A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Monzo Bank
Technical v Non-technical -Why language matters


The great divide
To me it’s simple. If we work within a profession, we possess the technical knowledge applicable to our field, yet the term ‘technical’ seems to be exclusively used in the realm of technology only to describe those who work closely with the platform, i.e., the developers, backend engineers, etc. You may ask, why does this matter?
As someone with a legal and corporate governance background (and who has in recent years, transitioned into a career within cyber security and observed this phenomenon) I believe that the language that we use to describe those around us in our workplaces does matter. A lot. I’ll tell you why. If we choose to divide our colleagues up and call them either ‘technical’ or ‘non-technical’ folk, this effectively polarises the two groups and sets us up for failure within our organizations as well fall into the trap of a ‘them v us’ dichotomy. It also creates a false sense that if something occurs within a business that is technical or non-technical (depending on which group you fall into), then it’s nothing to do with them. This kind of thinking is harmful to a business’ cyber security posture.
Working together not in siloes
Every role in a business is important because cyber security is comprised of people and processes, not just technology. That’s 2/3 of cyber security that is often disregarded by the ‘technical’ folk as not being important, simply because it’s not to do with engineering. It’s a symbiotic relationship, as a business cannot operate without its Legal, Operations, Risk, Finance, Marketing, Security, or IT functions. What people often fail to realize is that security isn’t just about what SIEM you deploy on your platform or making sure that you’re rotating your keys (although those things are important), it’s also about people (our colleagues, external customers, and rogue actors) and ensuring that everything that we do is backed up by robust processes that are simple to understand and implement which is then underpinned by good governance to make sure that we have a clear picture of our current security landscape. To make this work we need everyone in the business to be security aware and to work together. That way we can detect potential security issues and work to mitigate them before they turn into risks.
Summary
It is for these reasons that we should try and gently change this culture which pervades our businesses like Japanese knotweed for the sake of better relationships, but most importantly because it harms how well we do security. If people in engineering or security teams end up getting siloed from the ‘non-technical’ folk in our business, our security posture suffers, and we end up being exposed to greater levels of risk as people fail to have those important conversations which could lead to the discovery of flaws within our security.