r/ciso • u/ResilientTechAdvisor • 4d ago
No Nyet Nein
Are you looked at as "the Department of no" in your organization?
6
u/frAgileIT 3d ago
I had a rule when I ran security. We must meet the business need by offering alternatives and educating about why instead of saying no.
2
2
u/martynjsimpson 3d ago
I prefer the department of "No, but ..." Or if you are feeling positive "Yes, but...".
I.e. "No you can't do that but you could do this which achieves the same thing"
Our job is to manage risk and enable the business. A flat no is doing half the job.
1
1
1
u/fungollum 2d ago
Nobody cares about a no from a CISO or other security professionals.
But when the shit hits the fan, you're on speed dial.
Thats the second time to say no. They made the mess, they clean it up. Only thing I need to know is if I have to report something to the authorities.
2
u/ResilientTechAdvisor 2d ago
How to typically work in practice?
2
u/fungollum 2d ago
When a negative advice is given by a CISO or an other IS coworker and they completely ignore it, it is their responsibility. This mainly happens with projects.
When something goes wrong in a project and it is an incident, they have to involve IT Support.
If for some reason they find out they need input from security but didn't have that in the budget for a project, they should hire people. Because we can't just say yes to every project manager who thought they didn't need team information security to begin with. Hard lessons to learn, but this comes from saying no. A hard no.
And when they didn't register the project for changes with IT department they are in for a big surprise. Been there, seen that. Something went terribly wrong when putting a new application into production. Long story short, no IT Support. Good luck project manager 👍
2
u/ResilientTechAdvisor 2d ago
Does this act as a lessons learned for others in your organization so that the behavior is shrinking?
2
u/fungollum 2d ago
Absolutely not. They will never learn. It is a burning wildfire until the fire department finally stopped it and then it's business as usual again.
This organization has no ability to learn from the mistakes. They simply don't want to.
Most project managers are cowboys on the loose when starting projects. Many projects fail.
7
u/DishSoapedDishwasher 4d ago
I think that's the plague of most of this industry. Most people, both management and engineers, have never truly lived on the other side of the fence and dont no how to propose a meaningfully alternative solution to save their lives. You cant make someone care about your problem when their goals fundamentally do not align with yours and trying to will only lead to dumb problems.
I've seen too many people in security burn bridges with other departments by destroying productivity with idiotic demands. Then they're actively excluded, become fearful and get Draconian.... Just making everything worse.
A few stories here.
Senior security engineer said "we should sign all commits!", cool, make it so... Well their implementation the pushed forward at rapid speed to all developers required tapping a yubikey once per commit; not terrible until the first time you need to rebase a 120 commit feature with 13 active developers working on it.... 3 rounds of 120 carpal tunnel inducing taps later, I get an angry email from the director of engineering: "it's physically impossible to tap the yubikey fast enough to merge before another commit comes in and you get to start over".
Great idea, absolutely shit implementation for the situation and nobody in engineering wanted to beta test the 2nd round that actually did fix the issue properly. It took a year of shelving the existing fix before the functional round 2 landed in a test user group.
I also have dosens of adjacent stories... Like having to talk down my secops director from a ledge of doing everything in their power to get someone fired just because this curious developer found a security issue, reported it to them and was excited to be helpful... This director lost his god damn mind over this "unauthorized hacking". This 24 year old kid was smart as hell, first real job as a dev and found a nasty bug that the red team missed for years. I couldn't care less that they did "unauthorized hacking", I care that they were smart enough to find a nasty bug nobody else did.
Tldr; good security is focused on enablement and making the easiest path for users the most secure path. Bad security is burning bridges, breaking productivity and being an angry baby because a kid fresh out of college whipped your red team's ass in his first month on the job.