Go back

Episode 06: Security is an optimist’s game

46m 10s

Episode 06: Security is an optimist’s game

The speaker shares a non-traditional career path into cybersecurity, starting with a veterinary science degree and moving through IT support, penetration testing, and consulting before becoming a CISO. Key motivations include a desire to help people and understand how systems work, whether technological or biological. The discussion highlights that successful security integrates into business processes without being obstructive, emphasizing usability and alignment with organizational goals rather than operating in isolation. Additionally, the speaker addresses gender dynamics in tech, noting instances where her contributions were ignored until repeated by male colleagues, and advocates for allyship and inclusive practices to harness diverse viewpoints. This diversity is crucial for innovation, as illustrated by examples like product oversights in male-dominated teams. Ultimately, cybersecurity is framed as a business enabler that requires clear communication and consideration of wider contexts beyond technical vulnerabilities.

Transcription

8139 Words, 44715 Characters

English
But it's not uncommon to be in a meeting room and sort of give an opinion or a potential solution to a problem and almost have that moment where you think, "Am I on mute?" Or to want outcomes and they want to understand the implications and trade-offs of different decisions. I need to sort of take them on the journey. They need to understand what we're facing and I think fear, smoke and mirrors, the whole sort of black box approach, it just doesn't work. We spend so much time kind of in the security bubble and looking at the security problems that we sometimes forget about the board of business context and sometimes it's not that the security answer is the wrong answer. It's that actually the wider business context means that that's not a desirable path to follow. I don't think we can fix the lack of diversity and cyber by just constantly poaching people from other organisations. We just move the problem around, we don't actually fix it and so the one thing I would love to see is. Before we go any further, I think you've got a really interesting career. It's kind of anything but typical, I suppose, into how you've ended up at CISO at Traxxas. So I'd love to delve into a bit more about your background for the audience and understand a bit about how you've ended up, your career path and what's led you to being CISO. I think there's a bit of veterinary science involved, maybe some really technical aspects like penetration testing and things like that, a bit of consulting and then obviously leadership in a couple of roles now as well. Tell me about your security career in the first place. What kept you passionate about it? So yes, now veterinary science, I guess, isn't a standard starting point for cyber security but it's what my degree was and it's where my interest sort of initially lied way back when in the Domenistan's part when I was attending university. But I funded that degree by running a fabric networking company and digging trenches, pulling cables, it was really, really good fun. Particularly done in South Africa where the weather is nice, 90% of the year. I'm glad I'm not doing that anymore over here. Really good to say. There are a few people working for open reach in other other fibre companies there in the UK that maybe might disagree with you now. Yes, it's a very different environment. But just, life happened and I had to make a choice about continuing my degree or focusing on the business. And so actually I thought, you know what, I always come back to my degree, I can pick it up but actually having that capital early on in my life was really important so I could afford to get on the housing ladder. And so I went down that route. And I kind of never went back to veterinary. I then moved over to the UK and got into IT support. And I just, I loved, I loved the ability to help people with an IT support. I really enjoyed being able to fix people's printers. I still can't fix my own but that's another story. But sort of helping people figure out complex spreadsheet calculations and the likes. And I really, really enjoyed the being able to just give a little and make people's lives a bit easier. And then I was really, really nice. I think quite a parallel there, I suppose, between what people might associate with, you know, with a vet or something like that. It is about helping people, but also about understanding systems, I suppose. Be they technology systems or, you know, respiratory systems and in an animal law or kind of, you know, circulatory systems and things like that. So quite a few parallels, I think there may be, but I'd be closer than you feel, sort of in terms of your career trajectories. I think you're right because sort of helping people is very much coupled by the trying to figure out how things work. What makes people, animals, technology, tick and makes us operate? I think probably in my very younger years, my parents were probably terrified every time they saw me with a screwdriver because I would take everything apart in the house. Just to figure out, you know, why does it do that? How does it do that? I'd always put it back together again with the few screws lying left over that no one knows what they belong to. But it always worked so it was fine. But yeah, I just really enjoyed that and then yeah, I got really lucky. A company I was working at had an opening for a junior pen tester and I thought, right, you know, I know the nuts and bolts quite physically with building hardware and whatnot. It'd be really nice to get under the hood of technology and actually, you know, how are our platforms operating? I've done a little bit of web development and DBA work, but hadn't really sort of gone into the sort of security side beyond patching operating systems and the like. And so I did that for a while, really enjoyed breaking stuff. There's some scary stuff you find when you're pen testing. And yeah, absolutely loved doing that. It was fascinating, but actually, I got bored with the lack of the social side. Pen testing is very, very isolated and actually it's really, really difficult to form those connections with people that you do with an IT. And I absolutely missed that. So I spoke to my boss and he said, well, you've done a pen test report for this company. We're presenting the results to them on Tuesday. Why don't you come along and actually present them? That was a pet of the stomach moment and oh my god, I've got to actually talk to proper people again and present myself, you know, not just chatting to people at the desk. Well, and better got it right. That's an element to that, right? What if they question what I've done? Yeah, exactly. And what if they don't like the results I'm sharing with them? You know, part of pen testing is finding those vulnerabilities and some people take those really personally. They take it as an attack on them, particularly if you're talking to engineers who have built that system. It was really, really nerve-wracking. And I loved it. I loved talking about security with people who cared about security. And I'm very swiftly pivoted into security consulting and auditing. I try not to boast about the auditing, but because you mentioned being an auditor and people sort of turn away from your Christmas parties and the like. But yes, I just, that definitely sort of waited my appetite. And I thought, you know, no, I really like this. And then I was very lucky, again, one of my customers poached me and sort of took me over to the other side of the desk. And I think that's when I really found my niche and my happy space as I being able to take a company through that journey of building security from almost nothing or almost an afterthought and making it become BAU embedding it into people's lives so that, you know, I've always got the view that if you're doing security right, people don't notice it. And going through that journey and getting to the end point has been the thing that's really attracted me to security and kept me in the industry. There's also this sort of going right back to the original sort of thing of helping people. Actually, if you're doing cyber security right, you're helping a whole bunch of people. You know, you're helping the engineers who are building it because you're not constantly having to retrofit security issues. You're helping all the users of the platform by helping keep them secure. You know, we can't expect everyone to have the same cyber knowledge that we have. So actually, if the users of the platform can use an confidence knowing that their data's safe and it's not going to be exploited, then actually, you know, I think that's a mess of when. But yes, it's been an interesting journey. I agree. I think there's a really important part there about, particularly about kind of that security versus usability trade off. And I think it's something that all to often people can forget about is that good security protects people. And there may be some, you know, quotes cost associated with that in terms of, you know, maybe you can't just walk straight through the door. You've got to get the keys out first kind of thing. But it shouldn't be good security. I think you said it best. Keeps out the way of people and lets them get on with what they want to achieve in a kind of confident manner rather than getting in the way or making people's lives difficult. That's where I think you find people kind of going off the happy path and trying to work around controls and things like that that people put in place. That's probably a good indicator of where where something's gone wrong on a security program. Yeah, I think people forget that there's the A in the CIA triangle availability is key. It's got to be accessible. It's got to be usable because I used to say to people and this is going to date me somewhat, you know, the most secure system in the world is a nt4 server in a locked room with no network connections. So that kind of tells you how long ago I used to say that. How do governments standards would still have you have an nt4 system in a lot of terms with with no connections to anything else? They may not be quite as old as you think. It's actually not because when you look at it, it's not secure because it's not accessible and people can't use it. And I think sort of the way technology's moving, that accessibility becomes so much more important. Yeah, completely agree, completely agree. So yeah, I think really interesting the path that you've kind of taken and obviously ending up as a CISO in your last couple of roles, you know, senior member of technology and business leadership teams. You're one of a rare breed, I suppose, there being a woman who's a CISO. Unfortunately, there aren't many of you yet, a growing number, but still tends to be quite male-dominated. Do you find that as a woman in tech that you've had a different experience than a man might have had on that journey? How was your gender affected that kind of affected that journey and also coming back to the title of the podcast, I suppose, how you've communicated results and things to people? Yes, I mean, I can't say that no man has ever experienced some of the things that I've experienced because, you know, I can't speak for what they've been through, but I've had some really interesting experiences along the way. One of my absolute favourite that I love to talk to people about, just to show how much things have changed is not that long ago, I was entering a meeting with a new vendor. I brought my junior along with me because I thought it'd be really useful exposure for him, start getting a feel for how negotiations are done, how we talked to our vendors and about building those partnerships. And it was one of those days. You know, everything was running late, so I was a bit frazzled and came sort of barging into the meeting room and the vendor was sitting down at the table and they immediately looked at me and said, "Oh, can we have a couple of coffees, please love?" And I just thought, "Oh!" And it was a really weird moment because I'm sure had that been directed in a mail, they maybe felt a little bit different about it, they maybe, you know, it would have been less of a condescending statement and maybe just because I'm female, I took it as a condescending statement. But there was that sort of moment where it plays through your mind of, "Well, I'm a people pleaser. Should I just go and do that? Should I get their coffee?" But actually, no, I'm the leader, I'm the client. Why am I doing this? It made for a very, sorry. I imagine there was a, that comment was followed very shortly by them, you know, trying to remove the foot from the mouth as they realized what they'd just, what they'd just done, right? Yes, it made for a very, very awkward rest of the meeting, but some fantastic discounting. So, you know, swings and roundabouts. Every cloud I suppose, but yeah, it would have been nice for real. I think some of that is obviously a terrible situation to find yourself in, but also just really bad sales hygiene from not knowing your customer or having seemingly done any research about who the decision-maker might be in this situation as well. I will give them sort of a little bit of defence in that they were a French reseller. Michelle is a very common male name in French with the sort of similar spelling. So, I will, you know, I will give the benefit of the doubt. I don't think you necessarily have to do that. I think that's very generous of you, but yeah, not necessary. So, I mean, that's a very specific example, I suppose, of kind of well being recognised, but then also kind of making your voice heard in meetings and things like that. Is there, do you find that sometimes your ideas are overlooked or, you know, or that some of the value that comes from diverse perspectives is missed by kind of group thinking, you know, I'm assuming some of the organisations you've worked in are still kind of largely kind of male-dominated management teams and things like that. Are there any kind of concrete practical steps you've found as a woman in tech to get in your voice heard in meetings and, you know, yeah, any suggestions there, I suppose, for me to talk. Yeah, I mean, that is a fairly extreme example, but I do, I do love to talk about that one, but it's not uncommon to be in a meeting room and sort of give an opinion or a potential solution to a problem and almost have that moment where you think, am I on mute, but I'm actually physically in the meeting room because no one's responded, no one's reacted to what I've said, and then someone else will say exactly the same thing, sort of 30 seconds later, and everyone jumps on that. That's a really good idea. Yeah, we should look at that, and that's been really, really frustrating, and I know I'm not alone in experiencing that, you know, a lot of diverse people that I've spoken to have said exactly the same thing, and actually one of the things I've found which has been really helpful in working with that is ideally, and it isn't always ideal, but having someone within that meeting that you've got a strong relationship with who's prepared to almost stand up and say, actually Michelle said that first, can we just go back and dive into what she said and how we think it's going to work? And as I've progressed, I find I do that more and more with other people, particularly so if you've got a junior presenting in a meeting, knowing that you're there to support them in the meeting, be that friendly face at smiles and nods as they're talking so they're not just staring at a room full of scary execs, but I've had some fantastic leaders over the years who've been very good at sort of stepping in and sort of going actually, you know, in my case, Michelle's the expert here, let's talk to her about it, let's go back to the idea that, you know, she did say, and sort of take her guidance and advice, it doesn't mean I'm always right, and you know, sometimes I do have ideas where I go, well, could we do something along these lines? And they might be reasons we can't, but just having someone who's prepared to sort of back you up in a meeting, I've always referred to them as your sort of your corporate cheerleaders. I think it's kind of a lie ship that you can, or, or, you know, the ability to rely on them to kind of fight your core. I think it's quite cool. I mean, and it's a role that sort of our senior male counterpart really can help with that, like you say, that allyship is so important. It's really awkward the first few times you have to do it, and it feels unnatural to say to your peers, of, wait, hang on, someone else said that, but it really helps, and it really helps sort of in bringing people up and developing them and maturing them, and making sure we hear those diverse perspectives. That's why we want to hire sort of diverse candidates, because if you hire everyone from the same background, you'd just get one opinion, or slide variations on the same opinion. I worked with a chap who used to have this lovely phrase that he would trot out quite regularly. Talent has equally distributed, opportunity is not. And I think it's about making those opportunities available to everyone, and as many diverse candidates as we can, because having diverse opinions really helps strengthen a product set. I think that's super important. I think much, probably much to their corporate embarrassment. The example I always go back to on that front is the Apple Watch and Apple Health and period tracking, which were notably absent from product launch. Presumably because there was quite a kind of male dominated team there, and people had kind of thought, no, well maybe that's something that someone might want to be able to track or record, because it might be useful for them. So pretty obvious in hindsight that that was going to be a sensible thing that you could do with it. Funny enough, that's one of the reasons why I'm an Android and a Fitbit person. That was enough for me to swing my product decisions completely, and I still am an entirely Android and Fitbit person. I don't actually like an Apple product. Well, that's, I suppose, power of having more inclusive product decisions and diverse opinions that we're talking about. I also wanted to pick up, I think it was a really interesting bit that you mentioned there in a couple of minutes ago about going back and hearing what someone had to say, and it not necessarily having to be right. And I think that's also something that's quite important because it gives people the opportunity to hear that feedback. And it doesn't mean that you're, I think also one of the things that people sometimes miss in security is that we spend so much time kind of in the security bubble and looking at the security problems that we sometimes forget about the broader business context. And sometimes it's not that the security answer is the wrong answer. And that doesn't mean that that individual was wrong in what they were saying. They were presenting the correct perspective from that kind of, from that team up, but that ultimately security becomes a business decision. And if you're weighing up whether to spend a million pounds on minimizing risk on a security program or spending a million pounds on potential revenue growth or moving into a new market, you know, those are some of the decisions that are being made at that kind of top table. And if you're lucky enough to be presenting there, if that decision doesn't go your way, that doesn't mean that your analysis or your your recommendation or your presentation was fundamentally wrong. It just means that a decision was made based on a broader set of moving parts. And I think sometimes that that aspect gets overlooked and can be can be kind of people sometimes over index on that. And it's seen as, oh, they didn't they didn't get it right. And it's like, well, they know that that the content was still absolutely sound. But there was a, you know, there was a competing kind of competing kind of hypothesis here that needed to be considered as well. Yeah. And I think people get really scared of about saying something and then someone going, well, yes, but no. And they see it as a personal failure. And it's it's not we're still, you know, the security experts. We're still the people who have that experience. But it is about looking at that wider context and the business. I think it's also hearing you say, you know, about the link you that back to where you were, your history is a penetration test. They're like a large proportion of cyber security people spend time trying to find problems and preempt them. So, you know, we should be better at that. We should be better at kind of taking our own medicine and being able to receive the kind of like, you know, there's a there's a there's a vulnerability in your argument here or all kind of, you know, that kind of thing. You think we'd be kind of more more adjusted to receiving that. Well, it's an interesting thing you say there because I've had people ask me, do you have to be a pessimist to work in security? And I don't think we are. I think, I think actually at the heart of it, we're all optimists because we're trying to find things that could go wrong before they go wrong so that we can fix them and we want that brighter, I was going to say that brighter future, but that sort of that happy place where everything secure runs well, doesn't cost the earth. That's the place we're looking for. And I think I don't think you can go and strive for that if you're a pessimist. I think you have to have that sort of half glass, glass, half full of you on life. No, I think I think that's a really positive outlook, an optimistic outlook, one that we, one that I, one that I obviously share here with us here and our focus on positive security, I think, yeah, I think you're right. There's there's only so much so far that fear and certainty in doubt will get you. And that kind of fudge thinking, but also kind of arguments and persuasion. At some point you need to kind of actually go right, well, what is the, yeah, that balance between realism and rather than pessimism, but realism about the situation and optimism about what the future can be. And that's kind of core to being a technologist, I think, is that optimism and kind of how can we now we make the world better? We've kind of touched there a little bit on communicating risks to the board and kind of how it doesn't always go your way. They often want to understand the impact of cybersecurity without getting lost in the technical details. And obviously have a broader perspective to consider as well, not just cybersecurity, but financial, operational, legal, the wider kind of business strategy. As a CSO, how do you go about framing these risks in a way that resonates with potentially challenging, I suppose, leadership, both in a constructive challenge, but also those challenges may not always be constructive. How do you go about presenting those critical security decisions to the board and structure the conversation so they fully grasp the implications and ultimately make informed choices? It's a slightly tricky one and I think it's like any conversation you have to adapt to your style ever so slightly depending on the board you're presenting to. Some boards are very deeply technical and in some ways they're the hardest to present to because you've got to stop yourself getting right into the detail and the weeds of, you know, well, we could do this and we could do that, where it's actually you need to sort of pull back out, but then on the other hand, you have completely non-technical boards who, you know, understand that security is important, but they need to be able to understand enough without becoming a techie so that they can understand the risk and I'm going to sort of trot out the well-used cliché of security as everyone's responsibility. It doesn't just sit on mine and my team shoulders. So I always take the approach of I need to sort of take them on the journey, they need to understand what we're facing and I think fear, smoke and mirrors, the whole sort of black box approach, it just doesn't work because you can only do that so many times before people go, yeah, but you've said that already, you've said that already. So you need to get people to buy into the fact that, you know, not every business is going to have everything 100% secure. I don't think that's even possible to be honest. It's about choosing the right level of security for your business and what the risk appetite is of the board and so I think before you even start talking to them, understanding the risk appetite, how they want to operate, where they want their security maturity journey to, I don't want to say stop because it never stops, but at what level are they comfortable with that level of maturity? And so before you even talked to anyone, getting those foundations right is absolutely key. Then once you talk to them, that sort of framing that problem is, and I try not sort of frame it actually as a problem, I try to frame it as opportunities, you know, making ourselves more secure, we can talk about sort of reputational damage, brand damage, the inability to onboard new clients, and those are all very real, but actually if you frame it as cybersecurity being enabler, an enabler to that process, you know, can we be one step ahead of our competitor? Can we have maybe a certification that they don't have? Can we offer a different level of SLA for example or non-functional requirements that will make our product more salable? And I find that by turning the discussion to actually how can security enable the business, make us more profitable rather than talking about well, we've got this massive risk curve and we need to reduce the risk here. That's all very helpful, but actually when you're talking to a board, they want to drive the business, they want the business to be profitable. And so if you sort of change the conversation to show them how security can actually be a really significant part of that journey, it really helps make a difference and opens up a different type of conversation with them. Yeah, no, I think I think you're absolutely right, boards want outcomes and they want to understand the implications and trade-offs of different decisions, not necessarily the kind of low-level technical details, they want to have confidence that not necessarily even you directly, but like your team and the work's been done to a good quality and that there's some sound rationale behind there, but yeah, that doesn't mean that you need to expose the technical details in order to be able to build that confidence. I think the point you made about risk appetite and kind of what the end state do they actually want is a really really important and maybe often overlooked kind of aspect of it because you're basically getting agreement there for what good looks like and what the, let you say, there will always be more work to do, it's an ongoing process, but that level gives you the rules of engagement and the kind of the goal posts to be aiming for, right, so that you can get to the end of a day or week and go, you know what, that's it, we've done them, something bad may happen tomorrow, but today we've we've got to the point that we're that we're meant to be at and that makes sense for our for our organisation, we don't need to be Fort Knox or we don't need to be, you know, the Tower of London or something like that. Yeah, I got it very wrong and I first ever a board presentation that I did, I went in and presented and sort of said, you know, we need to be secure, we need to do these things, it was a sort of a relative start-up, small-ish business, I was the only security person there, I wasn't asking for a huge investment, but I was definitely asking for an investment in that and without understanding what the business would deem as acceptable and what the level of risk that they were willing to accept was, I completely mispitched that meeting, I was talking about sort of potential risks that would cost us, you know, hundreds of thousands of pounds and it hurts slightly to go back and sort of relive that moment, but I remember the company secretary turning around to me and saying, we've got a five million cyber liability insurance, why should we care about something that's only going to cost us a few hundred thousand pounds? And it took the wind out of my sales and I was like, yeah, good point. So we live and learn, you know, we make mistakes, we all do, we're only human and I think as long as we continue to learn and sort of shape the way we put our sort of, I don't say our arguments, but our sort of, how we present our ideas, we've got to constantly adapt, business changes, the tech industry changes, you know, AI coming in over the last few years has been, you know, introduced a whole new raft of different risks and things we need to consider and I think we need to be adaptable to that change and we've got to keep having that conversation with our board and saying, are we still okay with this level? You know, maybe we've signed a bigger client, maybe we've moved into another territory, maybe those risks are no longer acceptable, but that's where I think where the conversations need to start. I think you're, I think that's a really, a really intelligent place to be. And thank you for also sharing that because I think, you know, learning from one's mistakes, I mean, that is also quarter the vast majority of security frameworks and the idea of continual improvement. So being able to look back on that reflect, work out how, how and what you might do differently and how you might approach it, it's kind of is kind of core to what we're talking about and that. Yeah, I think there are lots of early stage businesses and I say this is having been an early, you know, in the first year, first idea as well. Security poverty is a thing. You can't afford to buy all the things you might want to have, you know, and surprisingly, they will cost 20 or 30 grand a year and, you know, we, you know, wouldn't, we'd have gone bust, frankly, trying to do the things that, you know, a larger organisation might just take for granted. So I think being able to understand some of that, particularly if you are, you know, early stage organisation, you know, maybe you've got, you know, maybe that security programme is the trade off, but these is the difference between having three months more runway for the business or something like that, I think, especially in kind of early stage startups. Those kind of security discussions and trade-offs can be, can be really difficult to make as well. And yeah, getting, getting some, some sensible cover or some ability to, to respond, I mean, yeah, you're going back to viewing it in a wider context. If, if, you know, nine out of 10 startups fail and that isn't because they've got hacked or breached, that's just because it was the wrong idea at the wrong time or they weren't able to get to market quickly enough or they weren't able to access the customers or something. Turning around and saying, hey, I think there's a, you know, there's a 5% chance we might have around somewhere, really kind of, you know, maybe that does pay it into, into, into insignificance, like so that doesn't make it any easier to hear as a security person, but I think that broader perspective may, may change there. So, is there anything in particular you, sorry, going, yeah. I'll say, I do, I do think it drives us to be slightly more creative. You know, I, my sweet spot is startups and scale-ups. I love that sort of, I don't want to say chaos, but it is that buzz, that drive, that energy you get with them. I really enjoy those environments. And like you say, security poverty is a real thing, but that doesn't mean you can't do everything you want to do. It just means that sometimes you can't go out and buy the tool that promises to be the silver bullet in that area. But actually, you know, there's a strong community of security engineers, other CSOs out there. And if you speak to people, I think you'll find there's a lot you can do with a slightly more sort of blue tech and cello tape approach because it covers the gap temporarily. Now, I know there's nothing more than a temporary solution at work. But I think, you know, it encourages us to be creative, to go and find solutions that might be a little bit out there. They might be a little bit more clunky. The reporting might not be great. They might not give you the shiny dashboard for the exec. But actually, do they fill that gap? Do they meet the requirements at the level of the business as willing to accept? Then it can't be a bad thing. And that moment in time, right? You know, those early stages are growing massively and often and rapidly. And, you know, the thing that's built today is absolutely not going to be the thing that's there in 18 months or 24 months time, right? The business will have changed beyond all recognition at that point. So, yeah, nothing's permanent. I think that's another thing to kind of remember, big difference there compared to larger enterprises maybe where, you know, it is a lot more kind of, you know, if you're trying to do to change a part of a technology stack in an organization with, you know, two, three, four, five, 10,000 employees plus, you know, there's obviously a lot more inertia behind the status quo at that point. I think, yeah, there's a lot of one of the superpowers that you've maybe got is that ability to be agile and adapt and improve. So coming back round and making those changes in the future, what's good enough today and then what will be good enough in a couple of months or a couple of years time at different things, right? Yeah, and other than taking the approach of, well, I can't invest, I'm not going to do anything. Sometimes by taking that slightly sort of circular approach or alternative method of doing things actually helps build your business case because then you're able to demonstrate the value you get from implementing processes or technologies and changing the way the business works, which often actually helps when you're trying to then later create a sort of an investment, or gain an investment from the board. Yeah, I suppose it adds weight, right? Because they know that you're coming and asking because you definitely need this and that you would have exhausted other avenues that you might have, you've shown that you can be resourceful and that you're not just, you're not just going to come for every little pound and penny, right? We've touched on a couple of different teams there. So we've got the technical security teams, senior execs, maybe investors. Each of those groups has different priorities, languages and perspectives. And as a leader, I'm guessing you've become quite adept at translating those complex issues so everyone can act effectively. How do you adapt your personal communication style for each audience and what have you found makes that particularly effective? I've been accused of being in a chameleon in the past. My sum of my team have watched me go from board presentations straight into sort of risk committees and then straight into engineering meetings. And I think, well, I don't necessarily like the word chameleon. I think it's a fairly accurate description. You need to be able to turn quite quickly and understand what the area of the business you're talking to actually cares about. Our engineers will care about their development cycles, what their throughput is. They don't want security to be something that slows them down, blocks their progress, prevents them from releasing code when they were promised. And so being able to switch to that mindset is really key. It's the same with the platform teams. You know, they want to, they don't want security tools, they're going to introduce latency. And then the risk teams come in at a slightly completely different, non-technical approach. So that switch is really important. I think I've been very fortunate in that I came from a technical background and through the auditing I did, I got to work with a lot of different areas of business. You deal with the HR team, which lots of people go, what have they got to do with security? But they all play an important part. And so something I do with my teams is I try and get them to to peer up or work really closely with other areas of the business. So they can get that understanding. They can understand not just what's important but why it's important to them. And that helps build that relationship. I think as long as you always approach conversation with other areas of this is making your life easier because you've told me this is important. You've told me this is what you want to see. I've listened, I've taken it on board, rather than security being something that's done to them. And I think that's where a lot of sort of security initiatives fail. It feels like something that's been thrown over the fence, something they have to do. No one's listened to their actual concerns and the real world they live in. And it's that I think sort of pulling yourself out of that security mindset slightly, but listening to actually what do they need? What do they want? And actually one of the first things I do whenever I join an organisation is when you're going around and meeting everyone is sort of, is phrase question, what do you want from security? How can security help you? What are your pain points that I can help with? Because you immediately start forming that bond of being on their side, understanding them. And it's great fun wearing many hats and having to swap them out. And sometimes it gets a little bit confusing and you think, you might talking to about what now. Coming back to that, understanding how things work and what makes people tick. I don't want to suggest you're taking the screwdriver and taking them apart when I'm in that first meeting, but an element of getting under the skin and understanding their role and their objectives and drives and things. I can understand why that's. Like say, not necessarily a binary zero, one type thing, it is more analog and kind of emotional intelligence than that, but yeah, I can understand why that would be a really important part about getting people on side and being able to deliver for them and therefore keeping them on side. Yeah, I'm very open about the fact that even though I claim to be an ex techie and I probably could still write code, it would probably take me three times as long and be full of bugs that they would then have to fix. So I do think sort of having that ability to talk techie, particularly when you go right down into the team level, it's definitely beneficial, but you don't have to know how to write code. You don't have to know how to configure, a CM solution. You have to understand enough to be able to talk to the people who are doing it. And actually just by spending time working alongside people and sometimes it's not even shadowing them, it's literally sitting next to them in the office and listening to the things they talk about on the calls, the pain points, the frustrations they feel really start giving you a real insight into how their part of the business operates. Gotcha. Yeah, I think that's a really, really sage advice for people when they may be moved to a new organisation or maybe they get a new security role for the first time or a more senior role for the first time and they've got that kind of exposure. Looking back on everything else that you've learned, is there any other kind of important lessons you'd like to share with someone aspiring to be a CSO today? Maybe they're really early in their career and just starting out or they're trying to think about what the future might hold? I would say definitely find a mentor. It doesn't even have to be someone who is within cyber. It's a very small industry, so I don't want to overload those of us who are here with 5 or 6 requests, but find a mentor. Find someone who is prepared to help you tweak those reports that you're doing. Provide a little bit of guidance on answering the so what when you're doing a presentation. It's great having 20 slides, but what are you actually expecting from your audience? What do you want them to take away? What are their actions that you need from them? The first time an old boss said to me, "Having reviewed my slides and went so what?" I didn't know what to say. I was like, "What do you mean so what? I've worked really hard on these, but having someone who can guide you through that is so important." That's really, really key. That's a really interesting point that actually if you're going to be communicating to non-cyber people, you can get really valuable mentorship. That mentorship doesn't need to be career advice in terms of cyber things. It can be a non-cyber people who are helping you with understanding the broader picture or how something might be received, a friendly ear to listen to. That just keeping you on the right track because they're the audience you're typically going to end up presenting to. Having them have that oversight and help, I always refer to it as the buffers that you have when you're doing 10-pin bowling. It just helps keep you on track. I think it really makes a difference. Networking as well. Go to the events, go and speak to people. We find a lot of people leave cyber because they come in and go, "Oh no, you know, and I'm going to use security engineering as an example. I'm not saying any part of cyber is bad because I love all of it, but it might not be for them," and then they go out and go do something else. There's so many different aspects, like you say, security engineering, GRC, SOC, instant response, pen testing, audit, audit compliance, loads of different aspects there. The list is literally endless. I tried to do a presentation for a local school recently about all the options in cyber and I had to stop at 48 because actually I ran out of space, but you've got business transformation management, you've got policy creation, you've got user awareness training, so if you're someone who is particularly outgoing and extroverted and might have done drama, actually there's a space for you in cyber. And I think getting people to see that is it's not a, I know people talk about it's not a one-size-fits-all, but I think cyber is because no matter what you are and what your preferences is, there is something in cyber that works and fits with you. It's very optimistic. And I don't mean that in a sarcastic way. I mean genuinely, like you say, there are so many opportunities there. I think that's a brilliant place to start bringing this to a close. And as we wrap up, I'd love to ask you one kind of final question. Beyond everything we've talked about today, are there any particular key messages or initiatives or things on your personal agenda that you want to share or help others communicate cyber more effectively? So this is my little soapbox moment. So I'm going to apologise in advance, but I don't have policy messages. Here you go, stand on. I don't think we can fix the lack of diversity in cyber by just constantly poaching people from other organisations. We just move the problem around. We don't actually fix it. And so the one thing I would love to see is those of us who are in cyber getting much more involved at the entry point. So go and speak to schools, go and get involved in them. Whether it be careers days, CV writing, just talking to local groups, be it scouting, guiding schools, colleges, let them see that cyber really is an opportunity for you to get into a business, gain a huge variety of skills, and try different things until you find the bit that fits with you. You know, there are so many opportunities and I think we don't fix the issue until we actually increase the pipeline of people coming into security. And I think we really need to focus on encouraging more and more people to join cyber. I've had fantastic opportunities where I've worked for fashion houses, I've worked for really cool artistic companies, all within a cyber role just because the cyber doesn't make it geeky and sort of isolated and you don't have to be sort of a super genius coder to get into it. It's literally an opportunity that anyone can get into and I think we really need to go and shout about that and speak to people and make them aware and just open those doors a bit so that the new talent entering the market can actually see what a fantastic opportunity working in cyber is. Brilliant, I think that's a lovely place to leave it and yeah, agree. The more diversity that we can get in thought and experience, I think we can get into cyber security, absolutely the better. Michelle, it's been an absolute pleasure. Thank you ever so much for joining us today. No, thank you so much for having me. I've really, really enjoyed the conversation. Lovely and thank you all for listening. I hope you found this really interesting and insightful. You can find Michelle on LinkedIn. This is probably a good place to go and look up. Yep. And yeah, follow the work that she's doing and yeah, if you're in cyber security already, strongly encourage you to, as she says, get involved with some local maybe schools, local community groups and help kind of be up the cyber recruitment pipeline. I think that's a really important message to end on. Thank you ever so much for listening and catch you next time on the next edition of communicating cyber.

Podcast Summary

Key Points:

  1. The speaker transitioned from veterinary science to IT support, then to penetration testing and security consulting, ultimately becoming a CISO, driven by a passion for helping people and understanding systems.
  2. Effective security must balance protection with usability, embedding seamlessly into business operations without hindering productivity, and decisions should consider broader business contexts, not just technical aspects.
  3. As a woman in tech, the speaker has faced challenges like being overlooked in meetings, but emphasizes the importance of allyship and diverse perspectives to strengthen teams and product development.

Summary:

The speaker shares a non-traditional career path into cybersecurity, starting with a veterinary science degree and moving through IT support, penetration testing, and consulting before becoming a CISO. Key motivations include a desire to help people and understand how systems work, whether technological or biological. The discussion highlights that successful security integrates into business processes without being obstructive, emphasizing usability and alignment with organizational goals rather than operating in isolation.

Additionally, the speaker addresses gender dynamics in tech, noting instances where her contributions were ignored until repeated by male colleagues, and advocates for allyship and inclusive practices to harness diverse viewpoints. This diversity is crucial for innovation, as illustrated by examples like product oversights in male-dominated teams. Ultimately, cybersecurity is framed as a business enabler that requires clear communication and consideration of wider contexts beyond technical vulnerabilities.

FAQs

Take them on the journey by explaining the broader business context and implications of security decisions, rather than using fear or a 'black box' approach. This helps align security with business goals.

Simply poaching talent from other organizations doesn't fix the lack of diversity; it just moves the problem around. True solutions require creating more opportunities for diverse candidates.

An ally can step in to acknowledge when someone's idea was overlooked, saying something like, 'Michelle mentioned that earlier—let's revisit her point.' This helps ensure diverse perspectives are heard.

Good security should protect without hindering usability; if it gets in the way, people may work around controls. Remember availability in the CIA triad—systems must be accessible and usable.

It doesn't mean the security advice was wrong; business decisions involve trade-offs with broader context like revenue or market growth. Focus on providing sound analysis while understanding the bigger picture.

Women often share ideas in meetings only to have them ignored, then repeated by someone else later who receives credit. Having allies to reinforce credit can help address this.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.