In this episode, host Aaron Crow welcomes Chris Robertson, CISO at Apogee Defense, to discuss the evolving landscape of cybersecurity, focusing on the distinction and strategy behind Virtual CISO (vCSO) roles.
Chris shares insights from his dual roles at Apogee Defense and as a virtual chief security officer for various companies. The conversation dives into the intricacies and responsibilities of vCSOs, the importance of understanding IT and OT risks, and the necessity of integrating cybersecurity deeply into business practices.
Chris and Aaron explore practical solutions for businesses, emphasizing adaptability and continuous improvement in security measures, drawing parallels between accounting a century ago and cybersecurity today.
They also touch on future trends, the impact of AI on security, and the importance of setting aside egos to foster a culture of learning and collaboration.
Join them as they navigate the challenges and opportunities at the intersection of IT and OT cybersecurity, offering actionable advice and anecdotes from their extensive experience in the field.
Key Moments:
00:00 Outsourcing Risk Management Expertise
08:22 Hiring External Experts: Cost-Effective Strategy
12:04 Understanding OT Risks in Cyber Leadership
20:36 MBA Curriculum Needs Security Focus
23:31 Integrating Security in Legacy Systems
27:47 Tech Efficiency and Shadow IT Challenges
35:56 Optimizing Inefficient Appointment Systems
39:08 Bridging Tech and Business Worlds
45:43 Simplifying Risk Communication
51:52 Joe Rogan's Impact and Risks
57:09 AI Evolution: Professionals Riding the Wave
01:05:53 "Embrace Vulnerability, Seek Help"
About the guest :
Chris Robertson is a seasoned cybersecurity expert, currently serving as the Chief Information Security Officer (CISO) at Apogee Defense. In addition to this role, Chris extends his expertise as a virtual CISO for various companies across multiple sectors. He specializes in implementing robust security solutions that Apogee Defense delivers to its clients, predominantly within the Small and Medium Business (SMB) space.
With a keen focus on the defense industrial base, Chris's work also spans various other industries, enabling businesses to strengthen their cybersecurity frameworks. He is highly regarded in the industry for facilitating vital connections and contributing to advancing cybersecurity practices.
How to connect Chris: https://www.linkedin.com/in/christophersrobertson/
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Please leave us a review on Apple/Spotify Podcasts:
Apple - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124
Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4
Aaron Crow (0:1.454): Thank you for joining me, Protect It All. Chris, I'm super excited. We just got off this, this is what, Friday, about a week after the event that we just had at Staccato Ranch. So obviously you were there. Man, it's been, it was an amazing event for me and lots of good feedback and all that kind of stuff. So thank you so much for taking time out of your day to spend time here and kind of talk cyber and geek out. So why don't you introduce yourself, tell us who you are and what it is, your kind of background.
Chris Robertson (0:29.932): Yeah, well first I want to say thanks for putting together that event. It was amazing. There's not a lot of things out there like that and the chance to get to connect with a lot of the people in the industry is awesome. So I want to thank you before going on, but Chris Robertson. I am the CISO at Apogee Defense. And I'm also a virtual CISO for a number of other companies across number of sectors and then.
Chris Robertson (0:57.804): We also, or I also help implement a lot of the solutions that Apigee deploys out to customers, primarily within the SMB space. And we focus a lot on the defense industrial base. We've got customers that span a number of other industries as well.
Aaron Crow (1:15.364): So I love that name Apogee. My son is in a group called Apogee. Anyways, that's just a tangent. talking on the VC, so that's a relatively recent term. We understand what a CISO is. Talk a little bit just real quick about what that VC so role and why more and more industries and verticals are kind of using that instead of necessarily maybe they don't need a CISO.
Aaron Crow (1:43.044): a full-time dedicated see so that kind of thing talk a little bit about
Chris Robertson (1:48.024): Sure. So what has happened a lot with a lot of companies is you end up with someone who's the head IT head of development or something and they, they realize they have to have someone who's legally responsible as a CISO or CISO. And so they just go and task someone to go, Hey, you do it. And one of my buddies was like that a number of years ago, he got pulled into it and I was like, well, I've been running, you know, CMMC development for a while. like,
Chris Robertson (2:16.920): I'll kind of give you some guides and help you get going. But he still had his normal day job, but he also all of a sudden had a lot of responsibilities as a CISO. So he was thrust into all of a sudden a lot of GRC stuff. He has to deal with the SEC, a whole bunch of things. But he didn't have the background to really move into it quickly. he struggled. What I think a lot of companies have realized is that instead of
Chris Robertson (2:45.710): pushing someone who's already got a full-time job in-house into doing this. They go out and find someone who can come in part-time and fill that role and help guide the company and build the program up to the point where they can make it a full-time role. So typically as a VC, so we've got companies that don't have a program in place at all, or maybe they had someone in-house doing it and their background is heavy in development or heavy in infrastructure or something.
Chris Robertson (3:15.726): And they realize that they don't have the time to sit there and go through and learn more about the intricacies of risk management, about policy development, that sort of thing. So they see value in bringing in someone from the outside as a consultant to help develop those programs and take that load off of them so that they can focus on what their typical job is. And in part, a lot of my time is spent coaching. I spend a lot of time.
Chris Robertson (3:43.949): talking to those guys and helping both train them in how to make a decision and why decisions are made and lead them through that pathway of this is how we do the analysis, this is how we structure and weight everything and we build value on both sides of the equation of a decision before we make that final decision. So that helps them grow into that role if that's what they're going to do later or at least understand what
Chris Robertson (4:13.502): the information security group is going to be doing. And so that that's really been a driving factor. think that need for those outside consultants, bringing them in, having someone who has already been doing that type of work and can help that company get their feet underneath them. And like I said, a lot of times those companies will end up growing and hiring someone on full time. Or there's even cases where they'll bring in junior staff.
Chris Robertson (4:43.084): who will report to the VCISO. And then, so they start developing in-house first to do a lot of the tasks that you don't need to pay someone as much to do. And so, you know, they're just being resource effective. And then from there, they eventually will grow the CISO position to something else.
Aaron Crow (5:3.256): Yeah, I mean, it's no different than, you know, any role. You can be the best engineer and the most, the best subject matter expert. And then what do you naturally do? You get promoted and now you're the manager, but you're not necessarily that's not a skillset that you're great at, right? What got you here won't get you there. You know, they're different skillsets to do depending on people managing and processes and technology. can, I can configure firewalls and, and build code and all that kind of stuff. That does not make me a good leader.
Chris Robertson (5:17.858): Yeah. Yeah.
Aaron Crow (5:30.836): That doesn't mean you can't be a good leader. It just means that sometimes you may have to work on those skills. So having consultants and people that have that experience to help guide and coach, like you said, that could be huge. It could be that bridge to maybe this person is the person you want to be that role, but maybe they're not quite ready. You could, you can actually coach them into a place down the road where you can hand them that baton and they now have that skillset and they're in house and they have the trust and understanding of the business and the team and all that kind of stuff. That's, that's a huge opportunity.
Aaron Crow (6:0.628): Especially now, like you said, like the legal obligation for a CISO as SEC laws have changed, especially here recently, and how important that ownership and understanding of we're accepting this risk, we're mitigating this risk and what all those things mean. Because as a CISO, you're signing your name and the board's name down on those risks and taking that in-house.
Chris Robertson (6:23.554): Yeah. Yeah. And then, you know, there's also the side where you've already got someone, they know they want to do it. They've got that title, but they still need someone to help them. They need that assistant. So while we're not taking the title of a CISO at that company, we're still coming in as advisors to help those guys navigate or just take load off of them. cause we, no one ever gets promoted within and fully drops their prior workload. It just gets added on. And all of a sudden the guy who is like,
Chris Robertson (6:53.230): Yeah, he was probably feeling comfortable in his job, I hope. And then he gets pushed this out there and all of a sudden his workload has tripled. And so now he's struggling to figure out how to do it. So we, we can come in and assist with that group as well. And it really helps that those companies get into a better footing more quickly and avoid a lot of the roadblocks. So when I was first doing policy development, I can't tell you how many roadblocks I ran into trying to figure it out myself.
Chris Robertson (7:23.246): sorting through issues. And it wasn't like until I ran into so many dead ends and realized that I'd skipped, I'd missed a single sentence in, you know, 20 page document that completely changed the order of how I do stuff. Like those are the things that, you know, if you haven't experienced it, you're not going to know what to look out for. So, you know, taking that experience and bring it to others is, you know, it's, it's actually really great to be able to show someone and shortcut their time of.
Chris Robertson (7:52.910): development because it you know you look at it and you go well this should have taken you guys nine months to figure out but bring it in someone that's got some more experience we can get it done in four
Aaron Crow (8:4.322): Well, and there's something to be said about that.
Aaron Crow (8:9.122): it's easy to look at, well, it's really expensive to bring in somebody from outside. Like, you know, we don't have that budget or we're trying to save costs because of X, Y, and Z. mean, obviously all, all boards and, and, know, CFOs are working on, you know, doing, doing the most they can with, you know, the least amount of, you know, revenue or output as they can. But at the same time, to your point, like maybe I do it in house and yeah, maybe I'm saving on paper upfront. I'm saving, you know,
Aaron Crow (8:36.150): six figures, $100,000, $200,000, $300,000, whatever that number is. But if I do it wrong or it takes me 10 times the time and it's still not done to the same quality that somebody that has the experience, has the processes, knows where the gotchas are, knows where the hidden bodies are gonna be, and you can navigate those things and you're not getting fined, you're not taking twice as long and impacts. There's so many dominoes that can fall in that space without the experience, it's really hard.
Aaron Crow (9:5.412): I worked for a big four consultancy and that's why they, that's why you hire consultants. That's why you hire coaches. That's why, you know, literally you get, you get somebody that knows how to do it and you teach it. Like we've always hired coaches there. This is no different. And it's really just leveling up these spaces and mitigating that risk. It's not all a cyber risk. It's sometimes it's a business process and lots, lots of those risks that you're also mitigating.
Chris Robertson (9:28.462): Absolutely. And there's another side of it too, where within CMMC and with SEC stuff, if you have a breach and what you've reported you're doing is not what you're actually doing, now that turns into a possible criminal action. So the federal government, when you're dealing with controlled unclassified information, they're not okay with you saying that you're a superstar in your security program.
Chris Robertson (9:54.998): And you might have written all the policy stuff, but you didn't actually go through and either complete the policy fully to meet the, the control, or you didn't document it or you're not doing it. So if you just slap something in place and you put it out there and you get breached, you actually now are facing some major problems. Now, if you do get breached, you know, everyone's going to get breached. We can't stop that.
Chris Robertson (10:22.786): and you come in get an audit and they see that like, Hey, well, you know, you wrote down what you're doing and you're doing it. And they may not even like what you wrote down, but if you wrote it down and you're doing that, you're at least being honest about that, that process. So there's that side of it. And I think that that's something that a lot of companies, you know, miss when they're putting together programs. And I've actually had a number of companies come to us and say, Hey, we're getting audit in two weeks.
Chris Robertson (10:52.153): Can you give us a program that scores us a perfect score? And the answer is I could do it one day, but I can't do it in two weeks. Can I do it in two months? I don't know. Like, where are you guys at now? But there's a lot of companies who are pushing out there that, hey, we are rock stars. We are top of cybersecurity game.
Aaron Crow (11:3.042): Yes and no.
Chris Robertson (11:21.370): we're scoring a perfect score for CMMC. And then the government looks at that and goes, something doesn't smell right. And they send over auditors right away to go check that. And if you're caught, you're caught. So avoiding those situations, I think, is really critical. And that's where a lot of the ethics of the industry come into place, where if you're not ethically doing the right thing, you probably aren't in the right role.
Aaron Crow (11:46.308): Sure. So how much, how much do you see? So briefly, we talked a little bit about OT before we started recording. Obviously I spent a lot of time in OT and these, and you talked about CMMC and, how much are you seeing people that are in that virtual see-saw or in a see-saw role at all, cyber leadership, you know, executives.
Aaron Crow (12:7.660): that really truly understand their OT risk. And as more and more CISOs and executives are looking at the risk of their business and they're better understanding the risks from an OT or at least they're hearing about it, how much are they struggling to kind of implement changes? And from what I've seen, a lot of them, I've seen them fail because they try to just take IT policies and push them into OT, expecting that to work.
Aaron Crow (12:33.028): I've seen them where they tried to start from scratch, but don't get business buy-in. Like there's a lot of, you know, hurdles to look at when you're looking at IT and OT. even though the technology can be similar, those policies and procedures are really the difference, right? It's people process the technology. The technology, you can use the same firewall in both places, but how I implement it are probably going to be a little bit different depending on the use case and the business justification.
Chris Robertson (12:55.758): Yeah. So when I have talked to companies that are like very large, you know, multi-billion dollar companies, and I've talked to the CISOs there, I am not a hundred percent confident. Even those guys feel like they've got a great grasp on OT. They understand that it's got to be protected and they understand a lot of intricacies to it, but they also recognize they need someone else to help them because it's outside of their wheelhouse most likely, unless they've been dealing with it a long time. When you get into
Chris Robertson (13:25.838): like smaller defense manufacturers, for example, you get two sides. One side, no one's going to come after us. We're fine. And you know, that's just crazy. So they'll, they'll go ahead and connect everything up and just hope that, well, it's an esoteric machine. uses, you know, coding that no one's going to know, which isn't true. We all know that, but yeah. So they run that, that mindset. And then you've got the other side that they still don't know it, but they know that they
Aaron Crow (13:45.444): Security by obscurity.
Chris Robertson (13:55.074): have no idea how to manage that situation. So they just disconnect everything. And their response in that situation is simple. go, great, you want to, you need to move, you know, files, instructions to that machine to go ahead and make something. You go to your desktop, you load it up on a drive, you bring it over there physically. That way you're at least disconnecting opportunities for a lot of malicious attacks. there's no network connectivity.
Chris Robertson (14:24.590): You're completely isolating it except for you're transferring with USB or floppy disk even. I mean, even I'll give you an example. Even a $500,000 mill that is was new six years ago will have a floppy disk option. So they're still out there and they're still in use pretty regularly.
Chris Robertson (14:54.050): But those guys recognize that they don't understand the risk, so what they do is they just disconnect it. And then they just hope that that endpoint computer is protected enough that they're not shuttling something over. And sure, when you do that, you're probably really limiting the probability you're going to move something. But if someone's really focused, like SESNX, they're going to target you, and they're going to figure out what you've got in place, and they're going to build
Chris Robertson (15:23.234): payloads to eventually get to your equipment. And I think that that's, you know, we can't defeat that, right? We can only try to defend against it, but we won't defeat it. But you've got that huge disconnect. So I prefer the guys who just disconnect everything. And they recognize they don't have the ability versus the people who just say obscurity is going to save me. But really the answer is they have to understand if they're going to connect it to the network.
Chris Robertson (15:51.502): and bring in someone who does understand the complexities to it. And I know your background with especially oil and gas, like that's a mandatory. They can't disconnect an oil well that's, I don't know, a hundred miles from the nearest person. So, you know, that stuff makes a ton of sense. But I think, go ahead.
Aaron Crow (16:4.312): Right. Yeah.
Aaron Crow (16:10.168): Well, and you've got to have it. So I have a prime example of both of those scenarios, but the disconnected one, right? Obviously Stuxnet is a great example of that, which obviously that was, you know, whoever there was a military agency that went after that intentionally. You know, we all know that story. But there's less malicious ones as well. Like I supported nuclear power plant and the power company I worked for.
Aaron Crow (16:37.858): There was a vendor, I won't say if it was our place or something that he talked about, but let's just say that, you know, it was an air gap system for sure. Like the nuclear environment, those systems are very, very well protected. They have tertiary systems and they have backups after backups after backups of, you know, how everything works. But there was an example where a crane inside the protected area, not networked to anything, somehow got malicious code on it. We found it, you know, we went through all the steps and they had, you know, scanners and
Aaron Crow (17:7.512): kiosks and all that stuff. We found it. We reloaded. It was acting wonky. We reloaded from factory load, all that kind of stuff. We being, you know, the company actually did. And then 18 months later at the reload, the refueling. So every 18 months there's a, there's a refueling outage at the, at the plant. They also had more maintenance come in. The same thing happened to the same crane after that. Well, what happened was the, the,
Aaron Crow (17:34.464): that was coming in doing normal maintenance on the system was bringing their laptop, again, going through the scans, doing all the things that we had in our program. It's not like we wrote something in a program and they weren't doing it. They have documented steps of everything they were supposed to do and they followed it to the T. But as we know with antivirus, it's a blacklist. if it doesn't find something that's in its list that it says is bad, then it's like, it must be good. And they were bringing in a malicious code.
Aaron Crow (18:1.924): and they did it twice, two outages in a row. So that's the point is you can't protect from that, right? luckily it didn't do much harm, it was just there, it started acting a little wonky, we figured it out. It wasn't a big deal, but the point is, is just air gapping or just disconnecting doesn't remove all my risk. It just removes one attack vector. It doesn't mean there is no risk.
Chris Robertson (18:23.500): Yeah, and I think that's a lot of people struggle with comprehending. I think if I just separate it, set it aside, and I just create a limited interaction with it that I've covered myself, but there's still risk. And now you have to do the risk analysis. Is it worth remediating? Is it worth building a better structure around it? Or do I take that risk and run with it? I think when you're talking about inside a nuclear plant, the equation
Chris Robertson (18:50.958): for that risk and the risk tolerance is a lot different than it would be for a lot of other operational environments. But if you don't know that you've got a vendor who's coming in to do that, it's hard to plan around that riskfully. But that's one of the things that we in information security have to figure out to manage that process, And there's always a gotcha. It's like...
Aaron Crow (18:56.110): Sure, yeah.
Chris Robertson (19:19.470): Oh, you were, you're doing what? Okay. And to be fair, there's a number of times it's, it's on me. Like I'm the guy who was in charge of that, that thought process and I didn't identify the problem or I didn't identify the opportunity. And it's like, okay, you're going to be a person. You're a human and you're going to do what humans do, which is not everything we plan. Right? So they're always going to create their own version and we're not going to be able to anticipate it. And so
Chris Robertson (19:47.946): that really falls on us. you know, that it kind of actually leads into like what my, I've been thinking about a lot is how do we like build security into a business as a fundamental way and move it outside of like just bolting something on place or in place to manage and remediate situations. Like how do we build a, an entire culture that's, you know, that thinks about cyber security.
Chris Robertson (20:17.550): And I'll give you an example. I was looking at the, an MBA curriculum and roughly 50 % of that curriculum is accounting and finance. And then there's other stuff that you need to, to learn to manage a business, but there's nothing in there about information security, about what risk management, how to identify risk. And I think that we need to start shifting that focus a bit.
Chris Robertson (20:45.720): to get other people outside of information security to go, this is a real thing and we can either ignore it and there's going to be a cost or we can adopt it and we're going to save money. And we turn it into something that, you know, can actually help business from the way that it prevents or even improves a situation for a company. And I'm sure you've seen where a lot of companies will go and they bolt on a security solution and all of a sudden the productivity of our user drops 20%.
Aaron Crow (21:15.128): Mm-hmm. Mm-hmm.
Chris Robertson (21:16.110): because now they're going through too many sign-ins or they've got, they have to pull up too many different, disparate applications to pull up data or, you know, the list goes on and on. Right. So I think if we, as information security professionals can look at that situation and figure out how to better set it up, and that includes IT people who are going to be heavily involved in it, but trying to design that security into every daily process of the business, we can help.
Chris Robertson (21:45.632): reduce a lot of that human like oops. and I didn't realize, and I think a lot of it is just that mindset. Like if you've got, if you've got that guy who's the vendor is coming in and he's been like thinking about security cause it's just like a mantra that the company beats a drum, he might go, Hmm, this laptop has the ability to bring in a bunch of stuff that they don't anticipate for this crane.
Aaron Crow (21:49.230): Mm-hmm.
Aaron Crow (22:13.399): Mm-hmm.
Chris Robertson (22:14.350): Maybe I have to think about what I'm and it may not work, but it might improve the situation.
Aaron Crow (22:16.099): right
Aaron Crow (22:20.694): Exactly. Yeah. And you know, there were easy solutions around that. Like instead of we call that a transient asset. So instead of that, instead of them using their laptop, we dedicated a machine that they would go plug in and it never left the site. So there was no way it could get infected outside. And then all we had to do is get the media through. And then we had multiple levels of scans and all the things. it a hundred percent foolproof? No, but we improved it like we learned and we improved. Right. And that was the goal is, is really that,
Aaron Crow (22:50.156): security mindset of really changing and adapting to your point. You know, in these environments, especially in OT, we have a safety culture, right? So it's, you know, a safety zero, zero impact. I don't want to have a safety incident. Like you see it in, you know, you go to a power plant or you go to a manufacturing facility or, or, you know, a warehouse and there's, there's safety. You've got PPE, know, protection equipment. I've got safety glasses and hearing protection and steel toe boots and all the things we need to look at.
Aaron Crow (23:18.788): our systems in that same way. Until now, to your point, we've been bolting on a lot of security because the system wasn't designed with security in mind. Many times the systems were designed 10, 20, 30, 40, even longer ago, years ago, and we're just trying to bolt on. And they've upgraded because they want to get, you know, process data out and they want to get logs and they want to get, you know, efficiencies out of the system. But by bringing that commercially off the shelf equipment into these O.T. spaces,
Aaron Crow (23:48.260): we're bringing in all those inherent risks that we've been solving for 20 plus years in the IT world. And now we brought them in, but we didn't bring all the lessons learned from all of those things in. We just brought the technology and the coolness and we're like, oh crap, now we have malware and all these other problems in these spaces. it's not that we should not do it, because there's definite benefits and we absolutely get huge efficiencies out of doing these things.
Aaron Crow (24:17.080): But to your point, like we need to look at this holistically as a risk, not just a cyber. Like cyber has been this step son of a word a lot of the times in that it's always expensive, it's always difficult, and nobody wants to talk about it. Nobody wants cyber, they just wanna have a safe system, right? So we've gotta get into the place where we're designing this as a risk and just cyber is another risk just like.
Chris Robertson (24:30.636): Yeah.
Aaron Crow (24:45.218): safety and the market, right? Those are all risks to my business. Cyber is no better or worse. It just needs to be considered in the beginning in the designing process. National Labs calls this cyber informed engineering, but it's a bigger picture of just really looking at the big picture of the system and the health of it. And cyber is just one of the many risks that are there.
Chris Robertson (25:8.386): Yeah, I actually started thinking about cyber risk, just cybersecurity as akin to accounting 150 years ago. So could you run a business without anyone in accounting? Absolutely. Now, would you be able to identify every product that was a loss leader versus products that were driving most of profit? Maybe not. Like you might have some intuitive feeling, but you could still run it. Would you catch the guy who's embezzling?
Aaron Crow (25:21.668): Sure. Yeah.
Chris Robertson (25:37.738): maybe like when he shows up in a super nice car and you're like, well, that's weird. I don't pay you that much, but otherwise you may not catch them. I think cyber is kind of getting to that point where, yeah, you can go without it. But if you go with it, you might identify a lot of like costs that occur in the case that you guys are talking or you're talking about with that crane. There was a cost to sit down format that, that operational software or that controller.
Aaron Crow (25:43.448): Right, right.
Chris Robertson (26:7.022): set up again. You that was a cost that you guys identified Zach and wonky. You know, let's just say, put a number on it. Just call that cost 15 grand. Well, that's 15 grand that was lost due to a, an incident really that, you know, if the program was designed, knowing what could have happened, which you couldn't have predicted everything, but that's a cost savings for the next time. So I think if we look at information security programs as more of like a core
Chris Robertson (26:36.418): function like accounting, we can start seeing that if we do consideration for it, we can start identifying ways to reduce costs. We can identify problems ahead of time before they get out of control. To me, the analogy is great and maybe it's just the way I think, I think if we separate it by a century, that seems similar to me.
Aaron Crow (27:0.693): Yeah, the whole ROI, is you're right. Like again, accounting, you don't necessarily think about accounting as a way that you're more profitable, right? But you are finding efficiencies. I don't know about you, but I've walked into organizations and they've got five different antivirus solutions and they've got five different patching solutions and five different of whatever solutions because different organizations are using different things and they implement them differently. And it's just like, wait, time out.
Aaron Crow (27:28.886): If we had one, not only would it be more efficient, but it would be cheaper because we'd get cost, you know, economies of scale and licensing and negotiations and all that type of stuff. Instead, we have one that's sitting over there, not being used at all. We've got three that are over there only partially used in the one that we use the most. If we just deployed it across everything, it would be half the cost of what we're currently spending, but nobody knows it because it's not getting bubbled up.
Aaron Crow (27:55.928): we've got shadow IT, like there's all of these problems and having that understanding of that system beyond just the cyber aspect, but you can make it more efficient. can understand, you know, the other side of the cyber thing is that sometimes you, know, the cyber nerd in you just wants to lock it down to the most secure version, but that doesn't make it work for business. Like there's a happy medium in there where you can't just
Aaron Crow (28:23.032): you know, lock the door and not give people the key. They have to be able to get in and it can't be so convoluted. They can't need a blood test and a urine sample and you know, a retina scan and you know, to go to the bathroom. you have to be, you have to make the controls and the mitigations align to the process and the environment and the cost of it as well.
Chris Robertson (28:45.088): Yeah, I mean, if you think about it, I don't, I imagine you this too, Aaron, but many times in my career, whenever someone shut down some access I had, I I'm like, well, I can't do my job as well. So I'm going to go around it. And being technical enough, I could just move sideways through the system and go back to what I was doing. And at one company, I had a whole group underneath me I didn't want to teach them how to do it too. So
Chris Robertson (29:14.808): They would come to me like, Hey, Chris, need to access so and so. I'm like, all right, cool. And I'd go and do it and then pull, just let them sit at my computer to access whatever they were trying to access. And that's the thing. If you make it too hard, people are going to find a way around it. Now, whether that be, you know, one time we had a rogue wifi in our office and I remember the director of IT came up to me and he was like, Hey, is that yours? Are you trying to get around?
Chris Robertson (29:43.660): the firewall and I'm like, no man, I can do that other ways, but I'm like, I wouldn't be throwing up wifi because we wifi was fully banned in the environment, but someone actually put up a wifi antenna, plugged it into our network and then was also using a cellular connection to bypass the firewall when they didn't want to access local network resources. So somewhat sophisticated person.
Chris Robertson (30:13.740): But people are going to get around everything, right? And the more we try to tie their hands, the more likely they are to avoid it, to not do it. And the business is just going to get upset. So next time you want to go to the business, you're like, hey, great, guys. We got this new thing that's going to protect whatever. And you go, let me put some more stuff on the things that you already hate and you're not doing. You're going to get a lot of resistance. Whereas if you come in with them, you're like, let's look at your processes.
Chris Robertson (30:43.032): Let's look at how you guys function. Let's see how the current systems are working for you. And if they're causing you too much of a problem and it's a risk that you guys don't accept, now we can change what we're doing and we can put something in place that makes sense for you guys. But the, you said, the, the security nerds inside of us are just like, dude, we got to block everything, shut it down. And I would, you know, it's not even just security. It's just the, I think it maybe it's an even IT mentality. Cause I remember
Chris Robertson (31:13.198): decades ago, we would, we would have, I'd have guys come in working for me and they'd start shutting everything down. I'm like, dude, don't do that. We're going to get a revolt amongst that group of people because yeah, going out to that, the internet and those things is making them less efficient, but they got a hard job and it gives them a break between, you know, their tough phone calls. I'm like, and the owners of the business accept this and it's a risk they're willing to take.
Chris Robertson (31:42.666): we as IT people have to support that decision because it's not our decision. And you know, it's, it's tough for a lot of like ideological people to accept that sort of thinking where they're like, man, what if they do Mike, you know what? We have to trust the people are going to decent decisions. And we also have to recognize that, yeah, they might do something bad. So we got to protect the environment over here, keep it, you know, isolated as much as we can limit.
Chris Robertson (32:12.022): whatever damage they get into on their own, because the business accepts that, we will let that be, but we will protect as much as we can from the consequences of what they're doing.
Aaron Crow (32:23.363): Yeah, I mean...
Chris Robertson (32:23.758): But that's just common sense, right? But I mean, that's a tough thing that I think when I talk to a lot of other CISOs and just people at different organizations, they're coming from the policeman standpoint of like, here's the law, we put it together, and the business doesn't understand. And I think when the business
Chris Robertson (32:52.418): starts getting pushback, then there's a lot of animosity and people are starting to butt heads. And now you've got a breakdown of the entire operational program. And you got to avoid that at all costs, I think. Because once you get to that point, it doesn't matter how good your security is, no one's going to agree to it.
Aaron Crow (33:11.598): Yeah. Yeah. And, and, and a lot of my world, I see that and, and I've seen it in so many organizations and it's, it's the, the mentality of the tail wagging the dog. Right? So it is not the reason the business exists. You are, we as it professionals, as OT professionals, the cyber security professionals, we are there to support the business. Not, we don't drive it. We don't, we don't dictate it. Like we are
Aaron Crow (33:40.824): We are absolutely a support organization to support the main thing that they do. Cause what we do does not make them money unless you're in a cybersecurity company and you know, that that's a different conversation. We're not talking about those. Like we're talking about, you know, companies that are making widgets that are selling things that are, you know, OT or IT, whatever those things are, a financial company, a bank, whatever your IT organization is not the reason you exist. And so many times I see these power
Aaron Crow (34:7.618): And I don't think they're doing it maliciously. Many times, sometimes they probably are, but many times they're not. They're trying to do what they think is right. So they're really passionate about it. Like they know that this is best practice and you should never allow these things. But what they have, what you have to remember is in these roles is you are supporting the business. If you make it so complicated that they can't do their job.
Aaron Crow (34:30.122): one of two things is going to happen. Either they're not going to be, we're not going to be able to create the widgets and we're going to lose market share and we're going to close shop. And then you're not going to have a job anyways, or they're going to go around you. And then when, when you walk in their office, they're going to be like, get out. We're not using you. I don't trust you. You don't understand my business. I don't like you go away. And I've been on both sides of that coin as the person they told to leave and the person that told somebody to leave.
Chris Robertson (34:56.174): Yeah. Yeah. And that happens, like you said, it's way too often. And I think it's to be fair, a lot of businesses have zero tolerance for like, don't you touch anything we do. I don't want you to get involved at all. And so I'm not going to put the blame fully on us as security professionals, but you know, it's a two-sided thing. You know, we're often responsible for, you know, starting those situations, but
Chris Robertson (35:25.986): people that don't realize that there's a need and driver for it, you know, they're going to run into a lot of problems on the other side. Yeah. We can't exist without that business, you know, functioning. And I, I, I've tried to create the, think about and try to implement programs where we come in and we, I'm sure you've walked into a number of situations where you watch someone doing something and you go, well, this
Chris Robertson (35:54.680): This seems messed up. Like I'll give you an example. I was going into a healthcare company, that's a customer of mine and I, I ended up having to sit outside for much longer cause I first I showed up early than they, their meeting ran long. So I was watching and I could hear someone, they were booking a series of appointments and I could see the person behind the desk and she had to keep
Chris Robertson (36:24.238): scanning her fingerprint over and over and over. And it took about five minutes per appointment to book. And this person was booking, I don't know, it was like five or seven appointments or something, but they, it took almost a half an hour, right? At a half an hour, I finally went in and I was like, that's messed up. Like whatever's going on there. And later I went back to the receptionist and I was like, I told the person I was meeting with about it and I'm like,
Chris Robertson (36:53.422): I mean if I'd go chat with them about what was happening and they go, they accepted the situation like, it's just, just how it works. And I'm like, it shouldn't take you five minutes to schedule someone's appointment. Like I saw you scanning too often, authenticating, you're looking up some sort of calendar stuff. She was checking the schedules and different applications. I was like, now maybe someone already evaluated goes, this person's pay isn't enough to justify improving that system.
Chris Robertson (37:23.160): which is unfortunate, but I think we have an opportunity at businesses to, to add extra value where we go, we just see this stuff and the business unit may not know better where they look at and they're like, you think we could improve that for a minimal adjustment or minimal cost and minimal investment? Yeah. Now all of sudden we've been saved that business, you know, I don't know, let's say 10 % of their labor just by removing a lot of roadblocks from
Chris Robertson (37:52.268): Maybe it's legacy programs that had bolt-on security that just weren't functioning well, or maybe it's just a poorly designed system to begin with. Whatever it is, I think we've got opportunities to see it, interact with it, and then help businesses improve that process.
Aaron Crow (38:9.720): Yeah, it's we're all in the same team. Like we all have the same Jersey on like whether you're in I.T., you're in the business, whatever. Like we're on the same team. Right. And Neil and I talk about this a lot and we do business at the speed of trust. Right. The sooner, the faster that you as the I.T. professional, the cybersecurity professional, whatever, the sooner you can get the business to trust you, the more likely they are to, you know, to
Aaron Crow (38:38.350): to work with you, right? And when one of the superpowers that I have in this OT space is because I've worked in OT and I've worked in IT, I kind of understand both sides of the coin. I've worked in the power plant. I've worked at the manufacturing facility. I've worn the steel toe boots. I've worked during outages. And I've also been in the data center, doing server upgrades and all the policies and all the things that go on that stuff, right?
Aaron Crow (39:4.932): the superpower that I have is being able to kind of translate those two worlds and come to a realization, help the business understand the concerns and the risks from the technology and the IT side, as well as translate to the IT side, the concerns of the business and why they're hesitant to lock things down. Something as simple as like I've had IT
Aaron Crow (39:31.650): you know, say, well, you can't use this model of switch that you guys have been using that the manufacturer gave you. We only use this model of switch and that's fine as long as it works with the manufacturer. And the other piece to this is, Hey, but you can only go through our support. Okay. Well, okay. So the question is this thing fails at seven o'clock in the morning on a Sunday. Are you answering your phone? Are you going to come out and replace the switch?
Aaron Crow (39:59.736): Do I have a spare that I can do? Well, you have a spare, but you won't be able to get the configuration. So this doesn't work. Like you can't just lock it down and say, well, this is mine. You can't log into my switch because it's my switch. That's fine. If you're going to be there at seven o'clock in the morning on Sunday, and if you're not, then you can't do that. Like you can't have both. Like you have to release some control and some trust to me and the business. If you want us to follow your path. Otherwise, that's when you get shadow IT.
Chris Robertson (39:59.868): Yeah.
Aaron Crow (40:27.640): That's when you get kicked out of meetings and they're saying, don't come to my site.
Chris Robertson (40:31.170): Yeah, absolutely. And I kind of go on on that, that subject line. I think my superpower comes from, I've, you I've been in IT, managed IT departments. Then I got, I got, did marketing as well. So I started getting into the more business side and generating revenue for the company. And then I, you know, I actually ran a sales group as well as doing IT, just cause we were a small business. So we're wearing multiple hats, but getting exposure to running,
Chris Robertson (41:1.144): purchasing, running, planning, running all those different departments. Now when I'm in security, there's like, okay, well how's this going to impact the accounting group, the purchasing group, the planning group production? Like what are we going to do? How do we make sure those guys are not like going, man, security, these guys are killing us. And it's funny, we, I've been hired at multiple companies to come in as a secondary opinion behind an existing VC. So
Aaron Crow (41:19.396): Mm-hmm.
Chris Robertson (41:30.642): or a consultant and they come in and I'll see stuff and I see ultra conservative thinking where companies are being told they got to spend millions on solutions where there's an alternative path that is wildly cheaper. And I'm like, you guys could do that. Sure. Or you could implement one of three other options with varying degrees of costs, but they're all cheaper.
Chris Robertson (41:59.566): they're all going to meet the requirements for the program and they're going to work better for your employees. You're not going to have someone who's going to be upset. You're not going to have the alert fatigue or you're not going to have, you know, someone who's having to scan too often to meet something. So I think, you know, just that diverse experience that we all have, you know, we have to utilize that and bring that into our daily lives within our jobs to go. I'm not just the security guy and the technician. I know I'm the guy who's been over there.
Chris Robertson (42:29.334): and done that. So let me think, how's that guy gonna respond? We have to deal with that. I hate saying it, but we have to be empathetic about those other people. And how do we make sure that we're empathetic to them doing their job, making sure that we're helping them meet their goals while also protecting their future job and the company itself. So it's a, it's a wider role than just going, let me just protect and lock everything down.
Aaron Crow (42:56.184): Well, you know, we think about this in products. There's a reason why Apple is so, so, you know, prevalent and everyone has one, right? It's that user experience. We think about that when we're using a platform, when we're looking at a software package that you that UX that user experience is super important. You have to expand that beyond just the product itself. Like, so if we have a system of tools in our, in our, in our environment, it's more than just
Aaron Crow (43:24.508): the technician that's logging into the interface. It's also the end to end of the process. And we need to consider that as part of that user experience as the person on the ground that's having to actually do stuff. If I'm having them to your point, if they have to scan something and it takes them five minutes to do a task that used to take 30 seconds, that's a cost. There's a frustration cost. There's an actual hours and time and resources. And there's an exponential cost to that.
Aaron Crow (43:53.984): All of these things need to be need to be weighed and this is where truly understanding and sometimes you know when I'm brought into to do an assessment on things obviously I look at the cyber you know yeah you've got a missing firewall rule here or you know the obvious things you've got Windows XP plugged directly in the Internet you're gonna die you know all the stuff that happens but a lot of times it's simple stuff it's like you've made this process way more difficult than it needs to be like if you just remove this out.
Aaron Crow (44:20.484): or disconnect this or turn off RDP, then you don't have to worry about patching it. Like, yeah, it's Windows XP. We're not going to rip it out. It's sitting there. It's been there for 20 years. Just put a crunchy bubble around it and let it do its thing and monitor it. Pay attention to it. Don't let anybody plug a USB stick into it. Don't let it connect to the Internet. But as long as you do those things, it's going to continue to run into perpetuity. Like it's just going to do its job. And sometimes that's enough. That reduces my risk enough where I'm I'm comfortable accepting that risk.
Chris Robertson (44:49.422): Yeah. And I think that's where, have you ever heard the adage that human beings are terrible at understanding statistics and risk? Like we, we don't really know what a one in 15 chances we like, you we can't, we could do the math and look at it at a calculator, but what does that mean? So I think a risk, when we do this risk analysis for businesses, it's kind of the same. We, we talk about it, but we start throwing dollars on it that helps people take that
Chris Robertson (45:19.212): that percentage and turn it into something that's a little more tangible. And we go, you got that XP machine and the probability that it is going to happen based on the new crunchy wrapper we put around it is 2%. Well, the cost of it going down is, you know, this amount of dollars, the cost of we don't put that crunchy bubble on it and it gets infected and then it becomes an entry point into our wider network. And the havoc that can be caused is this.
Chris Robertson (45:48.846): Now people can understand it, but when we just put statistics around stuff, people, you know, they can't process what that really means functionally. They just see numbers and they're like, well, know, one in 15, one in 20, one's a little worse. But when you throw numbers on it, you know, people start to get it and understand it a little bit better. And I think that's where, you know, making that shift from the probability of something occurring, the likelihood of damage, you know.
Chris Robertson (46:18.552): the resulting implications or mediation. That's where we can just boil it down and make it really simple for that group. And I think that's a key part of our jobs, right? That's what we wind up talking a lot with our customers is how do I put this in dollars and cents for you to go, okay, I get it. You know, one of the harder things I have to talk about people's reputation. That's a harder thing to put out there. know, personally, it's easier.
Chris Robertson (46:47.086): to talk to someone about reputation. But when you start talking about a business, it becomes a little more nebulous. So that's one where I think that I still have to do some journey on figuring out how to like communicate reputation risk and cost to people. But I think it's also something that we often overlook,
Aaron Crow (47:8.396): Yeah, you know, and we briefly talked before about, you know, the difference in digital and cybersecurity for a person and take a look at a celebrity, you know, name a person, Taylor Swift or whomever that may be. They're more than just themselves as a person. Like they are a brand, an entity, almost a corporation. And many times they probably have a corporation that's linked to that, right? But, you know, if you attack Taylor Swift or somebody like that,
Aaron Crow (47:38.020): It's more than just her as a person, right? Obviously she is a person. She's a human being just like you and I, but she also is this brand and there's this business that's attached to it. So her reputation directly impacts her ability to sell records and sell out concerts and sell t-shirts and all the things that she does and all of the people of that that caliber do. Um, so a business is no different. Like if I'm, if I'm a mom and pop shop selling water or whatever the heck that I'm selling,
Aaron Crow (48:6.476): my brand is that thing, that entity that if I get attacked and somebody steals my information or I had a thing I went to the other day and I took a friend as a guest and there was a fraudulent charge on their card. And so they reached out to me like, hey, do you know anything about, obviously it wasn't me, was the place that we were at. But again, I took them as a guest and I'm like, no, let me reach out. Well, apparently it was just somebody got their information and, but still,
Aaron Crow (48:36.248): the fact that they went to this place and then there was a fraudulent charge at that place, it didn't leave a good taste in their mouth. Like they were very hesitant to go back there and trust that they could buy something without somebody stealing something. Now, again, they figured it out, but it doesn't matter. It doesn't always matter if it's true. My perception of something is going to impact it, especially now with social media and all that. It's very easy for something to spiral out of control before you can
Aaron Crow (49:5.656): get access and whoa, time out. That's not what happened. Here's the truth.
Chris Robertson (49:9.738): Absolutely. Yeah. And I think that, you know, the more that people, you know, realize that and accept it and like, you know, the better will be. know, celebrities realize that, right? But everyone else doesn't see that because celebrities can probably point to someone else who had the reputation tarnished and then that person disappeared from the celebrity world. But I think businesses don't see that as often.
Chris Robertson (49:38.026): I mean, Wells Fargo is kind of the case where they've been majorly hit multiple times and more than likely people, a lot of people don't know. know, so I hear people talk about Wells Fargo specifically like, man, those guys done a lot of stuff. They've got a lot of trouble for, and I'm like, I, I bet less than like 5 % of their customers left because of it. So there's a, there's that.
Chris Robertson (50:7.436): I guess, mega corporation mindset where maybe they don't have to, but I think that that's, yeah. I don't think that's sustainable posture.
Aaron Crow (50:11.684): Too big to fail.
Aaron Crow (50:18.732): No, not long term, especially not today as things are as technology levels, the playing field of a lot of these things. You know, back in the day, the Wells Fargo's of the world, you you had to be that big entity to be able to compete. And now you just don't like. Yes, obviously, I'm not saying I can compete with Wells Fargo on the banking platform, but there's a lot of newbies that are out there. mean, there's there's a lot of banking that has been kind of turned on its head and technology is only going to make it even more so.
Aaron Crow (50:47.966): And that's going to be the truth in all things. mean, again, back in the day, you had to be on the news channel to really get your voice out there. As we know now, there's influencers and podcasters that have way more reach than any of the broadcast networks, any of the newspapers, any of that type of stuff. And I'm not saying it's good, bad, or indifferent. It just is what it is. Technology has changed the way we do things. And you can either adapt or you can not and see how that works out for you.
Aaron Crow (51:17.934): But I mean, again, you know, Joe Rogan, for instance, has more listeners that listen to his podcast like him or not that there's, there's millions more people that listen to his podcast and listen to the most popular CNN, MSNBC, anything else. And he's not even a news guy, but it's just, he gets more, more listens and more eyes than anyone in the world. And so that power is important. At the same time, it's very easy that Joe's reputation could get tarnished by
Aaron Crow (51:46.828): any number of things and that could impact his ability to do that. So all of these things are tied together. We have to look at these risks holistically and understand what the risks are. And to your point, we suck at judging that risk and saying what, and my experience is especially in those spaces where they do have OT and the CISO or the executive leadership team doesn't have an OT experience. They don't really understand the thing that they're creating. So.
Aaron Crow (52:13.860): If you work at a power company and the CISO didn't come from the power industry and they're a, you know, they're a consultant or anything like that. Yes, they understand the cyber side of things, but they may not understand the business side of things and that can impact you. That doesn't mean you can't do a good job. It just means that you need to let your ego down and make sure you have somebody sitting at the table that understands that business risk. So then when you're, when you're accepting the risk, you can look at that person and say, do I understand what I'm accepting here? And really make sure you understand the business process side of it as well. Like that's.
Aaron Crow (52:43.648): Again, it goes back to we're on the same team. We need to be looking at this holistically from a we all want this to win and I don't have to be the one that comes up with the answer. I just want us to get to an answer collectively and then we go forward.
Chris Robertson (52:55.598): Yep, absolutely. And I think that's, you know, that's what we're all struggling to get to, right? We're going to work our way to that point and make sure that we, or least we hopefully, we make sure we get to that understanding and that agreement. And now it's just making, you know, spreading that message out there and, you know, talking to people and making them understand the opportunities and the risks that are involved so that they can go, oh, makes sense.
Chris Robertson (53:22.350): It's a thing most of us are reasonable, right? And we're going to look at a situation and we're going to go, OK, I'm going to go ahead and hear what you're saying and maybe I'll make some adjustments in how we're functioning to take something into account. They may not buy into everything, but at least if we get a better adoption rate, at least to some degree, that's an improvement. That's all we can do. Just keep improving.
Aaron Crow (53:42.372): a percent. Yep. Constant improvement. And that's the other piece to this. I think we mentioned it earlier, but there is no goal line. You're never done. Like it's like going to the gym. Like you can't go once and say, I'm done. Like I worked out in 1982. I don't have to do that again. Unfortunately, that's not the way it works. We got to keep doing it. If we want to continue to improve or you're going to go the opposite direction, which I know that firsthand. So, um, with, with all that to say, um, you know,
Aaron Crow (54:10.980): I kind of lead with or end with this question and I did prep you a little bit, but next five to 10 years, what's something, you know, maybe come up over the horizon that's exciting that you see and maybe something that could be concerning.
Chris Robertson (54:23.576): Well, you know, thinking about that, it's kind of just kind of constant improvement, but within security. So I was having a conversation with a big company about a different role, and they were talking about AI security development, and they were telling me they're running about 18 months ahead of what's publicly known from their security development perspective. And it was pretty interesting what they were doing.
Chris Robertson (54:53.718): Then if I flip to the other side about the bad actors, they're running with similar tools, maybe not the same researchers, but they're creative and they've got access to boatloads of data. So now they're implementing AI in their attacks and they're getting through places we've never seen before. They're discovering tons of zero day on the, you know, the defensive side. You know, we're trying to build a same, the same sort of AI protective system.
Chris Robertson (55:24.428): And it's a war, So I think we, I'm sure tons of people have talked about it and I don't think that there's ever going to be a winner. So from a functional standpoint for people with insecurity, you know, we're going to have people's jobs change, but they're still going to be there. They might dramatically shift. They might have a lot less work in analyzing events, but there might be a lot more work in another area that we're not seeing. So
Chris Robertson (55:52.620): I think there's going to be a lot of upheaval, but overall we're not going to see a big shift in our labor. It's just our labor is going to be reapplied to other areas. And, know, it's a, it's a double edged sword, right? Like we're going to have a lot, I think we're going to go through a lot of like, bad dark events where someone got the better of a critical system and took advantage of it and hurt us. Whether it be a state actor or just.
Chris Robertson (56:21.612): someone out for a buck or just script kiddies, right? Like that have found something amazing. So we've got that side. So I think we're going to, we're going to suffer more things like that. And then on the defensive side, on the defensive side, we're going to get better, but it's just a, it's a, it's an arms race, right? So as we know from like the cold war, there's, there's no winner in the arms race except for the people making the arms. Those are the only winners.
Aaron Crow (56:24.418): Yep.
Aaron Crow (56:47.714): Right.
Chris Robertson (56:51.142): And everyone else is just going to suffer through that. So as us as professionals in that environment, we're just going to be going along for the ride. And on one hand, it's exciting to see what we can develop and create and how we're going to completely retool our infrastructures to accommodate tons of new AI agent-based security and processes.
Chris Robertson (57:17.368): But I think that there's too much unknown to really predict what it's going to be other than massive upheaval in our daily programs. I don't think that the wider businesses are going to have a big impact from the security standpoint. I do think that we're going to have a lot of that on the back end and how we're managing it and how we're processing stuff. So you and I are in for a wild time. The rest of the company is just going to be along for the ride.
Aaron Crow (57:46.596): That's right.
Chris Robertson (57:47.755): dealing with negative times, but that's where we're there. We're to limit those negative times and make them maybe a bump instead of a tsunami.
Aaron Crow (57:56.824): Right. Yeah. That limit, limit the exposure and the overall impact of the, of the bump, right? Yeah. So call to action. How do people get ahold of you? Reach out to you, what you got going on coming up in the future, all that kind of good stuff.
Chris Robertson (58:3.778): Yep, absolutely.
Chris Robertson (58:14.124): Yeah, so you're welcome to look at me on LinkedIn. You can reach me at Christopher S. Robertson on there. You can go to Apogee's website, apogeedefense.com. I'd love to talk to people about what they're experiencing. I like to mentor people and coach them on different things. So certainly, I'm always looking forward to doing that. those are probably the best ways to reach me. Find me on either one.
Chris Robertson (58:42.850): You can find my email on both of those. So please reach out. Let's have a discussion, because there's nothing more I like than just to talk to people and learn from their experiences. So you can see I've been having a lot of lighting issues. I put a sensor in place to tell me when there's movement outside, and it's going nuts. So apologies for the crazy lighting.
Aaron Crow (59:6.308): It's like I said, it's a Taylor Swift show. You're like, all the lights are going all over the place. That's awesome.
Chris Robertson (59:10.732): I know, I know, at least it's not changing colors. That would be even worse.
Aaron Crow (59:14.392): That's right.
Aaron Crow (59:17.092): Well, hey man, I really appreciate the time today and the conversation. I appreciate you being at the event the other day. It was a blast. I'm looking forward to more conversations over guns and bourbon and all the things. what better way to get to know somebody than to do more out of the traditional Danish and coffee thing that we see so many times.
Chris Robertson (59:17.454): Yep.
Chris Robertson (59:25.038): I'm sorry.
Chris Robertson (59:40.790): Absolutely. And there's another side of that where you put us in those situations and you learn people that you can trust. Like you watch how we're all interacting. You're like, okay, you know, that person like recognizes their weaknesses, which I highly value. And people are like, look, I'm not great at this. I like that. I like when someone stands up and goes, Hey, I need a little help here. And those situations like that event, you know, highlights when people are honest and you know,
Chris Robertson (60:10.702): I like that. want to be around more people like that rather than someone who's like, I got this. I got it all. I'm great. And that's when you have to go, OK. And maybe they do. Maybe they're a superstar. And you'll figure that out. But at least we can see that pretty rapidly when we've got a bunch of guns around and we're enjoying ourselves.
Aaron Crow (60:31.736): Well, you know, the point, the intention desire with, that is, is to put people in uncomfortable situations, not unsafe, just situations where they're not great. Right. And we have, you know, range officers and safety people and everything there is, is safe. Like even in, know, when we did the helicopter, you're strapped in, but it's still an uncomfortable, there were plenty of people there that were, had never flown in helicopter. There were, there were scared of heights.
Aaron Crow (60:54.730): And I know at least two people that did it and like they were super excited that they did. They were terrified the entire time, but when they got down there, like that was the coolest thing I've ever done. Right. And it's getting out of that comfort zone and being willing to admit I'm not comfortable and I'm not good at this. I'll need help, but I'm, I'm willing to go forth with it. Right. Those are the type of people you want your corner instead of one that's like, I've done this a thousand times. This is nothing and I'm the best. And then they show up and you're like, you're not very good at this. What do you mean?
Chris Robertson (61:23.618): Yeah. Yeah. And just speaking about those range officers, I shared with you a conversation I had there. So I was doing like a kind of pull from conceal type shot. And after I shot a magazine, one of the rangers officer said, Hey, so just be careful with that. And I'm like, and then he walked away and I was like, wait, wait, did I do something that was concerning? Did I do anything that you were uncomfortable with? And
Chris Robertson (61:53.720): Then someone else was doing it and he's like, no, I just don't know you. And so because I don't know you, I don't know your proficiency. I don't know. He's like, didn't, everything I saw was exactly right. I just don't know you. And then like that's the perfect response. It's better to be cautious and go, Hey, be careful, be aware. Then someone who's just like,
Chris Robertson (62:22.348): Like, assume this person knows what they're doing. I'd rather have someone come out and say something to me than not, because that way we're both on the same page. We can have a conversation about it. like, was like, whoa, did I do something that was like slightly questionable? And he was just like, no, I just didn't. I don't know. So I love that. And so the event was incredibly safe.
Chris Robertson (62:52.002): I think anyone from someone who's never shot would be completely fine there. Probably super exciting. There were people out there who'd never shot some of the types of firearms we shooting. And they did amazing. They learned a lot. So it was awesome. Then we got guys that were wildly experienced and did amazingly well. So it's awesome to have such diversity.
Aaron Crow (63:14.220): Right. Yeah. And everybody had a fun time. Like the person that won the shotgun competition had never shot a shotgun before that day, which is just awesome to see. And probably the reason that they were is because they were willing to say, I've never done this before. And they were able to take direction and they had no bad habits and all those types of things. And they were, it went really well for them, right? As opposed to somebody that maybe has done it more, doesn't ask for help, doesn't ask for guidance, thinks they've got it in the bag.
Aaron Crow (63:42.710): And then when the new guy that's never shot before out shoots and there's like, how did that happen? I'm better than them. Well, you, you were better. You were better when you started, but they quickly surpassed you.
Chris Robertson (63:48.843): I have to...
Chris Robertson (63:54.475): I have to throw out logic complaint against that. So one of the guys that was like, I've never shot before and he won my entire group. So he got, I forgot his name. The who was, who was the shotgun expert? The former yet? No, no, no. the guy who'd won Olympic medals, trained tons of, like probably one of the most decorated shotgun.
Aaron Crow (64:9.721): Jay.
Aaron Crow (64:15.103): yeah, yeah. I can't remember the guy's name, but yeah, I what talking about.
Chris Robertson (64:22.638): guys out there, maybe if not by far the most anyway, he's like, who needs help? And I'm like, well, I could definitely use some guidance on how to be a better shotgun shooter because it's not a big thing in my wheelhouse. The guy next to me was like, I've never shot. I'm like, well, I'm not going to steal the time from that guy because he for sure needs it. Like I'll be safe. I may not have a high hit rate. And then he won. He did amazingly well. And I was like,
Aaron Crow (64:23.746): Yeah. Sure.
Chris Robertson (64:52.940): I would have, I actually wanted some guidance and like some pointers. I'm like, and I mean, he needed it more than I did, but shoot, I missed an opportunity.
Aaron Crow (65:5.316): But it just goes to show how when you're willing to learn and you're willing to put your ego aside and you're willing to listen, that doesn't mean that everybody's going to go out the first time when the competition, that's not the point. But the point is, is you can grow really fast. Your ego is the death, right? As soon as you put that ego up and think I shouldn't ask, I can't ask. You know, it's the old adage of, you know, men don't ask for directions. They just drive around endlessly until they figure it out. Like, that's the stupidest thing in the world. Like, stop, ask for directions. Like it doesn't make you less of a man or a woman.
Chris Robertson (65:31.118): Absolutely.
Aaron Crow (65:34.744): to do that, right? It's just put your ego down, raise your hand and say, I don't know what I'm doing. Help people more. My experience is people are more than willing to help you, especially here in the South, but people in general want to be good people. They want to help people. But if you don't ask, they're not going to just butt in and say, Hey buddy, do you know what you're doing?
Chris Robertson (65:56.315): Yeah. And I think that, you know, probably society suffers from more ego problems than anything else. If we could just learn to set aside our ego. And I'm certainly guilty of not putting it aside every time. And I know that, and we, we look back and we're like, dude, I, I could have with that situation better if I just set aside my ego, you know? And you know, that's one great thing is when we're able to like recognize it and be self-aware, set it aside.
Aaron Crow (66:10.030): We all are.
Chris Robertson (66:25.208): know, things get so much better.
Aaron Crow (66:27.398): yeah, a hundred percent. It's amazing. It's amazing how quickly we can learn when we're willing to actually put our ego down and do it. So, well also man, hey, thank you so much again. This was awesome. I enjoy the conversation and I'm sure we'll be in contact many times in the future. Thank
Chris Robertson (66:35.362): Yeah, absolutely.
Chris Robertson (66:44.140): Yeah, absolutely. Well, I appreciate your time and I love talking to you. So I'm looking forward to another event and seeing you other places too. All right. Yeah, you do.
Aaron Crow (66:52.204): man. Thanks a lot. Have a good one.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.