Joan Goodchild
Contributor

Cancilla: Security Must Put Business First

News
Mar 24, 20097 mins

Baker Hughes CSO Russ Cancilla has been with the company less than three years. But in that short time he has transformed the oilfield services provider’s security operations from one that was fragmented to one with a converged approach under his leadership. Managing Baker Hughes’ risks for employees, resources and operations is no small task. The company currently operates in 94 countries, many in high-risk zones. But Cancilla, recently named a CSO Compass Award winner, gives us the details of why the new approach of his program not only secures the business, but also enables it.

Compass Award Winners: Security Leadership In Trying Times

What was your goal for security at Baker Hughes when you first started at the company?

When I came to Baker Hughes what I found was there pockets of security around the company that supported the operations. Then there was a traditional corporate security department. I saw that the two weren’t engaged very much and I concluded that we weren’t actually leveraging our skill sets.

We weren’t able to properly measure the performance of security people out in the field because the corporate guys weren’t doing anything with them. And, most importantly, I noticed that there seemed to be a perception that the corporate guys were the smart guys and then the rest of us slugs were just out here in the field doing our thing. I didn’t like that it didn’t feel like a team.

I thought that what we needed to do was create a more enterprise approach to security. As the CSO I wanted to have line of sight of what was going on with security across the company. So I wanted to have sight not only of the activities, but of our security people: What are their skill sets? How are they being developed? How are they being assigned jobs?

I also wanted to establish some standards or guidelines across the company. For example, if you went into Egypt our security program looked very different than if you went into Venezuela. I felt that we were probably creating some greater liability for the company, and exposure, by having fairly inconsistent security programs in place which nobody was really overseeing centrally.

What was your first step in accomplishing that enterprise approach?

I went out and met with people and did the kinds of thing s new leaders do. I was finding some of the people on the operations side of things did feel a little disenfranchised because there was this elite group of corporate guys that didn’t really interact with them that frequently. They didn’t feel they had a place to go if they needed some additional expertise on how to solve a security challenge.

So we created what we call enterprise guidelines that give the framework of how the Baker Hughes security would work around the globe. So when you go to country A or country B, the security components of the program are very similar, if not the same. However, how they are implementing and executing them may be different because of customs or profitability.

How did you develop the ideas about what that framework would look like?

It’s not like a Coca-Cola plant where it’s a plant so you have the same security protocols in place at all locations. We are out on rigs and in offshore locations. The question I had immediately is: How do we know what the risks are? In some countries I would ask the security personnel: “Why are you doing it this way? Why is your security program doing this?” And there was never really a good reason. The response was usually: “This is the way we’ve always done it,” rather than doing it consistently on a risk-based approach.

Did this enterprise approach involve some level of convergence between physical and IT security?

When I first came into this job as director of corporate security, IT security was not part of the security portfolio. When I interviewed for the job I explained to our CEO and the general council about the concept of the CSO and the theory of bringing together different disciplines of security and the benefits to doing that. I said: “I want to take an approach where, as head of security, I have influence over what goes on everywhere with security. I don’t need to have them all working for me, but I want to influence it.”

I also pointed to the IT security piece as largely influential of what we do in the protection of our intellectual property, and our access to our systems. I said I would like to see us migrate from director to CSO with all of those components rolled up under that title.

Was that convergence difficult?

It took us a couple of months to integrate the IT security piece into our portfolio. So now we have IT security and traditional physical security. I have a threat analyst and crisis management and a center of expertise for investigations in physical security. That is typically what some might think of as the corporate security team. But they are actually much more engaged with the operational security guys. They are the expertise to allow the operation security guys to avoid some unnecessary cost with consultants. That’s not to say we don’t use consultants. But the person who takes care of physical security standards and guidelines now helps the guys out in the field.

According to the person who nominated you for a Compass award, you have made security a business enabler at Baker Hughes. How so?

I have this philosophy: We have to be seen as business people who happen to be experts in security.

If we want to be engaged by the business and have a seat at their table, we have to speak their language and demonstrate to them that we understand that security supports and enables and reduces the risk and helps them make money. We demonstrate that we know the principles by showing a return on investment in us. We do that with what we call cost avoidance.

So, for example, say our company is looking at a contract to work for Exxon Mobile. They have asked us to provide the services that Baker Hughes provides. Historically within the company, security would not be engaged in that conversation. After the contract was signed they would come to us and say: “Oh, by the way, we just signed a contract with Exxon Mobile in the middle of the jungle in Africa where there have been six coup attempts on the government. We need you guys to put security there so none of our people get injured.” Only then would we enter the picture and give them an idea of how much security operations would cost in the location. So security then became a business eroder.

Now, we’ve frontloaded our estimation into the system and we look at the security situation ahead of time and say: “This is what we think it will take to manage the security costs I this location.” We factor those in so when the contract is negotiated, security costs are considered and it isn’t a matter of security costs eroding profits on the back end.

Our group understands that Baker Hughes is not a security company. Our aspiration is not to have a best-in-class security program. Our goal is to have best-in-class people who operate a security program that is appropriate to manage the risk for the business.

Baker Hughes operates in 94 countries. Given the current state of global tensions, how difficult is it to protect employees now?

Assuming you’re not in an organization which can just throw money at it, I would describe it as it takes more management skill combined with good sound security skills. It takes a more measured approach than it ever has before because the risks are greater. Security has to do a very thorough analysis to understand much better than before what the risks are today.

Joan Goodchild

Joan Goodchild is a veteran writer and editor with more than 20 years of experience covering cybersecurity, technology, and business strategy. She is the former editor-in-chief of CSO and has contributed to leading publications including CIO, Dark Reading, and SC Media. Joan has partnered with global security companies to produce thought leadership content, executive communications, and industry research. She is also the creator of CyberSavvy Mom, a consumer-focused brand that helps families be smart, secure, and civil online.

More from this author