“At the core of the relationship between an accountant and a business is – trust. Trust that you’ll be given correct accounts, the right advice and that your most closely held financial and organisational data will be given all due care and responsibility,” says James Dickinson, CIO of BDO New Zealand. It is this backdrop that BDO New Zealand embarked on an ambitious programme of enhancing its cyber defences and controls, says Dickinson. Before this, he presented to the board a comprehensive cyber posture assessment of the organisation, and emphasised the need for an independent review of the BDO cyber position. The cyber strategy plan was delivered and its components included the implementation of enterprise Privileged Account Management via CyberArk and RDM; implementation of enterprise wide AlienVault SIEM; cyber awareness training and automated self-phishing campaigns via KnowBe4, standardisation of 1100 desktops onto centrally managed ESET endpoint AV (from MS solution), and single pane-of-glass visibility into everything via Slack. “This all appends our prior investment in fortigate next gen firewalling and wifi, all managed centrally from FortiManager and FortiAnalyzer for threat hunting,” says Dickinson. He says the business and technical integration of the programme has largely gone well. “Most importantly, our users are responding positively to this new paradigm.” The board has responded positively to this change and to a large extent was the driving force behind their investment in this area. Affecting change is always hard but the leadership shown by our board and influential partners has filtered down, he says. On the technical side, he says the team faced immense hurdles as they implemented the scale of change across BDO’s vast IT estate. “My team are encouraged to challenge me, collaborate and make good independent judgement calls, safe in the knowledge that I’ll back them up. The result is a tight knit group who work well together to deliver exceptional outcomes. “The innovations in-and-of themselves are tried and true solutions to the enterprise security problem that avails the modern organisation,” says Dickinson. “For a professional services organisation whose success revolves around trust – reputation is everything. The investments we made; technologically, operationally and culturally – hold us in very good stead relative to our market competitors we believe. This is a compelling competitive advantage in this day and age of prevalent and persistent cyber threats,” Dickinson says. “This biggest lesson I have learnt, and one I espouse regularly, is to have a plan; B, C, D, E, Fhellip;as you’ll be astounded how often you have to go really deep into your contingencies in order to get the job done,” he says. Closely related to this is the need to build and maintain a vast network of contacts, he says. “You never know when you are going to come unstuck and need to reach out to someone you’ve previously met for advice, a favour or to solicit help on a project. “We can’t all be experts in everything so take the time to broaden your network and make it known that you are only more than happy to offer advice and support in areas where you are strong. In the hope that good karma will come back to you when you need it most.” Related content feature Key IT initiatives reshape the CIO agenda While cloud, cybersecurity, and analytics remain top of mind for IT leaders, a shift toward delivering business value is altering how CIOs approach key priorities, pushing transformative projects to the next phase. By Mary Pratt May 30, 2023 10 mins IT Strategy IT Leadership opinion Managing IT right starts with rightsizing IT for value While there are few universals when it comes to saying unambiguously what ‘managing IT right’ looks like, knowing how to navigate the limitless possibilities of IT is surely one. By Thornton May May 30, 2023 6 mins Digital Transformation IT Strategy IT Leadership analysis 5 domande difficili alle quali ogni leader IT dovrebbe rispondere Una leadership forte è fondamentale per il successo dell’IT e ciò non andrebbe mai dato per scontato. Al contrario, un’auto-riflessione continua, da parte degli interessati, è essenziale per capire se è giunto By Thornton May May 29, 2023 6 mins IT Leadership feature Red Hat embraces hybrid cloud for internal IT The maker of OpenShift has leveraged its own open container offering to migrate business-critical apps to AWS as part of a strategy to move beyond facilitating hybrid cloud for others and capitalize on the model for itself. By Paula Rooney May 29, 2023 5 mins CIO 100 Technology Industry Hybrid Cloud Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe