Cyber Security Business · 2025-03-05 · 26 min
Key moments - from our scoring
Substance score
57 / 100
Five dimensions, 20 points each
Karen Higgins-Carter draws on her experience as CTO at Webster Bank and Gilbane Building Company to address the critical challenge of assembling cybersecurity teams when 4 million roles sit unfilled globally. Beyond technical chops, she emphasizes hiring for business acumen - understanding how the organization makes money and identifying key business risks - paired with indicators of grit like candidates who worked through school or transitioned from military backgrounds. She reframes diversity hiring not as on-ramping people into an existing culture, but as building the house together, which unlocks the true value of diverse perspectives. On retention and development, Higgins-Carter advocates for creating accountability through process ownership roles (even without formal promotions), hosting monthly process reviews where junior talent observes senior-level dialogue, and requiring conference attendees to return with ten business cards and a presentation. She's a strong proponent of certifications like CISSP and ISC-2 credentials, and emphasizes that cybersecurity leaders must develop external focus - reading annual reports, understanding 10-K filings, mapping SEC risk disclosures to CIA frameworks - to operate effectively at the business level.
Look for business acumen (understanding how the business makes money and key risks), grit and work ethic (candidates who worked their way through school or transitioned from military), integrity above all, and willingness to learn. No one should get a pass on learning the business just because they have hard technical skills.
Ensure pay is market-competitive and equitable, create opportunities for growth and upward mobility, foster a strong team culture, and invest in developing people. Also consider recruiting internally from adjacent technical roles like network engineering where people can transfer skills into security.
Create accountability through process owner roles (incident management, vulnerability management) that give junior staff ownership and authority to redesign processes. Hold monthly process reviews where they present their work, and bring high-potential junior people into senior operating reviews to observe senior-level dialogue and set expectations for the next level.
Certifications are valuable, particularly ISC-2 certifications and early-stage certs like Network+ for career transitions. CISSP can be criticized as 'a mile wide and inch deep,' but the structure and pedagogy behind it tests thinking and experience, and gives leaders confidence in team member competence in domains they don't fully understand.
Cybersecurity is less about being an independent discipline and more about executing technology, operations, and architectures securely within your specific business context. Leaders who can map security priorities to business risks and financial drivers (via 10-K filings and risk factors) are far more effective at driving awareness and behavioral change.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains several solid, actionable ideas (process owner accountability, external focus requirements, reading 10-K filings, internal talent recruitment from adjacent teams) that would be useful to security leaders, but much of the content is conversational filler, personal anecdotes (cupcake promotion, ice skating), and well-rehearsed talking points on hiring traits (business acumen, work ethic, integrity) that won't surprise experienced operators. The density of novel claims per minute is moderate rather than exceptional.
create accountability so named process owners
if you think that you can run a program based upon what you and your team know alone you're kidding yourself
The advice is practical but largely conventional: hire for business acumen and technical skills, develop talent internally, pay competitively, attend conferences with purpose. The frameworks recycled here (belonging vs. on-ramp, process ownership, external focus) are sound but not novel. There are no counterintuitive claims, contrarian takes, or first-principles arguments that would distinguish this from dozens of other talent management conversations.
you need both business acumen and technical acumen
pay has to be in line with markets smart candidates know what the market is for their skills
Karen Higgins-Carter has substantive credentials: CTO/CDO roles at Webster Bank and Gilbane Building Company, board roles at International Money Express and Otsuka Pharmaceutical. She's a practicing executive with real responsibility for building and managing security teams at scale, not a pure consultant or thought-leader. However, the transcript provides minimal evidence of deep security domain expertise or specific incident/program outcomes that would elevate her to the highest tier of guest caliber.
Karen is a multi-industry chief tech and digital officer with recent roles at high profile organizations such as Webster Bank and Gilbane Building Company
I've inherited a team for most companies
The episode lacks concrete numbers, named examples, or measurable outcomes. Karen mentions a 4 million open jobs figure (cited by host, not her), references to 'one organization' and generic examples (vulnerability management process owner, network engineer transitioning to security), but provides no specific companies, budget figures, timelines, or quantified results from her tenure. The 'cupcake promotion' anecdote is memorable but not evidence-based.
4 million open cybersecurity jobs globally
I held what I called the mental promotion party where I bought cupcakes
The host asks reasonable follow-ups (e.g., 'is that hard to find?', 'how do you find them?') but rarely pushes back, challenges claims, or explores nuance deeply. Most questions are softball confirmations of points already made. The rapid-fire personal questions at the end are friendly but off-topic and add no substance. There's little evidence of the host stress-testing Karen's advice or surfacing tensions in her thinking.
Now is that hard to find when interviewing candidates to have both business and technical acumen?
So outside business acumen and technical acumen, are there other, let's say, unconventional traits or skills that you look for?
Computed from the transcript - who did the talking, and the words that came up most.
Kevin Pouche, COO of K logix, sits down with Karen Higgins-Carter, Board Director and Chief Technology & Digital Officer, to discuss building the Cybersecurity Dream Team - how to navigate the talent shortage, develop key skills, and retain the best professionals in a competitive market. Learn more about K logix: Follow K logix Linkedin: X (Twitter): #Cybersecurity #CISO #CybersecurityLeadership #CyberJobs #CybersecurityTalent #WomeninCybersecurity
Transcribed and scored by The B2B Podcast Index.
Hello everyone and welcome to another episode of Cybersecurity Business. I'm your host, Kevin Puchet, the COO of K-Logix. Today's topic is all about building and developing your ideal security team. And it's not just about tech expertise, but more about navigating the highly competitive talent landscape and finding the right people who can adapt, innovate, and thrive in today's challenging cybersecurity environment.
And I say competitive talent landscape because I think as of now there's 4 million open cybersecurity jobs globally, which is just a staggering number of open jobs. But thankfully we have the right person to talk to us today. It's Karen Higgins-Carter. Karen is a multi-industry chief tech and digital officer with recent roles at high profile organizations such as Webster Bank and Gilbane Building Company.
Currently she is an independent director at International Money Express, where she serves on the audit in nominating and governance committees and Otsuka Pharmaceutical Companies, where she serves on the compensation and organization development committee. Her career has been distinguished by shaping and executing innovation, technology, artificial intelligence, and cyber strategies to position long established global companies for the digital future that we're now in. So Karen, awesome to have you.
I know you have a lot of responsibilities, so thanks for pulling yourself away and joining us. Thank you for having me. Thrilled to be here. So Karen, let's jump into it.
You've built a lot of teams and as I mentioned, a lot of high profile companies. When thinking back to building some of those teams, what were some of the key traits that you looked for in those first few hires? Now, thanks Kevin. I think the first thing I look for is business acumen, is being able to understand the business that you work in, understand how the business makes money, understand key risks to the business plan, and being able to use that as a mental map through which you execute your responsibilities and think about the changes that you want to lead.
So business acumen. So is that a hard balance to strike when interviewing candidates and looking for business acumen versus let's say, technical expertise? I think the shorter answer is you need both. I think there's often, I think, an over emphasis on, well, they're just a techie and can't learn the business or they're a process person and are not technical enough.
I think the common thread across all teams, I think the best teams really have the right mix of skills because there's many aspects of cybersecurity that are process driven, control environments, aspects that are deeply technical, as well as putting that all through the lens of your understanding of the business. I think everybody needs to understand that. No one should get a pass because they have hard technical skills. They need to be able to learn the business as well.
And if you can learn cybersecurity skills, you can learn a business. Now is that hard to find when interviewing candidates to have both business and technical acumen? Yes, it is hard to find, which is why as a leader, you need to be willing to develop your teams. Okay.
Now most of the teams, have you built some of these teams from scratch? I have to assume that some of these large companies, you must have inherited a team to some extent. Yes, for most companies, I've inherited a team. I can't recall a time that I've had to build something completely from scratch.
I have had to turn over some leaders, particularly where there's integrity problems. Think about a cybersecurity team. It has to be one of the most trusted teams in the company and the slightest indication that there's an integrity issue will get you off one of my teams very quickly. But beyond that, I think looking at your team as a set of individuals who have their own goals, their own career dreams, and can be developed into roles such that when you put them together, you operate effectively.
So outside business acumen and technical acumen, are there other, let's say, unconventional traits or skills that you look for? Yeah, you know, I look for hard work. I don't know that that's unconventional, but one of the indicators to me of someone who is really a hard worker is someone who has had to work to put themselves through school. It's not necessarily going to the most renowned and highly thought of universities and colleges.
It's about, did you have to pay your tuition while you were going to school? Are you potentially coming out of the military and looking to transition careers? I think it's that type of background that is always intriguing for me because I think it brings not only a sense of work ethic, it brings a sense of acting like an owner and taking ownership for the outcomes you create, as well as a sense of creativity. If you've had to work your way through school or you are transitioning out of the military, I think it generates a sense of creative problem solving that I find to have very, very helpful, particularly in a cybersecurity team.
Because as you know, nothing is straightforward, particularly when you run into incidents or other challenges that creative streak can be very helpful. Oh, for sure. I think, look, it also gives a level of accountability. I think we're also talking about sort of grit, for lack of a better word.
Those are super important. Right. Yeah, great way to describe it. So let's talk about diversity.
That could be diversity in terms of background or diversity in terms of experience or thinking. Does that play a role in your strategy of building a team? Huge. It brings an incredibly important role.
I would start with making sure that a sense of belonging is first and foremost present on the team. And I think there's a distinction between, hey, here's the house we built and here's an on-ramp for you to be able to come into our house. And hey, you join the team and let's build this house together. I think if leaders and team members can understand that distinction, it's then and only then that you get the benefit of having diverse experiences and diverse points of view on your team.
And so I think a lot of folks and leaders, when they think about diversity, they're looking for people who have come potentially from different backgrounds, think differently. But it's all for not if your view of belonging is we will give them an on-ramp into our house. It has to be, they are here to help us build the house, rebuild the house, reshape the strategy that we're pursuing. So clearly you understand the persona of the type of people that you want to hire.
You have a plan. So you get a plan. You know the type of people you want to hire. You know their traits.
How the heck do you find them? I remember maybe this was seven years ago, there was 1.5 million open jobs in the world and now there's almost 4 million open jobs. And it used to be, well, you were competing in your geography because everybody went into the office and post-COVID, it's global.
So you're now competing against people in Ireland, the UK, all over the world for top talent. So how do you sell them on your specific organization? Is it culture? Is it pay?
How do you do it? I think it's, you know, pay has to be there, right? I mean, people, if they feel like they're being underpaid, it feels like a kick in the gut. So I think the basics of pay equity and not lowballing people because you can, I think that just goes without saying.
But sometimes I'm surprised by the fact that I actually have to say that sometimes. That just, you know, is clearly a non-star particularly for people who are in demand. But as you said, I mean, there's a huge mismatch between supply and demand for cybersecurity skills. So you have to be able to develop it and you have to be able to attract people into a team, even if it's just internally.
I think sometimes I have found cybersecurity folks from other areas of the organization, someone who's great on your network team, your network engineering team is a great candidate for a cybersecurity role because if they can learn, you know, if they're a network engineer, then you can clearly teach them the other aspects of the role. As you know, cybersecurity is less about being an independent discipline and more about executing technology operations processes and designs and architectures in a secure way.
And so if you can take people from adjacent areas, I think we can begin to close some of the skills gap. And I think the same must be true for retaining that top tier talent, right? It's so easy now for people to understand what other opportunities there are for them out there. And I'm also glad that you did mention pay because people tend to run from that.
But yes, you need a strong culture. You need a strong team. But if your pay is way out of line, I think you're now decreasing the talent pool that you could potentially hire. Right.
Now, that's exactly right. Your pay has to be in line with markets. Smart candidates know what the market is for their skills. And I think good companies are very, very focused on pay equity.
And pay is not everything, right? It's the complete package in terms of who you work for, the profile of the company, are they growing, will they invest and develop you. Those are the questions that I always look at when I look at opportunities and that I think everybody should be looking at. Likewise, I totally agree.
So you just mentioned opportunity and the ability to have upward mobility in an organization. Did you implement some sort of mentor program to take, let's say, junior talent and mentor that talent and help grow that talent and give a platform to people to really advance their career? Yeah. I would say less formal than say mentor program.
I have mixed feelings on mentor programs in general. Yeah, I think sometimes they're a little bit forced. One time I went to a cocktail party where mentors were going to meet with their mentees and it was the most awkward, an uncomfortable party I'd been to in a long time. So I wouldn't necessarily say it's as formal as mentoring.
One thing that I do do as a leader, I had one organization where we rapidly needed to improve capabilities and do it in a way that was sustainable. So the first thing I did is create accountability. So named process owners. So you own say incident management or someone else on the team own the vulnerability management process.
And I actually, you know, people were kind of shying away from it a little bit because I think I was less than clear when I said, hey, you own the vulnerability management process end to end. Like, here's your role, but you have a broader organizational responsibility. And so I held what I called the mental promotion party where I bought cupcakes. Everybody who doesn't love cupcakes.
Right. And I said, you know, you are hereby promoted into these process owner roles. Was it a formal job description? No.
And I wrote them all cards, you know, expressing my confidence and their ability to execute these roles. And so now they had something to own. So you could be say a vulnerability analyst, you could work in the sock, but you had responsibility for incident responses of process. And then I had a series of monthly process reviews where we would review, here's your process map.
Here's your risk and control self assessment. Here are your top control weaknesses that you want to resolve. And the agenda was completely driven by the process owners. And so it was an opportunity, I think, to demonstrate what managing by metrics is and how to drive continuous improvement.
And the talent that really engaged and embraced that have all been promoted since then because they could begin to think in a way that was different than simply executing tasks that were given to them in their roles. They could take a larger responsibility. They had accountability and authority to redesign processes, to prioritize control implementations and to execute that way. Another thing I like to do is bring more junior people into those meetings.
Like if there's high potential talent, I love to bring them into my operating reviews just to observe that this is the type of dialogue that you have at a more senior level in the organization. So they can get a sense of what the expectations are at the next level. So when developing skills, how do you feel about developing skills through certifications? Yeah, I'm a big fan.
I know I am because I think some of the certifications are really, really good on ramps for people into either a technical domain or into cybersecurity. Like if you are transitioning from the military or from another role, some of the early certifications are excellent at just getting you network administration skills or likewise. So those I'm a big fan of. I'm also a fan of the ISC-II certifications.
There's real structure. The CISSP can be criticized for being a mile wide and an inch deep, but there is a pedagogy behind that. There is rationale behind granting that certification that really tests your thinking and your experience. If not, you know, the thousand page book that you have to break, then why don't you prepare for the exam?
But I'm a big fan. I think it isn't everything, but it's definitely something that gives leaders a certain level of confidence that you have, a level of competence potentially in a domain that they don't necessarily understand. Right. Education is always a great thing.
I agree with you on certifications. How about conferences? I have this vision of some of the conferences out there where people are walking around with a plastic bag, you know, just begging for free mouse pads and anything else that costs 99 cents, which it always blows my mind that these high paid people just want anything free that is complete garbage. How do you feel about conferences?
Yeah, I would broaden the question a little bit in terms of I'm a huge fan of external focus. Right. I'm particularly in cyber understanding the landscape, you know, threat intel. I'm a huge fan of external focus because if you think that you can run a program based upon what you and your team know alone, you're kidding yourself.
You risk becoming ignorant of better ways of operating, particularly in constrained budget environments. My personal rule for conferences is if you go to a conference, come back with 10 business cards or contacts in these days for people who are not vendors. So here are the folks that you met and then give a presentation to the team on what you learned. So you go with some responsibility and a learning agenda when you come back.
So I will I'll fund that all day long. I think one of my pet pigs are folks who go to conferences for the sake of going to conferences. Right, it could be a reward, though. There's something to be said about that.
Right. Exactly. So I think if you're going to go, go with an agenda to learn, go with a list of people that you want to meet. You know, one great trick for conferences is find out who's going ahead of time and introduce yourself to them or create a smaller conference within a conference.
Like look for I don't know if you're a black hat people who work in regional banks who are also at Black Hat and join them for lunch. I think that is the benefit of getting out and going to conferences. I love that. I think I'm going to steal that from you.
Ten business cards and a presentation. Right. So great. So I think we've covered the nuts and bolts at least, Karen, of developing sort of an ideal security team.
Anything major that you think we're missing? Yeah, I mean, I would just circle back to where we started in terms of, you know, learn the business. Easy to say. Sometimes it takes time.
So so don't put too much pressure on yourself. But things, you know, very actionable things that can be done, particularly now in the spring. If you work for a public company, read the annual report, understand the financial statements. If you don't understand financial statements, go back to school, take an undergraduate accounting 101 class and you'll be able to read financial statements.
Read the risk factors in the in the 10 K filing. You can do a direct mapping between those risk factors and CIA. And so those types of very actionable things can make you much more relevant and effective because you can put what you're doing through the lens of the business that you are in. And that is what helps you accomplish your goals as well as lead change.
I mean, most cybersecurity teams are really made up of a number of change leaders because they're often I would say more often than not having to create awareness of risk and change behaviors to mitigate risk and doing that through the lens of the business that you work in is the most effective way to do it in my experience. Right. Look, if there's one industry that needs to be open to change, it's this industry, cybersecurity. Let's what I'd like to do, Karen, is close with some rapid fire Q&A, just a series of a few questions to get to know Karen, not necessarily Karen as the IT insecurity executive, but also Karen sort of personally.
So I'm going to fire a few questions at you and I can't wait to hear your response. I can't wait to hear his question. Okay. So if your CEO gave you unlimited budget for one thing, what would you spend it on?
Who? CEO gave me unlimited budget. I can only pick one. Okay.
I'd say talent development. Good answer. Talent development goes with the spirit of this podcast. What?
So what is the last book you read? Immunity to Change. Immunity to Change sounds like a business book. It is a book by Professor Robert Keegan at Harvard University.
It goes through the reasons why people resist change. So the premise of the book is you have all good intentions, but also conflicting commitments that are sometimes unconscious that prevent you from doing simple things like eat less, exercise more. It's a very relevant book. Very relevant.
I just bought a Kindle two weeks ago because I want to make it easier to read and move into the latest century. So that will be on my list. Next question, if you could instantly master any new skill professionally, personally, I don't care, what would it be? Ice skating.
Ice skating? Okay. Yes. Love it.
I'm trying to learn. My daughter is a high level skater and now hockey player. When she retired, and this was about two years ago, I took her spot with her ice dance coach because it's something I've always wanted to do. Sure.
I would have been a much, much better sports parent had I done this earlier. I had no appreciation for how hard it is and I've been slacking off a little bit more than I wanted to, but I love it when I can do it. I will never be good at it, but it's great stress relief because I will never be good at it. So I don't set goals.
And you can't think about work if you're on ice. Right. Okay. Next, if you weren't working in IT, cybersecurity as an executive, what other field would you be in?
Maybe ice skating. No, I don't. Yeah, maybe. I don't think I could do that.
It's too hard. Something creative. So either an architect, I spent a couple of years at a building company, as you know, and I'm always impressed at an architect's ability to visualize space in 3D and how people will use the space and the creative process that that entails, obviously with constraints around cost and physics. So I think that is a really interesting profession that if I had to do it over again, I might do that.
Architect. Awesome. One of my kids wanted to be an architect. I think it's a pretty cool field as well.
Okay. Last question. What's one piece of advice you wish you had when you first started your career? That it'll all turn out okay.
That's the advice. I've been very blessed to work with great companies and to have really wonderful sponsors and mentors and opportunities to learn a lot. I'm just so lucky. But I went through, particularly when I had my children, and they're older now.
I mean, they're in their twenties, but I had them fairly young. And when I did, I found myself looking around for a template I could copy. Like, oh, Sue has two children and she works full time. And then I learned, well, Sue's husband stays at home with them.
And that wasn't my situation. Or Mary's mom lives with them. And that was not my situation. So I think I spent a lot of nights worrying about how is this all going to work out in less time trusting that it would and trusting my own ability to make good choices.
Because careers are long. Life is long. Careers are long. And the good times are temporary and the bad times are temporary.
And I just wish I spent less time worrying about it and more time confident that it would all work out. It's great advice. I think sometimes it's hard to really hear and understand that when you're a lot younger. And I know you mentioned you were lucky and sure luck plays a part.
But you know, what I always say is luck is the residue of design. So I'm sure your success was due to a lot of hard work and putting yourself in the right place to take advantage of that luck. So well, that's a wrap on our rapid fire round in on the whole podcast. So Karen, this has been a real pleasure.
Thank you so much for joining us. And thanks for having me. I'll let you get back to a lot of other responsibilities that you have and maybe I'll see you on another podcast that talks about why people like free useless garbage at trade shows. But you know, until then to our listeners, thank you so much for joining us.
Thank you. Thank you. Bye-bye we appreciate it.