The CISO Whisperers – CISO Talk EP 31
They might be leaders in the cybersecurity industry and top of the ladder within their organization, but CISOs still need advice! And when they do, they often turn to trusted advisors to help them with strategy, product, network and vulnerability decisions. So, who are these CISO advisors? How did they achieve their ‘CISO whisperer’ status, and what role do they play? New co-host, cybersecurity expert, speaker and CISO advisor Jennifer “JJ” Minella joins Mitch Ashley on CISO Talk. JJ and Mitch explore the role advisors play in helping guide cybersecurity leaders and their organizations across diverse subjects, including network technologies, governance and compliance, AppSec and securing cloud-native infrastructure and applications. Mitch and JJ also discuss plans for future episodes including discussions with security practitioners about the cybersecurity challenges organizations face and best practices for addressing those challenges.
Transcript
Hello, everybody. Welcome to see so talk see so talk might look a little bit different than you've seen in the past and that's what we're going to be talking about today. I'm joined by our new co-host and longtime colleague and friend Jennifer JJ Manila welcome Jennifer.
I'm rich. Hi everybody. you're not new to our she's so tuck audience because you've been on several panels at RSA on Virtual panels and speaking on Tech strong events and a lot of other speaking it rsac and Conference and things like that.
So there are a number of folks in the security world. They're already know you Yes, and I'm so sorry everybody about that and you're just gonna have to get to know you better they're gonna have the opportunity to do so well, so we're gonna spend a little bit of time and I first I want to pay thanks acknowledge to Matt Newfield who we've been working with Alan shiml and I and Matt have been working with see so talk for a number of years and multiple episodes and building the program to where it is. And that's got a very busy schedule.
I'm sure he'll be back as a guest. Um because we love love them and appreciate that always done or somewhere and we're cat taking this now to the next place. So we're gonna have some format changes and maybe some new topics and things like that and we'll get into that next JJ first.
I'd love to have you introduce yourself to the audience. I think most folks know I'm CTO at text from group. I also in the principal and under of our research division Tech strung research and you know you and I work together as I mentioned this colleagues and security and security products way back when and so they know enough about me, but I really love for you to talk more about the kind of work that you've been doing.
It's evolved to some interesting places and now with your own company. That you're doing so jump right in there. Sure.
Well, I think the probably the most relevant pieces are you know, I've worked in technology for a very very long time. I'm not gonna age myself with that number and I've worked in security for approaching 20 years at this point. So and through that time a lot of what I I've done is kind of work.
In architecture between groups. Sometimes it's between two different technical groups. Sometimes it's between you know, executive leadership and then the Technical Resources, sometimes it's between the security team and the networking team and a lot of my experience throughout that time and you know, 20 years or so.
Has been really heavy in the network security side. But you know as the perimeter has changed that's morphed into being a little bit more holistic View and security architecture. And more recently a lot of stuff in zero trust.
And so that's that's kind of one of my passions along with a lot of the wireless security Technologies and wireless for me is not just Wi-Fi. It's all kinds of stuff but I think just because of where we are moving as as humans and where we were moving as Industries and security those Technologies become very important and are often misunderstood. So a lot of the zero trust stuff has been fun for me.
It's not a marketing buzzword. It really is real we are doing it. It's a thing but I think there's just so much misinformation so much marketing marketing hype that there's a lot of opportunity for us to have conversations around what that actually means.
And and then how to do it and when and where and how it's appropriate to do it and take you know, bite-sized projects. So that's been a lot of what I'm doing part of that involves the cloud security Alliance who has a zero trust Research group and working group. So I'm in leadership team with that doing several projects as well as some of their iot stuff.
So yeah, that's how I've been spending my time for the past 20 years and zero trust for the past, you know, two or three. It's it's been a lot of fun to be sort of a sidecar to the journey of that. You've been on and being part of that as a as a friend in colleague and seeing how far it's evolved because I mean you've you've worked with so many companies in Your Capacity both as a solution provider kind of systems integrator and security world now is a real an advisor to see those into organizations whether it's one-on-one or she talked about working with multiple groups.
It's it's a tough. It's a tough gig he knows he's those security people don't have easy jobs, and I'm not telling them anything. They don't know but I'm curious from your perspective because you spend a lot of time being an advisor to folks.
Why do they need advice or what do they looking for from you that that you're able to kind of fulfill that they're they can't figure out themselves or get out of the ways well and I wanted yeah, let me qualify that a little bit. I don't want to say that it's because they can't figure it out themselves. I just think that everybody has priorities in their day.
Especially when you're a ciso, right you're or a professional with cisotype responsibilities because a lot of people I work with, you know, don't necessarily have a ciso title. Or they do have a CSO title, but they've never been formally trained and had any type of mentorship in that area don't know how to build a new program. So just a little asterisk of you know, I it's you know, yeah, I tend to slide in when people just need a little extra help because sometimes there's not enough hours in the day.
And it is interesting, you know, you mentioned working with I work with an integrator. Well, I still work with multiple integrators now, but it was an integrator for over 20 years as well as Consulting with ions who's pretty heavy in the security space. So I've worked with you know at this point thousands of customers across every industry ranging from you know, the charter school down the street to large universities every tier of federal government into Department of energy and and Department of Defense lots of financial lots of healthcare.
And so, you know throughout that time there's been different. Sizes of organizations and different maturities in terms of their people and processes and expertise. So it's been really fun.
I'm a very non-judgy person because I you know, you kind of get what you get and everybody's doing the best they can do so, it's really been fun to just kind of get in and work with somebody or work with the team in an organization see You know what knowledge they have what resources they have and leverage that and moving your Security Programs forward and they're in their various technical projects. But yeah, I think there's just an especially now. I mean gosh and I you know, I really don't even get into I don't consider myself.
Cloud native so a lot of the application security. I think this is fun because you know you and I have known each other for a long time. I think approaching 20 years at this point and you know, you've always been a kind of like the the software and application side and I've always been a networking side.
So this is a pretty fun. I think caring of those expertise together for something that's pretty well-rounded. But yeah, it's been so much fun working with people and I just think there is opportunity to you know, use platforms like this and our relationship and see so talk and bring people in and just kind of amplify that and give you know much broader audience the benefit of All of that experience not just our experience, but the experience of the different professionals.
We're going to be bringing on and talking to it'll be it's a different take on see so talk because with Matt we're talking to who someone is they see so you might have been someone an example of somebody who might work with their eyes. But we're going to kind of have that the conversation we're having even though it's not with a specific seeso or maybe with a guest but isn't the conversations that are happening right and people are trying to fill in the gaps confirm. By the way one alone is jobs is being the ciso or the CEO or the CIO CTO.
Right as you talked all the same people in your organization and the vendor Community you work with sometimes you just need to talk to someone else and get their take on it kind of validate learn change your mind add to what you're thinking. It's you know, you don't want to kind of get caught in that Echo chamber you live and work in an everyday and that's I think that's kind of what one of our values and see so talk is expanding that conversation on a topic that's very near and dear and relevant to our audience what they're doing. Absolutely.
Well good. Let's let's do this and thank you for taking some time tones about your work, you know talking about your work. You know as as you know, you've gone from being a frequent guest to co-host.
Yeah, one of the reasons why I do shows like this. And first of all, I love talking with people and in a collaborating with you and people like you this is another way to do that and it's a fun and engaging way to do that. I kind of feel like for me our audiences are tuning in for the reasons we talked about.
They're also kind of part of their Career Development, right? They're learning. I want to know more about zero trust.
I've heard the buzzword. I'm trying to implement it or a cloud-native and kubernetes security. What the heck is that?
And how do I deal with that as a security professional, you know, give me some point or some tips, you know kind of fill in some gaps. So we're really helping people both advance in their careers as well as doing work in their job and I don't want to overstate that I watch that episode back. I became a PhD no, but you know, this is all part of our continuing development.
You know, that's the one things that really motivates me about doing this. I'm curious when we talked about. Let's let's join together in co-host this, you know things you're interested in happening why you're motivated to do this.
Oh, man. Well, I think oh if I had to slap a number on it, I would say probably. to maybe even 80% of the questions I get asked.
our questions that peer like peer professionals or peer organizations have so a lot of people, you know in the space a lot of professionals don't they're all seeking the same type of information. And so I think it's a great easy way to to share that I think there's also I mean if we get into this Little bit of interpersonal thing here, I think. There's a lot of pressure on csos.
and again, you know Security Professionals in general and I think there's this expectation that they're supposed to know everything and do everything and that's frustrating because again, there's only so many hours in the day and for as long as I've worked in Tech, there's still a whole this whole circles. There's whole like huge parts of the Venn diagram that I'm you know, I read a whole kubernetes book and I still do not understand what it does. Right?
So, you know, I think part of this is just having a community and just saying, you know, I I don't know everything where can I get that information? How can I ask the questions and and fill those gaps and just in a meaningful way instead of from vendors and I'm gonna get on a little soapbox here for a second. Let me just pop up here and say one one of my points of frustration.
So, you know, I although I've worked with an integrator the integrator and integrators that I work with still sell multiple products and multiple competing products in a space. And so, you know for 20 years when I walked in to a client, it's been out of this whole. You know Pantry of things or grocery store of solutions that I could bring to you.
What do you need and what fits for you and that's fun, right? Because I don't get you know, well, I never I was never in sales. So I never got paid for selling anything.
But you know, I am never attached to a product. and never worked in that space and I think you know Architects and Consultants, you know have a little bit of an advantage in that way and that we can pull anything off of the Shelf versus a manufacturer and a manufacturer team who no matter how technically competent they are because a lot of them really truly add value they speak at conferences. They write blogs.
They do like they have a lot of valuable information at the end of the day the way they are fed and the way they eat. Is through selling their product? And so there's always just a little bit of bias in a certain things.
There's certainly never going to you know, show a mirror and and show what their their product blatantly can't do. And so I think there's that's the other kind of value. of having a forum like this is we have the opportunity to share this knowledge.
Very unbiased. We're not we're not here to pitch products. We're not here to sell products.
We're here to just purely educate and share and build community. And I think there's a lot of value in that. There's a lot of value in that for me personally.
I like sharing. I like collaborating and I like educating people. We end and of course vendors technology providers, you know play an essential role, right we couldn't do this without them.
Absolutely. Absolutely. Yeah, they are biased because they have to be that's just built into the nature of selling what you have to sell and that is the role of folks who are Consultants or analysts or lots of different roles integrators many times where they can say, well, here's the options in let's look at what's the best fit for you?
And that's hopefully we're I think you know with with you and I we can sort of fine tune. Maybe what some of those questions might be to ask the technology providers or maybe ask your own organization, you know? Yeah.
I know that's a great product but let's step back and talk about why we want to use kubernetes whatever that is standing yet. And then how we're gonna figure out what we need to do. I mean what's on the boring questions?
Ask ourselves are so we know when we we go back to of the vendor. So there's a lot of those things. I think we can.
We can definitely pursue and kind of provide value on on the show. So you're passionate let's talk about some topics because of this show is kind of about the show and we will the format. First of all is changing Matt and I and Allen have been ciso talk primarily as a panel show where we get four to six maybe sometimes squeeze into seventh once in a while to pick a topic and sort of get a plethora of ideas and perspectives about that particular topics.
Sometimes it's maybe been a lot of vendors technology providers on the show could be folks like yourself more independent or a practitioner to try to get a diverse perspective and that's we have lots of shows and and more mass for that here. We're going to go to more of a let's meet with a person about a topic someone who's probably doing that work. Maybe they might be from a bed or sometimes right more than the practitioner side and take a little bit deeper into that.
and that I think that'll give us a different perspective for for the folks that are watching and follow see so talk and we'll explore that and we'll evolve and change our format too as we find what we think works. Well our audience tells those support works. Well makes sense to you JJ.
Yeah this show his been formatted to fit your new brain. Okay. Oh good.
Now we just need to fill that in with some good right at least mine. Anyway, well, you know, you mentioned zero trust and and network security. I'm sorry wireless security, of course as well as network security.
Those are great passions of years. I'm sure network security Wireless and zero trust are going to be some big topics. Is there anything any other things kind of top of mind that you know, I don't know if it'll be the next show we're not but somewhere in the in the collection of shows that we put together some topics that you're really excited to explore.
I mean, I have a few too, but I would definitely get your perspective. Yeah, I have a time and you know again my I think that the core of my being you know stems from that not working side but having worked with network access control. So for me this kind of shift into zero trust is really just a new way to do something like network access control.
We're just kind of extending that air quote perimeter into the cloud. And and working further up the OSI stock than we had before but fundamentally, it's it's all the same stuff. It's just slightly more complicated now so that you know, that's at the core of what I've liked to do because it's it's complex and it's one of those things, you know, especially zero trust you have to fit all of the puzzle pieces together, so For as much as I love, you know network security.
That is always to be taken in a holistic kind of Archer architecture architectural View. And so I think part of the fun of the topics, you know that we've talked about maybe sprinkling in here is that we have the opportunity to look at these things not through the microscope of just the one thing but how does this fit into everything else? Because you know for for years now and especially now as you're a trust, you know, we can't have a network security conversation without discussing endpoints without discussing the cloud perimeter without discussing things even like maybe sd-wan technology.
So, you know, I think all of it fits together so well and so a lot of the topics I think we can kind of like dive into certain things especially if we have a mechanism maybe for all of you guys watching and listening. We're maybe you can give us some feedback and comments about hey get more into this and we can dive more into something but I think back at that kind of 5,000 to 10,000 foot view, you know, there's a whole lot of stuff that we're struggling with now that I see organization struggling with in my clients are struggling with which is things for example For all of the convergence. We've been pursuing.
Within the different pieces of Technology. We have some things that we really need to be Divergent with and treat a little bit differently. For example, operational technology and OT is handled very very differently than Enterprise it.
And this is one of the challenges I've had in kind of helping with with some of the organizations running Frameworks for zero trust. It's like oh all of the vendors want to put iot. an OT and what we would do on just Enterprise lands all together.
and maybe even address them with one product said and one kind of overarching strategy and umbrella and those of us that work deeply in these spaces are going no. No, this is not how we do it and just because the vendors are pushing it to you that way it does not mean it's that's the appropriate way for you to consume that and so part of it is, you know, I think these topics about educating If you're a ciso if you're a security architect or other security professional, where are these areas that you need to to diverge some things and keep them separate instead of converge them. I'm using I you know Enterprise it and OT is one example, we have, you know, different opportunities for some of the stuff.
We're we're considering with with cloud and on-prem that might need to stay separated. We have different things on the networking side. We're doing a lot of stuff with like private cellular now, which is Cool, I love it, but it's its own can of worms.
From a security standpoint and from a compliance standpoint. I mean it's a good can of worms. These are like the worms you would want to eat.
Maybe they're fried and like breaded and panko or something. They're good French words. They're French words like yeah, that's going to go.
Cargo warmth wait escargoer snails they are. Yeah, not a good one. But I'm happy.
I'm having like flashbacks this lovely restaurant in San Francisco. We walk to if you blocks from westoni and they had like the best escargo I've ever had. But anyway, I digress so I think there's there's all kinds of stuff from like, you know, what I work with Cisco's.
It's We might be talking about pen test, right and maybe it's an application pin test. Maybe it's a network pin test. Maybe it's all of the above.
There are actually pre- precursors and things we do before a pen test that are more cost-effective and and more more cost effective and more effective effective. And so there's all these different things. I think it's like what Cisco's should know about fill in the blank.
And then we can kind of share some of that information for if you were here in making the decision. Here's really the the bubbled up version the takeaway that you need to know without having to go. Do you know eight hours of research or interview for people and then try to go fact check and see if what they told you was right.
So those topics are everything from you know, zero trust. starting projects identifying projects working through a maturity model because it's frankly all of the documents we have in Frameworks and everything we have on zero trusses for the federal government and it's complete just rubbish if you're in the Enterprise space, so are we working a lot of that? I think there's lots of opportunities for you know, how do you pick a framework if you don't have a controller or compliance framework currently and and how are you implementing that how does That Vary between different Industries?
I love those conversations. I think there's so many of these. There's so many of these professionals that have gotten stuck into a ciso-ish position and again haven't necessarily had any type of formal mentorship or training and don't know where to start and I think it's you know, there's that feeling of well, I'm supposed to know because I'm here now, but I think we can, you know, help help fill in those gaps and and the cracks there a little bit Yeah, there's so many great topics.
I mean I could just keep going. I'm it just just my my brains exploding with ideas over here. I'm excited to get into that too.
You know, one of the things I'm hoping to do is maybe I can make some kind of kind of Connections in the soccer World because the world for security. So those Engineers this change right all sudden. It's like there's there's applications and security and apis and Cloud native and we're kind of getting into the software stuff.
Even when we aren't software Architects ourselves or reading code that we may have people doing scripting and things that are security off. That you mentioned kubernetes and and Cloud native. What's interesting is if you look at that from a security perspective perspective Cloud native is kind of like it's a philosophy and approach like zero trust is a philosophy and approach.
It's not a technology. There are Technologies to use to accomplishment. You mentioned kubernetes mean one, but what what it's really about and I think relevant for us is You know for for a long time the network had perimeters and things that we could protect and usually there's an edge of the application.
There's an edge of the network. There's an edge of where the firewall and where the application firewall is and content filtering and all kind of things happening and applications. We've got into through, you know, 40 or or SSL or apis Etc that we're kind of the external hard layer to the soft interior of the application and what cloud native is is the network has come inside of the app.
Because now AppSec are building really small pieces things called microservices and they all talk over the network. It's an internal Network inside of kubernetes cluster across clouds or cross, whatever. But it's network communications.
And so we we have like instead of one big app or several medium or big size app. We have lots of little things that are moving around and changing all the time, but they're all talking over this network either amongst themselves or to other things. So we just start taking some of the ideas and bringing those inside to the application itself and how it communicates over this through the API Fabric and applying a lot of the security principles that we know and have tried and also some new things so we'll make some of those connections and hopefully make the the world of cloud native a little less mysterious because it's actually not that mysterious when we kind of kill apart that onion and there's a lot of things that we can bring to the table of Security Professionals and software Engineers to start to connect the dots to go.
Okay, I get now I see what that is. Here's how I can help you or you can help us or whatever that might be. So I'm hoping we get to go there together.
That'll be a lot of fun. Yeah, and you know something just popped up while you were saying that because one of the things I hear but both on the the application security side and then just in general kind of broad spectrum statement here is that You know a lot of the Consulting engagements a lot of the professionals I talk to are apologetic to me as a consultant, right? Oh, we know we know we're supposed to be doing this but we're behind we know that all of our peers are doing this and we just aren't there yet and they're almost embarrassed or apologetic about it.
And I feel like this feeling about you know, Most of the time it's almost like you know where they say a social media. What do they say about social media that it's um, oh for being left out or whatever it is. Well, it's it's like you see the best you people only put their their best, you know, like Persona on social media, like look look how great I am or look at this, you know, yacht I'm hanging out on and they're, you know, not not showing you the I'm not even going to come up.
I was I had examples I'm gonna leave that alone here that they're dealing with in their life. And I feel like the security industry is a little bit like this that There's this. difference between What's real and what people think is ideal?
And so there's this this expectation Gap where a lot of people professionals and companies and Boards feel like they're behind or they're not doing something the right way and you know, their peer organizations are doing something else or whatever and you know, I've seen so many case studies whether it's something on the application side or on the network side or just some broad security product. I've seen so many case studies where the company that's listed in the case study. Did buy the product or they were given it?
But they haven't even deployed it yet. So it's like, you know, all of these other organizations are looking in that going. Oh man, they're already doing this, you know, cool whiskey shiny thing and we haven't even done, you know, our basic stuff and One of my other soapbox things is I feel like everybody gets so dazzled with the shiny objects.
You know, it's like let's let's do let's do zero trust and they don't even have you know, basic segmentation done whether that's in workload segmentation or network segmentation. And so there's there's this kind of like this. Foundational knowledge that I think makes you and I are going to be able to do some cool stuff with of all of like the shiny objects are just extensions of foundational pieces and you really need to at least understand the foundational pieces enough to go build that if you don't have it if you want to do the shiny things that are up here and so I think that's fun because that's that's something that kind of those pieces fit together both on the application and Cloud side on premise side.
And I think that's another great opportunity for you know, a show like this with host like us and guests like the ones we're gonna be bringing on. I think that's gonna be great. That put the building blocks in place.
So it's not a shiny penny on the ground, but it's a great. All right. This is how we get there.
Well, let's so let's wrap things up. I do want to mention too that we have some new URLs that we can use you can get you can find this show if you haven't already on Textron dot TV, there's a series menu and it says to see so talk. com so you can go directly to it.
com go straight to it. It's available on all your favorite podcast platforms. So get the audio get audio and video on Apple if you want to watch the video that way too.
tv and our episodes will be about twice a month. We'll be doing some live round tables. Like we've done in the past and and have a lot of good good time and good fun doing it.
So JJ, I'm super excited. If you can't tell already about doing this with you and learning from you and create co-creating and doing some great content together and bringing in some kind of fabulous guests that that will be part of this journey with all this together. The feeling is mutual, especially about the learning that mentioned I have to tell you.
I can't tell when you're excited because you're always just kind of calm like this. So is this is this your excited face? Is this excited Mitch?
I'm always excited. So it looks the same and I'm joking around. That means a man fine.
Okay, good. Great. I'm definitely having sex we will be if you don't like joking.
We will be very serious. on here in our very last episode it was waiting for that one and watch that. Yeah, that'll be the end of the series when we're like But yes, all right.
I'm excited about our next one and getting some guests in here. It's like it's gonna be amazing. When thanks to our team at Textron group are producer executive producer Jody and video production team the web team everybody graphics and promotion and production.
Everybody helps put this on with this. 0. It'll be too but it'll be the next episode of that time.



