The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Human Side of Cybersecurity
The Human Side of Cybersecurity artwork

The Human Side of Cybersecurity with Jon Garza, CISO at PSA BDP

The Human Side of Cybersecurity · 2026-04-20 · 47 min

0:00--:--

Key moments - from our scoring

Substance score

48 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber14 / 20
Specificity & Evidence7 / 20
Conversational Craft10 / 20

Jon Garza brings over 25 years in IT and 14 years as a security leader across multiple industries to this CISO Spotlight conversation. Starting from a website defacement incident at the University of Houston Downtown that first exposed him to security threats, Garza traces how foundational incidents like the Melissa worm and ILOVEYOU virus shaped his incident response philosophy. His pivotal career moment came when his CIO mentor Hussein Shiroki recognized the need for a dedicated security role and brought Garza into that position. Throughout the discussion, Garza emphasizes that strong relationship-building within organizations matters far more than advanced tools - security leaders must engage business stakeholders early, build trust before incidents occur, and avoid the "ivory tower" approach. On technology trends, he cautions against both cloud and AI hype, arguing that vendors often rebrand existing machine learning as AI for marketing purposes. Garza advocates the KISS principle: master blocking and tackling security fundamentals before pursuing complex technologies. He frames cybersecurity concepts for non-technical audiences by relating them to personal and family safety, making the abstract threat of bad actors stealing money from halfway around the world tangible and urgent.

Key takeaways

  • →Relationship-building with key stakeholders before an incident occurs is more critical than having sophisticated tools or documentation, as you never want to meet people for the first time during a crisis.
  • →The KISS principle - perfecting fundamental security blocking and tackling - must come before adopting complex or hyped technologies like AI, which vendors often rebrand from basic machine learning for marketing appeal.
  • →Security leaders should avoid isolated decision-making and instead partner with business stakeholders early, framing security gaps and solutions as mutual wins to drive organizational buy-in and execution.
  • →Translating cybersecurity concepts into relatable personal terms - such as the risk of being scammed or having money stolen by remote bad actors - helps non-technical stakeholders understand and become advocates for security.
  • →Pivotal career moments often come from mentorship and early exposure to real security incidents, which leave indelible marks and provide lessons far more valuable than theoretical knowledge.

In this episode

  1. 1Introduction and Career Background in Security
  2. 2Learning from Security Incidents and Professional Scars
  3. 3First Security Incident: Website Defacement at University of Houston Downtown
  4. 4The Pivotal Moment: Mentor Hussein Shiroki and Transition to Dedicated Security Role
  5. 5The Critical Importance of Relationship Building in Cybersecurity
  6. 6Overhyped Technologies: Cloud Computing and AI in Security
  7. 7The KISS Principle and Mastering Security Fundamentals
  8. 8Communicating Security to Non-Technical Stakeholders

Mentioned

Jon GarzaPSA BDPUniversity of Houston DowntownHussein ShirokiAirbnbBrian Chesky

Guests

Jon Garza

Topics in this episode

Incident response planningBusiness email compromiseAI and machine learning in cybersecurityKISS principle (Keep It Simple, Stupid)Cloud security and riskWebsite defacement attacksRelationship-building in security leadershipRansomware incidentsMentorship in cybersecurityMelissa worm

Questions this episode answers

What was Jon Garza's first cybersecurity incident and why did it matter to his career?

His first security incident was a website defacement at the University of Houston Downtown by an attacker group while he was monitoring the lab on a Saturday. That pivotal moment piqued his interest in security and exposed him to foundational threats like the Melissa worm and ILOVEYOU virus, but his true career-defining moment came when his CIO mentor Hussein Shiroki recognized the need for a dedicated security role and invited him into that position.

Why does Jon Garza emphasize relationship-building over technology in security leadership?

Garza argues that having great tools means nothing without the ability to work with people across the organization. Security leaders must build relationships with key stakeholders well before an incident occurs so they know how to collaborate effectively; meeting people for the first time during a crisis is too late and you don't know how anyone will react.

What is the KISS principle and how does Jon Garza apply it to AI hype?

KISS stands for Keep It Simple, Stupid. Garza uses it to argue that organizations must master fundamental security blocking and tackling before pursuing complex or hyped technologies like AI. Many vendors rebrand machine learning as AI for marketing, so security leaders should focus on basics first before getting distracted by the latest red shiny object.

How does Jon Garza explain cybersecurity threats to non-technical audiences?

He frames security threats in personal and relatable terms - explaining that bad actors get up and go to work just like legitimate employees, except their job is to reach into your pocket and steal money from halfway around the world via the Internet. He also relates threats to things that affect families, kids, and elderly parents who can be scammed.

What does Jon Garza say about the cloud security hype from previous years?

Garza notes that many organizations moved to the cloud too fast based on hype, only to later realize that cloud doesn't fix security problems - it just changes or adds different types of risk. Being several years past that phase, organizations have learned that cloud solves some problems but security leaders must address the unique risks it introduces.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains some practical wisdom about relationship-building, incident response, and the KISS principle, but much of the content is relatively generic and well-worn in security circles. Platitudes about learning from mistakes, hiring smart people, and staying current dominate large sections. Few novel, non-obvious claims emerge that would surprise a practiced B2B operator.

you don't want to meet, you know, the key people while you're in the middle of an incident
keep it simple, stupid. I'm reminding myself the KISS principle. Okay, are we doing the basics first?

Originality

8 / 20

The thinking is grounded and sensible but largely reflects mainstream CISO orthodoxy: build relationships, master fundamentals before chasing buzzwords, hire smart people, stay humble. The critique of AI hype as 'machine learning dressed up' is fair but not novel. Few contrarian or first-principles insights distinguish this from hundreds of other security leader interviews.

is it really AI or is it just machine learning dressed up as AI?
If we're not doing the basic things of blocking and tackling, almost everything else doesn't matter

Guest Caliber

14 / 20

Garza is a legitimate CISO with 25+ years in IT/security and 14 years as a security leader across industries. He has relevant operating experience and has clearly navigated real incidents. However, he is not a particularly prominent or widely-known figure in the industry, and the interview does not reveal standout achievement or distinctive domain expertise that would elevate him to top-tier caliber.

I've been in it for over 25 years at this stage, um, getting closer and closer every day toward that 30 mark
I've been a security leader over the course of my career for about, um, about 14 of those years at this stage across different industries

Specificity & Evidence

7 / 20

The episode lacks concrete data, named examples, metrics, and timelines. Early in his career Garza mentions a website defacement by 'Silver Cyber Lords' and references 1990s worms (Melissa, I Love You, Anna Konikova), but provides no specifics on scale, impact, or lessons learned. Most claims are abstract: 'don't be afraid to tell leadership about gaps' or 'stay current on threats' without documented incidents, dollar figures, or measurable outcomes from his tenure.

the website was defaced. It was a website defacement by a third party, you know, some hacker
the Melissa worm. Oh yeah. The I love you virus, the Anna Konikova virus

Conversational Craft

10 / 20

The host (Speaker B) asks coherent, relevant questions and occasionally pushes back or adds context (e.g., the Brian Chesky reference on hands-on management, the framing of bad actors as people clocking into work). However, follow-ups are often soft; the host rarely challenges claims, probe deeper on contradictions, or force Garza to defend positions. The conversation feels collegial and affirming rather than probing.

was it. Is that kind of your. Would you call that sort of your defining moment when you knew that you wanted to be more in a cyber role?
what do you feel like is, you know, sort of overhyped, uh, for sunder?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A66%
  • Speaker B34%

Most-used words

security35different22back19first16trying16cyber15career12keep11sure10learning10leader10moment10help9part9university9john9

Episode notes

In this episode of the Human Side of Cybersecurity, Dan Desko sits down with Jon Garza, a cybersecurity leader with more than 25 years of experience in IT and over a decade in security leadership across multiple industries. Jon shares how his career evolved from early roles in network and systems administration to leading enterprise security programs, and the lessons that shaped his approach to risk, leadership, and cybersecurity fundamentals. The conversation explores Jon’s early encounter with a real-world security incident and how experiences like that leave lasting “professional scars” that shape security leaders throughout their careers. Dan and Jon also discuss the importance of mentorship, relationship building across the organization, and why cybersecurity success often depends just as much on communication and trust as it does on technology. They also examine the trends surrounding technologies like cloud and AI, and why strong security programs still depend on mastering the fundamentals. If you enjoyed this episode, please leave review, it helps more people find the show! Want first access to future interviews?

Full transcript

47 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Garza, thank you so much for joining me here today, uh, on my CISO Spotlight series for my Cyber Intelligence, uh, newsletter. Uh, it has been great getting to know you. And also, um, you know, this. The Spotlight series has afforded me a wealth of opportunities to help tell some stories of some great leaders in our space. Um, so really humbled that, uh, you joined us here today. And, um, why don't you kick things off here by giving us a quick intro of who you are, um, and maybe a quick background on, um, you know, how you came to be where you're at today.

Speaker A: Sure. Well, first of all, Dan, thank you so much for the invitation. I really like what you guys are doing here. Um, I enjoy watching the different videos and. And, uh, what other people are doing. It's so interesting to me, um, and learning from so many other people. Um, so, yeah, I guess a little background on myself. I've been in it for over 25 years at this stage, um, getting closer and closer every day toward that 30 mark, which is a little crazy to say out loud. Um, and specifically in security. I've been a security leader over the course of my career for about, um, about 14 of those years at this stage across different industries with different companies. And all along the way, I've really tried to be cognizant about learning from the different companies I've been a part of, the industries, the uniqueness about them, and. And then when it comes down to it, the different people that I've come across my path, um, and I will say, you know, the good and the bad, and. And, um, I learned from the good. And I tried to take all those elements and carry them on. You know, if I go to my next gig or my next industry or whatever that is. And even the bad things, you know, I think I've. I've taken those to heart and really learned probably more from those situations.

Speaker B: Yeah.

Speaker A: Whether they're my own mistakes. Oh, yeah. Or from mistakes that I've seen. I've, uh, observed others make, you know, and go, wow, I am never gonna do that ever. Yeah. That kind of stuff.

Speaker B: Yeah. I saw a video recently. I've mentioned this a couple times. Um, it was Tom Brady talking somewhere on a stage, right. And he was talking about, like, how he remembers the tough losses more than any of the wins. Uh, yeah, same with, like, poker players. You ask poker players, like, you tell me your top, like, poker stories, and they all describe, like, their. Their worst beats, like, uh, had this, like, terrible beat. Like, uh, you know, an ace on the river. Um, and you know, it's multi time World Series champion poker, uh, champion. Um, but I think that's a great thing to sort of like anchor this conversation is that we learn more from those tough situations than we do, you know, the, the, the big rosy wins. Right?

Speaker A: Yeah. And, and specifically for those of us in the industry where, where we've been a part of cyber security incidents, ransomware incidents, business email compromises, whatever those are that you, that you've been faced in your career, especially the bigger ones, um, those really stick with you. They, they, they leave an indelible mark on your, on your psyche or your soul. Yes, for, especially those, you know, you're up for, let's say a couple of days at a time, trying to, you know, restore things from an outage, um, you know, all of those types of things. I remember almost every second of those types of events. And what I did in those cases, whether I played a small part or whether I played a bigger part, those. And uh, but you learn from them and you learn what to do and what maybe not to do. The next time that you're faced with situations like that, why don't you, you

Speaker B: want to like click in, dig in one of those like a professional scar that maybe like, you know, you obviously don't have to like be super detailed on it, but something that taught you the most, like what's one that comes to mind.

Speaker A: I will tell you, probably my first interaction with a security incident. And this is going way back to my time when I worked at the university. And uh, I'll even say a little bit more. When I graduated, I graduated with a bachelor's in finance. This was course back in the day when there was no cybersecurity degree or even a cybersecurity course at the time.

Speaker B: Yeah, um, this is computer science. Maybe.

Speaker A: Maybe. Yeah, computer science. And it was maybe some developing.

Speaker B: Basically it was coding and developing. Uh, yeah, yeah.

Speaker A: But I graduated with, I started working at the University of Houston downtown in the IT department because I needed a job because I was a poor college student and I was like, hey, I think I can do that. I learned so much during my time that it really set the foundation for my entire career. I made lifelong friends there that I still talk to. Um, and we talk about, you know, remember when we did this stupid thing that was so dumb, uh, around it. And um, I learned so much during that time. But my first interaction with a security related incident was I was working on a Saturday in the lab, the student lab, and I was monitoring the university website and all of a sudden when I did a refresh of the website, as I was poking around, the website was defaced. It was a website defacement by a third party, you know, some hacker. And they didn't do it for any other reason other than that they could. And I think the name, they totally changed the whole web page. They defaced it. And they basically said, hey, you've been had. And it was some goofy attacker group name called the uh, Silver Cyber Silver Lords or some goofy name. Right? Sure, it was probably some, some script kiddies. But um, they defaced it. And that was my first interaction. I'm like, oh my gosh, what do I do? So I started making phone calls. Um, you know, that was my first interaction with that. And I was like, wow, this is, it's crazy, but it's kind of cool. And I took that and that ended up me, me getting exposed to so many other types of um, security attacks. If you remember back in the day, the Melissa worm. Oh yeah. The I love you virus, the Anna Konikova virus. That was all of these different things that were, I remember in my career, some of them, you know. Yeah, overnight, you know, you're up all day, all night long trying to resolve and, and recover from. But they were foundational events in my career that I learned so much from every single one, uh, that I tried to carry on forward to help, you know, make the next one at uh, least the reaction be much better the next time around.

Speaker B: Yeah. And I'm um, I'm thankful you shared that. I ah, think first time any IT cyber professional deals with the first sort of like incident that has clear implications and impact. It's kind of eye opening, right? It, it is really that like everyone has a plan until you get punched in the mouth scenario, Right?

Speaker A: Exactly.

Speaker B: And you're like, holy crap, like this is actually real. Someone from halfway around the world reached out and touched us here. And now I gotta jump into action. I gotta figure this out. Um, I remember, yeah, I remember my first bout with that myself. And if I had done years of advising, um, but then finally had my first like, interaction with a real incident, and I was like very uh, little shook by that. Right? It's, it's, it's. Sure, it's kind of wild.

Speaker A: Um, it's totally different reading it in the news. And then when it affects you and your environment, you're like, it's that oh, crap moment. What do we do? And this was in the days before, you know, the existence of incident. True, uh, incident Response plans. Yeah, we didn't know what that was. We could barely spell incident response.

Speaker B: Exactly, exactly like you said. I mean, cyber wasn't even a word then. Right.

Speaker A: Yeah.

Speaker B: You know, that word came a buzzword, I think, in like, you know, 2010, 11, 12, something like that. Right.

Speaker A: And. Exactly.

Speaker B: Um, now it's a whole industry, uh, which is, which is wild. But, um, let me ask you, John, like, was it. Is that kind of your. Would you call that sort of your defining moment when you knew that you wanted to be more in a cyber role? Because, you know, you, you started more on the IT side, but that was obviously like a moment that stuck, uh, with you. Was, um, that the defining moment for you?

Speaker A: I don't, I don't think that was necessarily the defining moment. I think it was a pivotal moment that first piqued my interest in the area again. At that time, it was a small, burgeoning, just barely growing of a thing area as more and more of these types of attacks started to come about. Right. And, uh, at my university that I worked at, University of Houston Downtown, there was no cyber security director, anyone in that role. It was. Security was a part of everybody's job. Whether you were a dba, whether you were an application developer, whether you were guy. Good idea, you got to have that in there somewhere, Right?

Speaker B: Yeah.

Speaker A: Well, obviously, you know, that approach wasn't maybe the best at the time, but it was all we could do at the time. Right.

Speaker B: Right.

Speaker A: So I had what I guess was probably the biggest moment to get me into cyber was, uh, after being a network admin for many years and being a server admin and even, um, an old exchange email administrator, um, that I used to do back in the day when in the days of email systems were, uh, on premise and having to manage those, um, those are, those were fun days. Um, but, uh, I had a great mentor, um, and who was my boss at the time. Um, he's still the CIO at the University of Houston downtown, Hussein Shiroki. And he saw the need to have a dedicated security role at the university. Wow. Uh, and he approached me about the idea of, of getting into that role. And if, if it wasn't for that, I probably wouldn't be sitting here talking to you. So that was if that was a pivotal moment. I think that was really the, the pivotal moment. And I was like, yes, yes, this is great. And then we started talking about philosophy, you know, at the time and, and, and how react to certain things. But I think, um, the different things that I did, of course across the course of my IT network, admin, server admin, all of that career helped kind of lay that foundation for me to be able to get into cyber. And I think I don't know exactly what he saw in me but I think he saw something that how I was going to be able to relate into that world and then bring that heightened awareness to the rest of the organization.

Speaker B: That's amazing. Um a I think it highlights the foresight that a great leader that you worked with saw you that as an important part of what needed to be addressed there at the university. But also you know he had you in mind for that. Um, it sounds like you had a wonderful relationship with him um to begin with.

Speaker A: I did and I still do to this day. Uh, we still talk um, yeah none of us get here where we are on our own and it's only with having key people in your corner and key mentors along the way um that we end up where we are and help us. And um, I, I hope that I have, I've um, made attempts to try to do that myself. Yeah kind of you know pay back and I hope to continue to do that through the rest of my career but only because of, of examples of, of of him doing that for me.

Speaker B: Let's click on that a little more. And the power of relationships. You and I were talking a little bit about that before the call started and yeah how, how important that is in this field and it seems like a big field but I think in comparison to like other professions it's really not um and you know it's a small industry with um, I would dare to say very driven by relationships. Everything from how, how and who you learn from to how you can you get ahead or find opportunities for yourself or just be taught new things like. Yeah tell me, tell me you know about the importance of relationships in your

Speaker A: life as uh, the more that I got into security as a security leader um and trying to understand different organizations, um, you've got to talk to people having the cool hacking tools and, and the greatest whiz bang technology out there is great and you got to have some of that but you're never going to be successful in almost any career without really good relationship building skills. And when it comes to security and especially when you're coming new into an organization you're going to have to build those relationships and understand who to tap this on the shoulder when you need it. And but you've got to start that early on. There's a saying that goes yeah, you don't want to meet, you know, the key people while you're in the middle of an incident? No, it's almost, it's almost too late because you don't know how they're going to react, and you don't know how you're going to react.

Speaker B: Amen.

Speaker A: So you got to do all that getting to know you stuff with those key people way in advance of that because you know it's going to go ahead.

Speaker B: I say that all the time. It's so funny you're saying this. Um, one of our key pieces of advice when we're working with a client, we see, like, they haven't put much thought into their instant response planning or like, their whole idea is, oh, yeah, we've got a document and we've got a insurance policy. I'm like, well, does anyone on the other end of that insurance policy, like, know who you are or, like.

Speaker A: Right.

Speaker B: Know your name or, like, what your systems look like? And our advice is always, My advice is always like, you never want to be saying, how do you do, uh, on your worst day.

Speaker A: Right, Exactly.

Speaker B: You got to build those relationships so early. And that's so true across, like, everything we do.

Speaker A: Absolutely. And so that's why, you know, um, whether you're coming new into an organization or you're in an existing relation, uh, organization for many years, you still have to have those relationships. And that can be when you're talking about dealing with incidents. It can be when you're just trying to solve a problem in the organization or address a gap. You've got to go, you know, maybe talk to the other business leader that it might be affecting the most and say, look, we found a gap. This is what we're proposing to do. I need your support. And most of the time, if you're reasonable, they'll come along and say, look, this is going to be a win for you. It's going to be a win for me. At the end of the day, it's a win for the entire organization. Let's go do this right.

Speaker B: Amen. Uh, yeah.

Speaker A: And. And that's how you really get stuff accomplished. But, um, I've seen so many people take the opposite approach. So many security leaders say, all right, I'm gonna sit in my ivory tower and say, you know, thou shalt do this and thou shalt do that. And then meanwhile, I'm going to sit back and just see if it happens. Well, good luck, because most of the time, it's not going to work like that. That approach doesn't work. You can Attract more bees with honey than anything else. And that's not the way to do it, you know.

Speaker B: Amen. Yeah, I think I was, I heard Brian Chesky, uh, the founder of Airbnb, uh, once and you know, they talked about like, you know, growth and how things start to get siloed and um, layers of management. And I think it was him that said the only way to manage the work is to be part of the work. Right. Like, there is no magical like management layer where we sit around and talk about feelings and um, you know, it's all related to the work. Right. And sure, the most effective managers, like, understand and can opine on what's happening and how to make it better and how to try new things and to work through the actual problems at hand together. And I think it takes that hands on approach. And yeah, to me, cyber security is very much like a apprentice mentorship field. Right. Like you, you said it. I'm, I'm, um, in the same boat. Like, I learned from so many great people coming up that I still have a relationship with today. If it wasn't for them and the opportunities they gave me and the like, little chances I took along the way, I would not be here right now for sure.

Speaker A: Yeah, none of us get here on our own, regardless of. And if anybody says that.

Speaker B: Uh, yeah, totally. Yes, totally.

Speaker A: Yes, absolutely. Yeah, absolutely.

Speaker B: I agree. Um, awesome. Uh, John, I would love to hear like, from your perspective and in your seat, you probably have a new unique perspective on this also given your industry, um, and you know, that you work in today is definitely also very unique. Um, we talk a lot about like, overhype under hype, um, in this field and Lord knows, like, there's a lot of stuff that's hyped. I mean, the marketing campaigns and dollars behind some of the solutions and tools and uh, you know, there's a big, there's a big grab for security budgets. Um, from your perspective, John, like, what do you feel like is, you know, sort of overhyped, uh, for sunder?

Speaker A: Well, I think, you know, I go back to earlier when, you know, cloud was kind of a thing and everything was cloud, cloud. We got to move everything to the cloud. A lot of hype around that. And I think, you know, being several years past that phase, there's a lot of organizations that probably, you know, they, they went out too far ahead too fast. And then now, as you've seen some organizations kind of pull back and say, you know what, going to cloud doesn't fix all of our problems. It fixes Some problems. And then for those of us in security, it definitely doesn't solve any security risks. I think it just changes or adds a different type of risk.

Speaker B: Right, yes.

Speaker A: Um, and so now with the latest thing that's out there, it's not even a buzzword anymore. There's reality around it, around the use of A.I. um, I was at a conference recently where M. It's a bunch of security leaders sitting around without vendors in the room. And we're guilty of this. Where it's been, it was created and designed for us to sit around and talk about different security challenges we have. And they come in with a set agenda of two or three items. And then from there the conversation just supposed to flow. In this particular session that I was in, there was no mention of AI at all. And I think it was by design, but not even three minutes into the conversation. AI Somebody inserted AI into the conversation. I get it. It's reality of what we're dealing with on the day to day right now. But I think when it comes to kind of philosophy, uh, I love AI. I use it all the time now for certain things at the same time. But the philosophy that I have prescribed personally to is myself and I try to promote amongst my teams is keep it simple, stupid. I'm reminding myself the KISS principle. Okay, are we doing the basics first? If we can't do, um, I'll go with the old football analogy. If we're not doing the basic things of blocking and tackling, almost everything else doesn't matter. You've got to be able to perfect the fundamentals first before we start to get too fancy. And it's security. You've got to do a lot of the basic pillars of, uh, protection and uh, just security principles first before you start bringing in the complexities that AI brings in and, or any other technology for that matter.

Speaker B: And even in, we'll call it some of these frontier technologies like AI or where cloud was, you know, 10 years ago. The KISS analogy, uh, applies there too, right? Like, yes, at the end of the day, I think the hype often comes from this gap in understanding. Like, yes, it feels like hype because you don't actually understand maybe the actual capabilities yet. And m. When you start to like unpack what, you know, AI is doing, whether it's like the agentic stuff or LLMs, um, you start to learn it and how it's operating, what it's doing and oh, okay, this is like a fancy word tumbler that's making educated guesses based on like my, like Very vague input. Right, right.

Speaker A: And I think what we have to be careful of is that um, you know, a lot of organizations, a lot of, especially people that are selling products, it's like they're required to put AI in their marketing stuff, their plan.

Speaker B: Oh yeah. Oh yeah.

Speaker A: But sometimes if you really look under the hood, is it really AI or is it just machine learning dressed up as AI? And I think many of us, uh, when you look into the details of it, oh, it's just machine learning. We've been doing this for years. But AI is the big buzzword of the time. I get it. And I'm not saying that AI, true AI is not, is particularly overhyped. I think there's a huge amount of potential of what we can do from an industry or even as the technology, uh, with AI. Um, definitely, I think more so than if, you know, back to my cloud analogy, I think we can do a lot more from AI perspective than we ever could even with cloud. Um, but I think we have to be really careful of again, don't get too focused on the red shiny object. If we're not taking care of the basics first, then we can focus attention on that.

Speaker B: Amen.

Speaker A: Amen.

Speaker B: Yep. Totally agree. Um, I'd love to ask, are there any uncomfortable truths that you see in our enterprise security today?

Speaker A: Uncomfortable truth?

Speaker B: Yeah, I think people think, yeah, like people think, you know, they have this idea about cyber security, but really under the hood, um, you know, it's a whole different, uh, vantage point that you see things from.

Speaker A: Yeah, Um, I think it depends on your audience. Right. And I think I get the most fun out of, or enjoyment out of talking about what we do to people that don't live it on the day to day and so other parts of the business, helping them understand what we do from a security perspective and breaking it down, going back to my kiss principle, breaking it down into the simplest terms that they can relate to and maybe say, well, this can be an issue for you perhaps in your personal life, your family's life, your kids life, your elder parents, elderly parents can be affected by this stuff. Right. Because they can get scammed. Um, if you can frame what we do in those, in that kind of a context, I think the non technical person is much easier to grasp a lot of these concepts and then they can, you know, if, if you really again back to the relationship building, you can make them possibly an advocate of cybersecurity inside and outside of the organization because it really affects everybody at some level and it can personally and in your Career. So.

Speaker B: Yeah, yeah, I, I hear what you're saying and I liken it to this idea of like what I tell people that aren't in this field, that there are bad guys that get up and go to work and clock in just like we do. But their job is to reach into your pocket and take your money. Right?

Speaker A: Yes.

Speaker B: And you know, just with the Internet and the way things are, that they get to do that from halfway around the world.

Speaker A: Right.

Speaker B: And uh, when, when we explain that uncomfortable truth and people realize that that is the world we live in, like it becomes real. And then like people like you and me can actually tell stories of like how we see this in our day to day.

Speaker A: Sure.

Speaker B: And you know, I think for us we're so used to it, right, because we see all the bad things that can and do happen.

Speaker A: Uh, yeah.

Speaker B: But you know, for the non initiated, you know, those that aren't in our field that are out there, uh, that's, that's sometimes jaw dropping for them to understand.

Speaker A: Absolutely, absolutely. And I think if I draw back to another uncomfortable truth for security leaders, especially when you're talking to, let's say your C suite or your board, I think there's some of us that prefer to take the approach of when you're giving a, uh, kind of a state of the union of your cybersecurity program to the board, hey, everything's great. We're doing this, we're doing all these things. Everything is awesome. But I don't think you're doing yourself any favors or your organizations any favors if you take that approach. So my uncomfortable truth would be don't be afraid to tell those, especially those that hold the purse strings, where you have some serious gaps, where you have some real true challenges. You know what we've been, we've been trying to, you know, hammer our head against this particular problem and we're not having any luck. Um, now at the same time, you got to come up with some solutions. You just can't come to them with problems. You got to have some, some possible, uh, opportunities to resolve those. But maybe you need their assistance to uh, remove some barriers so that way you can get those problems solved. But don't be afraid to bring those issues to light to those folks because that's what they're looking at you for as the security leader. They've got tons of other things to worry about on the business side, but if you don't tell them you got an issue here that needs some addressing and you, maybe you need some support, whether that's you know, financial resources, some other type of resources or help in other parts of the business that maybe you haven't built a relationship on. Try to see them hopefully as an advocate for you and hopefully they view you in the same way. But again, it goes back to, you got to have those conversations early on because. Build those relationships so that way you can have those difficult conversations because, uh, if you just tell them everything's great, that's not, you're not going to really solve anything there.

Speaker B: Yeah, totally agree. And you have to have that relationship capital in place to be able to like, have a real moment and say, like, I understand there's limitations or whatever it might be, but I really want you to understand how this could hurt us, like if we.

Speaker A: Exactly.

Speaker B: If we don't fix this thing or if we go on like the way we're going on today. That, uh, is your decision, but I want you to understand the realness behind it and this is how we could get hurt from that.

Speaker A: Right. And I think oftentimes that you might need to pull real world examples of that particular gap. Yeah. That has affected other companies either in your same industry, in different industries. And then it can start to be real. It can't be a manufactured risk. Right. Yeah, it's got to be. You got to make it real for them.

Speaker B: A fairy tale, like a fable, right?

Speaker A: Like, exactly.

Speaker B: Uh, yeah. Take the examples from Dan's, uh, Cyber Intelligence Weekly newsletter. Print them out and show them to your audit committee. Like, this is what can happen.

Speaker A: Uh, right.

Speaker B: Shameless plug. Shameless plug, yes.

Speaker A: Good insertion there. Good insertion, absolutely.

Speaker B: Uh, John, let me ask you, I mean you, you've obviously have been a great leader in the space and um, one thing that we know about our great cyber professionals is that they truly see this as like, ah, you know, war between the good guys and the bad guys. And they're out there to fight the good fight every day. And there's obviously no like, shortage of work for us to do on a daily basis. Right.

Speaker A: Um, yeah.

Speaker B: So what, what, what are some strategies or solutions that you found have worked well to help, like make sure your team stay fresh and healthy and uh, effective?

Speaker A: I think, um, you know, there's the concept of professional development that I think as a leader, we have to support our, our teams.

Speaker B: Yep.

Speaker A: And have them, whether that's attend a conference or uh, meet with some sort of, you know, local community group, like, like a B side kind of thing or.

Speaker B: Yeah.

Speaker A: Or something like that. Um, get out there and, and open your mind to what else is going on out there. I think at the base of that is you've got to keep learning. Right. But I. I'm just a guy learning in this space like everybody else, every day.

Speaker B: Yep.

Speaker A: Uh, and. And hopefully I pick up some things along the way that I can bring to my team and have them, you know, go and investigate or maybe they can put in practice and see if it works. And you know, what if it doesn't work? Okay, well, then we'll go try another thing. Um, you know, Alex, uh, Alexander Graham Bell, what he took. I don't know what the number is. How many attempts at trying to, uh. Or no, Thomas Edison. I'm sorry, with the light bulb. Yes, Edison with the light bulb. How many attempts?

Speaker B: Hundreds of attempts. Right. Yeah.

Speaker A: Until he finally was successful. Right. So you've got to keep trying and pivoting and trying to figure out what's the best way we can address this. Trying to take that as an example of don't be afraid to. To fail. Now, I will say you. You've got to test some things. Right. I will. I will say back in the day, I was guilty of trying something out in technology and it failing miserably because I didn't test it. Well, you know what? I never did that again.

Speaker B: Yeah, exactly.

Speaker A: You kind of learned from that. Right. So you don't want to fail. Fail in an extraordinary way because you've tested it. Right. So I. I put some caution there with the, uh, trying new things concept.

Speaker B: Yeah.

Speaker A: Right.

Speaker B: Yeah. Yeah.

Speaker A: But only because I've done that. I've made those mistakes in a measured way. Totally. But going back to, um, the professional development. Yeah. I. I like to promote my teams to get out there and learn in different things. And. And yeah, you don't have to go to a conference. You could just read stuff online, you know, play with AI agents or whatever.

Speaker B: Exactly.

Speaker A: All those kinds of things. Because I enjoy doing that stuff.

Speaker B: Yeah. M. Me too. And I wish I had more time to do more of it. And cyber is one of those unique fields where I think there is so much of that out there for us to consume and learn from.

Speaker A: Totally.

Speaker B: Like, that's what kind of drew me in in the early days was like, wait a second, you mean all these, like, tools and, like, information? This is all, like, freely available and open source. Yeah. Because, like, the good guys want to work together. Right. And. Yeah, like, that's awesome. Right. And so there's lots of opportunities to do that.

Speaker A: Totally. It's. You're. If you're not constantly learning in this business. You're doing it wrong, man. You just are.

Speaker B: Yeah.

Speaker A: Um, because this stuff changes so fast. You have to keep up with the times. Yep. To keep your skills fresh. And that's for leaders, and that's for. For technical folks, too.

Speaker B: Yep. I. I honestly, you know, it's hard for me to, like, point out another field where I feel like you have to stay so sharp with new stuff all the time.

Speaker A: Um, yeah, the threats are coming out, they're evolving. And if you don't evolve, belong to how to, you know, in terms of your way of defending against those. Those threats and attacks, then you're going to fall just that much further and further behind. Yep. Um, and you're going to put your company at risk and, you know, and potentially you put your own career at risk if you're not doing those things.

Speaker B: Thousand percent. Yep.

Speaker A: Yeah.

Speaker B: Um, so, John, I talk to a lot of younger folks coming up in the industry a lot. Right. And, um, whether it's meeting them at conferences or they apply for. For jobs here, and I hear from a lot of them that, like, yeah, like, I want to be a ciso, you know, um, like, okay, why, you know? Uh, like, tell me your thought process. Like, I know, like, it sounds like it's the pinnacle job in a cyber career in a lot of ways. Um, but I think they often have a misconception of, like, what that actually entails and what that means. And, uh, I would love to hear from you, like, what. What are some misconceptions, um, that you think, you know, they have, and what does it actually mean to be a ciso? Like, what are some of those things they're probably not thinking of?

Speaker A: Um, I had someone reach out to me on LinkedIn that I kind of knew through another connection, and they wanted to talk to me exactly about this, uh, a few years ago, and I don't think I gave them the answer that they were expecting. I think they were looking for kind of an easy button.

Speaker B: Yeah.

Speaker A: And I'm like, yeah, dude, there. There was nothing easy about how I got to sit in this chair. And then the other side about that is, be careful what you ask for or what you wish for, because, I mean, when I kind of got into that kind of a role where you're head of security, you know, what name, whatever the title is, CSO, but, uh, the end of the day, you're the security leader. Um, there's a lot more that you have to worry about. Um, but, so, okay, now you're here, then you kind of ask yourself now what, where's the uh, the magic potion? Oh yeah, that doesn't exist. There's no magic button here that's going to help solve all the problems. And you have to be really humble in your own self and say, I don't have all of the answers either. But now you're tasked with, you got to go out and find the answers and reach out to whoever you need to, to figure that stuff out. Um, but it, it, you've, you've got to be willing as someone coming up, you got to be willing to get your hands dirty for one. And it may not be in the thing that you think is going to get you directly to security. It's got to be in different aspects of technology. Whether that's database administration, whether that's code development, whether that's um, being in the help desk area. Um, you've got to get exposed to different parts of IT organization to see how they function. But then if you're able to pivot and go into a different area and learn a different one there and then after a little while get exposure to a different part. I think if you're able to do some of that over the course of a few years that can set a foundation for you along with the interest in cybersecurity and knowing some of these concepts that can help you lay that foundation of. Okay, now maybe I can, maybe I can take the leap into that. And again, hopefully you gotta, uh, you gotta have the right mentor kind of recognize some of that in you. But you have to have the right aptitude, uh, of constant learning and constant education. And while certificates are great, they serve a purpose. Um, you just have to have that kind of innate learning in your DNA that you just constantly want to be learning something new, uh, in technology.

Speaker B: Absolutely. Yeah. And you don't always have to be the world's foremost expert, but you got to stay on top of it. So at least like you're, you know how to delegate to your team or to the right person on your team to be the expert. Right, right.

Speaker A: And you got to hire people when you, when it comes to bringing people onto your team. Yeah, you want to hire really smart people. I know other security leaders that they, they want to be the smartest guy in the room. They're afraid of bringing these other folks in even with different skill sets. I think that's a big mistake, you know? Yeah, you've got to, you've got to be humble. Humble in your, in your own self confidence that you can handle that. And uh, but at the End of the day, you've got to hire them, because hopefully they're going to make you shine and help protect the organization, which is, by the way, that's why you're there.

Speaker B: Look, I say it all the time, John. I am lucky that, uh, I founded this company, because I don't think I'd be able to get a job here otherwise, at this point in the maturity of this. This company. Um, and look, you're doing it right. Yeah. Right.

Speaker A: You're doing it right.

Speaker B: I. I don't want to be the guy that has to feel like I have to answer every question. That's impossible. Right. There's great smart people out there, and, uh, I'm good at my thing, and they're good at their thing, and, you know, that's, uh, that's. That's a great way to look at it.

Speaker A: Uh, absolutely. Yeah.

Speaker B: So one of my favorite questions, I love to ask if you could put a message on a billboard that every new CISO had to read once a day when they drive by it on their way into the office, what would that say and why?

Speaker A: Uh, I'd want to put this on a billboard for other CISOs, and probably for my own kids, too, to see. And I'll go back to the KISS principle. Keep it simple, stupid. Don't get too complex in your own thoughts.

Speaker B: Yeah.

Speaker A: You've gotta really accomplish the basics and make sure that you're doing that. Go back to the basics. Are we doing some of the things. Are we putting MFA on all of our accounts? Are we doing the right things around our password security policies?

Speaker B: Is, uh, the operating system secure and patch, like. Yeah.

Speaker A: Yes. Those. Those really. Those basic fundamental things, you've. If you've got to do those really well. And by the way, when you asked me earlier about how my week was going, when you really think you've got that accomplished, something will pop up out of almost nowhere. Uh, uh. And then you ask yourself, how the heck did that happen?

Speaker B: Yep.

Speaker A: When it comes to you, you thought you just had it covered. And right when you thought you did, something just pops up out of the ground. You go, oh, my gosh. Are you serious?

Speaker B: Yep.

Speaker A: Are you serious? And then. Okay, then. And that kind of. It's kind of like. I'll, uh, use another sports analogy. It's kind of like golf. I like to play golf. I'm not good at it, but I enjoy getting out there. Uh, but there will be, over the course of a round of golf, a shot that you take that you're like, wow, it's Amazing.

Speaker B: Oh, yeah.

Speaker A: And then you're like, I love this. And you can't wait to get to the next hole or get to the next, play another round the next day. And then you get out there and then you realize, oh, my God, it's terrible. That's terrible. What happened to that thing that I just did before? I can't replicate it now. Um, so. Right. But you do keep coming back, right? Because you, because you have that in the back of your brain, you're trying to repeat that feeling, try to repeat that, that golf stroke that you had.

Speaker B: Amen.

Speaker A: Um, but you've got to just kind of keep that there. Um, so that way you're, you're trying to, I guess, all right, you're, in some way, you're kind of striving for, you know, whatever you want to define greatness as.

Speaker B: Yeah.

Speaker A: But, um, that's what you're, you're trying to shoot for. But, um, yeah, that's, that's just kind of how. How I look at it.

Speaker B: That's great advice. That is great advice. And that's a, That's a great saying. And, uh, I think it's easy in this field to get lost in, in your thoughts and to let some of the hype trickle in and start to take your thought process in a lot of different ways. But if you have systems to keep things simple and make sure you're executing on the, the basic things, well, uh, that's a recipe for success. And then eventually it allows you to focus on, you know, the other stuff.

Speaker A: Right? You, you still got to worry about it, and you, and you probably still will worry about the more complex types of attacks, but there's probably a larger portion of the attacker population. They're going to go after the easy stuff because that's just how humans are. Yep.

Speaker B: Yep. Well, John, I know we're, uh, we're getting close on time here, and, um, I wanted to ask you kind of final question. Uh, you mentioned you've worked with a lot of talented leaders and co workers and colleagues, uh, mentors, etc. Um, if you had someone that you could shout out and, you know, show some gratitude for, who, uh, would that be?

Speaker A: Um, so the gentleman that I mentioned earlier on, uh, my, My original mentor, uh, Hussein Shiroki.

Speaker B: Yes.

Speaker A: My, uh, he was my, my cio, uh, for my first security role, first security leader role at the University of Houston downtown. Um, he's still, he's still doing it, and he's still doing it strong.

Speaker B: Amazing.

Speaker A: Um, he's a guy that he just Loves technology, and he loves getting into the details. His background. He's an, uh. He's an old programmer, an old developer guy at heart. Uh, and I will tell you, he will get into the weeds. When I was in security, he was sitting there next to me when I'm, you know, trying to browse through different logs, when I'm trying to invest, do an investigation. Yeah, I'm like, don't you have something more important to do? And he did, but he enjoyed it just as much as I did.

Speaker B: He sounds like a teacher. He sounds like he's very into teaching.

Speaker A: Um, I don't. He. I don't think that he knew what he was doing. Maybe he did. I don't know. I should ask him. But, uh, I definitely learned a lot from him, for sure.

Speaker B: That's.

Speaker A: And there's things that I. That I keep, uh. I try to carry on in my own career as a security leader and try to emulate that, um, and share that with. With other folks. Yeah.

Speaker B: Well, thank you to Dr. Shropke for, uh, helping, uh, mentor and guide you, because we wouldn't be having this conversation today if that didn't happen, so.

Speaker A: That's absolutely true. I wouldn't be here without it.

Speaker B: Amen. Well, John, hey, it's been fantastic, uh, having this conversation with you and, uh, really appreciate you being part of this, uh, this podcast. And, um, you know, really appreciate your, uh, leadership, uh, and, uh, the relationship we have. So thank you so much.

Speaker A: Thank you, Dan. I appreciate it. Love what you guys are doing. Keep doing it. Awesome.

Speaker B: Ah, have a great one. Thank you, John.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your ProblemsThe Backup Wrap-Up · on Incident response planning88 / 100
  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Business email compromise86 / 100
  • ACH Rule Changes for 2026: What Treasury Needs to KnowThe Treasury Update Podcast · on Business email compromise85 / 100
  • 2026 Payments Outlook: Staying Ahead of AI-Driven ThreatsThe Payments Podcast · on Business email compromise81 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Business email compromise80 / 100
  • Domain Security Plus BlackHat USA 2026 Interviews from Balance Theory and WiCyS - Ihab Shraim, Greg Baker, Lynn Dohm - BSW #460Business Security Weekly · on Business email compromise75 / 100

More from The Human Side of Cybersecurity

All episodes →
  • The Human Side of Cybersecurity with Luca Desko | A Special Episode with Dan's Son21 / 100
  • The Human Side of Cybersecurity with Adam Markowitz, Founder of Drata62 / 100
  • The Human Side of Cybersecurity with Adam Gunnett, VP of BI & Strategy at Busy Beaver63 / 100
  • The Human Side of Cybersecurity with Dawn Cappelli, Head of OT CERT at Dragos78 / 100
  • The Human Side of Cybersecurity with Jamie Giroux, CISO at Platinum Equity59 / 100
Explore the best B2B Engineering & DevTools podcasts →
All The Human Side of Cybersecurity episodes →