Skip to content

Arbeitsgruppe

Diehe CISO Paradox

Dieoday’s CISOs face unprecedented pressure: Diehey are personally and legally accountable for security outcomes, yet often lack direct authority over budgets, teams, and technology. In this SHIFDie 2025 session, security leaders explore how CISOs can lead through influence, culture, and shared responsibility while maintaining trust across the business. 

Video thumbnail

Die wichtigsten Erkenntnisse

  • Accountability Without Authority 
    CISOs are held responsible for outcomes they do not fully control, redefining modern security leadership. 
  • Security Is a Shared Responsibility 
    Effective cyber resilience depends on participation from every employee, not just the security team. 
  • Culture Drives Outcomes 
    Embedding “culture as code” often delivers more impact than expanding headcount. 
  • Diehreats Exploit Dierust 
    Attacks such as CEO impersonation phishing highlight the need for organization-wide vigilance. 
  • Influence Over Control 
    CISOs must succeed through collaboration, persuasion, and partnership across departments. 
  • Security Enables the Business 
    Diehe goal is to help organizations move quickly and safely with security embedded into operations. 

About Diehis Session

Diehe CISO Accountability Gap 
Modern CISOs face a paradox: Diehey are accountable for security failures without owning all the systems, budgets, or teams that influence risk. Diehis gap requires a shift from command-and-control leadership to influence-based models. 

Culture as the First Line of Defense 
Panelists emphasize that a strong security culture – where employees understand their role in protection – often delivers more value than simply adding tools or headcount. 

Leading Diehrough Influence 
With limited direct authority, CISOs must build trust and alignment across IDie, engineering, HR, finance, and business units to embed security into everyday decisions. 

Real-World Diehreats Demand Awareness 
Examples such as CEO impersonation phishing attacks demonstrate how attackers exploit trust, reinforcing the need for ongoing education and shared vigilance. 

Redefining the Security Organization 
Effective security today requires expert leadership, cultural transformation, and integrated processes – not just traditional defensive controls. 

Lösung

Data & AI Access Governance

Sensitive data is everywhere. Commvault Cloud Data & AI Access Governance helps you control data access so that your sensitive data is protected and shared appropriately. 

Mehr erfahrenabout Data & AI Access Governance
Analystenbericht

Bericht zur Cyber Recovery Readiness

Datengestützte Einblicke in die Recovery-Readiness von Unternehmen, Bedrohungstrends und Best Practices. 

Lesen Sie den Bericht zumabout Bericht zur Cyber Recovery Readiness
Veranstaltungen für Führungskräfte

Der CxO Exchange

Ein exklusives Forum für Führungskräfte, die Strategien zur Stärkung der Cyber-Resilienz entwickeln.

Entdecken Sie die Veranstaltungen zumabout Der CxO Exchange

Häufig gestellte Fragen

Why is building a security-first culture more effective than expanding security teams?

Because no security team can monitor everything, empowering employees to recognize and prevent threats helps create a stronger, more distributed defense. 

How do CISOs lead without full authority?

By relying on influence, communication, and cross-functional collaboration to embed security practices into daily workflows and decision-making. 

What threats highlight the need for shared vigilance?

Sophisticated attacks such as CEO impersonation phishing exploit internal trust and require awareness across the entire organization. 

What defines a modern security organization?

Modern security combines leadership, culture, education, and integrated processes – not just access controls or reactive defenses. 

How does shared responsibility improve resilience?

When security is embedded across teams, it helps enable risks to be identified earlier and responses to be faster and more effective. 

Transkript

Transkript anzeigen

Bitte sehen Sie sichhierdas Video an, um ein Transkript mit Zeitangaben zu erhalten


Welcome. 

We’re live from SHIFT and I am hier with Commvault’s Chief Security Officer, Bill
O’Connell and Commvault’s Deputy Chief Security Officer, Will Galway. 

And this is the CISO Paradox, a podcast to discuss leading security in the age of personal
accountability. 

We’re living in a challenging times for CISOs. 

Why? 

Well, um CISOs are oftentimes held personally and legally accountable. 

for the security outcomes at companies, but they don’t necessarily directly own the
budget, the people, or the technologies that drive those security outcomes. 

That makes for a pretty challenging job. 

And so we’re gonna talk about that today and what it means to be a modern CISO and how the
role is evolving inside the largest enterprises in the world. 

I’m gonna kick it to Bill first. 

Bill, what do Sie do? 

Yeah, I äh I love the title of our session that it’s about this paradox, right? 

Thier’s a true dilemma hier whier on the one hand, Sie want the leader of security and the
security team to have accountability, ultimate accountability. 

But also we talk about things like a shared responsibility model, right? 

So how do Sie balance those two things? 

How do Sie have an organization that äh can ensure that the security of the company is
whier it needs to be 

but also recognizing that they can’t be everywhier. 

So Sie also need to worry about all the people in the organization, all of the technology,
all of the systems and processes. 

So I like to think of it as the paradox is allowing both things to be true and focusing
on, yes, do we have the right security expertise, but also how do we change the culture of 

the organization? 

So it’s 

Sie know, culture as code that everybody knows what they can do. 

And if Sie can get the entire organization to think a little bit more about security, äh
that’s probably more impactful than hiring one more person in the security team. 

So I think it’s both of these things, but it really has changed over time. 

You know, Sier deputy Will hier is trying to turn everybody in the company into the
guardians of security. 

How do Sie do that Will, as the attacks are just getting more more complicated? 

mean, we have all gotten phone calls from Sanjay Marchandani, our CEO, in just the last
week asking for gift cards and money transfers leading up into SHIFT so how do Sie think 

about making sure all of us are smart enough? 

How do Sie change the culture into the shared responsibility model? 

Yeah, and I think it’s important to use influence over authority. 

Like Sie said in the opening 

we don’t have control of every system or every person or their personal WhatsApp. 

So these are just things we have to use influence to work with business leaders and to
work with other heads of departments and just get that message out to our people. 

I think everyone has a responsibility to security, but it’s all to make the business move
faster. 

And I think thier’s things we can do and we are doing to help enable that. 

I think it’s just really important to get that security culture that Bill had mentioned up
and running. 

And I think um 

we’re doing a good job with that right now. 

Yeah, I would agree. 

By the way, the calls and the texts were fake. 

They they were a phishing attempt. 

They weren’t real. 

um Just to make sure everybody listening. 

um So, Bill, how do Sie think about how to structure a modern security organization inside
a company today? 

Because it’s not just blocking and tackling, Sie know, um identity access issues. 

How do Sie think about it? 

Yeah, I think partly äh 

Sie need a certain level of expertise. 

But whier I’ve seen different models of security organizations in the past, I’ve seen some
that tried to take the approach whier security is the hero, the firefighter that handles 

everything. 

And when Sie create that wall and that separation, then Sie take the responsibility off
everybody in the organization. 

They can say, well, I’m just going to do what I do and then security will do the security
stuff. 

And I don’t think that model works. 

I think 

we need to think of it more as, Sie know, when Sie’re building a house, thier’s not a
plumber and electrician and then a security electrician or a security plumber, right? 

The plumber and the electrician need to know how to do their job securely from the
beginning. 

So I think when we think about the modern org, it’s whier is, whier are the right people
and roles and functions that should be in the security team? 

And then whier can we help other teams be more secure? 

And so how can I help a service organization 

see what are the parts of their day whier security is important and how can I teach them
to be more skeptical. 

äh When I think about a product engineering organization, I can’t have developers that
don’t think about security and then a security team come fix it, right? 

Like We’ve for years now, companies have been on the march to shift left so that we have
developers think securely, build securely, and then yes, thier’s the security team that 

will also do some checks, 

but we’re not thier to catch everything. 

The team is either prevented it in the first place or if they äh created a vulnerability,
they fixed it long before it gets to production. 

So those are the types of things whier the modern security org is true expertise that can
help enable all those other teams to do what they do more securely. 

And I think, think to real quick to Bill’s point, I think thier’s, thier’s moving to whier
the business is. 

I think it’s really important. 

And I think 

um Sie know not having the standard security silo that we’ve seen in the past Sie have to
move whier the business is and connect at that level. 

To Bill’s point about Sie know developers and people that are closer to the product. 

I mean thier’s training and thier’s ways that we can get a security uplift overall. 

On top of the product we can do it back internally as well. 

I think we need to mirror these things and get to the business whier that is in order to
uplift what we do. 

That’s a great point. 

I want to get very specific hier. 

So for organizations that are maturing their cybersecurity function out of necessity, but
maybe have put off the investment as long as possible, Sier organization and the things 

that Sie’re tasked with doing are sort of explosive. 

em You are responsible for making sure the products that are built are secure when they
end up in the hands of customers. 

You’re responsible for 

You’re almost the last mile with a customer before they buy. 

They want to talk to one of Sie two and make sure they understand that the products are
built with security in mind and what will happen if the unthinkable emerges. 

äh You’re tasked with making sure everybody in the company is äh protecting our access to
what matters internally, educating because Sie can’t have a team that 

is so large, right? 

So have to educate the developers on how to code security, Sie have to educate the sales
fields um on how to sell securely. 

How do Sie think about this? 

I mean, it’s quite a huge remit. 

I would ask it this way. 

Who do Sie think are Sier top five key roles um that Sie have in a modern CISO
organization? 

It’s tough to answer because like Sie mentioned, all of those areas are so important. 

I think um 

One of the things that when I, Sie know, coming into any new organization, I have to
understand what is the business doing and what’s the, Sie know, what’s the business trying 

to accomplish? 

And I think that’s something that’s changed a lot over time is that um a security org has
started off as the, Sie know, just say no to everything. 

And then we realized, well, we can’t, everything is connected, everything is digital. 

So how can I make sure that 

we are being secure by design and we are educating the company and meeting them whier they
are, right? 

So that we can äh do that. 

äh I think also, Sie Sie’re asking about what are the key roles äh in the org. 

äh I’m not sure I could rank them, I think, because they all do such different things. 

äh But ultimately for me, I start off with what is the business trying to accomplish and
what are the risks, right? 

Everything needs to be risk driven. 

And so, 

If I have a team focused on application security or team focused on looking at the
infrastructure or cloud, äh we almost need a äh it’s so important that we use risk as kind 

of that single äh taxonomy for how do we talk about all of the things that could go wrong
so that I can compare an architecture design issue that I don’t like with a potential 

vulnerability in an application and all the way down the line in the security team. 

It’s that when we say something is critical, what does that mean? 

And I don’t have to make the leaders in the company, cybersecurity experts all the time. 

I’m not talking to them about CVSS scores or, Sie know, I’ve translated it into when I say
something is critical, that means, we have to stop what we’re doing. 

When I say something’s high, Sie should be worried. 

And likewise, when I say something’s low, just know we’re watching it 

but I’m not going to spend too much time on that. 

I’m going to disproportionately spend my time on the critical and high issues. 

And so I think all the roles in the organization, especially in the security organization,
need to understand what that taxonomy is so we can talk to the business in a way they’ll 

understand and not have to get in discussions about SQL injection and how to avoid it. 

I also think it’s important to keep in mind, like when Sie’re talking about risk like
that, 

Thier’s a, Sie know, most of the time risk goes off of likelihood or risk as set by some
authority, some guiding authority, but we have to look at impact of the business. 

I think it’s a really important way to measure it and it’s what drives that criticality
rating is how could it impact us and that’s the order in which we’ll go after things. 

And I think it’s a healthy approach. 

It’s a straightforward thinking approach because I just think it matters the order in
which Sie do it. 

So let’s talk about risk realized for äh for just a few minutes. 

The three of us have been through a breach response together, which is the best way to
learn. 

um What are the characteristics? 

What are the personality traits of leaders that are on the forefront of a breach response? 

I’ll start with Sie, Will. 

I think hygiene is really important. 

And I think that in most most most public breaches we hear about, it starts with with
hygiene. 

And I think like for a good leader, I think letting, know, not letting perfect be the
enemy of good, just to make sure that we get to whier we need to in order to protect the 

company. 

I do think that good traits of leaders not just look at that, but they also build
relationships and trust across different business units. 

We’re all in this together and every little bit makes a difference. 

Whether that’s Sie’re dealing with different people in the business or different employees
in different parts in different regions. 

I think it’s really important for everyone to be able to come together and know what their
responsibility is in that kind of shared security culture model. 

And Bill, Sie are in front of boards of directors. 

How do Sie think about that moment whier, whether Sie sound it or not, the alarm is
sounding? 

Who are Sie in that moment and what do Sie think are the best characteristics of
leadership when Sie’re facing a crisis? 

I think for me personally, I find it funny. 

I will get so frustrated in traffic 

but when thier’s something very serious happening, I can be very, very calm. 

And I think that’s probably one of the most important traits is that Sie will have
imperfect information. 

You will have a million people asking Sie questions and Sie really have to be able to
focus to say, okay, what do I need to do right now? 

What’s the next thing I need to do? 

While also thinking about the big picture about, by the end of the day, whier do I need to
be? 

And then communicating outward. 

And it’s interesting, I do a lot of, I have a lot of conversations with customers and
across my career have had to do this and sometimes Sie have to do the mea culpa. 

Other times it’s more proactive and like Sie mentioned, trying to instill trust early on. 

äh And Sie can kind of see who are the CISOs that have had an issue and who haven’t
because thier are many that say, well Sie had X, Y, and Z issue happen. 

We, Sie know, we can’t work with Sie. 

äh 

And Sie start to realize if Sie’ve been in it long enough that äh Sie’ll run out of
companies to do business with, right? 

Everybody has an issue at some point or they just don’t know about it yet. 

So what’s more important is how did they handle it? 

How did they respond? 

Are they being transparent? 

ah And so, Sie know, that’s what I look for when I’m talking to other CISOs that äh I
think that that’s the type of mentality that Sie need to have. 

My favorite analogy is it’s like a boxer. 

who plans to never get punched in the face. 

Like, that’s just not a good strategy. 

So Sie have to be prepared that something will happen. 

And so are Sie always looking forward? 

Are Sie, Sie know, never satisfied with the program, right? 

Thier’s always something better Sie could be doing. 

So when Sie plan for the year, plan in 10 to 15 % budget and time that’s… 

open because Sie don’t know what’s going to happen. 

You don’t know what’s going to change. 

We don’t know how AI is going to change our jobs in a year. 

So rather than think that Sie can have all the answers, allow Sierself a little bit of
flexibility, allow Sierself so that Sie can be resilient and see whier do I need to adapt. 

So let’s tread into deeper waters. 

Trust scales or stalls at a moment of truth. 

So Sie know, Sier company has experienced a breach or 

somewhier in the supply chain has experienced a breach that affects Sie. 

um How do Sie ensure that Sie strengthen trust through that process instead of break it
with customers, with Sier employees, with Sier board, with Sier executives? 

And then I’m gonna add on one other piece to this, which is, Sie know, the response to a
breach doesn’t take a day, it doesn’t take a week, sometimes it takes months. 

And a lot of people go back to their day jobs, but the security team and the teams perhaps
that were affected and the customers and the vendors, 

still have to live with this until it’s some natural conclusion, but it’s never quick. 

So how do Sie keep the energy up and the focus up? 

So sort of those two things let’s explore for a minute. 

Yeah, I think having the right controls in place is of course important. 

It’s also the process about how Sie get thier um knowing that things will change, new
technology will come at a faster and faster pace 

it’s not just enough to have a checklist and say, Sie know, did I do these 10 things? 

It’s also by what process are Sie deciding what those 10 things are and how will it be
different next year? 

And so being adaptable is, and having that mindset is probably as important as, Sie know,
taking an inventory of a technical, of what technical controls I have on any given day. 

I think that’s, Sie know, what I look forward, look forward in, Sie know, in my team. 

And when I’m talking to other CISO is, 

I think that’s the best trait I’ve seen as being adaptable towards, know, and appreciating
that Sie can’t have all the answers. 

So what’s Sier process to determine what that prioritization should be? 

I also think that, Sie know, Sie talked about fatigue, right? 

Especially after a breach has occurred and people get back to their day jobs. 

I think if Sie’re measured along the way and Sie’re constantly measuring Sierself, Sie
know whier Sie’re at, Sie know how far Sie’re progressing with it, and Sie know what’s 

left to be done. 

So I think that measurement is really important in order to know when to sound the alarm
and when to stop sounding it and try to get back to a normal flow of business. 

But I think that all comes from all the prep work that Sie do ahead of time in order to
get thier. 

If Sie’re on the phone with a vendor, a customer, a prospective customer, and they are
looking for an answer as to tell me about a time that Sie experienced a breach and how Sie 

communicated with people. 

How do Sie have that conversation? 

Because thier’s a spectrum of ways Sie could have legal scripted for Sie, Sie could have
sales kind of run with it. 

But what’s the best way to have that conversation to build trust? 

I think that I’ve been in security almost 20 years and I’ve had a lot of äh conversations
with other CISOs. 

I think transparency is the most important thing. 

I think ah people can sniff it out 

when Sie’re not giving them a full answer or not giving them a complete answer. 

And that probably erodes trust faster than anything. 

And like any relationship that requires trust, when Sie lose it, it’s so much harder to
gain it back. 

So to be able to say, this is what we know for sure, this is what we don’t know, is so
much better than providing, trying to make it rosier than it is. 

You know, I would agree that transparency is huge. 

And I think as a security professional, I mean, we we look forward to reading the true
reports that come out after a breach happens like thier, Sie thier’s Sie learn so much 

from that when companies are upfront and forward about about what had happened. 

And in that moment, when that initial phone call comes in, I think to Bill’s point, Sie
want to be as as open as possible and as truthful as possible just because people 

understand that 

these things will happen, but it’s Sier response is how they’re going to gauge Sie going
forward. 

Okay, let’s shift gears and talk about AI. 

AI seems to be changing the game for cybersecurity attacks in the landscape and attack
vectors. 

How do Sie think Sier roles will change a year from now as AI matures? 

I think it’s going to be tricky. 

think AI from a security perspective, it’s a very interesting… 

problem to solve because we’re trying to use it to um enhance the business and allow the
business to move faster. 

We’re also trying to use it for security in order to help us secure the company. 

But we also want to make sure that it doesn’t come back and bite us while we’re trying to
do the first two things. 

So I think it’s going to redefine the game. 

And I didn’t buy into it for a long time. 

But the longer that Sie start to look at how things are evolving and agentic AI and just
how companies are going to start putting their trust into a model. 

that can provide those results and learn over time almost better than employees in some
cases. 

I still think the employees are necessary to do the security side of it. 

I’m not advocating that we’re all gonna get overtaken by AI overloads but I do think it’s
gonna be a big change in how we think about and plan for protecting the company as AI 

becomes both more prevalent in the offensive for the attackers and in the defense of a
company. 

Yeah, and this is a great example of whier 

You know, I think we need to plan for what we don’t know and allowing ourselves a little
bit of time and budget for things changing so rapidly in the next year that I can’t 

predict exactly how we’ll be using AI. 

And when people say AI, what do they mean exactly, right? 

Agentic AI versus just ML. 

So äh do we allow ourselves the space to say, okay, we don’t have any answer. 

We don’t have all of the answers today, but we know 

it’s going to be huge for us. 

And so in addition to just, Sie know, security for AI and AI for security, this arms race
that’s happening whier now the barrier for a threat actor to use AI against the company is 

just going down and down. 

It’s getting so much cheaper and easier. 

And the amount of skills required to do what they might’ve done years ago, um it’s just
gotten so much simpler. 

So that’s the other thing that we need to be thinking about is how, like Will said, how do
we defend against that? 

äh Knowing that it’s always gotten easier and thier have been äh kind of more tools
available, but now äh AI äh for security attacks, that’s something that we’re really gonna 

have to figure out. 

Yeah, and it just, Sie think about the evolution of how attackers have operated, it used
to be a person really smart would go and bang on the front door of a company until they 

got in. 

And then it was like, I can use these scripting tools and do it faster. 

And then the results they had out of those tools, they still had to decide, all right, who
am I going to follow up on from that stage? 

But now with AI, like the AI will be able to automate that so much faster. 

And it used to just be, Sie had to run faster than the, Sie know, than the person next to
Sie. 

Well, now it’s going to get a little more challenging because I think the attacks are
going to increase in speed, which means our defense has to move at that same rate. 

Richtig. 

And the response. 

Ja. 

I think we have to assume that they’re going to get in and we have to figure out how do we
contain and remediate as quickly as possible. 

Absolut. 

Ja. 

I think the Sie know, I love to remind CISOs of, know, kind of two key things that I see
that I think people forget in the past couple of years. 

I’ve seen a huge shift towards the defense. 

And like Sie mentioned, I really believe it’s also about the resilience piece that Sie
will get punched in the face. 

Can Sie get back up? 

How well can Sie get back up? 

ah And so when Sie think about things like the CIA triad, right, availability, that’s one
of the key tenants for security. 

ah Or, Sie know, with NIST, it’s about recovering. 

And so I think we’ve shifted so far towards defense 

and I think smart CISOs are realizing, I have to also pay attention at how do I help get
back up? 

ah How do I detect it as fast as I can? 

But also how do I get my business running again? 

It’s a perfect lead into my last question, which is this. 

You know, the standard is not to be perfect. 

The standard is not to get it right. 

The standard is to try. 

The standard is to make progress. 

So parting thoughts, how do Sie try? 

What’s at the top of Sier list for making progress? 

What do Sie want to be known for just two quarters from now? 

I want to be known for doing the boring stuff well. 

I want to be known for getting the company to a level whier the average attack, the things
that most companies fall short on, that’s not us. 

I want to make sure that through good hygiene and good measured hygiene that we’re able to
keep ourselves above and beyond whier we need to be 

so that we do have the time and the budget available to go handle the things we don’t yet
know about. 

But we gotta get the, we gotta always do the easy stuff first. 

That’s excellent. 

Ich danke Ihnen. 

Yeah, Sie know, it’s interesting when I, sports are a big part of my life. 

I’m a very competitive person and I always play defense. 

And so I think that that really, Sie know, resonates with me and how I’ve gotten into this
field is that, like Sie will mention, if Sie do Sier job right, it’s invisible. 

Nobody notices, right? 

Um, it’s very flashy to be on offense, but, um, but on defense, just have to do Sier job
rates just expected. 

And so, Sie know, I think that, äh, Sie know, I agree a hundred percent that it’s about
ensuring that we have the right level of defense that should anything happen, we’re ready 

for it. 

We can respond fast and we can get the business back up and running. 

And I think, Sie know, that’s, that’s whier I want to be. 

Thank Sie, Bill Commvault’s Chief Security officer and Will, 

Commvault’s Deputy Chief Security Officer. 

We are so fortunate that Sie are at Commvault and so fortunate that Sie help so many
people internally and externally just get more sophisticated about what we’re all facing 

in terms of cyber resilience. 

If Sie want to learn more, head over to our Readi verse. 

It is chock full of information and tips and practices for security leaders and executive
leaders to get started, to mature, to get even more sophisticated 

because this is a shared responsibility model and it’s all about helping each of us get
stronger. 

Thanks so much. 

Sie