Inclusive Cyber: Unlocking Innovation in Cybersecurity · 2026-01-05 · 46 min
Key moments - from our scoring
Substance score
40 / 100
Five dimensions, 20 points each
This conversation examines the systemic barriers preventing cyber intelligence professionals from advancing to executive positions and contributing their analytical skills beyond traditional intelligence remits. Melissa identifies several interconnected issues: intelligence remains a small profession relative to other security domains; many professionals emotionally identify as analysts and resist leadership transitions; organizational structures inherited from government and military traditions create rigid career paths; and intelligence teams often fail to translate their work into business language that resonates with stakeholders. The episode also addresses the current operational crisis facing intelligence programs - simultaneous budget cuts and understaffing alongside increased C-suite recognition that geopolitics poses significant business risk, forcing security operations centers to become "intel-led" without proper training or resources. For B2B operators, this episode offers practical guidance on how intelligence professionals can increase their strategic influence by learning business models and financial drivers, thinking beyond their functional remit (similar to how one head of intel added trust and safety responsibilities), and translating intelligence products into stakeholder language rather than diluting them.
Multiple factors combine: the intelligence profession is smaller than many realize; professionals often self-identify as analysts and resist moving away from the technical work; and organizational structures inherited from military and government traditions create rigid career formulas that corporate environments replicate without questioning.
Rather than diluting or dumbing down intelligence products, professionals should convert them into business language that speaks to stakeholder concerns - demonstrating clear value back to the organization's mission, revenue streams, and strategic decisions.
Budget cuts are narrowing team sizes and restricting tool access while simultaneously C-suite leadership increasingly recognizes geopolitics as a significant business risk, creating a contradiction where security operations centers are asked to become "intel-led" without proper resources or training.
With the right tools, training, and leadership, operators can become more intel-forward and contextual in their thinking - asking second and third-order effect questions rather than just triaging alerts - though this raises questions about what constitutes actual intelligence versus adjacent operational security functions.
Intelligence professionals are trained to identify second, third, and fourth-order effects of decisions, understand complex systems, and calculate risk across geopolitical and business contexts - skills directly applicable to strategy roles if paired with business acumen and stakeholder communication ability.
Our reviewer’s read on each dimension, with quotes from the episode.
A handful of genuinely interesting ideas surface - whether corporate intel is meaningfully distinct from government intel, the 'diluting vs. converting' framing for stakeholder communication, and the needle-in-haystack critique - but they are buried under extended personal anecdotes, agreement loops, and unfinished thoughts. The insight-per-minute ratio is low for a 46-minute episode.
does intel as, you know, somebody who comes from the government space, as we might know it, does that exist outside of government spaces?
we should not be diluting them, we should be converting them into their language
The 'does corporate intel actually exist?' question and the IOC-as-Bonnie-and-Clyde infrastructure pivot analogy are genuinely interesting framings, and the opinion-vs-assessment distinction offers a real nuance. But most actionable advice ('learn the business,' 'think bigger,' 'speak stakeholder language') is generic career coaching that circulates widely in the security community.
does intel exist outside of the government? Is a question I really ask myself a lot
IOCs are like bank robbers...we change our attributes and the getaway vehicle, that's like changing the infrastructure
Melissa is clearly a genuine practitioner with government/military intelligence background now working in a corporate intel advisory role, and she speaks from real experience. However, her full name, title, and employer are never established, making it impossible to verify seniority or scale of impact; she comes across as a thoughtful mid-career practitioner rather than a demonstrably senior operator.
in my role now, dealing with lots of different, um, companies and lots of different security teams, um, and had a company come and ask us some questions about a piece of analysis
actually at OSAC talked uh, to somebody who's ahead of intel, um, at a big tech company and they have taken on uh, trust and safety in addition to traditional, um, sort of intel type work
The episode name-drops real artifacts (APT1 report, Diamond Model, the Clarity Factory CSO survey, OSAC) and the M&A due diligence use case is the most concrete moment, but no actual data, dollar figures, timelines, or outcome metrics are provided anywhere. Most claims are asserted rather than evidenced.
there's a CSO survey which I highly recommend by the Clarity Factory that's really, really interesting to read
in my previous role we started doing, working with mergers and acquisitions...we can look at all the vulnerabilities...you haven't. Then we're going to decrease the price
The host is enthusiastic and occasionally lands a legitimate push ('Would that be considered intel, though?'), but he frequently hijacks segments with lengthy personal anecdotes, openly forgets his own questions mid-episode, and lets most claims pass unchallenged. The conversation functions more as a mutual venting session between two people who already agree than a structured, probing interview.
um, I'm um, actually doing a, a brain fart here which I'll delete here
Would that be considered intel, though? I think people question. People outside of our profession would just say, uh, that, that's a good analyst
Computed from the transcript - who did the talking, and the words that came up most.
Why are intelligence professionals stuck in the shadows while other executives climb to the C-suite? In this compelling fireside Chat, Danny and Melissa dive deep into a question that has been largely ignored in the corporate world: what is holding intelligence professionals back from reaching CEO, Chief Strategy Officer, and other top leadership roles? With backgrounds spanning FBI, military, and private sector intelligence, they explore the disconnect between the valuable skills intel analysts bring to the table and the rigid structures that keep them boxed in. This is a must-watch for anyone in cybersecurity, corporate intelligence, or global security who feels their expertise is undervalued and wants to understand how to change that narrative.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign. Yeah. Melissa, I am super, uh, excited to have this conversation. There has been, I think over a year and a half that I've wanted to talk about Intel. And as you've seen my diatribes on LinkedIn, I'm extremely passionate about it and I've tried to make it work with other, uh, friends, but just timing has been wrong. And I think when you posted your LinkedIn talking about Intel, I'm like m. Let me chime in. So thank you for responding and having that initial pre call. But yeah, I'm super excited about this conversation.
Speaker B: Yeah, thanks for reaching out. I've been thinking a lot about it since, so glad. Gets the, Gets the creative juices flowing. So I appreciate it.
Speaker A: Yeah, no, it really does. So for those who have not read your post, can you provide a quick summary to kind of lay the foundation of what we're, uh, going to be going into?
Speaker B: Yeah. Uh, so I made a post after, uh, OSAC week, um, after hearing lots of different conversations about intel, um, and intel professionals in the corporate. Corporate intelligence environment and merely, um, the corporate structure as a whole. And uh, there were a lot of conversations about Chief Intelligence Officer and sort of elevating intelligence professionals in their own field. Um, but it has always struck me that we don't always see intelligence professionals sort of break out of that mold and wind up in other C suite roles and really being positioned in other parts of the business, uh, to do those kinds of leadership roles that are outside of just an intel remit. And it always occurred to me, um, that we have a lot of skills. Intel professionals have a lot of skills that are really applicable for, uh, those kinds of roles. And um, for whatever kind of reasons, they just don't always see, uh, intel professionals in those spaces.
Speaker A: Yeah, no, thank you for that quick summarization. And I think you touch upon a lot of great things and you might be the first person that's actually mentioned that. I know there is. And I forgot this individual's name. Oh my God. Just at the tip of my tongue. But he previously wrote kind of a white paper on one of uh, I think LinkedIn or some, some um, something online talking about a Chief Intelligence Security Officer. This was maybe about two years ago, but then I think you are looking at it from a higher level. Right. Running businesses. And that risk calculation that we've been, I guess, ingrained with in our profession, I think would bode well in our current world in geopolitics. Right. Because we do understand that risk calculation. And then we just have to marry that with obviously business understanding and fundamentals. Right?
Speaker B: Completely. Um, as you said, I mean it's, look at the world we live in today. The geopolitics of uh, is everywhere. It's in everything, um, it's every part of the business, it impacts every function within a business and ah, you know, Chief intelligence or chief Intelligence and Security Officer, there's a lot of utility to that too. Um, but I think there are unique skill sets and knowledge sets that will put us in really good positions to take those other kinds of roles. Those other, you know, beyond intelligence roles, like a chief Strategy Officer I think is a really interesting um, role for an intelligence professional. Chief, uh, SEO, that's another, you know, position. We have a lot of um, you know, nevermind the geopolitical knowledge and sort of the world we're in today. But uh, they need to solve complex problems and think second, third, fourth order effects, um, of decisions. And those are all things that we are trained to do that are just part of the fabric of, you know, how we think. Right.
Speaker A: No, I definitely agree with you on that. And to add additionally to, to, to what you're saying, I've been going knee deep into systems theory. I had a guest that was in the biomedical field that is a program manager in cybersecurity and she mentioned systems theory. And I'm like uh, I'm kind of ignorant about that. Can you give me a quick overview? And she did. And ever since that conversation about a month ago, I've been diving deep into that because the second, third, um, and, and fourth order effects, that's something that we, I think as a society and obviously in cyber security, kind of in the M Micro, um, we don't pay attention to. But you and I, coming from, you know, this field, we're thinking about that. Right? So I, I, I think everything that you're saying, uh, that you're saying is resonating with me. But let's kind of break up this discussion. Feel free to push back because this is uh, you know, give and take here. So let's focus part of it on your um, understanding of our capabilities and why we're not at those higher levels. Right. That could be a part of it and understand why what's the environment like that is preventing us from attaining those higher levels. And then maybe at the back end talk about the current problem of cyber threat, intel programs in cybersecurity, uh, organizations and you know, it's not about only mentioning the negatives and they're like, oh, this is crap, this is crap. But then Offering possible solutions as well. So, or like in our world, recommendations, here's what we advise.
Speaker B: We could talk about that too. That's a whole other, uh, That's a whole other subset of this. Providing recommendations versus information as a whole, um, you know, subset of what makes a corporate intelligence professional, uh, successful in their realm versus a government intelligence professional or military intelligence professional. But I love this deep dive, um, because I've really had to think, you know, in making that post, there were so many comments and interesting, um, things that people like, DM'd me about. And so it really generated good, uh, good discussions going into the first, you know, the first part of your, um, question. Uh, why don't we see that sort of. What is. Why, why is that, um, that you don't see, uh, intel professionals in that space? And I, I keep leaning to one of the simpler examples, like one of the simpler reasons why somebody had left a comment and said there just aren't that many of us. And I thought, you know, there's. Actually there might be something to that. Um, that we are a smaller industry than maybe we realize because it's, you know, once you're on the inside, it's kind of hard to, to look bigger and you think about how many CROs or, um, you know, CFOs there might be out there that are able to, um, to. Able to rise to those levels or, you know, shift around into different C suite levels. So I kind of like that as one, One reason. But I don't. I personally don't know that that is, um. That's exactly why we don't see it. I think there's. There's multiple, Multiple factors I kind of see at play. I think one is this feeling like, um. And you know, I, I have it too. I deeply feel this, that I will always be an analyst at heart. Um, I, it was the best job I ever had was just being an intel analyst, brand new, you know, fresh out of training and getting into that seat. And it's the best job I ever had. I loved it so much. And I think there are so many of us that feel that way, um, about. About the discipline. And it's hard to, you know, you just want to be that analyst forever. And it's hard to make that, you know, that pivot away from it because you feel so close to it. Um, and I think that I see that across a lot of people that I would think, you know, are sort of on a path or maybe in a journey in that direction and just can't really Break away from that feeling.
Speaker A: Yeah, and I never really thought about it that way. Um, but it's kind of leaning towards that individual contributor, you know, verbiage, as opposed to leading a team. So. Yeah, um, the other one I hadn't heard of, but, you know, about, you know, not enough people in our. In our profession. Um, yeah, that's. That's another interesting, um, I guess, perspective. I guess what I lean on being in, in cyber security for over 15 years is that we're not allowed to shine. And what I mean by that, if we look at the history of technology and the Internet, what back in the, um, 50s, 60s type of thing, and when security came into focus to say, whoa, what's going on here? It was that great book from, I think, the Cuckoo's Egg or the Cuckoo's Nest or something like that. It was this astronomer, I want to say Stanford, that noticed. It was almost kind of an analyst at heart, noticed a discrepancy of a couple of cents and went down the whole espionage rabbit hole. Um, I'd try to get the book. Um, um, but that's when we noticed that our adversaries, in this case nation states, were targeting, um, trying to get intel. At the end of the day, what we're doing. But so now you had people that created the networks, and now they had to wear a double hat and say, now you get a secure. Like, well, I don't know how to do that. So being engineers, being, um, smart individuals, they devised a plan to kind of sit on top of the infrastructure. And then what they did is start becoming teachers and educators. And then now that created that traditional path. Because a lot of people that I talk to, I don't come from that traditional path. And I push back. I'm like, what is the traditional path? And everybody says, you know everything about tcp, ip, you know everything about networking, all of that quote, unquote foundational work. Because that's what we've been teaching generation after. Well, uh, maybe not generations, but for the past, let's say 40 years. Right? So then now the individuals have. Who learn from that or come from that background. They're teaching that. So you and I come from a whole different skill set. We don't come from that traditional background. So they're like, m. Yeah, I want somebody who knows how to, um, who develop code. And we might know how to do that. I personally don't. But we lean to those hard skills and we don't look at, I guess, the holistic perspective of what life skills, the analysis, the Communication, both written and orally. So that's kind of my take being in this industry scene. Okay, who's getting promoted? Promoted? Who's going up here? Who is not getting promoted? And I don't know. What are your thoughts on that? I could be just talking nonsense.
Speaker B: No, I think there's, ah, it's. It's twofold in my eyes. It's what we. It's what we do to hold ourselves back. Um, and then it's sort of what are what the structures around us that don't necessarily allow us to, uh, as you say, to shine, to get up to those levels. And I think there is a level. You know, some of it is us holding ourselves back or, you know, putting us in boxes. Um, you know, by way of the things you exactly described. And um, sort of that like, well, this is what an analyst looks like, or this is the traditional way, you know, coming through the military is the way you get into intelligence. And like that, you know, that kind of like formula, um, that I would argue is going away now, um, anyway, whether we want it to be or not. Um, but there's also the structures where they're. They're holding us back to some degree. Um, and I think some of that is on the old style, formulaic, traditional. This is how a cybersecurity professional comes up the path. This is how an intelligence professional or corporate security professional, um, finds their. Their way up the corporate ladder, or, you know, whatever ladder that might be. A lot of that I find is still driven very much by, um. And both you and I are from that tradition of government, law enforcement, military really winding up imprinting on corporate environments and corporate global security environments and cybersecurity environments in ways that, I mean, when I got into private sector, I didn't expect that at all. Um, in retrospect, now it makes perfect sense, um, that that's what would happen. Um, but I find that a lot of those sort of formulaic feelings, those traditional feelings get, um, overplaced into corporate environments by way of those same people that have come up in those traditions. I try not to be that person. But, um, you know, I think if you're really intentional about it, you know, you, you can, um, steer away from that. But there is something to the sort of, uh, the. The people, the. The powers that be and the people in those positions that bring over that sort of tradition, that formula with them and expect that to also play out in other environments as well.
Speaker A: And it's about being adaptable. Right? We tend to be rigid and maybe that's just human nature, what we know, what we feel comfortable with. Well, I want to keep on doing that. I don't want to change. And I know some people are to a greater or lesser degree of where they feel comfortable with change. But I think as you're saying that what started my path down this, uh, road was thinking, um, ah, isac. I don't know if it was healthcare, must have been healthcare here in Denver. And there was this speaker that said how not to build a CTI program. Okay, let me see what you got. He totally lost me because the first thing that he said, he attacked kind of my ego. That whatever you did in government or military, don't do it. Don't try to replicate what you did. I'm like, whatever, uh, this guy doesn't know what he's talking about. But then it took me a while for it to sink in. And talking to a lot of people, former colleagues, friends in different sectors. Oh, we don't talk with this team. We don't do this, we don't do that. And I'm like, hm. And they're all from our traditional background. And I'm like, oh man, I think this guy was right. And I've been trying to get a hold of him. He might have been with the agency, I don't know because, um, I reached out to isac, uh, um, Healthcare, ISEC sec. I'm like, no, he didn't want to. He didn't share his slides, he didn't do anything. But I, I think with osin, we can, we can definitely look for him. Um, that really shed the light. And then now I use that to really analyze the current employer that I was working with at the time. And I'm like, we're, we're pushed to the corner to this, uh, within the SOC Security Operations Center. I'm like, oh, um, man. And this is where I kind of started developing my, um, my uh, articles on LinkedIn to say, look, we're missing the value proposition of what we can do, um, with this profession. But let's circle back. If you had the power, how would we get the profession to start filling those executive roles? What are some of the, I guess, potential. I hate using this term, but it's the only one that's coming through roadmaps. What is kind of the potential path that we can take to start leveling up and showing the value prop of what we can provide? Global corporations
Speaker B: learn, I think that's the single biggest thing, is be willing to learn other things. Uh, learn the business, learn what it means like that. Learn what it means. When your company is saying they're making money, how are they making money? Uh, is it ads? How are they uh, constructing the financials around those ads? How are they selling them? Who are they selling them to? Uh, how, how is your company making money? And learn to speak those stakeholders language, understand what the business is. In so many environments, intel security, cybersecurity becomes a service to the business. And that's all well and good, you know, that's, that's part of the, that's par for the course in some cases. But we don't always necessarily try our hardest to speak their language as well. We figure out ways to make our intel products or you know, the reports and things that we're providing them. Um, I think we maybe lean towards like dumbing them down for lack of a better word and like diluting them to some degree so that they're digestible to the stakeholder. But what we should actually not be, we should not be diluting them, we should be converting them into their language, um, and so that it makes sense to them. And then they see the value. They see you're not just a call center or you know, you're not wasting their time by giving them an intel product. You're giving them something that's actually providing them value back into the business. And I think, and by way of that, I think we often just think too small, think bigger, think beyond, you know, beyond your remit. Think bigger than that. You know, what, what other things kind of make sense actually at OSAC talked uh, to somebody who's ahead of intel, um, at a big tech company and they have taken on uh, trust and safety in addition to traditional, um, sort of intel type work. Um, and that's pretty unconventional, that's generally pretty squirreled away. Um, but the way that he described it, it made perfect sense. The patterns and the tools and the professionals they needed were exactly the same. Um, it's just imprinting it in a different way. And so the business was completely in line because he spoke the business language and was able to translate to them why it made sense to do that and think unconventionally and think bigger, um, outside of, you know, what would traditionally be acceptable in a company like that. And so it's really learning and thinking bigger I think are the two things that I, for myself I'm trying to um, like internalize and uh, I think others should really think that way. And you know, those are things that we can control and that you know, we can, we can do to sort of think about how we might reach those levels or at least influence at those levels. Um, if you're not going to reach, maybe you don't want to and that's, you know, totally fine. But if you want to influence at those levels, uh, I think you still need to do that too.
Speaker A: Yeah, I love the think bigger. Think bigger. Right. Think more strategic. And I know thinking strategic is a hard thing to do, but in my experience a lot of the technical folks that are kind of in middle management or a little bit higher, they're super myopic. They're thinking in the weeds. Like for example, a former boss would be, uh, inside the security tools. I'm like, what are you doing? You have hundreds of people that can do that for you. Why are you in these tools? And they couldn't give me a good answer. I think I know why they're in there because they feel most comfortable there and they might not be thinking bigger or asking those, like you said, those inquisitive questions to really understand where cyber fits from a business value prop versus the zeros and one that we tend to uh, gush over, uh, here in cyber. Um, so no, I, I, I, I love everything that uh, that you're saying there. Um, the other thing I wanted to talk about, uh, I'm um, actually doing a, a brain fart here which I'll delete here.
Speaker B: You had a third. There was a third point.
Speaker A: Yeah, there was. Man, listen, there's a lot of things that are going through my head right now because I, I love this conversation. Oh, okay. Let's shift towards um, the current state of cybersecurity. What has been your experience with your past? And one other thing I forgot to do a caveat. I don't know how I could do this. Whatever opinion stated in this episode of past, present and future employers, there are opinions and they do not um, you know, coincide with uh, our current or past employers. Opinions are our own. What have you seen in your experience and within your network on how intel programs are currently being leveraged? Because I have a follow up question depending on what, how uh, you answer that.
Speaker B: It's a tough time. Um, there, there's definitely, there's a couple of, couple uh, of similarities I see across lots of different um, organizations. The first budget, uh, cuts, I think that's you know, that's impacting lots and lots of people. That means layoffs, that means uh, restricting access to tools, to information, um, trying to consolidate in ways that make it really difficult to do the job, um, that teams were doing before. Um, there's definitely also within that narrowing, um, size of teams and things as part of that as well. Narrowing, um, ah, widening remits, narrowing teams, which just means um, code for do more with less. Ah, there's a lot of that. Um, but at the same time there is also a recognition from C suite leaders and not just your CSO across C suite. And you know, this has proven like there's multiple surveys. There's a CSO survey which I highly recommend by the Clarity Factory that's really, really interesting to read and see how CSOs across multiple. You know, many multinational corporations are thinking about intelligence and security and there is a recognition at that level that geopolitics is a significant risk factor, um, across the business, not just for, you know, a global security organization, but that's a significant risk factor. So simultaneously, um, doing more with less, but also recognizing that now more than ever geopolitics is a significant problem, um, and something more important than it ever has been. Uh, so I don't know how you square those two. Um, ah, it's sort of mixed messaging. Um, and the third piece which I uh, think ties in perfectly well with that a lot of operations centers and watch floors are now being because of budget cuts and because geopolitics is considered a significant risk area, uh, global security operations centers and watch floors are being asked to be more intel forward, more intel led. Um, and a lot of times you're asking operators um, to be something that they haven't been trained to be, that they don't have the experience to do, maybe didn't sign up to do either. Um, and really asking them to simultaneously do more with less geopolitics is a significant risk factor but also be more intel led. Um, and so I think that really puts security, ah, and intelligence organizations into a extremely difficult position, uh, to try and figure out. You know, it's easy to say think bigger and uh, you know, drive the speaker stakeholders, language. But when you're put under those pressures, I do recognize that, you know, there's only so much time in a day uh, to try and do all the things that you're being asked to do now.
Speaker A: Yeah, I want to focus on that third one because I think I'm seeing something similar. You're having people that don't understand how to do intel. And one question for you. Intel engineering, Red team, purple team engineering. And I'm like, so I tend to be, for the lack of a better term, a traditionalist on what an intel person can do and Then there's this additional verbiage out there, maybe marketing verbiage, that intel, you know, uh, domain, uh, takedowns. That's Intel. So what has been your, I guess, experience? What do you think about when intel is being done by people that are not trained for it? And as an example, when I first went into one of the previous companies I worked for, domain takedowns, that was Intel. I'm like, uh, okay, what else? That's how the intel does. I'm like, man, huge opportunity to do that. But what. Well, what do you think about that? Where intel is doing things that maybe shouldn't, but maybe I'm just looking at it from a myopic perspective.
Speaker B: I think it kind of depends. Um, there's, you know, it's. With the right tools and the right, you know, training and leadership and things like that, you can get a GSOC to a place where they're being more intel led and intel forward and understanding context around situations, you know, not just triaging alerts or triaging, you know, door alarms and things like that, but they're thinking more contextual. What does this mean in a bigger picture? So, like, there's one aspect I think, which, um, you know, is just an exercise of the brain versus, you know, needing like, specific training for things where you can start to ask those second, third order, um, questions.
Speaker A: Would that be considered intel, though? I think people question. People outside of our profession would just say, uh, that, that's a good analyst. They, That's a good SOC analyst. So then I guess, where, Where. How do we differentiate that?
Speaker B: Yeah, I mean, does intel exist outside of the government? Is a question I really ask myself a lot. Um, does it. Does. Does intel as, you know, somebody who comes from the government space, as we might know it, does that exist outside of government spaces? Um, I don't know that I have an answer to that, but I have toyed with that. Um, uh, in my role now, um, tell you a little bit, a quick story on this because I think it's relevant, um, in my role now, dealing with lots of different, um, companies and lots of different security teams, um, and had a company come and ask us some questions about a piece of analysis, um, that we had written, um, and wanted to understand where they were coming from. Where are you getting your information from? Um, you know, this seems like it's beyond factual. Was the, um, was sort of the, um, the, uh, pose, the way they posed it and so set up a meeting with them, had a conversation about it, uh, and come to find out, uh, they had come from a government background, had done like long time, uh, military intelligence. I'm, I am that too. So I totally get it. Um, but come to find out they, they really focused on the fact that, um, things were not written factually, there was opinion in it. And so it's not, it's not opinion, it's assessment. And that's different. Um, and they said, well, it should. Where is, where are the multiple sources, you know, corroborating sources and things? And I'm thinking to myself, like, you don't, you don't really get that outside of the government. That's a really hard thing to get. And so what is, you know, intel in the government? An all source intel analyst was like the, you know, the thing everybody wanted to be for a while there. Um, and that's all these different pieces of intel that you're puzzling together and sort of building connections and putting the puzzle together. Uh, does that exist outside in that way? I don't know. Um, so we, it's kind of like a different definition of what intel actually is to your point. Um, because you're right, that is just an analyst. That's somebody that's analytically minded, who can, you know, dive in on second, third order questions and understanding context. But is that actually intel? I don't know that it is.
Speaker A: No. Yeah. It's just fascinating when we dive deep into this. I, um, remember I was interviewing a couple of years ago, uh, for telecommunication, and they asked me what's more important, tactical or strategic? I'm like, oh, I know I'm going to fail this question. And I'm like, it's strategic. Why? I'm like, because if you don't have, uh, an understanding of your environment, you're going to be chasing the wrong fires tactically. Right. The one thing that I always this analogy because I've used a lot of analogies in cyber and talking to my legal team, they're like, oh, thank you for explaining that. And hopefully I'm creating just like what you said at the beginning, that business value speak brute. You know, again, for the lack of a better term, dumb it down with analogies. But one thing I always say that everybody's looking down, doing the work, putting out fires and creating silos. And what, what do we do as an organization? We award people for how many fires you put out in a week, a month, quarter, et cetera. Melissa, you, you put 40 fires out last week. Amazing job. Everybody gives kudos there. And then in from a strategic standpoint, I'm like, What if we just pick up our heads and there's a massive window in front of us? What if over that hill, you, uh, have somebody with a lighter? Hey, imagine if we stop that individual now. We're not putting out fires. And what adds to the complex word, to the burnout? Like you mentioned, the people left and right of us have been laid off. So now we have to do not only our work, but their work. And over here. But again, I think it's missing that bigger picture. So I answered strategically. And of course, um, I didn't get a call back. Which at that point these guys were, I think, more of the soc analysts and not our background. So I knew where they were going with that. I'm like, yeah, ah, I guess I'm just going to sabotage my, my own, uh, interview here. But I, I, I, I stood my ground. I'm like, no, I, uh, know what you, where, where you guys are going. Because a lot of their questions were all super tactical operational. Oh, one, one thing I wanted to, to kind of circle back. I blame the NSA analysts and Mandiant APT1 report. And why do I blame those that started the whole intel feeds, um, IOC feeds and this threat intel platform industry to aggregate all these IOCs. But the analogy that I use, IOCs are like bank robbers. You and I are Bonnie and Clyde. We go rob a bank. You have a wig, I have a wig, I have facial hair. The next bank we rob, we change everything but the bolo. Be on the lookout for an Escalade for a redhead, um, a Hispanic male. We change the, our attributes and the getaway vehicle, that's like changing the infrastructure. So one thing that nobody has really been able to answer, at least for my perspective, have IOCs ever been beneficial and said, oh, we stop this unless it's like maybe three hours within the incident that systems were able to block it. But after that, infrastructure follows there. So that's what came out of the APT1 report. Again, amazing report. But then that put us into the box and the NSAers, they came up with the diamond model. Right? Again, great for government. Who needs to know who hacked us? Attribution. But in the corporate world, maybe, you know, there, there's always those individuals that want to know who hacks so we can hack back. That's a whole nother, a whole nother issue. But it's like, well, why do you care? And it goes into the legal function. Well, if it's nation state, we kind of wash our hands. Right? So there is, you know, circumstances when it comes to that. But yeah, I just wanted to kind of throw that out and I want to talk to the NSAers that that came out. And it's an amazing model, but I think that only works in government. And I've seen people in corporate America use it. You know, the social medias, they're talking, I'm like, I don't know how I should take that. What's your thoughts on that?
Speaker B: Yeah, I completely, I think it's another, it is another model that makes sense for a government use case. Um, and there are so many of those, you know, those kinds of things. And it does. When you said that, I thought, well, who out there is actually like developing that model for a corporate, uh, a corporate function? They might be. They're developing it, but developing it for their corporation because there is money to be made in doing that and you're not going to share that knowledge, you know, with another corporation to necessarily, to uh, have their business be as impactful. And so it's an interesting like, dynamic there that there's a lot more on the government side, willingness in some cases to sort of share. And you know, we can all benefit from this kind of information. And it's not really money to be made. We're trying to do other things. There's other missions, um, you know, uh, on the government side. But from a corporate perspective, that's a different ball game. Uh, and it does actually kind of goes to this, uh, this concept I've been thinking a lot about because I think it does drive a lot of the corporate, um, security, cybersecurity, intel realm is the needle in the haystack Being so focused on finding the needle, finding that single actor, finding that, you know, exactly as you said it, finding uh, that, that Bonnie and Clyde, but actually you weren't really looking for Bonnie and Clyde in the first place. Um, and you get so hyper focused on looking for the needle that you forget to see, you know, the forest through the trees. Um, as I think that's a military, it's like a military phrase, but you get what it means, um, that you forget to sort of look at the bigger picture, as you say, like, and try to put the fires out before they start. Um, and you get so focused on the needle because the needle is the thing that might get you laid off or might ruin your team's credibility or if that, you know, that that's a high risk situation, uh, that could come out of that. And so I need to be focused on the needle because it matters to my livelihood and my credibility in this company to find the needle, but actually you wind up missing the bigger picture about what it actually means holistically. Yeah.
Speaker A: Ah, that's a valid point and hadn't really thought about that. Yeah, I think with the current environment where you have to show that value, in this case, trying to find that needle as opposed to, well, where does, um, that haystack actually fit in the world? It's like, I don't care. You're going down the rabbit hole. Just find that needle. Um, so I think what I'm hearing from you, Melissa, is that you and I have to develop a framework and sell it to corporations. And I was going to say out
Speaker B: of the goodness of our own hearts, but we could sell it too.
Speaker A: No, no, here. Yeah, it's about selling it for, for, for a lot of money. There. Um, I, there was. So I have a, you know, a, a presentation deck that I do locally here, and I think I have one, uh, next month. And it talks about intel, um, on how it's a business, uh, enabler and just kind of to your point, about listening more, integrating into the business concepts. Like for example, in my previous role we started doing, working with mergers and acquisitions and it's like, well, how does intel work there? Give us insight of who we're wanting to, uh, to acquire. And then now we can do that open source research to say, hey, this company, you look at the job descriptions, they have the whole list of their security stack, which is um, a bad thing to do. You never want to put what exact tools that you're using. But then we're able to look that up. Oh, here's our partners. Let's just use sim, uh, Splunk. Then we can look at all the vulnerabilities. And then now we provide that to legal. So when they're having these discussions with these companies, hey, you use all these tools. Have you addressed all these vulnerabilities? You m. Haven't. Then we're going to decrease the price. So that is outside of the government. We've never done that. Obviously for government.
Speaker B: Um, knowledge is power.
Speaker A: There you go. There you go. I think there's just so much opportunity here that we need. In my kind of diatribes, in my LinkedIn articles, I want to bypass middle management because I know I'm over assuming here, but it's like talking to a brick wall. They don't understand Intel. Intel belongs in a small little closet inside the SoC. That's it. That's all you do. Go find the domains and take them down. M. I want to Start talking and reporting straight to the CISO and the board of directors to show that value proposition, um, you know, moving forward there. That's kind of my high level, um, eye in the sky North Star initiative when it comes to intel and then marrying it with yours to say, hey, we could run companies. We can be the CEOs, we can be the individuals making, um, the informed decisions based on your intel team there.
Speaker B: So, um, Melissa, I wonder, within that. I do have one question here, within that, because this is another. This is a debate, um, I see here and there, uh, finding value, uh, as you say, beyond middle management. Sort of like, can I leapfrog them sometimes or are there ways to get around that and get clever about, you know, slipping reports on desks in certain places or showing certain things? What are your thoughts on that? Because there's a lot of discussion and sort of like working around those channels, um, which is great in some cases, but I wonder how realistic it really is or if it winds up biting you in the end.
Speaker A: So I struggle with that because. And even today I was talking to my senior manager, I'm like, oh, uh, chain of command, right? Military, government. It's like, well, do you really want to bypass? And I'm trying to, I guess, move away from that. And it's not a matter of bypassing the chain of command. It's, hey, I have these ideas, who's here to listen? And any opportunity that I have with the executives, here's what I'm going to do. Um, like for example, the one pager, something that I got from a book. And that's another thing that there was an analyst that I used to work with. And I kind of throw this out too. Obviously names would, uh, I'm not going to mention. They told me I don't like to read. I had zero response to that. I'm like, don't say anything mean. Don't say anything mean. And I'm like, well, you need to start. Is the only thing I. Because knowledge is power. So the reason I mentioned that I, I read a book, um, I'm a big gamer, 80s, so it's all Nintendo when time permits. But there was a book, a small little book by the CEO of Nintendo of America. I'm like, ah, I'll be able to, to get some, you know, geek knowledge. Turned out to be a business book. And I'm like. And he went, he started after college to Procter and Gamble. And it was a one pager and it gave me, um, ptsd because the one pager is A product that, that Procter and Gamble does to the executives. And his boss kept on putting, right, uh, uh, red lettering, do it over. Do it over. It was like six to nine months and it gave me PTSD because of our editors in government. It's like, what does talking about DDoS, uh, what does volume volumetric mean? I'm like, it's a massive thing. We'll put it that way. Using that word. I'm like, by the time it got released, I had to redo it all over again. It almost took nine months to get that paper out. Um, but it gave me insight on kind of the bottom line up front. The what, the. So what and what's next? And I've been teaching that, uh, to my teams and even colleagues. Look at. We have, um, a small bit of time to inform our key leaders. We can't give them a novel, we can't give them a strategic assessment. They're not going to read that. Um, but so hopefully that answered your question. I, um, think we need to shy away and there are, I guess, professional ways of doing that without trying to sink your manager. Trying to. Well, this person doesn't know much, but any opportunities you have when you're talking to your manager's peers or higher level, that's where you have to take advantage of that and prep, you know, a lot. So you can start impressing them like, oh, this person knows what they're talking about. Melissa, you drove some value here. Let's have a separate meeting. Right? And then now, you know, if, if your current manager has issues with that, then that's more. That tells you more about them than what you've done.
Speaker B: Great. And I love, I love a short, like a one pager. Even better than that. Shorter than that is. The shorter, the better. I had a boss, an old boss that, um, we always wondered why he would do this strange formatting or like highlight. Use a highlight and bold and italics to highlight different parts of an email to, you know, C Suite executive. But he, in his head, he had an equation and he had a conversation with that executive already that I'm going to highlight this. And that's the thing you need to take action on. And then the thing I really want you to read, if you don't have time to read, you know, the other four sentences, just read the thing that's in bold. And it was just a way to quickly get information that, yeah, makes perfect sense. If that's all they have time for, um, then, then they know exactly what they need to be pulling out of the information that you're sending them.
Speaker A: Yeah, no, I love that. It definitely makes sense. Melissa, we can talk, I think for hours. Um, but I want to be respectful of your time. Thanks for this conversation. I would like to, to get you back so we can talk about more on how to deliver this for corporations and not only here in the US but globally. Right. Because the US Is not the only country that is suffering from cybersecurity data breaches there. It's the entire world. And if we are able kind of be evangelist of our profession, that's going to benefit global companies and, um, we get paid there at the same time there's.
Speaker B: I love it. Yeah, I'd be happy to, anytime. It's a great conversation.
Speaker A: Awesome. Again, thanks for, uh, being on the show and we'll definitely do it again.
Speaker B: Thanks, Danny. It's been fun.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.