CISO Confidential: What Separates The Best From The Rest
RSA Conference 2024 · West Stage Keynote
Overview
This talk, delivered by Trellix CEO Bryan Palma and CISO Harold Rivas at RSAC 2024, delves into the dramatic evolution of the Chief Information Security Officer (CISO) role, charting its journey from an obscure, often overlooked position to a critical executive function at the forefront of global security. Drawing parallels with Taylor Swift's "eras," Palma traces the CISO's transformation through various stages, highlighting the increasing complexity of the threat landscape and the growing strategic importance of cybersecurity leaders. The presentation culminates in the declaration of a new "Era of Possibility," where CISOs are positioned as "Cyber Titans"—pivotal figures not only within their organizations but also on the global stage, particularly in defending critical infrastructure against sophisticated nation-state threats.

Key moments
- 0:00 Introduction and Taylor Swift 'Eras' analogy
- 2:45 CISO 'Debut Era': Invisibility and early challenges
- 4:15 CISO 'Red Era': Regulatory compliance and risk focus
- 6:15 CISO 'Reputation Era': Attacks increase, full spotlight
- 7:15 Current CISO role: High responsibility, limited resources
- 8:15 The New 'Era of Possibility' for cybersecurity
- 9:10 Improving capabilities: Industry collaboration and open ecosystem
CISO Confidential: What Separates The Best From The Rest
Speakers: Bryan Palma, Chief Executive Officer, Trellix; Harold Rivas, CISO, Trellix
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=ABGsvsePdEY
Overview
This talk, delivered by Trellix CEO Bryan Palma and CISO Harold Rivas at RSAC 2024, delves into the dramatic evolution of the Chief Information Security Officer (CISO) role, charting its journey from an obscure, often overlooked position to a critical executive function at the forefront of global security. Drawing parallels with Taylor Swift's "eras," Palma traces the CISO's transformation through various stages, highlighting the increasing complexity of the threat landscape and the growing strategic importance of cybersecurity leaders. The presentation culminates in the declaration of a new "Era of Possibility," where CISOs are positioned as "Cyber Titans"—pivotal figures not only within their organizations but also on the global stage, particularly in defending critical infrastructure against sophisticated nation-state threats.
The talk is significant because it provides a high-level strategic outlook on the future of cybersecurity leadership, emphasizing the need for enhanced collaboration, specific skill development, and a recognition of the private sector's emerging role as a "sixth domain of warfare." It challenges CISOs to transcend traditional operational boundaries and become architects, operators, and connectors, capable of navigating an increasingly volatile and interconnected threat environment. The insights presented are crucial for current and aspiring CISOs, as well as executive leadership, in understanding the demands of modern cybersecurity and fostering a more resilient global defense posture.
Background
▶ Watch: Introduction and Taylor Swift 'Eras' analogy (0:00)
The CISO role, as detailed by Bryan Palma, has undergone a profound metamorphosis over the past three decades. In 1995, when Steve Katz was hired as the first CISO at Citibank, the position was in its "debut era." CISOs were largely invisible, often relegated to IT departments, and their primary function was perceived as technical support rather than strategic risk management. Palma recounts his own experience as an early CISO for Pepsico in the early 2000s, feeling this invisibility while grappling with less sophisticated tools and emerging threats like the first email-based attacks against the president, which he investigated as a Secret Service agent.
Around 2002, the landscape shifted dramatically, ushering in what Palma likens to Taylor Swift's "Red era." The passage of Sarbanes-Oxley (Sox) in 2002 was a watershed moment, pulling cybersecurity professionals into the spotlight by mandating controls and compliance. This regulatory push, combined with significant cyber incidents like the I Love You virus and the Melissa virus, forced organizations to recognize cybersecurity as a critical business concern. The CISO role began to evolve, becoming more risk-focused, though questions lingered about its organizational placement—was it IT, corporate security, or something else entirely?
The mid-to-late 2000s saw attacks become more frequent, complex, and expensive, with nation-state actors playing an increasingly central role. This period, dubbed the "Reputation era," saw CISOs gain significant visibility, moving "from invisible IT guy to magazine covers." This historical progression underscores the journey from a reactive, technical function to a proactive, strategic leadership position, setting the stage for the challenges and opportunities of the current cybersecurity landscape.
Key Findings
▶ Watch: CISO 'Red Era': Regulatory compliance and risk focus (4:15)
Trellix's "Mind of the CISO" research, surveying 500 CISOs, provided several critical insights that underpin the talk's central arguments. A striking 96% of CISOs reported setting strategy and having overall responsibility for their company's cybersecurity program. However, this level of responsibility often comes with an imbalance of organizational authority and limited direct reports, meaning CISOs possess "incredibly limited resources pitted against incredibly high visibility." This disproportionate impact, akin to Taylor Swift's influence in the music industry, highlights the outsized role CISOs play in their organizations' resilience and success.
The research also revealed a sobering truth: more than 80% of leaders experienced an increase in cyberattacks in the past six months, indicating a persistent and worsening threat landscape. When asked what would most improve their organization's defensive capabilities, the top answer was not advanced technologies like LLM models, algorithms, or machine learning. Instead, it was "industry peers sharing insight and best practice." This finding underscores a critical need for a more collaborative approach to cybersecurity, moving away from platform debates towards a unified, open ecosystem.
Based on these insights, Palma declared a new "Era of Possibility" for cybersecurity, emphasizing that the work done by professionals in this field will dramatically shift. The core concept introduced by Harold Rivas is that of the "Cyber Titan": a fusion of industry leadership and cybersecurity specialization. This term recognizes that the private sector, particularly at the intersection of critical infrastructure and information, has emerged as a "sixth domain of warfare," alongside air, land, sea, space, and cyber. This signifies a profound shift where cybersecurity professionals are increasingly vital to global conflicts and national security, making every individual in the room a potential "Cyber Titan."
Technical Deep Dive
▶ Watch: CISO 'Reputation Era': Attacks increase, full spotlight (6:15)
While the talk avoids deep dives into specific code or protocol vulnerabilities, it offers a crucial strategic and operational "technical" deep dive into the evolving threat landscape and the necessary skills for CISOs to navigate it. The concept of the private sector as the "sixth domain of warfare" is a paramount technical finding. Harold Rivas explains that this domain exists where critical infrastructure and information converge, making CISOs and their organizations frontline defenders in geopolitical conflicts.
This new reality implies a significant increase in nation-state actors employing sophisticated cyber tactics timed with kinetic warfare. A prime example cited is the wiper malware used in Ukraine, targeting essential infrastructure like satellites and telecommunications. This demonstrates that cyberattacks are no longer isolated incidents but integrated components of broader military and political strategies.
Furthermore, the talk highlights the escalating importance of space assets as a critical and vulnerable domain. Rivas points out that almost all organizations are reliant on space assets in some way, yet current research indicates that this attack surface is "not well protected," and CISOs often have "limited knowledge of the domain." The speaker even ventures into scenarios like wiper malware attacks against Mars-based colonies, emphasizing that what once seemed like science fiction is rapidly becoming a tangible threat that future CISOs will confront. This necessitates a fundamental expansion of CISO expertise beyond traditional terrestrial networks.
The role of Generative AI (Gen AI) is also acknowledged, though not extensively detailed within the talk itself, as a significant emerging technology that cybersecurity leaders must tackle. The implication is that while AI may automate some tasks, the human work that remains becomes "so much more important," requiring a higher level of strategic thinking and problem-solving.
Addressing the pervasive battle for talent, the talk underscores the critical need for an "all hands on deck" approach. Initiatives like CISA's "50% by 2030" goal and Trellix's "soulful work campaign," alongside partnerships with organizations like the World Economic Forum, HACE, Gotera, and the National Cybersecurity Alliance, aim to bring more diverse talent into the industry. This is a "technical" challenge in that it requires engineering a workforce capable of defending complex systems against advanced threats.
To thrive in this evolving landscape, CISOs must cultivate three core skills:
- Architect: This skill demands deep domain knowledge, strong technology skills, and the ability to fuse business and technology priorities. An architect CISO understands how security frameworks integrate with business objectives and can design resilient systems that support organizational growth while mitigating risk. They are not just implementing solutions but building secure foundations.
- Operator: An effective operator must speak the language of their business, understanding its operations, revenue sources, and industry norms. Beyond internal knowledge, an operator needs a keen awareness of the global landscape, regularly consuming information on international affairs, global politics, conflicts, and elections. This external awareness allows them to anticipate threats and understand their potential impact on the business. Rivas mentions reading at least five publications every morning to stay informed.
- Connector: This is deemed the "most important" skill. A connector CISO is an independent, yet credible member of the executive team, acting as an agent of change. They must effectively communicate the story of risk, translating complex technical threats into business impact and using risk to their organization's advantage. Crucially, connectors communicate outside the organization, engaging with regulators, policymakers, customers, and industry peers to build a collective defense. This involves actively participating in and fostering community, as highlighted by the CISO to CISO initiative. The ability of adversaries to form "Shadow Syndicates"—where criminal gangs, activists, and nation-states blur lines and collaborate for economic incentives—serves as a stark reminder of why the good guys must also embrace robust community and collaboration.
These three archetypes—Architect, Operator, and Connector—provide a framework for the technical and leadership competencies required for CISOs to become effective Cyber Titans in the Era of Possibility.
Demo / Proof of Concept
▶ Watch: The New 'Era of Possibility' for cybersecurity (8:15)
This particular talk did not feature a traditional technical demonstration or a proof of concept in the sense of showcasing a tool, exploit, or vulnerability. Instead, the practical manifestation of the talk's central theme of collaboration and community was the introduction of the CISO to CISO initiative. Bryan Palma proudly unveiled this as a "crowdsourced channel for collaborating with peers, fostering discussions and sharing best practice." This initiative serves as Trellix's direct response to the "Mind of the CISO" research finding that industry peers sharing insights and best practices is the most desired improvement for organizational defense capabilities. While not a technical demo, it represents a concrete, actionable outcome of the strategic insights discussed, aiming to operationalize the "Connector" skill at an industry-wide level.
Defensive Implications
▶ Watch: Improving capabilities: Industry collaboration and open ecosystem (9:10)
The insights from "CISO Confidential" carry profound defensive implications for organizations and cybersecurity professionals alike.
Firstly, the most critical defensive implication is the urgent need for enhanced collaboration and community building. The research clearly indicated that peer-to-peer insight sharing is paramount. Defenders must actively seek out and participate in initiatives like Trellix's CISO to CISO initiative or establish informal networks of trusted peers. As Harold Rivas recommends, having a "dozen other CISOs on speed dial" is not just a luxury but a defensive imperative. This collective knowledge and shared defense strategy are crucial to combat the increasing complexity and novelty of threats, as "CISOs can't rely on their experience alone anymore." The blurring lines between threat actors into "Shadow Syndicates" further emphasizes that defenders must mirror, if not exceed, the coordination of their adversaries.
Secondly, organizations must recognize and prepare for the evolving threat landscape, particularly the rise of the private sector as the "sixth domain of warfare." This means anticipating nation-state cyber tactics timed with kinetic warfare, understanding that critical infrastructure is a primary target, and investing in resilience against such sophisticated, coordinated attacks. CISOs need to expand their threat intelligence to include geopolitical developments and their potential cyber ramifications.
Thirdly, the emerging importance of space assets as an attack surface necessitates immediate attention. While it may seem futuristic, organizations reliant on satellite communications, GPS, or other space-based services must begin to assess their exposure and develop defensive strategies for this domain. This may involve training security teams on space-based system vulnerabilities, engaging with relevant experts, and integrating space-asset security into overall risk management frameworks.
Fourthly, CISOs must actively cultivate the three archetypal skills: Architect, Operator, and Connector.
- As Architects, they must develop deep technical domain knowledge and the ability to integrate security into business strategy, ensuring that security is designed in, not bolted on.
- As Operators, they must speak the language of the business, understanding its revenue streams and operational intricacies, while simultaneously maintaining an acute awareness of global events that could impact their organization. This requires a dedicated effort to stay informed through diverse publications and intelligence sources.
- As Connectors, CISOs must hone their communication skills to effectively articulate risk to boards, executives, regulators, and customers. They must become agents of change, capable of influencing organizational culture and driving security initiatives across the enterprise and beyond. This also means actively contributing to industry dialogue and policy-making.
Finally, the battle for talent remains a significant defensive challenge. Organizations must prioritize attracting, developing, and retaining diverse cybersecurity talent. This involves not only competitive compensation but also fostering a culture that emphasizes purposeful, mission-driven work, as highlighted by Trellix's "soulful work campaign." Investing in training, mentorship, and career development pathways is crucial to building a robust and sustainable defensive workforce capable of facing future threats.
Key Takeaways
- The CISO role has evolved dramatically: From an "invisible IT guy" to a "Cyber Titan," the CISO is now a pivotal strategic leader, operating in a "sixth domain of warfare" (private sector critical infrastructure).
- Collaboration is the top defense priority: Despite technological advancements, CISOs overwhelmingly prioritize peer-to-peer insight sharing and best practices as the most effective way to improve defenses against increasing cyberattacks.
- Threats are increasingly complex and geopolitical: Nation-state actors are integrating cyber tactics with kinetic warfare, targeting critical infrastructure and even emerging domains like space assets. Adversaries are forming "Shadow Syndicates," blurring traditional lines.
- Future CISOs need three core skills: To succeed, CISOs must be Architects (deep technical and business fusion), Operators (business acumen and global awareness), and most importantly, Connectors (effective communicators, agents of change, and community builders).
- Space is an emerging attack surface: Organizations are increasingly reliant on space assets, yet this domain is poorly protected and understood by many CISOs, representing a significant future vulnerability.
- Talent development is critical: Addressing the "battle for talent" through initiatives that attract diverse individuals and offer purposeful work is essential for building a resilient cybersecurity workforce.
About the Speaker(s)
Bryan Palma is the Chief Executive Officer of Trellix. His career spans several significant roles, including an early CISO position for Pepsico in the early 2000s, where he experienced the role's initial challenges firsthand. Prior to his corporate career, Palma served as a special agent with the Secret Service in the late 1990s, where he was involved in investigating the first email threats against the president, highlighting his foundational experience in cybersecurity and national security. He is a strong advocate for the CISO community and the importance of collaborative defense.
Harold Rivas serves as the CISO at Trellix. With extensive daily experience in the field, Rivas is presented as a vanguard of the cybersecurity profession. He is deeply involved in managing cyber risk and is a proponent of the "Cyber Titan" concept, emphasizing the private sector's crucial role in global security. His insights into the evolving threat landscape, particularly nation-state activities and the importance of space assets, reflect his practical understanding of the challenges faced by modern cybersecurity leaders.