This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

How businesses should think about their cybersecurity investments?

Download resources

About this session

Shamla Naidoo, head of cloud strategy and innovation at Netskope and a former CISO, argues that security leaders will only be invited into the C-suite if they treat every business change as an opportunity rather than a threat. She walks through the forces reshaping organisations (digital-first consumers, heavier privacy and security regulation, geopolitical tension, climate pressure and cheap, ubiquitous technology such as IoT and cloud) and shows how each one expands the attack surface while also opening new markets. Her thesis is that a larger technology footprint means more exposure, so security must become agile, fast and elastic enough to let the business grow and shrink with demand. She reframes data as a business asset to be protected and mined with AI rather than deleted, urges security teams to apply the same analytics to their own alert volumes, and describes Zero Trust as adjusting trust through visibility and control rather than distrusting partners. She closes on executive communication: earn credibility with metrics and demonstrable risk reduction, tailor the message to each executive's fears, and fold the security strategy into the single corporate strategy rather than running a parallel one.

It is no secret that the requests for cybersecurity investments are constantly increasing. Businesses have complicated technology environments, complex
business models and relentless regulatory and consumer demands. How should business owners approach
innovation while also extracting value from their cybersecurity investments? Shamla will share her practitioner experience on this topic while offering us a
constructive approach to make these decisions.  

Key takeaways

  • Read every business shift (new consumer demographics, regulation, geopolitics, climate, cloud and IoT adoption) as an opportunity to enable, not just a risk to block.
  • Design security to be agile, fast and elastic so it can scale up and down with the business instead of becoming the obstacle to going global.
  • Stop telling the business to delete data; protect it as an asset and use AI to extract insight from it, and apply the same analytics to your own alert volumes.
  • Frame Zero Trust as adjusting trust through visibility and controls over rented infrastructure, not as refusing to trust partners.
  • Earn executive trust with competence and credibility: bring metrics and concrete risk-reduction actions, speak to each executive's own concerns, and merge the security strategy into the corporate strategy.

Speakers

Shamla Naidoo
Shamla Naidoo
CISO, Head of Cloud Strategy · Netskope
Shamla Naidoo brings a rare mix of global business experience, technical knowledge and legal expertise to her numerous roles. She is currently the head of Cloud Strategy and Innovation at Netskope. She is also an independent director at multiple… Read moreRead less

Shamla Naidoo brings a rare mix of global business experience, technical knowledge and legal expertise to her numerous roles. She is currently the head of Cloud Strategy and Innovation at Netskope. She is also an independent director at multiple public and private companies. She was recently a Managing Partner at IBM where she advised CEOs, board directors, and executives on how to ensure digital transformation, innovation and strategic risk management co-exist while creating business value. Prior to that Shamla was IBM’s Global Chief Information Security Officer (CISO), where she was accountable for the protection of the worlds largest Intellectual Property portfolio and IBMs global technology estate. After 25 years as an engineer and technologist, Shamla acquired a Jurisdoctor degree and is licensed to practice law. She teaches multiple courses in Information Technology, Security and Privacy law at the University of Illinois at Chicago (UIC) Law and she coaches a number of Security and Technology executives.

Resources

Tags

More from GoSec 2021

Also from Shamla Naidoo

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.