CXO Spotlight · 2026-06-02 · 45 min
Key moments - from our scoring
Substance score
56 / 100
Five dimensions, 20 points each
Mignona Cote, a top 10 CISO and Hall of Fame inductee with three decades of experience across AWS, PepsiCo, Bank of America, and Aetna, shares how vendors and startups consistently misunderstand what drives CISO purchasing decisions. Rather than demos and slides, CISOs evaluate partners on accessibility, empathy, and accountability frameworks. Cote emphasizes that modern security architecture must default to being locked down - requiring intentional, documented action to open access rather than relying on users to configure protections. She advocates for embedding security into products at build time, using tools like auto-protect mechanisms and continuous self-checks similar to Safari's tracker blocking. The conversation covers responsibility models in SaaS environments, the critical role of empathy in developer relations through "shift anywhere" approaches (not just shift left), and how AI compounds both threats and detection capabilities simultaneously. Cote warns that governance models for AI security remain undefined; organizations need clear inventory of AI agents, data protection frameworks, and flexible Evergreen-style governance rather than static policies. For startup founders building enterprise platforms, she stresses understanding market fit, ROI forecasting, and lessons from the dot-com era to avoid repeating accountability failures. Relevant for security leaders, enterprise platform builders, and anyone selling into Fortune 500 security operations.
SaaS providers are accountable for protecting their underlying infrastructure and databases, while customers who control application settings and configurations are accountable for those settings and the security implications of how they use the product - since vendors cannot see customer data.
Security should be enabled by default with platforms locked down at deployment; users must intentionally acknowledge and enable any access, creating accountability similar to how Safari shows users that 1,088 trackers were blocked - making protection automatic rather than relying on manual configuration.
Shift anywhere means embedding security feedback continuously throughout development and operations, not just moving it earlier; developers get real-time guidance (like Grammarly for code) rather than discovering problems after code is written, making security augmentative rather than prohibitive.
Organizations lack defined accountability partners, control frameworks, inventories of where AI is deployed, clarity on whether agents are people or code for identity purposes, and standardized ways to measure and protect AI-generated data - all of which must be decided upfront but remain flexible.
How CISOs are surviving rapid technological change, regulatory complexity, and lack of understanding from leadership - requiring them to speak multiple languages (CFO-speak, marketing-speak, technical-speak) while managing stress and burning out faster than CIOs.
Our reviewer’s read on each dimension, with quotes from the episode.
There are genuine practitioner insights - default-secure architecture, accessibility as the primary vendor-selection criterion, and the 'courage to share missed capabilities' point - but these are interspersed with significant meandering, personal anecdotes that don't land actionable points, and generic platitudes about AI governance and career development.
They also need to have courage to share with me the potential I'm missing by not paying attention of other capabilities because I cannot know everything.
we keep hearing shift left, shift left. I call it shift anywhere because you're going to shift left. But at the end of the day you still want to have a check just to make sure it stayed clean.
The 'shift anywhere' reframe, 'auto protect by default' inversion, and the Grammarly analogy for embedding security feedback are fresh and useful framings, but the overall arc - AI expands attack surface, governance models need flexibility, empathy matters - recycles familiar themes without genuinely contrarian or first-principles argument.
I call it shift anywhere because you're going to shift left. But at the end of the day you still want to have a check just to make sure it stayed clean.
It's kind of like me using Grammarly. I rather know that, uh, wordsmith spelled right when it underlines it as opposed to having a document I'm getting ready to turn in and I've got all these errors.
Mignona Cote is a genuine tier-one practitioner who held senior security roles at Bank of America during the financial crisis, NetApp when it held 50% of the world's data, GTE/Verizon, and AWS - giving her real at-scale operator credibility rather than thought-leader positioning; the slight deduction reflects her current advisory-only status meaning claims are retrospective rather than live.
I was head of security across all the consumer organization which was large, 200,000 people and it was the credit card business, it was the home loans business and it was all the banking centers everywhere, Merrill Lynch. And what was unique about it was all during the financial crisis.
I'm thinking back at NetApp where we had 50% of the world's data. How do you protect that?
The episode earns credit for named tools (ScoutSuite, Prowler, Wiz, Upwind), specific counts (200,000 employees, 600 Oracle databases, eight rules for logical security, 12 acquired cloud companies at NetApp), and dated incidents like SQL Slammer; however, large portions of the conversation remain at an abstract level without data, timelines, or dollar figures.
we'd run a tool called ScoutSuite or Prowler fast forward. We got CSPM in abundance. We've got Upwind that's doing it new, um, early company is doing it, we've got wiz
There were eight rules for security at that point in time. And one of them's three times and you're out. One of them, um, is having your eight character password
The host demonstrates some creativity - surfacing the 'empathy' callback from a prior interview and closing with 'what didn't I ask?' - but is consistently deferential, rarely probes contradictions, and frequently summarises answers back with overt validation rather than pushing for sharper specifics or productive disagreement.
Wow. I don't know if a lot of companies are thinking and onto the way you explained it
You know, it is, what you said is such a validation.
Computed from the transcript - who did the talking, and the words that came up most.
Mignona Coté, a top 10 CISO in the world with three decades of security leadership across AWS, PepsiCo, Bank of America, and Infor, reveals what vendors keep getting wrong in the first meeting, why every cloud platform is equally secure, and how the "human in the loop" governance model breaks the moment AI touches your stack.Mignona has led security through three major technology inflection points: the explosive growth of the internet at GTE and Verizon, the financial crisis at Bank of America where she ran security for 200,000 people across credit cards, home loans and Merrill Lynch, and the cloud adoption wave at AWS. Most recently as SVP and CISO at Infor, she was responsible for the security of a platform serving more than 60,000 companies across industries.
Transcribed and scored by The B2B Podcast Index.
Chirag Khanija: Today's guest is a top 10 CISO in the world and two time Dallas Orbi Award winner for the CISO title and a Hall of Fame inductee. We are talking about Mignona Corte.
Mignona Cote: You know, I'm thinking back at NetApp where we hit 50% of the world's data. How do you protect that?
Chirag Khanija: 1088 trackers were blocked by Safari. That's the fact that scares me. That there was 1088 things trying to track me that were blocking.
Mignona Cote: You know, we keep hearing shift left, shift left. I call it shift anywhere.
Chirag Khanija: First thing when somebody wakes up to make a, uh, purchase decision is not that. Let's see a demo and a presentation slide today. Nobody wakes up saying that. How does a chief Information Security officer really decide which partners is right and which partner is not right? Is there sort of a playbook that you used to have in your mind in making that kind of decisions?
Mignona Cote: Yeah. Accessibility.
Chirag Khanija: Welcome to CXO Spotlight, powered by Flywheeler. I'm your show host, Chirag Khanija and today's guest is someone really special. If you're anybody in information security or have anything to do with cyber security, you do not want to miss this. Today's guest is a top 10 CISO in the world and two time Dallas Orbee Award winner for the CISO title and a Hall of Fame inductee into the Chief Information Security Officer. We are talking about Mignona Cote and she has three decades of experience with AWS, PepsiCo, bank of America, Aetna. You named the industry and she has secured it. Welcome, Mignona. Welcome to the show.
Mignona Cote: Well, thank you, Chirag. I am so glad to be here and wow, I didn't know I was that good. Sound better than what I feel.
Chirag Khanija: We are super grateful to you to accept this and I think I'm really looking forward to this conversation because so relevant in today's time. But first things first. Congratulations on your recent Dallas Orbi award win. I think it's really special. Uh, three decades of experience and first question is on that, that, um, what does it feel after three decades of work in the security space across all industries and then to be recognized by your industry?
Mignona Cote: I feel like I'm just getting started.
Chirag Khanija: Fantastic.
Mignona Cote: Yeah. I have spent my entire life learning and I still get up at 5am and learn from 5 to 7 and then I learn from others. And so I'm still learning. I'm just still trying to see what's coming next.
Chirag Khanija: Yeah. You know, um, I find something very fascinating about your role a lot of chief information security officers are protecting one company. At times they're protecting one company where they have to play this role and protect the infrastructure and everything around that company. For you it feels very different to me. It's like a platform chief information security officer role where There are over 60,000 companies across industries using in force layers and as their supply chain, as their erp, as their cloud platform. That's very different. And how does that um, change how you look at the protection and the security?
Mignona Cote: Well, I'm just going to think my entire career has been supporting customers as well as protecting an environment. If you go back to bank of America, I was head of security across all the consumer organization which was large, 200,000 people and it was the credit card business, it was the home loans business and it was all the banking centers everywhere, Merrill Lynch. And what was unique about it was all during the financial crisis.
Chirag Khanija: Wow. Yeah.
Mignona Cote: And so, um, go back farther. I was at gte which became Verizon and we're protecting the public infrastructure on how communications happen, including the growth, explosive growth of the Internet. So I was right there in the middle of it. Now here we are, another big explosion and I'm right here in the middle of it.
Chirag Khanija: Yeah, yeah. And when you look at um, the thought process of bank of America, AWS and gd, right. And then you change that to infor or a platform based security, does that change how you secure or is that more harder to do?
Mignona Cote: Yeah. Uh, I recently shared this with some people on my team, is that I um, have a different security program everywhere I go. Largely because you've got cultures, corporate cultures. The others, you've got different technologies and you also have different skill sets. But there are different ways of technology in each one of the companies as well. And so there's a completely different way to secure the environment. Uh, like what? Years ago we had firewalls. Uh, I'm thinking of an incident I worked on across 600 Oracle databases. Well now we've got S3 buckets. We've got other types of data platforms. And I'm thinking back at NetApp where we had 50% of the world's data. How do you protect that? And so how do you embed in security into the product that goes to the customer? So each company has a different way to shift the way you think about security. So the goal is protection and what are you trying to protect?
Chirag Khanija: And I think that's where your career arc also sort of tells me that it's cross industry. One is that um, I think one of my question was about platform, but now if I switch it. You have worked across industries. What has that taught you that you can use today? You know, from the different, the playbooks of the different industry. Is that different?
Mignona Cote: Yeah. So, um, it's taught me a lot. First of all, I feel so special to have got to work in telecom at the early stages because you look at gte, Verizon and then go into northchild networks, they were like very innovative on creating the technologies that the Internet would be born from, as well as how to secure it and secure it in different ways than what we know it to be. So we often think of security as passwords, but also security as the architectural design of how this technology is implemented. So thinking about the different shifts, uh, you do take valuable lessons on how it was done, how to adapt that into a different environment. I want to say banking was the most, the tightest secured environment and that was because of the heavy regulations. And if you look at bank of America, I love these statistics of America at that time was in every other household. So the government depended on economic trend data from the bank. And we talk about like we talk about AI today at bank of America. We that was when we built our data lakes, merging credit card data and banking center data and being able to see how consumers make purchases. So I've always been tied to the economic value of the data that we've got in addition to the way we're controlling security. And I think that's what's made me successful. Successful is always interested in that economic
Chirag Khanija: value M and the business side of it, because security has a backward and forward impact on the business side of it. Right. So fast forward to now. How does your day in the life differs?
Mignona Cote: So my day now has changed tremendously. I have started working with the startup movement and with the startup movement, advising companies as they go into the security field. They're showing me what they're doing. Like I actually RSA judge startup companies and give them advice on how do you make it applicable or relevant to the environment. And just looking today like we got a lot of identity companies, we got a lot of flooding in certain areas. So how do you bubble up to the top? So one aspect is working with the startup companies and then working on other advisory roles to look at how we're going to influence and shape. So when you work at a single company, you have a large scope and you get to work with a lot of customers. But then when you move out and help influence companies that are working across a lot of customers all of a sudden I'm quote thinking big like AWS and looking at how to make a broader impact across the world on protecting the environment.
Chirag Khanija: You know I think this resonates with me so much. I'm um, we ourselves and I am building a platform. You know it's a purpose built contextual platform for IT industry with a whole intelligence layer, knowledge graph and as um, intelligent and as complex you can imagine for a lot of startups like us who are thinking about building these things um, that are going to be consumed by enterprises. Right. What is it that we are not thinking? What should we think when we plan the security?
Mignona Cote: So what are we not thinking? What we're not thinking and what we need to go back and look at is the rapid growth eras that we've gone through. Now we are at a much quicker growth era. But I went and did some research yesterday about the dot com era and the growth curve and then where all of a sudden the accountability model of all the funding set in and the investors start requiring more accountability and house growth measuring to that accountability. So let's take that lesson and on building now let's look at the investment funds and let's look at the, I want to say the ROI on that or the forecasted ROI and how we're going to fit into the marketplace because you only have a finite set number of companies that will be purchasing the software. So how are you going to fit into that and what is the market share and how are you going to get into and be the leader in that market share? And I'm sure in your business case you're thinking about those things. But we need to go back read those lessons so that we don't have the same lessons to learn over.
Chirag Khanija: Yeah and I think I want to even further fine tune that to the security lens of it. Think of it this way, that um, as a startup founder, as a builder of enterprise consumption platform, something that will be used by big enterprises, right. I am having them come to my platform, use my intelligence layer and say hey, drop your brand content here and get new content. Every day there is a new content, new things being created. These are assets which has brand data in it which needs to be protected. Right. Um, how should modern day companies that you advise um, think about building a security layer that protects enterprises.
Mignona Cote: So I think you should um, auto protect M. So what we've seen in the past is we enable the person to set their own configurations on how they want to protect the environment. You give an example, when you deploy a database you can turn on, is it publicly accessible or not? Make it not accessible. And you have to turn it on to be accessible. So when you're building out your new platforms or your new environments have it already secured, it comes default secured. And it has to be intentional on anything that would open up the security and on intentional even have kind of like when you have that thing, you go into an unhealthy website or whatever, have it that way. So reverse the thought process with it tightly secured and then opening it up with the person acknowledging it, creating accountability and then have self checks continuously running to monitor the environment. Uh, the MacBook does that. It tells you how many sites you know on Safari, how many sites have tried to or how many unhealthy pings or scans you've had against your environment. Just make it automatic.
Chirag Khanija: Yeah, 1088 trackers were blocked by Safari. That's the fact that scares me. That there was a 1088 things trying to track me that were blocked. So, uh, agreed. And how about, do you think the market has the ready tools and the right tools right now to uh, be able to do that auto protect?
Mignona Cote: Like you said, we do have the right tools. We've got to deploy the right tools correctly. And as a solution provider, I think the challenge is how to build in some of the protections yourself because it gets expensive buying lots and lots of technologies. And so while we do have the right tools, more and more tools are coming out and different ways of using the tools are coming out and even um, on the different technologies that are coming out, easier ways to use that technology. So what happens is as a practitioner we get in the cycle of continually implementing technology as opposed to having mature cycles of the technology in use where you get the true value.
Chirag Khanija: Interesting.
Mignona Cote: Just build it in.
Chirag Khanija: And let's think about these. A lot of SaaS security platforms that are out there, or the SaaS platforms that generally people are using now. Right. It's very ubiquitous. You can't say that uh, on prem or SaaS now it's just uh, permeable boundaries. Right. And when SAS comes, there's this uh, stat that I read recently which was that 88% of security breaches could be traced back to human errors. Right. And there was another one which was that 63% of um, employees inadvertently are sharing the data. They don't know that is the company data. My question is, when we start using SaaS, where does the responsibility model sit? Like whose job is to protect? Is it the enterprise job to protect? What and where does it start becoming the SaaS provider's job to protect.
Mignona Cote: So the SaaS provider is accountable to make sure the product is delivered and what they run, the underlying databases and all of that are protected. The application layer, the person who's the purchaser of that, who has control over the settings. Because remember, the provider doesn't even see the customer's data. So who's in control of the settings are accountable. So their security also is. I mean, this is going back to segregation of duties or authorization levels for transactional processes. They're going to be the ones who know what security needs to be in place.
Chirag Khanija: Hmm. Okay. All right. That reminds me, a very interesting thing about you. I was seeing one of your conversation with AWS and CrowdStrike. Um, and you mentioned a word that never comes up in security discussions ever.
Mignona Cote: Oh, no.
Chirag Khanija: Which was empathy. And I was so happy and, uh, pleasantly surprised. Um, can you share a little bit about how you, you know, um, you shared empathy as a security strategy in that discussion. Do you remember that? Can you recall that and share back some of that? Because I love that point and the placement of that word when it comes to security.
Mignona Cote: Yeah. So there's a couple reasons why start off my career as an auditor, and no one likes auditors at all. Um, I think my greatest gift has been having a natural curiosity to learn and having a southern accent, which softens me. And so people, um, gravitate towards wanting to talk to me and help me. And so I've used that to my advantage and learn what I learned over time is not to have the answers. If you have the answers, then you don't learn. And also you're not giving the other person the opportunity to share their magic. And that's where the empathy comes from, understanding what they go through on a daily basis. So let's look at the developer. We were really hard on developers. Time to market, time to market. You got to get code out really, really quick. So we take someone early career and tell them how to get something out really, really quick. Their goal is to get it out because they want to get paid. Now security comes into play and after the fact, we've got to go scan and do all these other things and you got to go back and redo some of your code. Well, that's not very empathetic at all. Instead, let's work together and say why it would be more valuable to you to know when to fix this. It's kind of like me using Grammarly. I rather know that, uh, wordsmith spelled right when it underlines it as opposed to having a document I'm getting ready to turn in and I've got all these errors. So um, it shows respect, it helps the person feel relevant and you learn and become more valuable because you have fostered the empathy from learning from these people and then they become part of the solution and instead of me being the check mark person that's bothering them.
Chirag Khanija: Wow. I don't know if a lot of companies are thinking and onto the way you explained it because the way I got it is with your Grammarly example is that the feedback loop and the check and the value of security or anything else is so embedded and so um, current that you're getting the feedback loop right away and there's a respect for your work that you're doing. It's not that somebody's going to evaluate later, you're right away getting the feedback on that and it's augmentative rather than prohibitive. So that's fantastic.
Mignona Cote: Yeah, yeah. We keep hearing shift left, shift left. I call it shift anywhere because you're going to shift left. But at the end of the day you still want to have a check just to make sure it stayed clean.
Chirag Khanija: Yeah. Right. Um, let's talk about something that no conversation is ever complete about nowadays, which is AI. Um, AI has um, compounded almost everything in terms of speed, in terms of risk and everything. And a little bit back I shared that stat of 88% of errors can be traced back to humans. Right now humans have AI. Has that increased the surface area or the threat vector multifold or how do you see that problem?
Mignona Cote: So, um, first of all, our attack surface is growing incredibly fast because of AI. But also because of AI, we can check it incredibly fast. So we've got to look at the potential of what we can do with AI to protect the environment and keep our eyes open. And you keep hearing about this human in the middle or human in the loop. And in my mind like how, how are you going to have a person be able to handle all of this? And so I see all these governance models about humans doing. Humans doing that. And we got to automate, we've got to use AI to check AI. And yes, there has to be a person somewhere with good judgment m to make sure this is presenting correctly. And I think when you use AI, if you use AI to write a paragraph, you read it, you go, oh my gosh, so something wrong with this.
Chirag Khanija: So you, I think you question the human in the loop a little bit with the scale that is coming. Right. And you said about governance model, which is sort of the favorite thing I hear in CISO conversations. Governance model. Governance model. Because they're being asked to give that back to the CIO's organization. Right. Uh, do you have a preferred governance model that you could describe?
Mignona Cote: I actually was looking this morning at an org chart for our governance model on one of our, um, security sites. Uh, so one of the things about governance models, when you hear the conversations around them, they've fail to talk about the content of the governance model. So I do think within the government's model, you've got to have, um, define your accountability partners, who's going to be accountable and what's going to be their control framework for accountability and then measuring the accountability and what's going to be the common way to measure, let's say security of AI. So right now that's not defined. The other thing is where is your AI, what's the inventory and what AI mechanisms or what AI, uh, technologies are you going to use and then how are you going to make sure that it's used correctly? So I'm trying being cautious. I'm erasing certain words because you hear safe AI or all these other things because I don't want to use words that we get into this large debate of what the words mean. So I'll try to always gravitate away from industry standard vocabulary words and go something more basic. So we want to a know where our AI agents are.
Chirag Khanija: Okay.
Mignona Cote: What is the type of AI that we're using? How do we detect something that is outside those realms? And then how do we make sure the data is protected, the data that the AI is going to use and then the data that comes, the outcomes from that data. So, um, it's some of it's basic and then I think the big thing that, you know, just, you know, around identity, a lot of, um, you know, is an agent a person or is it a piece of code? Or how are we going to create the identity program around it? So you've got to make those decisions up front, but you've got to be so flexible because it's going to change.
Chirag Khanija: So the governance model is very flexible. It's like a Lego block now, right?
Mignona Cote: Yeah. Well, when I was at, I think it was even at gg, we used to call them Evergreen, uh, back then. So it's not like it's a new concept of things changing. We've got new people with things changing that didn't grow up in the same different iterations of technological growth.
Chirag Khanija: M what's so different about this AI and security inflection point that you see. Is there any difference than what it was before?
Mignona Cote: Yeah.
Chirag Khanija: Is it?
Mignona Cote: Yeah. So it's bigger. We have more unknowns and the unknowns are hitting quickly. So for example, uh, I'm just going to think back when I worked on SQL Slammer at Northtrail Networks. That was like a big, big thing. But you only had like one big thing a year. Now it's like every day you've got, you got, you read news of big things happening. And so it's just, the influx is very, very rapid. So our minds have got to be, we have to have a resilient mindset. This having a standard stoic way of looking at something is no longer applicable.
Chirag Khanija: Um, now I want to know a little bit about the insider track. Like, I think you're on the CISO Ascent board, um, and you also advise a lot of, um, security startups and cloud startups and different kind of startups. What conversations is happening between CISOs, um, that doesn't happen in, that hasn't reached the boardroom yet. What are you all seeing as a pattern and discussing between, um, your peers that will make it to boardroom very soon?
Mignona Cote: Well, let's talk about the CISO Ascent board, for example. It was founded on the premise of CISOs don't get to clear their head. Yeah, okay, so we're all going to go clear our head in Colorado for a couple of days. And it stems from the fact if you look at the lifestyle of what we've got, um, we've got lots of regulations, we've got lots of technological change, we've got a lot of business activities we've got to do and no one seems to understand us. And with that comes a lot of stress. And so why it's not making it to the board is how's the CISO surviving the influx of rapid change continuously and the lack of being understood. Because in the midst of all this, we've got to adapt our language so that the CFO can understand what we're saying, adapt our language so the marketing person can understand. But then we've got to speak in our language so that we can talk to each other and talk to the vendors and the other technology stakeholders. So it's kind of like we spend, speak multiple languages as well. So that has not made it into the boardroom. What I am seeing is, um, CISOs are rotating quickly. I see that happening. And CIOs, um, we have some that are staying in place for a long time, but more rapidly, you see the rapid change, which is in essence kind of good because, um, if you're same role for a long, long time, it gets back to that book. What got you here won't get you there. Then we don't see that adaptability to rapid change.
Chirag Khanija: Yeah. Uh, curious that. Let's say the retreat is over. Right. When your retreat is over in Colorado and all CISOs are walking out and if you had to fill up a cliff note with three or four things that happened and you learned and you walked out with, what would that be?
Mignona Cote: Something, um, I walked out with is a CISO role.
Chirag Khanija: Yeah.
Mignona Cote: I think the most important thing that I've walked out with is that it's very important to groom your successors. So my last two roles, I've groomed the ciso, um, backfill, but is you've got to groom on everybody. You've got to be accessible. And I've talked about accessible. I just heard someone talk about, well, you know, we talk about, well, don't reach out to me on LinkedIn. Don't reach out to me here. But realistically, you've got to be, oh, there's got to be a way that you can be reached. And so LinkedIn is the only way they can find you. Or if it's through text messages or Slack channels or signal channels or email, I've got all of them. And trying to balance it, it is hard. But I want people to be able to get to me because that person, I had someone this morning reach out and ask me m. He's trying to go from being a field CISO to a CISO and ask me, since I'm transitioning from CISO to advisor, how can I coach him on going from field CISO to ciso? And I said, sure. And I allocate time when I do this. And so, um, usually Friday afternoons, because I'm driving to Louisiana to take care of my mom, are times that I know that I'm going to be able to do hands free in a car and talk freely to them, give them the time that they want and the advice they need. But I want to be able to give back to everybody that people reach out. So many people have given to me. I have had many, many mentors and I've learned from each one. I try to remember the notes they give me. And I still do my best to keep in touch with those who helped me.
Chirag Khanija: Wow. I hope this circle continues and continues. This flywheel keeps going on. That's very powerful. And I have a question for that then. Is that Think of all the peers in your industry which are far, um, early in their journey. Not C suite executives, but who are ushering into cybersecurity or in the middle of it in this whole industry security space. The space is changing so fast. Everybody thinks that will my skill be relevant in one year, two year, and they would love to hear from someone like you who sees the patterns and has systems thinking and has spent and has seen different phases come and go. What would you advise them and help them with?
Mignona Cote: Um, I advise them not to stay in one role too long.
Chirag Khanija: Uh, not to stay in one role too long. Yes.
Mignona Cote: Because you want to be adaptable. So let's talk about the security role. So security role. Yeah. You can go in through many, uh, areas. You can go in through security awareness, you can go into vulnerability management or incident response or many of those avenues. Rotate through those. I'm not saying stay there, but rotate through them. So a, you could develop the empathy, but more importantly, you can develop the skills you need. So as a security analyst, you learn an investigative skill. I learned the investigative skill early on by working for the city of Shreveport and in an audit role and also learn to talk to leaders and not be intimidated by them. So, good news, city of Shreveport. I worked for the general auditor for the city of Shreveport, and I got to go into the mayor's office and talk to the mayor, that was our CEO and getting to talk to her. And I was just in my early 20s. I learned to develop the rapport with executives early on instead of being intimidated. Quite often the early career person says, oh, well, they're busy. Well, you're busy too. They want to have, they want to hear from you. So make sure you have the right frame of reference with people. Realize they're all people. Respect them for their time, but also take advantage that they're your leader and get some time with them.
Chirag Khanija: I interpret that as, um, rotate between roles. Right. I interpret that as have mentors and coaches around you, and I interpret that as speak business language as well. Beyond the security language, what about skills in terms of tools and technologies? With AI coming in, do you think there's some emphasis that needs to be spent on learning new tools and technologies as well as.
Mignona Cote: Yes. So historically, these OS, there are certain set of CISOs that felt like they were just leaders. You can't be that. You've got to be. You've got to have some hands on, you've got to have capabilities. Everybody knows how to use their mobile device. I hope most people know how to use smart TVs. I can't figure out sometimes how ours is set up. But you're using technology in your home, your family's using technology, use it at work. Embrace when something new comes out. Learn it, explore it. So with AI, learn how to use it, know how to use it, know what value it brings, play around with it so you can get your own aha moments. When I went to aws, I went there because the cloud was taken off and I was receiving what I call audit issues on cloud and I didn't really quite understand it. So I went to work at AWS and I took the solutions architect training three times. So it click in my head to get the aha moment and I, the first time I took a lab, I can't do this. This was so long ago when I had to do these type of things. But then I started getting it. You start, you know, it's kind of like the first time you cook something and it flops. You make it a few more times like, well, I can't believe it flopped the first time.
Chirag Khanija: Yeah, uh, about aws, you have been called one of the top leaders in multi cloud security and a lot of people get a single cloud security right, but they get multi cloud very wrong. What's different about multi cloud security that you learned as a part of being in aws?
Mignona Cote: The multi cloud came when I was at AWS and we would work at our customers. So there I built an advisory business for um, executive advisory and we worked solely with aws. Google was the search engine at the time. We're gonna still use Google and I wanted to, okay, well what is it that I'm missing on this? And then we all have a little bit of flavor of Azure activities going on and then Oracle. So I've used all of them. And what you learn is there is differences in settings, there's differences in customer preferences and you've got to be that's going back to the empathy and adaptability to the different corporate um, cultures on being able to do that. So going into NetApp gave me that opportunity because we were taking stores from an on premise environment and then adapting it to the different cloud environments. So that gave me the opportunity to be at the end, um, onset of that activity. And then same time we had bought 12 different cloud companies to provide security on it. So you look at um, AWS, we'd run a tool called ScoutSuite or Prowler fast forward. We got CSPM in abundance. We've got Upwind that's doing it new, um, early company is doing it, we've got wiz, we've got other companies that are doing it. But you look at what are those holes and how it can get it. So you go to the fundamental what are you trying to protect? But now what technology is available and how does the technology work across multiple cloud environments?
Chirag Khanija: Very interesting. Um, I want to switch my role a little bit and say this, that because I find this very interesting, that how you understand what's the right way to go about doing this for multi cloud and for different things. Imagine me being uh, a uh, CIO and a decision maker on deciding different cloud platforms or startups or all the things that I'm trying to buy. What are the questions, uh, when I'm trying to make a decision on buying a platform or a product that I'm not asking from security perspective that I should ask.
Mignona Cote: So, um, if you're getting ready to make a purchase and you want to um, what should I care about? The first question I always get asked, is it secure? Because the. I'm learning that Quite often the CIOs are dependent on their teams to tell them, but then they get asked by the board, is it secure? So you've got to have your answer, is it secure? And all of them are secure. It's based on how you configure and set them up. So is there a difference or a preference? I literally had this question. I was talking to my former boss from AWS on the way over here. We were talking about the Unix versus Microsoft days and um, how security started from that era. There's differences in the security, but what you're looking for is the ease of securing the environment and the flexibility of that cloud environment for the solutions that you want to provide. There's not a wrong or right answer on that because it's based on what you want to do. It's like the difference between using a Microsoft or a Mac book.
Chirag Khanija: Correct.
Mignona Cote: It's your preferences.
Chirag Khanija: Correct. Um, you played a role, uh, at different large companies. PepsiCo, Aetna. Ah. And different companies which used to buy security services, not just apply security services. Right. Um, so you must have dealt with hundreds of security partners and vendors and things like that. Now I want to change the perspective back to your role as a CISO and ask that how does a Chief Information Security Officer really decides which partners is right and which partner is not right? Is there sort of a playbook that you used to have in your mind in making that kind of decisions?
Mignona Cote: Yeah, accessibility.
Chirag Khanija: Accessibility, yeah.
Mignona Cote: So I think back, yeah, um, first Time I made a purchase with at North Hill Networks and I recall and if the guy's listening, he'll just laugh. But I was making a purchase and the account replacement shared with me that I have to go through her to talk to this systems or the solutions engineer. I always gravitate towards the solutions engineer because they usually solve the problems that you need on how to set something up and make it work. And that's why I say accessibility. Accessibility to being able to get your problem resolved quickly. Because there's not going to be a perfect solution. So you've got to have that commitment, be able to, um, I guess get it set. I also have, like, I call him my favorite account rep. So I have, um, this one account rep and I think the whole industry's heard me talk about him from CrowdStrike. I will reach out to him and like one day I saw some chatter on signal. I reached out to him, I said, there's some chatter on signal. He went and got a bridge set up at his company and had it fixed. And he wasn't even working with me. But he's got that customer service accessibility gift.
Chirag Khanija: Wow. And if, uh, IT company or a cybersecurity provider is listening this, what should the build in their sales teams? Account teams that they can do this and be better at what they do today.
Mignona Cote: So you're asking what the account teams can do in the vendor companies?
Chirag Khanija: Yeah. What can they do, uh, to do better, like to sell more, to be able to. More relevant to people like you. What can they do better?
Mignona Cote: I think there's two things, and you'll see different answers from CISOs. One of them, one of the answers is they need to know my environment and know what's going on. I have a kind of an alternate answer. They also need to have courage to share with me the potential I'm missing by not paying attention of other capabilities because I cannot know everything. But they see it from a broader scope of other customers. So they've got to bring to the table. This would work in your environment. These other things will solve these problems too. But have the courage and be able to do it in a clear and concise way without having to necessarily watch a demo and definitely don't bring 10 or 15 people to a meeting. When you meet with an executive, have one or two people so they can ask questions and then get their answers done quickly.
Chirag Khanija: Yeah. You know, it is, what you said is such a validation. It's a funny story. It's such a validation of I, uh, was at a Keynote and talking to, I think, 80 or 85 CEOs from IT and tech companies. And they asked me, everybody had the same question, that how should we present to chief, uh, C suite leaders at enterprise tech companies like yourself and, uh, what should go in our presentation? And I said, nothing. Nothing should go in your presentation. Your presentation should be the second thing. The first thing is reframing that what you just said, that they're not there to see your demo. The first thing when somebody wakes up to make a, uh, purchase decision is not that, let's see a demo and a presentation slide today. Nobody wakes up saying that. They are not saying it, but they want to be educated on what is your experience in implementing it of 50 times. Tell me the gaps that exist today and tell me the problem with the current options that I have, because that educates them on making the right decision. And that's what, um, you said. So it reframed the whole thing for me and just validated that right there.
Mignona Cote: Well, let me give you a story. This just happened last night. So a CIO reached out to me and she had a data question. And she goes, can you talk? And I couldn't find my iPhone. I had left it in the car. I said, sure, but you have to call me through my computer. So we're like, talking on my computer to her. And she had a data question. She was preparing for a board presentation this morning.
Chirag Khanija: Okay.
Mignona Cote: And her question, she had, uh, kind of a complicated question. I said, I think I've got the answer. And it's called digital watermarking, but let me do some research. And I found it. And I said, look, I've got the right person. They have that capability. And so I sent a text message to the CEO of that company, and it was Ciara. And he instantly called her up. She sent me a message this morning thanking me that she's ready for her board presentation, that she's comfortable. That is what it's all about. He did not bring a presentation, a slide deck or anything. He got on the phone late last night and talked her through what she was trying to figure out. And she felt very, very comfortable. And it's all around digital watermarking.
Chirag Khanija: Super, super. Um, from the perspective of where you're now in your career journey and as you're advising different startups on their journey, um, what are you seeing? The pattern, what kind of excites you about what you see in these startups that they're doing?
Mignona Cote: Oh, my gosh. They're not inhibited by anything that's what I see is, um, working around the clock, uh, totally enthralled at the capabilities of what can be done. And they're not inhibited with the way we always done things. That's what I like. I'm seeing new ways to solve the problems. And that was one of the things, um, in the CISO role, you're kind of solving yesterday's problems. And someone shared with me the other day, he goes, miyana, you're solving yesterday's problems. And I want to solve tomorrow's problems. I want to be able to see. And that's what I bring to the table, is I can just connect the dots and see where we're going with it. And that's because I have been at the onset of every single technological change, even the beginning of laptops. So, uh, my dad taught electronics. I grew up in the environment. But they're not looking at how it's done. They're instead looking at the potential of what we can bring. Big difference.
Chirag Khanija: And what feels different about now in last three decades that you have seen every threat come, every security phase come. Blockchain came, cloud came, dot com came. Now it's AI. Does it feel different?
Mignona Cote: Yeah, well, it seems fast. And I have to tell you, I'm very disappointed on, um, my lack of investments in the right companies.
Chirag Khanija: Yeah, you mean you should have made the right investment.
Mignona Cote: Yeah, well, yeah, I look back and, uh, I was looking at something and I thought, one startup company sold to another big company. And I said I was doing some work with that company. Why didn't I even know to invest in that company? So, yeah, good message.
Chirag Khanija: Invest in startups, guys. Very nice. Okay, um, I want to know. This is generally my end question, but I do have a follow up after this as well. Uh, which is that imagine two years from now or three years from now, what is it that excites you most about this industry?
Mignona Cote: Two years from now?
Chirag Khanija: Yes. Okay.
Mignona Cote: I'm just going to hypothesize that the role is going to be completely different, that I do not have to do all this stuff because we have AI doing it for us. And instead we become thought leaders of what happens next. And so what happens next would be in the forms of newer technologies, as opposed to continuously worried about if Iran is going to attack us, Russia is going to attack us, or if someone inside is going to steal some Social Security numbers.
Chirag Khanija: Very interesting. Well, my last question is something new I thought, when I was talking to you. Um, is that there's so much wealth of information and an Experience that you have at many times. I would not even know the right question. What is it that I did not ask from you that I should have asked?
Mignona Cote: Well, um, I guess, um, the question is, uh, why do I have so many books? Oh, yeah, yeah. So I have an office in Louisiana, a home office in Louisiana. I have all the books from all the different technological changes. They represent who I am. But more importantly, like, I have a textbook on strategy that when in grad school, I kind of. I don't have photographic memory, but I can kind of remember the SWOT analysis is around like the middle of the book and so I can go look it up. I have my Six Sigma for Dummies book. Every time I tell someone, it's like, no, the FEMA is really the most thought provoking way to understand risk. And the other day I found, um, a book on digital security and data security from 2006. And I looked and it had, um, Eric Schmidt signed it and he's now passed away. And I was like, well, I've got to look at this book, see what we thought data security was back then as opposed to what it is right now. However, having said that, going back to GTE in the late 1990s, data security was classification. And you talk about it today. Classification. I was like, wait, that's like decades of the same subject.
Chirag Khanija: Deja vu. Yeah.
Mignona Cote: Yeah.
Chirag Khanija: And interestingly, I remember when we were talking before starting the podcast was it wasn't even information security at that point of time. This was logical security.
Mignona Cote: It was logical security. I have still, um, I still have them. They're in print copy. It's called gted. The Data center, um, GT Data Center. And there is like that computer paper on how to set up logical security. There were eight rules for security at that point in time. And one of them's three times and you're out. One of them, um, is having your eight character password and one of them is your computer screen times out. And so that was the beginning of security for me. And we called it logical security.
Chirag Khanija: Awesome. Awesome. Well, uh, how many books do you have?
Mignona Cote: A lot. I can't count. And again, it goes back, um, worse than that. My husband is from Latin America and so we have his calculus book and it's got yellow pages in it, but I have books from IBM, um, days.
Chirag Khanija: Wow. Yeah.
Mignona Cote: So when we learned ACF 2, I learned ACF 2 Top Secret and RAC F. So I have those books. I have, um, I think it's called the IMS database. So it was before we had relational databases. I had to do an audit of that at, um, data center in Tampa where GTE could figure out how to audit. So I went and got the installation guide and read, okay, well, if I look at how I install this database, then I'll know what needs to be turned on and off to install it, and that will be my security.
Chirag Khanija: Yeah, yeah.
Mignona Cote: See, I just kind of created it.
Chirag Khanija: Yeah. Awesome. Awesome. Well, we share a lot in common. I'm an xibmer. Xibmer.
Mignona Cote: You know, so, you know, of IBM stuff then.
Chirag Khanija: Yeah. Awesome. Yeah. Thank you so much. I think this was one of the, uh, best conversation where we went through a lot, but we went into the depth as well. That should help a lot of people. And Vinora, thank you so much. And also the best of luck for a lot of advisory roles coming up. And, uh, thank you for accepting our offer.
Mignona Cote: Well, delighted to be here. And I just want to grow the next wave of talent so we can have a better tomorrow.
Chirag Khanija: Awesome. Let's do it together. Thank you.
Mignona Cote: Okay. Thank you.
Chirag Khanija: Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.