRITICAL TIME CONSTRUCTION SOLUTIONS

Opportunities for Action in Financial Services. The Business-to-Business Race Is On

Be clear about your talent management goals

Opportunities for Action in Technology and Communications. Creating Value in Mobile Telecom: Beyond ARPU

What CEOs Need to Know to Make Diversity and Inclusion Really Work

Cloud Computing: A Primer on Legal Issues, Including Privacy and Data Security Concerns. Privacy and Information Management Practice / Washington, DC

Rents continue to recover. Global Office Index Q2 2014

GOING FOR GOLD IN THE GLOBAL OFFICE MARKET

Leadership Development Yesterday and Today. Approaches that Work

Synopsis: In the first September TripCase product release there will be several big updates.

Walid Tohme Jad Bitar. Healthy Links Bringing Interoperability to Healthcare Delivery

Generating Serialisation Code with Clang

the next generation of family office leadership

Cybersecurity Risk Factors: Five Tips to Consider When Any Public Company Might be The Next Target

STREAMLINE YOUR TRADING COMMUNITY TRADING COMMUNITY SERVICES

Improved Outlook? French Manufacturing Competitiveness Radar 2014/2015. Paris, March 2015

Accessing DC savings: The new rules.

Best practices from senior HR executives

GLOBAL FINANCIAL CENTRES 7

Travel, Hospitality and Leisure Sector. Expertise of a specialty. Reach of a global firm.

Background. 9 September Practice Groups: Investment Management, Hedge Funds and Alternative Investments Broker-Dealer Finance

Opportunities for Action in the Automotive Industry. How Electronics Will Revolutionize Innovation in Autos

Opportunities for Action in Financial Services. Passage to India: The Rewards of Remote Business Processing

Telefónica Global Solutions. Channel Partner Program Expand your limits through our global scale

Cyber Risks in the Boardroom

Transcription:

cybersecurity dinner 2015 Discussion Highlights In February 2015, President Obama, speaking at a White House Summit on cybersecurity and consumer protection, declared that the Internet has become a sort of Wild West, where private corporations are prime targets of hackers and cyber criminals. Egon Zehnder recently hosted a cybersecurity dinner in for cross-industry executives in the DFW Metroplex to discuss the challenges of preparing and responding to cyber threats in an increasingly dangerous environment. Egon Zehnder invited executives who would act as first responders in the event of an attack: general counsels, chief information security officers, heads of corporate communications and chief information officers. The conversation was led by panelists David Chamberlin, Executive Vice President and General Manager at Edelman; Erin Nealy Cox, Executive Managing Director at Stroz Friedberg; and Matt Haltom, Senior Vice President, General Counsel and Secretary at Sally Beauty and was moderated by Kal Bittianda, Selena LaCroix, Kristi Maynor and Chris Patrick, all representing Egon Zehnder. Here is what we heard: If you want peace, prepare for war Sixty-five percent of hacked companies are informed by law enforcement or third parties when they have been breached. In other words, internal sensors are not detecting intruders in the network. Companies need to take a proactive stance by investing in more sophisticated security monitoring functions that are designed to perceive not only unauthorized entry but also exits and lateral movements. Companies should regularly pay auditors to access their systems to monitor for dormant malware (hackers can be extremely patient) or malignant software that has not yet been detected. Asked for their opinion on the most worthwhile type of InfoSec investment, all three panelists suggested regular internal exercises simulating a hack/breach. Companies should hire a white -hat hacker to test systems and bubble up vulnerabilities.

Information security as a differentiator Companies like, Bank of America, IBM and Visa are making Information security (InfoSec) a business differentiator compared with their competitors. For example, they have hired communications directors who are solely responsible for dealing with InfoSec. It greatly improves organizational agility and response when there is a team member, like a head of InfoSec communications or a chief information security officer (CISO), whose sole focus is cyber protection. Lessons learned in a crisis Continual monitoring: Hackers can do a lot of damage in 48 hours. Even with software monitoring systems in place, an attack that commences on a Friday evening while no one is physically present to oversee the systems over the weekend can be disastrous. First steps following a breach: Hire a forensics team that is retained by the company and has the company s best interests in mind. Notify your insurance company. Do not notify government agencies until you are sure that consumer data have been lost (until that time, the law does not mandate notification). Cooperation with law enforcement: Cooperation and information sharing with the government are important. However, government investigators primarily will be concerned with attribution; that is, who is behind the attack? The priority of a company will be to close the doors and stop the leak of information. Law enforcement will want to publicize progress on an investigation. On the other hand, the victim of the hack will want to be more prudent with external communications in order to maintain consumer confidence. Disclosure: Do not rush to report the size and scope of the hack. If you are imprecise with those numbers, which is likely in the immediate aftermath, you will have to backtrack. It s better to complete a thorough private investigation before disclosing the breach to partners and customers. Customers will want you to provide them with accurate and confirmed answers to their questions, not speculation before facts have been established. Economic espionage across industries Seven years ago, companies primarily concerned with cybersecurity were in finance, retail, pharma and defense. Now all industries are at risk. For example, in the consumer space, product formulas are bought and sold on the black market. Why would a company spend years coming up with a competing formula when it can be bought and paid for via the Internet? Even in the technology space, hackers can access the internal networks of software companies and embed malware in the code gene used to develop consumer products. In essence, software releases can be infected even before going to market, giving cyber criminals access to information on thousands of consumers. Cybersecurity is an issue that cannot be ignored and one that ALL companies need to consider very carefully in order to survive in an increasingly interconnected and digitally dependent global marketplace. 2

Market observations of trends and the rise of the CISO Companies are actively looking for cybersecurity solutions to reduce their exposure, address regulator concerns and protect their customers, employees and profits. 1. Increased interest and investment in new companies and innovative solutions are on the rise. 2. Corporations are making process and policy adjustments (e.g., BYOD policies). 3. The CISO role is being formalized, elevated and/or expanded in companies. Companies at the forefront of dealing with cybersecurity issues are primarily in five areas: financial services, technology, defense, energy and infrastructure. The threat, however, now extends across all industries. Company boards are increasingly looking for information security experts to either join the board or serve in an advisory capacity to set a workable and effective information security road map and hire and develop effective IT and InfoSec teams. Public-private partnerships (exchanges, Business Executives for National Security, presidential working groups, etc.) for collaborating and sharing information to combat cyber crime are expanding to more companies. The CISO role was first formalized as a result of the Patriot Act in 2001; the 2008 financial crisis then triggered the next wave of hires; and now a third wave is under way, triggered by recent high-profile hacking events at global retailers, banks and other organizations. A talent pool is emerging. While there is much attention to this topic worldwide, there are emerging pools of U.S. talent from government/military agencies (FBI, NSA, Cyber Command, etc.), large defense contractors/consultancies and established white-hat organizations. 3

The Egon Zehnder Team Kal Bittianda New York kal.bittianda@egonzehnder.com +1 212 519 6070 Kal Bittianda is a consultant in the New York office of Egon Zehnder and a core team member of the Technology, Telecommunications and Financial Technology Practices focused on emerging technologies, information technology and cybersecurity. Selena LaCroix selena.lacroix@egonzehnder.com +1 972 728 5975 Selena LaCroix, based in, is the Global Leader of Egon Zehnder s Legal Practice Group and Semiconductor Practice Group. Selena is deeply experienced in board-level consulting and senior executive talent management in the technology sector with expertise in the semiconductor and smart devices segments. Kristi Maynor kristi.maynor@egonzehnder.com r +1 972 728 5935 Kristi Maynor is a consultant in the office of Egon Zehnder and is a core member of the firm s Consumer, Technology and Communications Practice Groups. Kristi also is a member of our Diversity and Inclusion specialization and provides management appraisal and accelerated integration support for clients. Chris Patrick chris.patrick@egonzehnder.com +1 972 728 5950 Chris Patrick, based in, is a trusted advisor for CIO and C-suite talent strategy and development for global companies across a diverse set of industries, including retail/consumer products, IT services, industrial, financial services and digital. As the Global Leader for Egon Zehnder s Chief Information Officer Practice, Chris advises some of the world s leading corporations on talent development and assessment at the board-level and across the executive suite. 4

Egon Zehnder is the world s leading privately held executive search and talent management consultancy with more than 400 consultants in 69 offices across 41 countries. The firm provides senior-level executive search, board search and advisory, CEO succession and family business advisory, as well as leadership assessment and development to the world s most respected organizations. Egon Zehnder s clients range from the largest corporations to emerging growth companies, family and private-equity controlled entities, government and regulatory bodies, and major educational and cultural organizations. For more information: www.egonzehnder.com. Amsterdam Athens Atlanta Bangalore Barcelona Beijing Berlin Bogotá Boston Bratislava Brussels Budapest Buenos Aires Calgary Chicago Copenhagen Dubai Düsseldorf Frankfurt Geneva Hamburg Helsinki Hong Kong Houston Istanbul Jakarta Jeddah Johannesburg Kuala Lumpur Lisbon London Los Angeles Luxembourg Lyon Madrid Malmö Melbourne Mexico Miami Milan Montreal Moscow Mumbai Munich New Delhi New York Oslo Palo Alto Paris Prague Rio de Janeiro Rome San Francisco Santiago São Paulo Seoul Shanghai Singapore Stockholm Stuttgart Sydney Tel Aviv Tokyo Toronto Vienna Warsaw Washington, D.C. Zurich 2015 Egon Zehnder International, Inc. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system or transmitted in any form or by any means electronic, mechanical, photocopying, recording or otherwise without the prior permission of Egon Zehnder.