The Security Collective Podcast: Recent Episodes

Claire Pales

The Security Collective is the podcast for leaders tasked with, and interested in, securing technology, people, processes and data for the protection of all. Join best-selling author Claire Pales, together with industry thought leaders who answer your questions about security leadership, trends, technologies, and more.

'The Security Collective' podcast - formerly 'The Secure CIO'

View Details

Today we are recapping some of the great episodes from season 11 'In Case You Missed' them!

We have put together a snippet of the best parts from each guest for you, and if you like what you hear, click below to listen to the full episode, or head to wherever you enjoy our podcast, and check out the full back catalogue.

Links:

Marc Bown

Stephen Kennedy

Craig Ford

Naveen Chilamkurti

Paul McCarty

Yvette Lejins

Jamie Newman

Paul Wenham

Samm MacLeod

For the full episode, transcript please visit our website

View Details

It’s our last episode for the season, and we are joined by a very good friend of Claire’s and of the podcast, Samm MacLeod. Samm and Claire discuss what's been happening since we caught up with her 12 months ago in season eight, when Samm generously shared her CISO journey through burnout and recent sabbatical. She's now back CISO-ing, and this time they covered digital transformations and security transformations.

Samm MacLeod is an experienced Information Security Executive with experience across multiple industry verticals including tech, financial services, and critical infrastructure. Having led several cybersecurity transformation programs, Samm helps organisations imbed effective security practices through cyber security strategy, security operating models, and risk management frameworks. Samm’s experience with boards, audit & risk committees, and executives allows her to bring a unique set of experiences and perspective to the management of technology and cyber risk and the delivery of security best practice. She is currently an appointed Netskope Security Board Advisor and has previously held non-executive positions on a critical infrastructure board (AEMO Cybersecurity Board), securitisation & financial services board (MEPM) and Information Security education and research board (Deakin Executive Board). Based on the Bellarine Peninsula, Samm is an industry speaker and writer, and an advocate for diversity in cyber.

Links:

Samm LinkedIn

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Jamie Newman has a refreshing take on security and joins Claire as they chat about understanding the security posture in diverse organisations, they discuss about third party contracts, how much money you should be spending on compliance and what meaningful metrics might look like.

Jamie is an experienced IT Leader with more than 20 years experience in applications and infrastructure transformation in varying national and regional roles. His career started in HR, but then quickly moved into a technology path in the late 90's and has worked predominantly in Manufacturing, Retail and B2B environments, working in Singapore, Japan and the Middle East. Jamie moved into senior management in 2008, and has been in C level roles for the last 10 years.

Links:

Jamie LinkedIn

Jamie Twitter

Episode 68

For the full episode transcript please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Paul Wenham joined Claire to talk about the what, how, and why he started Assurance Lab. They also cover the value of auditing, how compliance can be the foundation stone for startups and his new book, which he is making open source for others to contribute to; and talked about the fact that Assurance Lab is a B Corp, and why that is so important to Paul and his team.

Paul has worked in cybersecurity audits and compliance for over 11 years. His past roles have spanned professional services at PwC, leading the cybersecurity and compliance program for a global software company Qstream, and governance over third-party cyber standards at Westpac and Mercer.

Paul founded Assurance Lab in 2018, a Regtech software and audit services firm now working with over 150 cloud software companies across 12 countries. AssuranceLab supports their security and compliance programs to meet global standards (SOC 1, SOC 2, ISO 27001, HIPAA, Consumer Data Right, CSA STAR, GDPR, CCPA, and ESG reporting). Assurance Lab has a broad network of partners in the cybersecurity industry, leveraging the natural synergies of AssuranceLab's independence as an audit firm.

Links:

Website Assurance Lab LinkedinPaul LinkedIn

Episode 102. Cyber in Local Government with Paul Barrett

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Paul McCarty is a DevSecOps evangelist, and his recent chat with Claire was so great, we had to split it into 2 parts. In part 2 they discuss minimum viable security product, the Software Bill Of Materials (SBOMs) and making governance material consumable for senior audiences, no matter how unsexy policies might be.

Paul is the founder of SecureStack, the world's first DevSecOps Maturity Platform. Paul has been helping organisations build more secure applications for almost 30 years. He’s worked for large organisations like NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, but he’s also worked with several startups going back to the mid nineties. Paul is a frequent contributor to open source and Linux projects and is a co-organiser of several community group meetups here in Australia.

Links:

Website LinkedIn Twitter GitHub

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Paul McCarty is a DevSecOps evangelist, and his recent chat with Claire was so great, we had to split it into 2-parts. In part 1 they talk about his DevSecOps Playbook, the challenges of security and engineering teams working together harmoniously, and how to apply the Essential 8 to the software development lifecycle. You can hear Claire really enjoyed chatting to Paul about some of the more technical aspects of security and hearing his views on application security best practice.

Paul is the founder of SecureStack, the world's first DevSecOps Maturity Platform. Paul has been helping organisations build more secure applications for almost 30 years. He’s worked for large organisations like NASA, Boeing, Blue Cross/Blue Shield, John Deere, the US military, but he’s also worked with several startups going back to the mid nineties. Paul is a frequent contributor to open source and Linux projects and is a co-organiser of several community group meetups here in Australia.

Links:

Website
LinkedIn
Twitter
GitHub

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire is joined by Yvette Lejins as they discuss what people centric security means to her, what boards need from their CISO communications and the very real risk of insider threat. Claire was also curious to ask a bit about Yvette’s transition from CISO at Jetstar in house to being residency CISO for a security vendor.

Yvette joined Proofpoint from Qantas Airline Group in 2021, where she was the CISO for the Jetstar Group of Airline companies (Jetstar Aus/NZ, Jetstar Asia, Jetstar Japan and Jetstar Vietnam). Prior to Qantas she was the CISO at Australia's largest freight and logistic company Asciano, as well as having built up the security function at Atlassian before they went to IPO. She is a Fellow of the Australian Information Security Association.

In her role as Resident CISO, APJ, Yvette focusses on driving Proofpoint’s people-centric security vision, strategy, and initiatives amongst its customer base. Her hands on experience, knowledge, and perspective in managing risk and improving cyber security posture across complex enterprises is extensive. She provides trusted cyber advice and insight advisory services for Proofpoint customers.

Links:

Yvette LinkedIn

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire is joined by La Trobe scholar Naveen Chilamkurti as they cover some of the amazing work La Trobe is doing to welcome people into the cyber industry through great micro credentialing programmes. They discuss what micro credentials are, the value of this way of study, and how employers are valuing University qualifications such as micro credentials. He also shared what academia are currently working on, including crypto and 6G.

Naveen is currently the Associate Dean (International Partnerships), SCEMS Professor and Head of the Cybersecurity discipline, previously the Director of International Programs since 2017. He serves as the Technical Editor of the highly ranked IEEE Wireless Communications Magazine and IEEE Transactions on Vehicular Technology. Naveen has published more than 330 journal and conference papers, including IEEE and ACM Transactions and is active in editing and authoring 9 books with Elsevier, Springer, IGI-Global and NOVA publishers. Naveen has successfully attracted 20 research grants since 2000 to support PhD Scholarships, fellowships, and travel grants for research collaboration and in 2012 and 2018, he was awarded a research fellowship to work with IIT Kanpur and IIT Hyderabad.

Links:

Website

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

We welcome back author Craig Ford as he and Claire dive a little deeper into his latest book 'Foresight' which has been nominated for an Aurelis Award in the young reader category. There is cybercrime, romance, spies and hacking and a few matrix references in there for the fans. Aside from the book, Craig and Claire discuss the ongoing challenges of the cyber skill shortage and the state of cyber in Australia over the past 12 months.

Craig is the CTO for Baidam Solutions where he leads the technical services division of the organisation. Craig is also the Queensland Chair for the Australian Information Security Association (AISA). He is an experienced cybersecurity professional with various qualifications including two master’s degrees and a history in both pen-testing and security engineering.

Craig is a published author with the books “A Hacker, I Am” and “A Hacker, I Am – Vol 2” in his first cyber awareness series and “Foresight” a new cyberpunk/hacker fantasy series published in June 2022. He is a freelance cybersecurity journalist who is best known for his work on CSO Australia (IDG Communications) in which he contributed almost 100 cybersecurity articles between 2018-2020. He is now a regular columnist with the Women in Security Magazine as well as a freelance contributor for Careers with STEM, Top Cyber News, Cyber Today and Cyber Australia Magazines.

Links:

Episode 67 -Getting the Basics Right with Craig Ford

Website

LinkedIn

Facebook

Twitter

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire is joined by Stephen Kennedy as they cover the balance of engineers between security and functionality. They talk about secure coding expectations, and also the role compliance plays in software development. Stephen shares his experience moving from being an engineer into C-level leadership and the security lens of which he then had to look through.

Stephen's background is as a software engineer, but he's since transitioned into CTO and a CIO roles. He's worked across Australia, New Zealand, and the United Kingdom for organisations ranging from start-ups to large scale enterprises. His most recent role has involved increased security scrutiny in working with large multi-billion-dollar partners (e.g. shipping lines) with compliance mandates, and as such he's had to evolve his career to take on more of a security, privacy, and compliance focus.

Links:

Stephen LinkedIn

Stephen Twitter

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

For the full episode transcript, please visit our website.

View Details

The first episode for this season we welcome Marc Bown the CISO and Enterprise Technology lead at Immutable, a web3 gaming scale up.  Claire and Marc discuss the culture versus tech debate, exactly what web3 gaming is, and Marc shared his thoughts on what we as a security industry are still trying to get right. 

Prior to Immutable, Marc helped found the security teams at Sportsbet, Fitbit and Afterpay. Passionate about building empowered, high-performing teams, he believes that good security is as much about culture as it is technology.

Links:

Marc LinkedIn

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

For the full episode transcript please visit our website.

View Details

Listen as Claire provides a quick overview of what to expect this upcoming season on The Security Collective podcast - kicking off next Thursday 27 October.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

You can read the full transcript on our website

View Details

Listen as Claire provides a quick overview of what to expect this upcoming season on The Security Collective podcast - kicking off next Thursday 27 October.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

You can read the full transcript on our website

View Details


We've taken some clips of wisdom from five of our guests this season and brought them together in a neat package for you. This season in partnership with LastPass, we focused heavily on third party risk and supply chain security.

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details


We've taken some clips of wisdom from five of our guests this season and brought them together in a neat package for you. This season in partnership with LastPass, we focused heavily on third party risk and supply chain security.

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Following the success of our recent webinar, Claire is again joined by Alla Valente, this time they discuss the role of procurement, talk about supply chain risk as an enterprise wide risk and discuss who might own this risk. They covered how businesses are struggling to give third parties limited access to data and systems, and the flow on effects of managing the right level of access to get the job done.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Links:

Alla LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire is joined by Paul Barrett as they talk about cyber culture in local government, how the governance model for cyber is changing for the better, and Paul shares why he sees audits as a gift. It is great hearing Paul's view on cyber and getting a glimpse into being a CIO and local government.

Paul Barrett is an experienced an IT professional with nearly 15 years industry experience and 7 years local Government experience. His technical background is in network and security with a transition into people leadership, governance and information management over the last 6 years. Paul has a passion for implementing tangible change within organisations and place business process improvement at the core of technology solutions, and enjoys building high performing teams, hiring character ahead of technical ability.

Links:

Paul LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire is joined by Grant Chisnall a crisis trainer, advisor and podcaster, who has a passion for leadership communication and decision making. In this episode they covered a lot of ground including the escalation from incident response to crisis management, and talk about business collaboration before an incident, and how to plan for resilience while mopping up a cyber incident.

Grant has supported some of the world's leading organisations through crisis events ranging from cyber attacks to coronavirus; activism to air crashes; and from Natural disasters to workplace fatalities. His podcast ‘Crisis Talks’ tells the extraordinary stories of people who have led through crises and their stories of leadership and resilience in the face of adversity. Grant’s aim is to help leaders prepare for the worst-case scenarios and respond proactively and with confidence to any incidents that threaten their people, operations or reputation.

Links:

Grant LinkedIn

Left of Boom website

For full episode transcript please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

To celebrate the 100th episode and recently hitting 30,000 downloads, Claire wanted to honour some of the guests that have given their time and thought leadership so generously. So here's a little trip down memory lane, which we hope that you enjoy.

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

In part 2 of Claire’s webinar with Alla Valente and Vijay Krishnan they cover software supply chain, how to navigate fourth party risk and talked about offshore supply chain risks such as privacy and data sovereignty, as well as some great audience questions.

they cover software supply chain, how to navigate fourth party risk and talked about offshore supply chain risks such as privacy and data sovereignty. They also covered some great audience questions.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Vijay Krishnan is the CISO at UniSuper leading Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability. In his role, he leads a multi-year security program to reduce UniSuper security risk thus protecting UniSuper members. Vijay has extensive experience in negotiating clear and concise security and technology outcomes in regulatory, policy and outsourcing agreements delivering value creation opportunities. He has large, diverse national and international experience with extensive executive and Board level exposure.

Links:

Alla LinkedIn

Vijay LinkedIn

Episode #48 The value of great boss with Vijay Krishnan+

Questions for Alla's upcoming recording with Claire

For the full episode transcript, please visit our website

The Security Collective podcast is brought to you in partnership with LastPass, the leading password manager.

View Details

Earlier this week Claire hosted a live webinar with Alla Valente and Vijay Krishnan as they shared their insights on supply chain security versus third party risk. In part 1 Vijay covers APRA's CPS234 and the need for effective security controls, not just compliant ones. We also cover the role of legal and procurement in the third party assurance process. There's a tonne of great insights to be gleaned from both Alla and Vijay in this ever present risk.

Alla Valente is a senior analyst at Forrester serving security and risk professionals. She covers GRC, third-party risk (TPRM), supply chain risk (SCRM), and contract lifecycle management (CLM) strategy, best practices, and technology. Her research includes coverage of key regulatory compliance issues; risk management, ethics, and trust in digital transformation; and operational resilience. In this role, she helps Forrester clients build and mature a comprehensive programs that maximises business opportunity and performance while minimising risk and protecting the organisation’s brand.

Vijay Krishnan is the CISO at UniSuper leading Security Operations, Security Governance, Risk & Compliance, Security Strategy, Architecture & Design, Identity & Access Management, and Enterprise Observability. In his role, he leads a multi-year security program to reduce UniSuper security risk thus protecting UniSuper members. Vijay has extensive experience in negotiating clear and concise security and technology outcomes in regulatory, policy and outsourcing agreements delivering value creation opportunities. He has large, diverse national and international experience with extensive executive and Board level exposure.

Links:

Alla LinkedIn

Vijay LinkedIn

Episode #48 The value of great boss with Vijay Krishnan

Questions for Alla's upcoming recording with Claire

For the full episode transcript, please visit our website

The Security Collective podcast is brought to you in partnership with LastPass, the leading password manager.

View Details

Join us Tuesday 19 July 2022 at 10:30am (AEST) as we are going live for The Security Collective podcast in partnership with LastPass. We've invited Vijay Krishnan from UniSuper and Alla Valente from Forrester to join Claire in a conversation about supply chain security.

You can learn more on our website 

Register for the event here

View Details

Claire chats with former Toyota Australia CIO Ellis Brover, as he shares his thoughts on incident response through the lens of the CIO. They discuss how security maturity can dictate reporting lines, how organisations should seek to test the reality of systems being shut down because of an incident, and really how moral support goes a long way during a cyber incident.

Ellis Brover is a recognised IT leader with a track record over three decades of building and leading world-class IT organisations, driving transformational change, and delivering tangible business value. His experience spans a range of roles and industries, across a range of organisational scales from startups to multi-nationals.

Most recently Ellis was CIO of Toyota Australia, where he led a transformation of the IT function from an internally-focussed service provider to a strategic enabler, driver of innovation, and role model for outstanding customer service. Ellis grew and led a team of 300+ that delivered an industry-leading digital business capability as well as a rapid transformation in cyber security maturity, whilst dramatically improving efficiency and contributing to business growth.

Ellis is now pursuing advisory and consulting opportunities, aiming to add value to the business success of organisations and the development of their people through his extensive experience.

Links:

Ellis LinkedIn

For the full episode transcript, please visit our website

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

Claire chats with Jeremy Herbert, the CIO of Premier Technology Solutions. They covered how small businesses were affected during COVID, and what organisations of all sizes need to consider when it comes to the partners they need to manage cyber risk. On the podcast, we don't often cover cyber risk for organisations as small as maybe just a handful of people, so it was so great to change things up a bit and hear about the challenges that Jeremy and the Premier team are managing for smaller business.

Jeremy Herbert is the CIO of Premier Technology Solutions with a unique approach to technology. As a CIO of a Technology Managed Service Provider, he is not only focused on the strategic business direction for Premier but also focused on the strategic direction for the clients that Premier support.

Links:

Premier Website
Premier - free cyber check
Premier Talk
Premier LinkedIn

For the full episode transcript, please visit our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

We are back with our 10th season of the podcast, and to kick it off Claire is joined by Susie Jones from Cynch Security. Susie and Claire discuss supply chain risk, small business cyber fitness and the recent changes to security legislation. Susie also shared her thoughts on the role of government in securing all businesses.

Susie Jones is an experienced leader and risk manager who spent years specialising in the people and process elements of general and cyber risk management, and is passionate about bringing big solutions to the small business market. Before co-founding Cynch in 2018, Susie's previous roles included Head of Cyber Security Business Services at Australia Post.

Links:

Susie LinkedIn

Cynch Security website

Cynch Twitter

Cynch LinkedIn

For the full episode transcript, please see our website.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

We are thrilled to be bringing you Season 10 of The Security Collective podcast, with the first episode out this Thursday 23 June.  Take a listen for a preview of what is to come this season.

The Security Collective podcast is proudly brought to you in partnership with LastPass, the leading password manager.

View Details

This season on The Security Collective podcast we have invited guests to speak specifically about how we can change the behaviours of our staff when it comes to their cybersecurity habits and actions.

This is a mashup episode where Claire wanted to cover some really important points that some of the guests made, and encourage you to go back and listen to the full episodes if you find these nuggets of gold to be incredibly interesting, and you want to hear what else these guests had to say.

Quick link to guest episode:

Christie Wilson

Susan McLean

Erica Hardinge

Amy Ertan

Olivia Grandjean-Thompsen

For this full episode transcript, please visit our website

View Details

Closing out the theme of this season Claire is joined by Chris McNaughton and they discuss how data protection and security awareness are linked, the challenges of insider threat, and how leaders across your business can promote more secure behaviours.

Chris is a Director of SECMON1. Chris’ career commenced in law enforcement, where he was a recognised expert in digital forensics and management of electronic evidence. Moving into the corporate world in 2007, Chris accepted a global role with General Electric (GE) Capital where he was responsible for electronic discovery, digital forensics and investigations. In his position at GE, Chris implemented and managed a number of e-discovery platforms for GE Capital as well as reviewing and improving the Corporate e-discovery platform. In his current role Chris provides advisory services to Government and corporate clients in the cyber security areas of Insider Risk, Data Analytics, Digital Forensics and Workplace Investigations.

Chris LinkedIn

For full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

Claire is joined by Ian Yip, Founder and CEO of Avertro, the cyber-why company. They discuss cyber culture at the board level and talk about the impact of security leadership on the culture within cyber teams. Ian talks about the value of using the business's language in your cybersecurity discussions at the board level, and about bringing meaningful information to directors and doing so proactively. They also discuss that you have to rock the boat sometimes to make real change and the burnout that can come from this.

Avertro is a venture-backed cybersecurity software company based out of Sydney, Australia. Ian has two decades of cybersecurity experience in a variety of leadership, advisory, strategy, sales, marketing, product management and technical roles across Asia Pacific and Europe in some of the world’s leading companies including McAfee, Ernst & Young, and IBM.

Links:

Ian LinkedIn

Ian Twitter

Avertro Website

Avertro Twitter

For the full episode transcript please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

Olivia Grandjean-Thomsen is passionate about designing and implementing internal and external communication and stakeholder engagement strategies for the private, public and not-for-profit sectors. Olivia joins Claire and shares what good long-term communications planning can look like, how to measure cybersecurity communications programmes, and they talk about some of the grand scale comms activities Olivia has led.

Olivia currently works as the Head of Communication, Media, Events and Brand at Stone & Chalk Group, which includes AustCyber – an Industry Growth Centre aimed at driving innovation, productivity and competitiveness in the cyber security sector by focusing on areas of competitive strength and strategic priority. Previously, she was the Strategy Lead and Head of Content at My Health Record – a high profile digital transformation project at the Australian Digital Health Agency. She has worked as a Senior Communications Strategist at contentgroup, and for Global Access Partners – a public policy think-tank that initiates strategic discussions on pressing social, economic and structural issues to increase stakeholder participation in the development of government policy.

Links:

Olivia LinkedIn

Olivia Twitter

For the full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

Claire talks with Kate Monckton, a Partner in Cyber Risk at Deloitte, about the difference between cyber and privacy, and why we should never apologise for cyber or privacy being boring.

Kate joined Deloitte in February 2022 as a Partner in Cyber Risk. Prior to this she spent over ten years as part of the Security Senior Leadership team at nbn. Before joining nbn, Kate held security roles at Symantec and Microsoft both in Australia and the UK. In December 2021 she was named 'Australia's Most Outstanding Woman in IT Security' at the Australian Women in Security Awards. Kate was a member of the Board of the International Association of Privacy Professionals ANZ for five years, including two as the President. She is also a co-founder of the Security Influence and Trust (SIT) Group.

Links:

Kate LinkedIn

IDCARE website

For the full episode transcript, please visit our website.

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

In Claire’s chat with Cyber Security Fellow Amy Ertan, whose research focus is on the security implications of emerging technologies as well as themes relating to the human aspects of cybersecurity, they talk about her recent findings post COVID lockdowns.

Amy shares the impact of COVID on security behaviours and her research into how psychological safety, company loyalty and culture all play a part. They talk about whether phishing exercises work, and who Amy believes is doing security influence well. Amy's commitment to cyber through her studies and what she gives back to the industry is commendable.

Amy Ertan is a Cybersecurity Fellow at the Harvard Kennedy School’s Belfer Center for Science and International Affairs, an Information Security Doctoral Candidate at Royal Holloway, University of London, and a Visiting Researcher at the NATO Cooperative Cyber Defence Centre of Excellence. Her research interests focus on the security implications of emerging technologies as well as themes relating to the human aspects of cybersecurity. Amy has published UK government-affiliated reports on organisational cybersecurity behaviours, engaging C-suite colleagues with cyber risk management themes, and on the impact of pandemic-driven remote working in organisations. She holds CISSP and CREST Threat Intelligence qualifications and has previously worked in roles in areas including cyber intelligence, strategy and policy research, cyber wargame design and execution, and security risk management.

Links:

Amy LinkedIn

Amy Twitter

Amy website

For the full episode transcript - please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

It is always a pleasure to speak to passionate cybersecurity leaders and Erica Hardinge from ANZ is no exception. Erica and Claire talked in this episode about SIT and the work they do to bring the security awareness industry together on a regular basis. They discussed the magnitude of her role to influence the behaviours of tens of thousands of staff, and covered the pain points for security professionals when it comes to trying to get their message heard.

Erica is responsible for developing the global strategy for engaging and empowering secure behaviour change across customers and 40,000+ employees over ANZ’s 30+ geographies. Erica feels strongly about the role of sharing and learning across industry to improve the security awareness and enablement function. As such, is excited to have co-founded and grown the Security Influence and Trust group for Awareness professionals in the Australasia region. The group was recognised with the Australian Information Security Association “Educator of the year” award in 2017. Erica completed her MBA qualification at Melbourne Business School in 2008 following the earlier completion of a Bachelor in Arts and Science at Melbourne University, with a focus on Behavioural Sciences, including Criminology, contributing to her passion to help staff become cyber safe.

Links:

Erica LinkedIn

SIT website

For the full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

This is the episode to share with your colleagues, friends and family as Claire talks to Susan McLean, Australia’s leading expert in the area of cyber safety.

Susan was a member of Victoria Police for 27 years and the first Victoria Police officer appointed to a position involving cybersafety and young people where she established and managed the Victoria Police Cybersafety Project. She has completed advanced training in the US and has qualifications also from the US and UK. Susan has also been awarded The National Medal, the Victoria Police Service Medal - 2nd Clasp, and the National Police Medal.

Susan presents to over 250,000 students each year as well as tens of thousands of parents and educators both within Australia and Internationally and is the most highly qualified of all Office of the eSafety Commissioner, Trusted Education Providers.

Susan is a published author with her book 'Sexts Texts and Selfies' acknowledged as the definitive guide to online safety. She collaborates with a variety of international bodies and is a member of The National Centre Against Bullying (NCAB). Susan has developed comprehensive Policy for a range of organisations and also authored resources for the Victorian Education Department.

Links:

Cyber Safety Solutions

Susan Twitter

Susan LinkedIn

The Cyber Cop

For the full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

Claire talks with Christie Wilson, the Cyber Resilience Manager at UniSuper, where she helps employees understand cyber security threats and how to take the right steps to protect themselves. They cover how hard it is to measure cyber behaviour change through metrics and also the lessons Christie has learned in nurturing security champions at UniSuper. Christie also shares her use of nudge tactics and how consistency is so vital in behaviour change.

Christie brings a business lens to technical challenges by giving employees simple, easy to understand advice on cyber safety for work and home, as well as up-to date information on the latest cyber security threats and how to respond. Christie is a senior IT leader with over 25 years’ experience in both the vendor and corporate IT roles. Before moving into cyber security four years ago, Christie’s IT career spanned roles in sales, service delivery and management, vendor governance and management, and IT governance risk & compliance. Christie has a BA in English Literature and Sociology, and a Graduate Diploma in Social Science, from the University of Tasmania.

Links:

Christie LinkedIn

For the full episode transcript, please visit our website

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

View Details

In part 2 of Claire’s chat Lloyd Evans from LastPass, they talk about the hybrid work setting, communicating the cyber messages to the board, share questions from the audience, and Claire asks the age-old question, are password managers secure?

Lloyd Evans leads LastPass business across JAPAC (inc India). When he’s not training for his next ultra-marathon, Lloyd and the global LastPass teams are helping companies address the human habits and behaviours of password risks to help reduce the leading cause of data breaches globally - compromised credentials. 

A Cyber Security, cloud and technology industry veteran, Lloyd has previously held senior management roles with SolarWinds, Commonwealth Bank Australia, St. George Bank and Macquarie Bank.

This season we have partnered with Lastpass -the leading password manager – and we are discussing behaviour and influence when it comes to cybersecurity.

Links:

Lloyd LinkedIn

Lastpass website

For full episode transcript, please visit our website

View Details

Opening this season is part 1 of the webinar recording Claire co-hosted with Lloyd Evans from LastPass as they discuss human behaviours and the impact of culture and values on cybersecurity.

Lloyd Evans leads LastPass business across JAPAC (inc India). When he’s not training for his next ultra-marathon, Lloyd and the global LastPass teams are helping companies address the human habits and behaviours of password risks to help reduce the leading cause of data breaches globally - compromised credentials. 

A Cyber Security, cloud and technology industry veteran, Lloyd has previously held senior management roles with SolarWinds, Commonwealth Bank Australia, St. George Bank and Macquarie Bank.

This season we have partnered with Lastpass - the leading password manager - and we are discussing behaviour and influence when it comes to cybersecurity.

Links:

Lloyd LinkedIn

Lastpass website

For the full episode transcript please visit our website

View Details

Season 9 is nearly here and we have partnered with LastPass, the leading password manager to bring you this season.

Listen as Claire shares what to expect from the upcoming season.

For full transcript, please visit our website

View Details

In part 2 of Claire’s chat with Samm they discuss her sabbatical, starting a new business, and the operating model changes she has seen since returning to the security industry.

Samm is responsible for driving The Security Collective’s Interim CISO and Virtual CISO business. She also supports our clients with cyber security strategy, security operating models, and advice on security risk management, with a focus across multiple industry verticals including financial services and critical infrastructure. Samm’s experience with boards, audit & risk committees, and executives allows her to bring a unique set of experiences and perspective to the management of technology and cyber risk and the delivery of security best practice. 

Links:

Samm LinkedIn

For the full episode transcript, please visit our website

View Details

To conclude our season of returning guests, Claire is joined by our very own partner, Samm MacLeod, for a two part podcast. In part 1 they discuss Samm’s career break, what she has noticed since returning to the cyber industry, the SOCI Act and reporting to the board.

Samm is responsible for driving The Security Collective’s Interim CISO and Virtual CISO business. She also supports our clients with cyber security strategy, security operating models, and advice on security risk management, with a focus across multiple industry verticals including financial services and critical infrastructure. Samm’s experience with boards, audit & risk committees, and executives allows her to bring a unique set of experiences and perspective to the management of technology and cyber risk and the delivery of security best practice. 

Links:

Samm LinkedIn

For the full episode transcript, please visit our website

View Details

We welcome Brendan back to share what has changed since we last spoke. We discuss his new role as CISO for Cube Networks; outsourcing and cyber risk management; and the 3 key things he has seen change in cyber in the last six months.

Brendan Smith had a vocational interest in security, across various internet technologies and cryptographic systems, prior to commencing his security career, and maintains his technical interest to this day. He has built high performing teams through authentic leadership, and continues to mentor and coach new entrants into the field. As the CISO for Cube Networks, he brings his experience from major enterprise to a new audience, enabling them to mature their security governance and defences in the face of increasing threats.

Links:

Brendan LinkedIn

Cube Networks website

Cube Networks LinkedIn

For full episode transcript, please visit our website

View Details

Michelle Price is the CEO of AustCyber, the Australian Cyber Security Growth Network Ltd, part of the Australian Government’s Industry Growth Centres Initiative. She joins the podcast again to discuss reducing organisational risk, ransomware, cyber as critical infrastructure, and 'purple teaming'.

Michelle has an extensive career and held several Government roles, including the first Senior Adviser for Cyber Security at the National Security College, various strategy and risk management roles including at the Department of the Prime Minister and Cabinet (PM&C), and roles in law enforcement and health portfolios. She has also worked in risk management and strategy in Australia’s food industry and also in the advertising industry.

Michelle is passionate about Australia’s cyber security sector enabling all Australian organisations to grow and take advantage of the cyber world. She is also a strong advocate for increasing diversity in the cyber security workforce and inspiring people with the possibilities of cyber innovation.

Links:

Michelle LinkedIn

AustCyber website

AuCYBERSCAPE website

For the full episode transcript, please visit our website

View Details

It has been several years since Dan Maslin last joined Claire on the podcast.  Dan shares what has changed since their last chat, they discuss cybersecurity awareness, the benefits of a deputy security leader, and the Security of Critical Infrastructure Bill.

Dan Maslin is the CISO for Monash University, the largest university in Australia.  In addition to 20+ years enterprise IT experience, Dan is committed to playing an active role in the cyber security community, participating as a volunteer Executive Advisory Board member with AISA, Executive Advisory Board Member for Cyber with Deakin University and is an Industry Advisor with CyRise.  Dan is a Fellow of the Australian Information Security Association (FAISA), a Graduate of the Australian Institute of Company Directors (GAICD) and holds the CISSP, CISM & CRISC security certifications.

Links:

Dan LinkedIn

Episode 14: From Security Architecture to Senior Leadership with Dan Maslin

For the full episode transcript, please visit our website

View Details

After the success of Nick’s first episode, we welcome him back to discuss what has changed since we spoke a few years ago. We chat about the cyber job market, how things have changed through COVID, how ‘good cybersecurity is boring’, shadow IT, and Nick’s thoughts on the future of cybersecurity.

Nick Ellsmore has started, built, merged, acquired and sold multiple cyber-security businesses. Now Global Head of Strategy, Consulting & Professional Services at Trustwave following the sale of Hivint to Trustwave in 2018, Nick previously founded SIFT (acquired Safecoms, merged with Stratsec), sold to BAE Systems in 2010. The inaugural “AISA Information Security Professional of the Year” in 2012 and a past Australian APEC TEL delegate, Nick is an advisor to Universities and fast growing cyber startups including Bugcrowd, is a published author on the topic of cyber security and a keynote speaker on various things cyber and startups.

Links:

Nick LinkedIn

Episode 12: The Cybersecurity 'Roles' Crisis with Nick Ellsmore

For the full episode transcript, please see our website

View Details

A multi-episode guest on the podcast, we welcome back Anna to discuss how boards have adjusted during COVID - from governing cyber risk; technology and audit risk committees; to encouraging resilience and collaboration. Anna also shares what work looks like since leaving her corporate career.

Anna is a Director of The Secure Board, a Non-Executive Director and senior executive across the financial services, management consulting, telecommunications and technology industries. With three decades experience in leading customer, business and digital change, she is a sought after advisor to Boards, Chief Executives and IT leaders on digital transformation, data, cyber, leadership and culture.

Links:

Anna LinkedIn

Episode #21. Anna Leibel, CIO, UniSuper

Episode #38. Lessons Learned with Anna Leibel

Episode #60 The Secure Board with Anna Leibel and Claire Pales - hosted by Paul Rehder

For full episode transcript, please see our website

View Details

When Laura Staples was last on the podcast she shared that Laminex were undertaking the biggest work from home experiment ever.  Laura joins us again to share how things have played out over the last 18 months.

Laura is the Head of People & Performance at Laminex Australia and has spent the last 15 years pushing the boundaries in organisations with an eye on the future, seeking out the best experiences to fuel her knowledge and passion for the future of work. Laura is passionate about untangling complexity - be it people, processes or systems - and uncovering the hidden opportunities to transform ways of working. Naturally curious and at times outspoken, Laura is known for her creative leadership and ability to design innovative and commercially viable solutions which surprise and delight.

For the full episode transcript, please visit our website

Links:

Laura LinkedIn

Laminex website

Ep 44. The biggest work from home experiment we have ever done with Laura Staples

View Details

One of our original podcast guests, Craig Searle, returns to discuss how cyber has changed in the few years since we spoke - from navigating the pandemic; awareness of supply chain security issues; to achieving diversity in the workplace.

Craig Searle is the co-founder of Australian cybersecurity consultancy, Hivint, and the security collaboration platform, Security Colony – both of which were acquired by Trustwave, an Optus company, in December 2018.

Craig has over 12 years of experience in the security industry, working in the finance, government, telecommunications and infrastructure sectors. He has been directly responsible for the delivery of a number of strategically-critical security programs for a range of clients, including a $10m PCI DSS compliance program for one of Australia’s leading health insurers, achieving compliance on-time and on budget.

Links:

Craig LinkedIn

Craig Twitter

Episode #3 Security Sourcing: Cracking the Code with Craig Searle

For the full episode transcript, please visit our website

View Details

After joining the podcast as a guest in Episode 64 ‘The 14 day Security Challenge - Paul De Arajo is back as we continue our chat about the role of marketing and communications in cybersecurity risk management.

Paul joined NBN during COVID-19 in 2020 delivering security influence programs to protect NBN’s people and assets from personnel, physical and cyber security threats. Prior to NBN, Paul served in local and international Corporate and Government roles in the IT industry for over 30 years with experience in sales, marcomms, corporate social responsibility, compliance, and cyber safety/security roles. For over 19 years, Paul carved his career with Microsoft Australia and abroad.

Paul’s passion for keeping citizens safe in the digital world began as a founding member of the ThinkUKnow online safety and security program. In 2017, Paul joined the eSafety Commissioner in marketing and stakeholder capacity driving awareness of the office and its services to citizens and delivering the annual Safer Internet Day campaign.

Links:

Paul LinkedIn

Episode #64 - The 14 Day Security Challenge with Paul De Arajo

For the full episode transcript, please visit our website

View Details

Today is R U OK? day and it seems fitting we revisit my previous episode with Graeme Cowan. Last year, I was fortunate to meet with Graeme Cowan and ask him about his story, ask him about R U OK? day, and talk to him about some resilience activities that cybersecurity leaders can do, given the burnout that can occur in our industry.

As a mental health and resilience author and speaker, and Board Director of R U OK?, Graeme spends his professional life helping people understand just that. Graeme uses his first-hand experience after coming through an experience of extreme burn out to help others appreciate and understand the importance of looking out for themselves, as well as looking out for the people around them.

My goal for my discussion with Graeme was to give you the knowledge to build safe, resilient, and healthy security teams and leaders, but this episode goes so much further than that. It is PACKED full of information, resources and simple, actionable ideas that you can use today immediately to check in not only with your team, but also with yourself.

Links:

  • Graeme’s Website
  • LinkedIn
  • Twitter
  • Back From The Brink
  • R U OK?
  • TED Talk on the Harvard Study of Adult Development
  • Self-Care Snapshot Checklist
  • Project Aristotle results
  • Debunking Maslow’s Hierarchy of Needs
  • Peter Gollwitzer

Full episode transcript on our website

View Details

Vaughan Shanks is a Co-Founder and the CEO of Cydarm Technologies, since the company was founded in 2017. Prior to Cydarm, Vaughan worked as a software engineer in a range of Federal Government positions, working with organisations in Defence, intelligence, and law enforcement, in both a Public Service and private sector capacity, in Australia and the USA. 

Vaughan shares his story, we talk security operating models, and the learnings from y2k that can be applied to the cyber challenges we face today.

Links:

Vaughan LinkedIn

Cydarm LinkedIn

Cydarm website

Cydarm Twitter

For the full episode transcript, please visit our website

View Details

Jacinta Whelan is an author, thought leader and popular speaker on the concept of Interim Executives, Portfolio Careers and future ways of working. A partner with Watermark Executive Search leading the Melbourne office, she has over 25 years’ experience starting and leading Interim businesses in Hong Kong, New York and Australia. Jacinta advises corporates and governments on the Executive Interim marketplace. She is regularly asked to speak to Boards and business leaders looking to stay abreast of the way organisations are engaging executive talent.

Jacinta shares her story, the framework of her book, and the interim executive role in cyber security.

Link:

Jacinta LinkedIn

Jacinta’s book

For the full episode transcript, please visit our website

View Details

Aaron Bailey is one of Australia's leading Cyber Security experts and is the driving force behind The Missing Link's Security team. Aaron is the Chief Information Security Officer at The Missing Link, and kick started their Cyber Security business. Today Aaron and his team has become the trusted advisor to some of Australia's largest companies and government departments helping them to develop innovative and robust solutions to solve their security needs.

Aaron shares how The Missing Link is growing locally and globally, and why he is so passionate and proud of the business.

Links:

Aaron LinkedIn

The Missing Link

For the full episode transcript, please visit our website

View Details

Chloe Sevil is a Senior Associate at Clyde & Co, and has assisted over 143 clients recover from cyber incidents and is known for her ability to handle the complex regulatory environment surrounding a cyber incident.

Chloe has helped some of Australia’s largest listed companies deal with several of Australia’s most complex cyber incidents in recent times and manages multi jurisdictional legal teams, forensic vendors, law enforcement, PR/communications teams, and executive teams to deal with the fallout, and bounce back from cyber attack.

Join us as we discuss the different types/styles of Ransomware, Chloe's role as a breach coach, and why businesses should be prepared with a cyber incident response plan.

Links:

Chloe LinkedIn

Clyde & Co

IDCARE

For the full episode transcript, please visit our website

View Details

After what he describes as a chequered early career, Simon Jones settled into corporate technical and leadership roles in 2000. The problem space of financial services drove a shift in focus to Information Security, and he completed a Master's degree in 2017. This time served to fuel Simon’s passion for solving complex problems with effective communication, and he continues to work in banking as a cyber security consultant, as well as develop and deliver learning material for students in cybersecurity.

Simon shares why real world experiences assist in the cybersecurity curriculum; we discuss cyber qualifications; and how learning material and the way we educate has evolved.

Links:

Simon LinkedIn

For full episode transcript, please visit our website

View Details

Shamane Tan is known for her passion in developing strategies with the C-Suite and Executives so that business growth is achieved within the cyber risk industry. Shamane is Privasec's Chief Growth Officer and one of the most established women in the fields of technology and cybersecurity. Recognised by IFSEC as their global top 20 influencers, was also recently listed in the 40 under 40 Most Influential Asian-Australians and attained the Highly Commended award by the Australian Women in Security Network as the One to Watch. Shamane is also the Founder of Cyber Risk Meetup, an international community and platform for cyber risk executives to exchange learnings, and the author of ‘Cyber Risk Leaders’.

Shamane uses her network to bring cyber communities together, and with COVID forcing more people to work online and different hours from home, it has allowed a more global reach. We discuss this, the Cyber Risk Meetup and her book.

Links:

Shamane LinkedIn

Cyber Risk Meetup website

Shamane’s book - ‘Cyber Risk Leaders’

For the full episode transcript, please visit our website

View Details

Charles has 20 years hands-on experience across multiple security disciplines including Security Consulting, Ethical Hacking, Cybercrime Research, Security Architecture, Security Operations and Security Leadership. He has also held a role as a part-time lecturer in the Masters of Information Security course at RMIT. Charles has built and led security teams at two of Australia's big four banks, before moving to senior roles in the Cloud & Managed Services spaces. His diverse experience has given him the technical understanding of the current threats faced by organisations, as well as the knowledge on how to uplift the security posture of the organisation in a pragmatic way to address those threats.

Join us as Charles shares his career journey, and we compare our views on security as an enabler.

Links:

Charles LinkedIn

Full episode transcript available on our website

View Details

Craig Ford is an experienced cybersecurity professional with various qualifications; an accomplished author with the books “A Hacker, I Am” and “A Hacker, I Am – Vol 2” from his first cyber security series and “Foresight” a cyberpunk novel published in March 2021; and now works as a senior security architect for Baidam Solutions, currently placed in the ATO.

Craig shares how he became an author; we discuss basic business security measures every company can implement; and what it’s like working for an inspiring and philanthropic company like Baidam Solutions.

Links:

Craig LinkedIn

Craig Twitter

Craig’s books

Pip Jenkinson Episode

For the full episode transcript please visit our website

View Details

The world has changed in so many ways in the past year and having a digital and online presence is fundamental. Criminals are just as likely to disrupt a small business as they would a major enterprise. The threat is real, and these days for businesses to thrive and survive, it’s imperative they prioritise security.

Ben Jones has a simple mission, to secure small business. Ben started his career journey as a psychologist caring for teens with cancer, moved into pharmaceutical sales, and in recent years he has joined the cybersecurity space. Join us as Ben shares how his psychology career assisted his move into the cyber security world, we discuss cyber dissonance, and Ben’s business Jumpstart.

Links:

Jumpstart Instagram

Jumpstart Security

For the full episode transcript please visit our website

View Details

Ian Pham is the Information Security Senior Manager at Certane, where he leads the information security strategy and capabilities to manage cyber risk for the Group and its subsidiary companies.

Ian has over 10 years of IT experience across finance, health, and higher education sectors. Starting his career in operational IT and consulting roles before specialising in cyber security, Ian has fast tracked his cyber career in the past 6 years by working across all security domains. This has given Ian a broad view of cyber and a mindset of constantly questioning the status quo as to 'why' security is needed in our current threat climate, instead of simply just performing security for compliance sake

Ian shares his career journey; the benefit of using analogies; and we discuss the importance of asking the ‘Why’ of our security people, as well as people outside of the security team.

Links:

Ian LinkedIn

Please visit our website for the full transcript of this episode.

View Details

As we take a break between seasons, we wanted to update you on whats going on at The Security Collective podcast.  Most importantly its our second anniversary!  Over 15,000 downloads and more that 60 guests, we are so proud to be bringing you this podcast, so a big thank you to all our listeners and guests!

Enjoy this short update on our upcoming season.

Full transcript on our website

View Details

Paul De Araja joined NBN during COVID-19 in 2020 delivering security influence programs to protect NBN’s people and assets from personnel, physical and cyber security threats. Prior to NBN, Paul served in local and international Corporate and Government roles in the IT industry for over 30 years with experience in sales, marcomms, corporate social responsibility, compliance, and cyber safety/security roles. For over 19 years, Paul carved his career with Microsoft Australia and abroad.

Paul’s passion for keeping citizens safe in the digital world began as a founding member of the ThinkUKnow online safety and security program. In 2017, Paul joined the eSafety Commissioner in marketing and stakeholder capacity driving awareness of the office and its services to citizens and delivering the annual Safer Internet Day campaign.

Paul joins me in this episode to share his career story, and how he and NBN ran with an idea I had, creating and implementing the 14-Day Security Challenge!

Links:

Paul LinkedIn

For the full episode transcript please visit our website

View Details

Despite having held a range of leadership positions in security technology, Gabe Gumbs considers his most valuable experience to be the time he spent on the ground as a security practitioner. Now he’s spearheading Spirion’s vision for data privacy in the next decade and beyond, leading the way to a more secure and private tomorrow for us all.

Gabe has a deep-rooted passion for technology, information security, and problem-solving. As Chief Innovation Officer of Spirion—a leader in rapid identification and protection of sensitive data—he’s channeling that passion to make the digital world a safer place. Join us as we discuss this, how data and technology will protect businesses in the future, and the need to uplift everyone’s security literacy.

Links:

Gabe Twitter

Spirion website

Spirion Twitter

For full episode transcript please visit our website

View Details

Darren Kane has been the Chief Security Officer at NBN since 2015. In 2020, Darren was appointed to the Federal Government’s Cyber Security Industry Advisory Committee to help guide the implementation of the nation’s Cyber Security Strategy and provide ongoing advice to address emerging cyber security challenges.

Prior to NBN, Darren served in Federal Government Law Enforcement Agencies for over 19 years in the Australian Federal Police and financial markets regulator the Australian Securities & Investment Commission, and 11 years at Telstra Corporation in varied security management roles culminating in 5 years as the Director, Corporate Security & Investigations.

Darren was appointed as an Adjunct Professor in the School of Information Technology, Faculty of Science, at Deakin University in 2020. Darren has a Master’s in Business Administration, a Diploma of Financial Markets and is a Graduate Australian Institute of Company Directors and in 2020 Darren was awarded Male Champion of Change at the AWSNA (Australian Women’s Security Network Awards).

As Darren is so knowledgeable and well renowned in the security industry, it seems fitting he joins me on this episode of the podcast as he shares his advice on security careers.

Links:

Darren LinkedIn

You will find the full transcript of this episode on our website

View Details

Meet Nathan Chung. As someone with Autism and ADHD, Nathan knows what it is like to be a minority. In this episode he shares his story of how he encourages others to elevate the voices of neuro diverse people, support women and to flip the script on the negative stigma of those in a minority.

Last year Nathan won the Male Ally of the Year Award for his advocacy for women in cyber security globally. Nathan is also an advocate for neuro diversity and racial equality, hosting his own podcast NeuroSec where he interviews amazing people in cybersecurity with very diverse conditions and supporters. Nathan serves on multiple boards, including IGNITE Worldwide; WiCyS (Women in Cybersecurity) the largest women in cyber nonprofit in the US; and also Spark Mindset. Originally from Hawaii, he specialises in cloud security with a career spanning more than 20 years.

Links:

Nathan LinkedIn

For the full episode transcript, please visit our website 

View Details

Claire Pales has recently co-authored a new book 'The Secure Board' with Anna Leibel - founder of 110% Consulting, a board member at Ambulance Victoria and multi-The Security Collective podcast guest; and for this episode we are doing things a little different!

Behind the host mic is Paul Rehder, managing partner from Deloitte.  Paul's extensive financial services experience running a broad range of strategy, business architecture and delivery programs and initiatives in Australia and abroad, as well as being a trusted advisor to both executive and non-executive directors, seems fitting as he hosts this episode of The Security Collective podcast discussing with Claire and Anna 'The Secure Board'.

Links:

The Secure Board

Anna LinkedIn

Claire LinkedIn

Paul LinkedIn

For the full transcript of this episode please visit our website.

View Details

Brendan Smith had a vocational interest in security, across various internet technologies and cryptographic systems, prior to commencing his security career, and maintains his technical interest to this day. He has built high performing teams through authentic leadership, and continues to mentor and coach new entrants into the field, as well as supporting incubators through knowledge sharing.

Brendan's episode is so informative we shared it over two weeks - in part 2 Brendan’s shares his career story, the massive success that he has had in security awareness and behaviour change programs, and provides some great tips on how he managed to achieve this.

Links:

LinkedIn

Please go to our website for the full episode transcript

View Details

Brendan had a vocational interest in security, across various internet technologies and cryptographic systems, prior to commencing his security career, and maintains his technical interest to this day. He has built high performing teams through authentic leadership, and continues to mentor and coach new entrants into the field, as well as supporting incubators through knowledge sharing.

Brendan's episode is so informative we are going to share it over two weeks - in part 1 we discuss security standards, compliance and engaging with the board.

Links:

LinkedIn

For the full transcript of the episode please visit our website The Security Collective

View Details

Gary Jackson is Vice President for Asia Pacific at Tenable - the Cyber Exposure company helping 30,000 organisations around the globe understand and reduce cyber risk.

Gary joined Tenable to lead the Asia Pacific region and build the reputation and coverage of Tenable in the risk-based vulnerability management space. His career spans more than 40 years in the technology industry. Prior to joining Tenable, Gary held various regional vice president roles with Cisco Systems, EMC and Aruba Networks.

Links:

Tenable LinkedIn

Gary Jackson LinkedIn 

Twitter

Facebook

View Details

Emily Edgeley is a Public Speaking Coach, helping people in Tech give more interesting talks, magnify their influence and learn to enjoy public speaking.

Emily shares her story of a career spanning 15+ years in IT & Security roles, only to realise they didn’t give her the satisfaction for helping people she really wanted deep down. After 4 years running the ANZ Toastmasters Club, hosting Storytelling Workshops off the side of her desk and coaching people on a volunteer basis, she left corporate life in 2018 to start her own business. She’s coached 1000+ people across various group and private sessions, formally supported first time speakers across 6 Conferences and now runs online Group Coaching Programs.

Links:

Website

  • The Power of Stories' Masterclass - Find out the magic stories hold and why you need to start telling them.
  • 30 Storytelling Scenarios - All the ideas you need to tell more stories, more often.

LinkedIn

Twitter

Instagram

View Details

We open our latest season with Nic Martin whose career of over 25 years spans defence, major events, senior corporate positions, and strategic and risk management consulting, Nic has experienced first hand the challenges of successfully delivering security and crisis management programs in both corporate and complex operating environments.

Nic shares his story as he transfers his physical security skills to cyber security, how they differ, and the resources he has found that have helped him with his transition into the cyber space.

Links:

LinkedIn

For the full episode transcript, please visit our website 

View Details

Formerly known as ‘The Secure CIO’ podcast, we have rebranded and are now 'The Security Collective' - the podcast for leaders tasked with, and interested in, securing technology, people, processes and data for the protection of all.

Join best-selling author Claire Pales, together with industry thought leaders who answer your questions about security leadership, trends, technologies, and more.

Listen to this short episode as Claire shares why the rebrand and her excitement for the future of The Security Collective, as the latest season with more amazing guests kicks off next week!

View Details

This season on The Secure CIO podcast we have heard from some of the cybersecurity industry’s greatest minds as well as some amazing business leaders.

We are taking a break from recording over the summer/holiday period - if you manage a team and want to hear more about leadership, need help with burnout, have a toxic culture, or hear more about flexible work environments we have over 50 podcast episodes for you to enjoy!

Here are some recent episodes I really enjoyed recording:

  • Ep 31 - Flexible Working Without Compromise with Niamh Fitzpatrick
  • Ep 34 - R U OK? with Graeme Cowan
  • Ep 36 - Investing in Employee Experience with Fiona Wynn
  • Ep 38 - Lessons Learned with Anna Leibel
  • Ep 39 - Women in Security with Jacqui Loustau
  • Ep 43 - Meetings for Good with Carl Gough
  • Ep 47 - Toxic Teams with Jinan Budge
  • Ep 52 - The pace of change in cyber security with Michelle Price

View Details

Michelle Price is the CEO of AustCyber, the Australian Cyber Security Growth Network Ltd, part of the Australian Government’s Industry Growth Centres Initiative. Michelle has an extensive career and held several Government roles, including the first Senior Adviser for Cyber Security at the National Security College, various strategy and risk management roles including at the Department of the Prime Minister and Cabinet (PM&C), and roles in law enforcement and health portfolios. She has also worked in risk management and strategy in Australia’s food industry and also in the advertising industry.

Michelle is passionate about Australia’s cyber security sector enabling all Australian organisations to grow and take advantage of the cyber world. She is also a strong advocate for increasing diversity in the cyber security workforce and inspiring people with the possibilities of cyber innovation.

Michelle joins me once again as a guest –this time discussing the intersection of cybersecurity, privacy and safety. How do we build that cross-skill-capability in our staff? We also discuss how cyber in Australia compares to the rest of the world, and how/will organisations accelerate of out this pandemic?

Links:

Website

LinkedIn

Michelle Twitter

Austcyber Twitter

Time stamps:

  • 01:16 What has changed in the world of cyber since Michelle was a guest in season 1
  • 02:38 The growth of cybersecurity companies in Australia
  • 03:39 The intersection between cybersecurity privacy and safety and the capability requirements
  • 05:37 “the way that we go about our lives, we need to take…an account of the security, safety and privacy implications of what we're doing, because data is so intermingled”
  • 08:59 How do we find people who can look at security through a risk lens & build that skill in our staff?
  • 10:48 “it is encouraging those kinds of curiosities and those behaviours that really do question”
  • 11:03 Encouraging a culture that is supportive of psychological safety and knowledge
  • 13:06 “how we trust that the knowledge sharing is going to be for the overall betterment of those people that have come together, as opposed to one or two of them snatching and running”
  • 15:05 When it comes to cyber, how does Australia compare to other countries?
  • 16:25 “cyber is a pretty good example…because of the innovation that's required, at the same time as the deep tech…as the go to market, in a very intermingled noisy environment”
  • 17:22 How are organisations going to be able to accelerate out of this pandemic into 2021?
  • 19:04 “more innovative and agile companies to come in and help them meet teams in particular, who we need to survive in the economy, to be able to regroup and I would say evolve, not pivot”

View Details

Stuart Harrison is a passionate and motivated Information Technology Executive with strong business acumen and deep understanding IT services across multiple disciplines. A career spanning two decades primarily focused on the Cyber Security aspect of Information Technology, Stuart's experience ranges from some of the most simplistic systems and management, to some of the most complex, from low level technical engineering through to business leadership.

Stuart is the CISO of Medibank Private and in this episode he shares his story, how his skills evolved as he moved from technical roles to executive roles, and his approach when hiring security teams. "There are so many different facets of security, so many different things you could do".

Links:

  • LinkedIn

Time Stamps:

  • 00:55 Skills Stuart brought to his CISO role and how he stays current
  • 02:56 That pivotal moment of moving from a technical leader to an executive
  • 03:30 “It really taught me about how to run the business of technology, not just how to run technical aspects of a technology business”
  • 04:45 Succession planning
  • 05:56 “Becoming comfortable means you become complacent”
  • 07:33 Stuart’s approach when hiring
  • 08:44 “We've tried to be as consistent, yet adaptable over time with who we're hiring
  • 08:55 Medibank’s shift and the role security plays
  • 11:02 “If you drive to do the basics, and you do them really, really well, you've covered a substantial part of your business risk, not just your security risk”
  • 11:45 Stuart’s thoughts on the skill shortage in the security sector
  • 13:40 “There are so many different facets of security, so many different things that you could do.”
  • 17:06 Starting a security team from scratch, who do you hire first?
  • 21:06 “Making sure that your hiring process is ultimately going to complement the strength of the team in the medium to long term”
  • 23:27 What do you wish you had known when you first started as a leader?
  • 25:30 “It's not what you're saying, it's how you go about saying it.”

View Details

David Fairman is a highly experienced professional in the Security & Fraud and has worked for, and consulted to several large financial institutions and Fortune 500 companies, across the UK & EU, North America and APAC. David is a passionate leader in Cyber Security and Financial Crime and has been actively involved in founding several industry alliances and expert groups, holding Board positions, across multiple regions with the aim of making it safer to do business and transact in the digital world.

David has been recognised as one of the Top CISOs to know, is a published author and adjunct professor.

David's current focus is driving collaboration and innovation across the industry to address current and emerging threats prevalent with digital risk and improve the cyber resiliency and literacy in the community.

Being a leader means we need to do more than just look after ourselves and focus on bettering ourselves - what do we do about bettering the country and bettering the community? In this episode David discusses how we can do this, and other tips and steps we can take to be great leaders.

Links:

LinkedIn

Time Stamps:

  • 01:03 What shaped David’s career journey
  • 02:16 “as I progress through my career, I'm learning more things, you get exposed to more things, and you learn to what you like, what you don't like”
  • 03:32 Transitioning from the armed services into a corporate world
  • 05:10 What do you think plays a big role in how we resource our teams?
  • 06:30 “something that I've really enjoyed is exploring people who have a curiosity”
  • 07:34 How small and mid-tier businesses can learn from global organisations when it comes to building cyber security functions and teams
  • 09:38 ” a couple things that they can learn from is how they get those basics right”
  • 10:12 Transitioning from a small/mid-tier to a large organisation
  • 13:21 Staff retention tips
  • 16:35 Stretching and nurturing employees
  • 17:21 “your role as a leader is to help coach develop and mentor”
  • 19:27 Advice you would give to your younger self
  • 20:12 “…that cyber security space, it is tough, it is ambiguous, it changes rapidly. So embrace change, don't get frustrated with change”
  • 20:59 When faced with an incident, how slow down critical thinking is best
  • 21:51 “let's think for a minute, don't react”
  • 21:54 Self-awareness and steps taken
  • 23:53 “soft skills like you're never, you're never done with this stuff. You should be challenging yourself to get better every time”

View Details

This season I am again recording some solo episodes, and answering the big questions that I hear often when doing consulting work. I'm excited to share some of the experiences I have had during my career in security.

Receiving feedback can help you grow, but it does depend on how it's delivered. I recently received some feedback, which lead me to think about how best to give feedback in the recruitment process. In this episode I share these tips and what I have learnt.

Links:

  • LinkedIn
  • The Secure CIO

Time Stamps

  • 01:32 The value Claire found in feedback she recently received
  • 02:36 Providing feedback in the recruitment process
  • 03:22 “giving great feedback is to make sure that the people that are in the process are absolutely contenders”
  • 03:29 Giving feedback with actionable examples
  • 04:45 How feedback is a two way conversation
  • 05:08 “Giving them that opportunity for a two way conversation will make them feel heard”
  • 05:29 Choosing your words wisely
  • 07:17 Recap of feedback tips
  • 07:55 “giving feedback that's too general…doesn't necessarily help people today”

View Details

Vijay leads UniSuper's Security Program and Strategy including Security Operations, Security Governance, Risk & Compliance, Security Architecture & Design and Identity & Access Management. In his role, he leads a multi-year security roadmap to reduce UniSuper security risk thus protecting UniSuper members.

Vijay has extensive experience in negotiating clear and concise security and technology outcomes in regulatory, policy and outsourcing agreements delivering value creation opportunities. He has large, diverse national and international organisational experience with extensive executive and Board level exposure. Previously he was leading the Information security practise at Transurban, accountable for IT and OT security including accountability for PCIDSS compliance.

Join me as I chat with Vijay as he shares his learnings on why having a great boss, who provides you with the right opportunities, can improve your career progression. We discuss why you should strive to join a company with aligning values, and how to hire differently during a pandemic.

Links:

  • Linkedin

Time Stamps

  • 01:12 Transitioning from network security leadership to the Head of Information Security
  • 02:23 Acquiring soft skills
  • 03:42 Advice for transitioning from a technical role to a CISO or Head of Security
  • 04:48 “you have to combine your technical skills, with soft skills, with business acumen and strong stakeholder relationship skills.”
  • 05:11 When your boss provides you with the right opportunities
  • 06:27 “you need to show that interest and the passion for it, and then the opportunities will come”
  • 08:12 What to consider when joining a new organisation, in regards to strategy, team and op model
  • 10:22 “finding a candidate who is a cultural fit for the organisation is far more important and valuable than the most impressive qualifications”
  • 11:59 How recruitment differed during the pandemic
  • 16:16 “look internally within the organisation, I'm sure there will be people within your organisation that have (a) passion for security”
  • 17:17 How to help people make that internal transition to security
  • 19:48 What would you say to your 20 year old self about building teams and leading teams?
  • 20:16 “tune in to your gut and trust it”
  • 20:24 “if you have a passion for something…go in with your full heart”
  • 20:39 “your strong network becomes your extended support for future jobs”
  • 21:28 “the no word is also very important skill that we need to learn in this role”
  • 21:34 “just treat everyone with respect, it pays”

View Details

Jinan leads Forrester’s security and risk research in Asia Pacific. Jinan’s research focuses on enabling the success of the chief information security officer (CISO) role; creating transformational cybersecurity strategies; and building security awareness, behaviour, and culture programs at the heart of a security strategy.

Jinan is a champion for diversity and inclusion in security and brings a local and global perspective and cultural lens to her research and practice. Jinan’s research remains pragmatic, as she recently returned to Forrester after several years as director of cyber strategy at Transport for NSW and a similar role with Qantas Airlines.

Jinan has built, stood up, and delivered significant cybertransformation strategies across the public and private sectors. She is an experienced people leader and international keynote speaker, and she's passionate around her purpose in the security field. Jinan holds two bachelor’s degrees in science and commerce from the Australian National University.

When Jinan posted a simple question on social media about her research into the toxicity in cybersecurity teams, it exploded! 'We have all experienced toxicity, whether we've been leaders or we've been led'. In this episode Jinan shares how it enabled people to share their experiences, what she learnt and how she hopes to drive positive change in cybersecurity culture.

Links

  • Forrester
  • Twitter
  • LinkedIn
  • Email
  • Microsoft study mentioned in episode

Time Stamps

  • 00:58 What lead the research on toxic culture in security teams
  • 02:18 “If you're serious about security, you have to retain talent. And you have to create a positive culture for people to stay in”
  • 03:00 What happened with Jinan asked “what are the different causes of toxicity in cyber security specifically?”
  • 03:24 “the experiences that people shared, I have to tell you, it was both heartbreaking and enriching”
  • 05:03 The number one cause of toxicity in security teams and why
  • 06:46 “…what I do like about the top 10 is that I managed to break it down a little bit…”
  • 09:33 What if the CISO is causing the toxicity, and not the environment around them?
  • 12:29 The future of the CISO - the 6 different types of CISOs and knowing who you are or what you want
  • 13:29 “having that self awareness, what is your type? What is your leadership type”
  • 14:55 Why a good mindspace can lead to better leadership
  • 17:04 “the impact of your behaviour as a leader, how you're managing yourself, how you're managing your team has got huge impact on others”
  • 17:53 Tips on turning a toxic culture around to retain employees who may be tired of previous leader habits
  • 21:24 Steps to take when interviewing that could help identify a toxic predisposition
  • 22:50 “… important to check for cultural fit and trust, versus only technical skills…”
  • 23:33 The impact remote working has had on security teams that potentially had a toxic culture
  • 28:16 “it's much harder to hide toxic behaviour, (it) comes to the surface a lot easier than it did in an office environment”

View Details

Samm MacLeod is an experienced CISO and Information Security Leader with experience across Financial Services, Retail, High Tech, Utilities and the Energy sectors. With more than 20 years’ experience in technology risk management, security, and governance, Samm is an accomplished professional holding positions on executive boards relating to critical infrastructure (AEMO Industry Board), and Information Security education and research (Deakin Executive Board).

She has extensive experience developing Information Security Strategies and Operating Models; has built effective award winning security teams (winner ‘AISA Cybersecurity Team on the Year’, 2019). Having run a number of large Cybersecurity programs, Samm has experience helping business to imbed effective security practices. Samm’s subject matter expertise comes from an Honours degree in Technology and a number of Professional certifications. She is an industry advisor in Information Security, Speaker, and advocate for Women in Technology. In this episode Samm and I discuss why it is important to have effective Security Operating Models. We cover how they can be different to an org chart, why it's important to be flexible when creating one, how to measure its effectiveness, and why sometimes outsourcing their creation can be best for your business. Links: LinkedIn Time Stamps: * 00:47 How do you define security operating models? * 01:04 “It's the component that will help drive the security team to operational excellence” * 01:43 Why it’s important to anchor your security operating model to a strategy * 02:56 The risk of thinking a operating model is the same as an org chart * 04:58 “…so they go hand in hand, but they are different” * 05:14 What's the minimum you would need in an operating model to make it function against the strategy? * 07:28 Other than not being effectively implement, what else could make an operating model fail? * 11:17 “make sure failures are dealt with quickly, because there will always be some” * 11:23 What to do if you realise the operating model is not working? * 13:37 How do you measure if an operating model has been successful? * 15:20 “a good operating model breaks down those barriers” * 15:54 Why outsourcing the operating model can ensure it’s delivered effectively, efficiently and within budget. * 20:07 “…you've got to weigh up a few of those things and figure out which way is the best way for you”

View Details

This season I am again recording some solo episodes, and answering the big questions that I hear often when doing consulting work. I'm excited to share some of the experiences I have had during my career in security.

There are times in the hiring process when you will need to surround yourself with certain people - professionals and peers, that are not involved in the day-to-day security or technology function. Having that help and support will ensure you make the best attempt at finding the right security leader.  In this episode, I share tips on who can support and help when recruiting for new security talent.

Links:

  • LinkedIn
  • The Secure CIO

Time Stamps:

  • 00:50 Getting a referral is a great place to start
  • 02:22 The key benefits of a referred candidate
  • 03:39 Why networking is a winning formula
  • 06:04 Choosing the right people to co-interview with
  • 07:56 Key takeaway

View Details

As a neo-generalist, Laura Staples has navigated multiple domains - across transformation, organisational development and human resources - in a variety of leadership roles. Laura is the Head of People & Performance at Laminex Australia and has spent the last 15 years pushing the boundaries in organisations with an eye on the future, seeking out the best experiences to fuel her knowledge and passion for the future of work. Laura is passionate about untangling complexity - be it people, processes or systems - and uncovering the hidden opportunities to transform ways of working. Naturally curious and at times outspoken, Laura is known for her creative leadership and ability to design innovative and commercially viable solutions which surprise and delight.

In this episode Laura shares how just several months after COVID-19 forced us all into lockdown, Laminex Australia transitioned to a permanent work from home environment. She discusses how they made the change, having to take into consideration their current employees needs, as well as the recruitment and on-boarding of new employees.

Links

  • Laminex Australia

Time Stamps

  • 00:46 What working from home (WFH) now means for Laminex Australia
  • 01:21 “And then suddenly overnight…the world transitioned into the largest work from home experiment”
  • 03:11 What Laminex Australia has learnt about virtual recruitment and on-boarding
  • 04:29 “We're designing recruitment experiences where the candidate can put themselves in a real life scenario that may occur within the business, so that we can test how they would respond or react”
  • 07:34 Ways in which communication has changed at Laminex Australia to support the on-boarding of new staff
  • 08:50 “We created an online strategy festival...we broadcast that out to over 200 employees via zoom”
  • 12:05 Managing reward and recognition in a workforce that's so dispersed
  • 15:34 How Laminex Australia is helping WFH employees switch off once the workday is over
  • 17:06What's the physical thing that you can switch off at the end of the day, which is the symbolic shift from, I've left the office now and now I'm at home”

View Details

Started in 2017 by founder Carl Gough, Meet Magic is a new philanthropic platform that matches Executives with Vendors who want to meet with them. Their mission is to inspire a world of meaningful human connections, that simultaneously empower organisational growth and social change by creating conversations that count.

Carl's background is very humble and colourful being raised with a Jamaican family in Nottingham. Leaving school at 15, home at 16, with no university degrees, he set about trying to survive life. And here we are...

In this episode Carl shares how he started Meet Magic and subsequently partnered with The Starlight Foundation and created Meetings for Good - which has found a way to to bring Executives and Vendors together for curated business discussions, whilst helping sick children at the same time. .

Links

  • www.meetmagic.org
  • www.meetingforgood.org.au

Time Stamps

  • 00:25 Claire’s introduction of Carl
  • 01:30 How Meetings for Good started
  • 05:13 How Meetings for Good works by overcoming the usual vendor/client issues
  • 07:09 “The vendors get to see the list of executives who have pledged their time, and they can pick off that list, who they want to go and see”
  • 09:16 The executives and leader benefits from being a part of Meetings for Good
  • 09:39 “You end up going off and having a great day and being a better person to be around for a start, because you've just done some good”
  • 10:00 Why lead to Meetings for Good partnering with The Starlight Foundation
  • 12:20 Having targeted Vendor meetings means valuing everyone’s time
  • 14:24 “They're coming back for more. And they love the outcomes of the meetings”
  • 14:59 Carl’s goal for Meet Magic
  • 18:06 “1000 meetings a month in 10 cities around the world. That's a huge business.…it's making a massive contribution back to society in helping all these different charities”
  • 20:41 How you can get involved with Meet Magic and Meetings for Good

View Details

Meeting the desire to hire a leader who can deliver a cracking board paper that stands alone, and then when required, be able to address the board or sub-committee with gravitas and professionalism, isn’t always easy.

So I created a masterclass!  Listen here to the details of my 6 week intensive course where security leaders and aspiring security leaders can get real world experience creating a board paper, delivering their messages to board members and receiving actionable feedback. 

Click here to go to the registration page 

View Details

Here is a sneak peek of some of the industry thought leaders and change makers I have the pleasure of talking to in the upcoming season 5 of The Secure CIO podcast!

View Details

This season I am recording some solo episodes, answering the big questions that I hear often when doing consulting work. I'm excited to share some of the experiences I have had during my career in security.

Many CIO’s and leaders often say they feel lucky their security leader is still with them given retention in security is such a
challenge. In my final solo episode for the season, I share my tips to help improve the retention of your security leader.

Links:

  • LinkedIn
  • The Secure CIO

Time Stamps:

  • 1.37 Hiring the right leader is so important for retention
  • 2:27 “Tell them what you expect from them and what success looks like”
  • 3:00 Why you need to consider resources (both people and financial) for your security leader
  • 3:30 “To achieve great things, your new leader will potentially need funding...if you plan to make security a business priority, you must reflect this in your budget”.
  • 3:59 Retention of Security leaders also requires exposure.
  • 4:23 “Meeting them for a first time during an incident isn't ideal”
  • 5:19 Recap
  • 6:11 What feeds attrition?
  • 7:37 Final word

View Details

Clare has over 15 years’ experience as an HR professional in many corporate and professional services environments. Over the years she has partnered with many business leaders to support the engagement, selection, development and retention of talent. She has a deep understanding of the impact this can have on employee engagement, individual and organisational performance and the overall culture of a business. After a recent move out the corporate world into private practice, Clare now works Career and Leadership Coach with 'Relaunch Me', where she works with individuals to provide support, guidance on career transition, career planning and strategy, job search, personal branding, interview coaching and outplacement, as well as professional skill and capability development..

In this episode Clare shares why she became a career coach to others after having enlisted the help of one early in her career. We discuss the benefits of engaging the help of a career coach, how to avoid burnout and feeling more energised in your role.

Links:

Relaunch Me website

LinkedIn

Time Stamps:

00:25 Clare’s introduction and background

01:53 Pivotal moments in Clare’s career that led her to where she is today

03:27 “Organisations back then felt that if you helped employees to develop and plan their careers, then you're encouraging them to leave…we know now that that's quite the opposite”

04:51 Why people end up engaging with a career coach like Clare

07:22 Does burnout play a role in seeking the help of a career coach?

09:11 “Seeking help to gain greater self awareness of ourselves, so our personality, our strengths, career, drivers, interests, development areas…can allow us to put some strategies in place to proactively manage and alleviate career burnout”

09:27 Some great outcomes that people can achieve through a career coach

11:04 Tools or actions leaders can take to feel more energised in their role

11:38 “First thing I'd say is to understand your true strengths”

13:03 “Second area is around building a supportive team around you”

13:48 Understanding the importance self-reflection and fulfilment

17:23 The role that mindset plays in career progression for leaders

18:09 “Often what gets in the way of them achieving their goals, and then moving forward sometimes, is to do with their mindset.”

View Details

Jo McConnell is passionate about leading positive change, both in business and society. A 25-year corporate career in people and culture roles across various industries and countries culminated in Jo founding The People Collective, a consulting business bringing a unique perspective to helping complex, fast-paced businesses become the place that the very best people want to work. Jo is also the CEO of NFP The Gomo Foundation.

In this episode, Jo shares her knowledge on developing leadership skills in your team members, as well as how you can become a stronger leader yourself. We discussed what to look for in a great operating model, and the value that this can add to your business. Jo shared her simple habits and rules to create a great leader, her top three retention strategies, and a great recommended reading list to take your own leadership skills to the next level!

Links:

  • LinkedIn
  • The People Collective
  • The Gomo Foundation

Time Stamps:

  • 00:29 - Jo’s introduction and background
  • 02:15 - How to evolve and nurture leadership skills in a security leader
  • 03:33 - “You can't be what you can't see.” - Jo McConnell
  • 04:15 - Jo's reading recommendations on leadership
  • 04:55 - How to develop your direct reports into great leaders as a CIO
  • 05:57 - “Too many people in my experience don’t consciously and deliberately think about how they show up every day as a leader.” - Jo McConnell
  • 06:36 - Senior leaders as workplace role models
  • 08:23 - "Whether you are leading a team of 5 or 5,000, as a leader people are watching you and taking cues from you every day." Jo McConnell
  • 09:20 - Simple habits and simple rules to develop a great leader
  • 10:05 - Creating a dynamic workplace to help fill staff and skills shortages
  • 13:09 - The value of a good operating model
  • 14:00 - “I think of an operating model as the integrated engine that drives the execution of strategy in a business. It is the ecosystem of things that you deliberately architect to deliver your strategy.” - Jo McConnell
  • 17:15 - The art and science of salary benchmarking
  • 20.18 - Top three strategies to retain leaders and professionals
  • 22:03 - Changes in the current security workplace environment and function

View Details

Jacqui Loustau has 19 years of international experience in a range of technologies and practical experience across multiple security domains within different industry sectors. This includes working on various high profile projects within the European Commission, UK government, NHS and the financial sectors. Jacqui currently works for Cynch Security, where they are helping small businesses get and stay cyber fit. Jacqui is founder of the Australian Women in Security Network (AWSN) which aims to connect, support and inspire more people, in particular, women to pursue a career in security; and is co-author of the international book ‘Women in the security profession’.

In this episode, Jacqui shares her career history and how she ended up in security; being a remodel for other women in security; and why she started the AWSN. We discuss her new role at Cynch Security and flexible working, and how the AWSN is helping upcoming security leaders with their career progression.

Links:

  • LinkedIn
  • Twitter
  • AWSN website

Time stamps:

  • 00:29 – Jacqui’s introduction and background
  • 01:47 - How Jacqui got to where she is today
  • 02:49 – “I had to do my CCNA so I learned about networking for the first time, touched my first router. I did my SANS security course as well, so that's where I got my love for security” – Jacqui Loustau
  • 06:43 – What drove Jacqui to start the AWSN
  • 10:20 – “What lessons have you learned from…raising the network from its beginnings as a LinkedIn group to an organisation across multiple states?”
  • 12:09 - Being a role model and supporting other women in the industry
  • 14:16 –Starting work at Cynch Security
  • 16:14 - Getting that work life balance with job share
  • 20:56 - “For any of these schemes to work it needs to be equal. So it's not just women that are getting this flexible working, but it should also be the men as well” – Jacqui Loustau
  • 21:45 - Common discussions Jacqui has with other security leaders in regards to job search and career progression.
  • 26:33 - “We've created the AWSN cadets initiative…we expose them to different companies…that have security roles, and are in different areas of security…they go through technical workshops etc…we have something like 79 cadets at the moment going through that” – Jacqui Loustau

View Details

Anna is UniSuper’s Chief Delivery and IT Officer. Since 2017 Anna has been leading the business through transformational change to deliver better value to members through efficient, scalable and modern processes and technology. Anna’s cross-industry career spans more than two decades, and she is renowned for her ability to blend strategy development and transformational change across technology, business practices and growth culture. In addition, she is a passionate advocate for women in STEM and leadership, participating in many speaking panels about these topics at business and industry forums. Anna is a board member with Ambulance Victoria and is a graduate of the Australian Institute of Company Directors.

In this episode, Anna talks us through successfully implementing remote working on scale, as well as how this has impacted specifically on the security and tech functions of the business. Anna's board experience places her perfectly to discuss the impact of board diversity, and she also runs through the traits that lead to successfully cohesive teams. Anna shares her gems of wisdom that she imparts on graduates, as well as recommending some key knowledge for CISO's with direct reports.

Links:

  • LinkedIn
  • 110 Percent Consulting

Time Stamps:

  • 00:30 - Anna’s introduction and background
  • 01:10 - The impact of remote working on teams
  • 01:55 - “If there wasn’t trust there with the teams prior to working remotely on scale, you can’t build that trust once the people have left the office.” - Anna Leibel
  • 04:30 - Have security and tech leaders and employees been impacted more by not having hallway conversations?
  • 08:12 - Capability recognition in security
  • 09:01 - Focusing on your security leader
  • 10:34 - “We’re implementing a three-year strategy, we are two years into that. So Vijay makes it very easy for me to be able to understand where we’re at, what we’re doing and why we’re doing it, and then what is coming up next.” - Anna Leibel
  • 12:40 - Key knowledge for CISO's with direct reports
  • 14:13 - Traits of successful, cohesive teams
  • 14:58 - “The foundation for me in any team, regardless of size, is actually the clarity of accountabilities.” - Anna Leibel
  • 19:01 - The advice Anna gives to graduates
  • 22:23 - The impact of board diversity on tech and cyber

View Details

This season I am recording some solo episodes, answering the big questions that I hear often when doing consulting work. I'm excited to share some of the experiences I have had during my career in security.

In this solo episode I answer a question that I am often asked by CIOs when we are going through the hiring process; what is the difference between a CISO and a Head of Information Security?

Links:

  • LinkedIn
  • The Secure CIO

Time Stamps:

  • 01:01 - Key difference between a CISO and a Head of Information Security
  • 01:31 - What is a CISO?
  • 01:54 - Does a start-up need a CISO?
  • 02:15 - How to tell you are ready for a CISO
  • 02:52 - The role of the CISO
  • 05:46 - The role of the Head of Information Security
  • 08:00 - A final word

View Details

Fiona Wynn is a business psychologist, independent consultant and startup co-founder with extensive experience in people and culture, organisational development, and experience design. Previously, Fiona was Head of Culture, Inclusion and Innovation at Australia Post, where she built strategies and platforms for cultural change around inclusion and innovation. Fiona has worked with leaders across a broad set of industries over the years, solving unmet problems in new ways. Fiona is co-founder of Werkling, a start-up connecting on-demand professional talent with dynamic, future-ready businesses.

In this episode, Fiona shares her knowledge on company culture and its impact on your team. Learn about acculturation, and how strong organisational culture can work for you or against you. We discuss setting people up for success from day one, how a candidate can use the interview process to confirm a good cultural fit, and turning culture around as a new leader of an existing team.

Links:

  • LinkedIn
  • Werkling

Time Stamps:

  • 00:29 - Fiona’s introduction and background
  • 02:15 - How to evolve and nurture leadership skills in a security leader
  • 04:01 - How the values and belief systems of a company impact the people in the organisation
  • 05:05 - *“*Values of an organisation impact on everything. It impacts on the extent to how people show up, it demonstrates or helps shape the customer experience, it shapes so many things about commercial outcomes. But ultimately…to the individual, it does impact their decision making and behaviour. - Fiona Wynn
  • 09:13 - The impact of acculturation on staff
  • 12:01 - *“*If you’ve got a really strong culture that permeates and reinforces certain behaviours or certain attitudes or certain ways of working that actually reduces diversity, that’s a real risk. You can end up with very homogenous teams. - Fiona Wynn
  • 12:45 - Do we show up to work culture consciously or subconsciously?
  • 17:59 - Setting people up for success from day one
  • 20:20 - "If your employee experience is aligned to your brand experience, that is very powerful from a performance perspective. You’re much more likely to give customers a great experience if your employees are feeling really engaged, empowered, having a really good time." Fiona Wynn
  • 21:32 - Designing the perfect onboarding experience
  • 22:55 - Three things a candidate should ask during the interview process to confirm value alignment with an organisation
  • 27:15 - Turning around culture as a new leader of an established team
  • 28:00 - “Hold your assumptions. It is easy to pick up on stories... Blame culture might have actually really gotten its claws into that team. I think the really important thing is to stay quite impartial and to not make judgments on the former leader or make judgments on the team that was, and see this as an opportunity to start again.” - Fiona Wynn

View Details

Phillip (Pip) Jenkinson is an ex-serving member of the Australian Defence Force and has been involved in the ICT community in Australia for about 12 years.

Pip works for one of Australia's leading Indigenous ICT security providers, Baidam Solutions, committed to giving back to the local economy as a way to help us bridge the gap of Indigenous representation in the IT security sector. The Baidam Initiative provides both specialist IT security certification funding and meaningful employment opportunities for First Nations communities.

Pip sits on a number of not-for-profit advisory boards and regularly supports the charity Solider On, which helps contemporary veterans and their families build successful futures. A husband, father, brother, son and proud supporter of the cause, Pip is passionate about creating real change.

In this episode, Pip shares with us the role that community involvement plays in Baidam Solutions' growth, the barriers he has seen to organisations being more diverse and inclusive, and the current situation around STEM leaders on NFP Boards. As a passionate advocate for change, Pip also shares details on the graduate program Baidam has developed, and a brief overview of some exciting news to be launched during NAIDOC week.

Links:

  • Baidam Solutions
  • NAIDOC Week

Time Stamps:

  • 00:39 - Acknowledgement of country
  • 00:51 - Pip's introduction and background
  • 02:13 - Sorry Day
  • 02:58 - Pivotal moments in Pip's career
  • 04:50 - The driving force behind the creation of Baidam Solutions
  • 07:15 - The growth of Baidam and community involvement
  • 08:45 - Barriers to more diverse and inclusive organisations
  • 10:04 - "CHOICE is the acronym that we use in Baidam to articulate our value proposition. Courage, honesty, originality, innovation, to challenge the status quo, and to educate or to be educated...to a culturally significant story." Pip Jenkinson
  • 12:28 - The future for first nations in ICT
  • 15:56 - Planning growth in Baidam's grad program
  • 16:01 - "One of the reasons why Baidam was created in its infancy was that I was unable to rattle off indigenous participants in the IT security space as quickly as I could indigenous sports stars, or indigenous politicians, or activists, or musicians." Pip Jenkinson
  • 23:38 - ICT and Cyber on Boards in not-for-profits
  • 26:00 - What does real change look like to Pip

View Details

In the age of modern technology when we are all available all of the time, burn out is becoming more common. Cybersecurity, a notoriously 'on-call' industry, is a prime example where working long hours can take its toll on our mental and physical health. But what can we do to address it, before it gets out of hand? My guest this week is Graeme Cowan. As a mental health and resilience author and speaker, and Board Director of R U OK?, Graeme spends his professional life helping people understand just that. Graeme uses his first-hand experience after coming through an experience of extreme burn out to help others appreciate and understand the importance of looking out for themselves, as well as looking out for the people around them. In this episode, Graeme talks us through his personal experience of burnout, and his evolution out of that period of his life. Crossing paths with Gavin Larkin resulted in the launch of R U OK? Day in 2009, and Graeme shares how its simplicity helped it to grow. We cover a whole range of topics on how to consider and address issues that can lead to burnout, an issue that we know is prevalent in the cybersecurity industry. My goal for my discussion with Graeme was to give you the knowledge to build safe, resilient, and healthy security teams and leaders, but this episode goes so much further than that. It is PACKED full of information, resources and simple, actionable ideas that you can use today immediately to check in not only with your team, but also with yourself. Enjoy! Links:

  • Graeme’s Website
  • LinkedIn
  • Twitter
  • Back From The Brink
  • R U OK?
  • TED Talk on the Harvard Study of Adult Development
  • Self-Care Snapshot Checklist
  • Project Aristotle results
  • Debunking Maslow’s Hierarchy of Needs
  • Peter Gollwitzer

Time Stamps:

  • 00:30 - Graeme’s introduction and background
  • 01:46 - Graeme’s story
  • 03.10 - The origin of RuOK
  • 06:12 - The impact of stress and long working hours
  • 07:01 - “I don’t really believe so much in the concept of work-life balance, because that assumes that work is bad, life is good. And if you believe in your work, work can be very good for you. Lots of evidence around shows that work is essential to our wellbeing. But having said that, we also have to make sure there is time in our day, in our week, for the things that really help us.” - Graeme Cowan
  • 07:38 - Three areas that we need to regularly top-up
  • 08:02 - Harvard Study of Adult Development
  • 09:04 - How to wind down and disconnect when working in an on-call role
  • 14:36 - The role of mindset on burnout, and the benefits of self-care
  • 20:28 - Creating a safe space to empower your staff to call out when their resilience is being tested
  • 21:13 - “From a leader's perspective, I really recommend that if they want to have a high performing team, they need to be continually asking themselves these three questions; Are we connected? Do we feel safe? and Do we have a shared future?” – Graeme Cowan
  • 26:14 - Key advice for building safe, resilient, and healthy security teams and leaders

View Details

Welcome to Season 4 of The Secure CIO Podcast!

Over the past three seasons of the podcast, there has been a strong focus on interviewing security leaders, which has resulted in some really interesting and informative discussions. This season I'm doing things a little bit differently.

In Season 4 you are going to hear from a few people outside technology as we look at leadership and the role HR and people/culture leaders play in the recruitment process and the building of teams.

Topics include working remotely, STEM leaders on boards, and burnout in the security industry. Some of the themes that run throughout this season include trust, reflection, and leadership.

To kick off this season, the guest on episode one is...me!

Join me for my first solo episode, as I run through some of the lessons I have learned through a number of years consulting, as well as a career in security, and share the 7 mistakes that CIO's are making when hiring a cybersecurity leader.

Links

  • LinkedIn
  • The Secure CIO
  • Free Excerpt from 'The Secure CIO'
  • Buy your copy of 'The Secure CIO'

Time Stamps

  • 00:26 - Introduction to Season 4
  • 00:52 - Introduction to this episode
  • 00:52 - "What I have noticed about security hiring and retention is that there are many CIO's out there who are making decisions early in the hiring process that could be preventing making the right decisions at the end of the hiring process, or even preventing them from finding the right candidate to begin with." Claire Pales
  • 02:00 - The role of the CIO
  • 02:45 - Mistake #1; The reason for hiring doesn't set the CIO up for success
  • 04:17 - Mistake #2; You use the same job description you used last time
  • 05:42 - Mistake #3; The job description is written as a wish list of actions
  • 05:50 - "If the job description is laid out as a wish list of actions, this can mean that after the CISO delivers these items, it's unknown what their remit should be." Claire Pales
  • 06:17 - Mistake #4; Looking for someone that can do it all
  • 07:40 - "Seeking a security leader who can do it all will delay your hiring and possibly leave your security seat empty which only leads to increased risk." Claire Pales
  • 07:49 - Mistake #5; Viewing internal promotion as a 'quick win'
  • 08:39 - Mistake #6; Leader not nurtured or developed adequately
  • 09:33 - Mistake #7; Viewing hiring a leader through a 'set and forget' lens

View Details

Join host Claire Pales, as she shares some exciting details about the upcoming Season 4 of The Secure CIO Podcast, with the first episode due for release on Thursday 18th June!

www.thesecurecio.com

View Details

Fred Thiele is an information security and technology executive with a diverse, global background in large corporate environments, mid-sized consulting businesses, and small startups. Fred discovered the field of cybersecurity in 1998 while repairing Wyse Terminals and maintaining Linux servers at his university library. Currently, he is the Group CISO at Transport for NSW.

In this episode, Fred will share strategies for building and growing strong cybersecurity teams across the USA and Australia. Find out the barriers to cybersecurity success and how to overcome them.

Links:

  • LinkedIn
  • The Johari Window

Time Stamps:

  • 00:27 - Fred Thiele’s background and introduction
  • 07:13 - The best reporting structure for the CISO or head of security
  • 07:27 - “Just because you report to the CEO doesn’t necessarily mean you have a seat at the table.” - Fred Thiele
  • 08:38 - Building teams & hiring cybersecurity professionals across the USA vs. Australia
  • 11:40 - Choosing graduates to join your team
  • 14:37 - Principle to follow when building your new security team
  • 18:10 - Overcoming hurdles in all organisations
  • 21:01 - Best advice aspiring security team leaders
  • 23:23 - “In a leadership position you’re much more influential than you think you are. You’re setting culture by just walking around the office.” - Fred Thiele

View Details

Niamh Fitzpatrick is the co-founder of Puffling, a platform that provides tangible solutions for a more productive, engaged, and inclusive workforce.

Niamh has over 20 years experience in product and technology across a range of industries. In 2016 Niamh joined Facebook in an Asia Pacific role, leading a team of senior managers responsible for driving business opportunities and growth with technology and creative partners across the region. She has been a long-standing advocate for increasing the number of women in senior leadership roles and those choosing to work flexibly for a variety of life stage decisions or personal circumstances.

In this episode, Niamh shares how companies can successfully adopt flexible working practices. Hear about the benefits of embracing progressive and flexible work solutions. Learn why it is more important than ever for organisations to adapt their work practices. Discover how to attract and retain senior talent by offering flexible working options within your organisation.

Links:

  • Facebook - Puffling
  • LinkedIn - Puffling
  • Puffling Website
  • Puffling Tech Website

Time Stamps:

  • 00:32 - Niamh Fitzpatrick’s background and introduction
  • 03:37 - Differentiating Puffling and Puffling Tech
  • 05:18 - Embracing flexible working roles
  • 06:58 - “Flexibility has become increasingly important and a real driver when it comes to moving roles.” - Niamh Fitzpatrick
  • 07:27 - Top factors that cause job-sharing arrangements to the unsuccessful
  • 09:17 - Communicating a job share arrangements for success
  • 10:25 - Roles that are better suited for job share arrangement
  • 11:18 - What motivates people to change jobs?
  • 14:25 - How to attract flexible candidates to your team
  • 15:29 - “What works for someone in terms of flex might be quite different for someone else. It’s not a one size fits all is really important for the business.” - Niamh Fitzpatrick
  • 16:03 - Learning more about Puffling and Puffling Tech

View Details

Angela Coble is an executive leader, board member, and internationally published author, with experience in healthcare, utilities, finance, and agriculture.

Angela has more than 20 years of leadership experience including executive positions within the Healthcare industry in Security and Technology and Electricity Supply industry, including Group Manager Business Planning Infrastructure Operations for NSW. In 2019 Ange was announced as #18 in Australia’s Top 50 CIO’s – the second time she has made this illustrious list.

In this episode, Angela will share how to build and lead a high-performing security team as a remote leader. Find out the role that diversity, inclusion, and culture play in the workplace. Learn the best advice for aspiring leaders to excel and succeed in all parts of technology, even beyond security.

Links:

  • LinkedIn

Time Stamps:

  • 00:31 - Angela Coble’s introduction and background
  • 04:17 - “Leadership is interoperable. It’s more about the people that are around you.” - Angela Coble
  • 04:34 - How a security background shaped Angela in her tech leadership role
  • 06:20 - Interacting with security teams and leading organisations to success
  • 10:18 - Building security teams as a remote working leader
  • 15:29 - Ways to successfully work remotely?
  • 17:07 - “For people to be successful who work remotely they often have to be hyper-aware of over-communicating.” - Angela Coble
  • 18:40 - Defining diversity and inclusion in the workplace
  • 22:59 - The best advice for aspiring CIOs

View Details

Brett King is a lover of all things technology that make our work and social lives more rewarding. He is the Managing Director of two technology businesses that share similar customer objectives of implementing solutions that increase organisational efficiency and effectiveness whilst indentifying and implementing governance and risk management.

During this episode, Brett shares the benefits of integrating security technologies into your organisation. He will explain the three main strategies that organisations with limited budget, resources and knowledge can employ to manage cyber risk. Listen as we discuss managing your risk as a consultant, change management, and the challenges facing regional organisations. Hear about the power of hiring independent contractors and the difficulties building internal teams.

Link:

  • LinkedIn
  • Unified Technology

Time Stamps:

  • 01:00 - Brett King’s introduction and background
  • 06:08 - Discovering security landscape and needs of security CIO’s
  • 07:47 - “I see it as a very professional thing to do to understand your risks and manage those risks without addressing them.” - Brett King
  • 10:05 - The benefits of Integrating an element of security in the tech space
  • 12:14 - Addressing customers with cyber risk and a limited budget
  • 14:30 - “Organisations need to understand what assets they’re trying to protect and what the value of those assets are, and what they’re trying to protect those assets from.” - Brett King
  • 17:44 - Hiring internal employees vs independent contractors
  • 18:33 - “To have the appropriately trained internal people and to be able to afford them and retain them is a significant barrier to building internal teams.” - Brett King
  • 20:28 - Security in regional Victoria vs. capital cities
  • 22:06 - Best advice for aspiring CIO’s

View Details

The Secure CIO Podcast has been downloaded over 5,000 times!

Over the first two seasons of The Secure CIO Podcast we heard from 21 industry experts, discussing a range of issues currently affecting the cybersecurity industry.

We are now over halfway through another amazing season, and I am looking forward to recording season four.

I am excited to share with you that after just 25 episodes The Secure CIO Podcast has been downloaded over 5,200 times.

To celebrate, I wanted to share this episode with you. It features conversations from the top five most downloaded episodes so far. Hear from Jonathan Werrett, Nick Ellsmore, Anna Leibel, Craig Searle, and Dan Maslin as we discuss all things cybersecurity.

Links:

  • Episode 1: Security In Context with Jonathan Werrett
  • Episode 3: Security Sourcing: Cracking the Code with Craig Searle
  • Episode 12: The Cybersecurity 'Roles' Crisis with Nick Ellsmore
  • Episode 14: From Security Architecture to Security Leadership with Dan Maslin
  • Episode 21: Anna Leibel, CIO, UniSuper
  • The Secure CIO Podcast LIVE! with Anna Leibel (video recording)

Time Stamps:

  • 01:28 - Jonathan Werret on finding a leader that can do it all
  • 02:52 - “Rather than looking for a unicorn, have an idea of what you think the biggest risks are, and what you the most important skills will be in that person and start to optimise for that.” - Jonathan Werrett
  • 03:10 - Nick Ellsmore on the impact of how the first leader in the organisation can shape the perception about security, and if there is an ultimate path to security leadership.
  • 05:00 - "Security knowledge alone isn't often what's going to get the job done. My overall advice would be to find someone pragmatic and someone that can build relationships." - Nick Ellsmore
  • 09:47 - Anna Leibel on how information security is impacting the board
  • 10:42 - "Two and a half years ago we would talk about how much money do I have to spend to spend to be safe, and now we are talking about are we prepared for when we are breached." - Anna Leibel
  • 14.29 - Craig Searle's tips on how they source great people to work at Hivint
  • 16:40 - “One of our big beliefs is that good people attract more good people, and in fact what ended up happening was that ... people wanted to work with other team members in our team. That then attracted more people. It does get easier to recruit on that basis.” - Craig Searle
  • 17:35 - Dan Maslin on insourcing and outsourcing
  • 22:59 - "Sometimes the organisation is not the right fit, or it is not the right time for certain people within that organisation. I would say that is ok, and that does happen, and you need to have that conversation pretty quickly." - Dan Maslin

View Details

Graham Thomson is an independent consultant specialising in cybersecurity and information risk. With many years as a leader in cybersecurity providing advice to boards, senior executives and technical and operational teams, he has a unique breadth and depth of skill and experience in the industry.

During this episode, Graham shares his evolution into becoming a security leader, including the techniques and challenges in building a security team. He reveals useful techniques and strategies on how to retain long-term employees for your organisation. This episode delivers practical advice on how to ensure you are recruiting the right candidates for long-term success within your organisation.

Link:

  • Graham Thomson | LinkedIn
  • Blog - Is it time to rethink your interview process?

Time Stamps:

  • 01:02 – Graham Thomson’s introduction and background
  • 01:56 – His evolution to becoming a security leader
  • 04:00 – How does consultancy fit in security teams?
  • 6:35 - Building a cohesive and effective team for the Commonwealth Games
  • 7.29 - "Failure was not an option. The fact that it had to be successful meant that individuals brought a willingness-to-help frame of mind." - Graham Thomson
  • 10:30 – Hiring your first security team employee
  • 13:16 – Challenges in building a security team
  • 13:54 – An technique to use when interviewing a potential employee
  • 16:30 – What encourages Graham to work long-term with an organization
  • 18:00 – “Retention within a security team is very much a challenge for security leaders.” - Graham Thomson
  • 18:13 – Ways to inspire your team to stay long term in an organisation
  • 19:19 – “Cybersecurity is a great challenging area where you could actually enjoy what you’re doing” - Graham Thomson
  • 19:26 – Key lessons in building your security team
  • 20:54 - What advice would you give your 20-year-old self about teams and leadership?

View Details

Dr. Jodie Siganto is one of Australia’s leading privacy experts, sought by government departments, international corporations, and Australian businesses to advise on privacy and data security-related matters.

Over her career, she has held in-house counsel roles for Tandem Computers, Unisys Asia and Dell. She also co-founded data security firm, Bridge Point Communications, which was sold to Telstra in 2014, and held leadership roles with industry groups including AISA. Jodie has been involved with a range of privacy and security industry groups, including as Chair of the AISA Policy Committee and AISA Education Director.

During the course of attaining her doctorate, Jodie coordinated extensive research into privacy in Australia. In this episode, Jodie will share the important links between information security and privacy, and the significance of being able to protect individuals. Expect to gain insight into a statistical analysis of the privacy skills shortage based on the results of her research. Hear the issues hindering privacy from a resourcing and recruiting perspective, and how they compare to similar issues facing the cybersecurity industry.

Links:

  • Itsecuritytraining.com.au
  • LinkedIn
  • Privacy 108

Time Stamps:

  • 00:28 - Dr. Jodie Siganto’s introduction and background
  • 05:58 - What draws others into the cyber security industry
  • 08:30 - A statistical interpretation to the cyber security skills shortage
  • 11:18 - “Some of the traditional indicators of a skills shortage weren't present when we were looking at the data.” - Dr. Jodie Siganto
  • 14:00 - The importance of streamlining and standardising roles against the job titles
  • 17:29 - Insight into privacy from a resourcing and recruiting perspective
  • 21:50 - “The absence of [information security] now at a societal level would be enormously harmful.” - Dr. Jodie Siganto
  • 22:00 - Is there an obvious privacy skills crisis?
  • 24:43 - Upskill your staff with proper fundamentals

View Details

Paul Chapman is the Global Chief Information Officer at Box, where he is responsible for leading the company’s global information technology strategy, cyber risk and compliance practices and customer advocacy. Prior to Box, Paul was the CIO of HP Software for HP. Paul also served as Vice President of Global Infrastructure and Cloud Operations and Vice President of Enterprise

In this episode, Paul will share his hiring process and describe the characteristics that make a good candidate. He’ll provide insight into the potential conflict between a CIO and CISO, and its necessity in managing an effective decision-making process. Paul discusses Box's requirements for candidates with a strong personal brand, reputation in the market and having the respect of others in the community and why this is critical to the role, as well as finding a good cultural fit. He also shares the ways that Box invests in a number of different dimensions in security to ensure the highest level of security function and structure.

Links:

  • LinkedIn
  • Box.com

Time Stamps:

  • 01:03 - Paul Chapman’s introduction and background
  • 06:01 - The process of hiring the proper candidate first
  • 08:25 - The characteristic that makes a good candidate
  • 10:32 - Hiring principle to follow when selecting new team members
  • 12:41 - What’s driving compliance and trust under the CIO?
  • 13:30 - “More and more security and compliance functions converging into the one notion of trust. Compliance is such a key component of the value we bring.” - Paul Chapman
  • 14:30 - The pressure to have the highest level of security function and structure
  • 16:16 - “It’s about being forward-thinking, innovative, and constantly evolving our own security posture to be our own best referenceable company in the market.” - Paul Chapman
  • 17:19 - Top advice for other aspiring CIOs

View Details

Tamara Martin commenced her career as a qualified lawyer and then transitioned into consulting in Crisis, Emergency, and physical security management, servicing a broad range of global and domestic and critical infrastructure organisations.

After gaining a well-rounded skill set through her consulting experience and first client-side role with Jemena, Tamara decided to take up a newly created full-time position within the AGL Energy Security team. Since commencing at AGL in mid-2017, Tamara has developed high-end skills and expertise in business resilience, specifically intelligence, strategic, physical security, crisis management, travel security, and aspects of cyber security

During this episode, Tamara will provide insights into finding common ground amongst those within your diverse organisation. Listen as she reveals the most valuable lessons she has learned through her transition into the cyber security industry. Tamara shares her knowledge on the skills gained in other industries and professions that are transferable to cyber security, as well as the traits that can identify a candidate that may be new to cyber but has the potential to enhance your team.

Link:

  • LinkedIn

Time Stamps:

  • 00:34 - Tamara Martin’s introduction and background
  • 03:13 - What makes someone a good choice to come into a security team
?
  • 04:50 - Key skills from legal and consulting days that Tamara was able to bring into physical, security and resilience work
  • 06:55 - The role of diversity in the success of the team
  • 07:43 - “If you've got a really strong leader who can encourage the traits which motivate and drive you to work towards common goals and objectives, and the occasional giggle, it seems to work quite well.” - Tamara Martin
  • 08:15 - Finding the common ground and endearing trust
  • 08:49 - The importance of having support groups for a certain community
  • 10:50 - Gaining skills in other disciplines of the security industry
  • 12:23 - “We're all operating in roles that are inherently risk-based, and you will operate better and make more informed decisions if you're aware of those cross-functional cooperation opportunities and their impacts.” - Tamara Martin
  • 13:35 - Taking a chance on a not-so-obvious candidate who has the potential
  • 14:49 - “Self-driven learning manifests in a much more productive and enthusiastic team member.” - Tamara Martin

View Details

Damien Scalzo is the CIO of Mercedes-Benz Financial Services Australia/New Zealand. For over 15 years, Damien has combined his business and technology experience as a CIO, Management Consultant, Systems Integrator and Chartered Accountant to help organisations use technology to add value to their core and new business processes across industries including Financial Services, Manufacturing, Utilities, and Public sector. Damien is passionate about technology and also spends time mentoring startups to grow and scale

In this episode, Damien will share his tips on managing cyber security at the executive level. As a mentor for startups, Damien is able to share with us exactly when startups should be considering their security strategy. Using his experiences from a combination tech leadership and security background, Damien shares various effective reporting structures for security leaders. Find out how Damien keeps his knowledge on current security trends updated, and how he uses this information to protect the organisation

Links:

  • LinkedIn

Time Stamps:

  • 01:00 - Damien Scalzo’s introduction and background
  • 04:08 - How security organisations can obtain value and funding
  • 05:55 - Your first hire when building a new team security team
  • 06:14 - “I always liked the idea, in anything, in hiring the talent that finds its own talent. It’s always been better to hire the leader first who then builds their team up.” - Damien Scalzo
  • 07:20 - Understanding how to take risk in a corporate environment
  • 08:10 - Should security leaders report directly to the CEO?
  • 09:22 - “Whether the CIO represents security at the board or the CISO comes into the board as a guest, the CEO has to be the person that sets the tone from the top for security.” - Damien Scalzo
  • 10:03 - Understanding cyber security at the executive level
  • 12:08 - How to stay current with updated knowledge on security trends to keep your team, peers and executives informed
  • 15:05 - When should a start up organisation consider a security strategy and dedicated security leaders? What can they do in the meantime?
  • 17:00 - Damien's best advice for CIOs from his unique experience combination of start-up mentoring, and being a leader in tech with a security background

View Details

Victoria Kluth is the CEO of Araza, a technology company that specialises in the implementation of complex solutions including cloud-based applications and enterprise systems integration.

Victoria is recognised as one of Australia’s most successful entrepreneurs and has won the Optus Business Leader of the Year award and ARN Entrepreneur of the Year. Her organisation has been presented multiple technical awards, and is on multiple 'fast' lists in Asia and Australia.

During this episode, Victoria will share the guiding principles that have allowed Araza to achieve fast growth. Listen and learn about the Araza Women in Cyber program, developed to help address gender diversity within the cybersecurity industry. Discover how the program is providing entry-level female cybersecurity candidates with experience to launch their cyber careers.

Links:

  • LinkedIn
  • Twitter

Time Stamps:

  • 00:32 - Victoria Kluth’s background and introduction
  • 03:03 - “So many people just take clients for the sake of having that work. They are not looking at, well is this the type of company we should be partnering with. Are we both going to look good?” - Victoria Kluth
  • 04:20 - How to attract a diverse workforce of women
  • 06:43 - Principles to follow when building teams in the tech industry
  • 07:22 - “Be great and be grateful. Striving to be great is ensuring success for yourself, your client, and company.” - Victoria Kluth
  • 10:20 - The Araza Women in Cyber Program
  • 16:30 - Recruiting high-level cyber industry entry employees
  • 19:39 - Examples of training for program participants
  • 21:48 - Attracting diverse candidates for a successful team
  • 25:40 - “Diverse teams, whether it’s in cyber or anything, perform better. All the research shows it.” - Victoria Kluth

View Details

Anna Leibel is the Chief Information Officer of UniSuper, an Australian superannuation fund that provides superannuation services to employees of Australia's higher education and research sector. She has spent two decades building and leading teams to deliver business transformation, and has been successful in launching new businesses, expansion into Asia, enterprise technology, global sales, and start-ups.

During this episode, Anna will share her business technology and transformation strategy for Cyber Security leaders in this digital transformation age. Learn the non negotiable traits a successful security leader must have. Gain insight into the gender diversity in the workplace and the strategy for an internal or external security breach.

Links:

  • LinkedIn

Time Stamps:

  • 01:10 - Anna Leibel introduction and background
  • 06:00 - The fundamental shift in the size and focus of security teams
  • 08:44 - Non Negotiable traits a security leader must have
  • 10:33 - Insight into gender diversity in the workplace
  • 11:09 - “I think we are missing a really big opportunity to help people understand why it’s so important to have diversity. And for me, it's diversity of thought.” - Anna Leibel
  • 12:09 - New cyber trends from the board perspective
  • 14:49 - Are board members proactively educating themselves around cyber?
  • 16:51 - The immediate strategy for an actual security breach
  • 23:13 - Building a relationship with your CISO
  • 26:53 - Adjusting to the security language within your organisation
  • 28:17 - The role of the cloud & protection methods
  • 32:52 - Learnings from working within the cyber security industry

View Details

Fatemah Beydoun is a founding team member of Secure Code Warrior, a secure coding company with innovative solutions helping AppSec Managers and DevSecOps to not only shift left but start left. As VP of Customer Success and Operations, Fatemah is responsible for turning SCW’s customers into its biggest advocates, improving Customer Success maturity, and leading the Customer Success teams globally.

During this episode, Fatemah will discuss a family-friendly policy that will allow you to finally find your work & family balance. You’ll also hear insight into why the organisation attracts so many passionate employees. Lastly, find out how to retain quality staff during the ‘skills crisis.’

Links:

  • Securecodewarrior.com
  • LinkedIn

Time Stamps:

  • 00:25 - Fatemah Beydoun introduction and background
  • 04:28 - “We really believe that diversity is what makes really strong teams.” - Fatemah Beydoun
  • 04:39 - What attracts passionate employees to your organisation
  • 06:26 - Secure code policies for maternity and maternity leave
  • 09:10 - A policy that allows you to not have to choose between work & family
  • 11:29 - Lessons learned from a family-friendly policy
  • 12:06 - “Everyone in the organisation can play a role in creating that non judgemental environment where people except children into the workspace.” - Fatemah Beydoun
  • 13:25 - Attract and retain the proper quality staff during the ‘skills crisis’
  • 14:59 - Best advice to those aspiring to be in a leadership position

View Details

Kathleen Smith, CMO for CyberSecJobs.Com and ClearedJobs.Net, has coached thousands of job seekers and employers on how to better connect and work together to achieve the mutual goal of employment.

Kathleen presents at several conferences each year on recruiting and job search. Some of the conferences she has presented at as a sole presenter or moderator include BSidesLV, BSidesTampa, BSidesSATX, DerbyCon, CircleCityCon, FedCyber, and CyberSecureGov. Kathleen is Director of HireGround, BSidesLV’s two-day career track.

During this episode, Kathleen shares how industry volunteering can help career progression within your company. Learn to solve the cybersecurity skills shortage within your organization. Lastly, find out how to promote employee retention with quality security employees in the security market.

Link:

  • LinkedIn

Time Stamps:

  • 00:25 - Kathleen Smith’s introduction and background
  • 02:08 - Uniquely servicing the candidate community
  • 03:08 - Cyber security career survey overview: Talent Shortage
  • 03:34 - “We hear sometimes that there is this talent shortage, but there has not been a shortage of people who are constantly learning about finding better ways to be secure.” - Kathleen Smith
  • 06:49 - Four major job search methods
  • 07:25 - “Employee referrals and job boards are the number one and 2 ways of company’s finding their next candidate.” - Kathleen Smith
  • 10:01 - Why money is a driving force to join particular organisations
  • 12:53 - A survey around community volunteer work
  • 17:25 - Top skills that volunteer learn from volunteering
  • 20:42 - Employee retention in the security industry
  • 22:59 - Advice to employers who are hiring and build new security teams

View Details

William Confalonieri is Deakin University’s Chief Digital and Information Officer, appointed in January 2012. He has postgraduate qualifications in Computer Science, Business, Negotiation, and Economics, is a certified Enterprise Architect and a graduate from the Australian Institute of Company Directors. William was awarded Australian CIO of the Year by IT News in 2014 and 2018, and by the CEO Magazine in 2016 and 2018 (runner-up).

During this episode, William will identify and overcome the challenges you may face when building a quality security team. Learn the strategies for developing a cohesive cyber security team including his best advice for aspiring security team leaders.

Links:

  • LinkedIn
  • Twitter

Time Stamps:

  • 00:27 - William’s background and introduction
  • 03:44 - Developing a cohesive security team
  • 06:34 - Managing internal and external teams for success
  • 08:05 - The effectiveness of the security function prior to the shield program
  • 09:32 - Overcoming challenges in efforts to build a quality security team
  • 11:11 - “In the past, cybersecurity was about protecting technical infrastructure. Today, it’s people.” - William Confalonieri
  • 12:10 - Are boards expecting more from security teams?
  • 13:30 - Best advice for aspiring security team leaders
  • 14:19 - “Most of the problems are coming from the weakest link in the chain… our staff. Work on education, mainly.” - William Confalonieri

View Details

Justin Davies is the CIO at Ovato, Australasia's leading media, marketing, and printing company. Justin has over 30 years of professional experience in the Media and IT industry, holding a broad mix of functional skills including business management, consulting, sales, product, project office, and IT management.

During this episode, Justin will share how to get your network and security teams working together. Overcome common obstacles when building a security function and a secure way of doing business. Learn to find growth opportunities while understanding the different advantages of internal and external recruitment.

Links:

  • LinkedIn

Time Stamps:

  • 00:31 - Justin’s background and introduction
  • 06:00 - Bringing your network and security team together
  • 08:57 - “Although we can block things at the perimeter there is plenty that can still get in that looks legitimate.” - Justin Davies
  • 09:25 - Internal vs. external market network hires
  • 10:23 - “Just because you don’t have a budget to get those resources, it’s no excuse. You just need to find a way.” - Justin Davies
  • 10:36 - Observing your team to find the growth opportunity
  • 11:35 - “At the end of the day we are not a security company we’re a marketing services business. We are here to deliver marketing services to our customers but we have to do it in a secure manner.” - Justin Davies
  • 12:20 - Overcoming obstacles when building a security function
  • 13:51 - Best advice for aspiring security team leaders

View Details

Megan Haas is a former Cyber and Forensic Services Partner at PricewaterhouseCoopers (PwC) with over 30 years’ experience in Information Risk Management and Assurance and core competencies centered around Governance, Risk, Information Technology and Cyber Security.

After spending many years advising audit committees and specialising in business and Information Technology processes and controls, she turned her focus to increasing stakeholder confidence and governance of cyber security and privacy, anti-fraud and corruption risks, compliance and post-incident remediation. Her current board roles include RMIT University, Development Victoria and the Advisory Board of the University of Melbourne Academic Centre for Cyber Security Excellence.

During this episode, Megan will share insight into her 30+ years of experience working in the cyber security sector. Learn how organisations can retain long-term high caliber talent while attracting an appropriate level of gender diversity in the workplace. Find out ways board members can better understand security teams' roles and responsibilities.

Link:

  • LinkedIn

Time Stamps:

  • 00:31 - Megan Haas background and introduction
  • 06:01 - What was security teams like for clients around the world
  • 07:21 - Hiring principles to follow for building the proper team
  • 10:27 - Gender diversity in the workplace
  • 11:27 - “Those individuals doing the interviewing need to reflect the diversity of thinking.” - Megan Haas
  • 14:29 - How organisations can retain long-term high caliber talent
  • 16:23 - Understanding what security teams are doing as a board member
  • 16:49 - “There's been a real shift in understanding the concepts around cyber risk.” - Megan Haas
  • 18:56 - Advice to those inspired to run a security team
  • 20:04 - “Recognize the need for this ongoing technical competency but equally integrate and align the humanistic skills.” - Megan Haas

View Details

Dan Giesen-White is the Chief Information Officer at McMillan Shakespeare Limited, a trusted, market-leading provider of salary packaging, novated leasing, asset management, and related financial products and services. He has over 20 years’ experience in IT and 15 years’ strategic analysis and program management experience with a strong track record of leading change in IT and across the business.

During this episode, Dan will share how you can source the proper staff with the level of maturity your company needs to succeed. Find out what it means to build a security capability rather than just another team. Learn how ASIAL has helped lead his security team including the best advice for new security leaders.

Link:

  • LinkedIn

Time Stamps:

  • 00:30 - Dan Giesen-White’s background and introduction
  • 02:31 - How security is different from other tech areas of business
  • 03:39 - Build a security capability rather than a just team
  • 05:13 - Sourcing the proper staff for your company
  • 06:45 - Managing capability vs capacity
  • 07:41 - “Get the fundamentals right. That’s where people seem to struggle.” - Dan Giesen-White
  • 08:40 - Common challenges to overcome when building a security team
  • 09:50 - Addressing customer driving forces and concerns
  • 12:22 - How ASIAL has helped lead a security team
  • 13:25 - ASIAL helps me stay in front of mind and informed on how the landscape is changing.” - Dan Giesen-White
  • 15:31 - Best advice for new security leaders
  • 15:42 - “Be clear on what the role of security in your organisation is.” - Dan Giesen-White

View Details

Dan Maslin is the Head of Cyber Security for RACV, a key strategic role with accountability across several functions including strategy, architecture, operations, audit, compliance, risk, advisory and awareness & outreach, in a diverse and rapidly changing business. He has two decades of enterprise IT experience across various roles and industries in Australia and the UK, and holds the Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) and Certified Information Security Manager (CISM) security certifications.

During this episode, Dan will share the team management skills you need to lead and build your security team. Learn why your approach to hiring may be improved including a strategic diversity plan for new team hires. Find out how to strike a balance between your insource and outsource talent.

Links:

  • LinkedIn

Time Stamps:

  • 00:33 - Dan’s introduction and background
  • 03:26 - Should an architect be your first hire when building a security team?
  • 06:06 - Qualities and principles to look for when hiring for new roles
  • 06:21 - “We don’t want any ‘brilliant jerks’. We don’t need talented people that are going to come at a high cost of the team and organisation.” - Dan Maslin
  • 08:05 - How to Address the ‘skills gap’ or ‘skills crises’
  • 09:11 - Insource and outsource - The balanced solution
  • 10:44 - How diversity plays a role in new team hires
  • 13:03 - “Different skill sets, backgrounds, they all come together and play a part. It’s important to have a good mix.” - Dan Maslin
  • 13:13 - Overcoming challenges when sourcing for teams
  • 14:34 - “Poor people leadership can lead to poor retention and poor reputation in the industry.” - Dan Maslin
  • 16:40 - Long term advice for new CIO leadership

View Details

Cameron McLean is the Chief Information Officer at Yarra Valley Water, Melbourne's largest retail water utility, providing essential water and sanitation services to more than 1.8 million people. He developed his knowledge of and passion for Cyber Security during his time as CTO and General Manager of a credit card payments organisation, and this has stood him in good stead for the challenges facing his current industry.

During this episode, Cameron will share how to implement new strategies without disrupting your organisation. Learn from his hands-on experiences with security breaches and bring your security team together while fitting the needs of the leader and organisation. Find out ways to accept ongoing challenges for long term success and apply practical yet powerful advice as a new Cyber Security leader.

Links:

  • LinkedIn

Time Stamps:

  • 00:39 - Cameron’s background and introduction
  • 03:33 - Learning from hands-on experiences with security breaches
  • 04:30 - “Security is the number one issue for an organisation that relies on trust.” - Cameron McLean
  • 06:36 - Bringing your security team together while fitting the needs of the leader and organisation
  • 07:50 - Hiring your team internally vs external employments
  • 10:18 - Outsourcing working to a third party hire
  • 12:11 - Overcoming challenges when building a new security team
  • 12:32 - “The real challenge was gently but pointedly helping people understand that perhaps they didn’t know as much as they thought they did.” - Cameron McLean
  • 15:13 - Accepting ongoing challenges for long term success
  • 17:06 - Practical and powerful advice for new Cyber Security leaders
  • 17:35 - “Invest in yourself. Invest in your own learning.” - Cameron McLean

View Details

On the back of the success of season 1 of The Secure CIO Podcast, host Claire Pales presents a quick taste of season 2, and shares information on the upcoming LIVE recording of The Secure CIO Podcast! Hitting the road in Melbourne on 23rd October 2019.

Secure your tickets at thesecurecio.com.

View Details

Nick Ellsmore is Co-Founder of Hivint, now a part of Trustwave, an Optus company, and creator of cyber-security collaboration portal Security Colony. He was previously co-founder of SIFT and Stratsec, and has served on boards and forums including the Internet Industry Association, the NATA AAC for Software Testing, UNSW Advisory Boards, and the APEC TEL Security & Prosperity Steering Group.

During this episode, Nick will share the component to selecting employees who will fit well in your organization. Find out how great leaders create and share a positive vision and successful team atmosphere. Learn the benefits of focusing on diversity in the workplace and what it takes to become a great Security Leader.

Links:

  • LinkedIn
  • Securitycolony.com

Discussed:

    1. Security Sourcing: Cracking The Code with Craig Searle

Time Stamps:

  • 00:30 - Nick’s introduction and background
  • 04:19 - Principles to follow to bring the right people together
  • 06:26 - Hiring those who have a proper attitude yet lack the proper skills
  • 07:35 - “We don’t have a skills crisis so much as we have a roles crisis.” - Nick Ellsmore
  • 10:06 - Focusing on diversity in the workplace
  • 13:13 - What roles are clients looking for?
  • 17:15 - Building a function within the organization
  • 18:54 - “Your first security manager in an organization is going to shift the way that function is perceived by the organization.” - Nick Ellsmore
  • 20:00 - The ultimate path for security leaders
  • 25:29 - “If I am recruiting, the person that I want is the person who is clearly going to be passionate, do the right thing, and someone that’s a nice person.” - Nick Ellsmore
  • 27:33 - Giving the best advice to your younger self

View Details

Louise Smith is the Australian computer society director for workforce development and education. She is a business capabilities specialist with over 15 years of experience consulting to individual businesses and governments on the skill needs within their organization.

During this episode, Louise will discuss the SFIA Framework and its application to organizations. Find out how individuals can define their current skill set in the cybersecurity workforce. Learn if your organization can benefit from a variety of skills and experience amongst your team.

Links:

  • LinkedIn
  • Twitter

Time Stamps:

  • 00:32 - Louise introduction and background
  • 01:52 - The SFIA framework & how CIO’s can use it
  • 08:24 - SFIA's capability framework and assessment
  • 12:27 - What makes SFIA stand out from other frameworks?
  • 17:08 - Adjusting hiring practices to accommodate what's needed
  • 18:48 - “Truly understand the roles and define them effectively and consistently.” - Louise Smith
  • 22:12 - Successfully identifying skills of potential cyber security role
  • 27:27 - Do most teams have a specific set of diverse skills?
  • 31:34 - “There variation both in the depth and breath of the way in which skills are applied, adapted, and driven back into the business.“ - Louise Smith
  • 33:04 - “If you can refine and define your benchmarking it will ensure that you’re prepared for and supporting the depth and breath that you need across your workforce.” - Louise Smith
  • 34:00 - Skills you might need in the future - A self reflection

View Details

David Jorm is the Senior Manager at Commonwealth Bank, a business that offers a full range of financial services to help all Australians build and manage their finances.

David has been working in the tech industry for 20 years, with a focus on managing security teams for the last 7 years. His experience has spanned government, corporate, and startup environments in several countries.

During this episode, David will talk about the skills a CIO should be looking for if they want to advance a technical person into a leadership role. Learn the challenges of hiring and retaining staff including ways to building an effective team through diversity. Find out what you need to know about working with a third-party recruiter.

Links:

  • LinkedIn

Time Stamps:

  • 00:30 - David’s background and introduction
  • 03:06 - How the ‘skills crisis’ impacts vendors and in-house teams
  • 06:14 - Types of tasks and skills to outsource verse utilizing your team
  • 08:22 - The challenges of hiring and retaining staff
  • 10:40 - Building an effective team through diversity
  • 14:26 - “I can control the team culture and the way that we operate. It will attract people and candidates that other people wouldn’t get.” - David Jorm
  • 14:25 - The transition from a technical expert to becoming a leader
  • 18:18 - “You want to see evidence that they are acting in a senior capacity without having the title and the title or the pay rise follows.” - David Jorm
  • 19:59 - Using third-party recruiter when hiring new staff
  • 23:26 - David gives advice to his much younger self

View Details

Karen Worstell is the CEO of W Risk Group, a Denver based cybersecurity consultancy focused on helping companies demonstrate due diligence to a defensible standard of care. Karen has also been the CEO of AtomicTangerine, a Silicon Valley startup, and tenure as Chief Information Security Officer (CISO) at Microsoft Corporation, AT&T Wireless, and Russell Investments.

During this episode, Karen will share how leaders can build and cultivate a successful security team through her diversity and sourcing plans. Follow the discussed core principles when building and aligning your security team. Learn how the ‘skills crisis’ is effecting the hiring process and the impact the ‘Be an ally’ program has on the tech industry.

Links:

  • LinkedIn
  • FaceBook

Time Stamps:

  • 00:31 - Karen’s background and introduction
  • 04:30 - Why there are so few women in cyber security
  • 09:05 - “A personal resilience, level of confidence, and ability to do self-advocacy outside of a formal environment are very important to women for being able to advance their career.” - Karen Worstell
  • 11:18 - The role diversity plays in hire practices and sourcing plans
  • 12:57 - “We want to create an environment that’s welcoming for everyone.” - Karen Worstell
  • 15:01 - Core principle to follow when building and aligning security teams
  • 17:57 - “In order for us to be successful in the long term, we have to have people that are really good at change.” - Karen Worstell
  • 18:53 - Which roles you may want to our course verse in-house employees
  • 20:23 - How the ‘skills crisis’ affects the hiring process
  • 23:06 - The impact that ‘Be an ally’ has on the tech industry
  • 27:12 - Karens best advice to her younger self

View Details

Craig Templeton is CISO at REA Group Limited, a leading digital business specializing in property.

Craig brings over 23 years experience in the security field, having worked for a variety of blue-chip organizations globally including IBM, Deloitte and ANZ Bank. He sits on a number of Executive Board advisory committees, has association with research institutes in London, Canberra, Sydney and Melbourne and also participates in several cyber security start-up mentoring programs including CyRise.

During this episode, Craig will share how to attract and retain high caliber talent to your organization. Learn what skills are needed to run a small business and what type of tasks to outsource. Listen to the end for crucial advice for new startups in the industry.

Links:

  • LinkedIn
  • Rea-group.com

Time Stamps:

  • 00:31 - Craig's background and introduction
  • 04:11 - “You need to be resilient within yourself to withstand organizations and structural changes within businesses.” - Craig Templeton
  • 05:09 - Best hiring practices when building up a team
  • 09:26 - “By limiting yourself to somebody who has only ever worked in security you’re actually potentially sabotaging your own recruitment efforts.” - Craig Templeton
  • 09:41 - Skills or roles that should be within your business and what to leave for consultants
  • 12:08 - Attracting and retaining talent for internationally recognised organizations
  • 14:36 - Being affected by the supposed skills crises
  • 17:47 - Developing accountability outside your security team
  • 20:12 - “Experience is invaluable. You need to make mistakes to grow as a person.” - Craig Templeton
  • 20:38 - Advice to new startups in the industry

View Details

Caroline Wong is the Chief Security Strategist at Cobalt.io, a PTaaS platform that transforms yesterday's broken pen test model into a data-driven vulnerability management engine.

Caroline is a dynamic cybersecurity expert with more than a decade of industry experience as a day-to-day manager at eBay and Zynga, product manager at Symantec, and managing consultant at Cigital (now Synopsys). She also holds positions on multiple industry advisory boards, including the North American Advisory Council for ISC2 and the RSA Conference Advisory Board.

During this episode, Caroline will share how to transition from managing yourself to managing others. Learn to become a great security leader and encourage others to grow and lead. Match potential candidates with jobs that need to be filled, work with remote teams, and address compensation expectations.

Links:

  • Cobalt.io
  • LinkedIn
  • Twitter

Time Stamps:

  • 00:29 - Caroline background and introduction
  • 04:08 - Will the skills crisis impact security teams and vendors?
  • 06:37 - Supplementing your in-house security team and possible outsourcing options
  • 10:21 - Do you really need a core security team?
  • 12:44 - Overcoming dev sec ops movement challenges
  • 16:18 - Transitioning into a great leader and encouraging others to grow
  • 19:10 - “A great leader lays out that path to allow that person to grow.” - Caroline Wong
  • 19:51 - Transitioning from a maker to a manager
  • 23:30 - “In order to be whatever you’re going to be tomorrow you have to let go of who you are today.” - Caroline Wong
  • 24:03 - Matching potential candidates with jobs that need to be filled
  • 25:30 - "Hiring managers often find themselves in a position where they may frankly struggle to write a job description because they are trying to figure out what should this person do?" - Caroline Wong
  • 30:38 - Working with remote teams + compensation expectations

View Details

Darren Argyle is the co-founder of Cyber Resilience which delivers executive cyber leadership programs to support the next generation of cyber leaders and emerging CISO’s.

Darren is an accomplished executive with close to 20 years of international cyber risk and security experience and broad expertise in providing hands-on leadership, strategic C-level/board direction and program execution. He was named in the top 100 Chief Information Security Officers globally in 2017 and the top 100 Global IT Security Influencers in 2018.

During this episode, Darren will share how to navigate the global skills crisis in search of highly experienced and well-rounded security team members. Learn when to utilize an outsourced model and when to work with permanent in-house hires. Listen for ways to overcome the biggest challenges in the cybersecurity space including his major lessons learned over his career.

Links:

  • Cyberresilience.com.au
  • Uk.linkedin.com/in/darrenargyle
  • Twitter.com/d_argyle

Time Stamps:

  • 00:32 - Darren’s introduction and background
  • 05:13 - Analyzing the scope of security teams
  • 13:29 - Prioritizing the type of team you must hire
  • 14:44 - “The first role I would always employ is an enterprise security architect who thinks about business first and technology second.” - Darren Argyle
  • 16:39 - Utilizing the outsourced model versus permanent hires
  • 18:13 - “Anything that can be automated or highly specialized such as major breach response you could certainly outsource.” - Darren Argyle
  • 18:33 - Overcoming common hurdles when sourcing for the right people for your team
  • 21:38 - Navigating the global skills crisis
  • 24:48 - Searching for highly experienced & well-rounded team members
  • 29:53 - The role diversity plans in the hiring and sourcing plans
  • 30:39 - “For a senior leader to be successful: Recognize diversity.” - Darren Argyle
  • 34:51 - Sharing your successes and most importantly, your failures

View Details

Michelle Price is the CEO at Aust Cyber, a company that supports the development of a vibrant and globally competitive cyber security sector.

Before joining AustCyber, Michelle was the first Senior Adviser for Cyber Security at the National Security College within The Australian National University. In this role, she established an integrated approach to the College’s cyber security program across executive and postgraduate education and policy engagement.

During this episode, Michelle will discuss the skills and qualities that employers must look for in security staff in order to build a truly successful team. Listen as she encourages others to increase diversity in the cyber security workforce and continue to inspire people with the possibilities of cyber innovation.

Links:

  • Linkedin
  • Twitter

AustCyber:

  • Austcyber.com
  • Linkedin
  • Twitter

Time Stamps:

  • 00:30 - Michelle’s background and introduction
  • 02:36 - Overcoming the challenges of hiring staff into cyber roles
  • 03:20 - “Nine times out of ten I was actually hiring for attitude.” - Michelle Price
  • 08:49 - Addressing the skills gap with a university course
  • 13:03 - Preparing for the demands on the future of the cyber workforce
  • 16:07 - The role diversity plays in the hiring process
  • 18:16 - “Diversity in ethnicity, diversity in age is just as important as diversity in gender. It’s all about diversity of thinking.” - Michelle Price
  • 21:23 - The future of startups and consultancies offering contract work
  • 26:47 - Key lessoned learned around building teams
  • 27:14 - “It’s just so hard to teach attitude. You can shape attitude but you really can’t necessarily fundamentally change the underlying attitude of someone.” - Michelle Price
  • 30:20 - Michelle’s advice to her younger self

View Details

Jo McCatty is a recruitment leader with expertise across different sectors serving the UK, EU and APAC markets. Her key interest is driving success and delivery of outcomes through people, technology and change/transformation (aka ambiguity).

Jo also has an interest in working on Complex People Projects , and she is passionate about Candidate Attraction , Engagement & Management, Acquisition as well as Coaching. Currently working onsite with ANZ in their NICHE Sourcing squad, Jo is working to attract engineering talent into the business during an exciting time of change in the world of Technology.

During this episode, Jo will share how to overcome the top challenges when hiring staff in cybersecurity including ways to build and grow your team. Learn the role diversity plays in your hiring and sourcing plans. Find out how leaders and employees should harness the power of mentorship for long term success.

Links:

  • Linkedin.com/in/joannamccatty
  • Instagram.com/2_careercoach_u/

Time Stamps:

  • 00:28 - Jo’s background and introduction
  • 03:09 - Overcoming the top challenges when hiring staff in cybersecurity
  • 04:52 - Taking recruitment on as a project
  • 05:52 - Transferring skills from other industry sectors
  • 05:59 - What recruiters can do to fill cyber-security roles
  • 08:13 - Setting the candidate up for success
  • 08:55 - Do industries experience a skills gap?
  • 09:20 - “The skills crisis comes about because everyone is trying to hire the same thing at the same time.” - Jo McCatty
  • 10:07 - The role diversity plays in your hiring and sourcing plans
  • 12:11 - Reaching success + the power of mentorships
  • 13:33 - “I have a coach for life because you can always step up, level up, and improve.” - Jo McCatty
  • 15:10 - Internal coaching and mentoring services
  • 15:58 - The fact and fiction of the recruitment industry + building a team
  • 18:18 - "Looking at the team dynamic and making sure you're hiring to complement it." -Jo McCatty
  • 18:41 - “Huge consideration is looking at development areas and strengths for every individual you’re bringing into the business verse what already exist in the business.” - Jo McCatty
  • 20:27 - Advice to your younger and less experienced self
  • 20:39 - "[Don't] rush with the haste of the business to hire the talent". - Jo McCatty

View Details

Craig Searle is the co-founder of Australian cybersecurity consultancy, Hivint, and the security collaboration platform, Security Colony – both of which were acquired by Trustwave, an Optus company, in December 2018.

Craig has over 12 years of experience in the security industry, working in the finance, government, telecommunications and infrastructure sectors. He has been directly responsible for the delivery of a number of strategically-critical security programs for a range of clients, including a $10m PCI DSS compliance program for one of Australia’s leading health insurers, achieving compliance on-time and on budget.

During this episode, Craig offers a unique perspective on the shortage of talent in the cybersecurity industry and ways to create a proper solution. Find out if we are losing potential in house professionals to cybersecurity startups. Learn the best practices for new hire onboarding and enable your team to succeed long term.

Links:

  • Linkedin.com/in/craigsearleinfosec
  • Hivint.com
  • Securitycolony.com
  • Trustwave.com

Time Stamps:

  • 00:32 - Craig’s background and introduction
  • 02:45 - Transitioning from a technical to a leadership role
  • 06:39 - Attracting the proper work talent to your business
  • 08:07- “One of our big beliefs is that good people attract more good people.” - Craig Searle
  • 11:54 - The role diversity plans in the hiring and sourcing plan
  • 12:19 - “Diversity is an outcome of having a successful hiring and talent acquisition process.” - Craig Searle
  • 18:01 - Analyzing the ‘skills crisis’ and creating a proper solution
  • 19:08 - “We need to do better at looking at the outcome we want and find the right person for that outcome. Pay less attention to the university they went to or the certification they hold.” - Craig Searle
  • 20:13 - Are we losing potential in house professional to Cybersecurity startups?
  • 22:44 - Enabling a team to succeed long term
  • 23:57 - Overcoming obstacles when sourcing & best practices for new team hires
  • 28:19 - Wise and valuable words to tell your younger self

View Details

Samm MacLeod is the CISO at AGL, Australia's leading energy company offering electricity, gas, solar and renewable energy services to homes and businesses.

Samantha is an accomplished professional with more than 20 years’ experience supporting business strategies through technology enablement, risk management, security, and governance. In her role as CISO at AGL, Samantha is accountable for aligning Cybersecurity strategy with business strategic initiatives and integrating security practices across the organization.

During this episode, Samantha will bring light to the obstacles you may face when sourcing for security teams. Listen for her suggested immediate hiring needs and why you should strategically create employee longevity. Find out if the cybersecurity talent gap is really an industry crisis and how encouraging a diverse team of talented professionals may be the solution to a successful team.

Links:

  • Linkedin.com/in/samanthamacleod

Time Stamps:

  • 00:32 - Samantha’s background, introduction, and journey to CISO
  • 03:20 - Immediate hiring needs for a new security team
  • 07:36 - Roles that must be outsourced or can be done in house
  • 09:59 - Is there a lack of skill crisis?
  • 10:24 - “I don’t think you need 25 years experience to make a difference in a security team” - Samantha MacLeod
  • 15:41 - Are we losing in-house security professionals to micro business?
  • 16:18 - “Step out of that mold and challenge the industry and status quo” - Samantha MacLeod
  • 18:25 - Why women aren’t prevalent in this industry
  • 22:07 - The role that diversity plays on a security team of professionals
  • 24:51 - Overcoming obstacles when sourcing for teams
  • 26:14 - “The hardest thing is finding the time to find the talent” - Samantha MacLeod
  • 28:29 - Key lessons learned around cybersecurity teams

View Details

Jonathan Werrett is the head of information security at FitBit and prior to that, he ran product security at Palantir. Jonathan has spent the last decade building infosec teams and maturing security operations. His roles have spanned security engineering in Silicon Valley, pentesting in APAC, and devops/SRE in Europe.

During this episode, Jonathan will share core principles to follow when hiring and building a team in information security. Learn to find ideal leadership even when the talent pool is subpar and explore the importance diversity plays in the hiring process. Listen to the end to hear some of Jonathan's hardest lessons learned during his 15+ years in the industry.

Links:

  • Linkedin.com/in/werrett
  • Twitter.com/werrett

Time Stamps:

  • 00:27 - Jonathan’s background and introduction
  • 02:12 - Principles to follow when hiring a new team
  • 02:39 - “The team should reflect the risks that your particular organization faces” - Jonathan Werrett
  • 03:28 - Security teams role in proper context
  • 08:55 - Building and hiring a team in information security
  • 13:22 - Skills and roles that can be outsourced
  • 14:02 - “You don’t need a full-time red team even if your multinational” - Jonathan Werrett
  • 16:22 - The importance of diversity plays a role in the hiring process
  • 16:45 - “More diverse teams come up with better solutions over time” - Jonathan Werrett
  • 18:16 - Finding ideal leadership even when the talent pool is subpar
  • 23:55 - Hardest lessons learned in this industry