Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

United Airlines CISO Deneen DeFiore on elevating cyber’s value to the business

Deneen DeFiore is a Hall of Fame technology executive who currently serves as vice president and chief information security officer at United Airlines, where she leads the cybersecurity and digital risk organization to ensure the company is prepared to prevent, detect, and respond to evolving cyber threats. She also leads initiatives on commercial aviation cyber safety risk and improving cyber resilience across the global aviation ecosystem.

When we spoke for a recent episode of the Tech Whisperers podcast, DeFiore covered a lot of ground, delving into the complexities of the CISO role, the tricky balancing act required to manage the day-to-day, and the leadership skills it takes to be successful in this profession. Afterwards, we spent some more time focused specifically on her communication playbook and how she shapes the narrative around cyber and its value to the business. What follows is that conversation, edited for length and clarity.

Dan Roberts: Why is it important for CISOs to be intentional about ‘telling the story’? If two cyber organizations are delivering the same value to their companies, but one is good at telling the story and the other is not, what difference does it make?

Deneen DeFiore: There’s definitely value in having the ability to tell the story that’s connected to the business outcomes around what you’re trying to do to manage risk. If you have two organizations that are protecting the company and doing what they need to do, the one that’s not able to tell the story is operating at almost a technical level. They’re doing good things and driving good outcomes, but if they’re not able to connect the dots with the business outcomes, they’re going to stay at that level of entitlement. It’s going to be harder for them to say, ‘We need to do XYZ,’ because it’s going to be linked to ‘what cyber security needs to do.’

On the other hand, if you’re creating a value story, such as, ‘We need to go to a more seamless experience for our customers to access our systems,’ then you can talk about a new customer identity platform and moving to a password list and how that’s going to create great customer experiences. You’re going to start adding value at a different level and expanding your scope, as well as moving up the value chain for that organization.

You can be the best technologist with the best execution to the standards that you’ve set, but if no one understands them or understands the importance and why it matters, you’re going to stay there, as opposed to that storytelling organization, which is going to continue to grow and evolve at a much different rate and level.

In the podcast we talked about the plethora of stakeholders you serve both inside and outside the company. Some might have shared interests but different ideas of how to get there. Others might have competing interests. How do you deal with this when it comes to communicating and messaging?

There’s always going to be competing priorities between one organization and another or differences of opinions on how to get there. What I try to do, again, is focus on the outcomes, because if you’re aligned on the outcome, then you can really start to unpack what the issues are around the disconnects. So: If we do this, we’re going to get here. If we do that, we’re probably going to miss. And we all want to be here, right? That’s kind of the way I do it. It’s focusing on what problem we’re trying to solve, creating those shared needs and goals, and getting everybody to understand what the end state is, versus the details of how you’re going to get there.

I also make sure that I’m the facilitator and orchestrator, but it’s not my idea. It’s about getting the people that are not on the same page or may have disconnects in priorities to come up with the solution. I think that’s the key to success as well.

From industry regulations and TSA directives to SEC and cyber regulations, how do you provide clarity in this sea of complexity?

You have to make sure that you’re speaking in a language and terms that people understand, even if you’re trying to talk about complex regulations. I don’t, in normal day-to-day life, talk like a policy document. And I think sometimes when we’re trying to explain that the TSA has this new LSP or something, we just spit these acronyms and technology terms out. It’s really important to make sure that you are paying attention to your tone of voice and word choices. Use common language so you can explain what is happening, why it’s happening, and what we’re going to do about it.

Because if you think about the complexities around the way an event or attack happened or a really complex TSA regulation, no one wants you to regurgitate the low-level details or the policy documents. They want to understand, in summary, what is it? What are we doing about it? Are there like any risks or issues that we need to be concerned about?

The CISOs we surveyed for our CyberLX leadership program told us that one of their big priorities is building leadership skills with a focus on EQ [emotional intelligence], influencing skills, and communication skills. How do you instill that kind of marketing mindset in your leaders and develop these communication muscles in your people?

I don’t like to have meetings before meetings and all that kind of stuff, but for those important presentations or important meetings or discussions where you’re really trying to get people on board, or you need any kind of commitment from someone, I have a preview with my team. We go through the slide deck or the key messages, and I kind of play devil’s advocate and ask, ‘Well, why do I care about that?’ We practice that way, and after we do that a while, they get that and they can do it and we don’t have to have the meeting before the meeting anymore.

Communication is developing that muscle memory as well. There’s always a question you’re trying to answer. There are certain elements of communication where it’s the same components and you have keep that in mind and just know how to do it. So practice is really important.

How do you define the value cybersecurity creates for the business?

I think value can be defined in a couple of ways. It’s making sure that you’re meeting those key responsibilities that you have as a cybersecurity leader — there’s no significant data loss, no downtime or operational disruption associated with a cyber event.

There are those types of things, but there’s also things around, how do you enable the business to do something that they couldn’t do because you’re removing that risk or mitigating that risk, or you’re breaking down a perceived barrier that was there so you can go operate in a market that you weren’t able to before because you have a secure architecture. Or you can collaborate or share data in a manner that’s trusted that you weren’t able to do before. That creates value from a business outcome standpoint.

You have to think about defining value not only in terms of what you’re doing from a cyber perspective, but also what you’re enabling your organization to do from a customer or shareholder value as well.

What are the metrics you focus on?

This is evolving and I’m still working on it with my team, but the operational side of metrics are around the policies and standards that we’re setting, how well are we covering those within the technology services, and then how well are they performing. So it’s a coverage and an effectiveness type of type of view of metrics.

Of course, we want all the external endpoints behind our web application firewall, that coverage metric, but then how many threats are we actually blocking? What are they? And then are they in the application security standard? And why are people still using broken authentication or improper session management or whatever it is — we’re trying to close the loop there and make sure we’re not just saying we’re good because we have a policy, but is it working effectively? And then where it’s not, understanding where our gaps are. It’s that continuous loop. We try to pull that baseline of metrics and KPIs around core capabilities within our cyber program.

It’s probably not a metric you track, but I have to imagine that once you do a good job with the narrative, you’re seen as a strategic partner and start getting invited to the first meeting instead of the fifth meeting.

Definitely. I love it when somebody else is connecting the dots, when they come to me and say, ‘I think we should be thinking about this.’ That’s my measure of success. I’ve done my job.

For more insights from DeFiore on the leadership skills required to be a successful cybersecurity leader, tune in to the Tech Whisperers podcast.

Business IT Alignment, CSO and CISO, Data and Information Security, IT Leadership
Read More from This Article: United Airlines CISO Deneen DeFiore on elevating cyber’s value to the business
Source: News

Category: NewsMay 25, 2023
Tags: art

Post navigation

PreviousPrevious post:12 reasons good employees leave — and how to prevent itNextNext post:Register now: GenAI, risk & the future of security

Related posts

칼럼 | 멀티 벤더 프로젝트 실패, 대부분은 ‘거버넌스’에서 시작된다
April 29, 2026
샤오미, MIT 라이선스 ‘미모 V2.5’ 공개···장시간 실행 AI 에이전트 시장 겨냥
April 29, 2026
SAS makes AI governance the centerpiece of its agent strategy
April 29, 2026
The boardroom divide: Why cyber resilience is a cultural asset
April 28, 2026
Samsung Galaxy AI for business: Productivity meets security
April 28, 2026
Startup tackles knowledge graphs to improve AI accuracy
April 28, 2026
Recent Posts
  • 칼럼 | 멀티 벤더 프로젝트 실패, 대부분은 ‘거버넌스’에서 시작된다
  • 샤오미, MIT 라이선스 ‘미모 V2.5’ 공개···장시간 실행 AI 에이전트 시장 겨냥
  • SAS makes AI governance the centerpiece of its agent strategy
  • The boardroom divide: Why cyber resilience is a cultural asset
  • Samsung Galaxy AI for business: Productivity meets security
Recent Comments
    Archives
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.