The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Inclusive Cyber: Unlocking Innovation in Cybersecurity
Inclusive Cyber: Unlocking Innovation in Cybersecurity artwork

Never Assume Anything: Stacy O'Mara on Policy, Breaking Into Cyber, and Why Basics Still Fail

Inclusive Cyber: Unlocking Innovation in Cybersecurity · 2026-01-12 · 40 min

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence8 / 20
Conversational Craft7 / 20

Stacy O'Mara's journey into cybersecurity is unconventional - she holds a political science degree and has never been an operator, yet became a leading voice in cyber policy. Starting on the House Veterans Affairs Committee and moving through DHS, FEMA, and CISA during the post-9/11 era, she later covered the intersection of business and national security as an analyst at Bloomberg Government around 2012. That experience covering early information-sharing legislation sparked her focus on cyber. She spent seven years running government affairs for a global cybersecurity company (including during the SolarWinds breach response at FireEye), then earned an executive master's in cybersecurity with both policy and operational components. Today at Venable, she advises private-sector entities on how real-world cyber incidents translate to policy and regulation. O'Mara emphasizes that cyber careers span far beyond technical roles - governance, risk, policy, and business acumen are equally critical. She stresses the importance of cross-disciplinary mentorship, relationship-building over LinkedIn cold pitches, and attending in-person cybersecurity events (RSA, Black Hat, DefCon, local think tanks). Her mentor's two pieces of advice - never assume anything, and work smart not hard - have defined her career. She also highlights the disconnect between business leadership and technical teams in many organizations, and notes that while CISO reporting structures vary, what matters most is eliminating silos and ensuring direct access between technical leadership and C-suite decision-makers during incidents.

Key takeaways

  • →Breaking into cybersecurity doesn't require a technical background; policy, governance, and business expertise are equally valuable career paths in the field.
  • →Never assume anything and focus on relationship-building in person (events, conferences, think tanks) rather than relying on LinkedIn for mentoring and career advancement.
  • →Pursue education that includes both technical and policy/business components, not just IT certifications, and seek programs that don't require computer science prerequisites.
  • →The disconnect between business/board-level leadership and technical cyber teams is a major organizational problem; CISO and technical leadership need guaranteed access to the C-suite and CEO during incidents.
  • →Cybersecurity is ultimately a business risk and policy problem, not just a technical problem - companies need incident response plans, clear communication structures, and board-level awareness of vulnerabilities.

In this episode

  1. 1Early Career on Capitol Hill and Entry into National Security
  2. 2Career Evolution at Department of Homeland Security and FEMA
  3. 3Transition to Cybersecurity via Bloomberg Government Analysis
  4. 4Technical Education and the SolarWinds Breach Experience at FireEye
  5. 5Finding Mentors and Building Professional Networks in Cyber
  6. 6Career Advice for Aspiring Cybersecurity Professionals
  7. 7Education vs. Certifications and Non-Technical Paths in Cyber
  8. 8CISO Reporting Structure and Organizational Cyber Maturity

Mentioned

Stacy O'MaraDepartment of Homeland SecurityCISAFireEyeBloomberg GovernmentVenableSolarWindsRSABlack HatDEFCON

Guests

Stacy O'Mara

Topics in this episode

Department of Homeland Security (DHS)CISA (Cybersecurity and Infrastructure Security Agency)FEMASolarWinds breachFireEyeBloomberg GovernmentCapitol HillHouse Veterans Affairs CommitteeNPPD (National Protection and Programs Directorate)Cyber incident response planning

Questions this episode answers

How can someone without a technical background get into cybersecurity?

Seek out mentoring relationships with CTOs and operators who can help distill technical concepts, consider pursuing education that combines policy with operational components, and identify your weak spots - then find specialists who can fill those gaps across multiple mentors and experience levels.

What's more important for a cyber career: certifications or a degree?

It depends on the role - technical positions require certifications for hands-on work, but seek educational programs that offer more than just technical aspects and don't require computer science prerequisites; the business and policy components are equally critical.

Should a CISO report directly to the CEO or to the CIO?

It depends on the organization's size and mission, but what matters most is having a cyber incident response plan in place and open lines of communication (whether direct or via a dotted line) that give the CISO guaranteed access to CEO and board-level decision-makers during a breach.

Where should someone look for mentors in cybersecurity instead of just using LinkedIn?

Attend in-person cybersecurity events and conferences (RSA, Black Hat, DefCon) and smaller think tank events that are often free for students; relationship-building through personal interaction is far more effective than cold LinkedIn messages.

What were the key insights from the SolarWinds breach response?

Working through SolarWinds at FireEye taught O'Mara that policymakers need to understand the technical details of breaches - the attack vectors, what was stolen, and attacker motivation - before crafting legislation, which is why she went back to school for an executive master's in cybersecurity.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode is dominated by career biography and general networking platitudes, with only occasional substantive observations - notably that basic hygiene failures (MFA, patching) still plague mature organizations, and that AI may multiply defender capacity rather than replace jobs. These moments are real but infrequent and unlikely to surprise a working operator.

The thing that continues to surprise me the most are the less mature methods of attack that are continuing to um, proliferate. Um, you know, sometimes we're looking at really basic security vulnerabilities here and mishaps that could have easily been prevented by using things like zero trust or just multi factor authentication
when you think now about some of the advances in AI and how it could be used to perform some of these cybersecurity services, they're going to be able to 10x that role or that particular task

Originality

7 / 20

The episode recycles widely-held takes - AI is both good and bad, networking in person beats LinkedIn, cyber is a business risk not just an IT issue. The one mildly fresh angle is the difficulty of entering graduate cybersecurity programs without a CS prerequisite, but even this is an observation rather than a developed argument.

I couldn't find, I could barely find any programs that didn't require a computer science degree as a prerequisite for going in and getting a postgraduate degree in cybersecurity. And I didn't need that
I think I pursued those as mentoring relationships, but it also ended up being a mutually beneficial relationship, I think, for some of these technical folks as well

Guest Caliber

13 / 20

Stacy O'Mara has legitimate practitioner credentials - DHS/NPPD (pre-CISA) tours, analyst at Bloomberg Government covering the first major information-sharing legislation, and government affairs lead at FireEye during the SolarWinds breach - making her a genuine subject-matter expert on cyber policy. However, she is a policy and government affairs specialist rather than a technical operator, and the conversation rarely pushes her to deploy her most distinctive knowledge.

I was working for FireEye, um, again, you know, global cybersecurity company, and I was there during the Solar Winds breach
I did you know, a couple of tours in various entities throughout DHS, including FEMA, CIS, which is Legacy Um, and then also NPPD, which is now CISA

Specificity & Evidence

8 / 20

The transcript contains named entities (FireEye, DHS, CISA, SEC disclosure requirements, RSA/DEF CON, Kevin Mitnick) and a few concrete regulatory references, but there are no hard metrics, dollar figures, breach statistics, or detailed case specifics. The Ukraine anecdote and SolarWinds reference are name-dropped rather than examined with any depth.

if you're a publicly traded company, you're disclosing um, to the SEC if you've been breached
as part of the um, appropriations package right now that we're dealing with in 2025, includes an authorization of that Bill

Conversational Craft

7 / 20

The host asks mostly open-ended, biographical softballs and never challenges a claim or follows up with meaningful pressure. The CISO reporting-structure question is the lone attempt at a substantive debate, but when the guest gives a non-answer, the host moves on without probing. Praise is offered freely and disagreement is entirely absent.

Yeah. Stacey, thank you for sharing that amazing, uh, background in your career.
Not to put you on the spot there, Stacy, where do you think the CISO? Because I know I've been in various companies where the CISO is under the CTO. CIO.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A72%
  • Speaker B28%

Most-used words

cybersecurity35cyber32different20technical17career13back12government11security11field10part10sector10understand10folks10stacy9first9aspect9

Episode notes

From Capitol Hill to cybersecurity leadership, Stacy O'Mara's career journey proves you don't need a technical background to make a significant impact in cyber. In this episode of Inclusive Cyber, Stacy shares how she transitioned from political science and public policy into becoming a trusted advisor helping governments and Fortune 500 companies navigate the complex intersection of cybersecurity, business risk, and national security. Her candid insights on mentorship, education, and the evolving threat landscape offer a roadmap for anyone looking to break into or level up in this field. Key Themes 1. You Don't Need a Technical Background to Succeed in Cyber. Stacy built her cybersecurity career from a foundation in political science and public policy, proving that diverse skill sets like communication, policy analysis, and strategic thinking are invaluable in this field. 2. Find Mentors Who Fill Your Gaps. Rather than seeking mentors who mirror your strengths, identify your weaknesses and build relationships with people who specialize in those areas to become a more holistic professional. 3. Education vs. Certifications Depends on the Role.

Full transcript

40 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Stacy, welcome to Inclusive Cyber. How's it going?

Speaker A: Very well. Thank you so much for having me. Danny.

Speaker B: I appreciate uh, you you know, taking the time of your out of your busy schedule to have this conversation. One thing that I want to do with Inclusive Cyber is having guests on to talk about how they navigated their career and some, some people are barely starting their care, are in the middle and somewhere other guests have been kind of in their latter stages of their career. With that being said, can you provide a quick overview of what you've been uh, doing in the it cyberspace?

Speaker A: Yeah, sure. Well I think it's a great topic and I think cybersecurity is an interesting field to explore from the lens that you describe because I think you can kind of come into this career field at any point during your career because number one it's growing and the demand is so high. But then there are also lots of specialties where maybe you're not necessarily, necessarily um, an IT or technical um person um, but you're proficient in other areas that would also be applicable. So it's been kind of fun watching this, this, this workforce um, evolve over time. But I kind of um, came into it a little late in my career or maybe halfway through. Um, I've been in Washington D.C. my entire career and I cut my teeth on Capitol Hill and I was a baby and knew nothing. Um, but I probably maintain to this day that it, it's one of the most important jobs I've had because um, I about um, how our federal government operates, how it's funded, um, by working in Congress and understanding the appropriations process and that. So I was very young and didn't know anything but came out um, knowing a lot more. That served me later in my career. Um, I spent a couple years there and um, had every intention of staying on the Hill. Um, but candidly after 911 um, I made a determination that I needed to do something different. Um, I knew that I wasn't going to join the military. But um, you'll recall call to that shortly after 9 11m, the Department of Homeland Security was stood up. And I knew that's where I wanted to go. I wanted to be a part of this initiative. I mean we had no idea what it was going to be like. Um, when the department evolved of course they took all these um, individual agencies and put them under a single umbrella. So um, it was a very interesting learning experience. And um, I did you know, a couple of tours in various entities through, throughout dhs, including fema, cis, which is Legacy Um, and then also nppd, which is now cisa, where um, cybersecurity is managed for the federal government today. Um, but it was a blast. I mean we were duct taping seals on podiums and taking headshots in hallways with the American flag. I mean like, it was. It was a great time. It was a really interesting community. And I've grown up with a lot of those Homeland Security professionals in my career who also have evolved into uh, into cyber. Um. So Danny, I spent a ton of time supporting um, DHS as um, as a contractor. I never went in as a Fed, um, and that was somewhat on purpose because, um, I wanted to have the private sector pay for additional education. So I have two other master's degrees, um, in addition to my undergrad. And um, the private sector was very helpful in helping me um, get that additional um, education. But it was still great working side by side with federal employees at dhs. And then I also spent a lot of time working for the Defense Department as well. Um, performing a variety, um, of Congressional affairs and public affairs and strategic communication type roles, um, but all focused on national security. I left um, private uh, sector and consulting for a little bit and um, went to Bloomberg Government where I was an analyst. And I was doing a ton of writing there. And I had a massive portfolio. So I had press credentials, but I wasn't a reporter. I was considered an analyst. But I was basically starting to look at the intersection of business and national security and what that meant, um, for the public and private sector. And my portfolio included everything from Defense and Intel, um, to um, Homeland affairs and Veterans affairs, um, but then also cybersecurity. And that's where I got into cybersecurity. So probably that was around 2012, um, so more than a decade ago now. But um, it was becoming pretty prolific. I think. This United States government has always been doing cybersecurity and the private sector has helped in some way. But, um, that was the start of the first um, information sharing legislation that came about, which, um, consequently, uh, as part of the um, appropriations package right now that we're dealing with in 2025, includes an authorization of that Bill M. Everything feels like it's coming full circle. But that was the first major piece of cybersecurity legislation that I covered as an analyst at Bloomberg. And I just remember going to my boss at the time and thinking, you know, this is such a fascinating field. I want to cover more of this. Um, and then over time decided, I think I want to go back into consulting and helping private Sector companies, one on one, um, and focus on cyber. Cybersecurity has a national security mission, especially when you're working with, um, with governments. Um, and so that is kind of what led me to running government affairs for um, for a premier global CyberSecurity company about seven years. Um, so really trying to help governments understand some of the nuances and technicalities in some of these breaches and what the impact is to victim organizations. Um, but then more importantly, as policymakers think through legislation or any other type of executive actions from the White House on how CI owners and operators or how entities should manage cybersecurity, like, what are the real world effects of that? Um, which has brought me to where I am today. So, you know, at Venable today, and we've got a whole crew here that continues to provide that type of policy advice and support to, uh, private, um, sector entities.

Speaker B: Yeah. Stacey, thank you for sharing that amazing, uh, background in your career. So let's take a couple of steps back. So you're in the Hill and uh, you mentioned Washington D.C. so during that time you still weren't in that technical field. It didn't come until later, is that correct?

Speaker A: Yeah, no, not at all. I was working for the House Veterans Affairs Committee specifically for the health subcommittee. So we were trying to help veterans get greater access to health care through, um, the VA health care system. Um, I went into public policy and wanted to work on the Hill, um, to get that experience, but I wasn't at the time, at what was I, 21, 22 years old. I wasn't focused on a particular subject matter. I just wanted to get on the Hill and start getting that experience. Um, so I didn't start getting focused on the national security aspect until after 9, 11, until after DHS was stood up. Yeah.

Speaker B: So, so then you started looking at the intersection of business and national security and then getting into cyber roughly about what, uh, 13 years ago. So when you first started, what did you initially think of cyber? Um, since we love our technical jargon, actually did a video, um, kind of in my social media, but it's all the technical jargon. So was that intimidating? How did you, I guess navigate that aspect going into Cyber roughly in 2020?

Speaker A: That's a great question. And, um, yes, it was extremely intimidating. Um, I got an undergraduate degree in political science. My, my first master's was in public policy with a focus on national security, but I didn't take any technical classes. Um, and I've never been an operator. I've never been hands on keyboard. Um, and I was able to align myself and kind of broaden my, um, my network to meet operators and meet CTOs who understood a lot of that jargon and who could help break down for me and distill some of the technical aspects of some of these cyber attacks. For example, um, and it was when I was working for FireEye, um, again, you know, global cybersecurity company, and I was there during the Solar Winds breach. And. And, uh, at the time, you know, here we were trying to. We had disclosed to the government and to the public, to the world that this had happened. But then we started having these very, um, detailed conversations with lawmakers about that breach. And I realized I need to understand better the technical pieces of this. I'm trying to distill it and break it down for policymakers, but I'm still struggling. Um, and I went back to school. Um, I went back to school and got an executive master's in cybersecurity. And it was a blended program where there was a policy component, but there was an operational, um, piece to it as well. So I was in there doing labs, and I understand all of that now, and it's made my job. I'm way more valuable in my field, and it's made my job a lot easier to understand. You know, okay, so here are the attack vectors. Here's how they got it, and here's what they took. Here's why they would be motivated to take it. Um, and those pieces are really important when it comes to policymaking. Right. Like, we need policymakers to be able to understand some of those technical nuances before they start, you know, passing bills or putting out regs.

Speaker B: Yeah. Uh, just as you're talking, it just reminds me of during my time in government, and we had to break everything down to the policymakers because typically they didn't understand, uh, any of the basics of cybersecurity. So, remember, I was doing something on, uh, denial, distributed denial of, uh, service DDoS. And my editor was just going back and forth, you need to trim it down, you need to be. Provide basic terminology and even analogies to a certain extent for the policymakers there. So, definitely, um, going back to memory lane, during your transition into the cyber world, you said that you kind of befriended CTOs and operational folks. Were they kind of your mentors along the way?

Speaker A: I think I pursued those as mentoring relationships, but it also ended up being a mutually beneficial relationship, I think, for some of these technical folks as well, because I would, for example, give them opportunities to go. Go to the Hill and brief a member of Congress or testify before Congress, um, and they were able to bring their expertise into a world that they had not ever been introduced to before. Um, and I think we see a lot more of that now over the past, um, you know, dozen years or so. You do see a lot of technical folks who are, who are engaging in that way. Um, but, yeah, I mean, I have, I have lots of mentors, and they're in different specialties and play different roles and they're at different levels. Um, but I have always been a huge fan of branching out and meeting people who don't necessarily have the same skill set as me, so that I can kind of m. Borrow and get influenced by their backgrounds and their experiences. It's only made me, you know, much more smarter in this field.

Speaker B: Yeah, no, I definitely agree, Stacey. I think your background in policy is something that obviously a lot of cybersecurity folks, um, don't really pay attention to or even think about. But I think it's just a marrying of different, um, different topics, different domain to really understand cyber in kind of this interconnected world that we live in, that politics does play in, uh, influence to cyber and even the economy. So I think is, um, value into bringing in kind of. You're a, uh, transitioning professional coming into the cyberspace. So one question, kind of following up with the mentors, if somebody came to you, Stacy, how do I find a mentor in IT and cyber? What recommendations or what advice would you give them?

Speaker A: I think similar to kind of anecdotally, what I was sharing with you. What is your weak spot? Right? Where are you? Um, what's your weakness? What do you actually, you know, what would enhance your ability to do your job better? And then find someone out who. Seek someone out who specializes in that particular field or that particular skill set. Um, and I think that makes you a more holistic professional, whatever your specialty might be. Um, and I would also say do it with multiple people, um, and not necessarily someone who is just at your level. Um, obviously, you know, seeking out folks who have been around longer than you and have more experience is. More Is beneficial. But I also think it's really important to, um, do, um, that same type of networking with, um, folks who don't have as much experience as you, who might have just come out of school, who might have been working for a completely different organization, and they don't have as much experience, but they've got, you know, different experience. I think that lends itself really nicely to keeping you fresh and up to date on, um, on some of these, you know, evolving fields.

Speaker B: Yeah, no, that's great advice, Stacy. I have a lot of people reach out to me on LinkedIn to say, Hey, I want to get into cyber. But I think there's some due diligence that, you know, people need to really understand. It's the analogy that I use is, you know, they're coming to us to say, hey, I want to. I want to join the medical profession. I'm like, well, what part of the medical profession? It's a very wide, uh, field. So when primarily, you know, students say, hey, I want to get into cyber. Well, what part of cyber.

Speaker A: Right.

Speaker B: Could be in the technical? For me, the policy, the governance, risk and compliance was always boring, but I'm finally understanding that that is kind of the bedrock of cyber. If you don't have that, then you don't have a solid foundation.

Speaker A: Yeah.

Speaker B: Um, so in regards to, I guess, the advice, uh, for students, you're essentially saying, hey, just reach out to folks. Would you recommend LinkedIn? Would you recommend, um, local work opportunities?

Speaker A: The latter. So I think LinkedIn is a great resource. I use it quite a bit. Um, and I get a lot of cold calls, if you will, off of LinkedIn from students who similarly are asking for career advice in that. Um, but I also think that it's misused. And then people don't really ascertain, like, well, what do you really do? And there's a lot of miscommunication and. And it turns kind of salesy also. Um, so I would say, um, it's going to events. Um, so going to cybersecurity events around town. Um, I mean, you could look at a calendar every single day. There's some type of cybersecurity engagement, whether it's a larger conference out at RSA or Blackhawk or defcon, um, or some of these smaller groups, you know, think tanks hold, um, open events. They're generally free, especially to students, um, where you can go and meet and listen to practitioners. Um, and my experience in this field is that people are very open to having those mentoring relationships, but it really means, you know, pounding the pavement a little bit and going out there. Um, and yes, use LinkedIn as a tool, but don't rely on that. Um, sometimes I have people who will reach out to me on LinkedIn and ask for, like, a recommendation for a job. And I've not. I've never even met them. And so, you know, it's about relationship building and that, you know, one of my dear mentors was actually from, from the Hill My um, first boss here in Washington and he gave me two pieces of advice, um, which I main, the first is never um, assume anything. Which has saved me in a lot of different ways, um, over, over the years. It's a really great litmus test. I encourage everybody, um, to always think about that. No question is actually that dumb. Um, but the second thing that he taught me was work smart, not hard. And as a, you know, 22 year old that made no sense to me. You know, I was like, of course I'm going to work hard. What do you mean by that? And um, you know, I think he tried explaining it to me but it didn't make sense until I started progressing in my career and really thinking about how to be resourceful and also how to serve as a resource. Um, and part of that is your network. It is all about relationships and not just in D.C. um, you know, I think D.C. gets a bad rap for, for that and you know, yes, there is a little bit of that but I think in any career field, right, it is about relationships is being able to work across different types of organizations, different business units and in some cases across different sectors. Um, and if you don't have that human to human contact and interaction, you will fail. Um, so yeah, I think getting out there and being in person and introducing yourself, um, and people remember you that way, you know, I mean that's, that's way you're going to be way more successful than just trying to ping people on social media sites.

Speaker B: I definitely agree Stacy, and thank you for actually answering my, my request on LinkedIn. But I wasn't selling you anything so maybe that's why you responded. But no, I think you have valid points. Um, just get out there right, and just start asking questions and typically I think uh, it and cyber folks, the assumption part, like you mentioned, we tend to be introverts. Right. Not all of us but you know, at the end of the day, yeah, just go have a radical curiosity, meet local uh, folks. And you mentioned about the think tanks. I do miss that. Um, you know, um, not being in D.C. anymore to speak, uh, sitting in those conversations and just learning and looking at ah, the bigger holistic picture in cyber. So you, you mentioned education, that you went back to get your master's in kind of the business and then uh, the operational aspect of cyber. One question to you. There's two different camps. One, I guess one question is do you have any certifications and if somebody comes up to you, which one should I go for? Should I go for the education or the plethora of certifications that we have in our industry. How do you answer that, man?

Speaker A: Okay, so it is split reviews on that one. Okay?

Speaker B: Right.

Speaker A: I think it depends on the job, right? Like if you're in a technical role, those certifications are going to be important. You need to know what you're actually doing on these networks, in these systems, utilizing this equipment, you know, utilizing any type of cybersecurity software or services, um, that are going to help you do your job. Right. Um, that's, that's a no brainer. Um, but the educational piece is I, um, think is a little bit more wide open. I would say like try and pursue um, cybersecurity, but maybe seek out a program that offers more than just the technical aspect. Um, you know, when I had my realization like, oh, I need to get more technical, I couldn't find, I could barely find any programs that didn't require a computer science degree as a prerequisite for going in and getting a postgraduate degree in cybersecurity. And I didn't need that. There was no way that I needed to go through four years worth of CS and IT and math classes to do what I needed to do. Um, so I think there are a lot of conversations, um, within universities in that now, um, where they're taking that into consideration and trying to widen that aperture to attract students who have an interest in cybersecurity but either don't have it already or don't necessarily want to pursue the technical aspect of it. And that's the beautiful thing about cyber is again like you can be like a, um, a functional cybersecurity professional. Um, but the domains are completely different. I mean to your point, you could go into the healthcare sector, you could go into retail, um, you could go into government, you could um, go into any of like utilities, like if you wanted to support the energy sector, um, you know, there are a lot of opportunities. And the other piece that's interesting about this, when we talk about how cybersecurity is viewed, there's a huge business aspect to it. Right. People are talking about cybersecurity in the boardroom now. You know, this is about managing your overall risk posture. Cyber plays a huge role in that. I, um, mean if you're a publicly traded company, you're disclosing um, to the SEC if you've been breached. So naturally you need to be thinking, okay, I'm going to start this business or um, I'm going to um, participate in a particular market in this way. How am I going to Be a responsible agent for what I'm doing. How am m I going to make sure that my customer's data is safe, that my employees data is safe, um, and that we're doing the right thing. Um, so there's a whole business aspect and the governance piece that you mentioned as well?

Speaker B: Yeah, no, I think there is. And just kind of throwing my personal opinion out there. There is a disconnect from the business side of, of Fortune 500 and the technical cyber side. I've been in various, uh, meetings with both of those groups and they're kind of talking over each other. They're not on the same plane. Um, yeah, I think we need to do better as a domain to make sure that at the end of the day, to your point, cyber is just another business risk that needs to be kind of prioritized and calculated within, you know, the boards and CEO. So I, uh, definitely agree with that.

Speaker A: It takes a while to do that because, you know, we see there are variances in how companies and organizations approach cybersecurity. Right. Like sometimes it's just nested under it. And you have some, uh, organizations that are way more mature than others and they don't have the resources to dedicate to developing a cybersecurity incident response plan. Um, right. So there are different ways that you can do it and at different levels of sophistication. Um, but the fact that we're starting to have those conversations more and more is, is very encouraging. And you know, just looking at, well, how do you set this up? You know, does your CIO or CISO report to your CEO? You know, are they briefing the board and making them aware of their vulnerabilities? Um, you know, these are all really important questions to managing cyber as part of your overall business strategy in.

Speaker B: Not to put you on the spot there, Stacy, where do you think the ciso? Because I know I've been in various companies where the CISO is under the cto. Cio. Um, what's your perspective? Where should they, should they report under those, uh, two, um, kind of, uh, entities, or should they be going straight to the CEO and board? Just curious.

Speaker A: I don't have a canned response because I think it really does depend on the organization. It depends on its size, it depends on its mission, it depends on whether or not there is a board. Um, but there are other components that make that reporting structure less important and just having things like a cyber incident response plan in place so that there's at least a notification in a communications process if something pops off. Right. Um, you know that wherever that, that CISO or CIO is sitting, that they, once that plan kicks in, they do have access to the CEO or to the board or to whoever the decision makers are going to be with respect to how to resp. Um, I don't think that there's a right answer. I think it just depends on having multiple components in place so that you are um, positioned to respond to a breach if you become a victim. Um, there need to be open lines of communication. And so sometimes maybe it's not a direct reporting structure, but there's a dotted line and that door is always available to be open in the event that something happens. Um, you want to eliminate any of those silos where your technical leadership are not able to reach those senior level decision makers in the C suite.

Speaker B: Overly communicate is the key here for those situations there. So, um, Stacy, let's transition to artificial, well, generative artificial intelligence. It's the new buzzword, um, that is kind of uh, capturing um, the country here and probably globally. So kind of a two part, um, looking initially macro level and then micro. So is generative artificial intelligence, from your perspective, good or bad for society? And then micro, is it good or bad for it and cyber?

Speaker A: Those are big questions, right? I think a lot of it remains to be seen. It's an emerging technology. And just like every other piece of emerging tech that we've seen in our lifetime, it is both fascinating and exciting and creates opportunities and, and progresses society in some way or multiple ways. But it obviously comes with m risks as well. And I answer that question from different perspectives. You know, when I think about is this good for my kids, you know, my young daughters who are going to be writing papers and conducting research in college very differently than you and I did, you know, library and pouring over books and periodicals and authoritative resources like how easy is it going to be for them to generate some type of analysis on a particular subject matter without actually doing that analysis themselves? That, that piece worries me. Getting away from some of those basic, you know, quote unquote, like soft skills. Um, but that's as a parent, right? I obviously see the benefits and the advantages and the excitement around what we're seeing in AI and what it's going to do to hundred of professions, um, and that it's going to create different opportunities when it comes to cybersecurity. I think it's, it's twofold. So I think we have seen um, adversaries, you know, developing an interest in it and using it. Um, and we in turn as Defenders need to be able to, um, suss out, um, what those vulnerabilities in AI are. And we've heard a lot of discussions around, you know, how do we make a AI safe and reliable for general public use, um, but then also by governments who might be using it, you know, in their, in conducting government activities. Um, I think that there are going to be more advantages on the defender side. Um, anecdotally I'll share with you. During the war in Ukraine, um, the cybersecurity company that I was working for, we were one of many companies who were supporting the Ukrainians. And it was an exhausting job. And we had some of our analysts and our folks with hands on keyboard who their sentiment was. Um, I love the mission, but I hate the job because it was so time consuming. So when you think now about some of the advances in AI and how it could be used to perform some of these cybersecurity services, they're going to be able to 10x that role or that particular task and they're going to be able to divert their attention to other tasks that it's going to ultimately make them an even better defender. Um, so I think it's less about putting people out of work, um, or um, diminishing the quality of work. I think it's going to enhance the quality, but I think it's going to create room to actually do more as humans and as animals.

Speaker B: Yeah, that's an interesting point, Stacy, because I think, as you're aware of, there's a lot of burnout in cybersecurity. Kind of, uh, the security operations center, just reviewing all these alerts and then kind of the anecdote that you shared, where I think people are just tired of the mundane task and to your point that hopefully AI will be able to eliminate those tasks and then now we can focus on the more critical, um, leverage more critical thinking to think holistically and maybe more strategic on those, uh, fronts. So, um, yeah, no, definitely, definitely agree with you on that. Um, in regards to, and just kind of based on your, your answer, um, the ethical aspect of, of cyber, where there's biases and stuff like that, there's kind of two competing forces. Silicon Valley ethos is to go fast and break things. And then now we're trying to add the ethical component. How, uh, do you see that, I guess, working out?

Speaker A: I mean you see this with businesses all the time. Like how do I get to market as quickly as possible? And it's very competitive, um, and that's natural. I mean, and that's not just limited to emerging technology. We see that in everything related to business. Um, but as I mentioned, there's, I think, a responsibility for companies that decide to use AI in some way to make sure that they're using it safely and responsibly and that they are taking those biases into consideration. I mean, when you think about what, you know, these like, chatgpts and, and that are doing, they're scraping the Internet and pulling all of this information together. Um, and there's a lot of, you know, inappropriate content out there. Not everything is legitimate, not everything is real, not everything is true. Um, and so, yes, there, I think there will be some friction to make these types of tools available as widely and as quickly as possible. But I think it's important that, you know, and there's a good subset of organizations and people out there who are advocating for responsible and safe use of AI. And those conversations will undoubtedly continue. Um, you know, especially here and in Europe, you know, when we look at privacy, um, and civil liberties like that has been a massive part of, um, our policy debates on everything related to technology. Um, it is super cool to get access to all of these tools and apps, but, um, it is super important to slow down and think about some of these implications. And that's not to say to turn it off, but what can we do to make sure that we're using it wisely?

Speaker B: Yeah. And just, you know, having those guard rails. But then to, to your previous point as a parent, I know there was, I think, think there was. A couple of years ago, my son and nephew saw Guess, uh, the Queen of England playing a video game and like, oh, she played this. I'm like, no. So, yeah, I think from a parent standpoint, and I guess the term for that is AI slop, uh, which I just recently heard, it's trying to tell, uh, the younger generation, you can't believe everything that's out there.

Speaker A: Right. I mean, it's like garbage in, garbage out. Right. Um, and also, so it's similar to what we've been dealing with around, um, misinformation and influence operations, which is an issue that is very much on the peripheral of cybersecurity and especially around election seasons and that where we see an uptick in that type of activity. And for instance, what people are reading online, um, on, um, social media platforms, it's fake news. Uh, and so again, it requires a human, an individual to think critically about what it is they're reading, what it is they're looking at, and then to take the time to go to an authoritative source, um, and either validate or try to ascertain whether or not what they're reading is real. And it's the same thing, ah, with these AI generated images and videos that are out there. I mean it's, it's wild. Um, but yeah, as a parent that we're navigating that.

Speaker B: Yeah. So I, I'm, I tend to be a little bit more pessimistic as a parent when it comes to that because I think we, there was a wired, um, cover and this is way back in 2006. Remember I was in the military at the time and it said that we're in a snack cold culture that we quickly consume. And this is before I think even the iPhone came out. So there are no social media apps or anything and they're already talking about a snack culture. I think now we're really in the middle of that because we just quickly. And I know I'm guilty of this, I just read a headline, I'm like, okay, move on. Right. I don't dive deep into that and kind of ascertain to your point, um, the veracity of um, that story. So, um, what has surprised you the most, being in our industry?

Speaker A: What has surprised me the most? You know, I want to say that I'm surprised at um, the number of attacks have not decreased over time. Um, um, we've seen a level of sophistication where we're like, holy cow, I like how are they operating? Like, how, how are they doing this? The thing that continues to surprise me the most are the less mature methods of attack that are continuing to um, proliferate. Um, you know, sometimes we're looking at really basic security vulnerabilities here and mishaps that could have easily been prevented by using things like zero trust or just multi factor authentication, um, or you know, know, effective password use. You know, there are some very basic cyber hygiene, um, practices that are still not fully in place across all levels of organizations. And that part continues to surprise me.

Speaker B: Yeah, no, I appreciate that answer. The other thing is patch management, right?

Speaker A: Yes.

Speaker B: When I was in government I was kind of doing a lot of victim shaming. And for the companies that would get compromised, I'm not. How can you get compromised with a five year old, uh, vulnerability that you have not patched? And now being out of the, in the private sector, it's hard, right? So it's really, really hard to patch. And especially if you don't even know kind of your assets and what you have, uh, on Premise or like I say that.

Speaker A: But then I also understand. Right. It goes back to what I was saying earlier about the resource questions. Right. There are still a lot of entities who have competing interests when it comes to their budget and how they decide to, how, how much they decide to spend on it and cybersecurity in general. And you know, if you're not dedicating um, talent and money towards a, ah, like a really robust cyber security, um, posture, those types of things are going to fall to the wayside and you are going to miss things. Um, so I, I understand it, but I still continue to be baffled by it. Some of these things don't actually cost that much money.

Speaker B: Agreed, Agreed. So I know we're, we're coming up here on time, Stacy. So the way uh, I end the podcast is asking for books. I'm uh, an avid, uh, um, book reader and as you can see over here in the corner, all these books that I'm still in the middle of. So what book have you recently read or currently reading that you'd like to share with the aud audience?

Speaker A: Cybersecurity book or non cybersecurity book?

Speaker B: Yes. So it doesn't matter. Some people have mentioned um, I think fantasy books. So just something, it could be kind of a popcorn book that is non tech, uh, related. So anything.

Speaker A: I'll give you two, um, for favorites. So on the cybersecurity side, um, Ghost in the Wires by Kevin Mitnick is one of my favorite cybersecurity related books out there. Um, and sadly we lost him um, a few years ago ago. Um, but you know, he was one of the first, you know, well known hackers who murdered the FBI for a considerable amount of time. And this book is just genius. I mean he's just writing about the things that he was getting away with with some of these telecoms and it's, and it's, it's, it's fascinating. It's an easy, comical read. Um, but what's, what's great about it is it's, it's so foundational to the same problems and the same risks that we talk about today. Um, and some of these really advanced, advanced attacks. Um, so that's a, that's a great read. That's probably one of my most favorite cybersecurity related books. Um, non, non cyber Personal would be, um, the Awakening by Kate Chopin. And it's a very small book. Um, and I, I don't, I'm an avid reader as well, Danny and I, I don't really ever read books More than once. I don't go back and reread. But, um, this book I did and I, I read it for the first time in high school and when was horrified by the story and anybody listening can go look it up. And I had such a hard time with this story. But then I read it as an adult and had a huge appreciation for the primary character in that book. And um, it was an interesting exercise to go through to have such a different reaction to something after living life just a little bit and all ties back to that first thing I told you my mentor on the hill taught me is to never assume anything. And I think that was a huge lesson, you know, in a 15 year gap between reading that story is to never assume what someone else might be going through and what it might be like to walk in their shoes.

Speaker B: Great advice there, Stacy. And I'll make sure to put those books in the show notes, uh, for, for this episode, but I really appreciate, uh, this conversation. You have an amazing career and I would say you're still in the midd of it and I know you're going to be doing, you know, more great things here in the future and just kind of throwing this out. Um, another aspect of inclusive cyber. I'm doing Fireside Chat. So I lose kind of the stuffy overcoat and button shirt and I have my, my headphones and we just kind of do a deep dive into whatever topic. So one thing I love to, to kind of pick, uh, your brain on is uh, policies and kind of government and how do we inject cyber into that a little bit more efficiently and just kind of what you've, what you've seen. But uh, yeah, let me know. I'd love to have you back on the show, but again, I appreciate this. Yeah, appreciate the conversation.

Speaker A: Yeah, thank you so much, Danny. This was fun.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 84. The Vendor You Trust Most Could Be Your Biggest Security RiskUnHacked · on SolarWinds breach74 / 100
  • SN 1085: A SOTA State-Sponsored Campaign - AI's New Superpower: Loop EngineeringSecurity Now · on CISA (Cybersecurity and Infrastructure Security Agency)69 / 100
  • AI's Double-Edged Sword: Risks, Rewards and Race Dynamics in Cybersecurity with Dr. Joanna SantosParadigm Shock · on CISA (Cybersecurity and Infrastructure Security Agency)69 / 100
  • Managing the Mission at Homeland Security: A Conversation with Troy Edgar, Deputy Secretary, U.S. Department of Homeland Security.The Business of Government Hour · on FEMA66 / 100
  • No Password Required Podcast Episode 74 - Shane TewsNo Password Required · on CISA (Cybersecurity and Infrastructure Security Agency)65 / 100
  • Self-Driving Cars Today, Robot Coworkers Tomorrow?AI for Business with BCN · on CISA (Cybersecurity and Infrastructure Security Agency)64 / 100

More from Inclusive Cyber: Unlocking Innovation in Cybersecurity

All episodes →
  • AI, Adversaries, and the Human Problem in Cyber | Fireside Chat with Max Margolis59 / 100
  • Lavanya's Take on AI, Cyber Jobs, Social Media, and the Future of Tech35 / 100
  • Sofia Rodriguez on Breaking Into Cyber: The Entry-Level Trap, Help Desk Reality, and Networking57 / 100
  • Smriti's Journey Proves Cyber's Talent Problem Isn't a Pipeline Issue. It's a Perspective Problem.74 / 100
  • Why Cyber Intelligence Professionals Are Stuck in the Shadows with Melissa
Explore the best B2B Engineering & DevTools podcasts →
All Inclusive Cyber: Unlocking Innovation in Cybersecurity episodes →