The Department of No!

Not every CISO or security team has fallen into this trap

More Whitepapers

They’re the overly-cautious ones. While everyone else sees silver linings, they’re pointing out the threatening clouds within them. If they have a signature word, it’s: “no.”

Does marketing want to share some behavioral insights with a new partner? That’s a “no” from the CISO, even if it will bring in seven figures of business. Need to deploy a new business-critical application within the next week? Not without a pentest, says the security department. Oh, and they’re booked for the next six months.

You can understand why others tend to perceive them as a blockage. But that’s just part of the story.

Contemporary information security departments have evolved. What started as a murky corner of the basement-bound IT team has grown to encompass a broader swathe of disciplines: white hats, strategists, educators, regulators and so on. These various forms of evolution have ultimately transformed the role altogether.

Security is no longer exclusively concerned with password hygiene and document management. It’s now regarded as an integral part of a business. Security has earned its seat at the conference table, and the shiny corner office that ensues. And yet, that reputation for being the department that says “no” persists.

This prevailing reputation is not necessarily a good thing. While there’s always room for cautiousness, being excessively so can be harmful, cause damaging workplace cohesion, and encourage employees to circumvent existing rules. This trepidation can come from a desire to work faster, to work without being bogged down in (often necessary) bureaucracy, or from a fear of being reprimanded.

Not every CISO or security team has fallen into this trap. In some organisations, they’ve managed to market themselves as an indispensable asset. A department or person to work with, rather than fight against.

This report will take a closer look at the habits of successful security teams and the secret sauce that makes them work. These methodologies they’ve deployed could work for your organisation, transforming the perception of your security team from blockade to vital partner.

The Organisation-Security Relationship

Brad Pitt and Angelina Jolie. Kate Moss and Pete Doherty. And yes, security departments and literally everyone else in the organisation. These are all pairings known for their often-turbulent relationships. And just like the glistening showbiz world, infosec teams often go through the full cycle of relationship drama—turmoil, highs and lows, and even occasional breakups.

But where does the fault line originate? Attributing blame—be that to a security department or a colleague—isn’t always straightforward, because this remains somewhat of a taboo topic seldom discussed in the disinfecting light of day.

My first port of call was ex-CISO Thom Langford, who echoed that sentiment exactly. “It’s difficult to say,” he said. “Nobody would admit it.”

Langford went on to describe a real example of a security team earning the unenviable moniker of the “Department of No.”

“A former predecessor fell into this category,” he said. “I was regaled multiple times of the cases where she literally stopped a business in its tracks until they just ignored her.”

Of course, some factors influence the path a security team chooses to take. Shan Lee, CISO at fintech titan Transferwise, pointed out that the size and type of organisation play a role in shaping a security team’s perception.

“I think the bigger/older/more heavily regulated the business is, the more true that [IT teams are regarded as the “Department of No”] is,” he said. “My team has an unwritten rule that we never say no, we offer alternative routes. We also have a lot of informal ‘drop-ins’ on Zoom, where anyone can ask about an idea they’ve had before it becomes an actual project, and no questions are stupid.”

Of course, for every story of collaborative and healthy security-colleague relations, there are hundreds more of “shadow IT” leaking into an organisation, and valued employees potentially getting disciplined as a result.

Whitepaper

"Security teams have a reputation—perhaps deserved—for being a barrier to progress."