
The GC+CISO Connection · 2026-06-02 · 38 min
Key moments - from our scoring
Substance score
35 / 100
Five dimensions, 20 points each
Andy Land, general manager of the CISO Executive Network, and Sean Tuma discuss how legal and security teams can build stronger partnerships to improve organizational cyber resilience. Land brings insights from conversations with 400-500 CISOs across 27 chapters nationwide, revealing that most organizations struggle with untested resilience despite implementing correct controls - a reality exposed by events like CrowdStrike. The conversation centers on practical governance: CISOs should position themselves as business leaders first, not siloed security experts; reporting structures matter less than having supportive leadership with adequate budget; and the CISO-GC relationship remains underdeveloped despite its criticality. Land and Tuma address AI governance complexity (where federal, state, and international regulations coexist), CISO liability concerns (now mostly edge cases under specific regulations like NY DFS and SEC rules), and the mindset shift needed for CISOs to advance to board-level roles - requiring business acumen beyond cybersecurity expertise. The episode serves security leaders, general counsels, and enterprise risk officers seeking to align their functions and navigate evolving regulatory landscapes.
The 20-year-old CISO Executive Network operates 27 chapters across the US with a mission centered on CISOs, facilitating deep technical and strategic discussions through breakfast roundtables. Rather than social events, members engage in peer learning where they benchmark against each other's programs, identify action items (new processes, vendor relationships, or partners to contact), and receive legal updates on emerging regulatory issues.
True resilience is tested and verified, not merely theoretical; many CISOs implement correct controls but remain untested and paranoid about real-world scenarios like CrowdStrike. Effective resilience balances security investment within organizational budgetary constraints, operates under the reasonable person test, and requires collaboration with legal and executive leadership - not security-only decision-making.
CISOs prioritize having a supportive boss over a specific reporting structure; they can report to the CIO, CTO, Chief Risk Officer, or General Counsel successfully if they receive adequate budget and executive backing. What matters most is organizational culture that takes security seriously and leadership that advocates for security needs.
CISO liability remains an edge case under specific regulations like NY DFS and SEC rules rather than a widespread legal exposure; however, CISOs increasingly hedge by obtaining directors and officers insurance and external counsel, reflecting ongoing paranoia about future litigation even as the acute risk has subsided.
CISOs must become well-rounded business leaders who understand accounting, sales operations, marketing systems, and business outcomes - not just cybersecurity. Board members are selected for broad business acumen; companies can hire cybersecurity experts, but boards need leaders who span multiple competencies.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is dominated by mutual promotion, network-building small talk, and well-worn generalities about the CISO needing to 'be a business leader.' A small number of practically useful points surface - negotiating D&O coverage at hire, liability as edge-case not norm, the 'three Gs' AI framework - but these are brief and underdeveloped amid significant filler.
The best CISOs I've seen have legal as their champions at board meetings, at executive meetings. And those folks, they're getting more budget because the legal team's on their side.
Bill and I think you should put resilience. Resiliency, their officer. Because the business cares about risk, but businesses are willing to take risk
Almost every claim recycles well-circulated industry consensus: CISOs need to be business leaders, humility matters, collaboration with GC is important. The CISR renaming idea and the 'three Gs' AI framework are mildly interesting but neither is developed with enough depth or evidence to constitute genuine fresh thinking.
Are you a firefighter? Are you a builder? Are you a maintainer? Are you a transformer?
We need governance around AI... guidance... guardrails
Andy Land has genuine aggregate intelligence from facilitating 400 - 500 CISO conversations across a four-week series, which is a real and unusual vantage point. However, he is a community organizer and former product manager - not a practitioner who has held a CISO role or led a security programme at scale - limiting the depth of first-hand operational insight he can offer.
I get the privilege of doing that in 400. Uh, 400 to 500 in four weeks
I spent most of my career in product management. And I joke. I spent most of my career in the identity and access management industry.
A handful of real references appear - Crowdstrike, the Uber and SolarWinds/Tim Brown CISO liability cases, NY DFS, SEC reporting rules, ChatGPT's timeline - but none are examined with actual numbers, outcomes, or lessons drawn in detail. The episode leans heavily on anecdote ('a member in Houston said') without naming companies, figures, or measurable results.
go back in time a little bit after Uber and then, uh, right after Tim Brown. I can't tell you the amount of members that came to me and said, I don't want to be a CISO anymore
I mentioned it today at the roundtable when crowdstrike hit. I think a lot of our members realized how unresilient they were.
The host's questions are consistently soft, open-ended, and leading ('What does resilience mean to you?', 'What are you hearing from them with AI?'), and there is no moment of genuine pushback or productive disagreement. The episode reads more like two colleagues promoting one another's work than a substantive interview designed to extract insight.
What are you hearing from them with AI?
from the things you're learning from the CISO community. What does that mean to you?
Computed from the transcript - who did the talking, and the words that came up most.
Episode Overview In this episode of The GC+CISO Connection Show, Shawn Tuma sits down with Andy Land to discuss cyber resilience, AI governance, and the evolution of the CISO role in today’s business environment. Their conversation focuses on how the modern CISO must balance technical leadership with communication, business alignment, and stronger partnership with legal teams to help organizations build real resilience. About the Guest Andy Land is the General Manager of the CISO Executive Network (CISO ExecNet) and a recognized leader within the broader CISO community. He works closely with security executives across industries and brings a practical perspective on how the role of the CISO continues to mature as cyber risk, board expectations, and AI governance become more central to business leadership. Key Topics Covered Cyber Resilience as a Business Objective - Shawn and Andy discuss why resilience is the real mission and why organizations need to think beyond technical defense to business continuity and long-term strength.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Since the late 90s, Sean Tooma has been working with legal departments and security teams at the intersection of law and technology. This has given him a unique perspective for how these important defenders work well together and do not work well together, and what a difference that can make with how their organizations manage cyber risk. This led him to write a book called the GC CISO Connection to help start a dialogue and strengthen the partnership between the critically important roles. The next step is to bring together people who understand these roles to share their experiences and continue the dialogue. Because none of us have all the answers. It is through conversations like these that we can all improve how we work together to improve cyber resilience. This is the GCCISO Connection Show.
Speaker B: Hello, and welcome to the GC CISO Connection Show. I'm your host, Shawn Tuma. Joining me today is my good friend Andy Land.
Speaker C: Good to see everybody.
Speaker B: Andy is more in tune with the CISO community than anybody I know. He's the general manager of the CISO Executive Network. And Andy, uh, and I had a wonderful conversation this morning for about three, three and a half hours.
Speaker C: Yeah.
Speaker B: And, uh, and Andy, welcome to the show.
Speaker C: Well, thank you. I love that you said, I'm in tune with better than anyone else.
Speaker B: You really are. I mean, that's your job, you know. Thank you. Go around the country. Yeah. Talking to CISOs and helping them work through the issues they face. And I love that's perfect for what we do here.
Speaker C: No, it's been a, uh, it's not. Honestly, when I think about what I do, it's a privilege because I get to work with the two sides. That kind of why you wrote the book? You know, Sean, it's like we work with, obviously, chief, uh, information security officers from across the country, but part of our model in the CISO Executive Network is we have a legal update. And that's how I. For those that don't know, that's how I met Sean. And Sean does the legal update at all of our roundtables. And, uh, there's a strong connection, obviously, between the legal and the ciso. And I don't think always people make that connection.
Speaker B: No, they don't. And, you know, Andy, uh, and I know we've talked about this a little before, and for those of you who may have heard, uh, the episode with Ian Schneller, it was actually a conversation I had with Ian before one of the morning, uh, meetings of the CISO exec. Net. Ah. That Ian. Ian and I were talking about his relationship with legal, and it was that along with several other conversations I had at that time that led to me writing the book.
Speaker C: And, uh, I love that. I mean, it's one of the great outcomes of what I get to do. Uh, yeah, is one, I get to meet people like you, but I get to connect you with people like with Ian and all the other CSOs in just the Dallas community for you. And also you. Uh, Sean works with us in the Austin community also, which has been great. So he's get to expand the knowledge of our members down there also. But like you said, it's those connections. But learning, uh, what, how they think, which I know spurred you on to like, wow, there's something here we're missing. Something between legal and uh, the CISO that's got to get repaired.
Speaker B: Yeah, yeah, yeah. It's, it's. How do we build that bridge? How do we foster that relationship? But Andy, before we get into the substance, I want you to tell folks what is CISO Exec Net. This is a big year for y'. All. And what is your mission? What is the purpose of what you're doing?
Speaker C: Thanks, Sean. So, yes, uh, uh, Andy land with the CISO executive network been, uh, the network is a 20 year old CISO community. And that's crazy to say because when 20 years ago there weren't a lot of people even called CISO. And that's really an emergence over the last 20 years. Um, but it is a big year for us as we expand. And you asked about our mission and I look at what Bill, ah, Sieglein, our founder and I do, is a very mission based, um, idea which is to get the CISOs together to network in a natural environment where they can really share ideas and learn things like we've talked about today and we'll talk about more. But I guess if you want to use a tagline, Bill and I like to say, say, uh, the CISO is our mission, our purpose. That's why we exist to help that grow and foster that community. And uh, like, uh, Sean said, ah, we've been fortunate enough to build 27 of these chapters across the US and I'm very fortunate that I run the Dallas one and get to know Sean and the crew here. Yeah.
Speaker B: I mean, and, and you know, look, if anybody that knows me, you know, the security people, the security community, that's my community. Um, I love being with security folks. I love all the security events. I love to go to the nice dinners, I love to go to the fun conferences and, and uh, be a part of that. And I'M very thankful for it. But what really, to me makes. Makes what you do different is we don't have as much social. We have a little bit social. We're talking and we're friends and everybody used to know, know each other, but we're deep diving, right? We're getting into stuff that, honestly, as a lawyer, and I've been doing this a while, but I'm still just a lawyer, I come out of there and my head hurts from the depth of the conversations. We're talking about real education, real learning here.
Speaker C: No, I love that. That's our goal. You nailed it. And Sean coined a, uh, term a few years ago that I've stolen. I hope that's okay. And you said, well, you really attract the cerebral ciso, someone who really wants to dive deep. And hey, there's nothing wrong with a steak dinner or drinking a good beer. You're not going to do that. At CISO Executive Network, we are the breakfast people. We'll give you a nice breakfast. But most of the morning we are spent really deep diving into the topics. And really, if we succeed or fail, it's always when we succeed, it's because at the end of any meeting, just what happened to you happens to every one of our CISOs. Here's who I need to go meet. Here's a new process I need to put in place. Here's someone I need to go get in touch with. Here's a new vendor I need to talk to. Two to three action items should come out of every meeting. When. When they don't. I feel like that's a personal failure for me.
Speaker B: I mean, you're sitting there listening to someone from a major corporation or a major financial institution talking about the challenges they're facing and how they're dealing with that in the lessons that they're learning. Those are takeaways that are, uh, real life, that you go back to your organization and you're like, hey, I can. I need to do this. If they're having to do this, I need to do this. You know, agree. Those kind of things. And that's what I really love about it.
Speaker C: Well, even more so, it's somewhat of a benchmarking do, right? It's like, I, uh, am doing that, but he's somehow doing it better. She's doing that and it's working. Why is it not working for me? Right? Or I need to go try that thing that I've never tried before. But since that company, smaller than me, they've kind of figured it out. Now. I'M a larger company, and I can go try it and see if it'll work for me. So there's a lot of learning and experimentation, too, I like to think about. A lot of our members are tinkerers, experimenters. And so when they come to our roundtables, there's the opportunity to figure out what's the next experiment, what's the next thing I tinker on. And also, you're. You're part of. That's important too, because they don't always know the next step, uh, for what they should do legally or, you know, uh, they know, uh, they need to be, you know, working better with their general counsel and inside, uh, counsel. But they don't always know how. I think that's one of the things you always do great at our roundtables is give them a bit of the how on. Here's how I would approach that legal problem.
Speaker B: Here's how to go talk to them.
Speaker C: Right, exactly.
Speaker B: And help them know you're on the team. And that's why I wrote the book
Speaker C: is take a copy singing like I wrote the book.
Speaker B: No, the point is to say, hey, if you don't know them, here's two copies of this book. Take it. Go introduce yourself. Say, hey, this guy gave me this today, some schmuck lawyer, whatever. But at least start talking about it. And if you start that conversation, you might actually like each other. And then you might find you got a lot of things in common. And then you start building a relationship. And when you build that relationship, bam.
Speaker C: Well, you said something interesting there. Take a copy of the book to your GC and ah, if you're one of our CISOs. And the reason I say that is those kind of things are great icebreakers because we do a lot of them at our meetings, at our roundtables. What can we do to get people to really engage with each other and really try to learn together? I think an interesting thing would be almost like, go to your gc, give them the copy of the book. You have your copy, and almost make it a book club.
Speaker B: Yeah. I mean, look, each chapter has talking points, things to collaborate on to get your conversation started. Right. That was the purpose. But, Andy, one thing I want to make sure, uh, because a lot of people may not know this about you because you come across as this great, you know, sales guy. You're just, you know, I knew we would not have to prepare for this because neither one of us are at a loss for words. Right. But you've done a little bit in this space like, well, tell, tell people about your background.
Speaker C: Sure.
Speaker B: You know, you know, you've been in the trenches. Yeah.
Speaker C: Our founder, Bill was, is a CISO. So he formed it from the CISO perspective. I met him about 10 years ago. So I've been doing this for 10 years, which is scary. And to say, think to myself. But I was on the product side as a vendor. Spent most of my career in product management. And I joke. I spent most of my career in the identity and access management industry. I joke. I probably built every bad product that you should. You've thrown away by now. But it learned a lot along the way.
Speaker B: Way.
Speaker C: Um, and yeah, and I progressed in my career and worked in other places. Data security, uh, cloud, uh, security as cloud was coming out. And I'm pretty well rounded in all things security. I joke a lot of times with people. I say I'm a subject matter expert, but put the little E instead of the, you know, higher. Uh, kc. Make it lower. Casey. But I'm pretty well rounded in security. Just having played around with so many of these products. And I used the word tinker earlier. I like to tinker and understand products. I love the industry. I just love understanding the congruent parts. Like when you see in our industry, um, one of the big guys by another guy, I'm trying to break that down. What are they getting out of that? Why did they do that? And I try to help our members understand the value they're going to get. You know what I mean? There's a value of, as you see these Lego parts being put together with.
Speaker B: Someone said this morning that was so brilliant and we're going to rip it off now.
Speaker C: Yeah.
Speaker B: Were the ingredients. Searching for the recipe.
Speaker C: Oh, that was, that was one of the most awesome.
Speaker B: You know, we have the ingredients, we're searching for the recipe.
Speaker C: Yeah, it's true. And I think a lot of our members are searching for the recipe. And that's one of the reasons to come to our roundtables, because you're going to have some people that have some of the right ingredients. They might even have part of the recipe.
Speaker B: Correct.
Speaker C: They might even, uh, bake the good cookie, so to speak. Right. So how did they do it? Same thing I like, like I said, from the legal perspective, they get to learn from you. Like today, you did a great job talking about kind of zero trust and what's happening in AI. Our members cannot keep up with all that. I mean, there's too many things that. Too many moving parts. So every time at, uh, one of our roundtables when they get a legal update from you, they. There's a consistent approach, and they need that. We all need it. It's one of the best things. We all learn from you. You learn from us. That's like you said, it's the whole thing. Focus of your book is you come to our roundtables to learn from our CISOs. Guess what? They're learning from you at every meeting. And that congruency is what, you know, makes a meeting.
Speaker A: Right.
Speaker B: Uh, it's really one of the most fundamental things we in this industry all have to understand, and that is humility.
Speaker C: Oh, absolutely.
Speaker B: That none of us have all the answers. We have to be humble and receptive and willing to learn and actively try and learn. Because our world is changing so fast technologically. Well, strategically, legally, and politically, you know, it's just struggle.
Speaker C: Well, good, good example today, you said if just from the legal perspective, you showed some immense amount of AI regulations that are in some theory or process, but then in the one sense, I know our members have asked, well, didn't the President of the United States sign an executive directive saying, we don't have to worry about all that stuff? And then you said, no, you got to worry about that stuff. So it didn't just make them go away, but that's the kind of stuff that it's. Sometimes I think people are going through, and it's very unclear. It's like, on the one sense, are the states regulating this, or is the feds regulating this? And if they're not regulating, I know Europe's regulating it. You know what I mean? So all of the above.
Speaker B: Check, check D for all of the above.
Speaker C: Right, Exactly.
Speaker B: It really is.
Speaker C: So how do I.
Speaker B: And then the one person that asked, you know, I have all this Venn diagram of all these things. Where do I focus? Focus in the middle first.
Speaker C: Right.
Speaker B: And then let's build out. Yeah.
Speaker C: And I always think you do a good job. And it fits well with our theory of how we built the network. Pragmatism. You said the word humility. I think start with that. If you come to our roundtables, come with an open mind and humility that you don't know everything. And then take a pragmatic mindset of, you know, what can I achieve? Because I think every one of our roundtables is about trying to achieve a better program and also a better ciso. As you know, today we talked about CISO Persona, and that was geared toward trying to how do we make you as a human being, better? Because I think about that at every roundtable, how do I get better as a moderator, as a leader? And I learned from all of you guys how to do that. Yeah. You know.
Speaker B: You know, Andy, what I really love that you said this morning, this is something that I've. I don't want to say the word sold myself, but in a sense, I guess I am, is someone that's handled a lot, seen a lot from that. The strategic perspective. I've seen a lot that most people don't get to see. Right. And I get to bring the value of that. One of the reasons I really wanted to get you to have this conversation with me is you're talking to hundreds CS about issues that they're dealing with, and you're seeing this from a very big picture strategic perspective, um, that I want to talk about because I think you can share insights most people aren't going to have. We talked about resilience today. I know that's such a big buzzword, right. From the things you're learning from the CISO community. What does that mean to you?
Speaker C: Yeah, I mean, a few things. First, I've great transition is we're very. I use the word privilege a lot. I'm very privileged to get in front of sometimes 400 to 500 CISOs in four weeks. Yeah. And I kind of joke there's some major analyst firms that, you know, they. They probably don't talk to 400 CISOs in a year. That's right. And I. I get the privilege of doing that in 400. Uh, 400 to 500 in four weeks. Um, you know, as we go through a series, we see all the nitty gritty of how our members are having to deal with different types of topics. And like you said, resiliency is one that's popped up a lot. I mentioned it today at the roundtable when crowdstrike hit. I think a lot of our members realized how unresilient they were.
Speaker B: Done everything right.
Speaker C: Yeah.
Speaker B: And I'm down.
Speaker C: Yeah, and I'm down. Exactly.
Speaker B: And.
Speaker C: And I think a word that I like that I heard earlier this week and it came up again today, is, um, I'm untested. But they don't mean that they have not done executive tabletops. They don't mean I haven't worked. Worked with my attorneys. They don't mean any of that. They mean I haven't taken a bullet directly. They don't know until they know, I guess is what I'm saying. And that's what I think most of our members are today. They're putting in place all the right controls. A lot of them are working well with their GCs. We talked about this earlier. Too many are not working well with their GCs. But most of our folks are doing all the basics right. And a lot of the key things correctly, but none of them. You heard it today. The key. One of the key words was paranoid. A lot of our members are not sure, and that's a bad feeling. Uh, you know, the old can you sleep at night? You know, theory. I think most of our members sleep at night. Well, only because they know they could pass the reasonable test, which we. You often talk about, Sean, in our roundtables. But they're worried about it. I think resiliency today is as good as you can. You can make it under a budget. Right. Uh, you're never going to spend every dollar the corporation makes. Unsecurity. Well, that's right.
Speaker B: Because our mission of the organization is not security.
Speaker C: Yep. It's to make widgets. It's a. To produce a great service. Whatever you do great for a living, security has got to be in its box, right?
Speaker B: Yeah, yeah, yeah. And I mean, I, uh, had a visit with a GC recently who was, um, frustrated. And part of my role with this GC is to going. Going to be to help bridge the gap with their ciso because their CISO will not collaborate and focus is only on, um. My job is security. Right. My job is security. I don't need to care about anything else. And we're going to have to work together to overcome some of that.
Speaker C: Well, that's good. And that's interesting because I would say today, one of the things we coach our CISO members on our. Yes. Your title is Chief Information Security Officer. You're a leader in the company first and foremost. You are a business leader. Often we try to put ourselves in the box too much. We're an IT leader or we're a security leader. I think the CISOs that are going to survive and do well in the future are business leaders.
Speaker B: Yeah.
Speaker C: And they can span. We've talked about this before. They can be put in front of the board.
Speaker A: Yeah.
Speaker C: And there's a confidence level. And I think the folks that want to get that next layer of job and move up, that's where you need to work on and examine yourself most. Like, are you ready to present yourself at a level that the board wants you there, not tolerates you.
Speaker B: There you are. Instead of your, uh, identity being. I'm, um, the security guy, your identity is. I am a business guy. But I have an expertise in security.
Speaker C: Keyword there, expertise. I agree with you. You are an expert in cyber. In fact, many of our members often, and I know they probably come to you and talk to you about this too, want to be board members at some point. They want to be, and that would be great. And we, I think they should be. But then they'll always think it's because they have cyber experts. It's like, no, that's not what's going to make you a board member. They're going to get you a board member because you also know gap accounting. You also know how their marketing systems work. You know how the, the sales, uh, chain works. You know the business outcomes. You don't just know how to do security. They can hire anyone to be the security expert. A board member needs to be a well rounded, well understood, uh, of their business. Right.
Speaker B: That's such a great point, Andy. And you know, one of, one of the topics we talked about a few years ago, um, that I purposefully wanted to address in the book was this dovetails right into that reporting of the ciso.
Speaker C: Right.
Speaker B: Who does the CISO report to? Right. There's all these different ideas and theories, and I had my own that I wrote about. And then later in talking with one of the members, um, he said, yeah, it didn't work well because of budgetary issues.
Speaker C: We can't do that if they don't it. Right, that's right. Exactly.
Speaker B: What are you seeing as kind of the trends? What works? Well, I know the CISOs probably want a direct line. Right. But is that, what are your thoughts on that?
Speaker C: Yeah, the great question, John, actually, most of our CISO members today would say first and foremost, they just want a good boss. Yeah. Someone who's highly supportive of security. So start with that. That could be the cio, could be the cto, could be the chief Risk Officer, could be the general counsel. We have members today that report to the general counsel. I think they care less about that reporting structure. And more to your point, do I get the support I need? Can I get the budget I need? Is this taken seriously? Is there a culture that takes security seriously? If they don't have that, it doesn't really matter who they report to. They're going to fail. Right.
Speaker B: Yeah. And so we've got the, who do they report to on one side? And then we got that big issue that's been around for several years now of, uh, who's going to get blamed and CISO liability.
Speaker C: Yeah, we talked about it today.
Speaker B: We talked about it. Too. What, what are you hearing from the CISOs? I mean, I gave my impression, right? These are kind of edge cases. Other than a few regulations like NY DFS or sec, new reporting rules, things like that, probably not as much reason to fear.
Speaker C: Right.
Speaker B: As there is I've seen, but I know they feel differently.
Speaker C: Yeah. Well, it's, uh, interesting because I would say it's funny, go back in time a little bit after Uber and then, uh, right after Tim Brown. I can't tell you the amount of members that came to me and said, I don't want to be a CISO anymore, anymore. I've got to get out of this job. I cannot have personal, uh, you know, liability for decisions I make that are on the corporate, you know, behalf trying to do my job well. And it's somehow come back to me. So I think there's been a sense of huge relief that neither one of these things have, like you said, they've become edge cases, not the norm. I think there's always anyone that's a CISO is paranoid by nature. So that's their nature. They're protective.
Speaker B: Right.
Speaker C: So they're, they're all worried about that. What's the next case that could come. But I think you've done a really good job of, uh, at least in this chapter in Dallas, of making sure the members know, hey, this isn't probably the norm. I'd say we've gotten back to more of an even keel. But, uh, maybe the best way to say it is they all ask questions like now they want to be on directors and officers insurance. Should I have my own attorney that's outside the corporate. You know, you've got these questions. So they're all trying to hedge their bets. And that's where I'd say it is a little bit. Right now I'm going to trust the corporation and that I'm not going to get, you know, uh, personally sued, but I'm also ready. I know what to do now. I didn't know what to do or how to think about this a year and a half ago. And I think they're more, they're prepared type of people. That's what they, you know, they make risk management decisions. Right. So they're making a risk management decision about their own career.
Speaker B: That's right. That's right. They're. They're preparing the contingency plan.
Speaker C: Exactly. They are. Most of them, I think that's where they are. A year and a half, two years after those things, they have a contingency plan. They Have a backup plan. They know what they're going to do if. If this happens to them.
Speaker B: Yeah. And I know you explained to them this morning that the time to cover this is when you're negotiating that new job.
Speaker C: Oh, absolutely.
Speaker B: You know, that raise these points, talk about these issues.
Speaker C: You can certainly, within your current job, I've had many a member go back and get, you know, directors and officers or things that they need to make them feel more comfortable in the job. But certainly you have, as a ciso, you have a certain. When you're going to take a new job, they want you, you want them, you have more negotiating power, more leverage. That's the time to discuss a lot of these liability issues. And that is also a time I would definitely make sure you consult someone like Sean, you know, as an outside consultant, if you will, make sure you know what you're getting into.
Speaker A: Yeah.
Speaker B: And, you know, we've had, um. I've had several GCs on the show. Right. Who. Who will talk openly about this and say, yeah, we. We're welcome this conversation when we're in the interview process. But what they may not understand is whether you're going to be covered by DNO insurance pertains to what your corporate structure.
Speaker C: Right.
Speaker B: Because a lot of these companies have been around for 100 years, 70 years, the CISO title didn't exist.
Speaker C: Right.
Speaker B: So having them in the corporate, you know, uh, not, uh, minutes. The corporate, like bylaws and the, uh, the agreement and things, things like that, they're not covered. So you may have to amend it or something like that, or get indemnification or get a separate CISO insurance policy.
Speaker C: Yeah.
Speaker B: You know, and they have those out there. But. But have the conversation. Right.
Speaker C: That's the key.
Speaker B: Communication.
Speaker C: Yeah, it is. I mean, and I think where you're going with there is the new vociso, if there's such a thing, is going to have to be a much better communicator than I think maybe they had to be five years ago, certainly 10 years ago. Because your responsibility to communicate is much different. You probably have board communication responsibilities. You certainly have executive level, uh, communication responsibility. You certainly have general counsel level. And those audiences are all different. And you've got to learn the language of them. Unfortunately, this is the one thing I feel bad for our CISO members. Nobody's learning the language of ciso. Nobody's going to the school to learn the language.
Speaker B: They're not learning to communicate with ciso.
Speaker C: They're not doing that. They're expecting you to learn how to speak to them.
Speaker B: And.
Speaker C: And in some cases, that's okay, because the language of business. If you're a business leader, shouldn't you be how to speak, uh, uh, you know, business. But I do think. I feel bad sometimes that they can't learn how to be a lawyer unless they are a lawyer, but they sometimes have to figure out how to speak to a gc. And again, I think that's the crux of your book, is how to make. Yeah.
Speaker B: How to talk to each other.
Speaker C: I think it's very difficult to tell you, but if you went back to it earlier, all conversation starts with starting.
Speaker B: Yeah.
Speaker C: So take them the book or however you need to do it. Just do it. Make that conversation, make that hallway. You know, take them to lunch. You know, it's all dumb stuff. Sometimes the. Go get a beer. Exactly.
Speaker B: You know, go get breakfast together, have coffee. Because if you start talking, you start working through all these issues, and you don't have the friction many times that we find exists. And, you know, Andy, one of the things that really strikes me is for so many years, people thought of the great CISO as being the great technical expert.
Speaker C: Right.
Speaker B: You know, uh, and we're learning that really, it's more. Can you evolve or mature from being a technical expert to a business leader, a business communicator that still knows how to communicate your technical side. Right. But that goes into the personalities and the Personas and. And, you know, one of the things I love today is you're helping cisos understand themselves better and. And understand how to improve themselves as a professional through this new, uh, new. New game that you and Bill came up with.
Speaker C: Yeah, it was a little bit fun today. Sean was there. We. We. We built a CISO Persona test, uh, purposefully, but it was meant to be a game. We're not scientists. We're. You know, we joked, we're not the, uh, Myers Briggs folks or whatever, but we built a little bit, uh, game, uh, gamification, uh, around CISO Persona. But it was fun. It got the conversation going on. What kind of CISO are you? Are you a firefighter? Are you a builder? Are you a maintainer? Are you a transformer? And we didn't go with what you want to be like. It's. In other words, don't think aspirationally, what are you now? But then it's okay to think about what you want to be. But I think that's the biggest part is as they navigate their careers, what are you. Are you going to do? Do you want to change Maybe you're a firefighter today, and it's just by the nature of the company you're at, but maybe you want to be a transformer, and you got to find that right organization that wants a transformer. You know what I mean? You got to.
Speaker B: But you got to start by, uh, understanding yourself.
Speaker C: I agree 100%.
Speaker B: The starting point for today's conversation is, hey, do you understand yourself? Because, like I mentioned, um, several years back, I did a speech, uh, at Secureworld on own personalities and psychology and cyber security, based upon my own assessment of what I've experienced working with. With these clients. And, you know, you have your own tendencies of what you love and what you thrive on. And a lot of people were builders and, you know, things like that. But if you know your strengths, then you can learn your weaknesses and then focus on improving your weaknesses to be more complete.
Speaker C: Agreed. And I think it goes back to, uh, go use the word you said earlier today. Humility.
Speaker B: Yeah.
Speaker C: To look at yourself, you have to have humility, right? Because you have to really look at yourself and understand who you are, what your flaws are, what your strengths are, and then you can package that into, you know, what you are today, and then you could look at. Do I want to close gaps? Like going back to our conversation earlier about, you know, talking to the board, Maybe you're not equipped to do that today. That doesn't mean you can't be equipped to do that, but you got to really take a fundamental look at yourself and say, what would it take for me to be able to do that? How do I work better with these different constituencies? I know a lot of today, we've been talking about how to work better with legal, but it is really about, how do I just work better with all these different constituencies? Because time and again, I think our members tell Bill and I, our culture is what's holding me back. Yeah, well, you have a big impact on that culture. Certainly, you're not the CEO. They have the number one impact, but you certainly, as a leader, as a ciso, have a big impact in the culture. And so you got to decide how you're going to utilize that and. And where your personality fits and your communication style fits to make a change. Right. And if you find you can't do that at all, then maybe you're just at the wrong place, and that's okay. You know, that's okay to move to
Speaker B: the next place, but maybe you're not approaching it. Right.
Speaker C: Because you don't have.
Speaker B: Understand it totally.
Speaker C: Right.
Speaker B: You know, and you need to. And you know, that whole self improvement thing, I mean, Andy, a lot of people don't know this about me. As a, uh, in law school, before law school and as a young lawyer, I was scared to death to speak in public. Wow.
Speaker C: Like, I never, never, never thought this
Speaker B: fear of public speaking, I would tremble and almost pass out and um, from the fear, fear of it. But when you recognize it and then you make an effort to work on it, you can, you may still suck at it. Y' all be the judge of that. But if you're still listening, then Andy's carrying the load here. Right? But the thing is you can overcome and you may never be, you know, the greatest. Right. But you can be competent to not have that be your downfall. But you know, speaking of, uh, of concerns, boards and, and issues, humility, something that's humbling everybody right now. We're not getting out of here without talking about it. It's artificial intelligence. Oh man, AI is taking the world by uh, storm. And I know the CISOs, they're on the front lines of this. What are you hearing from them with AI?
Speaker C: Ah, well, it's funny, we. When ChatGPT blew up, I guess it's almost three years ago when I would just call it, literally everybody started using it. And the CISO and all security was not caught off guard, but certainly by the speed, it was much quicker because it was different than like open source software. What was. Which was mostly in like the development community. This was like any administrator, any marketing person could go use this tool and you didn't even know they were using it and that. And you uh, know the natural tendency of all CISOs at that point was block it, stop it. You know, Bill and I saw within like a five week period when ChatGPT really blew up, where our CISOs were saying block it, stop, stop it to I got to enable it. The business is most important and, and that's really where we are today. I think most of our members look at AI as I have to figure out how to get the business to be able to use it, get success out of it. Competitive differentiation. But I need some level of guardrails. We called it, I think you saw it in the series today. We called it the three GS. We need governance around AI. I think of that as the rules, if you will. The umbrella. You live in the governance lab.
Speaker B: Like governance is such an intimidating word, but ultimately it just means controlling it.
Speaker C: Right. You know, and then underneath that, the other two GS that we felt like from our Members that were important were guidance. So people are using this stuff, uh, tell them what, how you want them to use it. Give them the things you want them to use. A great member in Houston said a couple of times ago when we talked about AI, uh, we have an app for that. Meaning they have an app that is, you know, either their version of ChatGPT or, you know, Copilot, uh, or whatever that you're supposed to use. Use ours. Don't go use somebody else's. And the third one's guardrails. Because, let's face it, people may not know the rules. Even if they know the rules, they don't always follow the rules. You have to have guardrails. What can you do? I think of it like I said today, as when you go bowling, the little kids, they put up the guard. You know that.
Speaker B: I love that.
Speaker C: So we keep the, you know, the ball going still toward the, uh, pens, because that's what. Ultimately, we're not going to stop this stuff. The business is getting too much value out of it, and they want to get value out of.
Speaker B: Sure.
Speaker C: And. And we also don't want the business to stop experimenting because, you know, every great corporation, most things they fall into, you know what I mean? They didn't design that. They were like, we tried something and, oh, my God, that works. Let's do it. And I think that's what's happening with AI today. A lot of people are tinkering, experimenting. And so I think that's, uh, you know, our members want to enable. That's what I've seen. But they are. Their job is to make sure it doesn't go bad.
Speaker B: Man, I love your analogy of the guardrails for the little, little kids at the bowling alley. Right. Because I.
Speaker C: Well, you got a lot of kids. You got a lot of kids.
Speaker B: First off, I've been through this, and if you don't have the guardrails, uh, up, they're. They're paranoid. They're scared when they throw the ball and it's going to hit the gutter every time.
Speaker C: Yep.
Speaker B: But if they know the guardrails are there, they have this sense of security that, hey, I can try it. And it. And I don't have to worry as much. I love that.
Speaker C: Well, that's also. I didn't. It's funny, you caught into that faster than I did. I was thinking about more from protecting them from themselves. But you also went into a psychology there of our users. If you give them that sense of security and safety, they're more willing to utilize something, but they're going to utilize it more appropriately. And that's what. That's the word. I would say our CISOs want today appropriate use of AI.
Speaker B: Yeah.
Speaker C: It's the inappropriate use of AI that scares them and also is going to
Speaker B: typically cause our security risks because ultimately they're responsible for what happens within their environment.
Speaker C: Doesn't matter if it was supposed to be or not supposed to be. If it happens, it's on their watch. I'm an ex. You know, I'm an ex Navy officer, so I always kind of think about. It was on my watch. It's my. It's my problem. Right.
Speaker B: Yeah.
Speaker C: I'm accountable.
Speaker B: So all of this has fallen into their laps.
Speaker C: Yeah.
Speaker B: And, um. And. And, you know, um. Are you hearing anything out of them on. Are they looking for other roles? Are they looking for their roles to change with AI? Uh, are they looking for a chief AI officer? What do they. What would make their lives easier?
Speaker C: It's a good question. First off, on the roll thing is kind of funny, a little sidestep, because we talked about resiliency today. Bill and I are really on to this thing. We think your role is really the CIS row. Uh, Chief Information Security and resiliency. I know you want to put risk there, but Bill and I think you should put resilience. Resiliency, their officer. Because the business cares about risk, but businesses are willing to take risk, as you know, Sean. But resiliency, the business has to operate.
Speaker B: Yeah.
Speaker C: They have to be resilient. So we. We thought that's a name that you should go for as far as AI. Uh, yeah. I'd see a lot of corporations right now are hiring a chief, uh, AI officer, or it falls under the Chief Data Officer. Another communication line. Because now our CISOs, besides having to talk to the GC and the CIO and other folks, they do have to deal with the folks that own AI or own the data that's flowing into AI because it's, as you know, it's all about the data.
Speaker B: It's all about.
Speaker C: That's. That's where it fits. What did you used to say?
Speaker B: You have data is the hot potato.
Speaker C: There you go. Where's your. Where's your cup? We need your.
Speaker B: Data is the hot potato.
Speaker C: We need Sean's mug. I've seen his mug, by the way. It's. It's awesome.
Speaker B: Yeah. No, that's so great, Andy. And, man, you know, it kills me that I, uh, look at the timer and we're, uh, running. Running at the end Here. No worries. But, um, we could talk about this all day, which is why we talk about almost four hours. And, uh, and. And it was a conversation really a lot like this, but with a lot smarter people in the room than us.
Speaker C: It was nice having everybody there.
Speaker B: Wasn't you?
Speaker C: Yeah.
Speaker B: Um, but, Andy, as we come to a close, you know, thinking about the CISOs that haven't. That aren't taking the effort maybe or don't know to come get. Get the benefit of these conversations, what would be maybe one piece of advice you could give them? Just how to improve themselves within their organization and how to maybe better work with their legal team, their cfo, their other executives. And then for the other executives, like the legal team or the CFO or whomever, what would be a piece of. Of advice you could give them?
Speaker C: Right. Yeah. From the CISO side, I think, uh, one. I mean, that word humility that we said, we started to be humble. Be okay with not knowing everything. Be okay with being open, which means open conversations with your general counsel, with other members of the management team. I mean, sometimes the truth does hurt you. It is true. We know where people have gotten burned, but most of the time, it doesn't. Most of the time, doing the right thing is the right thing. So if. If you keep doing the right thing, I think you're gonna. You're gonna make progress. I think one of the ways you can maybe broach some of that is do get involved in the community. Whether it's our network or not, it doesn't matter. There's plenty of great things out there. Get involved in something where you can hear from your peers how they're doing this, because that's gonna give you some coaching of how to make those first steps. If you're not ready to jump fully in the pool, but you know how you dip your toe in the water. Dip your toe in the water. But if you're not ready for that, find somebody that can tell you how to do that.
Speaker A: That.
Speaker C: And then do it. From the legal side. Um, it's interesting. I always think, uh, the attorneys I hope will be open to the conversations, and I think that's where I'm hoping that you're coaching that side of the fence, because I think our members are seeking that advice. They want that advice. They want to work together. I think sometimes their frustration is they don't know how to talk to the law lawyer. And I'm sure the lawyers on the other side are sometimes like, I don't understand the word they're saying.
Speaker B: Right. We Each have our own language, right?
Speaker C: And so I think that's also the side of it. Both sides probably have to meet a little bit. But I would say on our side, the CISO side, I think you're gonna have to go more than 50%. You don't maybe have to go 100% there, but you're gonna have to go 75% of the way there to get the legal team to really understand what's going on here so that they can help you. But if you think of it from. They can help you. The best CISOs I've seen have legal as their champions at board meetings, at executive meetings. And those folks, they're getting more budget because the legal team's on their side. When a bad risk comes up, the legal team saying, we can't take on that risk. It's not them saying, no, because all of you guys, all of our CISO members, are always getting, you know, I don't want to be Mr. No, no. And I said, well, there's good ways to stop that. And one is you got to work with your gc. You got to work with your outside counsel. They can help you. They can help you, uh, convey risk, because that's what they do for a living, right?
Speaker B: Absolutely. That is risk and resilience, you know, is what we're all coming back to at the end of the day, because our real mission is making the business.
Speaker C: That's it. Making the business better.
Speaker B: Right? Yeah, Absolutely. Well, Andy, thank you.
Speaker C: So thank you, my friend.
Speaker B: Be here today. This was a lot of fun.
Speaker C: Was great.
Speaker B: Thank you for tuning in to this episode. I hope you enjoyed it. And, uh, if you enjoyed it, please be sure to share it with others. Tell people about the wonderful opportunities in the community. Community. To get involved, uh, such as with Andy and the CISO Executive Network. And, um, just really thank you for your time listening, and hope you have a great day and catch you next time. Bye.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.