September 2019: In this month's edition, Anthony Robinson, Oceania Cybersecurity Leader at EY, shares his story.
September 26, 2019
Throughout 2019, this mini-series will interview leaders from around the globe to discuss areas of cybersecurity. The purpose is to help students and those new to the industry gain perspective and guidance from professionals in the field. These interview insights aim to kick-start or re-energise your career journey in cybersecurity. In this September edition, Anthony Robinson, Oceania Cybersecurity Leader at EY, shares his story about: His cybersecurity career and his concerns within the industry. How he evaluated professional opportunities during his career. His passion as a life-long learner. How he suggests others new to the field get involved. Robinson started his career consulting clients with general technology delivery and systems integration after earning a degree in engineering. “I always found myself enamoured with solving complex business problems that have never-before-been addressed or attempted. Early in my career, I would piece together cybersecurity elements to help create an appropriate solution. Today, I help Chief Information Security Officers (CISOs) and their management teams better: communicate their message to the business and their Board of Directors; depict the organisation’s cybersecurity journey to improve their risk posture; maintain the organisation’s momentum to continue to uplift the control environment with today’s continually changing goal posts; and convert the organisation’s program from being predominantly centred around maturity to a risk-based, data-driven approach to ensure investments are made to areas of the business that matter most. Cybersecurity was in its infancy in the early 1990's. Four years into my career as a consultant I began to specialise to separate myself from my peers. I explored many of the cybersecurity domains we know today, with application development as my fastball. This passion for complex problem solving has driven my 20+ year cybersecurity consulting career that includes over 80 clients and numerous sectors. One sector I wish I would have had an opportunity to explore was automotive manufacturing. This would have triggered my inner love and passion for cars. If I could pick one sector to have spent more time with it would be automotive manufacturing because of this admiration.” These are his insights. What aspect of cybersecurity concerns you the most? “ Understanding normal versus abnormal behaviour. Our biggest challenge is to improve our ability to sense when something is wrong before our adversaries are aware we detected and contained their movements. Working in cybersecurity has always been about defining and deploying controls with appropriate measures to counter threat actors. We continue to engage with clients who believe they have not experienced a large-scale cybersecurity incident…until they do. This consistent inability to sense when something is wrong is worrisome. We often see this pendulum for an organisation shifting quickly from generally-speaking: Everything is Okay We are improving and maturing our ability to defend against common attacks A threat actor is targeting our organisation The attacker is inside our environment We experienced a data breach The data breach made the front-page headlines We must continue to uplift and automate our cybersecurity capabilities to allow for humans to focus on more sophisticated actors and attacks. Thus, it is imperative to consistently improve organisation’s ability to sense abnormal behaviour and quickly react to maintain resilience. Misguided investment. We invest in technology and continue to misunderstand how this will mitigate our risk. We often do not have the structure or discipline to link investment to risk reduction. We invest in technology because our: peer organisations have made similar investment, and this worked well in their environment; or third party vendors are recommending we need the ‘latest and greatest’ to support our organisational needs. There is a great deal of investment in this ‘hope that technology will solve our problem’, and less about the expectation and knowledge of our organisation’s core fundamental issue. I am a strong advocate for better linkage and decomposition of risks with the actual capabilities and controls that will help support mitigation.” How have you evaluated professional opportunities throughout your career? How has this changed over time? “ Learning. I am going backwards if I am not continually learning, pushing myself or being challenged by others. With learning comes personal and professional development along with growth. For each opportunity I may ask: How much learning I will do today versus tomorrow? How does this help me prepare for a future role I may aspire to take on? How does this role allow me to explore personal growth opportunities? What are the challenges with the current opportunity? How may these challenges evolve in the future with the enhancements to analytics, machine learning, AI and eventually quantum computing? How will these challenges prepare me for a future role or opportunity? Train-the-Trainer. I have been fortunate to spend my 20+ year career in cybersecurity with two firms where I have worked with over 80 clients across numerous sectors. I was with my first employer for eighteen years and my current firm for the past four because of the tremendous growth and development opportunities each presented. I eagerly explored and allowed curiosity to drive my learning. Once I master a specific task I have a goal to pass this knowledge onto others. This enables me to take on the next role, project or client, and allows for the other individual to gain new experiences. I never aspire to be static. I always have my eyes on the horizon for the next complex problem to solve. People and mentorship. After a long, memorable and exciting 18-year career with my first firm, I moved on and into my current role as the Oceania Cybersecurity Leader at EY. This provided new learning opportunities to share knowledge and experiences gained throughout my career with our clients and our people. I am most satisfied when I have an opportunity to share an experience with our people, which provides them with tools to act on new knowledge and reap the benefits. We are a people-first organisation because without our people we do not have a business. Experiences and growth. My wife and I had an opportunity to transition from Australia to the United Kingdom and travel the world early in my career. We place a high-value on global experiences because of the unique perspective they provide that support our personal development. As we progressed in our careers we made the decision to return and watch our family grow up in Australia. When we evaluated opportunities we often looked at how they help us attain personal experiences and balance this with the professional growth opportunities to make the best life decision for our family.” What fuels your passion? Why do you do what you do? “ Strive for excellence. I am quite competitive and like to win. I tell our people we should aim to create the best cybersecurity team in Australia. I want our teams to strive for excellence and be the best. This drive to be excellent is part inherent and part learnt. Over my career, I have seen what happens when you lack the determination and perseverance to achieve excellence – you do an average job with a trickle-down effect to the business. I want our people and our teams to always feel proud of our accomplishments and achievements.” How would you suggest others new to the field get involved? “ Have patience. Early in my career I remember thinking ‘I want to be a Chief Executive Officer by the time I was 25’. While not impossible, it is difficult to have the perspective necessary to set yourself, and your teams, up for long-term success. If we apply this view to cybersecurity and survey non-IT leaders, they may say cybersecurity is niche and narrow; however, there is so much to learn and absorb across the domains. No one cybersecurity domain is more important than the other and can be challenging to obtain this knowledge without experience in the field. Prioritise your interests. Do not search for that perfect opportunity. Rather, spend the time and energy developing and striving for excellence in your areas of interest. You may find your areas of interest change over time, or that you deep-dive into a subject matter to continue to satisfy your curiosity. Stay flexible. I see some graduates and professionals with rigid career plans that often miss out on ‘once-in-a-lifetime’ opportunities. To be successful and effective is to make the most of every opportunity. Whatever you do early in your career you will gain invaluable experiences and learnings. You may experience challenges with a hard project, difficult client or working in a new area. This may create a level of discomfort but be prepared for this! We often learn most when we find ourselves in these demanding positions. Perform post-reflection exercises and ask internally about the key takeaway – we are often surprised with a sense of satisfaction and accomplishment for what we had achieved through these strenuous times. Be adaptable and resilient. Be comfortable not having all the answers. In some cybersecurity roles we are expected to have this knowledge to operate autonomously as the front-line defender. There are many other roles where we may not know everything about our client, their concern or a potential solution. We work in teams of experts with a wide-array of experiences to learn about their industry, to help define the root cause and to support the development of solutions that support our clients. We are customer-focused as consultants. We must quickly define needs and adapt how we operate based a client’s sector to be successful.” Cybersecurity is intriguing, in-demand and considered as an excellent career starter. Please be on the lookout for next month’s issue of Decoding Cybersecurity: Interview Insights with Leaders as the journey continues.