1.1 CISO Competency - Productivity

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

1 hour 2 minutes
Video Transcription
Hi, everyone. Welcome to 12 competencies of the effective C. So, competency seven productivity. With that Amoroso,
uh, looking forward to the session.
Take it away, Chad.
Okay, Thanks. Leave. Hard to believe we're already on seven, right? I remember
when we were starting thinking Wow,
such a long journey through the summer and we're on our way here. So I hope you guys are enjoying the material. This is the first time I've been through this material. So
But my processes, I I did an outline that I went over with leave,
and, um,
I get it. Sort of, you know, 50% where I want it. And then I spend the week before each of these lectures are trying to put together material either knew or stuff I have, but it's mostly new.
That wasn't so Let me know what you think. I have had a nice some ongoing dialogue with a bunch of you. You can just use my email. The amorosa, tagged as cyber dot com or
late leaf might have another way that you could be in touch with me, But look to you. Which think, um,
like I said, the first time you're through something.
I'm not sure which things play, which don't some of the material that I take you through you might find
right on the right on the money just bull's eye and others Summit May Mr Mark in. You'll have to let me know
when you get to be my age usually have decades of experience with material, so it's a lot of fun and new and interesting when
really creating fresh stuff. So
this, um, competencies on productivity And you've already noticed that we've travelled kind of away from, um, many of the things that we talk about day in, day out and in cyber security.
Um, we're talking more about the management activities. That's one of the
I think our Larry's toe. All of the a lot of the assertions I've been making here to you
that most of the attentiveness and building a career as a C so our asses executive in an enterprise team were just as I'm on effective manager doing cyber,
I really has nothing to do with the discipline, these air things that travel well across
other disciplines of year in the pharmaceutical industry or if you're in the academic community or if you are,
uh, you know, manager in A and a big telecommunications company, these these air skills that are useful. There was one of things that was interesting for me when I started managing as a C. So I realized
that all that goofy stopped like the
career tapes I used to listen to Now those would be podcasts. But I remember there used to be cassette tapes.
Um, and now I know now I collect podcast. Unless I still do all that stuff and all the career motivating stuff from the big speakers on big Giant,
um, stages in front of people pepping everybody up.
None of that really is is useful when we make fun of that. And, you know, I'm surprised at how useful it is.
The reason I bring that up is because the topic for today,
his productivity
as a security executive as a C. So
there's a few things you're gonna have to attend to let me list off and just give you an idea of what the time constraints are. One is you have to keep up with tech, period. You gotta find some way to do it. Whether it's during the day or on weekends. At night,
you have to set aside some time to keep up. You can't be a complete dummy
if someone's asking you about
different methods of machine learning. For Edie are something you better know. So you gotta keep up.
Second, you're gonna have to keep up with compliance issues. And I don't just mean compliance in the sense of
the letter you have from your regulator, but just general trends and compliance. Waterson issues and knows the GDP are emerges and somebody an executive position is asked,
um, how well does NIST map over to the GDP are you ought to know that,
um, the answer, by the way, is sort of.
And then management is 1/3 thing. You're a manager, so you have to find time not just to manage your team, but the hone your skills as a manager. Be empathetic to be
sincere, to be helpful, be honest. You need to learn
those as habits and our guest for today, somebody who's really, really quite good in that area.
When we get to about 40 somewhere between 40 and 45 minutes past,
I'll invite him on, and I think you're going to enjoy hearing from them.
The fourth thing yet to learn is the business. So if you are on Acme Manufacturing, you better learn what the heck you manufacturing, how you do it.
If you're in Acme Banking, you better learn how the bank works. The major customers are what
what's going on with the business units are how those business units interact and how it works and what the workflow is and what the
key assets are, what the priorities are for the sea. So
are for the CEO Rather and is part of that. I always made sure to memorize,
you know, a crib sheet of, um, factoids about the company because you'd be amazed how many times that's demanded.
You're sitting amongst other executives and somebody says, What was our revenue last year? You better know you get the point, so you gotta find time
to keep those things in your head. You also have to find time to learn to be an act and and and emerge with and socialize with other executives. You have to be an executive, which means it probably you're gonna have to learn to play golf or the equivalent in whatever the metaphor for golf is in your environment.
When I worked in Telcom golfing was something you did.
so you find time for that? You find kind of build relationships to have a drink with others to sit down with, um, toe listen to their story. To be somebody who is interacting is appear with others and company on Ben. Finally, you have to interact with the external community.
I've only just his career management. Um, because he says, Do ah have that problem that if there's an issue a lot of times the CEO of you, she was incompetent for any other jobs here out. So you do have to go to events and socialize
occasionally, talk to headhunters or whatever. Add all this up,
and that's a heck of a lot more than 40 hours in a week. And I know there isn't a person on this call. It works 40 hours, but you get the point. It's probably more than 80 hours.
So question is, what do you do? What are some skills that could be useful to help you
become more productive in the context of cyber security? I'm gonna take you through some of that today, and I hope it's useful for you.
Let's read our little sentences. We always do, says the effective C said. Develop strong personal productivity in time management, right time management being
an important component of that productivity equation. But not said tests that we're talking about here range from both the day to day be a you stuff
toe. Also emergency stuff. You have to be willing to delegate If you can't delegate, you're going tohave problems,
and I totally get
even that sometimes you're uncomfortable delegating and fury of the wrong team. It's a simple is that people ask me all the time they'll say,
I don't know. I have the right team that I've picked for this task or as my directs or whatever and the answer is the sentence It's here if you are willing,
And if you were in fact enthusiastic to delegate to that team and your threat, T Um, if not, then you got the wrong team. It's really that simple. There's not much more
to it than that.
So let's get into some specifics now that this first this is a book, the Auto Bag, A Tree of Ben Franklin so amazed how few people have actually read this.
I think it's one of the most spectacular books
on productivity of clear thinking. I'm just being an amazing person.
Um, I probably read this thing for five times through my own career, and there's two things in a highlight here.
Well, let's start on the left there. These 13 traits or virtues that Ben Franklin developed when he was 20 he wrote down and wished he did better.
And you can see them there. It's, you know, like just start like them. Seven. It's Don't be deceitful or hurtful to others.
Never be being sincere. Justice is important. Don't don't injure others. Be fair. You could see the don't be disturbed. A trifle kind of things, you know, bottom. Imitate Jesus and Socrates. These are the things that he said in his mind,
would be important to be successful.
Now, I'll tell you, I was at an event
about a month ago
and somebody had actually pulled out something like this, like a list of virtues,
and said something to the order that
without these virtues it's impossible to achieve any type of success.
I actually had to call the day out on that because that's not true.
Um, I think it's it's possible to achieve certain levels of temporary or situational kind of success. But I don't think sustained
Rio success is achieved here. And, you know, let's face it, there's some politicians
that you could point to, as
you know, not doing any of these things, you know, always being hurtful and deceitful, always wronging others always walking into extremes, always being disturbed. Trifles. I mean, you see that frequently.
So admittedly, it's a little difficult with young people when you show them this,
Um, they don't believe you because what they see in front of their face
is evidence that in all of this is a bunch of hooey,
and you want to get ahead than lie. You want to get ahead, then you know, be be mean and go after people take them down.
I think it's your job is an executive. I don't care who you are, who you vote for, what you do
to to try toe to dispel the myth
that these virtues are no longer meaningful. I think every one of them is meaningful, every single one of them and and what Ben Franklin did is because you picked 13 for a reason.
13 is 52 divided by four.
So he would basically divide the year into 52 weeks
and four times a year he would take himself through a little temperance kind. Of course, in his mind, he would focus on Week one, so January 1st would hit,
and from the first of the seventh, he would focus on not e overeating, not over drinking
and exercising Cem Temperance in the way he, you know, would would would deal with food and other things. And again, part of this was a metaphor for just being temperate.
And then january 8th to the 15th he would do silence. He would, And this is big one for May
like, I feel like I was talked too much and was cutting people off. So this is a trade or virtue that I always felt
I need help with. And he would do it through the whole year
and always think men
has been Franklin, for crying out loud. I mean, it's a man who probably accomplished more,
was more eclectic, and his interest was a Renaissance man who was just incredible. It's probably one of the
the great joys of being an American is two point back to the fact that Ben Franklin was one of us. And it's how he did it,
you know, by by doing this is ah, habit
Now on the right, this is his day. The look. It starts at five. In the morning
and it goes down until where he blocks out his sleep at 10 p.m.
Um, I think it's so cool is at work. He's got read works, put things in their place, the music. He lays it all out.
Um, evening question. What could have I done today?
Now you're gonna think this is corny. And if there's some people here who have worked for me in the past, you know, this is true.
But I've been doing this this thing on the right, This list where you map out, make sure
that you're planning the day
since I was 24 I'm 57 now,
I have all of these still stored. I have been in books in my office, in a cabinet,
and if you ask me what I was doing at 3 p.m.
On June 27th in 1987. I could tell you exactly what I was doing. I know that's very creepy.
Um, my wife thinks I'm nuts. I don't do it on vacation on weekends, I give myself a little bit of a break. Not totally.
I do this now. You don't have to do it. But I'm just saying
that we said the beginning to be productive, to be a sea. So to be attending to all these different matters
each evening, you should be thinking through
technology Compliance Management Business Unit's CEO slash working with other executives community externally with career, it's on their bread alone there's 123456 different areas that need to be attended to on a frequent basis, perhaps every day.
And then you disperse all the other nonsense you have to do. One of the reasons that I felt I was ready to retire
is because I reached the level as an executive where
most of the things that I was doing didn't seem to match.
Um, you know what? What, what I wanted to be doing that was more tending to things that struck me as being more administrative. And there's people who are wonderful that that better than that
better, Better I thin and then I waas So
So It's also a way of matching up. If they're others who control your day
and they don't match up with what you would like to or choose to do during your day, then you're in the wrong position.
Let me say that again.
You should be able to sit down and plan out what you would like to do tomorrow
without some external influence at work, messing it all up with things that you think are unimportant.
And if that's the case,
you're in the wrong place. That I didn't say quit. You know, I just said you're in the wrong place. I'm sorry.
If you have to stay where you are and that is your situation,
then you've got a dilemma. And and I'm sorry you're more grown ups here, but that's life.
If you're wasting your days and meetings and you think they're all stupid, but you have no choice. Well, then you're in the wrong place. But if you have to do it because you got a mortgage and kids and no options, well, then you say that's the way it is, that's just calling it like it is.
But the beauty of what Ben Franklin teaches us here
is that you really ought to take control of your day. And you ought to take control of these virtues. And you should do it diligently every day. Justus. Someone might go to the gym every morning,
you know are gonna work out from time to time or take a walk or do whatever it is you do or meditate.
this is something that's absolutely essential for you to be a successful executive. I I do not know
a single executive
who doesn't do something like this.
Um uh, who would not attribute this activity
to whatever success they've had. Your chaotic. You don't do this and you wander through the day.
Then again, it's I believe it's temporary. As a young man, I read all of the Donald Trump books. I loved Art of the Deal, a book that actually had a lot of
influence on me. If you've never read it, it's a spectacular. But,
but I remember reading that Donald Trump says he didn't do this thing on the right that he didn't plan his day and just let things happen always struck me as confusing as long before running for president. So it's so funny that
he he would be an example of somebody does none of these things. I'm again. I didn't say that's bad. I'm just saying that I don't think
that that's the way
you should manage your executive activity. I don't think it's a good idea to be C cell and say, Well, I don't really don't plan anything tomorrow What do you see? What happens?
So take a look at this. Yeah, if you haven't read the autobiography of Ben Franklin, read it. It's a wonderful book, and I also think you should read art of the deal. I think it's maybe the contra
to this and see what you think. You should adopt some sort of an opinion around this.
Now, let's take something specific.
Um, these air charts now that I shared mostly with more junior folks around GRC. But I think it's an interesting case study and manual versus automated work activity, and I'm going to go through fairly quickly. But I'll show you what, um,
what is all about? You guys know that when you've got a J R C tool like Archer Metric Stream or something. Um,
the first step is that you've got to get your policies into those,
um, tool into the tool
and it and on the right here, you see my little scale, my automation scale. I would say nothing is our productivity sale. Nothing
is less productive
then doing manual data entry to a G r C tool. Good Lord. I mean, that is about as unproductive and activities you're ever gonna get. Thio. So this is a case where security team and executive team or whatever is not productive. You're banging out numbered assertions from your policies into grc tool.
But then, after that, once you think that thing into the tool,
you can download a framework
and map it up against the thing. Now granted, you do back here, you doing manual sort of mapping. But once you've got,
say, the NIST framework or something in then all of a sudden your coat, your productivity goes way up because now you can do certain types of gap analyses and other sorts of things that, you know, lay out. You know what you've got now? Let's say that your corporate requirements are six character passwords and the framework is a
on. Let's say that the corporate security requirements are you must prove critical access. And the framework says you do all.
So now you got to do something about that. So, you know, you see six to a critical tall. Well, the first thing that one with passwords, usually a security team can just kind of do that.
You can just, you know, demand that it be done, make everybody kind of buy in. Um, not gonna be a lot of pushback. You're just gonna be doing this, Maybe some,
but it could be reasonably automated manual balance there. You're gonna have to
get the word out, everyone that it's changing. But you can usually automate the changes. Hearing be reason productive. But this next one going from managers must approve. You know, where we had before critical access requests. And now I want it to be all access requests.
Well, that requires that you deal with the whole company with their change business processes. Go give
pitches across the company about why that has to change. You have to update workflow. You have to.
You know, modified compliance documentation. Unbelievably non productive stuff again. Low on the productivity scale. So you see the point like you're doing these things. Some are very productive, some or not, and the automation many cases dictates the difference. So let's say you have one framework in, and now you drop a second framework
which again is very automated. That's the beauty of the GRC tool. I can drop like P C I N
and let's say PC I requires complex
and I've got a
and let's say it says critical. And I've also critical and all be good because all subsumes critical, but does eight subsume complex so the framework drop is automated. But now the paperwork
to go back and changed if you just decide eight is complex. That's good enough.
again, you're not productive again. You get the point that you're going back and forth between automated tests that go very quickly and manual test that take forever and automated tests to go very quickly and manual tasks it take forever
and sadly, for compliance. Look at all this stuff you gotta worry about. I just This is a no older chart, but
you know It's got a whole bunch of
stuff in here that most companies have to attend to the whole. You know, there's a subset here that I suspect are going to be important
for your company, and most people would start with mist, have to deal somewhat with G P R. And there might be others. If you're in government, fisma is important. And if your public company servings oxidize and force you get points,
you got to do all this *** for all of these.
So good luck being productive again. You better delegate compare of some teams that can do this for you.
Um, and if you have a little tiny team and you have to deal with this thing, you got to be good enough to go get some more. Resource is because you can't do this all yourself.
If you do this, then you're not keeping up attack. You're not keeping up with management skills. You're not working with the business units to learn what they do. You're not out attending things to interact in the community and develop skills and tips and ideas from your peers and on and on and on on. You can't just do this,
you have to find a way to be productive. Get the point
Now let's do our usual do's and don'ts. I like to start with the dotes. Now, this isn't buying. You should pay attention here.
These air tips that Here's what I'd like you to dio as they go through each Don't
you know? You know we're not in class here, so I can see your face. I'm not gonna make your raise your hand,
but in your mind, be honest
and keep a little crib sheet and see which of these don'ts things you shouldn't D'oh! You actually do. Dio.
Let's let's see how you do it. We'll do the same thing for the dues. So the first don't is this one
Don't demand to be copied on everything. Now that feels a little weird, right?
Like, uh,
you mean my managers are, you know, interacting on something and not copying me. And my feeling is
because if you're copied on these things, you're gonna feel obliged to chime in.
Um and that's not delegating. That's, uh
participating. And you're going to slow things down. And there's the Heisenberg principle. Here is well, that by including you on the email exchanges. You slow everybody else up.
So things. The first thing I think you should do. If you do this, then promise me that you're gonna get back to work and you're gonna go to the team. You supervise. You gonna write him a note and say, from now on,
um, I don't want to be copied on all your email exchanges, Just things that you think I need. And don't say it's because you're not interested, you say, because you want to let them do what they gotta do without you mucking in.
Um, you know, mucking in the soup, get the point. So that's number one. Here's number two.
Don't extend meetings to be synchronous meeting if you have a meeting scheduled from 1 to 2 and it looks like you've completed everything by seven minutes after one,
then finish the meeting leave.
I have people that I've worked with in my career
who still will joke about the fact that I
you know that I I mean, I don't do this.
They were don't extend meetings to the end
makeup. See, some folks there in a bar somewhere are hears that and Then they let me tell you something about Ed, man. We we would have a meeting at two o'clock
three minutes into it. If it looked like we were in agreement, we were done and we might have set aside a whole hour. And I was like, Are you kidding me? That's that's
that. Is it that rare that people do that
and I get that? Yeah. In many cases, you have to sit here, but it work from eight until five.
So if you have meeting from 3 to 4, it's more fun and interesting to be sitting in the *** meeting from 3 to 4 than to be done. Go back to your drab little cubicle.
If that's your existence and I recommend you quit tomorrow, go find something else to d'oh!
But developed the habit
and the
persona that when a meeting is done, it's done.
And if it finishes early, great. And don't make that little joke of me to give you 10 minutes back, you're not giving anybody anything.
Just when you're done, you're done and it be great to be finished way before
somebody you know had had planned an hour for your meeting.
Here's another don't
when you treat meetings and then that's a typo. It's is at an end. It should be as a s and then treat meetings as in don't. So don't treat meetings as an endorses me means that if the meeting is the purpose of the thing,
you got a problem in government. Does this all the time? My God, Federal government,
you know? Hey, what did you accomplish? Where we met with such and such? And there we go.
What do you mean, that's That's not accomplishing anything.
Fact that's on the negative end of things. A meeting should be booked on the
the other side of the ledger. Meeting is a cost. It's not an asset. So many organizations that view meeting is the purpose of your in sales, for example.
Then you go back and you say I had a meeting with this person meeting with that person made with this person Who cares? Just sell anything? No, But if you care, so you had to meet you.
So don't treat meetings as an an versus means.
Um, there's another one that your email, um,
you have to learn to make a shorter
and and that includes accepting, like if somebody send you along the email on your team
and you're gonna have to sit there and peace through it,
I think it's perfectly reasonable to bounce back to them and say, Listen, I could you do me a favor
You wrote me a 1000 word email here is too much in there. Can you go through and just pull out a little executive summary so that I can understand it?
And you should develop a habit of helping people understand that you do that for a reason.
If you're like me, you've got about 150 to 200 e mails every day
and do the math. If you spend one minute on each one, that's 200 minutes. That's, you know, three over three hours doing email,
so every evening from 7 p.m. To 10 p.m. All but there's a lot of people on the skull all you d'oh from 7 to 10 instead of being with your family instead of reading a book instead of going to an event, you're sitting there banging through email that people wrote that in many cases you shouldn't have been copied on
and it was way too long in the first place.
So let's see if we can do something about that. And then finally,
it's a curious kind of
habit that I see in business
that I almost can't believe happens.
And that's a prep meeting for a meeting.
Like I get that. Sometimes you have to do that. Like if you're gonna go meet the secretary of State, you won't have a meeting to talk about what you're gonna cover on. All right with that.
But sometimes people are doing meetings remains like it's a status meeting, and you do a status meeting to go over the status to go over at the status meeting. Are you kidding me? Mrs Dilbert? Stuff I. I had the good fortune to become friends with Scott Adams, the guy who writes the Dilbert cartoon.
The delightful guy so talented.
Um, hey, he says, when people send them these crazy stuff in one of the funniest things, he gets his stuff like that. We did a prep for a prep for a proper, but there's people who have done that. I bet people on this call have been a prep meeting for a private meeting
for a meeting
and and I can't think of anything that drives you into the productivity sludge more more, more readily than something like that. So now let's do some dues.
So again, on your crib sheet, I hope you I hope you wrote that. I don't do any of those things. But if you do, then stopped here. Things I want to see. If you do these, tell me if these were things that you do, you don't tell me. But in your mind,
the 1st 1 is delicate, says number one.
And when I mean delegate, I mean
Like when I come home from work,
my wife happens to be a gourmet cook. It's her favorite hobby. He has a very nice, beautiful kitchen that we don't for her. It's her delight in life
and she cooks. So I delegate the cooking. What that means is, I really delegate. She decides what we're eating. She cooks, She shopped. She puts it all together. I walk in. I say, Honey, how are you doing? Like a kiss. So sit down while she's cooking, we'll chat.
I've delegated it. I'm not. I don't say, Hey, you really shouldn't have chopped something that way
or, you know. Hey, what'd you do this for? You know, let me let me have that. I'll show you how to do that. I don't know any of that. I'm delegate means you're delegating.
So to your direct reports and in some cases, to others, you need to be doing this. If you don't, you get the wrong team. It's a simple is that you're uncomfortable delegating of the wrong team.
cancel meetings If there's nothing to cover.
that always seems like something that people don't want to dio because they're afraid that their job will seem
less important. Or if you're serving a sponsor or customer
and and there's a regular stand up meeting to go over things,
and you're afraid that they're gonna think that you're not providing good supports, you make a bunch of *** up just so you can have a meeting.
Um, don't do that. And again, if you're in that environment and it's demanded, then you're in the royal bad environment and you fix it or move or something.
But you should feel comfortable canceling meeting. It's there. If there's no purpose, for it
is going to put away your phone during discussions. You know, people do that weird thing where you put your cell phone
on the table face up during a discussion.
I don't know if you realize it, but when you do that, you're elongating the discussion because you've made the person you're speaking with, aware that there is now a priority interrupt mechanism. You know, like on a CPU
that is sitting there and occasionally it'll buzz you both paws, you lean forward, you look at the phone, and there's some probability that you're going to either dismiss it or say who I'd better get this.
And furthermore,
you know what a disgusting concept that that priority interrupt might be more important than the person you're speaking with. So my advice is, if you want your discussions to be shorter,
more productive, more compact,
that put the *** phone away, have the discussion and take the phone out. Unless you are a heart surgeon
and and you've got a patient who is, you know about to commit, you need to be ready on the dime. I get that and we all do into the response. You know, I understand there are mitigating circumstances. But most of the time
you put the phone there, and the *** that comes up would be, ah, notification that, you know, the Yankees air over playing the Red Sox in London. Or that
some movie star somewhere, you know, just divorced her husband or some cookie *** that pops up and use you. You take your attention away from the conversation and lean into that. Give me a break.
Um, take good vacations, air currents that your team to do. So I think you need to demonstrate the people that,
if you're the kind of person says I can never leave,
then that means you're not delegating if you're too. If you're afraid to go away from business than
you don't trust, your team sends a message. When you take a vacation, you should go. Should not have to check back in every two seconds.
And you should encourage your team members to do something very similar.
And then, finally, this may be the most important role of the executive, something that I always took very seriously. Still, take seriously now with my own team, try to buffer them from the time wasters,
so if you're being imposed some time wasters being imposed on you
and see if you can buffer your team from that nonsense. Like if your boss demands weekly status and it's just a bunch of nonsense,
don't cascade the weekly status to someone because then that someone has to do it. It has to go to you. You have to review it. Every hop on that path
makes the whole process less productive.
If you could do the weekly status, then *** it, just do it. If you Condell a gate, the weekly status to somebody where you don't have to be involved, that's equally productive.
But stay away from these time wasters. They really can destroy the culture of a team could bring everyone more or less to their knees.
Now, the last sort of picture here is something that's very meaningful to me.
Um, before we get to our case study, I had the good fortune when I graduated Undergrad. Uh, well, I went to Dickinson College, and Carlisle studied physics. Their little small liberal arts school
way had David at Borough
as our graduation speaker the year he did the movie on the Move big epic
film on the life of Gandhi.
So for about a week, we all watch the movie and went to seminars.
I became very taken
with, um, Mohandas Gandhi. And what a credible man he waas Amazing leader and probably
a man who understood symbols more than anyone.
Like as a chief information security officer.
You're in a
sizable position, you're in executive and they're people who come in on the pen testing team or on a compliance team or
a group of folks that are doing some scanning or whatever. And they view you. You might as well be the king. You're so high up
and it's the symbols that matter like this. This morning I came into the office
when I call in to the office and I say, Hey, what's everybody want for lunch?
And I get the lunch order, you know, whatever it was today, 12 sushi balls or something,
and I go over and I get wait line and I get it. I bring the bag of stuff
and I hand it to my team. We pass it all out and I'm the boss and I went and I bought the Munch. Why do I do that? I do because it's assemble. They do it because I watch Gandhi sort of do these things, and I know
that it sends a clear message to everyone. That the boss is is is acting in a certain way. And Gandhi was perfect around that. But the reason I bring him up
this is nothing new productivity. But look at the picture there. What do you notice that's unusual about Gandhi in that picture? And I bet you've seen 1000 pictures of him.
But I'll bet you've not noticed what I'm pointing out to you now. What's right under his left hand There
there's a lot a watch. There's no clock.
And Gandhi became well known for that. That watch the fact that
he believed that
as well as temporary, insa as well a sympathy as well as kindness.
But punctuality was something he was obsessed with. How funny is that, right? Who thinks of Gandhi is this dude who you know, was worried that he was going to be late for a meeting,
you know, but Iwas that was part of who he was and and he would talk about that. I am grizzly like even a
a museum somewhere where they have that watch. It's like probably costing $10 billion to buy that watch. I don't think it would even be for sale,
I would think it's disrespectful
to not be punctual and productive and get things done. When you when you do that, I think you disrespect your team. It is your responsibility
to get things done to do a punctually toe, have a plan for your day and then all those other things, like all those virtues we started with with Ben Franklin.
Boy, I'll tell you, there's no no person maybe who's ever lived
who embodies most of those wonderful virtues. Is Gandhi just kind,
very thoughtful Guy caught up in some interesting
times. You know, the different religious debates going on in India, Pakistan so so fascinating stuff.
And I know a lot of you like me
when the engineering schools, you know, I have a degree in physics and my PhD in master's in computer science. They don't teach you
political history or philosophy when you're studying atomic, a theory and calculus and physics. I had that problem
and a lot of you do, too, so you do have to go back and build your your your knowledge based by reading things like this
because I think they make you a much better manager. So So let's just summarize before we get to our case study.
Being productive is about being a better person. It's about
temperance. It's about punctuality. It's about thoughtfulness. It's about delegation and trust. It's not about being this obsessive
banger out of work. You know where you just put the hours in and you crank out the work like if the word crank
just part of your productivity equation, you got it wrong.
It's It's different. It's trust. You want to be productive. Trust is probably the most important word. And the little clock there, too, because I ieave you know me.
You know, I'm going absolutely nuts when I have a meeting with somebody in there 15 minutes late. I'm not because I'm not antsy, but it just embarrasses me that they're doing it
like it strikes me that I'm witnessing a shipwreck
when you're 15 minutes late for a meeting. It is a shipwreck, and I feel bad for you. And people always get on my head. I'm so sorry. And I would say, Oh, no problem. I got some email done. Some was trying.
You know when? When somebody you know spills coffee all over them, you try to make them feel just fine. It's fine. I was trying to do that, but in Vermont, my mind, I'm thinking if you don't fix that habit, you're gonna destroy your career because disgusting habit
to be late. Um, not only because you have the productivity
kind of implications, but also because I think it's just disrespectful. So So, from we sweep of the book ends here around. Productivity are two things that I suspect you wouldn't have expected. You know, we start with Ben Franklin would finish with Gandhi, and they're both really truly wonderful
human beings. Make sure makes me,
hopeful for our species. Now, the productivity case study here was a fun one too, right?
Because I've seen it happen.
Let me let me summarize the case study
and I won't be read it. But if you haven't, you know I can give you the essentials here, and you tell me what you think. And again, I hope you take this back to your team.
So what happens is again our hero Emily is taking questions during the event.
And, um, it's funny we were in Week seven here, and this is Emily. Seventh question. You're probably laughing thinking, but that's a hell of a meeting. Emily is that you get these tough questions, but it gives me an excuse to write the case. Studies just every writes and says, Hey, you know, Is it okay
for somebody who's really, really, really, really, really smart
and capable and comm bang things out to be treated differently than others? That's sort of the general question on what we have Here is a young man named Sanjay who works for her in her business,
and they think the kid is a genius, like I haven't deriving Maxwell's equations on a white board. The reason I use that reference I remember Bob Morris senior when he worked in the labs. He was the team lead on the project. I was working
a unit's security project, and at his going Away retirement luncheon,
he was going to work at the at N. S. A. Is their chief scientists. This is before
the Mara swarm his sons. I remember because I was one of the younger people there.
My supervisor's Terry Hart asked a NASA astronaut,
um, Czar, Supervisor. He said, Where's Bob? You know, we're all in the room. Knew he disappeared
and he said, They said, Ed, Go that I got sent to go find him in his office. When I went to his office,
he was standing in his office and he was writing equations on the board. I said, Bob, we're gonna like, blow out your cake here. Would you like to come and have some cake?
And he goes, Ah, and I said, Well, what are you doing? Because I'm deriving Maxwell's equations and he was doing it on a white board like the ultimate guy who just did not not want to be at a party eating cake, which is odd because he was a very friendly
and sort of, ah, gregarious persons. But whatever reason, you didn't want us to be in the party, and I managed to cajole him toe,
put the pen down Italy. But ah, lot of the references. When you see me writing these things, I put those little Easter eggs in, and maybe I'm the only one who notices it, but it makes the writing so delightful for me because I can put things in there from my life.
But at any rate, I have this kid's Sanjay being really good
at the present because I was late for work and he doesn't show up and as a kind of annoying
and then and, you know, Emily would say it says, you know, I spoke with him at this, and each time I said something, his behaviour would change, and then it would soon come right back again, missing meetings late for work,
and everybody's kind of, you know, you know how that issue. You know, that person at work? Well, amidst that, um, Emily had, ah, young lady ask if it would be okay
for her to take three weeks to go back
and visit with her family in India,
presumably for a wedding. You know, uh, I've never been to a wedding in India, but they sound and I got a hell of a lot of fun. They seem to go on for a long time. So she wanted to go, and he and she said, Well, look, you only have one week vacation. She's very disappointed that she could always go only go away for one week, but she accepted it well around that. Time is a
big problem in that
some project and,
you know, something had to be done quickly, and there was a team off figuring out how to do it. But Sunday comes in like literally over weekend and bangs the stuff out so quickly and so perfectly and delivers it to the C i o. Sort of sidestepping the whole process. So the team that had been planning it
looks up, and Sanjay had it all done.
So the c i o. Is beaming. You know, she doesn't care that,
um, you know, whatever. You had a process. And maybe there's some hurt feelings, not my problem. This stuff works perfectly,
and everybody gets called into the demo. Sanjay says the software works great. It's perfect
and just a TTE that moment, the CIA says, I'm listen because this is such an amazing job, Cygnus, all this work,
Sanjay mentioned he wanted to go visit with his family in India for three weeks, and I said, of course, and I want to wish him well, and everybody claps and Emily's there, along with the young lady that she just told, couldn't go to India for three weeks. But now Sanjay is gonna go blah, blah, blah, blah. You get the point.
So Emily says this is not good. So she calls a meeting.
I invite Sanjay to come. He does come there on the room. She walks into the room, closes the door. It's her team it Sanjay. It's the young lady who she said couldn't go to India. It's everybody else,
and that's where I leave the case. Study off.
You know what does? Emily said.
What does she do?
And it touches on productivity because we tend to reward
the deliverer herbal
right? We tend to say Who cranks it out.
Who gets it done. If you work in sales, it's what do your numbers?
You sold $18 million with the product,
and this other person sold $375,000 worth of product.
Well, guess what? I'm going to reward you and not this other person. Never mind that. Maybe the $18 million you stepped on everybody's heads to do it. Maybe allied and maybe did all kinds of horrible things, but I don't care.
You sold 18 million bucks in the 375,000. Well, maybe we're given a bum account that had to be done and that 3 75 might grow in the future into 70 million
and may be required that you do some extraordinary work. But I don't care.
It's the result.
Ah, so productivity and output are often viewed is synonymous. So So the discussion items. Have you ever had somebody like Sanjay and your work group?
How do you feel about somebody side stepping
a process and just banging something out?
Do you think it was reasonable for the CEO to call that demo and thanking everyone without really consulting Emily?
Um, should Sanjay be allowed to go to India for the extra weeks
and what would you D'oh! What would you say in that meeting? You just close the door. There's your team there, Sanjay, there's everyone. What are you going to say?
to the wonderful world of management, executive management, those thes air, the kinds of things that
you need to think through because this is exactly the kind of thing that happens on a somewhat regular basis dealing with this and again
earlier, we talked about Ben Franklin and we talked about Gandhi.
You should close your eyes and think if I was Ben Franklin what I say, Well, what would I talk about? You might come in and talk about the virtues of team
and you might start by. I'll tell you what I would do. I would start by congratulating Sanjana Very good job done, at least in terms of the productivity, the output, the work that was done. But then I would have a very large but comma.
And then we would talk about the virtues of team
and how important it is to work together and how much it means to all of us to be a team rather than a group of individuals blah, blah, blah. But that's what I would.
But you have to develop your style.
So if that's useful again, I hope you take that
back. Now, this little funny cartoon year I've got a guest here that's been a friend of mine for
a number of years now. I think he's an absolutely wonderful Ah person manager, executive
business leader.
His name is Mike Stang. Go and I'm gonna just say a couple words about him before,
ask him to share with us some of his experience from working with. He says he and I were part of a new event that his team at Security 50
which is part of World 50 had put together and a river.
Madeleine Albright was the, uh, was one of the speakers at the event, and we've done a cartoon for her rich pal and I do the Charlie see so serious that I know a lot of you read
and Mike was kind enough to let us commission something. So we wanted to do one for Mike
and you know why we did one And Mike's Last name is It wasn't His name is M I k E e Mike. And then his last name is S t a N g o.
So we made the first frame a manager looking at expense, presumably, for like a world's 50 bill or something. You you've gone in your
you're paying World 15 and would have said, Mike's tango is a point of contact, and I have the manager saying, What's this expense for Mike's
And then Charlie goes now, dude, you know what? Mike's Tango. It's Mike Stang go from world 50.
That's what the expenses for. And then in the last panel, we have the manager saying, you know, I care who it's from. We don't pay for dance lessons on Duh.
And we frame an unusual picture. My friend Mike, who's who's on the line with us now.
Mike, I hope you weren't mad that we, uh, put you in a cartoon. I hope that was okay. We certainly enjoyed
doing that for you again. I hope that that wasn't
too tedious, Frito to be the star of our car too.
Do we have my con? You're on my
leader. Can you hear me? OK, OK, I can, Mike. I can hear you just fine. I was just saying I hope you I hope you enjoyed being the star of the cartoon back a couple of months ago when we did this.
But I think we lost you again. Mike, can you, uh, whatever you were doing before we heard you. Now
you can hear me. OK? Can Yes. You're coming through loud and clear, but well,
no. I much prefer to be the frame rather than the picture. But everyone in the office really enjoyed the comic strip here and sad to say, I still haven't learned how to tango yet. But thank you so much for the opportunity.
Mike, I want you to take a minute and share with the group here. This is We've got a fairly large group here,
folks who are
either mid or latter portion of their career who have in their career plans
to become ah see, so are a senior executive in our business and, like you work with an awful lot of them. Share about security 50. And then I've got some specific questions related to some of the habits and traits of some of the more successful he said you work with, but just briefly tell us about your work at Security 50.
Yeah, so as you mentioned early on, Security 50 is a private peer to peer organization. We're under the umbrella of World 50. So if we imagine that the top pieces in the world and top chief marketing officer of financial officers we basically have these communities of practice and
we have to call it that the Fight club for si SOS, where everything stays in the organization Chatham House rule,
where is really just some of the best leaders in the world trying to help each other to become better at what they're doing. And we really focus on some of these leadership aspects and less around the technology. But more just around, what is it that helps you to be a better leader, more effective within the organization
internally, with a colder management
externally being a true business enabler across the organization? So really try to do that in fun and interesting ways, and not just from the standpoint of helping them to be better security executives or technologists, but
better leaders in life as well.
Well, I think you run one of the finest programs I've ever seen. Bar None, and you personally
are one of the finest leaders of of, uh, executives I've ever seen. Well, I'm no Casely prone to hyperbole, but
you really do a great job. Now. We we deluded earlier to these
personality traits, you know, we started, You know, you may not been on, but we're talking a little bit about Ben Franklin's autobiography, things that he thought about,
um, to make him a better executive.
Sometimes it's a little corny, but I've always wanted to ask you, Is it corny for executives to make a list of things like
be listening and being temperate and being sympathetic and being friendly and being thought? Our eyes that just a bunch, according nonsense? Or has it been your observation that people who actually embrace that tend to be more successful than ones who don't? What's been your observation?
Absolutely not corny. I'm even going back to punctuality with Gandhi there. I mean, I think that's all applicable to
the sea. So some of the most effective one, I would say. I've seen a lot of chief information security officers
somewhere, always rushing around hair on fire, whether they're looking at their phone constantly putting out another fire.
But perhaps the best, he says. I've seen, I think this goes for any leader. They always seem to have time for the person right in front of them, and they're truly present. And this goes for individuals like yourself. You always had time to talk to the people that you run. They're not distracting or rushing from meeting to meeting.
It's almost like the doctor's office right
the doctors are running 45 minutes or an hour late for every appointment and running, meeting to meeting, like, you know how many patients you have that day? Why wouldn't you just pad your schedule to accommodate those meaningful conversations that you know we're gonna last for more than 29 minutes? 59 minutes.
So I would just say you model the behavior at the sea. So for your organization, if you're going around with your hair on fire or being the person that can just pick something in a weekend, you're setting that example like a Sanjay that that's acceptable behavior to just be a rogue individual contributor.
You know, Mike, we were talking earlier about some of the counter examples The things that I've learned from you
and that you and I have both observed in successful C says We see it in business. We see definitely in politics
where you see these rough and tumble types who,
you know, a very confrontational and non sympathetic and, you know, just kind of roll over. Anything in their way is you all can think of business leaders who done that.
But, you know, did you ever find yourself in conversations even either over a beer or during it. One of the fine discussions You lied at Security 50 where people debate that point like, How is it
that some people seem to violate some these personality traits that you and I value and yet can still seem to get ahead? What what's the How do you explain that paradox? Or can you explain the paradox?
I think I think it only gets you so far. I mean, some can get to the highest levels of of their organization. But I think in terms of truly becoming an enabler of the business or a partner to business owners or risk owners across the business,
you want to have people that
you can count on in a crisis.
You want to have people that really represent the best of the organization or in a true alignment with the mission for that organization.
So I think a good example have, ah see so in our community, who is a former U. S. Secret Service agent
And he was telling a story back when he was a Secret Service agent, and they were on the tarmac with a plane fully loaded with some major dignitary. Terry's on the plane
in order to move from Point A to point B and do what he needed to do. He ran.
He just ran across the tarmac.
Now did he get there faster? Yes, but did he just alarm everyone around him?
and basically go counter to what they needed to feel that level of safety. Everyone thought there was a major situation, So when he got out of that, he learned right away, like
I do not need to run. I need to walk from Point A to point B and even take that into the board room with him, where
the when he tells his story of security or has the conversation with the board members, It's always a low, confident toned that measured that's trusting. They know that in crisis mode, this will be a measured individual that they can count on.
I think we need to do that. It calms you down anyway. I think there's something to
if you want it. If you want to become the knack calm. If you want to be confident than act confident, there's something to that
and I think that over time you learn that. But Mike, I want to ask you about community and and in particular external community. You do as good a job as anyone I know in helping to foster relationships between security folks that work in different businesses and different industries, different levels of their career.
How important would you say? Is it for the people who are listening here?
Thio two maybe recognized that at some point it's going to be more than just that inward focus around the company and that at some point you need to recognize you. Not only should be part of a community is your benefit, but I would even dare say maybe oven obligation to contribute to the community. What do you think in that regard? What have been your experience with
building and running
Uh, my experience is even talking to pieces on the phone earlier today. It's a very lonely job, and unless they're constantly seeking that outside perspective, not just within their own industry but
other industries. Whether you're in telecom, you need to talk to energy sector or financial service is which may have
more mature operations, but you want to hear from some consumer product goods or retail or manufacturing environments, where They may be doing more with less in certain situations, but it's a very lonely position.
And if you're going at it from an internal perspective, what you've been in your organization for 10 years is like That's just the way that things work around here.
I'm having trouble pushing this up the hill.
You're stuck in a situation where you're looking at something myopically and just need help reframing the problem.
So being able to talk to appear and whether it's another chief information security officer or whether it's someone from a different feel the CFO, our chief human resource officer, or just someone else out there in a different industry,
they can be great sounding boards for you to just help you reframe the problem and look at something a different way that if you were focused internally and had your head down, you're not gonna be able to come to the same understanding.
You know, Mike, for people who might have some interest
in getting involved in what you d'oh! I have a feeling I'm going to get barraged with the notes from people saying How'd away
get involved, helpless and just sort of is a closing thought there. I suspect somebody who just left Stanford and just started work on the scanning team at the city.
Probably not the type of person who would join a security 50 to share with other executives. Do you not an executive, but kind of win is the right time for somebody to be thinking about your type of group. And when it is that time, what? How logistically would they go about getting in touch with someone like you?
Yeah. So, ah, lot of our organization is sea level C minus one C minus two level. So maybe director to VP, the senior VP and beyond a sea level positions.
But we do a lot of program leadership development for those next in line, perhaps like a deputy. See, So, um, or someone who's who's the head of a stock who's looking to go into the next level of their career? We we do a lot of cross functional leadership development because,
as you're even thinking,
you can get too focused in one, particularly whether it's the technology or just one aspect of the role itself. You need exposure to some of the best leaders in the world and That's what we try to dio expose them to true practitioners like yourself who have been battle tested.
Been there, done that and just share your story.
It's just one of those where it's like
whatever got you to wherever you are
in that organization at the next level,
you need a different skill set. You need to approach it a different way. It's not necessarily the same role, just amplified to a degree, so that's really where we focus. It really is a wonderful program. It's helped me immeasurably. You guys have must win the award for the most sparse website ever.
It is. I guess there's probably an intro ad or contact hat or something like
that on the website. If someone wants, would it be World 50? Is that with issues? Yeah, Or you could just feel free to share my information with folks on the line Here is well, and it's just mike dot tango at world 50 dot com, not Mike Tango.
We had better reserve that we're gonna have to find
Hey, Michael, Listen, uh, you're so kind to join. I wanted people to hear your voice and hear a little bit. About what you do and
and just also get a feel for one of the benefits
of getting to the point where you become a C or C minus one executive you get access to programs is
as great as from world 50. So, Mike, thanks for getting on and sharing a little bit with our community here
very much. Appreciate the opportunity. And thanks for your men to worship at as well. You bet. Well, listen, everybody, that's Ah, that's our seventh lecture will be back next week with number eight.
Um, keep the comment rolling. And everybody have a really wonderful week and we'll talk to you next week and leave. Thanks for setting up this week. We'll seal.