The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Cybersecurity Ecosystem Show
Cybersecurity Ecosystem Show artwork

Data Governance, Board Buy-In, and the Thing You Can't Shut Off: A CISO's Cross-Industry Playbook

Cybersecurity Ecosystem Show · 2026-05-14 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

37 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence5 / 20
Conversational Craft6 / 20

Janet, a CISO with cross-industry experience spanning pharma, manufacturing, cruise lines, broadcast media, and healthcare, discusses how security leaders can drive organizational alignment and tackle industry-specific challenges. The conversation covers three core themes: AI's dual nature as both defensive tool and attack surface, requiring proactive team reskilling and curriculum redesign; data governance as the critical foundation for both security and AI effectiveness, yet chronically underfunded compared to protection tools; and the executive communication playbook - framing security initiatives through four business lenses (operational, financial, reputation/trust, and regulatory) rather than technical jargon. Janet emphasizes a recurring pattern across industries: the 'thing you can't shut off' - critical systems that resist standard security patching and tools - which forces creative security architecture. Her core insight ties data quality directly to AI outcomes and organizational efficiency, making governance a cross-functional unlock rather than a pure security problem. Ideal for security leaders seeking board alignment strategies, those managing legacy systems in regulated industries, and organizations beginning AI deployment without foundational data practices.

Key takeaways

  • →Frame security initiatives to executives using four categories: operational continuity, financial impact, consumer trust/reputation, and regulatory compliance to increase buy-in and resource allocation.
  • →Data governance is foundational for AI success - organizations need clear data lifecycle management, single sources of truth, and proper data stewardship to get accurate AI outputs and operational efficiency.
  • →Legacy systems and technical debt remain a critical security blind spot across industries due to business prioritization favoring core operations over modernization, requiring creative approaches to patching and protection.
  • →Every industry has 'the thing you can't shut off' (e.g., biologic manufacturing, healthcare operations) that requires non-traditional security implementation strategies around patching and endpoint tools.
  • →Security teams must align their mission and messaging to their company's core purpose and business language to demonstrate contribution to overall objectives and gain stakeholder engagement.

In this episode

  1. 1AI Tools in Cybersecurity: Opportunities and Risks
  2. 2Retooling the Workforce: AI Education and Skills Development
  3. 3Data Governance as a Critical Foundation
  4. 4Technical Debt and Legacy Systems in Cybersecurity
  5. 5Executive Buy-In: Framing Security Through Business Priorities
  6. 6Industry-Specific Challenges: The Thing You Can't Shut Off
  7. 7Aligning Security with Company Purpose Across Industries

Mentioned

JanetClaudeChatGPT 5.5 CyberHigh Point University

Guests

Janet

Topics in this episode

Data governanceLegacy systemsEndpoint ProtectionAI security risksChatGPT 5.5 CyberClaude MythosCISO roleBoard buy-inData lifecycle managementHigh Point University

Questions this episode answers

How should CISOs frame security initiatives to get executive and board buy-in?

Frame initiatives within four business categories: operational (keeping the company running), financial (keeping it profitable), reputation/trust (maintaining customer confidence), and regulatory (staying compliant). Janet uses this across industries - from healthcare operations to cruise ship scheduling - to connect security work directly to boardroom priorities.

What is the main disconnect Janet sees between data protection and data governance?

Vendors focus on protecting and classifying data, but few organizations have dedicated data stewards or chief data officers who govern the data lifecycle, manage source-of-truth questions, or prevent data sprawl and replication. This gap creates inconsistent answers across departments and poor inputs for AI systems.

What is 'the thing you can't shut off' in cybersecurity, and why does it matter?

Every industry has critical systems that cannot be interrupted - biotech manufactures living organisms, hospitals run continuous patient care, cruise ships maintain life support at sea. This forces CISOs to implement security patches, tools, and reboots creatively rather than using standard methods, and is a universal challenge across industries.

How should cybersecurity teams adapt to rapid AI and tool changes?

Janet recommends proactive self-teaching, certifications, and dynamic curriculum updates (potentially every six months at universities) rather than static four-year degrees. She sits on advisory boards to ensure entry-level education matches real-world AI skills needs, since the traditional experience requirements barrier is becoming harder to overcome.

What fundamental security problems does Janet say still haven't been addressed industry-wide?

Despite advances in tools, many organizations still run outdated, unsupported systems that resist modern security approaches. Janet attributes this to business prioritization outside tech companies - legacy systems are often 'good enough,' forcing security teams to protect multiple versions with non-standard methods instead of modernizing.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

There are a handful of genuinely useful frameworks - the four-category board framing and the cross-industry 'thing you can't shut off' insight - but the episode is heavily padded with host affirmations, circular summaries, and surface-level AI commentary that doesn't advance past the obvious. Insight-to-filler ratio is low.

there's always the thing you can't shut off. Whether it's because, you know, I worked in biotech and in biotech you actually grow your medicine, right? It's living, it's a living organism, right? So you can't shut down the manufacturing line
I think of it in four different categories...what is it that keeps our company operating? So operational. What is it that keeps our company afloat? So financial. And then how do we keep customers coming in? So reputation trust...And then of course, regulatory.

Originality

7 / 20

The 'thing you can't shut off' framing is a legitimate cross-industry insight that practitioners will recognize. However, most ideas - AI as the new internet, data is an asset, align security to the business - are well-worn CISO talking points, and both host and guest independently reach for the same AI/dot-com analogy, signalling how well-trodden the territory is.

there's always the thing you can't shut off
it's kind of like when the Internet first came out. So it's so funny that you mentioned that because it was like the same thing

Guest Caliber

11 / 20

Janet is a genuine multi-industry CISO practitioner - pharma, biotech, cruise lines, broadcast media, healthcare - which is legitimately uncommon and gives her real cross-sector credibility. However, the transcript reveals limited depth: she avoids naming companies or incidents, her book is a career self-help title rather than a technical work, and her answers stay general throughout.

my interest in different industries has been intentional because I really love to take what I know how to do, which is, you know, build a cybersecurity function or mature cybersecurity function
I don't really want to go into details or divulge companies or anything like that

Specificity & Evidence

5 / 20

The episode is strikingly thin on concrete data - no named companies, no incident timelines, no dollar figures, no tool names, and the guest explicitly declines to provide details on past incidents. The most specific moment (biotech manufacturing of biologics) is illustrative but still unnamed and anecdotal.

I don't really want to go into details or divulge companies or anything like that
some of them value the data. But Some of them don't value it as much as they should

Conversational Craft

6 / 20

The host asks some reasonable opening questions but consistently undermines follow-up by paraphrasing back rather than probing, interjecting personal anecdotes that eat time, and offering uncritical affirmations ('super cool,' 'fascinating,' 'super interesting') after nearly every answer. No claim is challenged and several natural opportunities for deeper follow-up are missed.

That's super cool. So figuring out what their priorities are, what they're interested in, then using those four categories
Yeah, totally. Yep. Yeah. Tying back to operational or obviously compliance is like. Yeah, it's a kind of a pass fail type of situation

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Janetguest62%
  • Host38%

Most-used words

data42industry24security21love16different15interesting13super13feel13sure13value13book12across9curious9cool9team9worked9

Episode notes

Janet Heins has led cybersecurity programs in pharma, manufacturing, cruise lines, broadcast media, and healthcare. Every industry felt unique from the inside, and they are. But the patterns she's found underneath are what make this conversation worth listening to. Every industry has a system that can't be shut off, even when security demands it. Every organization has legacy infrastructure that's too embedded to replace and too old to protect with modern tools. And almost no company has a dedicated leader responsible for governing the data that everything else depends on. In this episode, Janet walks through what she's learned moving across industries by design. She shares the four-category framework she uses to get board buy-in for cybersecurity investments: operational, financial, reputational, and regulatory. She explains why aligning security to the company's mission is the difference between being seen as the department that says no and being treated as a strategic partner. And she gets into why data governance is the gap that's making every other cybersecurity and AI challenge harder than it needs to be.

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

Host: I have Janet here today. Excited to have you today. Thanks for coming on the show. So, Janet, I'm really excited for our conversation because she's had a very interesting career. We'll get into it working as a CISO and security leader across multiple industries. She's also an author, which we'll talk about her book and all sorts of fun stuff. So we're looking forward to our conversation. Janet. Um, let's just jump right in. My first question, which we're just talking about before I hit record, was you've probably heard it's all over the news. Obviously, a couple weeks ago, Claude, uh, Mythos, uh, had their little, uh, industry announcement. And, uh, and then obviously last week, as we're recording this on. On May 4, ChatGPT 5.5 Cyber came out. So, yeah, I wanted to start the conversation. It's a big topic, but AI, right? What. How are we thinking about AI? Maybe from the defense side, but then also as the tax surface. So, yeah, just love to hear your thoughts, Janet. Let's start there.

Janet: Yeah, I mean, I think there's like, there's a good. The good and the bad. Right. And I think there's a flip side for each. So having the ability to do what these tools do and kind of, you know, self assess, if you will, if you've got the. If you're authorized to use them. I understand ChatGPT 5.5 Cyber is limited access, just like the other one. Right. Um, hopefully they can keep the bad guys out, but it's gonna uncover things that, you know, humans can't. Right. Or wouldn't have the time to. Not in the same. At the same speed. And that's good. They can. Things that we didn't know about that we can fix. But on the flip side, if that information gets into the wrong hands, it's also exposing us and, you know, our systems to vulnerabilities that normally wouldn't have been seen. So. So I think, you know, if with the right guidelines and the right policies and the right usage, they're. They're. They're good. You know, that's their intention. Right.

Host: Thanks for sharing. Super interesting. I'm curious how you think about maybe going a little bit deeper in the AI front. How do you think about either, like, enabling your teams or training or continue education as it relates to AI and thinking through. It's almost like we're in this, like, retooling era. Like, I. I was talking to somebody this morning. I'm like, I kind of feel like my parents maybe in the.com era or you know as like uh, or in the 90s as like cell phones were started becoming ubiquitous in the Internet. And uh, for me like I'm like oh, I can kind of relate. I kind of feel what they felt of like this is like every week I'm having to learn something new and I have to learn these new skills. I'm just curious how you think about. Yeah. Re. Re. Tooling this. The, the cybersecurity practitioner and. Yeah, just. Any thoughts there?

Janet: Yeah, I mean it's, it's just, it's another uh. And I want to say it's the same because it's bigger and I don't know, more, much more challenging AI is um, but it's a, it's another vector. Right. It's another place we have to you know, think about how it can be used to take advantage of us, take advantage of our companies, our data. It's you know I kind of someone I was talking to recently about AI was saying it's kind of like when the Internet first came out. So it's so funny that you mentioned that because it was like the same thing. It was. Everybody has access to it, right. And it's not so it's, it's uh. But do they really know what they have access to and how it's you know, what, what it can do? Right. It sounds really cool. Everyone wants to be able to you know, say they've got this experience or get this experience. So I know, you know my, my team, some people on my team are kind of doing like a self teaching making sure that they're staying up to date, you know, apprised of what's going on. Some people getting certifications, that kind of thing. So I think that the people who are proactive in this, in respect to this are going to do well. I mean if you're you know, not going to think, not going to get involved in AI when. In learning about AI and how it's used and how you can use it at your company for your own personal use. I think you're going to get left behind for.

Host: Yeah, yeah, agreed. I, I feel it. I. You feel the shift and even how things are, things are accelerating and, and obviously an upside. Right. I think leaning into that upside, leaning into that potential of like how can we be more efficient and dissimilar to. To how the dot com era. So super cool. Thanks for sharing. Oh yeah, please.

Janet: I would add to that um, one of the things I sit on an advisory ah, committee for High uh, Point University here in North Carolina. And um, that's what we're talking about. Like what's the curriculum need to look like for these freshmen coming in? You know, they're going to be in school for four years. Right. What are, what are they, what do they need to learn so that in four years when they're launched out into the real world, their skills are, you know, applicable and useful. So that's, that's another kind of way to think about it. Right. Those entry level jobs might not be there anymore. So I think we're coming, we're going through probably one of the biggest changes.

Host: Yeah, I've, uh, I, I feel for people that are just getting started because I have a guy that goes to my church that is getting, trying to get into security and he's, you know, know, taking some courses and, and stuff and I've tried to give them some, you know, some intros to folks and uh, you know, try to get some internships and it's just hard. I mean number one, like everyone wants experience. Uh, seems like there's kind of a running joke in cyber that you need five years experience to get a introductory job. You know, you see these posts on LinkedIn and, and so yeah, thinking about like folks that are coming into the space and like AI and education and imagine for that curriculum, you'd probably want every six months to reevaluate the curriculum because things are changing so fast, which is like how do you build a curriculum for you?

Janet: I almost have to like create front of this, like, you know, right in front of the students coming into it. Like if they're going into their junior year, here's what the junior is going to look like. Yeah, it's going to have to be pretty dynamic. But that's not typically how universities work.

Host: So that's, so that's so interesting. I'm sure they're going to have to be more innovative and just uh, more scrappy. Um, that's fascinating. I never thought about that from the four year degree side. Yeah, super cool. Thanks for sharing. Let's change gears a little bit. I'd love to hear, um, maybe some honest, maybe some hot takes on the industry. And we were kind of talking a little bit off, off, uh, before we hit record. Yeah. Just curious what's working. Let's start with kind of what's working in cyber security. Um, that doesn't usually get credit for. And then we'll go to the other side, the negative, like what's broken? Um, that, that needs to be talked about. So let's talk about what's, what's like, what's really working really well that you feel like people don't talk about and don't highlight.

Janet: Yeah, well, I mean we, we live in a. I work, I work in an organization regardless of what company. Right. I work in a security organization regardless of the company. And as long as things are going really well and nobody, nobody hears anything. Right. So I think the, the, the tooling for security seem, is going well. There's a lot of good things out there, a lot of good tools out there that help protect companies. And I think that those, you know, they're, they're doing their best when nobody's talking about it. So I think that that's, and that's kind of always been a challenge too because then it's like, what are you doing? Well, I'm stopping this and I'm stopping that and I'm preventing that and, or, you know, uh, so it's, it's. That part of the job will never, I don't think I'll ever change.

Host: Fascinating. Do you feel like, um, either the vendors or the greater ecosystem is evolving fast enough? I know this is a little off script, but any, any thoughts there as far as like, do you feel like we're, we're, um. Yeah, we're anticipating the needs and that's, you know, that's why you don't hear, maybe you're not having those security instances. Do you feel like you're getting the support you need?

Janet: Yeah, I think the vendors are starting to, you know, maybe not starting. They've been for a little while focused on data now. And I think that's, that's the key. Right. Uh, but, but what, what the. And by data, I mean in helping protect companies. Data. Right. So whether it's identifying the data that you already have, classifying the data that you have and better protecting it. The, you know, the biggest challenge with AI is it all starts with the data that you have. Right. And if you don't have good data, you're not going to get the best results. So, um, I don't know that. I still think there's a little bit of a disconnect though between protecting data and actually governing the data that you have, like good data governance. So I haven't seen a lot of chief data roles and I think that that's information, it doesn't have to be called data leaders that actually are stewards of the company's data. And I think that companies in general that I've experienced, some of them value the data. But Some of them don't value it as much as they should. It's their, it's their, it's their digital, it's their assets. Right. The data is, is an, data is an asset and an asset's got value and you got to treat it like, uh, that.

Host: Interesting. I'd love to hear more about data governance. What is your, what's the problem? You see that more leadership in data governance could solve? What do you see in organizations?

Janet: Well, I think that data is, you know, tossed around and replicated and storage is cheap and we keep a lot of it, maybe we don't need to keep it all. So there's sort of like the life cycle, um, like data life cycle, right from creation to actual usage of the data, how it's stored, you know, when is it, when is it retired, is it archived? Is it completely deleted? So I just think of, like, if you think of all the different data repositories a company has that has potentially duplicate data, that, you know, there's a whole like, which data is the source of truth and how do we know? And I think that that's, you know, when you have someone who's actually thinking about what is the information that's valuable to the company and how do we treat it and where do we, where do we, where do we put it and how do we know it's the truth of, you know, the source of truth.

Host: Fascinating. Obviously there's a security implication and compliance implication, risk implications. But if I'm hearing you correctly, there's probably also like a performance implication as far as the organization doesn't have the right data or they're using too many different data sources. And so the efficiency of the organization is that what kind of getting at, as far as not having a single source of truth?

Janet: Yeah, it's efficiency. And it's also, if I ask five people, you know, a question and they go to different data sources, I'm going to get five different answers. So it's also making sure that, you know, you get the answer and it's the correct answer. And that's where I kind of go back to AI. Right. If we've got all this data and we're feeding it in, how do we know AI is going to give us the right answer?

Host: Yeah, fascinating. Anything else there? Anything else? It sounds like it's a big area. Like any other reasons why folks should like, you know, double click on data governance and maybe, I know it's an interesting topic especially AI governance is, uh, ties into that also. But yeah, any other Thoughts there?

Janet: Well, I just think that data is, is a company's data is. I think I kind of said this before, right. It's, it's valuable to the company and it has different, different data has different value. And I don't think people think of it, I don't think it's thought of unless you're protecting data like we do in information security. I don't think it's thought of as something that's, you know, you've got to really put a science around and not just let it happen. Because that's what I think has been happening at companies is they just kind of let a data sprawl happen or replication happen or you know, the lack of, really lack of governance. Knowing where it is and knowing what it's used for and knowing when it's no longer useful.

Host: Yeah, that's fascinating. That's a really interesting uh, topic. Especially in this world of AI where it is all about the data. Like if you actually want to get good use about, get useful outcomes from AI, you need to input effective data. And so I imagine with organizations where yeah things haven't been AI almost as like this force, force multiplier or this force for lizing things in the sense of like hey, we need to um. Yeah, that has the potential to bring things together which I think is actually really exciting. Like cross functional like departments that are just nations. I know, you know, as you get into large organizations this is like crazy complex and getting everyone to get point in the right direction is really hard. And so if I'm hearing you correctly, if you can figure out the data problem, obviously security and privacy and compliance um, is super important and near to our hearts but also from the utilization, utilization data governance can be that uh, unlock and really probably the only way you can probably figure out how to use AI effectively is if you have your data dialed in. So that's really interesting. Thanks for sharing.

Janet: I agree.

Host: What is there any other areas of the cybersecurity industry, kind of looking at the industry in general that you feel like that's broken, that no one is talking about, that you feel like needs to be talked about?

Janet: Well, I think that there's, I think we've still got you know, in, in a lot of cases and a lot of people I talk to my similar roles as me. I think we still struggle with some of the fundamentals like you know, let's talk about just good it, high tech hygiene, right. Having systems that are out, you know, that are you know, out of support and you know, older and having to, you know, run things that run systems that, uh, you know, or I should say protect, uh, systems that. That aren't modern enough to really protect with modern tools. So I've come across that at companies I've worked for, I come across it with, you know, people I talk to. So I think, you know, we've got all this great new stuff coming out, but then we still haven't cleaned up all the old stuff. And by we, I mean like the industry in general. Right. Yeah.

Host: Interesting. I love that. You'd be curious what. Where do you feel like the main hindrance for that to happen? Is it a resource constraint? Is it a, uh, getting buy in across other departments? Is it. Yeah, just curious. What, why, why you think prioritization.

Janet: I think it's like business prioritization. Like, what's. So I haven't. I have yet to work for a technology company. Right. So I would think maybe at technology companies where that's their business, that they're better at that because they'd want, you know, they're selling a technology. They want to have the highest tech stuff and not have any of this legacy stuff laying around. Whereas when you're in a different industry, that's not your primary goal. Right. Is to be, you know, on top of everything when it comes to technology. And some stuff is just good enough. Right. And without the, um, understanding of, you know, what we do in security, the challenges that come with having those kind of things. Right. So you're always dealing with multiple versions of things and some of them are outdated, and you've got to come up with different ways to protect them than kind of the traditional. Well, not even the traditional. The modern way. Right. So, yeah.

Host: Fascinating. So you feel like a prior. A business prioritization? I think that's actually one of another topic we. We have on the agenda, which is around getting buy in. Uh, what is your thoughts on. Let's talk about getting buy in with executives or boards, um, or whoever you report to. I'm curious what's worked for you to kind of help, obviously, with prioritizing security and prioritizing some of the things you think are important.

Janet: Yeah, I think I like to focus my conversations with executive leadership and with the boards that I've met with over the course of my career with the things that they are concerned about. So if I can frame what I'm trying to accomplish, which I should only be trying to accomplish things that frame up into, like, what they're thinking about as a board member for the company or executive member, of the executive team. Um, and so I think of it in four different categories that we need to like, what is it that keeps our company operating? So operational. What is it that keeps our company afloat? So financial. And then how do we keep customers coming in? So reputation trust. Right. Consumer trust. Um, and then of course, regulatory. So if I can frame what the initiatives that I'm looking to do and the roadmap that I've laid out into those one and sometimes many of those four categories, depending on the initiative, I find that it gets a lot more traction and a lot more attention.

Host: That's super cool. So figuring out what their priorities are, what they're interested in, then using those four categories to, you know, uh, hopefully achieving all those at some point or another. Um, and roll those up into their. Yeah.

Janet: If I talk about an initiative and say, listen, this is going to make sure that we still are going to be able to operate whatever we do, whatever the industry's in. Right. Whether it's broadcasting radio shows or, you know, cruise ships going out, you know, leaving port or, you know, to go on cruises or, you know, providing healthcare, like with my current company to our patients, that if that operation, that, that's one of the four. Right. Keeping us operational. So if anything that I identify as a risk to that from a cyber perspective, you know, I categorize it that way. This is an operational risk because I know their parent, you know, they, they want to make sure the company's still running and they want to make sure the company's still making money. And they want. In order to make money, you've got to have trust in your, you know, your consumer base has to trust you. Right. And so, and then of course the regulators need to, you know, let you still run. So it's, it's, it's sort of like common sense and it's a practice. I can kind of lift that. Lift and shift that model really to any industry.

Host: I love that. That's super cool. Do you do like risk quantification or anything like that? Are you familiar with that?

Janet: Yeah, I haven't gotten to.

Host: Yeah.

Janet: Having um, to do that. Usually it's more like con. Foundational than it is, you know, number crunching and uh. Yeah. And, and that kind of. I think it's some of. It's just really common sense.

Host: Yeah, totally. Yep. Yeah. Tying back to operational or obviously compliance is like. Yeah, it's a kind of a pass fail type of situation. So it's pretty, pretty cut and dry. Well, cool. Let's, let's switch Gears a little bit. You, you kind of already hinted at it, but you've, you've worked in a bunch of really interesting industries. Some of them I've never worked in. And so I'm personally curious that you've worked in pharma, um, manufacturing, cruise lines, broadcast media, and now healthcare. I probably missed a few there. But I'm just curious what's unique about each industry. And then obviously we don't have an hour, so, you know, high level, um, and then what's been the same. I'm just curious what's been the same.

Janet: Yeah, my, and my interest in different industries has been intentional because I really love to take what I know how to do, which is, you know, build a cybersecurity function or mature cybersecurity function, and really learn about what makes this particular, you know, that particular industry ticket. Like, I love to learn. That's one of my, you know, lifelong loves. And so learn new things. So learning the new industries has been really, you know, and I've only been in, you know, you think about how many industries are in the world, right? And I've only been in like a handful, so. But I realize that it's maybe more than most. Right. Um, and I think that each industry that I've been in, um, definitely feels like they're unique, right? Like they've got this unique thing that's really challenging and I, I think they do. But I also think that these, uh, like every industry also has some things that are the same like across industry that I've seen. Like I'll give you a couple examples. One example is there's always the thing you can't shut off. Whether it's because, you know, I worked in biotech and in biotech you actually grow your medicine, right? It's living, it's a living organism, right? So you can't shut down the manufacturing line versus like if you're making a pill, like a pharmaceutical company, you can sh, you can, you know, if you have to, you can shut down the manufacturer. Nobody wants to, but you could. If you shut down the manufacturing of a bio biologic, you're, you know, saying goodbye to a huge batch, right? Um, so there's those kind of things. Um, there's always something unique. It's something that you can't turn off. So from a security perspective, when you need to implement, you know, install, you know, install patches or reboot a system or implement a, uh, you know, an endpoint tool or whatever the case may be that you need to interrupt something that can't be shut off. It's a challenge, right? You've got to figure out how to do it a different way. So there, there are some common things, themes across companies. That's just like one example that I, that I like to use M the thing that can't be shut off. So I'm sure people are listening to this, are going to go, oh yeah, that's true. We have one of those. Right?

Host: Yeah, that's, that's super interesting. Any differences, idiosyncrasies of different industries? Anything that you've been really fascinated by that? Well, I think it's um, if anyone is.

Janet: I think, I think what drives the company, like what's, whether the company's mission or the company's purpose. Right. You know, they're all over the place, you know, and for good reason. Right. Because they're in different industries. You know, when, when I worked for the cruise line, you know, it was all about making vacations fun, right. So that was like a very upbeat positive who doesn't want to have fun, who doesn't want to go on vacation. Right. It's a great thing to do. So I think everybody's mission, you know, or, or purpose, uh, is very, is different. And I think it's really important to align yourself to the company's purpose so that you know that your messages are, are heard because you're, you're doing what you, you're contributing to the company's overall objective and you can demonstrate that because it's, it's hard to align. I mean, I find it. Years I've been in this business, I find it um, hard for the receivers of your message to kind of connect where you fit in. And so if you can align what you do directly to the purpose of the company and how the company promotes their purpose. Right. What's, what's the language they use? I think it's really important.

Host: I love that we were talking about that before we hit record of a gist that yeah, I think security can get siloed sometimes. And uh, and there's a way to obviously create that cross collaboration and get that buy in is to understand not only your peers, mission and goals, but also like you said, the executives, et cetera, but then also the overall organization and that you're. We're, we're kind of joking that you kind of have two jobs, right? You have the security job, but then you also have whatever industry you're in, right. You kind of have to be. Understand that industry, understand that. I love that advice because I think that can be sometimes like my background's in marketing. So if I'm just, yeah, I can be a great marketer, but horrible in the industry I'm working in because I don't read the news outlets, I'm not going to the conferences, I'm not getting the certifications and I'm not really understanding the, the multiple levels of every industry and the nuances of every industry. And then I love the why to the business. What's the business about? What's that mission? And, and it's another thing too. I think security can. Is we're, uh, yeah, we're kind of throwing out the term back office. Right. And it can be seen as that. Whereas if you're actually a part of this mission and include and seen about being an important part of the mission, you'll get more resources, you'll get more buy in, your job will be easier. Um, it obviously takes that extra level of work, right. Where you kind of having two jobs to do versus just one. But super important, I think.

Janet: And I've also found that you'll. Then you'll be included. People will go, oh, we don't. Let's not forget about security because they're enabling us to do this. Right. As opposed to, I think like the old school way of thinking, let's not tell security because they're just going to tell us. No, it's like you want to show that we'll, we'll make it sure that you're able to do what you want to do in a way that keeps, you know, in our case, it's keeping our patients data secure. Right. And regardless, you know, pick your industry. What is it that you're trying to keep, you know, that.

Host: That's super great. Yeah. And I think there's uh. Oh, you could probably write another book. Maybe that's what your book's about, which we'll get into in just a second. But there is, that's a whole area where I think is just my perception of it is, you know, as a marketer by trade, I'm all about being in front of people and getting the message out. And I think that skill set, you know, drew me to this field. Whereas I think cybersecurity folks could use some of that. Right. The industry could use some of, uh, that. Not just any particular cybersecurity folks, the industry could use some of that evangelism, some of that buy in some of that cross collaboration. Because that's the only way any function can work is if it really well is if we are working Together, so love that. That's super cool. Um, let's. I just want to hear a story. I have a couple more topics and we only got a couple more minutes left here, but I would love to hear, is there any interest. I love stories. So if there's a story you can share with me, that's, that's, that's uh, kind of shaped your experience maybe, or a notable moment, an aha moment, something in your career in cyber that's just kind of been life changing. Is there a story or a situation that you just like, you know, really learned a lot from or shaped your perception of the industry? Anything, Anything come to mind?

Janet: Well, I think that anyone who's been through a, uh, major security incident and while they're in uh, a cybersecurity role has, has had that happen to them. Right. It's been a major eye opener. So I, I would say that, you know, having been through a few, I don't really want to go into details or divulge companies or anything like that. But you know, you get hit over the head, right? You think you're going about your business, you're either entering it. It's usually, usually a weekend, I don't know why, but usually getting ready to enter into the weekend and then all of a sudden you got flipped completely upside down, right? And all those things you practice for and all those things you review and all those call trees that you have in place, get tested, right? In real time. Probably, um, most memorable, memorable to me because it's probably the highest stress that I've ever been in. And it, and it's, it's really around the clock. And you know, humans aren't made to work around the clock. So that's always fun too because it's not like you can go, okay, we're all going to go to sleep now because, you know, can we just, you know, close the incident for now? We'll open it back up in the morning. It doesn't work that way, right? So it's happening real time 24, 7, sometimes days on end. Some people have been through it. You know, it's been months on end. So I, I think that that's uh, I think the thing that I come out of that on the other side having been through a few is it's, it's really one of the best team building experiences I've ever been through. I wouldn't wish it on anybody. But you know, they always say when you're in the trenches with people, you come out, you know, whatever you want to call it sisters, brothers, best friends, uh, you know, because you've gone through this very hard thing together in a short period of time and it was, you know, you're thrown into it. So I would say, like I said, without kind of giving away any of the details of it, I think that the couple times I've been through very good sized incidents that have, you know, fortunately ended okay, uh, for everybody, including the company, those are probably the most impactful to me and actually have made me want to stay in the industry. Because you, you know, it's your opportunity to really like be there for your company and, and get it, make things better.

Host: That's super cool. Wow. I can imagine you probably are never really a. You can never really say you're like, hey, I'm trying to encapsulate this idea of like, you can never really say you're like a true security practitioner until you've experienced that it's probably such a life changing experience. Like it's so I'm sure it, like, I'm sure it completely changed how you view security. It completely. Like, I'm sure you carry that, It's a form of trauma, right? You carry that with you. And uh, so it's almost, yeah, it's almost like you uh, don't really know, you know, how secure you are or um, how strong you are as a security person or um. And it probably all made you a lot stronger. Right. And even obviously made you more excited to be in the industry, which is a really positive outcome because I imagine, um, in certain situations that doesn't. But fascinating. Thank you for sharing that. That's really interesting. Cool. A couple minutes left. I'd love to hit on your book. Uh, it's called Go ahead, ask for. Tell me about your book.

Janet: It's backwards or not? Might be backwards.

Host: Oh, it's not. I see it. Okay.

Janet: That's my book, so I'm selling it on Amazon. Just give you the. Do that because I'm not good at the marketing part. So I'll, uh, you know, I'll work on that part.

Host: Love it.

Janet: Before I forget, uh, all formats, you know, book, e audio. Um, so the book is. I developed it after I realized I had a system that I would never, you know, up until I started thinking about it, never really call a system for how I've progressed in my career. And it's basically for me asking for what I want. Right. And in asking, I don't mean like, may I? May I please. Right? It's not that kind of asking. It's really positioning yourself so that it's it your value is seen and your value is known, which means you have to make yourself visible and you have to make your value visible which a lot of people are very uncomfortable with. It's can be seen as a negative, it can be seen as self promotion. I've actually been um, misinterpreted I'll call it for uh, showing the value that I bring. And I don't mean just me but like the value that my work brings. The value that my you know, having a team, uh, you know, leading a team brings and having a strong team to the company and aligns to like go back to kind of like aligning to the purpose of the company. So if you can get your purpose aligned with the company's purpose and you are able to make your value visible, which again I say that that way because a lot of people just don't do that. They just you know, and then ask for something with that backing. Like I'm going to do this because it's going to be good for the company. Can you support me be like that? Kind of just a little, a little bit more than just a, ah, may I please have that job? Right. So I've gotten some of my promotions. That's how I've gotten my um, you know, fun assignments that I wanted to be on companies. One case, it was an assignment across across functional uh, assignment across the company and I was the one person representing it for that team. A small team, like a dozen people.

Host: Um, um.

Janet: And uh, yeah, so that's kind of the system I've documented in my book. And I tell a lot of fun stories about my career. Some of them are not so great but it's. You like stories. I figured I'd share that.

Host: Yeah.

Janet: Somewhere where it's worked and somewhere where it hasn't worked. So you know, you can learn from those. Like if you get a no on a question, you ask for something, you get a no, you get data, you get, you can learn from it.

Host: Love that. Well, I'll have to go get my copy because that sounds super interesting and I think once again it's almost been the theme of our conversation. A lot of ways of, of that kind of forward facing, asking for it, being out there, showing your work, you know, cross collaborating, showing empathy, getting buy in from your peers. Um, is there any specific, you know, how does it show up in cyber? Obviously your stories in your book will elaborate but in, in closing, is there any little nugget you can share with audience of maybe Something tactical that they can do a little bit more about. Showing their work, showing up, showing their work, and then also asking for stuff. Is there anything that comes to mind?

Janet: Well, I think for showing your work, I think it's important to make sure that the people that are in the rooms that you don't get to be in. This could be your. Your. This could be your boss's peers, your might be your peers, depending on the way your department's laid out. Just making sure you're connecting with those people, like I said, understanding what it is they do, understanding what it is that they're concerned about. Right? So they've got goals they're trying to reach. They've got things that keep them up at night. Like, what are those things? And then connecting to those things, connecting what you're doing to what they're doing.

Host: Right?

Janet: And then they're gonna, you know, see the value, right? That. That's the. That's the kind of bring the value to them and show it to them. Right. And tie it to something that's memorable to them, that's important to them. So that would be my. I don't know if that. That answers your question exactly, but that's my tip.

Host: It does. Yep. Super helpful. That's great. Well, Jen, I know we're up on time here. Thank you again so much for coming on the show, uh, sharing your insights. A lot of interesting stuff I'll be thinking about. I'll have to go get a copy of your book, and I'll throw, uh, the link to your book in the show notes so folks can, uh, easily get it on Amazon. Thanks again, Janet, for coming on. Really appreciate it.

Janet: Thank you. Take care.

Host: Take care. Thanks. Thanks, everyone, for listening. Take care.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 224: How OpenAI’s GTM leader structures teams and spots standout candidates with Keith JonesHumans of Martech · on Data governance87 / 100
  • 204: The Surprising Connection Between Data Foundations and AI's Value CeilingAlter Everything · on Data governance83 / 100
  • Episode 105: From AI Idea to Production RealityValue Driven Data Science · on Data governance82 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Data governance79 / 100
  • From Ai4: Coca-Cola FEMSA's Jose Martinez on balancing continuous improvement and CX consistencyThe Agile Brand with Greg Kihlström® · on Data governance78 / 100
  • Why Great AI Solutions Start with Listening: Navigating the Data Quality Crisis with Joe Reis Part 2Bringing Data and AI to Life · on Data governance77 / 100

More from Cybersecurity Ecosystem Show

All episodes →
  • The Dark Knight of Game Economies on AI, Curiosity, and Guardrails72 / 100
  • Shift Left, Real Moats, and Where Your Data Actually Goes, with Chris Bollerud69 / 100
  • Line Cook to CISO: Eric Freeman on AI, Access Control, and Why Security Is Just Dinner Prep74 / 100
  • OEM Partnerships: What Every Practitioner, Vendor, and Investor Needs to Understand82 / 100
  • Code War: How Nations Hack, Spy & Shape the Digital Battlefield - Allie Mellen on Cybersecurity’s Geopolitical Evolution
Explore the best B2B Engineering & DevTools podcasts →
All Cybersecurity Ecosystem Show episodes →