SecurityMetrics Podcast | 18
The CISO Role: Social Strategies for Enterprise Security
“Gaps in security are behavioral . . . find out what drives behavior at your company, and you will find your vulnerabilities.” As the Strategic Lead of Amazon Web Service’ Global Security Services Team, Dutch Schwartz talks with SecurityMetrics Podcast Host and Principal Security Analyst Jen Stone (MCIS, CISSP, CISA, QSA) to define what CISOs need to understand about human motivation in order to strategize security programs, utilize company culture, and protect critical data.
Listen in to learn:
- How the CISO position has changed in the last decade and how it’s currently defined.
- The surprising differences in intellectual property between companies and the role those differences play in security.
- Why culture and social strategy should be more important to a CISO than technology, and tips for facing company culture challenges.
Resources:
Dutch's LinkedIn: https://www.linkedin.com/in/dutchschwartz/
Dutch's Twitter: https://twitter.com/dutch_26
Download our Guide to PCI Compliance! - https://www.securitymetrics.com/lp/pci/pci-guide
Download our Guide to HIPAA Compliance! - https://www.securitymetrics.com/lp/hipaa/hipaa-guide
[Disclaimer] Before implementing any policies or procedures you hear about on this or any other episodes, make sure to talk to your legal department, IT department, and any other department assisting with your data security and compliance efforts.
The CISO Role: Social Strategies for Enterprise Security Transcript
Welcome back to the Security Metrics podcast. I'm super excited to have you with me today because I am talking to Dutch Schwartz. We're going to talk about CISOs, about the evolving role. Dutch, first, I would love it if you would introduce yourself to the audience.
Yeah. Thank you. And thanks for having me on. So, Dutch Schwartz, I'm a cloud security strategist for Amazon Web Services. So functionally, what that means is I work with CISOs, their staff, the architects, to help them design strategies for security as they adopt the cloud.
My background, I'm a military officer by background. So I think of myself as sort of a generalist specialist, if that makes any sense. So I'm a big proponent of range. I think that you can take competencies from one life skill and move them into another area.
So that's kinda what I try to do is combine those things. And, you know, when I'm not doing this stuff, I like to hang out with my my family, hike with my kids, play board games. You know? So that's, that's me.
I love that little offhand comment about bringing competencies into other things. And I think that we could probably have an entire conversation just about that. But today, our conversation is about CISOs. And, I mean, let's start with the basics.
A lot of people don't even know what is a CISO. We have a lot of we have a very broad audience. Some people know exactly what we're talking about. Some people are very new to the technology and security space.
And so so they they may or may not have a CISO position in their companies. But Sure. But the role, I think, exists regardless of whether it is a named title. So tell us a little bit about, what you see a CISO doing.
Sure. Sure. So chief information security officer and to your point, you know, ten years ago, we really didn't even have that title. Right?
Especially twelve years ago. Right? Sure. So so there was somebody who was sort of responsible for the area, but wasn't explicitly called that.
Right? And it really was about seven to five years ago, that range you started really seeing this role. And so, really, I use, Gary Hayslip's definition because I I think it's the most, the most accurate as we sit here today. So what he would say is a CISO is a business executive who happens to use process technology and people and frameworks to manage risk.
And so the the difference there is that it's not, you know, it's not sort of starting from the ground up, but from a technology standpoint. So, that's really the the change is your business executive first. You just happen to be somebody who has security as a domain, but you're first and foremost a business executive.
Excellent. And Gary, of course, nails things.
Good good choice good choice for choosing where to start from.
One of the things that I've seen, over the last especially as we figured out what does a c what does a CSO do? What is how do they function? And one of the challenges is, you know, that understanding that they are a business person first. So a lot of times I've seen over the over the years, peep people have might have a CSO in their company, but they might report to the CIO. Or they might, you know so they don't actually have that seat at the table. Do you see that changing much, currently?
Absolutely. I do. So if you look at the statistics again, so I'll talk about kind of enterprise. Right?
So we'll start with there. Yeah. You've seen a movement. So in the last five years, we went from around sixty to eighty percent, again, depending on what kind of research you look at, of CISOs reporting to CIOs as you as you mentioned.
And now we're seeing that that the majority of CISOs at the enterprise level report to a CEO, report to the board, report to a chief risk officer, or some other, like, CXO, COO type of role. So it's actually the majority, and that's consistent not just in the research that I've read, but also if you talk to, CSO organizations, they'll they'll echo that same thing. Right? And so what that is is an indicator of of a couple things.
It's a recognition, right, that the role is important. That's that's sort of implied.
But the other thing is the digital transformation.
Right? All those efforts around digital transformation have really changed, not just the role, but the business. Right? So there was an era where technology may or may not have been intrinsically important to whatever it is you do, whether you build something, hardware, software, bicycles.
Right? But today, with digital transformation, it's integral to pretty much every company. Right? If you look at America's GDP, right, we're a knowledge worker.
That's our output. Right? And so that that's so that those those forces really, change the way that the CISO needs to be, directly reporting to somebody, and put them really commensurate with the other business executives.
Right. And it feels like that's an important change where, you know, the struggle of where does that fit, I think, it it didn't really sink in for people until some of the challenges regarding security started to to really make themselves evident.
And so like you said, ten years ago, twelve years ago, for sure, this was a brand new thing.
Right.
What is it about the the general landscape of of the the digital world that that you think is driving this as more of a of a strategic position rather than, something that's more tactical?
Sure. It's because the the the risk related to your data has has risen. Right? And so it's really commensurate with any other business risk.
Right? And so I talk about that sort of from both directions. So if we're talking with people who are just security really steeply, you know, in security, I try to remind them, hey. We're just one of the risks.
So that that that's a context as well that sometimes you have to kind of, you know, right size the conversation. But if you're looking at it from the business's standpoint, if they're not really steeped in security, because of that history, right, they're like, oh, it's just sort of security is a thing over here, and it used to be under IT. Yeah. Yeah.
They're they're just over there. Right? And it didn't feel like it was part of the business because it wasn't important. Again, unless you're an outlier maybe when if you were a software company, right, or a security vendor, stuff like that.
But but for the average enterprise, it wasn't deemed as critical. But but now that we look at data privacy, not only from the the the laws which kinda shine a light on that, but data privacy and how important it is to your business. I'll try to be general, but I had a conversation with a beverage company, Cecil. And I said, hey.
So what do you guys consider, you know, intellectual property? I mean, not so not just your privacy and your customer information. I mean, that's kind of, consistent across industries. And I thought they were going to say, oh, it's our formulas, right, of how we make x y z beverage.
And they said, no. No. No. No. Every of one of our competitors has chemists. They we all backwards reengineer our stuff.
Like, everybody knows exactly what's in every beverage. I said, well, what what's the intellectual property then? They said, it's our marketing campaigns.
We cannot let anybody know those because that's how we make a buzz, and that's how we generate, you know, more viewership, more connection, more, you know, you know, you know, more people who are using this this this and so that's really interesting, right, to always ask that question.
Right.
What is it that you consider that? Right? So, again, so some of them are table stakes from from mostly any executive who kind of understand security. But you you have to go in and ask that question, like, what is really critical to you, not only from a privacy standpoint, but from a also from a business operation standpoint.
Right? What's the workflow? Like, what would interrupt you being able to get that can of x y z out the door? You know, like, it's so it's all of those things.
And so it's just become integral to what everybody does. And so that's really the right place for that CSO. That's what we see a lot of times reporting the CEO. There's there's not a right or wrong.
There's, of course, lots of debates around that. There's also healthy discussion around what are the different types of CSOs.
I don't think that's a bad approach from a thought exercise. Right? Are you a post breach CISO? Are you a transformational CISO? Those are all interesting ways of thinking about it. But I also like, if if you were gonna be a CISO tomorrow, then I wouldn't wanna pigeonhole you into one of those things.
Right.
Right? So it's a thought exercise, but that's not the scope of anyone CSO. Right? Not over the span of of their certainly other tenure, even even at one company, but certainly over time.
Right? So but it's an interesting the sure fact that we're having that conversation is a good indicator that we we haven't really settled, you know, on all of the things. So you see a range of job descriptions. If you go read CSO job descriptions, sometimes the chagrin of people who are trying to, you know, say that's not actually the most important thing.
But you have to ask those questions. What's most important, and what do you want out of the CISO role, you know, for that business? Because they may have different views.
Right. And I like how you couch that in the for that business. Because, from what I've seen, the understanding of security and what you're protecting differs widely depending on the organization itself. And like you said, if they don't know what they're protecting, then they how how are they going to structure the CISO position and the security stance of that organization without knowing that? And so as you work with organizations, how do you help them figure that out?
So it depends it depends on their maturity, of course. Right? So so, and that's not really specific to an industry. Some industries, because of rigor and regulation, they tend to be more structured.
Right? They have more maturity. So federal government, public sector, financial services, health care, life sciences, those those spaces because of they were earlier in this process. Right?
They've just been doing it for a longer time. Right? So the original CSO who had that official title, right, came from financial services, of course. Right?
And so they're sort of a little bit ahead in the maturity, but you're now you're seeing digital native companies, you know, sort of, the two thousand eight, two thousand nine companies that come out. They've really caught, you know, caught up to those. Right? And so it's really a maturity.
I I when I get into this discussion, I'm trying to understand where are you at from security maturity standpoint. Right? And so I might start with and it just depends on the the interaction. Hey, Jen.
Help me understand, like, which frameworks do you use? Right? Because that gives me an idea. Again, no right or wrong.
They're they're all great. There's tons of great frameworks, but it helps me understand sort of where you are.
And maybe a simple question of, Jen, what are your top three business initiatives? Not security, business initiatives.
Yeah. Yeah.
And then we layer on the security lens. And so that helps me understand it. And and the CSOs typically do know that. But we're we're, we try to help is now how about CISO minus one.
So deputy CISO director and down through the staff. And that's part of that evolution of the CISO role. There's, you know, a lot of good, podcasts, books, evidence now out there for if you were thinking about growing into or moving into a CECL role, there's really good stuff there for you. But what, I'd like to see more of is continue to push that down to the rest of the staff, both to your security staff as well as the rest of the enterprise.
Right? And so to me, that's kind of the win. So the, you know, the leadership part because your your business is accurate. So the leadership part of that is you still owe your people direction, purpose, mentoring, and motivation.
Right.
Right?
And so as part of that process, if I talk to a manager or an employee in the security staff and say, hey. I looked at your, annual report, your ten k, and I looked at section one a for risk. And I've showed this to some folks and and they said, where did you get this? And I'm like, this is your annual report.
You know what an annual report is. Right?
You know, not not to trip them up. Right? But say, hey. Look. So of these ten that your executive, the boards, you know, and the executives decided, three of them are explicitly cybersecurity.
Right.
So but the other seven aren't. So but what if we put our security lens on that? What does that mean, you know, to the business? And so it's really just starting that conversation. And so so pushing that sort of evolution of the CECL role down to the entire security staff so they understand that you might if you're a less experienced person, you might have something really explicit that lands on your desk. Hey, Jen.
We need to buy a DLP.
And so you're off doing all great things trying to look at that or fill in the blank, CASB or XDR or whatever the street thing is. Right? But what you really need to know is why.
Exactly.
What is this tied to? What's the business initiative that it ties to? Because it does two things. It informs your thinking, right, of what am I looking at. So you don't just do oh, I have this weighted matrix and, you know, that's all fine. But it doesn't really get you does it get you the business value?
Right.
And it doesn't allow you to flex and be creative. And as new solutions come out or new ideas or approaches, you're like, I have to buy this thing. You know? And if you start with that as the box, it's hard for anyone to get out of, you know, out of that box.
And it also if you frame it so narrowly, then that manager, doesn't have the the connection to what's really critical to the business. Right. So then as the and the business, the business changes so rapidly. Right?
Sure.
So maybe that project that was important is no longer as important. Maybe it's still still necessary, but it's not as important. So it really needs to be tight. You have to start with first principles, and that's, what is the risk?
Right? And who owns the risk? Right? That's a that's a continual topic that, I talk about a lot with folks.
There's a sort of a latent perception sometimes in a good way. Security people are like, well, we own risk. I'm like, you don't own risk.
You don't? Nope. Not an enterprise. And here's why. I'm like, because the board owns all risks.
That's right.
The board is there from a from an oversight and compliance standpoint. So the board sets risk appetite.
Mhmm. Right?
So use the fair definition. Right? So how much risk are we willing to take? Correct. No way.
And then risk tolerance. Right? How much variance are we okay with against that that that appetite that we set? Then it's the business who owns the risk. Right? Just like they would own the risk of arbitrage or currency fluctuation or some kind of natural disaster that happens to to a warehouse. Right?
And and yet Business owns the risk. That that's a disconnect that I see all the time. So I'll I'll go in and and one of the things that I help organizations is do a risk, risk analysis, risk management plan. And yet, those things are impossible to do if you give that project to the IT group.
Hi. We need a risk, we we need a risk analysis and a risk management plan. And then Right. The the IT group is left going, well, I can do certain things.
I can run certain scans. I can I can apply certain tools to that? But if they're disconnected with what is the larger problem we're trying to solve and what is our risk appetite of our organization, they're not gonna make as good decisions. Right?
And so so what you said, about, like, twenty six minutes ago was all good information. But one of the key pieces that that I think was foundational to it was if, if people don't know why, they're not going to produce good information for you. They're not gonna like the DLP. Hey.
Go go purchase a DLP.
Alright. That might be the solution to the actual problem that you're trying to solve. But if there is not a why there, then perhaps Right. The DLP that they choose is not going to be adequate for the problem that this that they're trying to solve. Right? So how do you see people successfully closing those gaps between the business that understands or or sets the the risk?
They might not even understand some of the risks because of security things might be hard for some people.
Right.
And so so closing those gaps those gaps from the bottom up and from the top down, how do you how do you create those communication pathways where Sure. Where it makes sense so that people can make good decisions and do their jobs to, the overall, benefit of the organization?
Yeah. So it's really there's a kind of a couple of motions that happen. Right? So the CISO, sort of sort of the the CISO of the twenty twenties.
Let's call it that. Right? The CISO of the twenty twenties has to foster trust with the board of directors and their business peers. Right?
It has to start with that. Right? And then I have to do the the connection to them and understand what's what's important to so, Jen, if you're the chief marketing officer, what's important to you? Alright?
So we here's our three business initiatives. What does this mean to you personally? Mhmm. What does this mean to your organization and to your team and to efforts?
So I have to really get to understand you before I start telling you the seventeen acronyms that we all love to talk about as as security people. It doesn't really make any it doesn't connect to anything for them.
So you really have to have first of all, I need to establish relationships.
Right?
Right.
Establish rapport. And so that, you know, if you do that genuinely, that will start to earn trust. And then you need to use the language of the business. Right?
Mhmm.
So whatever it is that you focus on as a business, that's what you need to that's the translation, right, that you need to do to the other leaders. So when we're sort of helping that process, if for the two two two groups are not connecting, I go back to, like, just simple things. Like, there's five general business strategies. Right? Which of these are you guys using? And let's start with that. Right?
So speed to market Mhmm.
Improve customer experience, increase flexibility.
Do you know, so you pick those. You say, which of these are the ones that are important to you? Right? And then that's a way of framing things.
They say, okay. We're really let's say that, Jen, you're the chief marketing officer, and you're really focused on customer experience. Okay. Now what would interrupt the a good customer experience?
Well, if our app wasn't working, if our website was down Mhmm.
If we had some kind of unauthorized access. Right? So now you're tying to say, okay. I understand what's important to you, and I know that customer experience is one of our big three.
Now now we put the security lens on and say, okay. What are the things that might impact that? And as we walk through sort of the risk mitigation piece, and then we go to, okay. Now what can we do to enable that?
We'll make it a better experience. Right? Why would somebody is there a way to help us see it as a business enabler so that we have a better experience? Because people get sort of availability or is that third letter of the CIA.
Right? So if I'm not available, I don't security is somewhat immaterial. Right? My my the people who need access to the resource don't have access.
So that's a way of saying, hey. So we're an enabler for you. Right? By having great networking that's robust and resilient and security that's not interruptive, but but in cure you know, secures the customer and the data and our own data.
You know, you just so you talk them through that process. And you just need to do that down to to your, you know, through your entire staff as well and make sure that they understand that, hey, hey. I know we have you work on this project. Here's why.
Here's why this project is important. Right? You've gotta give them that context, and that gives them flexibility. Right?
Strategy is really about giving you enough of of of guardrails so that you know that we're all moving the same direction to keep multiple teams coordinated.
Sure.
But it gives you freedom at the individual or team level to use whatever tactics that you see fit. And so that's the balance that you're looking for.
And I I think that, in working with organizations, even before the I shifted fully to a a security standpoint.
A lot of times what I saw was good work doesn't happen if you are dictating tactics to people.
If you give them, like you said, the guardrails and what is the end goal, and then allow them from their position to come up with how are we going to get there, that seems to be where the best work comes from. And I see it again in in all of the organizations that I work with to help improve their security is if the the frontline workers understand the end goals and understand how they tie into those end goals, they're going to be more successful. So how how do you help people, kind of take on that concept and Right. Get those those frontline workers engaged?
So so we talked about sort of the kind of the the specifically, what a CISO role is or, you know, what CISO so if we talk about what CISO does, right, we we touched on some of the things, But one of the things we haven't kind of fleshed out is the CSO has a responsibility to establish security culture.
Right.
Right? And security culture, not just the training and the things that you would do for what we would think of as technology. Right? So the the dev team, the the quality team, your own security team, but the entire cult the entire enterprise's culture.
Right? All the organization has a culture. Right? And so when you look at so you step back and say, okay.
How do we impact culture? Well, effective ways to impact culture, number one, make it aspirational. Right? It has to be something that we're excited about.
Right? It's shared values and beliefs that, excuse me, that that we all would would would would buy into. Right? We then we have to, grow and select leaders, right, who fit and and will push forward those values and beliefs.
You can use what we call, like, organizational stories, right, to explain to people in a way that they will absorb. Hey. These are the things that are important, you know, to to Jen and Dutch's company. Right?
And then lastly, you you have to create an organizational structure. Right? But you have to start first with the company culture. What is our company culture?
What are we all about? Right? And there's different ways of plotting that. But if we have to start with that as a business executive team.
Right? What is our culture? And then you take that culture. Okay. Now what does this mean for security?
Okay. So, like, if you have a if you're a, sporting goods retailer, you might have really a game oriented culture. Right? And you love gamification.
Okay. That's a great way to then teach people about security.
Right? It doesn't matter that your job isn't IT related. Right? You can still gamify things if that's kind of your culture.
Right? And so we we've tried different ways of talking about security to get people to care for you know? Right. And and so Chris Roberts for a while has talked about maybe we should call it safety.
Right? Because people intrinsically understand, oh, like, safety is important.
Mhmm.
And so, I don't disagree with Chris. I think Chris is brilliant. And that's a that's an interesting approach. And if it resonates with your the people, absolutely wrong with that.
But I think another way of talking about it that people can absorb is about is quality. Right? You look at the quality revolution. Right?
You know, really, if if doctor Deming hadn't gone to Japan and they hadn't started doing great quality Right.
It would not have come to the US, arguably. Right?
And so if you look at doctors, Deming and Juran, what they did was they they quantify that and they told told people explicitly, hey, quality is important.
And that sounds like duh, obviously.
But it wasn't it wasn't a duh before they did their work.
It really wasn't. And there's massive, of course, variation. Right? How Jen, you know, puts the the bolts onto this car wheel is different than how Dutch does it.
Right? And so quality now today, you know, these deck is, like, everybody intrinsically understands that, you know, in an enterprise because nobody would be like, well, quality is not important. That's no. Everybody gets that.
Right? It's important. So you just try to make that same thing because the the gaps in security are behavioral.
Right.
It it's people. Right? So you have to think of it as a behavioral challenge. That's why we take something that we all, you know, know intimately and have talked about a million times, like passwords. Right?
Mhmm.
And moving to passwordless.
Right? There's great solutions out there. And frankly, there's been great solutions for for for years. Right? So to but it's you're having to you have to change people's behavior.
Sure.
Right? And so you have to think of it as a behavior issue. So you you gotta look through the lens of what's my company culture, then what are the activities that that would, you know, catch on here? Like, what would drive behavior?
You have to start looking at as behavior, that we all agree. Hey. This is good behavior. Like, this is intrinsic to what we do just like quality is important, whether or not you're in cost accounting and finance or whether you're in HR and training.
Right? It's everybody agrees that quality. So security and safety have to just be viewed as table stakes. Like, we all have to care.
Mhmm. So, you know, a once a quarter or once a year, you know, employee awareness training, I mean, do it, of course. Like, you should do awareness training, but that's probably not gonna solve it.
Right. Exactly. Change the culture. And I like how you said, that in some cases, people might resonate with the word safety in some some for me, I don't personally resonate with the word safety because I believe that that growth does not happen in safe spaces.
But that quality is something that really resonates with me because you can you know, that that whole the concept of the oodle loop and you can always get better, you can always get better. Right? That is something that personally, resonates with me. But I am not everyone.
Right? Right.
So there are some organizations where the safety, and especially a lot of the the health care organizations that I work with, they care a lot about that safety concept.
And so that is something that I speak to with them. So I think, like you said, knowing, first of all, what is the culture of an organization? And how do you maximize that culture from a security perspective to bring in these concepts to what is already valued in that organization? I thinks the way forward for security.
Yeah. And if you think about the things that we've talked about for the last few minutes, none of those are about a specific technology.
Right.
We they're not. Right?
Can't you're not gonna just go buy a tool for these?
They're not. Right? And so look, I love technology. Like, I have a house full of it.
Right? I mean, so so I'm a full on, you know, technology geek, like like, probably the majority of us are. Yeah. Having said that, the path forward to make substantial enduring change is about people.
Absolutely. Right?
And so it's really about the things that we need to do to engage. Because if you think about the risk just in general, right, and we look at any any kind of Verizon DVR, any report you wanna look at. Right? So most of it comes down to some kind of human, you know, you know, issue.
Right? Unintentional, intentional, compromised, social engineering. The exact vector in this case is not really that important. Right?
But we could we could say it's fishing. I'm playing with that. Let's just say it's fishing. But you have to if you can teach the the the everybody in the organization that it's important, that changes the way that you talk about it, and it changes the way that and we know that culture, if you're let's look at it let let's look at it when it's not working.
If if you feel like the culture that you're in doesn't fit you and that doesn't mean that it's a bad culture. It's just, hey. This is not Jen's jam.
Yeah.
You know?
Like, it's not the culture she likes. Here's what happens. What the research shows is that you, you feel higher higher levels of stress. Mhmm. You become disengaged.
Mhmm.
You have a tendency to work quickly or skip things Yeah. Or just the minimum because it it's just not a good fit for you. Well, all those things I just mentioned, those are the way things happen for compromises.
Yes.
Right? So when you're not engaged, when you're working too quickly, when you aren't thinking about the bigger picture of what is my my role in, you know, the, you know, in the legal department mean vis a vis the actual business. When you're disengaged, then that's far more likely. Right? And the research shows that you'll have, more mistakes.
Right.
And those mistakes will lead ultimately to unauthorized access or breaches or or what have you or or potential risks.
Right? So the flip side of this, you you you have to consciously think about culture and and explicitly build that out, and then that engages people.
Sure.
Right? And it and it makes you feel excited. Right? And it makes you go, oh, wait a minute.
Let me oh, how does what I do impact Susan in accounting and Sanjay in legal? You know, like, it it it changes the way that you just approach your job. Right? And so, I think that's one of the one of the things that you need to do moving forward to be successful.
I I agree. And I think that it's it there is responsibility on both sides for that. That's good. So if you're in a position where the culture does not fit you, it's okay to recognize that this is not the place for me.
Drop drop that fear and allow yourself to go find a place where where the culture is right for you. And I and I get this question a lot in in mentoring people, especially people who are new to the workplace or who have been stuck in the same place for a long time. And they say, how do I find a good culture fit? Well, as crazy as it might sound, just go find another job.
And if it doesn't work for you, you know what? You get a buy and you get to go find another job. And it's okay. I mean, don't every six months for five years do it.
But but chances are good if you if you try and you'd go, oh, man. This still isn't right. You're gonna find another one that that really is for you. Because during the the, the interview process, you'll you'll start learning to ask the right things that that give it a good place for you.
On the other hand, the CISO's role is to help people find their footing in a certain culture.
And and one of the things that you said to me was people make mistakes. People people, come come up short. And we can either, as leaders, discard those people, you know, ask them to leave, shuffle them to decide, find a place for them that they're not going to to cause damage or turn it around and make it a positive thing where they become a a fully functional engaged person. So, what are your thoughts on the CISO's role in in bringing people along into a culture?
Yeah. So to use the example we use there, right, there there's a great phrase, that I heard recently, mistakes of effort. Right? And those are different kind of mistake.
Right? Mistake of effort is I was trying to do something and either I wasn't aware that there was an impact. Right? And so that that then that's one thing.
You know, that's one way that or I was really trying to do my job in a way that I thought was, you know, commensurate with with my role and my responsibility. And so here's a good example. Right? So the entire fact that CASB exists, in my estimation, is because, by and large, employees were trying to do the right thing.
They were trying to go get a tool that enabled them to do a thing Mhmm.
Either in in a way that was they felt was simpler, faster, easier, more effective than whatever tool or maybe they didn't have a tool. Right? And so, the ability to go do that changed the paradigm. But but mostly, it was well intentioned.
Mhmm. It wasn't you know, the the employees weren't trying to do anything nefarious. They were like, hey. I need to do x y z, and we don't really have that tool.
I'm just gonna go get that tool.
Right.
And so if you don't have good awareness and good training, or or even to ask or here's the other thing. Or if you don't have a connection. If I have a connection, if I have a security champ Mhmm. Or mentor or, you know, again, there's different ways of kind of, you know, inculcating that in the culture. But if I if I also I'm like, oh, I should maybe I should go ask Jen.
Right. Somebody that you're somebody that you feel comfortable asking something of, then they won't make fun of you or they'll they'll help you with your and instead of pointing out how you have, deficiencies.
Right. It's pretty critical.
Yeah. So mistakes of effort. Right? Those are totally different. So now either have to figure out we've gotta do a better training program or a different style of training because it didn't connect with Jen. Or Dutch, I understand where you're headed with that.
By you purchasing x y z software, there's a EULA, and I know you don't know what that means. Here's what you know, but it's a it's a license. And when you do that and then you use it to put any kind of company content in there, we're actually at risk. Because I know you I know you were trying to do it for the right reasons.
I know you're trying to be expedient, and you're trying to do sharing with five different people in five different parts of the world.
Right.
So kudos for awesome as an employee. However, there's a risk associated with that. Mhmm. And that's why and so that's part of that that circular loop.
Right? Is that, the the piece I haven't talked about is is GRC. Right? And so I would talk about policies.
Right?
And so if policies are sort of, wonky people over here create policies and they just get shoved down to every employee Who ignores them?
There's not gonna be good engagement. Right? So the other method to approach that is, hey. Let's have whatever we would call them, town halls, sensing sessions, team meetings, whatever. With the security, and especially in this case, GRC teams need to go out and actually connect with the people and say, hey.
Here's three examples that happened last year. Right? And and not to to, you know, highlight negatively what that that that person or that team did. Just say, here's why that was a risk. You know, Dutch went and used Zipi drive, and it has a EULA which says anything that's put in there, they own or they have the rights to. And Dutch puts some content in there that, you know, we we wouldn't really want somebody else to have.
And I mean, it wasn't as maybe he or she didn't think of that as super sensitive, but but it's still, you know, intellectual property of ours.
It's just a marketing campaign, Dutch. Right. Exactly. Right.
Right. And you're like, well, this is the marketing campaign. It's the branding stuff. Right? And and and then but I'm trying to share it with, you know, with, of course, you know, my my peer who works in Germany.
Right. And this was an easier way for me to do that. So so you have to get out there. You have to have a connection.
There has to be a communication path.
Sure.
Right? That I, as the employee, have somewhere to go to that I feel comfortable. Go, hey.
Like, we don't have fill in the blank resource. I think I need that.
The official process came back as no. But, like, how do I I don't, like, I don't wanna get around it per se, but, like, I really need a way to solve this. Sure. And they need somewhere to be able to go to have those conversations.
Yep. And and I know for myself, I often am much more, tolerant of those conversations with people who are less experienced or maybe, of a of a different role classification than I am, where if it's my peers or someone that who is, senior to me in management, I have I have historically had zero zero tolerance for their limitations.
And I just am here to tell people who might be in a similar situation, that does not go well for you. Right? And so the expectation that our senior people are going to be patient with the the junior people, it needs to go the other way too. If you're junior, you need to be patient with senior people because we all get things wrong at some times. And if we have open communication where we can resolve it in a way that is positive for their both the relationship and the organization, everybody gets to to move ahead, rather than, you know, kinda getting bogged down in irritations. Right?
Well, that's that's a great point about right. It's it's an an internal bias that that, you know, it's it's easy for anyone to have. Right? So whatever your domain expertise is in, especially as you're building it out and you feel really passionate about it and you're really, you know, really this is my jam.
This is what I do all the time. Right? But think about it. Well but what if it was reversed?
And what if somebody showed up and said, hey, Jen, I cannot believe that you did this thing because this violates Sarbanes Oxley. We're like, what? What?
What was that?
I'm like, how do you not know what SOX compliance is?
I mean, Jen, seriously.
And then where does our relationship go?
Yeah.
So horrible. Exactly. Yeah.
Right. Right. So that's back to the trusting. Right? So you have to you have to develop trust.
Right? And trust means I show up. I do the things I say I'm gonna do. I have competence in my domain, but I respect the competence that you have in your domain.
Right.
So so when we're working with other people, sometimes there's more time and opportunity to build those relationships. But I kinda wanna bring it back to, a a personal, question that I, sometimes struggle with. And that is, I'll go into an organization that is asking for an assessment. They need one by either by law or or for for whatever reason.
And I'll I'll go in and I get handed, here's the team that's going to work with you. And then the seesaw walks away.
So from your perspective, what's a good way to help engage them and and get them so that they understand their value to what's going on?
Yeah. So that's a tough one. Right? So first, I think that we would all orient on, hey.
Look. There's sort of a higher level value to the thing. Right? Whether it's a a pen test or or a compliance or an audit.
And I'll I'll I'll give you an analogy. Right? So let's I picked on DLP and CASB. So now let me pick on, you know, let's say that it's it's it's it's WAF.
So a very common use case for WAF is I just need it because I need it for compliance. Right?
Mhmm.
And so, so so I'm trying to pick on different topics, you know, different technologies equally. So I love WAF, by the way. So but but you you can go in, and if you're the the person who's loves the WAF Mhmm. As I do, you're, of course, passionate, like, you know, well, no. But there's it does all of these things and here's the problems it can solve and here's how it mitigates risk. But if the orientation starts with, I just need it for compliance.
Yeah.
Now, again, we would say if we were coaches, wait. That's not the right approach.
Right.
But you have to be realistic that it might be where they're at.
Uh-huh.
And and so if if that's where they're at, then and I do all the things that I would wanna do to try to coach you and say, right. But if we're going to invest in x y z, let's get maximal value. Right? Let's bring business value back to to to your to your organization.
At the end of the day, the customer gets to choose. And if if their assessment is, this is just in right now, it's not in my top five. And so I just need to do then then in candor, I would say, then then buy the minimally safe, you know, usable WAF for you and move on.
So respect the business decision from where they're coming from and and You have to.
Right? So try to change your course. Right? Try to try to ask those questions. So when I've talked with, you know, managers, directors and say, hey.
But so but but but why do we need, you know, the thing? Right? Whether it's a service or or technology or solution. And if they don't know, I might coach them through, like, well, okay.
Is it one of these five? Mhmm. Like, what do you like, do we know where it ties into? Right?
So bring it back to the why.
Bring it back to the why. So if you ask, hey. Why you know, not not, like, challenging, but, like, hey. What's what's the scope of the why are we trying to why are you guys trying to accomplish this? If they don't know, then you can kinda coach them through. Okay. Where's the five big business, you know, strategies?
You know, is it about speed to market? Is it about reducing friction? Is it innovation? Is it flexibility?
You you walk through that. And then sometimes that will click. And they'll go, oh, yeah. You know what?
Yeah. You know what? I do know that my boss or the board cares about, reducing friction. Like, that's a really big issue for the COO right now or whomever.
And so sometimes that will just walking them through that. I've done it on a barn at. You know? And they went, oh, yeah.
It's actually because they might present to you as a problem. They say, hey. We need to, we have too many firewall rules. And I went, okay.
Cool.
Why do you think that is? No. But I want you to fix this and write a script. Oh, no.
No. Well, like, I got a bunch of smart nerds. Like, okay. I mean, well, sure.
We'll do that. But, like, why why do you think you have too many fire models? And then they're like, what? What?
I'm like, yeah. But, like, why do you think that is? And eventually, we'll get to one of those things. Right?
Yep. So it it keeps coming back to what is the business reason behind what's what's going on.
Right. And in that instance, it was speed to market. We're trying to move so quickly, and we've outsourced.
And now we've accepted more risk, but I'm having to create all these rules. And so when we got there, then that person went, oh, it's speed to market. My boss is fixated on that. And I'm like, cool. So now we have now we can have a different conversation.
So I think you're trying to firewall your way around what is actually a zero trust issue.
Mhmm.
So right? So now change the conversation, and then that led to all the security people in the room, all the networking people in the room, all the right and we said, okay. Let's think about this backwards. What's the we're net.
Right? This is the issue. The issue is how do you give ephemeral trust to to to Jen for a finite period of time and then and then retract that? Because that's what you're doing.
So, really, you're staying with, where they're at. You're accepting the business decision that they're giving you and maybe, you know, return to the security, question again next year.
Yep. That's it.
Well, this has been a super conversation.
Have we missed anything? Is there anything else you wanted to touch on before we left?
No. I think no. We've made a bunch of the great topics. There's I would just encourage people.
There's tons of great, like I said, there's new books that have come out. There's tons of great podcasts out including yours, of course. I mean, people are talking about this topic, and I think what I would ask is, like, let's continue to socialize it both with, the the people who are are coming up in the security realm. Right?
So that they understand that maybe you come in through GRC or maybe you come in through threat hunting or whatever, but there's more opportunities for you. Sure. Right? That would be the first thing.
My second thing that that I have a goal as a goal is we need people from other domains. We need people from Definitely. Social sciences, from psychology, from HR. Like, we need people to move into security.
Right.
Right? So there's there's a projected gap, right, that we all hear over and over and over again. Right? And so that I I'll take a face value that the numbers are right. Let's just just say they are. Having said that, I I don't think the gap is the is is the same dimensions as what it's being described.
We have people. There are people who want to get into security.
Right.
We have to be more creative in helping them get into security.
And one of the ways to do that is, one thing you mentioned, right, mentoring, Uh-huh.
Right? I think we should bring back internships, right, that we need to do in nineteen ninety nine and two thousand before the global burst. Right? There's tons of internships. There's ways for you to get or ways for you to move. Oh, I'm in HR, and I've done this for three or four years. And, oh, this actually seems really interesting.
And today, those paths are mostly all of us cutting our own path to try to figure out how do I do that.
Right? And so I would encourage, you know, hiring managers, whatever your your capacity, to think about that. How do I bring other people in? Right?
Because competencies transfer. Right? Whether that's I used to work at a charity. I I grew up working at a pool.
I was a stay at home parent. Like, you still have competencies. And so you have to just be more creative. Like, how do I leverage those and bring those in? Because, Jen, I can teach you how to do a pen test.
Yep. Yep. I I can teach the techniques. I can teach the tools. I can but the competencies, that's that's baseline.
Yep. Absolutely. So I would say, let's, you know, let's do a better job collectively as a community. I think there's a lot of energy around this right now. So, that's my message.
Terrific. Well, if people want to get in contact with you, what's the best way for them to do it?
So you can just find me on LinkedIn. I'm I'm Dutch Schwartz, so you can just you can look me up and and find me there and it's easy. But you can find me on Twitter as well. Dutch underscore twenty six on on Twitter. But I mostly just read what everybody else, is is chatting about. I'm not a super active on on there. But on LinkedIn, I'm pretty active in the in the various communities.
Well, thank you so much. I've really enjoyed talking to you today and and hope we get to connect again in the near future.
It was great. I appreciate being on. Thanks.
Thank you so much for joining us. I hope that you learned some things about CISO's. I sure did. I really appreciated Dutch's time with us and, hope to see you again next time.
Thanks for watching. To watch more episodes of Security Metrics podcast, click on the box on the right. If you prefer to listen to this podcast, it's available on all your favorite podcast platforms. See you on the slopes.
