Chief security officers are starting to lose their executive management influence. The chief security officer position became popular after Sept. 11, 2001, when many CEOs and boards made security and business continuity, rightfully, their top priority. Many of these newly appointed chief security officers had physical security or law enforcement backgrounds, rather than technical or business backgrounds, limiting their interaction with executive management to security policy and status updates on vulnerability assessments. In short, chief security officers often have little to offer at board meetings, when business strategy, revenue growth and productivity enhancement are discussed. Instead, they are subservient to the CIO, who is often key to fulfilling corporate initiatives and achieving business goals.
Many chief security officers were put in place primarily as a means for CIOs to “CYA” (as in Cover Your A**). That is, if something on the security front blows up, the CIO can say, “That’s the chief security officer’s responsibility, not mine.” And, unfortunately for chief security officers, the situation is only going to get worse.
In my last column , I discussed the concept of trusted networks, a major shift that is occurring in the network security arena. Trusted networking is the trend toward increasing security features bundled into Ethernet switches and routers, rather than within network appliances. As the trusted networks market expands, a shift in suppliers will occur. Network security appliance firms are being forced to change their business models and cut deals with Ethernet switch firms, as the network becomes the platform to deliver security services such as access control and compliance tied to policy managers.
So how do trusted networks affect the chief security officer? Think about IP telephony for a second. Before IP telephony, the telecom manager was in charge of enterprise voice communications. But as the role of the PBX has diminished, so too has the telecom manager’s influence. The network architect and designer now have influence over enterprise voice decisions. This shift in power over architecture, design and purchase influence has huge implications for suppliers. In the case of IP telephony, many of the traditional PBX vendors lost their customers. Their salespeople no longer had the right contacts, and many were forced to seek out and court the new influencers. They had to learn new skills and master a new language. The same shift is occurring in the network security arena. Those suppliers who sold mostly to the chief security officer will find that the chief security officer’s influence is dwindling. They’ll get their first glimpse of this when the sales cycle takes a lot longer to close until it doesn’t close at all.
So as network security features increasingly move to Ethernet switch and routers companies such as Cisco, Enterasys Networks, Nortel, Extreme Networks, Foundry Networks, HP and 3Com, so too will influence flow to network architects and designers, leaving the chief security officer with one less thing to talk about at board meetings.
Lippis is an authority on corporate IP networking and consultant to CIOs of Global 2000 companies. He can be reached at nick@lippis.com. His Enterprise IP Communications Symposium will be held April 19-20 in New York. For more information, go to www.lippismedia.com.




