TrollEye Security

Brett Price Episode

Conversations with CISOs, Security Leaders & Technology Executives
Podcast Episode

The First 12 Months as a CISO

Brett Price shares what security leaders should prioritize during their first year, from building executive relationships and understanding the business to identifying critical assets, quantifying risk, and delivering early wins.

Executive Relationships Business Risk First 90 Days Security Leadership
Brett Price
Featured Guest Brett Price Global CISO at Quint
Featured Conversation Watch the Full Episode
Episode Takeaway

Effective security leadership begins with understanding the business, earning organizational trust, and translating technical findings into measurable business impact.

Explore the Conversation

Episode Chapters & Full Transcript

Select any chapter or transcript timestamp to begin watching from that exact point in the episode.

Complete Conversation

Full Transcript

Sullivan Tuck
Sullivan Tuck

Welcome to Conversations with CISOs, Security Leaders and Technology Executives, where we sit down with the leader shaping cybersecurity and enterprise technology. Today I'm joined by Brett Price to discuss what security leaders should focus on during their first twelve months. Brett, thank you for joining me today. to get started, could you introduce yourself and tell us a little bit about your background and your current role?

Brett Price
Brett Price

Sure, my name is Brett Price. I've been in the business probably about twenty-five years, maybe a little more.

Started out swapping out printers and fixing PCs and gradually moved to system admin, and then network admin, routers and switches, and got into security shortly thereafter, so I did that for worked at a healthcare organization for about seven years and then routing and switching started to get a little a little redundant a little boring so I figured I'd take on the security world and so I got into mostly Cisco got a bunch of certifications MCSE, CCNA, CCNP, CCDA, you know all those not the CCIE. But.

Worked for Verizon Enterprise Security Solutions for another seven years. I was a senior engineer working mostly on Cisco firewalls, proxies, did some checkpoint stuff, a few other different different vendors were the firewalls on the Fortune fifty, mostly Fortune twenty fifty, right around there. Larger organization firewall management. And then kind of got burnt out doing that. So I took on a advisory role at Verizon. So I was a senior advisor, security advisor, again staying within like the Fortune 50. Did that for a couple of years and then moved to the vendor side. So I took a role at Qualys as a technical account manager.

Worked there for five and a half years, worked my way up to VP of Sales, regional vice president, and then ended up taking a job as a consultant at a consult a cybersecurity consulting firm. I built the vCISO program there. I built the NIST assessment program, the CMMC ISO a few programs. And one of my engagements was virtual CISO for a company out of Charlotte, North Carolina. So I was their virtual CISO pretty much full time. They're a global public company. So there was a lot of GDPR ISO certification for one of our partners, and Sarbanes Oxley and PCI and in January of this year they hired me on full time as their global CISO.

Sullivan Tuck
Sullivan Tuck

Excellent. Okay. So seeing as you have just become this CISO this year, this question should be pertinent. what do you believe the first ninety days should look like as a CISO?

Brett Price
Brett Price

So the first ninety days, I think one of the most important things is starting to build relationships, right? Understanding the culture is critical. And understanding leadership, a lot of it depends on where you sit in the hierarchy. So where you sit, are you reporting to the CEO? I report directly to the CEO. You report to the CIO. It a lot of it depends, but building those relationships, understanding the culture is critical.

All this while you're actually understanding crown jewels, understanding how the business operates, identifying crown jewels, and then assessing the risk around those crown jewels. So you know while you're doing that, you're interviewing individuals asking them about their business, about their portion of the business, how they manage their business, et cetera. And then you know, you're learning about the organization and you identify the crown jewels, Which are the most critical systems with the most critical data to the business.

In other words, what would impact the business most if that portion of the business were to be shut down? So that's what I consider crown jewels. Whether it's cloud, whether it's on premise or what, it doesn't really matter, But identifying the crown jewels. And then identifying the top risks.

Right. So you can list it as the top five risks or whatever that you consider to be high risk. And then looking for quick wins. So first ninety days, you know, you should identify some quick wins. Things that you can mitigate or remediate. Within that first ninety days. Obviously gaping holes within the security posture are critical.

So building relationships, understanding who the leaders are, understanding what the crown jewels are and then getting those those quick wins.

While you're doing this, obviously you want to document everything. So I document what what your risks are. Document top five top risks and when I say risks again I what I'm talking about is I'm talking about what would it what would impact the business the worst, from a quantitative perspective. Right? So the way that I manage my relationship with senior leadership is discussing business impacting situations.

And with the business impacting situations that means how much would it hurt the business from a quantitative perspective if X were to be taken offline? Right? And then discussing things like what would the what would the reputational damage be? What would it cost us to bring in a forensics investigation team? What would potential fines be?

Or potential litigations due to lost data and that sort of thing?

Within that first ninety days as well, while you're identifying key individuals within the organization, you definitely wanna put together an incident response plan. So the incident response plan doesn't have to be all that detailed, But you have to understand who the key players are.

So you wanna understand who the CEO is, who the CFO is, who's chief legal counsel, who's HR, and start developing relationships with your with your local FBI special agent of the Cyber Division, you know, understanding that. Who from a compliance perspective, who do you have to report to in the event of an incident? Whether it be the Department of of Homeland Security or whether it be the Department of Health and Human Services or the data privacy office in in the UK, say for a GDPR. So and then develop starting to develop metrics.

Sullivan Tuck
Sullivan Tuck

Got it. So what would you say the biggest mistake new security leaders make during their first year is?

Brett Price
Brett Price

One of the biggest mistakes I think is not building relationships. Right? And and I emphasize this a lot. Because the worst thing for a CISO to have happen is pushback. So if you don't understand the culture and you haven't built the relationships, then you're gonna get pushback. You're gonna get negative responses from some of the things that you're trying to accomplish. So that's probably one of the biggest things.

And I guess another issue would be that not being able to articulate your technical findings in a business manner. In language that the business can understand. So I guess there's two.

Sullivan Tuck
Sullivan Tuck

So you've talked a lot about building relationships within your first ninety days. What does a good relationship between a CISO and the rest of the executive team look like?

Brett Price
Brett Price

So it's a one, it's a mutual understanding and two it's being able to communicate again in business terms. So the CEO wants to build revenue, you know, and avoid certain risks related to revenue, not necessarily cybersecurity risks. So if you can have conversations in a business sense related to cybersecurity, then it helps a lot.

If you can convey that you are here to help improve processes, procedures, efficiencies, effectiveness, ways that can that can add to revenue generation or assist with revenue generation. Those the those are the better relationships.

Sullivan Tuck
Sullivan Tuck

So as far as presenting risk in those business terms and focusing on supporting, you know, the business's goals, what are some ways that you found are an effective way to for that CISOs can use to communicate that?

Brett Price
Brett Price

So again, I use you know, I I try to incorporate quantitative risk. So building metrics, you know, obviously you're gonna have your metrics, your MTTRs, MTTDs and your vulnerability management and your training, your security awareness training. But really trying to quantify those top five risks and including those in those metrics really helps.

And a lot of it is an education. You know, you may have to excuse me, a lot of times it's baby steps, you know, so you have to pick and choose. and you have to understand that if you're coming in as as say a first time CISO or the company's first CISO then chances are those senior leaders are not gonna understand cybersecurity. They're certainly not gonna understand the technical language. So making sure that you have those metrics that can communicate that they can understand.

Sullivan Tuck
Sullivan Tuck

Okay. So in over the course of your first ninety days as a CISO, you're you're building relationships, you're you're learning how to, you know, communicate risk to business stakeholders. If as a CISO in your first ninety days you identify some some areas you want to change, at what point would a CISO know that they've earned enough trust to start trying to drive those bigger changes and get that executive buy-in?

Brett Price
Brett Price

Well, it I mean it depends because it depends on the level of risk, right? The buy in may take time, a long time, you know, it may take a year for you to build that true level of trust where you can say, you know, hey, I have an issue here that I need to mitigate, I need this solution and you know, without a whole lot of explanation, they approve it.

But if it's a top risk, you know, then you have to communicate it in those in those business terms. Or or you have to make sure that you've communicated very well to the business that there is a level of risk acceptance you know, that they're willing to to take.

So you need sign off on the fact that if we cannot mitigate this solution or remediate this issue, vulnerability say or whatever, because we don't have a vulnerability management program, then it's up to senior leadership to completely understand the risk and then sign off on that risk.

Sullivan Tuck
Sullivan Tuck

So when a CISO comes into a new organization, obviously every organization is going to have their vulnerabilities, compliance requirements, they may have technical debt, different strategic projects going on that are competing for attention. As CISOs are working through identifying these different risks and these different scenarios that can impact the business, how do they determine what deserves focus first?

Brett Price
Brett Price

So I would say exploitability. You know, threat intelligence has a lot to do with it. So I monitor threat intelligence every day.

So, take for instance, you know, you identify a competitor that has just been breached because of the threat actor exploited XYZ vulnerability. Right? That should be at the top of your list if you have XYZ vulnerability. For sure. You know, So it's it's those wide open holes. If you have an S3 bucket with public access, you know, those are those are critical to patch immediately.

And then prioritize based on that level of risk, I would say. Did that answer your question?

Sullivan Tuck
Sullivan Tuck

Yeah, yeah, yeah. That makes sense. So after after your first year as a CISO, what outcomes would you say would tell you if that if you made meaningful progress in risk reduction?

Brett Price
Brett Price

So I guess, you know, because because we build those metrics and because we build our strategic plan, checking off some of those top risks, you know, the exploitable things, the wide open S3 buckets and those types of things.

Success would also be your level of communication to the business. Are you still open? Is the business still open to freely communicate with you? Are you making progress with the CEO and the you know the executive leadership team? Are they more educated than they were yesterday?

Have you implemented a security awareness training program that actually the organization adopts and you know, is not pushing back on. Things like that, policies, you know, are are the par are you is the business adhering to your policies or are they reading and accepting your policies?

Those types of things. Because you can get a sense of of how well the security program is being accepted by the responses that you get on some of those things, whether it be policy adherence, policy acceptance security awareness training, reducing your exploitable vulnerabilities and helping the business to adapt to, say, artificial intelligence, and those types of things are big wins.

Sullivan Tuck
Sullivan Tuck

So after your first 12 months, if you've looked back as a CISO and you see that some of these areas aren't improving, you know, you don't have a security awareness training program that's been adopted heavily, you're not reducing vulnerabilities at the rate that you'd like to, you're having problems with AI adoption, et cetera. What are some things that CISOs could look to change within their next 12 months to mitigate some of those issues?

Brett Price
Brett Price

I was immediately gonna say get a new CISO, but. Ha ha ha.

Not I think I think again it comes down to communication, right? So if those types of things aren't working, then you didn't start at the top, so you didn't get executive leadership buy-in and support.

So you know, the way that you are presenting to the leadership team there's probably a gap, you're probably being over technical. You're probably putting too much emphasis on the bigger picture as opposed to just being very specific. So, you know, I think changing your way the way that you present to executive leadership or you present to the business and interact with the business is probably gonna be key point for for you moving forward.

Sullivan Tuck
Sullivan Tuck

Okay. So our last question, and I think I know what your answer's probably going to be. If you could give us new security leader one piece of advice for their first year, what would it be?

Brett Price
Brett Price

Dumb down the technical mumbo jumbo. Learn to speak in business terms. And you know, with that start adopting quantitative risk. because I've been saying this for years, it's coming. Where more and more CEOs, executive leaders are being held accountable for data breaches. They're paying a lot more a lot closer attention to cybersecurity. And so with that, they're going to expect more.

Whereas before you could say, you know, there's a level if this a this a high severity issue that needs to be mitigated. And they say why and you say because I'm the CISO and I've been doing this a long time. Nowadays that doesn't fly.

What does this mean to the business? You know, what is the impact to the business if this were to materialize? Those types of things.

Sullivan Tuck
Sullivan Tuck

Well you very much. It sounds like every CISO in the first ninety days needs to be building relationships and quantifying risk. Thank you everybody for watching. if you enjoyed this conversation, be sure to like, subscribe, leave a comment. And thanks again to Brett Price for joining us, and we'll see you guys in the next episode. Thank you.

Brett Price
Brett Price

Thank you.

Continue the Conversation

Conversations With CISOs, Security Leaders & Technology Executives

Hear practical conversations with the executives responsible for protecting complex organizations. Each episode explores leadership, risk management, infrastructure, incident response, governance, and the decisions security leaders make every day.

Conversations With Security Leaders Practical insights from the people leading security
CISO Leadership
Risk Reduction
Incident Response
Cloud Security
Infrastructure
Governance
Compliance
Executive Strategy

This Content Is Gated