CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

CVE-2024-3400: PAN-OS Command Injection Vulnerability in GlobalProtect Gateway. Learn More

Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

Database Security

Prevent unauthorized access and exceed compliance requirements.

Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

How to Thrive as a CISO in 2017

The job of a cybersecurity executive is a test in resilience and thoughtfulness. Aside from standing on constant guard against villainous outsiders and naive and nefarious insiders, you may also be mired in a tortuous battle to remold organizational culture and exhort support from senior leadership.

Stress and pressure are part of the routine, and a healthy compensation awaits those who are up for the challenge and excel at their duties. But big salaries don't always equate to long-term success. It is those infosec leaders who find a way to remain cool, calm and collected amid the perfect storm of modern cybercrime that will find the most sustainability in their careers.

Here are six helpful ways to practice grace under fire, stay recharged, achieve maximum results and - most of all - be your best CISO self in the New Year and beyond.


Control Your Emotions

Between confronting attackers, coping with skills and other resource shortages and satisfying the board, tense moments are almost a guarantee for the security leader - and this could lead to poor decision-making. Your patience will be tested, and equanimity is key. When you do get emotional, try to channel it into positive vibes, as studies show that the more you energize your team, the more motivated they will be and the better they will perform.


Accept Short-Term Adversity 

There is an expression in poker that to be a long-term winning player, you must learn to "embrace the variance," meaning as long as you play your hand optimally, you may run into some random bad luck along the way - but that's OK. You'll still profit in the long run. The same applies in your role as CISO. Short-term results are saddled with a lot of variance. Not everything will fall your way, but as long as you are problem solving and decision making with the long term in mind, you'll net the biggest and most strategic wins for your organization.


Learn from Your Mistakes

Of course, the reality is that in security, immediate tasks are part of the job because incidents will arise that need addressing. From those, mistakes will happen. How you respond to them is paramount to your growth as a leader. If a member of your team committed the transgression, send the message that admitting to their blunder (as long as the intent was positive) is not grounds for the end of the world, especially considering the complex and imperfect science that is cybersecurity. If it was your own misstep, you should not only admit that you were wrong, but also learn from the experience. Which is a good time to remind you: Never stop learning and seeking constructive feedback from peers.


Be Confident, But Humble

The position of security executive is tricky. On one hand, you must diligently work to enter the good graces of company stakeholders because they control the purse strings and can help you deliver a culture of security across the organization. But on the other hand, you are the one who is responsible for keeping the company off the front page in the event of a major data breach. Thus you must be malleable. Show tenacity for your position by communicating powerfully, while also letting it be known that you are open for collaboration to help others better understand what you do.


Practice Self-Care

At the end of the day, there is only one of you. The harried and anxiety-inducing obligations of CISO is one that may knock off your equilibrium, erode your mental clarity and emotional intelligence, and - in the worst-case scenario - lead to burnout. Managing stress and maintaining a healthy lifestyle will prove invaluable. What are some options? Try your hand at meditation and mindfulness, reflect through journaling, take breaks, find time to exercise, implement digital detoxes and schedule "do-nothing" days.


Be Open to External Allies

Earlier we referenced the widespread and still-worsening security skills shortage facing the industry. This is leaving many CISOs and security executives with limited in-house options for performing the often-complex tasks of vulnerability identification, network protection, security monitoring, threat detection and incident response. Examining and measuring the viability and value of your existing resources will help you better understand what you can accomplish internally and help guide you to learning whether you can benefit from an outside ally. An external partner, such as a managed security services provider, can help complement and support you and your team on a wide array of tasks.



We hope these suggestions help you maintain your groove (or get it back!) in 2017. If you have any other strategies that have worked for you, please leave them in the comments or @ us on Twitter.

Dan Kaplan is manager of online content at Trustwave and a former IT security reporter and editor.

Latest Trustwave Blogs

Unlocking the Power of Offensive Security: Trustwave's Proactive Approach to Cyber Defense

Clients often conflate Offensive Security with penetration testing, yet they serve distinct purposes within cybersecurity. Offensive Security is a broad term encompassing strategies to protect...

Read More

Behind the Scenes of the Change Healthcare Ransomware Attack Cyber Gang Dispute

Editor’s Note – The situation with the Change Healthcare cyberattack is changing frequently. The information in this blog is current as of April 16. We will update the blog as needed. April 16, 2024:...

Read More

Law Enforcement Must Keep up the Pressure on Cybergangs

The (apparent) takedown of major ransomware players like Blackcat/ALPHV and LockBit and the threat groups’ (apparent) revival is a prime example of the Whack-a-Mole nature of combating ransomware...

Read More