logo

NJP

Who is Ben our ServiceNow CISO?

Import · Apr 20, 2021 · video

[Music] great to be speaking with you today a quick background about myself i've been working in security since i was 17 so well over two decades now firstly in australia and the last 16 years in the us here in seattle the primary focus has been responding to security act tax in many different areas and other security domains but for the last 10 years it's been all about clout i've had the privilege to be the service now ciso for about a year and a half now cso's get all asked all the time how their organization is structured my personal opinion is that there is no perfect one-size-fits-all security organizational model because it depends not just on the company but where that company is at as a business for servicenow our customers are some of the most regulated in the industry so our security organizational model takes us into account and is allowed to affect both resiliency and risk but in a way that is scalable given our rapid growth to that end the way in which we have grouped our security organization is to take like-minded security functions so for example those that write code are on the same team those that do operations are in another and those that are field-facing are yet in another group and so on this design is to avoid silos built about specific security projects it also allows us at any given time to look at the body of work that we do have and make crisp prioritization calls not only on what you work to do or what work to automate but importantly what work to drop for greater priorities given our growth these priorities are quite dynamic in six months our current processes may be out of date which is why we have an agile structure that allows us to be constantly refreshing workflows and our approaches to work what is so cool about reporting to the servicenow cio my boss chris betty is that our target customers are also cios so chris is essentially customer zero for everything that we do at servicenow and this gives himself and his organization which includes security limitless possibilities on improving work for our customers in the future i've been in product and operational business units for most of my career but it is a privilege to be part of the it org at servicenow it does help of course that our cio is so security conscious and that's not always the case what this does mean though is that we're constantly challenged by him when reporting on the maturity of our security program and the way in which we do this is with a focus on enabling the right outcomes and value derived from security to support the business we use both quantitative and qualitative measures and consider both known risks but also known unknown risks internally we've set the expectation that we will be continuously uncovering new cyber risks every time we report to the c-suite and the board and that we will in turn address these risks diligently and aggressively regardless of their complexity c-suite relationships are crucial for any cso and in many ways they're pretty standard at servicenow we work hand-in-hand with our general counsel our cio of course and our cto other crucial relationships with our chief marketing officer and chief revenue officer for the purposes of cyber security resiliency but also our cfo as we align our security and risk objectives and subsequent budget needs to support our customers in the future what is great about this leadership team is that when we report to the board we do so when speaking the same language we have the same framework so whether it's myself our general counsel our head of privacy or ahead of physical security whenever we talk about risk we do so using that common framework and you know while this is supported and enabled by our grc product it simply wouldn't happen if it wasn't for the strong collaborative ties between servicenow security and other leaders across the company uh one c-suite group that is most crucial and not yet mentioned is that of our customers as a customer-focused company we are always listening to our customers and using our resources to anticipate their needs in security there is also the all-important shared responsibility model between a cloud provider and consumer and we're always looking for ways to uplift not just our own security but that of our customs as well i consider them to be a very essential component of our c-suite you

View original source

https://www.youtube.com/watch?v=P6qSc95dL9w