Episode Summary
How Echo Cyber helps growing companies connect business goals with practical cybersecurity leadership. Brian talks with Michael Faas about his path from studying computer programming, pivoting away from computer science after calculus, and turning a part-time IT job into a 25-year cybersecurity career. Michael explains why his work often centers on translating between technical teams and executives, how businesses can balance security with convenience, and why even small companies are big enough to be targeted. They also discuss SOC 2, cyber insurance, project prioritization, vulnerability risk, AI security concerns, and why founder-led companies often need CTO-level thinking before they need a full-time CTO.
Key Takeaways
Cybersecurity leadership often depends on translation: helping executives and technical teams understand each other and align security work with business goals.
Security and convenience exist in tension, and the goal is to reduce risk without preventing the business from operating.
Small and mid-sized companies are still targets because attackers often use automated tools to find easy opportunities rather than hand-selecting every victim.
Vulnerability prioritization should consider both severity and likelihood, not just the scariest score on a scanner report.
Many companies reach out for help when customers ask for SOC 2 compliance, cyber insurance costs rise, or leadership realizes they need security guidance but does not know where to start.
A fractional CTO or cybersecurity advisor can help founder-led companies prioritize projects, unclog stalled initiatives, and decide what to start, pause, or kill.
AI can be powerful, but companies need to understand what AI systems can access, how they are governed, and whether the output actually improves the business process.
Timeline
Early
00:00:00 Michael’s introduction, name pronunciation, and early path into IT
00:01:00 Starting in computer programming, switching to sports management, and turning IT into a career
00:02:00 College, career paths, and why practical ability matters as much as formal education
00:03:00 Calculus as a roadblock and the difference between theoretical and practical learning
00:05:00 Michael’s 25-year career in IT, enterprise security, and translating between technical teams and executives
Middle
00:07:00 Bridging the gap between IT teams, leadership, and day-to-day business needs
00:08:00 Balancing security with convenience so the business can still operate
00:09:00 How excessive controls can push people to work around security
00:10:00 Why small businesses are still big enough to be hacked
00:11:00 Moving companies away from being the lowest-hanging fruit
00:12:00 Prioritizing vulnerabilities by likelihood as well as severity
Late
00:14:00 Why companies usually call Michael: SOC 2, cyber insurance, and unclear security needs
00:15:00 Finding stalled projects and prioritizing the work that reduces the most risk
00:17:00 Providing CTO-level guidance without requiring a full-time CTO hire
00:18:00 When AI projects should be delayed, refined, or stopped
00:19:00 AI access, data governance, secure permissions, and prompt injection risks
00:22:00 Learning from failed AI experiments and evaluating whether automation is worth it
00:23:00 Michael’s sweet spot with founder-led companies from roughly $2.5 million to $25 million in revenue, and 15 to 200 employees.
00:24:00 Helping companies decide when they actually need a full-time CTO
00:25:00 Where listeners can connect with Michael and take the Echo Cyber assessment
Links and Resources
LinkedIn: https://www.linkedin.com/in/mfaas
Company: https://echocyber.io
Echo Cyber Assessment: https://echocyber.io/assessment