The Forecast – CISO Talk Ep 29
CISO Master Class Pt. 5 – The Forecast: Great Execution Requires Clear and Consistent Communication. Clear and effective communication is crucial for business success – especially when it comes to security and risk. To effectively explain risk and help the organization make smarter security decisions, CISOs must be able to speak the same language as business executives and cybersecurity professionals to bridge the communication gap between the C-suite and IT.
CISOs need to regularly communicate with their fellow C-suite executives, of course, but must also translate a proper understanding of IT systems, security strategies, potential risks and the necessary investment needed for cybersecurity maturity. Without this, the entire organization is at risk if inaccurate information gets passed around.
Host Mitch Ashley is joined by Jennifer Leggio (Netography) and Mike Rothman (Techstrong Research) to discuss the best ways CISOs can keep key stakeholders properly informed about threats, risk and security programs and why proactive communication is an essential part of high-performing teams and the foundation of a solid security strategy.
Transcript
Well, thank you for joining us for another ciso talk episode. We have a great topic today. We're talking about Communications with some Communications experts.
So, my name is Mitch Ashley. I'm CTO with Textron group and also work with the research part of our organization and I host our ciso talk show and this is part of Master Class series that we're doing it's actually episode 5 and we talked about a number of topics. So please check those out and we have a live event coming online virtual event coming up they'll tell you about at the end with lots of good stuff in it.
So let's get right to our topic but I first want to start by having our panel and just introduce themselves. I say panel. These are two friends colleagues.
Yeah, that's a panel. We're Palin what's up friends? Yeah.
It's a friends isn't like a gaggle instead of a panel. I don't know what you call it when it's friends, but it's still. All right.
Well anyways, so generalizio great to have you on introduce. Yourself if you would I'm Jen Lazio. I've been in security marketing Communications for about 20 years now and currently cm of a company called nitrography, which I absolutely love and I'm just really honored to be here with just gaggle of friends to talk about Communications.
Okay, the term is stuck. Thank you Brandy Brandy exactly talking to the expert. Okay, Mr.
Rothman my colleague the text wrong research. Yeah, so Mike Rothman, I am chief strategy officer of tech strong group and GM of tech strong research and General gadfly and and this topic is actually one that is near and dear to my heart. I've been talking about this for Gosh, 15-ish years from a published standpoint a big part of my book The pragmatic CSO was all about communication at a senior level.
So yeah, I'm excited to be here. I'm excited to see Jennifer. It has been way too long.
I missed RSA. I didn't get covid so that that's a plus but I did not see a lot of the people that I have not seen in a long long time and I miss them terribly so it's not quite the same but as soon box will do for at least the next 35 or 40 minutes exactly and we have somebody we have some construction going on and I'll let you guess who's who's sight it is but anyway, if you're not giving me any of us, we're not gonna Point anything else. It's not a piston in our engine similar back room production.
It's you know, some construction person upstairs. So, you know, Mike I'd love for you to say tell us a little bit about your book because I remember when when the pragmatic see so came out our And that I don't remember if there was any other books targeted at a CSO role at that time. I think it was one of the first was it was so this was in 2007.
I mean it's actually painful to say that and then do the math and go. Wow. I've been doing this for a long time, you know, um, but really, you know kind of it it originated because I had a number of folks who would approach me and basically say I've been thrust into this situation where I have to address the board.
I don't know what I'm doing. I'm now a managing a team. I don't know what I'm doing.
I you know, there are all these other aspects of this job. I don't know what I'm doing. So I tried to write a little guide for folks that are kind of thrust into a management position for the first time thrust into a position where they have to start selling the benefits of their security program thrust into a position where they are accountable to the board and the audit committee and and what is that mean and really The structure for how you do that but the thing underlying all of that is communication and collaboration, right?
You security folks cannot exist on their own where part of the team if anything were a service organization of the rest of the team. We've gotta meet our mission, right which is to protect the critical data the organization, but we have to do that in tandem right working hand in hand with the rest of the organization or it doesn't work. And this was back in 2007.
Right things have gotten a lot more complicated since then we're doing things a lot faster. We've got everything that's in the cloud cloud was like hardly even a thing back then right, you know, it was like a time sharing thing all the cloud right copy. You sure right?
Yeah. All right, not quite sure but you just a lot more diff, you know complicated significantly different than it was but a lot of those core constructs are the same which is your cube is a dangerous place. To spend the day if you're a senior security professional, right?
You've got to get out and talk to folks. You've got to get out and and really sell the Austin and how the advantages of your security program. You've got to work with your team.
You've got to work with senior manager. So, you know, it's just interesting to see a lot of these things, you know, come back around after a long time when we're like oh my God apt right or oh my God, you know ETR and we've got to do this now. It's actually going all that.
I remember the current day a lot of what we're doing is consistent, right it needs to be because you know, that's how we are successful is as leaders. You know Jen we we talked we actually just had an episode talking about incident response and couldn't plans together. And of course Communications is a huge part of it not telling you what you don't know.
There's the formal Communications and of course you you have an extremely a big role in that as well. There's also the internal Communications we're way past the days, you know Mike's referring to of oh we had an instant now, who do we call should we call Legal? Do we call the CM mode we call ahead of you.
Who is that a Communications? Right? We don't talk to them and we're past those those kind of days as you sit in your chair and you think about now about how we have to build the relationships and the kind of communication paths and workflows.
If you will, how do you see the landscape as a Communications professional and executive? So it can back up from that a little bit. I think it starts with how you know, not just the communications process when there's an incident or there's a new program or what have you that the ciso or the security Team master allowed.
It really comes back to I think there's a whole totally new structure of accountability. Not only for the communications with security itself across the c-suite or it used to be all eyes were on the sea sound like csos responsible and the csos heads on The Chopping Block. The seaso goes in front of the board.
There's a lot of work. I think that has to be done at the Forefront that starts with Communications across the leadership team of any organization where they know what their roles are and helping to enforce and communicate the policies or whether it's a policy or awareness or training or what have you to their teams. Um in order to help the security organization and I think that they're somewhat culpable they don't do that and something goes wrong because of some action that might have happened from their teams.
Not that it's a Blame Game you don't ever want to blame but obviously you do again when you do like your post investigation to figure out what wrong, you know, you're looking to see the source of it. So I kind of say I when I think about it now, I take a step back of I mean think about any policy roll out to a company you can't just be like for us. So for instance if I roll out of calms policy in general and my company can't just be me shouting from the rooftop saying everybody do this.
The cro has to kind of engine CTO has to Etc with their teams. It's not one person's responsibility and that's very similar to see so so now answering directly your question. I think when you get into the communications process now, it has to be a whole leadership response and Communications product project very quickly and the CMO is heavily involved because we're more likely to communic Pros or have them on our teams internally to to make sure that people know what they have to do next and then eventually controlling what goes out to whether it's SEC report or a broader communication so long answer, but I really it's really something that's been eating at me for a bit that I really think people need to think about and talk about the whole executive team is responsible for security.
It's not just the CSO in their team and a vacuum. I don't know my what you think of that. Yeah, I think let's take it in two parts.
I love the way you speaks directly to what Mike was talking about of that time. The communications happened. Yes.
There's a hopefully a well-oil plan that's been worked out but that's all built on relationships and communication paths and understanding what's going on. Well before anything out else happened because you know, you don't want that education and learning to all have to happen the time or the day or the minute. You've got something hit I think Mike that's what you talk about.
That's what you're you talking about investing all of the time and building those relationships and not talking down to people about security but helping figure out that translation from security ease and to business or into customer or whatever language. Yeah, I think that's right and and there are two points. I want to make to you know, kind of piggyback on on Jen's point and and one is to reiterate the importance of Senior Team alignment, right security is gonna ask the rest of the business to do certain things.
They may not like those things, right, you know, we've got a test this stuff. We've got to kick things back if we have a security defect we may, you know have to quarantine or take down. Active systems that are customer impacting because we possibly have you know, some type of data loss.
We've got to figure that out. Right? These are things that Business Leaders want don't want to hear about two don't want to do right.
So if you don't have that alignment at the senior level it doesn't happen, right you can get in and you know, I'll use a term we're gonna try to keep it a family show right, but I call it green effing right and use your use your imagination in terms of that. It's like, oh yeah. I'm doing that no weapon way.
Am I doing that? Right, you know and they'll tell you right to your face. Oh, that sounds great.
Right and and they're you know kind of relaying that back to you know, kind of their team that says we don't have to take that seriously, right? If you have the senior folks like the CEO right the chief legal officer or general counsel or the CFO in there basically saying, um, no, this is pretty important when we've got a critical vulnerability. It's something we're about to ship, you know to customers or you know, obviously software we're gonna ship to customers.
We've got to block the bill, right? We've got to break that build if we're in a devops, you know type of mentality and they have to have the air cover from that perspective. Right?
So so one without alignment none of this stuff works right without you know, kind of seeing your level buying for the fact that security is a corporate imperative and and really the the way to know this right is Um, I've never spoken to a CEO who has told me security is not important to them. Not once right. It's what they do, right?
They'll say what they think they need to say. It's what do they do? Right do they fund it do they support it?
Do they, you know kind of allow Business Leaders to kind of go around the machine or or you know kind of obfuscate and and violate some of the policies that were there. If you've got those kind of issues mean you don't have that kind of alignment. So so without the alignment, I mean, you're just you you're nowhere and that that really I think is is highlighting the point that Jen made is that if everybody's not on the same page, you've got very little chance to have a successful Communications program because you just got a bunch of different messages flying around within the team.
Say some more about your experience Jen from the alignment perspective. What are from a Communications professional? What are the challenges you experienced him Mike and I can probably talk more about the CTO and the CSO see so side of it.
What's your side of that coin of getting everyone on the same page? and hurting cats It's interesting is that you know, I've spent most of my career working for security companies and they're not we all know security companies are not immune to incidents. And so you do have to you have to have those crisis Communications plans and escalations and all of that stuff developed and and know what to do and I think you know, it really depends on the or the size of the organ the CEO.
I think Mike nailed it said, you know, it's really top down CEO says Securities are important to me but allows marketing pick up my people marketing to use a bunch of cloud apps that aren't sanctioned by the security team because it makes our jobs easier. Maybe we get more leads and faster and he or she or getting pressured by the board, right? Then all of that goes out the window.
So for my experience, it's it's there's always a kind of like not me not my issue when something happens in my experience regardless of the company regardless of how wonderful the people are involved. Um, and and I think you know before I get into what I think should happen and it's there's always in my experience. There's the first question especially again outside of a brief stint.
I was at Cisco after an acquisition and my time at sourcefire. We are public and I was involved in this piece there, but I'm mostly wrote for smaller private companies. So there's not as much of that like regulatory pressure to actually report things.
The first question is awful. Do we have to say anything do we even have to communicate this? Can we sleep this under the run and help the Bryant Crest doesn't find out about it.
That's the first conversation that happened but happened to me at a company not long ago. Not the one I work for currently where it was basically all the conversation. I was screaming like we need a plan we can't risk this we're gonna lose customer trust.
If we don't tell the customers what happened, even though it was a minor non-material data that got out there because of a user error and it wasn't an issue with our product. We have to own that they show us not to own that I don't think it ever came back to bite them good on them, but I think that's that. Me and the CMO role and even when I was in the communications officer role like that drives you insane because the first thing as a business no matter what your role is should be about trust and integrity and how you run the business with your employees customers your partners, whomever else and every single executive on a team is responsible for Revenue reputation business continuity and everything and across that line, but unfortunately in my experience, it's really varied in there are some folks that have been like, all right, Jen you've done this you lead us you help us and of course, there's lots of inputs from the technical teams because I'm only technical enough to be dangerous and then there's the ones of like Jed how do we hide this and that I'm like I won't do it and that creates all kinds of internal conflicts and then I don't stay long.
Up, it reminds me. And I think that's an important aspect of that. Right?
If you can't get that alignment and you don't have the support that you know, you need it's unlikely that you're gonna be successful. So go find anything and and if you're on this call and you're at a seniors security professional level, I suspect finding a new gig won't be all that difficult. Now, you got to find the right thing.
You got it and I don't want to minimize, you know kind of the the, you know, kind of considerations that go into making a move but I can tell you if for something that I believe is relatively simple, right which is if we've done something wrong. Let's craft the message that we're not running away from it, right, you know, we want to be honest and and you know, and you were joking about you know company you work from like She worked for okta right because they were obviously of now and I know it wasn't that but they were obviously an example earlier this year where they had a very very minor issue. I mean, it was some third party reseller and stuff America that you know, somebody got access read only access to two of their customer accounts.
I mean, we don't only right. I mean this is this minor as it gets and it became this big Fiasco because OCTA just wouldn't come clean, right it cost them in stock. I've talked to a whole mess of investors about I've lost my confidence in them and customers.
You know, what should I be closing this deal and and all because they didn't say it was a pretty minor thing. Some dudes got read access. We fix the issue, right?
We've locked down that problem and we're moving on right and they didn't do that. It was obfuscation. There was you know, it just felt wrong, right it felt like they were hiding stuff and if it feels like they're hiding stuff man.
That is not a good place to be in. Right, but it all gets back to this idea of trust. And collaboration right?
And then let's you know kind of segue into the whole business centricity of what security has to be now, right Jen works for security company, right? So you've got some specific considerations because you work in a security company right reach happens for security company bad news. So we have to be, you know, probably more over rotate on that front right financial information Healthcare information.
All those work customer information is at risk, you've got to over rotate on security you make bolts I mean, I'm not gonna say we're gonna minimize it but in terms of my investment priorities, I don't know that, you know kind of Securities. I mean maybe if you have some patent on your boat That's um, but if you just make a crap ton of bolts, not a lot of Ip in the business. It's really all about operational excellence, you know, maybe I have different considerations and that's really the point right you build your security program for the company you're in for the business you're in for the culture that you're in and you've got to be able to really modulate what your processes are gonna be based upon those considerations because you know, you come from mortgage Stanley and you show up at you know, kind of a very small Credit Union and they're like, oh my God, this is the you know, the second coming because you know of all that great experience, you'll find out pretty quickly my consideration and and a small Financial platform are far different than in, you know, a global ten Bank.
Right, true size definitely says the company impact to Market presence Etc. I make a huge huge difference. So let me present the other side of the coin you can you can agree or disagree.
We're also numb to the announcement of security breaches. It's you know, it's not a daily thing. It's a hourly minute by minute thing almost and yes, there are the high profiles actors or it's not the days of Target, right, you know back when someone is a credit card records got stolen in a way.
It's to your point Mike. If you go and hide it you're guaranteed you're gonna make a big deal about it. Well YouTube you made that point to Jen but if you disclose it, you know, here's what we did what happened you're doing about it.
Here's what the impact was Etc. Yeah, it pretty much moves past you unless maybe a security company has got a bigger impact because you're not, you know, the fact is all companies either have Will are both get breached. It's it's a fact of life.
It's just what we were all do we did we live in have we gotten to the point where we're so numb about it. It doesn't matter just disclose it and move on. What do you think again?
He's kind of edge case here. I would well I should say I would hope not. I mean, I I am happy that.
This is a double-edged sword. Right? So obviously there's much more frequency in the disclosure of reaches now.
It's not in the days of there's one big one and everybody talks about it for two weeks. I am happy that because that that a lot of the The the what's the peanut gallery kind of everybody like assessing what must have happened with that company and blaming them and saying what they should have done stuff has stopped right and it's become something that like be careful what you say because this could happen to you tomorrow, right? But on the I don't think you I I don't think people have become numb to it.
I think they've gotten to a point of I've accepted that. I'm going we're going to get breach. And we need to prepare for it.
You still have your like people out there like babbling on Twitter about things they don't know anything about but I think it's less numb and more about like another moment of okay, so this isn't getting any better. Why are we not stopping this and why are these things still happening? But I guess I better make sure that I bring this this new example up with my board or with my security team and alter our plans accordingly because we don't want to make mistake that they made and you're constantly in wackable mode.
Just waiting to see what's gonna happen and to touch on your point. Like it's a totally different. It's totally different situation if you're a security company, right because when you're security company and something happens, you know, that's that's huge.
I do think it comes down to how you handle it. And the biggest reason I think some security companies try to hide it is they're afraid to lose deals and flight. And that's the biggest mistake because then you lose renewed customers which is much bigger.
It's much more expensive to get a new customer than to keep trust with an existing customer. So I think that's I don't know that that was kind of a flurry of thought you guys know me, you know, that's the way I think but that's where I am on the numb versus not numb and how to react and how to remediate your calms plan as new stuff happens. I I think we've gotten to a point where you know breach notifications have been normalized.
But there are three situations where it's you know, it'll make news right first to scale. So when you start getting into the you know, all right, 150 million, you know kind of Records that's kind of passe right? So when we keep hitting these additional, you know, kind of levels.
Oh my God 300 million, right? Oh my God Facebook us and in a billion, right? I mean that's gonna be next right?
You know, so it just what when they're scaled there's news in that right something that's just particularly aggregious and stupid right, you know kind of that is that is you know, that'll make news because you're just like really could they have been that stupid right? So so folks will jump on that because they just love the story of somebody that was just, you know, ostensibly does something that it just so dumb that you you can't believe it. It's like shocking and it's idiots.
So you just you know, like I'll cover that let's talk about that because that's just like the dumbest thing I've heard and then something that is new and Innovative, right? You know when and I'll use the example from a couple years ago and they're obviously new ones. But but when some of the details around stuxnet came out right that made huge News why because it was a space alien attack.
You were just like, oh my God, I didn't know that was a thing. That's a thing. Oh my God, right.
So so we started talking a lot about you know, kind of what other things that we didn't think I mean air gap. I see your air gap and I say screw that I'm gonna you know, totally transgress your air gap, right and everybody who's like, oh my God, I put all my stuff in an air gap and I not safe and secure on that front. So so you have all those issues and we kind of dove into and and hit on a lot of the technical things.
But the point is you need to have a plan right to Jim's point, right? You need to have a communication plan for the fact of what happens if right and part of it is kind of a game. It's not a life.
It's not a lot different than threat modeling. So all my security folks out there, right? I mean you're sitting there going How could I get killed today?
Right and then so when you figure out okay, this is how I can get killed today. Then you gotta say what am I gonna tell to the markets? Who do I have to talk to?
How do I have to keep my board, you know and my audit committee on board and and in line from that standpoint and it starts to become again just more of an external Communications threat model than it is, you know kind of an oh, how am I gonna protect my systems or model what the mentality is the same right? And I think that that's a metaphor that that can really help security folks and start to understand. Oh, so if this happens I have to have a plan for that.
Well exactly and by the way, you can't make that plane you have to go find the Gen in your organization who's gonna help you craft those messages and make sure that you've got a process in place so that when something does, you know go down you're ready to to really kind of go into action. Just like if you find out somebody's device got compromise, you know exactly how to deal with it, right? Same same thing but different.
I'm curious Jen. Do you from a marketing Communications perspective, do you have different scenarios of the kind of security incidents and what you're going to handle that from your perspective? I'd love to learn from you.
How you think about that problem? Yeah, so most of the that's that's a good question and that's good for people to consider especially like I think I read this it was in an exeby report. It was like everybody has to be in the assumed reach mentality now and I thought that made a lot of sense and so you have to kind of be in an assume preacher soon to attack mode as a Communications professional as well.
And so the scenarios I just made me a few but it even goes beyond security when you look at crisis. It's like a death of an executive. There's some kind of harassment issue.
There's some kind of other legal issues. There's a financial issue like there's all you know, you have to just like that you have your Communications trees and you have it for like was it an Insider issue was it an accident wasn't? Actual was it a nation-state situation was it?
You know, was there a flaw in the product? So you have like what type of response was it who needs to be in the know immediately who needs to be part of the communications planning who are the immediate audiences that you need to communicate with? What do you need to communicate?
What do you need to do to do your risk assessment? What's the worst case scenario of what's going to happen kind of what Mike was saying with threat modeling. Like, how am I going to die if this goes wrong right?
Like what do you do? Okay, so they received this message here the five ways they can react to it. So how do we respond to those things for every single scenario?
Whether it's security or not anything that in fact that could impact the bottom line of your company you ever Communications person to have it my company's like how many small right I've been with photography for six months now, we're small series a startup. I haven't rolled anything official apps with a company. Answer it's small at this point.
But I have a lot of my back pocket. Should we need it? Because I just know that in my role it would be irresponsible as a CMO at a company that size.
I am most of the calms person because we're small marketing team. It would be irresponsible to not have these plants. Right and even if I haven't already vetted them with my boss or the CTO remember else that needs to be involved yet because of the size that we're at I need to be ready to in a moments notice.
I think every marketer should keep that in mind and building trust with the security team that's really hard because a lot of security teams don't trust marketers because For all the reasons we know right with just crazy fun and all the things that I you know, I'm trying not to be able to have but you never know so you really have to build that trust to be like, hey, I'm not gonna screw you over whether you have something good to put out or if you have something bad to report. I'm your friend and we are a team. I think that's really important.
You got to be ready for that. It's got to be documented. Security people don't trust anybody.
So don't feel bad. That's fair. That's fair.
That's fair. I'm just saying maybe some marketers might have earned it. That's all that's some more.
It's let's got you know shift a little bit in terms of the mechanics of the program jamming because I think you know what when we talk about kind of rolling something out like this. Um, I mean, how often do you communicate the folks? I mean you'd sit.
I mean you're on exact team meetings and you know, you tell your story when you do that is that sufficient. What if the sea so isn't in you know, kind of those meetings how often you have to get in front of these people. Is it a FaceTime thing?
Can I do leverage Communications a newsletter, you know a weekly video. I mean what you know when you're trying to think about rolling out a Communications plan and you know, obviously we're talking within a context of you know, kind of security program security policy, but we can even broaden it because I think a lot of the techniques and tactics are gonna be the same right? It's it's about how often do I get to them how much repetition do they need?
Um, you know given what all the stuff that's flying at. Everybody's head every day, right? How often we have to keep it from them to make sure that that kind of what we're Them out is is front center.
How do we not get, you know kind of bogged down with all the other, you know, kind of nonsense that's out there. I mean, did you kind of have some some you know points or things that you've done, you know, as you roll out Communications plans and some of these companies you've worked in. Yeah.
So again, it really depends on the size and the maturity and where we're at and the risk level right for where the company side but in terms of rolling it out, you know, you make your list to the Keys takers the stakeholders like who are the must have teams maybe the leaders and maybe some folks on their teams that have to buy into this because they have to action it and then who are the nice to have now some of the nice to have maybe the other some of the other Executives but they still have to be engaged and informed right? So, I think it's really important. So I I never rely on executive team meetings for those types of things one.
They always go off agenda no matter what because they're so we song customer issue or some other thing. Are some the board wants something or there's you know, there's always something that throws those meetings off. Right?
So there has to be there's almost like a Communications type Council or whatever you want to call it. That sounds a little maybe too formal but and conceptually a council where it's like, all right. We're rolling out an overall Communications policy for the company.
Here's the formality. Here's the overall overarching if when what who Etc HR and CEO and usually the CFO because of the whole remediation reputation continuity are involved in like the Baseline of it. And then for the different scenarios, there are the must have folks.
You cannot roll it out unless you have buying of the people and you can't really you chase them down. If you have to right it's a dependency to be able to do it and I know that sounds really silly but there's not silly but basic is like you chase them down. It's like I must align to see CFO on this I must align with the sea.
So on this and there's Also the and then you know, I must align the cro on this because the cro has to agree on how we communicate to the customers. They're usually the ones that like at the least that you have to put these things out there, of course, but the the Smart Ones the good ones, you know comply with it because they understand the long term impact and and then you don't check off and actually roll out the plan until all those people are there for it and when you roll it out to the company you have all those people usually do a company-wide meeting followed up with a written communication. You have every single one of those people that are the key communicators for it speak during that meeting.
So every team here's it for the most important folks and it's not just coming from marketing because that's gonna be a big failure. No offense to my people out there, but you know, we all have lived it. They're like I was a marketing Thing versus.
Oh wait, there's the CEO. There's a seesaw. Mmm.
What's wrong? Let's listen. It's just fact.
It really interesting because it seems like one of the symptoms of the unhealthy situation is Jen just keep us Off the Wall Street Journal front page Mike, whatever you do make sure there's not a breach right? It's sort of that you own this and don't ever let that happen. You know, I've been in those situations.
You're like, yeah. Well that it yeah. Sorry, but this is gonna happen.
I hope we're never On The Wall Street Journal front page. We're gonna be on somebody's front page at some point time. It's just gonna happen probably I actually think that's that's a very important Point Mitch.
Is that how do we start to communicate and Really impart that urgency and importance of what it is that we do to a lot of these folks and it's not about you know, pointing to a clip from 10 years ago about the APT or whatever the bridge to Jour is, right, you know, whatever Krebs has been up to Brian crabs right now. That's we got two crabs. We got to deal with now, you know, Brian Krebs on that front, you know what he's discovered and I think a lot of it gets back to you know, one what we were talking about before, you know, kind of collaboration having those relationships, but being able to frame the issue within the context of the business, right and that's the our word right risk.
So what you have to do is I mean we think about security issues right most sees those do right you think about things within the prism of security issues, but what you have to do in order to really be a convincing and and successful leader in security is be able to translate that security problem into a business risk. All right, and you can't do that if you don't understand the So this is something I you know on our last episode I got on the soapbox and it was kind of awkward, you know, it's down the zoom box and I'm you know, it's a soapbox just wasn't right. But you know kind of the importance of that it was a center but the importance of that was really about just again, you know kind of beating home that that message that if you can't frame your issues in business terms that business people are gonna understand you've got no shot, right?
You know again you Jen you got to do it, right, you know, you're talking about positioning or other kind of things in a way that the sales people have to understand right in the way that the engineering folks have to understand what you can't build it that way. It can't look like that because we've got to tell a different story same thing insecurity, right? If you can't frame those issues within the context of something that's gonna impact the ability of the senior leaders to make their numbers or achieve their goals.
You are just in the way right? And if you're in the way they've got you know these magical Hours to make you go away. So so part of that again.
It really about relationship building but it's also about ensuring that you understand and have the contextual Nuance of the business to be able to make sure that folks understand about you know, what that process looks like we get breach here because one of your folks didn't follow the policies it plays out like this which equals bad day for that executive. If you can't communicate in terms of bad day Miss bonus right not being able to do the country club, although that's an old thing right, you know. Use that example all the time.
I know you gotta do that so they can make their car payments whatever. I don't know that that's kind of old school stuff right now. It's really about you know, kind of being a steward for the organization and making sure that they can meet the needs that they have, you know, the diligence to ensure that they're protecting the assets of the business.
Yeah, I I mentioned I'd like to add something to that. I think you know, I used to talk a lot about how every marketer or calms person whether they work in security or not. I've done interviews about this Mike you not talked about this.
Like I've done talks about this and regardless of the type of company that you work for. You should have an understanding of security and how to communicate research or findings or anything that might impact your company right? But I think now it's gotten to the level of you need to get every single marketer or Communications person needs to have an understanding of breach response.
And how to have and how to build a Communications plan internal and external to manage that and there are a lot of firms out there that will charge you a gazillion dollars and probably not do a really good job to help you with those things that you can run to but I honestly think that the most the most like any any again any calm some marketing person is responsible for reputation business continuity helping with Revenue all of those things. So regardless of the company that you're at and the industry BBC whatever maybe not vote Builder as Mike said you need to educate yourself on how to handle these things because they will inevitably come up in some way whether your team your security team comes up with some random thing. They want to take to the market and you can't be blindsided by it or your company gets it.
Well, this is a this is a master class Series in what we mean by that it's it's it's sharing knowledge. It's helping people that are progressing to their career. Maybe they're aspire to or they're the vendored into a ciso role.
Maybe they're in one for a while and you know, we're all always learning but it's it's still, you know, you're making that transition from super technical to now I got to speak business to why don't we wrap up with this this thought? I'm what is it Jen in I ask Mike you kind of the other side of the coin. What is it that you either hope or wish that Security Professionals knew would learn that you see from your from working with multiple ciso ctOS, technically.
In your role. What is the one thing you kind of one or two? I think I hope they kind of figured this out because this is gonna help them a lot.
And is there to help you Jen? Just you you're their friend others and their friend. I'm a friend of every season so oh, yeah that the bed.
Know that there to help them. and to plan early to plan early so it's not a fire drill. I mean, it's always going to be a fire drill some degree because you don't want to be doing these things but early and build trust here with your marketer and work in tandem with them to build Communications plan.
So it's not a bunch of push and pull and you don't have your marketing team out there trying to represent you without your buy-in because that ultimately leads to the mistakes that publicly look like you were responsible. And that's not fair to anyone right? Those are my two things.
I wish. It's a good point because you know, we talked about cesos keeping their job right when something happens and I would venture to guess if you don't have a great relationship with your CMO, certainly there's trust there. You're probably going to be on the end of losing your job because it's not gonna go well externally, right really good point Mike from your perspective.
What do you wish upcoming maybe existing? She says new about this issue around Communications. Um, that is the higher in the organization that you climb the more your job is predicated upon relationships influence and persuasion.
And that's a very hard thing for technical people to get their arms around right? It's like but I did this it worked out. It's a and I told the story, you know, Mr.
Van, right, you know, you may be right but you'll still be dead. He was my driver's ed teacher and you know kind of told me when I was about to do something that was right, but it would have resulted in me getting into an accident. It's the same kind of thing right you may be right but you're not gonna be successful.
If you can't figure out how to frame that in a way that the your peers on the team, you know, understand it and and remember we're service organization. We don't in few cases does the security team contribute to the revenues of the organization? I can certainly impact the revenues the organization but in terms Contributing their revenues of the organization less.
So right which means we need to ensure that you know, again, it's a position of influence, right somebody who's responsible for huge deals, right bring in huge amounts of money the organization they they can kind of do kind of what they want within certain, you know parameters obviously, but they get a lot more leeway than somebody who's really a service organization to the rest of the business. So if you can just get your arms around the fact that you know what this is not about my proficiency in you know, keeping all of my desktops, you know updated or all of my servers, you know kind of at the right patch levels, right? This is about making sure that we've got an agenda.
We've got a Communications plan. We are communicating that to the rest of the organization understanding why they're doing that we talked about the why a lot, you know kind of in the fourth master class, right the importance of understanding why we're asking people to do this stuff makes it a lot easier to go down especially if they don't like to do it, but really just to get your arms around the fact that my Now is to influence and persuade and less about you know, kind of actually doing security things like you've done for most of your career. Really good point.
It's about Communications believe it or not. You know, I heard a phrase once you remind me of Mike, it's great to be right. You just don't want to be dead, right?
We're I first a lot. I've said this a lot like do you want to be right or do you want to be happy? Do you want to be right or do you want to be successful?
Right? You can sit in your you can sit in your your opinions all day long and hold to them. But if everything's blowing up outside the wall, that's right.
Yeah, so that's good good. Yeah. Well, it's been fantastic.
I want to remind everybody our audience that we have our kind of live interactive wrap up episode of this series The Master Class we call this master class catching lightning and a bottle. com. They'll be a registration page there for webinars.
That's what it's listed under. So it's live as in we interact with the audience. We incorporate your comments your questions your suggestions.
Sometimes it goes interesting places that always is actually and we will try to touch on the topics that we've hit on on across this master class Series, so Jen thank you so much. You truly made it a master class with your presence your knowledge and experience and it's great to do with us with a colleague that we know and trust so well might my friend colleague as well. Always it's a pleasure and we talk all the time.
And so I learned something every time so it's great. It's awesome walking around smarter every day from you both and I know there are audience is to well as well. Thank you everybody for joining us for ciso talk our Master Class series, and we look forward to having you join us on the 30th of August and be sure to tune in.
com. Thanks to you both Jen and Mike. Thank you.



