Kylie Watson’s ascent through the enterprise tech and cyber security ranks was never planned.
At just 17, Watson joined the Australian Army at a time when women couldn’t serve in combat roles. She was briefly given quartermaster and payroll tasks before moving into her preferred role as a field engineer. There, she worked on water security, bridge and decoy building, road alignment and explosives ordnance.
“I was doing a whole bunch of stuff in networks and cabling as well,” she says. “When you build things, there’s stuff under the ground – you’ve got to know where it is and be able to provide a provision for infrastructure.”
But it was the psychology of army operations that truly fascinated her. This led her to pursue a master’s degree in sociology, which helped her understand team dynamics and why decisions were made.
“I started to get really interested in not only the group dynamics of the troops and sappers…but [also] how we are all interacting because it’s really interesting under pressure in those environments and how people react,” she tells ADAPT.
After leaving the army in 2000, Watson spent five years as a GM of a PR company, held director roles in the ACT Government and Murray-Darling Basin Authority, and consulted in water and infrastructure for American engineering firm, AECOM.
Watson’s Defence experience was a catalyst for her first move into the tech sector. This was coupled with a downturn in engineering work due to lack of funding for major capital projects as a result of the global financial crisis.
A colleague encouraged her to pursue an IT consulting role with the Department of Defence.
“I said, ‘I can’t go over to IT. How would I help IT? Building bridges and roads and stuff like that, what are you talking about?’ And they said, ‘Well, you’ve got a lot of Defence experience in serving and consulting. There’s an IT project at Defence. You know the environment; you know how to get things done in Defence.’”
IT project management was a steep learning curve for Watson and a role that she enjoyed, particularly the ethical (white) hacking activities.
“I really liked [being on] that side of the fence; I actually understood it and got across it.”
Watson says the network-building side of her background, combined with operating under threat in a Defence environment, had given her deep knowledge that she didn’t realise could be applied in cyber.
The rest is history. Watson has spent the last decade in senior business transformation, data analytics, cyber and cloud roles at SAP, Deloitte, IBM, PwC and DXC Technology.
In April last year, she was appointed Head of Cyber Security at DXC, overseeing Australia and New Zealand, ASEAN, Japan, India, the Middle East and Africa.
Balancing cyber security priorities
Although Watson agrees there is a lack of rigor in some industries when it comes to maintaining the best cyber protections, she says this is not the main issue.
Watson’s experience as a regional CISO and consultant has taught her that organisations need to prioritise where they spend their cyber dollars.
She says that the Australian superannuation providers impacted by the recent credential stuffing attack should have employed multi-factor authentication (MFA) protections, but it’s not possible to do “everything all the time.”
“When you look at superannuation, the first thing I thought of at the time – and it’s not an excuse – was ‘how often do you go in a check your super account?’ Because that’s not something people go into every day. It was probably considered…low risk,” she says.
Watson says it’s a question of where rigor needs to be applied to strengthen security postures across different elements.
“I’ve seen instances in my consulting career where people are saying, ‘yeah, we’ve absolutely got this protected. They’ve protected it thinking, ‘Ok, a nation state actor would be the most obvious person [wanting] to get into our systems. But actually, a social engineering attack came through and it was from a competitor. They were not thinking about a competitor or the social engineering aspect.”
Watson has written about cyber-criminal profiling and protecting against all kinds of bad actors who she says have different nefarious means of compromising systems.
“As a consultant, I can say, ‘yeah, that’s not rigorous enough. But, as a CISO, I [say], ‘Well, I can’t protect everything to gold-plated platinum level. Sometimes I’ve got to pick the Datsun out the back…and protect that too. There’s a lot of legacy that we’re dealing with.”
Vendor outreach not up to scratch
In April, ADAPT recently surveyed 118 CISOs on tech vendor outreach. Only 15% found outreach useful, and just 1% saw value in the insights shared. The bulk (59%) said outreach was generic, 14% ill-informed and 10% just plain bad.
“I’m surprised at the ones [respondents] who actually like it. I hate it, I absolutely hate it,” says Watson.
“I did write back to someone the other day and I said, ‘Thanks for letting me know, I’ll keep that in mind.’ Quite often, I am not the kind of person who likes ignoring things, but I’ve had to get to the point where I just ignore them,” she says.
Watson says if she spent all her time getting back to vendors who reach out, she would have no time to do her job. Her high social media profile means that she is getting around five approaches every day from vendors selling their wares.
She suggests that the best way for suppliers to reach DXC would be to start small and get some runs on the board by networking locally and then across the region.
As an example, Watson works with a government-funded cyber hub that helps smaller vendors build stronger networks. It recently ran an event, attended by around 100 CISOs, where 8 small vendors pitched their solutions.
“Find the more formal programs, don’t keep doing the individual outreach. It’s just a pain. In fact, if more of them do it [outreach] from an organisation, I’m more inclined to not want to reach out to them because I think, ‘Go get your marketing right.’ It annoys me,” she says.