creating a security champions’ network at diageo · john haren head of information security...

20
John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Upload: others

Post on 17-Mar-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

John Haren Head of Information Security Governance, Risk & Compliance

Creating a Security Champions’ Network at Diageo

Page 2: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Our Core Brands

Page 3: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

A little bit of theory……

•  Distributed Network of ‘Accelerators’

•  Change agents

•  Facilitates Rapid Change

•  Supporting

understanding

Page 4: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

What were we up against?

Page 5: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Symbiosis

A Security Champions’ Network - Creating a win-win situation

Page 6: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Identify the end game – SMART Objectives

Be ambitious

Page 7: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

The Approach: Start with Top Down

1.  Identify the stakeholders and

the benefits for each

2.  CTO Support

3. Regional IT Support

Page 8: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

The Approach: Start with Top Down

4. Line managers’ support 5. Sell it to the potential champions

Page 9: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Champions’ Network now in

place : Bottom up

•  40+ Security Champions across 21 markets

•  The model for other global policies

Page 10: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Tools of Engagement

Page 11: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Issues we encountered

•  Culture •  Language

•  One solution size does not fit all •  Pockets of weak engagement

Page 12: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Issues we encountered

Page 13: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Continuous Improvement •  Train your

champions! •  Use formal goals •  Share key learnings •  Refresh the network

•  Demonstrate tangible value to the business

Page 14: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo
Page 15: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo
Page 16: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo
Page 17: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo
Page 18: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo
Page 19: Creating a Security Champions’ Network at Diageo · John Haren Head of Information Security Governance, Risk & Compliance Creating a Security Champions’ Network at Diageo

Key Take Aways

Takeaway 2: Gain support from senior management first

Takeaway 3: Empower your champions

Takeaway 4: Build the program into champions’ annual targets or development plans

Takeaway 5: Actively drive continuous improvement

Takeaway 1: Aim for a Win-Win situation