Q&A
Cyber Security Versus Physical Security: Smackdown!
Two former colleagues square off to debate the division of roles and responsibilities of security leaders.
By Scott Berinato
I get offended when I see the CSO title being captured. Why do they feel compelled
Spernow: Well, because George is right, and George is wrong.
Campbell: He used to say the same thing when he worked for me. [Laughs.]
Spernow: From the percentage of organizations that reflect your experience, George, you're right. But you represent only 5 percent of the population of folks doing any type of security. But because that 5 percent has high visibility, it represents most of what happens. That 5 percent gets the press, and as a result, the other 95 percent is struggling with trying to figure out how it's going to make its security stuff compatible with its infrastructure and IT culture, which primarily hasn't been focused on anything to do with security.
What most companies are doing is taking their best-case experience and saying, "We need to have somebody in charge of security." Then they go out and find somebody who is a former bureau agent with great physical security credentials and the stuff that they can relate to, and because he took one information security training course, he's also considered an information security specialist. So they hire him, and they task him with doing all the security.
I don't see the people who, according to George, call themselves CSOs but should be information guys only, because that's all they're actually doing. In fact I see just the opposite of what George sees. I see guys being hired as CSOs who are only doing physical security, because of their background, but are also in charge of information security.
Campbell: I absolutely agree that people like myself or these ex-bureau agents
george campbell
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



