The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Leadership/The New CISO
The New CISO artwork

CISO 3.0: The Playbook for Delivering Impact and Influence

The New CISO · 2026-06-25 · 58 min

0:00--:--

Key moments - from our scoring

Substance score

51 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft8 / 20

Walt Powell draws from his extensive background as a former CISO, educator, and author to outline what success looks like for security leaders stepping into field advisory roles. He emphasizes that becoming a field CISO is fundamentally different from being an operational CISO - it requires developing new skills around trust-building, staying technically current, and understanding sales cycles, rather than simply having been successful in a CISO seat. Powell discusses the concept of "eminence," using examples like his book CISO 3.0 to illustrate how field CISOs must build credibility and brand. He explains the measurement challenge: field CISO programs are expensive and difficult to prove ROI on, so he's structured his organization around four measurable pillars including embedded customer accounts, research and thought leadership, go-to-market collaboration, and internal enablement. Powell also shares how he prepares new field CISOs through 90-day onboarding programs and discusses what causes failure - typically stale technical knowledge, poor sales cycle understanding, or inability to adapt from authority figure to trusted advisor. For security leaders considering this career path, Powell stresses it requires intentional brand-building and ongoing learning.

Key takeaways

  • →Field CISO roles require fundamentally different skills than operational CISO positions, including sales acumen, advisory positioning, and the ability to influence without authority.
  • →Personal brand and eminence are critical assets for field CISOs - one or two bad client meetings can permanently damage credibility and make sellers unwilling to bring you into opportunities.
  • →Staying technically current is essential; CISOs moving to advisory roles often fall behind on cutting-edge topics, making them appear stale to customers seeking forward-looking guidance.
  • →Field CISO programs should be measured across four pillars: embedded customer accounts, research and thought leadership, go-to-market enablement, and internal organizational support.
  • →Transitioning from practitioner to advisor requires mastering consultative skills like asking the right questions and positioning yourself as a trustworthy voice rather than the ultimate authority.

Guests

Walt Powell

Topics in this episode

Post-quantum cryptographyField CISO rolesCISO 3.0 (book)Personal brand and eminenceISC Squared CISSP examCISO Evolution (Matt Sharp)Embedded customer accountsSales cycles and buyer-seller dynamicsThe Speed of Trust (Covey)Global Security Strategy Office

Questions this episode answers

What do field CISOs actually do different from regular CISOs?

Field CISOs transition from being people leaders and decision-makers to individual contributors and advisors. They work with multiple customers, advise on security challenges, and must understand and influence sales cycles - while having no direct authority over outcomes, making it a fundamentally different role requiring new skills.

Why do some CISOs fail when transitioning to field CISO roles?

Failures typically result from stale technical knowledge that falls behind cutting-edge topics, misunderstanding sales cycles and political landscapes, or inability to shift from being an authority figure to a trusted advisor. Once brand credibility is damaged through poor meetings, sellers stop bringing them to clients and recovery is extremely difficult.

How should new field CISOs be prepared before working with customers?

Walt recommends a 90-day onboarding period where new field CISOs shadow experienced colleagues, deeply understand the company's offerings, stay current on industry trends, and understand expectations before being put in front of clients - though even with preparation, not everyone succeeds in the role.

What does eminence mean for field CISOs and how does it help?

Eminence is building personal credibility and authority through activities like writing books, speaking, and research. It provides instant credibility in customer meetings and helps sellers land conversations with CISOs by being able to say 'we have the person who wrote the book on being a CISO.'

How do you measure the value of a field CISO program if there's no sales quota?

Walt's organization breaks value into four pillars: embedded customer accounts (repeat engagement, not one-time advice), research and thought leadership, go-to-market collaboration, and internal organizational enablement, rather than trying to attach direct sales attribution.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

There are genuine, actionable ideas scattered throughout - strategic debt, the CFO green-arrow analogy, the 30-60-90 plan during interviews, asking about D&O insurance pre-hire - but these are buried under extended CISSP test-reminiscing, book-writing war stories, and the host narrating his own career for long stretches. The insight-to-filler ratio is below average for a 58-minute run time.

there's a term that I coined some years back, I call it strategic debt. It's kind of the opposite of technical debt. So if technical debt's all the stuff you should have gotten rid of and didn't, strategic debt's all the stuff you should have done 10 years ago
I would tell you to write your 30, 60, 90 plan after the second interview. Like, if it looks like it's serious and you're headed down that path

Originality

10 / 20

The CFO green-arrow analogy for exposing CISO board communication failures is sharp and memorable, and 'strategic debt' as a coined framework is a genuine contribution. Most other material, however, recycles standard CISO career orthodoxy: speak the language of business, use carrots not sticks for phishing, build your personal brand.

If the CFO walked into the boardroom and said, I can't tell you what last month's financials were, but I can tell you that they're, uh, up Green Arrow...He'd be drummed out...We come in and we do that stuff all the time
the two big strategic debts that I find almost every organization have are identity governance and data governance. And they're impeding folks now

Guest Caliber

13 / 20

Walt Powell is a genuine practitioner with real credentials - ISC2 exam development, authored two niche books, runs a multi-person field CISO program, and has observed dozens of security programs up close. He is not a career conference speaker, but he has transitioned to the vendor advisory side, which mutes some practitioner sharpness.

I've written a couple of books. I wrote a book called CISO 3.0 about how to be a good CISO basically
I'm part of the ISC Squared exam development group now

Specificity & Evidence

9 / 20

Named references to Matt Sharp at Crocs, Gary Fish and Fishnet, John Candillo, ciso3o.com downloadable resources, and a $300 token bill all add texture, but the episode's core advice on board communications, skills gaps, and program measurement floats almost entirely at the conceptual level with no hard data, budget ranges, or outcome metrics cited.

my friend Matt Sharp, who I worked with back in a former life, became the CISO of crocs
I accidentally spent $300 one night and tokens and didn't see that coming

Conversational Craft

8 / 20

The host occasionally lands a sharp follow-up ('lose money - unpack that'; pressing on how the four pillars translate to traditional CISOs) but routinely hijacks the floor to narrate his own CISSP experience, book-writing thoughts, and career history for minutes at a time. There is no meaningful pushback on any of the guest's claims.

Lose money. Like I wouldn't expect that you would...But you say lose money, uh, unpack that
can you take or do you recommend These four pillars and one sort of measure into a traditional ciso. Can you overlay that thematically?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B60%
  • Speaker A40%

Most-used words

ciso69cisos27security27book24build18back18sure18field17team17part16didn16value16folks16seat16first15land15

Episode notes

What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook - why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens. Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades. He and Steve break down the four pillars Walt uses to measure his team - embedded advisory, eminence building, sales enablement, and voice of the customer - and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.

Full transcript

58 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Brought to you by Exabeam. I'm Steve Moore and this is the new ciso, Walt. Thank you so much for being here. Uh, as I ask every guest and as the way I say it most every time for the uninitiated, who are you and what do you do?

Speaker B: Yeah, my m name is Walt Powell. My title is lead field CISO. So I'm, uh, a recovering CISO that leads a team of former CISOs who, uh, got tired of having real responsibilities and thought it would be more fun to talk, uh, to customers about their challenges and help advise CISOs, especially new CISOs, on how they can do the job. And we also are part of this thing called the Global Security Strategy Office. So we do a lot of like, learning about cutting edge topics and trying to be out on the forefront of what's coming so that we can help, uh, CISOs tackle those problems too.

Speaker A: So what's the best part of that job?

Speaker B: There's several. So part of it is that nobody's, uh, calling you at 2 in the morning, hair on fire problem, but also you get to dig into cool new problems. You get to meet lots of people. You get to see lots of programs. You get to see the good, the bad and the ugly. And it's like you get to have more careers than you could ever have on your own. You get to see all these organizations and all the ways that they build their programs and you can share that information with others. And that, to me is really cool and rewarding.

Speaker A: A, uh, veritable cornucopia of programs to go in and have a look at. And yeah, I completely agree. We're going to get way more into that. Uh, but I first want to talk about just sort of your genesis story, as I do with every guest. And you had, I think, an interesting one, an element of teaching. Tell us about that.

Speaker B: Yeah, so I started off way back in the olden days teaching, networking and then security at a university level. And I'm talking like pre stateful firewall days. So like, we barely even called it cybersecurity at that point. And then I moved over to a, to a company called Fishnet, which I think you have to be an old head to remember them too. Um, but Gary Fish is a serial entrepreneur and has done several things since then. So you may be familiar with Sideris or Firemon or any number of other things he's done. But back then I, uh, was teaching CISSP boot camps and F5 classes and checkpoint classes and things like that. But that's how I got involved with ISC Squared. And I'm part of the ISC Squared exam development group now. And so if you've ever tried to take your CISSP test and said, what idiot would write these test questions? I'm part of the team of idiots that writes those test questions. So sorry about that. I've done every job you can think of on both sides of the table. I've been every kind of pre seller, I've been every kind of practitioner. I've done all the things. I landed in this role. And then I started writing books. So I've written a couple of books. I wrote a book called CISO 3.0 about how to be a good CISO basically, and how we modernize the role, um, from what it used to be to where it should be going. And then this year I dropped a book on post quantum Cryptography. Uh, uh. Cause I did a lot of research there and it seemed like something cutting edge that was interesting.

Speaker A: So a lot to unpack there, I guess. First off, ISC Squared. So you're still involved?

Speaker B: Still involved.

Speaker A: So I remember years ago when I, when I sat for that exam. I'm not a good test taker. And I, I studied well, funny enough. So I took a class as part of my study. I took a class that actually Eric Cole, which was not through ISC School Squared, but it's. It's, uh, through Sans. And I can remember it came with. This is like early enough where having MP3 audio files was a new cutting edge. Like carrying that around, right. So you could fit. This is the area where you could fit just a handful of songs on whatever media player. And so the point of this is I remember taking the. The m. One of the most meaningful things that I had as a study aid was listening to audio. As I would go through my day and listen to somebody speak in addition to the reading that I did. But I remember sitting for that test. And I think the allotted time you would know or have better memory. I think it's five hours. Is that right?

Speaker B: I think that's the max you can do.

Speaker A: Max. Yeah. Yeah. Well, I used all of that time because I was so paranoid. Cause I'm such a garbage test taker. Um, but I remember thinking several times that I'm like, who the hell wrote these quacks? Like, none of this makes any sense. And so it's funny how the world aligns itself with itself. And now I met one of the people that were involved that contributed to this long list of, uh, classes. But it's a class It's a body of knowledge. I'll tell you that. I would recommend. It's controversial to some, in some circles, to be fair, but the journey to prepare and the personal, I don't say strength because that sounds lame, but the not being a great test taker and then going through and doing the test to me is still an achievement. Uh, and that was many years ago. Right. And I maintain it. You talk about, you know, not wanting to get called out. I spent my whole career kind of in that 24 hour mindset until recently as well. But you don't want to go back and take that test again. You want to run. There's like a fear element. Like, I don't want to let this thing expire. I don't want to have to go take that again. I've probably gotten dumber, not smarter, you know, so, But I would recommend anyone listening that hasn't gone and done it to make that a goal. And it's the, it may not even be the exam itself, but it's the preparation and all that goes into it that was so valuable to me. So it is a, I think it's a worthwhile measure of a security leader and I want to make that point despite the teasing I did about the crummy questions. Right.

Speaker B: But it's funny that you said that you wouldn't want to retake it because, uh, back in the olden days when I taught the class, every time they would change formats, they would make you retake it. So I've taken it several times. So we originally did it on paper and then they moved to computers and now it's that, uh, augmented, uh, where depending on how well you do, you may get more, less questions. I haven't had to take it that way because I quit teaching before that happened.

Speaker A: But mine was paper, Mine was an old, I mean it was like sitting for the sat.

Speaker B: Yep. And I'll tell you, the first time I took it, it took me just shy of three hours. And I remember at about the two and a half hour mark losing my will to take a test. And I'm just like, I got to the point where I didn't care if I passed or failed. I just wanted to be done. I can't imagine doing it for five hours. I don't think I'd have made it.

Speaker A: Oh, uh, I, I, I have fond memories of all of it. And actually a very good friend of mine, Brian Carter, was a proctor who I, I, I didn't know that well at the time, but we ended up working Together. He's, uh, brilliant and does amazing things, but he was a proctor and, uh, made sure I didn't cheat. So you're involved there. And I want to talk a little bit about being an author. And so I look at you and I'll tell you, we've not met before, and we had a we. For those who listen to the show, there's a prep call and some people I know that I'm just going to. I'm not going to have to work very hard to get you to say sort of interesting things that will be useful. You're going to fill the air, right? And I don't mean that in a negative way. That's a positive. It's a rare trait because I think a lot of the listeners are like, what do I do? What else do I do? What else can I do? What do I do with my career? What do I do to augment my career? What am I going to be after? I'm a director of security or ciso? And so you've covered a lot of that teaching, whether it's earlier in your career or late being an author. I have authored a book for sans, co authored a book and submitted chapters. I've never done something quite as ambitious as what you described. I don't have anything on, you know, Quantum crypto or CISO 3.0, but what goes into your thinking there? You're a busy guy. You've got. I know you've got a team to run and deliverables. And then you decided to write a book. Like, what's the. What was the spark there? For example, you, CISO 3.0. Why in the hell did you do that?

Speaker B: So, uh, I'll tell you. Uh, my friend Matt Sharp, who I worked with back in a former life, became the CISO of crocs, and then the ciso. Now he's the CISO of. Exactly. And he wrote a book that really sparked my interest in a major way called the CISO Evolution. And I read that book and I was like, this is a spectacular book. And I was like, if Matt can do it, I can probably do it. So I reached out to Matt and said, like, hey, what's it look like to write a book? Like, tell me. Tell me the process. Tell me the story. And I feel like he tried to talk me out of it. He's like, this is, uh, this is an awful process that is, uh, you're going to lose money. Are you sure you want to do this? And I didn't listen to him, and I did It. And he was right. It was an awful process and I lost money. And I'll probably continue to lose money.

Speaker A: Let me interrupt you there. Lose money. Like I wouldn't expect that you would. I m mean, make. Authors typically don't make much money, especially with security books. But you say lose money, uh, unpack that.

Speaker B: So, so much went into this book. And I think that Matt and Rock, when they wrote their book, they did even more things than I did because they, uh, sourced graphics and things and that they needed to pay licensing for. And I think that they bought a piece of software. I tried to do it on the cheap as much as possible and do everything myself. So I created all of my own graphics and just to be cheap even. So I had a bunch of resources that I wanted to share. So I built a website and I paid a company to make the website because I just didn't have time to build a website and make it pretty. And, um, so I paid for that. And then publishing the audiobook is a completely separate stream from publishing the main book. And so I had to pay for a producer and somebody to read the book. And there's just a lot of like, little stuff that goes into like, I kept finding myself outlaying money for this book and it's such a niche topic, like being a ciso, that it's not like you're going to get on the New York Times bestseller list selling cybersecurity books. So I, I think I'm close to breaking even. But it's not a money making endeavor. So if you're thinking you're going to write books to get rich, that's probably not the way to go.

Speaker A: No. Yeah, I mean, I, I would expect it to be a fall under the bucket of a personal challenge and, you know, achievement, maybe a prestige thing. Just something being very transparent to say, hey, I wrote a book, uh, and it's career adjacent, so maybe there's something that gets some participation from the employer. Sometimes this works, sometimes it doesn't.

Speaker B: You nailed it. So it's all of those things. Right. So I wanted to contribute back to the industry. And like I said, I've talked to so many organizations and I've seen so much of what works and doesn't work. I wanted to give some of that back. Um, so that was part of the driver for it. But also in this job that's this field CISO job building eminence as part of the job and the ability to land meetings with CISOs and help sellers land meetings with CISOs as part of the job. And it's instant credibility, right? So, like, when they're like, hey, I have the guy that wrote the book on how to be a ciso, it's easier for them to land a meeting. Right?

Speaker A: So you bring up. Okay, you bring up a really good point. And I don't know that, uh, I think everybody gets this, but if they don't, I, uh. Let's spend a second on this. I don't want to go too deep into Imminence, but this notion of there's a lot of people who think they want to go be a. A field ciso, and that's. That's not my, My current title, but it's in many ways it's an equivalent. You know, I've got hooks into a lot of different areas of the company of running. Running a, you know, a software company. But part of it is in that imminence element. There's a slice of that pie. And some people think that they just want to. That it's enough for them to have been a leader in security and just to show up and then work for a software company, and then the job is just going to sort of work itself out. It isn't. There's a lot of elements to it, and there's a lot of new skills that you must develop and honestly must master. Otherwise, you're not going to be valuable enough to the company. You're going to be seen as overhead and they will get rid of you. That is fact. And I see this happen all the time.

Speaker B: I've seen it over and over.

Speaker A: So. So as an ingredient, as a pebble on that beach. And again, I bring this up for the listener here because again, I know there's people that are like, maybe I want a different direction in my career. I have friends that are like, hey, I want to, you know, do something different, and I want them to explore that. But this type of job isn't really what they often what they think it is. Right. It's a little different, for sure. And eminence, there's little pieces that go into this and having the book taking the extra effort is insulation and is an accelerator all, uh, of that. Right. So it's going to protect you to, you know, put you on a higher level of value in the eyes of a lot of people. It's going to keep you sharp and relevant, but it's going to put you on the. A step forward. And so, you know, all of that. But I want to underline that and emphasize it for those listening that are thinking Maybe I want to go be a field ciso. Maybe I want to be run strata, you know, these kinds of things. It's one of the reasons why I do the podcast. You know, it's virtual mentorship. It's not associated. You know, we're not mentioning products at all, ever. It helps people, it gives back to the community, but it also makes sure that I'm known to some degree. Right? There's some people who listen and you walk into a meeting room and someone's like, hey, I listened to your show. Well, that feels good. And that makes the meeting a little easier. That's m a good thing. Same thing with your book.

Speaker B: You'd mentioned earlier. Like, folks, what do you do later? M, what do you do after you're a ciso or what do you do in addition to being a ciso? And a lot of the time when I talk to CISOs, they're like, Man, I really want to do what you do. I want to wrap up being a CISO and come be a field ciso. And it's funny because it's not that simple. Like you said, some people can do it and some people can't because it's such a change. You go from being a, uh, people leader to being an individual contributor. You go from being the source, the authority that says, this is what we're going to do, to being an advisor that oftentimes people don't do the thing that you think that they should do. You're switching sides of the table from a sales perspective too. Like you're used to being the buyer and you're becoming the seller. And that is a huge challenge for a lot of folks that they just can't, can't wrap their minds around. Right? Because even though this isn't a sales job and I don't carry a bag and have a huge number or something like you would think a seller does. This is a sales oriented job and that is a change for a lot of practitioners.

Speaker A: That is a stumbling block, I think, tactically for me. And this is something that needed. This should happen as you mature anyway. But for me, it's when you're in many of these meetings and you are, how do I say this? It's being comfortable, getting better at asking the right questions and also trying to be a vehicle of trust. There's a great book I've mentioned before, uh, on the podcast by Covey. It's called the Speed of Trust. It's how do you convey sort of authority on a topic, but also that you're A trustworthy voice. And, and you know, I don't have a quota or anything either. I'm not, you know, a salesperson, but I work with them. Right. And I represent an organization. There are goals there. But in general, uh, I'd rather be seen as an advisor first. And you have to sort of prove that out and you have to be seen as somebody who's trustworthy. And sometimes that comes through. For me and my own brand, there's an element of candor, there's an element of experience. Things that I've done and breach response and espionage stuff and building programs and these things kind of get into that notion of maybe, you know, maybe imminence is too bold to say for me, but it's that, that halo that's, that sort of surrounds you, that allows you to speak about a certain topic. But I was going to tell you what, what we're going to ask you what makes for a, uh, bad when you see the churn. So someone says, you know what? I'm going to retire as a ciso. I'm going to become a field ciso. You know what, I'm gonna ride this out for the next five years until I can go fishing every day. And they fail after about, you know, three months, four months, five months. What are the things that come, what don't they do? Well, from your perspective, and what's an example of the types of feedback that you get that that person isn't gonna cut?

Speaker B: It almost always follows the same trajectory. So when you become a field ciso, it's almost like hanging your own shingle. It's a little bit like being an entrepreneur. You're building your own brand. So you're going to land in this company and you're going to build this brand. And you need to convince all of the sellers and pre sellers and folks that are going to bring you into meetings that they should trust you in front of their client and they should bring you into these meetings. And it only takes one or two bad meetings where you didn't provide value, where it didn't land, where you're input seemed stale for the word to get out and for people to be like, don't put this guy in front of your clients. And uh, it becomes toxic fast. And once your brand is tarnished, it's super hard to turn that around. And it might just be because you don't understand the sales cycle. It may be because you stuck your foot in your mouth because you didn't understand the process or the political landscape or whatever it is. It might be because. And this happens a lot, once you land in the CISO seat, you become a lot less technical, and it gets easy for your knowledge to get kind of stale. And oftentimes, when they're bringing us in, they want us to talk about the stuff that is new and hot and cutting edge. And if you're not staying on top of that, it's real easy to come off as dated. Right? And once you do that, once or twice, the word gets out and your brand gets tarnished. And so we've been talking a lot about eminence. Uh, it's eminence for everybody, right? You're building eminence for the organization, but you're building it for yourself. And whether you're a field CISO or a regular ciso, that's always true. Like, your brand carries a lot of weight in whether or not you're trusted, you're respected, you carry any authority. You gotta build your brand, and once it's tarnished, it's hard to come back from.

Speaker A: Is there a way then, that you prepare? So you're gonna hire somebody who think. You think. Let's say there's someone who's unproven. Maybe they've been a good ciso, but they've never been. They've never moved into this sort of consulting field role. How do you prepare them to be ready for that? Or do they just have it or they don't? Like what I mean? Said plainly, no.

Speaker B: I oftentimes try as hard as I can to make sure that we're not just throwing folks to the wolves. Right? Like, if I bring a new field CISO into the program, generally I tell them, like, I don't even want to put you in front of clients for 90 days. Like, I want to spin you up and make sure that you are as prepared as possible to go in and be as strong as you can. Sometimes I can hold the wolves off for 90 days, sometimes I can't. But the goal is to give you enough time to ramp up, to understand all the things that the company that's new to you offers so that you're an authority on what there is to offer, but also to make sure that you've shadowed kind of seen what good looks like, have an understanding of what the expectations are. I have a really kind of in depth onboarding program I go through with folks because it is hard, and it's a hard transition. And even with all the preparation in the world, it's just for some people, and not for some people. Some folks think this is going to be great. And then they get into it and find out just, this isn't for me, and there's nothing you can do to prep them. Um, um, because it's just not a fit. And that happens sometimes, too.

Speaker A: So you mentioned when we spoke last time, kind of avoiding having people's soul crushed. You know, I think that leads me into how do you measure a program like this then? I mean, obviously there's a monetary amount that you could try to attach to, but how do you prove maybe in another way that you're adding value? And the, and the statement I shared with you to kind of prompt all of this kind of section of what, uh, what I want to cover is you're sort of overhead until you're not in a way. Right. Because these are typically. We're not cheap. But you gotta add value. You gotta do a lot of different things, gotta help a lot of different areas. It's not just fieldwork either. You mentioned research. Uh, there's also things like other elements that go to market. There's product elements, there's partnerships and strategic alliances and all these other things. There's just the need to sound smart. There's even working on delivery and communication and how good you are on video versus audio and news and rapid response and all these other things. So how do you measure this? And not only that, how can a ciso, because many big security programs, as you well know, have an office of the CISO that's kind of similar. There's kind of, there's an element of that where you have these besos. You have sort of a, uh, an internal element of what you're doing in the field. So how do you measure and does it relate?

Speaker B: Sure. So there's a ton to unpack there. So there's a lot of answer here. So we talked earlier about seeing field CISO organizations close up shop and be cut because, uh, they weren't showing value. And I've seen it at large organizations and small, and I have lots of friends who have found themselves in the midst of a riff. And I think a lot of the reason that that happens is you laid out we're an expensive resource and we're hard to measure. So what is the value of what it is that you're doing and how do you measure the value of what it is you're doing? I said, I'm not carrying a sales bag and I don't have a huge sales number. So how do I prove that I'm having some positive impact on the bottom line? And that's one of the hardest things to do for this job. And how do you measure it? And I will tell you that I have struggled with how we measure it. What we ended up doing is we've broken the program into four kind of pillars, four essential elements of the things that we do. So the first thing that we do is we consult with our customer CISOs. Right? We're peers to the CISOs, we're mentors for CISOs, we're advisors for CISOs. That's the core of what we're doing. So we need to make sure that we're not a, uh, one and done type of situation. Right? It's real easy to come in and advise one time and then disappear and not add a ton of value. So what we do is we call them embedded accounts. Like how many accounts are you embedded in where you are back on a regular basis and you're providing kind of ongoing advisory. That's one of the things that we count to try and figure out like what is the value that you're providing. We also do eminence building stuff, right? So that stuff is pretty easy to measure. What is the non client facing stuff that you're doing? Speaking engagements, podcasts, paper writing, uh, writing articles, blogs, et cetera. That stuff's pretty easy to count. And it's pretty easy to tell when people are outputting things that are eminence building activities. We also interface with sellers. And how do we engage, uh, with the sales team to make sure that they are not only utilizing us, but understand what it is that we're selling and help them better engage with C levels in general. So we do a lot of enablement and that's also kind of easy to measure, right? So it's easy to measure how many uh, enablement activities we're doing and what that integration looks like. And then the last pillar is part of our mission as the Global Security Strategy Office is we're the voice of the customer back into the organization. So we're building new kind of cutting edge service offerings and we're working with the services teams to make sure that the message that we're putting out jives with the thing, the work that they're doing and we're working with delivery and to create new products and make sure we're going to market as strong as we can. And so the same way that I lay out in the CISO 3.0 book that you should be using skills matrices and whatnot to m measure the capabilities of your folks as a CISO to like build a strong team. We do the same thing. So I built a skills matrix that covers like what industry verticals do you know? What, how do you. Well, do you know our practices challenges, how well do you understand our clients challenges? Uh, how well do you understand the tool landscape? Uh, how well do you deliver educational content? How well do you do the things that are the four pillars of the CISO job? And then we go in and we kind of self rate them. And what I just added recently was like a felt system, basically. So think karate like you're a white belt, you're a green belt, you're a orange, uh, belt, whatever. And so we can now use the skills matrix to kind of figure out like not only what do you know and what are you good at, what does the team know and what are we good at, where are our gaps and then how many, uh, we don't even. I am not a black belt currently. Nobody's a black belt right now because, uh, we made it hard, right? So like, where are you on the journey of being a good field cso? And then the ability to share all that up really helps provide a lot of value. And so I'm constantly trying to figure out new ways to report up what value we're creating. Since I don't have a salesforce number that I can say we contributed $30 million last year. Right. Or whatever it is. So there's a, there's a lot there.

Speaker A: But the question then is, so you walk through, you know, the peering, eminence, sales enablement, and then elements of strategy, which has a, uh, piece of kind of the voice of the customer back into the services org. Those are the four high levels that you mentioned. In theory, then, the belt system. What I'd like for you to do, if you would, for us as a, as a game to play, live. Well, not live, but in the moment you're not prepped for this, is do those four pillars and maybe even the notion of the belt system for the CISO listening or for the BISO listening, is there a. Does that rubric apply? You know, you're applying it to a field CISO role. But I would argue potentially that it could apply to a traditional CISO framework. Meaning when you start thinking of all the cooperation that you must have and all of the other areas that you're supporting and all the ways that you're evaluated, you know, there's often not a revenue generation element either. There's value is important, of course. So how do you, or can you take or do you recommend These four pillars and one sort of measure into a traditional ciso. Can you overlay that thematically?

Speaker B: So I actually treat it as three pillars for CISOs. And you don't even have to buy the book. You can just go out to the website ciso3o com and download the resources. And in the resources, you'll find a skills matrix for CISOs, and you'll find the thing I call the CISO wheel. And basically in the CISO wheel, there are all of the things that you should know and be able to do as a ciso. And you plug in, like, what is your current competency for that? How frequently is that called upon as part of your job, and then how frequently are you doing it? And it creates this radar wheel, basically, that shows, like, here's where you're competent, but here's where you're using it. Here's what's called upon, where you're not using your strengths, and here's where you're called upon and you don't have a strength there. You should probably go spin yourself up.

Speaker A: Interesting. So. So a spider chart, basically.

Speaker B: Yeah, exactly. And that all exists. You can go download it right now. So we. The skills matrix that I built for my team is really built off of the original CISO skills matrix. It was meant for CISOs. Right. So you absolutely should be spinning yourself up and figuring out, self assessing what are your gaps. I also am a big fan of 360 assessments. There's several places where you can do those for free. Where you go and you ask the people who are, who you report to, and the people who report to you to kind of give you feedback in a anonymized way, uh, so that you can figure out what your own skills gaps are and fill those. I think that's huge. I haven't come up with a belt system for CISOs yet, but that would be a thing that I think could be really cool. But I haven't put any thought into it for actual CISOs. But your. I find that CISOs come to the seat in two different ways. Usually there are two main paths that I see people land in the seat. There's the technical path where I came up through security, and I was the smartest architect, and I ended up in the CISO seat. And I have very strong technical security skills. And oftentimes those guys don't have business skills. They're missing all the MBA knowledge that would make them a, um, good business partner in the CISO seat. And then the other way that I see people come to that seat is they'll pull some MBA that's done something else and stick them in that seat and they know nothing about security. And oftentimes, depending on how you ended up in the seat, you got to have both pieces. Like, to be a really good, successful ciso, you have to have both. So if you got there through the technical track, you've got to learn the MBA stuff, you got to learn the language of business, you got to learn how to speak to the board, you got to learn how to translate those KPIs into KRI that matter to a business. And if you're the MBA person, you got to go get your CISSP or whatever it is that it's because we talked about that earlier, right? Like, is there value to that? There's value in, it's a mile wide and an inch deep and at least it exposes you to all the security ideas. Right. And that's the goal is like, if you came in as an MBA with no security background, you've got to spin, uh, up fast on how you understand the technology part. So oftentimes when we talk to CISOs, we'll try and assess, like, which set of gaps do you have and how do we help you remediate the path that you're on?

Speaker A: That's a really good point. So understanding where they're coming from as an individual, as a human, what are their strengths? I always used to break down myself into three areas. What, what am I good at? Which is like two things. What am I disinterested in and what am I bad at? And that's how you, that's how you build, it's how you set strategy, it's how you do hiring plans, it's how you do lots of stuff. Uh, not everyone is that aware. I, I, I wasn't myself for a long time. Until you get moved into leadership and then executive leadership. Right. So you don't, you don't think about it. I didn't. And so I could see that being a really powerful tool to bring in if you can connect with that individual and they trust you. Right. Otherwise, if they're not, if there's not that connection there. Kind of a bit of a left field question. There's likability, there's presence. We talked about eminence, but there's, there's presence, there's likability and that's, those are super important for a ciso, certainly for a field ciso, but ciso, most importantly, can you be a good CISO and not be well liked no, Flatly, no.

Speaker B: For several reasons. So for the first reason, the CISO is the talent magnet. And this is a, this is an industry where we have like negative unemployment. There's, there's a skills gap, right? It's very hard to hire good qualified security people. And they don't want to work for a jerk. Like, they can go somewhere else and work for somebody who's not a jerk. And it's a very difficult job that requires some inspiration. Like, it's hard, it's easy to burn out insecurity and, and someone who has a vision and is inspiring will help keep their team from burning out as early. But not only for building a team, but when you are building a security program inside of an organization like we so often hear about, like, hey, they're the office of no. How do you not be the office of no? Well, you have to build a security culture. And you can't be a jerk and build a coalition and build a security culture and make other departments want to care about security when they care about driving revenue and driving down costs and delivering products and whatever else. Like, it's a charm offensive to get security ingrained in these other parts of the business. And if you're a jerk, it's not going to work. And it's funny because I see a lot of people, like, when we talk about security, we talk about like, do you lead with carrot or stick? And we'll use like phishing as an example. People will do phishing campaigns and then they'll try and punish people for failing. And then they're surprised when they don't self report and they're surprised when people don't participate in the security activities because those people are afraid they're going to get punished. Like the programs that I see work. Use the carrot, right? Fish of the day reward. You want a gift card because you reported a fish or whatever, you catch more flies with hunting. It's the old adage, and it's a hundred percent true in security because you have to build a, you have to build a culture of security. And you can only do that as an inspirational figure.

Speaker A: I think also I've seen some CISOs that are pretty good at that stuff, but as they work with their peers and above, they struggle with that likability with that, with that influence with. And different, yet related, but different. I spent a lot of my time speaking about dealing with difficult situations. So, like a breach situation and the concepts of comfort and confidence, those two things. They don't see you as rated highly in both of Those in the moment, you will be replaced a hundred percent.

Speaker B: Uh, one of the things we do a board ready CISO masterclass where we teach CISOs how to deliver to the board and we give them like board level templates and stuff. But one of the very first slides is understand the assignment. And what is your job when you're walking into the boardroom? And oftentimes when I ask folks, hey, like, what do you think is the most important thing? What do you think you're doing when you walk into the boardroom? And I'll get any number of answers about, like, it's my job to update them or give them statuses or whatever it is. But one of the biggest things that you're doing when you're walking in there is you're proving that you're the person for the job. Every time you walk in, you're proving that I am the person who can manage this program. I am the person for this job. I have this in hand. And it's very easy to undermine that in the boardroom, but it's easy to do that with executives. It's easy to do that with other business units. Like, you're always proving that you're the person for the job. And it's, uh, when you come in with fud, when you come in with fear tactics, when you come in not being a jerk and not having good influence, like, it's very easy for folks to be like, he's not the guy for this job. Let's find someone who is.

Speaker A: So that's a very big task, uh, doing that all correctly. And there's a lot of work that goes on well before that meeting even starts, as you well know. For example, the notion of making allies before you walk, before your shadow crosses that threshold and you darken their door, as they say, you need to have friends before you go in and the way. Or at least a friendly. And you got to figure out, okay, who's likely to be most interested. Who have I met with ahead of time, have I briefed them in general? Do I understand their currency in conversation? What do they think I should do to prepare? Right. So do I have. I see this happen now? Sometimes you get called into meetings. Depending on your reporting structure, where you have. You don't have the ability to have that. Um, it could be a new board member. You may be a new ciso, you may not have. You may not be the ciso, but get called up to the SLTELT or board meeting and you're going in cold or, or hot, depending on how you're looking at it. And so there's that, that variable. For those that are thinking of that, what do you recommend? Right. That preparation before you go into the meeting. I'm sure your class covers that, but maybe one or two things pursuant to that that would help those that are maybe a bit uneasy.

Speaker B: Sure. Uh, so it you were talking first about like, hey, I have to have friendlies. And oftentimes what I see is we don't even get a seat at the table as CISOs to come in and talk to the board. Or when we do, frequently it's filtered through some other C level. Like you're giving your message to the CIO who's going to go deliver it, or the CTO or the CFO or whoever, who's going to go deliver it. Because we're not seen, we're often seen as second class C level citizens.

Speaker A: Right.

Speaker B: It's very common for me to run into folks who are doing the CISO job, but, uh, don't get the CISO title. They get some VP title or some director title or some manager title or something where they're not the C level. And it's partly because we don't sound like the other C levels. Right. We come in and we do something different than everyone else does. If the CFO walked into the boardroom and said, I can't tell you what last month's financials were, but I can tell you that they're, uh, up Green Arrow. And we did 20,000 more transactions than we did the month before. He'd be drummed out and they'd run him out on a rail and he'd be over. We come in and we do that stuff all the time. We're like, we have no idea where all our assets are, but it's up Green Arrow. And we closed 50,000 vulnerabilities this month.

Speaker A: We're going to go back to that. I got to go back to that point there. Continue on. But we're going to go back to that point. That's one of my pet peeves on assets in particular. But yeah, go tactical, but please continue.

Speaker B: So, yeah, so we don't sound like our peers. And so consequently, we become second. We've made ourselves second class C level citizens and we have to sound more like our peers. We have to perform more like our peers. We have to be talking about how we impact revenue, how we impact cost, how we impact risk. Those are the things that board folks care about. Right. Oftentimes I hear the tale too, of like, go meet all of the board members and make friends with them and learn about their backgrounds and all that. For most folks, that's not an option. A lot of the times you're gated from that. If you went and talked to board members, your CEO or whoever would frequently be upset with you. Um, you don't have access to them. So it's very common for you to have to come in cold. So what you need to be able to do is tell a story. You have to have a story arc, right, that's going to land. And you're training them almost, right? Like you're teaching them what to look for. Because oftentimes these board members sit on multiple boards and they've seen what other CISOs give them, and maybe they're giving them a, uh, a risk matrix or a, uh, NIST score or whatever it is, and that's what they've been trained to look for. And so you're training them to hear your story and understand, like, how you impact revenue, cost, and risk. Right. So the idea that you're going to get in and you're going to learn a bunch about your board members is nice if you can pull that off. But for most folks, that's not an option. And so you just have to be prepared as you can be to tell the story that you want to tell.

Speaker A: So I'm going to go to that. That first, there's two things I want to hit. One is that preparation. You're absolutely correct. We spend. Have spent a moderate amount of time on this show talking about interviewing better and even talking to people that were let go and fired. And then my question to them is, hey, had you known what, you know now after getting, you know, whacked, would you interview differently? And they'd say, absolutely. And I was like, would you be willing to talk about that? And they're like, yes, this is one of those things. So if I agree to come on and be the CISO at your corporation, uh, let's talk a little bit about our first board meeting.

Speaker B: A hundred percent.

Speaker A: Let's talk about how I plan to prepare for that. Does that sound okay? Right. So you need to begin socializing that idea. Say, this is how I prepare for those big meetings. And then, by the way, if you're not interviewing with the people that you think you should, if you're not interviewing with counsel, if you're not meeting the CEO, if you're not, every company's different. And I'm. I'm talking in the most, in the biggest sense of a larger company, but even if you're a midsize, I think this is an important thing. Depending on where your risk and where your brand and where your responsibility and where your authority all align, which you very well know. So you kind of have to, and, uh, kind of call the ball well before you even start the role. And then if you see that gap begin to form where you know what, hey, you told me that I'd be able to do this and now you're not exposing me to these meetings or you're not giving me a warm introduction, you know, so, hey, I would expect to have. That's an early warning sign. And so I know not everybody has that laid out as you know, in a, in the pretty way that I just described. But I think my theory, the emotion that I want to share is I, I think I want security people to be way more aggressive or maybe more assertive on points like that. Because of the point you made of being seen as a second class C level position, for sure.

Speaker B: Lots of organizations treat their CISOs. They set them up for failure, right? And when you're interviewing, you should be interviewing them as much as they're interviewing you. And not just that, uh, you should always have a question. When they say, do you have a question? You should have a ton of questions. You should want to know, like, if you're going to make me the ciso, are you going to put me on the D and O insurance? Am I going to need to carry my own errors and omissions? Are, uh, we a publicly traded company? If so, am I going to have access to help write the information that's disclosed in our 10Ks? Or is that going to be done by some legal team and they're going to hang it around my neck when I had nothing to do with it? Right. Those are all questions I want to know in advance before taking that seat. Like, how, how's my budget work? Like, who do I report to? Who gets to release my budget? Like, what are the budget cycles? All of those kind of things. Because a lot of the times folks get excited and they land these CISO jobs and then find out like, there is no formal budget cycle. And no, I have no insight into what's written in our disclosures. And no, you're not on the insurance. And then you end up being the solar winds guy where SEC comes after you personally. Like, oh my gosh.

Speaker A: Yeah, very. A very real situation. And excellent advice. Uh, any other. I mean, we're, we're. It's already been the best guests that I, you Know, I'm very fortunate to be able to do this show is one of my favorite things I get to do. Meeting people all around the world, sometimes having to push them for all the smart things that they've done. I haven't had to push you much at all. Uh, you know, you trigger off of what, uh, I say very quickly. But all for the benefit of the, of the listener who I know really appreciates it. Any other interview tips in general? Anything top of mind, maybe not even just for the ciso, but just something that, that you see as a accelerator for those that are maybe looking for work right now. It could be something more spiritual. It could be something more tactical. It could be a tool or a method. There's some people I know that are out of work right now that's, uh, been top of mind. I've been coaching them, trying to do the best I can to help them prepare for their next opportunity. I'm sure you get questions on this front. Anything that comes to mind that you'd like to just remind them of or maybe, um, a perspective that you have when finding work.

Speaker B: Sure. I feel like you can do two things at the same time. So, like I said, they're interviewing you, but you should also be interviewing them. But while you're interviewing them, what you can be doing is telling the story of how you want to tackle this job. Like, what you're going to bring to the table and what it is that your vision is for how you do this job. And so often people leave that out and they want to tell you, like, why I'm qualified and what I do and what I've done. And here's some metrics about things I've done at previous jobs or whatever. But what they're trying to figure out is, are you the person to run this program, and how will you run it when you land in that seat? And in order to figure that out, you have to kind of void dear them on how they think this role works. And then you've got to tell them how, in your vision for this role, what you're going to do. Oftentimes I see CISOs wait until they're in the seat to write their 30, 60, 90 plan. I would tell you to write your 30, 60, 90 plan after the second interview. Like, if it looks like it's serious and you're headed down that path, how are you going to tackle this job? What's interesting about this organization? What are their crown jewels, and how are you going to protect them? Specifically, Right. What is your plan? And then once you have that plan, you have a list of questions you can ask about, like, am I going to be able to implement that so that you can find out if you're set up for success or failure before you land in the seat.

Speaker A: Two more questions for you. One's the final question for the show that we always ask. But before that, you're a busy guy, you do a lot of different things. You stay active, you stay sharp. I can tell that by speaking with you now. M. Anything else that you're working on? Any great book that you just read, an article that you found really interesting or a skill that you're working on developing that, that you'd like to share just because it's fun, uh, or interesting with the listener.

Speaker B: So I'm always working on a ton of stuff. So here lately I've been working on OpenClaw. So I, I got wind of OpenClaw and I tried to set it up in the cloud and it just wasn't working the way I wanted it to. And my friend who's on my field CISO team, John Candillo, had been doing it for a week or two before I got to it and uh, he has IT running all of his short term rental properties and advertising and being his marketing agent and all kinds of stuff. And he's like, you, you've got to get on board here. Like, you need to do this. And so I was doing some research, trying to figure out like, what's the best way to deploy it. And I deployed it in the cloud and it wasn't working for me. And he's like, you got to deploy it on a Mac Mini. And I was like, Mac Mini is just not in my budget for this month, maybe next month. So John sends me a Mac Mini. So greatest professional gift I've ever received in my life. Like, what an amazing shout out. John. He sends me this Mac Mini and it really has been a journey, right? Like installing it and then figuring out how to secure it. I wrote an article that's out on LinkedIn. I wrote an article originally, like, here's the framework of how I think you should secure it. And then after I did it, I wrote a, uh, here's where the rubber meets the road and what I actually did. And I tell the story about how I accidentally spent $300 one night and tokens and didn't see that coming. So it's been a journey for sure with some ups and downs and some failures, but I have it doing all kinds of stuff. I vibe coded several apps I've got it. Being my social media manager, it's managing like every part of my personal calendar and life. Like, it's amazing. Openclaw really is the future and understanding how it works and understanding how to secure it I think is important for CISOs because it's coming and understanding just agentic AI, uh, in general is huge. And then the flip side of that, every year we ask the CISOs that we talk to like, hey, what are the things that you're worried about? What are the things that you care about? What are the things that you're going to be working on next year? And for 26 we had a list of things and it includes all the things you would expect it to include. AI security and how do I use AI to uplevel my SoC and how do I do resilience and stuff like that. But one of the things that landed on the top 10 list was non human identity. And I didn't know much about like, how do you actually tackle non human identity? And now that everything's an AI agent, they're all a bunch of non human identities that perform like humans and have these privileged accesses. So how do you tackle that problem? So I've spent the last two weeks digging deep into like, how do you do non human identity? And it's a, it's a lot. There's, there's a lot to tackle there. There are non human identity platforms, but even in addition to that, there's just so much work that you need to do and it's, it's part security and part development team. There's a lot of automation that goes into it. It's a whole journey and I've spent a couple of weeks working on that and I have some papers coming out on that soon.

Speaker A: Time well spent, sir. Uh, I have had the privilege to advise Team 2 what I'll call identity. One of them is sort of non human or non deterministic space. We don't talk about vendors here, but that is an area from my background in breach response and running SOC stuff. In many cases the majority of your problems are surrounds identity issues, whether it's the misuse of them by the adversary or clumsy processes by, you know, that you're forced into using because you know, identity and IAM has been underserved or misunderstood. You know, we talk about earlier, I didn't even get to it, but the idea of asset management is never good, but identity management is often challenged and bad. We've never really gotten good at managing admin accounts, let alone you know, regular accounts struggle, admin accounts struggle, then we've got non human and service accounts, and then now we have AI. We still struggle with entitlement management, keeping accounts. And now there's just in time and this. And what happens if, when, when certain jobs are kicked off, uh, is there inheritance of, of identity as the action is taken by these agents? Is there a new set of credentials? How do you timeline that as a defender and as a responder? What does that look like visually? How, uh, do I respond in an absolute way. So think of the problem of someone quits and I disable their account. And even if I sever their, let's say, their VPN access, in many cases they still have access for a period of time even though I've disabled their account. And they have. Right. There's a persistence element. It's way, way worse when it comes to identity and the stuff you're talking about. And so having. You have to be sharp at that. I think it's beneficial to a C for a CISO to be. But what I would add to that is maybe, maybe the CISO level person jumps in if they're eager and willing and have the desire, but certainly to have someone on your team or a series of people that jump into a topic, do an assessment and then report that back to the larger group. So always have these things in a hopper would be my advice to the ciso. Have them in a hopper, have these, assign them out, make your senior leaders do the research on some of the other stuff at maybe junior level people, and then create your thoughts and then present them like that. Full circle.

Speaker B: Two quick thoughts on that. So there's a term that I coined some years back, I call it strategic debt. It's kind of the opposite of technical debt. So if technical debt's all the stuff you should have gotten rid of and didn't, strategic debt's all the stuff you should have done 10 years ago and didn't do because it was hard or expensive or you couldn't find ROI for it. And the two big strategic debts that I find almost every organization have are identity governance and data governance. And they're impeding folks now. So all the cool things that you want to do, I want to go to zero trust, I want to roll out agents, I want to do AI, I want to do whatever. Like that debt is keeping people from being able to do the cool stuff now. Like I want to roll out agents, but I don't have a governance framework in place because I never bothered to do it. And that's people are struggling with that and everybody has that problem and it's very common. So you were talking about how many senior folks go research stuff. Those days are almost over too. So OpenAI has rolled out a new feature called Deep Research. I don't know if you played with it. It is phenomenal. I think it's really going to hurt senior architects. I think it's going to hurt essays at VARs. Like all the people who currently bring you the this versus that. How do I shop? How do I compare stuff? Like instead of issuing some crazy RFI where you get back vendor tainted answers where they're trying to say yes to every question. Deep Research will do that in like 15 minutes and it's fantastic. I've run three or four different things through it now where I've compared vendors and compared spaces and its results are amazing.

Speaker A: It is. I worry about a future, so I completely agree. But I worry about a future where I'll give you an old school example and then we gotta wrap cause we're. We're over. But that's how great conversations go. The notion of, you know how when someone says hey, you're. They've. They've proven that if you read from a book, an actual old school book, that your retention is different than if you read from a Kindle. They've. They've. Or a scrolling. An indefinite scrolling screen at least like a giant PDF that's proven your retention, your recall, all that and comprehension are all affected. And now there's research that's come out. This is not new but maybe three months ago on the effect of the use of AI uh and the humans, your brain and all the rest. Right. You said it's going to affect architects and other thinkers. I think it's going to fall somewhere in the middle. But I worry that for there's going to be certain types of roles that it's going to make us less sharp for certain people. It's going to make them a hundred fold more powerful than they were. But I don't yet know what that mix is. So how do I keep my brain enough old school that I retain the strength. Right. Of what needs to be and then also augment that reality in a way that's powerful. Where I can now be that explosive asset. Right. That's. But without, without falling backwards in a way where I lose myself. I probably didn't make any sense in saying that but.

Speaker B: No, it makes perfect sense and it's happened throughout history and I think people are afraid of AI but this Shift happens a lot. So there are a lot of things that you use that you drive a lot of value from using that you don't understand how it works. Most people have no idea how their car works. Everybody uses their phone all the time. And most people have no idea how anything inside their phone works. But you can still use it for productivity. And I think that's where we're going to end up with AI. We're going to lose a lot of that, like, how does it work? But I don't think it's going to matter because it's going to be about the utilization of it. And that's where we're going to move toward. And I think it's going to move entry level of stuff. Right? Like, entry level has just become a different idea than it was before.

Speaker A: Good point. Excellent. Excellent way to phrase that. One more question. It's the close all question that we ask pursuant to the name of our show, the New ciso. This experiment of virtual mentorship. What does being a new CISO mean to Walpol?

Speaker B: Yeah. So, man, that is the hardest job I can. Like, of all the things, that's the place where you land in that job and you just have imposter syndrome right out of the gate and like, you're drinking from the fire hose and you're trying to figure out how do you do all of the things? And if you've never done it before, it is, it is so much to do. You're building a program, you're running a team, you're communicating that program. You're. There's so much to tackle. We, uh, talked earlier, and I think there are a couple of things that are super important when you first land in that seat. And the first one is figuring out what your plan is. So, like, if you didn't bother to build your 30, 60, 90 during your interview, you better build it like one of the very first things that you do. Right. A lot of the time, people start with, I'm going to build a strategy. I don't know that that's the place that you start on day one. There's a lot of learning that goes on to figure out what already exists before you can get to a place where you can build a strategy. And then we talked a lot about that introspection piece. Right. How did you land in that seat? Did you come in through the MBA track? Did you come in through the technical track? Did you come in through some other way? You're a CIO and they just dump security on you one day? I See that a lot of the time, validating your own strengths and weaknesses and figuring out what you need to do and then figuring out that for your team and figuring out gaps. A lot of the time when people build their strategies too, they build them around tool sets or NIST or risk assessments or whatever. And it's very easy to go out and buy tools, but what you really have to do is build capabilities and it's easy to buy a tool and have it become shelfware. In order to make a tool a capability, it's gotta have people, it's gotta have process. So understanding what you have, understanding where your gaps are, where your team's gaps are, that's not one thing. That's 10 things I think I've said. But that's such a hard job. I don't know that you can boil it down into, here's the one ultimate thing you should do when you land in that seat. But yeah, figuring out your plan and figuring out your gaps are the things that I would do first if I had to do it over. Being a brand new ciso.

Speaker A: Yeah. Start during the interview. More focus there, I think, is what we've agreed on here. Walt, thank you so much for all your time today. I really appreciate your contributions to the show. You've been a ton of fun to meet and have a chat with. I really appreciate it.

Speaker B: Thank you. You've been awesome. This is a great, cool show and I think that CISOs are going to get a lot of value from it. So I'm really excited to, uh, see how this show takes.

Speaker A: That is it for this episode of the new CISO. Thank you for listening. Check out more episodes on xbeam.com podcast. Remember to rate, review and subscribe to get brand new episodes first.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • When the Hacker Changes a One to a ZeroAuto Supply Chain Champions · on Post-quantum cryptography86 / 100
  • The Future of Tech - Key Themes for 2026 and BeyondThe B2B Podcast · on Post-quantum cryptography82 / 100
  • Is encryption enough to protect our data?Technology Now · on Post-quantum cryptography81 / 100
  • Auditing in the Age of AI: Risks, Rewards, and Practical StepsSpeaking of Risk and Audit · on Post-quantum cryptography80 / 100
  • Max Levchin - Building Affirm, PayPal, and Why He Only Starts Network BusinessesFintech Leaders · on Post-quantum cryptography79 / 100
  • Inside A Quantum Computer - The Race AI Is Speeding UpThe Identity Thread by Entrust · on Post-quantum cryptography73 / 100

More from The New CISO

All episodes →
  • Rogue Agents: The New Era of AI Insider Threats (part 2)
  • Lessons From a Spy Hunter: The Real Cost of a Breach (Part 1)
  • Your Most Valuable Skills Aren’t Technical
  • From Chef to CISO: Unlocking the Recipe to Security Leadership
  • Architect and Firefighter: How a Modern CISO Leads in Crisis
Explore the best B2B Leadership podcasts →
All The New CISO episodes →