Finding the right person to be your information security officer (ISO) can be a challenge. The person filling this role often wears many hats, most of which are critical to the ongoing success and security of your day-to-day operations. The value provided by an ISO is exactly what makes it all the more painful if they decide it's time to "start seeing other people."
If your ISO leaves, where would it leave you? Financial institutions don't have the luxury of wallowing while finishing off a tub of chocolate ice cream after a bad break-up. Your business would be much better served if you created a succession plan. This article will serve as your guide for what to do before your ISO leaves, what to do in the unfortunate event it happens, and your next steps.
I interviewed several individuals who have managed the departure of an ISO. Most of the "lessons learned" they shared had little to do with what happened after the ISO left. Instead, their suggestions focused on what they wished they'd done while the ISO still worked for their business. What I learned can be summed up in three steps: Appreciate, Communicate, and Rejuvenate.
When you are in a long-term relationship, it can be easy for things to become "business as usual" and end up taking people for granted. With each passing day, more items are often added to your ISO's "to do" list. Avoid burnout for your skilled staff by recognizing the work they do and taking steps to support them when they need it most.
Are you treating your ISO like you did when they were a prospective employee? If not, that might be a great place to start. Continue to get to know them. Find out what they like about their job and what they find challenging. An excellent ISO doesn't come along every day, so it is important to keep the spark alive. Schedule routine check-ins to make sure you both stay on the same page and keep working towards the same goals.
Aside from these general ideas, I don't know exactly what "appreciation" would look like for you. But I bet if you asked your ISO about their biggest pain points, the answer might just become a little clearer.
While the roles and responsibilities of an ISO vary depending on each organization's needs and resources, there is one thing which remains true pretty much across the board: The ISO is integrally involved with your business' information technology (IT), audit, and compliance functions. Basically, everything that makes the business run, your ISO is part of it. Because of this, it is of utmost importance to learn and understand the ISO's responsibilities, skills, and competencies. While you're at it, I recommend making a list.
Getting clear on this list is valuable for several reasons, including:
The ISO role is inherently controversial. The ISO's job is to secure the business. Every step towards security is often seen as a step away from efficiency. For example, multifactor authentication is the "control of the day." It's a great control for keeping people out, but it also requires you to unlock an extra lock before you can get in. The ISO is the person who usually pushes for these controls and is often seen as the "no" person. While important for the security of the business, always being the "bad cop" can be tiresome.
Another exhausting item on the job list is being on-call 24/7. Whether it is monitoring alerts, responding to incidents, or taking urgent calls from one of the many departments they work with, the ISO role can be demanding and can keep your ISO in a state of stress, just waiting for the next notification to pop up.
Make sure your ISO has an opportunity to step away from the inundation of security concerns. Have skilled personnel who can cover for them when it's time for family vacation, time for a random day off, or even just time for sleep. Make sure your ISO has the time they need to rejuvenate. This benefits them, and you as well, because it helps you know the business would be able to continue operations if your ISO left, which is the whole point of why we're here.
Besides, you know what they say… "Absence makes the heart grow fonder," right?
Hiring an ISO is expensive. It is much better for your business to retain your current ISO than to find a new one. In whatever ways you decide to appreciate, communicate, and rejuvenate, I'd be willing to wager it will cost you less than hiring and training a new individual to be your ISO.
"We need to talk." These are the four words no ISO's boss wants to hear. (Well, this and "there's been an incident.") Sometimes, things just don't work out. There are a billion and one reasons an ISO may choose to leave the company. Money. Family. Health. Flexibility. Culture. Location. Mid-life crisis. You name it. Some things you could have prevented, while others are out of your control. Whatever the reason for your ISO leaving, you need a plan.
So, what can you do? For starters, you can download our ISO Offboarding Checklist. The checklist will help you keep track of these six steps for what to do if your ISO leaves.
When your ISO announces they are leaving, the first thing you'll want to do is determine the nature of the departure. In other words, on a scale of "we're still friends" to "they're setting things on fire," how hard is this going to be?
Due to the breadth of the ISO's role in your business, the next step is to communicate the ISO's departure with all affected parties. Some examples could include the:
This part is the equivalent of returning the t-shirts you borrowed and getting back your mix tapes. While not necessarily specific to the ISO role, asset management holds extra importance in this case because if not performed correctly, it can leave your organization significantly vulnerable.
Here are some specific items you'll want to do:
An ISO is often tasked with critical responsibilities at an organization. To make sure nothing falls through the cracks:
Based on the nature of the departure, you may want to perform ongoing monitoring to make sure everything was adequately addressed. Specifically, be sure to monitor:
At the end of it all, be sure to make time for some deep introspection. The most important question to ask would be: "What do you wish you had known or done differently before your ISO left?" Based on this information, adjust your operations to make sure if this happens again, you are more prepared next time than you were today.
Losing an indispensable part of your business can be painful, but operating alone can be even worse. If your organization has determined having a standalone ISO is an important part of your business, there are plenty of fish in the sea, so to speak. Get on the business equivalent of dating apps (e.g., LinkedIn, Glassdoor, Indeed, ZipRecruiter, etc.) or call up some old friends and see if they might be willing to set you up with someone they know. However you choose to proceed, the most important thing is that you get back out there and make sure your business is secure for many years to come.
If you're looking to get that special someone a gift to tell them how much you appreciate them, check out Tandem. Tandem is a cybersecurity governance, risk management, and compliance (GRC) application, designed with ISOs in mind. Our suite of products was created by a team of security and compliance specialists who know how challenging it can be to manage a business' information security function. We exist to form a partnership, be in Tandem, with you. Learn more about Tandem on our website at https://tandem.app.