From Military Intelligence to CISO: Jonathan Trull on Risk, AI, and Cybersecurity Leadership | ROCon 2025
Jonathan Trull shares his career journey from military intelligence to becoming the CISO at Qualys. He discusses his experience in IT auditing and security operations, particularly in Colorado and Microsoft. The conversation highlights the growth of the Colorado security community and the importance of effective risk management communication with boards. Additionally, the evolving landscape of AI and the need for frameworks to manage associated risks are emphasized.
Transcript
Hi, everyone. We're back here live at Qualys Rock on inaugural Rock on right here in Houston. And, uh, you know, we've been having a great day of, of interviews so far.
Let me introduce you to my next guest. His name is Jonathan Tow. Yeah.
His friends call him jt, so I'm gonna take the liberty of calling him jt. Jt welcome. Thank you.
Text on tv. Yeah. Thanks for having me.
Good to have you on, man. Yeah. Um, You know, I didn't even give him your title or anything.
I'm gonna throw it back at you. Why don't you share Yeah, yeah. The camera right here.
Okay. Alright. About your title and, and give us a little bit of your journey to Sure.
I don't wanna give the cat outta the bag Yeah. But how you got here. Sure.
Uh, yeah. Um, I'm the CSO at Qualys and, uh, you know, how did I, how did I get here is a, a long winding, uh, story. Probably like most, uh, spent time in the military as an intelligence officer.
Um, you know, and, and that, and that's while it was not cyber related right. You know, there's enough overlap where you find this common interest, I would say, of finding the needle in the haystack. I mean, that's what threat intelligence and, you know, trying to find it.
Uh, obviously I was dealing with like, human stuff, right? But, but, you know, it relates pretty well to cybersecurity. And, uh, you know, ended up, uh, just kind of going to that next career, which was an IT auditor.
Uh, then I got into security operations, pen testing. You know, I kind of just kept finding my way around and at some point someone said, you're, you're pretty good at managing people, so you should do that. And started managing people.
Became the CISO for the state of Colorado. Uh, so, so spent, uh, you know, over a decade with the state of Colorado, um, spent five years with Microsoft running the detection and response team. Uh, so primarily just responding to ransomware attacks and nation state attacks and, and, you know, really got back to the, you know, running large teams, but just technically deep, you know, engagements.
And then, uh, sum Ed gave me a call and said, Hey, I, he and I had known each other. He is like, I, you know, I'm looking for a CISO and really wish you'd come back and, you know, help us on the future of the company as well. So I said, let's do it.
I love Qualys. Yeah. So listening to you tell your story, you know, it's a funny thing to grow older.
Yeah. I'm remembering we discussed this Yeah. In San Diego.
Yep, that's right. You were at Qualys. Yep.
You had gone Yep. And came back. That's right.
That's exactly right. And I remembered the Colorado story. Yeah.
Yeah. It's all coming back to me now. You Live in Colorado, Do you?
Oh, yeah. It's good For you. Oh, try to.
It's home. It's home. So, yeah.
It's, You guys had snower already? We Did, yeah. Up in the mountains.
Yeah. I saw my friends out there. I mean, honestly, it's, I love the weather.
I love Fall Falls. Beautiful. You know, I, I spent some years near Boulder, actually.
I have a place in, uh, superior, right? Oh, yeah. Woodsville.
Yeah. Yeah, absolutely. And I started a security company out Boulder.
Oh. Called, still secure, going back early thousands. Yeah.
Um, so yeah, I, it's beautiful. It's beautiful there. Yeah.
And it's a good, I feel like Colorado has a great security community. It just, a lot of people don't know about it. It's a little bit smaller than like Silicon Valley or, yeah.
Well, No, it's Silicon Valley, but you know, the, so I was there when the Boulder thing was really rocking on Yeah, right. Tech, tech stars was launched. That's right.
You know, Brad Feld is a, a friend of mine and Brad, you know, Foundry. And actually my company was in the Mobius incubator. Oh, okay.
Gotcha. Yeah. Right on top of old Chicago there.
Oh, yeah. 36. Great place.
And, uh, and so it was an exciting time Yeah. To be in that community. Yeah.
It really was. Yeah, it is. Yeah.
Um, but JT let's, let's talk a little bit about what's going on here. You know, it's, it's no longer the QSC, right? It, it, it's moved up, I think Yeah.
From being a user conference for a vendor Right. To a, a conference about risk Yeah. Operations.
That's right. Your job as the ciso Well, you have a lot of hats as ciso. Yeah.
But one of your jobs is to talk to the boards Yeah. The exec teams, you know, the literally thousands of Quas customers, right? Yeah.
How is the con, you know, I had this conversation with Zoomed. Yeah, yeah, Yeah, yeah, yeah, yeah. How is that conversation?
Like, Hey, I'm not here to talk bits and bytes with you. Right, right, right. Not gonna tell you how many major critical vulnerability.
Yeah. If you have, I'm not gonna tell you how many intrusions you have or how many patches gotta be done. Right.
I'm here to talk about risk management. Absolutely. How's that play?
Yeah. You know, I, I think it's great for boards. Um, and I would say this started right when I rejoined Qualys.
You know, I think, you know, we were using some old school, you know, kind of heat map, you know, very technical like KPIs and, and you know, it's always a little bit of a dance with board members. But, you know, there's a time where I just finally kind of sat down and does this make sense? Right.
Are you, are you able to understand, you know, kind of the risk? And, you know, we had a really good conversation that, you know, while a lot of it, they sort of got, they had a difficult time, like piecing together how, if I'm making a budget request or when I present a strategy, you know, how was that tying back to, to risk and, and how we're measuring the risk appetite. And so, you know, we started from there and, and then really, you know, dug into honestly, a little bit of the, the parallel was working with my CFO and saying, okay, obviously, you know, you're also dealing with risk and financial risk and currency risk.
And boards seemed to always get that like, like, like they understand it or risk that you're not gonna meet some sales target, get it. And then really kind of the light bulb was, well, it all comes down to dollars and cents, right? I mean, board members are trained, like read the income statement, the balance statement.
And, and so, you know, the idea and, and, you know, working with Summed was, you know, we, we kind of need this, this financially minded like products that can translate to what a board or A CFO would, would understand, like what they're already used to. And, you know, so from there it was really just about, uh, quantifying the risk according to, you know, our applications and the assets that, that we depend on to run our platform. And, and, you know, it, it took us, you know, it took us a couple quarters to, to get it right.
But at the end of it, uh, the board was happy, summed was happy, and, and then he said, well, listen, I think we're onto something. Like, like, you should go talk to others CISOs, and, you know, we should, we should see how they're presenting today and see if this way of doing it is, is something that they would find valuable. And obviously it's been tremendous.
Just, yes, this is exactly what we need. You know, you're right. My board members don't always understand, you know, when I say, you know, we have a thousand critical, right.
What does it mean? Like, what, what should I do with that? You know?
So, so yeah. That's, that's kind of how we got here. It was kind of our journey with our board and working with other CISOs and, um, you know, we still have work to do, but I think it is, we're like, we're really on to something and we're bringing it here to Rock con.
Yep. Yeah. You know, one of the questions I asked Sum and I'll similarly ask you is, do you envision this conference being something bigger than just Qualys, where you'll have other vendors who are risk management?
Yeah. Even security risk manage, right? GRC.
Yep. You know, there was a time where the RSA conference was just about encryption. That's Right.
Yeah. It's obviously not anymore. Yeah.
And not just, and when I talk about that, I don't mean it just at this conference, JT Yeah. Yeah. I mean the, the industry sort of galvanizing around, Hey, we, we need to talk Yeah.
Risk Yeah. Instead of Right. Critical vulnerabilities.
Yeah. Absolutely. I mean, our, that is our goal and our desire, um, as part of the renaming and, and even if you see how we're like designing the tracks now there's business tracks.
'cause 'cause cybersecurity is a business problem. Absolutely. You know, and I think oftentimes in the past we've just technology, technology, technology.
And that's a component, but a huge component is the business aspect. Yeah. You know, and so, you know, I think we wanna open this up and, and, and even like my internal teams and how we're organized, you know, we've gotta bring GRC together with security operations, you know, with all of the other groups.
'cause oftentimes we do work in silos, you know, I mean, in your own team and, and, uh, Especially in security. Yeah. It, it's, it is one of the weirdest things that you, you know, and, and, you know, we're on the same team, but somehow you didn't share this risk because it wasn't your area.
It, it's a, it's a weird dynamic and we hope to break that down too. Right. It doesn't matter if you're GRC vulnerability management team, doesn't Matter.
Right. Exactly. Yeah.
com in 2013 because I bought into that whole, some people say it's kumbaya, but that whole thing of breaking down silos, right. Of bringing Dev together with ops. And from my point of view, coming from security, I was like, we could bring security together with op Yeah.
And SecOps. Yeah. You know, and Dev and I, I, you know, you could see a, a future where risk management becomes that unifier, if you will.
Right. Oh, absolutely. That, that grand unifier across all of these different silos.
Well, um, going back to your talking with your boards and CISOs and exec teams, they're buying into this, right? Yeah. They, they're, they understand.
I, and I think inherently they understand it. Yeah. Because there's something inherently when you hear the story, you're like, yeah, yeah.
Duh. Right. Yeah.
I I lost sight of that. Right. It's of course, it's about the risk.
Yep. Um, how do you, where, you know mm-hmm. Ai Yep.
Times person of the year or whatever, right. How does AI affect this? Where does it go from here with ai?
Yeah. Um, listen, I think AI is, uh, we were talking about our friend, the Cloud security alliance. It, it's what cloud used to be, right?
Yeah. I mean, I remember, and, and maybe I talked about this last time, but I still remember New as the CSO for the state of Colorado. This is many years ago now.
Um, and the CIO at the time said, we're gonna go cloud first. And I can't tell you what the uprising was, both in our employees, other executive, the cloud's the worst. It's gonna ruin us.
How on earth are you gonna share your, I mean, and, and it, you know, it was my job to help settle that down, really get to the real risk of it. But I feel like we're right there again with ai. Um, and for those that maybe didn't live through that experience of the cloud may feel new and scary.
Uh, but honestly I think we're in the same boat. Listen, we need some frameworks that we can all agree to and work within. Um, you know, we need to be able to manage the risks.
Absolutely. There are risks involved. Um, but once you really get into AI and, and this, you do need to get into the technology, right?
You need to really understand, you know, what is an MCP server and why, how's it coordinating the calls? And it takes a little bit to learn it, but it's not like any other, same as any other technology. It's A tool.
At the end of the day, I tell people that. Yeah. Especially younger people.
It's a tool. It's a tool. Humans are great tool.
You Yeah. That's what's made us Yeah. Reach through if you think we've reached the height of civilization, but Right.
Um, but you know, it's from being tools. It'll be interesting to see how it plays out. Yeah.
It's gonna be a fun ride. I mean, I have no doubt that it's gonna be a couple of interesting years and we're gonna have a few bumps in the road. I'm sure that, uh, There'll be learning experience or Are gonna be learning experiences.
That's right. Alright. Yeah.
T so much Matt. Thanks for having me. Jonathan.
Tell CSO here at Qualys. Actually to be fair, you, you have more than just CISO in your title. Yes.
Yes. Yeah. SB Customer Solution Strategy as well.
That's It. We're live at Rock On. We're gonna be back.
We got more for you today and a full day tomorrow. You're watching Techstrong TV.