Communicating with your IT Department

Listen to learn the steps to improve interpersonal relationships within your IT department.

Updated:  
October 12, 2023

SecurityMetrics Podcast | 30

Communicating with your IT Department

"It's the nature of our team's roles that there's always going to be trade-offs. It's hardly ever a simple decision between A and B. So you need to lean into that and get more comfortable with ambiguity."

Having clear and open communication with your IT or security team is essential to maintaining a secure business. Although, if the correct steps are not taken, working alongside these teams can be challenging.

Dutch Schwartz (Strategic Lead of Amazon Web Service’ Global Security Services) sits down withHost and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) and talk about how to build a straight-forward, strong relationship with your IT and security teams.

Listen to learn:

  • Steps to improve interpersonal relationships within your IT department
  • How to maintain good communication between departments
  • How to approach problem solving tasks with multiple teams

Resources:

Dutch's LinkedIn: https://www.linkedin.com/in/dutchschwartz/

Dutch's Twitter: https://twitter.com/dutch_26

Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide

Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide

[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.

Communicating with your IT Department Transcript

Hello, and welcome back to the Security Metrics podcast. I'm Jen Stone. I'm a principal security, analyst here at Security Metrics.

And today, I have with me someone who was with us in our, last season, Dutch Schwartz. Dutch, welcome. I just wanted to say, I don't know if you knew, we got an award for last season.

I didn't know that. That's awesome.

Congratulations. I'm just saying that a portion of that is because you're fantastic. And I I'm gonna actually read out your your bio here because you've got so much cool stuff going on. Dutch is the cloud security strategist at, Amazon Web Services. And, let me just read this so I don't get it wrong. Dutch Schwartz has more than twenty five years of experience in technology from security startups to several of the world's largest companies.

Having worked with more than fifty c CISOs of Fortune five hundred companies to collaborate on cybersecurity solutions, Dutch understands the evolution of CISO responsibilities and the challenges which security teams face in the cloud. A sought after speaker, he acts as a panelist on security topics and is a frequent guest on CISO podcasts and this one. Dutch holds a master's of business administration in global management, certificates from MIT Sloan Management, and Harvard on cybersecurity, and was a strategy and planning officer in the US army, which is very cool. He melts his formal training with his practical experience in cybersecurity to develop cloud security strategies for customers in Amazon Web Services. What did I miss that you wanted to talk about about you?

No. That was great. Thank you very much. I appreciate it. Yeah. Everybody sort of hates the bios.

Right? Because you like, it's a a piece of the the puzzle, and you're all just sort of like, oh, gosh. You you it's hard not to feel slightly arrogant and off when people read your bio. But I know.

But that's what it is.

But, you know, if we're gonna talk about something, it it helps even talking about this nonsense with me? Not that cybersecurity or your bio are nonsense. I just realized what I said.

No. No. No. No.

That's fine.

Some days, I wonder. Okay.

Super excited to have you here because I've been wanting to do this particular topic for some time. And and it's a it's a topic that all of us can relate to. It's a topic all of us understand. It's a topic that all of us probably have good commentary that we could bring to this conversation. And yet finding one person to sit down and really dive deep into the topic is has proved challenging. And so our topic today is communication in cybersecurity, not just within the team itself, but from team to team internally and then, also externally.

So communicating, speaking to cybersecurity, this is not an easy, this is this is not an easy task that that we have, to take on board.

Yeah. I I think it's, I I don't wanna sort of, you know, over rotate and say it's incredibly difficult. I I think to be the the maybe the clearer description is it's not something that everybody's really trained in. And so when you when you lack that, so then you lack the context, you sort of sort of that starts to build on what makes it challenging. So I don't think that the the the things that we're gonna talk about today are very standard things that psychologists or social sciences, everybody, then and they'll just resonate because they'll match, like, your personal experience and your personal life.

Right.

Right. Sometimes we forget to sort of bring those things correctly, you know, or or appropriately into, like, word conversations. At the end of the day, you know, if you and I are peers, you know, at a company, our business relationship is is is a relationship. It's like every other human relationship.

Right? And so there's a sort of a magic, you know, kind of a flow that you get into where on the one hand, you don't wanna be so abstract, it's only work and it's become sort of dry and it's not engaging. And and on the other hand, you know you know what the TMI over sharing that you know that I guess beyond the other end of the spectrum, but but at the end of the day, it's still people connecting with people. So really the things will I'm sure talk about today will will be things that everybody will go.

Oh. Yeah. Yeah. You know what? I know that in my personal relationship, or I know that with, you know, something I do outside of work.

And so that's what I would suggest to people is bring those experiences, you know, around communication. But I think the real lack there is we we we don't talk about a lot. And I know you've had Naomi on, I've been on with Naomi Buckwalter before. She and I talked about it one time sort of after after a a podcast, and and she expressed sort of, you know, gosh.

I I wish we had all of these things.

All of those things included communication, training. And I said, well, it's out there. Like, it exists. It's just that our particular domain hasn't been really, you know, I'm not sure why, but we haven't been really pushing it.

Just in the last couple of years, right, people really recognize that that that's really critical to your success. And certainly, when I interview, when I talk with my peers and my team members, that's part of my point of view, right, is that what will likely make you successful is the emotional intelligence stuff. It's the leadership skills is the communications that will differentiate us, right? If we're both great and, you know, we get hired to deep, you know, Python, it's probably not my skill versus your skill that will ultimately really make a difference.

What's gonna make a difference is all of these other things like communication.

Right. And as I was prepping for this conversation with you and and the topic itself, it made me remember the reputation that IT specifically and cybersecurity as a subset of IT has had.

It it kind of harks back to, the late, nineteen nineties, early two thousands. Do you remember the guy on Saturday Night Live? His name was Nick Burns, your IT computer guy.

Sure. Yes.

And and he was, you know, he'd sit down and move and then, you know, be very rude about whatever it was and make be belittling and make people feel bad about themselves. And then he'd say, things like, you know, you're welcome. And and it was funny because it was true.

Right. Yeah. There's always a kernel. Right? Or else it doesn't resonate with people. Right? So there has to be some truth to that.

Yeah. No. Absolutely. And I think, again, we could delve into the history, try to sort out why it happened the way it happened, but it doesn't it doesn't really matter today.

What matters today is there is kind of a history of that that's still sort of latent, you know, out there. And it's really probably because security specifically did come out of the I the IT function.

Right?

And so, you know, often, it came from Jen raising your hand and saying, Oh, I'll do that. I'll be the one who does that. And either it was because you had an interest, like, Oh gosh, I did some hacking and that was really cool. Or whatever, that got you interested.

Or you just sort of proactively call it We don't call it hacking.

We just call it, hey, I needed a a resource that I couldn't get to. That's all that was.

Well, I'm a Chris Roberts fan, so I use hacky the way he uses it, which is actually a positive.

Right? It's a positive story. For sure. But but whatever it is I get you interested.

So the the reality is that it was very informal. Right? You know, twenty fifteen, even really a decade ago. Right?

Yeah.

So then because of that, when you have less defined career paths, when there's less obvious, like, oh, there's path a, b, and c, and here's how you could get into those, then people make their way in.

The the the challenge sometimes with that is when you're sort of know it's on grandiose, but a self made person. Right? Because you you just sort of built your own career is it's hard than not to think, oh, well, this is the path.

Right.

You know, we're like the Mandalorian. This is the way. Right? You have to do it.

You have to do my this is how I came up, and it's totally valid how Jen came up or how Dutch came up or how, you know, Cynthia came up. Those are all totally valid, and and you shouldn't throw those out. But also, it may not be from a teachable, from a coaching training standpoint, useful, you know, to to people in in a more general sense. Right?

So communication skills is one of those that people arguably probably rose, you know, whatever that means in your organization, you know, to be, you know, to either from a formal, you know, team leading and a honor function or just became well known because they innately had good communication skills or they invested in those. But Right. I think the broader message that we're talking about here is it's critical to everybody. Right?

You have to be able to do that or the days of just being, you know, sort of the the smartest, you know, person on x y z topic, the the utility of that isn't isn't really high. You can't scale it.

Yeah. You if I can't teach it to somebody else, if I can't hand that over when I move on to the next thing, then it's and it's not the utility is really low. Right? Yeah.

And so that's where you have to think of, you know, training, coaching, scaling, bringing more people in all the things that we sometimes, you know, complain about as a more generally in the industry, those are all coachable moments. Right? So we have to stop and say, well, how do I help other people get better at communicating myself? You know, how do how do you get better communication skills? Because it's really critical.

And to your point, you know, historically, with the, you know, teaching it to yourself and or figuring it out as you went along, that that was a very different mindset than what we have now, which is we do have ways of learning how other people have learned. We do have ways of gaining, gaining that knowledge that are more step by step and prescriptive. So it's not like, and so I think that there are reasons that the mindset kind of existed in the past, but that's the past and this is now. And so now we look at where are we now and how do we then, regardless of what maybe the reputation was, regardless of what communication, lack of techniques were in the past, we are now in a situation where we can definitely learn from each other and have a positive, way of doing it going forward.

I had an interesting moment with a colleague the other day, where he and I were having a private conversation. And I said something about, I personally work to bring my best self to every single conversation because I know that I have been guilty in the past of being short with people, being impatient, being dismissive, being the things that are not positive and supportive in communication. And so now everything I do is what can I do to support whatever's going on right now in this conversation, in this group, in this dynamic, and and bring that person? And he said, oh, I just thought you were kind of being brown nosing.

And I just thought, oh, no.

That's interesting.

So did I I mean, did I take it too far or was his, you know, kind of older guy, maybe his perception of how we're supposed to be in this position was a little something different.

And frankly, he is kind of grumpy a lot, but we all have kind of our own baseline, right? And so actively looking at what is my responsibility in this moment of conversation and how can I make it comfortable enough for all of us to be heard and then Mhmm? Find the best way forward together. So that's that's kind of how I approach it. But, it was an interesting kinda gut check on it.

Yeah. Well but it so so one of the points there is, right, is is the transparency. Right? So by having the conversation with somebody else, you can say, hey. I've been thinking about x y z a lot.

And maybe in this case, you can see it's communication skills or empathy or connect with Right.

Tell other people that because then then they understand and it can at least appreciate where you're coming from.

Sure.

Yeah. That doesn't have so that's one of the things that's that that you need to do is consciously talk you think about it and then talk about it with other people and say, hey. You know, I've made a choice. So So I'll give you a simple example.

Like, on my team, I happen to be the the original person on my team. So, which zero percent makes me special, but I I am the original person on the team. So I'm now I'm aware that as the team is built out, oh, I have to to, you know, in in larger group settings, I, on purpose, will, you know, make an effort to make sure that other people get an opportunity. I'm not always successful.

Right? But I but but I also went to some of my peers and said, hey. Like, in this year, I'm really focusing on that. So if you don't hear me speaking up, it's not because I'm not listening to you.

I don't think, you know, the idea is worthy of a good genuine debate. It's because we have newer people on the team. And so they could easily be overshadowed, you know, unintentionally. Right?

So so that transparency letting the other person know, hey, I'm consciously doing this. Right?

You know, even when you meet them, like, you know, I wanna understand what your group does. And that a lot of the the things that we talk about in communication are, they're just it's unintentional.

Let's just, you know, say it that way. Right? Because if whatever you do all of the time, you just presume that it's really obvious why you're doing the things, and there's three choices and you made choice b and here's why. Because it's it's just part of what you do.

Yeah. But it's not obvious to everybody else. And so it really it behooves you, to to have that conversation. Right?

And and to show the empathy and understand what they're doing. So what what happens sometimes is we get really focused on the tangible tactical thing, and we don't say, why do you guys do it the way you do it? Help me understand that. Yeah.

You know? And that's a really powerful thing because it gets them to start to talk. Oh, well, you know, and it gets them to say, oh, well, here's why we do the thing. This is this is the way we approach it.

And hopefully, you're learning and they understand that you're listening at the same time.

Yeah. Absolutely.

And and getting to why, in a conversation setting, it just brings so much value to the conversation because if you're communicating something, but the reason that the two of you are talking is to reach a separate outcome, then not being aligned on why means the conversation's going to be even more difficult than, than it would otherwise have to be. So let's look at a specific Sometimes in cybersecurity, we sometimes feel like the department of no, You know? Like, no, you can't do that. No, you have to No, you have to do this.

And so sometimes those conversations one on one, become ego driven because one person's saying no and the other person's saying no, you can't make me. And so instead of the conversation being about, well, why is the no there? Why are we even talking about this specific thing that needs to be implemented? It becomes a power struggle of one person saying no and the other person saying you can't make me.

Right? So how do you get past being the department of no?

Yeah. So there's a couple of pieces there you sort of have to unpack. Right? So so one of it is the the backdrop to it.

Right? So this is one of those times where you do have to say, well, why did we get to that point? Why why are we in that position? Right?

And so it's arguably because security teams, are there to protect things. Right? And so that's intrinsically the way that that a security team sees the world. And so much of that is pruning things or saying no to things, and that's sort of natural to the way that you would look at a problem.

The the the the more sort of forward looking framing today is it's not the security team's job to to make that choice. It's the security team's job to understand why the business wants to go that direction and then to genuinely, authentically, you know, argue on on the other side if that's how you you know, what your experience tells you. But ultimately, it's the business's decision to make. Right?

And so when I hear, you know, CISOs or security leaders say, you know, well, I'm not in the business of saying no. Right? That that that that message has to get to everybody. Right?

That well, on a tactical level, we might say no, but then right behind you say, well, that's that's not the way that we would suggest doing it. Why do you need to do it that way, John? Help me understand. Because a lot of times, it's what what I would consider mistakes of effort.

Right? You're trying to do a thing and do your job. So I'll take something simple. Right?

I wanna use, as recording software, you know, like OBS, like we were talking about when we jumped on. Right? And so we have a company policy. We have a set number of tools that we use for obvious reasons, like any company.

We're trying to control those costs. And for whatever reason, we don't choose the one that that that you and I love the most.

And so we go sort of the formal process and we get sort of the formal no. Well, then we can either live with that or we'll probably try to find a work around, which is what most employees do. Because you and I have decided it's really the best choice. Right?

So that's why I made some mistake of effort. Like, we're trying to do this. What what we don't know if we're not, you know, aware of of security implications is there's probably some risk there. That that's why the security team, you know has said no to that or so then you have to there's got to be enough of a relationship that the the other you wouldn't know somebody to go to.

Right.

Because you just get the formal know whether that's through you know piece of software or whatever your processes that's unfulfilling to the other person. Right? But it's on the security team as well to establish a rapport and a culture that says, well tell me why you guys need that. Help me understand Jen, why do you think you need that one versus the other one?

And then you might give me the really good business case. Well, because it has this feature that we really need to do this thing, and the choice you're giving me doesn't have that. Well, that's a very different conversation. Now I may still respond with, you know, there's some inherent concerns that we have from a security standpoint to be able to deploy that to all the employees or or whatever their concern is.

But now we're having a very different conversation. Right? It's about it's a task discussion.

Right.

Right? So when you look at sort of conflict management, there's sort of it within the workplace. You have sort of task conflicts. We have relationship conflicts, and then we have sort of hierarchical conflicts.

Right? Where to your point. Right? I think I have some influence or power, and you you disagree with the scope of that influence or power.

Right? If you could get it down to a task discussion, then it takes through the heat out of it. It takes the emotion out of it. And you can talk about the thing.

You know, and so let me go back to the communication piece. If I understand why that helps ground me. Right?

If I if you if we don't have a discussion about why, then either party has to make assumptions Mhmm.

And then has to draw conclusions. Right. Right? So if you've ever seen the the the ladder of inference.

Right? You start with, I have a a piece of data, then I make an assumption. Right? Then I build a conclusion, then I build a belief, and then I take an action.

Right? That's really wordy, but that's how it happens. It could be. So, if you and I are on peer teams and, you know, we have some kind of, output that we're we're all expected to do, and I've asked your team to do it twice and they haven't done it.

Well, that's the data point.

Mhmm.

Now I start making assumptions. Well, Jen doesn't think it's important. Right?

Because you I mean, this is a normal natural human rational That's how humans go.

Jen must not think it's important. Right? Well, then what happens? Well, they go up the inference line and I go, well, Jen just doesn't get it.

Her team doesn't understand. Right? And then I build a belief based on that. Yeah. Right?

Well, Jen Jen is not she just doesn't get it. You know?

Right.

And then I make and then I do an action based on that belief. Mhmm. Right? Now I'm gonna presuppose that the next thing, Jen's Jen's not gonna be supportive.

She's not gonna be behind it. And see how we've gone up this really tricky ladder. Right? Built on these really tenuous things, and it's understandable.

So, again, both teams or both parties have to kind of nip that down here and say, hey, first of all, ideally, I would say, hey, Chen. Like, I have a a deliverable for our joint boss. And the last two times, like, you weren't your team, like, didn't get it done, you know, on Friday, like like, was expected. Can you help me understand?

And then you might be like, I had a competing I had a competing outcome that that that actually Susan also told me was, you know, and I didn't realize it. I mean, so you guys so get back down to the facts. Right. Like, help me understand why.

Or it might be just a misunderstanding. Right? You might be like, oh, I didn't realize I didn't catch that Slack message. I didn't see that, you know, but but if without that starting at that base level, then you go, okay, cool.

And then again, it takes all the emotion out of it. Okay. Hey. So then I got another one coming up next Tuesday.

I really connect can you can you get behind me and support me on this one. Right? And so that's where you're gonna get to the why. I gotta understand where you're coming from or why why you're doing and we could disagree.

It's totally fine. Right? We may have that that struggle where, like, well, we legitimately have two competing, outcomes that we're trying to get to. One is creativity and and agility and flexibility, the other is security.

Right? It's it's the nature of our team's roles that there's always going to be trade offs. Right? There's almost never an it's a or b.

That's it. Right? I mean, it's it's a it's a it's really, really rare. Right? So it's all about that.

So to to knowing that, you've gotta lean into that then and say, I got to get comfortable with ambiguity. I've got to ask questions, right? And vice versa. That's like coming to me, hey, I want to explain to you why my team thinks about it this way.

And you've got to do that because then again, like I said, you can you can hopefully step down from a relationship ship struggle to a hierarchy down to, oh, it's a task thing. We're trying to talk about this thing. Mhmm. You know?

And and I find that in in the work that I do in third third party assessments, you know, at at the task level, it it is we're trying to make sure that you have security holes taken care of. You've got a security stance that is sufficient for the purposes of whatever you you you undertook this assessment. You know?

So sometimes, let's say let's say it's PCI. Let's say you're you've got credit card data. Let's say we're trying to trying to to get that security. Well, I know that that one technique is as an auditor go in and only point out the negative things.

Mhmm. This fails. This is bad. This is not secure enough without any real interaction with why do you do it this way and what other potential things do you have in place to mitigate that that risk? And is there another way that we could go about doing this? For example, storing credit card data used to be something everybody did just because it's what they did. Right?

Right.

And so so going in and saying, all right, you can't pass because you don't have right key management, you don't have these, your DMZ set up so that your internal system is is, segregated away from that. You don't have so all of these things that you have to do to to keep credit card, safe, you can go in and just beat someone up over that. Or you can say, hey, here are the things that I have found that are going to make so that you don't align with the the the standard, which means we can't get you, compliant against that standard at this time. Mhmm.

So what do you want to do about it? And it becomes more of a and and you can do this whether you're internal or external, it doesn't matter. The thing is, what is the problem that we're trying to solve? What is the security level we're trying to meet?

And in what way are we violating that? And then it's not my decision how you solve that problem.

Right.

It's not even my decision whether you solve that problem.

Right? So there are companies that have decided to be not compliant with PCI and pay fines while they sort out what they're going to do. And then there are others who have been like, look, we're gonna revamp this because we don't want this potential issue. We're gonna completely revamp it or we're gonna lock it down in certain ways or we're gonna have a third party take care of things.

Like, there are so many ways to to resolve security challenges and to architect a solution to whatever you're making. But if you go in as either internal or extra, the person who's doing the security, if you go in there and only pour in top the negatives, we already, as humans, really take negatives on board a lot more than we take on positives. So the way I I like to approach it is I will point out as many positive things as I can while I'm working with people. Hey.

You've got your logs down. This is great. I'm super happy to see this. You have all of your people not only took their their training, but also signed this this form that said that they took it.

You've got you've got the extra bits here. You know, pointing out the the the awesome things that groups are doing means when you get to the conversation about the negative thing, it's a it's a less fraught, conversation because you're not there just to beat people up, But but you're there almost as if you were on the same team working on the same problem.

Yeah. And so let's just take your the the whole thread there. So and and why are why are we using somebody with your talents and your skills and your experience? Right? So if we frame that as Jen has seen a ton of different environments and has expertise that will help us, that's a totally different framing than Genesee here so we can check these blocks or not these blocks.

Right.

That's a totally different way that people internalize it. So now we're back to kinda why why has it's like Tiramisu has layers. Right? So now we're back to, like, intrinsically, why are we doing an assessment? Well, overtly, sure.

Like there's been a choice that we wanna be compliant, or we're required to be compliant.

We're correct.

Yeah. But that's really the simple answer to the why, right? If you're going to do that anyway, why not get more value out of that?

Right.

Right? So, hey, Jen, super smart person who has a lot of experience and sees this in other environments that are not mine, how can we do this differently?

Right.

Why do you why would why does the by the way, why does the control mechanism say it that way? I don't really understand. I mean, so that's the we're back to like, if you if the the the framing of it, because then people can internalize it completely differently.

Absolutely.

Yeah. And it's, it's a it's a much more fun conversation to have. It's a much more fun assessment. And and I see this with internal groups as well where sometimes I'll work with groups where they're the internal security people are working with me and are have a very negative relationship with their IT, with the people that they're supposed to be supporting as security folks. And that makes my job harder because everybody's angry already. And I can't imagine working in a situation where you're all ultimately trying to do the same thing, make this business successful, right? And so some people are trying to build things and get more features and create products, and other people are trying to get them to do it securely.

And and that that handshake of of conversation on and communication about how do we do this realizing what our actual mission is. And I think that's what some people lose track of is what's the actual mission.

Completely agree. Right? So now we're back to we talked early on about across the teams. Right?

So it's not just, you know, we're in the security team and we're talking to technology people and other engineers and devs, etcetera. That certainly happens. Right? But the business of the business is the business.

Right? So how can you, to the maximum, enable a business if you don't understand it? Right. And we're not being flippant.

Right? And so, again, I'm not saying, you know, you hired, you know, Dutch on day one, and I, you know, and I don't have a ton of experience. And it's natural for me to then focus on the tasks that you've given me, right? Because of my experience level, and because of the tenure that I have.

But as you, whether or not you have formal leadership role or not, as you get more tenure and as you can provide more value, you should be able to explain to somebody, well, here's what my company here's how my company competes. Right. And you need to be able to explain things in a way that communicates it to them that they think that you get each other. In other words, you know, I struggle when I hear, you know, absolute metrics.

Right? So so absolute metrics are, you know, yesterday, we stopped thirty two thousand seven hundred and fifteen DDoS attacks. Okay. Yeah.

It is that awesome?

Is that What does that even mean?

Anything. What does that even mean? Also, that only means something to somebody who understands that terminology. Right?

It doesn't it doesn't it's not that it doesn't matter. It only matters, like, in a in a narrow context. So, you know, as a as a as a leader, you have to be able to communicate, hey. What what is what are we oriented on?

Okay? Are we, you know and and, ultimately, it's dollars, it's percentages, it's financial terminology that it that goes across, you know, the teams because that's what the the business or in time. And so you have to have that taxonomy. So as a security team, in a leadership position, you need to understand that.

Right? So if your particular company is return on working capital as an example, then then you need to understand we're trying to work in capital. Again, at least at a at a work person's, you know, working level of what that means. Right?

Well, Cass, that means there's five levers to that. And here's all the levers, you know. And so you can't sort of only come from the, you know, here's what the attack matrix matrices say or here's what the vulns that's that's our terminology. That's what we talk about internally.

But that can't be the communication you have with the vice president of sales and marketing in Europe. It isn't because it's not it's there's nothing really just there's nothing really maintained and meaningful that's happening in that then. Right? And if you don't know that, that's okay.

Then we need to go start asking those questions. Sure. Hey. Help me understand, you know, what it is, you know, not you know, help me understand why we do marketing the way we do it.

Help me understand why we do development this way. Help me understand you just ask those questions because people love answering those. Right? And you're gonna learn, genuinely about how they approach things.

Right? And I don't know where the quarter drops and where that fits into them in the future conversation. But if you don't have that, then what are you left with? You're only left with the tech stack Right.

To talk about. Right? And and that's not and that's not moving the business forward.

Exactly. And and it also affects your ability to do your job. So one of the, in almost every report that I write, there is a section that says, what does this business do?

What is the business of this business? And so so having to write that down, that is one of the most difficult things for me to get in certain organizations where, IT and and security are are kind of separated from that knowledge. And and the the problem with that is if you don't know what your business does, how do you know what's important? How do you prioritize the security work that you're doing in an organization if you don't if you don't know what what the business if you don't know what the company that you work for does, how do you then frame your work properly within it?

So so, Jen, why do you think that is? Why do you think that happens? Do you know?

I think it it a lot of it is when we talk about communication between IT or or security and the business, it's hard for those of us in technology to admit we don't know something because we know a lot of things. Right? We know a lot of things that are hard, and we know a lot of things that maybe we've taught ourselves. So kinda getting back again to a little bit of the ego question. Right? And so we have all this knowledge and we wanna apply this knowledge, but but maybe we don't always see the value in in knowing the business or understanding the business.

And there might be some fear also in asking the business what they do because then, you know, then there is you have to admit you don't know I just remembered a specific example of this happening to me.

So remember back when Sarbanes Oxley was first a thing? That first came in, right?

Absolutely.

And so I was sitting across the table from a guy from Ernst and Young and he says, This is my first, Sarbanes Oxley audit or SOX audit.

I am not sure what to ask you because I am a CPA.

And I said, Okay, well, what is it you need to know? What are you trying to solve? And he used some words that I did not know.

They were words that you would find on a balance sheet, right?

Sure.

And so when he left, I thought, I don't think I was helpful at all. And I didn't know. And then I remember that feeling when I sucked it up and fortunately, I had an open door to the CFO's office.

And he was always willing to talk to me. I went in and I said, I think I need to understand what a balance sheet is and why it matters Because otherwise, how am I gonna know how the IT part affects that? And he walked through, he walked through it with me, and I don't remember the words now, but, what each of the the different lines were in terms of financials and things and how it affected the business, but it was not easy. And it took taking a breath and going, there's something I don't know, and I have to go admit that I don't know something.

And so, I think from from a tech person's point of view, there is that, you know, I know all this thing. What do I need to know your part? I just do my job. So maybe there's a little bit of a siloing thing too.

I don't what do you think?

Yeah. I I wouldn't disagree with that. I think those are certainly could be in play. I think that the the levers, though, that we can use our culture and leadership.

Right? So if if you have a culture, right, that and so in this case, you had a one on one relationship. But if you have the culture, that's okay to say, I I don't really understand what that means or, you know, and you're ask more questions. If you have a culture that isn't, you know, sort of zero sum and allows you to ask questions, that's really helpful.

And then on kind of a more personal level, it comes down to leadership. Right? So then, you know, as we move on in our careers and security, then then, frankly, the onus is on us, right, to to communicate that. Right?

So I'll give you an example from a totally, you know, kind of a different field. I I managed, the the storage for for a company.

And so I had a part portion of my team was like, we would call them today sort of inventory managers or analysts really. They manage inventory. And so they had what we call, you know, financial fiduciary responsibility to manage, you know, like three hundred million dollars of inventory. And they took that very seriously.

And they had lots of sort of quantity type stuff we talked about, you know, inventory turns and so on and so forth. And again, in our team that really all made sense. But, I was brought in along with some other folks from other teams who have more of a broader business perspective. And in the first week or two, I just sort of, you know, watch the team interact.

And they were just saying no a lot. And I just hear one end of a conversation where they're like, no, you can't have this literally, and then hang up. And then I'd be like, let's go to the conference. Can you help me understand what was the interaction there?

And they were basically saying, you know, to person a, you can have this inventory, because because inventory would be built into embedded into a product. Or and then no to another person. I'm like, okay.

Why did you say no? Help me understand. Like, I I don't think I understand. Well, I said no because of ABC reason. Okay.

I just didn't hear you explain that to the other person on the other end of the phone. Like, I just heard you say, no. You can't have it and hang up. Right?

And so then I was sort of looking for a way. Like, how do I explain this? And so they, again, felt very passionate. Like, well, it was because person a was air quotes, you know, gonna the project was bigger and more important.

Or, you know, they had some rationale in their mind. But I'm like, well, hey. You didn't explain it to person b. And then also, I'm not sure that that rationale that you're using encompasses actually the entire business.

So fortunately, the company I worked at, use return on working capital. And they actually had a formula that we use. So if we had a whiteboard, I I was love it. I I I would draw it out for you.

Right? So but then we had a formula that we use. And the the benefit of that was all managers, regardless if you are in legal, HR, finance, sales, everybody understood what that term meant. Mhmm.

Okay? So then I could I went into room a few weeks later and said, okay. Here's where to turn on working capital. I know you think it's a marketing term.

It's actually we actually use a modified DuPont formula. This is the formula. And guess what? I know you're concerned about inventory turns.

That's one of the metrics. Guess what all the other, you know and I showed them, hey, here's all the other levers that you can pull. So I don't know that that the recommendation you made was good or bad. I can't I'm not sure.

But what I do know is the second person didn't learn anything, and then nor did you. Yeah. So now we're gonna have a different conversation, which says, hey, Jen, help me understand what the project is that you're working at, what you're trying to accomplish. Mhmm.

And then, hey, when I look at return on working capital, I'm looking at inventory turns, I'm looking at accounts pay, you know, and then explain your point of view. And then you can have a even if you end up still saying no, you've learned something, they've learned something, and now you've made arguably a qualitatively better choice. Right? So so it's incumbent on us.

That's a totally different field. But it's incumbent us to have the same kind of conversations. Right? Why is the business doing these three major initiatives this year?

Right? How do I need to support those? Why are those things important? And you can just kind of keep tearing that why down until we get back again back to that tactical like, what's the task in front of us, right?

But there has to be a backdrop. Why are we trying to do this? Because maybe this year, we are trying to really move very, very fast. Because there's forces upon it, you know, in the industry or for whatever reason, the board and leadership, executive leadership team has decided that.

Well, if that's how we're oriented, then we know we're gonna have to trade off and take more risks that we then on a whiteboard, we'd want to. That's okay. Because that's why. Right?

So that's we have to get to that and say, help me understand. Again, I use return working capital, but it could be net present value. It could be ROI. It could be ROI.

See, it did there's a host of terms. Right? But the point is, you need to know what those are.

Right.

And you need to be able to talk to the business because now you have a common language. If we don't have a common language, then I'm talking and telling you how many DDoS attacks we mitigated yesterday. Mhmm. And you're trying to tell me about, you know, velocity, then we're not really conversing.

Right.

We're not really communicating about anything. And so we both probably walk away and go, you know, we probably roll our eyes. And even if we have a good rapport personally, you know, we probably walk away saying, yeah, that person just doesn't get it. Yeah.

They don't get it, you know. And that's not at the heart of most disagreements. Right? We're back to just, you know, most disagreements are around the two parties feel like the other party just doesn't get it.

Well, because not not only are you not using the same language, but you also are not deciding things based on the same, end goals, right? The same the same metrics, the same I liked the example that you gave that there's actual formulas or there is a risk stance that is set by senior leadership. And so if you're trying to make decisions, but you're making decisions based on maybe where you worked before or what your best knowledge is or, your own personal risk tolerance. Then Mhmm.

Then when if if something goes wrong or if you have to say no, what do you have to fall back on? You don't have the structure of the business to fall back on and you want that, right? So as an as an individual functioning within a business, what you wanna say is, I understand the business, what we're trying to accomplish. I understand the risk, stance.

I understand how we make decisions of this company well enough to fit what I do within that framework.

Yeah. And and so there's sort of plays out in different ways where wherever you are and where that conversation is. Right? And so if you're at the the CISO senior level, it may be a, hey.

So, Jen, I understand you wanna buy x y z software because you think it's critical to your to business success. We go back and forth. I explain sort of, hey. Here's how here's my informed viewpoint on why this isn't the greatest choice.

Here's where we would accept some and then ultimately, maybe that's it. Okay. So so, Jen, I'm I'm transferring that risk over to you. Like, you're gonna have to accept that risk.

Right? And so that's a technique. Again, at that level, if you're structured that way, other people do it through, you know, through their their software mechanisms. They may they may have sort of a sign off process.

But, again, it it still happens at each each of those levels. Right? It may just be, hey, let me help you understand why I'm concerned about that. Yeah.

And that might and that in of itself might be enough to go, gosh, I didn't I didn't have any idea. I'm only again, it's a mistake. I'm only looking at my piece of this. I really need to move fast.

And this is the and my team already knows the software, and that's why I wanna deploy it. And they don't they don't they won't, of course, won't know your point of view. So you've gotta take that extra step. Say, hey hey, here's why.

This is why I think about it this way. And again, if we have some common common, text not just like you said, not even taxonomy, but some kind of framework or some kind of risk that we we lean towards then and we go, okay. You know, not my favorite. Like, I wouldn't, you know, do it necessarily, but I see your point and that's that's what we're gonna go with.

Right. And then, like like, I think you were just inferring, recognizing who gets to make that decision. So I'm I'm often pulled into the question of who is responsible for breach.

And Mhmm. And my answer is always senior leadership is responsible for every outcome in their organization.

Right? So, but how can they be responsible for that if you refuse to let them make the decisions or you you refuse to take the decisions that they've made and then implement them in a way that is going to be supportive of that decision? Right?

So, do you That's a that's a great no.

That's a great insight because you've you take you've broken the whole chain of the process. Right? I mean, so so you've you've on the one hand, you're like, no. No.

You know? I I wanna be able to say yes or no to a thing. And on the other on the other turn, you're like, oh, no. But it went inevitably there's a challenge.

I don't want I wanna say, well, but they didn't listen to me. And you don't get to again, there's there right. Again, there that's that's, Alan offered jokingly calls this the the blame thrower. Right?

Where the blame the blame throwers are to come out. People start to argue about that, and that's totally not useful. It's certainly not useful one on one. And again, if that relationship conflict will inevitably flare up.

But also, if you're in a in a leadership, it's not useful to anybody else. Right? Because then your team sees that. Right?

And it's just the wrong orientation. Yeah. So you have to start you have to start from a different starting point.

Absolutely.

I'm here. We're here to support you. I'm here to inform you. I may have to, like, vigorously inform you sometimes and push hard.

Because that's they know that's my part of the responsibility, Chase, to really push hard and say, no. This is why but I think this risk is maybe I think the risk is bigger than you do. And I then I have to explain why that is and help you understand it. And then we've got to get walk away and then come back and go, okay.

But ultimately, that's your choice, Jen.

Right. You know?

And then now I'm in the position of okay, now, knowing that that's the choice, and we're aligned on that to the objective.

Now how do I mitigate that to the best of our ability?

Right.

Right? How do I how do I reduce that risk surface, reduce the likelihood of that risk happening? Or if it if there's something unfortunate to happen, how do we then quickly resolve that? Those are those are much more useful things.

Right? To say, well, that's the choice. We're gonna support that just because it's what the business needs. Now, day to day, how do we mitigate that?

And then if there were to be an instance, how do we manage it when that happens?

Right.

That's a way better exercise, right, than being huffy and be like, mom, I can't believe they did that.

How can they not present me? It doesn't help me, it doesn't help you. You know, everybody walks away unfulfilled with that. Right? Right. We've got to get beyond our own frame of view and understand theirs.

Yeah. Well, this has been a fantastic conversation.

If you were to give people, you know, one one really solid piece of advice on improving communication from where they are right now, what Mhmm.

What what would you have to start with? What would you have them focus on? How would you have them improve that?

I I I think two things. One is is just outlook. So as you go through your day, sort of even sort of jokingly in your in your head think, what if Jen is let's I'm gonna assume Jen is really smart but uninformed on this topic.

Like, I just presume I have charitable assumptions. I just assume you're you're well intentioned. You're trying to do a great job. You you're really you're you're you're here at the same place as me, so we share values.

Start with that and then go, but you just don't don't know anything about this. Right? And so just start with that that framing. You know?

So so that's sort of an outlook thing. And then in terms of, like, internally, get to your own why and understand why you like to do the things that you do.

And what does that mean about how you make choices so that you can communicate that to other people? Hey. This is these things are really important to me. This is why as I look at the resources and the the that I have, these are how I think about these choices. And then if you're in a leadership position, you need to communicate that to the people that you that that you're, you know, you have care of.

Yeah.

And then you communicate that to the rest of the business because then it's it's a people can connect with you and understand. And then again, it's not about agreement. People sort of over rotate sometimes like we're gonna agree to disagree.

Social psychologists would say that's that's not really that's not helpful.

No. Right?

We don't have to we don't have to agree to disagree. We need to I need to understand why are we disagreeing. Mhmm. And if I understand why we're disagreeing, then and we can professionally disagree, and that's okay.

And we can walk away. Right? But but if we just agree, disagree, it's sort of a flip. It's like, it's it's intractable.

It's unsavable.

That doesn't help any It's and it's pretty dismissive of the other person's viewpoint.

Super dismissive. Yeah. It's like, you know, yeah, for all of the reasons. Right? And, you know, it's the eye roll and the crossed arms and you start you know, it it just it it it helps nothing. So, a, I would just frame the interactions differently, as you go through your day.

And then think about your own think about, well, why did why do I think this thing? You know? Yeah. And if you can help expose that.

Because again, we do lots of heuristic choices every day all day long because there's so many things that we have to decide. But if you pause and think about that, then you can explain that to other people. And they might go, oh, that's really cool, Jen. I never thought about that way.

Yeah.

Perfect.

I don't know that I agree, but now at least I understand where you're coming from.

And I like what you said about assuming good intent in the other person.

Yeah. Chiritable assumptions. I I have I you know, because getting, doing anything else is fraught with danger. Yeah.

Right? It's so easy to make mistakes if you if you do that. Right? Yeah. So and then and when something happens, like you said, you a a fact pops up.

Jen, you know, your team, you know, wasn't behind you know, wasn't on time the last two things. Don't start with right. Don't go right up to, you know, I'm I make assumptions. Now I'm gonna infer why I think you did.

None of that's helpful. Hey, can you help me understand what was what was up? Yeah. And then give you a chance to tell me, you know, what was going on.

You know, then we're back down to here and we can we can communicate.

I find that in if you're relitigating old interactions every time before starting a new conversation, then those things are not really resolved. And so Right. So so those things need to be resolved if they keep coming up, then get them resolved because you need to be in a positive place to deal with disagreement.

Disagreement is it's uncomfortable for so many of us. And yet in our work life, we have to disagree in order to, help others find the best and ourselves find the best outcomes.

Completely agree with you.

Yeah. Well, it's always fantastic to talk to you. Thank you so much, Dutch, for for coming on the show. We'll have some links in in the show notes on how people can connect with you. And, and, is there anything exciting on your horizon that you wanna let people know about?

No. I'm just excited. I think like everybody, you know, the the the changes forthcoming. You know, we're starting to look at events and activities, and I know lots of people are just, happy to hey.

Can we go grab lunch? You know? So where everybody's sort of figuring out where the comfort level is and and and traveling and all those things. But I think, it we're coming to a point where it's almost summertime.

Kids are gonna be out of school. I think it's just gonna be, we're we're sort of putting a lot of the challenging, you know, year, year and a half behind us. So I'm just excited about that.

That's great to hear. Alright. Well, you take care, and we'll talk to you again soon.

Sounds great. Thanks, John. Appreciate it.

Bye bye. Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the left. If If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.