Also on Vimeo: watch this conversation on Vimeo.
About this conversation
A CIO Talk Network conversation with Patrick Benoit, Global Chief Information Security Officer, Brink’s Inc, hosted by Sanjog Aul. Recorded in 2023.
And how are Business, IT, and Security leaders prioritizing cybersecurity, fostering a culture of security, and building a secure future for the business, positioning it for growth?
Cybersecurity is not just a technical issue but a strategic business enabler. Cybersecurity is critical to building trust and reputation, from aligning cybersecurity with business strategy to driving innovation and transformation and facilitating new business models, mergers, and acquisitions. However, businesses must also balance the risks and opportunities associated with cybersecurity in this complex and interconnected world. So, what are the best practices for fostering a culture of security, ensuring that remote workforces are trained, and managing the aftermath of a cybersecurity incident?
And how are Business, IT, and Security leaders prioritizing cybersecurity, fostering a culture of security, and building a secure future for the business, positioning it for growth?
What the conversation established
Patrick Benoit, Global Chief Information Security Officer at Brink’s Inc, described a cybersecurity strategy that puts the security organization in front of customers: when a sales team takes him in front of a prospect to explain how their data will be kept secure, the sale moves quicker than when security is brought in at the end. He said both extremes kill a business, all innovation with no security, or controls so over engineered that the innovation is no longer useful, and that destructive testing belongs in an isolated sandbox until it is ready for production. A company that invests in a CI/CD pipeline has to invest the same way in continuous scanning and developer run pen testing, because perimeter era security cannot be bolted onto agile delivery. On culture, he argued that office awareness training rarely travels home while home habits do travel to work, so teach people to protect their own families first. He named three misconceptions: the department of no, that security people can only speak about security, and that another tool solves the problem. His larger worry is technology debt turning into vulnerability debt, with most companies unable to say where their equipment and data sit or that they are patched 100%. He wants fewer and more modular vendors: a truck to haul hay, not a Ferrari.
Contributors
- Patrick Benoit, Global Chief Information Security Officer, Brink’s Inc
Host: Sanjog Aul, Founder and Host, CIO Talk Network
On this page: Key takeaways · Chapters · Explore more · Transcript
Key takeaways
- A security leader in front of the customer closes the sale faster than a security review at the end. Patrick Benoit, Global Chief Information Security Officer at Brink’s Inc, said that when the sales team takes him on a call with a prospect to explain how the company will keep their data and processing secure, the sale moves quicker than if the business tries to do it alone and brings security in at the end, so the security organization works as a forward facing marketing and sales tool.
- Both extremes kill the business: all innovation with no security, and security engineered until the innovation is useless. Patrick Benoit of Brink’s said a company that runs off with all innovation and no security will get breached, and one that over engineers a security solution until the innovation is no longer useful or fast enough has done the same damage; his answer is to isolate destructive testing and development in a sandbox and apply appropriate controls only when the work moves to production.
- If you fund a CI/CD pipeline, you have to fund the security controls that run at that speed. Patrick Benoit of Brink’s said taking a waterfall methodology into agile while leaving security in old perimeter based, single firewall thinking does not work, so the same investment that speeds up the pipeline has to buy continuous scanning, developers who can request their own pen testing, and dynamic and static application testing that does not wait on the security team.
- The CISO seat at the table is earned the same way the CIO seat was, through business acumen rather than title. Patrick Benoit of Brink’s traced the role from the legend of the first named CISO in 1998 to the influx after PCI in about 2007 or 2008, when mid sized companies named whoever wrote the firewall rules, and said many of those leaders never held a business operations role; the seat arrives when a CISO can accompany a sales team to the customer and be strategic, which is why he has preached for years that security leaders have to be sales leaders.
- Awareness training aimed at the desk does not follow people home, but what they practice at home follows them to work. Patrick Benoit of Brink’s said very seldom does what we do at the office translate to what we do at home, while the values and integrity people live at home do come into the business with them, so security teams should stop teaching how to secure yourself at work and start teaching people to make cybersecurity part of their personal life and protect their families.
- Security has no right to say no, only the right to name risky behavior. Patrick Benoit of Brink’s said security does not own the end result, so it cannot say no, much like a parent talking to a 21 year old who can point out risky behavior but cannot forbid it; the business accepts the risk of its own actions, and the department of no is the first of the three misconceptions he named.
- Ransomware fades when recovery becomes routine, the way DDoS did once the money went out of it. Patrick Benoit of Brink’s said the way attackers get in will remain relatively consistent because most attacks still arrive through social engineering, so the work is in recovery: once a company can recover easily and there is no economic benefit to the attacker, ransomware falls away, as DDoS attacks did when there was no economic value in them.
- Unaddressed technology debt becomes vulnerability debt, and the basics remain the biggest exposure. Patrick Benoit of Brink’s said most companies cannot tell you where all their equipment and data are, cannot show that every vulnerability is accounted for, that they are patched 100%, or that no end of service and end of life assets are still running, and that this unglamorous hygiene work is still the greatest exposure to attackers while everyone looks for the next new thing.
- Buy the truck, not the Ferrari, and expect the market to move from a hundred vendors to ten or twenty. Patrick Benoit of Brink’s uses the phrase that he does not need a Ferrari to haul hay, he needs a truck, so seven figure products with 15 functions he does not need are the wrong answer; he expects the pendulum to swing back from best in breed saturation to integrated platforms built from best in breed modules that a buyer can still purchase individually.
- Stop asking the business how to secure it and start asking what it needs to grow. Patrick Benoit of Brink’s said the message moved from we have to secure you to help us understand how we can secure you, and neither is good enough; the question is what do you need to drive more revenue and enhance your business, and a leader who cannot tell a compelling story that people want to invest money in will not get the program anywhere.
Chapters
- 0:00 Introduction: cybersecurity strategy and business growth
- 1:58 Security as a forward facing sales asset (Patrick Benoit, Brink’s Inc)
- 4:03 Bringing security into a project at the start (Patrick Benoit, Brink’s Inc)
- 6:36 Balancing innovation speed against security (Patrick Benoit, Brink’s Inc)
- 9:02 Matching security investment to the CI/CD pipeline (Patrick Benoit, Brink’s Inc)
- 11:06 How the CISO role earns a seat at the table (Patrick Benoit, Brink’s Inc)
- 15:16 Security culture that starts at home (Patrick Benoit, Brink’s Inc)
- 17:05 Misconceptions about the department of no (Patrick Benoit, Brink’s Inc)
- 22:25 Ransomware and the economics of recovery (Patrick Benoit, Brink’s Inc)
- 24:29 Technology debt and basic hygiene (Patrick Benoit, Brink’s Inc)
- 27:37 A coalition with smaller vendors and customers (Patrick Benoit, Brink’s Inc)
- 31:39 A truck instead of a Ferrari (Patrick Benoit, Brink’s Inc)
- 33:58 The CISO as business person and storyteller (Patrick Benoit, Brink’s Inc)
Explore more
- Accepting Constant Threat Exposure in Cybersecurity Beyond Firewalls: Leon Ravenna, CISO and CIO, Openlane; Steve Lodin, Vice President, Information Security, Sallie Mae
- Does Integration Equal Strength in Cybersecurity?: Nitin Sharma, Global Director of Partner Development, Microsoft
- Stitching Seamless Digital Journeys in a Minefield of Threats: Prasanna Kumar Burri, Group Chief Information Officer, Dangote Industries
- Optimizing Healthcare IT Budgets: Balancing Security, Efficiency, and Innovation: Robert Eardley, Senior Vice President and Chief Information Officer, University Hospitals
- The X5 group Cybersecurity Transformation: A Case Study: Alexander Markov, Group Chief Information Security Officer, X5 Group
- Ensuring Digital and Virtual Healthcare Security: Anahi Santiago, Chief Information Security Officer, ChristianaCare
- The People side of Cyber Security – Turning organizations’ weakest link into their greatest strength: Abiodun Morolari, Chief Information Security Officer, City of Toronto, Canada
- Transforming Security Operating Model: Richard Kaufmann, Vice President and Chief Information Security Officer, Amedisys
- Enabling Secured Innovation in Your Enterprise: Tim Callahan, Senior Vice President, Global Security, Chief Information Security Officer, Aflac
Transcript
Introduction: cybersecurity strategy and business growth 0:00
Sanjog Aul [00:00:05]:
Hello and welcome to CTN. To learn more about the show, please visit ciotalknetwork.com. The topic today is actually an interesting one, because we’ve covered security and cybersecurity quite a bit, but we wanted to connect it to business growth. So the topic is Securing Business Growth With Cybersecurity. What we are talking about here is essentially that cybersecurity is no longer a technical issue, but we all want it to be a strategic business enabler, but easier said than done. We know it is critical to building trust and reputation, and we know that when we align cybersecurity with the business strategy, that’s what is going to lead to innovation and transformation, and it’s going to help with new business models, mergers and acquisitions, all kind of disruptions when they happen. Security, again, has to be put back on the front seat to make sure that we are a secure first organization
Sanjog Aul [00:01:01]:
even though you aspire to grow leaps and bounds. But how well are organizations able to do it? What are the challenges they’re facing? And what are those secret recipes some of the top security leaders are using so that they can deliver that kind of business growth on a consistent basis while making sure the organization stays secure? And I couldn’t have had a better guest to talk about it. I have Patrick Benoit, who is the Global Chief Information Security Officer with Brink’s. Hey, Patrick, how are you?
Sanjog Aul [00:01:36]:
So since the topic is about business growth, let’s talk about that, and let’s talk brass tacks. In which all areas would you say cybersecurity is actually contributing to business growth? Because the traditional definition of the cybersecurity function is okay, keep us safe.
Security as a forward facing sales asset 1:58
Patrick Benoit [00:01:58]:
Sure. The misnomer is we always try and put specific widgets that we’re selling or services that we’re selling as that’s the only thing that contributes to business. But just like a customer excellence organization or a marketing organization or any of these other supporting organizations do, you can’t do business without them, and you can’t do business without security. You certainly can’t do business without technology. Being able to be an affirmative part of a sales team, a customer experience team in a company as a CISO, makes me part of that team and makes me valuable. If they can take me on a sales call, maybe it’s a proposal, a potential prospect or whatever, and put me in front of that customer to talk about how secure we will keep their data and how secure we will make their processing, then all of a sudden I think we sell quicker than if you just try and do it yourself and bring us in at the end. So you have to use the security organization as a forward facing marketing tool in some ways, and a sales tool.
Sanjog Aul [00:03:15]:
So lately, when a lot of people got their names on Wall Street and people got fired, et cetera, that created almost a fear, and that drove cybersecurity to come to the forefront. But then if the fear dwindles, people have a tendency to pull back from that catalyst which got them around the fear part, or got the credibility going. But for security to be there forever, literally, and be embedded in the DNA of the business growth process, we got to go beyond that fear instilling face of security and make it more that this will make us think better, this will make us innovate better. Has a thought process started in that area?
Bringing security into a project at the start 4:03
Patrick Benoit [00:04:03]:
I think it absolutely has. I think we still struggle a lot with ensuring that we think about security in the beginning rather than as an afterthought. There’s still some struggle with that, because especially in the technology arena, people are running so fast. They get all these cool ideas, or they run out to talk to some vendor that’s going to have some great thing that’s going to help them out, and they don’t think about the ramifications to the entire environment until after the fact. So more and more, that’s changing. People are starting to be aware of and including security in the very first discussions that you have with people, and even if they’re just listening and understanding what’s going on early in the projects, that’s going to make the process go a whole lot smoother, and you’re going to get feedback from security engineers, security people, security experts that you won’t get from
Patrick Benoit [00:04:57]:
if you wait to the end. They have a different view of things, a different perspective of things. Security people also need to learn that they can’t talk from the point of view that we’re trying to block what’s going on. We have to be solutioning as we go. So we do need to call out information that’s important to make the innovation successful, but it’s how we frame it too, and that’s why I always go over this idea that you need to learn how to be a storyteller too.
Sanjog Aul [00:05:31]:
So we established that security could be offering that confidence and the trust which could help people think that this is a company where security is properly implemented, this is a good outfit to work with. That’s awesome. But now when we’re talking about growth, which comes from you being agile and also innovative, when it comes to agility and innovation, the tendency is for us to rip things apart, do creative destruction, tinker with things different ways. But that is totally 180 degrees opposite to when somebody is trying to implement cybersecurity and they want to have related compliance established. They want a stable state versus you keep ripping things apart and I’ll be running ahead of you to keep things secure. That seems to be too ambitious a task. So how does an organization on one hand say, go guys, go do your agility stuff and go do your innovation stuff, and we will take care of the security? Can it be realistically done?
Balancing innovation speed against security 6:36
Patrick Benoit [00:06:36]:
Well, the mistake that too many people make, and it’s not just in this situation, is that people fail to realize and fail to accept that in everything we do, there’s going to be some duality that goes on like that. In this case, it’s convenience or speed to market versus safety or security. There’s a balance point in there. Extremism on either side is not going to satisfy what you need to do as a business. You’re not going to be a stable business that way. If you run off with all innovation and you provide no security whatsoever, you’re going to fail somehow. You’re going to get breached, something’s going to happen, you’re going to fail.
Patrick Benoit [00:07:17]:
You might have the coolest, most innovative idea in the world, but nobody’s going to want it because they know that their data is not safe. On the other hand, if you try and over engineer a security solution that ends up driving down the benefit of the innovation to the point that it’s not useful anymore or it’s not fast enough anymore, then you’ve done the same thing. Both extremes will kill the business and kill the ideas. So you’ve got to find a balance point. In some cases, if you want to destroy and tear up and innovate when you’re testing and developing, then isolate that environment from the rest of the world, make sure that they can have fun in that sandbox and not risk the rest of the company. And then once it is ready for prime time, apply appropriate controls and move it into the production environment with the rest of the world. There’s got to be balance there.
Patrick Benoit [00:08:10]:
There’s got to be balance in all things.
Sanjog Aul [00:08:13]:
So when we talk about DevOps and when we talk about continuous improvement in CI/CD and many other new models that are coming up, especially in a cloud environment where you literally want to put 20 things into production every day because you want to stay ahead, that is a different animal than the traditional old SDLC or other form of changes that you will test, et cetera. I’m not saying we will not test, but imagine that environment where you’re moving at warp speed and you want security to catch up and create different environments and test it thoroughly to your satisfaction as a security leader. Do you see us giving away the potential of security being true to its potential in the interest of trying to do 20 things in a second?
Matching security investment to the CI/CD pipeline 9:02
Patrick Benoit [00:09:02]:
I think again, this is where in some ways security has fallen a little bit behind. Not necessarily because of our own desire to stay behind, but sometimes it has to do with whether the company is willing to invest. The same way you invest in CI/CD technologies and things to make that pipeline move faster, you are going to have to invest equivalently or appropriately on the security side to have controls that are consistent with that kind of methodology. Taking an old waterfall methodology and advancing it into agile while leaving your security based in the old perimeter based, single firewall kind of security is not going to work. So you can’t have old security trying to apply to new development. If you want to really move fast, you’re going to have to invest and bring your security program up to a level where it’s integrated into that CI/CD pipeline, where you have continuous scanning, where the developers can ask for their own pen testing and it gives them that testing, or their own dynamic and static application testing, and not wait for the security team to make that work for them.
Sanjog Aul [00:10:19]:
See, we all have been talking about integrating cybersecurity into the business strategy and planning and all the way to execution, almost like putting it at the very DNA of the organization.
Sanjog Aul [00:10:33]:
But then we also have situations where many CISOs have not become business CISOs yet and are not considered business savvy CISOs. So they are still struggling to get a seat at the table, or to get the leaders at the top to think security first. So is this a pipe dream, or in your experience have you done something where you could confidently say that yes, based on how you play your cards, this is doable? Because for the most part, most people struggle.
How the CISO role earns a seat at the table 11:06
Patrick Benoit [00:11:06]:
I think it’s an evolutionary and a maturity kind of process. If we go back and we look at the evolution of the CIO role, if you went back to the 80s, 90s timeframe, you had primarily IT directors, and nobody called them CIOs except in the biggest of the biggest companies, and even then CIOs oftentimes reported to CFOs or some other L2 leader in the ELT. It took time for CIOs to project the business acumen and confidence in how they were building and working towards the same business goal and strategically complementing it, before they were believed and they got that seat at the table. What we have in the CISO role is the same thing. If you look at the evolution of the CISO, the legend is that 1998 was about the first person that was called that
Patrick Benoit [00:12:03]:
but you don’t really see the real influx of the CISO until after about 2007 or 8, when PCI first came out, maybe 2007 or 8. PCI was the one that said, hey, you have to have a named Chief Information Security Officer, a named head of security, and all of a sudden people started turning around. Companies would turn around, especially mid sized companies, and they go, oh gosh, Pat, you’re doing the firewall rules, you know the most about security of our network and everything because it was all perimeter based. I think we need to name you as the CISO, you need to be the CISO. And that’s okay. Those folks that took those early roles were then very successful at parlaying that into the next bigger company, the next bigger company
Patrick Benoit [00:12:53]:
and they learned more about how to be a CISO as we got more resources and we interacted with the community. But many had never had a business specific role, a business operations side role, and as a result they just don’t have that experience. That’s happening more and more as CISOs are brought into that side of the equation, and so it’s going to evolve into they’re going to have more business acumen, at that point where they can have those discussions with business leaders, where they can accompany a sales team out to the customer and face the customer and be strategic. That’s when that seat at the table will start to occur. Personally, after many years of preaching that security leaders have to be sales leaders, I’m finally getting traction in companies where they are realizing the benefit of putting a strong security leader that has a good business background in front of the customer. That’s going to drive more business, it’s going to help the business enhance revenue, it’s going to drive more confidence in the security, the CISO role, and eventually that’s where that seat at the table will come from.
Sanjog Aul [00:14:12]:
So traditionally we have always aspired to have a cybersecurity aware culture where each individual will take ownership of the data that they have, and or the application and system, and they take ownership of the security of that organization. In fact, not stop there, but almost champion and advocate it. A great dream, but people have constantly struggled. The second thing, which is even more important, is does just becoming cybersecurity aware push an individual, or create an intrinsic motivation for an employee, to go to that level, or is there something more required? Because this looks like, oh yeah, we will train these people and we’ll do this awareness training, but there is still something left to be desired and it has not been solved. So if you had a choice to build a culture and define culture so that everyone does what we are hoping them to do, would you stop at just cybersecurity awareness, or would you do something beyond that?
Security culture that starts at home 15:16
Patrick Benoit [00:15:16]:
Well, I think you do go beyond that, but I think we’ve missed the opportunity over the years, and I’ve said this many times, that the culture that’s at a business comes from the people that lead the business. The people that lead the business got their culture primarily from their upbringing and their home life, and then they bring what their values are into a company, and they have influence over the values of the company over time. We’ve been teaching cybersecurity awareness for years and years from the point of view of here’s how you protect yourself when you’re sitting at your desk at the office. The problem with that is very seldom does what we do in business at the office translate to what we do at home. However, the reverse is not true. What we do at home, the values that we live, the integrity that we bring, the way we operate at home, in our personal lives in general, we do bring into the business with us. It’s part of who we are.
Patrick Benoit [00:16:19]:
So we need to stop teaching purely from the how do you secure yourself at work point of view and start teaching how do you make cybersecurity part of your personal life. How do you become cybersecurity aware all the time and protect yourself and your family? Because that will translate into benefits in the workplace.
Sanjog Aul [00:16:40]:
Now let’s talk about some common misconceptions that exist about security, which demotivate people and leaders and hinder business growth overall. If we can inventory them, maybe you could also share some solutions or some remedies to address them.
Misconceptions about the department of no 17:05
Patrick Benoit [00:17:05]:
So obviously the cliche misconception is that it’s the department of no, that we say no to everything, and I think everybody’s worked real hard to try and make sure that’s not the case. The fact is we’re not the business. We don’t own the end result of what’s going on, so we don’t have the right to say no. We definitely have the right to say this is risky behavior. It would be much like a parent talking to a 21 year old: they can’t necessarily say no, but they can certainly point out risky behavior, and then at some point somebody’s going to have to accept the consequences of their decision. That’s a huge misconception.
Patrick Benoit [00:17:44]:
And again, it’s all in how you present that. We’re not saying no, we’re just saying if you want to do this, we’re going to protect you as best we can, we’re going to provide you safety nets, but in the end, as a business you have to accept the risks of your actions. Big misconception. I think it’s a big misconception that security professionals can only work in security, but we have the same problem with technology, with CIOs, that CIOs and technologists are only technologists. That’s a misconception, because there’s so much more to be gained from accepting their experiences and taking their viewpoints on business and bringing them into those business discussions and those strategy discussions, allowing people to operate outside their confined role in terms of providing input and learning, so that you get the benefit of that person as a whole. We talk about diversity all the time, and that’s the real gain of diversity: don’t look at a person and say, oh, you’re just the CISO, so unless you’re talking about security you have nothing to contribute.
Patrick Benoit [00:18:57]:
No, that’s part of that diversity. Yes, you’re the CISO, but you have so many other experiences that could be beneficial. So don’t fall into that trap of it’s a security person or it’s a technology person, that’s all they can talk about. Explore that further. Big misconception. There’s also a last one I’ll give you, a huge misconception, that security really is a technology problem, that if we go buy another tool it will solve the problem.
Patrick Benoit [00:19:24]:
We had a conversation at one of the conferences that you and I were at, and somebody was talking about artificial intelligence and how it’s going to play a big role in future attacks and bad actors. My point in that was it will, but I think it’ll play less of a role in how do we attack devices. It’ll play a much greater role, in my opinion, in how do we attack social engineering, how do we attack individuals. So in the end, we still have to go back to that awareness thing and go back to ways that we can protect and help the individual protect themselves, and not just always think that we can buy another tool and that’s going to solve the problem. So those to me are some of the three biggest misconceptions.
Sanjog Aul [00:20:10]:
Let’s take a quick break, listeners. We’ll be right back after these messages. And let’s actually now dig deeper. We are seeing this happening with us: the threat landscape is definitely changing, and that means there are emerging cybersecurity risks, and if we are not cognizant of them and are not taking some proactive steps and staying on top or ahead of them, then it could come and haunt us and hinder our business growth. So which emerging cybersecurity risks should we be aware of as businesses, and what are some of the ways we can stay ahead of the curve and try to make sure that the business growth is not dampened or hindered or stalled? Please stay tuned. We’ll be right back.
Sanjog Aul [00:22:11]:
Welcome back. So, Patrick, let’s talk about some emerging cybersecurity risks which could be showing some weak signals or strong signals. First of all, let’s inventory those.
Ransomware and the economics of recovery 22:25
Patrick Benoit [00:22:25]:
So I think that obviously as long as ransomware is successful, it’ll continue to be a problem. Now, I don’t necessarily view ransomware from the recovery point of view. It’s a much greater effort than it is from the attack point of view, because from the attack point of view it doesn’t matter if it was ransomware or just malware or some other exploit. When they attack, they still have to come in through some method that has nothing to do with what the attack is, generally, and so we’re still going to have a lot of opportunity to protect against what are similar attacks. So I don’t think that changes that much. How they get into the system to begin with is going to remain relatively consistent. They might come up with newer, quicker ways to do it, they might come up with more innovative ways to do it, as we talked about, AI for social engineering, but they’re still going to gather most of their attacks through social engineering type avenues.
Patrick Benoit [00:23:24]:
But the difference is how do we recover, how do we make ourselves safe and able to easily recover from ransomware, so that it becomes a situation where nobody can really make money on that. If we are able to recover, and it just becomes a natural event that, oh, it happened and now we move on, and there’s no economic benefit to the attackers, then that’s going to fall away eventually, and it’ll just be like now, we see DDoS attacks from time to time but not like we used to, because there’s no economic value in it to them. So I think that’s important. But where we’re really going to see an uptick, frankly, is we continue to build technology debt that’s not being addressed, which means we’re going to continue to build vulnerability debt in that old technology, and so we have to take the time and invest in the basics and the hygiene things
Technology debt and basic hygiene 24:29
Patrick Benoit [00:24:29]:
and it’s not sexy. But the fact that most companies cannot tell you where all their equipment is, where all their data is, and cannot tell you that they have all of their vulnerabilities accounted for, that they’re patched 100%, that they have no end of service, end of life assets out there, that’s a fact. That’s still going to be our greatest exposure to attackers, those basic things, because we’re so fundamentally focused on looking for the next new thing.
Sanjog Aul [00:25:00]:
So if we ever had best practices about handling cybersecurity, especially when you have got some third party cybersecurity risks that we might encounter, and also making sure that the vendors and partners meet those standards, given the speed at which the security landscape is changing, we might have to reimagine them. First of all, I wanted to ask you, are you reimagining them, as a representative of the cybersecurity community, or are you picking something that used to work in 2018 and still applying it?
Patrick Benoit [00:25:37]:
I think it’s a mix of both, because there are still some good practices, some things from way back when that are still applicable. Patching your systems, that hasn’t changed. We still got to patch our systems. But there are things we can look at that might be new ways to deal with the problems. We see that all the time with the emergence of the idea, the concept of zero trust, and finally we’re getting past the idea that it’s a thing, and people are starting to understand that it’s a philosophy, a concept, a viewpoint and approach
Patrick Benoit [00:26:10]:
and so that’s an evolution and that’s a new thing. We need to get past this idea that we can only have either best in breed products or we have to have an integrated platform. It doesn’t have to be either or. The best in breed idea is why we have thousands of vendors out there, and every day we get saturated with more vendors of products, and so it makes it very difficult to even sort through the noise to get to what really works. For everything that really works, there may be 10 or 15 that only work a little bit. So I think that’s where our greatest opportunities lie in innovation, to be able to cut through the noise somehow. That’s what we need innovation in.
Sanjog Aul [00:26:58]:
If I were to define cybersecurity as a means to and a catalyst for business growth, because that’s the premise of this topic, and I bring in the third party partners that we might use, the vendors and partners and all the solutions that you mentioned they are introducing, is there a realistic way to get them to rally behind that cause or that agenda you have? Or is it still a vendor customer relationship when it comes to cybersecurity, because you will otherwise keep managing them versus leading them to help you get to that holy grail of using cybersecurity to enable business growth?
A coalition with smaller vendors and customers 27:37
Patrick Benoit [00:27:37]:
I think you have to be creative, and you have to understand what your particular business model is. For example, if you are in a business model such that a lot of your vendors are smaller SMB type vendors, small midsize vendors, and they don’t have the investment capability for security that you might have as a large company, well, do you have an opportunity at that point to build a coalition with your vendors whereby maybe you can extend your capability in, say, the area of your GSOC? Maybe they can’t afford to go to that level, and so you can extend through coalition and provide to your vendors some kind of benefit to that, and to your customers. Maybe you have smaller customers, maybe you could do it the same way, and the customers could pay for that at a much lower rate because you’re using economies to drive your prices down. The vendors could maybe pay for that by giving you some sort of discounts or enhanced value or service. So maybe some kind of coalition format could create that kind of synergy that you’re talking about.
Sanjog Aul [00:28:52]:
And when you try to do that, how have the vendors and partners stepped up to help you meet your agenda? Are you finding that warmth building between the cybersecurity leaders and the vendor partners that exist? Especially when you keep seeing new people come, and then even if you had a good partner who had a good relationship but doesn’t have the solution you want, then you’re stuck again, to go after new people. What does that look like, that revolving door of sorts?
Patrick Benoit [00:29:20]:
And I don’t know that there’s any panacea to the revolving door, there’s no secret to that. I think that’s going to continue, because what I see happening is when companies are startup or early stage, they’re very willing to be collaborative and to build that kind of a situation where you can both benefit together. You could help them benefit their product through your information and your testing and your feedback, and they can help you through pricing or through whatever other means they have, and that’s always very common, in my opinion, in the startup and early stages. What we have seen over recent years and decades is we see large companies, multibillion dollar companies, or multimillion at the very least, that want to get into the security space, as an example from networking or some other space, and they’re trying to get into it because they see that there’s money in security to be made. When they do that, they’ll go buy these startups or early stages, and they’ll suck up the IP
Patrick Benoit [00:30:28]:
and then all of a sudden you lose the culture that got that startup and early stage going to the point where they were. You lose that collaboration because you get lost in the big company, where you’re just a small fraction of their income. So I think that’s the concern. The challenge is how do these big companies figure out how to absorb the intellectual property without losing the culture and the customer orientation that got them there to begin with.
Sanjog Aul [00:31:02]:
Can cybersecurity reasonably be made flexible and scalable so it could be reduced in terms of its complexity, and or scaled in terms of its scope, by doing it very quickly, basically making it nimble? So that when business is growing, or interestingly nowadays, for example, we are talking about recession, so businesses want to shrink. But since security has a cost, you don’t want to have Ferrari level security for a buggy cart based business.
A truck instead of a Ferrari 31:39
Patrick Benoit [00:31:39]:
And you either have heard, or I psychically gave you, one of my common phrases, which is I don’t need a Ferrari to haul hay, I need a truck. So don’t bring me solutions that are seven figure solutions that have 15 functions that I don’t need. Bring me the truck that will let me haul the hay and does what I do need it to do for a fraction of the price. I think some companies, some vendors, have learned how to do that by giving you the ability to select off a menu and kind of modularize where you can. Some companies, the product doesn’t lend itself to doing that. It is kind of an all or nothing product
Patrick Benoit [00:32:21]:
so I get it. But that’s where we look at this change now from the idea of best in breed. Everybody was chasing best in breed, and you had to be in the leaders quadrant, you had to be in the front wave, you had to be best in breed, and that’s why we have, as I said, this saturation of vendors. I think now we’re going to see the pendulum swing the other way. We’re going to start to see vendors that have figured out that as a CISO, it’s not like I want all my eggs in one basket, but I also don’t want a 100 baskets. So again, we got to come back to a balance point that says here are some integrated platforms that use best in breed modules that if you want to buy them individually, you can. However, we will also offer you an integrated platform that does this logical piece of your program, and you don’t have to have 100 vendors. Maybe now we get down to 10 vendors or about 20 vendors, but it’s not a hundred
Patrick Benoit [00:33:24]:
and I think that’s the opportunity that’s in front of us.
Sanjog Aul [00:33:28]:
If you had to reimagine the leadership style, the communication style, the way you play politics, not in a negative sense but basically to rally everybody and lead them rather than manage upwards, downwards, sideways, what would you change or recommend changing in the way a CISO functions today, so that they can eventually fulfill that agenda or contribute effectively towards that agenda of securing the business growth?
The CISO as business person and storyteller 33:58
Patrick Benoit [00:33:58]:
Well, first of all, I tell all leaders that they need to stop seeing themselves as whatever their technical specialty is. Stop seeing yourself as only a CISO, stop seeing yourself as only a CIO, as only a CFO, and start seeing yourself as a business person, and in addition to that, a salesperson. So you’ve got to learn to build a story and tell a story. When you talk about, quote, politicking, you’re talking about the art of influencing, and you can only do that by getting your story across. If you can’t tell a compelling story that people want to listen to and want to invest money in, it doesn’t matter if you’re the greatest CISO or the greatest CIO in the world, you’re still not going to go anywhere with your program. So learn to tell stories. That’s what I would tell everybody to change.
Patrick Benoit [00:34:52]:
Read and learn about sales tactics and sales techniques and develop this ability to put together a compelling story. That’s what’s going to make you most successful on the business side.
Sanjog Aul [00:35:05]:
And one final question. If you had to get help, because I’m asking a whole lot from the CISO leaders to show your magic, but of course everybody needs help and there’s nothing wrong with asking for help. So if you were to go back and appeal to business, given the way the whole security landscape is shifting, what help should the rest of the organization and the people within it offer the CISO and the security team, so that they help you help themselves?
Patrick Benoit [00:35:40]:
And that’s exactly the way it was coming across in my head as you were saying that. We have to stop going to the business and saying we have to secure you, and then for a while it evolved into help us understand how we can secure you. So a little bit of a twist on it, but still not good enough. The message really needs to be, what do you need to drive more revenue? What do you need to enhance your business? Tell me that, let me understand that and learn about that, and then I’m the expert, I can tell you how we could solution that to help you get to that result. So again, it’s all about that compelling story, and we have to start thinking empathetically about what’s the business trying to do.
Patrick Benoit [00:36:28]:
Well, the business is trying to keep customers, get new customers, drive business, enhance revenue. So how are you going to do that on the business side? And what can I do to help you do that?
Sanjog Aul [00:36:42]:
Amazing. Once again, thank you so much, Patrick, for sharing your insights about how the CISOs and their team can work individually and collectively to help secure business growth leveraging cybersecurity. So thank you so much.
Sanjog Aul [00:37:01]:
And listeners, hope you enjoyed. Got some nuggets? I got a bunch. So please connect with us on social media. Subscribe to our podcast. Once again, thank you for listening to CTN. This is your host, Sanjog Aul, signing out till next week. Take care and God bless.


