The Human Side of Cybersecurity · 2026-04-27 · 37 min
Key moments - from our scoring
Substance score
39 / 100
Five dimensions, 20 points each
Jamie Giroux brings three decades of cybersecurity experience to a conversation centered on a critical gap in the industry: the overlooked human element. As CISO at Platinum Equity, Giroux has progressed from traditional technical security work - pen testing, firewall configuration, compliance checkboxes - to recognizing that technology alone cannot solve security challenges rooted in human behavior and organizational culture. His recent book, The Drew Methodology, codifies an EQ-centric approach to security training, developed partly through a master's degree at RIT focusing on emotional intelligence and cybersecurity curriculum. The conversation reveals specific inflection points in Giroux's career: firing a client in 2004-2005 after four years of ignored assessments, and recognizing during cyber range exercises around 2015-2016 that performance metrics obsessed over MTTR and detection speeds while ignoring people entirely. He advocates shifting security teams from enforcers to enablers, checking employee capacity rather than just workload, and building vulnerability and trust through authentic storytelling. On AI, Giroux identifies a critical underhyped concern: data governance and AI governance gaps mean organizations are flooding AI systems with unvetted data without understanding compliance implications around GDPR and privacy - the garbage-in-garbage-out problem that will compound security risks.
Organizations treat human problems with purely technical solutions; phishing tests, email warnings, and link caution have remained unchanged for 25+ years with minimal behavioral impact, while billions spent on technical protections undermine the human instruction to 'be careful.'
Giroux studied emotional intelligence and cybersecurity as part of his master's degree at RIT and found that no other high-stakes profession (medicine, law enforcement, firefighting) ignores tangible emotional skills training; EQ - self-awareness, trigger recognition, and controlled responses - directly improves security decision-making and team culture.
Many organizations deploy AI without establishing data governance, data tagging, or AI governance frameworks, risking processing of sensitive, non-compliant, or improperly classified data - creating privacy violations (GDPR implications) and amplifying security risks rather than reducing them.
Instead of asking only about workload, ask about capacity - whether employees are mentally and physically available; this determines whether they can safely handle incident response or defense roles and reflects understanding that stressed or diminished employees cannot contribute effectively to security.
Around 2004-2005, Giroux stopped renewing a client contract after four years of ignored assessment recommendations, realizing that compliance reports and technical fixes mean nothing if the organization won't change behavior - prompting a shift toward human-centered messaging and culture.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuinely useful ideas - notably the capacity-vs-workload Monday check-in, the enforcer-to-enabler framing, and the data-governance critique of AI adoption - but they are buried under extensive throat-clearing, mutual validation, and meandering storytelling. The ratio of novel ideas to airtime is low.
I go into a Monday morning meeting with the team and ask them questions like what's your capacity? Not your workload, your capacity
I think we're treating human problems with technical solutions. At the end of the day, I think that we have security awareness trainings that really don't work that well
The human-centric cybersecurity thesis is genuine but by now well-trodden; the specific framings ('enforcer to enabler', 'goal isn't compliance, it's commitment') are catchy one-liners rather than first-principles arguments. Nothing in the episode is contrarian or challenges the listener's existing mental model in a surprising way.
we have to move away from being enforcers to enablers
the goal isn't compliance, it's commitment
Jamie Giroux is a legitimate long-tenure practitioner - 30 years in the field, current CISO at a real PE firm, with cross-sector experience in law enforcement and finance - but the episode functions largely as a book-promotion vehicle and the depth of operational insight shared is modest relative to his stated experience.
I'm the Chief Information Security Officer at Platinum Equity. I've been in Cyber for 30 years
I did a bunch in law enforcement, a bunch in different areas of things that we can't talk about in organized crime
There are a few anchored anecdotes - a client fired circa 2004-2005, a master's programme at RIT, cyber range work in 2015-2016 - but there is no hard data, no named company outcomes, no dollar figures or programme metrics from his actual CISO work, and references to '49 vulnerabilities' are vague and uncontextualised.
I won't say the customer's name, but I can tell you the customer. And. And the approximate time frame is probably around 2004 or 2005. And I fired my first client because I had done four assessments year after year after year
49 vulnerabilities have been a couple of um, them that have come out
The host consistently validates rather than challenges, frequently inserts his own anecdotes (Simon Sinek reading, SOC night-shift stories) that redirect attention away from the guest, and relies on generic podcast formats like the 'billboard question' and 'overhyped/underhyped'. There are no genuine follow-ups that pressure-test a claim or surface new information.
Yeah, I love that so much
Yeah, yeah, I, I had the same epiphany when I started this firm, right. I, I told you, I think I read, uh, start with why Simon Sinek like three times in a row
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Dan Desko sits down with Jamie Giroux, Chief Information Security Officer at Platinum Equity. With more than 30 years in cybersecurity, Jamie shares what it was like working in the industry long before it was even called “cyber,” and how the field has evolved over the decades. The conversation explores leadership, emotional intelligence, and the human side of cybersecurity. Jamie also discusses themes from his book on security leadership and culture, where he examines how emotional intelligence, employee engagement, and leadership mindset shape stronger security programs and healthier organizations. If you enjoyed this episode, please leave review, it helps more people find the show! Want first access to future interviews?
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign. We are live. So, Jamie, great to, uh, great to see you again this morning. Thank you, uh, again so much for joining, uh, my CISO Spotlight series for my Cyber Intelligence Weekly newsletter. Uh, it's been great you're getting to know you over the years here, and, um, so thrilled that you joined us today. Uh, do you mind starting off by maybe introducing yourself, letting the audience know kind of who you are, what you do and where you came from?
Speaker B: Absolutely. Ah, thanks, Dan. And first. First, thanks for. Thanks for having me on your, uh, on your. On your podcast here. And I, um, really appreciate it because it's, uh, I think what you're doing is. Is noble. And, um, I love the messaging that's out there. So this. This should have a lot of fun. Yeah, we should have a lot of fun. Um, all right, Jamie Drew. Um, I'm the Chief Information Security Officer at Platinum Equity. I've been in Cyber for 30 years. This is 30 years for me. I incorporated a company in 1996, uh, in Cyber. It wasn't called Cyber then. Um, but that's, uh.
Speaker A: You're like 37, right? I don't know.
Speaker B: Yeah, that's exactly right. Okay, good. All right, this is over.
Speaker A: We're good. Yeah. Well, um.
Speaker B: Yeah, so, um. So, uh, yeah, 30 years ago, um, I was. I was reflecting on that because it's always, you know, you're updating your LinkedIn, you're updating this and that, and you're like 20 years or 25 years. And then, uh, my. My resume and my. My LinkedIn profiles and bios and stuff have always been 25 plus years. And then this year it's like, I gotta Change it to 30. Anyway, um, so, yeah, I, ah, I started a long time ago, before cyber was cyber. Uh, and I' here, like, I've always been in this space. I mean, it. And the intersections between, um, you know, uh, between, you know, audit compliance, um, uh, you know, it controls all these things that, you know. And of course, you start with firewalls and pen testing and all those different pieces that are. That are associated with it. Um, but cyber's kind of always been. Been the thing, and, um, Canadian. Uh, um, but, uh, and spent quite a bit of time in the US Doing different, um, different, uh, working with different organizations in health and finance. Uh, I did a bunch in law enforcement, a bunch in different areas of things that we can't talk about in organized crime and all those kinds of great, great scenarios. Um, and so I've just been really blessed with all the opportunities that I'VE had. And, um, recently, uh, uh, last, uh, I guess it was November, I launched a book, um, called the Drew Methodology. And it's kind of, um, this EQ centric, human, uh, human focused roadmap of how we can spend so much time and so much effort in training about the things that don't actually matter. We do these phishing tests that say, don't click on these links. Or we train on new technologies or new, uh, capabilities. Um, and I think we have this underinvested frontier of our people and how we teach them. Um, EQ is a muscle. One of my taglines is, um, EQ is a muscle. We have to train it every day. This is what we have to do. Um, so really exciting stuff as it relates to that. Um, and working with some education, um, institutions, um, to put it out there and to get it into the hands of students. I'll digress. It stemmed from, um. Uh, a while back, a few years ago, I went and did my master's, um, at rit and what I studied was, um, emotional intelligence and cybersecurity as it relates to what's out there, what's been in there from a curriculum perspective. And so we built a curriculum as part of my master's, uh, and then really was the impetus to start the book. Uh, and what a gap, Dan. Like, no one, not emt, not doctors, not nurses, not firefighters, no one is really focused on teaching these tangible skills of getting humans ready for what they're about to go through. And, uh, so, uh, that's kind of from the start of pen testing and doing all that work back in the 90s, uh, which is a whole other story how I get into that. But anyway, and then all the way through. Full circle. Read the book. No, um, all the way full circle, uh, into where we are today, you know, ciso, um, helping organizations, helping to. Helping to, um, helping to build and grow. You know, um, you know, this, this, you know, I'm going to say this security story as it relates to what we need to have as a. Because that's what we are, storytellers. Um, and then to, you know, on this other side of things, to be able to kind of generativity and giving back to others and kind of trying to just send the message of what we're working on. Yeah.
Speaker A: And it's so perfect that you're here on this show with me. Right. And I think it's the reason why we clicked so well. Um, we deeply care about the human side of cybersecurity here. And, uh, that was core to the mission of this organization when I started this firm. Um, you strip away all the cool tech and the tools and the techniques and the fun hacking bits, and it's like, well, why. Why are we doing this at the end of the day? And it's about people, right? And one of the most overlooked things is, is the people. And, you know, for us, I mean, we're. We're a human first. Ah, cyber company. We say that all the time. Um, so when did you first feel like in. In your. Your kind of career, that that was like a glaring missing piece for you? Like, when did that be?
Speaker B: So I. I would say it took. It took. It took longer than I wish it would have, because man would be at a different place today if I had known all this stuff. You know, you look back and, um, for sure, 100%, but. But, you know, similar. I mean, you're. You're familiar with this. I mean, working with companies, doing assessments, doing audits, doing, um, you know, control work, doing entry, you know, trying to put programs, um, um, you know, get. Get, uh, get organizations, you know, compliant. But there was no. There was no comprehension. It wasn't. It was. It was just. It was just compliance. It was checkboxes. It was, you know, make sure your firewall's tight or make sure this is in place. And, and so I can tell you. I won't say the customer's name, but I can tell you the customer. And. And the approximate time frame is probably around 2004 or 2005. And I fired my first client because I had done four assessments year after year after year, and. And nobody was. Nothing was changing. It was like, you're writing up all these responses, you're writing up all this work, and you're doing all these things to say, this is what you're going to. This is what makes you better. This is.
Speaker A: Yeah, this is.
Speaker B: And then you. What's the point? Nobody's listening. Nobody's. Nobody's doing anything with it. And I went, so. So I fired the client. And I was sitting there and I fired the client. I just didn't choose to renew in the next. In the next review. I mean, that's harsh words to say, fired the client. Um, but. But realistically, I didn't go back and renew. And I sat back and I reflected on it at that point, and that was probably. That was one of the defining moments, um, was. Was, hey, we have to do something better. We have to send better messages. We have to do better with our messaging. Um, and then the second one was I was doing a bunch of work, um, in the, in the mid 2000, 2015, 2016 mark, um, in cyber ranges. And we were bringing lots of companies through cyber ranges and just technical drills on how um, you know, how you're going to, how you're experiencing it and how you're um, you know, how you're performing and all the performance, performance metrics were about um, you know, what mttr, MTT did. Meantime to detection, meantime to response, meantime to mean time, to everything. And nobody was looking at the people. And this is where, this is where it went off. This is what was like really clear that we have a human piece of this, that I actually don't care what the technologies are. I mean AI coming, it's going to turn everything out of 10. We'll talk about that in a minute. But um, I actually don't care. You know, firewall, SIM tools, they're all really agnostic to me. It's about the human approach and the human centric side of how we deal with them. And that's, I think that that's, that's where it was, you know, really, really clear then. Um, as ah, it related, it just, just hit, it was like, wow, we are training the wrong things. We're just focused on technology and, and ones and zeros and, and it's, it's just the wrong approach.
Speaker A: Yeah, yeah, I, I had the same epiphany when I started this firm, right. I, I told you, I think I read, uh, start with why Simon Sinek like three times in a row and really just deeply thought about why are we doing any of this? Why does any of this matter? And I had that little sort of light bulb moment myself. And um, it's an interesting point in time when that happens because you could realize that you could have the greatest technology in the world. And if you don't have the right people that are motivated and are fresh and you know, in line with the mission and believe in you as a leader. Uh, like who cares what tools you have? Like none of it's going to work. Um, you know, maybe we'll reach some, you know, uh, singularity with agentic AI where it'll magically take care of all of itself. But uh, I think we'll be far gone by the time that happens. Right? Um, so uh, Jamie, let me ask you, like in a CISO's journey, in someone as successful as yourself, um, you, you think about like wins and losses and sometimes those losses are kind of remembered more than the wins, right? Because they could leave some scar tissue behind. But those are the very best, like teaching moments, whether it's in your career or life. You know, what is a scar that sort of like set the foundation for you or taught you the most.
Speaker B: Yeah. So without. Listen, we're not going to get super deep here and go crazy. So I had a defining moment in 1994 when I had a car accident. I crushed every bone in my lower body. I died twice in the table. I had 17 surgeries to correct. Bad stuff. Bad. Um, and so you carry a lot with you when those things happen. Um, but one of the things that you can take out of it is I'm going to say this and it's going to sound cheesy, but the glass half full, um, methodology or mainstay in your brain. And, and there is something about that of, you know, it's, it's first one is, is woe is me. And this is dark. And I don't, you know, how am I going to continue or how is this going to be or you're never going to walk again or you know, all those, all those different pieces of it. And then it's. You flip into the now I'm alive and I've got all these opportunities and I'm so, so it's so everything, um, and this, this draws here everything frames itself into, into reactions and responses and so, and then those reactions and responses in any situation. And this is all about self awareness, is all about the triggers that set you off and then how you react to those and how you respond to those. And so, you know, I've had, I've had significant times and memories in my career where I've reacted poorly. I've reacted, uh, I maybe flew off the handle. It's funny, we were just, just recording a um, segment for the training stuff and how we react or respond when somebody says something or does something or triggers something emotionally. And if we're aware of what our triggers are, we are so much better in being able to control our responses. Maybe we pause. We don't send that email because I know I've sent it. I can tell you that I have definitely been in HR offices, um, on a couple of occasions because of something that I said was not the right response, it was not the right thing to do. Um, and I think that's, and that that comes with maturity. And this, this is, this is growing your EQ of um, you know, your controls, your self awareness, your self management and then the social side of, of um, how are you? What are Your responses and how are they impacting others? Especially as you get into leadership and you start to, you know, you start to run a team and you're looking at it and saying, if I act in this way, they're going to mirror that behavior. They're going to react in a similar fashion. And I need to not be a dumpster fire right now. I need to not be, um, you control. I need to be fully in control and calm and right. So, so, uh, I look back often, um, uh, and reflect on areas in my career where I know. Because you know what you remember them like when you, when you, when it, when it really doesn't go well, you definitely like, you kind of, you keep those in your pocket and you remember them often. Uh, and so I've, I've started to turn those and we're using those as modules, um, as training modules to say, hey, I can remember a time when I did this, I can remember a time when I reacted this way. And um, and, and I think what it does is it, it builds trust, it builds connection. Uh, because we're all human. We all, we all mess up. If I, if I sat here and said I've been perfect all my career and everything's been great, uh, well, everyone would turn off and no one would watch us and your, your, your subscription numbers would tank. But, but the point of this is, is, is how do as we bring in the human side of, of being vulnerable and being open and being um, um, uh, communicative and, and the vulnerability is a big piece and we share, and we share our stories. We built this incredible amount of trust with our team. Incredible amount of trust in how we, how we go forward.
Speaker A: Yeah. And you know, there's how to great responsibility and taking those learnings and putting them out there for everyone to see. Right. And the great courage, I think, in you sharing your story in the book. Um, you know, I think I, I said to you when I first, you know, kind of read the introduction, the prologue to your book and you know, uh, you opened up and told, you know, probably a very tough story for you to tell publicly, um, that you just shared with us. And you know, there's, there's a way to go about life. Like you could send people out there and they'll just brute force their way through and they'll have all these hard learnings themselves. But whole idea of coming on a podcast like this or you putting your thoughts down in a book or building a whole rubric around it to train people on it, I think that's the whole idea, right? People are still going to have to learn for themselves, but you can at least arm them with the right ideas how to manage situations. When you run into these in life and put some of those arrows in their quiver so they get to a point in their life, they see that, they pattern recognize it and maybe they have a better idea of how to react, respond differently. It helps them, helps everyone around them. Um, and I love that you're focusing on bringing that to this field because this is a field that is missing that in a large, large way. Um, this field needs more empathy. It needs more, you know, it really does. I mean like everyone in this field is out there hard charging every day wanting to do the best that they can for the right reasons and with almost, you know, no one thinking about, uh, the well being of those folks. Right.
Speaker B: So a couple of comments there. First one arrow in the quiver, um, arrows in the quiver. I love it. Um, I use tools in the toolbox. Um, and that same approach, same everything. Because it's like, you know, we're asking, we're asking people to build, you know, a giant house with a screwdriver and a hammer and it's nuts. Um, and I think as we build culture for security, uh, and we move away from being enforcers to enablers, um, and I think that's a key statement, um, for folks that are in security. And um, when I talk to students or guest lecturing or talking to different teams, um, we have to get away from that approach. Being an enforcer is not what security culture is about. Um, an enabler, absolutely. I think that's the right, um, because I think a lot of organizations, they run, they run security culture as compliance programs or compliance checkboxes. Uh, uh, we have these things in place and that doesn't do anyone any good. Ah, from that perspective. So, um, yeah, it's just really changing trying to change that. Um, um, um, I've used this for years now, uh, where I go into a Monday morning meeting with the team and ask them questions like what's your capacity? Not your workload, your capacity, where's your capacity at? Because if our employees are contributors to our culture and somebody has something that happens to them on the weekend or something happens to them in personal lives and they come in and they're at a 20, I can't ask them to be an incident responder or a defender or do anything that's of any capacity as it relates to, uh, something that's going to tax them both physically, mentally. I think we have to be. And this isn't just about being soft or being the soft side. We say soft skills or emotional or touchy feely or any of those things. This is about being connected at a human level and understanding where our most critical resources are in the defenses and the things that they have to do. That's, that's, that's, that's kind of the approach, one of the approaches. And, and um, if I, if I could sum it up, that's, that's how I want that, that's how I would want a team to feel. That's how I would want, um, teams in general from, from any organization to feel that connected with each other, to know that somebody's, somebody's. Somebody's falling down a little bit. Somebody's. And, and we step in and we, and we, we contribute and help.
Speaker A: Yeah. All part of the. I love that, Jamie. Yeah, I love it. Um, shifting a little bit to cyber landscape. I want to ask a couple questions around there and I think you have really great perspectives on this. I mean, you get to see how many businesses are doing different things on a daily basis and they all have different risk profiles, and that's an interesting place to be. Right. Um, so we talk a lot about what's overhyped, underhyped in the security world. Um, I would really love to hear from your perspective, like, what out there right now is kind of, you know, on that overhyped side for you and conversely, like, what's on that other side of the coin, like something that's maybe under hype, not talked about enough that you wish people would pay more attention to.
Speaker B: So, uh, I have a, I have, I have a. Yeah, I have one that I'll start with because I think it's the underhyped that leads to the overhyped. So AI is obviously slightly overhyped. Everybody's, everybody's building everything to do AI. Everybody's.
Speaker A: Everybody.
Speaker B: AI is going to solve the world's problem. It's gonna, it's gonna, you know, take over and, and help us to do all these things. The underhype side of this is, is that is the garbage in, garbage out, in the data side of it. And I think that we're in a, I think that the industry is in a big. I think we're in a challenging place right now where we haven't done enough work in the data governance, in the data tagging and the data. Uh, I think that m. Many, many organizations are not doing anything with AI governance. They're just, they're taking AI in. They're doing whatever it is that they're doing with it to revolutionize and save their world. Um, but they haven't thought about the ramifications, um, around processing data that's not supposed to be processed within those tool sets. And I think that's a, I think that's probably a bigger challenge today than people realize. Um, and I think that you're going to start to see it with, I think privacy is going to overlap and start to have conversations. I think you see GDPR is starting to come into play now and saying, hey, you have to be very careful about what data you're putting into AI, whether it's agentic or whether it's, um, um, you know, just LLMs in general. But I do think that, I think that the overhype is, it's going to fix everything. And the underhype is you haven't, you haven't done enough to protect it.
Speaker A: Yeah, yeah, I think that's brilliant. I think it's brilliant. Um, I think, you know, some of the capabilities of, uh, some of the agentic stuff that's out there and just how it can make cyber professionals maybe a little more efficient just in every day, like daily tasks, you know, versus it being infused in all the security tools. Right. It's like, okay, how can we enable our people just to be more efficient, more effective, reduce some of, like the, you know, burden that's on them every day, um, with more AI personal assistance versus, like the focus on what's the next, you know, AI in the SoC or AI in my EDR. That's all important. Right. But yeah, uh, how can it help the people?
Speaker B: I think that there's tremendous opportunity for AI to have a very strong role. Especially you mentioned socks. And I think, I think Security Operations center. I mean, I remember building Security operations centers. And the first thing we do is you have to staff it 24 7. And in staffing it 24 7, you know that the night shift is probably just watching Netflix and waiting for a red light to. Green light to turn red. I mean, that's, that's. And we accepted.
Speaker A: I did that. I did that role. Yeah. But I didn't have Netflix. There's a TV that we rolled into our, our office, you know. Yes. And in a va, vhs. Like, you know, and we had like, I think three movies. Right. Like Field of Dreams, like Star wars and maybe one other thing. But we watched the same movies on repeat. But I've been there.
Speaker B: Yeah, but that's, but that's the. And so AI transformational. And I mean, I mean, uh, ingesting, you know, investigations and investing log data and taking that log data and you know, making heads or tails out of it. Awesome. I think it's, I think transformationally it will be, it will be so helpful in those, in those, uh, in those roles. Um, and so I do, I think there's a great place for it. Um, but I do think, think that that, um, that we have to be, we still have to be cautious around the decisions that we're making or not making associated with what, what we're ingesting or what we're, what we're doing with it. So.
Speaker A: Yeah, yeah, yeah, yeah, completely agree. Um, so I know you like to speak the truth. Uh, for you, what would be an uncomfortable truth in cybersecurity today? Like what is, what is something that people maybe don't want to hear but you know, is a true statement?
Speaker B: I think that if I was just. I think we're treating human problems with technical solutions. At the end of the day, I think that we have security awareness trainings that really don't work that well. We've been dealing with and fighting with the same, the same fundamental problems for 25 more years. We can't surf the web securely, we can't send links securely, we can't send emails securely. Um, and I think it's. Listen, I have tremendous amounts of empathy for the end user there because what we do is we go and spend hundreds of thousands of dollars of protections to put in place so that they can surf and email and do all these things securely. And then we still say to them, well, be careful of the banner because if it doesn't have a banner, it came from outside. Or if it. Or you just be, be wary of links or be wary of toad attacks or be wary of. It's like, what the hell? What, what are we doing? This is 25 years. And so we just keep throwing technical solutions at human problems. And AI is like transformationally, it's changing the world in the number of attacks and what attackers are using this for. Um, and so, you know, I think if we, and listen, I mean I did it. I mean we send in phishing campaigns and we tried to do pen testing and do all these things of like, haha, we got this person and haha, we got them to click and you know, almost a, almost a shaming game in the early days of like, I can't believe that you would do that. And now it's not who clicked. I think we have to be.
Speaker A: Why, why did it. What.
Speaker B: What was it. What was it about that message that resonated? What was it about that, that, that, um. And then. And then. And then in the background, from a technical perspective, we can look at things of how do we. How do we secure a better, secure system? How do we better block and trends, but not. We can't lead with technology. We have to lead with the human side. We have to lead with fixing these problems first.
Speaker A: Yeah. Yeah. I love that so much.
Speaker B: Well, and. And here's the uncomfortable part. We've never done this. I mean, yeah, I can walk into a room all day long and tell me, when was the last time that I stood up in front of you and talked to you about email security or firewalls or firewall management or programs or all those things in place? And I'm. When was the last time anyone walked in and said, hey, I want to talk to you today about empathy. I want to talk to you today about eq, or I want to talk to you about cultural leadership. I mean, it's just. It just doesn't. It's not the norm. And I think that's what we have to. I think that's where we have to change.
Speaker A: Yeah. Well, that's a perfect segue to. To my next question. Right. And one of the uncomfortable truths I hear a lot about in cybersecurity is, um, people that get, you know, a bit burnt out. There is a, um, you know, a asymmetric war being waged every day. Right. That the hackers only need to be right once.
Speaker B: That's right.
Speaker A: There's need to be right 100 of the time. And typically, the people that are involved in, um, defending networks and on the good side of cyber, they care. Right? They're in it because they care, and they want to do the right thing, which is hard to tell people to, like, hey, slow down. Um, the work is never going to end. You know, you got to take a break. You got to clear your head. Um, what are some ways in your career that have worked for you to help keep people fresh and the best that they can be?
Speaker B: So, I mean, a couple of things. So I talked earlier about capacity versus workload, because it's a very different thing. Capacity is just, how are you? Where are you? Are you good? Um, if the big event happened today, how do you feel that you are to be able to handle that? Or how do you feel you can handle, uh, what's on, um, your plate? Not workload, because we'll always be overworked, and I shouldn't Say overworked. But there's always a vast amount of work to do, right? I mean it's always there. But burnout isn't just workload. It's that emotional weight then as well, right? It's, it's uh, it's the, it's the pieces that you have to carry with you. It's what you're taking home at night. It's where you feel. And then lots of people, lots of people carry this emotional weight of. I know these systems aren't quite secure, so they're staying awake or staying, you know, sleeping and not sleeping at night because of, you know. And I think, man, I think that's, that's a, that's a game changer today because we're starting to see it in attack vectors. You know, 49 vulnerabilities have been a couple of um, them that have come out. There's been some other, other instances where zero days come out and the attackers now have tools to write the exploitation code and the detection of the search capability to go find it. And so uh, uh, you know, you start to talk about, you know, we, we used to think it's a seven day patch cycle, was an acceptable patch cycle. I mean those ideas are going out the window. Like that's. And so how do. So we have to think about, you know, like, so we, so we think about it from a business risk perspective and all the things that are happening that way. But then, but again then go back to this emotional weight of you have those resources on your team that they just, they care, they're pleasers, they want to make sure everything's. And they're carrying that home with them, they're carrying that weight with them. Um, and so I think it's. Communication is really key in this space of just being, you know, um, um, aware of it, having conversations and then, and then normalizing that burnout signals, you know, before there's a crisis, normalizing that, that it's okay to say I'm tapped. Like I have to, I have to step back a little bit or I need you to step back. Time off is a really important p. Um, you know, I think I've become pretty good at this point in my career of detecting when someone's struggling. Um, and then, and then, but being able to do something with that, being able to understand and um, you know, and that that's no career liability here, that, that you're struggling because of something else that's going on. This doesn't mean that you failed. This doesn't mean that you're in a bad spot. This doesn't mean that you're going to be fired. This doesn't mean that you. We're here as a team, you know, collectively. Collectively, we all, we all stand. So, um, uh, and then I guess the other, the other piece of it to kind of help burnout, um, or to help that. That, that feeling of burnout, um, is we have to stop. Just stop punishing mistakes and then. And start celebrating the wins and celebrating the other sides of it, um, because we spend too much time in post mortems and, and just pointing fingers. And this was the problem or this was the. And that was just that, that. How do we learn? Not how do we blame. How do we learn? Not how do we blame m. Because I think we'll all, we all learn collectively from that. And if we do that in a collaborative team session, everyone gets to bring their pieces to it and their, and their, um, um, what do I say? Their experiences from it. And we grow, we grow together with it.
Speaker A: Yeah, it's easy to play the blame game and. Yes. Yeah, that's the easy side of the equation. It's much harder to, you know, do it. Do you do what you said and have empathy and really go through it? Right. Yeah. Um, you know, I have to ask a question. I often see a lot of younger cyber pros, right. They, they love the idea, or maybe it's their goal to become a CISO one day. But yeah, I realized in my conversations with them that there's a lot of misconceptions they have about what being a CISO actually means, you know, versus what they see on tv. Right. Um, yeah, yeah. What would you describe as like, maybe a biggest misconception that, you know, younger cyber professional might have about what being a CISO actually is?
Speaker B: Yeah, I think the first one that probably, you know, kind of sets them back in that chair a little bit is that it's not a technical role. Yeah, it's, it's actually, it's, it's a. Ah, it's. We sell it as being this, you know, security leadership, uh, technical security role. It's, it's, it's, it's not. It's really about the business, it's really about enabling. It's really about not. It's, you know, the right amount of enforcement. Yes. Or protections, controls and capabilities that are put in place. Uh, but it's really about its communication, it's influence, its leadership. Um, and then being able to take, you know, being able to take risks that are there, translate it to the board, negotiate, you know, you know, budget negotiations, making the right investments, the right components, um, you know, inspiring teams. Teams inspiring leadership. Inspiring those. That's, that's managing stress and, you know, managing stress and incidents and keeping that control and bringing that. But it's really not a technical role at all. It's, it's, uh, I think some of the best CISOs I've met, some of the best security leaders actually, didn't maybe had a little bit of it understanding and background. But, but they understand people. They understand. They understand the business.
Speaker A: Yeah. And some, for some, that's maybe something that carries them there. Right. The technical chops maybe carry them to that position. But then they realize they have to kind of retrain themselves and, you know, take on a different Persona to be successful. And that can be difficult, but, um, that is a common thread.
Speaker B: Yeah. And I think daunting for CISOs themselves. I think it can be really challenging. Is that you. So you carry all these technical chops and you get in and go, oh, crap, what have I. You know, here's your title.
Speaker A: Good luck with that.
Speaker B: I mean, off you go. It's like, it's like, it's not like
Speaker A: there's some CISO finishing school that, like, teaches you how to be successful. Right. It's tough.
Speaker B: Spend time with your peers. Spend time with your. Spend time with your. With other CISOs. Uh, that would be my, that would be my advice on that, is that there's lots of resources out there. There's lots of people out there that are willing to share and help. Um, but you have to, you have to be willing to reach out and be vulnerable and ask for that help. Yeah.
Speaker A: So I'm so excited to ask you this next question. It's the billboard question. You know, I've been asking CISOs if you could put a message on a billboard that every new CISO had to read and drive by once a day, what would that be?
Speaker B: Well, I mean, I think, I think the first one is, um, stop being an enforcer and start being an enabler. I think I do. I mean, I, I, I live by that. I really do think that that's an important one. But I, I think, uh, I think if it's for a new ciso, uh, the goal, uh, probably the goal isn't compliance. It's commitment. It's, it's, uh. You're not, you're not here, you're not here to check the box. You're here to commit to the role. You're here to commit to everyone. That supports it. And you're here to commit to the. The overall, uh, journey of the organization. And I think that's so. Yeah, the goal isn't compliance, it's commitment.
Speaker A: Yeah, I like that. A lot of people. Yeah, I love that. That's, uh, catchy too. That's catchy.
Speaker B: Nice.
Speaker A: You might have to trademark that. Yeah. Okay. All right. Um, so, you know, we're kind of nearing, uh, the end here, but just have a couple quickies, uh, for you, other than. Other than your book. Have any recommendations on, you know, books, concepts, philosophies, good podcasts to listen to, newsletters to subscribe to?
Speaker B: Yeah, yeah.
Speaker A: What are some good resources that, you know, you would want to share with the listeners?
Speaker B: Yeah, I spend. I spend quite a bit of time in. In this. In the psychological side of emotional intelligence. So. In the. And yeah. Ah, yeah, yeah, on that side. So, you know, some of the pioneers like Daniel Goldman has there, you, um, know and written EQ Emotional Intelligence. Um, I, I spend quite a bit of time in that. Um, I actually don't spend a lot of time with podcasts specifically on the technology side, because I think that they go into rants that I just don't. It's not that I don't care, I just don' the right message. Um, so. So I do spend, um. It's, uh, been quite. I mean, of course you have to listen to and watch, you know, the certain things that are happening within the industry and what's happening with threat intelligence and, you know, what's happening as, you know, trends. But, um, Um, I, I'd like to. I like to follow along with people, you know, like Goleman's or others that, um, that just. I don't know, that just, Just bring this level of professionalism and bring this level of, uh, of. Of, um, EQ demeanor that just. That's just.
Speaker A: Just.
Speaker B: Yeah, so that's, that's, um. Yeah, sorry, you caught me on that one because I was like, I got a whole list. Now I gotta go flipping through my. Flipping, uh, through my podcast to see. That's like. Who.
Speaker A: Who said. Yeah, yeah, absolutely. Well, we will certainly link to your book when we publish this. Uh, so perfect for. For anyone listening, you know, make sure you, uh, check out Jamie's book because I feel like that's. That's a wonderful resource. Um, and that. Yeah. So last thing I want to ask. Right. Uh, oftentimes we have a lot of people that help us along our journey. Um, and, you know, some more than others, and some are very impactful if there was someone that you could give a shout out or show some gratitude towards, um, or someone that you would want to see come and tell their story on this podcast. Yeah. Who would that be?
Speaker B: Uh, okay, well, first one. Um, so I think. Two. First off, I think you should be flipped around and put in the seat because I think you have a great story and I'd love to interview you in this as well. So anyway, there's one. Let's do that.
Speaker A: Thank you.
Speaker B: There you go. Let's do it. Let's do that. Um, listen, there's a gentleman I've worked with for years. Um, and there's a lot of them. Uh, there's a lot of them. Um, but there's one in particular and, uh, I've been spending some time with him, bouncing some ideas off of him and been working on. And I realized how important or impactful his role is. Um, his name's Tim Keith. Ah, Runs a company called Transform cx. Uh, not a ciso, but, um, they have a product called Bounce Wise iq and it fits very much with employment engagement and asking questions and asking. And I think that there's something there that organizations really need to start to think about. Um, and I think he'd be fascinating for people because. For people to hear his message or talk about. And I say that because, um, it's things that we can all do, Dan. It's things that we can all do to just ask questions of our employees, our resources, um, the ones or folks around us and what that means. And he's just got. It's a great story. So I just, I've been, I've been working with him quite a bit in the last little while and um, we, we just really got a synergy here around this, you know, eq, um, employee engagement, where engagement is so.
Speaker A: Engagement. Right.
Speaker B: Yeah, well. And with all the insider threats, with all the people, all the things that are happening internally and all the, all the bad stuff that happens, man. It's the right, it's the right approach.
Speaker A: Totally. Yeah. I mean you could tell when employees not engaged and sometimes that is a sign of like nefarious things like inside threat, you know.
Speaker B: Absolutely.
Speaker A: Yeah. Uh, well, fantastic. Jamie, this has been so great, uh, you know, hearing some of your story and you sharing it, you know, here for, for the newsletter and for our listeners. Um, really, really wanted to say thank you so much for a. Being a, a good friend and, and um, uh, love working with you and having you here as part of this has just been tremendous. So really, really appreciate you.
Speaker B: I appreciate you. I appreciate being here, uh, uh, and sharing my story. It's been a great experience. Thank you.
Speaker A: Awesome. Thanks, everybody. Cheers.
Speaker B: Thanks.