AI, Risk, and the Board: A Straight Talk with Sean Murphy and Chuck Markarian
Smart Cookies features Sean Murphy, Field CISO at F5 and Former CISO at BECU, and Chuck Markarian, Former CISO at PACCAR, discussing AI governance, board communication, security fundamentals, and the risks that come with team burnout.
Listen now
Sean Murphy, Field CISO at F5 and Former CISO at BECU, and Chuck Markarian, who spent 21 years at PACCAR where he became the company’s first CISO, have both led security programs through multiple waves of technology change. In this episode of Smart Cookies, Derek sits down with both of them to talk about what the AI conversation actually looks like at the board level, and what security leaders need to have in place to navigate it well.
Both guests come back to the same point from different angles: the fundamentals matter more than ever. Patching, identity governance, data controls — these are what put an organization in a position to absorb whatever comes next, whether that is AI, quantum, or something nobody has named yet. Chuck puts it plainly: organizations doing the basic work well are simply in a better position to deal with what comes down the line.
On AI specifically, Sean draws a clear line. Non-human identities are projected to outnumber workforces by ten to one or more. Organizations without solid identity governance in place today will find that a serious problem. He also argues that many organizations are implicitly accepting more risk than their stated tolerance would suggest — because nobody wants to be in the headlines.
The board section of this episode is practical. Chuck describes the simplest measure of whether a board presentation is landing: are they looking at you, or at their phones? Sean adds that being invited to strategy sessions and offsites, not just board meetings, is the real signal that the board understands cybersecurity as a business risk and not just an IT risk.
The episode closes on a question Sean raises that he says boards do not ask enough: how is the mental health of the security team? Burnout is a leading risk indicator. Tired people make mistakes. Tired people miss things.
What this episode covers
- Why security fundamentals matter more in an AI environment, not less
- How to frame AI risk for a board without triggering panic or stalling innovation
- What governance needs to look like as AI adoption accelerates
- How to know whether the CISO-board relationship is actually working
- Why team mental health is a security risk indicator worth tracking
FAQ
Who are Sean Murphy and Chuck Markarian?
Sean Murphy is Field CISO at F5 and Former CISO at BECU. Chuck Markarian spent 21 years at PACCAR, where he became the company’s first Chief Information Security Officer, and has held security and IT leadership roles across Boeing, AT&T Wireless, and others.
What do Sean Murphy and Chuck Markarian say about AI and security fundamentals?
Both argue that AI makes the basics more important, not less. Patching, identity management, data controls, and defense in depth are the foundation that puts an organization in a position to handle whatever new threat or technology comes next. Chuck says organizations doing those things well are simply better positioned. Sean adds that identity governance in particular is urgent — non-human identities are projected to outnumber workforces by ten to one or more, and teams without solid foundations in place will struggle.
How should security leaders frame AI risk for boards?
Chuck describes it as storytelling — translating the virtual world into terms the board already understands from the physical one. The goal is helping boards see that AI introduces risk on a spectrum, that some of that risk can be managed down, and that the answer to innovation pressure is guardrails that work with the business rather than against it. Sean adds that boards carry a lot of curiosity and some panic around AI, and the CISO’s job is to be the voice of confidence and reason.
What does good AI governance look like?
Sean frames governance as starting with inventory. You have to know what AI is in your environment, who is using it, and how data moves through your organization. From there, acceptable use parameters, contracting language around data handling, and ring-fencing controls become possible. He says organizations embarking on AI without governance in place are going into the Wild West.
How do you know the CISO-board relationship is working?
Chuck starts with the simplest signal: are they looking at you when you present, or are they on their phones? Engagement and questions related to what you have just presented tell you they are listening and see value in what you are saying. Sean adds that the deeper signal is being invited to strategy sessions and offsites, not just board reporting. That means the board understands cybersecurity as a business risk, not an IT risk.
What question do boards not ask enough?
Sean says boards do not ask often enough about the mental health of the security team. Burnout is a leading risk indicator. People who are exhausted make mistakes and miss things, and that is a real source of organizational risk worth tracking and surfacing at the board level.
Full transcript
Derek: Well, welcome everybody to Smart Cookies Podcast. We are here again, focusing on local leaders that are translating some complex topics into hopefully some clear business insights and building communities around these discussions. I’ve got Sean Murphy and Chuck Markarian in here, two seasoned veterans in the cybersecurity world who have worked for and led a number of notable organizations around town.
We’re gonna be talking about the soup du jour right now of AI in the boardroom, and hoping we can get our conversation into some things that are really gonna help leaders that are trying to bring along their organizations on what’s real, what’s not, and everything in between.
But before we do that, I think it’s always important to get everyone’s origin story. I’m gonna start with you, Mr. Murphy. Before we get into this talk, you gotta help us and tell the story again of how your high school baseball career and the Air Force led you here.
Sean: Yeah, so it starts with the idea that you’re often asked, “What did the 10-year-old version of yourself wanna be when you grew up?” And for me it was to play catcher for the, at the time, Pittsburgh Pirates, ’cause I was from that area. But then the follow-on is, you’re obviously not a catcher and never have been for the Pittsburgh Pirates. Well, what happened? Why are you not doing that? And the answer is that I found out that I could not hit a curve ball at any kind of proficiency, certainly not one at 90 miles an hour. So I went to college for a little while, and then found that you actually have to go to classes when you go to college.
So that led me to go into the Air Force, and that is me bragging about doing the best, smartest thing I’ve ever done in my life. Joining the Air Force was a great experience. And then fast forward many years, I got into healthcare administration, and then at some point, to get the story to the point where I’m going into information security — which was healthcare information security at the time — was around the Air Force attaching medical devices to the warfighter’s network, and that came with a lot of security requirements that the commercial sector, where you buy medical devices from, had no concept of. The Air Force warfighter line did not negotiate cybersecurity requirements. This is back in early 2005, 2006 — that far back — that the Air Force, even in Air Force medicine, was serious about cybersecurity. So I learned about cybersecurity at that point. And then the rest is history. Got out of the Air Force and went into the private sector, and again, healthcare information security really wasn’t that pervasive across the healthcare system. But that changed very rapidly and dramatically through data breaches, and I was fortunate enough to have my first two CISO roles as kind of the turnaround specialist for recovering organizations that had massive data breaches. And at BECU Credit Union, never had a data breach, so that’s good. Knock on wood, cross my fingers. Yeah, a real quick version of a lot of years of battle scars of being in the cybersecurity business.
Derek: Wonderful. Now, Chuck and Sean, I’m gonna ask you to needle here ’cause I know the two of you guys are very good friends. So we’re gonna disclose that up front.
Sean: I always love to hear the origin story of Chuck, so I will not —
Derek: Yeah. Worked at some fascinating places — PACCAR, math and science background. I’m sure if I cyberstalked you more I could find even more insights, but maybe not. Tell us a little bit about your origin story.
Chuck: So I went to school at WSU. He’s got his USF fan sign back there. I’m a Coug. Sorry you live near Husky Stadium. I know —
Derek: I’m gonna find my Husky gnome floating around here somewhere.
Chuck: So went to school at Washington State. I grew up in Spokane, always played sports until I got to high school and realized when you’re going to a four-star school and you don’t even weigh 100 pounds and you’re barely five-six, you’re probably not suited to playing football with everybody else who’s about 150 and up. So any hopes I had of professional football or baseball kind of died on the vine there. But I kept playing sports — intramurals and all that stuff.
Went to WSU and got a degree in math and physical science, physics, chemistry, a teaching certificate, and was gonna teach high school and coach baseball. That’s what I wanted to do. And then realized —
Derek: Oh.
Chuck: — that teachers do not make very much money at all, and I thought, “Well, maybe we’ll see what else is out there.” And I got a job at Boeing. Through the interview process it sounded fascinating. They were doing this thing called Moire analysis and photoelastic coding, and I knew absolutely nothing about it, and I told them it sounded really fascinating. I don’t know anything about this, and they said, “That’s okay, we can teach you,” and I got hired.
So was there for about almost nine years, I think. Eight, nine years. They were waiting for a big military test. It kept sliding and sliding, so I said, “Can I go work with the computing group upstairs?” And they said, “Sure, you have computer experience.” Well, I’d run the Apple Math Lab at Washington State University, which had consisted of pushing in a floppy and saying run. That was pretty much what it was. Dating myself — Compaq 286, 4 MHz machines with five meg disk drives and DOS. So I taught myself DOS and how to write batch files in Windows and how to hook those up to mini computers and all that fun stuff. DEC machines, PDP-11s, that kind of stuff. It was a lot of fun.
Then I had an opportunity to go to AT&T Wireless into a management role, so I did that. I was there for about five years on the paging side. They sold that, and I had IT responsibility there. Back then the security side was: did you have a firewall and did you have antivirus? So that was where my kind of security career, I guess, started. Left there when they sold that company to a company called Metricall. Had to stay out of the industry for about a year.
Came back into the industry with AT&T Wireless, working for my old boss. Sean, I think Kirsten was just before you went to Premera, if I’m not mistaken. I think she was gone before you got there, but I worked for Kirsten there when I was at AT&T Wireless — she was my boss.
Sean: I didn’t know that.
Chuck: Yeah. So worked there for about three or four more years. They went through another sale — to Southwest Bell, I think, I forget now. At that point, had an opportunity to go to PACCAR, and so I did that.
But the funny thing is, when they brought me back into AT&T Wireless, it was to take what they called the e-commerce cowboys — who couldn’t spell change control — and manage them with the data team, who nothing could happen without five pages of documentation and three weeks of warning. I got those two merged together.
Derek: Find the middle.
Chuck: A lot of fun. Finished up that work and they said, “Hey, how about security?” And I said, “Okay.” And that’s how literally I fell into security. So worked with the team there, started expanding that, and then went to PACCAR. Started there with a small role, grew the role, had both security and IT responsibilities. Four of our divisions across PACCAR — PACCAR Australia, Dynacraft, Winch, and Kenworth — all reported to me for anything related to IT on top of the security stuff. The board decided they didn’t like that. They wanted to have a segregation, so I got rid of my IT stuff, just focused on security, and that’s where we kinda got security on the map. I became the first Chief Information Security Officer for them. Kinda had the role for probably about 10 years, but was truly CISO for about the last seven or eight, titled CISO for about seven or eight years. So was there in total of 21 years. It was a great company, learned a lot, treated me well, a lot of exposure to the globe, compliance around pretty much any country across the globe.
Derek: Wow. Well, thank you both for your origin stories. And the topic that I wanna dive into might be one that you may be tired of talking about, or you might not. But I think you, Chuck, you gave the great segue of just talking about where technology’s come from and what you were doing to start and where you are now. And I think there’s some interesting parallels in this now paradigm change of AI, and what does that mean when we think about going from mainframe to client server to desktop client server, SaaS, cloud — there’s some connection there.
So I guess my first question to throw into the room is: AI keeps coming up in the boardroom at the most senior level. The two of you have a wealth of experience. How’s that conversation typically look today, and where’s that conversation going over the next 12 to 18 months? And pretend one of those newer minted CISOs is in the room, and you guys are getting to teach and getting to talk to them. What are the things that you would start sharing as you look back and then as you look forward? And it’s okay if you both don’t agree, ’cause that would be good. I feel like Chuck’s ready to go, so I’m gonna tap him on the shoulder first.
Chuck: It seems like from a security perspective there’s always something new and there’s always something different coming, and AI is just one more of those new things. But what it has really felt like — ’cause I would say over the last probably five years the speed at which something new is coming just gets faster and faster. That time in between gets shorter and shorter. We’re gonna have quantum here before we know it, and that’s gonna change everything. And then who knows what’s behind beyond that. AI and deep fakes and stuff — we talked about it for years, and then boom, it was just suddenly here and we had to deal with it.
The thing I always tell people: I don’t care if it’s AI or whatever, you just have to make sure you keep the basics strong. Do the grunt work, do the dirty work, do the basic stuff that’s not sexy, it’s not fancy. Are you patching systems? Get really stinking good at doing that. Do you have some data controls? Depending on the industry you’re in, you need better controls than others. If you’re doing all those things right, whether it’s AI, quantum, whatever it is that comes down the line, you’re just in a better position to deal with that and to figure out the next steps.
So when you’re talking to the board and you’re talking about your program, you’re talking about the things you’re doing, and then they’ll throw in, “Well, what are you doing about AI? What are you doing about data protection?” Well, these are the things we’re already doing from a data protection standpoint, and these are some of the additional challenges we need to face because of what AI is doing to it. And you just come in and you share with them the plan and the approach you wanna do. Sometimes with AI, we weren’t even talking about it, and then four months later it was like everywhere, right? So that plan had to evolve very quickly, and you had to go into the board and talk to them about it and help them understand what that plan was. Which means you have to have a plan, which also means you probably have to have a budget to support that plan. And typically, at least for me, that’s one of the hardest pieces to it — you can have a plan and you can know the tools and things you wanna do, you don’t always get the budget. So what can you do? How can you be prepared without the budget? That’s as simple as I can put it.
Sean: You gotta do the blocking and tackling — things like defense in depth and zero trust architecture and identity management. They are not less important. They are the foundation of being able to even think about AI. If you are not handling human identities correctly, forget about handling non-human identities. The projection that non-human identities will outnumber your workforce ten to one, a hundred to one — that’s gonna be a nightmare for people who don’t have solid foundational identity governance and identity management in place.
It’s not magic. It’s not something you have to go out and get any really advanced tooling for, ’cause that never has saved us. There’s no silver bullet technology. That doesn’t exist, never has. But if you’re doing the hygiene and you’re doing the fundamentals, then you’ve got a chance. I’m not saying you don’t have to build on that, but that’s a step you gotta take.
Yes, in this new environment, the promise is not only will more vulnerabilities be identified at a scale we’ve never seen, but they will also go from exposure to exploit in a record time. Every model so far discounts the human intervention that exists within the detect and respond capabilities. It doesn’t talk about that activity — that exploit attempt, over and over, trying different things and data chaining pathways through — it’s a very noisy set of circumstances through the kill chain. And at that point, you should have tooling in place and processes in place that capture that anomaly that shouldn’t be there, that shouldn’t be happening. So you should be alerting on those activities. They are not silent and stealthy. But that could change if agentic AI gets improved to the point that it doesn’t go down that way.
But as of right now, that’s how I think people are seeing it. So the fundamentals are important. And Chuck said something that is so spot on — we’ve always had these changes, we’ve always had these things that come, and there’s gonna be more, and they’re gonna come faster.
And the other side of the coin is: so many of us have seen things come and go. Nobody says blockchain anymore. That was just two years ago, man.
Chuck: Yeah.
Derek: There we go.
Sean: Two years ago everything was blockchain this and blockchain that, and distributed ledger. You know it’s gonna change the world, and economies and currencies are gonna change from the US dollar to cryptocurrency. Not that that couldn’t still happen, but that’s not the thing right now. When quantum hits the papers, when quantum hits the press — Q Day or whatever they’re calling it — then it’s all, is that gonna change everything and we’re not gonna talk about AI anymore? We’ve had AI since 1975. It’s not brand new. The agentic piece of it, the frontier —
Derek: Are there any —
Sean: Yeah, I’ll shut up now. Thank you. Go ahead.
Derek: No, that wasn’t the Academy Award music coming in and trying to pull you off stage. There was nothing but brilliance flowing. I’m intrigued — you were talking about doing the foundational work, doing the basics, doing the non-sexy work. Are there themes you see in the gap between where somebody shows up, whether it’s at a board level or a manager level, with the excitement or fear, and the reality? Are there some key themes where you see people having gaps in understanding when they’re thinking about AI versus risk, AI and security? Because I think those things would be interesting for people as they’re thinking about how to build skills for themselves or to lead through those spaces as newer CISOs. Are there any themes you see there in that gap?
Sean: Well, to some extent, at the board level there’s a chance that board members will be on other boards, and they’ll certainly be in tune with current events and the literature in the industry, if they are AI-savvy in the first place. And they’ll come to the table with a lot of interest, a lot of curiosity, a lot of questions. You hope that it’s not panic, and that’s something you gotta contend with and try to be the voice of confidence and reason around these things. But then there’s also the tug and pull of a board or an executive level that wants a lot of innovation. They want growth, they want advancement. And then when you start to talk about the risks we’re taking or exposing ourselves to, or what the cumulative risk becomes and that is starting to raise, then there’s a reluctance to change risk tolerance. I’m certainly not advocating for changing risk tolerances higher — I don’t necessarily advocate for anybody taking more risk. Actually, editorial comment: many people are implicitly taking more risk, because I don’t think anybody’s risk tolerance is probably at where they really want it to be. So you’re implicitly accepting a lot of risk in that scenario.
But yeah, just avoiding the panic and keeping the confidence, and of course supporting innovation, is super important — but it’s in the face of just being able to communicate what the risks are so the right trade-offs are being made.
Derek: I’d be remiss though if I didn’t say you made a point about something that is having a notional understanding and a definition of what your risk tolerance is and what that is objectively within your organization. And even if it’s not truly quantified, it’s something that leaders are coming back to when they’re having these conversations, testing something that maybe they wanna innovate on or something that maybe there is some fear around, and testing it against. I think that’s a really interesting point.
Sean: Everybody wants to run fast and do crazy stuff, but nobody wants to be in the headlines. I have been there, and nobody wants to be in the headlines.
Chuck: Yeah. And it’s always been fascinating to me — folks on boards are smart people. Very smart people. Way smarter than me. They get business and they understand business and all of that. They are working with your executives in collaboration, making business decisions that involve risk every time they meet. And it’s looking at financial benefit versus potential financial downfall, and it’s risk-oriented. But when you start talking about security risks, it’s kinda like, “Wait a minute, there should not be any security risk. You can’t have risks on security.” It’s just a strange conversation to have to help them understand.
You’re not gonna get down in the… hopefully you’re not getting down and giving them all these details about your vulnerabilities and all of that. But you may be sharing with them a report from your auditor around what the findings were. And there may be everything’s really good and a couple little things, and they’re just like, “Well, how could you have those little things? That sounds like incredible risk. What are you doing about that?” And it’s like, “It’s not that big a risk in comparison, but it’s a risk.” And they’re saying, “It’s a medium risk. We shouldn’t have any medium risk.” You have medium risk in your business every day. You probably have some pretty high risk every day. They just look — at least in my experience — they look at security risk differently.
So I think part of what I’ve had to try and do is just put things in terms of kind of story time, if you will, to help them understand the bigger picture, the risks that exist, how we’re handling those risks. And I really always try to turn it into something from the physical world that they really understand to the virtual world that they don’t understand as much.
The one simple example I go to all the time is: I’m a thief, I’m gonna break into a house and I know absolutely nothing about it. I’m just gonna simply look for the easiest target. If I’m walking down the street and that house has a bunch of people in it, probably not good. This sign says it’s got an alarm system and a guard dog, not very good. But this one — the lights are out, the bushes are overgrown, there’s newspapers on the porch. Probably nobody’s there. That’s my easy target. We can make ourselves very strong against being the easiest target. And we can do that from a security perspective.
Then if you take it to the next level and you say, “Okay, a nation state wants something we have” — forget it. We cannot keep them out. They will get in, period. But then it goes back to kind of what you were talking about, Sean — have your detection tools in place, have the ability to spot that quickly, and then take a reaction and make the damage as minimal as you can. But it’s helping them understand that there are different types of folks out there, different things they’re doing. And then when you throw AI on top of that, and like Sean said, they wanna run — you have to help them understand, “Okay, we can do that, and here are some things to be aware of and concerned about in doing that, and here are some things that can help take that risk and drop it down.” So to me it’s always been about how do you tell that story to them.
Derek: Interesting. How does governance start to play in this? Obviously it’s a big part of a cornerstone security program. But I think there’s lots of governance that can be flat files that sit and collect dust and don’t really move the needle. Don’t address the cultural elements, the human elements, and of course the elephant in the room, the AI elements. What are the decisions and structures that you see, as you lean into the next 12 to 18 months, that you think governance needs to evolve around these forces?
Sean: The governance is part of the guardrails that we have to have in place, mostly along administrative type controls. I can’t think of any process that doesn’t start with identify or inventory. So inventory is very much synonymous in this way with the identify step in any plan, do, check type of activity. And governance is in that camp — you have to know what’s in your inventory. If we’re talking about AI specifically, you have to know what AI is in your environment, who’s using it. And we go back to: you have to know where all your data is and how it moves through your organization.
And it just goes back to the hygiene. It goes back to doing the blocking and tackling. You had to know these things, and that’s where governance starts — having the discipline around forcing that inventory, that management around knowing what you have and knowing what it’s doing. And then you go from there around the guardrails. You can put in acceptable use parameters around AI: here’s what kind of information you can put into the systems, here’s the contracting language we wanna see so that we know where the data is going and it’s not being used to train publicly available models.
If you’re not doing governance and you’re embarking into the AI world, you’re going into the Wild Wild West. It’s pretty chaotic. You have to have those guardrails in place to help ring-fence your organization around safely using AI. It is possible to be innovative and be within those guardrails. We used to talk about shadow IT — shadow AI is an even bigger possibility if not a problem.
Derek: That’s far more dangerous. And let’s be real, AI is architected to be an amoeba.
Sean: It’s so democratized.
Derek: Chuck, what do you think? So much of it is decentralized. Not to say that all governance is centralized, but Sean’s talking a lot about guardrails and ring-fencing. Where does your head go?
Chuck: Completely in line with what Sean’s saying. You have to have the guardrails out there. You have to make the guardrails acceptable to the business, because otherwise they’re just gonna find ways to work around those guardrails, and then you’re just right back where you started. So you have to make them meet what you feel you need from a security perspective, but also put them in a way that the business can work with them and get what they wanna get done. There’s a lot of give and take there, and it’s not an easy road to work through.
AI folks — this week, this is a tool they wanna use that you vetted and studied and you feel good about it, and you got the guardrails in place, and a month later, that’s old news, and now it’s this tool. Well, you can have your basic guardrails in place, but then you need to look at that tool and what can that tool do and what can’t it do. Is it properly meeting your guardrails of keeping data local, et cetera. It’s just a constantly evolving world that you have to stay up to date on. So it’s a big challenge.
And I think the other part from a true governance perspective is: depending on what industry you’re in, you’re gonna have different regulations that you have to adhere to. Sean’s got super strict ones from a financial standpoint, and he’s had healthcare in the past — again, super strict ones. Mine from that perspective when I was with PACCAR were not as restrictive that way, but they were global. So European regulations vary by country, and sometimes they can even conflict with each other. So you’re trying to meet this one, but if you meet that one you can’t meet this one. That’s another huge challenge.
And across the US, we don’t really have a lot of federal-type regulations like GDPR. So when we started dealing with that way back when, we just said, “Hey, wherever we can that it makes sense, we’re gonna comply to GDPR even across how we handle data in the US.” That was just our goal and objective. And I think when you start talking about AI and you’re a global company, you need to put policies in place that target that highest watermark.
Derek: Interesting. Kind of wanna pivot — as we’re gonna rapidly run out of time here — to some things that I guess apply to any size organization. The two of you have had to broker so many governance and technology decisions with boards. In your mind, what is the way, and how do you kinda know when that relationship between the CISO and the board is really working well? How do you orientate the relationship of the CISO with the board? I get this a lot in my business — from the Series A, B, C businesses, not just our enterprise customers — like, how do we do this right and learn from all the big organizations ahead of us? Chuck’s time to go first.
Sean: Age before beauty. I got it.
Chuck: There we go. When you’re talking to the board, first thing is: are they looking at you? Simple. Are they looking at you and paying attention? Are they looking at their phone? Are they looking at their tablet? Are they doing something else and just buying the time till you’re done at the podium?
That comes with time. It comes with developing a trust and developing some relationship with your executives first, and then with your board second. If they’re not paying attention to you, you’re probably not talking their language or a language that they understand or that they care about. If they are looking at you, you know at least you’ve got their attention. They’re listening. And when they start asking questions, and those questions have some relevance to them, then you’ve got a pretty good sense that you’ve got their engagement and their involvement, and then you can start further developing that trust.
So when you’re talking to them about whether it’s AI or whatever it is, they see you as the expert in that space. They see value in what you’re telling them, and they’re gonna listen. Now, again, they’ve got a business to manage and run, so you’re not gonna be able to get in the way of that and stop it. It’s like standing in front of a freight train. So do you run with them? How do you move with them and help them get a sense that you have a handle on what it is? And if there are gaps and you don’t have a handle, then it’s helping them understand, “Here’s the gap. Here’s what really worries me. And here’s what I would suggest we do about that.” So to me it’s: when you look at your audience, are they looking at you, or are they looking at their watch, looking at their phone, doing something else?
Derek: I love that. That’s not where I expected you to start.
Sean: No, but that is absolutely true. He speaks the truth. I won’t say the exact same thing, but I do echo what Chuck just said. I think probably, first of all, it matters if you’re invited. If they start saying, “You don’t need to be on the agenda this time,” when you were on the agenda before, then that sends a signal.
Taking it up another level — you’re really hitting the mark if the board, not only at board meetings but at strategy sessions or offsites, wants to know from the CISO. They want that strategy perspective, that business perspective. Because then they are saying that cybersecurity is not an IT risk. That was dispelled long ago. It’s a business risk. And if that’s not happening, then you’re probably not reaching them in the way you need to. And that’s not always the fault of the CISO — not every CISO is invited to board meetings at all. They pass information up through a CIO or a CRO, and that’s that. But taking it to the next level, I think we’ll see more and more CISOs involved very deeply in the business and strategy-type discussions outside of board reporting, but with the board. I don’t see how businesses are gonna survive if they don’t start thinking that way.
Chuck: Yep.
Derek: So you’re invited to the board, you’ve got their eye contact. Is there a question that you always wish they would ask, or you love to see boards ask you every time, that kinda helps you bring the right insights at the right time for the organization?
Sean: Maybe not every time, because hopefully I figure out a way to answer it and it doesn’t come up again. But I kinda like when they might say something like, “What aren’t you telling us?” Like, what is it that you wanna tell us but you’re not telling us? Because it gives me the opening to maybe be a little controversial.
Derek: Be vulnerable — pun not intended.
Sean: Yeah, a little vulnerability there too. But I don’t like — and I hope nobody gets this question — “What more do you need?” Because if you answer that question and you haven’t talked to your executive staff about what more you need, that can be a resume-generating event. I have been asked that before and I tried to dance around it as best I can.
Chuck: Yeah. That’s a double-edged sword question. I’ve got a patented response where they basically say, “Hey, do you have all the resources you need?” And my response is, “Hey, look — I have a very good executive team. They’re very supportive of our needs, and I know we’re just part of one element of the business, but they are funding security.” I said, “At the same time, there’s not a CISO out there who won’t say they could use more.” And that’s just kinda how I answer it.
Derek: Fair. Is there any question you like to be asked outside of the ones you don’t? I think it’s interesting because the two of you are in such different industries and have landed in similar executive roles. Chuck, is there something that given so many business lines and the global footprint, you always wanted to be asked or consistently wanted to be asked?
Chuck: Not really, to be honest. I always would go through what the NACDs say are the top questions you should expect to get. You never get those questions, or at least I don’t. What I wanna hear are questions related to the topics I’ve been presenting, whatever that is. I want questions around that, because then I can step out of my script and give them a little bit more detail to make sure it’s clear to them what we’ve been covering. So any time I get questions related to what we’ve just been talking about, that’s what I want. Because again, it just tells me they were engaged, they were listening, and they wanna know a little bit more.
Derek: I just love how both of you kind of bring it to that EQ, that human element, even though we’re talking about things that are highly strategic, highly technical, process-oriented. They have all the dimensions of what it means for it to manifest itself in an organization. But are you invited? Are you getting the eye contact? Are you telling a story that resonates and is compelling? Are you getting engagement? Are we aligned in trying to go the same direction together? That’s what I reflect back and keep hearing from the two of you as you give counsel on how to engage boards.
Sean: That comment and Chuck’s response makes me also think — I don’t think boards ask enough about how the team is doing and how you are. Maybe that’s not asked enough across the board. But I read all the articles about cyber burnout and CISO burnout and just how stressful the role is, how stressful this work is. And that’s true — I don’t minimize that at all. But you talk about EQ, maybe the question that should be asked is: how’s the mental health of the cybersecurity team? Tell me something more about that. Because at the end of the day, that’s a leading indicator — or maybe a lagging indicator — of a level of risk you have, because people make mistakes. People quit. Even if they don’t leave the organization, they quit. So they’re burned out, they’re tired, they make mistakes, they miss things. And I personally keep an eye on those kinds of things and worry about people’s stress levels, and I always encourage people to take time off, take a mental health day whenever they need it. But anyway, I think that’s a question I’d like to hear more of.
Chuck: Yeah.
Derek: Well, I think in closing I can just reflect back and see the educator in both of you. Now hearing that Chuck was going to be a teacher, and Sean, I know how much you lean into teaching the next generation. And I know, Chuck, you’ve got future things on the horizon where you’re doing exactly that — leading and educating the next generations of CISOs and giving back into the security community.
So I like to think that’s a small sliver of what we’re trying to do here. I appreciate both of you bringing some honest takes and leaning into topics that are already getting a lot of airtime, but maybe demystifying a few things and just helping those out there that are maybe at that midpoint or early point of their executive career figure out kind of where to go next with this.
So thank you both for joining us on the Smart Cookies Podcast, and a couple good laughs along the way. Thanks for being real, guys. Really appreciate you both.
