The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Get IT Started. Get IT Done.
Get IT Started. Get IT Done. artwork

Episode 32 - Tyler Farrar, CISO at Exabeam

Get IT Started. Get IT Done. · 2024-02-15 · 39 min

0:00--:--

Key moments - from our scoring

Substance score

34 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality5 / 20
Guest Caliber13 / 20
Specificity & Evidence6 / 20
Conversational Craft5 / 20

Tyler Farrar brings a unique military-to-enterprise background to his role as CISO at Exabeam, a security operations platform built on behavioral analytics to detect credential-based attacks. The discussion covers Exabeam's core value proposition - proactive threat detection rather than reactive incident response - and how organizations like Adobe and Cisco deployed it successfully to shift from reactive SOC operations to predictive security intelligence. Farrar shares his 11-year Navy career at Fort Meade as a cryptologic warfare officer managing signals intelligence and cyber operations, his aerospace engineering degree from the Naval Academy, his time at defense contractor Maxar Technologies, and his consulting work at KPMG translating military-grade security operations into commercial practice. The conversation also explores leadership philosophy, team building around diversity of thought, and the distinction between management and authentic leadership - emphasizing listening, accountability, ego-checking, and removing execution blockers for teams.

Key takeaways

  • →Exabeam's behavioral analytics platform focuses on detecting misuse of compromised credentials, which underlies phishing, ransomware, and malware attacks - making it a proactive rather than reactive security tool.
  • →Transitioning from a large regulated defense contractor to a security startup involves less-defined processes but similar core security imperatives around prevention, hygiene, detection, and tooling.
  • →Authentic leadership requires diversity of thought, empowerment to challenge decisions, checking ego at the door, and clearing execution blockers rather than micromanaging team decisions.
  • →Decision-making velocity matters: reversible decisions should be made quickly, while irreversible decisions warrant deliberation and comfort with incomplete information.
  • →Effective CISOs must listen to their team and domain experts rather than assuming they have all answers, and should take full ownership and accountability for team performance including failures.

Guests

Tyler Farrar

Topics in this episode

Security operationsBehavioral analyticsMITRE ATT&CK frameworkExabeamcredential-based attacksFort Meadecryptologic warfaresignals intelligenceUS Cyber CommandMaxar Technologies

Questions this episode answers

What does Exabeam do and why would an organization deploy it?

Exabeam is a security operations platform using behavioral analytics and alert triage to detect threats before they impact the organization, helping teams shift from reactive incident response to proactive threat detection by identifying misuse of compromised credentials underlying phishing, ransomware, and malware attacks.

What is a cryptologic warfare officer and what do they do in the US Navy?

A cryptologic warfare officer manages signals intelligence (monitoring communications and electronic signals) and cyber operations, protecting US military and critical infrastructure while also providing offensive cyber capabilities for forward-deployed military commands - essentially non-kinetic warfare in cyberspace.

How did Tyler Farrar transition from the Navy to becoming a CISO?

After 11 years in the Navy stationed at Fort Meade as a cryptologic warfare officer (with an aerospace engineering degree from the Naval Academy), he consulted at KPMG on security operations and threat intelligence, then joined defense contractor Maxar Technologies where he became a customer of Exabeam before being hired as their CISO.

What is the key difference between management and leadership according to Tyler?

Anyone can be a leader regardless of management title, but managers must be leaders; true leadership requires accountability, ownership of team mistakes, removing execution blockers, and empowering team members to challenge decisions - not just managing tasks or blaming others for failures.

What advice does Tyler give to people entering cybersecurity careers?

Listen to the experts and smarter people around you since you won't be the smartest person in the room; identify what interests you within the broad cybersecurity field, follow established training pathways, and learn from others' recommendations even when you have decision authority.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is dominated by career biography, a vendor product pitch, and generic leadership/lifestyle advice. The only substantive security insight is that breaches stem from credential misuse, which is a well-known observation, and there is almost no tactical depth beyond that.

what Exabeam really identified through all these breaches that we see out there is that they're rooted in really one thing and that's the misuse of credentials
security is not a one time effort. It's an ongoing process. There is no finish line.

Originality

5 / 20

The episode recycles well-worn leadership bromides (check ego, listen, diversity of thought) and the only attempt at a fresh frame is rebranding 'work-life balance' as 'work-life integration,' which is a minor terminological distinction rather than a genuinely new idea.

work life integration. Because when I think about work life balance, it seems to be like a balanced scale
I look for diversity of thought. That's, that's huge for me

Guest Caliber

13 / 20

Tyler Farrar has legitimately high-caliber credentials - Naval Academy aerospace engineering, US Cyber Command cryptologic warfare officer, KPMG consulting, and CISO at an aerospace defense company before Exabeam - but the conversation fails to extract operational depth commensurate with that experience.

I was stationed at Fort Meade, Maryland as a cryptologic warfare officer
served within U.S. cyber Command. So a lot of my work, I mentioned there was a few aspects of cybersecurity or cyber operations. Most of my work was involved in the space of protecting US Critical infrastructure

Specificity & Evidence

6 / 20

Concrete details are limited almost entirely to biographical facts (Maxar headcount, years of Navy service); there are no security program metrics, no incident data, no named threat actors or campaigns, and the Exabeam deployment anecdote is left entirely vague.

when I was there it was roughly, I'd say 6,000, 7,000 uh, employees
within the first few weeks of us deploying Exabeam and starting to get that data coming in, we were finding stuff

Conversational Craft

5 / 20

The host asks broad, biographical prompts and frequently redirects to personal anecdotes about his own career at Adobe and Cisco, leaving no room for genuine follow-up or productive challenge; no security claims are probed or contested throughout the episode.

Awesome. Ah, Tyler, welcome to the show. You know, there's so many things to peel apart there.
that's awesome. Um, I love, I love you say how this is different from a leader.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C49%
  • Speaker B49%
  • Speaker A2%

Most-used words

security41team19exabeam17leader17cyber17love11tyler10home10operations9navy9life9different9maxar8intelligence8important8decision8

Episode notes

Hello and welcome to Get It Started Get It Done , the Banyan Security podcast covering the security industry and beyond. In this episode, our host and Banyan's Chief Security Officer Den Jones speaks with Tyler Farrar . Tyler is CISO at Exabeam and is a veteran security leader with a background in defense department cyber operations and the US Navy. We hope you enjoy Den's discussion with Tyler Farrar. About Tyler: Tyler Farrar is the Chief Information Security Officer (CISO) at Exabeam. In this role, he is responsible for protecting Exabeam - its employees, customers, and data assets - against present and future digital threats. Farrar also leads efforts in supporting current and prospective customers’ move to the Exabeam cloud-native New-Scale SIEM and security operations platform by helping them to address cloud security compliance barriers. With over 17 years of broad and diversified technical experience, Farrar is recognized as a business-focused and results-oriented leader with a proven track record of advancing organizational security programs.

Full transcript

39 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello and welcome to Get It Started, get it Done, the Banyan Security podcast covering the security industry and beyond. In this episode, our host and Banyan's Chief Security officer, Den Jones, speaks with Tyler Farrar. Tyler is CISO at Exabeam and is a veteran security leader with a background in Defense department cyber operations and the US Navy. We hope you enjoy dense discussion with Tyler Farrar.

Speaker B: Hi, everybody. Welcome to another episode of get it Started, get it Done. I'm your host with the win and the wisdom, Dan Jones. And, uh, every episode we try and find interesting and cool guests to bring on. Hopefully you'll learn something. We'll hopefully bring a little bit of, uh, wit, uh, maybe that's a Scottish word, I don't know, uh, but humor and some wisdom, which I guess in tales that we might be somewhat intelligent. Uh, so I'm hopeful that we'll get a bit of that, a bit of both. Uh, so let me introduce today's guest, Tyler Farrar. If I don't butcher your name, the CISO of Exabeam, a company who, um, I've, I've had some great, great fun with deploying when I was at Cisco as part of our Zero Trust endeavor. And, uh, yeah, so I've, I've been a big fan of Exabeam for a number of years. Tyler, welcome to the show. And why don't you introduce yourself?

Speaker C: Oh, thanks for having me, Dan. Um, Tyler Farrar. As Dan mentioned, I'm the chief information security officer at Exabeam, uh, responsible for product security, enterprise security. Uh, prior to Exabeam, I worked at a clear defense contractor called Maxar Technologies. Does really cool space stuff with satellite imagery and satellite manufacturing. I've consulted with KPMG and done things like security operations, threat intelligence, vulnerability management. And prior to consulting with KPMG, I was in the Navy for 11 years, stationed at Fort Meade, Maryland as a cryptologic warfare officer.

Speaker B: Awesome. Ah, Tyler, welcome to the show. You know, there's so many things to peel apart there. Um, well, let's start with a little bit of Exabeam. Do you want to explain, like, who's who for those that don't know? Who is Exab and what does Exabeam do? What, what, what brilliance do you bring to the market? And if we were going to look to put buy your stuff, what would be the reason we'd deploy it?

Speaker C: Yeah, no, absolutely. So Exabeam is a security operations platform, and it helps organizations to detect threats, uh, and defend against cyber attacks. And it's all done through behavioral analytics and alert triage capabilities. And what Exabeam really identified through all these breaches that we see out there is that they're rooted in really one thing and that's the misuse of credentials. So if you look at things like phishing and ransomware and malware, it all ties to compromised credentials. And whether or not that's because the adversary has been able to use those valid credentials of a legitimate user or they've gone inside your organization somehow, the objective is really to use those credentials to access your systems and your data. So that's really what the product um, was built upon and really from the ground up over the last couple of years to be cloud native. And it allows um, our customers to scale and really manage those credential based attacks so that we can know what normal behavior really is in your environment.

Speaker B: Awesome. Yeah. And it's interesting. So I was interesting. I was uh, running enterprise security at Adobe for a number of years and we built a team called Security Intelligence. And my team was kind of like the proactive side and we ran services for the whole company and at that point we used open source stuff. We spent months building and building and we got to this anomalous detection and you know, it worked really well. Um, when I got to Cisco, Cisco is an investor in Exabeam and for us, when I built the same security intelligence team, there was a couple of other competitors in the market. But as an investor into Exabeam, we looked at ah, Exabeam with some serious eyes because uh, does it meet what we need? And then there's this political pressure from above. Right. Um, and I'm not one for political suicide. So we looked at Exabeam and actually we deployed it in a small number of weeks. And this is the thing, the thing to get to that I want to do anomalous detection, alert response, the, the ability to catch bad things before they really impact your environment. That was huge for us. And I know within the first few weeks of us deploying Exabeam and starting to get that data coming in, we were finding stuff. Um, and it's brilliant if you can get to a position where you can do proactive security rather than reactive. I think a lot of people, they'll look at a SIM and they'll use it as a reactive tool as opposed to what you guys are promoting, which is, hey, this is a proactive tool. You can use this before the shit really hits the fan. Um, for me that's what I'd rather spend my money.

Speaker C: Yeah, exactly. Understanding those security objectives and Being able to provide legitimate outcomes for the log sources that you have to detect against. Things like the mitre, ATT and CK framework. Now your outcomes based security operations.

Speaker B: Yeah, exactly. And I used to in both companies. So enterprise security was a proactive. We've delivered a lot of services and my peers, I had a peer both which was the soc, the incident responders. And it used to always be this like tug of war really on the budget like depending on um, how well you can sit there and say I can prevent things from happening and then there's the other guy saying yeah but I need to respond to things happening and if I don't have a big enough team or enough money I can't find stuff. So I think uh, for me there's always that tug of war on the security game of are you proactive or are you reactive and then where do you spend your money? One thing cryptologic warfare officer, I'd love if you can share a little bit. What, what is that role?

Speaker C: Uh, I, I would try to summarize it maybe in two high level buckets. I think the first one is if, if folks listening are familiar at all with the concept of signals intelligence. And signals intelligence goes back decades and maybe the, the best example would be of, of monitoring and understanding signals during things like the Cold War. Right. Communications, whether or not they be voice communications, electronic communications, that's kind of traditional signals intelligence. But as technology has evolved over time and this use of the word cyber or cyber operations or anything, any word with cyber before or after it has come into play. And so that's the other big aspect of the cryptologic warfare community and really more broadly is cyber within the military. And that's a big component. So things for protecting military uh, organizations, um, ways to protect the critical infrastructure within the United States, um and then ways to also be a little bit more if you want to call it proactive or offensive in nature, um, being able to respond when an attack happens on US soil and also being able to provide the same military uh offensive capability in the cyberspace for forward deployed uh military um, commands that you would uh, if it was like a kinetic warfare. So same same kind of ways of if you're dropping the bomb if you will, um, dropping that non kinetic uh, bomb. So that's really the big pieces signals intelligence and cyber operations within the cryptologic warfare community.

Speaker B: Yeah. So in your, in your journey to get to see. So I'd love to hear a little bit about this, the origin story. So you joined the Navy. I'm not sure, but I'm guessing you didn't join as a crypto guy, right? So when you joined the Navy, how did you get into the crypto business? And then what was your journey to Cecil like?

Speaker C: Yeah, quick backstory. So I did, I did enlist in the Navy out of high school. And what was quickly interesting, quick backstory is I actually was interested in enlisting in the army first. And I did go to the army recruiter, and they told me that the, uh, quota had been met for the month and come back next month. Well, later that, that week, or maybe even the next day, I'm sitting in school and the guidance counselor, uh, calls me down and there's a Navy recruiter there, and I talk to him, and the rest is history. But it's very interesting how things like that play out in your life. And it would have been a very different, um, you know, career path had I enlisted in the army instead. So. Yeah. Anyways, listed in the Navy, I served on an aircraft carrier. I did that for about two years. And during that time, I, I did apply for enrollment at the United ah, States Naval Academy. Um, I was accepted. I majored in aerospace engineering there. And so that was kind of my first real dive into, um, technical systems, building, uh, those systems, critical vulnerabilities. It really more was not just an academic thing, but you have a lot of, um, aspects of protecting complex systems within the US Military, the US Government that have parallels with the cybersecurity world. And after I graduated, uh, I was stationed at Fort Meade, Maryland, as I mentioned earlier, became a part of that cryptologic warfare community and served within U.S. cyber Command. So a lot of my work, I mentioned there was a few aspects of cybersecurity or cyber operations. Most of my work was involved in the space of protecting US Critical infrastructure, but having the ability to respond more offensively if necessary, and building out those types of capabilities in order to do so. Um, I completed my service obligation, uh, and that's when I transitioned out from the Navy and I did go to kpmg. I consulted there. Again, translating. Well, a very large organization, strong internal process is pretty comforting for a military member. Yeah, I mean, like I said, I did things like security operations and kind of pushing clients to like, what is, what does security operations look like in the 21st century? What does threat intelligence look like? What does vulnerability management look like? Um, and that was. That was a lot of fun. Got, um, to work in a handful of different industries. And then, um, kind of this amazing opportunity came up where Maxar was hiring and this is an aerospace defense company and it. I'm going to be able to do cyber security there. So now I'm um, both bridging this cyber security experience that I've received in the military with this aerospace engineering knowledge that I learned when I was in college and being putting it all together in this high octane environment where the stakes are super high. The threat landscape is extremely sophisticated. You're talking about the big nation state actors now.

Speaker B: Yeah.

Speaker C: And it was, yeah it was a lot of fun. I got really the best of both worlds while I was there. And while I was there I did become a customer of exabym. I got to see it and experience it firsthand and I loved it. I loved what they were doing. It was, we needed a capability like that for again the mission that Maxar played in the sophistication of the actors that we were dealing with. And I guess I loved it so much that when I saw the, the Chief Information Security Officer role, uh, open up, I went for it. I really wanted that opportunity and so I went for it.

Speaker B: Awesome. And um, I mean it's great because that the path to see. So you know, the only other person I know who is I think Navy was Chase Cunningham. Right. And, and you know, Dr. Zero Trust and he gives you the whole origin story where he's messing around with a laptop and some blah blah, blah, blah, something he's not meant to do and could go to jail for. And at least your one doesn't have one of those like, oh moments. Um, and, and when you think of um, like Maxar, I don't know much about Maxar. How, how big is Maxar, like how many users and what kind of revenue do they have?

Speaker C: Uh, when I was there it was roughly, I'd say 6,000, 7,000 uh, employees.

Speaker B: Yeah. So you go, you go from being like the CISO Maxar with a big, big kind of user base, kind of like me, Enterprise Security, Adobe, then Cisco. And then all of a sudden I go into this small little rinky dinky startup. So exabeam, I know they're not rinky dinky any longer when you joined, um, they probably weren't rinky dinky then either actually. But what was it like going from Maxar where probably money and budget is amazing to then a startup where if in this economy right now, I mean I know this from being a banyan. Right. Money's not falling off the trees. Right. We're really, you know, you're in a um, fight for, for money. Really? What Was what was that transition like for you and how did you handle that?

Speaker C: Well, I say thankfully it's, we're a security company, so security is at the forefront of what we do and, and how, and what we talk about and, and what goes into the products that we provide to our customers. Um, so that, that was a pro. Wasn't just any, any kind of startup or any kind of smaller company. Thankfully, you know, it is a security company and Exabeam takes security very seriously. Uh, I, I think, you know, you go down to just a smaller organization in general. Um, I think the big thing that stood out as maybe different is, and I, it's a strong word to say lack of. It's just your processes haven't been well defined yet. Your business process, these haven't been well defined yet. You haven't had opportunities or time to really define all those, those processes. And some are just brand new. They're new as you grow and mature and, and um, start to think about, you know, what happens next in the company's journey. So I think that was a little, the biggest difference. It, it certainly was where coming from a large organization, well established processes in a very highly regulated, uh, industry mind you, with um, you know, customers across the board within the US Government, there's something a little bit more where these processes haven't been defined, but they haven't been defined yet. So it's our opportunity to do so. I think otherwise though, it's, it's really apples to apples when you start talking about what types of uh, projects and initiatives that need to happen and be executed upon in order to just continue to improve the cyber security program. Because you're always going to have issues with prevention, hygiene and issues with detection, making sure that you have those, those right tools and um, the people, et cetera in place. So that to me wasn't a change. In fact, in some areas it was easier to execute because you're in a smaller organization.

Speaker B: Yeah, I, I, you know, I found something similar. I mean I, I still think any company CEOs are always like, it won't happen to us, it won't happen to us. You know, they're, they're always fingers crossed kind of. Um, so you're, you're still having to, even in a security company, you're still having to justify the expense. You're still having to talk about the risk of the business. I think the conversations maybe land easier because you're in a security company, but it doesn't mean you're still not scrapping for why Is this worthy of the money? Right. Um, and one thing for me is I kind of look at it like the security companies. I always said, like, I didn't want my first CSO gig to be in a security company. I wanted it to be in, like, someone who gives a crap about the data. The data is not really important, but. But still, you get to, like, get your chops going, you know? Um, but, yeah, like you, I found processes are a bit more ad hoc. The. The ones that need to be buttoned down or fairly buttoned down when I arrived, the ones that can be a bit fluid, they were pretty fluid. And some stuff hadn't been even figured out at all. I mean, it was just like, as. As the thing happens, and we'll decide what we'll do. Um, and. And I even remember, like, hey, creating the user account. What's the naming standard? Well, when a company's really small, who gives a. It doesn't matter. When the company grows, you start giving a. And. And in my last two years at Banyan, you know, we start to give a. We're like, wait a minute, we need to think about this. Yeah. Um, so, yeah. So, also, awesome origin story. If. If you would give any piece of advice for someone who wants to get into cyber security, what would it be?

Speaker C: Listen, listen. I think that cyber security is a huge word. There's a lot to obviously learn. You don't need to know at all. So you kind of, you know, you go about your way of identifying what's interesting to you. There are certainly kind of set pathways for training and, uh, the roles and how you. You kind of develop yourself and start to look at career pathing to, uh, do you want to be a technical leader, do you want to be a ciso, et cetera. But what I have found most important with respect to cybersecurity and how I've gotten here, and that's outside of leadership, mind you. I have. I definitely have thoughts on that, too. But as far as. As far as cyber security, I've listened because I know that 99 of the time, I'm not the smartest person in the room, and there are smarter people in there. And so it's my opportunity to listen to what they. They know, what they're thinking about, how they're thinking about it and listening to those recommendations. I'm the leader, so I certainly still have the ability to trump that recommendation. Uh, I can still make my own decision, and that's my responsibility to do so. And sometimes those decisions differ. They. They will sway from Whatever is being recommended to me. But I have found by listening to others around me, I learn a lot and that's definitely helped me in my career.

Speaker B: That's awesome. Um, I love, I love you say how this is different from a leader. So I, I kind of would love to peel this one back a little bit. There's managers and there's leaders, and I think people who manage other people, they have a management responsibility. But I think leaders, you could be an individual contributor and still be regarded as a, um, awesome leader in an organization. What's your, what's your take on that, the difference between those and, uh, what do you think of when you think of leadership?

Speaker C: So I, I do, I do think that anybody can be a leader. I do think that everyone should be a leader. And I think that anybody who's in a management position, you know, people, manager, etc, must be a leader.

Speaker B: Yeah.

Speaker C: And that I think is probably the biggest issue that most organizations face is that not every manager acts as a leader. Or maybe I'll say it a different way, is they're a bad leader and leader. It's all about accountability, ownership and accountability. Leaders have to have to accept full responsibility for their team's performance. They have to acknowledge the mistakes, they have to learn from those mistakes, and they have to take again, ownership of those mistakes. They cannot blame others for that. So I don't think there's any, anything, you know, any concept of. There is no bad team. It's a bad leader. Yeah, it really depends on that. Leadership.

Speaker B: Yeah. One thing for me that, I mean, I've had had some great leaders, bosses of mine in the past, um, and then I've had some really shitty ones. And the time when I think of a shitty leader for me or a shitty boss, it's always just been down to trust. You know, if I trust my, my boss, my direct boss and, and usually their boss too, I usually need to see trust going at least two levels up. And I remember saying to one of my old bosses a while ago was, you know, I wanted to do something, I can't remember what it was. And then I was just like, well, wait a minute, there's maybe something I don't know in this conversation we're having because she, she wasn't forthright and normally she was right. And so I just turned around and said, if there's something going on that I'm not aware of, um, that's above my pay grade. That is the reasoning for why you're giving me this answer. Just say yes. And she's like, yes. And I'm like, cool. I, I'll not, I'll not harass you anymore with my, my desire. I can't remember. I think it was, I think it was about to increase the team size and there was literally a month before there was a pending layoff. You know, so you're kind of like, you're confused, but you can't know everything. You know, you've got to realize even as a leader, there's things above you that you just, you're not privy to. The other thing. Love your thoughts on this. Um, when, when you're building a team and you're trying to, you know, lead a team, I think of a couple of things. One is I'm hiring diversity, but I'm, I'm hiring people that I think are going to make me a better leader and that I just see my role in the team as, you know, equal to everybody else's, but I play a different role. My role is to maybe make the decision. My role is maybe to help guide the team to come up with a strategy. Um, when you're building a team, what do you look for in the team that you're building? You know, I know you've, you've certainly built. Built a team at exabeam. You've built teams before. So what do you look for?

Speaker C: I do look for diversity of thought. That's, that's huge for me. Uh, and it's uncomfortable. It's definitely uncomfortable to be in. Um, but it's, it's a good uncomfortability. It's a positive uncomfortability. And I, I am challenged by my team and I, I empower them to challenge me. I empower them to challenge my way of thinking. Because I, I can't have people that just nod their head and say yes all the time to me. I pro. It's. I'm not always going to be right, you know, so I check my ego at the door and, and I, I look for that diversity of thought. If I have that diversity of thought and I can empower them to share those thoughts freely, then I can empower them to make decisions that they are able to make. Whatever, uh, level that they reside in. And to your point, I have, I really have two main responsibilities. It is to make the decisions that I'm supposed to be making at my level and, and just free up the blockers to execution, whatever those are. Get rid of those blockers to execution for my team.

Speaker B: Yeah. And, um, if you were going to give so from a leadership advice, what Piece. What piece of advice would you give to someone who wants to be a leader or thinks they are a leader?

Speaker C: Uh, that's a good question. I, I think again, like check your ego at the door. Listen to your team, listen to your people and be comfortable with the uncomfortability, which could be something like you're not always going to have all the information available to you to make a decision. You have to be comfortable with the uncomfortable and still make those decisions.

Speaker B: Yeah, no, that's awesome. Um, one person said to me years ago, a decision that can be reversed is a decision you should make quickly. A decision that can never be undone is one you should take your time on. And I figure uh, watching a lot of leaders, they, they struggle to make decisions quickly.

Speaker C: Yeah.

Speaker B: Uh, they procrastinate and, and when I bucket them into that kind of format, then it makes it easier for me to say, okay, wait a minute, this decision, we should be like rolling fast on this stuff. Um, I like, I like to get shit done. I like to get, I don't like things to take years. I don't have the patience for it. So decision making I think is vitally important. Now before the call at our little pre chat we were talking about, I would call it work life balance. But then you said, no, there's another term that you use. Can you explain that to the audience and share a little insight as to your method of thought there?

Speaker C: Yeah, I said, uh, work life integration. Because when I think about work life balance, it seems to be like a balanced scale. So you're either kind of doing one or the other and they, they may go like this over time and maybe you try to find equilibrium, but they're separate from each other. But let's be real, is, is work really separate from, from home, from personal anymore? I'm sitting in my home office right now and work, work is home, home is work. And work life integration is much more realistic. And I think what needs to be considered nowadays and a quick example of that is finding opportunities throughout a working day to, to do something personal, to do something for yourself. And you might not always be able to do that. There might be, you might be back to back meetings, but in other times you might not. And so if it's something small, just to have a little time to just take a breath, for me it's sometimes just going, taking the dog out for a longer period of walk gets me outside, gets me off of the computer screen, um, and allows me to take a breather. Uh, and it's not just again Balancing and waiting out that time to have that day off, wait for the holiday. It's finding these little moments throughout your life and integrating it into your work life as well.

Speaker B: Yeah. And I think, I think it's important to be pretty organized as, as you do that. Right. I mean, I use my calendar, I use my work calendar to organize my life in the sense of I know when I've got meetings and I know when I've got tasks or things I need to do. And I'll block time in the calendar to do the things, the bigger work items that I need to do. And I'll also use the same calendar if I need to go to the dentist or a kid's appointment or stuff like that. I'm gonna, going to use that calendar to organize my life. And sometimes I'll invite myself on my personal Google calendar, just, just so I know. Right. I'm quite forgetful. Um, and I, I think it's important to realize that these things, they've, they've, they've always coexisted because it's not like you've, you were before COVID It's not like you didn't have personal responsibilities. But I think when Covid hit, everybody then goes home and that whole I'm at home thing and then things around the house that need done, they stare you in the face every single day when you're, you're home. Right. So that made it, that made it, I think, incredibly hard for people to be focused about their work. There's more distractions, I think if I go into the office, I, I, maybe there's a balance here because maybe there's more distractions with people knocking on my door in the office, actually. Yeah. So maybe that's, so maybe that's all in the end. Maybe there's this equal distractions. But the home ones are certainly more in your face and they're more visible.

Speaker C: Yeah, the home ones are your ones, though. And, um, I think that's the thing is where you have things that eat at your mind because, you know, you need to check those off your list versus somebody walking up to you in the office. That's. That wasn't on your list of things to do. Maybe they just gave you something to do, but it's a distraction that takes you away from whatever your checklist, actually.

Speaker B: Yeah, yeah, definitely. Minimizing distractions is huge. Um, now one of the things, so you're, you're pretty active on advisory boards or councils or those kind of things for somebody who wanted to get involved. Ah, kind of board level, what advice would you have for them on how they start or explore that?

Speaker C: I, I think being in, involved in some of the, um, if, if you have like local chapter groups, whether they don't have to be within cyber security either. There are, there are different ways to get involved in various organizations just to network and meet people. They don't, if they don't know who you are, I mean that's, that's a big piece of it is just starting to meet people. Um, so that's been one of like social events. So outside of just those types of networking events of what conferences can you go to? Um, they don't again just have to be security conferences. And if they are things like RSA as an example, like I participated in many different types of meetings while I was there. That was more within like the venture capital space and talking to portfolio companies and talking to VC firms. So it's, this was all just going to events and networking. That was a big, that was a big piece of it. I think the other piece is if you have an interest in a specific topic area, talk about it. Talk about it. Um, for, you know, for me, blogs, podcasts, like today, find your voice, find your topic, find your interest and talk about it. Get your, get yourself out there. You will create conversation, you'll create noise and you'll create attention. Yeah.

Speaker B: And networking. So you touched on this, right? Networking, especially the executive level, I think is vitally important. Your brand and your reputation is vitally important. I have a guest coming on the show, um, um, Victoria Verhey. She's uh, a coach, you know, leadership coach. She's a strategic communications expert. And one of the things that she taught me and my teams years ago was team brand and personal brand is vitally important. You need to consciously manage your brand, right? So when you're out, uh, networking, you're really managing your brand. When you're doing podcasts and blogs, you're, you're promoting your brand. And I, I think people overlook the importance of, of market marketing and networking yourself. So the next C level job you and I get, um, they'll not be because we applied for the job on LinkedIn, right? They will more likely be because we know people who know people and ah, they reached out to us. And I would say my last few jobs have all been someone reaching out to me and either because of good work I had done in the industry, so they knew who I was, or because they had saw my LinkedIn profile and my activity on LinkedIn. So I think you gotta Use those mechanisms. Pretty wise. Now, talking about work, um, when you're not working and you're hanging out with non techie people, which is very hard to do in the Valley. But when you do do it, how do you describe your job to people who are not technical? I think of talking to my mum about it. Uh, but how do you describe it?

Speaker C: I would say. You ever seen the Tom and Jerry Show? I'm, I'm the Jerry. I'm the little, I try to be the clever, resourceful mouse. I try to constantly outwit and stay ahead of the threat, which in this case is Tom the cat. So I, I think that's what I would, I would like talk about and resonate with of this little agile, quick thinking, trying to anticipate what the cat's gonna do next. And that's what we, we say all the time is this game of cat and mouse and cyber security. So I, I'm the mouse in Tom and Jerry.

Speaker B: You're the mouse. You know, hey, when you're up against nation states and some of these big threat actors, then, yeah, shoot a, we feel, we feel like the mouse in that scenario. And then when, when you're not working, what do you do for fun? What do you do to keep yourself, uh, upbeat and uh, and distracted from the pressures of work?

Speaker C: I mean, some of the normal things I, I, and, and Covid really was a, a big contributor to this. I went to the library and, and took out like a stack of books. Nowadays it's more of what's, you know, through the, the online apps and stuff. But I do read a lot. Um, I do go to the gym a lot and, and weightlift. But what I'll share a little bit more broadly is when Covid started, uh, I needed to find another hobby. I couldn't just be reading all day and the gym was closed, uh, so what am I going to do? And I started doing some coding, mostly Python. And that was fun. Um, but I was just finding myself on literally a computer all day long and I thought, I need to find something else. And so I traded that keyboard for a different keyboard and I bought a piano keyboard and I started initially teaching myself. And about a year after that I, um, engaged a piano teacher and I've been seeing her ever since. It's now been almost three years since I've been playing piano and I actually have a grand piano now in my house and I play every day. That's my, that's my m. Chance to unwind.

Speaker B: That's awesome. It's and what one of the things you know in that story is like when you're trying to disconnect from work, still being on your computer. Yeah, that's, that's not a disconnect. That's just. And I think the hard thing for me, right, I mean, I love music. I'm. I'm only in this industry so I can buy m more music gear, really. Um, but this is my home office. So when I'm not working, the thought and the inspiration to be in the same room and do music has been really challenging. I mean, that's been the hardest thing, I think, for me. Um, but I love. Yeah, I love the thought. I know so many people actually, that during COVID they, they took up playing some musical instrument, which I think is always brilliant.

Speaker C: I hope you kept at it, everybody.

Speaker B: Yeah, don't quit. And I think, I think the interesting thing is there are things that you can do that actually bring back to your career. Um, for me, there's the notion of being able to play an instrument and create a song and think of finishing that thing. That body of work is very similar to when you're in work and you're creating a plan and sometimes you're not inspired, sometimes you are inspired, but you've still got to finish the body of work. Um, and you can't, you can't get to walk away from it.

Speaker C: Yeah.

Speaker B: So I know we're, I know we're way over time. Uh, it's amazing how quickly these minutes roll through. I'd love you to leave the audience, Tyler, with one, one last thought. Uh, one nugget to take away. What would it be?

Speaker C: Security is not a one time effort. It's an ongoing process. There is no finish line. So, so focus on continuous improvement, shared responsibility. Make sure every member of the team plays a part in maintaining that security integrity of the organization. But don't forget the value of learning both from your successes as well as your setbacks.

Speaker B: Awesome. Ah, thank you, Tyler. So everybody with that amazing, uh, last thought there, thank you first of all for, uh, paying attention to the show, hanging out with us for what is almost, uh, 40 minutes. We appreciate it, Tyler. Uh, really appreciate having you on the show. We'd love to have you back sometime soon. Ideally, you know, maybe in person someday soon because.

Speaker C: Yeah, absolutely. Thanks for having me.

Speaker B: We're at the other end of the bay though, right? So it's probably like a 15 hour drive when, when it rains, when it rains outside, it's probably 15 hours. I mean, geez. Thank you, sir. Really. Appreciate it. Have a great, great Christmas, a great new year. Uh, and yeah, hopefully we'll catch up in person. Uh, 2024 sounds great.

Speaker C: Thanks Dan.

Speaker B: Thanks bud.

Speaker A: Thanks for listening. To learn more about Banyan Security and find future episodes of the podcast, please visit us@BanyanSecurity IO. Special thanks to Urban Punks for providing the music for this episode. You can find their tracks, Summer Silk and all their music@urbanpunks.com.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How GTT Rebuilt Global Security For The AI EraWhat's Up with Tech? · on MITRE ATT&CK framework91 / 100
  • AI Agents vs. AI Agents: The Future of Security Operations | Interview with Monzy MerzaSecure & Simple · on MITRE ATT&CK framework85 / 100
  • Security Data Pipelines: How to Cut SIEM Costs and Noise with Dina KamalCyber Sentries: AI Insight to Cloud Security · on MITRE ATT&CK framework85 / 100
  • Zero Fraud Means Zero Revenue w/ Zach from ComunRisk and Reason · on Behavioral analytics79 / 100
  • Ep. #91, Every Failure Becomes an Eval with Janaki VivrekarO11ycast · on Behavioral analytics77 / 100
  • How to Think like a CRO Expert with Josh SilverbauerMarketing Roundtable · on Behavioral analytics74 / 100

More from Get IT Started. Get IT Done.

All episodes →
  • Episode 31 - John Yeoh, Global Vice President of Research at Cloud Security Alliance
  • Episode 30 - Anil Karmel, RegScale
  • Episode 29 - Alex Bovee, CEO - ConductorOne
  • Episode 28 - Maurice Hamilton, Infinavate
  • Episode 27 - Leadership Panel - Women in Tech
Explore the best B2B Engineering & DevTools podcasts →
All Get IT Started. Get IT Done. episodes →