The Odd One Out - Unleashing the Power of the Unpopular Opinion
RSA Conference 2024 · Track Session
Overview
In a departure from the typical technical deep dives often found at security conferences, this RSAC 2024 talk, "The Odd One Out - Unleashing the Power of the Unpopular Opinion," offered a compelling exploration of the crucial "soft skills" and strategic leadership required for cybersecurity and IT executives. Delivered by a seasoned leader with experience as a CEO advisor to Net Scope, a board member of a cybersecurity advocacy nonprofit, and a "recovering CEO," the presentation provided invaluable insights for Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) navigating complex organizational landscapes.

Key moments
- 0:00 Introduction and the 'odd ones out' analogy
- 2:00 The universal struggle: AV equipment and shared frustrations
- 4:00 Shifting from back-office to strategic business partner
- 5:50 Understanding remuneration: budget, scope, and strategic influence
- 6:50 Top-level CSO attributes: automation, data, culture, influence
- 8:10 Matching CSO capabilities with organizational needs and risk
The Odd One Out - Unleashing the Power of the Unpopular Opinion
Speakers: (Name not provided in input), CEO advisor to Net Scope, Board of Cyber Security Advocacy and Education Nonprofit, Recovering CEO
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=xoyPPGivPQc
Overview
In a departure from the typical technical deep dives often found at security conferences, this RSAC 2024 talk, "The Odd One Out - Unleashing the Power of the Unpopular Opinion," offered a compelling exploration of the crucial "soft skills" and strategic leadership required for cybersecurity and IT executives. Delivered by a seasoned leader with experience as a CEO advisor to Net Scope, a board member of a cybersecurity advocacy nonprofit, and a "recovering CEO," the presentation provided invaluable insights for Chief Information Security Officers (CISOs) and Chief Information Officers (CIOs) navigating complex organizational landscapes.
The speaker's core message centered on the idea that true success in these leadership roles hinges less on technical prowess alone and more on mastering the art of acceptance, influence, and stakeholder management. Through personal anecdotes and real-world examples, the talk illuminated the journey from being a perceived "back-office function" to becoming a strategic partner at the executive table, emphasizing the importance of reframing traditional challenges like "politics" into opportunities for human-centric engagement and organizational transformation.
This session is particularly vital for leaders grappling with budget approvals, overcoming organizational inertia, and ensuring their security initiatives are not just technically sound but also embraced and sustained by the wider business. It challenges the conventional wisdom that technical excellence is sufficient, advocating instead for a holistic approach that integrates strategic communication, cross-functional collaboration, and a deep understanding of organizational dynamics to drive meaningful and lasting change.
Background
▶ Watch: Introduction and the 'odd ones out' analogy (0:00)
The journey of IT and cybersecurity leaders, as outlined by the speaker, is frequently characterized by common frustrations and misperceptions. Historically, IT departments have often been blamed for issues outside their direct control, perceived as "too slow, too expensive," and generally opaque to the rest of the business. This sentiment resonates deeply within the cybersecurity community, where practitioners often feel their efforts are misunderstood or undervalued. The speaker recounted a relatable anecdote of a crucial board meeting derailed by malfunctioning AV equipment, a situation that initially led to personal feelings of incompetence but later, through shared experience with other CIOs, revealed a universal challenge: the unexpected "biggest enemy of a CEO is the AV equipment." This realization underscores a fundamental truth: many struggles are not isolated failures but systemic organizational friction points.
The talk drew parallels between the evolution of CIOs and the ongoing journey of CISOs. CIOs, once relegated to back-office functions, successfully transitioned to gaining a seat at the table by learning a "different language." This shift involved moving beyond purely technical jargon to communicate with the business in "real and simple terms," focusing on creating engagement platforms beyond project-specific initiatives, and reframing "politics" as stakeholder management. This transformation brought tangible benefits, including easier budget approvals, more strategic conversations with the business, and even improved remuneration.
The speaker introduced a framework from Russell Reynolds, an executive search firm, which outlines a four-level maturity model for CISOs, ranging from tactical (Level 1) to transformative/adaptive (Level 4). Key dimensions distinguishing higher-level CISOs include:
- Automation: Proficiency in leveraging automation, particularly in an environment of scarce skills and increasing complexity.
- End-to-end and 360-degree protection: Convergence of digital and cyber-physical security.
- Data-driven decision making: Utilizing data and analytics for insights.
- Culture shaping: Leading the organization towards a strong security culture.
Furthermore, the model highlights individual attributes such as the nature of relationships (transactional vs. relational), interaction styles (reactive vs. anticipatory), and the scope of organizational influence (IT/cyber vs. executive committee/board levels). These attributes directly correlate with leadership competencies like change orientation, influencing, collaboration, and strategic capability, all of which are essential for driving the kind of organizational acceptance and transformation discussed in the talk. The speaker also stressed the importance of understanding the organization's intrinsic risk assessment (probability and impact of compromise) and its appetite for long-term technological transformation, suggesting that a mismatch here can lead to frustration and a need for self-reflection regarding one's career path.
Key Findings
▶ Watch: Shifting from back-office to strategic business partner (4:00)
The central and most impactful finding of the talk is that success for cybersecurity and IT leaders is fundamentally driven by acceptance, not just quality. The speaker candidly admitted to having been a leader who "hated politics" and focused solely on quality, only to realize that without acceptance from diverse stakeholders, one risks becoming a "busy fool," expending immense energy with limited appreciation or lasting impact. This paradigm shift from viewing "politics" as a negative to reframing it as a necessary, human-centric aspect of leadership is crucial for anyone aiming to move beyond a purely technical role.
Another key finding is the critical importance of relational interactions and anticipatory leadership. The Russell Reynolds model, referenced by the speaker, clearly delineates higher-level CISO roles by their ability to foster strong relationships, anticipate organizational needs, and influence at the executive committee and board levels, rather than merely reacting to incidents or operating within the confines of the IT department. This requires developing a strategic capability to align security initiatives with broader business objectives.
The talk also underscored that effective change requires focused intervention and deliberate platform creation. Rather than waiting for a crisis, leaders should proactively establish mechanisms for cross-functional engagement. The speaker’s experience with an IT control board, designed to provide transparency and joint decision-making for a troubled ERP implementation, exemplifies this. Such platforms enable stakeholders with diverse opinions to contribute to the roadmap and prioritization, fostering a sense of ownership and reducing friction.
Finally, the speaker highlighted that making change irreversible is paramount for sustainable transformation. Many initiatives fail because they revert to old ways once the initial momentum fades. By embedding new processes or data models into core organizational functions, such as budgeting, leaders can ensure that the changes are maintained out of necessity, creating a lasting impact that transcends leadership cycles and organizational shifts. This strategic embedding transforms a temporary project into a fundamental shift in how the organization operates.
Technical Deep Dive
▶ Watch: Understanding remuneration: budget, scope, and strategic influence (5:50)
While this talk did not delve into traditional cybersecurity technical details like specific exploits, vulnerabilities, or tools, it offered a profound "technical deep dive" into the methodologies and strategic frameworks necessary for effective organizational change and influence for security and IT leaders. The "technical" aspect here refers to the systematic, repeatable approaches and architectures for human engagement and process transformation.
One of the most practical and widely applicable strategies discussed was the "Can I pick your brains?" approach. This involves proactively seeking informal conversations with key stakeholders from other departments, particularly those often perceived as challenging. The speaker specifically highlighted Marketing as a crucial, yet often difficult, stakeholder for IT and security teams. Marketing departments frequently engage with external creative agencies and adopt SaaS platforms without formal IT authorization, leading to shadow IT and potential security gaps. By initiating informal coffee chats and asking "Can I pick your brains?" before sending out broad communications or presentations, security leaders can:
- Gain insights into their operational needs and existing tools.
- Leverage Marketing's expertise in communication to refine security messaging for non-technical audiences.
- Build rapport and trust, making it easier to address security concerns related to unauthorized platforms later.
This strategy extends to other departments like Finance, Procurement, and HR, allowing security leaders to understand their perspectives on budget allocation, project prioritization, and awareness campaigns, respectively. The core mechanism is to invite collaboration and shared credit, rather than imposing directives.
Another critical methodology presented was the creation of engagement platforms or IT control boards. The speaker recounted an experience as a CIO inheriting a difficult ERP implementation. To gain organizational trust and transparency, an "IT control board" was established. This board served as a forum where stakeholders from across the organization could see into the "black box" of IT, discuss priorities, and make joint decisions. The speaker emphasized that such a platform doesn't need to be a massive, formal statement; it can start small, even with just two or three key people meeting regularly. The goal is to create a sustained cadence of conversation, allowing for alignment of priorities, feedback on roadmaps, and shared ownership of outcomes. This proactive engagement is framed as a focused intervention that doesn't require a crisis to initiate.
To overcome organizational inertia, particularly when direct reports or peers seem resistant to change, the speaker advocated for focusing personal leadership efforts on a limited number of strategic initiatives – ideally one to three. By personally driving these projects, leaders can bring enthusiastic team members with "eyes on the project" into the fold, demonstrating momentum and success without alienating existing structures. This approach allows for targeted energy application where it can yield the most visible results, gradually shifting the broader organizational mindset.
The talk also detailed a "technical" approach to resource allocation for large-scale, transformative projects. In a utilities organization with 35,000 employees and 1,500 IT staff, the speaker needed the "best people from across all functions" for a critical data quality initiative. The challenge was securing these highly skilled individuals who were already "more than busy." The solution involved negotiating for 20% of their time – effectively "one week a month." This approach leverages the organizational familiarity with managing employee holidays, making the temporary reassignment of a small percentage of time more palatable and less disruptive to ongoing business. The "investment case" for executives responsible for these resources was framed around clear mid-term benefits: lower operational costs, improved service to the broader business, and the opportunity to close critical security gaps, such as criticality assessments for assets. Crucially, the buy-in from the IT team was secured by framing the initiative not as "data cleansing" but as a transformation of the IT function "from a super tanker to an armada of speedboats," empowering them to "do things differently." The underlying principle is that "people support what they create," fostering joint prioritization and contribution.
Finally, the most sophisticated "technical" strategy for ensuring the sustainability of change was making it irreversible. For the data quality and data model transformation project, the speaker changed the fundamental approach to IT budgeting. Instead of budgeting by cost centers (e.g., "data center cost U X," "ERP licenses cost U Y"), the organization shifted to budgeting based on service cost to the business and the new data model. This meant that funds for operational maintenance, external support, and licenses would only be released if they aligned with and were maintained under the new data model. This architectural change in financial processes created a powerful, non-negotiable incentive for the new data model and associated processes to be continuously maintained, making the transformation permanent and essential for the organization's financial operations. This also strategically linked foundational work like data quality to high-interest organizational topics like AI, which is impossible without a robust data foundation.
Demo / Proof of Concept
▶ Watch: Top-level CSO attributes: automation, data, culture, influence (6:50)
This talk did not feature a live technical demonstration or a software-based proof of concept in the traditional sense often seen at security conferences. Instead, the speaker's "proof of concept" was delivered through a series of vivid "world stories" and personal career experiences. These anecdotes, drawn from various leadership roles in different organizations, served as practical illustrations of the methodologies and leadership principles being advocated. For instance, the story of the supply chain organization creating a new business unit for transformational deals, achieving "fivefold growth in five years" with "10% profit margins," demonstrated the potential of breaking traditional rules and fostering innovation, while also highlighting the challenges of peer acceptance. Similarly, the detailed account of the data quality initiative in the utilities company, and its successful implementation through strategic resource allocation and irreversible budgeting changes, served as a compelling real-world case study for the principles discussed. These narrative examples acted as experiential proofs, showcasing how the "unpopular opinions" and unconventional approaches could lead to significant, measurable outcomes.
Defensive Implications
▶ Watch: Matching CSO capabilities with organizational needs and risk (8:10)
While the talk did not directly address specific defensive technologies or threat intelligence, its focus on strategic leadership and organizational influence has profound implications for strengthening an organization's overall cybersecurity posture. The principles outlined are critical for building a robust, resilient, and proactive defense.
- Strategic Alignment and Budget Advocacy: By learning to speak the business's language and aligning security initiatives with strategic business goals (e.g., ESG, digital trust, zero trust at the board level), CISOs can secure better funding and executive buy-in. This enables investment in advanced defensive technologies, skilled personnel, and comprehensive security programs that might otherwise be deprioritized. A well-funded and strategically supported security function is inherently a stronger defense.
- Proactive Threat Surface Management: The "Can I pick your brains?" approach, particularly with departments like Marketing, offers an informal yet highly effective way to uncover shadow IT and unauthorized SaaS platforms. These unmanaged assets often represent significant attack vectors and compliance risks. By building relationships and fostering trust, security teams can bring these systems under governance, extending defensive controls to previously unmonitored parts of the enterprise. This proactive discovery is a critical defensive measure against unknown assets.
- Enhanced Organizational Resilience through Collaboration: Creating IT control boards or similar cross-functional committees fosters a shared understanding of security risks and responsibilities. When diverse stakeholders have a voice in security roadmaps and prioritization, security becomes a collective effort rather than an isolated IT function. This collaborative approach enhances the organization's ability to respond to incidents, implement security policies effectively, and build a culture where security is everyone's concern, thereby improving overall resilience.
- Irreversible Security Posture: The strategy of making changes irreversible by embedding them into core organizational processes (e.g., re-architecting IT budgeting based on service costs and a new data model) is a powerful defensive mechanism. For instance, ensuring data quality through such a mechanism provides a foundational layer for effective security analytics, threat hunting, and the implementation of AI-driven defenses, which rely heavily on accurate and structured data. Without this foundational integrity, advanced defensive tools will operate on flawed premises. This ensures that security improvements are sustained and not easily rolled back.
- Effective Resource Mobilization for Critical Security Projects: The speaker's strategy of negotiating for 20% of key personnel's time for strategic projects is directly applicable to critical security initiatives. For example, a CISO could use this approach to staff a comprehensive criticality assessment of all organizational assets, a crucial step for prioritizing defensive efforts and incident response. It allows for the temporary allocation of top talent to high-impact security projects without crippling ongoing operations, ensuring that vital security work gets done efficiently.
In essence, the defensive implications of this talk are about shifting from a reactive, isolated security function to a strategically integrated, proactive, and collaboratively defended enterprise. By mastering the art of influence, gaining acceptance, and embedding security into the fabric of organizational operations, CISOs can build a far more robust and enduring defense against evolving threats.
Key Takeaways
- Prioritize Acceptance Over Pure Quality: Success in leadership roles is less about technical perfection and more about gaining organizational acceptance and buy-in for your initiatives. Reframing "politics" as human-centric stakeholder management is crucial.
- Proactively Engage Diverse Stakeholders: Use the "Can I pick your brains?" approach to build relationships with departments like Marketing, Finance, and HR. This fosters collaboration, uncovers hidden challenges (like shadow IT), and helps tailor security messaging.
- Establish Collaborative Platforms: Create formal or informal committees/boards to involve stakeholders in IT and security roadmaps and prioritization. This increases transparency, fosters joint decision-making, and garners collective ownership.
- Be Persistent and Adaptable in Transformation: Driving change requires continuous "review, readjust, and iterate" cycles. Be prepared to take two steps forward and one step back, and focus your personal leadership on a few strategic initiatives to overcome inertia.
- Make Strategic Changes Irreversible: Embed new processes, data models, or security requirements into core organizational functions, such as budgeting, to ensure their long-term sustainability and prevent reversion to old ways.
- Align Aspirations with Organizational Needs: Regularly reflect on the type of leader your organization truly needs versus your personal capabilities and aspirations. This self-awareness helps in making strategic career choices and effectively advocating for yourself and your team.
About the Speaker(s)
The speaker, whose name was not provided in the input materials, brings a wealth of experience from senior leadership positions across the technology and cybersecurity sectors. They are identified as a CEO advisor to Net Scope, demonstrating current influence within the industry. Their involvement on a board of a cybersecurity advocacy and education nonprofit underscores a commitment to advancing the field beyond corporate interests. Furthermore, the speaker's self-identification as a "recovering CEO" highlights extensive executive-level experience, including the demanding role of a Chief Executive Officer. This diverse background, spanning CEO, CIO, and advisory capacities, provides a unique and holistic perspective on organizational dynamics, strategic influence, and the critical soft skills required for success in complex IT and cybersecurity leadership roles.