Building Leadership Strategy Beyond Tech with Brian Haugli

Building Leadership Strategy Beyond Tech with Brian Haugli

Brian Haugli, Founder and CEO of SideChannel, brings his CISO expertise to the security podcast this week for a discussion about strategy and leadership in cybersecurity. Working alongside CISOs and fractional VCISOs, Brian has seen his share of leadership mistakes and has learned about the purposeful approach that security needs along the way. In this episode, Brian revises the mantra of “people, process, and technology,” to include the first and most important element in your security success: purposeful strategy. Be sure to subscribe to Hacker Valley Studio, the premiere cybersecurity podcast for cybersecurity professionals.

Timecoded Guide:

[02:01] People, process, and technology in your leadership strategy

[05:12] Tenants of a strong security strategy

[13:11] Setting up new fractional CISOs for success

[18:29] Creating SideChannel & walking the line between CISO vs consultant

[27:44] Thriving professionally by thriving personally

Sponsor Links:

Thank you to our sponsors Axonius and NetSPI for bringing this episode to life!

The Axonius solution correlates asset data from existing solutions to provide an always up-to-date inventory, uncover gaps, and automate action — giving IT and security teams the confidence to control complexity. Learn more at axonius.com/hackervalley

For more than 2 decades, NetSPI has helped companies discover and remediate critical security issues through its platform-driven, human-delivered security test. NetSPI is much more than a pentesting company, bringing you the most comprehensive suite of offensive security solutions. Visit netspi.com/HVM to learn more.

What has been your philosophy throughout the years when it comes to leadership versus technology?

The security adage of “people, process, technology” isn’t one combined concept. That is, in Brian’s opinion, why so many leaders make the mistake of prioritizing technology as a central part of their strategy. Strategy is not what technology you use, and you can’t buy your way out of every security conflict with a shiny new product. Ask yourself what problem you’re supposed to solve, not which tech is going to solve your problems.

“Strategy is not technology, it's figuring out what you want to look like when you grow up, in a sense. Everyone jumps to the shiny object. What can I buy to go solve this problem? You never stop and question: Was that the first problem I was supposed to solve?”

What are the tenants of making sure that you've done the work of creating a strong security strategy?

The North Star of your security strategy should be the identity and purpose of your business, according to Brian. If you don’t have a current assessment of your current capabilities, assets, resources, and objectives, you aren’t positioning yourself for success. Strategy comes from a knowledge and understanding of where you are now, and where you need to be. When your company “grows up,” what do you want security to look like for you? Understanding that guides you towards your target state without wasting your time on the wrong problems or objectives.

“I think a lot of people throw strategy around as a grander concept and don't actually think about the elements that need to go into building one. You need to align to a definition that supports your business and outcomes, and that's what is strategic. The idea is not strategic.”

Let's say I'm a brand new fractional CISO and I have my first client. What are the top three questions I'm going to ask of this organization to set me on the right path?

When dealing with a new client, fractional CISOs have to understand why they’re involved with this client in the first place. Why are you here? Who brought you here? And, most importantly, what is the reason security is being addressed now? A fractional CISO can’t defend what they don’t know exists, and they can’t meet a deadline without first understanding what this company’s unique security environment needs are.

“You don't jump into, ‘Okay, well, what's the budget?’ No, I like to understand what I have to actually defend and build to, how fast I have to actually make that happen, that then informs and sets up the much better discussion around, realistically, what you should be considering.”

What advice do you have for our audience that is interested in becoming a CISO?

Although Brian jokes that he would advise anyone against taking on a CISO role due to the workload, he understands and loves the grind of cybersecurity leadership. To not only survive but thrive as a CISO, Brian believes a practitioner has to keep their love for problem-solving and protecting organizations at the forefront. Still, as passionate as someone might be, Brian also advises knowing when to unplug and unwind to avoid burning out fast in such a strenuous role.

“Look, just take care of yourself. I think exercising is huge. Eat right, sleep right. You've got to take care of your mental health, take care of physical health, you've got to take care of your spiritual health. You've got to do all that, or you're never going to be good professionally.”

---------------

Links:

Keep up with our guest Brian Haugli on LinkedIn and Twitter

Learn more about SideChannel on LinkedIn and the SideChannel website

Connect with Ron Eddings on LinkedIn and Twitter

Connect with Chris Cochran on LinkedIn and Twitter

Purchase an HVS t-shirt at our shop

Continue the conversation by joining our Discord

Check out Hacker Valley Media and Hacker Valley Studio

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(441)

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Do You Know What Your Agent is Doing at 3AM? with Amir Ofek

Every AI agent in your environment inherits someone's permissions, and most teams have no idea what those agents are actually doing with them. Amir Ofek, CEO and co-founder of Aizome, shares how to ma...

16 Syys 38min

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cloud Broke My World Before AI Did with Dr. Jay Abdullah

Cybersecurity has survived cloud, mobile, and a dozen other "biggest disruptions of our lifetime," and each one felt unprecedented in the moment. In this episode, Ron sits down with Alyssa "Dr. Jay" A...

9 Syys 36min

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

The Dashboard Is Dead, Long Live the Harness with Myke Lyons

Security teams spent decades begging for more logs. Now the enterprise is generating petabytes a day, and the thing drowning in it isn't just the SOC anymore, it's your AI agents too. In this episode,...

1 Syys 35min

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

The AI Already Inside Your Company with Russell Spitler & Richard Penshorn

A year ago, the average employee held about 30 OAuth grants. Today that number has risen to 88, and it isn't slowing down. Ron sits down with Russell Spitler, co-founder and CEO of Nudge Security, and...

25 Elo 35min

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Humans First: Adobe's Rule for Building AI Security Tools with John Gillis

Imagine how much investigation time your SOC could get back if the busywork just disappeared. Ron sits down with John Gillis, Staff Security AI Engineer at Adobe, who built an in-house AI investigatio...

19 Elo 34min

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Let AI Do More Without Surrendering Your Judgment with Jen Easterly

Fresh off the showroom floor at Black Hat 2026, Ron brings back some hot takes from the crowd. Nearly every booth he visited, including the Exaforce booth, was pushing in the same direction. Trust in ...

14 Elo 23min

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

Post-Quantum Cryptography: What Every Organization Needs to Know with Michael Fasulo

What if the encrypted traffic flowing across the internet right now (emails, files, logins) is already being quietly collected and stored by someone waiting for the day they can finally crack it open?...

12 Elo 30min

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

Stop Defending the Edge: How to Rethink Your Mobile Security with Jared Shepard

What if the biggest risk to your organization isn't the device that gets lost, but the data that lives on it? Ron Eddings sits down with Jared Shepard, Founder and CEO of Hypori, whose path ran from h...

7 Elo 38min

Suosittua kategoriassa Koulutus

rss-murhan-anatomia
aamukahvilla
psykopodiaa-podcast
adhd-podi
psykologia
voi-hyvin-meditaatiot-2
koulu-podcast-2
rss-luonnollinen-synnytys-podcast
rss-liian-kuuma-peruna
ilona-rauhala
rss-duodecim-lehti
kesken
rss-vapaudu-voimaasi
rss-koira-haudattuna
rss-niinku-asia-on
rss-rahamania
rss-psykalab
rss-narsisti
rss-arkea-ja-aurinkoa-podcast-espanjasta
rss-uskonto-on-tylsaa