Ep 53: Navigating Cybersecurity Challenges in State Agencies with Joshua Kuntz | PrOTect IT All
HomeEpisodes › Episode 53
Episode 53
Episode 53 Interview

Navigating Cybersecurity Challenges in State Agencies with Joshua Kuntz

Apr 14, 2025 00:41:44 with Joshua Kuntz
OT SecurityRisk ManagementNetwork SecurityLeadershipCareer

Watch This Episode

Episode 53 gets into the intricate world of IT and OT cybersecurity with host Aaron Crow and guest Joshua Kuntz, the Chief Information Security Officer for a state agency in Texas. With a comprehensive background spanning two decades and involvement with seven state agencies, Joshua shares his journey from the Marine Corps to leading security programs in the public sector. 

 

The episode covers a range of topics, including the transition from military to government cybersecurity roles, the intricacies of budget allocation, and the significance of mastering both technical and business soft skills in cybersecurity leadership. 

 

Joshua provides insights into navigating legislative changes, adapting to rapid technological advances, and the essential task of balancing cybersecurity risks with operational priorities. 

 

Listeners are treated to an engaging conversation that offers practical strategies and real-world experiences aimed at protecting critical assets in today’s dynamic cyber landscape.




Key Moments: 

05:46 Ownership Alters Risk Perception

09:39 Technical Leaders Developed Through Soft Skills

11:52 "Value of MBA Over Technical Expertise"

14:29 Navigating Ambiguity in Future Planning

19:46 "Questioning Budget Cuts Amid Surplus"

21:05 Efficient Resource Sharing in Texas

25:31 Remote Work Cybersecurity Challenges

27:36 VPN Secure Access for Remote Work

33:21 Prioritizing Critical Executive Decisions

34:45 Understanding Cyber Risk Impact

38:16 CISO Role: Beyond "Yes Men"

41:05 "Exploring IT and OT Cybersecurity"

About the guest : 

Joshua Kuntz is a dedicated professional who successfully transitioned from a military career as an electronics technician to a role with the Texas Department of Public Safety. Embracing the paramilitary structure of the department, Joshua leveraged his military experience to adapt to the law enforcement environment, focusing on protecting citizens. 

While he found comfort in the familiar rank structure and chain of command, Joshua faced challenges in adjusting to personnel management outside the military realm. Despite the loss of certain disciplinary tools common in the military, Joshua continues to evolve as a leader, emphasizing adaptability and commitment to public service.

How to connect Joshua  - https://www.linkedin.com/in/joshua-kuntz-cissp-35a825176/

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

05:46Ownership Alters Risk Perception
09:39Technical Leaders Developed Through Soft Skills
11:52Value of MBA Over Technical Expertise
14:29Navigating Ambiguity in Future Planning
19:46Questioning Budget Cuts Amid Surplus
21:05Efficient Resource Sharing in Texas
25:31Remote Work Cybersecurity Challenges
27:36VPN Secure Access for Remote Work
33:21Prioritizing Critical Executive Decisions
34:45Understanding Cyber Risk Impact
38:16CISO Role: Beyond
41:05Exploring IT and OT Cybersecurity
Read the full transcript

Aaron Crow (0:1.630): Awesome. Hey, thank you for joining me. Another episode of the protected all podcasts. I've got my friend Josh here. We actually just went to a hockey game the other night. So hadn't been that long since we saw each other. Josh, why don't you introduce yourself? Tell us who you are and, kind of, kind of your background in, this, fun cyber security space.

Josh (0:18.412): Absolutely. So, Jones, I'm currently the CISO for a state agency here in Texas. I've been doing this for, shoot, going on 24 years now. This is my seventh state agency, the fifth one that I've led the security program for. Before that, was six years Marine Corps as electronics tech, which helped me make the transition over to state service. And just really excited about, you know, kind of

Josh (0:47.369): where we're going in this field.

Aaron Crow (0:49.934): So what was it like, so I do talk with a lot of folks that were primary military in that transition. So obviously going from military to state agency and in the public sector, what is that transition like? So most of the folks that I've talked to have really transitioned into the private space, which has been a harder transition. Do you think it's been an easier transition going into the public space as opposed to the private space from that military career?

Josh (1:16.810): Well, I made it, I made it a softer landing for myself. Uh, so when I left the military as an electronics technician, I went to the Texas department of public safety. Um, and so they, uh, they're, know, it's a law enforcement entity that is paramilitary. So they have a rank structure and chain of command, you know, very strong chain of command. so that was a little easier to transition over into, um, similar mission, uh, as far as, you know, protecting.

Josh (1:46.250): uh, the seasonary, uh, and so that was, that made that transition a little easier. Um, I will say that as a manager, a personnel manager, that was a much harder part of the transition. I lost a good portion of my toolbox when I left the military, um, the whole physical portion, um, where, so, uh, that I couldn't the position of attention and berate you for an hour or, uh, make you do pushups until you collapse. know, that kind of stuff was gone now.

Aaron Crow (2:15.652): That's disappointing, I think.

Josh (2:18.313): Yeah, I believe it was difficult the first couple of times I had some disciplinary instruction to give and how to not go back into those old habits.

Aaron Crow (2:31.896): So obviously, again, this is not to be political at all. I don't want to listeners, this is not that right. We see a lot in the news today with new administration coming in and Doge and all the things. And again, I don't want to talk about that stuff. What I'd love to talk about is, since you have been at multiple agencies and their state agencies, but they're still large, is big state. We had a lot of resources and a lot of things.

Aaron Crow (2:58.518): Talk about like what is the differences? So obviously you've seen multiple of those agencies. What's the strengths and weaknesses that you've seen? Whether it be between agencies and again, I'm not asking you to call out by name at all, but really just some of the struggles that you've seen because I know from a private from a private side, a lot of corporations struggle with finding budget and finding the right resources and finding the right, you know, justification to do these projects. Having that experience from from the you know the government side. Can you talk to that a

Josh (3:23.665): Mm-hmm.

Josh (3:29.039): Absolutely, and some of it is a little easier for me in the government side because we have regulations that require certain compliance and there's a floor that we have to meet and unlike the regulatory bodies hold on the private sector on very specific tasks, they get to direct every part of a service security program

Josh (3:57.767): in government space and so I at least had the, well it's required by statute, part of my justification in any of my funding asks. The next best piece I had in making sure that my funding asks got really the attention they needed is storytelling. And I will say that it's...

Josh (4:24.088): I was fortunate enough not to be in any state agency that had a major information security breach, but we have had some. The most famous was the 2010 Comptroller Public Accounts breach where they had a server on the internet that did not have authentication protections and was exposing millions of state employee data. And so it was a big wake up call.

Josh (4:54.153): And the response to that, especially in 2010 when credit monitoring was not an inexpensive thing, the cost of that actually got born out of the campaign war chest of the comptroller, the statewide electric official, and woke up a lot of state agency. Wait a minute. I might have to be partially responsible for this. That's okay. And so they started.

Aaron Crow (5:11.480): Mm-hmm.

Aaron Crow (5:18.412): Right? Yeah.

Josh (5:22.186): Let's make those small investments now so I don't have this big cost later.

Aaron Crow (5:29.026): That's interesting. It's amazing how a little bit of you know, ownership changes that perspective. And it also changes the risk, the willingness to accept risk. Cause a lot of the conversations I'm having with executives and boards, know, board directors, know, C-suite executives, it's all about translating that risk and making sure they understand the risks that they're accepting and that they're really comfortable. Cause it's really easy to accept a risk on paper.

Aaron Crow (5:56.812): without truly understanding what that risk is, right? You look at Colonial Pipeline, you look at a lot of examples where they accepted the risk, but nine times out of 10, if we went back to them and we had that conversation, they'd probably not be okay accepting those risks once they fully understood what that risk meant.

Josh (6:13.827): Yeah, I think that's a big part of the job that is lost to a lot of CISOs. I know that the traditional paths to cybersecurity were network, server, and desktop support. Maybe some folks came through application development, but primarily those areas. Very technical minded. Now we're seeing that start to shift as more more colleges and universities have cybersecurity degree programs.

Josh (6:44.210): but it's a very technically weighted industry and we tend to talk in technical risk. You know, this CVE with this score and this risk level and they don't understand that. You got to break it down. A lot of this job, if you're doing it right, is translation. It's taking those technical risks and explaining how that can impact the business, how that can impact the mission of your organization. I would say that the

Josh (7:13.602): There was some clamor over the new SCC rules, especially in the CISO community when the first rules came out, and it was like, you're gonna require that you have someone with cybersecurity certification on the board. Those of us who've been doing this a while said, oh, wait a minute, there's some board seats gonna open up for us. And then they saw from that, they said, you have to have board acumen, or the board has to have cybersecurity acumen. like, okay, we'll see how that goes. But.

Aaron Crow (7:20.270): Mm-hmm.

Josh (7:42.081): They did add the rules about having to disclose cybersecurity incidents if they were material. And so the question started becoming, well, what is material? How do you define materiality? And who says that it's material? in our, in my circles, we've been having this conversation in the last year or so, it shifted. Initially it was like, oh, well, you know, we need the CISO to tell us if it's material.

Josh (8:10.271): And when you push back and said, no, no, no, no, no, our job is to tell you what happened. You tell me whether or not that's material. And so we started the risk attorneys involved and get people who have a better idea of how to translate that. But that's really that that shift is you have to be able to speak in business language and take that technical knowledge and translate it into something they'll understand. Or it's just a bunch of gobbledygook and they don't care.

Aaron Crow (8:38.892): Yeah, and in my career, so I started out on that technical path you just talked about, right? It was network engineering and architecture and systems administration and Active Directory and VMware, like all of those super technical things. And I got to a place in my career where I kind of hit that glass ceiling, right? I kind of hit the, really can't, there's not much else to elevate me to that next level on that technical stream.

Aaron Crow (9:4.779): So I really had to work on those softer skills and a lot and I wasn't comfortable in those places. And honestly, when they, when they, was thrust upon it. I worked at a power utility in Texas and they put us in this, they, it was, it was very forward thinking, but they created this thing and they called it leadership circle. And within that, they took their top leaders and most of them were technical engineering type folks. And they put them into this leadership circle where we did book reports and

Aaron Crow (9:32.374): had to create use cases, business use cases and go over business risk and do presentations and really those softer skills that we didn't have a lot of opportunity to kind of hone our skill sets on. And again, the first year I was in it, I was annoyed because I'm like, I'm not in college anymore. Like don't want to read a book. Like what am I doing? Like this isn't going to help me configure a firewall and that's what I do. But man, I'm so glad looking back now.

Josh (10:0.894): .

Aaron Crow (10:1.346): that I did those things because that allowed me to get to the next places in my career. It's why I was a CTO of a software company. It's why I was an executive at Ernst & Young and now as a at Morgan Franklin and the things that I've done, yes, I'm still technical, but you don't want me configuring your firewall. If I'm configuring your firewall, then we've had a bad day.

Josh (10:19.453): Mm-hmm.

Josh (10:26.486): Working side as well and if put a gun to my head I could probably Question mark my way through a firewall configuration But it would take 10 hours, which would would normal analyst about 30 minutes But yeah, I haven't been hands-on keyboard in years because of that, you know, I'm in edge programs and personnel and so That has been the part that making that transition

Aaron Crow (10:33.240): Sure.

Josh (10:55.713): from the technical expert to the personnel and process expert who has a technical, you knowledge. It's what really has advanced my career through the years. I do mentor a number of folks and I've given advice to folks that are asking, you how do I get to the next level? I'm going back to college.

Josh (11:23.952): Should I get a cybersecurity degree? And I'm like, well, are you already doing cybersecurity work? Well, yeah. said, okay, well, you don't need the cybersecurity degree. You need a business. You need a business degree. And they look at me where to say, if you're to go from after go for an MBA. Cause that'll give you the skills that you don't currently have. just, just sharpening that knife from.

Aaron Crow (11:32.898): What are they going to teach you?

Josh (11:49.347): real sharp to razor sharp on the cyber security side is not going to help that much. But if you get a new knife, now you have a whole new tool set to make the cuts with. And so it's really more useful the higher you get in organizational structures and the more span of control that you're provided to have those softer skills, as you call them. I know that I went through the state's elite program.

Josh (12:17.065): which is really garrard geared towards building the next generation of c i o's but it was all they had that was you know technical but but we and but that we had those soft skills in there how do you testify in front of the senate how do you how do you prepare a legislative appropriation request what is that process look like how do you build a budget within the state parameters you know

Josh (12:44.696): You know, we do biennial budgeting. So I have to think about what I need three years from now so that I can ask for it six months from now when the legislature's in session and then get it, you know, almost a year, a year and three months from when I asked for it to start to use it for the next two years after that. So you have to think way out ahead of yourself.

Josh (13:12.866): about and in technology that's ludicrous. It changes so fast and the threats and the technology changes and to try to keep up with that is difficult. So I teach a lot of folks that have a mentorship program for CISOs and we teach that process that when you're asking for things, don't be specific. They're not going to be able to publish your list anyway because it reveals vulnerabilities.

Josh (13:42.233): Be general. Ask for a, you know, to take care of a functionality problem. And then once you get there, you can start looking, okay, well, what technologies are going to address this and how much, you know, you have to get good at guesstimating cost and, know, what's out there, what will fit within the budget I got and how do I make that work for the, you know, the landscape that you find yourself in at the moment you actually have the money.

Aaron Crow (14:11.340): Well, and another one of those soft skills, I think you're really talking through is dealing with ambiguity, right? And you don't know the answer to your point. Two years from now, there's no way you can know exactly what technology is available or even what gaps you're going to have or whatever priority of your risk is going to be. But you have to be future case casting something. Hey, I know that I need some some help around.

Josh (14:19.021): Mm-hmm.

Aaron Crow (14:36.620): you know, remote, secure remote access, or even more general than that, you know, access into my environment and, you know, data loss prevention and, and, know, totally whatever those things are that you're cloud based focused AI, whatever those things are, and put a big enough budget in those things and estimations in those things so that you're not trying to, you know, platinum code or gold plate every anything, but you've got enough budget and wiggle room that you can actually get the things done they need to get done, because you're stuck with that.

Aaron Crow (15:4.140): stuck with that budget for the next couple of years after you get it approved.

Josh (15:8.511): And even further than that, mean, who could have predicted two years ago or three years ago the impact that AI is having on cybersecurity? It was a thing, but it's like, well, where is it going? How advanced is it going to be? How useful is it going to be? Is it purely academic? Looking in the future, it's like, well, I know that quantum computing is a thing that seems to be making

Josh (15:38.058): you know some headway and that we may see some what impact is that going to have on you know on the future of cyber security and how do we how do we try to plan for that you know with when the technology is not you know not play super catch-up you know we will have to wait till that comes out and then the next two-year cycle I'll ask for money about it then that's putting yourself on behind the eight ball so

Aaron Crow (16:4.364): Well, and the other piece to this that we all have to fight with, and I'm sure it is even more so, or not more so, just different for you guys in the government space is it's not just technology. It's easy to talk about firewalls or AI or secure mode access or whatever the thing is, but it's people, process and technologies, right? So you need bodies and you're impacted as the CISO, you're impacted by decisions that other people in the government agency are creating, whether they're hiring people or

Aaron Crow (16:33.438): expanding or whatever they're doing in those spaces, those all have things that impact you and you may not necessarily know what those things are going to be until too late. So how do you go about thinking about or planning for those things that you may not even be aware of two years down the

Josh (16:50.367): Well, so the fact that our legislature only meets once every two years for 144 days does have its advantages. That means they also can't come up with new ideas in the middle between session. So the good idea is that can't just visit all the time. So that gives us some predictability in what the requirements are going to be.

Aaron Crow (16:56.994): Yep. Sure.

Josh (17:20.084): talk to my fellow CSOs about this all the time, so you've got to be plugged in with your GR folks, your government officials. If you're not, you're going to have a problem because they need to know that you need to see bills as they're being considered and going to, when they get assigned to a committee, they've got legs. Now you've got to have an idea of what the impact is, and you've to write impact statements. Like, oh, well, this is going to add a whole new...

Josh (17:46.428): regulatory framework to our agency and it's going to require us to look at different data than we currently do. And by the way, that's regulated data by the feds. I got to put different security controls in place. Well, that's going to cost some money. So I need to, you know, I need to add, you know, bodies or funding for, for, you know, new tools or new, new security controls to that bill to say, Hey, that's got a fiscal note on it. It's going to cost me money to implement that because it has implications.

Josh (18:16.669): but not being part of that conversation, it just comes to you say, yeah, so this passed, now you have to do it, figure it out with what you got.

Aaron Crow (18:24.418): right. Which means you're robbing from Peter to pay Paul to try to figure out where you're to find the money. it unfortunately, as much as you know, my kids think money doesn't grow on trees.

Josh (18:34.694): Hahaha!

Josh (18:37.554): Yeah, well, and you know, that is one of the other things we're blessed here Texas is that we can't just print the money. We're constitutionally obligated to have a balanced budget. So we can't run deficit. And that helps because that makes us a little more conservative about the spending. It also gives us the opportunity, if you have a bill that's going to be really crazy, and that happens, you get stuff where people, oh, we want to

Josh (19:6.386): regulate manhole covers and we're like, okay, I don't think that's really necessary. And in order for us to do that, we'd have to increase the number of inspectors we have by, you know, 6,000. you put 6,000 and, you know, you start attaching those kinds of numbers to those bills and they start, suddenly they get disinterested in regulating manhole covers. Yeah. It's a, you know, it's just, it's, it's where you, know, so that's part of that process is understanding where to say, okay,

Aaron Crow (19:25.366): Right. Yeah, maybe that's not as important as I thought it was.

Josh (19:36.461): Is this really needed? Do we need to be a little more, well, you said it, the age of the Doge, and Texas is picking up that mantle a little bit, except it's the council, their committee for delivery of government efficiency or effectiveness. can't remember what E they use, but it's the same. They're looking at how do you do more with less?

Josh (20:6.306): And which I also have to laugh. like, you know, we came into this budget cycle with a record surplus. Why do we have to cut? You know, let's let's let's figure that out. Is that is that really necessary? So.

Aaron Crow (20:23.352): Yeah. Yeah. Well, Texas is unique in that way, right? Is, you know, we have a record surplus, you know, us and a few other States. And again, this is not a political statement, guys. We're not talking politics here. We're really just talking logistics wise of, you know, Texas is in a great, unique position and that they've handled our budget very well so that we're talking about getting rid of, you know, property taxes because we don't need it, right? We're in a, we're in a surplus and we have enough.

Aaron Crow (20:48.768): revenue coming in from other avenues. So offering things like that and still, but to do that, to your point, we have to be fiscal with the resources that we have if we're going to do interesting things like that and continue to grow and be safe and provide services that our citizens are, you know, look forward to and need, whether that be, you know, roads or bridges or, you know,

Aaron Crow (21:12.450): You talked about Department of Public Services or firemen or policemen, all those things that we've grown accustomed to. And not to mention power utilities and our Texas grid is independent of the rest of the country. There's just so many things in a big state like this in any state, really. But but there's so many factors that go into those things. And you said you've worked at six different agencies within within the government. There's so many agencies. And so how much do you guys share and cross pollinate with?

Josh (21:19.726): Mm-hmm.

Aaron Crow (21:42.190): programs and processes and work that you're doing to kind of get the benefit of economies of scale. Because I Texas is big, but we've got X number of agencies that are y'all sharing stuff and are you getting a Microsoft license and like how does that work across agencies?

Josh (22:0.567): So we do have a state central IT department that does the

Josh (22:9.663): large purchasing, thing and that sort of thing. So they get, better contract terms and costs instead of the agency trying to negotiate contracts with Microsoft. There's one major contract to Microsoft for all state agency for buying, you know, email and, you know, support and that kind of thing. have, you know, they do big contracts with the laptop suppliers. So we get, you know, okay, well, it's not just,

Josh (22:37.601): doing a deal with an agency that's 300 people. I'm doing a deal with the whole state government. It's, know, thousands. Okay, now I'm, you know, it's you get the better economies of scale there. And that works. Mostly. You do have some inefficiencies or some lag, because that process is cumbersome. You know, it's like the pendulum swing, right? So it gets more and more cumbersome as people make foolish mistakes, like

Josh (23:7.807): brother-in-law deals and no-bid contracts and so okay so they put a lot more process on top of that and it makes it harder, it takes longer. But if you swing too far the other direction and you get you know less and less requirements and guidelines then you have grift and people doing sweetheart deals and it's you know it's not in the best interest of so you're trying to find that sweet spot of enough

Josh (23:34.793): regulation to make sure that everybody's honest, but not so much that it takes too long. Especially in technology space where things change so fast. It taking five to six years to get on a state contract. The new inventive technologies have come and gone. They got here, it's a thing, and then now it's baked into other things. That's a tough position to be in sometimes.

Aaron Crow (23:42.638): percent.

Aaron Crow (24:5.366): It is, but also if you think about it, the fact that you survived, even though the technology came and went and you didn't get the technology shows that OK, maybe the technology wasn't all that great in the first place and that you could figure out another way around it.

Josh (24:19.422): Oftentimes what we have to do, we just have to figure out how to work through it. With that, like I said, we do have the economies of scale of purchasing. We do have some economies of scale in data center services, that kind of thing. But it gets, because it's so bureaucratic, gets cumbersome to try to meet the business needs of...

Josh (24:48.977): each individual agency who have different missions, have different leadership, executive leadership, who have different vision and have different things that they're trying to accomplish. And so trying to meet all of those and balance between being lean, having just enough staff to meet the need without having so many staff that you have people going idle, it's a tough balance.

Aaron Crow (25:19.298): Yeah, and throw into mix with COVID and work remote and all those things just made everything more difficult. Even, you know, in state governments and corporate and the private sector, all of those things. And we're still having those conversations. I know that's another topic right now is working remote and all those things. And again, not to get to the political thing or say where somebody should work or not, but there's just there's technical and cyber and risk statements to every one of those things. If somebody works from home,

Aaron Crow (25:49.218): then your device is in their home network and then is it safe on that network and what else are they plugging into it? Like there's just all, they taking it to Starbucks and connecting to the public wifi? Like there's just all these other risks that come aboard where you don't have that when you're inside of the office because your device, mean, back in our day, it was a desktop attached to your desk. So it was perfectly safe unless somebody broke in and physically walked up to your desk, right?

Josh (26:15.068): And different organizations have talked about risk tolerance and levels of amounts of risk that they're willing to accept when it comes to how inconvenient can we make the desktop experience versus being secure. I'm fortunate that we're a little risk averse here.

Aaron Crow (26:34.188): Right. Yeah.

Josh (26:45.211): We only use agency, know, agency devices. So it's only managed device under our network. Some of that came out of the government, what we affectionately call the governor's ban on TikTok. where, know, in order to utilize, BYOD, you had to have the ability to, do management of those devices for what, what other applications could and could not be on their containerized the area that the agency data would be on.

Josh (27:14.340): And we're like, you know, I don't, don't have the, we don't have that tool currently and we don't have that, that the extra people to manage that kind of thing. we're just not going to do it. So it's, there's no BOD. You have to use an agency, managed device. We, we have a VPN on login. So when you log in and you're on the internet, it connects you directly to the, to our systems. You don't get to go to the wide, the open internet on, on anything else. So.

Josh (27:43.941): that helps alleviate, I won't say eliminate, but it helps alleviate, mitigate a lot of those risks with the work at home. We still, in many areas, still, well, the government still struggles. If you have regulated data that you're dealing with and the rules around that regulated data were built pre-COVID,

Josh (28:12.217): They don't, you know, they're expecting certain physical protections for the area that that data is being handled, especially if you're dealing with criminal justice information and draconian measures if you're going to try to do it remotely. Like you must be subjected to a physical inspection of the workspace. You have to have a separate workspace and doesn't have outward facing windows.

Josh (28:41.304): or computer can't be facing an out facing window, you have to have the ability to keep family away from you know, unauthorized personnel away from those kind of things. So that it creates a burden and work through that is sometimes cumbersome. I'll say that.

Aaron Crow (28:51.811): Yeah.

Aaron Crow (28:57.710): For sure. You know, it, it, came again, like I said, I came from power utility. It's been a lot of time there and you know, regulation like with NERC SIP for instance, same thing, right? Is, is who has access to that data? Where can you access it from? You know, what data is available? You have to go through training courses to even be able to have access to the databases and, you know, the asset information and all that kind of stuff, right? For obvious reasons, like the data that we're talking about is, is protected. And the same thing goes with PCI, you know, people's

Josh (29:7.524): Mm-hmm.

Aaron Crow (29:26.104): personal information and credit card information and social security numbers. And, you know, we've all been hacked. Everybody's always laugh when people are like, well, they're going to get my information. Like more than likely, if you've been on the internet in the last 10 years, they've already gotten your information and a number of different attacks. You know, I had a security clearance. It's not secret or anything, but, know, I had a security clearance and I'll work for a nuclear power plant. Right. So I had the, the DOE's

Aaron Crow (29:53.646): background check to work at a nuclear power plant. And I also had a security clearance so that I could have, you know, certain conversations with three letter agencies around, you know, risks and things like that, pointed at power utilities in general. that database was stolen. So all the information for all my background checks and all that information was taken by whomever. I'm pretty sure it was China, but you know, whatever. So that information was out there. So anytime anybody's like, well, they're going to get your social security number. I'm like,

Aaron Crow (30:22.358): It's been gone 50 times.

Josh (30:25.473): Yeah, the key is the key is don't give them any extra information to get to your bank. And I talk about that a lot. I've worked at agencies where we had highly regulated data, FTI and IRS data, 1075 requirements and CJIS requirements and federal office, child support enforcement, the social security administration, Department of Labor, Department of Education. And they all had a little different requirements.

Aaron Crow (30:29.006): Correct. Correct.

Josh (30:55.016): requirement on you're doing and so you know that's and and we had you know there's an organization where we were paying out benefits so you know now you have the possibility of fraud in multiple vectors because billions of dollars are going out well apparently with a regulatory entity we we collect a fee and the way we collect it is either you send us a check or you go to the state's online payment portal which i don't manage

Josh (31:25.968): And pay for it. you know, I don't have a massive target because people got all, well, we have millions of personal records. Yes. And they're worth about a nickel apiece. What they want is your bank account or a credit card where they can actually get money. Your PII is, mean, yeah, we have to protect it. We want to protect it. We don't want to be just

Josh (31:54.260): willy-nilly letting people have it, but they're only going to expend so much effort to get that kind of information because it's just not worth it. Now, you're routing it, you're checking account number and you're routing number and a copy of your signature, that's a lot more valuable than emptying out your bank. Get some actual money for that transaction. So that's where having to kind

Aaron Crow (32:17.856): Right.

Josh (32:24.445): temper those expectations sometimes. I've been doing a business impact analysis and everybody wants to believe that their stuff is critical. I've worked at agencies where the data was critical, the system was critical. If the system went down, people's lives were at risk. Okay, that's critical. When I'm doing this, I have these critical applications. You have an important application.

Josh (32:55.002): If that application goes down, will anybody die? Well, no, nobody's going to die. It's not critical. Let's level set what critical is. And everything can't be number one. If everything's number one, nothing's number one. having to go through that, sometimes that's a really hard conversation to have with the group of executives where you're having to tell them that out of the 10 programs we have, yours is number eight. And they're not happy about this. Well,

Josh (33:22.395): You know, that's why we have these group discussions where we can talk about what is actually critical. What is the next most important thing? What's the next most important thing after that? And the surprising one when we have those is you need to be able to get your HR payroll people back to work. Right after your life safety systems. Why? Because your state workers are not going to miss a check and not and still work for you. Most of these folks might have one month

Josh (33:52.629): of slack in their budget where they've got a savings so they can make it one month after the check stops coming. But some of them don't have that. Some of them are waiting for that check to hit so they can go to the grocery store for next week. And we only get paid once a month. If the disaster happens on the 25th of the month and

Josh (34:20.142): And we're not, and we haven't certified time sheets yet. They're not getting paid. And there's a problem. So let's make sure we get those things up first.

Aaron Crow (34:26.616): Right. Yep.

Aaron Crow (34:32.290): Well, it goes to understanding the risk to the business and it's not always a nation state bad actor, know, Russia, somebody coming after sometimes it is, but many times it's not. Ultimately, it's understanding the risk to your business, right? And that cyber risk, it doesn't matter the attack vector. Does it matter that it's malicious or it's it's malware or it's phishing or whatever the thing is? What is the impact? What does impact your business? What is the impact to your employees? What is the impact to

Josh (34:40.347): Mm-hmm.

Aaron Crow (35:1.026): you know, the customers that you're servicing, what does it impact your reputation? Like those are the conversations that you've got to have. And I've been in those conversations, you know, where where the CEO, you know, thinks his email server is critical. It's important, but if the email server goes down, we still do business. Nobody's lives are impacted. We're still able to make payroll. So, yes, your email server is really important to you.

Aaron Crow (35:29.410): But ultimately to the business, it is not critical. Now you can make it critical if you want because you're paying the paycheck and you're signing the checks. But ultimately you're going to have to prioritize that over other things because everything can't be critical to your point unless you have an unlimited budget. And even that you still have to prioritize because if everything's a 10, okay, which 10 do I take care of first?

Josh (35:51.898): Yeah. At some point you got to put them in an order and which one am I first? Cause we can't bring all up at once. So yeah, that's a, that's a good point. And we, we talk about that, you know, the thing that's most important to the, to the executive management is sometimes gets the most, most grease and it's like, yeah. But you know, is that the thing that really is the most important?

Aaron Crow (35:54.830): Correct. Yeah. Right.

Josh (36:19.850): I like using the new example, the Clorox breach. And we know about that because they're publicly traded company and they had to file their AK on that. And this was no longer, I think that was one of the turning points, that and Sony were the turning points where it went from, well, you know, if we have a cybersecurity breach, it's data, we'll have to make a notification. The cost of credit,

Josh (36:47.265): Monitoring has gone down. It's only you know 25 cents a person It's not really that it's not gonna cost us that much Okay, but those those data breaches Cost you the thing that you actually use You know in the case of he was their intellectual properties is their movies. So that's that's their whole and their music That's that's their portfolio in the case and it was more poignant in the case of Clorox that ransomware event shut down production line

Josh (37:18.370): They can't make the product they sell. That's critical. And I guarantee you, their cybersecurity budget got a 5X injection after this because they never, ever, ever want to have that happen again. I love this classic meme of the pile of pennies, the cybersecurity budget before the breach and the pile of $100 bills, the cybersecurity budget after.

Aaron Crow (37:20.824): Yep. Yep.

Aaron Crow (37:46.828): Right. Yep.

Josh (37:48.140): reach, which you most, you know, I'd like to not have to go through a breach to get the budget up to where it needs to be. But, that's why I point to these examples and say, let's not be them. Let's spend a little now to not spend a lot later.

Aaron Crow (38:3.694): So how much do you see your job as a CISO and your CISO peers as a job to be, to your point, we've seen the yes man. We've seen the cyber, the CISO, or even just executive in general. And it happens all the way down in the military, right? You don't wanna talk about the bad. You wanna, everything's great. We've got it under control. We're gonna win it by next week.

Josh (38:29.718): Mm-hmm.

Aaron Crow (38:33.006): I'm gonna sign the treaty by tomorrow, the day, you all the things that you hear politicians say and yes men say, but ultimately that's not the best thing for the business. The struggle is, is how do you weigh the benefit to you and your career over telling the boss bad news or the baby is ugly when maybe it's the real thing to do. So how much of that is your job is to be the one that really stands up and says, hey, these are the facts.

Aaron Crow (39:1.880): Just the facts, ma'am.

Josh (39:3.968): Yeah, unfortunately, that's the job. And I keep saying this. We have in our CISO mentorship program, the last session that we do is on managerial courage. I talk about that and I talk about this. There's the everyday managerial courage with a small C. That's the having the guts to have difficult conversations with your subordinates, right? Hey, your performance really isn't, I need the

Josh (39:33.853): I need you to make this improvement or what you did was not okay. If you keep doing it, you'll have a problem. Nobody likes to do that stuff. It's tough. But you got to have the courage to make those little, get through those tough moments. Then there's managerial courage with a capital C. And that's those life-changing moments where you have to go and tell the boss's boss's boss that there's a problem.

Josh (40:4.308): And that problem is going to cost him public embarrassment. your boss's boss is the one that started it. And that's going to be a problem. And I've had that moment in my career. The former agency I was at, the cybersecurity group reported under IT, actually reported way under IT. It was poorly placed.

Josh (40:33.400): And it was a large enough entity with a mature enough program that we were at the oversight phase. We were doing oversight of IT operations. Are you compliant? We're doing audits and we're seven federal audits every three years and all that kind it was a tremendous amount of oversight. as you, I like that phrase, having to call the baby ugly.

Josh (41:4.607): And the problem I was facing was that that message wasn't making it to the top. We'd identify a risk, we'd articulate the risk, and the risk would get spun or softened or, you know, the language, it would get buried in, you know, a 60 page report or something else where it didn't really make it to the top. And so I had one of those moments where I had to go

Josh (41:35.366): to my CEO and provide them with a nine page letter that read like an audit report, articulating six instances of major conflicts of interest in which the IT executives had either ignored a statute and overridden my objection or made a poor decision without bringing the business or the executives.

Josh (42:5.326): into that decision to actually understand the risk or just completely suppress the risk altogether. And I ended it with a summary. In summary, the suppression of the risk measures to the executive level has placed the agency at a significant disadvantage to the malicious actors and constitutes an immediate threat to the cybersecurity of the agency.

Josh (42:35.120): Within two days, I had a meeting with my executive director and the deputy executive director. And I always laughed. The first thing he said was, I really wish you'd come to me first. And I wanted to say it, but I didn't because I'm smarter than that. I want to say, if I had done that, you'd have told me to go work it out. And then I'd really been in trouble.

Josh (42:59.893): In all those instances over those two and a half years before that happened, those six instances, I had bucked the system. I had called the baby ugly. had, you know, deigned to say no to the, you know, the powers that be. And I did suffer for that because I was administratively reported to them to that chain of command. I entered that agency and left it at the same salary.

Josh (43:29.903): I got no raises in a period when the overall general cost of living went up 23%. I lost 23 % of buying power, almost a quarter of my salary and buying power for those four years because I did the right thing and it sucked. Now I made sure my people were taken care of so that I could ensure that I kept a good crew and that they were looking out for the best interest.

Josh (44:0.079): state, but that was a hard four years. So it was about three years into it, got the cybersecurity program moved out from under IT to the chief operations officer, and that worked very well. We were able to actually increase the size of the program from 12 individuals to 16, no 17, that we had an apprentice. And implemented an apprentice program.

Josh (44:29.714): So it was, you know, we were able to really make the program thrive. But that took me making a sacrifice. And unfortunately, that's, you know, kind of where you get to is that you can be the yes man and just go along to get along. And I could have done that or could done the right thing and really made sure that we didn't have, you know, we weren't the next agency in the

Josh (44:58.965): in the paper. That's one of things I tell people, my job is to keep us out of the paper because you do not want be in the paper for my kind of stuff. We call that an RGE, it's a resume generating event.

Aaron Crow (45:5.378): Yeah.

Aaron Crow (45:8.194): Nope. Yeah. That's right, we want to be the offensive lineman. Nobody should know our name. The only time they know about the offensive lineman's name is when somebody gets past him and sacks the quarterback. You never want to know the offensive lineman's name.

Josh (45:22.473): Absolutely. yeah, that's, that's the job is to not one out front making the headlines and not being the one that, you know, the developing a relationship or a reputation of trustworthiness and integrity and technical acumen is, is what has made me successful. because that

Aaron Crow (45:24.162): But it... Yeah.

Josh (45:50.773): people can trust the advice I give them. tell, I try to, you folks always ask that, that standard question. Well, what keeps you up at night? Not much. because I give good advice. I, I learned long ago that I do not make the decisions for about 90 % of the issues that come up. There's the 5 % down at the bottom, like the, Hey, we're trying to look at this website because it's part of this business thing we're doing and it's getting blocked. And we look at it like, yeah, that's miscon.

Josh (46:20.795): It's getting misindexed, so yeah, we'll allow it through. It's small things. And then on the other end, the top 5 % of the things like, that's illegal and we're going to go to jail if we do it, so no. I'm just going tell you no. And so in between there is the 90 % of the gray. I tell people this all the time, it's not black and white. It's a thousand shades of gray. You have to give them the information, your executives, your decision makers.

Josh (46:49.096): And then tell them, and I tell them, said, I'm your dark little cloud. You pay me to be pessimistic. I'm going to tell you the worst possible thing that can happen. And then I'm going tell you how likely it is. And then you get to decide whether the business need to move forward outweighs the risk that doing it presents. And sometimes I'll have something where I say, well, you can do it. And if you do this, that'll help mitigate that risk. Sometimes there's not.

Josh (47:15.483): They really like it when I have a mitigation effort. Sometimes there's not really much of a mitigation effort. But I try to, and that's where I've been successful, I just tell people, look, I'm not here to tell you no, unless it's illegal. I'm here to tell you, I wouldn't do that. But you don't have to go with my advice. But do understand, if you do, you'll be out there on your own. Because if it goes pear-shaped,

Josh (47:43.849): You know, I talk about this in some of my other talks. It's like rolling the dice. You you might keep rolling eights and it's great and everything is going along, but eventually that seven is going to come up. And what happens, and everybody's wringing their hands going, whoa, it's me. How did we get here? The answer should not have been, we didn't listen to our security professionals.

Aaron Crow (48:8.349): Sure. Well, and you know, I remember back in my time of being the technical person and have done all the research and I've had hands-on experience and let's use firewalls as an example. I like firewall vendor A over firewall vendor B, right? They're both firewalls, they both do the job, but for whatever reason, I like firewall vendor B. And then so you do your bake-off and you make your recommendation and the other vendor gets chosen.

Josh (48:34.984): Mm-hmm.

Aaron Crow (48:35.340): At the end of the day, yes, it's not my preferred, but it'll still do the job, right? It's not like it's a risk. It's not like it's a damage or anything like that. It's just that sometimes you have to put your ego aside and say, okay, I made my recommendation. Y'all went a different direction, but I'll still make that work, right? Yes, I liked Firewall Vendor A better, but B will do the job. I think it's a little subpar to Vendor A, but...

Aaron Crow (49:0.278): I can still configure it and make it work. And you've got to be able to put that aside and you're not your ideas. Like it's okay to change your mind. It's okay to be wrong. It's okay to put that ego aside, make your recommendations. And then it's to your point, it's their decision. So let them own that decision and then implement whatever they decide to do.

Josh (49:2.856): Mm-hmm.

Josh (49:20.874): Sometimes it's a business, it's a cost decision. Well, the one you like costs twice as much as the other one. Okay, if we only have X amount of dollars and the one that I wanted was X plus 50,000 and we ain't got it or X plus 100,000, okay, well then we can't do it.

Aaron Crow (49:40.174): Sure. Yeah. Want one hand and in the other. That's what my dad always used to tell me, right?

Aaron Crow (49:49.400): So all this to say, man, I really appreciate this. This has been an awesome conversation. Over the next five to 10 years, what's one thing you see coming up over the horizon that's maybe concerning and maybe exciting or awesome that in the cyberspace with all the changes, obviously you're already future casting for your budgets and everything else. So what do you see coming?

Josh (50:11.942): So I will say this, the two things that we really as security professionals need to pay attention to are the data management. In and of itself, it is a relatively matured discipline, but as a practice, it is fairly new.

Josh (50:40.229): Most people see that as just another piece of IT. But that's been, my experience has been that it's not. It's another risk mitigation factor like cybersecurity is. mean, when cybersecurity first became a thing back, I'm gonna date myself, 22 years ago in the state, it was rolled out very,

Josh (51:9.890): in a very long period. There's this thing called information security at the time, and you really need to it. And then, hey, well, there's this thing called information security. You really should have a dedicated person to do it. And then it was, well, we really should be doing a framework. And then, well, maybe we should also adopt a control set. And maybe we should audit that, do a self-assessment. And then maybe we should third-party assess it.

Josh (51:39.992): And so it came in stages. But as technology has increased its pace, things like data management come at us faster. for the state, was three years ago, they said, there is this thing called data management. You will have a data management officer. They will do these things under using this framework. You're going to get a self-assessment and that self-assessment report is going to go to the people who control the purse strings, the legislature.

Josh (52:9.421): to determine well you're doing all at once. So there's been a large resistance to that. And I would say that's one of the things where cyber security professionals need to be paying attention because several of those disciplines within that data security, data privacy, overlap with us. And so being a partner with your data management is really advantageous. The other thing I would say is, you know, watch the bleeding edge technologies.

Josh (52:37.730): we talked about who could have predicted what AI is going to do. Common computing is just starting to become reality. For a long time, was very science fiction or academic. They made it work for six milliseconds in a supercollider lab and 1,600 feet under the ground. Now it's actually looking like it's going to be a reality fairly soon. And what are the implications of that on things like encryption?

Josh (53:7.296): What kind of measures are we going to have to make to just do the basic of keep the communications that we have secure? What are the countermeasures to that where you have something that compute so much faster at a exponentially larger or faster amount than what we currently deal with? The limitations of the silicon. So I think that's an area to really watch is

Josh (53:36.034): What are the implications of that in how our security can be broken? Because if AI has taught us anything, it's that the malicious actors are much more astute at utilizing the new technology than we are at defending against it.

Aaron Crow (53:51.756): Yeah, they don't have anybody telling them policies that they can't do certain things or they don't have a regulator saying you can't put your data in there, you can't test it. They can do whatever they want, right? And we're constantly being attacked and that's just individuals. That's not even counting nation-state bad actors that have funding behind them and research labs and all of this type of stuff, right? And we're always going to be behind that eight ball. So we have to have, you know, focus around those topics.

Josh (54:10.977): Mm-hmm.

Josh (54:18.109): yeah.

Aaron Crow (54:22.182): and not just put our head in the sand, to your point, in critical infrastructure and power utilities, 10 years ago, nobody wanted to use virtualization, right? And virtualization has been around for decades, but we didn't want to use it in critical infrastructure because they didn't understand it. And now it's here. Same thing is going to be with cloud and AI and all these things. Before long, we're going to be controlling OT in the cloud. It's going to happen. So we need to be thinking about it. I'm not saying that we should push it there. I'm not saying it's okay or not.

Josh (54:32.224): Mm-hmm.

Aaron Crow (54:51.480): but we just need to stop putting our head in the sand and saying that will never happen in my space. Never is not a word you should use. You should be considering, I don't want it to happen, but I need to start thinking about what would success look like if I was forced to put my stuff in the cloud and how could I do it safely?

Josh (54:56.032): Mm-hmm.

Josh (55:10.748): Absolutely and that's you know that that's the the futurist But what is what is possible and then what are they gonna do with what is possible? And then how might that be utilized against me? mean, that's that's how the you know, like I said, we're negative people We're pessimistic. What what is what is the worst thing is gonna happen if the bad guys get a quantum computer? Okay, well then crack my encryption the in my

Josh (55:37.628): my currently uncrackable encryption in like 2.6 seconds. So what do we do to combat that? How do we, know, is it a different communication type? Is it, you know, is it different, different protocols? Is it different formulations of encryption? Is it thinking about, communications in a different way? all of those things, you know, so how do you, how do you get around it and how do you make, you know,

Josh (56:8.034): make your countermeasure. I think that's where, in that space, going to be where the most venture capital is going to be successful, is how they're going to utilize AI against the bad guys who've got probably a five-year jump on us in using it maliciously. And then how are the newer technologies going to force us to do what we do now differently?

Josh (56:35.867): And how do we make that change adoptable? because that's a, you know, that's the other part is you have to deal with the human effort. I was just talking to somebody the other day about this. It took 50 years to get people off of paper stock certificates, the trusting that the computer says I have a thousand shares of, you know, Disney, you know, and, so getting people to accept electronic currency has gotten there. mean, we're, much closer to that.

Josh (57:5.894): Getting people to accept electronic ownership of items is creeping in there and it's going to take things like cryptocurrency crashing doesn't help the credibility of But just thinking about how can innovative technologies be utilized in ways that they weren't initially intended.

Aaron Crow (57:19.831): Right.

Aaron Crow (57:29.639): Yeah, absolutely. Man, that's awesome. This is this has been a great conversation. I really appreciate the time in the big end. I don't get to always talk with folks from the government side, so it's always a difference. And although we have similar problems, you guys just have some benefits and some, you know, maybe cons on, you know, oversight or whatever that may be. So I really appreciate that time. Any call to action you want people to know or find you or seek out or

Aaron Crow (57:57.696): are things that you recommend they go check out?

Josh (58:0.997): Well, the first thing I will say is that if you are in a leadership position, reach down. Do not covet and hoard that position and the knowledge that got you there. Teach the next generation. Because at some point you want to retire. I know I do. That's the thing. Teach the next generation. Show them the way and pass on that knowledge so that you're not the only one who knows how to do it.

Aaron Crow (58:11.800): Yep. Yeah.

Josh (58:31.161): And then the other thing is be a futurist. Really look at, know, for the nerds amongst us, myself included, know, look at the science fiction and say, is, what are we, what are we imagining now that will be a reality later? And we can start thinking about how do we position ourselves to best utilize those things that are coming.

Aaron Crow (58:58.392): Yeah, absolutely. That's a, it's what we all need to be doing. And to your point, the mentorship, it's why I do this podcast. It's why, you know, I have conversations as people reach out and are wanting to get in this space to your point. Like I want to eventually be able to hand this off to somebody else, but I still want this thing to continue. Cause I want my, I've got kids, like I want it to be a safe world for them as well. So definitely, teaching others is, is, is part of my, know, what, what, what's close to my heart and, and, and growing this, this community. It's what I love about this community.

Josh (59:14.189): Mm-hmm.

Aaron Crow (59:28.344): but it takes effort. It takes effort for those of us that have made progress to remember to look back and lift other people up as well and kind of train them on the things that we've done to get here beyond just the network certification that I used to take and MCSE and CCNA and all the buzzwords that we've all done, CISSP, all those things that I've done, but also those software skills that I've done as well, like I talked about. So thank you so much for time. I appreciate you.

Josh (59:43.149): Mm-hmm.

Aaron Crow (59:55.936): And the service that you do for the great state of Texas also appreciate your services, Marine Sir. So thank you for your time and for all that you've done to make us a safer state and world to live in.

Josh (60:8.718): Thank you.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.