Identient: Recent Episodes

None

View Details

SPI 360: A Strategic System for Realizing Cybersecurity Value* Steve Tout * June 4, 2025 In today’s high-pressure landscape, cybersecurity leaders face a familiar but dangerous trap: strong technical execution in a system that’s misaligned, under-resourced, or strategically adrift. Tools improve. Teams hustle. But outcomes remain murky—and value, elusive.

That’s where SPI 360 comes in.
It’s not just a framework. It’s a leadership system—built to help CISOs, CIOs, and executive teams lead with clarity, measure what matters, and deliver measurable business impact from cybersecurity.

Related Resources

  • Blog
  • Strategy Layer Live
  • Solution Guides
  • Book: The CISO On The Razor’s Edge
  • SPI 360 Executive Circle (On Slack) Align Cybersecurity with StrategyMany organizations have a cybersecurity program. Few have a strategic one. SPI 360 starts by forcing a moment of truth: is your mission clear? Do your priorities ladder up to enterprise outcomes? Are your investments justifiable—outside the security echo chamber?

The Strategy quadrant helps leaders move from “security-first” to business-aligned. It clarifies mission, defines priorities, and supports investment decisions grounded in value—not fear.

Enforce Governance That Builds ConfidenceBoards don’t lose sleep over controls—they lose sleep over accountability gaps. SPI 360’s Governance lens enables leaders to define clear decision rights, implement performance oversight, and create systems of trust—not just policy enforcement.

This isn’t checkbox compliance. It’s executive-grade governance that scales across change, audit, and risk environments—and tells a coherent story when it matters most.

Align Systems to OutcomesToo often, technology leads. Strategy follows—or worse, gets ignored. SPI 360’s Technology dimension brings leadership back into the loop. It links tech capabilities to strategic goals, identifies friction in execution, and pinpoints where investment is producing returns—or creating drag.

It enables a shift from tool sprawl to tech precision—so your systems help you execute, not just exist.

Build Teams That Can DeliverAt the core of SPI 360 is a hard truth: you don’t secure systems—you lead people. The People & Culture domain evaluates structure, clarity, trust, and burnout. It shows where leadership needs to show up—and where fragmentation and fatigue are costing you effectiveness.

Because no security strategy is stronger than the team implementing it.

The Outcome: Value RealizationAt the edge of every initiative, executive teams are asking: What’s the value?
SPI 360 answers with a repeatable, measurable system:

Assess. Measure. Improve. Report.

It connects strategy to operations. Technology to trust. Risk to decisions.
And ultimately, cybersecurity to value.

Let us show you how SPI 360 can help you align cybersecurity strategy, strengthen leadership, and realize measurable value.

Your leadership operating system starts here.

Like it? Share it with your network!

Download Infographic Recent Posts CISO Transformation: It’s Time for a New Mental Model April 3, 2025 Read More Beyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Performance Intelligence March 2, 2025 Read More Transform IAM From Technology Burden To Business Advantage December 8, 2024 Read More The post A Strategic System for Realizing Cybersecurity Value first appeared on Identient.

View Details

CISOs aren’t being eliminated — but they are being quietly redefined, compressed, and sidelined.

The post Co-Morbid Poisoning of the CISO Role first appeared on Identient.

View Details

CISO Transformation: It’s Time for a New Mental ModelCISO Transformation: It’s Time for a New Mental Model Steve Tout * April 3, 2025 * 6 minutes Executive Summary:*

CISO mind maps are a helpful tool for illustrating the complex, cross-functional nature of the role. But as security leaders face growing pressure to demonstrate business value, influence executive priorities, and justify investment, a tactical map alone no longer cuts it. This article introduces a new mental model—Strategic Performance Intelligence (SPI 360)—designed to help next-gen CISOs lead with clarity, impact, and board-level relevance.

Table of ContentsRethinking the CISO RoleEach year, respected industry leaders publish updated mind maps to help CISOs visualize the scope of their responsibilities. These visuals serve as valuable references for onboarding, program planning, and illustrating the multifaceted nature of security leadership. The 2025 CISO MindMap includes timely updates like securing GenAI, managing security debt, and creating more meaningful metrics.

These updates reflect how fast the landscape is changing—but the underlying mental model remains largely the same:

Add more responsibilities. Catalog more controls. Manage more complexity.

That’s not enough anymore.

Today’s security leaders are expected to go beyond managing risk—they’re expected to deliver results that matter to the business.

Why a Map Isn’t Enough AnymoreMind maps are helpful. But they’re not designed to help CISOs:

  • Prioritize what matters most right now
  • Track strategy-to-execution performance
  • Align security initiatives to business outcomes
  • Communicate clearly with boards and executives

They’re descriptive, not directional.
They show everything, but they don’t tell you what’s working, what’s wasteful, or what’s driving results.

CISOs need more than a map.
They need a compass.

Traditional vs. Modern CISO ThinkingHere’s how the traditional checklist mindset stacks up against a more strategic approach grounded in Strategic Performance Intelligence (SPI 360):

| Dimension | Traditional CISO MindMap Approach | SPI 360 (Next-Gen CISO) | | --- | --- | --- | | Core Focus | Responsibilities & Controls | Strategy, Value, Outcomes | | Reporting Style | Technical, Compliance-Oriented | Business-Aligned, Outcome-Oriented | | Engagement Model | Reactive & Role-Based | Proactive & Portfolio-Based | | Stakeholder Management | Implied Governance | Structured Influence & Alignment | | Financial Discipline | Budget Tracking | ROI, Cost-to-Value, Justification | | Tooling Philosophy | Static, One-Size-Fits-All | Adaptive, Contextual, Metrics-Driven |

Where Traditional Models Fall Short (and SPI 360 Delivers)No Board Reporting View

Mind maps don’t help CISOs walk into the boardroom and clearly demonstrate what’s working, where risk is rising, or how cybersecurity investments are delivering value.

SPI 360 produces board-ready dashboards that speak the language of business value, ROI, and strategic alignment.

No Strategy-to-Execution Engine

There’s no way to see whether you’re making progress toward your goals, or just adding more effort.

SPI 360 measures the maturity and performance of your security program across four strategic pillars: Strategy, Governance, People, and Technology.

No Financial Storytelling

While the 2025 MindMap recommends “creating meaningful metrics,” it lacks a way to quantify impact.

SPI 360 helps CISOs demonstrate how security initiatives reduce risk, improve operational efficiency, and drive measurable business value.

Validation from the IndustryThe 2025 edition of the MindMap includes a recommendation to focus on meaningful metrics—like risk reduction and program performance.
That aligns perfectly with SPI 360’s approach.

According to Gartner, only 23% of CISOs say their current metrics are useful for decision-making. That’s a major credibility gap—and an opportunity for transformation.

A Better Way ForwardTo be clear, mind maps like this one are useful—they help CISOs communicate their scope and educate stakeholders. But they don’t help prioritize, don’t track outcomes, and don’t show the ROI of cybersecurity investments.

SPI 360 is built to do exactly that. It helps CISOs:

  • Turn assessments into board-ready insights
  • Track progress toward strategic goals
  • Engage stakeholders with influence, not just information
  • Quantify the business value of cybersecurity

From Static Map to Strategic CompassCISOs don’t need more controls to manage.
They need a better way to manage what matters.

Mind maps describe the territory.
SPI 360 helps you choose the right path—based on where your business needs to go next.

Ready to Lead with Strategic Intelligence?If you’re a security leader looking to move from tactical execution to strategic influence, it’s time to shift your mental model.

Request a demo or join the SPI 360 waitlist to see how Strategic Performance Intelligence can elevate your cybersecurity leadership.

Recent Posts A Strategic System for Realizing Cybersecurity Value June 4, 2025 Read More Beyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Performance Intelligence March 2, 2025 Read More Transform IAM From Technology Burden To Business Advantage December 8, 2024 Read More The post CISO Transformation: It’s Time for a New Mental Model first appeared on Identient.

View Details

Candid CISO Season 2 dives into the evolving role of security leaders—navigating AI, boardroom battles, burnout, and business impact. Unfiltered insights, sharp humor, and real talk for CISOs charting their path in 2025’s high-stakes landscape.

The post Candid CISO Podcast first appeared on Identient.

View Details

The Strategy Layer Live is an audio project by Tout Media that helps CISOs and cybersecurity leaders rise above operational noise to drive business value through smarter strategy, better alignment, and leadership that lasts.

The post The Strategy Layer Live first appeared on Identient.

View Details

The CISO Playbook provides a strategic guide to evaluating the SPI framework, enabling CISOs to align cybersecurity initiatives with business objectives, measure true ROI, and confidently communicate cybersecurity's strategic value to stakeholders and boards through AI-powered analysis and financial discipline.

The post CISO Playbook first appeared on Identient.

View Details

SPI 360 bridges cybersecurity strategy and execution by automating performance tracking, accountability, and business impact measurement. It moves beyond static assessments, delivering real-time intelligence that enhances decision-making, optimizes investments, and aligns cybersecurity with financial and operational goals.

The post Solution Guide: The Business Case for Strategic Performance Intelligence first appeared on Identient.

View Details

Beyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Performance IntelligenceBeyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Intelligence Steve Tout * March 2, 2025 * 6 minutes Executive Summary: Compliance alone won’t protect your business. As AI reshapes industries, CIOs and CISOs must adopt AI-driven Strategic Performance Intelligence (SPI) to move beyond check-the-box security. This post explores how real-time governance, risk visibility, and business-aligned cybersecurity leadership* are now essential for resilience—and why SPI 360 is the key to staying ahead.

Table of ContentsAI Is Reshaping Business—Are You Keeping Up?AI is no longer a future trend—it’s the present reality.

98% of executives plan to increase AI investments by 2025, according to a recent survey. AI-driven decision intelligence is already transforming finance, supply chain, and customer experience, enabling businesses to move faster and smarter.

Yet, when it comes to cybersecurity and identity governance, many organizations are stuck in outdated, manual processes.

Take identity and access management (IAM), for example. 50% of IT leaders say slow identity processes impact business growth, according to Gartner. Security teams spend weeks or months provisioning access, managing policies, and responding to audits—slowing down innovation and leaving organizations vulnerable.

This disconnect is a ticking time bomb.

While CFOs have AI-powered financial forecasting and CMOs leverage AI-driven customer insights, CIOs and CISOs are still relying on compliance checklists and static dashboards to measure security performance.

That’s no longer good enough. Boards, regulators, and investors are demanding more.

It’s time to move beyond compliance and adopt AI-driven Strategic Performance Intelligence (SPI) to lead cybersecurity governance into the next era.

Regulators and Boards Are Raising the BarCybersecurity is now a business risk issue—not just a technical one.

Regulators and boards are no longer satisfied with compliance reports and one-off audits. They expect real-time, continuous assurance that security and governance programs are actively reducing risk.

Consider these shifts:

  • The SEC’s new cyber disclosure rules require evidence of cybersecurity governance effectiveness—not just policies.
  • NIST’s updated Cybersecurity Framework (CSF 2.0) now emphasizes continuous monitoring and business alignment instead of static risk assessments.
  • CISA’s Secure by Design guidelines and EU regulations (DORA, NIS2, AI Act) are pushing for governance as a proactive, ongoing discipline.

The takeaway? Compliance is no longer a checkbox—it’s an ongoing expectation.

If your cybersecurity program can’t prove its effectiveness in real-time, you risk regulatory scrutiny, investor concerns, and executive frustration.

This is exactly why SPI is critical.

AI-Driven Intelligence: The Next Evolution of Cybersecurity LeadershipFor years, security and IT leaders have relied on lagging indicators to make decisions—compliance reports, security audits, and dashboards that show what happened weeks or months ago.

Meanwhile, attackers and market disruptions move in real time.

That’s why AI-driven, multi-agent intelligence is the only way forward.

  • SPI 360 continuously analyzes security performance, governance effectiveness, and team health.
  • Instead of static reports, it provides real-time, prescriptive insights that tell you where to focus, what to fix, and how to improve security posture.
  • It connects cybersecurity governance to business outcomes—giving CIOs and CISOs the same strategic visibility that CFOs have over financial performance.

This isn’t just a dashboard upgrade—it’s a structural shift in cybersecurity leadership.

SPI isn’t another security tool—it’s a fit-and-finished framework for governance, inspired by McKinsey’s 7S model and the Balanced Scorecard. It ensures security leadership is measurable, actionable, and aligned with business resilience.

This is how the best CIOs and CISOs will lead in the AI era.

The Hidden Risk: When Compliance Creates Blind SpotsIn a recent interview with a cybersecurity leader of a public company I witnessed this challenge head on, and what he shared was not surprising.

His team wasn’t ahead of threats—they were constantly in firefighting mode. The focus was on technology, not governance, and trust between cybersecurity, IT, engineering, and GRC was shaky at best.

Even worse? Critical security controls had gaps.

This wasn’t a startup operating on a shoestring budget—this was a publicly traded company. One that regulators, investors, and customers assumed had its security act together.

But in reality? They were one breach away from disaster.

This is what happens when security leadership is reactive instead of strategic. When governance is treated as an afterthought, and when cybersecurity teams operate in silos instead of aligning with business priorities.

This is exactly why SPI is essential. It’s the only way to break out of reactive mode, rebuild trust across teams, and continuously measure governance effectiveness—before a crisis forces the issue.

SPI solves this problem.

It enables CIOs and CISOs to see beyond compliance and measure what actually matters:

  • How well is our security program reducing real-world risk?
  • Where are governance gaps that could expose us to financial or operational risk?
  • Are our security investments actually improving resilience—or just maintaining compliance?

Without real-time, AI-driven visibility, security leaders are making high-stakes decisions in the dark.

CIOs & CISOs Must Measure Security’s Business ImpactSecurity teams still struggle to get executive and board-level buy-in—because cybersecurity is seen as a cost center, not a business enabler.

That changes with SPI

  • CFOs can forecast financial risk. SPI enables CISOs to quantify cyber risk.
  • Sales leaders can track revenue impact. SPI enables CIOs to track security’s impact on operational efficiency.
  • Executives want cybersecurity investments to drive resilience, not just meet regulatory requirements. SPI connects security to business growth.

Boards don’t want to see a list of security controls—they want to understand:

How does IAM maturity impact business continuity?
How do security operations bottlenecks affect time to market?
Are governance gaps creating financial exposure?

SPI 360 transforms cybersecurity governance from a reactive function into a strategic advantage.

Beyond Compliance: The Future of Cybersecurity LeadershipThe best CIOs and CISOs aren’t waiting for regulators to push them into AI-driven governance. They are proactively adopting SPI to:

Build real-time security oversight that meets board expectations.
Measure governance effectiveness continuously—not just at audit time.
Turn cybersecurity into a strategic business enabler.

The future of cybersecurity leadership is:

AI-driven, continuous, and measurable.
Governance without intelligence is a liability.
Compliance won’t save you—Strategic Intelligence will.

We’re at a crossroads. Will you lead this shift, or fall behind?

Download the Solution Guide & Take ActionCIOs and CISOs who adopt AI-driven Strategic Performance Intelligence today will be tomorrow’s security leaders.

Download our latest Solution Guide: The Business Case for Strategic Performance Intelligence to learn how SPI 360 can help you:

Move beyond compliance into continuous, real-time security governance.
Measure the business impact of security investments.
Align cybersecurity, risk, and business resilience with AI-driven insights.

The next era of cybersecurity leadership has arrived. Are you ready?

Steve ToutSteve Tout is the founder of Identient, where he transforms IAM into a business-first, strategic powerhouse. When he’s not pioneering new approaches to IAM, you’ll find him training for ultramarathons or chasing his next big idea. Recent Posts A Strategic System for Realizing Cybersecurity Value June 4, 2025 Read More CISO Transformation: It’s Time for a New Mental Model April 3, 2025 Read More Transform IAM From Technology Burden To Business Advantage December 8, 2024 Read More The post Beyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Performance Intelligence first appeared on Identient.

View Details

Metrics don’t just measure performance—they shape it; used carelessly, they can destroy it.

The post Metrics as Loaded Weapons: Secrets from a 7x CIO first appeared on Identient.

View Details

Transform IAM From Technology Burden To Business AdvantageTransform IAM From Technology Burden To Business Advantage Steve Tout * December 8, 2024 * 6 minutes Executive Summary:* This blog post challenges the conventional approach to IAM, emphasizing a holistic strategy to unlock its full potential. By adopting the Sentient IAM framework, organizations can balance governance, people, and technology to drive agility, reduce risk, and deliver measurable business value. It’s a reminder that true transformation comes from aligning IAM initiatives with business goals, turning identity into a competitive advantage rather than a constraint.

Table of ContentsThe next wave of digital transformation has most enterprises racing to strengthen their IAM capabilities. Yet despite pouring millions into IAM technologies, many organizations find themselves facing an uncomfortable truth: their IAM programs have become more of a burden than a business enabler.

Look closer at most enterprise IAM implementations and you’ll find a common pattern. Multiple IAM solutions that don’t talk to each other. Mounting maintenance costs. Implementation timelines that seem to stretch endlessly. And perhaps most frustrating – all this complexity is actually slowing down the business initiatives IAM was meant to enable.

But there’s a bright spot in this story. A growing number of forward-thinking organizations are discovering a different path. Instead of leading with technology, they’re approaching IAM as a strategic business initiative first. The early indicators are compelling: faster digital transformation, reduced risk, and clear business value. These organizations aren’t just managing IAM better – they’re positioning it as a competitive advantage.

The key lies in transforming how we think about IAM. The Sentient IAM framework introduces a fundamentally new approach, shifting focus from technology alone to a balanced view across strategy, governance, people & culture, and technology. This isn’t just a minor adjustment – it represents a transformation in how enterprises can think about and deliver IAM.

The Hidden Cost of ‘Good Enough’ IAMThink your IAM program is doing its job? Look again. While your current IAM solutions might be checking the basic boxes for security and compliance, they’re likely creating invisible barriers to business growth. Most enterprises today are living with IAM programs that are simultaneously over-engineered and under-delivering.

The real costs show up in unexpected places:

  • Digital initiatives that stall because identity processes can’t keep up
  • Innovation teams waiting weeks for access to critical systems
  • Security teams drowning in access reviews that don’t actually reduce risk
  • Technology costs that keep climbing while agility keeps falling
  • Valuable IT talent spent maintaining systems instead of driving value

But the more serious cost? Opportunity loss. In today’s digital economy, speed and agility aren’t just nice-to-haves – they’re survival skills. When your IAM program becomes a bottleneck rather than an enabler, you’re not just losing efficiency. You’re losing competitive edge.

This is where the traditional technology-first approach to IAM reveals its limitations. Adding more IAM tools or upgrading existing ones won’t solve these fundamental challenges. The solution requires a completely different mindset.

Reimagining IAM for Business ValueThe most successful business transformations often begin with a simple question: what if? What if IAM could accelerate your business rather than slow it down? What if it could become a catalyst for growth rather than a necessary cost? What if your IAM strategy could actually drive competitive advantage?

Forward-thinking executives are starting to ask these questions, and for good reason. In a digital-first world, identity isn’t just about security anymore – it’s about business enablement. It’s about how quickly you can onboard new partners, how seamlessly you can integrate acquisitions, how effectively you can launch new digital services, and how confidently you can enter new markets.

This shift in thinking changes everything:

  • Instead of treating IAM as a technology project, view it as a business transformation initiative
  • Rather than measuring success by systems implemented, focus on business value delivered
  • Move from reactive compliance to proactive business enablement
  • Transform IAM from a cost center into a strategic investment

The Sentient IAM framework is built on this fundamental reimagining of what IAM can be. By balancing strategy, governance, people & culture, and technology, organizations can begin to unlock the hidden potential in their IAM investments. It’s not about replacing what you have – it’s about transforming how you think about, implement, and measure IAM success.

Measuring What MattersWhen it comes to IAM, we’ve been measuring the wrong things. Server uptime, password resets, and access certification completions tell us how our systems are performing – but they say nothing about business impact. It’s like measuring a digital transformation by how many cloud servers you’ve deployed.

The conversation in the boardroom isn’t about identity systems – it’s about business velocity, risk reduction, and value creation. This disconnect between technical metrics and business outcomes has made IAM success invisible to executive leadership, and business impact impossible to quantify.

The future of IAM demands a new calculus. One that connects identity directly to business performance:

  • How is IAM accelerating (or hindering) your key digital initiatives?
  • Where are identity bottlenecks creating business friction?
  • Which investments are delivering measurable business returns?
  • How effectively is your program reducing operational risk?

The Sentient IAM 360 Platform introduces a new generation of business-aligned metrics and leading indicators that bring IAM into the boardroom conversation. By providing early visibility into potential challenges and clear alignment with business objectives, organizations can spot issues before they impact projects and ensure IAM investments deliver measurable value.

From Insight to Action: Your Next 90 DaysThe gap between where IAM is today and where it needs to be represents more than just a technology challenge – it represents an unprecedented opportunity. Forward-thinking executives who seize this moment to reimagine their IAM strategy will unlock not just operational efficiency, but genuine competitive advantage.

We stand at the threshold of a new era in IAM excellence. One where identity drives business value instead of hindering it. Where IAM investments deliver measurable returns instead of mounting costs. Where your identity strategy accelerates transformation instead of slowing it down.

The path forward is clear. It begins with shifting perspective from technology-first to business-first thinking. It continues with adopting frameworks that balance strategy, governance, people, and technology. And it succeeds through measuring what truly matters to your business.

The Sentient IAM 360 Platform is designed to guide you on this journey. As we prepare for launch, we’re inviting forward-thinking organizations to join our early access program. You’ll be among the first to:

  • Shape the future of strategic IAM
  • Access transformative frameworks and metrics
  • Join a community of innovative business leaders
  • Turn your IAM program into a competitive advantage

Ready to lead in this new era of IAM excellence?

Take the first step in your transformation journey. Connect with our team for a business value assessment, or join our platform waitlist to be among the first to access these revolutionary capabilities.

Steve ToutSteve Tout is the founder of Identient, where he transforms IAM into a business-first, strategic powerhouse. When he’s not pioneering new approaches to IAM, you’ll find him training for ultramarathons or chasing his next big idea. Recent Posts A Strategic System for Realizing Cybersecurity Value June 4, 2025 Read More CISO Transformation: It’s Time for a New Mental Model April 3, 2025 Read More Beyond Compliance: Why CIOs & CISOs Must Lead with AI-Driven Strategic Performance Intelligence March 2, 2025 Read More The post Transform IAM From Technology Burden To Business Advantage first appeared on Identient.

View Details

My life with books


I read 20-30 books each year in prep for my podcast or as a required text for school. When I find a book I like, I usually pick up a print copy, the Kindle version, and often, the Audible version to give myself as much opportunity to absorb new information and insights as possible. Obsession with books has become such a thing in my household that my daughter competes with me on who can build the biggest and most curated library. But I digress…

I came across some real gems this year and wanted to share them here.

I recently picked this book up for light reading during my winter break from classes at Santa Clara University. The Practice by Seth Godin is a motivational guide that empowers readers to unleash their creativity and succeed by committing to consistent, purposeful work rather than waiting for perfect ideas and inspiration. From getting into a flow state and finding your voice to overcoming imposter syndrome, this book will inspire you to engage in consistent practice and become more comfortable with getting shit done and shipping your best creative work.

Buy on Amazon

Tom Kemp‘s book Containing Big Tech is a seminal reference on how data brokers and big tech companies misuse our most sensitive data, how AI is being exploited, and the abuse of our privacy. Kemp argues that big tech companies like Meta, Apple, Amazon, Microsoft, and Google, despite creating valuable products, pose threats to our civil rights, economy, and democracy due to their intrusive data collection practices. The book is well-researched and provides executives and policymakers valuable insights on emerging privacy regulations in California. It launched as a Bestseller and #1 New Release on Amazon and is a must-read for anyone interested in privacy and freedoms in the digital age. I was fortunate to be able to write an endorsement for the book and produce an event for Tom on The State of US Privacy and AI to celebrate the book launch.

You can watch on-demand and buy the book here:

Webinar: The State of US Privacy and AI

Buy on Amazon

Kat Holmes is Chief Design Officer and EVP at Salesforce, entrepreneur, and leading expert in inclusive design who has written an excellent book on user-centered design called Mismatch, How Inclusion Shapes Design. What makes the book great is that it’s accessible and written in plain language and shows how inclusion should be viewed as a source of innovation and growth, not as a tax on an organization’s revenue. Economically speaking, Kat explains that it’s better to build for inclusion at the beginning of the product lifecycle rather than as an afterthought. She argues that the best time for inclusion is now, large or small, to make a difference in the lives of customers and stakeholders.

Buy on Amazon

Robert Herjavec‘s book You Don’t Have To Be A Shark, Creating Your Own Success is not new. Still, it includes his stories and anecdotes for success that are vitally important in the lives of entrepreneurs and business leaders. I got the print book and purchased the Audible version because it’s narrated by Robert, which elevated my time spent in the “pain cave” running the trails over the summer. He talks about the value of relationships and trust and argues that success is not just about aggressive competition (like a shark) but about fostering trust and connections with others. From his tips on cold calling to becoming better at selling and his list of things you need to do when making a significant change in life, the book will pay for itself many times.

Buy on Amazon

Anthony Iannarino is a prolific author who has written several best-selling titles on the craft of professional selling. What I love about reading Anthony’s books is they are packed with valuable guidance without the BS and ego that fill the pages of other books on the topic. Elite Sales Strategies will quickly pay for itself by helping sales executives elevate their email tactics, design and use executive briefings in their pursuits, and when and how to listen. The book spends time diagnosing common problems, building a better talk track, andthe sequence of modern discovery calls and outlines how to offer transformative insights with integrity and skill.

Here is one quick test from the book demonstrating its high impact and value: Does the client benefit more from the conversation than you do?

Buy on Amazon

Jeffrey Pfeffer‘s work on power breaks the taboo of the subject and presents a realistic and practical perspective. I listened to 7 Rules of Power on Audible twice and sent it to a couple of my friends. In the book, Pfeffer argues that political skill is one of the most powerful predictors of career success and that the absence of power in one’s life is stressful. Power and influence can permit you to change lives, organizations, and the world. To the extent that it is translated into job control, power is associated with better health and longer life. In the book, you will learn the rules, including how to get out of your own way, the role of strategic networking, and breaking rules, among other rules.

Seek power like your life depends on it because it does!

Buy on Amazon

Richard Stiennon published the Security Yearbook 2023 for a fourth year and offers extensive research on the cybersecurity industry. The book covers the latest trends, technologies, people, organizations (over 3200 of them!), and threats in the industry, offering a comprehensive view that is essential for staying informed and ahead in this rapidly changing field. Stiennon’s extensive research and expertise make this book a must-read for professionals seeking to deepen their understanding of cybersecurity challenges and opportunities.

Buy on IT-Harvest

2023 will be remembered as “The Year of AI,” when artificial intelligence and human ingenuity merged, forever changing how we see data and ourselves. Bill Schmarzo, the “Dean of Big Data” and author of several seminal books on data science, wrote AI & Data Literacy, Empowering Citizens of Data Science to educate readers on the fundamentals of data science, data economics, analytics, applying ethical principles to AI, privacy implications, prediction, and value engineering, making innovations in AI accessible to [most] everyone. These components comprise the AI and Data Literacy Framework, which Dean Schmarzo uses to empower businesses and citizens alike to become productive with and even monetize AI, data, LLMs, and so forth. The book is organized, written clearly and concisely, and has illustrations and references that make this a must-have volume on the subject.

Buy on Amazon

Good Strategy Bad Strategy by Richard Rumelt is a game-changer in understanding what makes a strategy truly effective. The book argues that objectives are not strategy, and explains that good strategy is unexpected, how most companies get strategy wrong, and how to overcome obstacles using chain-link analysis. Rumelt breaks down the essence of a good strategy into three clear components: diagnosing the challenge, developing a guiding policy, and executing coherent actions. This simplicity in approach, contrasted with real-world examples, makes the book incredibly relatable and practical. It’s not just about complex business scenarios; Rumelt’s insights are applicable to everyday life. The book’s strength lies in its ability to demystify strategy and present it as a tool for clarity and focus in any situation.

Buy on Amazon

Choosing a favorite book of 2023 is hard, but this one would make a great candidate. Ethics in the Age of Disruptive Technologies: An Operational Roadmap, written by Jose Flahaux, Brian Green, and Ann Skeet from Santa Clara University’s Markkula Center for Applied Ethics, serves as a guide for organizations to improve their ethical management approaches. It focuses on helping organizations handle the challenges posed by advanced technologies like artificial intelligence, machine learning, encryption, and tracking, ensuring they adhere to high ethical standards. The book provides a roadmap of five stages that help those in the corporate and technology industries define and implement a Responsible Technology Governance Framework and Responsible Technology Management System, or RTMS, and aligns it with the ITEC Responsible Technology Governance Framework. While the RTMS is most applicable to mid and large enterprises, the principles for leadership and decision-making can be applied in any organization of any size.

I recently had the pleasure of chatting with Brian and Ann about this book for an episode of my podcast, available wherever you listen to podcasts or at the link below.

Listen to the podcast

Buy on Amazon


View Details

A note to my future self


As you stand at the threshold of another year, remember the unwavering dedication and hard work you put in during 2023. This year was not just about counting miles; it was about surpassing boundaries and redefining limits. You ran more than 1500 miles, not just traversing distances but also journeying within yourself, exploring the depths of your endurance and willpower.

Training for multiple marathons wasn’t just about physical preparation; it was a testament to your mental strength. Each stride was a step towards becoming not just a runner, but an elite one.

The self discipline helped you to discover and embrace these crucial insights, which have become your guiding stars:

  1. Adopt a Growth Mindset: Remember, every run, every challenge was an opportunity for growth. Your mindset wasn’t fixed on the hardships but on the potential for development and improvement.
  2. The Pain Cave: You learned to embrace discomfort, to find strength in it. Pushing through fatigue wasn’t just a physical act but a mental conquest. You understood that pain was not a barrier but a pathway to greatness.
  3. Consistency Is Key: Your journey was not made up of occasional leaps, but of consistent, steady steps. Every day, every run added to the foundation of your excellence. It was this unwavering consistency that transformed your goals into achievements.
  4. Stay Focused: There were distractions, obstacles, and moments of doubt. Yet, you stayed focused on your goals. Your vision was clear, and your commitment unwavering. This focus was your shield against all odds.

As you move forward, carry these reflections with you. They are not just lessons from the past but beacons for the future. Your journey of becoming elite is ongoing, and each day brings new opportunities to grow, endure, be consistent, and stay focused.

Whether you become elite by Olympic standards for time, distance, points, or rankings or not, the transformation you experienced was worth the effort. It’s the process that improves your mind, body, health, confidence, esteem, relationships, and lifespan.

With admiration for your past achievements and excitement for your future endeavors,

RunHard


Steve’s playlist for the Seattle Marathon

View Details

This is a Q&A session Steve had with Gary Zimmerman, CMO and Principal Consulting Analyst at TechVision Research in October, 2022.


Steve Tout: We are coming up on the 3rd Chrysalis conference, everyone is excited to be together in person more than ever this year. What can attendees expect in terms of learning, networking, and keynote speakers this year?

Gary Zimmerman: First Steve, Chrysalis is all about learning. Our presenters invented standards like XML, SAML, UMA, XDI, and OpenID. They defined what we mean by phrases like “computer virus” and have developed advanced defenses to secure the enterprise. They are published authors of several books explaining protocols and security to novices and experts alike. They have built many of the security and IAM products available today. And they have defined and implemented identity and security strategies for hundreds of companies.

Chrysalis is also meant to be conversational. It’s a live, intimate event built around a story. Leaders in the industry (many of whom have keynoted at other events) and experienced users of the technology interact with each other and the audience in panels that connect the different aspects of identity and security. To carry the conversation forward, breaks, meals and evening gatherings are set up to encourage further learning and networking. You won’t walk away with a thousand business cards, but you will walk away with knowledge and relationships you’ll value.

ST: What trends do you see driving innovation and growth in the broader IAM market?

GZ: Steve, we see three trends that are driving innovation and growth going forward.

First, coming out of the Pandemic we’re seeing things are different than they were in 2019. The reality of hybrid work, hybrid infrastructure, anti-fragile supply chains, shifting business models, and changing customer preferences are focusing investments in IAM on interoperability, orchestration, and governance across many identity solutions operating at the edge, on premise, and in the cloud.

Second, enterprises have traditionally implemented IAM “point solutions” as their digital environment, threats, and interactions evolved which, for some, has resulted in an expensive and complex architecture, friction, and fragility. Because of this, we’re seeing the rise of identity platforms which offer flexibility and consistency for the next normal. Microsoft’s announcement of Entra and industry rollups by Thoma Brava and Okta are pointing in that direction.

Finally, we’re starting to see a shift from traditional knowledge-based authentication (KBA) solutions, for example, UserID /Password, and shared secrets, to newer concepts of Decentralized / Self-sovereign Identity, passwordless authentication, and cryptographically Verifiable Credentials —where authentication is not about the spread of personal information (Identity), but proving authorship, provenance, integrity, and control of the information required to establish and maintain trust.

ST: As the costs and frequency of data breaches continue to rise, secure identity is on center stage and ever more important. What themes and hot topics are expected to appear at Chrysalis this year?

GZ: Steve, the industry has been working on answering three simple questions FOREVER

  1. Do I know you? (Identity)
  2. Can you prove you are who you say you are? (Authentication)
  3. Should I let you to do what you’re trying to do? (Authorization/ Access Control)

And while the questions are simple, the answers are not easy. Every day, security professionals are dealing with new risks posed by negligent users, compromised users, malicious users, and now, synthetic users. The volume of digital connections and the sophistication of the “bad guy’s” tactics test the protective capabilities of the enterprise every day.

At Chrysalis, we’re going to be discussing topics like Enhanced Identity Governance, Decision Velocity through AI/ ML, Advanced Authentication techniques, Pragmatic Zero Trust, and API security to help attendees be better prepared to recognize and counteract these evolving threats.

ST: Most organizations will struggle with the execution of their projects and managing their program effectively. What resources and opportunities will attendees have available to them to help with their day-to-day work?

GZ: Throughout the event, insights, answers, and recommendations on all aspects of identity, security and privacy will be shared. So, every attendee can leverage the knowledge and experience of all the experts at the event.

On the last day, we’ll do something that’s different from any other event you’ve experienced. We’ll get real. For each area, Identity, Security, and Privacy, we’ll present tools, reference architectures, baseline enterprise requirements, and vendor assessments /observations to help you make professional progress and prepare you to execute when you are back in the office.

ST: You revealed TechVision’s innovation reference architecture back in 2019 which brilliantly lays out a practical framework and tools to manage technology more effectively. Can attendees expect to revisit the innovation framework, or any new updates this year?

GZ: As I’ve been researching and building out the details under the Innovation Reference Architecture (Innovation Governance, Innovation Execution, and soon Digital Operating Models, and Innovation Methods) I’ve recognized innovation is about increasing an enterprise’s decision velocity and execution speed. It’s about laying out a strategy, testing it, and adjusting. This year, I’ll review some of the new details of the reference architecture, ways enterprises are using technology, including Web3, to increase velocity and speed, and how that’s changing our perspectives on identity, security, and privacy.

ST: You talked about the need for IT leaders to systematize innovation to maximize the benefit they can realize. Please break it down for us. How can we systematize innovation to make it practical and achievable?

GZ: Steve, this is a broad topic that requires the business to think about how to align business strategy with digital capabilities. The greater the alignment, the more integrated IT and business functions become, and eventually innovation becomes just part of how business is done. Not everyone is at that level of maturity, but everyone is innovating. As I laid out in our Innovation Governance report, you must understand where you are before you can move forward.

Start by assessing your current innovation management capabilities, including mapping of ongoing innovation activities and other existing management systems. Another important activity is to understand the innovation opportunities and challenges facing the organization, including new user needs, technology trends, competitor moves, and other changes in society and the environment, in other words your business/digital strategy. Finally, decide your innovation intent or ambition-level. What is it you are aiming for in terms of innovation activities for your organization, and why?

Next, develop an innovation strategy and policy that describe the areas of opportunity for the organization, the types of innovations that will be focused on, the resources that will be allocated to pursue the opportunities, the people and teams that will be involved, and how results will be measured and followed up. Start with “low-hanging” innovation initiatives, communicate frequently, create awareness, and recognize achievements. Also, focus on competence development and on providing (digital) tools and methods for innovation managers, facilitators, and coaches.

ST: Who needs to get involved to make systematic innovation a reality? Steering committee? Stakeholders?

GZ: I hate the fact that everyone who is proposing a change in the way things are done in an enterprise says, “it must start at the top”, but I have to say that for this one. The digital enterprise must allocate capital to develop its innovation supply chain. I use this term because just like a manufacturing firm, the digital enterprise must source and build digital “products” that support the business strategy. So, the leaders need to support and prioritize those innovation capabilities.

The next step is more dependent on where the enterprise is in its maturity. Everyone should have a governance mechanism, a steering committee if you like, to maintain alignment with business strategy, set policies, establish standards, and define metrics. Finally, someone needs to be in focused on building / improving the innovation supply chain, be that an officer-level position or someone with the authority to work across the business to build capabilities and promote change. It’s not easy, but for most enterprises, innovation is necessary for survival – and being able to invent with purpose and efficiency is becoming a competitive advantage.

ST: We hear a lot about Zero Trust these days, yet most organizations struggle with implementing the least privilege consistently. Is Zero Trust a distraction to the execution of basic security hygiene, or is there real value there?

GZ: In a world where data breaches are rampant and remote work is a permanent fixture, the need for a better security model is apparent. One of the goals of Zero Trust is to simplify security execution. No matter where the user is or what device they are on, you just start with a policy of no trust and have them consistently become trusted through MFA, IAM and data security checks. In the past, the policy differed if the user was in the office or at home, or if they were using a company device or their own. Those lines of demarcation have blurred over time and that created the need for consistent application of security policies regardless of the situation. But that consistency comes with complications.

Our clients have told us that zero trust is hard to set up and maintain because capturing and managing the details necessary to apply security policy to all users and all devices is something that is not needed in traditional perimeter prevention. Implementation isn’t easy either because zero trust components need to work with existing systems and security infrastructure not necessarily replace them because “rip and replace” isn’t an option. Finally, business process and application performance can be hindered if the policies are not implemented properly.

That’s why we say you need zero trust with zero friction.

Zero trust is not a distraction in a world where the enterprise isn’t in control of the networks, devices, and services users need to get their jobs done. In that environment, basic security hygiene cannot be assumed nor enforced so the continual verification and enforcement of a zero-trust architecture is a way to limit enterprise risk.

ST: What is your best advice to conference attendees looking to maximize the value of their time spent at Chrysalis this year?

GZ: From the beginning, we set Chrysalis up to be different from other events. We recruit speakers that are not there to promote their products. They are there to provide guidance and move the industry forward. We develop a story for the conference based on what is happening now and where we see things are going. All the sessions are in a single track and connected to that story, so that experiences and trends are not just academic, but end in practical advice that the attendees can apply as they plan and execute back home.

So, my advice is to come to Chrysalis, engage in all the sessions, ask questions, and build relationships. I haven’t experienced any other venue that gives you this level of access to the leading thinkers and practitioners in identity, security, and privacy.

MORE INFORMATION:

You can learn more about the Chrysalis Conference and register here

nipod25 for a 25% discount at check out when registering online.

When: 7 – 9 November 2022
Where: Loews Coronado Bay Resort in San Diego

View Details

At Starbucks I designed a two-tiered approach, called “Can We, Should We. One tier being based on global privacy regulations, the other tier of the program focused on ethics.