Talking Cyber Security

In this 40 minute episode, Richard provides the top 10 recommendations to help you get to the next level. You can have all the certifications in the world, but without the non-security related skills... you will find it hard to progress. 

Show Notes

In this 40 minute episode, Richard provides the top 10 recommendations to help you get to the next level. You can have all the certifications in the world, but without the non-security related skills... you will find it hard to progress. 

What is Talking Cyber Security?

Cyber Security, data breaches, Hackers, Chief Information Security Officers, Talking Cyber Security (formerly 'The Australian CISO') is a podcast for anyone interested in Cyber Security. Hear about data breaches, cyber news, how security personnel 'tick', how to answer questions at an interview, lessons learnt while doing the security role, how security people network, how they succeed etc. Use the email address talkingcybersec@gmail.com to make comments, pose questions or even ask to be on The Australian CISO podcast.The main presenter is Richard Heron. Richard is an experienced CISO and has learnt many tough lessons during the many and varied Security Management roles he has held since 2002. He also holds some security accreditations as well. Richard enjoys AFL, podcasting, e-Biking and charity work.

Speaker 1:

Welcome to Talking Cyber Security, a weekly podcast listened to in over 50 countries. My name is Richard Herron, and I am your presenter. In the Talking Cyber Security podcast, expect to hear all things related to the cybersecurity industry, whether that's getting your first job, interviews, board reports, data breaches, different approaches to cybersecurity, or conferences. None of the opinions expressed on this podcast by myself or guests are necessarily reflective of the opinions of the organizations we represent. If you want to continue the conversation, feel free to join the LinkedIn group, Talking Cyber Security.

Speaker 1:

I use Pixabay for most of the music heard on this podcast. Hi, everyone, and welcome back yet again to the Talking Cyber Security Podcast. This is episode 105, and my name is Richard Herron. For those of you who have been on the journey for a while, welcome back. For those of you who are new to Talking Cyber Security, then thanks for tuning in.

Speaker 1:

For the new listeners, this podcast is all about me drawing on security experiences since reinventing myself in 2002, throwing in lessons between 1994 and 2001 when I was involved in security related jobs so that was disaster recovery, tech risk, business continuity and consulting. Before then it was very much ITIL related roles, especially in service management. What I'm getting at is that there is a lot of ingredients that go into the big Talking Cyber Security cake that some of you ingest every episode. It's certainly not a technical podcast. More of a well, it's not a dummy's guide to moving up the ladder.

Speaker 1:

It's more of a Cliff's Notes of how to progress your career in the security field. The first 100 or so episodes were like that, with the last five or so episodes trying to help you get to the next level in the security hierarchy. Talking about rising up to the next level in the security hierarchy, the last five episodes have covered many aspects that can get you to the next level. Now a few things on that. One, these are just based on my experiences.

Speaker 1:

I'm sure there are more learned, more experienced and smarter folk than me that may scoff at some of my suggestions. That's fine. Despite what you read on LinkedIn, no one is an expert. We're all still learning. And when you think about it, I can only remember security being a thing in the early 1990s when I started with technology risk and business continuity.

Speaker 1:

So it's probably only, say, a thirty year old industry anyway. Experts? Meh, probably more like a piece of charcoal that hung around for a good while and then turned into a diamond. Okay so we've had the last five episodes covering many many areas that you should consider that may help you move to the next level. Some of the suggestions I would rate higher than the others, whereas some of you may just need some of those one percenters to move up to the next level.

Speaker 1:

Anyway, I've gone through the 50 plus recommendations that I've made in the last five episodes, I've tried to distill them into a top 10. A word of warning before we get really stuck into this episode: I originally thought this would be a quick episode just summarizing my top 10 recommendations. But as I reviewed them, I just didn't want to regurgitate what I'd said about them in the previous episodes. So there are new examples in these top 10. And when I think about it, whether you like the Talking Cyber Security podcast or not, whether you might have been with us since episode one when it was known as the Australian CISO, this might well be.

Speaker 1:

Now in fact, this is the most important episode of the 100 plus episodes I've provided to you over the past three years. And you do not have to be in the cyber security industry for these lessons to help you. When you hear them you'll realize how industry agnostic they actually are. Okay, let's listen to these top 10 suggestions. Remember this could turn out to be a relatively long episode and you don't have to listen to it all in the one sitting.

Speaker 1:

What I've also done apart from having my top 10 here if you remember episode 69 where I did all of it in an AI voice or should I say my voice that AI had cloned what I'm going to do for the next it could take twenty or thirty minutes, I'm not sure I'm actually going to put my script of the top 10 into the AI cloning machine. So the voice you hear, you'll think it's mine, and to some part it is mine, but it is an AI clone of my voice. So I can't say that none of the words may be pronounced incorrectly. I'm not saying it'll be perfect, but if you hear a glitch or two in the middle there, it'll be because the AI cloning has well, it's not a human being, is it? It's a machine that learns things and it tries its best.

Speaker 1:

Who knows? It might even hallucinate and get me talking in Chinese. Ni hao. Who knows? Anyway, I'm now going to hand over to the AI cloning machine.

Speaker 1:

So these are my words and thoughts, but it is the AI clone talking to you. I'll jump in at the end and say thank you for listening. And that'll be about the end of episode 105. I hope this meets your needs. The number one recommendation to move you to the next level is relationships, relationships, and relationships.

Speaker 1:

I know, I know. You may have heard me say this before. Work relationships, especially the one you have with your boss, is absolutely numero uno. Now I want to spend a bit of time on this one because I think it is more important than most people in our industry give it credit for, and it is number one for a reason. This is the single most career defining habit I have ever observed in my years of doing this.

Speaker 1:

Yes, it took me quite a few years to realize how important relationships were to being successful at security, but I got there in the end. And the many years it took me to realize that, well, if you are early in your cyber career, this is a present to you. Relationships, especially those with your boss, are the most important thing for you to work on if you wanna go higher up in the ladder. Think about the organization you work for a bit like a retailer. The rest of the business are your customers.

Speaker 1:

Treat them with care. Your boss will often speak with others in the business. You want them, your customers, to say good things about you. And your boss needs to hear these good things about you because at some stage there may well be considerations towards pay increases. See the link.

Speaker 1:

The company you work for assumes you know your security work. They assume you have the experience. After all, that's why they hired you. But here is what they also assume, and this one is critical. They assume you can work with them and not against them.

Speaker 1:

And yet I am still hearing from too many people that our industry has a number of what I'll call doctor knows. I thought we got rid of the department of no twenty years ago. And I think we largely did where entire security teams would say no no, and by the way, no to everything. But from what I've been told, there are still a number of doctor no's floating around in individual security staff, and I genuinely cannot understand this. If the doctor no's have too much pride not to come to a compromise and work out a way how they can work with the business rather than against, well, they are not going to move upwards.

Speaker 1:

Well, not in their current organization anyway. Personally, I have been working long enough in risk management security to realize that people overrate both likelihood and consequence when they consider risk. Perhaps the Doctor. No's aren't being pig headed about their decisions. Maybe they just don't appreciate the true risk posed by the situation they have assessed and said no to.

Speaker 1:

At its core, a security team exists to protect customer and corporate data, to protect the company's reputation, and to ensure business continuity. How then can a security staff member say no on a regular basis? Surely, surely, it is a matter of hearing what the organizational department wants to achieve and then coming up with a secure solution that allows them to get there. We know that security is a balancing act between security and convenience. That is the job.

Speaker 1:

You work your magic so the business can continue operating while making risk based decisions that protect it at the same time. Please do not be known as doctor No. You will never go past your current job title if you are. And for those of you who disagree with me on this, my first big security position was as global security manager at a large corporate. I didn't get it by saying no.

Speaker 1:

I got it by finding secure solutions to business needs. Actually, think about anyone you know who may be a CISO. Again, I reckon after some thought, you'd realize that they didn't get to where they are by saying no. Think about conferences you have attended where they have CISOs on a panel. I bet they don't come across as a rigid security executive who look at putting a dampener on the business by saying no, no, and no.

Speaker 1:

Yes. You may be highly risk averse, but you do not carry the risk. Either your CIO, CTO, or CEO does. If you want to stop a business project, especially a strategic one, do your risk assessment objectively. Provide both sides to the ultimate decision maker and follow their lead.

Speaker 1:

So build relationships and do it before you need them. Be proactive even if you are a bit of an introvert. Learn who your department's legal team are, and don't just talk to them when you need a contract reviewed. Learn who your procurement people are, and just don't talk to them when you need to buy something. The same with HR.

Speaker 1:

Be nice to people. Do not be combative. You will need them one day. Do what my dad said to me many years ago, son, when you're in the workplace, try and be a nice guy. You'll go further that way.

Speaker 1:

And if anything else, life will be a bit easier for you at work. And that's pretty much the way it has been for me. I fight the battles I need to. The rest doesn't overly matter. Have coffee with your target people, but do it subtly.

Speaker 1:

Don't send them a meeting invitation for a coffee catch up. They will know you are up to something. Instead, do it almost by accident. So if you see them early in the morning, Hey Billy Bob, had a coffee yet? A note when and where they do have coffee, and maybe visit that coffee shop when they are usually there, etc.

Speaker 1:

It may even be in the tea room. Ask them what their priorities are. Ask them what keeps them up at night. Because when you need their help urgently, and you will, you want to be calling someone who already knows you and already wants to help you. Build a relationship with them.

Speaker 1:

It doesn't mean you need to, stealing a nineteen seventies saying, suck up to them. Just be nice. A little niceness goes a long way. And here is the career piece. Remember what I have said earlier.

Speaker 1:

When a promotion discussion happens at the C level, it is rarely just your direct boss in the room. It is other leaders, other executives. And when your name comes up, you want those people to already have a positive impression of you, not just as a security person, but as someone who said yes, who found a way, who worked with the business rather than against it. You build that through relationships, not through technical certifications. Work with the business, not against it.

Speaker 1:

Work with your boss, not against them. With respect to the relationship you have with your boss, It's probably most important when you're at that manager, senior manager, or head of level, and it is so simple, so blindingly simple, yet so few people actually do it consistently. My two best employees over the years, and I mean the two I would go to war for, the two I would probably give up a kidney for, and the two I would happily but begrudgingly provide a glowing reference for, share exactly one trait. When I ask them for something, it gets done every single time. They never forget it.

Speaker 1:

They never deprioritise it. They never come back to me three days later and say, oh, yeah. I've been meaning to get to that. They just do it. Prioritizing your boss's requests matters so much at the C level.

Speaker 1:

Your boss, whether that's a CYSO, a CIO, a CTO, is being asked by their boss, which could be the CEO or the board for information. And when your boss asks you for that information and you come through with the goods every single time, your boss looks good in front of the CEO. And when your boss looks good in front of the CEO, guess who they think of when a promotion conversation comes up? You, the person who always comes through. It's not glamorous.

Speaker 1:

It's not exciting. But it is absolutely the number one thing that will move you up that ladder faster than any certification ever will. Number two is you need the right staff to help you meet your objectives. So we've prioritized your boss and the rest of the business. Let's make sure you have the right team.

Speaker 1:

Because let's face it, if you surround yourself with good staff, your job becomes a whole lot easier. I flagged this one as a spoiler too at the end of the last episode, and here is why it is so important and thus makes number two. When I say you need the right staff, this is really broken up into three areas. Firstly, employ the right people. Don't go for second best.

Speaker 1:

Ensure you have your job description right. Create questions with waiting criteria against each essential item you are hoping to discover. I know it can be a tiresome process, but keep searching until you find the right person. You've advertised, many keen applicants have sent through their resumes, you look forward to interviewing them, and you just don't find the perfect candidate. Well, a candidate that meets most of what you are after.

Speaker 1:

In some cases, you then get follow-up emails from these applicants or the HR recruitment firm representing them, telling you how great they really are or how could you not have picked this great candidate. Quite often they use why you rejected them to promise they will achieve that shortcoming, I. E, let's pretend we said Joe doesn't have a CISSP. They will then call back and say, well, Joe is committed to get their CISSP. Hire them, and they will do the required training.

Speaker 1:

But as you would know, sometimes it's not just that they didn't have that certification. Sometimes it's other reasons, and you just use that as an excuse because you don't want to hurt their feelings. Having employed people three times now, almost on sympathy, trust me, it's just not worth it. If they are not the right person, then don't fall for any sympathy card like I have done before. You will know when you have the right person.

Speaker 1:

Just hang in there until you get them. Because if you don't get the right person, you will be stuck with probably the best of a bad bunch, and you will have to make some decisions in the next few months, which aren't always easy. Let's cover those decisions now. So if you do pick the best of a bad bunch, I can tell you now they quite often do not work out. Trust me on that one based on my three sympathy hires I have made over my forty year work history.

Speaker 1:

So the only option you really have is to ensure you invoke the probation period termination clause. Most new staff are on a six month probation period where you and the staff member decide whether they are a good fit for the organisation and whether the organisation is good for them. Many of my CYSO associates and myself have invoked this clause over time. It's always a difficult situation bringing the employee into a room and saying that it's not the right fit. People probably think managers get some sadistic kick out of letting people go.

Speaker 1:

It couldn't be further from the truth. It is not a great feeling letting people go, and that goes for handing out redundancy packages, which some of us have had to do during our careers. So bottom line for this one, and I know I have dragged this out, but it is important. Keep persisting until you find the right person. Not finding the right person will just result in more pain, which is the pre six month exit interview.

Speaker 1:

Oh, and one more handy hint with your new staff member. If they have risk management experience, it ain't gonna hurt you. Being able to articulate a risk, calling on likelihood, impacts and controls. It can be frustrating in meetings with the business when security staff overrate risks, or talk about impact rather than likelihood and impact. If you are struggling with this one, remember that one of the hardest things about progressing to a leadership role is that your performance is no longer just about what you do.

Speaker 1:

It is about what your team does. And if you have the wrong people in your team, it does not matter how technically brilliant you are, how politically savvy you are, or how good your relationship with your boss is, you will struggle enormously. So another lesson here is if you have interviewed someone and they are pretty good, great. Get them in for a second interview quickly. Do not wait around thinking the next candidate might be even better.

Speaker 1:

Good people are hard to find. If you have one in front of you, move. Get a peer or your manager in for a second look and make a call. And a sub lesson from above. If you bring someone in and it becomes clear very early, emphasis on early, and it usually does become relatively clear early that they are not the right fit, do not sit on it.

Speaker 1:

Use the probation period. I have learnt this the hard way. One thing I haven't mentioned is that I have hoped things would improve when the signs were already telling me they would not. The right thing for you, for your team, and ultimately for the person themselves, is to act decisively when the probation period is still active. Having the wrong person in the team costs you time, costs you morale, and costs you credibility with your boss.

Speaker 1:

Without the right people around you, your job becomes dramatically harder. And you will feel it every single day. Long rant on selecting the right person, but it is a key lesson you need to learn. So you may want to think about questions you can ask your future leaders when you interview them. And some of these questions I will reel off now will pop up during this episode.

Speaker 1:

So to pick the right staff apart from listening to their history and how it could relate to this role, I'd be thinking about these questions in no real order. When do you think you would use FUD to get your point across in a security discussion? My point of view on this one is never. By all means, talk in risk terms, but good old FUD should never come into the conversation. Quite a few years ago, even one of my staff tried to use FUD on me.

Speaker 1:

He said, Richard, what will your boss think if we don't do what I am saying? And the problem for them was that I knew my boss better than they did, and I also knew security and risk management better than my staff member did. Remember, your boss is your boss for a reason. And it's usually because of knowledge, experience, and the way they communicate with executives. Another question could well be how they build up relationships with staff, their boss, and the business.

Speaker 1:

Another question could be how they argue a point with their boss or someone from the business. You wanna see how far they push it until they give up or if they ever give up. Do you really want a direct report that will keep arguing with you and not work with you? Another question. Your boss asks you to do something, but you think you are at full capacity.

Speaker 1:

What do you say? Now the smart people may say, I'd walk through my work list with my boss and ask him slash her to deprioritize one task for me. I'm sure that's what the textbook or an AI tool may tell you. I'm here to tell you that is the wrong answer. The better answer to the question about full capacity is, I'd say to my boss, give me the work.

Speaker 1:

I will make time to do it. Another question. One of the c level has invited you to a meeting at the end of next week. When, if ever, do you let your boss know? Most people will answer, I just tell my boss during my next catch up.

Speaker 1:

That is a reasonable answer, but not the one I am looking for. I am looking for, I think it is important for you as my boss to be aware of significant events, including meetings that could impact our area. This meeting is with a c level, and I think you should be aware of it. Your boss will thank you for it. The next time this happens, you won't have to repeat that sentence again.

Speaker 1:

Just say, the CTO has asked me to have a meeting with him tomorrow. What do you think? Or similar. And while I'm at it, I had a very keen analyst start with me a few jobs ago. They booked a meeting with both the CEO and CFO.

Speaker 1:

Oh my goodness. Did that cause me some pain? My boss, the chief operating officer at the time, was not overly happy about that and asked me why your analyst is booking a meeting with the CEO and CFO. I didn't actually know, so I told them I was totally unaware of the meeting. We stopped it quickly.

Speaker 1:

So if you are relatively new to security, I know it would be a great experience to meet the c level. It's probably best to ask your boss first and explain why you want to meet them and what you want to get out of that meeting. That last one could be linked to one of my recommendations coming up about learning the language of business. You could well argue, hey, Richard. How am I going to keep up with the language of business if I'm not chatting with the C level people?

Speaker 1:

The best way to keep up to date with your organisation, what they are working on, etc, is to read every communication that comes out about your organisation. This could be reading the annual general report, paying close attention to the all staff town hall meetings, reading all the internal communications that come out, and asking other staff members what is Project X all about, etcetera. So maybe the question you can ask your potential staff member is as simple as, how do you keep up to date with all the happenings within your organization? Actually, that forces the direction the answer will take. Maybe a better question is, do you think there is benefit paying lots of attention on where the company is going as a whole, or do you think it is more beneficial to concentrate on the security work?

Speaker 1:

Now I doubt many people will answer, concentrate on the security work. If so, absolute red flag. I'd be really questioning whether you wanted to hire that person. As a security person, you must know which direction the company is going. It will dictate your future actions.

Speaker 1:

I. E, if the IT department said, We have decided to go for a cloud first strategy, then that will dictate the direction security will take. If the business said, We are looking at offshoring a lot of our workload in the next nine to twelve months, that obviously is going to impact security. How are you going to secure all that? Will you get them to use virtual desktop, their own devices, or will your team strongly recommend that you ship over enterprise strength PCs?

Speaker 1:

And that's where you get a really good insight into your potential security leader. Do they possess that strategic mindset, or are they just sitting in front of you at the interview because they have been in security for a while? Number three is accept decisions and move forward, also known as just let it go. I flagged this one as a spoiler at the end of the last episode, and here it is. Acceptance.

Speaker 1:

It is, I think, the most underrated professional skill that exists. About fifteen years ago, I was working for someone who I genuinely felt was treating me harshly, shooting first and asking questions later, to use the phrase I used in episode 103, I think it was. And I came to a realization this person was not going to change. So the question became, what could I change? I decided from that moment that if my boss said jump, I would not question it.

Speaker 1:

Instead, I would ask, how high? And because I stopped swimming against the tide and started swimming with it, my work life became dramatically easier. Whether you like it or not, whether you think your boss is any good, whether you think you could do a better job than your boss, it doesn't really matter. You are not the boss. Accept what they decide and move on.

Speaker 1:

The C level, the CEO, the CFO, the board, they watch how leaders respond to decisions that don't go their way. And what they are watching for is maturity. Can this person accept a decision and move forward constructively? Or do they sulk, whinge, or regurgitate it in every meeting for the next six months? Because the person who says, even quietly and even privately to a confidant, All right, that decision has been made.

Speaker 1:

Now how do we make the best of it? Is the person the C level will trust with more responsibility? Words get back to your boss. You don't want your boss to hear that you were really annoyed with your boss's last decision. Your boss is your boss.

Speaker 1:

They ultimately sign your paycheck. If you don't like your boss and you aren't willing to change, leave. That's a good chance for you to either reflect on your behavior and the way you react to things that don't go your way, or to find a new place where you believe you will be heard. And don't get me wrong here. You probably are being heard where you are, but your boss may not always agree with your point of view.

Speaker 1:

It's nothing personal. Remember your boss is your boss, and more than likely they will have deeper and wider experience than you have. Remember what I said in episode 100, a decision is like a football umpire's call. There is not much you can do to get it reversed. So move on.

Speaker 1:

The sooner you move on, the better. Number four is never. And I mean never say I have no capacity. This is linked to numbers one and two, building up relationships with your boss and the rest of the organization. This one does get me fired up.

Speaker 1:

I have genuinely heard people say this to me, and I will tell you now, it sticks. It absolutely sticks. Managers do not forget it. Here is the thing. When your boss comes to you and says, Can you help me with this?

Speaker 1:

They are not coming to you because you were the staff member they saw in the office one day. They are coming to you because they believe you are the right person for the job. They have identified you as the person capable of delivering what is needed. And then when you respond with, I don't have capacity, what you are actually saying is, I don't have time for what you think is important. And that is a very dangerous message to be sending your boss.

Speaker 1:

Now I get it, we are all busy, genuinely busy. But if you can wander off for a twenty minute coffee during the day, and most of us can, you have time. Make it work. Make capacity. Because the alternative, being known as the person who says no when the boss asks for help, is a reputation that is incredibly hard to shake.

Speaker 1:

And reputations, as you will hear in this list more than once, follow you everywhere. Number five is keep your boss informed. I'd previously named this Never Surprise Your Boss, but I think I'll give it more of a positive spin and call it keep your boss informed. This is closely linked to number one, but it is different enough to deserve its own spot on this list. Your boss has almost certainly made commitments upward.

Speaker 1:

They have told their boss that your team will deliver x by y date. They have told the board that a particular initiative is on track. And when something is going sideways and things will always go sideways at some point, that is just the nature of this industry. The absolute worst thing you can do is let your boss find out about it from someone else. Or worse, find out about it at the board table.

Speaker 1:

I have seen this happen. It is not pretty, and it is very, very hard to come back from. The habit I'm asking you to build is this. If something is going wrong, tell your boss early, even if you don't have the full picture yet, even if you don't have the solution yet. A quick message that says, hey, heads up.

Speaker 1:

We may have an issue with x. I'm across it, we'll update you by end of day, is worth its weight in gold. It gives your boss time to manage upward to prepare to help you course correct. They will not thank you for the bad news, but they will absolutely trust you more for surfacing it early. And while I am at it, never forward meetings from your boss or someone higher than you to anyone else without their approval.

Speaker 1:

Again, been there, done that, bought the T shirt next, and I have been burnt when I have forwarded messages that my boss or someone higher has arranged. It's just not the right protocol. Just ask the meeting organizer. They will either say yes or no. Easy.

Speaker 1:

Number six is a common one you will hear, and that is learn to speak business language, not just security language. This is probably obvious, but many still do not follow this. You will hear this on every security podcast, every security conference, every security leadership article you have ever read. And the reason you keep hearing it is because people keep not doing it. I want you to stop saying to the exec's words along the lines of, we need a WAF because of the OWASP top 10.

Speaker 1:

I want you to start saying this investment protects our revenue and our customer trust. Execs don't care about CVE scores, next generation firewalls, or your SIEM alerts. What they care about is the business. What is at risk? What does it cost if it goes wrong?

Speaker 1:

What does it cost to fix it? And how does this compare to every other dollar they could be spending right now? What is the risk? Are we susceptible to it? Are you working on a mitigation?

Speaker 1:

Or do you need people, processes, or technology to fix it? If you can answer those questions in plain language without the jargon, you will stand out because many security people cannot do this. Many security people walk into an executive meeting and immediately lose their audience in the first thirty seconds. The ones who can translate technical risk into business risk, those are the ones who get invited back. Those are the ones who get the budget approved, and those are the ones who get promoted.

Speaker 1:

Learn to speak business language, and you will be noted as someone the execs can deal with. Because the higher up the ladder you go, the higher up the ladder you will need to communicate. How good would it be for you to develop those communication skills to be able to talk to the board in terms of risk and governance rather than firewalls, EDR, and SIEM? Invest in yourself. Either get internal presentation training or pay for external presentation training using your own money.

Speaker 1:

You can always claim it on tax. Invest in yourself. Number seven is learn the art of the pre meeting. This one I learnt from watching C level executives do it incredibly well, and it changed how I approach every significant meeting I now attend. Here is the concept.

Speaker 1:

If you need something approved at a formal meeting, do not walk into that meeting and hope for the best. Instead, go and speak with each of the key stakeholders before the meeting. Walk them through what you are proposing. Listen to their concerns. Answer their questions.

Speaker 1:

Build your support base. So that by the time you walk into the actual meeting, there are no surprises. There are no objections that you haven't already addressed. And the decision you need is far more likely to go your way. I've seen c level executives do this before board meetings.

Speaker 1:

They will go to each board member individually, run through the paper they intend to present, and check-in on how the board member feels about it. If a board member has a concern, they have time to address it before they are sitting at the board table in front of everyone. It is not manipulative. It is smart. It is respectful of people's time, and it sets you up for success rather than leaving things to chance.

Speaker 1:

If you're looking for a particular decision at any meeting, and especially if that decision matters to your career, invest the time beforehand. Do not gamble. Number eight is learn to present to executives and the board. You might get five minutes. You might get two.

Speaker 1:

You might, and I have prepared for this, and I will tell you it pays dividends, get pulled aside just before a board meeting and told, look, we are really running over time. We have about thirty seconds for your paper. Can you give us the key points? And when that happens, you either have a crisp, clear answer ready, or you don't. The skill of presenting to executives is a learnable skill.

Speaker 1:

Lead with the bottom line. Answer the so what question before they ask it. Use simple language. No jargon. No acronyms.

Speaker 1:

Without explanation. And never ever assume that the board member or executive in the room has read your paper in advance. They may have skimmed it at best. I've also made the mistake of getting too familiar with board members. Treat them as the professionals they are.

Speaker 1:

You are there to inform and advise not to be their mate. The board has their function, risk, and governance as do you. As a side note, the same applies to vendors. You may like some vendors, but remember the bottom line with the vendors is the bottom line. They are salespeople, not your friend.

Speaker 1:

Why do you think they are so friendly to you, laugh at all your jokes, and ask you to events? It's not because the vendors think you're great. It's because they may land a sale. There is a warmth you can bring to the interaction absolutely, But maintain your professionalism at all times, whether it is the board or vendors. They will respect you more for it.

Speaker 1:

Number nine is understand your organization's politics. I am not talking about office gossip. I am talking about understanding how decisions actually get made. Who has influence? Where are the alliances?

Speaker 1:

Who does your boss trust? And who are they less comfortable with? These things matter enormously, and pretending they do not exist does not make you noble. It makes you ineffective. I will give you an example of how this plays out.

Speaker 1:

If your boss says notice something and your instinct is to push back or escalate before you do that, stop. Consider whether there might be political reasons behind that no that your boss has not shared with you. They very likely are. Your boss is not always able to tell you why they said no. So before you assume they are being unreasonable, consider that they may be managing a dynamic you are not fully aware of yet.

Speaker 1:

Accept the decision and file the observation away for later. The c level are masters of political navigation. They do not always fight battles they could win because they are thinking three battles ahead. If you want to operate at that level, you need to start developing that same kind of awareness, Know the landscape, know who the players are, and choose your moments carefully. The last lesson, number 10, and this could have been a number of my exhaustive list of approximately 60 recommendations, is the magic word over communicate.

Speaker 1:

Remember that security is a cost centre, not a profit centre. So you're going to have to use opportunities to promote the good work that the security team has done. I. E, you have done a pen test, include those results in your next board paper. Put the actual results in the appendix, but use business speak to describe the main findings and the actions you will take in the main body of the board paper.

Speaker 1:

If there's been a major global or country wide data breach, send an email to the execs explaining what occurred and how your company may need to improve in some areas to handle a similar situation. So there you have it. My top 10 all provided to you with my AI cloned voice. In fact, this is my cloned voice talking to you now. I hope it came across as a pretty accurate representation of my real voice.

Speaker 1:

Please reflect on this episode. Hink about it. Not a firewall insight. Not a single mention of encryption or zero trust or threat intelligence feeds. At some point in your career, cybersecurity stops being about technology.

Speaker 1:

It becomes about influence, judgment, and leadership. And the people who understand that are the ones who get to the next level. And don't think that because I am spruking these ideas, I have it all worked out. I don't. Even after working in security for twenty five years of my forty year working life, I am always learning.

Speaker 1:

Thankfully, I'm making less mistakes, but, of course, learning is a culmination of all those wins and mistakes just as long as the wins exceed the mistakes. So here is the truth of it. And this is what security knowledge alone isn't enough has always been about. Security knowledge gets you into the room. It gets you the interview.

Speaker 1:

It gets you the title. But these 10 things, these are what determine whether you stay in the room, whether you get to the next room, and whether eventually you are the one deciding who gets let in. Thanks for sticking with me through this series. I genuinely hope something in these episodes has landed for you. Whether you are new to the industry, whether you have hit a ceiling you cannot seem to break through, or whether you are already up there and just want a reminder of how you got there, I hope it has been useful.

Speaker 1:

And I do hope this AI cloned voice of mine was reasonable. Well, folks, that's it. Until next time, take care of yourselves. Speak to you next time. Goodbye.