Stop Chasing Shiny Objects - Dana Kilcrease - Guardians of the Data - Episode #51

GOTD - Dana Kilcrease
===

[00:00:00] Welcome to Guardians of the Data. I'm your host, Ward Balzerzak. Each episode will explore the passions, expertise, and real-world experiences of security leaders who are helping the future of data security and governance. Guardians of the Data is made possible by support from Sentro. To learn more about our AI-powered data security platform, please visit sentro.io.

Let's dive in.

Ward: Welcome back to another episode of Guardians of the Data. My guest today is a seasoned cybersecurity builder and leader with almost two decades of experience. He's built security programs from the ground up for colleges and nonprofits, and is currently a CISO in higher education. Dana Kilcrease, welcome to the show

Dana Kilcrease: Thanks for having me. Glad to be here

Ward: Oh, glad we finally, finally made this happen.

We saw each other in person. We've talked about it, and here we finally are. You are a busy, busy man

Dana Kilcrease: Yeah. It kind of goes with the territory, right?

Ward: Absolutely. Absolutely. So Dana, in your [00:01:00] professional opinion, what is the biggest data security challenge organizations are facing?

Dana Kilcrease: So I think, um, you know, so the easy answer to this is gonna be AI, right? This is what everybody's gonna say, and then that's kind of the overarching theme that, that's kind of stretching across everything right now. Um, but maybe digging in a little bit deeper, I think I would say probably, you know, velocity, right, is really that underlying thing that's happening, where all of the security issues that we've been facing forever, um, the speed at which we're, we're forced to address these issues has been increasing, uh, you know, as AI's come onto the scene. Um, and it's really amplified a lot of the gaps that we've always had, right? So whether it's, you know, just issues with tooling that we've had, to maybe we don't have the, the proper exposure to our boards or other things of that nature, right? So anything that we've been dealing with for a long period of time, all of a sudden these gaps and these technical debts are just growing exponentially, and it's difficult for us to keep up, um, because the resources [00:02:00] aren't growing along with the threat, right?

And they're not growing along with the technology

Ward: It, it's not, it's not a linear model between the two. They're both growing exponentially. I, I wish.

Dana Kilcrease: know, and I, well, I won't, I won't say this is a universal thing, right? I, I am lucky enough to know people across many different sectors and verticals and, and some have kept up with the technology, um, and, and have the budgets and the resources to, to run at full speed with it. Um, but for the other, I would say probably 75% of us, it, it has not kept

Ward: I would agree with a lot of the conversations I've had for, for sure. So Dana, like, I mean, yes, absolutely. I, I think that's been a commonality though over the years, right? We, I think every year we said, "Oh my goodness, like velocity, we gotta get..." I, I think it was the opposite though. We gotta get faster. We gotta patch sooner.

We gotta do these things sooner. And now it's everything is moving at hyper speed, uh, to include in some cases security tooling to, to maybe [00:03:00] assist. Maybe. Um, so from, from your perspective, what can we do about it? Or, or what are you looking to do, or how are you advising others to try to keep up?

Dana Kilcrease: I've taken the approach of taking a step back, taking a deep breath, and really focusing on the fundamentals, right? What are those, those first principles that we've always had to deal with? Um, and, and really making sure that we're, uh... It, it's very easy to see the shiny new thing and have to follow that.

but for the past, you know, 18, 24 months, there have been so many shiny new things that it's on a weekly basis there's something new we can point our, attention at. but going back to those fundamentals, those first principles, making sure that, you know, you might not have that newest thing accounted for, but as long as you have other pieces of that kill chain hardened and identified, you're in a good place.

And you're, you might not be 100%, and security's never gonna be a perfect practice, [00:04:00] but getting those pieces in place is really gonna pay dividends down the line. And especially because this technology's not going to slow down, and resources aren't going to all of a sudden explode and become abundant in our environment.

Just making sure, like, you have those endpoints protected, you have those processes in place, you have that incident response plan in place so that you have those resiliency measures is really what it comes down to. So when something does happen, the blast radius is as minimal as possible

Ward: You know, I, I, I find it very interesting how a lot of these conversations, really honing in on, on kind of your last statement there. Um, i- in the past, people would say, "If something happens, you could do it." You use the, the term when, and, and pretty much all of my conversations that is the case. 'Cause I, I think we are in a world now where it is not if.

Truly it is not if, it is when. And, and we used to use just that phrase, I, I feel like, to scare folks for many years. It's not if we're [00:05:00] targeted, it's when we're targeted. Like, no, truly it is when these days

Dana Kilcrease: And, and that could be anything, right? Uh, uh, it doesn't mean necessarily the, that we're gonna wake up tomorrow to a, you know, hopefully not to a large scale ransomware attack, right? That, that cripples our business for the next six months. Um, but I, I would say not a week goes by I don't have a user who clicks on a phishing email.

Um, a- and even those smaller security incidents, uh, such as they are, um, you know, they do add up over time and, and there are things that, again, it's just a matter of sure, our phishing, um, campaigns have gotten more advanced. Attackers have improved their language. They've improved, you know, their abilities on their end. Um, but it's still a matter of doing the same basic first principle fundamentals and saying, "Okay, well when somebody clicks on that message, what happens? How bad is it when somebody does that?" And really minimizing that, that downstream effect of those user interactions, um, because they're just gonna get worse over time, and they're gonna become increasing, uh, in frequency

Ward: [00:06:00] Agreed. Agreed. So g- going back, you, you mentioned, um, getting really back to the foundations, you know, those, those, those key items that, that every program should have. Let's focus in on data security. What, what are a couple that you feel are the absolute musts that everyone should not just be doing, but doing well?

Dana Kilcrease: So one of the things we had to do early on in our AI journey, um, was really again, take a step back and, and say, "Well, what do we have? Where's our visibility? Where's our gaps?" Um, and we didn't necessarily have anything in place to identify a lot of that. Um, so, you know, a DSPM technology would be the first, uh, sort of thing that comes to mind, right?

Where gives you that visibility into what do you have, where are the holes, a-and not just like, oh, this document might be over-shared, but maybe this collection of documents is over-shared by this or this part of your organization. So this is maybe a, a group of people that you would need to talk to and say, "Well, just change your process, and we [00:07:00] can fill in a lot of those gaps."

Um, I think really getting a, a tighter grip on that level of technical debt that tends to accumulate year over year, uh, especially in organizations, you know. We've been around for, for 95 years now. So imagine, you know, the levels of technical debt that we've had build up over the years. Um, so, so early on, implementing a DSPM to get that level of visibility, um, bolstering DLP on top of that, right?

So you've identified where, where that data is, um, where that data is, where, what you have, where that sensitive data is, classify it, put your policies around it, and then make sure it doesn't leave. Um, a-and those are really the big things to do now, um, because again, it, it's one of those things where AI is just going to increase the likelihood of all of these things happening.

It's going to increase the likelihood of people surfacing information through Copilot or possibly, you know, if somebody, you know, there's an insider risk or an insider threat, all of a sudden being [00:08:00] able to rip apart a large part of your environment. It's minimizing the blast radius. It's going back to square one and saying, you know, "How do we stop this in the kill chain?

How do we get alerted to these things earlier on so we can stop them?"

Ward: I like it. I like it. Definitely speaking my language as, as a guy who's been doing this for a long time. Um, although, you know, kinda going back, it, it seems and sounds simple, right? You know, do DSPM data discovery, do data loss prevention, do those things. But I mean, you mentioned something interesting, right?

Your organization's been around 95 years. You probably have tech debt, probably old data. There's other, you know, organizations out there just as old or older, right? With probably same thing. So, you know, really kinda digging into that, like instead of boiling the ocean, do you have any recommendations on how to start for the, for those-- A- a- and I'm not even talking about behemoth organization, right?

Like, we can put some of those, you know, big super-sized ones to the side. There's plenty of [00:09:00] long-lived orgs that have tech debt, old data sitting around that might not know where to start

Dana Kilcrease: It's true. true. And, and it's, it, it, it's kind of maybe my, my inner, you know, stoic, uh, where I can... I have to really take a step back and say, "Well, what can I control? What pieces of this puzzle are things that are solvable at this point," right? Um, with a unlimited budget, if I had a billion-dollar budget, I could do a lot more, and I could fix things, and I, I could probably say with relatively s- you know, a high level of certainty, we will not get hacked in the near future. budget is not that big. Um, so it's taking a step back and it's saying, "Well, what can I do with what resources I have in the constraints that I'm working in?" Um, and I, I would say for any other organization, we're mid-market size, uh, so any other organizations that fit into that profile, it's really, you know, taking a step back and saying, "Well, okay, so maybe we don't need to have the latest and greatest MCP, uh, you know, safeguards in place for these [00:10:00] particular things, as much as we need to go back and make sure that our endpoints have these, you know, security measures on there, or these controls, or these hardening configurations on our servers.

Or we have MFA in place." You know, just making sure that you have these basic controls in place is really the first step in combating those larger emerging threats that are coming out

Ward: I like that. You know, z- zooming out, and that's something that I've seen over and over again where something happens and there's a knee-jerk, right? I mean, pl- plenty of people, plenty of organizations do that. Oh, oh, AI was a big one, right? AI came out, many organizations said, "Oh my God," slammed the door shut.

Like, "We're, we're not gonna allow that in." But, you know, fortunately/unfortunately, right? Uh, you know, AI jammed its foot in the door and started leaking into every organization. And it's there, right? For better or for worse, and now people need to solve for it. But, you know, that's, that's the a- a- again, example of a knee-jerk of, "Hey, I'm gonna do this thing."

So really what I'm hearing from you, Dana, is, um, a- and you mentioned, you know, [00:11:00] stop change-- chasing shiny objects, all of that. So stop doing those knee-jerks or, or stop chasing, but really take a breath, take a pause, and think more macro. Is, is that where you're going?

Dana Kilcrease: Yeah, 100%. And, and you really have to at this point, um, because there are so many things that would cause knee-jerk reactions. Every day there's a new news story that comes out. But it, it is kind of a double-edged sword, right? 'Cause, because on one end of it, you are dealing with the constant influx of new news, new things that you have to deal with. But I found that there, there's a, a silver lining of sorts, right? Where these news stories are making their way to our boards, right? And one of the things that every CISO and, and security leader has always fought for over the years is, well, how do I get that executive leadership and that board visibility?

How do I get these talks started? And what I've found is that now the board is coming down to say, "Hey, we read about this. What are we doing?" And so it's giving maybe more, uh, opportunity in a lot of ways to maybe increase the [00:12:00] visibility of your security programs and then, you know, hopefully down the road, get a bigger buy-in to tackle some of these emerging threats

Ward: Yeah. Yeah. I mean, that's definitely a, a, a good thing that's coming out of it for sure. Um, you know, not something that I've thought a lot about as of late, but yeah, I could definitely see that, right? Instead of having to always say, "Hey, look at me, look at me," right? You know, "Listen to me. Think about the, the, the security of the organization at the board level."

Um, do you find you're getting challenged though at the same time? Like, is it, is it tough to kind of stay in front a- and try to forecast what some of those questions may be so you have good answers in the moment?

Dana Kilcrease: Not necessarily. I've found that by staying upfront, being part of the technology, um, I've been building on my end, so I'm in the technology, not just from a strategic level, but from a builder and practitioner level. And being at that level with the technology has allowed me to stay on top of the news a [00:13:00] lot quicker than a lot of executive leadership might. a lot of the questions that I'm asked are then maybe something that I saw surfaced a week, two weeks, three weeks ago. Um, so I've already it overcome the, the question itself and found the path forward. Um, so it, it, it's a matter of staying in the technology to stay ahead of those questions i- is really gonna be the most beneficial thing you can do

Ward: I haven't asked a lot of folks this on, on, on the podcast. I'm gonna put you on the spot here. I mean, there's, there's, there's a lot of information out there, right? Like that, that folks could, uh, seek, try to assimilate to, to stay in front of these things, to stay up. What, I mean, what are, what are one or two good sources that you leverage to stay up on the latest trends, the latest information that are out there?

Dana Kilcrease: There are good blogs. Uh, you know, I'm not going to say any specific ones because tomorrow it could completely change. But I, I

Ward: [00:14:00] Sure

Dana Kilcrease: there are a, a handful of good blogs that are, are leading the way. Um, but other resources, even going back to, you know, where, where security news has always come through, whether it is social media or newsletters or those things.

Um, there has been a shift I've seen, um, a lot of The, the social media world and influencer world especially, where the focus has absolutely pivoted from sec- cybersecurity being kind of that sexy part of the IT world to, well, that's boring now, let's go to AI and just talk about AI. uh, the, the benefit there is that a lot of the blogs that I was following, a lot of the newsletters, a lot of the people I was following on X or, or LinkedIn or whatever, um, just immediately pivoted over to AI.

And I, I-- my news has, has reflected that, and I've been able to stay, uh, stay on top of things

Ward: I mean, I guess that's good and bad, right? You, you get, uh, you know, definitely inundated by, by the AI things. [00:15:00] But, um, you know, I suppose with, with that AI noise, you might miss out on some other things at that point. I, I too have the same... I'm not gonna call it issue, uh, but I, I too have the same LinkedIn feed, we'll go with that, with,

uh, very much AI forward and little things here or there sprinkled in.

Dana Kilcrease: It is, uh, you know, one of the things I, for better or for worse, AI has definitely given a voice to a lot of people looking for a voice somewhere. And so a lot of people have a lot to talk about and, and unfortunately it does all kind of boil down to the same thing because at the end of the day, so many of them simply just AI to write their post for them or, or create their topics for them.

And, you know, even if you go into AI and you say, "Well, what's... I wanna further my career. do I do that?" The first thing it says is, "Well, why don't you go on LinkedIn and start doing these posts?" And it's, it's, um, it, yeah. So, so I mean, that's [00:16:00] probably an, a whole different topic, uh, and, and, and issue to deal with

Ward: Yep. I, I totally... And, and, and we see that, right? We see that out there quite a bit. Um, going back, I am curious, so again, going, going back to you and your organization, been around 95 years. So that's, that's not, that's not a young organization. I would imagine when AI hit and you started really, you know, doing some of those gap analyses, right, if, if you will, and trying to figure out what's going on, I would imagine you probably also found some culture items that might not have been great, that you might have needed to try to change or mentor or whatever.

Um, for other organizations that, that might have that as well, right? Cultures of, "Well, we've always done it this way. We don't want to do it this way." Or, or maybe the opposite of, "We've always done it this way, and I want to jump, you know, both feet into to Claude instead." [00:17:00] Um, any, any tips or tricks that, that you've leveraged over the last couple years to, uh, you know, make, make those conversations successful?

Dana Kilcrease: So from a, a, a cybersecurity standpoint, I, I would say that we were in a good place as, uh, an organization prior to AI coming on board. Uh, you know, our security program, um, is mature enough to the level that we have a good relationship with every line of business that, that we operate. Um, and we have, uh, organization-wide that, that makes sense. When AI hit though, uh, being in higher education, the, the biggest thing wasn't necessarily, well, how are we going to secure all of this technology? It was the academic portion of it, right? From an administrative level, it's, it's fairly straightforward, right? We have our data, we wanna protect our data. What are the new technologies, and how do we resolve that in each individual bucket, um, that we have? And that's relatively straightforward. But the larger question was, well, okay, so for higher education, what are we [00:18:00] doing? And, and faculty and, and the academic side looked to obviously the IT side of the world saying, "Well, okay, so how do we stop students from just simply using ChatGPT?" Um, and, and unfortunately, you know, in the, in the beginning, there definitely was a large period, there was a huge gray area where there were no great solutions right off the bat.

A lot of the, the anti-plagiarism tools and things that we had leaned on for years, um, obviously weren't able to immediately meet that moment. Um, and they have grown to mature to a certain extent since then. Um, but it did provide an opportunity from a cybersecurity to become more ingrained in the business aspects of the organization, instead of just being that force to say, "Well, okay, so we're, we're here as part of the procurement.

We wanna shift everything left. We want, you know, as soon as you think about buying a product, we wanna be in the [00:19:00] conversation." And, and, and that has always been somewhat of a contentious argument a lot of ways, or a contentious relationship, where when AI came on board, everybody was really looking for guidance and saying, "Well, how do we, how do we come to terms with this?" And, and being able to sit down with academics, each administration, uh, administrative line of business a-and talk to them on their level and say, "Well, what are your concerns? How can we ease those concerns? And then how can we also flip this around and help you utilize this technology, leverage it in a way to increase efficiencies across the board for you?" Um, really matured my relationship with the business, uh, dramatically over the past 18 months

Ward: Love that. So y- re- really more of a partnership at this point is, is what you would say

Dana Kilcrease: Yes. Yeah. And, and, and it, it's, it's been good, and obviously having those conversations about AI does have that downstream [00:20:00] effect of improving your, your relationship with people and then improving the posture of your security program as, as a result

Ward: That's really interesting. I mean, for, for years, and, and this topic has come up a lot on the podcast, uh, but for years folks have said, um, well, actually it started with, "Hey, security is a cost center. It's a, it's a money sink. Why are we doing this? How is it enabling the business?" Then there was kind of the interim where that still existed and everyone's, like, beating the drum, "Hey, you gotta get close, you gotta create champions."

And, and the idea of creating champions has been ki- kind of a, a, a common theme that, that's come up i- in episodes. Um, i- is that something that, that you're doing as well with, with those groups now that you've got a good relationship? Are you creating some either AI or security champions out there in the, uh, business units?

Dana Kilcrease: So we have formed a couple of, uh, AI committees that are ultimately chaired by, [00:21:00] uh, the, the CIO, uh, who I report to, and the, uh, the provost, who's the chief a- academic officer. Um, and so we have that sitting on the academic side, we have that on the administrative side, and, and we have, uh, several groups that we run within, in the, the college as a whole, um, that are either working groups, uh, whether it's working to update our academic integrity policies or helping faculty come to terms with this new technology, to administrative side.

You know, like I said, working alongside each line of business to say, "Well, how can we help you, you know, those efficiencies in your de- in your department?" Um, and so AI has really grown in those ways. With security, um, we've always had certain champions, uh, that in each department that we could look to and say, "These are the people that we can talk to," uh, you know, about any initiatives or anything that we have coming on board. Um, and that nec- hasn't necessarily translated directly, uh, into who's gonna be the [00:22:00] AI champions. Um, but time will tell, right? Um, and, and as everything moves along, who... I, I, I can't really say

Ward: So kind of digging into actually that last statement, kind of, kind of perfect segue, time will tell. Um, you know, we are now, scary as this is, right, looking at the calendar, we now have half of the year behind us of, of 2026. So you and I are talking, you know, beginning of July here, right? So going into second half, at least second half calendar year.

Um, any, any thoughts or predictions on where cyber's gonna be kind of going in the next six months? Usually I say, "Hey, any predictions about the next 12, 18 months?" But things are moving so quick, like it doesn't even pay to forecast out that front. So any, a- any big thought for the next six months of, of cyber?

Dana Kilcrease: Six months? Uh, I don't know. Uh, looking towards the future though, I [00:23:00] think that we're most likely going to see a, a few shifts. Um, I think that, that right now we're still at the tail end of that initial explosion of AI's here. We need to find every niche use case for it and have a cybersecurity come out for that. Um, so I think you're, you're gonna see, uh, somewhat of a collapsing, uh, together of, uh, uh, of companies, right? Where a lot of acquisitions will happen. Um, you're gonna see a lot more push towards more unified or, or s- a holistic approach to a lot of these issues, right? Where you don't have to get these little edge cases.

Uh, they don't deserve their own products. And, and for companies of my size, mid-market size companies, we're never gonna invest in those types of, of companies because it doesn't make sense, right? Because s- maybe not six months, 18 months down the road, they will be, uh, swallowed up by, by larger companies, some of whom we might already own, right?

Like, so Microsoft will probably do a [00:24:00] lot of acquisitions. You know, we're seeing, you know, s- a lot of these other, you know, larger cybersecurity companies bringing these technologies on board, DSPM being an example as well, right? so I think you're gonna see a lot of that. Um, other than that, I think that you're going to see, especially in the mid-market space, I think you're gonna see a lot more emphasis on tooling being built in-house, again, a lot of these smaller edge cases If there is no true moat in your product that would stop a company from just simply having their development team use Claude Code to redevelop it in an hour or two, um, there, there, there, there's just no chance that, that these companies are gonna survive long term, right?

Um, and we've already seen some of that. And, and in-house we've already been doing that, um, where I am, where, where we're not maybe redeveloping entire products, but say we have a use case for a certain piece of a technology, [00:25:00] we can develop it in-house and we can just manage that in-house rather than going through our full procurement policy, allocating a budget for it.

You know, we're higher ed, so we operate on a 12-month budget schedule. Um, so it, it doesn't make sense for us to, to, to really invest in like a brand new startup that does this tiny little thing for us when we could just build it. So, you know, from a cybersecurity perspective, I... That's where I see a lot of the product going in the, in the near future. Um, but also for, you know, again, from the mid-market space, there's a lot of, you know, going back to what I said earlier, like just having that, that sort of stoic approach where you say, "Okay, well, I can do so much with the tooling that I have. I can't buy every tool in the world. I can't develop every tool in the world." So there's gonna be a certain reliance on our existing vendors grow as quickly as the attackers are growing, um, and, and meet that moment, right? Where you have, um, you know, obviously attackers are growing, they're leveraging AI, their [00:26:00] attacks are becoming quicker. They're ex- they're, they're developing AI exploits for CVEs a lot quicker. Um, and, and we're getting hit with that, but there's only so much we can do at the end of the day, uh, where we do have to rely on those Microsofts, those CrowdStrikes, those larger vendors to say, "Okay, well, we've developed that technology to be that counterpoint to that attacker." Um, but yeah, time will tell.

A- and, and the things that I've heard coming out of not just product companies, but also larger organizations who have larger budgets, um, they are doing things to meet the moment that are really encouraging. Um, and so I, I do have somewhat of an optimistic view that after 18 or 24 bumpy months that we might have, on the flip side of that, I think we're gonna see a lot of technologies emerge that will give us things that we've wanted for the past decade and put us in a stronger security posture than we were maybe 18 months ago

Ward: Oh, that's amazing. I, I mean, I'm already seeing [00:27:00] some of that as I talk to folks, right? Like I, I'll, I'll have some conversations and I'll actually get goosebumps and I'll have the, "Why the heck didn't I have this 10 years ago? My life would've been easier." And then it's like, "Oh, well I didn't have it 10 years ago 'cause the technology wasn't there yet."

So I, I completely agree with everything you just said for sure, for sure. So Dana, you, you've clearly been doing this for a while. You've been very successful in your career. Um, what was your journey? How did you get to where you are today?

Dana Kilcrease: So, um, I came up through IT is really the short answer. Um, and so, um, I started off as a desktop technician, um, working my way up through IT and learning the ropes there, right? And saying-- A- and learning the hardware aspects, learning that the interacting with users. Um, from there I taught myself, uh, programming and moved into the mobile application development space. From the mobile application development space, I moved into more enterprise level, uh, applications.

Well, Dana, I mean, you, you've been doing this for a while, you know, almost two [00:28:00] decades. Currently a CISO, so you've been successful. What was your journey? How did you get here? So I came up through IT like most people in, in cyber. Um, you know, I started fixing computers, uh, on the side, and, and one of the people I was helping to fix computers ended up being a manager for a desktop technician team.

Um, you know, after helping him for a while, he, uh, had an opening on his team, and I joined as a desktop technician, which really gave me the background in, you know, kind of that wide breadth of hardware, software, troubleshooting, dealing with end users, understanding everything from a networking level a- a- and really that enterprise environment right away.

Um, after doing that for a bit of, I moved into the programming area first, uh, you know, doing mobile application development. Um, I taught myself iOS development back when that was, uh, you know, coming online. Uh, and so I, I became a, a iPhone developer and developing internal, uh, iPhone applications. Um, and from there transitioned into more of the enterprise software [00:29:00] development, right?

Uh, doing things on top of the Microsoft stack, SharePoint, you know, general web development. Um, and, and did that for a long period of time. And, and by that point I had a pretty, uh, rounded understanding of IT, um, enterprise systems and everything that that encompasses. Um, and it was kind of a natural transition to say, "Well, what's next?"

And I pivoted into information security, right? Um, and, and it was, it was a natural transition and, and, and kind of goes to the argument a lot of people make where cybersecurity isn't necessarily an entry-level job. And the benefit I see of not having it be an entry-level job is, you know, going through IT, coming into cybersecurity and information security with that rounded background allows you to think about protecting systems in really that holistic manner and understanding how all the different pieces fit together, um, which I think is really important, um, to being successful in cybersecurity.

Um, and then it's, it's really just a matter of doing that for [00:30:00] a bit, um, and moving into leadership positions, right? After a certain amount of time, the experience, uh, across IT and cy- and security does lead to a path of, um- Leadership and eventually, you know, from, you know, managing to director to, to CISO, uh, where, um, where I've sat for the past three and a half years now.

Wow. Wow. That's, uh, that is quite the journey. So I'm curious, right? You, you, you're currently in the higher ed arena. I'm sure you get asked this quite a bit, right? Like, or, or, or get the, get the folks that they get a degree, whatever the degree is, and assume, "I'm gonna go right into cyber, right? I'm gonna get my first job," or, or whatever it ends up being, or, "I'm gonna get a certification.

I'm gonna get the job." Um, any, any words of advice for those out there looking to get their first cyber gig?

It's difficult, and, and in- increasingly so, uh, [00:31:00] over the past five years, I would say. Not five, may- maybe the past three years. Um, there, there has been a large amount of people in the workforce looking for those positions, uh, so the competition's become extremely deep for those entry-level positions. Um, I think that there is a, a, probably an undue focus on certifications, where a lot of people think that by racking up certifications...

I did this myself. I have a whole stack of certifications, and y- the thought process is the more certifications I get, the higher likelihood of me getting a job, um, which I would advise against. What I would advise is to focus on where you want to be in cybersecurity, um, and, and attack those certifications.

And there's a lot of great roadmaps out there that can plot you from the entry level if you wanna be, you know, a pen tester, to, you know, what certifications will lead up to where you wanna be, to security [00:32:00] research, to, you know, a SOC analyst or anything else that you wanna do. Um, and I would, I would really suggest to focus on those areas, define your niche, a- and, and work at that as hard as you can rather than trying to be everything, right?

Um, a lot of people see, like, CISSP as, as kind of that, that gold standard of what you want to achieve, um, but it's not really a great fit for a lot of people. Personally, I got into information security because I wanted to be a pen tester, and I thought that getting my CISSP would be a good thing, it would help me out in my career, which it has, but it had a negative effect on my ability to become a pen tester because it pushes you into a management track in a lot of respects.

Um, so I would've been a lot more, um- likely to go down the pen tester route if I had gone, you know, OSCP and down those certifications a- and focused in on that niche. So for anybody getting into it now, understand that the competition's deep. Um, it's out there. You're competing against a lot of people with a lot of experience.

Um, you're competing against, you know, [00:33:00] not just people who have worked in, in enterprise, but people coming out of the government, people coming out of the armed... You know, a lot of veterans who come out of- Oh, yeah ... the service with, with significant experience, um, behind them. So if you're struggling to find an entry-level cyber job, my, my suggestion would be to go into IT and, and, and work your way up, and it might not be what people wanna hear coming out of college-

but it's one of those things where you know what? In five years, either you're going to still be looking for your first cybersecurity job, or you could have five years of help desk experience behind you that would allow you to leverage that into an actual cybersecurity job. I think that's good advice. I think there's a lot of ego, right?

You know, people go and get, you know, bachelor's, maybe they go bachelor's right to master's. Maybe t- to your point, they stack up those badges and certifications and they're like, "Oh man, look at me. I'm gonna get this job." And they, they won't... Uh, they let their ego get in their way instead of going the IT route, which I did.

I've had a lot of guests that, that have done as [00:34:00] well. Um, very legitimate route, right? Very, very good way to, to your point, to, to get, um, that experience. So now I'm really curious, given your, your track that you laid out there, like how much do you find yourself like kinda going back to that knowledge that you've obtained in those, those early days?

Like do, does it happen quite a bit, or is that just the foundation and, and you're onto bigger and better things from a knowledge platform? So it's a good question and, and it's one of those things where I lean on what I've learned a lot because I operate in a similar environment to what I learned in, if that makes sense, right?

So there are different types of CISOs and, and I've seen this, you know, across the board where there's a lot of CISOs who come up the way I did through IT or through, you know, working in entry-level jobs and bit by bit worked their, their way up through the ranks. Um, and then there's, you know, your, [00:35:00] your MBAs, uh, you know, CISOs who lead, you know, Fortune 100 companies and things like that.

They're two completely different worlds. Um, and so it's really defining what your end goal is going to be, um, a- and working towards that. For me, being in the same environment that I learned in, every day I am able to say, "Well, oh, this is a problem that we're having." And because I understand the environment, I understand how these pieces of an enterprise fit together in this type of an organization, I'm able to quickly identify what needs to be done, whether it's a project, whether it's an incident, whatever it may be.

And I'm very good at doing that in my environment. If you threw me into a Fortune 50 company, I don't have an MBA, and so there would be a lot different approach needed to be successful in that environment. Yeah. More of a learning curve, essentially. Yes. Well, a different skill set, really. You know, dealing with, you know, for me, dealing with managing IT resources and cross-functional teams is a lot different than managing, you know, [00:36:00] global, um, lines of business across, you know, um, whatever, you know, 30, 50, 100,000 employee size, you know, organization a lot of these people run.

Which, you know, again, is, is, you know, to be successful in those roles is a different skill set. You don't necessarily need to know help desk stuff to be a successful s- you know, C-level employee at those types of companies. Sure. Sure. That makes sense. So, you know, you know, again, starting your career in IT, being successful pivoting into, into cyber or information security back then, now everyone calls it cybersecurity.

It's all the same thing in my opinion. But anyways, um, if you could go back in time and, you know, may- maybe talk to yourself when you were in those IT roles, is there a different track you would have taken or, you know, do you like, uh, the track you took and, and all those experiences that, uh, made you where you are today?

[00:37:00] I think that it's inevitable that, I don't want to say inevitable, even though I, I do mean it, that after a certain amount of time you're gonna be, you're gonna have to move from a practitioner role, for most people, move from a practitioner role into a leadership position. So for me to be in the position I'm in now, um, and especially with AI and being able to kind of dip back into the technical aspects more and, and leverage the things that I, I grew up learning, um, is a great fit for me.

Um, with that said, you know, like I said, you know, I, I got into information security for the pen tester, you know, aspect and, and really, um, you know, had a strong passion for that. Sure, maybe I'll go back in time and say, "Well, maybe I get the OSCP instead of the CISSP." Uh, and who knows where that would've ended up.

Um, but you know, I, I don't think I would change much in my journey so far. That's, that's, that's funny to think about, right? If you'd gotten your OSCP, like would, would you be [00:38:00] like, uh, an uber red teamer out there doing that type of work or, uh, you know, would, would you have still landed in the same spot?

It's, for me at least, thinking about my own career, it's always interesting to think about. No, absolutely. And I actually have taken the OSCP training, although I've never sat down for the test. Um, and it's, it's fascinating and I have so much respect for, for the people who do that. Would... So I, now I am curious, since you've done the training, uh, would you go in and sit for the certification?

No, because there's no real benefit at this point in my career. I don't think it would necessarily pay dividends. Um, again, it, certifications are one of those things where a lot of people look at them as a stepping stone into something, where I tend to look at certifications now as they certify that you know how to do something.

Um, a- and taking that approach is, well, what do I wanna certify? Do I wanna... What, do I need to prove to anybody that I can be a pen tester? No, I don't. [00:39:00] That's not gonna necessarily help me. I don't need to prove to anybody, uh, that I'm a SOC analyst, uh, or, or any of those roles, even though I do understand, you know, what goes into those.

Um, so yeah, no, I, I definitely would not sit for, for any of those. And I don't know if there really are any certifications that I would sit for at this point. Um, even some of the AI ones that have come on board aren't necessarily too attractive for, for me at this point. Not, yeah, not yet. I- I've looked at a few of those too.

I was like, "Meh, I'll, I'll wait." But h- here's the thing with those, right? Like, with, with everything happened to everything we've talked about before, so hyper-fast, like you, you could take one of those and it's highly likely it's gonna be null and void in, you know, six to 12 months from now anyways. Right.

Right. And what's it gonna show? And that's, at the end of the day, you know, if you're gonna put something on your resume, what does it show about you? What are you trying to prove with it? And right, um, a low-level AI certification, um, doesn't really mean much these days, as much as experience. You know, experience [00:40:00] trumps everything, so if you have the, you know, option of taking a certification or, or getting into the, the trenches and really learning what this means, get into the trenches by all means and, and, and go nuts.

Well, there you go, listeners. You heard it directly from Dana. Don't, don't worry about the badges as much as getting your hands dirty and learning something. Um, so Dana, if folks wanna follow, you know, connect with you, you know, maybe reach out, what's the best way to do so? Connect on LinkedIn. Um, yeah, happy to, happy to have any conversations that are helpful.

Awesome. Well, Dana, thank you so much for joining me today. This has been a great episode. Absolutely. Thanks for having me. And big thank you to the audience. Really hope you learned something today and enjoyed the episode. Please tell others in your network to follow and listen. This has been another exciting episode of Guardians of the Data.

See you next time. That's a wrap on another episode of Guardians of the Data. Thanks for tuning in. For show notes and more, visit guardiansofthedata.show. Guardians of the Data is made possible [00:41:00] by support from Sentro. To see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving petabyte scale data protection without the fuss, please visit sentro.io.

Catch you next time

Stop Chasing Shiny Objects - Dana Kilcrease - Guardians of the Data - Episode #51
Broadcast by