
On 18 January, teissTalk host Jenny Radcliffe was joined by Daniela Lourenço, Business Information Security Officer of CarNext.Com as lead guest; Neil King, European Business & Information Security Specialist of Canon Europe; and Tariq Wani, Business Information Security Officer, Kimberly-Clark
The panel discussed the news highlight of the week – the crackdown operation by FSB, the principal security agency of Russia, that led to the arrest of 14 alleged members of the REvil ransomware gang. Many see it as Russia’s demonstration of how efficient they can get in the fight against cybercrime once they knuckle down. There were some doubts about the originality of the video that shows key moments of the operation. However, whether genuine or an illustration, the footage gives the viewer the impression that the perpetrators, who extorted a ransom of $6 million in cash, cryptocurrencies and luxury cars, are, by the look of them, ordinary human beings too. The gang fired on all cylinders. They created their own file encrypting malware, deployed it to extort money, as well as running an RaaS operation and stealing money from bank accounts.
Last October it was reported that law enforcement and intelligence cyber specialists took control of some of the gang’s servers as part of an operation conducted in the US and some other countries. The Russian crackdown came in response to President Biden’s call for urgent Russian action against these gangs.
Although responsibilities that a BISO has have been around for some time, a separate role is a relatively new thing. Some of their remit overlaps with CIOs and CISOs, but you need them as the other two functions are too close to the board and are closely involved in strategy building or may lack the communication-related skillset that is key to what BISOs do. A BISO’s role is to translate or act as a messenger between the business and the security functions. They often play the devil’s advocate. If, for example, info security comes up with the idea of segregating roles, the BISO, relying on their first-hand knowledge of business culture, will explain that if only one member of the team is authorised to perform a task, the workaround is bound to be the sharing of passwords, which will defeat the purpose of the planned security measure. By asking questions from a feasibility point of view, they also serve as a useful counterbalance to COOs, who will usually implement what the CEO wants to do.
Paradoxically, you can tell the role creates value by the increase in the number of reported incidents, as this reflects higher security awareness and alertness to report anomalies. But there are KPIs too that you can measure the success of BISOs’ service delivery against to tell if the embedded controls they have put in place actually work or not.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543