IT professionals have long operated in isolation. Removed from major business decisions and working behind the scenes, they’ve largely been left alone to address their companies’ technology and security needs.
But that’s no longer the case. IT professionals are now integral to business decisions and have a much more visible role in protecting sensitive data. They’re also increasingly expected to manage information privacy when key privacy positions aren’t filled or simply don’t exist.
Effective translators
IT professionals today must translate what they’re seeing in their threat-intelligence and risk-management efforts into business impact. According to the “Technology’s Impact on Workers” study conducted by the Pew Research Center, 59 percent of workers take their jobs outside the boundaries of the office. This means IT professionals must be able to protect mobile workers on multiple devices from cybersecurity threats like malware, as well as physical security threats, such as a visual hacker in a coffee shop. And for every threat, IT personnel must evaluate what are the potential business risks.
There are different approaches for formulating such costs. Ponemon Institute’s annual “Cost of Data Breach Study” sponsored by IBM uses direct and indirect costs to calculate the cost of a data breach. Similar models exist to help companies identify not only costs but also risks.
It’s important to remember, however, that these models aren’t a one-size-fits-all solution. They’re merely a starting point and should be right-sized to your specific company or industry.
More engaged
IT professionals who think they can fight security and privacy battles alone have already lost the war.
Today’s security threats seek to exploit vulnerabilities in the workforce, through tactics such as more targeted phishing attacks, visual hacking and social engineering. As a result, IT professionals can no longer remain behind the scenes. They need to actively work with employees for support.
This requires building security and privacy programs that are both visible and invisible. They must be visible in that they communicate and enforce good behaviors, such as not opening suspicious email attachments and being aware of surroundings when working in public places. They must be invisible in that they don’t prevent employees from doing their jobs or scare them away from using productivity-enhancing technologies.
Open to change
An open mind and flexible approach can go a long way in helping keep IT professionals relevant in today’s organization.
Security and privacy policies should be aspirational rather than definitive. This is especially true as companies adopt new technologies. For example, revising policies for mobile devices to require the use of privacy screens is much easier than restricting mobile device use to comply with existing policies.
Flexibility can be equally important when working with upper management. Outright dismissing major decisions such as an acquisition because of policy-compliance issues will only diminish the value and role of IT professionals. A more reasonable approach would be to conduct an assessment to identify and quantify the risk involved in the acquisition.
Finding the right workers
Today’s IT candidates should have strong technical expertise but also business acumen. They also should be good communicators, preferably with at least some experience where this was required, such as retail or customer service. And they should have a firm grasp on privacy issues as much as they do security issues.
Attracting well-rounded candidates with these qualities will help you fill IT roles that are prominent, more visible and more integral to everything you do.
With over 20 years of security management in several vertical markets, Patricia Titus has been responsible for designing and implementing robust information security programs ensuring the continued protection of sensitive corporate, customer and personal information in her various positions. Titus is currently the chief information security officer at Markel Corporation and is instrumental in the protection and integrity of Markel’s information assets while transforming the information security program.
New breed of IT professional




