Go back

The Defender's Journal Episode 27 - Aimee Cardwell

45m 16s

The Defender's Journal Episode 27 - Aimee Cardwell

Amy Cardwell, a seasoned tech and cybersecurity professional, shares insights into her career journey and personal growth. Reflecting on her past overconfidence and lack of teamwork skills, she acknowledges the pivotal role of feedback and executive coaching in her development. Transitioning from an individual contributor to a team leader, she stresses the importance of inclusive leadership, teamwork, and embracing diverse perspectives for effective problem-solving. Amy's experience underscores the value of observing and learning from colleagues to enhance leadership skills and navigate various organizational settings, including boardrooms. By emphasizing self-awareness, continuous learning, and adapting to different work environments, Amy exemplifies the evolution from a confident yet isolated professional to a collaborative and inclusive leader in the tech and cybersecurity domain.

Transcription

8153 Words, 42937 Characters

Hello and welcome to episode 27 of The Defenders Journal. Today's guest is built one of the most uniquely well-rounded careers in tech and cyber security. From leading mobile innovation, Expedia and eBay to engineering strategy at American Express and driving digital transformation in the healthcare space, she's operated at scale across some of the most complex and highly regulated industries. Now she serves as a fractional CISO and advisor to multiple private equity firms helping rebuild cyber programs, restore trust after incidents, and scale production across high stakes environments. Alongside that, she sits on the board at WX or WEX, bringing cyber and tech oversight to the highest level. Please join us in welcoming Amy Cardwell. Thank you Cameron, it's such a pleasure to be here and wow, you make my accomplishments sound better than I think they felt when I was doing them. Every guest says the same thing, but it sounds like you don't give yourself enough credit. Or maybe we just need somebody to walk around beside us every day and tell us, no, you've got this, you already did that there or you've got this, you were able to do that, like that would be nice. I'm open to employment opportunities if you need one. I'm more than happy to be your height man. Look, before we get into strategy and boardrooms and everything about your experience, I think this question is as long as you want it to be, who were you when you started in tech and what do you remember about that first season of your career? Yeah, I was raised by my dad who was a self-taught engineer and not a software engineer, but like an engineer who built prototypes of things that had never been built before. So he was both a really solid individual problem solver and also a systems thinker because in order to build a prototype, he needed to understand what he was trying to achieve and sort of all of the things around that and then build each of the components to make that happen, whether it was hydraulics or machining or whatever. And when I came into tech, I came from, you know, 10 years of working at his side as his helper, understanding problems and trying to solve them. And I'm not going to lie. My dad was quite egotistical and so was I as a result. And so I frequently came into problem solving and being a little bit vulnerable here right off the bat as somebody who already knew the answer or somebody who I was so confident that I already possessed all of the tools I needed to solve the problem that I wasn't very good at working in a team. I wasn't very good at listening to other perspectives. And frankly, I discounted the contributions of other team members because I was so confident one would say overconfident looking back in my own abilities. And so I was that really annoying and I know we've all met one and some of us are one and I still struggle with this. The smartest person in the room, I'm using air quotes when I say that because you're not actually the smartest person in the room but you act like the smartest person in the room. And in fact, I can remember having my internal dialogue be literally, this is the quote from my internal dialogue. If everybody would just stop talking for a few minutes and listen to me, we could get out of this meeting faster and we could just get out with finishing the work. I guess if I had to sum it up in one word, insufferable would be that word. Like, oh god, we don't want to work with her. She's not curious. She's not trying to understand all these different perspectives. She's like already fixed the problem in her head and just wants to execute. So that's who I was when I first got started in tech. And if I'm lucky, all of the extreme effort and five years of excellent executive coaching have gotten me up out of that mindset. It was extremely interesting because I think it's also a trait that you see in a lot of early or people that end up being very successful in this field and in most fields. Almost a little bit pedantic and you said it's egotistical but yet to be so self-confident to be able to push towards some of the barriers that you'll face. Was that a self-awareness thing or was that a critique you received from leaders and other people around you that early on? I started getting the same pieces of feedback over and over from different leaders but I couldn't understand what action or what thought pattern I was doing that was causing me to get the consistent feedback. And so what I the theory that I created in my own head was oh I always get this feedback in the first six months and then people get used to the fact that I actually am as smart as I think I am and so then they just do more of what I say. So I was creating a story of this is not my problem this is the people that I'm just meeting or the team that I'm just joining's problem and that was probably the literally the first 10 years and the feedback that I would get most regularly is you don't have to have the answer to every question thinking about where I came from right there wasn't a world in which we couldn't solve the problem and so for me I personally took the responsibility for being the owner and solver of the problem and when you get into a company that's really large in American Express or United States Health Group it's difficult as a young person to understand all of and I didn't go to university either so I often call myself the unlikeliest executive all of the stuff that goes into why we're trying to solve this business problem I'm seeing the technology's shard of this problem and I'm like oh I can solve that but I don't if I'm not understanding the context because I'm not being curious about it or I don't understand it or I don't know what I don't know then I'm only solving the shard and I maybe actually solving it in a really short-sighted way instead of solving it as in a longer way so yeah I just kept getting the same feedback over and over and it wasn't until amx invested in me by getting me an executive coach I say this from time to time executive coaching if you're if you're doing it right and you have a really great coach it's like having all of your skin flayed off and you have to grow it all back again it is the most uncomfortable and miserable experience and that's not because your coach is saying do this don't do that do this don't do that it's because a really good coach holds a mirror up to you yes that you can see yourself the way other people see you and man when you actually see the true view of you the way you're being perceived by others it's really tough it is a really challenging feeling god bless my coach because I wasn't an easy person to get feedback to she was like I actually am I'm she said I'm nervous giving you this feedback I'm nervous telling you how I feel but this is how I feel and it was like each so that is the point where my career changed it's the point when I stopped being an individual contributor even as a team leader and started being a team leader and started understanding curiosity and started understanding how groups solve problems and why all of the research says that more diverse teams of people are better at solving problems in business I started to understand the unpack that whole bit of research and understand why that works for you what was the hardest piece of advice or reflection when once that coach had held the mirror up what was the hardest thing to hear the the hardest lesson to relearn is that even if I think I know the answer so there's a great piece of McKinsey literature which I'll actually send you the link to and you can share if you want to and it's the the literature which I found within the last couple of years I find really poignant for me one of the things that it says is the tool that most of us go to as our number one tool for influencing and convincing people is data we're like how the data is right here here's the data that is also one of the least effective tools for changing someone's mind so the tool that we use most often is one of the least effective really and you and I are you know we're here we're we think of ourselves as scientists or as engineers or as logical thinkers we're like that's ridiculous of course if somebody if you present the data someone's going to be one over in fact not very effective what is very effective is inclusive leadership where you're saying what do you think we should do how do you think we should solve this problem if we went this way what do you see as the benefits what do you see as the potential negatives that sort of influencing by teaming people together giving them some skin in the game all of that inspirational leadership is actually one of the most effective tools and I had zero skills at that so I'm like wait I'm not supposed to say the answer when I know it and my coach was like you actually don't know if you know the answer and I'm like but I do and she's like no you don't and she's like you have to stop knowing that you know the answer in order to be curious enough to get to the right answer and that dichotomy was a habit of my thinking that was the hardest thing for me to hear the hardest for me to execute and put into action and also the most impactful over the course of the last 15 years since I learned it and do you mental now do you correct anyone in my fractional roles I'm often brought in as a sort of short term CIO or CISO I have to immediately adopt a team and make them feel comfortable and confident if I can try to sus out who's where in the scale of both talent and effectiveness and what they're you know how the morale of the team is and so the very first thing I'm doing is saying what do you folks think we need to do where do you see our gaps what do you think is is going well with the company and where the places where we need to improve and by doing that I'm essentially gathering up this basket of items that the team feels like we need to do I'm also of course going to do some assessment over here and I may request to drop some of those items in the basket also but I'm trying to build our roadmap together so that we each feel motivated to work on it together as opposed to well my boss just gave me a bunch of stuff to do and I need to go execute against that I kind of call that the delicatessen worker right like you go to the deli and you're like I need a half a pound of pepperoni and they're like here's half a pound of pepperoni I need half a pound of cheddar of here really all they're doing is taking the ticket and doing the thing taking the ticket and doing the thing they don't know that you're building a great pizza or an amazing sub or you know some amazing culinary creation they're doing what you say and that is the least effective kind of team member what you on is the team member who's thinking how is this thing that I'm doing related to the rest of the work that we're doing and how is that related to what the company's trying to achieve how do you teach that day today instead of saying hey here's what I don't agree with I might look for a way to make you see why I don't agree with it so you might say it's not important for us to upgrade this Rails library this year because we're going to be off of it next year and I might say understood thank you for that what might happen if we need to finish our sock two type two audit and Rails 7 is clearly no longer supported how can we deal with that conflict and they might say well what if we bought support like great so I'm trying to I'm trying to show them the the unpacking of the problem that I'm doing instead of just unpacking and then telling them what to do you have to do it together I suppose that's the easy way of getting buy in as well isn't that and understanding how every part links because I mean the roles that we we work in terms of recruiting for I'd say anyone from three plus years and this goes into the operational strategist thing that we'll talk about in a bit but once you're past that point you we need to understand how to interact with and engage every stakeholder from different levels of the business and in different departments and if you don't understand the buy-in it's really hard to do that yeah hundred percent cool well actually before we touch on the operators and strategist question which I've got lined up you did mention not going through the university route the way you hold yourself with the confidence that you had from a from a younger age and obviously that's grown and developed in a different way you probably held you or hold yourself very well in a boardroom considering the role you've got now but did you ever feel like an outsider in those rooms especially as you were progressing and if so how did you learn to own that space anyway in a different way as your confidence or your perception of your own confidence changed yeah I have felt like an outsider in different parts of my career from my entire career from beginning to end and still do so back in the day when I felt like you know when I was in my 20s and 30s when I felt like an outsider I thought I had to make up for the fact that I didn't have a unit degree and would just try to be smarter exacerbating the problem we talked about earlier today when I feel like an outsider I recognize that that is my growth edge that is the place where I'm growing and if I don't feel uncomfortable then I'm not actually growing so if all I'm doing is pulling out all the skills that I already know how to use well okay I can be a totally reasonable executive at that point but I get really bored because I'm not growing personally so yes in the boardroom even now I'm a brand new board member I've been on a board for not even two full years and board meetings are slow and they happen over time and so that means I've probably had 12 or 15 board meetings with wax in that period of time I can't feel confident as a board member without amount of expertise I am not confident and part of what I want to do is listen to the my colleagues on the board and ask them important questions about was that the right amount of interaction was I too tough was I not tough enough did I speak too much did I not speak enough literally the nuts and bolts of what should my interaction be like and please give me that feedback but also and this is critical I observe how they interact so you know one of the the chairman of our board has been a board member for more than 20 years what does he do you know what he speaks the least of anyone on the board by design by personality I don't know so I look at each board member I think about where they are and what they're trying to achieve and I look at how they do that and I sometimes mimic the things that I admire about them and sometimes try to do more or less of what I'm doing based on what I see other people doing that's a really good skill in any company so I don't care if you're an individual contributor or a VP or an EVP watching what your colleagues do seeing who's effective at moving the opinion in the room seeing who is the leader that people love and admire and who is the people that the leader that people shun and figuring out which of their behaviors make them in one camp or the other and then mimicking or abandoning behaviors that you have that are similar to one of the other that is literally how you learn I wouldn't tell you Cameron I'd like you to learn to ride a bike here's a manual and then as soon as you read this manual and you tell me you're done I'm going to give you a bike and expect that you can ride it instead riding a bike is you get on the bike you do something wrong you correct you get on the bike you do something wrong you correct you correct you correct I still correct when I ride my bike because the other day I tried to put my paddle board on my bike which is very sketchy that process of learning to do a physical activity is exactly the same process as learning to do a non physical activity and the more you can observe the experts and observe the people who are not being successful and choose which of their behaviors you want to try on that's not really I use the word mimicking but that's actually how you learn a new skill I noticed that somebody is a great listener I want to be a good listener I'm going to try that skill which means I keep a mouth shut more and that for me is the number one way of learning how to be a better leader and learning how to be a better colleague we hear a mixture I mean we work with different variety of financial services clients across different verticals and spaces each one has a very different approach to the way they execute a boardroom or execute a senior leadership meeting you able to show an experience where a boardroom works extremely well or didn't work extremely well and for what reason yeah so for the benefit of your audience not only do I serve on a board but in my capacity as a SISO I have spent a lot of time in boardrooms presenting to boards and especially cybersecurity information can be quite technical and can be presented in a way that is either fear inspiring or not and I think I have seen some SISOs present cybersecurity information as a OSHIT because it feels more impactful that way you know when you're talking about log for J and you know how how easy it would have been for people to get into your systems and how any high schooler could write an email with a strip of code in the subject line that what like that's interesting and it captivates your audience but it's also not really board level it's not actionable for people it's a great story but then you want them to leave the boardroom and do what with that and it's not in keeping with what the board is designed to do and it took me a lot to figure this out and this so this is new for me within the last three to five years the board represents the shareholder so in a public company the board represents the shareholder so it says though you owning a share in google stock have the opportunity to sit with the google executives and say well as a shareholder I think you should be spending more money in AI and less money in search advertising or whatever I'm obviously making all that up so when I'm sitting in the boardroom I'm I've got all these tens of thousands of shareholders behind me right saying okay I hear you but is that the right long-term strategy for this company and the right short-term strategy for this company and what risks are standing in front of you and what are you doing about them and so that quantification of risk is for me the job of the SISO and if you're again imagining that the board is the shareholder and you're probably if you work for the company you're probably a shareholder anyway so now you can go as a shareholder what do I want to know about how the company is understanding evaluating and dealing with the risk profile of the company if you're a SISO that says I don't think we should take any risk at all you're probably not doing a great job because we all know that companies need to take risks and it's part of how companies operate the question is is this a tolerable risk or an intolerable risk and that's for me where boards can sometimes go astray and where SISO is presenting to boards can sometimes go astray because the board members want to hear the stories and I want to leave them with the stories because I want them to take what I've given them and repeat it elsewhere it's useful that's a great thing so sometimes I'll wrap something in a story and drop it into the board meeting and then later at the dinner someone will come up to me and say oh I never thought about that that way and you know I actually use that again at a different board meet like this story keeps going but what I really want them to do is say yes we are undertaking some risk and here's how we decide what risks we're going to undertake these are the ones that I'm uncomfortable with and which that we would invest more in these are the ones that I'm very comfortable with and in the worst case scenario here's why I think these risks are totally reasonable for the company and I'm trying to focus on the ones that I want the board to take action on or move on but most of the time I'm trying to say everybody just calm down we're probably going to get bit at some point so we're looking at resilience and we're looking at risk reduction continuously I think that's for me that's the most interesting thing about boards is the way you tell your story will determine whether the board is comfortable or not comfortable and will drive their action in a direction that you will hope that they'll go in. Is there a unique way that you or the companies you've worked with have measured risk? That is the hardest thing to do as a SISO and smaller companies I can't like well let me bust out the fair methodology and because that works better for larger companies for a small company I basically say let's look at a couple of our worst case scenarios and then figure out whether you know let's say a company gets gets bitten by a threat actor and they take all of their all of the sensitive data in the company. Do we have backup of it? Is it an is it impenetrable? Is it a immutable backup? Can we stand our systems back up and then how much money are we going to have to invest in regaining client confidence? And generally that number for a smaller company is going to be like 5 to 10 million. Sometimes 20 million. Is that an unswallowable number for that company? Most of the time no. It's going to suck but as we can see from all I mean just look back over the last two or three years and I hate to be the SISO who says this but most of the companies that have had an incident are all doing fine. It sucks for a long time and then everybody's fine. So for me the focus is often on the resilience and sort of pointing out the places where I think we're most at risk and then what are we going to do when that happens? Talking about building a good CISO profile or building a good experienced funnel for yourself as a leading cyber professional. I know in a previous conversation you took that actually you've seen relative success of those individuals that have come from a software background. I was wondering why and what others aren't seeing that these individuals might be. Yeah so it's interesting I actually believe that the reason I think that I thought about the question after we had our last chat is in part because I've worked in digital companies. So if I worked for you know a beverage manufacturing company or a clothing manufacturing company that didn't have as large of a digital footprint I might feel differently but as it is you know a healthcare company is as much a digital company as a bank is almost because the healthcare company it's not just the doctors providing the service that's just the last mile. All the rest of that is electronic health records and patient experience and so there's a huge digital component. I think at United Health Group when I was there the engineering team was something like 35,000 people. So that's a really big digital footprint and I recognize that the company was 470,000 people. When I see a CISO who comes from a non-digital space it's very difficult for them to understand how important the software development life cycle is and making secure coding the path at least resistance instead of relying on engineers to write secure code. So I believe that I have a bias but I would also say that you know when I look across the world at the world's biggest companies most of them have a really large digital component. So I would prefer someone who has if I'm getting a candidate for almost any role in cyber my two preferences are one I want them to be technical because most of the problems that I'm seeing in cyber security are technical problems and then two I would love them to come from a highly regulated background so coming out of financial services or healthcare because you can't just solve the technology problem these days without also solving the regulatory problem. Especially and you know one of the roles that I'm doing right now is CISO and residents for transcend. Transcend is a consent platform which is great everybody understands we need a consent platform for you know all of the different regulations that are out there now but in order to do a good job at consent you also have to do a good job at data discovery because every company I've worked in has sensitive information in places they didn't know that it existed and they didn't find out that it existed there until they got hit by a threat actor. One of my favorite examples is a company that had all of their patient data in their invoices folder. Why did they have all of their patient data in their invoices folder because they invoice third parties and they say here are all of the patients that we treated and all of the conditions that those patients had and therefore here are the services that we provided for them. Well I wasn't expecting 100% of our sensitive data as an enterprise to be sitting in the finance department less to learn. So one of the things that transcend does is also build really robust data discovery tools by having 200 integrations with every place that data could sit is you know they integrate with QuickBooks they integrate with Salesforce they integrate with Oracle they integrate all the places where you might have data and so that way you can bring a company in and say okay now I know where all of your data is so that camera and if you say I'm going to exercise my right to be forgotten they don't have to have a single individual login to every system and try to delete you in 200 systems they say we're going to pluck this person out of all of these systems ready go however that problem gets even more complicated I love this because in healthcare and in financial services there are regulations that say you can't delete a transaction within seven years so Cameron if you came to see the doctor and then you asked to be deleted I need to delete all of the things that I can delete for you and not delete all of the things I'm not allowed to delete for you so you know this is the combination for me of technology and regulation regulatory background that if you don't understand both sides of that you're going to solve the technology problem wrong or you're going to solve the regulatory problem wrong so that's where that thought of having someone with a software background is very helpful or at least a deep technology background is really helpful 100% I think we're seeing a very similar pattern over the last 18 months and I know there's slight nuances in this but the GRC roles that are out in the cybersecurity world and the complexity especially in the blockchain or the digital asset space currently as well is a is a minefield but quite exciting growth area as well have you noticed though that most privacy organizations which is where consent management happens sit in chief legal is this sit under the chief legal officer and so then the SISO is sitting under the chief digital officer often and so now you have two teams who are trying to achieve I mean the Venn diagram of those two must be 60% but they're sitting on different ends of the organization and also think about once the last time the chief legal officer had to make a change to the software of the company for how the company delivers the product so there's this weird like the requests are coming from the wrong part of the company and that's why as a SISO one of the first things I try to do is embrace the privacy team because the SISO has power to get things done for privacy that privacy doesn't really know how to achieve sometimes and that way you can sort of work together get a little additional budget by doing similar things with the same software package as an example interesting so spearheading that sounds quite complex but very rewarding when everything is fluid um one of your progress moments I think you've said was leading security transformation during a billion dollar rollout in the middle of a pandemic under pressure most people will never experience or none um I've been done it what did that season teach you but just explain a little bit more about what that experience was like yeah um so I started at United Health Group in January of 2020 and of course COVID happened just a couple months after that and I was in a remote role which is difficult to be an executive and a large company in a remote role because the folks who are sitting at headquarters they you know meet each other in the hallways and they're face to face and so it's tough to break in um it was fascinating because we were all sent home so now I wasn't competing with people who were in the office together as a remote employee we were all remote employees that was cool uh and the the project was actually to pay all of the healthcare providers the supplemental income that the government was providing in order to keep the doctors solvent while nobody was going to the doctor so it was how do we pay all of the medical providers in the United States well United Health Group being the largest payer of medical providers in the United States offered to do that business the government did some analysis uh and paid UHG a trivial amount for the amount of work that we did but it was a I think it was a the right thing for everybody to do and a pleasure to be able to help out and they basically wanted to give it ended up being a couple of billion dollars uh to the providers our first billion was was distributed I can't recall the exact number but it was definitely less than a couple of months so within about four months we distributed more than a billion dollars to providers uh we already had payment connections with about 80% of the providers in the country but there was another 20% that we didn't have connections to so we needed to build this really interesting fraud capability to make sure that we weren't giving money to the wrong people or allowing the wrong people to come in and request money um but that was a fascinating project it was it felt so timely and important because it was happening during a pandemic so it almost felt like we were having a way to to help people in the middle of this crisis um it also leveled the playing field as I mentioned because everyone was remote so if I'm leading a call in some cases I'd be leading a call with executives that I would never have had the opportunity to intersect with in my regular role uh so it was a great career building opportunity because now people get to see you at your best uh and they never would have seen that before so they were like oh this is so I don't know what this is so does they're over there as opposed to oh this person is working here I see them every day I watch what they say in meetings I see how they interact I see how they pull people together and it was very beneficial for me to get that kind of visibility I guess you learned a lot during that period my team isn't jealous yet I've only been there a couple of months and then suddenly we're asked we're being asked to pivot a system that was meant to do one thing to do something completely different and build a website and records and I mean it needs to be auditable in case the government changes their mind or a payment goes to the rock print like it was really interesting and pulling a lot of teams together to do all of that work and then having daily calls with the federal government as we were just delivering uh it was just a really fascinating project a ton of fun as all of those spikes are right everybody likes to go you know get their fireman's hat and grab the hose and do a thing yeah for sure it's almost like a newbie mentality where you've just started and and you yeah you've got a firefight your way through multiple-buttoning buildings just to even try and survive trial by myself exactly it's probably the most common phrase in cyber I think um and that newbie mentality I suppose comes back to the point that we were going to touch on earlier which is um you've described or previously described your professional as operators rather than strategists and that's natural obviously they have not had the exposure to everything that that you have or you will do as you progress how do you break through as a newbie as a amateur as a beginner in industry into leadership and what clicks what what separates those individuals to everyone else yeah that's a brilliant question it's not a question I've ever been asked and I just love thinking about that what separates the people who are always going to be operators or I'll use the word tactical from the ones who can shift to strategic and I I feel that when I give feedback to some leaders and say I need you to shift from tactical the strategic I you know you're thinking about the delivery and I want you to think about the strategy and a lot of folks when I say that and I was one of these people when people said it to me kind of get a weird glaze look in their eye like what do you mean and so I'm going to say it in the way that in the simplest way I can which is the tactics are the what and the strategy is the why so what are we doing how are we going to get it done all of that like how do we get from point A to point B what is point B look like all that stuff is how do we deliver against a thing that's all tactics why are we doing it and here's the really important one what outcome do we expect from this how will we know if we succeeded or failed how is it going to impact the rest of the business there's all these questions about like okay let's you can almost get yourself out of tactics and into strategy by saying imagine that the project is done that the thing you're working on is finished what what's the so what what happened what's different now because as a result of that and it's very difficult because when we start we're given tasks and that's great that's what we're supposed to do we do those tasks shifting out of that idea of I know what I need to do I'm going to go do it into that really uncomfortable space which is not your comfort zone of okay why am I doing this why are we being asked to do it how much money is it worth how does it change the way our business does business how does it change the way our team operates all that weird stuff that doesn't have any it's really hard to get a feel like how do you measure that we shy away from those questions because they're not comfortable to answer the comfortable ones are the okay it's going to take me one month to do this and these are the tasks I have to do and then the that list that to do list that you can check off and feel a sense of accomplishment when you do it that thing's amazing the strategy work is so squishy and it's like nailing jello to the wall like well I don't know and that's the place where I'm always trying to push everybody yes it's uncomfortable however all this money and time and effort that you're spending doing this thing whatever it is implementing this GRC platform or putting I am in place or whatever the thing is what's the so what what's it for what's it going to do why would a shareholder I'm going back to the board now as a shareholder I want us to implement the system because the answer to that question is the strategy yeah yeah so move over there and try to understand because and it's important for you to understand that because that's how you'll talk about the product the thing the achievement to everybody else in the company because they don't really care how long it took you I mean of course they care how long and how much money whatever but that's not the interesting thing the interesting thing is we've implemented this GRC platform so now we can also you know we're already getting audited for sock to take two but now that we have this awesome platform we can also do CCPA and it's only this much extra effort and people will be like oh that's interesting why do we want CCP oh there we go so we're going won't step bigger in the strategy because and so you're basically trying to situate what you're working on in the grand scheme of what the company's trying to achieve now you're getting into strategy and that's the stories that you can tell especially in interviews when you're in an interview and somebody says well why did you build that platform if you can't answer that question the interview is not going to go that well and so you want your story to contain the strategy as well as the you know the ability to talk about the tactics I suppose naturally the strategies refine to every level of management you go down or up so that makes complete sense and I know that you love cooking we we talked about this before and then I one of my questions was going to be kind of like if you dissected cybersecurity leadership or just cybersecurity as a recipe what's the ingredient most people always forget I'm thinking now potentially strategic thinking might be one of those little things that I've forgotten but is there anything else that's missing a storytelling actually and we have touched on this just a little bit when you're talking to a non-technical audience the best way to to talk to a non-technical audience is by telling stories that resonate with them and make them feel like they understand I was literally reviewing slides this morning where someone was trying to talk about implementing a GRC platform and they said right now what's happening is the audit company gives us their toolbox that we get to borrow we use their toolbox to do our home improvements for a little while while we're doing the audit and then we give their toolbox back at the end and if we have a GRC tool we're essentially like doing home improvements we're going to the home depot first we're buying our own toolbox we're bringing it home and now we've got it and we can keep using it throughout all of the projects that we do not just this once and that for me felt like a really solid story because when you talk to a CEO and you say I want to spend money on a on a GRC platform they're like what is it what does it do what is it for and why do we need it and that's the sort of story that you want to be able to tell to say oh let me explain and you don't want to explain it as well it takes care of all of our compliance and regulatory needs by allowing us to intersect with the systems of like that's not going to resonate find a way to tell the story that resonates and frequently that's by using a difference a whole different very personal story as opposed to one that actually feels like it has to do with what you're talking about I used to use my favorite is tech debt people would be like I don't understand what tech debt is what does that mean and I said well you probably have a hot water heater in your house right and there yeah of course well hot water heaters tend to be rated anywhere from 10 years to 30 years what's the year rating on your hot water heater and how old is it and you get this cricket stare and I'm like if it's a 15 year rated hot water heater and you've had it for 20 years that's tech debt and they're like what do you mean and I'm like well the chances of your hot water heater exploding in your basement are significantly higher now than they were 10 years ago and with every year that you don't replace that hot water heater the tech debt goes up so you have a choice you can either invest in a new hot water heater now or you can wait until it pulls up and then invest in the hot water heater plus replacing all the stuff that flooded when you say it that way they go got it so there's software in our system that is not performing the way we need it to and it's likely to fall over and if we don't invest in it now it will fall over and cause a bigger business problem yes so storytelling for me one of the most underused capabilities by executives and people who want to be executives and it pushes people to be proactive which is which is good love that it's been an absolute pleasure chatting to you today I've got so many more questions as I say to most guests but genuinely I think I've got about 10 I've dropped a little paper next to me so we may have to do a part to at some point my last question if this was your last recorded interview ever what do you want people to hear from you and in a few words how would you define your career I have gone from one fascinating problem that I love solving to the next I have not planned out where I needed to be at the end I just keep wanting to solve new and interesting problems the transition from many people and myself included when I was younger I was like I don't want to be a people manager that's too hard it's really interesting and fun to solve problems with code I can't imagine not doing that I want to stay technical once I realized that people leadership was actually solving problems with people I got a lot more interesting and so I've basically shifted solving problems with technology to solving problems with people but I haven't left the solving problems part so my suspicion is a lot of your listeners are in technology or in cyber because they like they're curious and they're interested and they want to solve problems just recognize that you can also solve problems with people can I say one more thing because we talked a little bit earlier about the growth edge and about the places where I am uncomfortable even still in my career I just want to encourage all of your listeners to lean into that discomfort when they're feeling uncomfortable don't shy away from that area which is the natural response that we all have oh I don't want to do that that's uncomfortable instead go oh that's uncomfortable I'm gonna do more of that because that really is your growth edge and if you learn to run toward the discomfort run toward the difficult conversations and toward the places where you're like I have imposter syndrome you will do better you will grow faster you will learn more and you'll you'll you'll just get further in your career and to any listeners listen to this podcast which has been fantastic I'd encourage you to look back on our previous one with Alexander Forsyth who is much earlier on in the journey and experiencing exactly what Amy's talking about there awesome and that's it we'll close today's chapter here full of lessons worth sharing I hope and we really appreciate Amy being as honest and transparent as she was it's not always easy to senior leaders to reflect on how these handled situations including those they may approach differently in hindsight under state idiot impactful Amy is becoming an ever present voice on LinkedIn appearing on more and more podcasts and sharing real value if you found insight in today's conversation I'm sure she'd appreciate a follow too until next time

Podcast Summary

Key Points:

  1. Amy Cardwell has had a diverse career in tech and cybersecurity, working across various industries and now serving as a fractional CISO and advisor.
  2. She reflects on her initial overconfidence and lack of teamwork skills, which she attributes to her upbringing and early experiences.
  3. Amy discusses the importance of self-awareness, feedback, and executive coaching in her personal and professional growth, especially in transitioning from an individual contributor to a team leader.
  4. She emphasizes the shift towards inclusive leadership and the effectiveness of teamwork, curiosity, and diverse perspectives in problem-solving.
  5. Amy highlights the significance of observing and learning from colleagues to improve leadership skills and adapt to different organizational environments, such as boardrooms.

Summary:

Amy Cardwell, a seasoned tech and cybersecurity professional, shares insights into her career journey and personal growth. Reflecting on her past overconfidence and lack of teamwork skills, she acknowledges the pivotal role of feedback and executive coaching in her development. Transitioning from an individual contributor to a team leader, she stresses the importance of inclusive leadership, teamwork, and embracing diverse perspectives for effective problem-solving.

Amy's experience underscores the value of observing and learning from colleagues to enhance leadership skills and navigate various organizational settings, including boardrooms. By emphasizing self-awareness, continuous learning, and adapting to different work environments, Amy exemplifies the evolution from a confident yet isolated professional to a collaborative and inclusive leader in the tech and cybersecurity domain.

FAQs

The guest has a well-rounded career in tech and cyber security, with experience in leading mobile innovation, engineering strategy, and driving digital transformation across highly regulated industries.

The guest helps rebuild cyber programs, restore trust after incidents, and scale production across high stakes environments for multiple private equity firms.

The guest struggled with overconfidence, being insufferable, not listening to others, and discounting contributions of team members due to her belief of already knowing the answer.

Through consistent feedback and executive coaching, the guest learned to let go of overconfidence, embrace curiosity, and shift from individual problem-solving to inclusive leadership.

The guest fosters teamwork by soliciting input from team members, encouraging curiosity, and aligning efforts towards shared goals to ensure collective motivation and effectiveness.

The guest embraces feeling like an outsider as a growth opportunity, learns from observing board members, and adjusts her behaviors to enhance leadership and collaboration skills.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.