pathdoc - stock.adobe.com
The CISO role isn't universal: 5 industry perspectives
One title, many jobs: CISOs at Fastly, SolarWinds, DeVry and other organizations reveal how industry shapes their responsibilities and priorities.
Though the title of CISO is common, the specific responsibilities of CISOs across verticals are not. CISOs at legal services firms, content delivery network providers and universities report to different bosses, defend different assets and answer to different regulators. Yet they all carry the same title.
This article explores, from a CISO's perspective, how companies and industries approach the crucial top cybersecurity role.
CDN and edge infrastructure: Fastly
A CISO is always responsible for their own organization, but in an infrastructure company, a single architecture decision shapes risk for every customer built on top of the platform. As deputy CISO at Fastly, a global content delivery network and edge networking provider, Fernando Medrano has security responsibility across the board.
"One thing that lands squarely on my desk that wouldn't necessarily land on a CISO's desk in, say, retail or healthcare, is that our security posture is part of the product we sell, not just a function that protects it," Medrano explained. "We're the infrastructure layer for thousands of companies' websites and applications, so a security architecture decision I make -- including how we segment environments, how we manage keys, how fast we patch -- doesn't just reduce our own risk. It directly shapes the risk profile of every customer built on top of us."
The nature of the business also means that Medrano must be technically adept enough to go toe-to-toe with his own engineering leadership and with technical customers. According to Medrano, this past year, the pressure that showed up most concretely was AI.
"Every business is under pressure to adopt AI quickly, but for us that pressure cuts two ways. We have to help engineering and the broader business use AI capabilities securely, and we're expected to use AI ourselves to scale a security team that will never grow as fast as the business does," he said.
Medrano noted that the biggest misconception he runs into is that, because tech companies are full of deeply technical people, they must have security figured out. "In reality, technical depth in one area doesn't transfer to another," he said. "A company can have world-class network engineers and still have real gaps in third-party risk, data governance or how quickly a new tool gets adopted by a team without security ever knowing it happened."
In his view, fast-moving, engineering-led cultures create their own risk surface. A lot of smart people are empowered to make independent decisions quickly, which is great for the business but challenging to secure at scale.
Medrano said he'd advise CISOs from other industries to unlearn the idea that security's authority comes from policy and sign-off. "In a lot of industries, security can mandate a control and expect it to be followed because of compliance obligations or hierarchy," he said. "In a company full of engineers who can route around anything they see as friction, that approach fails quickly."
What works in his industry is actual credibility earned by understanding the systems well enough to ship security as tooling and automation that engineers actually want to use, not by publishing a policy and hoping it holds. "If your team isn't writing code, or at least deeply fluent in the code being written around it, it'll struggle to be taken seriously here," Medrano said.
IT management software: SolarWinds
SolarWinds builds IT management software that helps organizations manage their own networks. Like any vendor, the CISO's security decisions and responsibilities have a broader impact.
"A configuration decision I make about our build environment or a call I make about how and when to disclose a vulnerability doesn't just affect the company. It ripples out to every organization running our product," Justin Henkel, CISO at SolarWinds, said.
The company has many products in its portfolio, including legacy technologies that no longer align with its current security processes. "If we're not actively resourcing and testing a product to the same standard as our current secure-by-design process, we have to ask whether we should still be supporting it, because an unsupported product still sitting in a customer's environment is a liability for them and for us," he said.
Outside the industry, people often assume a vendor CISO's job is mostly reactive. "The reality is the opposite as my job is overwhelmingly proactive," Henkel said. "I have a seat at the table with engineering and product teams from day one of the build process."
The biggest adjustment, Henkel added, is dropping the idea that security is a gatekeeper function that reviews things after they're built. He also noted that those coming from other industries have to relearn the scale of consequence.
"In a lot of industries, if you get breached, it's your problem," Henkel said. "As a vendor, if something goes wrong in your build environment or in your product, it becomes your customers' problem too, and you're the one who ends up in the hot seat to explain it."
Real-time data platform: Hydrolix
Hydrolix develops a real-time data platform used for analytics. Its CISO, Joshua Scott, has a different set of problems. Most CISOs will limit access to customer data in production, which is all about privacy -- but not Hydrolix.
"That's not a rule we can implement at Hydrolix because we're a petabyte-scale data platform and certain employees need access to our platform directly," Scott said. "My job isn't just deciding whether to allow access. I must determine who looked at the data, who did what with it, whether it was actually authorized, what the details of the agreement are and whether we have the right agreement in place."
When an engineering team needs real customer data to build something, Scott said the job is to find a path to "yes" rather than block the request outright, since a blanket "no" is not viable when real customer impact is at stake.
At a larger company, CISO functions such as IT, compliance and vendor risk typically sit with separate teams. At a startup, Scott said, the CISO's role does not divide that way. For example, he covers IT, architecture, software security, compliance, privacy, vendor risk and parts of legal himself.
Scott said that someone stepping into the CISO role at a company like Hydrolix would have to unlearn the belief that they can't easily prohibit access to production data. "We have to replace that prohibition with an authorization model because if we start enforcing the restrictions, the teams route around us and we end up with less visibility than what we started with."
Legal services: Lexitas
Lexitas provides technology for legal services and law firms. Joe Giannetti currently serves as both the company's CIO and CISO.
At Lexitas, most growth comes from acquiring other firms. "I have to support a security program that can absorb a new company's environment, with its own history and gaps, without ever creating a moment where confidential data is exposed during the transition," Giannetti said.
Giannetti pointed to AI vendor risk review as a particular challenge, saying it carries extra weight at Lexitas compared with typical software procurement. Before any AI tool touches client-related work, his team requires a clear answer from the vendor on data retention and model training.
People outside legal services sometimes assume the industry is low-tech and paper-driven, so the security stakes must be lower than at a bank or a hospital. "We handle some of the same categories of sensitive data, financial records, health information [and] PII," Giannetti added.
Giannetti said CISOs entering the legal industry must abandon the notion that their sole obligation is to the client who signed the contract. In reality, much of what flows through the firm's systems belongs to plaintiffs, witnesses and opposing parties who never signed anything directly with the firm. "You owe them the same diligence as a direct client, even though they'll never know your name," Giannetti said.
Higher education: DeVry University
Educating users is one element of a CISO's role, but for Fred Kwong, vice president and CISO at DeVry University, it's a core reason why he took the role in the first place.
DeVry's CISO helps shape the school's cybersecurity curriculum alongside the dean. "I'm making sure that students are learning things that they need to know for the enterprise moving forward -- the latest trends, technologies -- and making sure that the curriculum is not just filled with open source technologies, but things that the enterprise actually uses as well," Kwong explained.
"One thing that's unique about [education] is that your customers could potentially be your attackers as well," Kwong said. "In the educational world, because we are dealing with students, it's usually not malicious in nature, but more about the exploratory channels, just to see how far they can get."
That blurred boundary shows up in the volume of alerts DeVry's security operations center manages. Kwong said his team triages far more activity than a typical enterprise SOC, since students connecting from personal machines and unfamiliar locations do not fit the normal pattern, though every flagged account is still checked as carefully as a compromised employee's would be.
"We have students using VPNs showing like they're coming from Africa or France or other countries, connecting into our networks," Kwong said. "Those are all things we have to separate because it's not part of the normal pattern."
Kwong explained that CISOs must realize that most of higher ed is decentralized. A university functions like a larger enterprise made up of separate business units, and individual schools within it often run their own IT and security operations, each with its own challenges. He also pointed to research funding as an ongoing gap. "Professors and others who get research grants will often take that grant money and invest in technology, but they don't necessarily think about investing in security to protect those technologies or the data that they're creating."
"The role is constantly evolving and constantly changing, especially in education," Kwong said "We almost have to stay on top of technology more than other fields because not only are we bringing it in-house to enhance our services, we're also teaching about those technologies -- doing both in a responsible manner is really important."
Sean Michael Kerner is an IT consultant, technology enthusiast and tinkerer. He has pulled Token Ring, configured NetWare and been known to compile his own Linux kernel. He consults with industry and media organizations on technology issues.