The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Cyber Leaders
Cyber Leaders artwork

Your CISO is Now Your Chief Trust Officer with Jitender Arora

Cyber Leaders · 2026-05-15 · 43 min

0:00--:--

Key moments - from our scoring

Substance score

62 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber16 / 20
Specificity & Evidence10 / 20
Conversational Craft13 / 20

Jitender Arora's journey from learning Unix before English in India to becoming a top-ranked CISO in the UK cybersecurity establishment illustrates how individual resilience shapes leadership in an emerging profession. His core argument is that cybersecurity has shifted from a technical infrastructure role to a strategic trust function - what he calls the Chief Trust Officer paradigm. This reflects broader changes in how organizations operate (cloud, remote work, distributed systems) and how security intersects with every business decision. Arora emphasizes that cybersecurity remains a young, undefined profession where scope creep is inevitable: when organizations don't know who owns emerging risks (AI governance, privacy, ethics), they default to the CISO. This creates unsustainable pressure. He advocates reframing stress as a biological tool for achievement rather than purely negative, and calls for CISOs to develop personal playbooks for recognizing stress signals and preventing burnout rather than waiting for catastrophic failure. His message resonates with security leaders managing mounting expectations while protecting their teams and organizations from both external threats and internal collapse.

Key takeaways

  • →The CISO role has evolved into Chief Trust Officer, encompassing organizational trust protection and societal defense rather than purely technical system security.
  • →Cybersecurity's undefined professional boundaries create de facto scope creep, where CISOs become default decision-makers for emerging technology risks (AI, privacy, ethics) that extend beyond traditional security.
  • →Burnout in cybersecurity stems not from single events but from creeping stress combined with always-on systems and blurred work-life boundaries, requiring proactive stress-navigation playbooks rather than reactive crisis management.
  • →Technology shifts (on-prem to cloud, office to remote work, new platforms like AI) have accelerated faster than the profession's ability to define its own role and limits.
  • →Security leaders must model understanding stress as a positive biological tool for achievement while building supporting ecosystems to enable teams to meet demands without burnout.

In this episode

  1. 1Introduction to Jitender Arora and CISO Evolution
  2. 2Jitender's Journey from India to UK Cybersecurity Leadership
  3. 3Early Career in Technical Infrastructure and Firewall Building
  4. 4Defining the CISO Role as Chief Trust Officer
  5. 5Rapid Technology Changes and Blurred Role Boundaries
  6. 6Burnout, Stress Management, and Human Dimensions of Cybersecurity

Mentioned

Jitender AroraKieran MartinJames LyneSANSDeloitteZolandoFlorence MorteCheckpointJuniperCiscoSun SolarisNational Cybersecurity Centre

Guests

Jitender Arora

Topics in this episode

Chief Trust OfficerCISO role evolutionCybersecurity burnout and stress managementProfessional scope creepAI governance and CISO responsibilityTrust and organizational resilienceCloud and remote work transitionsUnix and Solaris systemsCheckpoint firewallsBoundary lines in cybersecurity profession

Questions this episode answers

How is the CISO role changing, and what does Jitender Arora mean by Chief Trust Officer?

Arora argues the CISO role has transitioned from protecting systems to protecting organizational trust and societal confidence. CISOs are now chief trust officers defending not just technology but the people, families, and stakeholders affected by cyber incidents - similar to firefighters or defense forces protecting society at large.

Why do CISOs face burnout despite the importance of their role?

Burnout occurs because cybersecurity systems run 24/7, incidents happen at worst times (holidays, weekends), work-life boundaries have blurred, and stress creeps in gradually without recognition. CISOs must develop personal playbooks to recognize stress signals and navigate pressure proactively rather than waiting for collapse.

What causes scope creep in the CISO role, and why do CISOs become decision-makers for non-security issues?

The cybersecurity profession remains young with undefined boundaries, so when organizations face new technology risks (AI governance, privacy, ethics) where ownership is unclear, they default to asking the CISO. This makes cyber the de facto place for answers on technology safety and risk across the entire business.

What does Jitender Arora say about learning technical skills before speaking English, and how did that shape his career?

Arora taught himself Unix systems during university while learning English as a non-native speaker, initially unable to speak the language confidently. This early technical foundation combined with overcoming language barriers built the resilience and determination that later enabled him to build a global cybersecurity career.

How should CISOs reframe stress and burnout prevention?

Rather than viewing stress as purely negative, Arora argues stress is a biological tool designed to help humans achieve difficult things - like athletes or mountain climbers harnessing it productively. The key is learning to recognize body signals, maintaining work-life boundaries, and building supporting ecosystems so teams can meet demands without breakdown.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains some substantive ideas about the CISO role evolution, burnout management, and board communication, but is heavily padded with personal anecdotes, repetitive philosophical reframing (trust, mission language), and lengthy throat-clearing between hosts. Novel claims are present but diluted by filler.

CISO role has transitioned into what I call chief trust officer
AI is going to amplify either good practices or bad practices

Originality

11 / 20

The 'chief trust officer' framing is a modest repackaging of existing CISO conversations. The board communication advice (pre-read materials, 1-1s, link to strategy) is standard playbook. The stress/burnout discussion, while valuable, relies heavily on generic wellness metaphors (skiing, Zen, firefighters) rather than original frameworks or contrarian thinking.

CISO role has transitioned into what I call chief trust officer
think of ourselves as a noble profession, just like you have firefighters, you have police

Guest Caliber

16 / 20

Jitendra Arora is genuinely senior - partner CISO at Deloitte with responsibility across North/South Europe and global strategy, named #1 CISO in CISO Awards 2021, 20+ year veteran with operational depth. His actual role and scope justify the invite; he's not a thought-leader consultant but someone running cyber at enterprise scale across regions and board-facing.

partner and CISO for Deloitte North and South Europe and also serves as global deputy CISO
In 2021, he was named number one CISO in the CISO 30 CISO Awards

Specificity & Evidence

10 / 20

The episode is notably light on concrete examples. Personal stories (selling shirts, early Solaris days, skiing incident) are specific but anecdotal. Discussion of board communication mentions a sticky-note tactic and inherited deck, but lacks named companies, metrics, or case studies. AI section discusses amplification generically without specific breach examples or data points. BAU hygiene is repeated without quantified payoff.

I put a sticky note on that deck. And when I next time I went to the leadership team meeting, I said, What is this?
AI is going to amplify either good practices or bad practices

Conversational Craft

13 / 20

The hosts ask reasonable setup questions and signal genuine interest, but follow-ups are mostly permissive and affirming rather than challenging. When Jitendra makes sweeping claims ('people don't understand stress' or 'burnout comes from blurred lines'), hosts don't push back with counter-evidence or ask for specifics. The tone is conversational warmth over productive tension. One solid follow-up: 'how do you get to grips with all of this?' on AI and basics, but mostly soft.

What do you think is the biggest challenge for people adapting to all of those things together?
So how do you get to grips with all of this? And what hope is there for us sorting out all this newfangled AI threat stuff if we can't fix the basics?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber37cybersecurity23different19technology19ciso18profession17board15kieran13security13journey13organization13means13podcast12back12anyway12leaders12

Episode notes

In this episode, Ciaran and James sit down with Jitender Arora, Partner and CISO for Deloitte North and South Europe, to discuss the human side of cyber leadership and how the role is changing. As a veteran of the industry, Jitender shares his perspective on burnout and supporting cyber talent, how the CISO role is shifting towards trust, and how organisations can prepare for AI. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org

Full transcript

43 min

Transcribed and scored by The B2B Podcast Index.

Welcome to Cyberleaders with me, Kieran Martin, and me, James Lyne. Now we're both from Sands who are kindly backing this podcast. I myself am a techie, a massive geek, and I've spent my life chasing cybercriminals around the internet. And are you a massive geek, James?

I mean, we know you are, but we are starting this podcast recording late because you couldn't quite cope with a software update, but never mind. Writing an exploit easy, selecting a microphone difficult, as they say. I'm sure that's a saying. So maybe the geek gap narrows a little bit today, because I was fine.

You can get me back next time. Anyway, I'm not so much of a techie, although my software updates are fine and they're up to date. Patch kids, I dealt with cybersecurity policy and operations in government and set up the National Cybersecurity Centre. But together, James and I are now trying to unpack the weird, wacky, wired and wireless world of tech security and all the complicated things that it involves.

That's right, Kieran. This podcast is a voice for security leaders. We want CISOs, security directors and leaders, and frankly everyone beyond to build up their knowledge of what works, what doesn't, and ultimately to secure their organizations more comprehensively and quickly. Anyway, James, maybe there was a location issue with the software update of yours.

But anyway, are you back from France yet? Where are you? I actually am still in France, although I am imminently to be uh over in the US and uh why do you ask Idiot? Just being nosy.

I'm just hurt. Not your CEO. You've turned off share my location with me. Can't keep track of you anymore.

It's just horrible. Listeners, for the avoidance of doubt, Kieran has just completely made that up, except for the part where he has a great longing to understand where I am. That's probably true. I did just completely make that up, and I don't have a great longing for where you are.

Anyway, off you go to America. So why do you want to know exactly? Well, I was hoping that you might say in London, because I was in London yesterday, but not today. I'm at home.

I wanted to do a London gag to introduce our excellent guest. Well, I can't help you there, but why don't you do your London gag anyway? Oh, okay. I'm in an indulgent mood today.

Yes, boss, I'm very excited because I've been working on this for ages. What do they say about London buses, James? Uh, that you wait for ages and then two come along at once. Exactly.

Boom. And this season is turning out to be the London Buses of Cyberleaders podcasts. Because you wait ages to get a discussion with world-class award-winning sisters, and then two come along, not quite at once, but in the same series. I see what you did there.

Boom boom. Very nice, Kieran, very nice. Boom boom. So earlier in the series, we were blessed with the wonderful Florence Morte of Zolando and her tales of stopping her firm's clothes buying chatbot from telling her customers how to pick the right clothes to commit and then get away with serious crime.

Yeah, that was absolutely brilliant. How could one forget that? Well, that's not just the only reason you can't forget that one. You can't forget that one because that's the one where we spent most of the time talking about your recent appointment as CEO of Sans.

Did I mention that? Anyone not here yet that James has been appointed as CEO of Sans? It did feel a little bit self-indulgent. Maybe that's why I'm feeling so indulgent today.

It's a bit of reciprocity. But anyway, look, stop it. Let's focus. Tell us who the next bus, I mean um, world-class CISO is.

Well, I'm very focused, James, so why don't you do it? Prove that you're on it today after all this. Ha, fine. All right.

Well, we really are getting some absolutely brilliant cyberleaders on the show this season. And today is one of the best. We're thrilled to invite onto the show someone at the very top of the cyber defense profession and a 20 plus year veteran of the industry. He's a computer science graduate with a master's in consultancy and management.

At the start of his career, and I'm gonna love exploring this bit, I'll tell you now, was highly technical, building firewalls, proxy servers, hardening Unix servers, presumably eating pizza whilst typing commands with his elbows, as we all did in those days. And then he pivoted towards security and has run his own firm and helped hundreds of different partners with all sorts of different cybersecurity problems. He's currently partner and CISO for Deloitte North and South Europe and also serves as global deputy CISO with responsibility for cybersecurity strategy across the firm.

If he wasn't busy enough with the first part, his expertise spans cybersecurity, cyber resilience, technology risk, operational resilience, and operational risk with a strong emphasis on CXO and board level relationships. I know we're going to ask you about that. That's great practice for our listeners right there. And in 2021, he was named number one CISO in the CISO 30 CISO Awards.

Terrific speaker, and is helpfully outspoken about the human dimension of cybersecurity, the issues of capacity and burnout and skills, other long-standing challenges of this profession. He is, of course, the legendary Jetenda or JIT, as he is sometimes known. Aurora. Welcome, Gitenda.

Thank you for having me. I really appreciate it. You are extremely welcome. And it's good to be here in such an esteemed company, to be honest.

Um, that was mouthful. That was really mouthful. Who gave you all that introduction? Oh, you don't want to know.

The same people that disrupt my location sharing services for Kieran, I think, Gitenda. That's the secret to it. I think it's what we call the sans small language model, otherwise known as me. But there we are.

Now, look, thank you so much for coming. It's a real pleasure and privilege to have you on. It's genuinely great to get so many good cyber leaders on. We want to hear about frontline experience and developments in the industry and so forth, and you're just ideally placed to do that.

But we always start with your story into this business. So just interested, you have crossed continents to become a big figure in UK cybersecurity. I even read that English isn't your first language, which you could have fooled me. Me too.

You've been around as a large and important figure in the UK cyber scene for quite a while. But how did you get here? Tell us about your journey into cybersecurity and the UK cybersecurity. How did you get started and what was then a relatively new profession?

What drew you into all of this? I always say before the role, I'm always interested to understand the person behind the role because the individual, the human is a lot more important. So just to give you my journey. Again, born and brought up in India, and you're right, English was not my first language.

It's actually still not my first language. Wow. I studied in a Hindi medium school, uh, couldn't speak English until university. Really?

So it has been a journey. Absolutely. It has been a journey. You didn't speak at all.

You didn't speak English? No. I couldn't speak. I used to try to listen very carefully and lose what people are saying when I was having the conversation.

So yeah. I just realized something. J does that mean that you learn, you know, Linux and Unix command line? I was gonna ask the same thing.

Before English. So technically, your cybersecurity skills predate your English skills. Yeah, I mean I started working on Unix um when and some basically specifics during the university days. At the same time, I was picking up English because I think I could read.

Writing was a bit difficult, but speaking was very, very hard. Very hard. It was, I think I think one of the biggest challenges I think I had in terms of trying to learn and build my confidence to be able to speak English. So, but again, that's the computer science graduate.

I think I found my love for technology. I was somehow good at it. Mathematics was always my gig. I was very good in math and maths.

And then when I started my career, in fact, my first job was not a techie. Okay. When I finished my engineering, I couldn't get the job. That was a time dot-com bubble burst.

So I was actually selling shirts and trousers door to door with a big backpack, a very skinny eye on my back. And then in the morning, there is an area which is given to you with some targets. Wow. And you go door to door.

And where were you doing this? India. It was in India. Wow.

And that was a time my burned up subcourage to ask for my dad for a little bit more money to do a diploma in advanced computing, which was a very intense six months course where you learn coding, databases, Java, C C, almost everything. So took my engineering to a next level. And then after I did that six months, basically I got my first job in technology infrastructure services in a small company where they were training us on the Sun Solaris with the hope of that at time you go to US.

And guess what? After one year, the company closed down. I was made redundant. Of course.

So lost the job. And that's quite the journey. Quite a journey, exactly. So after that, finally found a job in one of the big Indian SI companies and then ended up building server farms, you know, Unix administration.

And that's where at one point somebody said, Hey, is we are starting a new security practice. Something called as firewalls, something called as checkpoint. And they asked us, somebody would like to join AirSight. Why not?

I had no idea, by the way. Wow. Um, but then learned to become the building the checkpoint firewalls on Sun Solaris, then on the Nokia devices, and then Netscreen, Juniper, Cisco Pix, you know, proxy, DNS. You talk about all this.

Yeah, it's been a beautiful journey. I always say I'm very privileged that maybe some guardian angels have shown me the path to be here. Incredible. I have an alternative interpretation, which is frankly, anyone who managed to suffer their way through the early days of Solaris, frankly, deserved some grace for the rest of their career.

It was fun configuring those systems in the early days, wasn't it? Different threading models and ZFS file system. And I will say though, Solaris D-Trace was nice. Oh, some machines were beautiful.

Come on, some microsystem machines go so on so that's about them a beautiful piece of machineries. They used to have those T2000s and they didn't get the Terminator reference. Like surely someone did that on purpose. Yeah, but there was something beautiful about it.

You know, you order the servers, you wait for them, they come in the boxes, you take them out of the boxes, put them into the cages, you know, screw them up, plug in all the cables, configure them from the ground up. I miss those days. Beautiful. Those were elegant times.

Although I did once have to install JSMS on Solaris and that. Well, anyway, Kieran, we should probably move on to something else. Otherwise, I might start weeping in anger. I think we're getting geeky here, so.

Yes. I was enjoying Geek Fight. But anyway, let me just ask, I'm just fascinated by the backstory. So one more quick thing on that, uh Jajindra.

When you finally broke through in Western companies and so forth, how much barriers were there for someone coming from another continent when you weren't completely confident in the language yet and so forth? You know, how much did you feel like an outsider in this profession and how long did it take you to settle in? Oh my God. See, 2007, when we decided to come to UK, uh-huh.

It was me, my wife, two and a half-year-old son, one-year-old son, four suitcases, three thousand two hundred pounds of lifetime saving to build a dream, to look for a job. One of my very good friends from college days, so we used to sleep in his living room on the air mattress and making sure that we get up clear in the room before they get up. And you don't realize money runs out very, very quickly. Yeah.

So you just basically try to find a job and then get to the first job as quickly as you can. And remember that that was a time English was still I was not still very confident about it. So I got my first job in one of the large retail banks in UK. And that's when my journey began in 2007.

Here. It's been 19 years since then now. So basically, I will go to the office, try not to make an eye contact with anybody, go and sit my desk in a corner. I will always look for a corner desk.

Right. And then open my machine, get the tickets, do my risk assessments, reviews, exception to policy, whatever. And with the hope that, you know, just do my job as quickly as I can and as best as I can. Right.

And that's where my journey began. And I'm just thinking about the chronology of that and the sector you're in. It's also the time when the global financial system starts collapsing. So you really picture my.

I came here and it happened. Exactly. Exactly. So ideal.

I think this is something with me that you know I keep having some interesting challenges. So hopefully this fit doesn't befall the Sans Cyberleaders podcast after something goes wrong, Kieran. I'm the reason. Are you suggesting, Kieran, that Jit joins the podcast and then there's a global recession as a result of this?

Important that we are, there's less systemic risk to the world from something happens to us. Butterfly effect. Exactly. Well, who knows?

Well, it's just an extraordinary story of one of the most incredible stories we've had of people's journeys into the profession, as Jane was saying, learning Linux before you learnt English and so forth, then following that dream over to the UK. So I can see why, to get into the substance of some of the things we really want to talk to you about. I can see why you're so passionate about the human side of cybersecurity. So let's be a bit introspective, you know.

Let's be geeky in a different way, sort of cyber professionally geeky now that uh having crashed through all those barriers, you are very much a pivotal figure in CISO world and in the cybersecurity community. So you've lots of ideas and thoughts about the role of CISOs and some of the current issues around that. To you, what is a CISO and how is it changing? Oh wow, that's a very interesting question.

There's a jokey part of it I always tell some people when I mean CISO stands for career is so over. I've never heard that one before. That's very good. Yeah, it's um I think if I just follow my journey, right?

It's it is a very technical area, you know, systems, technology. But just look at the landscape, how it has shifted from on-prem data centers to cloud, and nobody knew. You know, you can work from home and you can completely have the whole organization running where you do not have any real estate. So I think things have changed and evolved quite a lot.

While it was about protecting systems and people, organizations, I think CISO role has transitioned into what I call chief trust officer. Right. Because end of the day, this is the ethos with which I operate. Working in cybersecurity is not a job.

It's not a role, it's a mission every day. Because what you're really doing is you are protecting, you are defending not just the organization, but colleagues who are working in the organization, families of those colleagues. Because any organization that comes goes through a big cyber event, it's a moment of distress that is felt everywhere. And that's why this role I think is very profound.

I think of ourselves as a noble profession, just like you have firefighters, you have police, you have defense forces. So we are protecting not just the organization and the people, but we are really protecting the trust that is established in the organization and the society at large, because I like to call ourselves, included both of you, community of defenders. We are essentially a community of defenders who are protecting our societies and nations at large. I do like that because coming out of government and even in government, I remember noticing that a lot of private sector cyber people really had a sense of motivation that often public officials allowed themselves, they allowed themselves to feel they were doing something special.

But I think cyber defenders do have that motivation. Firefighters are a really good analogy. They feel like they're doing something that really helps people. Anyway, sorry to cut across you, James.

No, no, I I couldn't agree more. You preached the converted on, you know, those who have a respective mission in this area. I want to underline the other thing you said as well, though, because there has been a lot of evolution very quickly. I mean, we all know cyber criminal tactics evolve and put pressure on us.

Yes. You listed a few of many transatlantic shifts in technology use cases. And of course, they're within cybersecurity, but we're also subject to all of the ones around us in business as well. A complete change in the operating model of how people work and how they use technology.

And of course, we'll get back to AI shortly, because there's another transatlantic shift right there. But there's also been this evolution of expectation of security leaders. I mean, when you and I started, you were quite literally in the corner of the IT room finding that corner desk. But that's kind of where security was too.

And now it's at, you know, in senior leadership teams connected to the board. And I just I love that notion you described of the chief trust officer that comes out of this. So it's all these different pressures that have culminated into a really rapid change for cybersecurity professionals. What do you think is the biggest challenge for people adapting to all of those things together?

See, the thing is, I think technology has changed the way we live, the way we connect, the way we work, we provide services, consume services, everything. And it's and it's evolving very rapidly. And whether people accept it or not, cyber is still a very, very young profession. We are still trying to figure it out.

What does this profession is supposed to do? Where are the boundary lines? And maybe there are no boundary lines at all. And also, when nobody knows the answer, cyber effectively becomes a de facto place where you go and get the answer.

Means even if you look at the AI when it came along. I'm sure every CISO had the same conversation, which is about what do we do about the AI. AI is a lot bigger than cyber. There's a confidentiality aspect with a legal aspect to it, there are privacy aspect to it, ethics aspect to it.

So there is a lot more to unpack in these areas. But eventually, CISO role or the cybersecurity function becomes a de facto place where when you do not know the answer, that's the place you go and ask anything to do with the technology. Because somehow cyber is also being associated with the safety aspect to it. How can we safely use technology in the organization for whatever purpose basically they are using it for?

So I think the biggest challenge for me is there are boundary lines of the cyber function that are still not that clear. They're blurred, and cyber means different to a different person. An engineer, it means different, a developer, it means different. A normal practitioner makes different for a board member, and the exact one means different.

And then you apply the industry context, which is a very different context in terms of healthcare, very difference in aviation, and very difference in banking, financial services. I think it's still a new profession. Boundary lines are not clear, scope is not clear, and whether we accept it or not, it's a huge sense of accountability, responsibility that comes along with it. There most certainly is.

It's woven into the fabric of almost every other part of a business. And as you pointed out earlier, the human dimensions, people's lives, people's jobs, people's mortgages. Yeah. So there is great responsibility to it.

It's a young profession. And then, of course, you said the lines haven't settled yet. Of course, all those technology trends and change in business practices are forcing changes as well. So we're trying to kind of define it a little bit on the fly as it's moving around us.

But I think that this point you make about the being the catch all is really fascinating. And I think this builds into something I wanted to ask you about that I know you've been very kind of positively outspoken on. You've been saying over a number of years around the kind of risk of burnout and strain in the profession. And there's an obvious tie between these massive technology trends, a lack of definition, and being a catch-all to everything across a business and the pressure of accountability.

So can you talk about these trends? Do you think things are getting better or worse? Where are we in those challenges? First of all, I think there is a human side to it.

I think there is cyber as a profession is very demanding. That's where the stress comes along. But as a society, as the way we live and work, I think the lines have been blurred where the work stops, where your personal life begins, everything is intertwined very nicely in a way. So people talk about stress in a very negative way because we are not really understanding the definition of stress.

It's a very simple biological and chemical phenomenon which is designed as part of the human ecosystem for us to achieve things which we possibly is difficult. So I went for skiing last year in February. Trust me, I thought working in cyber is hard. Gosh, when I put the ski boots on, walking was hard.

Then when I went onto the ski slope, I was hanging on for my life. I thought, you know, cyber is so easy. You know, doing the skiing was harder. You'd much rather configure a Solaris than go skiing.

Yeah, I mean, so when that was a very stressful environment. But when you harness the power of the stress and you understand how that positive stress we talk about, you achieve something much, much bigger. Whether athletes, you know, people who are going to climb the Everest, lots of other things that you think about. It's basically we allow, as long as you know how to harness the power of the stress, you can achieve great things.

The problem is the lines have become blurred because we are not in tune with our mind and body. So we do not know. Body's giving us signals, we're not taking care of them. And then when you try to combine that in the cyberspace, I think there is cyber as a profession is such that it's always on.

Systems are always on. Things go wrong at the wrong time. Christmas, holiday period, evenings. Most cyber professionals will tell you that, you know, Friday is a curse.

Sometimes things go right on exactly Friday, 4 o'clock, 5 p.m., or when you're going on the Christmas holiday. So it's very difficult for people to switch off, which creates this kind of a challenge of a burnout.

Burnout is not one big event that happens, it happens because stress is kind of creeping into your life, into your work, profession, boundary lines are getting blurried, and you're not paying attention to it. And then one event basically breaks the camel's back. There is a lot more to unpack than I think maybe we'll have time because I talk about this very extensively around how do we spot the signals of stress? I have a playbook that I have created for myself.

And how do you prevent that burnout? Because I believe it's the concept of navigating the stress and avoiding the burnout, which we need to practice. But again, as an industry, it is demanding. I think the challenges are not going to be less.

So we everybody needs to come up with the playbook and have the right supporting ecosystem around you so that when demands are excessive on us, we can fulfill our responsibilities effectively without having that burnout, either for ourselves as leaders or also to our teams. Yeah, it makes a lot of sense. A couple of thoughts for security leaders who are listening, building on what Git's described there, having watched over the years many teams in many different organizations.

So I'm going to generalize in a way that won't be true literally everywhere, but it's very often the case. You don't see a lot of security teams that operate at 80, 85% capacity. You see a lot that operate at 100 to 110. And I think it's tied up on average with this mission, catch-all, accountability culture that we've described.

People want to do a fantastic job of this. They know it matters. There's a pride to it. And there are some parts of cybersecurity where it is an unending deluge that the job is never done.

Stack on top of that now challenges with AI, and it's kind of new terms flying around like AI fry, where people are getting more burned out from these challenges, not less. I think for security leaders, on average, you are likely to find your security team is more likely to overwork than under, which is an interesting variation to performance management frameworks for lots of other parts of an organization on average. Make sure you are building in purposeful time to stop, you know, have them research, think, train, develop, have a cup of tea.

It really is very easy to fry folks in those positions because they care so much. Anyway, I shall get off my soapbox, Kieran, take us somewhere else. Let's talk a bit more about this. So, when you were talking about that lovely, folksy but inspiring story about how to think about skiing and all the difficulties.

That reminded me that's the sort of thing Ted Lasso would come out with. Now, for those who don't know who Ted Lasso is, but many will. He is uh a fictional, sadly fictional American. Delaris administrator.

Anyway, he is American born. He is a coach of soccer football in England for some random reason, even though he has no experience. And he's in a hopeless position, but he seems to rescue his club, his job, and his career, essentially by being very nice and supportive of people. Is that a fair enough summary, Evan?

Yes, absolutely. Yeah. Now, I know I'm stealing other people's content here, but I saw two years ago in a podcast with a friend at CyberArc, the interviewer said that uh you've been described by your friends as a sort of cyber Ted Lasso. So I have two questions for you.

One, is this true? And two, whether it is or it isn't. Having talked about the stresses and strains, what a more sort of human-friendly cybersecurity industry would look like. So Ted Lasso, yes or no?

Oh my god. Are you the cyber Ted Lasso? Yeah. I think a lot of people have said that.

Excellent. I think it's maybe because of the kind of human aspect of life I talk about and the importance of the human first before anything else. I don't like to think about work-life balance or whatever. For me, it's a life-work harmony concept.

But yes, I think Ted Lasso is something which is very close to my heart as well. And I think it was a great compliment, by the way, somebody when they gave it. Yeah, yeah. It really is.

It really is. Yes. He's impossible to dislike and very much somebody you want to support. And you can see why the team get behind him.

The only difference is I think, unlike Ted Lasso, you do actually know something about the subject that you're working on. Passive aggressive insult, Karen. I tell you what, it was very interesting when recently when I went to one of the universities, I was talking to one student and she said to me, I do not know what it is, but there's some sense of calmness when I'm talking to you and we are having a conversation. Are you calm all the time?

So she spotted something I had no idea. I was meeting her for the first time. And I think I get this feedback quite a lot. There's a sense of calmness around this.

And I think it comes when you are in tune with your mind and the body. And I think that's what I talk about because a lot of us have lost that. So I want to give one tip which works really well for me because you know, jobs are jobs. They are, and as a CISO, you're having budget conversations, yeah, you are managing incidents, you know, there is never enough resources.

You're always trying to do more with less. So I don't like to do back-to-back paintings. I have like a five-minute breaker. So I will get up from my desk.

I don't do emails. I will walk sometimes. Now the weather is night. I may go to the garden.

The context switching creates such a fatigue in your mind. So kind of just a little bit of a reset allows you, and especially not emails, not screen, but just looking out. And one thing I always do is it may sound very cliche, but end of the day, I actually do not go out of my room. I will sit in silence for five minutes and I stay in tune, listen to my body and the mind to say how I am feeling.

And I always say red, amber, green. Am I feeling red? Am I feeling amber, green? And if I get an answer, I'm feeling red, amber.

I'm more of a cyan color, I think. Yeah. Then I talk to my wife about it and just about how I'm feeling. Similarly, similar practice that she has, if she's not feeling good about something.

So we generally have a just have a conversation. That's really interesting. And what it does is that it brings your mind back to a very calm state. And I think there's some simple, simple things that we can do.

Similarly, example, if I'm on an incident call, even if somebody asks me the question, I actually focus on my breath for five breaths before actually I lean into the conversation. It's magical. Small, small things, absolute magical. Fantastic.

Thank you. It is so true. Your incident example is a fantastic one, though. Is you know, we've described on this podcast in prior episodes the notion of being Zen in the middle of chaos or the kind of calm island in the middle of a storm.

And it is what is required in these types of scenarios. And there you go, folks. There's a couple of specific practices for your mindful CISO routine, assuming you know, JIT will be launching an app available soon with a subscription service on how to no technology, please. But if somebody has to visualize, in fact, I have a presentation I give on stress and burnout.

So one of the slides where there's a firefighter and you have a stack of paper above you. So it's almost like your work stack is huge, and then you have a firefighting going on. And the next slide is about Zen, which is you know just the Zen person looking at the lake and everything else. And I think I can't control what's happening outside around me, but what I can control is what's happening in my mind.

And I'd like to be that calm Zen inside, irrespective of what's happening outside. I love it. And by the way, if you have a large pile of paperwork above you and there's firefighting going on, the solution is simple. Use the fire to burn the paper, problem solved.

But hey, look, we we let's pivot to another area because there are so many things that we want to ask you about. You're you're a wonderful guest. Kieran, you mentioned before something prescient to this transition here, stealing other people's content, Kieran. A great segue into talking about AI, of course.

I see what you did there. On mass. Yeah. So, Jip, one of the things changing the work of the CISO, AI, right?

I mean, it's the excitement, the hype, the hopes, the fears, the boardroom panic, the whole gamut. Yeah. We've had so many fascinating perspectives on the show so far, and we'd obviously love to hear yours. Is it a simple race between goodies and baddies in terms of the use of AI?

You know, do you have more hope for defenders? Are you seeing more bad stuff? Are we winning? Assuming we're the goodies, of course.

I think we are. Reminds me of that sketch. I think for these purposes, we'll be the goodies, otherwise correct the whole principle of the podcast. But anyway, yeah, are we winning?

I think we are. But it's an unfair game, in fact. Uh, I always use the analogy, you know, think about unboxing match ring, where referee turns to you to say, Hey, you have to follow these rules, do not hit below the belt. All kinds of rules of the road are given to you.

And referee turns to the opponent saying, Do whatever you want. So I think the interesting thing here is because you know, we have to comply with regulations, even if you think about the EU AI Act. Do attackers have to comply with the EU AI Act? No.

Be great if they would. Yeah. So are we winning in the context? I believe that as a community of defenders, our intent is right.

We are working through the problems, whether there's a vendor community, researchers, you know, the CISOs and the cyber team and everything else. And I'm a very optimistic person in life, very positive person in life. So I would like to think we are winning. Is this something which where you like win and everything gets over?

No. I think it's a constant mission. That's why I'm saying it's a mission every day. And we will keep on innovating.

The people, adversaries will keep on innovating. And I always like to give credit to the adversaries. I think the moment you start becoming complacent and thinking we are winning, maybe that complacency is going to come and hurt you. So I think we have to give the queer the credit is.

We are up against smart people, very organized people who know their stuff really well. They know technology really well. But I would like to think we are winning. But I know you've talked about frustrations about our inability sometimes as a community of defenders to fix some ancient and basic problems.

Which means that. You read that. Yes. And it also means I was very taken by it, very struck by it.

It's something I think about because we are loading expectations on the Susseos and all the cyber defenders on having to cope with the innovations of AI, the innovations of talented adversaries and so forth. But the implication of what I read from you was that there are plenty of other harms being done because people haven't patched properly, because the adversaries don't have to be innovative. So how do you get to grips with all of this? And what hope is there for us sorting out all this newfangled AI threat stuff if we can't fix the basics?

So my view is AI is going to amplify. If you are good in maintaining hygiene, if organization has good data governance practice, if organization has got their arms around technology well, they are going to leapfrog everybody, and then AI is going to amplify the dividend that will come along with it. But if there are issues in the technology estate, you have technology tech, AI is simply going to amplify the problems. I was giving the analogy, and I love analogies for some reason.

I was giving the analogy, you know, if let's say before AI, if you have a big house, you know, where you have different doors and different windows and everything else, then the attackers have to go to every window and every door to knock and find which one is open or which one is vulnerable. Yeah. Now they can do that at scale. Yeah.

So your window of exposure through which you can find it's actually reducing, is shrinking big time. So AI is going to amplify either good practices or bad practices. And BAU hygiene and all these things I talk about, you know, it's a very interesting thing. I don't think people are ignoring these things, but it's just that there's a small amount of teams have to do a lot.

They're trying to get through the day work, keeping the lights on, patching the machines, and you know, applying the patches and doing the upgrades, developers are trying to rush the code and everything else. It'd be busy people trying to do their thing. But my honest view is cyber and all the technology organizations need obsession with the BAU hygiene. I just want to emphasize, we need to be obsessed with it.

Because if we are really good at doing that, and example, if developer takes pride in not writing the code, it's not about how many CPU cycles, what's the memory footprint of the code that you take pride in. But basically, even though it may take some more CPU cycles, a bit more memory footprint, but the code is safe and secure. Before I push it into the production, if I take pride in that, I think we'll go a long way in defending and winning. Similarly, if somebody is just an application owner who is asking for the investment for creating a new user features, which users will love, a new user experience, you also ask for making your application secure as part of that investment cycle.

And you put the same passion behind it like you prefer user experience. I think if we get to that point where people start caring about it, I think that we'll go a long way. I think that makes a lot of sense. And there is a lot of opportunity to solve many of these issues earlier, if we can be obsessive over, you know, those security problems as a matter of quality.

Shipping a car without breaks is an oft-used analogy. It's not as good as your analogies, though, Jay. You are very good at analogies, I have to say. Very good indeed.

I know we're burning through time here because of course we are, because pick any one of these topics and talk to you about it for two hours, make a nightmare for our editor. Maybe we can do it in San Francisco and we're together or we'll coffee. We will, and we'll have to have you back again for part two. But there is one issue I do really want to ask you about because it's so important to cyberleaders.

You know, we have lots of listeners who are here for the geekiness and the fun and to listen to fascinating guests, but they have to go back, you know, to their desks and try to lead their organizations forward. And it's about communicating with, you know, the board-level decision takers in organizations that aren't all about cyber and all that clued up necessarily about it. Now, we touched on this many times on the show before, but probably not as much as we should given its importance.

So it's, I suppose it's a bit like one of, you know, Kieran's London buses, but it's got stuck in traffic, which is frankly very London indeed, actually. But you're here now and you've advised loads of different companies and individuals. You know, you're a senior figure in a massive company in Deloitte. You do board-level strategic engagement all over the world at mind-boggling scale.

So give us some do's and don'ts for CETOs communicating with the board, things that cyber leaders listening can take away and apply to make their lives a little bit easier and their businesses a bit more secure. Oh wow. Big question, I know. Sorry.

Yeah, big question, very big question. Again, we can have one podcast just on this topic, to be honest. But there's a lot been talked about it. And I am a big believer of simplicity rather than complicating these materials, complicating these things.

And one thing I learned a long time ago when I was in a role in one of the financial services, I used to see board papers, which are loads and loads of pages with loads and loads of data. I completely get it for regulatory reason, traceability, and everything else. We do need to have some of those papers. But what needs to happen in the boardroom is the quality of the conversation.

So one technique I have used quite well, it took a little bit of a courage to kind of start with. When I inherited an organization, I was given a pack. Said, this is the pack that we discuss with the leadership every month. I looked at the pack and I thought, oh my God, I don't think that makes sense.

And it takes a lot of time. So I asked my team how much time it takes to produce that pack. And then they gave me an idea and then I applied kind of how much typically it costs. I put a sticky note on that deck.

And when I next time I went to the leadership team meeting, I said, What is this? What is this number? A sticky note. I said, This is how much it is costing you.

And it was a very interesting penny drop moment in that meeting. The leaders basically said, powerful device. Very sick, oh, so couldn't nobody told me saying my predecessors obviously I have inherited it, but I don't think it has the level of information we should be using and discussing. I said, Do you guys read it and everything else?

He said, Yeah, in the in the beginning we started reading it, but we don't really pay attention to this. So, why my precious resources are pulling together that deck every month and month without getting challenged, or what's the value it is coming? So, end of the day is coming back to the value conversation and we changed the game after that. Really, folks sat down to talk about what really we care about.

Have the conversation with the exec members. What is it that you want to know? And what is it that you should know? And what is it that we must know?

Because from the regulatory standpoint. So having a very clear conversation and agreeing to that, it took a while to get to that point. And then I went next step forward, and as I obviously became more senior, more mature, build more confidence. In one of the board meetings, I said, Do you want me to talk to the slides I have prepared?

Or would you rather listen to your CSA? So I like to think about good, bad, ugly. Let me tell you what is good, let me tell you where we are bad, let me tell you where we are ugly. So now I, whenever I send the papers to the board, I always put a very clear instruction that I'm going to assume the papers are being read.

But that's where the responsibility comes, giving them an advance. And then focusing on the conversation, sitting across the boardroom, looking in the eye, and basically letting them ask any questions and answering them rather than going through the deck. Because this KPI, KRIs, they serve a purpose. But what it really requires is actually an engaged board is to have good conversations.

And engagement happens when you start linking cyber where the organization is trying to do the business strategy. So a lot of hard yard happened behind the scenes and also building your one-to-one relationship with the board members. So for those 15 minutes in the boardroom are not going to give you everything, but those 15 to 20 minutes outside the boardroom with key members of the board are so essential to understand their priorities, understand where they're coming from, and then making sure you're able to address that and also get to know the person and for them to get to know the season.

Yeah. Speak their language, know their priorities. Sorry, Karen, you've got something much better to say. Go on after you.

Well, I was just gonna say if you had a few minutes with a board member or if there was a board member listening here, what would you say to them about how to use the CISO time most effectively? I would say give your time. Spend time because end of the day, this conversation is all about cyber. A lot of people think cyber is too technical and everything else.

It is, but it doesn't mean we have to be scared from this. It's about spending time to understand because every organization has gone through a journey and they are on the journey already. And that requires investment of time. So for me, my plea to every board member is spend time with your CISO.

Help them explain to you the journey they have been on, the challenges, and ask the question: how can I support you in this mission? I love that package of advice, shall we say, to both parties. And it's only going to matter more in the coming years. I mean, we spend a lot of time in this industry fighting from, you know, JIT's corner desk all the way to the boardroom.

But with all the more technology that we're rolling out and how businesses are changing and AI and everything else going on around us, the role and the importance of these relationships and ability to articulate cyber risk and resilience as a part of business strategies is just going to be absolutely crucial. So I suppose, you know, knowing we're thrashing against time here, but wanting to finish big in utility to cyberleaders, you know, you've thought about cyber leadership issues a lot more than most.

It's apparent in your wonderful analogies. So I thought it'd be nice and perhaps uplifting at the end here to invite you to paint a picture of what it might look like as a profession in say five or ten years' time. This could backfire horribly if you say that 99% of people are unemployed and the world has ended due to Terminators. But what would be a better cybersecurity profession?

What does this look like in five to ten years if we're successful, Jim? The most important thing will be where cyber as a profession is not just seen the responsibility of the people who have got cyber in their role title, where people care. So a developer cares, an application owner cares. They understand their ownership.

I have written a lot of pieces around ownership culture. I have a big reaction to the shared sense of shared responsibility model because the person on the left thinks the person on the right is doing it, person on the right thinks person left is doing it because nobody does anything. It's about owning the outcome. And I personally think the cyber means will mean very different, and society would feel very different if people understand that ownership.

A developer understands what that means, an application owner understands what that means, a CISO understands what that means, a cyber incident responder understands what that means. And everybody is playing their part of ownership and they're doing it really well. And I think if we can get to that point, we will not be winning, we'll be thriving. We will be in a space which I call the state of nirvana.

I think we can get there. But main point is, you know, get the people to care about this topic. Well, look, we've covered so much here, Jatana. Wonderful package of advice for security leaders.

Lots of things they can apply. And I shall be using the five breaths tactic in several of my meetings today, I suspect. But we do have to bring things to a close, don't we? But not before, surely, this one, given there's been so much sage advice on everything from technical issues to how you stay calm in difficult situations, whatever they are.

So surely, James, you're not gonna omit your favourite part of the show. No, it is undeniably 30-second takeaway time, isn't it? And I have a funny feeling if we set a timer that Gitenda's gonna land on 29.2 seconds with a three analogies per minute density of some sort.

I know he likes metrics too. Jatenda, look, this podcast is about lessons for cybersecurity leaders. So you've done a lot of this already, but to finish the show off here, if you had just 30 seconds with a cybersecurity leader, what would you advise them? Something to pay more attention to, less, something to do every day?

It could be anything. What would you tell them to do? Yeah, what I would say is this cybersecurity is not about protecting systems. I think it's about protecting trust.

The trust is built by the people. I always say trust is an emotion. And so if we want stronger organizations, if we want stronger society, if we want the stronger nation that we are living in, breathing in, then it's all about understanding that it's a people problem. We have to get people behind it.

We have to get different roles behind it. Because technology will keep on evolving. Means it started from laptops, desktop, then we get to the point of smartphones came in now that we are talking about AI. So the evolution will keep on happening.

But what we really need to understand is the cybersecurity is a mission every day. It's not a job, it's not a role. And it's about protecting the trust, protecting the people, protecting families, protecting the nations at large. And if we show up as leaders that understand the impact behind and they understand the relevance of this role and treat it like a mission, I think we will get to the point.

And again, coming back to the obsession with the BAU hygiene. If I have to ask any cyber defender, anybody who's there, be absolutely obsessed with the BAU hygiene. Be absolutely obsessed with embedding the ownership culture. Because if we get to that point, I think we will make our organizations and our society a lot more safer and better.

The mission of protecting everyday trust every day. Absolutely lovely. Thank you so much, Chinda. And thank you so much for coming on the show.

It's been wonderful having you. No, thanks for having me. Really appreciate it. Thank you.

And that is it for this episode of the Cyberleaders Podcast. You can leave us feedback at the podcast site. You can even leave us a rating, preferably a nice one. You can email us nicely or nastily at cyberleaderspodcast at sans.

org. Tell us whatever you like. And with that, thank you very much, everyone, for listening. Yes, thank you for listening.

Keep cybering from me, Kieran Martin. And me, James Lyne. And me, Jip. It's goodbye.

And friends don't let friends configure Solaris servers without taking five breaths first. Still goodbye.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ep 116: Ask a CISO with Steve ZalewskiLevelUp Cyber · on CISO role evolution79 / 100
  • 086| Why showing value is more important for CISOs than everCyber Security Sauna · on CISO role evolution64 / 100

More from Cyber Leaders

All episodes →
  • The Rise and Fall of Conti with Geoff White97 / 100
  • Defending with the Same AI That’s Coming for You with Chris Cochran80 / 100
  • She Convinced the Pentagon to Let Hackers In. Legally. With Katie Moussouris92 / 100
  • Still Getting Cloud Wrong. Here’s what to Fix. With Simon Vernon89 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin Jones88 / 100
Explore the best B2B Ops podcasts →
All Cyber Leaders episodes →