Harvinder Gill, Vice-President - Cyber Security, State Street talks about the work done by them in the security domain, key challenges to security of large organizations, new technologies that are in focus to help aid security professionals in doing their work, solutions they have implemented within their organization to alleviate security challenges and their plans to enhance security of their organization going forward.
1. Please tell us about yourself and the work you are currently doing in the security domain.
As the Vice President of Cyber Engineering at State Street, I lead a team of passionate and talented cyber engineers. Our mission is to provide cutting-edge security services that safeguard and empower the business objectives of our global financial services company. With over 18 years of experience in the security arena, I hold the prestigious CISSP and CISA certifications, along with an MBA degree and a product management certification from ISB. Currently there are different program that I am directing which are in the field of making the applications MFA and SOX compliance using engineering practices. I am also working toward building and streamlining the Identity and access management solutions for the enterprise.
2. What are the key challenges to security of large organizations?
The security challenges faced by large organizations vary based on their maturity level. Let’s explore some key aspects:
As organizations progress toward modernization, alignment becomes crucial. Ensure everyone is on the same page to avoid silos and redundant technologies. Legacy systems often hinder scalability and agility. Navigating complex regulatory landscapes (e.g., GDPR, HIPAA) is resource-intensive but essential. Compliance efforts are vital.
Insider threats pose risks. Balancing trust and vigilance is critical. Organizations rely on external vendors and partners. Ensuring their security practices align with yours is vital. Regular assessments are necessary to address supply chain vulnerabilities. Weaknesses in vendor security can impact your organization. Vendor assessments are necessary.
Educating employees about security best practices remains a priority. User awareness is crucial.Remember, addressing these challenges requires a multifaceted approach.
3. What new technologies are in focus that help aid security professionals in doing their work?
Security professionals must adapt to emerging technologies, especially Artificial Intelligence (AI), Machine Learning (ML), and Generative AI. The technology landscape evolves rapidly, impacting how businesses solve problems. Anticipating future threats is crucial; what we handle today will differ significantly from challenges five years hence. Staying informed and agile is essential.
Additionally, focus on the following areas:
1. Strong Identity and Access Management (IAM): IAM forms the backbone of Zero Trust and cloud security. Ensuring robust access controls and authentication mechanisms is paramount.
2. Securing Developer Environments: Code quality matters. Security professionals should emphasize clean, secure code practices to prevent vulnerabilities.
3. User Behavior Analytics: Monitoring user actions helps detect anomalies and potential threats. Behavioural insights enhance security.
4. User Awareness: Educating employees about security best practices remains critical. A vigilant workforce contributes to overall resilience.
Remember, adaptability and continuous learning are key in the ever-evolving field of cybersecurity.
4. What solutions have you implemented within your organization to alleviate the security challenges?
As a security professional, I champion the “security as code” philosophy. My strategy revolves around empowering engineering teams to tackle security challenges effectively. Here are the key pillars of my work:
I’ve developed custom tools that assess control effectiveness, dynamically test security measures, and provide continuous monitoring. These tools enable proactive security practices. My focus lies in securing critical assets and applications, ensuring robust, multifactor authentication to maintain their integrity. Securing CI/CD pipelines is paramount; I ensure that code deployment processes remain resilient against threats. Additionally, I keep a vigilant eye on vulnerabilities, reporting them in real time, and swiftly addressing critical issues. Device security is non-negotiable; I create digital footprints for all controls, enabling intelligent analysis.
In the ever-evolving landscape of cybersecurity, adaptability and continuous learning are our greatest assets.
5. What are your plans to enhance security of your organization going forward?
As organizations prepare for the future, several strategic imperatives come to the forefront. Resilience remains a cornerstone, ensuring continuity even in the face of disruptions. Organizations must build robust systems that can withstand unforeseen events. Automation is another critical pillar; it streamlines processes, reduces manual effort, and enhances agility. Efficiency, too, plays a vital role—achieving more with fewer resources is essential.
User awareness remains a priority. Educating users about security best practices is crucial, especially in mitigating phishing incidents. By fostering a security-conscious culture, organizations reduce susceptibility to social engineering attacks.
In the ever-evolving landscape of technology, scalable security is non-negotiable. Whether it’s cloud adoption, IoT, or AI, our security framework must adapt seamlessly to changing environments. Additionally, with the rise of generative AI, protecting customer data becomes paramount. Anticipating novel threats and developing robust defences are imperative.
Lastly, metrics-driven security provides visibility into effectiveness. By defining and tracking relevant security metrics, organizations guide decision-making, highlight areas for improvement, and demonstrate their commitment to security excellence. Collaboration and strategic foresight will drive success in this dynamic landscape.