Cyber Security Business · 2025-04-03 · 31 min
Key moments - from our scoring
Substance score
63 / 100
Five dimensions, 20 points each
The cybersecurity vendor landscape has become impossibly crowded, with thousands of companies competing for CISO attention through aggressive outreach. Bob Litterer recommends ignoring unsolicited vendor pitches entirely and instead starting with clear business and functional requirements, then seeking solutions that match those needs rather than chasing problems. He emphasizes staying current through peer networks like Boston CISO and the Cyber Risk Alliance, and leveraging strategic partners like VARs to filter options. When building technology roadmaps, Litterer advocates for 2-3 year planning horizons rather than five-year predictions that become obsolete, and stresses customizing security investments to organizational culture and needs rather than blindly following benchmarks. For board communications, he notes that modern boards are highly capable and well-prepared on cybersecurity, especially post-SEC requirements around fiduciary responsibility. Critically, Litterer argues that ROI is the wrong metric for security spending since it offsets risk rather than generating revenue - a distinction that fundamentally changes how security budgets are justified and measured.
Ignore unsolicited vendor outreach entirely. Instead, define your business and functional requirements first, stay current through peer networks and industry conferences like Boston CISO, and work with strategic partners like VARs who can recommend solutions that fit your specific needs without adding unnecessary complexity.
Plan 2-3 years ahead rather than 1 year or 5 years - one year is too short to justify major platform investments, while five years is impossible to predict given rapid technology change and potential business pivots from acquisitions, divestitures, or strategic shifts.
Use assessments against frameworks like NIST CSF to show program maturity, benchmark your budget against peer organizations (while customizing to your culture), and brief boards quarterly on specific capabilities and risks - modern boards are well-prepared and understand security adds defensive value that cannot be measured as revenue-generating ROI.
No single benchmark is determinative because organizational culture, strategy, and risk appetite vary; however, CFOs, CISOs, and security practitioners may cite different percentage-of-revenue benchmarks, and most organizations gut-check their budget against peers to avoid being an outlier.
Define success criteria and OKRs (operational results) before buying, then track them over time to identify trends rather than reacting to short-term spikes, since sustained performance against SLAs and planned timelines demonstrates true operational effectiveness.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains moderate substantive content on budget justification and vendor selection, with some useful operational guidance (QBRs, OKRs, peer intelligence). However, much of the value is repetitive or already well-known (defining success criteria before purchase, understanding business needs first, complexity kills security). The framework-based discussion lacks novel depth, and significant airtime is spent on pleasantries, rapid-fire personal questions, and non-substantive banter that dilutes actionable insights for a B2B operator.
I focus on my business. I focus on what my business needs and the problems they need to have solved. And then I go look for the solutions.
you should have had your success criteria before you bought it. So it's not a question. I mean, that list is there. Now we can do this, this, this, and this.
The conversation recycles established orthodoxy in the security buyer space: requirements-driven purchasing, avoid vendor noise, complexity as an enemy, peer benchmarking concerns, and skepticism about ROI as a metric for security. The asset management story from the VMware vulnerability is concrete and instructive but not novel. The framing of CISO as business risk executive is standard. Few contrarian or first-principles arguments emerge; Bob largely affirms conventional wisdom.
I don't think you need to overcomplicate. Right. There's nothing like highly formalized. You understand the business need. Yeah. and those business requirements and you translate those into functional requirements and tech requirements
I think it's the wrong measure for cybersecurity. And I know people can trot that out, but I think you're applying like a different sort of capital investment ROI
Bob Litterer is a genuinely credible, battle-tested CISO with substantial tenure at a real operating company (Teradyne), board-level exposure, peer leadership roles (Boston CISO Chair), and documented industry recognition (Orbi CISO of the Year). He speaks from actual operational experience managing cross-company integrations, board dynamics, and real budget trade-offs. His candor about mistakes (the VMware disclosure fumbles) and pragmatism about risk ownership reinforce authenticity. This is a proper practitioner, not a consultant or theorist.
I was going to say, I pride myself on having the best introductions in podcasting.
Major breach. They went dark for weeks, six weeks. They were off the map because of how bad this was.
The episode includes concrete examples (Teradyne asset management case, VMware vulnerability response, peer-to-peer Signal group intelligence sharing) and actual processes (QBRs twice yearly, NIST CSF benchmarking, board quarterly briefs). However, specificity is undermined by vagueness on key details: no named vendors in the security stack, no actual vulnerability metrics or timelines beyond 'six weeks,' no specific budget percentages or dollar figures, no concrete ROI alternatives proposed. The rapid-fire questions at the end abandon substance entirely. Numbers mentioned (3-4k vendors, Google/Alphabet acquisitions) serve as scenery rather than evidence.
One organization very similar to ours in the same industry, serving the same kinds of customers. We're not competitors, but they're kind of like a sister company of ours. Major breach. They went dark for weeks, six weeks.
But that vulnerability played a part, a major part to allow it to go east-west.
The host (Kevin) asks reasonable opening questions and sets up topical threads (vendor clutter, roadmap, budget justification), but rarely presses for specificity or challenges Bob's assertions. Follow-ups are mostly confirmatory ("So...", "Right") rather than probing. When Bob deflects a question (unlimited budget scenario), Kevin accepts it without pressing. The rapid-fire personal questions in the final segment are charming but represent a significant tonal departure that signals the substantive conversation has ended. No productive disagreement or sharp push-back emerges; this reads more like a friendly peer conversation than investigative dialogue.
So let's jump into it. So 3,000, maybe there's 4,000 cybersecurity vendors in the space.
How about ROI? Do they ask you about ROI?
Computed from the transcript - who did the talking, and the words that came up most.
Kevin Pouche, COO of K logix, sits down with Bob Litterer, CISO at Teradyne, who shares practical strategies for cutting through vendor noise, aligning security investments with business needs, and effectively communicating cybersecurity value to leadership. Learn more about K logix: Follow K logix Linkedin: X (Twitter): #Cybersecurity #CISO #CybersecurityLeadership #CyberBudgets #RiskManagement
Transcribed and scored by The B2B Podcast Index.
Hi, everyone, and welcome to another episode of Cybersecurity Business. I'm your host, Kevin Pouchet, COO of Klogix. Today, we'll be diving into strategies for justifying budget spend on security technology. Joining us is Bob Litterer, the CISO at Teradyne, Chair of Boston CISO, and Co -Chair of Cyberist Collaborative, and also the winner of last year's Orbi CISO of the Year.
With deep expertise in cybersecurity strategies and leadership, Bob brings a wealth of knowledge on navigating complex security challenges in driving business -aligned security outcomes. Bob, welcome to the show. Thanks very much for having me and such a lovely introduction. I was going to say, I pride myself on having the best introductions in podcasting.
Well done. Thank you. So, geez, you've been around as a security leader as long as I remember being in this business, right? I think you're one of a few people that...
has a really solid reputation. And I'm really happy to have you on the podcast. And this is true. I think of you and a few other people and your reputation and how you've continued to advance the cause of cybersecurity as like legends.
Oh, let's not carry away. You know, I very much appreciate that, but it grows over time. Like anybody in this industry, you are small and you just keep building and building and you just keep learning as you go. And suddenly you find yourself here.
Well, I can't believe it's taken this long to get you on this podcast. You should have been top few. But here you are. So let's jump into it.
So 3 ,000, maybe there's 4 ,000 cybersecurity vendors in the space. There's been blood of VC funding. You know, maybe 10 years ago, it started coming in at really an insane clip and companies popping up almost every day. to address new threads and challenges and some great technology too.
I'm not saying it's garbage. There's some great companies coming out. Lots of M &A, consolidation, Google buying Wiz for $6 billion, which just at this point seems like monopoly money. It was like $32 billion, was it?
Oh, $32 billion. That's right. That even seems more absolutely insane. It's astounding.
So much money in our space. marketing buzzwords, right? Suffice to say, it's such a noisy space. And I imagine as somebody, you can't hide, your name is out there as a CISO for a large company, you just get inundated constantly from all these companies.
So, you know, let's start with this. How do you clear the noise in the market and make sure you're investing in the best and the right products to meet the needs? Yeah, it's pretty easy to ignore them all. Okay.
Very easy. Don't answer the emails. I never answer the phone because I don't follow the idea of the solutions trying to chase my problems, looking for problems. I focus on my business.
I focus on what my business needs and the problems they need to have solved. And then I go look for the solutions. So it's very easy to put them out of my head. I will go find them when I need them.
Until then, I don't really need to know. I keep. up with what's happening, though, by mixing with my peers in the organizations you mentioned, like Boston CISO or the Cyber Risk Alliance and some of the other conferences or communities of CISOs. I hear about things.
We're not in the dark. You read about things. I talk to people such as yourselves at Klogic. I can stay current with what's happening without having to entertain all of these vendors or, you know, I can't tell you how many times they come to me and say, hey, I just want to hear about what's going on.
I just want to hear about your problems. I'm like, you're not my therapist. You don't get to hear about my problems. I will come to you when I have it.
How do they even get to you to have that conversation? They drop cold calls. They put invites on your calendars. They hit you up on LinkedIn.
And there's all sorts of ways that they try to get access. But it's also very easy to shut them out. Right. Well, it's interesting because I'm in a unique position as a business owner.
Yeah. These same companies will try to sell to me, but they also. want to sell to me. So I recommend their products to my customers.
So I get it. And surprisingly, I'm the type of person that answers their phone. I get very little phone calls. And when I do, I typically let them pitch, not because I want to hear what they have to offer, because while we're hiring salespeople, maybe they're a good fit, but nobody calls anymore.
Interesting. Okay. They do call me. They do.
Yeah, they try to. I don't know about actual literal calls, but by email or LinkedIn or whatever. Right. But this is why a CISO such as myself, my peers, value resellers or VARs, CISO VARs still such as Klogic.
You act as that buffer. You act as that vetting kind of line. So you take those calls or you evaluate and you have a great customer base. You can say, hey, these are the solutions we're seeing getting a lot of traction.
It's solving a lot of needs. And maybe you know about my problem. We have a strategic relationship. I only need to have a strategic relationship with someone such as yourself.
And then you can help sort through the wheat for the chaff of all this dramatically changing better landscape. You guys can handle a lot of that for CISOs such as myself. Which is interesting. And I want to get into that.
But when it comes to vetting out all the companies in a certain space, right? Are you following a specific methodology when it comes to? looking at the market? Is it talking to peers?
Is it building your own requirements? Is it doing an RFP? Because that's why, as you know, we have a cyber research team. And the whole point of the cyber research team is so we can follow our own methodology.
So we have method to our madness and our vendor strategy, but also to help customers come up with requirements, come up with critical requirements, normalize those requirements, right? And take those requirements, point them at the different vendors, strengths and weaknesses. So at the end of the day, the decision correlates to exactly what the technical and business outcomes are to give that justification. And I think a lot of companies, it's not that they don't have the intelligence.
They just flat out don't have the time to do it themselves. Yeah. I don't think you need to overcomplicate. Right.
There's nothing like highly formalized. You understand the business need. Yeah. and those business requirements and you translate those into functional requirements and tech requirements that's that is going to be specific to your organization um and so that's why you know just this broad approach saying i not this this solution that fixes these 12 things well maybe you do but i'm not the person or the organization that needs those 12 things maybe i need three of those things and therefore you're not a great fit for me Or someone else might say, well, actually, between this and this, that fits like nine of my 12 things.
And so that's what works. So it's always got to be customized to my business needs and requirements. And I'm going to know that. They're not going to know it.
So when you go from the business requirements to technical requirements and functional requirements, and then you go looking, and then you say, hey, okay, I feel like these one, two, three things could possibly fit. Then you start looking across your peer group or your strategic partners and stuff. Who's been using this? Who's had good success?
How much have you paid for it? Because you want to get an idea of like what that cost is going to be. And also, can I drive my cost model down? You know, you want to get that intelligence.
Will your peers divulge that information? Will they divulge costs as well? It depends. It depends.
You know, sometimes they can, sometimes they can. It could be any, it could be not. But the CISO community is very close in a sharing capacity. We share things.
intelligence, what works, what doesn't. See, I think that's fantastic. So I think a lot of people wonder how that actually works. So break that down for me.
Are you just picking up the phone and calling one of your peers? You guys have a Slack channel? Like, how does that work? Well, I have a signal group.
Okay. Right. Apparently this is a very popular thing to do for things that are both sensitive or even things that are very sensitive. So yes, between signal groups or I don't do Slack that much.
But there are Slack channels as well, or these organizations that I'm part of will have a Slack channel or a Signal group. So, all right, we talked about sort of clearing the clutter a bit. Let's talk about sort of roadmap. So when you're building out your roadmap of technology investments, I guess first question is how far out do you build that roadmap?
Are you just looking a year ahead of time? Are you looking at five years ahead of time? the budget to cover those costs? I think it's going to be somewhere between one year and five.
It's not going to be one. It's not going to be five. It's somewhere between. I tend to think that if it's one, it's going to be just way too short of a runway.
Oftentimes, the business cycle is going to push you to think one and a half to two to three years out. It's just too short. But five years, I don't know anybody who can predict what things are going to look like five years from now. So I figured like two to three is probably the right kind of window that I'm looking at or time horizons that I tend to be planning around.
Anything outside that is just too much, you know, creative fiction. Technology changes too fast. Too fast. Too fast.
And quite honestly, the business might change too. We might have to pivot one direction or another, whether because of an acquisition or a divestiture or anything dramatically business changing would affect my strategy necessarily. Yeah. So.
When communicating the value of security investments, right, when you're going to your senior leadership or your board, how do you communicate the value of your security investments to those non -technical stakeholders? I have to imagine, you know, your board is proficient, but they're not super technical. Yeah. So they they'll have proxies to help them along, though, too.
They'll have like consultant organizations. Of course, they're also probably members of boards of other organizations as well. So they have frames of reference to compare a particular cybersecurity practice at one organization versus another. So even if they're not technical experts or certainly not cyber experts, they'll have an understanding of what a good program is versus a mediocre to a bad one.
So they're coming in with some knowledge and they're probably getting some consultative assistance as well. But then, of course, there's other measures, independent measures you can use, like assessments against, say, a framework like a NIST CSF framework and your maturity against that. That's also a marker, a temperature, a barometer of how good or strong a program is. You ever need to benchmark your budget?
Benchmarking budgets are interesting because you can go and shop benchmarks. So, for instance, I may have a benchmark. that is coming from, say, more of a cyber IT practitioner focus. And they may tend to have like a higher benchmark to say, OK, the cybersecurity budget should be a percentage of revenue or IT budget should be a percentage of revenue.
And then cyber is a percentage of the IT budget. Right. But that number, that percentage of revenue varies depending if you're a CISO, a CIO, CFO. OK.
I guarantee you that CFOs. benchmark ratio is going to be a lot lower than, say, a CISO or a CISO. So they might come to the table already having an idea of what the budget should be relative to your competitors. Or to their peers.
Or to their peers. Generally peers. I think everybody has found in my role or at that kind of role that one of the first questions asked when something comes up. Whether it's like a commitment to a platform, a commitment to a budget, or maybe something else happens.
Like, well, what have others, what have our peers done? You get asked that a lot. That's one of the first questions asked when anything comes up. Because they don't want to be an outlier.
They don't want to spend too much. They don't want to spend too little. There's definitely a comfort in that herd. You don't want to be the outlier.
It's the other thing about benchmarks too. They're organizations. So let's say you can even agree on a benchmark. And we're all fine with that.
Your organizational culture strategy may be one where they want to hit that benchmark. Exactly. Maybe they want to be over benchmark because they want to be perceived to be expert in that or very strong in it. Maybe they want to be under benchmark and they do it purposely because it shows a fiscal discipline that supports what they need even more.
So every organization is going to approach it differently. That's why when I say, is there a benchmark you can follow? I don't know if there's one that's determinative that way. It is always going to be based on the culture and the needs of your organization.
And then they're just going to keep kind of gut checking it against their peers. Now, do you brief your board directly? Quarterly. Either the audit committee of the board or the full board.
Quarterly, we talk. I've said this on the podcast before. I've only had a couple of occasions. where I've had the privilege to be in front of one of our customers' boards as an output of an assessment that we did.
And in both occasions, I was pleasantly surprised just how competent and prepared the boards were to talk about cyber. I think there's this notion in our business that boards are all staunchy, older people that just have no idea. what goes on in the cyber world, nor do many of them care. And I had the exact opposite experience.
They were all very prepared, much, much more knowledgeable than I thought they would be. And they all want to help solve the problem. Definitely. Is that your experience?
Same experience. Yeah. Certainly with the Teradyne board, also with some of my previous boards. I mean, your mileage is always going to vary there.
Right. But I do agree. I think there are misperceptions about people on the board. Like that's where you go to retire, collect all these fees and be flown around.
They do a tremendous amount of work. They always come in. They read all the pre -materials. And they are sharp.
One of the reasons why they are on a board is because they've been very successful executives in their own right. These are smart, sharp people. Maybe they don't know cyber as well as you or I, but they're just very sharp, successful people. So they come in well -read, and they also come in very committed.
I'm sure even before, but certainly now with the enhanced SEC requirements for cybersecurity related to boards fiduciary responsibility, they are very interested in making sure that cyber programs are robust and defensive. How about ROI? Do they ask you about ROI? I know we talked about how it's difficult to benchmark budget, but do you need to demonstrate ROI when it comes to an investment that you've made?
I know ROI is almost an impossible thing in our business. I think it's the wrong measure for cybersecurity. And I know people can trot that out, but I think you're applying like a different sort of capital investment ROI, product investment ROI, or services ROI that actually turns, when you get revenue, then you can see return on investment. But if you're just doing offset of risk, and it's really kind of like voodoo magic to try to quantify.
offset risk. Well, it's like cost of a breach. I remember 10 years ago, that was a big thing, right? What is the cost of a breach?
What is the cost of a lost record? And I think it's so hard to put your finger on because it depends, well, what was the record? What was the breach? What industry you're in?
And at least from my perspective, I feel like that's died down a bit. Do you ever talk about cost of a breach? No, because I don't think you can project or predict what that's going to be. You don't have enough fingers to predict it because it could be anything.
You don't know the cost of your breach until five years after that breach. Right. Because that's when the dust is going to settle. Right.
There's organizations that I know that had a breach or maybe any of them, the major ones. You have the upfront cost. You have to respond. You have to contain.
You have to hold back. You have probably lots of revenues. And you probably aren't going to find out the true impacts of that until quarters pass. You may have had customers who were impacted and they're going to sue you.
Shareholders are potentially going to sue you. All of these after effects, these kind of hangover facts, they take years to settle up. So the cost of the breach, you won't know for years and years. Not the true cost.
So can you remember, I mean, you've purchased a lot of technology, I'm sure, over the years. But can you share an example of a time when you did successfully justify? Major security spend, and did it save a breach? It did, actually.
This one is in reaction to a breach, and luckily it wasn't ours. So an organization very similar to ours in the same industry, serving the same kinds of customers. We're not competitors, but they're kind of like a sister company of ours. Major breach.
They went dark for weeks, six weeks. They were off the map because of how bad this was. And so we looked. As much as we could, because when these things are happening, it's not like you're having a conversation with them saying what happened.
They're in the trenches. They're there fighting and they can't disclose. So you kind of have to extrapolate and say, well, this other thing was going on in the broader cyber world. The exploits, the vulnerabilities, what have you.
We think it was this. So we thought it was a vulnerability that maybe let the bad guys in. Turns out it was that and something else. Something else started the exploit, but that vulnerability played a part, a major part to allow it to go east -west.
Anyway, jumping forward, we said, wait a second, this thing's pretty bad. Why do we think this was leveraged to be breached? Do we have this in our organization? And so Paradise is an interesting company.
It's a great company. It's a successful company. It's been around for a long time. And what Teradyne actually is, it's a collection of companies that have to varying degrees have been integrated or not.
Because the first mission of these acquisitions was to continue to develop and sell products to our customers. So that degree of integration sometimes creates challenges in visibility and also in execution across a service. Jumping forward, what this means is when I asked, do we have this vulnerability? went to our Windows team, went to the VMware.
It happened to be a VMware vulnerability. And the person responsible for it came back to me and said, no, we're good. And so I reported that to my executive committee and to the board. We're good.
Six hours later, I get a call from this guy saying, oh, but wait, we do have this in this area over there. This part of the business, turns out they have it. And so then I had to go hand in hand back to my executive committee, back to the board. Oh, I'm sorry.
Wait, no, we do have it. Here's where it is. This is how long it's going to take. Yada, yada, yada.
The next day I get another call from this guy saying, oh, no, wait, I found some over here. This time I had to go back to the executive committee and the board and actually meet my hat because of this kind of revise, revise, revise and talk about losing credibility. with your executive stakeholders. It's like, we can't trust what you're saying.
Are you in control of your environment? So we said, okay, we have to fix this. We need to get asset management and asset disposition done right. It's not optional.
You need to know what's in your environment, what its value is, what its current state is, so you can respond with authority and with speed if something like this happens. So that generated... instant abilities that need to get the new platform that style that asset management. And you got your credibility back.
Definitely. And we've used it over and over. It's great. We use it.
That's a great story. That's a good success story. I'm glad we were able to achieve that. When you look at your existing technology stack, how do you ensure that Your existing tools are all fully operationalized and fully capable.
So when a new risk comes up and you start looking for new technologies, that you're not looking to buy something that overlaps with something you already have. Yeah. I don't know if that's a challenge for us because I'm not looking for more vendors, more solutions to add complexity to the environment. Because I think complexity kills security success.
It definitely makes it more difficult. So I'm always going to be looking at my existing platforms to see, do they have this capability? In some respects, it would be maybe they only do 80 % of, say, what the best in breed is. However, the operational efficiency of staying with my current platform is going to make the net benefit greater than getting the best in breed, best in class thing over there because that's yet another platform.
Integration challenges, you know, getting the advanced SIEM, managing with your SIEM, response processing. All those things get complicated when you have to add yet another vendor to do that thing. So the degree I can extend a current platform. So what do you do, though?
Do you do an audit of everything you own to make sure it's being fully used? Well, you do that with your, I don't know about a full audit, but you are, if you have a good relationship and an active relationship with your major platforms, you're going to be doing QBRs, quarterly business reviews, and health checks. I think sometimes QBRs is too much on the queue. Maybe they should be done like twice a year.
I don't know if enough changes quarterly, but at least twice a year, you're going to want to be having that kind of review. And maybe once a year for the most important ones, you're going to do just a general health check. I mean, you're going to take your car in to get its health check once a year. You might go and get a health check once a year.
So I think your major platforms should have that. We literally just did that in this office yesterday with the customer for their major platforms. Every time I've seen it done, it's intangibly valuable as long as you structure it correctly. Right.
I love going to my doctor. Nothing happens there, but I'm gone. And then I know I can say that I'm in good health. So operationalizing something doesn't necessarily mean it's successful.
When you buy technology, how do you define success? Well, you should have had your success criteria before you bought it. So it's not a question. I mean, that list is there.
Now we can do this, this, this, and this. And hopefully you've built some sort of, I don't even want to call them KPIs. I like OKRs better than KPI because they're operational results. So it's like, what?
You bought this thing for a purpose. Is it delivering? And also, I mean, you need to track these things because it's important in the moment, but it's almost more important over time in the trend. Right.
Because I see this a lot in vulnerability management. People will react to spikes or what have you, and it's easy to get a little carried away. But when you snap that chalk line, it could be like the day after Microsoft dropped their monthly vulnerability report. And so, of course, your vulnerability is a sky high.
But if you look over time, are we maintaining our SLAs? Did we patch within the window we set? That shows you have the actual skills and muscle memory. and effectiveness right to handle it right and also you can see over time wait we're getting behind you know maybe there's legitimate business reasons why you couldn't patch you couldn't get the downtime the environment couldn't handle it you had to push it up push it out push out maybe there was a quarter close and you couldn't you know do whatever but if you keep doing that more and more over time you can see that trend and that trend says hey we're putting ourselves more important risk so you have to have those operational key results.
You have to understand why it matters, why you have that platform in the first place. You've got to be measuring something. And then you can then measure your operational effectiveness and also kind of like outcome effectiveness over time. Are you doing a good job or not?
Are you getting more risky or not? Is it serving a purpose or not? Got to measure. I imagine at some point in time, you've experienced major budget cuts, right?
Go toward the end of the year. You put your budget forward. Everything gets conditionally approved. Christmas is great.
New Year's is great. February comes around. That budget gets released. And all of a sudden, sorry, but times are tough right now.
Budget's not available. Not only that, but I think you need to increase your current operational costs. How do you approach that? It's a conversation.
I think as a CISO. The first and foremost thing you need to understand is you are a business risk executive for the company. You were there to serve the business. And it's their money.
If they say, you don't have that much money, or we need this money in order to do this other thing to make the business grow, your job is to find a way to do it and say, okay, this is where we can maybe move this down, cut this out, delay this, understand how that changes our risk picture. And it's there. And it's their responsibility to then say, yes, that's still within our risk tolerance. We will do it or not.
I don't own that risk. They own that risk. What I own is the obligation to tell them what that risk is and to guide them. But ultimately, they're going to decide.
So if I have to cut budget, we'll cut budget. It's just business. What do you do? And it's just risk.
We will always live in a world of risk. Right. You're an educator in some ways. It's just a question of how much you're mitigating it or how much you're living with it.
Right. Well, I could keep talking about this all day, but I'm going to move to the next round of questions. So I've started doing these rapid fire questions and by and large, they don't have a lot to do with cybersecurity, but I think it's just a way for people to get to know Bob and what makes him tick in some other ways. Are you ready for this?
Let's see. Let's shoot. Okay. So sort of cyber related here.
If your CEO gave you unlimited budget for one thing, what would you spend it on? It's such an interesting question because it would never happen. But she's going to say one you probably never think about. Yeah.
Yeah. It's never been a problem I've had to confront. Okay. A good CISO, a good organization is going to already have a strategy and a roadmap.
And so there's not like one single thing that I would choose. I would say I would look at our roadmap and then accelerate those things that I feel like give us the most bang for the buck and put us in that right position to support the business for a longer term. There's probably things you can do about better detection, automation, orchestration to drive us to be more efficient, to just be able to find it faster and fix it faster. Listen, if the Teradyne CEO is listening, maybe tomorrow you'll have that chance, unlimited budget.
Whatever you need, Bob. One can always hope. Okay, second question. I think we might have even talked about this before.
I know you read. What was the last book you've read? The last book I read was James. James.
It's a novel. Okay. It's kind of a reimagination. It is.
It's a reimagination of Huck Finn. Oh, cool. Very good. Okay.
Nice choice. Third question. If you could instantly master any new skill, personally, professionally, what would that skill be? Yeah, that's a great question, too.
It's like the genie question. It's like you only have one wish. Like, what's it going to be? I don't mind.
It'd be play guitar. Play guitar. I think for me, it would be to sing. To sing?
Now, can you sing? No. And I'm right into my core of doing it. And I'm going to be going on a trip soon where karaoke is mandated.
I went two weeks ago to a karaoke birthday party. And like you, I think I'm tone deaf to some extent. So I run from singing. And so that was pretty frightening.
Yes. I shared that fear. Good luck with that. Thank you.
Thank you. If you weren't working in cybersecurity, what would you be doing? It's such a hard one also to contemplate. It is.
Doing it for so long. Maybe you'd be a singer. If you combine the two, I absolutely would. I would.
It's a hard one to navigate because it's like, well, assuming like financial security, what would I do? What did you major in in college? Oh, so history. Okay.
Maybe be a history teacher. No, thank you. No, thank you. Yeah, yeah.
You know, assuming like financial success, I would be doing things around baking and beekeeping and doing things like in the community, you know, that kind of thing. Yeah, I love that. Being outside, what have you. But I don't have, I have a variety of interests.
I don't have like a burning passion. If I could, I'd be racing Porsches. Ah, okay. Love that.
All right. Last question then. What's one piece of advice you wish you had when you first graduated college with that history degree? Well, I'd say be careful of that first job you get because it's very likely to turn into a career.
So after undergraduate and graduate school, I moved, I'm originally from Minneapolis, moved to Boston and was looking for a job in regulatory affairs space because I have a master's in public policy around science and technology policy. And so when I went for a job interview, I actually went for two. There was two interviews in the same company. One was a reg affairs, the other was IT.
And I happened to do a lot of IT growing up. I did computers with my brother. I was just very... competent with them.
And more so than, than a lot of people, a lot of people were very afraid of it. I was not afraid of it. I could do it. But I went to both interviews, wanted the reg job.
When I walked in, wanted the IT job when I left, I got the IT job and I figured it was going to be just for whatever a year, just tell you I'm going. And here we are now. If only that first job was working for Porsche. Wouldn't that be something?
I have to say, which I love Tara and I. that the only risk they have is if Forger calls me and says I need a new C. So I should consider it. I would definitely have to consider it.
Well, that was great. That's a wrap on the podcast. Thanks for sharing your thoughts. I know you weren't one of my first guests, but I think you'll be one of our best.
So I really appreciate it. It was. So, well, thank you for coming on and we'll catch up next time on the next episode. Thank you, everybody.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.