The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cloud Security Today
Cloud Security Today artwork

Cyber and the NY Giants

Cloud Security Today · 2026-07-01 · 48 min

0:00--:--

Key moments - from our scoring

Substance score

47 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality9 / 20
Guest Caliber14 / 20
Specificity & Evidence6 / 20
Conversational Craft8 / 20

Christina Murillo's journey from Microsoft's identity and cloud security work to becoming the Giants' first Chief Information Security Officer reveals fundamental lessons about enterprise security leadership. The NFL mandated new security roles at all clubs after a ransomware attack, creating a unique challenge: standing up a security function that the business didn't organically request. Murillo's approach centered on three pillars - empathetic listening, collaborative execution, and delivering visible results - rather than assuming technical priorities. Her breakthrough came through a third-party risk assessment conducted in her first 90 days, which revealed that the actual business risks differed dramatically from what cybersecurity professionals typically prioritize. Contrary to industry assumption, the playbook wasn't the crown jewel; instead, critical systems, operational continuity, and regulatory compliance (including HIPAA for player health data) were what mattered most. The Giants operate as a single organization with two distinct operational models: football operations (players, coaches, scouting, medical) and business operations (ticketing, HR, marketing, finance). Murillo's security architecture had to protect both while respecting that they function under different risk profiles and compliance requirements.

Key takeaways

  • →Security professionals often misidentify what's actually critical to the business by making assumptions rather than conducting genuine discovery - third-party assessments and cross-departmental interviews reveal true priorities.
  • →Building trust in a mandated security function requires listening to stakeholder concerns first, executing collaboratively using 'we' language, and delivering tangible results rather than just creating compliance artifacts.
  • →The NFL clubs compete fiercely on the field but collaborate closely on cybersecurity through a league-wide community model, proving that industries with naturally competitive dynamics can still align on shared security threats.
  • →Sports franchises manage fundamentally different operational models - football operations with HIPAA-regulated player health data and business operations with PII from ticketing - requiring security strategies that account for distinct regulatory and business contexts.
  • →New security hires should use their outsider perspective as an advantage by asking naive questions during discovery, then rapidly executing on findings to build credibility before organizational skepticism sets in.

Guests

Christina Murillo

Topics in this episode

HIPAA complianceBusiness continuity planningIncident response planningThird-party risk assessmentZero Trust NetworksMicrosoft identity and cloud securityNFL cybersecurity mandateransomware incident responseplayer health information securityticketing PII protection

Questions this episode answers

What was the crown jewel security risk at the New York Giants instead of the playbook?

The playbook is important but not the critical asset most assume. The real risks center on operational continuity systems, player health information (HIPAA compliance), ticketing PII, and business-critical infrastructure like revenue systems - identified through departmental risk assessments and business continuity evaluation.

Why did the NFL require new security roles at all clubs?

A ransomware attack on one of the clubs prompted a concerted league-wide effort to raise security posture across all teams, resulting in mandatory Chief Information Security Officer or information security roles at each franchise.

How does Christina Murillo build trust when joining a mandated security function the business didn't request?

She uses empathetic listening to understand what stakeholders view as important, executes collaboratively with collective language ('we' not 'I'), and delivers visible results quickly rather than just creating documents - building credibility through action and showing tangible improvements.

What are the two different business models operating within a single NFL franchise?

Football operations include players, coaches, scouting, medical, and athletics teams handling HIPAA-regulated health data; business operations manage HR, marketing, ticketing, and finance with different PII and compliance requirements - both housed in the same facility but requiring distinct security considerations.

How do NFL clubs approach cybersecurity collaboration despite being competitive on the field?

NFL clubs operate as a cooperative community for security, sharing intelligence and approaches with each other and the league office, rather than competing - treating cyber threats as a shared league problem requiring collective defense.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

There are a handful of genuine operational insights - using a third-party risk assessment as a learning accelerator in your first 90 days, applying manufacturing-style blackout periods to security deployment windows, and the counterintuitive take on NFL club crown jewels - but they're separated by long stretches of career narrative, soft life advice, and conversational filler that dilutes the overall density.

if you have the opportunity to form some kind of like assessment, whether that's you doing it internally or having a third party vendor that you work with to do that, um, I would say that that's like the cheat code
for every other department, it may be dead for it. And security, we can now deploy patches. If things break, it's okay because we don't have to worry about. There's a game on Thursday night

Originality

9 / 20

The NFL-specific reframing - seasonality as a security operations lever, competing clubs collaborating on cyber, the playbook-not-crown-jewel thesis - is genuinely fresh contextual framing, but the underlying advice (listen first, execute, use 'we' not 'I,' invest in yourself) is well-worn leadership guidance that circulates everywhere.

It's not the playbook. I think everybody thinks it's the playbook. Uh, there, there's other, you know, data that is way more important
we're competitive on the field, but we are not competitive in the back end

Guest Caliber

14 / 20

Christina is a legitimate practitioner with nearly 30 years in industry, deep Microsoft identity and cloud experience, co-authorship of Zero Trust Networks second edition, and she genuinely built a security function from scratch at a major franchise - not a career thought-leader - though the transcript doesn't surface much technical depth beyond the practitioner narrative.

I'm also very Tactical. So I actually get hands on to kind of like get it going
I started in the traditional IT world. So I've been in the industry almost 30 years now

Specificity & Evidence

6 / 20

The episode is almost entirely anecdotal - there are a handful of concrete anchors (32 clubs, Giants founded 1925, one unnamed club ransomed, promoted after year one) but zero dollar figures, zero named vendors or tools, zero measurable security outcomes, and deliberate vagueness on the most interesting specifics like which club was ransomed and what the actual crown jewels are.

a couple of years ago, and this is public knowledge, one of the clubs, I won't called him out, um, got ransomed
after my first year, I got promoted

Conversational Craft

8 / 20

The host asks contextually reasonable questions and does a competent job summarizing Christina's answers back to her, but rarely pushes into unexplored territory, never challenges a claim, and leans on soft openers ('as much as you can say,' 'dance around that however you want') that let the guest off the hook on the most interesting specifics.

So I'm curious, like, when. And, you know, as much as you can say. But, like, what is, like, the reach of cyber with the individual players
It sounds like there's three things, at least, that, uh, were successful for you

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A79%
  • Speaker B21%

Most-used words

security30important30football23different22organization21first19understand13depends13build11super11role11department11terms11listening11cloud10didn10

Episode notes

Christina Morillo shares her unconventional career journey from traditional IT to cybersecurity in the NFL, highlighting the importance of building trust, understanding business risk, and addressing misconceptions in cybersecurity. Christina's book: Zero Trust Networks

Full transcript

48 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: This is the Cloud Security Today podcast where leaders learn how to get cloud security done. And now your host, Matt Chiode.

Speaker B: Today I'm joined by Christina Murillo. Christina is the senior Director of Information security with the New York Football Giants. That is an NFL team, in case you don't watch football. Christina's career does not fit the standard standard cybersecurity template. She came up through identity, cloud and enterprise security. She spent nearly four years working at Microsoft, focusing specifically on identity and information protection. She also co authored Zero Trust Networks, second edition, and then took on a very different challenge, building the giant's first dedicated cybersecurity function from scratch. What I really appreciated about this conversation is that it cuts through a lot of the romanticized version of sports. In cybersecurity, everyone assumes that the crown jewel is the playbook. Christina makes the case that the real risk is much more nuanced. It's understanding how the business actually operates, building trust in a function that the organization didn't originally ask for, and protecting two very different worlds inside one. Franchise football operations and business operations. We also get into why the clubs compete fiercely on the field but collaborate on cyber and what other industries could learn from that model. And how Christina's work with women of color in tech shape the way that she thinks about credibility, representation, and showing up as the expert in the rooms where people may not always expect it. This is a conversation about security as a business discipline, not just a technical function. And about what it really takes to build a program where the stakes are high, the culture is unique, and the playbook is not the whole story. I hope you enjoyed this episode. Christina, thanks for coming on the show.

Speaker A: Thank you for having me.

Speaker B: All right, this is going to be exciting. So you've, um, you've got a really cool background, right? You've worked for Microsoft, you've gone deep into identity and cloud, co authored books on zero trust, and now you are working for the NFL Giants Football club, which is really cool. Again, my family, big Giants fans. So this is extra special. Tell me, what was the path that took you from Harlem and Enterprise Tech to securing the NFL franchise? What was that journey like?

Speaker A: That's a great question. And honestly, there wasn't a playbook, right? It was just me kind of following my gut and curiosity. So there was really no path. I think for me, I started in the traditional IT world. So I've been in the industry almost 30 years now, and I started, like, first, like, level one, right. Help desk, and kind of navigated, uh, my way through that and just continued to learn as much as possible. And for some reason, like, I ended up here. Right. Well, backtrack. I started working for different companies within New York City, like the financial sector. And then I had an opportunity to go to Microsoft because I was super curious about the cloud at the time. The cloud was like this new thing, right? Yeah, you remember. And so I was like, well, what is it like? I have no idea. And I got the opportunity to work at Microsoft, focusing on identity in M, the cloud, and, uh, data DSPM pretty much. And I was like, okay, this whole new world. So it forced me to learn, and I just took that experience and ran with it. Right. Um, and then I ended up here. And this wasn't a strategic move for me. It was just recruiter called me and was like, hey, we have this opportunity. You would be building the security program. Um, you would effectively be the ciso. And so I was like, okay, who's the company? He's like, well, I'm not gonna tell you yet. And I was like, okay, no problem. Uh, and then finally, when, you know, it was time to come on site for my second interview, well, before my first interview, I was told, ah, the company. And I was like, okay, cool. I don't like football. So, I mean, as long as the job works.

Speaker B: I thought they would disqualify you as soon as you said that.

Speaker A: No, actually, that was one of my interview questions, my panel interview questions. It was like, do you watch football? I was like, no, I don't. I don't watch football. I don't. I don't know anything about football. So, um, I think it actually helped. It helped because, you know, they didn't necessarily want, like, an avid football fan, right? Because then you would be distracted and not focus on, like, the mission and the work. And I was just like, I have no idea. I like it a little bit more now, obviously, because I know more. But, um, at first I was like, I haven't. I don't even. Is that yellow line real? Is it fake? I don't know. You know? Um, but you have to learn, so.

Speaker B: Well, kudos to the Giants, uh, football club for not making that a gating requirement. So.

Speaker A: Yeah, yeah, they were smart. They were smart.

Speaker B: I know that every time I've taken a new role, I've gone in with, like, some assumptions, right? Like, oh, it's going to be this way. And then within the first, you know, 30, 90 days, it's usually demolished. Yes. Talk about something like, what did you believe about securing an NFL team before you Got there. That turned out to be like absolutely wrong.

Speaker A: I think one of the things that there were a couple, but one of the primary things was the um, hierarchy. Like how the NFL works, like how a club works versus the NFL and vice versa. I didn't understand like that structure. Right. I always thought like, okay, well the NFL sits at the top of the food chain and all the clubs kind of follow suit. And that's not really how it is when you really look at it. The NFL is the front door, but all of the clubs, all of the teams, um, owners own the NFL. Right. So it's more of a collaboration. It's not a uh, like, well, they tell you what to do and you have to do it. It's more of a. No, it's all of us like working together to um, kind of protect the entire league. It's not really a top down approach. That was my one. I was like, oh, mind blown. This is what, this is not how it works. Right. That was the first assumption that I just had to like throw out the window. Um, and then there are other things like what I thought was important or considered crown jewels versus not. That was the big, that was a big one for me because I assumed I'm like, oh, you know, the traditional what everybody thinks. Right. But it's not that. And there's like so much more happening in the background. So that was like really interesting. Um, and then just how the organization works. Right? Ah, the organization has been around since 1925 and so it's very traditional. Um, very football first. Right. And fan first. And so that's, that was new to me coming from like corporate, you know, corporate, uh, systems and understanding that type of like infrastructure from like a people and even technology perspective. And this was like, no, this is something different. So it, it's, it, it's almost like my experience was, is helpful, but I still had to learn this from m scratch this environment, like the sports world, uh, because it is like an entirely different world on earth. So um, that was very interesting as well.

Speaker B: Well, I want to go back to one thing you just said because I think people are probably curious about it that are hearing this. Right. So you said that everyone assumes the playbook is the crown jewel, but it's actually not like, you know, you can address that however you want. I know there's some intellectual property there too probably around that. So dance around that however you want. But like, I guess the bigger question is, is like what does that reveal about how security people often misunderstand business risk?

Speaker A: Yeah. I think that, um, it's not the playbook. I think everybody thinks it's the playbook. Uh, there, there's other, you know, data that is way more important. It's important. The playbook is important, but it's not, it's not as important as people think it is. Um, and it's usually the same plays, right? So coaches come from different teams, same plays. It's just in a book. So take that any way you want to take it. But, um, I think one of the things is that we assume what's important versus not important. Um, which is mistake number one. Right. I think in our view, we think, oh, these systems, these details are super critical. But from a risk perspective, the business may not think so. Right. And you discover this as you start, um, learning the business, learning the environment, learning the people and what's important to each person, to each department, and then to the entire organization. And it could be different. There may not be one thing that's like the critical thing. Um, there may be multiple things that are important and are just kind of like prioritized or, uh, you kind of have to put them in separate buckets or levels, um, if you will. So that's one thing I think that we do across the board, whether it's sports or finance. I think we make a lot of assumptions coming in. Um, instead of first understanding what the business is, how do we make money, what is it that we do, what does our day to day look like, what are all the moving parts? And then determining at that point what is really critical, not because you assume, but because of what you have learned and what you are hearing from the people that are in the thick of it.

Speaker B: Were there. You know, I think when you, when you take a new role, there's always, there's always this kind of this learning process, the discovery process. I'm curious, what, what was that discovery process like for you? Like, um, were there, like breadcrumbs that led you to, you know, kind of say, oh, it's, it's not. I mean, yeah, the playbook's important, but it's not like the thing. Like, were there things that you've looked for around that?

Speaker A: Yeah. So it's funny because I started and I already had my ideas and I created like this 30, 60, 90 plan, right. And then I converted that into like a roadmap after my first 30 days. But something happens within my first, um, 90 days. And that was, we needed to, I think it was like a risk assessment and there was another business, uh, continuity, um, assessment and we had a third party vendor that was already on the books before I joined. So we had a third party vendor come on site. And based on that assessment, like I was able to sit in, uh, meetings with everybody in the organization, right? In terms like senior leaders and people, department heads and managers. And uh, those meetings like catapulted me to the other side of the planet because I was able to as a newbie, I don't know anything, right? So I didn't even know what to ask. This vendor had done this before, but there wasn't someone like me in the room, right? So I was able to kind of work with them prior to them coming and to understand like, what are the questions you're asking and here's what I would like to know. So they were able to ask these questions and with me sitting in the room and I was able to get a better understanding of what is it that you do, what are the critical systems that you're using? If something were to go down, how long could you, um, you know, how long could you survive, how long could the business survive with this system or this critical piece component being down? And that gave me so much insight, so much so that from that level of detail, I was able to write our incident response plan, um, from scratch. And I was able to also write a business continuity plan. And then I was able to speak to, okay, now I understand how things are working, right? Um, and what's important versus not versus what's not important to my senior leadership. So those two things, I think people take that for granted. But in a new organization, if you have the opportunity to form some kind of like assessment, whether that's you doing it internally or having a third party vendor that you work with to do that, you know, that does this, um, I would say that that's like the cheat code. It was a cheat code for me.

Speaker B: It's a great way to get your, get your feet wet and kind of, you know, as a new person. I think you also mentioned too in our, our pre show interview, we were chatting that you said that when you joined, like this was a brand new role that was required by the NFL. So it wasn't like there was all this institutional like history and all that. This was a net new role. So this sounded like a great way for you to just be like, hey, I didn't even order this thing right? This thing just like this was part of it and it was a great learning process for you.

Speaker A: Exactly, exactly. It was definitely a great learning process. I mean, I think that Allowed me to look at the roadmap and say, oh, no, this is wrong. This is not what we need to do. Um, because again, I was assuming things that were important. From looking at, uh, our IT security and some of those components, like our cloud security, I was like, okay, we need to button things up. And those things were super important. But there were other things that were a little bit more critical that also opened the door for me to do more down the road. So, um, I'm glad it happened within my first 30, 60 days versus a year out, because it saves me from making that mistake of assuming that, um, things that I thought were important were important. And then running in that direction, I was able to reset very quickly, uh, and run in the correct direction, um, which was amazing. Amazing. For me, at least it worked out well. Um, so I highly recommend that approach.

Speaker B: So this position, again, it was a brand new role required by the NFL.

Speaker A: It was a brand new role required by the NFL. So what happened was a couple of years ago, and this is public knowledge, one of the clubs, I won't called him out, um, got ransomed, right? And so because of that, you know, there was a concerted effort across the league to, um, you know, kind of raise up security, right. And look at every team's security posture and improve the security posture. Not that it was bad, but we knew that there could be some, you know, bells and whistles, we could tune some things. Right? So that's where, um, a lot of these roles came. My role specifically the. The Giants did not have an IT security or information security officer or person at all. And so, um, that's what I came, uh, here to do. And then other teams were the same. They had some people that were already doing a similar role internally, so they shifted into the role. And then there were some people that were brought in from the outside, um, net new, um, to kind of focus on this function. So this is like my sole function focus. And, you know, working very closely with it, working very closely with the other clubs as well, with other teams. Um, we're all. We're like a little community, so we all know each other. Uh, we're not competitive in that regard. Like, we're competitive on the field, but we are not competitive in the back end. And, uh, the NFL as well, right? So we work with them closely as well. And then to basically translate, like, some of the NFL's requirements in terms of, like, improving our security posture into, like, tactical, actionable things. And because I'm the first security hire, I'm also very Tactical. So I actually get hands on to kind of like get it going, which has been fun. Exhausting, but fun. Um, being strategic and tactical, um, has been very interesting. But yeah, it was a net new. I've been here m almost three years now, so, um, we've come a long way.

Speaker B: Um, yeah, let me ask this. So a lot of times I've been in roles where, you know, it was created because there was some requirement, either some kind of compliance mandate that was driving it. And sometimes you don't get the best reception from the business because it's like, I didn't ask for you and you're here. Right. So I'm just gonna do it. Like, tell me, like, you know, for the leaders that are listening that are, you know, either are in similar positions or maybe there is some kind of new requirement that's driving a role. Like, what are some ways that you kind of built trust with the business, especially given that they didn't organically ask for the function in the first place.

Speaker A: Yeah. And, you know, I'm not gonna lie, it is tough. Um, and it was tough for me initially because it was like, well, we've always done things this way and it's worked. Why?

Speaker B: You know, we've always done things, uh,

Speaker A: you kind of want to. Yes, we've always done things. So for me, it was, you know, it was. I had to do a lot of listening. And I will say that it depends on the organization, right? It depends on the people, it depends on the culture. It depends on so many things. But what I did specifically is that I came in trying to understand what they felt was important. The people that hired me, like the senior leadership. What is important to you? Like, when you think of cybersecurity or information security, what is important to you? And initially it was like, well, we need these things. We need these documents, we need these plans. We don't know where to start. For me, that was not necessarily critical. I'm like, I need to lock things up, Right? But I didn't say that. I was like, no, yeah, that makes sense. That's important. So basically what I'm trying to say is that at Microsoft, uh, we used to call it listening at scale. So that's like listening not to respond, but actually listening. Because if you listen and don't make any judgments, um, you will hear what they're trying to say. And the minute you, you showcase that, like, no, I listened to you. Um, we got this done. That's very important. Even though you're one person and maybe you're the one doing the heavy lifting. It's not a I thing, it's a we thing, right? So bringing people along for the ride, um, actually understanding what they feel is important and never making anyone feel that, like, well, I'm the expert. I know more about this topic than you do. Like, never. It's more like, no, I'm here to collaborate. What do you think is important? Here's my perspective on it. What is your perspective from a risk perspective? Right. What is your perspective from a legal perspective? Like, how do we look at this as an organization? And that worked for me, right? Because I think that's one of the hardest things to build trust. Um, but the most important thing is once I listened and once I asked these questions and got responses, I was able to execute. And that was the third most important. Um, I, um, guess I don't want to say skill, but that was the number. And I'm going to say that as number two. Listen and then execute. When you execute, you can't just, it can't be fluff, right? You gotta, like, show and prove. You gotta show that you are. Yes, I'm listening, but I'm also doing that thing and I'm thinking about it a little bit. I'm taking a little, taking, um, a step further, right? So going a little bit more above and beyond. Um, don't wait for someone to say, can you write this? Can you document this, can you whatever. Once you understand, then take that and run with it. And that's what I did. So those three things is that's how I was able to build trust, you know, understanding that, like, I'm not here to judge, I'm here to, um, help and I'm here to execute and improve the posture of the, you know, the organization's security posture, right? That's what I'm here for. So there are give and takes when it comes to that. Um, but it takes time, right? I think I was only able to build trust over time, um, because I brought results, right? Whereas other people maybe a lot of talking emails, a lot of emails, a lot of meetings, but then there's nothing to show for it. It's like, okay, well, you've been here six months, what have you done? Right? Um, so I kind of hit the ground running and I think that showed that, like, oh, we've accomplished so much, right? And we've done this so much so that like, after my first year, I got promoted. Um, because like I said, you have to execute and you have to show, but it's not a, ah, Well, I did this. It was like, no, look what we've done, you know, um, collectively. So we have like a committee, an information security committee. And so that's part of that collective. And so while I'm the one, like, running, you know, I need support from the committee. I need, like, that buy in funding, et cetera. So I always make it as, um, when I. When I speak about the things that we are doing, I speak in we and not I. And that helped. That helped a lot. But again, depends on the people, depends on the culture, depends on the organization. So a lot of depends.

Speaker B: It sounds like there's three things, at least, that, uh, were successful for you. You know, again, going back to the original question was, is, you know, this was, uh, not a role that they necessarily asked for. It was something mandated by the business. Yeah, but it sounds like you did. You did three things. One was listen with empathy.

Speaker A: Right.

Speaker B: Second thing was, you know, when you're discussing it, using a lot of collaborative language as well, so they can see themselves in the situation. And the third was, go figure, delivering results. Right. Not just being another talking head and delivering on the results that ultimately the business, I guess, has had asked you to deliver on. Right.

Speaker A: So, yep.

Speaker B: I love that.

Speaker A: And maybe not always directly. Right. That's why. That's where the listening comes in. Right. Um, so those, again, the formula may not work for everyone, but it worked very well for me. Still working. Right. So.

Speaker B: So you described the NFL as almost. Or like the NFL, your club. The club's almost as two different businesses. Right. There's the football operation, which is what everybody sees on, you know, when they're watching the football game. And then there's the business operation. Maybe just, like, tell us a story. Like, how does. How does kind of that bifurcated, you know, model. How does that impact cyber and, like, how did you kind of address that?

Speaker A: Yeah, so it's really interesting because every club is different, but at this club, um, we are one organization. And then you can kind of think about it like departments. Different departments. So we have like an HR department. We have like a marketing department. We also have a football department. The football department is, um, huge. Right. Because now you're talking about the players, the coaches. Right. Um, staff, scouting, and every other medical, um, athletics, nutritionist. So that's a huge department. So they're almost like departments within that huge department. Um, but it's one organization. Right. We're actually in the same building, same facility. Um, so we share everything. Right. And so that's how I look at it now, the use cases may be different, but it's one infrastructure. There are some little caveats in there not to share too much, but, um, it's just that it just looks a little bit different in terms of maybe every organization doesn't have a ticketing department, which means that I have to look at PII a little bit differently. Uh, maybe every organization, unless you're a medical organization or hospital, doesn't have to deal with hipaa. Right. Because we're looking at player health information or player medical records. So again, it's just understanding what we do and then looking at every specific department, looking at what they do and what's important, and then you can kind of determine, um, okay, what is it that I really need to protect or what is it that really matters in terms of the flow. The only difference is that our business, you see it on Sundays. Right. Like the result. But there's so much. That's another thing. Back to your first question. There's so much that goes on behind the scenes. Like, I had no idea. Like, people watch a football game and it's fun and it's great and all the lights and all the like, you know, commotion, um, which is exciting. But there's so much that goes into that behind the scenes. So much so that when we talk about like the off season, which is like this period, uh, it just means that there's no football on tv, but the organization is still going. Like, we're still working. It's actually our busiest time of the year, um, because it's, you know, we can make changes and do things and deploy things. So. Yeah, that's. But it's. I don't want to say it's the same, but it kind of is the same. If you're looking at it from an ah, organizational perspective, it's just different departments, um, and one of them happens to be a football team. Right. Like, so that's, it's, uh, it's interesting, but it's almost the same. It's almost the same as any like, corporation. Right.

Speaker B: So it sounds like you, you know, you definitely, if you build out, you said you've been there over a little bit over three years now as you built your roadmap out. It sounds like there is a seasonality. Obviously we talk about the football season, but that's something very different as a football, you know, watcher of football versus somebody that's on the internal operations of the business.

Speaker A: Yes.

Speaker B: So part of that learning process that you said is that you've had to adapt how you Apply your, you know, your version, your strategy of cyber around this. That internal seasonality of. In terms of when you can do things.

Speaker A: Yes, exactly. It's like. It's like, you know, when you have, um, like a blackout period, regular organization, you may have a blackout period that may be December or because finance is closing the books, or it might be the end of Q4. I don't know. Um, so I look at it like that there are things that we can change during the season. Um, because, you know, we're in production, right? It's like, uh, we're producing, uh, these games on Thursdays. Well, the NFL is producing the games, but there are things that happen behind the scenes. Whereas during the off season, it's a little bit quieter in terms of the TV things. Right. But there's a lot of things that are happening in the background that, um. For it. Right. For every other department, it may be dead for it. And security, we can now deploy patches. If things break, it's okay because we don't have to worry about. There's a game on Thursday night. Right. And that stress. Um, so we can, you know, we have a backup plan. We can upgrade servers. We can do more. We can touch production a little bit more during the off season. But it's also a time where we could kind of reevaluate. You know, what are we doing? Do we need to change to another vendor? Do we need to rethink our strategy about xyz? Um, so you have a little bit more of a buffer time, but it goes really fast. It goes really fast. And then we're back into, like, the swing of things. And then in between that time, though, there are peaks because we have, like, the draft. We have. You know what I mean? So, like, those things happen. We have, um, uh, the combine before the draft. So there are those, like, events that it gets super, super busy, but then it, like, goes down again until the season. Um, the season starts. So. Yeah. And it depends how long we're in the season, too, because if we get to, like, playoffs or whatever, then it's, you know, our season doesn't end at the end of January or January. It goes a little bit longer. Um, so it really depends on a lot of things as well.

Speaker B: So I'm curious, like, when. And, you know, as much as you can say. But, like, what is, like, the reach of cyber with the individual players? Like, how much does it impact them? You know, whatever. I just think that would be interesting. Whatever. You can kind of speak about that.

Speaker A: Yeah, not so much because the Players have, they're end users, but they're not end users. So they get secure devices, um, that they use for their work. Um, and so that in terms of the devices that they're using, those are part of our environment. And so we provision those on a day to day perspective. Not much because that falls more under our physical security. Um, so that's not something that I do right now. In terms of like the coaches and everybody else in the football organization. Yes. They have to do like annual security awareness training. They have to read my annoying emails. Um, they have to. Right. Uh, which, you know, they have to do my little snippet trainings and they tell me how much they like them or dislike them. But uh, those are like requirements. Right. So I try to make it fun. I try to make it like, you know, like not cool but kind of like it's like a talking point. Right. So they're more like, I did your training, you know, or I'm gonna do your training soon. Or I'm like, I see you, I know that you didn't do the training. Right. So I make it, I make a little like joke out of it. Um, and sometimes I do a little like there's like a little competitive. Mm, mhm. I see that you're on um, low on the little like dashboard, what's going on? You know, so just to try to make it fun. But the players, not so much. Yeah. There's also like union stuff and stuff with the players. There's like a lot of things that happen in the background.

Speaker B: Yeah. Probably things you can't do. They're probably in contracts and stuff like that.

Speaker A: Yeah, yeah, yeah. But you know, like when they are here, like, you know, you talk to them, right. Like if they. Obviously they had a question. There were a couple that have asked me questions and I'll answer the question right. Like if there's a specific question. But if it's um, if it's like I think someone couldn't like log into one of their apps or something or like that's funny. I don't know. Yeah, yeah.

Speaker B: If you're like an NFL athlete, like they'd be like, darn it, my, my single sign on is not working well.

Speaker A: You know, you have like multiple phones and all that, you know, you know, celebrity life, I guess. Uh, so then I was like, okay, we have to do those things. But it's not. Yeah, yeah, that's different.

Speaker B: So for listeners that are listening right now. Yes. Even professional athletes have to use single sign on and they have trouble with

Speaker A: Logins every once in a while and forget their password. And forget their password or pins or whatever.

Speaker B: I love that. I love that. One of the other things you had mentioned in our pre, um, interview chat was that there's about 32 different clubs M who compete fiercely on the field.

Speaker A: Yeah.

Speaker B: But when it comes to cyber, you guys have great collaboration. Like, tell me, like, why does that work? And like, what would it take for other industries to maybe copy that model? And I'll caveat that by saying, I know, like, everyone's listening. We know there's like, various Isaacs out there for pretty much everything, but a lot of those I've been part of a lot. A lot of those are really light on action. Like, there's not a lot. Lot of them are very vendor heavy too. So I'm curious, like, why does it work for you guys? Like, what have you found that's like, unique maybe about the NFL model that you guys have?

Speaker A: I think it works because the. I'm going to blame the NFL. Right. Or give them kudos. Right. I think it works because of them. Right. So there's like an information security office, there's a ciso. And I think they do a lot of outreach in terms of making sure that we're all good, that we're supported, and I think that's why it works. Right. We will complain, we will fight with them, we will push back. Um, but it's all healthy pushback because we all have the same mission. And I think that's why they also make an effort to get us all together a few times a year so we get to see each other in person and we can relate to, like, the struggles. Right. We all understand, oh, the football organization, they want to watch video, they want to do it from their phones. They want to do this, they want to do that. So it's like we have this commonality and we can, uh, talk about, um, issues that we're facing, like, on the spot, like, oh, what are you guys doing about xyz? Um, and you can't really talk about it with anybody else. So I think because we're in the same industry, and I would assume that, I don't know, maybe if you're, like, in finance or, like, in fashion. Like, I know folks in, um, sisos in the fashion industry, and they speak even though they're from competing brands. Right. And so I think it just, it depends on the people, but I think all of us are, um. I guess maybe, I don't know. We're good people, are a good Bunch, because we all share. We're just. I'm like, hey, what are you using? You could have just won the Super Bowl. And I'm like, hey, what are you guys using as a segment? You know what I mean? Uh, or what are you guys using for training? Um, and awareness. And everybody's willing to share because we all understand what we do. And honestly, you can't really talk about it with anybody else. It's like, we only have each other, so I don't know if that's a good or a bad thing, and I don't know how others can replicate it. I think we kind of do a good job in the industry outside of sports, but it depends on the. There are a lot of little, like, mini groups. And I think that's one of the issues that I found. Um, so, you know, I don't know. I don't have the secret sauce formula, but I will say that it's a godsend, because when I first joined, I had no idea, right? So having these people to reach out to that kind of gave me a little insight into, like, oh, this is how it works and this is how we do it. You know, it's super helpful.

Speaker B: So maybe, maybe some of it that makes it more effective is, yes, you guys kind of all have a very similar, you know, part of the NFL, but I think the other part of it could be just that it's. It's. It's. There's. It's smaller, most likely there's only 32 clubs. And so there's not so much, uh, diffusion of what people are after. So that might be something also for other ISACs that are incredibly broad, that may, uh, lose. That could be part of it as well. I don't know.

Speaker A: It could be. I mean, I do. I go. I attend a lot of other events, and not within the sports industry, uh, but just regular. And I meet people from all different, like, different verticals, different industries. And what I've discovered is that we all have the same issue. I'm like, oh, you're dealing with that too? Like, so it's not specific to the industry. I mean, some. Sometimes there are some things that are specific, but I feel like at the base of it all, at the core of it all, we are all struggling with the same issues, right? Whether it's budget vendors, whether it's, um, consolidation of tools, whether it's tools brawl. So I think if you find those commonalities, I think it makes it easier. The problem is when we all think we're special and too Important to talk to each other. I think that that becomes like a blocker. Um, you know, I don't know. That's my, that's my take on it. But yeah, but we were, when I, when I joined we were kind of siloed and it was ah, another person that had joined a month before I did at another club and we met, um, just cause introductions and stuff like that. And we were like, hey, let's set up like a channel and let's invite the other, um, the other security officers or security analysts, whoever. If you're doing security and you work at a club, we're going to invite you. Right. So every time we would go to like these on site or in person, we would talk about it. I still talk about it and I say, hey, if you're not in the group, let me know and I'll add you to the group. Right. And so it's like common knowledge now. And that's where we're like, um, we are active so something is happening, you know, if we need to share IOCs, it's in instant. Right. So that's how it becomes a plus. But then also for, hey, I have a question. How are you doing this? Or how are you complying with this? Um, so it's just grown into that. But I think initially we all knew about each other, but we were kind of like siloed. Right. Different states and all that. So I would say that it takes, sometimes it takes one or two people to kind of like bring it together. Right. Um, but I'm not going to say that it's, it's always easy. And again it really depends on your industry and your area. But even if your group is small, as long as you impact one or two people. Right. Like you can be helping one or two people when that matters. That's important. So. And then it'll grow. So start, start where you are. Start small. Just do it. Execute. Love that.

Speaker B: I uh, love that. Well, you've done a lot of work in cyber over the years, but you've also done some serious work around representation and community through women of color in tech.

Speaker A: Yeah.

Speaker B: Tell me like what did like kind of going through that, what did that teach you about building credibility in rooms where people maybe not expect you to be the expert?

Speaker A: Yeah. So one thing it showed me was that um, I needed to be super confident because at that time it was my first time like pitching and I've never been like a salesperson. But I learned quickly that we're all salespeople. Right. You have to Sell your idea. You have to, you know, sell whatever, um, and convince and storytell. So that's the one thing it showed me that I still use today, right? That a pitch doesn't mean that I'm trying to get you to buy my car, right? I may be trying to get. Convince you to, like, give me budget or to back me on an idea, um, or something like that, right? So that's one thing. So it gave me that confidence. But also, I think, you know, that was an interesting time. It was like the heyday of Twitter, and there was a lot of work around, like, um, representation. And, um, I just thought it was important, right, to show people that, like, hey, there are people that look like me that have had very long, successful IT careers and that are technical and that do not have imposter syndrome, um, that can, you know, that have careers insecurity as well, that there are more of us. And that's why I thought it was super important for me to. To do that. The idea came from. I don't even know how I. It just, you know what happened? The woman. Women of color in tech. I was actually. I needed to build a site, and I was looking for photos of women like, that look like me, okay. And I was like, I don't want to take pictures. Like, I just had a baby or whatever. Like, I don't want to, you know, whatever be on camera. And I was googling. And when I searched, like, information security, it, whatever, I just found, like, men, right? And specifically, like, white men, right? And I was like, okay, great. But I'm not that person. I want someone who looks like me. And so that kind of spawned that idea of, like, these stock photos. Um, but that was really it. And that grew into something bigger. But it was just, hey, I need to showcase that, like, there are people that look like me so that other people coming behind us, um, you know, the younger generation understand that this is a viable career path as well. Because I didn't see it growing up. I just stumbled into it. Right? Um, so that. That's what that's shown me. And just also that you have to, like, continuously, I don't know, like, be curious, right? Like, I've just always been super curious. And you can call it nosy. I'm a little nosy too, right? Um, when I'm, you know, in terms of, like, discovering new things and trying to solve problems. And so that is, I think, what has led me down all these, like, rabbit holes. The book. The books were Covid. And that was just being visible and someone from, like, O'Reilly reaching out and saying, hey, would you do this? And I'm like, I have never written a book before. Okay, I'll do it. Right. I'm stuck at home anyway. Right. And that's so, you know, sometimes saying yes and kind of pushing through fear. Right. Like, you know, that whole imposter mumbo jumbo, which doesn't exist. Um, yeah. So that's. That's how. So it's not a traditional path. Again, I don't have a playbook. It's just been kind of following my instinct, but also, um, being a little bit defiant in terms of, like, I don't have to do what everybody's doing. You know, if everybody's, I don't know, blogging, I don't have to do that. Right. I need to do what feels good to me, what I'm comfortable and what I feel like I'm bringing the most value. Right. And so, you know, I was always told when I was young, you don't have to dance at every party. So I don't go to every party. You know what I mean? So I go to the parties that I feel like I want to go to. And I think that can be a gift or a curse. For me, it's been more of a gift. Right. Because I'm not trying to follow. I'm trying to lead and charter my own path. So I think that also has helped me a lot. But I'm also from New York City, so I have that little, like, I have a little attitude when it comes to Larry's. I'm not following you.

Speaker B: My family's from the New York, New Yorks and Bronx and all that, so I know exactly what you're, uh, you're talking about.

Speaker A: Exactly. Exactly. So, yeah.

Speaker B: Well, you've done, uh, certainly a lot in. In cyber. You've done a lot for women of color in cyber. I. I love that. How do you. How do you stay current? Because there's always. There's so much changing, especially with the world, with AI Now. Right. Where it's. There's a new model every week.

Speaker A: Yeah.

Speaker B: What's your routine look like? How do you stay current? How do you stay sharp?

Speaker A: Well, you know what I mean. I'm going to tell you when you routine is doing a lot of heavy lifting, because, um, I am also a mom, and I have, you know, I have. They're not that young anymore, but younger children, younger than me, obviously. And, um, it's difficult for me to have a set routine where I'm like, okay. Every day I'm going to read five chapters of this like AI Security book, right? That doesn't always happen, so I have to change it up a bit. Um, I, before I got the job at the Giants, I was doing my master's and that was like, uh, that was more async. So that was like an online program. And so that I would dedicate like my Sundays, right? I would say evenings when the kids are in bed. And my Sundays, that was like my homework time, my re up time, my figure out, figure things out. It was a very difficult, challenging, technically challenging program. So there was a lot of screaming, right? And on Sundays, um, and so that's what I did back then. I finished that program and now what I do is I try to find um, time within my day or evenings, right? And weekends to explore different topics. So that could be reading books, that could be, be listening to podcasts, listening to interviews, that could be attending events, attending conferences specific to, you know, it doesn't have to be sports related, it's um, you know, security, industry related, CSO summits, stuff like that. To understand what's out there, what are people talking about. But also going back to the executing, I am a proponent of investing in yourself. So even if my organization does not provide a book budget or budget for tools, I create my own budget. So I set money aside and I pay for my own cloud licenses, my own, you know, chat GPT licenses, my own like I invest, but I also take the time out to log in, build skills, build this, think about this. Like I need to, I'm very um, hands on and visual. So I can't just talk about it or read about it or listen to people talk about it. I have to actually do it to feel comfortable. And then I use those skills, uh, within my organization, right? Like to, to solve problems, right? Um, to talk about AI, to look at AI security, to understand, you know, what's the difference between an LLM and an agent, right? Like I, you need to like dive in and get your hands dirty in order to really like grok it, understand it, right? And so that's what I've always, um, that's what I've always done. Honestly, I've done that since before Microsoft. But I think at Microsoft it was like, it became real because my first month they were just like, okay, well just like, here's your access. You need to build this cloud environment. You need to build a hybrid environment. And I was like, wait, what? And they were like, yeah, just go. So I gotta build an ad Environment and then sync it to the. Yeah. And I'm like, okay. So I had to get my hands dirty. Right. And that was the best way for me to understand it. And it still holds true today. Um, if I don't get. If I don't, like, put hands on keyboard, I won't really understand it. So I have to, like, dive in. Um, so, yeah, so that's how I stay sharp. So it's not. I don't have like, oh, ah. I wake up every day at four in the morning and I go for a jog. Like, I don't do that. I listen to my body. I listen to. I mean, I do wake up at five in the morning, but that's a different story. I do wake up super early. Um, but I don't have, like. I feel like I am the type of person that I have to, like, listen to myself. I have to listen to my body. So some days it's literally Netflix and chill. And I think that makes me more sharp because I'm taking time to kind of like say, okay, I'm gonna watch this Netflix thing and then I'm gonna go do some yard work and then I'm going to go for a walk and go take my kids for ice cream. Um, so understanding when to, like, stop because there's only so much that you can like fit in your brain, rest, reset, and then get back to it. Right. Um. But yeah, I don't, I don't have a regimen. I need to.

Speaker B: I think you actually do. You don't realize as you've been talking about this for the last couple of minutes, I think you do have a regimen. And it's, it's, it's, um. I think it's a pretty good one. 1. The one thing I heard a couple things, but the one that I really loved is the fact that you've built your own personal learning budget, like taking your own dollars, not just expecting your employer to do it. And I love that because I also discovered that years ago too. Like, yes, take what your company will give you. But I know personally, for me, the value that I put on my own dollars that are going into investment, I will definitely not let those be wasted. Right. So investing in those things, that was really key. I heard that. And then the second thing was you realize that you can't be doing that every day. You've got to take time for yourself, for true rest and relaxation.

Speaker A: 100%. Yeah. Yeah. No. You do have a model. I guess. I do have a model. I guess I'm not very regimented, but I feel like it's a little bit diverse. I have a little bit of. I do a little bit of, um, those things so that I can stay fresh. I feel like that helps me, um, stay fresh. It may not work for everybody. And, of course, understanding that not everybody has access to, like, take money out of their budget and spend it on that. Right? Like, times are hard. Gas is $5. Well, almost four now. Um, so that's understandable. But I would say, like, even if you can spend $5 on a book, that goes a long way, right? It's just. It just means investing in yourself. So that's, you know, when I can, I can, and I do that. Um, and I just make that a priority, like, for me.

Speaker B: Yeah, I love it. Well, Christina, this has been a amazingly far ranging chat. Thank you so much for coming on the show.

Speaker A: Thank you for having me. This was fun. Thank you for joining us for today's episode. To find out more, please visit us@, uh, cloudsecuritytoday.com.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Enterprise Software Buyers Now Demand a Vendor AI Training Data AuditB2B SaaS Talks with Fexingo · on HIPAA compliance90 / 100
  • The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your ProblemsThe Backup Wrap-Up · on Incident response planning88 / 100
  • Operational Resilience, Risk Management and Crisis Decision-Making with Bruce McIndoeRiskMasters · on Business continuity planning87 / 100
  • Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS RiskSecure AF · on Business continuity planning85 / 100
  • Why Most Productivity Apps Fail Neurodivergent PeopleColorado Tech People · on HIPAA compliance83 / 100
  • Episode 015: The Last Flintstones LawyerAI Tools for Practicing Lawyers · on HIPAA compliance82 / 100

More from Cloud Security Today

All episodes →
  • Identity for AI agents
  • The future of CISO
  • AI agents and the future of cyber
  • From GTA to MFA
  • CISO burnout and boardroom truths
Explore the best B2B Engineering & DevTools podcasts →
All Cloud Security Today episodes →