The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/StateScoop Radio
StateScoop Radio artwork

NJ CISO Michael Geraghty at Google Cloud Next '24

StateScoop Radio · 2024-04-16 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

52 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality9 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft10 / 20

Michael Geraghty brings a comprehensive view of state-level cybersecurity from the frontlines of election season and evolving threats. New Jersey has maintained an Election Security Coordination Task Force since 2016, recently conducting statewide tabletop exercises across all 21 counties to stress-test incident response capabilities. On generative AI, Geraghty emphasizes a "trust but verify" stance - the technology offers promise as a force multiplier for security analysts handling increasingly burdensome threat activity, but hallucinations and bias remain concerns until proven reliability. The more structural challenge Geraghty addresses is ransomware vulnerability across municipalities and school districts. As a home-rule state, New Jersey offers decentralized governance but no distributed cybersecurity capacity; many local IT roles are part-time, held by teachers or administrators doubling other duties. His solution is a whole-of-state shared services model providing tools, technologies, and services collectively. Geraghty also reframes the "cyber talent shortage" narrative, arguing the real gap is CISOs' ability to spot and develop talent rather than an absolute scarcity - New Jersey invests in high school and college internship programs. Key partnerships with CISA, FEMA, DHS, and private sector actors amplify capabilities across levels.

Key takeaways

  • →New Jersey conducts regular statewide tabletop exercises with all 21 counties and maintains a persistent Election Security Coordination Task Force that meets almost quarterly, not just during election years, to stress-test response to election infrastructure threats.
  • →Generative AI is being evaluated as a force multiplier for security analysts - enabling natural language queries of large datasets and automation - but only under a "trust but verify" framework until hallucinations and bias issues are resolved.
  • →A whole-of-state shared services approach addresses ransomware vulnerability in underfunded municipalities and school districts by collectively providing tools, technologies, and 24/7 security focus that individual towns cannot afford independently.
  • →The perceived cyber talent shortage is less about availability and more about CISO investment in talent development; New Jersey runs high school internship, college internship, and externship programs to build the workforce internally.
  • →Implicit trust models emerging with generative AI adoption pose a risk if implementations prioritize speed over testing; Geraghty warns that first movers should also be first to implement correctly, not hastily.

Guests

Michael Geraghty

Topics in this episode

Zero Trust NetworksElection Security Coordination Task ForceGenerative AI for security analyticsWhole-of-state shared services modelRansomware defense for municipalities and school districtsImplicit trust modelsElection infrastructure tabletop exercisesCollective defense partnershipsCritical infrastructure (water, energy, grid)

Questions this episode answers

How is New Jersey preparing to defend against election security threats in 2024, including both cyber attacks and AI-driven disinformation?

New Jersey maintains an Election Security Coordination Task force established since 2016 involving state, county, federal, and private sector partners. The state conducts statewide tabletop exercises with all 21 counties, covers both cyber and physical security threats, and addresses misinformation and disinformation through its Office of Homeland Security and Preparedness. Election security functions fall under the CISO's purview within the New Jersey Cybersecurity and Communications Integration Center.

What is New Jersey's approach to using generative AI for cybersecurity?

New Jersey adopts a "trust but verify" stance on generative AI, viewing it as a force multiplier for analysts through natural language queries of large datasets and automation to prevent analyst burnout. However, the state is not implementing it until concerns about hallucinations, bias, and reliability are adequately addressed through testing.

How does New Jersey address ransomware threats to municipalities and school districts that lack dedicated cybersecurity staff?

New Jersey employs a whole-of-state approach providing shared services, tools, and technologies to municipalities and school districts that cannot individually fund cybersecurity functions. This collective defense model recognizes that many local IT responsibilities are part-time roles held by educators or administrators without 24/7 cybersecurity focus.

Does New Jersey have a cyber talent shortage?

Michael Geraghty argues the issue is not talent scarcity but rather CISOs' willingness to invest in developing talent. New Jersey operates high school internship programs, college internship programs, and externship programs within the NJCKIC to build cybersecurity capacity internally.

What are the main cybersecurity trends Geraghty expects to shape 2024 and beyond?

Election security, critical infrastructure protection (water, energy, grid), and generative AI implementation are top priorities. Geraghty warns that implicit trust models in generative AI adoption create risk if organizations prioritize implementation speed over rigorous testing.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode touches on several relevant topics (election security, AI, ransomware, talent development) but mostly stays at a thematic, high-level view without drilling into novel specifics. The 'whole of state' approach and the partnership metaphor are conceptually sound but not deeply unpacked. Most claims are predictable for a CISO discussing 2024 priorities.

We're not there yet with generative AI. And whether it be bias, whether it be hallucinations or those types of things
this whole estate approach is doing is we're collectively working with them and providing them tools, technologies and services to help them

Originality

9 / 20

The guest reframes the 'talent shortage' as a leadership/investment problem rather than a supply problem - a useful reframing - but most other talking points (election security task forces since 2016, zero trust pivoting to AI trust, shared services for municipalities) are standard CISO playbook. The Mike Krzyzewski fist metaphor for partnerships is borrowed wisdom, not original thinking.

I disagree with the lack of cyber talent. There's a lot lack of people at the CISO level that know how to spot the talent and develop the talent
with generative AI, it's implicit trust. And I'm afraid that rather than being the first to implement it, what we really need to do is the first to implement it correctly

Guest Caliber

13 / 20

Mike Geraghty is a genuine state-level CISO with clear operational responsibility (election security task force, whole-of-state initiatives, workforce development programs), making him a legitimate practitioner rather than a thought leader. However, the conversation doesn't probe into his deepest operational challenges or decisions, limiting the full value of his seniority.

Mike Garrity, the State of New Jersey's Chief Information Security Officer and the Director of the New Jersey Cybersecurity and Communications Integration ce
In New Jersey, we have high school internship programs in the njk, college internship program, externship programs

Specificity & Evidence

9 / 20

The episode names New Jersey initiatives (task force since 2016, statewide tabletop with 21 counties, internship programs) and mentions structural facts (home rule states, school district resource constraints) but avoids metrics, timelines, threat data, or named incidents. Claims about AI bias and hallucinations are unsubstantiated by example or data.

Last month we had a statewide tabletop exercise with all of the 21 counties
New Jersey is what we call a home rule state where each town has their own police department, each town has their own school system

Conversational Craft

10 / 20

The host asks reasonable setup questions and covers multiple domains (election security, AI, ransomware, talent, partnerships) but rarely pushes back, asks for concrete examples, or challenges soft claims. Questions are open-ended and informational rather than probing. The Krzyzewski tangent goes unquestioned despite being a digression.

So how are you thinking about all of that?
Um, how are you thinking about, um, ensuring that you have the workforce you need for that cyber mission?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C60%
  • Speaker B33%
  • Speaker A7%
  • Speaker D0%

Most-used words

jersey14state12election11security10cybersecurity9generative9level9talent7cyber6elections6school6thanks5mike5government5sure5sector5

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Coming to you from Google Cloud Next 2024 in Las Vegas, Nevada. I'm Billy Mitchell. Thanks so much for tuning in. Today we have a special podcast recorded from the Mandalay Bay Resort and Casino on the Vegas strip, home of next 2024, with more than 30,000 attendees. For this podcast, recorded from the sidelines of the next conference, I sat down with Mike Garrity, the State of New Jersey's Chief Information Security Officer and the Director of the New Jersey Cybersecurity and Communications Integration ce. During our conversation, we touched on everything from election security and generative AI to intra government partnership and the cybersecurity workforce. This is one of many interviews captured at GoogleNext, so make sure to tune into the others released throughout this week. Now, without further ado, here's my interview with Mike Garrity.

Speaker B: Mike, thanks so much for joining me. It's great to meet you and chat with you at Google Next 2024 in Las Vegas.

Speaker C: Thanks for having me. I'm excited to be here.

Speaker B: So let's start with, you know, it's election year. It's one of the biggest election years globally ever. And it's obviously a big state challenge. It's something that the states have to do a lot and focus a lot of effort on. So, um, as we go into the election year, I'm sure it's something that's been underway for quite a while now. But in the heat of it, post primaries and gearing up for November, how are you prepared to defend New Jersey's election security infrastructure in your state? Both from direct cyber threats, but also, you know, there's all this, you know, new level of, uh, other malicious influencing with AI and things like that that are going on. So how are you thinking about all of that?

Speaker C: Yeah, great question. And so I'm going to go back to the 2016 presidential election. And that's when, you know, there was first reports of Russian interference in the elections. And what we did is we created an election Security Coordination Task force with the state, the counties, federal government and private sector partners to actually secure the elections infrastructure in New Jersey. Um, and we all have a role to play. And it wasn't just on the cyber side, it's also on the physical side. So all the voting locations and the polling locations and those types of things. But also what happened in 2016 was the start of that misinformation and disinformation. So, um, in New Jersey, cybersecurity is organized under our Office of Homeland Security and Preparedness. And so we think of all Threats, all hazards, all the time. And then the election security function is actually under my purview as well within the njkic.

Speaker B: So I'm sure lots of preparation. And is it gonna just heat up more and more as we closer to November, or is a lot of, um, you know, the heart of what you've been dealing with kind of where are you at, I guess, in the scope of this entire election security issue?

Speaker C: So I think we're going to see more focus on the elections as we go forward after the primaries and the conventions and we get closer to November. But everything that we've been doing, we've just been scaling to prepare for it. Um, last month we had a statewide tabletop exercise with all of the 21 counties to make sure they're prepared. We threw every sweet sort of, um, you know, incident at them so that they could practice, you know, in responding to those types of incidents. So, yeah, we're going to see more and more focus. We'll see, you know, more and more acute events around the elections. Um, but I think we're in a pretty good shape. We've had this task force in place since 2016. Uh, we meet regularly, almost quarterly. You know, not just on election years, but, you know, we do elections almost every week in New Jersey. Local school board elections, Fire. They use the same infrastructure. They don't obviously have the same threat level or interest.

Speaker B: Yeah, that makes sense. Um, so at the conference, we've been hearing a lot about generative AI. Obviously, it's one of the biggest topics in the technology space and really the world right now. Um, what are you seeing as the biggest opportunities for New Jersey to bolster its security with AI?

Speaker C: Yeah, so, great question again. Um, and so I'm going to take it from the security perspective and any tool that we use in cybersecurity, we, um, have this mantra of trust but verify. We're not there yet with generative AI. And whether it be bias, whether it be hallucinations or those types of things, but it's early days for the technology. I mean, generative AI, you know, obviously there's lots of development that have gone on with it, but, you know, the release of ChatGPT really focused, um, you know, generative AI in the sense that it was creating content. Okay. So we're looking at it in a lot of ways to help our analysts, natural language queries of big data sets, um, being able to ask questions like that, being able to get answers back, doing a lot of automation around AI so that we don't burn out all the analysts that we have, because there's more and more threat activity going on. Um, and obviously that's taking a toll on the limited personnel and the resources you have. So being able to bolster and use generative AI as a force multiplier is really what we're looking at. But again, we need to have that comfort level that when we ask it a question, it's going to give us the right answer.

Speaker B: Yeah, um, staying on the topic of, you know what, what is really hot, I guess, in the cybersecurity sense, especially at the state and local level. Ransomware is a big, um, you know, threat that um, it seems to permeate the state and local level a lot more than maybe the federal level and some other levels. But, um, you know, how are you preparing and thinking more about, um, as you see more and more states or localities that are fallen victim, what are the lessons learned there and how are you thinking about, um, preparing for that next threat?

Speaker C: And so all those unfortunate victims, okay, that were hit with ransomware, we do study how they were hit and making sure that we're learning lessons from those issues and stuff. But one of the approaches we took in New Jersey is this whole of state approach. Um, we realized that local school districts and municipalities probably don't have the resources to fend off such attacks. Um, and so what this whole estate approach is doing is we're collectively working with them and providing them tools, technologies and services to help them. In a school district, the person responsible for it may be teaching phys Ed, you know, in fifth class, you know, the fifth marking period and yeah, when. And um, and then mowing the lawn later on. So he's not focused. He doesn't have that 247 focus on cybersecurity. That's what we're trying to help is that shared service, if you will. Um, New Jersey is what we call a home rule state where each town has their own police department, each town has their own school system, and they like it that way. But each town doesn't have a cybersecurity function. So this is a great area to provide those shared services.

Speaker B: Yeah, I'm glad you mentioned that because you spoke on a panel earlier and one of the big things you keyed in, um, on was this notion of collective defense. And um, you know, it strikes me as something that um, is more important than ever, uh, particularly that partnership with the feds, the state, the local, you know, any of those different shades or varieties of government, um, and obviously the commercial sector and everybody in between as well. But how are you working with partners? You know, whether it be some of your, your adjoining states or the localities you mentioned, or even the federal level, whether it's a CISA or a FEMA or, you know, the big dhs, how are you working with, um, all those different partners to ensure that those services are shared and that, um, you know, that the supply chain of threats is not kind of, um, putting each one of those layers at risk?

Speaker C: Yeah. And so we've got a strategic plan for cybersecurity in New Jersey. And one of the third strategic objectives is that pervasive partnerships. We know that we can't do it alone at the state level, so we need help from the federal government, from the private sector, from international partners, from locals. They're going to see things that we may not see. We're going to see things they don't see. Being able to share that information, share the threat intelligence and respond together is really what's going to make us stronger. Last night was the end of the, uh, NCAA championships. UConn won, um, but I go back to, um, Mike Krzyzewski, who was the coach at Duke University, and he was the commencement speaker at my son's high school graduation. And, you know, he used to hold up his hand into five fingers, and each one of these fingers is strong, but when you put them all together and make a fist, you're actually, you know, a lot stronger together. And so that, that's the concept and that's the mantra that we have as far as partnerships. We're stronger together.

Speaker B: Um, one of the worst kept secrets, I think, in any space, especially government, is that there's this lack of cyber talent right now. Um, so as the CISO for the state of New Jersey, how are you thinking about, um, ensuring that you have the workforce you need for that cyber mission?

Speaker C: See, I disagree with the lack of cyber talent. There's a lot lack of people at the CISO level that know how to spot the talent and develop the talent. A lot of us want to be lazy and just have, you know, these unicorns come in and be all skilled up and trained up and stuff. Um, we have to invest in developing them, and we've done that. In New Jersey, we have high school internship programs in the njk, college internship program, externship programs. And the way we look at it is that we can train anybody to do cyber, um, and we're better off for it, at least in the state of New Jersey. So, yeah, I think it's more just of recognizing that there's talent out there and being willing to invest in them, rather than there's a lack of talent

Speaker B: and finding creative ways to attract that talent. So as we close out, one of the questions I like to ask everybody I'm talking to or at a conference, sort of forecasting what's next, Google Next. And, um, I'd be curious, from your perspective as the CISO of New Jersey, what are some of the topics, trends, themes, developments that you're most excited about or that you think will shape your space for the rest of 2024 or beyond?

Speaker C: So I think all those things that we've already talked about, election security is a big thing. Um, the critical infrastructure. So we talk about the water sector, the energy sector and the grid and everything. Um, but the other thing that we talked about is this generative AI. And in cybersecurity, just a couple of years ago, the big buzz phrase was zero trust networks and zero trust this and zero trust that. And with generative AI, it's implicit trust. And I'm afraid that rather than being the first to implement it, what we really need to do is the first to implement it correctly. Um, and I think there's going to be a lot of mistakes made by those making decisions to implement generative AI without doing the testing that needs to be done.

Speaker B: All right, well, excited to see regardless where, ah, you land on that, but, um, a lot of exciting, I guess, developments. So thanks, um, so much for your time, Mike.

Speaker C: Thanks for having me.

Speaker D: Sa. Sam.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Cyber and the NY GiantsCloud Security Today · on Zero Trust Networks67 / 100

More from StateScoop Radio

All episodes →
  • 'Friends' helped North Carolina 911's call centers withstand Hurricane Helene69 / 100
  • Centralized identity management: Okta's Christine Halvorsen and Pam Van Meter54 / 100
  • UC Riverside's Matt Gunkel at Next '2461 / 100
  • Covered CA's Karen Johnson at Next '2472 / 100
  • Rich Lavers at Google Cloud Next '24
Explore the best B2B Ops podcasts →
All StateScoop Radio episodes →