ComputerWeekly

The Security Interviews: Nicole Darden Ford, Microsoft


Being a black woman in a predominantly white, male-dominated cyber security industry is “tough”, acknowledges Nicole Darden Ford, vice-president of Microsoft’s customer security officer programme.

But despite this, and despite working in an industry where burnout is widespread and churn rates are at least twice that of other senior leaders, Ford has held chief information security officer (CISO) positions at large corporates an impressive six times.

Such corporations include department store chain Nordstrom and manufacturing conglomerate Rockwell Automation. They also include medical technology company Baxter International.

So, what is the secret to her resilience and, just as importantly, her success? Ford certainly believes her training and background in the US military, where she worked in signals intelligence, helped. In her time there, she was taught “what to do in war but also in peacetime”.

“CISOs are first responders, and you have to be wired to do the job,” she explains. “But if you have the skills to be a first responder [such as calmness under pressure and quick thinking], you also have the skills to shield yourself from burnout.”

As a result, at a personal level, Ford is careful about her own self-care. This includes decompressing by regularly doing things that bring her joy and ensuring she takes vacations.

It also involves ensuring she invests as much energy into her personal life as she does her professional life – and being “really strict about that”. This approach is important, Ford points out, because “to be in an optimal state, you need to have downtime”.

Addressing the human cost of cyber

But she recognises that the work comes with a “human cost”, simply due to its high-pressure nature and the inability to control when incidents occur.

“You really have to understand and know yourself and be clear about who you are,” Ford advises. “It’s about how you manage being always on and the fact that an attack can happen at any time, so it’s important to build a team structure that enables you to operate at the top level as much as possible.”

The idea here is that the cyber security function should be able to function without its leader for a given period, if necessary. For this to happen, it requires not only having the right team in place, but it also means testing processes to ensure they work effectively.

Another important point that Ford “learned the hard way” was understanding that “not all CISO roles are created equal”. In other words, it is necessary to be selective about the jobs you take.

“[As a CISO], you have to balance pragmatism with the realities of what’s required in cyber terms. Soft skills are the most important part of the job as you have to interact with boards”

Nicole Darden Ford, Microsoft

A key consideration here is determining if a prospective organisation not only has a supportive and friendly environment and culture, but also establishing if it is willing to provide enough resources to enable you to do your job effectively.

“Sometimes, CISOs take on roles without knowing if they’re right, but you have to go in saying that you won’t take the job if they won’t meet your minimum requirements,” Ford advises. “Burnout is real, but sometimes it’s all about the budget. If you see an opportunity but they’re not willing to put in the necessary support structure and resources, I’d pass.”

A key point here, she says, is that the CISO role is one “the C-suite loves to hate”. As such, it is seen as a “necessary evil” because the function is a cost centre rather than a revenue generator.

“You have to balance pragmatism with the realities of what’s required in cyber terms,” Ford explains. “Soft skills are the most important part of the job as you have to interact with boards, which means you need to be an excellent communicator and great storyteller, have great people leadership skills and know how to develop them.”

Dealing with being ‘different’

As to how she has dealt with being “different”, Ford says she took several approaches. The first involved building a supportive community around herself by joining groups like WiCys for women in cyber security and Women in Tech. These were spaces where it felt safe to have “honest conversations” and where advice and support were freely given.

The second route entailed being “intentional” about her professional development. Having supportive sponsors and mentors was “vital” in this context, she found.

“I knew I wouldn’t succeed unless I put time into my own development, so I created a ’board of directors’ who tell me the truth, even if it’s hard to hear,” Ford explains. “They’d sometimes open doors for me and they’d coach me and help me develop a plan for where I wanted to go.”

As a result, her advice to anyone coming up through the ranks is that “networking is the one thing they have to do” to succeed.

“Develop the right relationships and invest in them because you’ll need them,” says Ford. “Oftentimes, people think if they work hard, people will see and recognise what they’re doing, but you have to actively learn how to be a leader, to delegate, and to do important things well.”

It was this learning that helped her build the necessary confidence required to progress. But there were other factors, too.

“My confidence has come from serving my country and being on the front line, but also from being among the first in my field and charting a path, so I can pass my knowledge and expertise on to the next generation,” Ford reveals. “When times get hard, it’s also about remembering who I am – so not Nicole the CISO, but someone who’s trying to be a good human.”

Changing the dynamics in the room

Building this kind of confidence and self-belief was essential. This is because, on top of facing microaggressions and being subjected to other people’s assumptions, Ford also found it necessary to continually prove herself to others. Doing so involved providing evidence for her opinions in a way that white, male colleagues were not required to do to earn respect.

But she also discovered that “the more knowledge, skill and expertise I developed, the more I was heard”.

In other words, Ford says: “You have to own your own power as you build it over time and develop the ability to communicate without fear. Realising that I deserved to be in the room was a turning point for me, and I recognised that I had to change the dynamics in the room.”

I want to see more black and brown people in cyber, AI and tech more generally. The white male old boys’ club hasn’t served us well and hasn’t helped us solve our problems
Nicole Darden Ford, Microsoft

For her, this meant becoming an “advocate for diversity”. As a result, she started forming teams with an equal male and female balance. Her teams also include people of colour as “I didn’t want them to be the only ones in the room as I’d so often been”.

“I want to see more black and brown people in cyber, AI [artificial intelligence] and tech more generally,” Ford points out. “The white male old boys’ club hasn’t served us well and hasn’t helped us solve our problems. So, I’m using my platform to say we have to call it out, own change, and do something to make it happen.”

In her own life, this has been about taking on high-level roles and acting as a role model for others to help “change the landscape”. But it has also been about being a servant leader. This is essential in a sector like cyber, Ford believes, as it is a “people-first business”.

“Sacrificing people doesn’t work due to the value they bring,” she explains. “They’ll do whatever you need them to if they feel psychologically safe and you make it clear you want them to succeed, so I always say to young leaders, ‘Lead by taking care of your people as then they’ll take care of you too’.”

Being a servant leader

What this means in practice is helping team members to develop. Doing so entails fostering a growth mindset and “connecting the dots for them to help them achieve their goals”. It also means giving people stretch assignments to keep them engaged, and spending time on getting to know them as individuals.

But in a broader sense, it is also about showing empathy and establishing the values that underlie psychological safety. This includes creating space for “the hard conversations”. It also involves providing consistent, appropriate feedback as “people will rise to it”, Ford says.

One example of where this approach paid off was when she was hired by climate and energy solutions provider Carrier. Her remit here was to design and build a cyber security programme from scratch within a year. The aim was to help the business prepare for an initial public offering after its parent company, RTX (formerly UTC), decided to divest it.

Early in her career after leaving the military, Ford had managed the roll out of the US Department of Agriculture’s Integrated Acquisition System, its first third-party solution, to 10,000 users. In doing so, she discovered there are three key factors if an implementation is to succeed: time, cost and speed.

“You can’t have all three, so you have to forsake one – and, going to Carrier, time was not on my side,” she explains.

This meant Ford had to rely on her “existing playbook” and her relationships because, with a budget of $100m, money was not an issue. As a result, she put together a strategy and plan and hired the best people she knew in the shape of an architect and a team of “builders”, all within 60 days.

“A big challenge was trying to find the right people, so I went to people I’d worked with in the past,” she indicates. “But under that amount of pressure, you also have to create a safe place to fail fast and move forward, to create a continuous learning environment that isn’t punitive, but where people can experiment.”

Not only did the team hit their goals, Ford says, but it was also “one of the best teams I’ve ever worked with as people understood the mission upfront, were mission-focused, and able to execute”.

The importance of knowing your ’why’

Unsurprisingly given such a strong people focus, one of the highlights of Ford’s career has been seeing members of her team become CISOs themselves. Two have even made it into the CSO Hall of Fame – as she herself did in 2023.

As Ford points out: “Successful CISOs invest and develop people. You can work yourself out of a job but, in reality, it may feel cool to be the go-to person until you realise that isn’t leadership. What is, is having strong boundaries, non-negotiables, and knowing who you are.”

Ultimately, she believes the secret to her own success has been having a can-do attitude and having enough “hope that you can be part of a greater ecosystem that impacts the world in a positive way”.

“To do that, you have to know your ‘why’, what your purpose is, and how that aligns with cyber,” says Ford. “I’m what you could call a ‘first generation’ CISO, and my superpower is having the drive and tenacity to be the first to chart territory and be a groundbreaker.”

As such, she is taking part in a docuseries on various high-profile CISOs entitled Declassified. Produced by Red Mirror Studios, the first film studio dedicated to cyber security, the first episodes of Declassified were released on YouTube on 28 July.



Source link