The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Man In The Middle Podcast
Man In The Middle Podcast artwork

S02E05 - From IT to Strategy: Sash Vasilevski on Reframing Cybersecurity as a Business Enabler

Man In The Middle Podcast · 2025-04-09 · 47 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft13 / 20

Sash Vasilevski, founder of Security Centric, brings over 20 years of experience in technology and cybersecurity across defense, federal government, and mid-market organizations. The conversation focuses on three interconnected themes: first, the CISO-as-a-service model - positioning it as a cost-effective way for mid-market organizations (100-1,000 seats) to access seasoned security leadership without full-time overhead, structured to avoid artificial hour limits that undermine proactive security work. Second, the critical need to separate cybersecurity functions from IT departments to eliminate conflicts of interest (IT optimizes for uptime and user experience; security requires different tradeoffs), prevent IT from auditing its own work, and bring specialized expertise to complex systems like Microsoft 365, cloud migrations, and API security that generalist IT teams cannot adequately protect. Third, the business alignment piece - moving cybersecurity from saying 'no' to initiatives toward enabling business objectives transparently, using ROI and competitive advantage language (like IRAP compliance for Australian government contracts or SaaS differentiation) to justify investments. Vasilevski argues that astute organizational leaders, particularly those with finance backgrounds, recognize that separating these functions - much like auditors separate from accounting - delivers both security and business outcomes rather than short-term convenience.

Key takeaways

  • →Unlimited CISO-as-a-service engagement (not capped hours) encourages early-stage involvement in architectural decisions, avoiding expensive rework and residual risk that occurs when consultants are brought in too late.
  • →Separating cybersecurity from IT eliminates conflicts of interest (IT is measured on uptime/performance, security on risk mitigation) and allows cybersecurity teams to develop true subject matter expertise in specialized areas like cloud security and identity management rather than remaining generalists.
  • →Cybersecurity should be framed as a business enabler that makes initiatives seamless and competitive advantage possible (e.g., compliance certifications opening government contracts) rather than a function that blocks organizational growth.
  • →Integration of external CISO-as-a-service resources into the organization chart, email systems, and executive presentations creates implicit organizational understanding that the role carries the same authority and standing as an internal position.
  • →Effective cybersecurity communication to business leaders requires translating technical risk into business language - competitive advantage, market differentiation, procurement requirements, and ROI - rather than discussing advanced persistent threats or nation-state actors unrelated to the organization's actual threat landscape.

Guests

Sash Vasilevski

Topics in this episode

Identity and access managementMFA bypassCISO-as-a-serviceMicrosoft 365 securityIRAP complianceAustralian government procurementCloud architecture (AWS, Azure)SaaS differentiationInformation securityDefense and federal government security

Questions this episode answers

Why should cybersecurity be separated from IT departments?

Cybersecurity and IT have conflicting priorities - IT optimizes for functionality, uptime, and user experience while security manages risk through controls that may impact those areas. Additionally, IT cannot objectively audit its own work, and IT generalists cannot develop the specialized expertise (like Microsoft 365 PowerShell security configurations or API security) needed to adequately protect complex systems.

How do CISO-as-a-service models differ from traditional part-time security consulting?

CISO-as-a-service provides unlimited engagement without hour caps, encouraging early architectural involvement to prevent problems rather than fixing them post-implementation; traditional hourly models discourage use due to finite budgets, causing organizations to defer security reviews until late-stage deployment when major rework may be required.

How do you align cybersecurity investment with business ROI?

Frame security investments in business terms - competitive advantage, market differentiation, procurement requirement compliance (like IRAP for Australian government contracts), or simplified vendor selection processes that expand addressable markets or reduce due diligence friction for customers.

What's the importance of including the CISO in executive communications like CEO town halls?

Positioning the part-time CISO on the org chart and having them present alongside executives at company standups sends an implicit organizational signal that the security function carries equal authority and is integral to business strategy, not an external service.

How should cybersecurity practitioners approach requests that introduce security risks?

Rather than saying 'no,' security teams should work transparently to mitigate risks while enabling business objectives - making security overlays seamless so users experience the functionality without perceiving security friction, while involving security early in architectural decisions rather than late in implementation.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains moderately useful business-applicable insights, particularly around CISO-as-a-service delivery models, separating IT from security functions, and aligning security to business objectives. However, much of the content consists of Sash explaining his background, philosophy, and business model rather than delivering novel, non-obvious claims. The CrowdStrike discussion adds little new substance beyond 'technology fails, plan accordingly.' Several sections involve extended anecdotes and motivational reflections that pad runtime without adding density.

There is a requirement for some steering um, strategic direction within an organization around cyber security. How we can manage cybersecurity risks, but also how we can use that as competitive advantage
you can't check your own homework. Um, if I asked any technology function, um, IT department, however you want to refer to it, any technology function, have you deployed a system, some infrastructure, some technology? Have you deployed it securely? If we do that and ask that question 100 times, I'm going to get the same answer 100 times. Yes.

Originality

11 / 20

While Sash articulates some sensible positions - separating IT from security, treating security as a business enabler rather than a blocker, risk appetite frameworks - these are not novel concepts in 2024. The CISO-as-a-service model is somewhat differentiated operationally (unlimited hours, org chart integration) but the underlying logic is not contrarian. The CrowdStrike take is generic ('tech fails, plan ahead'). There is little first-principles rethinking or counterintuitive argumentation; mostly sound professional practice explained clearly.

Most organizations um, are not, do not exist because of cyber security. Ours does, but most don't.
You need to understand that those platforms, much like Crowdstrike, uh, Endpoint, uh product, they will have issues and um, that's not unknown. You, nobody could say that I couldn't forecast a technology issue.

Guest Caliber

14 / 20

Sash Vasilevski is a legitimate practitioner with ~20 years in security and defense/federal government experience, plus founder of an active MSP-style firm. He has hands-on credibility and real client exposure. However, he is primarily a service provider/entrepreneur selling CISO services rather than a multi-company operator or transformation leader at enterprise scale. He speaks authoritatively but from a mid-market MSP lens. Not a tier-1 guest (e.g., CISO of major tech company, head of security at scale-up unicorn) but solid mid-tier practitioner caliber.

I had seen the way information security was being implemented for large organizations. The largest, including the largest in Australia, the Department of Defense. 120 odd thousand employees.
We have clients that um, are in the legal space. We have clients that are in the dairy space. They milk cows and create products that consumers love.

Specificity & Evidence

10 / 20

The episode lacks concrete numbers, named examples, and granular case studies. Sash references 'Department of Defense with 120k employees,' 'mid-market organizations between 100 and 1,000 seats,' and a generic anecdote about a contractor gaining 'visibility' - but no specifics on financial impact, timeline, metrics, or named clients. The Microsoft 365 example mentions 'PowerShell' and 'MFA bypass' but no specific breach or cost. The Harbour Bridge analogy and supermarket kiosks are illustrative but not evidentiary. CrowdStrike discussion avoids numbers entirely. Overall reliance on frameworks and soft examples rather than hard data.

There is a requirement for some, some steering um, strategic direction within an organization around cyber security around cyber security
one off to get us to that point. Here is the Ongoing operational, uh, cost of that framework. And here is the market size that we were able to uh, open up because of that.

Conversational Craft

13 / 20

Jeremy asks reasonable, logical follow-ups that move the conversation forward (e.g., 'how do you integrate a part-time CISO?', 'why separate IT from security?', 'how do you align security to business?'). However, he rarely pushes back, asks sharp clarifying questions, or challenges claims. When Sash makes broad statements ('technology will fail,' 'risk appetite frameworks'), Jeremy mostly accepts them and pivots to the next topic rather than drilling into specifics or exploring contradictions. The host is competent but not incisive; mostly facilitating a thought-leadership monologue rather than conducting investigative dialogue.

Yeah. And is that where this um, you know, this concept which has you know sort of gained a bit more traction over the years of um SISO as a service really comes into play
Yeah. And how do you find that integration process within an organization?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B79%
  • Speaker A21%

Most-used words

security53cyber34technology26organization26risk22systems20organizations16cybersecurity13function13experience12part11sash10information10important10case10impact10

Episode notes

Welcome to the latest episode of the Man in the Middle Podcast , where we dive deep into the world of cybersecurity and technology. This episode, we interview Sash Vasilevski , Founder and Principal of Security Centric . With over 20 years of experience in technology and cybersecurity, Sash has built a reputation for helping organisations align their cybersecurity strategies with business objectives. As the founder of Security Centric, Sash's work ensures that cybersecurity is seen not as a hindrance, but as an enabler for growth and success. In this episode, we discuss Sash's journey into cybersecurity, the rise of the CISO-as-a-Service model, and why it's crucial to separate security from IT functions. Sash also shares insights into the cultural shifts organisations must make to see cybersecurity as a business enabler, as well as the lessons learned from recent cybersecurity incidents. Whether you're a business leader, cybersecurity professional, or simply passionate about the evolving cyber landscape, this episode is full of invaluable insights for anyone looking to integrate security into their business strategy.

Full transcript

47 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign. Welcome to another episode of the man in the Middle podcast. I'm your host, Jeremy Mullally. This is an It's a Comedian podcast, and today I'm really thrilled to be joined by Sash Vasilevsky. He's a seasoned Expert with over 20 years of experience in technology and cyber security. Uh, he's the founder of Security Centric, and Sash has built a reputation for helping organizations align their cybersecurity strategies with their business objectives. So ensuring that they have, uh, you know, security to be a true enabler of their growth and success. Uh, we're going to dive into, um, a couple of topics today. Um, one of them is around, um, what Sash is passionate about. Aligning that cyber security element to their business goals and then also, um, separating, uh, your IT and cyber security functions along with some other topics. But with that being said, Sasha, I want to welcome you to the show today.

Speaker B: Thanks Jeremy. Pleasure to be here.

Speaker A: Yeah, no, pleasure's all mine. Um, and to always start, uh, by asking my guests who come on this podcast how they got involved in this world of, um, cyber security and, you know, technology more broadly. So Sash, could you bring us sort of up to speed how you, um, you know, a bit about your background and how you got involved in, in tech and cyber security?

Speaker B: Great question. Um, look, uh, let's, let's think back to, uh, the 90s. I was taking things apart. So technology was always going to be my, my future. Ah, computers were really starting to make their way into the homes back then. So technology, computers. Ended up doing a computer, uh, systems engineering degree. Um, partway through that, ended up with a role in an, uh, IT consultancy and worked in different areas in it, uh, consultant side, internal roles, large, medium, small organizations. Had a, had a mini career in it. Took a step back and thought maybe I'll, uh, followed my engineering roots, uh, a bit closer. So ended up at a defense contractor working on all sorts of, uh, military systems, communication systems, things like that in a tactical space that, uh, was quickly coupled with my IT background to end up in the strategic space. So, um, parts of defence, federal government, uh, three letter agencies, uh, down in Canberra, spend a lot of time working on tactical and strategic areas, um, for defense and federal government. They take information security quite seriously. They've been doing it for decades. Before cyber, uh, security was hip, happening and sexy. And before it was called cyber security when it was referred to as, as information security. So cut my teeth in those environments, saw how to implement information security effectively, uh, and was hooked, uh, ever since.

Speaker A: Yeah. Great. And as Far as um, the founding of Security Centric, can you sort of um, fill us in on how that came about? Because I know a big part of um, like we sort of mentioned at the top of the episode was that passion between bridging that gap between um, businesses and the importance of cyber security. Tell us how that came about.

Speaker B: I had seen the way information security was being implemented for large organizations. The largest, including the largest in Australia, the Department of Defense. 120 odd thousand employees. And the methodology uh, was sound. Um, and what I was keen to do was extend that uh, to organizations that perhaps didn't have the resources, uh, the focus at the time, this is 2012 we're uh, talking about, um, and take that methodology proven in classified environments, very sensitive environments and really make that available to the, the broader economy. Uh, uh and for Security Centric, uh that was the, the mid market, um, there's a lot of organizations between 100 and 1,000 seats, UM and cyber security is important uh to, to them. Um, they have sensitive data that they don't want compromise, they don't want um, made unavailable and all of those things. Um, but didn't have the resources of Department of Defense, didn't have the resources of a lot of the agencies and federal government departments uh across Australia, particularly in Canberra. And so that was really the impetus to start Security Centric and really make uh, uh that proven m methodology available to more than just the big end of town, the banks, the defence, the large organizations, the 5, 10, 20,000 uh seat organizations that um, can solve many problems with massive budgets, massive teams, subject matter experts across the board. Um, they just 500 seat organizations don't have uh, the resources uh to build up um, a cyber security capability as it should be with various, half a dozen at least subject matter experts. Um, and that's where we come in to get them the same result that the Department of Defense that large organizations get, but make it available um, and economically viable um, for the mid market.

Speaker A: Yeah. And is that where this um, you know, this concept which has you know sort of gained a bit more traction over the years of um SISO as a service really comes into play because you're you know um, gaining access to uh, like the expertise of you know, taking your case of yourself and your team, um, where it's not so resource heavy, is that sort of where that's gained a bit more popularity over the years?

Speaker B: 100% Jeremy. There is a requirement for some, some steering um, strategic direction within an organization around cyber security. How we can manage cybersecurity risks, but also how we can use that as competitive advantage um, or organizational advantage in more broader sense. Uh but again there's resource limited organizations. They can't hire a ciso, um, maybe that takes up a significant portion of their cybersecurity budget. Do they need them 40 hours a week? Probably not. Um and so that's where the CISO as a service it's getting all of the upside of an experienced professional who's seen many different environments, uh, but you don't need them ah all day, all day, every day, five days a week, uh, 40 hours a week. Um, it needs to be right sized. Um and trying to find, fill a part time position, you make other compromises where you have someone who's either uh, potentially distracted um, or making other uh, compromises um, they don't have that breadth and depth of experience. It's not as attractive to people in that um, they want to pursue that uh, particular career track as well. So the other alternatives, contractors essentially, um, hiring bodies, you don't get that same buy in. And so what we've tried to do is really replicate all of the plus points, the advantages of having that full time permanent ciso, ah resource within your organization. Um, getting them part time, getting them uh, getting cost savings obviously.

Speaker A: Yeah. And how do you find that integration process within an organization? Because you know security is so important and critical to um an organization and a big piece of that is trust. How do you find that integration um, of ah a part time CISO coming into an organization to sort of like really integrate themselves to feel uh, a part of the whole.

Speaker B: That's one of the most, one of the most important parts of the process. Um, it's also a reason why that particular construct delivery method is really attractive is how well we integrate compared to uh, some of the other options uh available in terms of contracting, body shopping, things like that. Um, the way that the onboarding works, the way that the engagement works is they really do become part of the organization. Um, their timesheets m might not show 40 hours a week but they're part of the organization, they're on the org chart. In most cases they have local uh, accounts, uh, email accounts, they interact with staff, uh, third party suppliers, vendors, customers in exactly the same way. Uh, that and an internal CISO resource would, and that's encouraged from day one. And so rather than here is an external resource and people having to relay uh, information, they're really brought in, they're brought into um, many cases uh, town halls or company stand ups where a CEO Might present uh, where the company is headed at the, in terms of their vision and strategic initiatives. They'll bring in their CISO in to deliver on security initiatives, uh, that might be internal, that might be customer facing cybersecurity initiatives, but they will come in and present alongside the CEO uh, at those town halls as exactly the same role. And so from day one the organization, people within uh, the organization see that role, uh, referred to, used, invited, uh, as an internal role. And so there is an implicit understanding, regardless of what direction you give uh, staff, there's this implicit observed understanding that actually they're acting, behaving, appearing exactly like uh, one of the team, one of the management team, uh, so we'll treat them as such. The other part, uh, and something that we've adopted over the last couple of years is there isn't uh, from a commercial construct perspective set number of hours, uh, there isn't a here's a retainer, here's some hours. Once you've used that siso, you're out of hours for the week, uh, or month. We thought that was limiting um, and it really undermined the entire reason for having that sizer and that is uh, treat them to get ahead of the curve, use them before there's a problem, to avoid a problem, not to clean up the mess. And so much like a full time sizer, they're there, they're there for you whenever you need them. And maybe a uh, full time internal sizer has quite with weeks and they have busier weeks. That's the same with our uh, sisos. They're unlimited. Use them as much as you want and they will have quiet weeks and they will have busy weeks. But what we want you to do is involve them at the whiteboard stage before there's a problem, before you go away and implement a new system or change to the way your organization works. You've brought in some suppliers that gone through and tested and integrated and you're about to go into production and now you tap the size on the shoulder and want their blessing, their checks. And by this stage you might have all sorts of fundamental architectural issues. You have to get to wind that back or you have to run with um, some of that residual risk, um, because you waited too long. And when you have a cap on um, leaning on that resource, that's what happens. It's just human nature. If you have a finite ah, amount of something, you try and safeguard it. And that undermines the very purpose of a siso, which is to help steer and guide and have you thought about X and Y early on and so engaging them really early on is, is important. We've changed the way that ah, services is delivered because of human nature. We encourage use that as much as you can. That's how you're going to get a real benefit. It's uh, very hard to quantify that because you're avoiding problems down the road, you're avoiding risk, you're avoiding potential incidents, breaches. But you're also. And what's difficult to quantify is that rework that you uh, you avoid by engaging. Engaging early.

Speaker A: Yeah, it's really interesting model because uh, especially around the piece of um, the resource allocation. Right? Because I feel like that that's an important element to ensuring that that integration is, is there as far as you know, the SISO being really part of the organization in the same way that if they had a full time siso, um, you know, hired within the organization. So I think that's, that's really critical. But um, I wanted to ask you Sash around um, this when it comes down to the IT departments because usually I imagine that you know, the companies and organizations you're working with, if they are having a um, you know, an outsource size service model prior to that, usually it's the IT department which is having to carry the burden of, of security. Um, and that's actually quite typical for a lot of um, you know, companies of that side. So I wanted to ask you what, what's the importance of, of separating that out, so separating that responsibility of cyber security away from the IT department. Why do you think that's an important feature to have?

Speaker B: There's a, there's a few areas. Uh, but the, I suppose the most important is uh, and uh, the easiest to understand is you can't check your own homework. Um, if I asked any technology function, um, IT department, however you want to refer to it, any technology function, have you deployed a system, some infrastructure, some technology? Have you deployed it securely? If we do that and ask that question 100 times, I'm going to get the same answer 100 times. Yes. Now maybe that's the case. Uh, or maybe um, you shouldn't be checking your own homework, you shouldn't be reviewing your own work. Um, so there's uh, number one is the conflict of interest. Uh, you need to separate those functions. Um, there is the overall remit of the technology function. It's to uh, provide technology that supports the business. Uh, and your important characteristics are uh, functionality, performance, availability, uptime, uh, user experience, um, and some of those uh, are uh, completely at odds with uh, the information security, the cyber security requirements. And so there will always be compromises made. However, if a technology function is on the hook for customer experience and functionality, uh, there is. What we often see is there are ah, compromises made that introduce cybersecurity risks. Um, because the technology function is measured upon different things. Different things are, uh, functionality, performance, user experience, things like that. Uh, and so that function needs to be separated from a conflict of interest uh, perspective uh, as well as what is your overall remit. And the remit is not in many cases around the technology side. The focus isn't. The second reason is um, subject matter expertise. Uh, there are uh, exchange experts, SharePoint experts, there's experts in AI, generative AI coming out of the woodwork, um, mailbox migrations, uh, email migrations into the cloud, use of uh, orchestration containerization in public cloud, your aws, Azure. Azure. There's a lot of technology there. There's a lot of knowledge and experience in terms of how do I do, how do I provide this function, how do I provide it with a great user experience, how do I make it uh, reliable, available, how uh, do I make it uh, perform and scale. That's a lot to know. We don't know that um, to tack on all of the areas of cybersecurity. It's just uh, an unrealistic expectation to also have that depth of experience and knowledge. We have a large team and within those, within that team we have sub teams within those specialist business units. We also have individuals with areas of expertise. All we do is cybersecurity and we still need to have uh, those differing areas, uh, of subject matter expertise and that depth of knowledge to do it well, to expect the technology professionals who also need to know the ins and outs of Azure architecture, AWS, APIs, uh, the ins and outs of SharePoint and how to integrate that with modern business applications. There's just too much to know. And so you have a generalist approach, uh, taken by technologists, um around cyber security. I'm giving an interface. Here's a product. It sounds all relatively straightforward. Um, an example we might use is Microsoft 365, um, heavily used by most organizations, heavily used by the technology function. I've got admin portals, I'm familiar with those admin portals. I can secure Microsoft 365 90% of the security parameters necessary uh to adequately secure and Deploy um, Microsoft 365A PowerShell only. Uh, and so that in itself we have subject matter experts that know the ins and outs of each one of those parameters and how that's used and how that might be used to gain an initial foothold, uh, into a cloud, essentially someone else's cloud system, uh, that holds a lot of sensitive data. Um, MFA bypass is uh, one of the common ones M that we've seen doing the rounds a few years ago. And it's because uh, the technology function was deploying those systems but they didn't have the adequate depth of knowledge to secure those systems other than what made sense within a portal thereby to be a little bit unfair. Uh, and so you've got that conflict of interest that ah, differing remit in terms of what that function is trying to achieve as well as the uh, the depth of knowledge required to do it. Well, uh, you know we can't do any of those migrations, uh any of that functionality. There are some slick systems we've seen uh, implemented within our customers by the technology uh partner, um, super impressive. That's their space. Cyber security is our space. And so what we see with uh, the astute leaders, um, and what I'm doing not, not the hands on um, I'm playing with tools and deploying systems um, and really, really in the, in the weeds. But those leading a technology function, leaders within more broader leaders within an organization, the astute ones know, they know we need to separate those functions and they will, in the mid market they will choose a uh, technology partner and a cyber security partner and those, those three organizations for a common outcome. Uh, and that is to deliver uh, world class systems functionality to support business objectives and to do that uh, reliably, securely. Uh, and uh, there's definitely some leaders who have a very good view on um, separating those functions. And a lot of them come from enterprise, a lot of them come from a finance background. That's normal where you separate uh, who puts the accounts together from the auditors. Uh and that's slowly starting to be adopted by those who have a bit more business now. Um, even though it's convenient for an all in one, um, it's convenient to have one organization deliver all of those things. They just recognize that um, it's a short term convenience. Um, and those with, with business now separate those two functions.

Speaker A: Yeah, that's great Sash. And you like towards the end there you're leading to one of the other areas we wanted to um, uh talk about which is that um, that alignment of cyber security to business objectives. Because you know, quite commonly, I mean even just towards the end they use the word convenience like it's It's a case of um, you know, cyber security can be, you know, easily viewed as an obstacle or a burden for companies. But um, I know like yourself and a lot of others out there in this space have this passion for. No, like it's, it's about aligning it to um, you know, the vision of the company and what the, what the strategy and direction, um, should be. So could you talk a bit about that around how, how um, how you are able to um, effectively align the cyber security strategy to whatever the business objectives are as a whole?

Speaker B: I think it's, it's common that the cyber security function says no, no, you can't do that. Here is a control that stops you from doing something and uh, there is a, ah, it develops over time somewhat, ah, my epic view of, of things. But an organization, most organizations um, are not, do not exist because of cyber security. Ours does, but most don't. We have, we have clients that um, are in the legal space. We have clients that are in the dairy space. They milk cows and create products that consumers love. Um, they're not in the, in the, a business of cyber security. And so um, the cybersecurity industry, many professionals need to be reminded of, of that fact. Um, and so rather than saying no, you can't do that, that's that, you know, you're cutting the nose to spike the face there. You're undermining your organization's ability to perform by saying no. And so, um, cyber security practitioners, whether it's external or internal, really need to take the view, uh, of uh, yes, if you want to move something to the cloud, you want to use byod, you want customers, partners, contractors, whatever that may be, accessing certain systems or data sets. Yes, if, um, there are risks and those risks can't be ignored, ah, they need to be mitigated. But uh, that's the truth challenge um, is to support business objectives by being as transparent as possible. The way that, that we operate is if we can allow a new initiative like the assistant way of working, whatever that may be, if that can occur and the users don't know that there's a cyber ah, security overlay on that. We've, we've done our job. Uh, we've been seamless. Now that's not always the case. Sometimes there is an impact on something, um, user experience perhaps, uh, sometimes, but um, as seamless as possible. So yes, if is important, um, it also comes down to leadership. Uh, and here is what we're trying to do as an organization. Here's what we're trying to, where we're trying to get um, it's the standard CEO remit of uh, here's the vision. He's what we're going to do, how we're going to do it, we're going to end up at this place and the cyber security function needs to know about that and be creative, professionally creative in how can we support that uh otherwise we're hindering the success of the organization that uh for the most part doesn't exist for cyber security, exists for something else. Its core purpose, focus on that core purpose. Not, not saying no because of some um, something you read on the Internet about an advanced persistent threat by nation state actors. That sounds cool in a, in a cyber security blog, but does it, does it really impact your organization? Are you going to uh, impact the success uh of your organization because of something that's borderline applicable to that ah, organization? I don't think so.

Speaker A: Yeah. And is it a case of um, having that ability to really effectively communicate that to the business leaders like in a language that is applicable to them and if so I guess how do you um, uh how do you put it to businesses and business leaders in a way that is linked to ROI or linking it to a particular initiative that they're looking to implement?

Speaker B: ROI is a good one. Uh we see uh, some fairly sometimes uh simple views from uh certain industries, financial services, they need to plot out an investment uh that do a uh net present value and see what the ROI is, uh what the return on equity is, um, you know factor in many quantitative financial uh factors and that's difficult uh initially to do with cyber security. Um but really competitive advantage is one that shouldn't be discounted. Um a lot of the clients we work with, some SaaS, global SaaS providers use cybersecurity uh to open up markets or to establish themselves uh with a market differentiation. Um in some cases consumers of these products want their job to be their procurement exercise to be made simply. Uh, and so simple examples are uh, if you have certain compliance framework certifications in place, um, Australian government is a great example of this where they will choose systems products that have gone through the IRAP compliance process um, uh, over systems that haven't because the due diligence, the uh risk assessment process is far more involved. And so providers of systems products, uh, platforms that gone through this compliance framework uh are at a competitive advantage. And so that's a very simple business case of here's an investment uh one off to get us to that point. Here is the Ongoing operational, uh, cost of that framework. And here is the market size that we were able to uh, open up because of that. Here is uh, putting ourselves uh, ahead of some of our competitors. And we've seen that happen in certain industries where there's a couple of really standout products. There's a couple of also rans. Also rans have had ah, very easy to consume, uh, security posture for what is uh, a procurement department. Uh, and so they perhaps don't understand the functional differences. This ticks my boxes from a compliance perspective. So we've seen some suboptimal product selection purely because they tick the cyber security boxes better than products that were far more superior from a functionality perspective. User experience solved my underlying problem better, uh, but they didn't get selected um, the other way, the other side of that in terms of ROI is risk management 101 which is here are some scenarios that might occur. Uh, here is what the impact is on the organization. And uh, essentially what you're doing is uh, evaluating risks for risk against your risk appetite. And that risk appetite, very easy concept. Uh, but there needs to be some quantifiable measures against that risk appetite. That might be types of scenarios, it might be financial impact, it might be time of downtime, it might be certain ah, scenarios uh, that lead to reputational impact. Not all reputational impact is as uh, severe as others. And so really it's then making a business call. It's going to cost this uh, to reduce the risk of a threat from eventuating. Uh here is how often that's going to occur. Here is the impact, uh, do a little bit of maths and you get a really clear ROI on. If I spend 10k here, I'm going to save 100k every three, four, three or four years. Um, you know that math is very, very easy to make. Um, not all risk is, is uh, needs to be mitigated or reduced. Um, we cross the road every day, there's a risk of getting hit by a car. I will cross a quiet one lane road down the road here in the cbd, um, with uh, no more than a left and right look as my risk mitigation, there's no way I'm crossing a, ah, you know, the Harbour Bridge, 10 lanes, 12 lanes, whatever it is, um, in peak hour traffic that is way outside of my risk appetite. And so it's really quantifying what is that impact to the organization. Are we okay with that? Um, you know, if we lose a laptop, okay, it's inconvenient, um, maybe we run a little bit of encryption to protect the data but otherwise we lose a little bit of money, a little bit of downtime for an employee. That's okay. Uh, versus here's a production database with customer data, with health information, medical information for the last 15 years. Uh and in one case our testers were able to uncover that said database connected to the Internet, um, and be able to access that full database of a decade plus of health information. That's not a risk, uh, that um, I would want to hold. Our job is to communicate that risk to the business and in this particular case the business took that system offline line until they could remediate. Um, but there's some very clear uh, paths from here's a technical risk, uh, several steps to here is the business risk. Are you okay or not? And that's a business risk call. And every organization is different.

Speaker A: Yeah, that's excellent. And it sounds like mixed up in all of this. It really comes down to um, uh, the strategic thinking that goes behind all of these decisions and why it is so important to have um, you know, someone with that um, experience and expertise in order to you um, know, weigh in on um, on some of these challenges that a business might be facing and some of the um, some of the initiatives they're looking to implement. So that's. Thanks for sharing, that's really great. But um, I do want to sort of slightly move to a different area Sash, as far as um, you know, moving more globally and I'm um, getting you to weigh in on um, sort of like a recent um, uh issue and that's the um, the CrowdStrike bug. Um, could you sort of just explain a little bit about um, uh that issue and then also the, the broader implications it has around um, you know, businesses who rely on the, on um, uh, cybersecurity services out there.

Speaker B: Sure. The subs. The CrowdStrike issue received a lot of media attention. It was widespread. Uh, but at the end of the day it was less of a cyber security issue and more of technology in general. Um, I won't go into the nuts and bolts but uh, there's all sorts of systems and processes, checkboxes that go into trying to uh, avoid these sorts of things. Um, and sometimes ah, a technical issue within a complex system uh affects that system. Um, and that's technology in general. Um, airplanes fall out of the sky because of technical issues and we try and learn from them and avoid them. Um, there's systems um, that uh, products uh, in the past from endpoint vendors that have done the same if not more significant in terms of recoverability. So there will be technology failures. Um and so in this case yes there was a focus on cyber security. I think the media like, like often happens, um, likes to jump on things. Many um, commentators uh, like to jump on very very quickly and I'm glad a lot of those um, who were jumping uh, on the bandwagon, quick to speak um, really had a negative experience from that where they're trying to get exposure, they're trying to get whatever likes or shares or whatever that may be that sort of fuels their agenda and it ended up poorly for them. Um, so it was a little bit of karma there but it identifies uh, the reliance on key pieces of technology and uh, risk management in general. You uh, should always be aware of the risks and anyone who uses uh an operating system, an endpoint product, a piece of hardware knows that there could be some failure uh, in that product. What can I do to minimize uh the likelihood and what can I do to minimize the impact of, of that occurring? Crowdstrike, um, they're in a space where they're making on an almost minute by minute basis compromises, they're compromising, uh, they're dealing with compromise of trying to secure from threat actors, uh, scenarios, actions, things that haven't been seen uh, in the wild yet. New techniques, new scenarios that need to be keeping ahead of the curve. That's a tough race to be running and on the other side of that is availability and reliability and making sure that we don't mess any of our systems up. Uh, and that's a tough one because you're always going to end up in a bad position in the media. You're either brought down supermarket checkout, uh kiosks or you missed uh a uh, cyber security threat that you were purchased and implemented to protect against. And sometimes you don't get that perfect, um, uh, but you get it right more times than not. So there's unpacking some higher level responsibility on users of these systems to really be uh, aware that um, technology has failures. Uh, aws, ah Azure, they have fantastic reliability. They spend more and have teams of experts that know about maintaining reliability at scale far more than any other organization. Most organizations out there, um, that's great. That's where I put my money in. AWS and Amazon and Microsoft, they're having more reliable systems than our team, my um, small MSPs team could ever build. But those systems still have outages and to think that they're perfect ah is naive. You need to understand that those platforms, much like Crowdstrike, uh, Endpoint, uh product, they will have issues and um, that's not unknown. You, nobody could say that I couldn't forecast a technology issue. It happens. You need to have uh, appropriate processes and forward planning to, to understand that these things could happen. And what will I do now? We weren't impacted, uh apart from very, very minor sort of test systems. But when we do our risk analysis we go those test systems will be down until we recover that we're okay with that. Um, if my uh, my, my supermarket kiosks were, were down for several hours. Okay, is that okay? If it's not, what can I do about it before it happens? Are there manual processes? Can we switch over? Do we have some sort of other uh, you know, boot up recovery, uh tech, super tech involved um, that will, that will be different for different organizations. But what it highlights is um, technology will fail. It's not just a cyber security issue. Could be power could uh, be a flood. Uh and diesel generators being uh located in the basement. The basement gets flooded, those diesel generators can't operate. So my data center above ground that I'm perfectly happy with uh, and secure in my knowledge that it's above ground. Well actually it doesn't have power because power uh, is down because of storms and my, and my basement with my power generators is flooded. So thinking about these things ahead of the curve, it's business continuity, it's disaster recovery, it's risk management. Uh at a fundamental level it just happened to be uh, a cybersecurity product. In this case, um, could have easily been an operating system or some, some other product.

Speaker A: Yeah, okay, that's, thanks for sharing because like it sounds like sort of two big lessons out of it. Number one is like just recognizing it that there's always going to be risk. Nothing's perfect but the ability to be able to um, plan ahead, manage and to sort of like use an analogy like if, if we have a road that's closed ah off there's you know there's signs to virtual way and like usually there might be signs prior saying it's going to be closed on this date. So like similar to that, having that ability to make people aware and have that communication piece and then also like related to what we're talking about earlier having those checks and balances and um, you know on the smaller scale with companies separating their IT and cybersecurity functions at a larger scale it's like making sure that other functions have checks and balances that uh, Are, you know, being checked by third parties and. And whatnot. Right? Yeah. Yeah. Fantastic. Um, unfortunately, we are getting to the end of this, um, conversation, Sash, but I'll sort of want to finish up, um, on a bit more of a personal note for you and just, um, um, just sort of asking, like, what. What motivates you most? Um, um, to, you know, stay in this industry and, you know, keep, uh, problem solving in the cyber security space.

Speaker B: The days are long, the days are hard, the challenges are, uh, uh, ever increasing. But I, uh, think I got into the industry because it was just so interesting. Uh, you have to be one of those people that is continuously learning. You can't sit still. If you sit still, you're going backwards. The environments, the threat actors, the techniques on the good and bad side, uh, are evolving. And that, for me, keeps things interesting, keeps things fresh, keeps you on your toes. Um, so that was really the initial, uh, piece, um, running security centric. Uh, you get exposed to other things. Um, and so there's, uh, when a client calls me up and this happens, uh, a couple of months ago, where they had a contractor in, and we started with and brought in a, uh, CISO as a service, and a month later calls me up, um, I've had a little bit of involvement with him on the early end, uh, calls me up and says, well, Sash, I have to say thank you so much. For the first time I actually see, uh, what, um, I get some visibility into my subsecurity posture, into my program. I know where we are, what's happening. What we need to do was in a month, uh, of having these people that, uh, do this all day, every day, they need to hit the ground, uh, running. They need to understand the lay of the land and they need to make change. And to make change and improve things, they need to communicate clearly to management. Uh, and this was someone who was, in their own words, pulling their hair out last two years, not knowing what's happening. Uh, a real lack of visibility, getting that client feedback and saying, actually, you've moved the dial. You've improved things, uh, for the team as well as myself, uh, that, uh, drives me, motivates me no end, um, progress, uh, essentially. And the third part is the team seeing how they're growing. You have some very, very bright people with, with absolutely ridiculous skill sets, and they're applying that across, you know, not just one environment. It's not that they have one job and they apply their skill set in one environment. They're seeing new environments, they're seeing retail, healthcare, Education, manufacturing, not for profit, defense, across the board and seeing them develop um, their both their technical and non technical skills. Um, there's a little bit of uh, proud parent, um, comparing them today versus when they join the organization. Um, the cybersecurity industry needs technical skills but they need far more non technical skills, um, in terms of change management, understanding, uh, the user base and uh, their day job. Um, and, and there's a lot of highly technical professionals in the industry who really um, we wouldn't hire uh, because they need to develop broader than just the technical skill set. So seeing those skills uh, develop again, um, development, progress, moving that needle really motivates me.

Speaker A: Fantastic. And um, no, I personally look forward to seeing um, um, what the future of Security Centric is like. So um, uh, yeah, but um, Sasha, I really um, appreciate you coming on board today and uh, sharing some of your insights, uh, with us. Um, but before we close off, uh, how can people find out more about yourself and also about um, the work that you guys do at Security Centric?

Speaker B: Look, the usual, um, securitycentric.com you can find me there or, or LinkedIn. Um, my name isn't particularly uh, common. So uh, you'll see my face there. Send me a message, connect, um, stay up to date with what's happening in terms of effective information security.

Speaker A: Fantastic. And um, once again Sash, thank you for coming on the man in the Middle podcast and we look forward to um, future conversations.

Speaker B: Jeremy, my pleasure. Sat.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Identity and access management87 / 100
  • Security Is a Human Problem, Not a Tool Problem ft Steven Asifo, Director of Security & GRC @ YahooSecurity & GRC Decoded · on Identity and access management85 / 100
  • Ep 116: Ask a CISO with Steve ZalewskiLevelUp Cyber · on Identity and access management79 / 100
  • Harish Peri (Okta): When the Thing Accessing Your Systems Has a BrainThe Road to Accountable AI · on Identity and access management77 / 100
  • 2024 Trends & Predictions Series: RansomwareWait Just an InfoSec · on MFA bypass73 / 100
  • Considering Security, Compliance and Revenue with David GrazerSecure Talk Podcast · on Identity and access management63 / 100

More from Man In The Middle Podcast

All episodes →
  • S02E04 - Inside the Mind of a Top Bug Hunter: Shahmeer Amir on Security & Innovation
  • S02E03 - Inside the Dark World of Doxing: Cybercrime Meets Real-World Threats w/Jacob Larsen
  • S02E02 - Cyber War & Disinformation: The New Frontlines of National Security w/Meg Tapia
  • S02E01 - Strategic Security: How to get the Most Value from Your Cyber Investment w/Nikki Peever
  • S01E13 - Cyber Herd Immunity: Collective Defence in the Digital Age w/Yuval Hertzog & Michael Loewy
Explore the best B2B Ops podcasts →
All Man In The Middle Podcast episodes →