The Human Side of Cybersecurity · 2026-05-04 · 39 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
This episode traces Dawn Cappelli's remarkable career arc from software engineering at Westinghouse through her groundbreaking work on insider threat at Carnegie Mellon's CERT, where she pioneered empirical research that transformed insider threat management from considered impossible to scientifically preventable. After 12 years establishing the CERT Insider Threat Center and co-authoring industry standards with the National Insider Threat Center, Cappelli moved to Rockwell Automation as CISO, where she built the company's first insider risk program and later established OT CERT - a free resource portal now serving 3,200 members across 73 countries with 75 resources focused on operational technology security basics. She emphasizes that despite AI hype, most organizations haven't mastered foundational controls: the SANS Five Critical Controls for ICS (incident response plans, network segmentation, remote access security, logging, and vulnerability management). Cappelli advocates strongly against unleashing AI to autonomously defend OT networks, instead favoring AI as a decision-support tool. Her leadership philosophy centers on hiring for passion and deliberately managing workaholic tendencies to prevent team burnout - using tactics like drafting rather than sending work emails outside business hours.
The five critical controls are: ICS Incident Response, Defensible Architecture, ICS Network Visibility and Monitoring, Secure Remote Access, and Risk-Based Vulnerability Management - foundational controls that address most attacks coming through remote access, unpatched firewalls, and network segmentation failures.
She argues that unleashing AI to take independent protective actions on OT networks is dangerous because the consequences of mistakes are physical (power outages, industrial incidents) rather than information-only, making human-in-the-loop AI assistance the safer approach.
While building a bioterrorism response portal at Carnegie Mellon in the late 1990s, she noticed security was never discussed despite the system's sensitivity, and realized security needed to be built into critical infrastructure - prompting her to pursue a job at CERT.
She presented a one-page job description to the general counsel outlining what the CISO role should look like, expanded it to three pages when asked, and the general counsel told her she had 'talked herself into a job' by demonstrating enthusiasm for the position.
OT CERT is a free resource portal built by Dragos with 75 resources covering operational technology security basics, used by 3,200 members across 73 countries - including over half from organizations with more than $1 billion in revenue, not just small and medium enterprises.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains substantive career insights and some actionable advice, particularly around authenticity in leadership and focusing on basics in OT security. However, much of the content is biographical narrative and soft leadership philosophy rather than dense, novel frameworks. The discussion of insider threat methodology and OT fundamentals (SANs controls, logging, removable media) provides value, but the pacing is slow with considerable throat-clearing and repetitive affirmations.
Be authentic. If ever one. I felt like if I. If one time I was not authentic about something or you know what.
The five critical controls from SANs. And what's interesting is in OT cert, um, a few months ago I took a look at what are people accessing in our portal. Um, I can't see who accesses what, but I can see how many downloads of our data versus. And the top 10 is basic cyber hygiene stuff.
The guest recycles familiar CISO wisdom: focus on basics, communicate business value, hire for passion, manage burnout through boundaries. The emphasis on authenticity is genuine but not novel. The insider threat research from CERT (2001-2013) is genuinely foundational work, but discussing it retrospectively lacks fresh perspective. AI commentary is predictable (don't use AI before basics), and the OT/IT segmentation issue is well-established industry knowledge.
Just don't worry about AI until you get the basics down. The five critical controls from SANs.
Number one thing I would look for was passion. If they could answer all the questions right, and they had the technical ability, but they had no passion. Like, why do you want this job?
Dawn Cappelli is highly credible: she founded the CERT Insider Threat Center, built insider risk programs at Rockwell Automation as a CISO, and now leads OT CERT at Dragos. She has executed at enterprise scale (Rockwell creates ICS) and in government (Secret Service, FBI collaboration). Her background is operational - not a consultant or thought leader - with concrete wins (catching Chinese embedded firmware engineer, establishing national standards). This is a legitimate practitioner.
I started my career programming nuclear power plants at Westinghouse. From there, I went to Carnegie Mellon University, still as a software engineer.
So I became the founder and the director of the CERT Insider Threat Center. We went on to do a lot more work in insider threat with the government.
The episode lacks concrete metrics, dollar figures, and specific attack examples. While the guest mentions 3200 OT CERT members in 73 countries and 75 resources, most claims are vague. The insider threat CERT study is referenced but not detailed. Rockwell's specific vulnerabilities, threat models, and metrics are absent. The bioterrorism portal project is mentioned but not analyzed. The AI and OT hype discussion contains no case studies or real incident data.
We have 3200 members, and it's just a dream job.
We Caught a lot of insider threats, including a. Ah. Ah, senior embedded firmware engineer from China who stole all of our source code. But we caught him so fast that he wasn't able to do anything with it.
The host asks competent but often softball questions with minimal follow-up depth. Questions like 'what made you realize cyber was where you wanted to be?' invite narrative rather than challenging claims. The host affirms frequently ('Amen,' 'That's great') without probing contradictions or specifics. When the guest makes claims (e.g., 'people aren't doing the basics'), the host doesn't ask for evidence or counterexamples. There are no sharp disagreements or pushback on AI hype, risk frameworks, or OT strategy. The conversation feels friendly but lacks intellectual tension.
Uh, that is truly amazing. And isn't that what set the foundation for the whole, you know, the SEI inserts like Insider Threat Management Program?
Um, so Don, I'm going to ask you a question. You know, you've managed teams, and you've had teams, you've hired teams. Great teams. And how would you make sure, you know, if you're hiring folks that are like you, they're in it because they're passionate, they believe in the mission of what, what you're doing.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of the series from Cyber Intelligence Weekly, Echelon Risk + Cyber CEO Dan Desko sits down with Dawn Cappelli, former CISO at Rockwell Automation and current Head of OT CERT at Dragos. Dawn shares her remarkable journey from programming nuclear power plants to helping pioneer the insider threat discipline at Carnegie Mellon’s CERT program. Along the way, she helped develop some of the first data-driven insider threat models used by government and industry today. The conversation explores leadership lessons from decades in cybersecurity, including the importance of authenticity, building trust with executives and boards, and why cyber fundamentals still matter more than hype. Dawn also shares insights on OT security, AI risks, and the leadership qualities future CISOs need to succeed in an increasingly complex threat landscape. If you enjoyed this episode, please leave review, it helps more people find the show! Want first access to future interviews?
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign,
Speaker B: I believe we are live. Um, Don Capelli, so great, uh, to have you here on this, uh, this new feature that I've been doing for my Cyber Intelligence Weekly newsletter. Um, as you've probably seen, I've been talking to some great, uh, leading industry professionals and CISOs and former CISOs, uh, about their journey and their leadership styles and things they've learned along the way. Um, and I was super excited to hear that, uh, you'd be willing to be part of this. So thank you so much for joining us here today. And do you mind starting off by introducing yourself and, uh, giving our listeners a little bit of background about you?
Speaker A: Sure. Um, so I'm Dawn Capelli, and I currently am working at dragos, which is an industrial cybersecurity company. Um, but I started my career programming nuclear power plants at Westinghouse. From there, I went to Carnegie Mellon University, still as a software engineer. And then I became interested in cybersecurity and cert, the very first cybersecurity organization in the world, was right there at Carnegie Mellon. So I thought, I think I'll try to get a job there. Bought a job there. And, um, my first job was working with the Secret Service on how to protect, uh, national special security events from cyber incidents. And so we can get into that more. But it totally changed my life. Um, it unwoke a passion in me for security. And so that m. Guy of my career, um, ended up working on insider threats. So, um. Boy, this is going to end up being a long story, Dan. Do you want me to just get into it?
Speaker B: Yeah, let's go. I'm ready for it. I got my water. I'm going to take a swig.
Speaker A: Okay. So I started at Cert in 2001, August 1, 2001. And I knew nothing about cybersecurity, so I thought, uh, yeah, they told me, you're going to be project manager for this new project we just got with the Secret Service. You're going to help protect national special events from cyber events. Because the Secret Service at that point was gates, guards, guns. It was all physical protection. And they realized we probably ought to start thinking about cyber, so that I was the project manager for that. And I just told everybody, I don't know how I got this job. I know nothing about security. And I get to go with the Secret Service to the Olympics because that was our first event. We had to protect Salt Lake City. I know. So I thought, this is the coolest job in the world. I can't believe I'm getting paid for this. And one month later, no 9, 11 happened.
Speaker B: Oh, my God.
Speaker A: Suddenly, that fun, cool job was very serious because the intelligence community really thought the Olympics would be the next target, because they were in February of 2002. So suddenly, that cool, fun job, uh, just terrified me. I know nothing about cybersecurity.
Speaker B: That was Salt Lake City, right? 2002.
Speaker A: Exactly. So, um, we went on our first advance to Salt Lake City and met with the International Olympic Committee. And they said, don't worry, Don. You're the project manager. You don't need to know anything about security. You just, uh, will have lots of technical people to do the work.
Speaker B: Sure.
Speaker A: We're meeting with the Olympic Committee, and they're poring over network diagrams and trying to figure out how could the terrorists hack into the network and bring down the Olympics or cause harm. M. And someone just happened to say, so if you had any, like, systems administrators or network administrators that left on bad terms and already know how to get into the network. And they said, let us go get you a list. And they came back with a list of 20 people. And this is the International Olympic Committee. So there are people on there from the Middle east, which is where the terrorists came from. And so suddenly, the Secret Service said, whoa, I think we need to split into two teams. We need an insider threat team and an external threat team. And I thought, okay, I know nothing about security, but I do understand people. And so I said, I'll take the insider threat team. So I took that team, and they said, okay, so what are you going to do? And I'm thinking, heck if I know. But I thought, well, let's try and learn from attacks that have actually happened in the past.
Speaker B: Absolutely.
Speaker A: At that time, insider threat, the basic thought was, there's nothing you can do about it. It's an insider. They have access. They have the ability. If they want to do something bad, they're going to do it. You won't be able to stop them.
Speaker B: Sure.
Speaker A: So, um, I took the insider threat team, and the Secret Service gathered all of their insider threat cases they had. They went to the FBI, got us all of their cases that they had, and we just went through them and looked at each one and said, could this happen? How could we prevent it? How could we detect it? That's how we prepared for the Olympics. It worked. Basically, there were no attacks on the Olympics. Then they said, I think we ought to continue down this path. So we started an insider threat study that we did with the behavioral psychologists from the Secret Service. So it was a very Neat. Um, groundbreaking study. We have psychologists and technologists looking at these insider threat cases and looking at who did it, why, when, how, and what could have been done to prevent or detect it.
Speaker B: Sure.
Speaker A: So we ended up. That's what I did for the next 12 years of my life till 2013. Um, it was very successful because when we. We cataloged all of those cases in a database and then did empirical analysis on it, and we created models based on the data and real. And I have to say, it kind of made the insider threat field what it is today. Because for the first time, we could say, oh, yes, there is something you can do about it, because we know who does it and why and when and how, and we know what to do to stop it. So I ended up at cehrt, um, being the founder and the director of the CERT Insider Threat Center. We went on to do a lot more work in insider threat with the government. A lot of it was with the intelligence community. So I can't talk about that work. And with the private sector. So it was really, really a fun and rewarding 13 years.
Speaker B: Uh, that is truly amazing. And isn't that what set the foundation for the whole, you know, the SEI inserts like Insider Threat Management Program? And I mean, they've basically written the standard, too, right? On, uh, how to mitigate threats third or insider, you know, threats.
Speaker A: Yes. Um, we wrote a book on insider threat. Um, and so, yeah, we worked with the National Insider Threat center when the government formed that. And we, um, helped to stand it up, and we helped to kind of come up with those standards for what should an insider threat program look like?
Speaker B: Unbelievable.
Speaker A: Yeah, it was a lot of fun. Um, really rewarding. And then the CISO of Rockwell came along. Rockwell Automation. Rockwell creates Industrial Control Systems.
Speaker B: Yep. Great company.
Speaker A: So the ciso, um, came to see me and recruited me to go to Rockwell and build an insider risk program. And at that point in time, the only companies that really had insider risk programs were finance, because you had to protect the credit card data from administrators.
Speaker B: Right.
Speaker A: And defense contractors because of spies. And that was it. Like, companies like Rockwell didn't have insider threat programs. So I went to Rockwell and created our. We called it Insider Risk, um, and so created our insider risk program. And again, it was, like, really fun. I found that I love breaking new ground. I love tackling some problem that has never been done before. And so it was terrifying, though, like, to leave Carnegie Mellon, where I told everyone what to do and to actually go do it. Right. But it worked. Um, we Caught a lot of insider threats, including a. Ah. Ah, senior embedded firmware engineer from China who stole all of our source code. But we caught him so fast that he wasn't able to do anything with it. He couldn't transfer it to anyone because we got him. Um, so that was an experience testified at my first, um, trial. And that was the most intimidating thing I've ever done in my life.
Speaker B: I can imagine. I can imagine.
Speaker A: Uh, and then our ciso, retired, or not retired, went to a new job, and he told Rockwell. So I told them, you're my successor. And I said, I want to be a cso. I love my job. I don't know anything about being a ciso.
Speaker B: Yeah.
Speaker A: And, you know, it was very ciso. Again, it was very undefined at that point. This was 2016, and the NIST CSF was pretty new. And so, um.
Speaker B: Yeah, just not a lot of CISOs in the world. Ten years ago. Right. Like.
Speaker A: Right. So I met with our general counsel, and I said, I don't really want to be the ciso, but I did some research for you, and here's a one pager on what I think the CISO position should look like. And so you. That's in the job description, if you want. And he said, hey, I like that. Can you turn that into three pages? And so I did. I came back a week later and turned it into three pages with more detail, and I went through it, and he said, you sound pretty excited about this. I think I am. And he said, you talked yourself into a job, didn't you?
Speaker B: Yes, you did. Yes, you did. That's fantastic.
Speaker A: Yeah. So that's how I became ciso. And, uh, then after we created our IT security strategy, we did that from, like, April till January. Then I said, so who's responsible for our manufacturing plants? And they said, oh, you are, but don't worry, we have a firewall in every plant. I thought, well, somehow that doesn't sound sufficient to me. Yeah, again, OT cybersecurity wasn't a thing back then, um, in electric, in oil and gas, because they had had attacks, but that was really it. So, again, I got the chance to break new ground and pulled together CISOs from Rockwell customers. Um, and we all kind of worked together. Um, I called it our otciso group, and we kind of all shared ideas on how to do this. So I did that, uh, until 2022, and then I retired for two months, and then I couldn't resist.
Speaker B: It's, uh, like a lifetime for you.
Speaker A: Yeah, it was. It was Right. When Russia invaded Ukraine. And I'm in Hawaii on my retirement trip saying, I need to do something. What am I doing in Hawaii?
Speaker B: On the sidelines. Yeah.
Speaker A: Yeah. So, um, Dragos offered me my dream job, which was, um, they wanted me to build OT cert, which provides free resources for small and medium organizations that have OT environments, operational technology, um, industrial. And so I did. I just went there. I worked part time, I watched my grandkids the other part time and built OT cert. And, uh, so right now we have 75 free resources, we're in 73 different countries, 3200 members, and it's just a dream job. I call myself the security fairy godmother. I just get to give away things for free.
Speaker B: I mean, talk about no better person to have that role. I mean, it seems like it was just like, perfect timing, perfect situation for you. Um, yes. And I also love the story about how you kind of designed the perfect role for you prior to that at Rockwell. Um, and, you know, working your way from just the insider risk sort of area to the full scope ciso. Um, amen. All started by some great opportunities. Born out of the great city of Pittsburgh. Uh,
Speaker A: that's what I love. I have never moved out of Pittsburgh. And, uh, when I was earlier in my career, I thought, what am I going to do in Pittsburgh? How much of a career can I have in Pittsburgh? And I have had amazing career, and I have never left the city. So that. That's pretty exciting.
Speaker B: Super exciting. Um, it. Don, is there a defining moment, like, something that made you realize cyber was where you wanted to be? Uh, obviously, I think the way you explained it says it all. Um, but it was it getting that opportunity to work with the Secret Service on the, you know, Olympics, that really was like, okay, I'm never turning back. Like, this is. This is, like, where I want to, you know, take my career. Amen.
Speaker A: I. I realized I wanted to get into security A little before that. I was working on a project at Carnegie Mellon, and it was a prototype of a portal for emergency response in case of a bioterrorism attack. So that show, like, how ahead of, uh, things our government was like, here we were pre 911 working on portal for collaboration in case of a bioterrorism attack. And this was back in the late 90s. So back then, like, the Internet wasn't what it is now. There were no, like, phones where you could just do videos and.
Speaker B: Exactly. Right.
Speaker A: And so we created this portal, and that was for, you know, imagine a bioterrorism attack. You'd have to have the FBI, the nsa, the Pennsylvania Department of Health, local departments of health. Um, they talked about, like, getting your grocery store records of what kind of drugs are people getting so they could see how. How it's spreading. It was really, really cool. Very.
Speaker B: That's really interesting.
Speaker A: Um, I realized, like, we're doing this portal, but no one has ever mentioned security. And it seems to me this was early. This was in the late 90s, but still, um, you know, there were viruses and. Yeah.
Speaker B: And if a system like that is, like, totally exposed, I mean, that could be very damaging.
Speaker A: Right. And so that wasn't even mentioned. And I thought, yeah, I kind of like to learn about security, and so I think I'll try to get a job in certificate. And so that's what piqued my interest. And it also kind of introduced me to that. Well, the Dragos mission is safeguarding civilization. And.
Speaker B: Yeah.
Speaker A: Uh, love that.
Speaker B: Uh, yep.
Speaker A: Mother always said, dawn just wants to save the world. Ever since I got job in search, she used to always say that dawn just wants to save the world. And that's what awakened that love of cyber security in me.
Speaker B: Well, and, dawn, uh, I'm so glad you brought that point up, because it's something I've been talking about a lot in these conversations. It's, I think, some of the best cyber leaders that I've talked to in my career. Amen. And cyber professionals, I'll say in general, have that mindset of, like, they want to make a difference in this world.
Speaker A: Yeah.
Speaker B: And you maybe becoming a doctor, you know, who is, like, saving lives on a daily basis. This is the closest we could come to it with our God given abilities, Right?
Speaker A: Exactly. Yes.
Speaker B: And, yeah. And there's nothing else out there that you, uh, know, gives you that feeling of like, okay, we are, like, on the front edge of you being that line between seriously terrible stuff and how civilization, like, operates in order.
Speaker A: Right. Yeah. Yeah. I. I always say when I interviewed, you know, I don't hire anymore, but when I used to interview people, the number one thing I would look for was passion. If they could answer all the questions right, and they had the technical ability, but they had no passion. Like, why do you want this job?
Speaker B: Yeah.
Speaker A: If passion didn't come through, then forget it. You're not. You're not the person to work for, Don. Yep.
Speaker B: Amen. I love that. Um, so, Don, I'm going to ask you a question. You know, you've managed teams, and you've had teams, you've hired teams. Great teams. And how would you make sure, you know, if you're hiring folks that are like you, they're in it because they're passionate, they believe in the mission of what, what you're doing. How do you keep them from managing too hard and burning themselves out and, you know. Amen. Wanting to do too much. There's never a shortage of things to do in this field. You could literally run yourself ragged if you don't be. If you're not careful. What are some good strategies in order to mitigate, um, that, that sort of thing? Amen.
Speaker A: Number one strategy. I became aware of it pretty early on as a manager because I was a working mother and I would work till five, I'd, uh, turn everything off and then I would spend the night with my kids and after they went to bed, I would go back to work and sometimes until 1 or 2 in the morning.
Speaker B: Sure.
Speaker A: And I would be emailing that whole time, you know, and so then I started hearing people say, yeah, we know, we better be ready at like 11 o'.
Speaker B: Clock.
Speaker A: That's when Dawn's email start coming up.
Speaker B: Thought what you realized that had an impact on other people? Yep.
Speaker A: Yeah. Uh, I'm thinking, well, this way they can see it in the morning when they come to work. I realized because of me, they feel like they have to get on their computers at 11 at night. I thought, oh, um, I've got to stop this. So that's when I start drafting the emails. Keep them in the drafts folder, but don't send them until the morning. And the same with weekends. Like, like if I worked on the weekend, I started getting responses and I thought, wait a second, I'm not doing this because I expect them to be working. I just want to feel like I'm getting caught up. But I, uh, always felt like I have to control myself because I am a workaholic. They're going to feel like that's what I expect. No matter what I say, that's what they're going to think. I expect them to be.
Speaker B: Well, disclaimer for any of my colleagues or, uh, you know, friends out there watching this. Uh, I am sorry if I do that to you, because I do that a lot. Uh, that's my habit too. I like to hang out with the kids and once they're off the bed, I'm usually back, you know, back in the lab doing my thing. Um, so. But I think, I hope most people that I work with know that I'm only doing that because that's my time to be productive and I Don't expect them to be productive during that time. Um, but that's, that's very cool that you recognize that and did something about that. And, uh, I'm gonna definitely have to take a page out of your book. Um, so Don, let me ask you. I. I know, uh, you know, with you running the OT cert and um, you being at Dragos and Echelon is a, is a partner of Dragos. We, we love, uh, working with Dragos and in the mission there, I think Rob's fantastic. Um, love to hear from you, your perspective on what you see as overhyped or underhyped in the security field today. Um, there's lots of hype around obvious things right now like AI, um, but I feel like your perspective might be different, you know, being on the sort of ot, uh, side of things and that edge. So very curious to hear what you think's, um, you know, overhyped versus underhyped at this stage.
Speaker A: The hype on AI worries me. It is amazing. AI, ah, is amazing. I mean, I'm not going to disagree with that.
Speaker B: Yeah.
Speaker A: But I feel like people have jumped ahead on the AI bandwagon and they are. They haven't realized that they still haven't done the basics. Because what we keep seeing is basic cyber hygiene. And I remember when I was a cease early in my CISO career, I used to hear that about it.
Speaker B: Sure.
Speaker A: Just make sure you have the basics down. And so I really did focus on that. I want to make sure I get the basics right before we start getting to more sophisticated things. And in ot, I feel like the community as a whole, every time I do some kind of an interview, it's a, uh, well, what do you think about AI in OT? And I just keep saying, just don't worry about AI until you get the basics down. The five critical controls from SANs. And what's interesting is in OT cert, um, a few months ago I took a look at what are people accessing in our portal. Um, I can't see who accesses what, but I can see how many downloads of our data versus. And the top 10 is basic cyber hygiene stuff. It's like create an OT cyber incident response plan, do a tabletop exercise, ransomware hits ot. What do you do? Just the foundational things. Log. How do you do logging usb, like removable media? How do you control removable media in your plants? So I'm really excited to see. And the thing is, although OT Cert was intended to help small and medium organizations, over half of our members are Over a billion dollars in revenue. So we have a lot of large companies that are using that portal.
Speaker B: That's great.
Speaker A: I see large and small alike. That's what people are using. So that makes me happy that people are taking that message to heart and worrying about the basics.
Speaker B: ICS Incident Response Defensible Architecture, ICS Network Visibility monitoring with dragos, um, Secure Remote access and Risk Based Vulnerability management. Right, right.
Speaker A: Those are the five critical controls.
Speaker B: Do the basics well, do these fundamentals well. And uh, you're ahead of most of everybody.
Speaker A: You look at where the attack's coming from. A lot of people think the attacks in OT come through it. So, so ransomware hits it and then it impacts OT because you don't have your network segmented. But there's a lot of attacks coming in directly through your remote access that you think is secure, but it's not. Um, or unpatched firewalls, unpatched VPNs. These are the basics. And you can't just go out and patch everything in ot like you can in it, but when you have a vulnerability in your firewalls or in your VPNs and it's being actively exploited, you really need to patch that. Like, that's the,
Speaker B: um. I also love, uh, you know, the, the SANS has their, like, I think it's sans. They have their ot. Um, or. No, that's a, that's a CISA thing. Um, their OT vulnerabilities that they put out regularly. Right. Um, calling out critical vulnerabilities in a lot of these ICS systems.
Speaker A: Yeah, that puts those out.
Speaker B: Yeah.
Speaker A: And like dragos, um, we do disclosures, responsible disclosures of vulnerabilities ourselves. But yes, this puts out vulnerability disclosures. And so, yeah, there is kind of a one stop shop that you can go to.
Speaker B: Yeah. And like, just, just staying ahead on that and being very responsive to that. Uh, for a lot of OT teams, I think, uh, this is super critical. Um, you know, I think there will be a lot of value, you know, with AI. Uh, but I don't think I want like uh, this open claw or CLAUDE bot, uh, accessing my OT environments anytime soon. Right.
Speaker A: No, no, no. You, you really don't want to just let AI loose. I remember a few years ago there was a vendor that I heard talking and they said, and then the AI will take over and defend your OT network. And I just sat there and thought, oh, please don't buy that product.
Speaker B: Yeah, that doesn't. Yeah. Oh my gosh.
Speaker A: Want to unleash the AI, like at Dreos we're looking at how can we use AI? We have real data that we've collected for all these years and so we can create AI like an AI assist. What should I do when I see something like this based on, you know, what happened in the past?
Speaker B: And here are some suggestions. And then the human could take it the last mile. Right.
Speaker A: But don't just let the AI start taking action. Not.
Speaker B: Amen. Amen. Not on ROT systems anytime soon, hopefully. Um, so I, I often see younger pros coming up in the industry. They want to be a ciso, right? Um, they, that's what they aspire to do. But I often feel like there's lots of misconceptions the younger cyber professionals have about what does it take to be a ciso, right? What, what other skills, you know, are they missing? Um, what do you think is maybe one of those biggest misconceptions that those younger professionals have?
Speaker A: I mentor some young professionals that have that exact goal. I want to be a ciso. Help me create that career path.
Speaker B: Yeah.
Speaker A: And they, their impression is like they need to have technical skills, they need to work in the SoC, they need to be a network administrator, they need to understand all of the technical components. But what they don't understand is you really have to understand the business itself. And you need to be able to talk to those, the CEO, your senior vice presidents. You need to be able to talk to them and they don't want to hear your technical mumbo jumbo. You need to be able to communicate with them very clearly. And I feel like I'm not a deeply technical security person. I've always surrounded myself with really good technical people. But my skill has always been more to kind of see the big picture and to be able to take a standard and apply that and come up with a way of identifying risk. Um, so many people, you know, like I read the news feeds. I would read the news feeds every morning as ciso and everything I'd read, I'd think, could this happen to us? Could this happen to us? And usually I would say, no, we're okay. But when there was something that I wasn't sure about, I'd send it to the right people at Rockwell. Um, and then you had to make your risk based decision. Uh, is this one that I need to like escalate or do we put it on the list? Like just, man, risk is, is a very different skill than just understanding technology.
Speaker B: It totally is. Yeah. Brings together the, the impact to the business. It brings together the probability you're Based on everything else you've got going on within that business and who's potentially coming after you. Right. That's a big context, you know, loop that a lot of people don't even think of. You know, they. They think, okay, there's this standard. I've got to follow the standard. Well, yeah, the standard is like a great starting point, but based off of, like, your threat profile with your industry and your company. Like, you have to think in those terms and to talk in those terms, too. Um, that is a constant theme I'm hearing from a lot of folks that have been in your chair, Don, is that, um, really getting sharp on what does the business need and require. And to talk in those business terms is critically important.
Speaker A: And I think another piece of advice I give to people is authenticity. I think that was the single key to my success at Rockwell, because they trusted me, the CEO trusted me, the board trusted me. They knew what. When I said something that I could temper, I knew when something was serious and when something wasn't. And when dawn said something is serious, we need to listen, because she doesn't do that, like, all the time. Yeah, just being passionate. You want to just jump up and down and react to everything. And as a ciso, you have to really control your emotions.
Speaker B: Oh, yeah.
Speaker A: And choose when to react and when not to.
Speaker B: Amen. Amen. Um, dawn, if you could put a message on a billboard that, you know, every new CISO had to read and drive by once a day, what would it say and why it would be that.
Speaker A: Be authentic.
Speaker B: Ah.
Speaker A: Can deviate from that. If ever one. I felt like if I. If one time I was not authentic about something or you know what.
Speaker B: Amen was hard.
Speaker A: Was m. Uh, sometimes you would be getting pressure. Like, I don't think you have to raise that up the ladder. You know, they're not going to take that well. It's going to cost too much. I get it's a big risk, but I don't really think you want to be the one to. To bring that up. And it took a lot of nerve sometimes to bring it up. Uh, I remember the one year we were preparing for the board, the annual board meeting where we would present our strategy for the year. And I had a cross functional group that we all got together and we met once a month. So we knew, here are biggest risks, here's how much we need to mitigate it. And so for one of them, I had to go to the SVP of the development team, all the software engineers at Rockwell, they all were in One big product team, and that I need X number of dollars. And it was a lot for this new initiative because this is one of our top five, I think, risks in the company. And he said, don, I get it. But we just had a riff. We had to lay people off, like, earnings are down. We don't have money right now. I just can't give it to you. And I said, uh, believe me, I totally understand, but it's still a risk. Whether we can mitigate it or not, it's still a risk, and I have to raise it to the board. And so I'm going to put it on in the slides. I'm going to put it on the deck. Um, so it's. It's going on the deck. And I sent him the deck, and I said, there it is on slide five. There it is. It's on there. And so I kept going to him, like, every. Every couple of days saying, you know, it's in the deck. The deck is due Friday. It's in the deck. It's going to the board. And I knew we didn't want it to go to the board. Nobody wants to be that one of those top risks. And then say, oh, we're doing nothing about it.
Speaker B: Yeah.
Speaker A: So finally it was like, we're playing a game of chicken, like, who's gonna give first?
Speaker B: He's a budge first. Yeah.
Speaker A: It was really hard for me to stand my ground and not to give in. And finally, day before the slides were due, he said, tell you what, you can't use all that money at once anyway. How about if I give you half, you do what you need to do, get started, do product evaluations and all that, and then in six months, hopefully earnings will be better and I can give you the other half. And I said, perfect solution. So our, uh, plan thing was fine, but it took a lot of guts.
Speaker B: And, um, that's that authenticity, right? That's you staying true to yourself, true to your beliefs, and true to what you think is best. Amen. And look, I mean, you also gave them the ability to say, we just can't fund that right now, but thank you for sharing that risk. Um, but there's no way you would have lived with not raising it and sweeping it under the rug. That's not you. And that was your way of being authentic to yourself and sticking to your beliefs. Uh, so I think that's great advice.
Speaker A: Yeah. And that's one fear I have being retired. You know, a lot of retired CSOs want to be on boards and, ah, that's one fear I have of being on a board. Because you are totally reliant on what you're told.
Speaker B: Yes.
Speaker A: And I know there are a lot of people out there that are not authentic.
Speaker B: Yes. Tell you what you want to hear. Yeah.
Speaker A: Yeah. They can be beat down, and they will. Yeah. So, yeah. But that, to me, that's the most, um, important quality of a ciso or anyone, really. Anyone.
Speaker B: Yeah, totally. That's good. In life and CISO world. Um, well, you know, getting close to wrapping up here, and just wanted to ask kind of last question for you, Don. I guarantee, you know, based on your story, you've obviously met and worked with so many talented leaders in the space. Um, is there one CISO or cyber leader out there that you would like to call out or thank or show some, uh, gratitude for? Amen.
Speaker A: It's definitely Rob Lee. I mean, he's the CEO of Dragos, and, um, I've seen him speak for so many years, and that's really what. What has driven me. And, you know, he's just amazing. He's unbelievably amazing.
Speaker B: He's a powerhouse in this industry. Absolutely.
Speaker A: Building the company he has and in maintaining his authenticity.
Speaker B: Absolutely.
Speaker A: Yeah. Uh, he's an amazing guy. We're lucky to have him. Society in general is lucky to have him.
Speaker B: Dragos and, yes, everybody else involved, uh, that relies on the critical infrastructure that you help protect is lucky to have him as a leader of that company. Uh, no doubt. Um, well, Don, this has been fantastic. I, uh, wish we had hours and hours more to, uh, chat more. You're always full of, uh, great advice. I always learn something from you every time we're together. Um, and I always look forward to our interactions. So, really want to say thank you so much for just being part of this.
Speaker A: Thank you for giving me the opportunity. It was fun, and I hope it helps some people with something.
Speaker B: I. I believe it will. Undoubtedly so. Thank you so much. Amen.
Speaker A: Thank you.
Speaker B: Amen.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.