This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Eddie Thomason. Eddie is a Regional Sales Manager at DataLocker, a bestselling author, and an entrepreneur who has been featured on ABC, CBS, & FOX news affiliates. Eddie has worked with multiple Fortune 500 companies to improve their revenue and was named one of the top business professionals by the Chamber of Commerce. He also hosts the popular “Leaders in Cyber security” where he talks to cyber professionals about #InfoSec.
Chapter Titles:
00:00 Introduction
01:50 “People have to be people”
05:30 U.N.L.O.C.K. Yourself
11:56 Humility 15:14 Who you want to be
16:30 Negativity 24:15 Twitter CISO News
29:27 Who owns the risk in the company?
31:30 Why CISOs don’t stay more than 2 years
35:58 vCISO or CISO?
40:30 What’s new for Eddie
Audio:
Important Links:
Transcript
Manoj Tandon
Hello everyone, this is your host Manoj Tandon. Welcome to another episode of Dark Rhino’s Security Confidential. Today, we welcome back a friend of mine, Eddie Thomason, who really doesn’t need much of an introduction, but we’re going to do it anyway because he’s such a good guy.
Eddie is a best-selling author—not officer, I messed that up—author of the book Unlock Yourself, and we’re going to have him chat about that. I’m really looking forward to that conversation, getting the CliffNotes. He is a podcaster. You can find him on LinkedIn, and you can find him at all the podcast outlets. He’s got a lot of things in the works; we’re asking him about that here as well, on what’s happening with the world of podcasts with him.
He’s a very well-known speaker, he’s been documented on media, he’s made a lot of appearances, he’s an expert in cybersecurity, all-around general good guy. I’m just honored to have him here. It’s always fun when you’re around here, Eddie. Thanks for being here today.
Eddie Thomason
Absolutely, Manoj. Thanks for having me here, my man. I don’t know if I give myself that expert title in cybersecurity yet, but hopefully I don’t disappoint.
Manoj Tandon
Ah, I mean, I think all the “experts,” if they acknowledged how little they know, we would be better at cyber in general because it is a problem of the people. As you said before we started this podcast, people need to be people. I think that’s a brilliant theme. In fact, start us off there, Eddie. What do you mean by that? Let’s get into that.
Eddie Thomason
Man, so people are people. I feel like to different people that may mean different things, but how I perceive it and how I internalize that is: we’re all flawed individuals. We all have our own things that we are self-righteous about, or things where we have our own egos and things that we want to fulfill in our own selves.
Manoj Tandon
So you mean we’re not perfect?
Eddie Thomason
No man, not even close. Not even—
Manoj Tandon
I’ve been lied to my whole life, I’ve been lying to myself.
Eddie Thomason
There was only one perfect person that walked the world, walked the earth, and that was over 2,000 years ago.
Manoj Tandon
Well, there you go. That’s an impossible standard, so.
Eddie Thomason
Exactly. So, overall, I just think that that thought process of “people have to be people” is you’ve got to kind of build that in. You have to think and allow people—when you think from a leadership perspective, you’ve got to allow people to make mistakes. You’ve got to foster an environment so people feel comfortable making mistakes and don’t feel ashamed for making mistakes.
But then also, as a person, you should also be able to call out when people are going too far off the deep end, instead of being so sensitive about whether or not you’re doing something wrong or somebody’s telling you you’re getting some criticism or something like that.
I feel like now I’m just rambling a little bit, but this thought process that people will be people, or people have to be people, is just a simple thing, man. People just need to understand that we’re all flawed individuals, and we’re going to make mistakes along the way. And at some point, you have to course correct. You’ve got to figure out how to have a team of people around you that’s going to help you course correct, or you’ve got to be able to do that on your own.
Manoj Tandon
Sage advice. So now, tell us: is a little bit of this what’s in your book, Unlock Yourself?
Eddie Thomason
Yes and no. I would say the main principle of Unlock Yourself is really based on this idea of leading yourself. I love—you’ve probably heard of John Maxwell before, right? I call him the godfather of leadership. He’s written the most books on leadership ever. I think he’s up to like 75 or 80 books on leadership, and he said leadership is easy when you have to lead other people; it’s hardest when you have to lead yourself.
The hardest person in the room to lead is yourself. You can be up on stage, or you could be in a position or a role, and you can have the leadership title, but if you’re not good at leading yourself, people are going to follow your example. It’s kind of that old adage that people will do what you do, not do what you say. So if you’re practicing the wrong things and having the wrong actions and wrong attitudes, that’s going to be what gets infused into the team that you’re leading.
So, Unlock Yourself: How to Earn the Success You Were Born to Create goes through this process of how to lead yourself, how to put yourself in a good environment where you can win—win with yourself, win with people, and then win in life. That’s pretty much the three subsections of the book. But the “UNLOCK YOU” is basically an acronym. You go through the entire process of a formula that’s getting you to a point where you’re actually unlocking yourself.
Manoj Tandon
So walk us through the acronym then. I’m curious. I was a big sucker for CliffNotes. I love that. Let’s go through the abridged version.
Eddie Thomason
100%. So the “U” part of it is Upshot. Your Upshot is your big dream, your big goal. I always tell people: you kind of don’t know where you’re headed until you know where you’re going. You’ve got to have some kind of vision of what you want your life to look like. I tell people all the time: don’t think about what you want to be when you grow up, but instead think about what you want your life to look like, let’s say 5, 10, or 15 years from now.
What kind of house do you live in? What kind of car do you drive? How do you spend time with your family? What does that time look like? Because you’re going to make different decisions on the vehicle that’s going to get you there compared to just deciding, “I’m going to be a doctor.”
That doctor role may get you more money or some status in society, but it doesn’t give you the most flexibility with your schedule if you wanted to travel and spend time with your family and do all kinds of different things from that perspective. I’m not saying that being a doctor is a bad role, I’m just saying take that into consideration when you look at that Upshot and what you want your life to look like.
The “N” part is Negativity. In life, once you tell somebody your big dream or your big goal—things you want to accomplish—you’re always going to have negative people that tell you that you can’t do it.
Manoj Tandon
Oh, that’s a given.
Eddie Thomason
100%. So I tell people all the time: you want to limit the negative. “Cap the negative” is what I typically call it. Cap the amount of negative influence that’s going to be coming into your life, because you’re going to have enough people telling you that you can’t.
This moves into the “L” part of the UNLOCK, which is Listening. Instead of listening to all the negative, you want to start listening to the positive. Listening to the people who tell you that you can do something, compared to always dwelling on the people who continuously tell you that you can’t. So that’s the “L” part of the UNLOCK.
The “O” is Optimize your growth environment. It’s basically associating yourself with people who are growing in the areas that you want to grow in. They have success; they have fruit on the tree. In this world of cybersecurity, it’s saying, “Hey, this person has created incredible security environments. They’ve created incredible security teams, they’ve developed the skill sets”—not just based on credentials, but they’re a great person. Start surrounding yourself with different individuals like that so that you can continue to grow and put yourself in an environment where you feel as though you’re not getting left behind. It’s kind of like that natural competitive side of things.
That’s that piece. The “C” is Choices. Choices are what’s going to get you to success or not. We can choose to do wrong or we can choose to do right, but the thing about it is you need to understand how those choices impact your day-to-day. If you make positive choices that compound over time, those choices are going to lead to a much better life.
But it kind of looks like a bell curve. The way I look at it is, have you ever read the book The Slight Edge or heard of Darren Hardy’s book The Compound Effect?
Manoj Tandon
I’ve heard of The Compound Effect.
Eddie Thomason
So take the compound—I think Slight Edge is older. I say Darren Hardy because they are similar books in what they communicate. But it’s basically this idea of compounded choices. If you look at a regular graph and you look at a curve that typically starts to happen up front while you’re moving towards that upshot goal that you’re looking to accomplish, it looks like every small, positive decision you make results in no movement. You’re just stagnant; it’s a flat line. It doesn’t seem like anything positive is actually happening.
But eventually, somewhere down the line, because of all these compounded good choices, the curve sweeps up, and you start to create, receive, or experience incredible amounts of success and incredible amounts of accolades.
But the same thing is true from the other perspective. You can make decisions here—instead of making this big lofty goal about dreams, let’s just talk about weight. You can choose to work out every single day for 15 minutes, or you can choose to eat a bag of chips every day for the rest of your life. Which one is going to get you the results that you want?
Early on, you might not see any results from that bag of chips, but once you get into year two, year three, or year four, and you’re eating a bag of chips every single day, you’re probably going to go down a downward spiral somewhere you don’t want to be health-wise. So, your choices—
Manoj Tandon
I mean, chips aren’t really my thing. My thing is peach rings. I love peach rings. Every once in a while, especially on road trips, I have peach rings. But that’s when I pretty much limit myself—just eating peach rings on road trips.
Eddie Thomason
But that’s the choice side of things. The “K” is Knowledge. That’s what the “K” stands for: basically understanding that you don’t know what you don’t know. The more that you continue to educate yourself, be a lifelong learner, and understand that you’ve never really arrived fully in any position that you find yourself in, you always need to continue to grow your knowledge.
That typically happens through reading. I do a lot of reading. It could be podcasts like you’re listening to right now.
Manoj Tandon
You know, I think that’s a common trait among very successful people: they do read, or—let’s put it this way—they assimilate a lot of external knowledge. Because there’s a thirst and a desire to know it, and there is absolutely an acknowledgment that they don’t know everything.
Eddie Thomason
Yep. And I think the more people understand that, the more you set yourself up to be humble. You show more humility, because you understand that you can learn from anybody at any time.
Manoj Tandon
Well, there’s a lot of our leadership in American life—I’m guessing here, but just from their actions, it seems like humility and humbleness are things some would regard as a weakness. What would you say to those folks?
Eddie Thomason
Well, you know, my personality is a very choleric-style personality. What I wanted to say right off the tip of my tongue is, “Well, you’re wrong.” I like it. You’re wrong. But in all seriousness, I feel like humility is a huge portion of your own personal growth in general. I feel as though when you’re able to show humility, regardless of your accomplishments, how big your title may have gotten, or things that you’ve accomplished, humility allows people to believe that they can accomplish it, too.
Does that make sense? So it kind of levels that playing field. It levels that playing field instead of making it this big lofty thing that only this person can accomplish. It makes the average person feel as though, “Oh, I can accomplish that, too.” It just takes a certain amount of work, a finite amount of work, and a finite amount of effort in order for me to accomplish those same goals.
I’m a big fan of it. I don’t care how big I get or how many accolades I get. Hopefully, when I talk to people, they just look at me as, “Oh, he’s just a regular dude.” Yeah, he may have accomplished some things, but he’s just a regular dude.
Manoj Tandon
I appreciate that.
Eddie Thomason
But I say that all the time, man. Even when I used to go back and speak at high schools, I’d have some kids come up to me like, “Man, you played D1,” and, “Man, you did this,” and all these other things. I’m just like, “Well, listen, I appreciate the accolades. I know for you that may seem like this big, huge, crazy feat, but at the end of the day, you can do the exact same thing, man. All it takes is some good grades and you being willing to put yourself out there, either in some kind of sport or just being persistent.”
It sounds simple, and it is simple. The hard part is just doing it. The biggest gap in life is between knowing and doing. Most of us know what we need to do; we just don’t do it.
Manoj Tandon
We think about it. Well, they have to really question—so, when you look at the very first part, the Upshot, you might have some lofty goal as part of your Upshot because it sounds good, but your heart’s not in it. Right. The Upshot doesn’t have to be this big thing like, “Okay, I’m going to be a brain surgeon,” or, “I’m going to go to the moon,” or, “I’m going to be the next Nobel Prize winner.”
There’s just as much value in an Upshot like saying, “You know what? I am going to develop a new way to run food banks that feed a lot more people.” Your heart might be in that. I guess that’s the thing. Because what you just mentioned is that people know what they need to do but they’re unwilling to do it. I think they know what they might need to do for an Upshot that they may not be really mentally aligned with, but they like saying it.
Eddie Thomason
Exactly. That’s why I mentioned early on: instead of thinking what I want to become, don’t think about that. Think about who you want to be. It’s a different thought process.
Think about when we were kids. Everybody’s going to relate to this, because when we were kids, mom and dad asked, “Well, what do you want to be when you grow up?” As an eight or nine-year-old kid, you’re supposed to be able to answer this question. “I don’t know, I’m going to be a doctor, I’m going to be a lawyer.” Because, like you said, it’s something that sounds good to say.
Whereas, if you take that question out and stop asking people, “What do you want to be when you grow up?” and ask them, “How do you want to live?” It forces you to answer a different question. It forces you to understand what brings you happiness, value, and content. Then you start to build a life around that, compared to building a life around a position. You’re building a life around how you want your life to look. Does that make sense?
Manoj Tandon
That makes a lot of sense. Those who are looking to transition into cybersecurity, this has direct implications for that. Correctly, because you should answer that question for yourself. That’s going to drive how you’re going to become that contributor. That’s at a much lower level, but the same concept. What you’re saying is a wonderful life concept, and it’s a fundamental shift in thinking.
Exactly. Another thing there, though, is the “N”—negativity. Do you have any suggestions? There are always negative people; that’s just a given. I can tell you as an entrepreneur, I never met anyone—I’m trying to think who—who said that I should do it other than my wife. My wife was the only one that said, “You know what? If you don’t do this now, you’re just going to cry about it for the rest of your life, so just do it.” And I think she did it to stop the crying.
But almost everybody else was very, very negative. “Why do you want to leave a great corporate gig? You’re making all this money, why do you want to leave?”
You’re going to find a lot of those. How do you get over the biggest negative, which is yourself—the self-doubt?
Eddie Thomason
I love that you brought that up, and I’m going to answer your question with a story, if that’s okay.
I remember a time when I was a kid. I grew up in a single-mom household, and she was the cook of the family. There was a time where—I remember distinctly—I’m helping my mom in the kitchen. We’re preparing dinner; we’re making chili.
I probably had to be somewhere between seven, eight, or nine years old. I was a younger kid, and I remember my mom saying, “All right, well, here’s the stuff that you want to put inside the chili.” My mom was never one who measured stuff out.
Manoj Tandon
Yeah, like she knew a little bit of that—
Eddie Thomason
Exactly, like we eyeballed everything. You just kind of shake it in there, adding a little bit at a time. That was just how she’d always been. So we never really followed a recipe. We’d just sprinkle some stuff in there, taste it, and say, “Oh, not right, it needs this thing.”
Making the chili, she handed me the cayenne pepper. She’s like, “Hey, we’ve got to put some cayenne pepper in there so it adds a little bit of spice, a little bit of kick to it.” I’m like, “All right, sounds good.” I pop the top off the cayenne pepper and go to shake it like she does, but the whole top falls off. The whole top falls off. All the cayenne pepper jumped inside of this chili.
And here I am—I was a 100% sensitive kid, man. This dinner was supposed to be feeding me, my brother, my niece, and my nephew. We had a couple of god-siblings and stuff there. It was supposed to feed this family of thirteen. We were all young kids.
I’m like, “Oh my gosh,” and I’m crying. “Mom, I’m so sorry. The top just fell off.” My mom, being the genuine, caring woman that she is, said, “Boy, don’t worry about it. It’s a mistake; it’s going to be okay. Here’s how we fix this. You can’t take it out. You won’t be able to take all the seasoning out of the sauce, but what you can do is sweeten it up with more sugar.”
What she said was: you can’t extract the heat, but you can add more sweet. This is what that means for me when it comes to negativity: you cannot get rid of negativity in your mind, but you can dilute it with more positive.
If you’re currently feeling as though you’re getting a lot of negativity, feeding yourself a lot of lies—”I don’t know if I can accomplish it, I don’t know if I can win”—what you need to do is start listening to more positive stories.
Your brain is the most honest bank teller that you’ll ever have. If you go to your brain and say, “Hey, listen, I need you to tell me about a time where I absolutely sucked at something and I just didn’t accomplish it,” your teller will be like, “Absolutely, sir. Here’s that time when you were in the fourth grade, you were on a dodgeball court, and you got smacked in the face.”
Or you can go to your brain and say, “Hey, tell me about a time when I actually accomplished something. Tell me about a time that I felt inadequate, but I achieved something anyway. Tell me about a time that I maybe had some obstacles stacked up against me, but I overcame them and I won anyway.” Your bank teller is going to go back and say, “Hey, listen, I remember that time when you did this and you did that.”
So that’s the first step of it: you’ve got to recognize that you’ve already accomplished something good, and then you feed your brain more positive stories of you winning.
For example, if somebody’s making a switch into cybersecurity, maybe you’re coming from a hospitality background. There are people who’ve come over from hospitality, and I’m pretty sure there are stories out there of cybersecurity people who have successfully made that transition.
From your perspective, instead of being in your comfortable corporate job, you transition into having your own thing and being an entrepreneur. There are multiple stories out there about people who successfully made that transition. So you can’t listen to the people who are basically just giving you their opinions, because it’s not actual factual information. They’re just giving you their opinion based off of what their fears are. That’s all it really is.
What you need to do is start listening to people who have successfully made the transition, because what they’ll tell you is actually completely contrary: “Hey, listen, you can do this. It’s actually pretty simple. I was scared too; I went through this period of self-doubt, too, but here are the actions that I took and it created a much better life for me.”
So, that’s a long-winded answer, but hopefully that helps.
Manoj Tandon
That’s a great answer and an actionable answer, because now somebody can put that to good work. And I learned that you can put sugar in your chili and that does tone down the heat. By the way, I would have thrown a couple of habaneros in there.
Eddie Thomason
We had a lot of things in there. You can throw a little lime in there too, and that kills the heat a little bit as well.
Manoj Tandon
Yep, but it makes it more acidic.
Eddie Thomason
Sugar also helps with acid.
Manoj Tandon
Ah, there you go. It’s always 20 minutes to lunchtime, and now I’ve just torpedoed this interview because I’ve got food on the brain.
Eddie Thomason
That sure sounds really good. Go make yourself some chili dogs or a good old-fashioned hoagie.
Manoj Tandon
That sounds great. That sounds like putting potato chips on top to get that crunchy, salty feel.
Eddie Thomason
Yes.
Manoj Tandon
And every cardiologist listening is like, “Yeah, you do that.”
Eddie Thomason
Well, again, it’s all about how often and frequent you do it. If you’re doing it in small amounts and not every single day, you’re good to go. You’ve just got to limit how often you put the chips on top.
Manoj Tandon
So, unfortunately, as of this recording—today is August 23rd for anyone that’s listening—we’re going to go back to negativity because we had some big news today: some bombshell revelations from the former CISO over at Twitter.
And it relates back to a lot of things you just mentioned. We’re going to circle back to this: our people need to be people. So for our listeners who have not yet caught the story, the long story short is that their former CISO has turned into a whistleblower. He was fired back in January by their CEO, who was the former CTO of the company.
Why I emphasize that—and why people need to be people comes back here—is that at one level—and I’m not going to waste your time to get into all the details of the story; there are lots of articles out there—one thing that struck me was friction. Friction causing failures in what might otherwise be a very good cybersecurity program.
That friction stems from roles and positions. As important as architecting the program is, architecting the risk reporting structure in the organization is as well, because you really want an unbiased view. So, the CISO reported to the CTO before. Typically, the CISO reports either to the CTO or the CIO. More often than not, you see the CIO, and sometimes you see the CFO, which is the worst place, by the way, in my personal opinion.
You see, it used to be that a lot of the CIOs reported to the CFO. What do you think about this structure? If a CISO is to do their job, are they put in a very uncomfortable position by reporting to the very people that they need to be auditing or providing gaps that they may have inadvertently created?
What are your thoughts on this, Eddie, knowing that people will be people?
Eddie Thomason
Yeah, so first of all, I highly encourage the listeners to go back and read the story itself because I don’t know 100 percent of the steps and everything inside that story. But also, you don’t know 100% of everything that happened within the organization.
But I will say, based off of conversations that I’ve had with multiple cybersecurity leaders—majority of the people that I talk with on my show who find themselves in a CISO role or as a Director of cybersecurity—what’s typically best for an organization is when the CISO is able to report directly to the CEO.
And the primary reason is that, as you said, if you’re reporting to a CTO and your job as a CISO is to audit the CTO, then there’s a direct conflict between what you feel as though you can tell your boss, or how much flexibility you have to communicate, “Hey, we’re doing some things wrong,” depending on the ego of the person that’s in that seat.
Manoj Tandon
Yeah, that puts that condo in Florida in jeopardy.
Eddie Thomason
Exactly. So it’s very interesting when you look at that aspect because I personally believe, when you look at true business structures, the further you are away from the CEO as a chief person inside of the business, the less influence you have. The things that you share and the things that you believe in aren’t being implemented into the business itself.
Manoj Tandon
Right. Especially in this world where we talk about how cybersecurity is a part of the business—it’s not a cybersecurity issue; it’s a business issue.
Eddie Thomason
I think the best way to communicate that in a physical way is by giving them that seat at the table, not underneath somebody else that’s reporting to the CEO.
Manoj Tandon
Right. I’ve been a proponent of it, and I’ve heard the counter-side: that having the CISO underneath the CIO is a good thing because you don’t want to create yet another wall or another department, and then you’ve got isolation again and now you’ve created a different type of friction there.
But ultimately, the big question here for all companies is: who owns the risk at the end of the day? And that is the CEO and the board of directors of the company. And they need to be cognizant of how best they can get an unbiased view of that risk, regardless of where it may take them.
Eddie Thomason
At the end of the day, you shouldn’t—as a CISO—be afraid to expose vulnerabilities inside of your organization to the CTO because you feel as though your job is in jeopardy. It’s your job to make sure that data and information are secure within the organization.
Inside your daily activities, if your team identifies vulnerabilities, you shouldn’t feel as though, “Snap, I should not report this to my CTO because I might lose my job,” or, “I should not go over my CTO’s head and tell the CEO or the board because my CTO is going to say, ‘Hey, you made me look bad; now I’m going to lose my job.'”
There’s a level of uncertainty there that I feel should not be there. It’s unnecessary friction, and I don’t know that there’s a way to eliminate it because ego is a very natural thing, and people will be people. You don’t know the personality that’s going to manifest depending on the severity of the vulnerability that you have found.
Manoj Tandon
Twitter is a great case study in this. Everybody should read that story in its unabridged form. It sounds like there were people who absolutely didn’t get along, and they were putting their personal interests ahead of the company’s interests.
But also, when you look at the tenure of CISOs, you don’t see too many CISOs that have been there for three years or five years. It’s 18 months or two years. Is this a reason why that job is not one that you are going to retire from? Listen up, CISOs, whoever you may be.
Eddie Thomason
That is a great question. From the conversations I’ve had with other leaders on the Leaders in Cyber podcast, it’s a plethora of things. Some of the big things overall, though, is the work environment. I feel like the role of CISO is so needed at this point in time. It’s one of those roles that’s continuously opening up; there are always availabilities.
There’s a lot of people who feel underappreciated. They are overworked and underappreciated inside of the role they’re currently in. Or, like you said, there is friction between management and what they feel the security team needs versus what the business is willing to pay for. Then as a CISO, you’re like, “All right, well, if you’re not going to respect my thoughts and respect what I’m trying to do here, then I’m going to go and try this somewhere else.”
Obviously, it doesn’t create the most structurally sound security teams if you’re just kind of bouncing around from one organization to the next. But again, I think that comes back to a business issue; it’s a business problem regarding where that person reports.
And also, have you ever read the book The Energy Bus?
Manoj Tandon
No, I have not, but that’s a heck of an interesting title.
Eddie Thomason
I definitely like the book. I read it back in 2015 or 2016. It talks about this concept of getting the right people on the bus within an organization. One of the first parts of coming into a role—say if you’re a new CISO—is you’ve already got a team of people there; you’re replacing somebody else.
This is true for almost any business role, typically. You’re coming in as some type of manager or authority figure. It’s your job to take a full analysis and inventory of who’s already on the bus. You start to figure out who’s adding the negative side to the bus and not really contributing in a positive way, who’s adding the positive things, and who are “works in progress” that have what you need—like core characteristics—but maybe they’re not fully developed on the productivity side yet.
It takes you through this process of understanding what are the right people that you need to get on this bus. I think for a CISO, that’s also very important: to understand what role you play on that bus that you’re being hired onto.
Are you looked at as someone who—we talked about this the first time we had a conversation—but are you looked at as just a person that just has to keep this business in compliance? And that’s the only thing they want you to do: focus on compliance and nothing else. As we talked about before, you can be in compliance and still not have good security.
Manoj Tandon
And there’s a ton of companies in that boat.
Eddie Thomason
Could definitely fill up a cruise ship with those companies. Exactly. So you take those things into consideration.
Anytime you’re interviewing for a new role—maybe you’re switching out because you’re thinking the grass is greener on the other side—that’s one thing to understand: is this company just going to be more of the same, just in a different place with a bigger paycheck? Or is this an environment where you feel that when they bring you onto this bus, you’re actually adding value?
Are you able to be a part of some type of cultural change happening within the company where security takes precedence and is not an afterthought to all the other business decisions?
Manoj Tandon
I’m going to ask you this question—
Eddie Thomason
Oh no.
Manoj Tandon
But I’m going to consider it from the CEO’s point of view. CEOs who recognize that they may have walked into organizations where the culture was not conducive to openness—it’s not like that’s an uncommon scenario; there’s a lot of that going on—are those organizations better off hiring a virtual CISO, regardless of their size, rather than bringing on a full-time CISO into the environment, to get a real unbiased view?
Eddie Thomason
It’s a great question. I would say it depends. For a small to medium-sized business, yes, you probably want to do a vCISO. In larger enterprises, I think you can do both.
The reason I say that is because I feel like a vCISO—most of the time, if you have a good one—will come in and do a full analysis and, as you said, provide an unbiased view of the people there. If they do their job right, they’ll also get feedback from different sections of the business. They’re trying to understand the day-to-day of what’s happening in accounting, HR, and these different areas to understand how the business itself utilizes technology in their day-to-day lives, so they can make a solid interpretation of what security tools would be beneficial and what things can be taken away or altered so that end-user productivity won’t be extremely shot because of it.
I think sometimes when you look at it from a consultant’s perspective compared to someone in-house, in-house people are typically more lenient. When you think about somebody in an organization, they have a paycheck coming from this organization. They’re more lenient because they have to interact with these people on a daily basis, so you don’t want to ruffle too many feathers.
You’re basically saying, “Okay, well, Janice over here loves this one tool that she’s been using for the last 15 years; I don’t want to switch it up too much on her.” It’s a blessing and a curse, because you don’t want to mess with the productivity of Janice, but at the same time, you might have a big vulnerability.
Now, a vCISO typically might come in and they’re not as engaged; there’s not a lot of happy-go-lucky relationships already established. So you just get the facts: the numbers, the vulnerabilities, and the issues. I think so-and-so can change and so-and-so can adapt.
But I think at an enterprise level, you can do a mix of both. I’ve got a friend, Keon Williams—I think we talked about him at a different time—who owns Class LLC. Sometimes he might come in as a security consultant just to expose different vulnerabilities and things to the CISO that’s in place, because that CISO might be so close that they don’t actually see all the vulnerabilities happening within the organization because they just got used to how everything has been done.
Keon might come in and say, “Hey, here’s the bigger picture, here’s some perspective that you haven’t seen yet.” Now you have an opportunity where you can make some better choices. He kind of comes in and says things that the existing CISO can’t. The existing CISO can take his report and say, “This is what an outside, independent, unbiased viewer sees,” without necessarily jeopardizing their condo in Florida.
I don’t know why I keep saying that. I don’t have a condo in Florida, by the way. My in-laws do, but I do not.
Manoj Tandon
Speaking of which, switching it up here a little bit towards the end: what new things do you have cooking in the world of podcasts? Is there anything you want to bring to light as of August 23rd?
Eddie Thomason
In the next three weeks, we’re going to a new podcast distribution style with the Leaders in Cyber podcast.
If you’ve listened to the show—because I was on here before—you might have come over and listened to the show when it was actually still the Simply Secured podcast, and everything was basically long-form content, much like you guys are experiencing here right now.
Manoj Tandon
Exactly, like 30 minutes to an hour, and you’ve got to extract the information along the way.
Eddie Thomason
What I’ve transitioned into is that, instead of doing one episode per week of 30 minutes, we’re doing three to five episodes per week that are between three to ten minutes long. It allows you to consume something very specific that you want to hear in a quick amount of time.
I’m very excited about it. I think it’s going to be a very interesting way for people to start listening to podcasts, especially in our virtual world where we’re not commuting as much. Maybe your commute is literally just up from your bed, brushing your teeth, and sitting at your desk. So if you can listen to something that can impact your day in five to ten minutes, I think that’ll be a much better way to consume some of these shows. But it’s a testing process.
Manoj Tandon
Well, Eddie, we’re wishing you the best of success. And quite honestly, if we see that—and we have no doubt that you will be successful—then we’re probably going to plagiarize some of it. If you guys see the format on Security Confidential change a little bit, you know who the root cause of it was.
Eddie Thomason
Everything is shared anyway, man. Nothing’s completely my own thought. I actually got this idea from a marketing podcast, compared to a cybersecurity podcast, but it completely applies to the way that we look at life today.
Manoj Tandon
Couldn’t agree more. Well, Eddie, thank you so much for being here, as always. It’s a pleasure. We know you’re not going to be a stranger. We’re going to see you back. We’re going to connect with you once your new format is a couple of months in and up and running. We’d love to chat.
Eddie Thomason
Absolutely, we can discuss what’s going on. Thanks again for having me, Manoj. It’s always a great time having a conversation with you. And I can see this, obviously—we talked about this the first time—as a continuation of the foundation of a relationship that’s going to be a good one for years to come because you’re just a fun guy to chat with.
Manoj Tandon
And you are as well. It’s great having you here; it’s always an honor.
Eddie Thomason
Appreciate it, my man.
Manoj Tandon
Take care.
“The Compound Effect” By Darren Hardy
“THE ENERGY BUS: 10 RULES TO FUEL YOUR LIFE, WORK, AND TEAM WITH POSITIVE ENERGY” By Jon Gordon
“Unlock Yourself: How to Earn the Success You were Born to Create” By Eddie Thomason
Article Mentioned
To learn more about Eddie
Check out the other episodes in Season 8:
Ep. 0 Dark Rhiino Team – Data Loss Prevention
Ep. 1 Boyd Clewis – Cofounder, Author, and Cybersecurity Speaker
Ep. 2 Ken Underhill – CEO, Author, and Cyber Life
Ep. 3 Dr. Gerald Auger- Simply Cyber, Black Hat 2022, and Security Awareness
Ep. 4 Eddie Thomason – Humility, Negativity, and Twitter News
Ep. 5 Zinet Kemal – Author, Diversity, Cloud Security, and CISA
Ep. 6 Derek Scheller – Cyber Warrior, Veteran, and Podcaster
Ep. 7 Ted Harrington – Hackable: How to do Application Security Right
Ep. 8 Kevin Tambascio – Cyber Professional, Cleveland Clinic, and HIMSS
Ep. 9 Greg Tomchick – Pro Athlete turned Cybersecurity CEO
Ep. 10 Brian Stoner – Remote work: Can You Trust Your Employees?
About Eddie Thomason

Eddie is a Regional Sales Manager at DataLocker, a bestselling author, and entrepreneur who has been featured on ABC, CBS, & FOX news affiliates.
Eddie has worked with multiple Fortune 500 companies to improve their revenue and was named one of the top business professionals by the Chamber of Commerce.
Eddie hosts the popular “Leaders in Cyber security” where he talks to cyber professionals about #InfoSec.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
