
LevelUp Cyber · 2024-12-05 · 34 min
Key moments - from our scoring
Substance score
59 / 100
Five dimensions, 20 points each
Steve Zalewski brings 23+ years of cybersecurity experience to this conversation, having progressed from software engineer to enterprise architect at Pacific Gas & Electric to CISO at Levi Strauss, where he championed the philosophy that security's value lies in enabling business objectives - "selling more jeans." He frames cybersecurity as a 50-year-old profession still in its early childhood (roughly age 6-8) compared to the 2,000+ year maturity of the legal profession, arguing this fundamental immaturity explains many industry dysfunction. The discussion centers on two critical shifts: first, how CISO roles must evolve from firefighters tasked with preventing all breaches toward resilience-focused leaders who protect critical business functions while accepting manageable losses; second, why the projected "million cybersecurity jobs" never materialized despite massive investment in bootcamps and degree programs. Zalewski identifies the culprit as unrealistic economic projections colliding with automation and process improvements that reduce analyst headcount demand, plus misalignment between what training programs teach (hacking skills) and what security organizations actually need (product management, engineering, operations, help desk, vocational roles).
The original projections were based on unrealistic assumptions that security budgets would grow 20-30% annually indefinitely. In reality, automation and process improvements have reduced analyst headcount demand, budgets have flattened or declined, and organizations can only absorb limited entry-level hires relative to their overall team size.
CISOs must shift from trying to prevent all breaches toward protecting critical business functions and accepting calculated losses - like firefighters prioritizing life safety over property. This requires renegotiating expectations with boards and executive teams so CISOs aren't scapegoated for inevitable breaches.
Cybersecurity is roughly 50 years old as a concept but only 6-8 years mature as a profession, whereas law has developed over 2,000+ years and medicine over similar timeframes. This immaturity explains why approaches that worked five years ago are already obsolete and why the profession is still figuring out fundamentals.
Organizations need product management, engineering, operations, help desk, and vocational analyst roles (12-18 months of training), but most bootcamps teach hacking and penetration testing skills. The vocational addressable market is much smaller than the training pipeline assumes.
CISOs must negotiate realistic success metrics and workload scope upfront, similar to any other business executive, rather than operating as lone firefighters blamed for failures but invisible during wins. This requires boards to understand cybersecurity risk as one business risk among many, not an existential threat to prevent entirely.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains several substantive ideas about industry maturity, CISO role evolution, and talent gaps, but much content consists of extended analogies, throat-clearing, and repetitive framing. The firefighter metaphor and lifecycle comparison of cybersecurity to law/medicine are genuinely useful frameworks, but they're padded with explanation and restated multiple times, reducing idea density per minute.
if you look at cybersecurity as a concept, maybe fifty years cryptography aside, but fifty years okay. If you think of us as a child, we were like a five or six year old, okay, And the business are the parents and their first time parents
My job is not to try to put the fire out and save the entire company. My job is to save those parts of the company that are critical to the company's continued survival
While the firefighter analogy is moderately fresh, the core arguments about CISO burnout, shifting from prevention to resilience, and talent shortage mismatches are well-circulated in CISO discourse. The lifecycle maturity comparison (cybersecurity as a six-year-old child) is conceptually interesting but not novel in the industry. Most frameworks and concerns are standard talking points.
if you look at cybersecurity as a concept, maybe fifty years cryptography aside...we got another twenty five years minimum, okay, to be able to take cybersecurity as a concept and as a set of tool jockeys, and to establish a true profession
My job is to save those parts of the company that are critical to the company's continued survival...then you worry about the collateral damage to the house or the rest of the company
Zalewski is a former CISO at Levi Strauss with 23-24 years in cybersecurity and prior software engineering background, plus current investor/advisor roles in the security community. He has operated at scale in both product and security roles. However, he's now in an advisory capacity rather than active practitioner, which slightly limits recency and depth of current operational constraints.
I've been in cybersecurity probably about twenty three twenty four years. It was not my first career, so I spent the first half of my career building product right. I'm a software engineer by trade
I joined Levi Strauss and just tried something new again, which was you know, retail, and I tell people it is women selling genes to women, and was there for six years chief Security Architect, Deputy c SO/CISO
The episode lacks concrete examples, named companies (aside from brief mentions of Kaiser Permanente, PG&E, and Levi Strauss in biography), specific metrics, or data. The talent shortage discussion is abstract ("million jobs," "budgets increased twenty thirty percent") without named sources or detailed case studies. The insights are largely conceptual rather than evidence-grounded.
budgets were increasing twenty thirty percent a year, Teams were increasing the you know, new is talking about all the cyber attacks coming out in North Korea or Russia
a lot of companies can't carry the size of those cyber security team. It's just not economically viable right now
The host asks reasonable open-ended questions but rarely pushes back, challenges claims, or probes for specifics. Zalewski's long monologues dominate; the host largely validates and reflects back rather than interrogating. There are few sharp follow-ups or moments of productive tension. The conversation feels more like a collegial chat than a rigorous interview extracting maximum insight.
That's a great answer. So I want to kind of dive into some of the SISO stuff you alluded to
I like it. We mentioned a little bit earlier around just the idea of the entry level, right
Computed from the transcript - who did the talking, and the words that came up most.
Join host Tony Bryan, Executive Director of CyberUp, as he welcomes Steve Zalewski , Cybersecurity Advisor at S3 Consulting and former Chief Information Security Officer (CISO) at Levi Strauss & Co., for an exciting episode. Get an exclusive peek into the world of a CISO as Steve shares how to tackle today’s biggest cyber threats, practical advice for professionals aiming to break into or grow in the cybersecurity field and answers to the questions you’ve always wanted to ask a CISO! Whether you're a seasoned pro or just starting out, this episode is packed with insights and actionable tips you won’t want to miss.
Transcribed and scored by The B2B Podcast Index.
Good afternoon, and welcome to this week's episode of Level of cyber Live. My name is Tony Brian, executive director of Cyber Up and your host for the show. Man to say that I'm excited about today's conversation may be an understatement. I just, you know, Steve and I were just getting ready for the show and kind of dove into a few of the topics and a lot of really great insights that I know are knew were new for me and so I'm very excited to share those with everybody else.
So with that, I'd like to welcome steve's Aluski. Steve is a former CSO Levi Strauss Cool Company right Everybody loves Jeans and is now an investor and supporter partner in the cybersecurity community and many different facets across the community. So Steve, welcome to the show. Thank you.
Tony, really excited to be here today and looking forward to the conversation. So, you know, I've had the pleasure to get to know you a little bit. I'd love for you just to tell everybody a little bit about your story and how you got to where you're at today. Sure, so I've been in cybersecurity probably about twenty three twenty four years.
It was not my first career, so I spent the first half of my career building product right. I'm a software engineer by trade, and built enterprise products for twenty years, enterprise operating systems, data security, data protection, fiber channel, hubs and s, which is patents, all that kind of stuff. And about twenty three twenty four years ago when it went from that side to the to the practitioner side, the buyer side, okay, And so I literally left the R and D startup world and said, let me go join Kaiser Permanente, which for many of you is a very large health maintenance organization.
And I said, I'm just going to go into it and I'm going to go manage right a component of it. My kids are young. I want to be able to have work life balance. Let me go do that.
And did that for about a year and they just realized, oh my goodness, Grace, I am not a fit. Okay. But as part of that transition while I was there, one of the teams I picked up was identity and access management and that was a better fit for me early stage development architecture, and then I came in on a Monday and found out I was now in cybersecurity because they had hired their first CISO and he scanned through the organization, found all the security folks and we were now in cybersecurity.
That is how I got into cybersecurity, just like that, come in Monday morning to DA and then obviously I went on that path for a few more years than I joined Pacific Gas Electric as a very large gas electric utility as an enterprise architect, put down a large identity and access management program there, then was promoted up to a managing enterprise architect, had a team, did a lot of the critical infrastructure protection for the gas and electric side, which is really exciting.
Did that for six years, and then I joined Levi Strauss and just tried something new again, which was you know, retail, and I tell people it is women selling genes to women, and was there for six years chief Security Architect, Deputy c SOCISO, and I would say my tagline and what people know me for from Levi Strauss is my AHA moment of realizing it's not about security, it's about selling more genes. But that is all my executive team cared about. And so my tagline would be for security vendors or others that came in to try to sell me something, and I would simply say, if you can explain to me how this sells more genes, then we can have a conversation, because that's the only thing my executive team cares about, and I go.
So that was my journey, and then I retired a couple of years ago from that role. Had decided to start an advisory practice where I spent a lot of time with the security startups now representing the CISO Commute and trying to get them to understand what it's like to be a ce cell and to stop trying to help me find a problem, but own a problem, okay, And to stop trying to sell me sneakers and realize this is a war and you're selling me weapons and you have to understand how well those things work.
And so that transition was for me kind of a re engagement because being an operating CEESO is exhausting. It is a burnout exercise. And now here I am on this show and talking to all of you about what the ecosystem looks like and kind of wanting to be that connector of brutal truth where I'm not placing blame on anybody, but I'm there to be able to say, look, we have a common enemy, okay, but we have all got to do a better job from a security village perspective of protecting our children, which are our businesses, to the degree that we stop fighting with each other over who's better and keep our focus on the common enemy and build the security profession correctly.
I think we're on the right path. You and I before we hopped on, had a really interesting discussion around the timeline in which because I think it's easy to forget right, Like this sector, cyber's pretty young in the grand scheme of life. It is a very young industry where we're still figuring things out, and I think large and far, there's a lot of people to your point of this idea of who's better, this weirdly competitive nature when and I'm not going to say it because I hate when people say it's a team sport.
Yes, I get it, but at the same time, you know, I'd love to have you run everybody through kind of your twenty five or so year history right to where we were team I was an eye opener to meeting and it puts it in perspective of just I think we're all expecting Ferraris and Lamborghinis right now of like where team should be, and the reality is we're probably I might work. You know, we're good kind of staple Ford, you know, Ford Explorers. It's a good car, it's dependable, but we're not going fast, right, We've got the basics down and we've got a little bit of a cooot tremaster.
There's a lot of room for growth. So I'll stop randling about that, and like, would you mind running everybody through kind of that analogy from your timeline of just how immature an age, not obviously what we do for cyber. Yeah, sure, Tony. So when we were talking, I perceived it.
I positioned it this way. You say, look ce cell Roles maybe twenty five years old, cybersecurity maybe fifty years old, right, multics in the old days of where initial cybersecurity came in twenty five years ago to Seesell. So it feels like we've been around a while. But I go look at the American Bar Association, look at lawyers, look at how long they've been around and how the practice of law from thousands of years ago is matured right, and how it fits into our civilization.
They go, So, if you look at cybersecurity as a concept, maybe fifty years cryptography aside, but fifty years okay. If you think of us as a child, we were like a five or six year old, okay, And the business are the parents and their first time parents. So we're six years old. We've made phenomenal progress if you think about a child from being a day old to being six years old.
But we got a ways to go to even get to our teenage years. We got another twenty five years minimum, okay, to be able to take cybersecurity as a concept and as a set of tool jockeys, and to establish a true profession of understanding what cybersecurity is, similar to the legal perfection or the medical profession. So you got to look at it that way. And so you've got all the businesses right who are trying to raise the cybersecurity child, invest in it.
They've never done this before. They're trying to figure it out. The child itself is getting better and bigger and smarter and faster, but we don't know what the teenage years are going to look like, never mind the adult. And so what we're all trying to figure out, okay, is how we go on that journey.
Yet we're all treating it as if it was a mature individual already. Ok And that's just kind of the dichotomy that we're in. Why I simply say, look, we can only expect so much out of everybody to do this, and we've got to realize where we are in the larger journey of the maturation of the profession and embrace that. Okay, and realize, now, if you apply that type of a lens, look at some of the inflection points, look at some of the maturity levels that are occurring right at these stages where what a ceesow was five years ago, and all of a sudden, the transitions to one of tool jockeys to risk management, from one to secure the company to sell more genes okay, to one of security to prevent a breach at all cost versus security as a cost center to do business.
And I need to take certain insurance policies against key risks. But it's one more business risk to me. Now, it's not this ethereal concept of security fear uncertainty. Now, we're all going to be out of business because people are hacking us.
Okay, that's part of the maturity. We just realized, No, wait a minute, the child is going to trip and fall and get hurt, but they are going to walk, right, they are going to run. They are going to touch a stove. Sometime it will be hot, in which case we have to go to the hospital.
But we can't prevent these things. Have to do is learn and mature through them. And that, in my mind, is a better reflection of where we are from a cyber security profession and why a lot of these conversations that we're having taken, you know, independently, just kind of from a perspective of of you know that that problem when looked at the larger ecosystem, you start to realize, oh, wait a minute, right, and where we went for example, is you know, where's the one million security jobs in the vocations?
Okay, and some of the challenge areas, Look, security is not a four year degree. It used to be, it can be, but where's the vocational tracks and where's an appreciation that you know, we need a certain number of mechanics and plumbers and electricians and cybersecurity as analysts or pmos or some functions. But there's a limited capacity to bring that in in conjunction with the overall maturity of the cybersecurity profession to create the environment for those jobs. That just the fact that we wish those jobs or that we can grow exponentially now in the way that we do cybersecurity is not going to match the way we're going to be practicing cybersecurity ten or fifteen years from now.
The people processing technologies are just too dynamic, and the way we do things today will look nothing like we do them ten or fifteen years ago as a security organization protecting our companies. Yeah, that's a great answer. So I want to kind of dive into some of the SISO stuff you alluded to, because that role, along with the industry as a whole, has evolved quite a bit, right. There's a greater scrutiny from SEC and requirements for board members, there's board training, We've added more robust insurance products, you know, But it's still a job that comes with a lot of stress.
You alluded to that. You mentioned the burnout that comes along with it, and oftentimes a thankless job that in fact is probably a bigger risk to take it if something bad happens because there's really little backside protection for that individual at the end of the day. So you know how you know as your your city, as a ceesow in residence, and you know with the Professional Association of CISOs, which is a great organization by the way, because I think it is, there's a lot of there's a lot of supports I think for CISOs.
Now, obviously everybody's well compensated. But of course money is one thing, but like mental health and sanity and like job satisfaction is equally as important. No matter how much money you make, that's not going to matter. So I'd like to unpack that, right, how have you seen the role to CISO evolved over the last couple of years and where do you see it going into the future, And what are some ways in which you know CISOs can work better with boards, there's other executive leaders or how does that need to go.
Yeah, I'm not going to have a simple answer here, but here's the analogy. As I've thought about this with you, they go. My observation is people in cybersecurity, not just CISOs. We'll start with CESOS, or we'll just call CEESOS meeting anybody in the profession of cybersecurity at the management or senior executive level.
Okay. My observations, many of those people in a different life would have been a firefighter or a policeman okay, or a nurse or a paramedic. Because what you find is there's something just innate in our need to run to the fire. Okay.
We understand that there's a protective nature to our job to protect the business and protect the people, and we're driven to do that. So we will run to the fire to put it out, okay. And that's not a bad place to be. As cybersecurity was young, but when I think about it now, especially in the last three four years, it used to be that we had a bullseye on our chest, right the bad guys would attack us, okay, they would damage our company.
We as firefighters would come streaming in, do our incident response, have our SoC teams put the company back together, trying to prevent the attacks when they don't put the fire out. And the executive teams respected that job. That was what it was understood to be. The executives understood it, and so when we took the bullet or the arrow in the chest, the executive teams had our back.
Okay, did a good job, Steve Man forty eight hours, seventy two hours with your team's heroic efforts. Thank you. Okay. But that's changed.
And the way I described that is if you look at what a firefighter truly is, if you look at the role of a firefighter. When a firefighter rolls up to the house, now, is there a job to put out the fire first? An answer is no. Right when they roll in, their job is to determine if there are any people or animals in that building, and they get those humans or animals out first, okay, and then you put the fire out.
And the analogy there now is so when I roll up and a company has been attacked, my job is not to try to put the fire out and save the entire company. My job is to save those parts of the company that are critical to the company's continued survival. And you protect those and you make sure that those people are safe and secure, and then you worry about the collateral damage to the house or the rest of the company, and then you put it back together as best you can. Okay.
And so our role is changed, like the firefighter role, which is it's not to protec the entire company. Equally, it is to understand the insurance policies we have to take for the key business processes that are our company, Okay, at the expense of others, because I just cannot provide a uniform defense no matter how much money I have. So that's the shift of we're truly becoming firefighters in the truest sense now, which means who has our back? Because the executive teams are still working through that as well, right because we're still presenting as we're going to put the fire out and protect the whole company, and when we don't, the executive teams are saying, you didn't do your job, thank you, there's the door, or we burn out because we're trying to be heroic all the time and it is just beyond the ability of a human to do that.
And so therefore, how do I reset the expectations of the role similar to firefighters Now we're actually have a chance at being successful at my role and actually have a work life balance so to speak. Well, that is part of the we're eight years old now and we're having to have conversation with the adults about wanting a different perspective of how we grow forward, right, that's where we are in the industry. That's part of this. And so now as a CISO, it's I take the arrows from the bad guys and who's got my back?
Okay, because I have to renegotiate what the expectations of a CISO and a cybersecurity organization are now against the realities of the business risk. Knowing that what I committed to five years ago is I'm just going to prevent the attacks in my company is just not a sustainable or reasonable approach. We've demonstrated, except for limited cases, when you get to many companies, it's just not possible. And one of the reasons why I argue is because humans are the weakest link, right, make mistakes.
Humans are lazy, and so all the process in the world won't help me. All the technology in the world won't help me if the humans aren't willing to do their part. Okay, And even then it's not that they don't want to. But it's two in the morning, right, and you're not thinking, and you're traveling, and you click on a link and you fall for a fish.
So resiliency gave the ability to withstand the attacks, not by keeping the whole house from ever catching fire, by putting fire alarms in, by putting smoke detectors in, by putting automated sprinklers in. To realize that I've had to do all those steps because a fire will happen, and so let me manage that collateral damage and be resilient to move forward. That's part of the maturity change. That's what you're seeing in the industry right because we're young, but it is very chaotic as we're working through this.
And again because for the last ten or fifteen years, the way we've practiced cybersecurity is clearly not sufficient for the next fifteen years. Now that the business is realized, we can't carry the cost against the effectiveness that you've provided to stop the attack. Okay, an efficiency isn't good enough anymore. You've got to be effective.
And so that's the transition in the Ceesoll role. That's why I use the firefighter analogy. Okay. And the goal here when I talk to folks is to be able to say, look, I have this conversation about being a c cell and many people say that is the worst job I will never want.
Let's keep it that way to one of this can be the most satisfying career that you can possibly have. I mean, it is just so hard, and it is again so right because you're protecting the social fabric, right, you're protecting companies. But it has to come with conditions. Now, you have to to understand that you don't get to get out of jail free card that you, like every other business executive, have to negotiate the terms of success for an industry that is early in the maturation stages.
And you need to be able to adapt. That helpful, helpful perspective because it's easy to want to go fast, right, and like we've got the answers and we're told oftentimes but things were either one to buy or we're sold to that it could solve all of our problems. And it's nice to hear that. Of course, we don't have all of the problems figured out because we don't know what all the problems are, because the bad guys at this point don't even know what the problems are because they're still making them up as we go.
So I know, for me, the legislature and the mandates from SEC and putting the focus on for executives and board members. That's such an important part that it is back to being the team sport. It doesn't fall in a single person. As a point of I always think of jinga right, that the CISOs the one jinga board that pulls out that it all falls right, and like that's not necessarily the case.
There's a slew of people. To your point, this should problem up and expectations and things there to be able to go as we look ahead to the next five to ten years. Right. Hiring has been a big part of this discussion across the board, and you know, you and I we spent quite a bit of time kind of talking around where's the challenge, Where where's the rubber hit the road in this this entry level hiring conundrum.
I think we've found it right. We've we've painted a picture of millions of jobs you alluded to earlier. We've we've we've created degree programs and boot camps and apprenticeship programs. Ours included in droves to solve this talent gap, skills gap.
I don't know, we've had a lot of adjectives to describe what we've had right over the last ten years. We haven't gott any better let's be honest, right, where there's we've CYBRUP has had good success in doing we want to do it at scale, and there's a lot of good examples of people doing good work. But I haven't seen much of it scale to this, to the size in which I think we all expected the scale to be. Why is that?
That's a lot, that's a big question. But what you know, why, what what causes that? And what are some solutions we can do to try to maybe rectify that in the future. Yeah, so it's a combination of unrealistic expectations and unintended consequences.
Okay, so unrealistic expectations, right, Like I said, we're all firefighters, we want to help, we want to put people to work. Right, cybersecurity as an emerging profession, just you know, even five years ago was unbounded, right. Budgets were increasing twenty thirty percent a year, Teams were increasing the you know, new is talking about all the cyber attacks coming out in North Korea or Russia or you know, you pick your favorite nation state. And so therefore there seemed to be this unbounded need that we're going to need so many millions of analysts to be able to do the protection right and training and all the other facets because there's so many companies and every company's going to need a security team.
Okay, that was the unbridled enthusiasm. Okay for what it was. There's a million jobs. But the reality, okay, is that that didn't happen in five years.
Five years later, budgets got large for a lot of the fortune, five hundreds other companies were putting security teams in. But then the recessions started to hit the security industry itself, right, has been so overspent that the business executives are saying, I can't afford the cost of security at its current trend. It just doesn't scale. And so therefore there's some course correcting going on, which results in, hey, guess what those initial projections were based on some unrealistic expectations and economic models that now that they're coming home to roots, everybody politically still wants a million jobs.
Everybody says they must be there because look, you told me five years ago they were. What's changed, Well, what's changed is what we're talking about here that isn't so politically acceptable. And now what we're seeing is we don't necessarily need as many analysts because the process and the technology are replacing a lot of the work that we were doing with analysts three, four, five, seven, eight years ago. Right, we need more efficiency for effectiveness, and so therefore there's this moerating effect going on.
That said, oh, based on the projection for how budgets are going, everybody's going to be hiring. So of course I want to be able to bring in Okay, younger people and I don't mean young people, but I mean people early into cybersecurity into these roles that I can anticipate creating. But when the budgets didn't materialize or now they're actually going the other way, okay, that market's frozen. And what we were talking about is and so we're being creative and finding other ways to be able to bring cybersecurity resources within a company, right because we can't necessarily bring it learn from the outside.
And the other part of that we talked about too, which was most people think about cybersecurity as I want to hack, and so therefore I need a four year degree. I got to be good at hacking tools. I want to break things. Okay, Well, the security organizations, when you look at them, are maturing, and I need product management, I need some engineering, I need operations, I need help desks, I need analysts, I need purple teams.
So the twelve or fifteen people that I have are spread pretty thin. Okay, to cover the basics, where do I find the headroom? Okay, to be able to bring in another four year degree? We have to acknowledge there's a vocational component here that we have to think of cybersecurity as having a set of vocational jobs as well that only need a year or eighteen months of expertise.
But there's not as many of them because again, I can only use so many analysts, I can only use so many young pmos. I just don't have the room to carry people that are just bright and then bring them into the organization. The large companies do that and still do, but it hasn't materialized to the larger ecosystem because a lot of companies can't carry the size of those cyber security team. It's just not economically viable right now.
So that's the rationalization, which if you look at each of those pieces, makes perfect sense, and aggregate can somewhat explain why the million isn't even half a million. Okay, but it will evolve over time because some of the larger economics in the market and the maturity of cybersecurity and the way we accomplish cybersecurity is going through foundational change. I like it. We mentioned a little bit earlier around just the idea of the entry level, right, is hard, and you know a lot of it is being carried to your point by large companies with a little bit bigger budget.
But when you start hitting some of these smaller startup companies that have three or four, they need all three or four to be rock stars, right, because there's very little margin. And I think you said it in the pre right. If I'm a team of ten, I bring in one entry level, I've just cut my efficacy or my productivity by ten percent, right that person. So so how with that in mind?
And that's and for those that listen are in the market for a job, it's okay to panic. We're good, right, the jobs are there. It's just we have to get a little differently with it. Right, It's just there's some some different creativity.
However, how do we what's the counter to that? Right? How do we how do companies lean into some of the already existing people that have made this investment. Are there ways in which we can create more roles or periphery roles, or where should these folks that have maybe are finding themselves out of work or a little bit of frustration, like where can they go to really find ways to break into it?
Or where where should they be looking? Yeah, I would say from that perspective, the cybersecurity industry is no different than any industry. Right. If you if if you come out and your passionate about marketing, right, or you're passionate about fashion okay, or you're passionate about accounting okay, all those feel have openings as well, right, but they're somewhat saturated too.
And what's the answer. The answer is you network, You demonstrate interest, You find ways to get yourself introduced in okay, to demonstrate your worth. It's hard work, okay, it is, but that's what you do and then you get results from that. Putting a resume in those days, just the economy isn't there for that, so you, along with fifty others, you have to differentiate.
So what I say is, look, the good news is if you want to get into cybersecurity, cybersecurity is a family. Okay, we really act like a family. There's not that many of us, and there's more, but we really work with each other, that firefighter mentality of trying to help each other out. We want to help.
That's not necessarily true in the other industries. Okay, So you got to put your yourself out there a little bit. Okay. If there's local security communities and chapters, okay, use them, they'll be happy to embrace you.
Don't mean you have to pay come along, Okay. There's all kinds of courses on aws and others and certifications that allow you without having to pay a lot of money to educate yourself. Okay. Just like mechanics, some are just natural.
They can look at an engine and you give them tools and they take it apart. It's no different in cybersecurity. Right if you have a natural inkling as an analyst, right, or as a as a hacker okay, or as somebody who just likes to manage projects, okay, you have this natural inate abilities, take the courses right to be able to demonstrate your interest, and then you've got to fight for the job because there just aren't as many as we would like. That's just the natural reality, right of what we have to do.
So embrace it, Okay, go for it, and it will pay off, maybe not as quick as you want, maybe not in the ideal job that you want, but that very safe kind of creativity that made the United States where we just won't say no, we find a way. It doesn't mean that it's going to be comfortable, but you do it. The cybersecurity industry is the same and to a certain extent, you know, I mean when you when you get into it, you will find a role okay, and you will succeed. But you got to put the time and effort in to do the research to know.
In an emerging kind of field like this, it's not that we just need ten thousand people. You do kind of have to do some homework to know where you fit in there to be able to make the case, and then put yourself out there and good things will happen. I almost think that's a perfect summary. The last question is what is advice would you give level of your career?
Because you just answered it, nailed it right there with that answer, So man, I think we could probably go on for probably another thirty minutes because I've got some barn burning questions here on theso stuff and it's exciting, right, and it's it's easy to forget that it is. We are very a young sector with a lot of unknowns, and I don't think there are many industries or sectors that have you know, international threat actors and state actors that are coming at them. Right, So like to your point, I think you said it earlier in this and even when we got on, like there's a level of war and seriousness to this, right, Like real world things happen and implications happen.
It's not a stub toe or a splinter. This is data and money lost and jobs lost and other things. So it's easy to get caught up and forget that, right, and just in how serious this stuff is. And then there's a couple of at least for me, and that I in the back of mine mind and that I worry about more and probably put on a military hat to some of that extent of like okay, like there's risks that come along with this.
So yeah, we get focused on so many other things and forget the big picture oftentimes. So I appreciate the grounding and the reminder of that today in a good way, right, in a good way. So Steve thank you so much for the time on the show. I'm really thankful to get to know you, and am I to call you back up for another show.
I like the segment of ask a SISO. If I'm being honest, I think it's so many We've interacted with thousands of people over the last ten years of just trying to find their place and way into this sector. And so you know, I'm probably the work the cyber up is done to make that inclusive and to make more opportunities for non traditional students to get into it. I want to do it more because it's my favorite thing in the world to do right, is to you know, to have somebody call us to say I've got my job and I'm good and my family's taken care of, Like that's amazing.
So you give me hope that there's room there for us to see this over the next five to ten years and that we hit the level of maturity that we're doing the things we need to do. So long ramble, but as a long way to say thank you Steve for your time, thank you for everybody for listening, and everybody have a great week. Thank you. I'll buy everybody.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.