SlideShare a Scribd company logo
1 of 14
www.thalesgroup.com OPEN
Culture shock?
Academia vs industry
Bridget Kenyon
Global CISO
Thales eSecurity
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
2
Content
▌My background
▌Academic and industry approaches to information security:
Similarities
Differences
▌Methods to achieve security improvements in both sectors
▌Getting traction with senior management teams
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
3
▌4 private sector organisations:
Lucas Varity (aerospace)
7Safe (security consultancy)
Thales eSecurity (engineering)
Travelex (finance)
▌5 universities:
Aston
Birmingham
Warwick
Cambridge
UCL
▌Other:
British Standards Organisation
DERA
My background
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
4
How we view each other
Industry view of
academia
Academic view
of industry
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
5
Similarities 1/2
▌Top management have a short attention span
▌Spectrum of attitudes to home working
▌“Customers”
Academia has students and the staff community
Industry has customers and employees
▌Agility and speed depend on size and complexity
▌Everyone is worried about (GDPR) breaches
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
6
Similarities 2/2
▌Limited resources available for security
▌Silos between security operations/support and security
research/product delivery
▌Challenge with getting internal marketing bandwidth
▌People are still people:
Same problems with passwords
Culture drives behaviour
Trying to solve problems in isolation doesn’t work
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
7
Worked Example: Creating a Policy
Password
Policy
Dear all,
here is a
draft Policy
Dear CISO,
about your
password
policy…
The NCSC
doesn’t believe
in passwords!!
Why haven’t we
bought
Technology X?
I share all my
passwords! It’s
VITAL
Here’s my 100
page summary of
what we should
do
You’ve violated
Process 56 para
23
I’m INCENSED
you didn’t consult
me first
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
8
Differences 1/2
▌Sharing of information about security
Academia is good at it
Some private sector organisations do it well (e.g. media)
Some don’t (e.g. banking)
▌Mergers, acquisitions
More frequent in industry
▌Focus
Governance (e.g. large multinationals)
Risk (e.g. loss of trust > loss of revenue)
Compliance (e.g. financial sector)
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
9
Differences 2/2
▌More iconoclasts in academia
▌Top-down initiatives work better in industry
▌Industry may have more toys
▌Industry is still struggling with BYOD
▌Not as much “sales” in academia
▌Academics thrive on reputation
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
10
Industry infosec staffing challenges
▌Huge difficulty in recruiting and retaining infosec staff:
No qualified recruits
Hiring freeze
▌Large salaries
▌Focus on work-life balance to retain staff
▌Lots of churn (recent event, 90% of the 25 CISO attendees had
been in their role <1 year)
▌School leavers don’t consider infosec careers (9 in 10)
▌No problem in Israel!
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
11
Approaches which work in any sector to improve security
▌People are people:
Social contract
Personal networks
Get people involved via special interest groups/Champions
“Gamify”
Keep content fresh and relevant
▌Take the initiative after an incident or audit:
Have a checklist of wants
Keep quotes up to date
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
12
Successful liaison with senior management
▌Know the “business” and help it get what it wants:
Understand the drivers (e.g. revenue, number of students, academic rankings,
share price)
Know the key players and what they want
Make common cause with other business areas (e.g. Legal, Quality/Audit)
Speak “non-tech”
▌Get in front of business/academic leaders
Make your point clearly and briefly
Learn from their choice of words
Look at alternative solutions if you reach an impasse
Aim to be invited back
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
13
Finally… get people onside!
Thisdocumentmaynotbereproduced,modified,adapted,published,translated,inanyway,inwholeorinpartor
disclosedtoathirdpartywithoutthepriorwrittenconsentofThales-©Thales2018Allrightsreserved.
REF xxxxxxxxxxxx rev xxx - date
Name of the company / template : 87211168-GRP-EN-004
OPEN
14
In conclusion
▌Not so much culture shock as a brief
translation period
▌Skills and solutions are portable
▌Depends on your perspective as to what
the differences are
▌Business drivers and relationships are
key

More Related Content

Similar to Culture shock? Academia vs industry

Open / Collaborative Innovation Networks
Open / Collaborative Innovation NetworksOpen / Collaborative Innovation Networks
Open / Collaborative Innovation Networks
innovation-3
 
What is technology due diligence and why is it important © dr pete technology...
What is technology due diligence and why is it important © dr pete technology...What is technology due diligence and why is it important © dr pete technology...
What is technology due diligence and why is it important © dr pete technology...
Roelof Iball
 

Similar to Culture shock? Academia vs industry (20)

Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
Tenable: Economic, Operational and Strategic Benefits of Security Framework A...Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
Tenable: Economic, Operational and Strategic Benefits of Security Framework A...
 
Thales e-Security corporate presentation
Thales e-Security corporate presentationThales e-Security corporate presentation
Thales e-Security corporate presentation
 
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
neXt Curve reThink: What Meltdown & Spectre Mean for IoT Past, Present & Future?
 
Cybersecurity Introduction of Cyberlab
Cybersecurity Introduction of CyberlabCybersecurity Introduction of Cyberlab
Cybersecurity Introduction of Cyberlab
 
Ccie security 01
Ccie security 01Ccie security 01
Ccie security 01
 
Zero Trust vs Defense in Depth
Zero Trust vs Defense in DepthZero Trust vs Defense in Depth
Zero Trust vs Defense in Depth
 
M&A security - E-crime Congress 2017
M&A security - E-crime Congress 2017M&A security - E-crime Congress 2017
M&A security - E-crime Congress 2017
 
Open / Collaborative Innovation Networks
Open / Collaborative Innovation NetworksOpen / Collaborative Innovation Networks
Open / Collaborative Innovation Networks
 
3 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-23 oraclex evento reg puglia_v2017-09-14-2
3 oraclex evento reg puglia_v2017-09-14-2
 
10 KEYS TO EFFECTIVE NETWORK SECURITY
10 KEYS TO EFFECTIVE NETWORK SECURITY10 KEYS TO EFFECTIVE NETWORK SECURITY
10 KEYS TO EFFECTIVE NETWORK SECURITY
 
Embedded Analytics in Customer Success
Embedded Analytics in Customer SuccessEmbedded Analytics in Customer Success
Embedded Analytics in Customer Success
 
ICISS Newsletter Sept 14
ICISS Newsletter Sept 14ICISS Newsletter Sept 14
ICISS Newsletter Sept 14
 
Accenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber ResilienceAccenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber Resilience
 
What is technology due diligence and why is it important © dr pete technology...
What is technology due diligence and why is it important © dr pete technology...What is technology due diligence and why is it important © dr pete technology...
What is technology due diligence and why is it important © dr pete technology...
 
CV 2.4 18/06/2016
CV 2.4 18/06/2016CV 2.4 18/06/2016
CV 2.4 18/06/2016
 
Advanced blockchain
Advanced blockchain Advanced blockchain
Advanced blockchain
 
Accenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber ResilienceAccenture Security CG&S Cyber Resilience
Accenture Security CG&S Cyber Resilience
 
New technologies - Amer Haza'a
New technologies - Amer Haza'aNew technologies - Amer Haza'a
New technologies - Amer Haza'a
 
Transforming Information Security: Designing a State-of-the-Art Extended Team
Transforming Information Security: Designing a State-of-the-Art Extended TeamTransforming Information Security: Designing a State-of-the-Art Extended Team
Transforming Information Security: Designing a State-of-the-Art Extended Team
 
Putting the Product in Product-Led GTM
Putting the Product in Product-Led GTMPutting the Product in Product-Led GTM
Putting the Product in Product-Led GTM
 

More from Jisc

More from Jisc (20)

Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
 
The Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptxThe Open Access Community Framework (OACF) 2023 (1).pptx
The Open Access Community Framework (OACF) 2023 (1).pptx
 
Are we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptxAre we onboard yet University of Sussex.pptx
Are we onboard yet University of Sussex.pptx
 
JiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptxJiscOAWeek_LAIR_slides_October2023.pptx
JiscOAWeek_LAIR_slides_October2023.pptx
 
UWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptxUWP OA Week Presentation (1).pptx
UWP OA Week Presentation (1).pptx
 
An introduction to Cyber Essentials
An introduction to Cyber EssentialsAn introduction to Cyber Essentials
An introduction to Cyber Essentials
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 

Recently uploaded (20)

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 

Culture shock? Academia vs industry