
Sign up to save your podcasts
Or


This episode features an interview with Kelly Haydu. Kelly is Vice President of Information Security and Technology at CarGurus, the most visited automotive shopping site in the US. Prior to CarGurus, she served as Senior Director of InfoSec at Salsify. Before her tenure in the security space, Kelly worked in Quality Assurance including lead automation roles across markets and verticals. On this episode, Kelly and host Tim Chase discuss sources for keeping up on the latest privacy laws, why there isn’t a national privacy law in the U.S., the benefits of micro training and more.
Key Quotes
*”If you get too technical, you'll lose your audience very fast. So if you can correlate it back to somebody's real life or an example of how it may relate back to a theme, it resonates more. As soon as you start getting into the technical jargon, you're going to lose people. Because people already think security is boring and complex and don't understand the jargon. So that's how I start with education.”
*”From an engineering perspective, building privacy by design into our pipeline starting with the product teams. But really explaining why it's important to do that up front. The cost of a breach is the cost of a breach. But just looking at a vulnerability that makes it into production, let's say it's a high vulnerability. The cost to remediate that vulnerability is more expensive after the fact than if you address it up front, before it gets into production. And so explaining that to engineers and making sure that you're partnering with them and providing them guidance on what's a go/no-go decision, and not being a blocker, will help drive adoption.”
*”Micro training is great. And make it fun. I received a LinkedIn message from an old coworker at a new organization now that said, ‘Hey, don't know if you remember me, but you gave this security training at a previous company, and I thought it was hilarious but it stuck with me.’ And that really got to my heart, because I said, ‘Yes, I got to that person. They remembered the security training.’ And if you're going to be boring about it, It's not going to resonate with people.”
Time Stamps
[0:39] Introducing Kelly Haydu, VP of InfoSec, Technology and Enterprise Applications at CarGurus
[1:40] Where do security and privacy overlap?
[3:41] How do you educate the executive team on compliance?
[5:42] How do you stay up to date on current privacy laws?
[9:23] Why has it been so difficult to get a national privacy law?
[14:48] How did Kelly first become involved in IT and security?
[16:57] What was Kelly’s path to CarGurus?
[20:35] What makes a good cybersecurity leader?
[22:43] How is cybersecurity a strategic partner to the business?
[24:53] How does Kelly build privacy by design into their pipeline?
[27:08] How does Kelly’s team train the entire company on cybersecurity?
[28:38] How do you make cybersecurity training fun?
Links
Connect with Kelly on LinkedIn
Learn more about CarGurus
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Sebastien Jeanquier, Chief Security Officer at Upvest, a fintech startup that empowers other fintechs to provide their customers with seamless, reliable and secure access to the full range of investment opportunities. Sebastien has over 15 years of experience including security advisory consulting, penetration testing and incident management. On this episode, Sebastien and host Tim Chase discuss how to strike the perfect balance of functionality, process and education to build a security-first fintech ecosystem, what it means to take a bottom-up approach, and how to treat security as a first-class citizen.
Key Quotes
*”Security as a domain is now as wide as it is deep, and it's a very delicate balance; to have the sufficient depth but also breadth of knowledge to be able to go and have a conversation with the most technical person in your team and be a meaningful sparring partner for them, even if you're not going to be involved in this sort the details of how that thing gets implemented. “
*”Management has to make it clear that the expectation is for security to be taken as a top consideration, whether it's part of developing a product or as part of your back office operations and processes. It also means making someone responsible for that, not as a side job…putting someone, with the relevant skillset and experience in a position with their peers, with some of the other business leaders. For very small companies, this can be tricky because they may mean committing early on to hiring a senior security leader, which is not something that a lot of startups can feel like they can afford to do. But at the same time, that security leader can help lay the foundations for robust security culture and controls, whilst also helping to enable other teams.”
*”You can do a great deal of work very early on, with very little team and budget. But the earlier you can set the foundations, the more dividends they will pay off over time. Because, the rework of trying to implement security later on, both from a cultural perspective, but also from a technological and control perspective, it just gets exponentially harder…If you're at a stage where you do have a CISO, then effectively they should report to the CEO or a managing director, or in a larger organization directly to the board. That person needs to have the ability to disagree with their counterparts, and not just be overlooked and say, ‘No, the priority is to ship the product. But the priority is not compliance right now.’ You need to be able to have that constructive criticism between each other without fearing that you're stepping on your manager's toes.”
*”The traditional CISO of traditional or legacy organizations and a lot of top down or risk-focused security, they expect to put good sounding policies and standards in place, and expect those to get implemented as strong technical or procedural controls at the bottom. And I think that's overly optimistic. A modern CISO in the kind of space that we're in now has to have a strong grasp of the layers in between their strategy and the policies, all the way down to the kinds of threats that their kind of organization faces. And what does an effective control look like to counter those?”
*”Security is especially an enabler in regulated environments where a certain number of controls will be imposed on you regardless of what you're doing. And any number of controls poorly implemented will result in a drain on your company's resources over time.”
Time Stamps
[0:27] Introducing Sebastien Jeanquier, Chief Security Officer at Upvest
[1:41] What does it mean to treat security as a first class citizen?
[5:51] What advice would he give other companies to take security as a top consideration?
[9:09] How do you approach security from the bottom-up?
[12:30] How is security a business enabler?
[15:04] What makes a good cyber leader?
[17:56] How do you build trust with your team and with the board?
[27:27] What does Sebastien see as upcoming challenges in security?
[29:38] What’s the most important habit a security leader can have?
[30:46] What’s one thing people can do to increase their cybersecurity?
Links
Connect with Sebastien on LinkedIn
Learn more about Upvest
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Emily Mossburg, Global Cyber Leader at Deloitte, a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax, and related services. She has more than 20 years of experience across both federal and private sectors in developing strategy and programs, and implementing technical solutions to manage cyber and associated risk, information security, data protection and privacy. And on this episode, Emily and host Tim Chase discuss the benefits of cyber spend on business outcomes, how the role of the CISO has expanded as the cybersecurity industry has matured, and how to appeal to a diverse set of candidates when hiring.
Key Quotes
*”Any real, fundamental shift to the underlying way in which an organization does business changes the threat landscape. You can't ignore that. You've got to address the fact that you're making changes that are potentially opening up new risks as you go.”
*”There is no magic number. The cyber risk will never be zero.”
Time Stamps
[0:32] Introducing Emily Mossburg, Global Cyber Leader at Deloitte
[1:17] How does Emily think about risk?
[3:45] How is security a business enabler?
[6:52] How is cyber a differentiator?
[7:52] How is Emily addressing security needs across borders?
[12:03] What were the findings of Deloitte’s Global Future of Cyber survey?
[16:05] Can you ever spend enough on cyber to bring risk to zero?
[17:32] Are companies increasing or decreasing cyber spend?
[19:34] How does diversity in cyber lead to better business resilience?
[24:28] What is Deloitte doing to bring more women into the cyber industry?
[30:15] What’s the biggest learning of Emily’s career?
[34:14] What advice would Emily give to someone wanting to get into the cybersecurity field?
Links
Connect with Emily on LinkedIn
Learn more about Deloitte
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Bill Dougherty, CISO at Omada Health, a virtual-first, integrated care provider combining the latest clinical protocols with breakthrough behavior science to make it possible for people with chronic conditions to achieve long-term improvements in their health. Bill brings with him over 25 years of experience in IT and security at such companies as RagingWire, StubHub and Copart. And on this episode, Bill and host Tim Chase discuss the ins and outs of threat modeling, the cybersecurity basics every security leader should revisit, and why every IT or security leader should have another expertise within the business.
Key Quotes
*”If you've got the right relationships and you build the right risk model, you can get the resources you need. Not necessarily what you want, but the resources you need to do the job right.”
*”The best IT people and the best security people that I know have some other expertise within the business first.”
*”If you want to run Salesforce, run a commercial system. You should have some expertise in the sales side of the house and some affinity for what it's like to get up every morning and make 50 cold calls and get hung up on 50 times because that then gives you the knowledge you need to make the system better for the people who are going to actually use it. So I consider the fact that I didn't start out in IT or security actually a gift because it gives me empathy for my customers.”
Time Stamps
[0:16] Introducing Bill Dougherty, CISO at Omada Health
[0:51] How does Bill navigate HIPAA?
[2:26] How does Bill advocate for more budget?
[5:01] Does Bill add more regulations to those imposed by HIPAA?
[8:56] What’s the difference between following security regulations and compliance with the law?
[11:20] What’s threat modeling?
[13:15] How do you integrate threat modeling?
[16:47] What’s the INCLUDES NO DIRT threat model?
[19:41] Why is it important to revisit cybersecurity basics?
[24:27] How did Bill first get involved in IT and cybersecurity?
[28:46] Bill’s advice for other cybersecurity and IT professionals
Links
Connect with Bill on LinkedIn
Learn more about Omada Health
Read more about the INCLUDES NO DIRT threat model
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Craig Riddell, Field CISO at Netwrix Corporation, a provider of data security solutions for on-premises, hybrid, and cloud infrastructures. Craig is also a multiple award-winning Director and Strategist in Identity and Access Management. Previously, Craig served as Director of Identity and Access Management at HP. He brings a wealth of knowledge and experience around modernizing identity solutions while reducing costs and improving security. On this episode, host Tim Chase and Craig discuss managing third party permissions, how your tools are only as good as your implementation of them, and why a single daily identity authentication isn’t enough.
Key Quotes
*”A modern identity practice really needs to look at truly reducing the risk to the business, not just managing the risk to the business. A heavy degree of automation, especially in the concepts of, like, movers, joiners, and leavers so that you can prevent snowballing permissions, and then also needs to look heavily at third parties.”
*”Just because you've spent money on something in the past doesn't mean it's still a worthy investment today.”
*”A heavy degree in automation means if I hire somebody, I shouldn't have to go into any other system than my hiring system.”
*”Just having a multifactor authentication check in the middle of the day, or at the beginning of the day, does not mean that your identity is now validated for the next 24 hours. We need to be looking at things like user behavior analytics. We need to be looking at things like adaptive authentication. If you move into a certain risk profile, all of those things. There is no silver bullet for identity.”
*”Identity touches everything from the end user to the most complicated critical application. We have to know how all of these different workflows work. So it's a very hard skillset to staff with and collapsing some of these tools down and making them to where you can have one engineer to run multiple things obviously helps.”
*”Your tools are only as good as the implementation. If it's super easy to bypass your PAM solution by, say, dropping in an SSH key and bypassing it every time instead of going through it, your engineers probably have the best of intentions. They're just trying to get their job done. But they just created a backdoor through a critical security tool.”
*”It doesn't matter how good you think you are, you can be in hot water really quick. It's important to double check. And now I do, I double check everything. I don't push enter on a text message without making sure that it's good to go. Linux will teach you the hard way.”
Time Stamps
[0:26] Introducing Craig Riddell, Field CISO at Netwrix Corporation
[1:26] Why did COVID make identity a priority for businesses?
[2:53] What does modern identity look like?
[4:51] How can you automate identity?
[6:43] How do you navigate over-provisioning in identity management?
[9:58] What acronyms should you know in identity management?
[11:52] How will identity tools change in the future?
[14:16] How has cloud changed identity?
[16:40] What does zero trust mean to Craig, and how does it play into the future of identity?
[19:22] How did Craig get involved in identity?
[27:44] What advice would Craig give someone wanting to get into cyber?
[30:13] What was the biggest learning of Craig’s career?
[32:00] What’s the best habit an IT leader can have?
Links
Connect with Craig on LinkedIn
Learn more about Netwrix Corporation
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Wes Mullins, Chief Technology Officer at Deepwatch, Deepwatch's innovative cloud platform and borderless SOC extends their customers’ cybersecurity teams and proactively protects their brand, reputation and digital assets. Wes has nearly 20 years of industry experience, having started his career as a developer, then working in networking and finally cybersecurity. Prior to Deepwatch, Wes was the VP of Global Cyber at Nielsen. On this episode, host Tim Chase and Wes discuss the factors he considers when selecting potential partners - and how they got a partnership with AWS - why you shouldn’t try to sell anything during the first customer engagement, and the one most important quality in a new hire.
Key Quotes
*”You can teach aptitude, but you can't teach attitude. So how do you find the right people that maybe don't have the experience that's on the job description, that maybe don't meet the requirements that the recruiters want or the hiring manager want, but know that they can still do the job and afford them the opportunity to do that and put people in tough positions to fail? Because if they're never put in those spots, they're never really gonna break the mold and succeed.”
*”Culture and people. We can talk about technology, AI and automation. I think any good leader, whether it's cyber or any other role, needs to have a good handle on culture in the people. They need to have a great relationship with the people team itself. The HR team or the people team, they're your advocates. They're there to help you protect you, and ensure that you're doing the right thing.”
*”If you don't have good relationships with the other parts of the business that you have to work with, it's gonna be a struggle. You need to get their buy-in. And having a great relationship across line of service, across BAU, BU, Opco, Subco, whatever they call it, things just become things on spreadsheets and swapping head count, and swapping budget and moving priorities up and back, become random phone calls on a Friday. And that's the type of relationships you want to have.”
*”Security shouldn't just be considered a call center. It's considered a business enabler. There are situations that will continue to happen where security is going to be your enabler to go as fast as you can go. Because they're gonna let you know the minimum level of acceptable risk to go ship those features and make those changes that you need.”
*”Any good first customer engagement is a fact finding session. Like not selling anything, not pitching anything, not comparing anything, most certainly not talking about competition. But really trying to find out what that individual wants, what they need, what they're trying to get, and what is their problem.”
Time Stamps
[03:30] Introducing Wes Mullins, CTO at Deepwatch
[1:18] How did Wes go from developing into security?
[5:08] From CISO to CTO
[6:28] How does Wes’ security knowledge serve him as a CTO?
[8:51] What are the critical qualities a security leader should have?
[13:20] How do you tailor your leadership approach to each customer?
[16:34] How do partnerships drive the business forward?
[18:26] What factors does Wes consider when selecting potential partners?
[20:43] How does Deepwatch coordinate communications to deliver MDR?
[27:40] What’s the one tool Wes can’t live without?
[28:18] What’s the most exciting security trend currently?
Links
Connect with Wes on LinkedIn
Learn more about Deepwatch
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Terry O’Daniel, Acting Head of Security at Amplitude. Amplitude is a product analytics platform that helps businesses to track visitors with the help of collaborative analytics. Terry joined the company in October of 2022 as Head of GRC. Prior to Amplitude, he led Governance, Risk, and Compliance within Infrastructure Engineering at Instacart. On this episode, Terry and host Tim Chase discuss the failed promise of DevSecOps, aligning with business objectives, and how to translate security into dollars.
Key Quotes
*“I think at the end of the day, risk quantification is not very sexy. I understand. But we tie ourselves in knots in security doing this interpretive dance for the board of red, yellow, green, and ‘Here's what it means,’ and bibbety boo. And businesses don't run on interpretive dance. They run on dollars. And until we can come to the table like grownups with the rest of the grownups running our function and saying, ‘Here's the risk in dollars, here's the investment in dollars, here's the risk mitigation we're gonna realize in dollars,’ that's the key, right? We have to be able to talk the language of business to be successful and be taken seriously as business partners.”
*”There's a tax that's required in actually moving left. Shifting left involves having smaller pieces and smaller interruptions more frequently in the worst case, rather than having a single showstopping event at the end.”
*”Devs don't report to us. They have their own leaders and they have their own goals. We don't control engineering. But we can give them the context. We can help them understand the context for making better risk aware decisions.”
*“If you're a SaaS company, your CISO has to be technical. At the core, your CISO is not only protecting your people and your work systems and your SDLC, they also are inherently predicting the risk of your product and that B2B relationship. So I think traditional industries still can get a huge degree of value out of hiring a CISO who comes from a strong risk and governance background. But if you're an engineering-first company that's building neat stuff, if your CISO doesn't have the finger on the pulse of that, I think they're inherently hampered from their ability to help the company shift left.”
Time Stamps
[1:24] The failed promise of DevSecOps
[4:15] Why is shifting left so hard?
[8:39] Why is continuous improvement a key part of DevSecOps?
[11:30] How can security goals align with business objectives?
[13:49] How important is leadership in DevOps?
[17:32] How did Terry transition from engineering into security?
[22:28] Is it more effective for a CISO to come from a GRC background or an engineering background?
[26:08] What’s been Terry’s biggest learning of his career?
[34:05] What’s one tool Terry can’t live without?
Links
Connect with Terry on LinkedIn
Learn more about Amplitude
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Alberto Silveira, Head of Engineering at LawnStarter, a marketplace for outdoor home services. He has more than 20 years of experience in software development, having served in leadership positions at companies like OnDeck, Amplify, and Kaplan. He’s also an author, and his book, Building and Managing High-Performance Distributed Teams is out now. On this episode, Alberto and host Tim Chase discuss organizing teams around the shared purpose of driving the business forward, infusing good security practices throughout the organization, and how to deliver more than just “security theater.”
Key Quotes
*“If we don't make security a top priority as building a new feature on the application, as automation, as CI/CD, how can we actually out succeed? Like building a new feature, but actually lacking customer data or network security, or what's the point if we're gonna be on the news tomorrow with a new security breach? And then we have the most shining feature.”
*”Traditional security practices give the sensation that you are safe. [But] is this really actually taking care of what we are trying to achieve? Or is this just us checking another box and saying that we are safe? So that's what I refer to as ‘security theater.’”
*”Security should not be seen as a separate group, as a separate initiative. All the concerns when building software - it could be architecture, it could be security, it could be automation, it could be building new features or taking care of tech debt, you name it - all of them are one single source of truth as you are building your roadmap and as you are actually working on it. And it's everyone's responsibility. It's not only for the security team.”
*“The fact that you're in the cloud doesn't mean that you're secure at all. That's just the beginning.”
Time Stamps
[1:17] What’s “security theater”?
[3:36] How do you do more than just “check the box” in security?
[7:27] What do security practitioners need to know about collaborating more effectively with development and engineering?
[11:23] The importance of educating the whole team on the repercussions of poor security management
[13:40] Does being in the cloud mean your information is secure?
[17:20] The role of the security practitioner as an educator
[19:20] Learn more about Alberto’s book, Building and Managing High-Performance Distributed Teams
[22:42] What makes a strong manager?
Links
Connect with Alberto on LinkedIn
Get Alberto’s book, Building and Managing High-Performance Distributed Teams
Learn more about LawnStarter
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Fractional-CISO Aruneesh Salhotra. Aruneesh brings with him 22 years of experience across development, DevSecOps, security, containerization and more. He is also an award-winning presenter, panelist, and author. On this episode, Aruneesh and host Andy Schneider discuss protecting IP source code, what solution to pick based on your integrations, how he’s helping companies shift left, and much more.
Key Quotes
*”You can only protect what you know about. So cloud definitely has opened the doors for misconfigurations, and misconfigurations can lead to breaches. Cloud has changed the whole security landscape.”
*”IP source code is definitely your crown jewel. So you have to protect that with utmost importance. Even if you're storing your source code internally, there is always a threat of internal actors acting against your firm. Predictive branches is definitely a no-brainer. [And] you want to ensure access is configured properly.”
*”The skills and awareness of the CISO change manyfold with the cloud. So having that awareness of what can possibly go wrong, having an awareness of not just the field itself, but also understanding who are the key players. There’s a lot of pressure on security leaders and practitioners to not only realize the need for a particular control, but at the same time trying to figure out what solution actually fits the organization based on your culture and integrations.”
Time Stamps
[1:04] The rising challenges of securing the cloud
[2:40] How does Aruneesh protect source codes?
[6:41] What skills do security practitioners need today? Do they need to be able to write code?
[13:09] As someone whose background is in AppSec, what are security leaders missing today?
[15:48] What makes a good security leader?
[20:14] What was a lesson Aruneesh learned in his career?
[22:50] What is a Fractional-CISO?
[25:57] What’s the difference in responsibilities between a Fractional-CISO and an operational internal CISO?
Links
Connect with Aruneesh on LinkedIn
Connect with Andy on LinkedIn
Learn more about Lacework
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
This episode features an interview with Billy Spears, CISO at Teradata. Teradata is the connected multi-cloud data platform for enterprise analytics, solving data challenges from start to scale. Billy has more than 25 years of industry experience. He is an award-winning technology executive, author, speaker, and podcast host. He is also an adjunct professor of cybersecurity at Webster University. Prior to joining Teradata, Billy served as CISO at Alteryx. On this episode, Billy and host Andy Schneider discuss harnessing AI for better business intelligence while managing the risk posed by it, the push and pull of growing trust, and how to use security to drive the business forward.
Key Quotes
*”I don't want any of the listeners to listen to this and go, ‘Wow, Billy said whatever about generative AI.’ I think there's a lot of pros there. You know, creativity, innovation, what you use it for, right? The sky's the limit. And we have to do a really good job of making sure that whatever you're using it for has protections around it because it's a new capability. So we have to have some protections to make sure that we don't go in with a blind eye and create more risk as a result.”
*”You can also use [AI] for better business intelligence. When you start thinking about, ‘How do I get to the root of what I'm trying to solve in security?’ You have all of this data that comes in. How do you consume that data with any sort of consistency and then deliver out the maybe anomalous results or the spikes of risk at the appropriate point of time? And this is the future for us. You don't have unlimited humans that throw out the problem. So you're going to need to use technology or augment that technology to solve the need.”
*”A few things that we can do to continue to shape and evolve as a business leader. One, understand your business. Two, be able to read the financial sheets and understand what things like ARR and ACV and TCV are. Because when you're on calls with salespeople asking you for things, those are the kind of terms they're gonna use. Be able to translate the business and financial terms into your security portfolio and be able to tie your outcomes to business objectives, meaning it's not just about the security stuff you can deliver, but how does the security drive the business forward, whether it's through protections and mitigation outcomes, or whether it's from driving new business to your business by building trust and thinking about resiliency.”
*”The great security leaders that I run into in the business, they're also business enablers. And so there's lots of ways of doing that. Security acts as a business enabler by first protecting our assets. Second, building trust. We need to support digital transformation all around the business, which is constantly occurring anyway.”
*“I'm sure the audience is gonna look at their phone or devices or take their EarPods out and say, 'What did he just say?' But the way that you grow trust is you extend trust. In our business, we talk about a zero trust environment, meaning we wanna validate or verify before we allow things through. In human interaction, if you want to gain trust, you have to extend trust first.”
Time Stamps
[1:34] Understanding the current and emerging threat landscape
[3:00] Is phishing becoming more prevalent?
[5:19] What threat does generative AI propose to security?
[7:26] How can you harness AI for better security?
[9:33] How can CISOs be business enablers?
[11:44] When is something “secure enough”?
[13:14] What makes a great security leader?
[15:26] How do you build trust?
[17:40] How can you better give and accept criticism as a security leader?
[21:22] What has been Billy’s biggest learning of his career?
[25:02] What advice would Billy give someone wanting to enter the cybersecurity industry?
[28:57] What does the future of security look like?
Links
Connect with Billy on LinkedIn
Learn more about Teradata
This podcast is brought to you by Lacework, the leading data-driven cloud-native application protection platform. Lacework is trusted by nearly 1,000 global innovators to secure the cloud from build to run. Lacework delivers true end-to-end protection, empowering customers to prioritize risks, find known and unknown threats faster, achieve continuous cloud compliance, and work smarter–not harder–all from one unified platform. Learn more at Lacework.com.
From the publisher's feed