
Tuesday Morning Grind: A Cybersecurity Podcast · 2022-05-03 · 44 min
Key moments - from our scoring
Substance score
51 / 100
Five dimensions, 20 points each
Mark Weatherford brings three decades of cybersecurity leadership experience to this episode, tracing a path from Navy cryptologist to the nation's first Deputy Under Secretary for Cybersecurity at DHS. He candidly addresses the reactive nature of cybersecurity legislation - noting that over 2,500 federal bills now reference cybersecurity compared to zero twenty years ago - and critiques the fragmented, sector-by-sector approach to regulatory requirements. His work at the state level (Colorado and California) pioneered the first state cybersecurity legislation and built collaborative frameworks among disparate agencies, while his tenure at NERC managing NERC CIP compliance across electric utilities exposed gaps in voluntary security adoption across critical infrastructure beyond electricity. Weatherford argues that without regulatory mandate or financial incentive, private sector organizations won't prioritize cybersecurity investment, citing the PCI DSS model and nuclear power industry self-regulation as exceptions. For B2B operators in critical infrastructure, government affairs, or enterprise security leadership, this episode offers practical insights into legislative navigation, multi-agency coordination, and the governance challenges underlying national cybersecurity maturity.
Weatherford was the first Deputy Under Secretary for Cybersecurity at DHS, overseeing the National Communications Center, civilian federal agency cybersecurity coordination, and critical infrastructure security across all 16 critical infrastructure sectors. He managed organizations including the National Cybersecurity and Intelligence Center, US CERT, and the Industrial Control Systems Cyber Emergency Response Team.
He created the first state cybersecurity legislation (codifying his CISO role and budget), built a community of security leaders across agencies, developed an expertise inventory mapping security skills to individuals across departments, and facilitated resource-sharing where large agency purchases were leveraged to fund smaller agencies' infrastructure needs.
Legislators are by nature reactive, not proactive planners. They respond to incidents (like Colonial Pipeline triggering TSA pipeline security standards) with siloed solutions specific to each sector, creating dozens of fragmented regulations rather than economy-wide baseline standards that would be more efficient.
He argues that without regulatory mandate or financial consequences, private sector organizations won't invest in cybersecurity. The electricity industry's mandatory NERC CIP standards make it far more secure than other critical infrastructures like oil, gas, and water that remain self-policing.
PCI DSS is a self-regulatory framework created by card brands when data breach costs were hitting their bottom line in the hundreds of millions of dollars. Weatherford cites it as a rare successful private-sector security initiative driven by direct financial consequences rather than government mandate.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains some genuinely useful structural observations about government cybersecurity (state agency resource-sharing, regulatory gaps across critical infrastructure sectors, siloed regulation post-Colonial Pipeline) but large portions are career biography and surface-level policy commentary with no actionable density for a practitioner.
up until just very recently, um, the electricity industry is the only industry that had mandatory regulatory requirements
as of last week, there were, in the federal government, there were over 2500 different bills that had either cybersecurity in the title or cyber security was a big part of the legislation
A few genuinely contrarian observations surface - particularly the critique of TSA's siloed post-Colonial Pipeline rulemaking and the argument for mandatory program sunsets in government - but most of the discussion recycles familiar themes about reactive legislators and self-regulation failures without developing them into novel frameworks.
after two months after Colonial pipeline, legislature and tsa, actually it was a tsa, they, they created new standards around pipeline security. And at the time I was just saying, no, let's don't do this. You're going down this, this very siloed approach again
I almost wish you could say that program that you start in Washington D.C. has to have a maximum five year lifespan because as we all know, technology changes so fast
Weatherford is a genuine top-tier practitioner - first CISO of Colorado, first CISO of California, first Deputy Undersecretary for Cybersecurity at DHS, Chief Security Officer at NERC - with real executive-level accountability at historically significant scale; not a career conference speaker.
I became the uh, first Deputy Under Secretary for Cybersecurity at DHS
I was the first CISO for the state of Colorado
The episode has a reasonable number of concrete data points - agency counts, budget figures, nuclear plant numbers - but they are frequently hedged with 'I think' and 'something like,' and anecdotes (the substation break-in) are told without outcomes or measurable impact.
In Colorado I had I think 22 or 23 state agencies. In California I had over 160 states state agencies...and our IT budget in California at the time was something like $3 billion
I had a really, I had, I thought at the time there's a really big budget, not quite a billion dollars. Um, but that was to fund, you know, that was to support almost 2,000 people
The host asks some structurally interesting questions (prioritization at DHS scale, path from technical to leadership) but never challenges a claim, accepts all answers at face value, and repeatedly steers toward biographical setup questions rather than extracting deeper or harder-to-get insights.
When you're working for Homeland Security and you have an infinite number of things that need your attention, like how does that size and scale of an organization prioritize anything? Like, how do you know what to work on?
What is your role like Chief Strategy Officer. That that's one of the best titles you can carry. That sounds pretty cool.
Computed from the transcript - who did the talking, and the words that came up most.
Mark Weatherford, Homeland Security Cybersecurity Deputy Under President Obama talks about Cyber Risk and Leadership Mark Weatherford has a long career in public service including serving in Homeland Security and CISO for the state of California and Colorado. In this episode of Tuesday Morning Grind, Mark and Christian discuss cyber risks, cybersecurity legislation, and leadership in the public sector. About risk3sixty: risk3sixty is a security, privacy, and compliance consulting firm that helps high growth technology organizations build, manage, and assess security and privacy programs. Offering services related to SOC 2, ISO 27001, PCI DSS, HITRUST, Virtual CISO, Privacy Programs (GDPR, CCPA, etc.), Penetration Testing, and a GRC Platform built for cloud technology companies, Phalanx. You can learn more about risk3sixty at .
Transcribed and scored by The B2B Podcast Index.
Speaker A: My famous tagline is you can't say no to the governor. That's a million, million dollar idea if you know how to answer it.
Speaker B: Chief Strategy Officer. That, that's one of the best titles you can carry. That sounds pretty cool. Welcome everybody. This is Tuesday Morning grind episode number 69. And it is a rare privilege to talk to someone with this much experience and public service background as Mark. Our uh, Mark Weatherford is uh, the Chief Security Officer at Alert Enterprises. A really long and distinguished uh, background in public service working at nerc, US Homeland Security, States of Colorado and California, as Well as the U.S. navy. Uh, so I'm going to have a lot of fun just picking your brain about random topics today. But thanks so much uh, for being with us today.
Speaker A: Thank you, uh, Christian. I'm happy to be here.
Speaker B: Cool. So with a background like yours, I think the best place to start is just. Can you give us a quick high level overview like how did you get into security, like the career highlights and then we'll dive into some of that.
Speaker A: Yeah. Well, as you said, I was in the Navy, um, and uh, then the Navy, um, right after high school and the Navy and their infinite wisdom. I um, wanted to be a CB and drive tractors and build bridges and they said no, we think learn this uh, this electronic stuff. So um, I, I basically become an electronics, uh, uh, expert. I went to school on a big mini um, computer, um, back in the 70s. Um, and then uh, I got commissioned in the Navy. And um, and I ended up going to graduate school in the 90s, uh early 90s. And um, uh, I'd become a, when I got commissioned I became a cryptologist. Um, and, but, but what I know about cryptology could fit in a thimble. So um, I was really in the SIGINT business. But early on I got uh, when I was at grad school I, I wrote my thesis on information security. Um, and this was in the early 90s. So it was way before cyber security was cool. Way before cyber. The term cyber security had even been coined. And um, and so uh, that, that kind of started my career down this path. And um, I spent the last decade of my Navy career, um, doing uh, information security jobs at various places in the. Around the Navy. Um, and after the Navy went in the, in the private industry, I worked for Raytheon for a few years, um, in, in information security. Um, and then uh, I got hired as the CISO for the state of Colorado. Two governors here and then um, Governor Schwarzenegger from Cal, he was in California at The time called and, and asked if I could come to California and build the same kind of program that I'd done here in Colorado. So as my famous tagline is, you can't say no to the governor. Um, so I went to California, was there through the end of the Schwarzenegger administration. Then I left and went back to private industry, um, at nerc, um, and was running uh, the chief security Officer at NERC and working with electric utilities all across the nation, really around siphon, uh, uh, SIP compliance, um, and just helping the utility, uh, utility industry. Um, very exciting. And I literally never thought, I thought that would be my last job ever. And uh, I got a call from the administration asking me if I would um, come back into the government, uh, and go to dhs. So I became the uh, first Deputy Under Secretary for Cybersecurity at DHS and again was there for a while, left, went out and, and went consulting for a while with the Chertop Group. And then I, uh, did what no one, including myself, ever expected and I moved to Silicon Valley and, and joined a startup and worked in a startup for a couple of years. Um, and yeah, that's very exciting.
Speaker B: Like from going from, you know, startup or from really going from the biggest of the big government, Homeland M Security to a startup, that must be very different. You mentioned in the early, early uh, 90s you did a thesis on cyber security, which, which sounds like it kind of started it all. Do you remember like what sp sparked that curiosity? Because that's, that was pretty early on. Like it wasn't what it is today. Cyber security. Do you remember what sparked that?
Speaker A: Well, you know I, I was, I was in a, I was in a technology, uh, curriculum at the Naval Postgraduate School getting my master's degree. And um, and so I was taking a ton of, of uh, remember this is really early, it sounds funny to say this today, but I was taking networking classes and coding classes, um, and, and it was just really interesting to me. And uh, and then as I started looking around and thinking what the heck am I going to write a thesis about, um, a friend of mine, um, suggested this and he said hey, and I'll give you a little bit of funding to you know, if you need to go travel, you need to do research, whatever you need to do to, to write your thesis. And I'm like, okay, it's a great idea and you're going to provide me funding as well. So what the heck. So that, that did it, you know, that, you know, I wrote the thesis again really, really early. There's only a, they were doing information security. And so my thesis got a little bit of ability inside and, and um, my next job after that I was the, I was the network security officer software, uh, support activity where the Navy was developing these huge um, applications for, for big systems in the Navy.
Speaker B: So I know you went to private sector for a little bit, then you went to states, uh, Colorado and California. When you think about cyber security, like for a bunch of people, uh, what are for context. So at a startup, you know, cyber security might mean application security or user provisioning or maybe you're building a product. So that's how cyber security manifests itself in your life. But when you're thinking about public sector, uh, which I have less experience on, I would imagine it would be like policy making and some of the same blocking tackling when it comes to cybersecurity. But what were your day to day or primary concerns when you were working for Colorado and California?
Speaker A: Well, they were very similar in everything. Scale is like 10 times as big as Colorado on the government side. And it really. And you're exactly right, it's a lot of leadership, a lot of policy work. Um, you know I, I started spending a lot of time with legislators, educating legislators. And so I, I joined Colorado in 2005. The state of Colorado, 2005, I think. And um, so you know, nobody in state government knew anything about security. There was, I, I was the first CISO for the state of Colorado. And um, my job really around um, it kind of encompassed a whole bunch of things. Um, but working with the security leaders and each of the, and kind of bringing them together. So each of the agencies in Colorado at the time, you know, they were fairly independent. No, no, no, they were 100% independent. There was very little collaboration, very little communication, um, between the security teams. That was kind of my mission number one was um, to create a community of security within all of these state agencies. But concurrently I found a champion in the legislature, um, state, ah, Senator Ronnie May. Um, he was a retired Air Force guy. So we kind of had a little bit of a, a bond, a military bond. But you know, I was talking to him and I said, you know, have state legislation around cybersecurity. And you know, if you, if I've learned one thing about politicians, it's politicians like to legislate, um, they like to put their name on things. So, so we did, we wrote a piece of legislation for the state of Colorado codifying my role, uh, in this in and state government. Giving me a budget, giving me, you Know really a place to live. And we were the first state to actually have legislation, uh, that, that did that for us. And um, so, and then very similar. When I got to California I, in Colorado I had I think 22 or 23 state agencies. In California I had over 160 states state agencies, um, agencies, boards, commissions, councils, cats and dogs and um, and you know, and our IT budget in California at the time was something like $3 billion. Um, which is, was a lot back in, you know, in the, in the late aughts. Um, so I was built, help build a community around security amongst all of the um, the state agencies. Um, worked with the legislature, um, tried my darndest to get Governor Schwarzenegger to say cyber security during a State of the Union address, but he never did it. But you know, so it was, it was, they were very similar. Just everything except the scale of, of that. So a lot of policy work. Sorry about that.
Speaker B: No worries.
Speaker A: Um, I don't know why that's going on. It shouldn't be. Um, so a lot of policy work. Uh, we wrote the first um, for California anyway, uh, state cybersecurity strategy, um, you know, where we were, where we were going to go. Um, worked with. Um, I didn't have a lot a big budget in California, um, uh, but I had, I think we had eight or nine people in my office and we really were just working, trying to um, trying to get the haves and the have nots in state government working together. And there were, there were a number of opportunities where we're really able to help some of the smaller and under underfunded agencies. When you know, when a big agency would say we're going to go out and buy you know, 20 firewalls, um, I would say hey can you buy one more for this other agency? And then you know, magic of budgeting, we were able to make some magic happen. And um, you know, and, and even in some cases when a big agency would be buying new infrastructure, we'd be able to take some of their old infrastructure and repurpose it for agencies. Um, we built one, one of the other, I think really successful things that, that we were able to do is we kind of put together at the time a spreadsheet of, of all the people, um, or most of the people in state government that and what ex. What cybersecurity expertise they had. So you know, if I had a checkpoint firewall guy and you know, Department X and uh, Palo Alto firewall apartment, why and you know an endpoint guy, I knew where they all were. So if somebody had an emergency or somebody had a need, we could say, okay, call, you know, Sally Smith over here and, you know, talk to the CISO and say, hey, can we borrow her for a couple days? Because another agency over here needs some help. So, um, that was. That was pretty successful, you know, to have that, that kind of, uh, resources available and know where they all were.
Speaker B: That's. That's a great swath of, like, very practical things, but also legislative things, which are very macro. And government, um, what is the process like generally? Cybersecurity, especially, you know, in the early days, is not well known. Like, people are up to speed on all the different cybersecurity risks, how that's impacting the world, the things you need to do to implement better cybersecurity, even how to prioritize it. I guess that's changing a little bit with cybersecurity in the headlines. But when it comes to, like, legislation, there's an infinite number of priorities that people want to build laws around or best practices around. How are you able to kind of get the right people in a room and start the conversation, maybe bend their ear to get legislation drafted? Were there things that you were able to do to make that happen?
Speaker A: Yeah, the big thing is be very proactive. And I tell CISOs this all the time. It doesn't matter if you're in the public sector or the private sector, know who your legislatures are. Legisl up, say, hey, you know, um, I'm Sally Smith. I work at this electric utility company. Or I'm, um, John Doe, and I work at this big retail outfit. And if you ever need help or you ever, ever need have questions about cybersecurity related to an industry like mine, call me up. I'm happy to join you. So I did a lot of that. I, you know, I. I spent a lot of time on Capitol Hill when I was at dhs, walking the halls, uh, meeting with legislators, meeting with their staffs, um, and really just being available to them when they had questions. It's funny you bring that up. I gave a talk last week, and, um, the talk was, uh, my talk was around legislation and what's going on in the legislative world. And, um, as of last week, there were, in the federal government, there were over 2500 different bills that had either cybersecurity in the title or cyber security was a big part of the legislation. So we've gone from, you know, 20 years ago, when no one would even say cyber security, to now. Everybody wants their name on A piece of legislation that talks about cybersecurity.
Speaker B: Do you think? So I look at like uh, one of the popular things that people like to think about are the emerging trends. You see things like crypto, you see things like uh, what Facebook's doing with Metaverse and all the security concerns around that, or quantum computing or machine learning, you know, throw in your, your buzzword here. And then you look at cybersecurity, uh, legislation, uh, that's uh, actually getting passed and it's mostly, mostly mandating the bare minimum, the basics like incident response or access control. Do you think that uh, like, what's the plan here? How do we get like the, the national government or state governments to somehow catch up to the realities of where we're at with cyber security? Is there any path to do that?
Speaker A: Man, I tell you what, that's a million, million dollar idea if you know how to answer it. Um, and the answer, the problem is nobody does. You know, legislators, politicians are by very nature are reactive. They very, are planning for the future. Um, and I'll look at, you know, Colonial pipeline event last year was a, was a classic example. Um, so you know, after two months after Colonial pipeline, legislature and tsa, actually it was a tsa, they, they created new standards around pipeline security. And at the time I was just saying, no, let's don't do this. You're going down this, this very siloed approach again. You're, you're going a solution for one sector of the economy. We need to be thinking broader and look at cybersecurity for the entire economy, for all of the sectors of critical infrastructure and create these baseline, you know, these baseline standards or baseline requirements for companies, um, so that we don't piecemeal this, we, we continue to piecemeal security together. And, and you end up having all kinds of unintended, that um, instead of doing something one time, you do something dozens and dozens and dozens of times, which is very inefficient, you know, and that's why you end up with 2, 500 pieces of legislation. And instead of perhaps a couple dozen pieces of legislation. Mhm.
Speaker B: You, you work for, for nerc and you know, that's obviously a piece of critical infrastructure that they're monitoring. How mature do you think, uh, it. I would think because critical infrastructure is so important that it would have a level above in terms of security than maybe uh, you know, the administrative office for some small town. Do you get the sense that that's true? That like critical infrastructure is better security? Or are they still behind too. I guess I'm asking should we be worried?
Speaker A: Um, well I would never say, you know, I'm not a, I'm not a fear guy but, but yeah, we should be worried. I mean we have to be worried and you know, world events tell us that. But you know, up until just very recently, um, the electricity industry is the only industry that had mandatory regulatory requirements. Um, utilities and nuclear power. But you know, so when you look at all of their 15 other critical infrastructures. 16 critical infrastructure, you look at the other 15, they're mostly self policing, um, but there's no government oversight. And I think it's, you know, it's been unfortunately and I say, I say this because I am not a regulatory guy. I would rather that we be to do this without having the government push regulation. I think it's been over again that unless uh, there's some kind of elling cattle kind of a uh, incentive and maybe a negative incentive incentive, you know, the private sector is not just going to step up and say okay, we're going to start spending money or we're going to start devoting resources to cybersecurity, um, if there's no, you know, if there's no requirement to do so. Um, and that's why look, today you know, is, is, are the SIP standards in the electricity industry perfect? By no means at all. But the electricity industry is far better off from a cyber security perspective than many of the other critical infrastructures in my opinion.
Speaker B: It's kind of interesting like what uh, payment card industry was able to accomplish because uh, the card brands got together, they formed pci and that was at least from what I can see, probably one of the more effective uh, self regulation tactics out there. And I think they did that because the consequences were just so high, like it was hitting their bottom line. So they decided they had to do something about it. But I think the consequences are also really big when you look at some of this critical infrastructure. So I wonder why similar self regulation tactics haven't haven't come to play or at least reached that level of maturity which kind of makes you realize how special PCI is that they were able to accomplish.
Speaker A: Yeah, I mean, yeah, well at the time, you know I remember I was, I was there and you know, at the time, you know, some of these car companies were writing off hundreds of millions of dollars. Um, yep. Just as the cost of doing business and PCI was, was the result of trying to get behind that. Now I mean the nuclear power industry, they have been self regulating for a number of years. Um, and they have their own processes that of course there. I don't even know what the number is today, but it's 10 years ago there were only 104 nuclear power plants in the nation. So it's a very small number. It's, you know, and those 404 were probably owned by you know, 20 different companies, maybe 15 different companies. So it's a very small number, very easy to hold each other accountable to, um, to those kind of standards. What, you know, you get into the oil and gas business or you get into the water industry and it's just, you know, it's, it's just the wild, wild west.
Speaker B: Yep. What about? Um, so you talked a little bit about what you did at the state level. How did that ratchet up or what was the new level of responsibility when you joined Homeland Security? Because you're also the first. So I imagine there was a lot of like defining what that position should even look like. But what were you doing there?
Speaker A: Well, I was the first quote, Deputy Undersecretary Phil Reitinger had been, I was, he was my predecessor, but he had, he, when he was there he had both cyber security and physical security. And then I came in and they split those off. But um, the difference was, you know, I was focused on. I had two jobs, two primary jobs actually three jobs. I was in charge of national communications. Um, we had. The National Communications center was part of my portfolio. Um, I was responsible for uh, uh, working with all of the civilian um, uh, agencies. Civilian federal agencies. So civilian being non dod, non intelligence community. And then uh, probably the most interesting part of my job was working with all of the critical infrastructures. So working with, you know, with electricity, water, communicate, healthcare, etc. Etc. So you know, the scale of that is just vast. I mean every day, um, every day something happened in the world that impacted our organization. Um, and you know we had, we ran the nkic, the National Cybersecurity, um, Intelligence Center. We ran the US Cert, we ran the control Industrial control system. Um, we had, I mean all these different organizations were in, in my organization. So you know, every day something was happening. You know, we were, we had people traveling to other countries helping um, other countries with, with their cybersecurity issues. Funny, um, story. I, I went to Saudi Arabia, um, to brief them on, on how we had stood up and what we were doing at um, DHS with, with cybersecurity. And, and as we were wrapping up a two day talk they said well, we'd like for you to come and, uh, and help us build our, our organization. And I said, I don't think you understand how this works US Government, I can't come in and, uh, you know, help you. I did, I did help. I did work with them and help them. And now today, you know, Saudi cert. Saudi cyber security is like one of the best in the nation. The best, um, nations in the world that, um, around cybersecurity, they have incredible, incredible program there.
Speaker B: You know, uh, in the private sector. One of the things I hear CISOs talk about, especially big organizations, is like doing a risk assessment. And out of that risk assessment falls a set of priorities. And then they're going to focus their efforts on a set of priorities for the next year that's hopefully going to move the needle for the organization. When you're working for Homeland Security and you have an infinite number of things that need your attention, like how does that size and scale of an organization prioritize anything? Like, how do you know what to work on? Was there like a risk assessment process where you just kind of putting out fires? What was the way you balanced your work?
Speaker A: Yeah, well, it was, um, the way you do it is you have really good people. Um, I had a number of just amazing people working, uh, for us at dhs. Um, and you know, like, like in many, uh, in many government organizations, people that could have been making a lot more money, could have had a lot higher profile job in the private sector, but, you know, they chose to, to work in, in the government. So, you know, and having great leaders in each of these organizations, really, I, I won't say it kind of, I won't say that it, it freed me up to worry less. I guess it did free me up to worry less because I knew that there were good people there, um, in charge of those organizations. And um. But, yeah, I mean, you know, I worked on a daily basis with the White House, with, With the legislature, with Secretary Napolitano and, And her staff. You know, we. There were 23 different agencies that were part of DHS. You know, we worked with the Coast Guard, worked with the Secret Service, uh, Transportation, um, Safety Administration, um, you know, all of these big. Each of these organizations were. Could have been a standalone company on their own, and we had all of them working together. And you know, it was funny. We would have. I would have a weekly meeting and had all of these different agencies, you know, the, the security leads at all these different agencies, um, show up at this meeting and, and you talk about hearing the problems, you hear the problems of, you know, the, the um, the Coast Guard, what they're doing, you know, and, and how they're integrating cybersecurity in their new ships. You talk about customs and border patrol, you know, think about all the challenges that they have with, with data and securing data on all the immigration related things. And then they, I mean it was, it was a pretty dang big job, I have to say.
Speaker B: Did, when you come in, uh, is this, when you take a public office like that, is it a 40 hour workweek or is it just for, for the amount of time that you're in that position, it consumes your life. Like what does it feel like to be at such a role?
Speaker A: It's, it's, there's, there's no days off. I will tell you. I, I went on vacation in Costa Rica for a week and I had, they issued me a sat phone to go so that wherever I was, I was available. You know, if something bad happened in the world, you know, they want to be able to get ahold of me.
Speaker B: Um, one of the things I talk about for like we're a small business, we're about 50 people and we're kind of at this stage where uh, we have layers of communication. Uh, for the first time I've worked at larger organizations, but it's kind of watching it grow organically. There was a time where we could all sit around a conference room together. Now we have layers. So we developed this thing called a management operating system where we have you know, weekly meetings, one on ones, larger team meetings. But it was kind of an interesting process going through that for the first time because it was infrastructure that did not exist previously. So we had to be creative in terms of how we were going to communicate. Layer communications for uh, organization like Homeland Security. How much creative liberty do you get as a leader to like walk in and like tell people how you want to be communicated to. What bubbles up to you and how much of it is kind of built into, you know, the infrastructure that already exists?
Speaker A: Well that's a great question. I never, never thought about it a lot. But I, I can remember when I got there they said, okay, here's this guy, he's gonna, he will carry your bag with you wherever you go. This person will go with you to make sure that you know, the, the, that um, you have some interface between you and the, the um, audiences where you're speaking, you know, somebody to, to communicate for you. And I said, you know, and it took me a little while to figure out to say, wait a minute, I don't need this. I can carry my own bags, I can open my own car doors. You know, if somebody wants to come up and talk to me, they can. And so it took me a little while to figure out saying, to say no, I don't want all, uh, that, you know, kind of um, level of effort to help me. I, I really can do much this on my own. Um, but at uh, some times, I mean, I gotta say having a driver was probably the most valuable thing that I had because you know, I would spend probably four hours a day, many days going back and forth from meetings and D.C. you know, even though it's four miles away, it may take you an hour to get there. So having a driver enabled me to, you know, to, to be able to work while I was working. Um, but you know, I had a, I had a really, I had, I thought at the time there's a really big budget, not quite a billion dollars. Um, but that was to fund, you know, that was to support almost 2,000 people, multiple, multiple hundreds of different programs. Um, and where I think some of the flexibility came in, where I was able to look at program that had been in place for a long time and say, does this program still make sense ten years later? Um, could we start cutting back on this program and fund other things that may be more important today than they were 10 years ago? And you know, I got my hand slapped a couple of times, tried to, I tried to um, kill off a couple of programs that um, that were actually legislatively, you know, the legislature actually they. Funds money that goes to very specific programs. And so um, you know, I tried to uh, try to limit um, a few of those programs. And then I realized, well, wait a minute, you know, I don't have the authority to actually move any of that money because that's, that's legislatively appropriate. Um, but we were able to, you know, to kind of streamline a few things and start a few programs that exist today. And I, you know, I almost wish you could say that program that you start in Washington D.C. has to have a maximum five year lifespan because as we all know, technology changes so fast that you know, anything that you start five years today in five years is going to be obsolete. And if it's not obsolete, that means you're probably spending a lot of money to maintain old technology or to refresh old technology. Um, so, you know, there's a, there just the bot. There's just a certain amount of inertia that happens in Washington D.C. that um, that people just learn to live with and that's why, you know, and I said it a couple times, um, that's why I don't think I was a good government, uh, employee. Because I just don't have patience kind of stuff, um, to live with the status quo just because it's the status quo. That.
Speaker B: So before starting risk360, I was at big consulting firms and M M. Mostly my role was to deliver client work for the most part. Um, and now my role has evolved over the last six years in becoming CEO to kind of like leading strategy, leading people, which is, uh, a skill I didn't realize took so much effort to develop. Like it's a discipline into itself.
Speaker A: And I look at your, Your.
Speaker B: Your career. You were, uh, in the Navy. Sounds like you took on some technical roles, you took on some consulting roles, then you went on to lead some of the largest organizations where I imagine communication and just leadership and, and trusting people is the name of the game. Like, that's the real skill you need. How do you think you. Is that something that came natural to you? Did you just find yourself being really good at that, or did you develop into it? Like, what gave, you know, a technical cybersecurity guy who did a thesis on cybersecurity the right tool set to be successful in that career?
Speaker A: Well, you know, I say this all the time. The Navy, the US Military, um, is one of the greatest meritocracies in the world. You know, if you can do your job well, it doesn't matter where you came from, doesn't matter how you grew up, who your parents are, how much money you have, the military will reward you. Um, and I don't know that I was a great leader early on in my career, but I had a lot of great leaders. I had people that I, That I watched, that I learned from. I, I focus a lot of my attention on. On actual leadership stuff. Um, so. And I can remember, man, I tell you, I have. I. I've said this a number of times. I can remember having, um, these meetings right after I got out of the Navy, um, especially when I was consulting. And, you know, I can remember having a meeting. I won't say who the company was with, but, um. And we spent two hours. I was meeting with four people in this. In this consulting company. And they were just asking me, talking to me about questions. And at the end of this, they said they were just so enthusiastic. And they said, this is of our time that I have ever had. And I thought, we're just about leadership. We're just having a conversation about getting stuff done. You, uh, know, m. Maybe around answering it. I think the military. You, uh, know what I learned, the discipline I learned in the military, the leadership skills that I learned in the military really translated well, um, into the private sector.
Speaker B: Yeah. Our, uh, co founder, who's also named Christian, he's a West Point grad. He was captain of the army. So you guys got some nice Army Navy stuff going on there. He would say. He would say the exact same thing. Uh, yeah, he was not a cyber security. He didn't have a cyber security background, or at least not an expensive one. I think had a few years of experience. But he's an incredible leader of people and it's interesting to watch military, uh, leaders transition to civilian life or even public sector like you did in the leadership skills that you get, I guess, just from watching other great leaders and just accumulating all that body of knowledge. So really interesting. Um, I do want to talk about what you're doing today because you're. You're in the private sector now at Alert Enterprise. Can you talk about what you do there, uh, products you'll offer, your role there?
Speaker A: Yeah, well, so I actually have two jobs right now. Actually have multiple jobs right now. But, um, I'm the. I am the chief security officer at Alert Enterprise. And we are a. We're a tech company really focused on the convergence of, um, of IT OT and physical security really around identity management. Um, identity management. So what does that mean? Um, you know, if you go into most big organizations today, they will have at least two, sometimes three different security organizations. Security team, and those are the gates, guards and guns guys, um, you know, that are. That are responsible for, um, you know, for. For protecting the physical facilities. Then, um, you'll have your. Your IT security guys, your CISOs, and then, you know, potentially we'll have your chief security officer who is responsible for, um, ICS and OT security and what. And so each of these organizations, um, internal organizations, typically have their own infrastructure, their own people and their own budgets, which means most of the time, um, you end up with these silos of security. And uh, it first came to me when I was at NERC and we had a number of security incidents during my period there where, um, we would find out in many cases months after the fact that, um, had had a security incident at say, a remote, um, substation somewhere. And they sent out their. Their physical security guys would find out that, okay, yeah, somebody came out and they threw a chain over the fence, dragged the fence down, and they went in and stole all the copper. But we had a couple of incidents that um, that they broke into the substation, then they broke into the substation building themselves. Nothing appeared wrong. And then months later, you know, the ICS guys are finding out why are all of our PLCs, why is all the logic, why is all the logic code, um, um, having problems with it. Somebody broke in there form three ago that actually broken into this and caused some uh, damage to the equipment inside there. It wasn't just a, a physical security break in. So what Alert Enterprise does and we're, you know, we're used by airports now, by banks, by oil uh, and gas companies, electric utilities. We're able to take the data from physical security um, and integrate it with the data from IT and OT security and provide a bigger, more holistic picture. So now um, and really around identity management. So um, if you got a badge to get in the front gate of a building and you need that badge to log into a room and then you need that badge to log into a computer, you might want to, want to know if somebody's logging into a computer but they didn't log, they didn't come through a gate somewhere. Or um, or, or like in airports where somebody will have a badge like the baggage handler may have a badge to get through but all of a sudden this badge is being used in another part of an airport where there should not be a badge. So being able to integrate all of this um, information and provide a more holistic picture um, is just, it's game changing. I mean it increases security by orders of magnitude. And we find ourselves today working with, even with HR a lot because you know, the first place a new employee goes is to hr. Ah, to get, you know, to get bads and get outfitted with credentials. And many times um, as employees as they stay in the company and they take new jobs or they get new accesses, the hr, um, HR data never gets upgraded. So you find these employees for 10 or 15 years and they have all these accesses that they've just been accumulating over the years. So now we're working with HR and April to help them clean that up, clean up their er, systems. You know, from a, from an identity perspective that's really, you know, kind of in a nutshell what, what, what Alert Enterprise does.
Speaker B: Absolutely. I've been on many data center visits where uh, you know, the security team and the facilities team is completely different. So access controlled at uh, a, you know, services level or you know, active directory level is totally decoupled from who access has access to the physical facility and the badge reader and making those two things talk to each other. I could. It makes total sense.
Speaker A: Oh my God. Yeah. What about the work? I said. I said let me, let me so please. The other job I have is I'm actually. I'm the Chief Strategy Officer at the National Cybersecurity Center. Um and this is something um Governor Hickenlooper started this uh, organization in I think 2016 uh in Colorado Springs. Um and he wanted to bring together a uh non. Worked with small ah and medium sized businesses and small and medium sized government organizations to help these people. So um, I'm the Chief Strategy Officer there and now five years later. I um, was on the board initially and I joined the company as an employee, a part time employee last year. Um so uh, we're doing. The National Cybersecurity center is doing all. All kinds of really cool stuff these days. Educating Slaters, educating staffs. We have a program where we're educating K through 12 um uh uh students around the. Around the country. Um, and. And we, we um. Last year I guess 2020 now we were designated as the executive director of the Space isac. So. So the Space ISAC operates uh, out of the NCC as well. So huge. It's, it's a small organization staff wise but we have a whole lot of responsibility. Very cool place to be. Yeah.
Speaker B: What is your role like Chief Strategy Officer. That that's one of the best titles you can carry. That sounds pretty cool.
Speaker A: Yeah.
Speaker B: What do you, what do you get to work on like your role specifically?
Speaker A: Yeah, for the CEO we're just looking at opportunities where um, new thought into our existing programs. M. Look at um, how these existing programs can um, can mature better. We've had a couple of programs over the years that kind of ran their course and we said okay, these are no longer priorities for the organization. So we're going to kind of let them uh, let them uh often and, and um, and just sunset them. Um and we're always looking for. We have, we you know we have a couple of main really programs that we're responsible for education being one, space ISAC being one and just we do a lot of thought leadership kind of things as well.
Speaker B: Do you know of Rock Lambros, he wrote the book Cecil Evolution. I think he's a member of that. He was just on the podcast podcasts. I know there's a lot of volunteers there but uh, if you know him he's. He's remember that work too.
Speaker A: You mentioned it in fact I. I endorsed his book, so I think I'm on the back cover of the book.
Speaker B: I think you are. That's a leading question. Excellent. Well, that's awesome stuff. If you're listening to this, I'll definitely link to that organization, uh, so that everybody can get to that. And Mark, thank you so much for your time. This has been an awesome conversation. I appreciate it.
Speaker A: Thanks so much, person. Glad to be here.
Speaker B: Hey, thank you for watching Tuesday Morning Grind Podcast. If you like content just like this from cybersecurity executives, thought leaders, hackers, then come on over to risk360.com, check out our resource center where we have blog posts, white papers, videos, all for free, that can teach you about cybersecurity. If you want to know more about CyberSecurity certifications like ISO 27001, SoC2, PCI, HiTrust, and others, we have a ton of content on that. So whatever you're looking for, we have a lot of resources. Head on over to risk360.com, shoot us a note, and we look forward to keeping the conversation going.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.