From Protecting the Business to Running It
Ken Lawrence shares how his perspective changed as he moved from CISO to CIO and then COO, from defending and enabling the organization to running the business. He explains why technology leaders need to align with business priorities, tell a compelling story, and consistently deliver on what they promise.
Technology and security leaders earn executive support by aligning initiatives with business goals, simplifying the story, setting realistic expectations, and delivering measurable value.
Episode Chapters & Full Transcript
Select any chapter or transcript timestamp to begin watching from that exact point in the episode.
Full Transcript
Welcome to Conversations with CISOs, Security Leaders and Technology Executives, where we sit down with the leaders shaping cybersecurity and enterprise technology. Today I'm joined by Ken Lawrence to discuss the difference between protecting the business and running the business, and his transition from CIO to COO. Ken, thank you for taking the time to join me today. To get us started, could you introduce yourself and tell us a little bit about your background and your current role?
Sure, Sullivan. Happy to be here today. I am Ken Lawrence, the Chief Operating Officer for Lighthouse Federal Credit Union. We are headquartered out of Dover, New Hampshire. I make my home here in Orlando, and I commute. I've been with Lighthouse now for four years. Prior to that, I was at Disney Credit Union. I left there as the Chief Information Security Officer. I joined Lighthouse as the CIO, and at the beginning of the year I moved into the Chief Operating Officer role. I still today have purview over all of the technology stack as well as the security stack.
You wear many hats.
Wearing all three, but I've got great people under me, so I'm not necessarily down in it every day like I was when I was a CISO or when I was the CIO.
Excellent. So what motivated your transition from CIO to COO? And having sat in both roles, what is the biggest mindset shift between leading technology and leading the business?
Yeah, I think it was just the opportunity to move into a different role and pick up a little bit wider scope. But I would tell you there's a difference between all three roles. There's a difference in terms of mindset sitting in the CISO chair, which is more, hey, how do I provide the defense for the business? That's really what I'm focused on at that point. The CIO mindset is really, how do I enable the business to do the things they need to do, whether that's from an infrastructure standpoint or a development standpoint? I would tell you, as a COO, my mindset every day is running the business. Again, I have those pieces under my purview as well, but I'm not myopically focused on those as I would normally be if that was my only role. So it's really broadening your scope. As you step from one role into the other, they become markedly different. Once I stepped into the COO role and picked up a lot of other operational portions of the business as well, my mindset changed completely to, I'm on the offense every day, and I'm trying to make sure that we can execute in the most efficient way. So that's really the difference. Going from a smaller scope to a wider scope, you've got to broaden your thinking as well. You need to elevate your level of thinking and how you think about executing every day. I would say that's probably the biggest difference.
And how does your definition of success change from CIO to COO?
I would say it's as easy as sometimes looking at the metrics, right? Today my focus is not uptime. There are folks where that is their focus. My focus is: How do we execute? How do we execute in a way that sets the business up for success? I don't do that on my own. I do that in concert with cyber, with infrastructure, with risk. They're a big component of what I do. Back-office operations sometimes have to be brought into play. So it's a wide purview, but it does give me the ability to execute from end to end. Again, that's kind of how I look at it and how I tackle it every day. It's not one area that I'm looking at. I'm looking across the entire forest and trying to figure out, okay, where do I need to be? To use a hockey term, I try to anticipate the puck as much as I can. Again, the mindset is running the business. It's staying on offense. That's what I'm trying to do most of the time.
So many CIOs struggle to get executive buy-in for their technology and security initiatives. Now that you're, I guess you're not necessarily on the other side of the conversation. You're on both sides, sitting in those roles. But what are the biggest shifts that CIOs and CISOs can make to better pitch their initiatives to COOs and business stakeholders?
Yeah. I would say it's not always about the ROI, right? Sometimes you just need to tell a good story. We get much too wrapped up in the technical aspects and the minutiae, and you lose the larger picture. So the mindset that I would take when coming in to talk about whatever initiative it might be: Number one, is it aligned with the business? Is it aligned with the initiatives at the top of the house? It's a little bit easier from a cyber standpoint because everything you do should be aligned with what the business is doing. Your focus is protecting. It's a little bit different maybe from an infrastructure standpoint, where you can easily be looked at as a shiny-object kind of individual: Boy, those IT guys spend a lot. So it's about how you tell the story. Am I telling a story in a way that aligns with the business goals and business initiatives? One thing I would say most CIOs do is they won't do technology for technology's sake. They're trying to tie it into the business. But simplify the story so that folks understand what you're trying to do and the value that you bring. I think that's how you get buy-in. Finally, you need to deliver. Delivery, delivery, delivery. If you can't bring it across the line in a consistent fashion, it doesn't mean you're always going to hit the timeline, but we evangelize those things and set expectations. I think if we do that, that's how you get buy-in. You never get buy-in with a 30-page PowerPoint deck. That just doesn't do it. Know what the story is, make sure you're aligned with the business focus and business initiatives, and you're likely to get those things approved if it makes sense and it's within budget. That's always the advice that I give. What's the story? What do you want me to walk out of here and know? What is the value of whatever it is you're bringing to me? You need to make sure that I can understand that and we're not caught up in all of this technical stuff. I think that's how you get buy-in.
So how do you come up with that story? What's a good example of how you develop a story to tell executives to get the buy-in that you need?
I would tell you something as simple or as complex as a Zero Trust network. It sounds great, Zero Trust. If I'm not in the game, it just sounds like a really good thing. It's been a buzzword for a decade, roundabout. So when you actually come in and sit down and try to sell something like this, again, what are the benefits to the business? What are we bringing to the business? My story would be, if we pick something simple, in today's remote world, I get that it's moving back a little bit the other way, but we still have a lot of remote workers. We're always worried about what that individual is doing at home. Do we have the right monitoring in place? There's always somebody a little bit smarter than us. So, hey, what if I could make sure that every time you logged into your work equipment, whether it's a Mac or PC or whatever, you're instantly dropped in, you're on-net, you're in the VPN, and all policies and rules apply? Let's think about that. You log in, and all of a sudden you land in this secure zone. You probably have some other controls that you're going to go through. You probably have multi-factor authentication or a 19-character password and all this other stuff. But the ability to drop you into the corporate network and corporate resources behind the VPN, where you don't have to do anything more than log into your computer, when you simplify those things down, people start to understand. Hey, I get to control what comes into my network. I get to control what goes out of my network. So that means everything from an email standpoint to whatever might be moving on the wire, backups to the cloud, I've got it all. I've got it encrypted, decrypted. I know what it is. I know where it's moving. If I can tell those stories in a way that the CEO can understand and the COO has dug in on what we're trying to do, then I've told a pretty compelling story. But it's when I come in with a lot of technical speak and things that are theory and not proven in fact that we start to get a little bit squirrely. Even if I get the approval, if I fail to deliver, now I'm back in that same bucket again. I've got to climb up that mountain again. So you have to tie all of these things together. Make sure you're aligned with the business, tell a story that the business can understand, and then you have to deliver. You've got to show the value, and you have to deliver.
Okay. So as COO, what do you wish more CIOs and CISOs understood about how executive teams evaluate technology and cybersecurity investments? And what are some reasons a technology or cybersecurity investment they think would be approved easily may not be approved?
There's a lot in that. So ask me the first question again.
As a COO, what do you wish more CIOs and CISOs understood about how executive teams evaluate technology and cybersecurity investments?
Again, I think it's telling the compelling story and making sure that it aligns with the mission. It aligns with the direction that the organization is going. That's the biggest key. What I have oftentimes seen happen is we make these promises, but we don't deliver on them. At a minimum, you can bet the CFO is tracking on this. So what I've always tried to do is not bite off more than I can chew, be very honest about the outcomes and the time it will take to deliver those outcomes. I try not to pad them, but I have to give the teams the ability to make a mistake along the way and not feel like their backs are against the wall. So there's no silver bullet for this. It sounds like a broken record, but it's what has always worked for me: understanding where the business is going and aligning what you're doing to where the business is going. I can tell you that lots of times in cybersecurity we're going to be well out ahead of the business. That's where you want us. I want my teams bringing things back to me as they're seeing them out there. As AI starts to get stronger and stronger and more people are adopting it, we're going to have to think about how we change our security posture to be ready for this, because it's coming. It's here. The days of looking at just traditional spam emails and things like that, it's much more sophisticated than that. But again, I think if you tell the right story, from a cyber perspective you're never trying to scare anyone. You're trying to make sure that they're informed and that they know you are in front of whatever threats might be out there, and that's what you're bringing to protect the organization. Storytelling, storytelling, storytelling, and alignment. That's what it's about.
And for the second part of the question, what are some examples you can think of or remember from investments you've tried to make or seen not get approved? What are some reasons a board may not choose to make a cybersecurity or technology investment that a CIO or CISO may not expect?
I have definitely been in a position where I've thought whatever the solution was, it was the right thing for the organization. Some of those didn't go because of pure cost. Some were just the effort it was going to take across multiple teams to deliver on these things, where the business, evaluating the two, decided, hey, can we do something a little less heavy, a little less impactful, but still get there? I think we've all come to the table with, hey, I think I've got it. This is the thing. You'd have to be from a different world not to approve this, or whatever the case may be. But sometimes there just may be things that you're not informed about. I can tell you there are things where I will tell my teams, no, we can't do that. I'd like for you to think about going a different way with that, only because there are things that I know we're working on or there are potential possibilities that I can't necessarily speak to. But I can coach and guide. Over time, when you build that trust, they understand why certain things can't be done. In certain cases, you can just come right out and say, hey, you're going to have to tell me a better story in terms of the value. You're telling me this, this, this and this, but I'm looking at an eight-year payback. So it can be any number of things, and it also depends on the organization. But I would say, whether you're the CISO or the CIO or whatever, get aligned with your CEO. Sit down with your CEO and find out what his or her expectations are. What do they think about these roles? This is your opportunity to maybe fill some gaps from our seats in a realistic way, and we have to bring them along. But if we're quiet and we're over in the corner, and they only see us when we're in there shuffling around some stuff at budget time, it's much harder to get that buy-in. Spend the time understanding where the CEO wants to go, how they think about technology, and how they think about cybersecurity. If you do that, you're likely to get yourself in alignment, and you're likely to educate them along the way. That removes a lot of hurdles for you. If you have an opportunity to do that at a board level, I would do that at any given chance. Again, understand and know what the story is that you're bringing into the board, but get yourself in front of the board as well. I think those are things that we might not push hard enough to do. Get in front of the board, sit down, and make sure you're aligned with your CEO.
So you may have already kind of answered this question in that answer, but what is something effective CIOs can do that will help them earn influence beyond just the technology side of an organization?
Be a partner to the rest of the organization. Be a partner to your CHRO. Be a partner to your CFO. When I say be a partner, be a thought partner with them. I can tell you that I personally spend the bulk of my time, I believe, talking with the CFO. There's so much I can learn from him and a lot of things he can learn from me, but it helps keep the door open. I would say regardless of who it is in the organization or what role they play, put yourself out there. Try to be a thought partner for those folks. There are lots of times in my career when I've put stories together and run them by the CFO or the COO: Hey, how does this story play? But if I didn't have or establish a relationship with them, that's tough to do. So you definitely want to be a team player. It's not necessarily about pushing technology; it's about being the thought partner. I think that's how you strengthen your seat at the table. It also, I think, as a leader gives the impression that you're much more well-rounded. Yes, you're an expert in your field, but you can think outside of your field too, and we need that around the table sometimes.
So as CIOs and CISOs, as you put it, fight for their seat at the table, what's one mistake or a few mistakes that you see them frequently make?
Boy, that's another loaded one there, Sullivan. I think, again, you have to establish relationships. You have to be thinking organization first. Always organization first. If you bring that organization-first mindset, you're not likely to run into a lot of friction. It's when we start to look inward that we begin to run into problems. Again, keep your head up and look out over the forest and know what's out there. I do think today CIOs and CISOs don't struggle quite as much to get to the table as they used to. I mean, you turn on the news and someone's breached. It seems like every day there's somebody we're reading about whose data is ending up in the street. All of us have been impacted by one of these or something. We've all gotten a little envelope in the mail saying something happened and your stuff is out there. You're part of a breach. So I don't think today it's quite as difficult to get those seats at the table. But again, you have to be aligned with the business. You don't ever want to be perceived or seen as, hey, I'm a shiny-object person. I'm off to the next thing and I haven't pulled this across the line. I said the payback was this, and now I've got the CFO looking at me like, hey, we're underwater here. That's going to happen. Not everything is going to play out exactly the way you see it, but again, that peer connection, that storytelling and that alignment with your peers, I think, is how you get the ball across the line.
Excellent. So as we wrap up, looking ahead, how do you see the role of the CIO changing with AI and, just in general, as technology becomes more central to business operations?
The role is evolving. Today, a lot of people know this and a lot of people don't, but a lot of places don't log into domain controllers down in the basement anymore. They do all that stuff in the cloud now. So when you think about the cloud footprint, we manage Azure, AWS and GCP today, and then we have to provide security across all three of those clouds. We have to provide security for all of those API endpoints. And that doesn't start with the cyber guy; it starts with development. So the role is evolving, but there are still some basic blocking-and-tackling things that you need to do, and that won't ever change. Make sure you build things with scalability and with cyber, start with it. Don't bolt it in later. If you try to retrofit it later, that's where you run into a lot of problems, and it's too late at that point. So build from a cyber standpoint and build from a scalability standpoint. Continue to keep your head up and look for what's coming next. I was just talking to my cyber person this morning. I popped into his meeting and was just chatting about, hey, what do we see coming from an AI perspective? How are we trying to get ahead of this? Not looking at traditional tools, traditional SIEMs and those kinds of things. I don't know what's out there, but we've got to keep our heads up and keep looking forward because it is changing so fast. And if you're in the vertical that I'm in, you're concerned about stablecoin and tokenized deposits and all of these things, and digital currency. It's all coming. So it's not just that the CIO should be looking at this. The CISO should be looking at it. The COO should be looking at it. Everybody should be looking at it. Everyone should understand that the world is changing very rapidly, and we've all got to be ready to adapt and change. Look toward the future. If you think AI is not going to change the world, then we probably should talk, because it is. It's here to stay. It's not going anywhere. So the biggest thing that we can do as technologists overall is keep looking forward. Keep pushing vendors to be better. That's what we have to do because we can't all afford to go out there and come up with our own tools and all of these different things. We've got to continue to push the industry. I would say you push and you look at some of these younger companies that are coming through. They're far and away ahead of some of where our Fortune 500s are. So as technologists, we've got to be digging into those things and not doing what we were doing yesterday. All that's going to do is get you burned tomorrow. That's what's going to happen. So exciting times, Sullivan. Exciting times, I would say.
Indeed. Exciting times they are. Well, thank you everybody for watching. If you enjoyed this conversation, be sure to like, subscribe, and leave a comment with your thoughts or suggestions for future guests and topics. And thanks again to Ken Lawrence for joining us today.
Conversations With CISOs, Security Leaders & Technology Executives
Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.