Loading summary
A
You're listening to the Cyberwire Network powered by N2K. Welcome to Afternoon Cybertea where we explore the intersection of innovation and cybersecurity. I'm your host, Dan Johnson. From the front lines of digital defense to groundbreaking advancements shaping our digital future, we will bring you the latest insights, expert interviews and captivating stories to stay one step ahead. Today, I am joined by David Gee, a seasoned CISO and CIO who has spent more than two decades at the intersection of cybersecurity, technology and risk leadership. From HSBC to Macquarie Group. David is now a board advisor, a non executive director and author of both the Aspiring CIO and ciso and A Day in the Life of the ciso. David, welcome to Afternoon Cybertea.
B
Afternoon, Anne. How are you?
A
So let's start with a big theme from your book. I think it's a great place to start. There's this gap between theory and reality. You have mentored and interviewed many current and many aspiring CISOs. What is the most dangerous assumption you see new CISOs making when they step into the role?
B
It's a really good question for many people. And one of the CISOs yaobing from New York actually quoted saying, to fail in your first CISO role is maybe normal. And so I think this whole idea around imposter syndrome and all of us having to grow into our roles is very true. You know what I mean? Because every time you step up into a new role, whether it's a CIO or CISO or anything, there are new dimensions to learn. And so there are things that you don't understand, don't learn, you haven't had the experience or had the opportunity to, to maybe demonstrate a behavior that is required in that role. And so for me, that's actually part of the growth. And so trying to embrace that and reflect on yourself and how do you then step into and start to be more comfortable in that uncomfortable situation is really part of the growth.
A
I think that's right. And I think embracing the uncomfortable is hard for a lot of people, especially when you step into a job like a CSO and you feel like you're expected to know everything and make all the decisions and be the senior, most senior leader. And when people embrace the uncomfortable, you actually give the space for folks to help you along, right?
B
Absolutely. I remember there's one other chapter that I'd highlight when a book launched of it a few weeks ago and we had a few different CISOs there. One's the Westpac CISO from Australia. Who's the number? Probably Second largest bank in Australia. And he said, I was an accountant who moved into cybersecurity. And people were like, what? He'd been in his office 16 years in the Westpac CISO role. And then the person next to him, Catherine Rowe, said, oh, actually I was a lawyer who moved in the regulatory, into compliance, and then pivoted into being a ciso. So we all come from different backgrounds, but what you bring with that is a different skill set. In her case, she said, I was really great at stakeholder management and logical thinking, but I didn't know the tech. I had to learn the tech or have people around me that were really good at that and embraced the fact that I wasn't great at that side, but I had to learn that side.
A
I think that's right. And Richard is one of my favorite people, by the way. I've known him for, I don't know, 20 years. He's a great CISO.
B
Oh, definitely. He's got a lot of humility. And he talked a lot about his team and how being the front in his chapter, talking about the personal resilience crew. Resilience, but also how do you get the team to understand that when bad things happen. Unbelievable. From the front, I'm not going to be in the back watching you. I'll be making sure that I stand with you.
A
Yeah, exactly. Well, you have lived this across industries. When you were seeking contributors to your book, what did you find? Most of them thought the job was going to be and what did they learn? It really demands once they've been in the job, 30, 60, 90 days.
B
Well, firstly, I'd say that most CISOs and leaders in the space are kind of shy. Maybe shy is the wrong word. They're busy people. So getting people to want to contribute is hard because they're not outwardly looking. They're so worried about doing their normal job. There's a few basic lessons there and that everybody has to understand that you can't please everybody. But also you can't be seen as department of no. You can't be saying no, no, no to everything. And so on the one hand, you want to protect the organization, but your job is to help enable the business and not just block things. And I often talk about the fact that you can got these three constraints. You're there to, number one, defend against the biggest risks. And there's lots of things coming at you, but how do you define what's the biggest risk and make sure that you get clarity around that, because what's on the table what's on the metrics, what's on the roadmap may not be the biggest risk. It may be what the regulators ask for or people that have pushed you to put on that list. And so having that clarity is important. Second thing of course is that whole customer experience piece. How do you make sure that you're working with your business peers and your teams to figure out, I want to be able to improve customer experience in terms of being safe, but also we need to patch these things too and work with the fact that what we do disrupt the business. So how do we make sure that's not lost in the whole exchange? So the whole, to me, the whole DevSecOps for example, right. Is important. People often will just focus on DevOps. And thirdly then how do you then balance that in terms of that order, the compliance aspect? Cause we don't want to be necessarily getting a high distinction on the compliance, but we need to be making sure that we right, sizing, getting it right to the right point of being able to pass the test. And again, that order of biggest risks, then customer experience and then compliance.
A
I think that sounds right. And also it leads into this. The CISO can sometimes feel like they're responsible for everything, but they actually own nothing. So how does the CISO reset these expectations? How do they make the role sustainable and communicate with their boards, with their leaderships and even convincing themselves that they actually need to focus the job in a way that they're effective?
B
We all struggle with that. Right. We want to take on more because we recognize that. Let's take an example. If things grew up in that world over here, it could be this new AI projects. If we don't get engaged in that, actually when it does screw up, it's going to be our fault and we blame. But the way to think about this is actually that this is being a team sport. And I think data security is a great example. I remember doing my past roles where you'd sit there with a cio, a CISO or a Chief Data Officer and all the C suite people and say okay, so we've got this data security issue and who owns this thing? And they'll point to each other and say no, it's. I said, well actually your wrong. That's all of us, we need to own parts to this. And so if you're the chief driver officer, you own the classification piece and I help you with identification and we need to protect that, detect that, and the Chief Information officer or CTO needs to make sure the backups and the restoration process. So there's a bit of a team aspect to this. So how do you make sure that across the world, you know, hold spectrum of the business and technology side, people understand that you can't do this by yourself. As a ciso, you. I've got this title, but actually you will fail if you just rely on myself to do this role and my team. It needs to be everybody in that risk culture embracing this whole piece.
A
I think that's right. You've also written about. It's a good segue into how you've written about defensive CISOs. Right. They're protecting the environment and also strategic CISOs as leaders mature and as they learn to operate. Why do you think so many still struggle to be durable long term CISOs?
B
It's a really tricky one. I think there's the environment. If you look at the environment, the environment's harsh. The regulations coming out are definitely challenging. And you get an incident could actually invoke three or four different regulations. Okay. So it's not easy for the CISO to deal with that level of stress at the same time. From top down, from the boards down. Do boards get it? Do boards really understand that? And I go to a lot of broad briefing sessions and I was one a few weeks ago where there's a. Here in Australia there's a thousand board members. And I was looking around the room and thinking actually on the agenda it's all AI and cyber and maybe a little bit of green energy. Okay, so three topics. But around the room most people are trying to understand this because they actually got a non technical background. And so to me, the CISO gets asked the wrong questions often or the CIO gets asked the wrong questions to answer. And so we often will be dealing with favorites or funky things that may not be the biggest risk to deal with. And so I think the CISO being that technical person, having that technical background is important. But then, you know, the board need to be convinced that you understand their strategy, the business strategy. And then how do we risk buy down and how do we make these trade offs between we're making this business transformation in the next two or three years or four years. And when you take this business risk of not making these changes to legacy, that's a hard trade off. And someone to articulate that and to understand that is tricky.
A
I think that's right. And I do think that what you said really resonates that there's so many regulatory issues coming for the CISOs that it's sometimes hard to Think more strategically when you truly are in defense mode and also trying to make sure you're compliant. Let's talk a little bit about the future of the CISO role and we'll touch on regulation again, of course. But I recently wrote about what I call the CISO imperative, which is how the role is changing from one of control to one of influence, especially when you think about AI and the regulation we talked about and resilience at a reshaping landscape building on what you've seen in your own journey. How do you think the CISO role needs to evolve from here to stay relevant?
B
Look, it's increasingly tricky. I made a comment at this keynote last night that actually I've seen two banks in Australia where they've actually split the CIO role into two, and they put the CIO over here looking after cyber and infrastructure and engineering, and the Chief Data Officer looking after AI data and digital. And so influence becomes more important because you're no longer in the same line. So at the same time, I really reinforce the fact that in this AI era, your job as the CISO is not actually to be a spectator. Your job is to be in the game. And which means you need to be thinking about saying, I want to be making sure that I'm onboarding all AI. I'm working with the business people to not be reacting to their requests, but actually making sure that I'm the person helping. There's a thinking around from the Nvidia. Jensen Huang earlier this year said it will be the HR department of AI in the future. And what he meant by that, I think was actually you will onboard that you will make sure that they come on, they're recruited the right way, trained the right way, and not have this sort of shadow AI thing happening. So that whole responsibility that you see in HR apologies for people would be duplicated around hiring, firing, recruiting, promoting, being counseled. All that whole process is what used to be saying, I want to make sure that humans and AI work more together. How do I help orchestrate that? Both in the ecosystem for vendors, but also within our organization? Because there will be conflicts between humans and AI bots who don't work well together. All this maybe some sabotage or we get so concerned. These bots never slow down. So how do we make sure that happens? Well, and then how do we become oversight for that versus being a spectator on the sidelines?
A
Yeah, and I think that's right. I think that CISO's, it's becoming in a lot of ways a much bigger role. But I also think if CISOs really embrace a leadership aspect versus a we must do everything aspect of it, they become more effective. Right. It's about who they surround themselves with.
B
Yeah. And it's hard to do that because you need to be in the game. But also they're not trying to take all things on your shoulders, because that's a fool's paradise, in a way, and try to get that balance right. And working with your peers.
A
Exactly. So you've worked closely with a lot of boards over the years. What changes are you seeing in how boards perceive cybersecurity, and how does that change. Change how the CISO is prioritizing in their role?
B
I think boards are afraid of cyber security still. I think that's probably the position I'm hearing more and more board members. And you see this in these sessions. I go to where they look on stage and there's the board members from three companies. And actually I know two of them have been hacked in the last four or five years. So they kind of get the aftermath, they kind of get the incidents, and so they kind of understand that actually this is a bad thing. Now, the tricky part, of course, Ann, is that then what do you do about it? How do you then find a guidance, direct the organization in the right fashion? So for me, I think it's a challenge in this AI era, it's a challenge because threat landscape surface, you'd say, has doubled. There's lots of new attack vectors and controls. You want to call it controls that are continuous now and may not exist in your current format. So how does the board understand that? Because the board sees the upside around AI and AI productivity and all that promise. So I think there's a real interesting challenge for board to get that and embrace that and try to get their arms around it.
A
That makes a lot of sense to me. And it also brings me to a question I wanted to ask you about AI. What do you think CISOs today should be thinking about how they integrate AI into defense and also potentially into their governance models, given we do have a proliferation of AI across companies. Right.
B
We have to do that. I think we've all seen the last few weeks this anthropic example of 30 companies where it's gone from reconnaissance through the escalation of privileges, through the lateral movement. And so to me, evaluating is a good thing. And so to me, it's a portfolio aspect of this. So I think the portfolio piece is, okay, look at energetic AI to take manual toil out of your system, take that savings and Put it into things like the SOC and penetration testing, other areas. But you're not going to get a new starting, new budget or new set of resources. But you need to then work around how do I take what I have in my pot and make it better? And I can't wait. And it'll be too slow because it's been proven from the anthropic example that they're going to use AI against me. But I'm still thinking about how to apply it. So accelerate that process. 2026 will be a real focus around accelerating the process and then applying null AI and energetic AI to my processes to play catch up so we can start to be maybe on the front foot.
A
Yeah, I agree. I think it's pragmatic application today. Where can you get the most value out of agentic AI and applying it there? Where do you have the biggest gaps? Also? So let's talk about mentorship and the role of the ciso. Because we do need to prepare for the next generation of ciso. The CISO role is becoming more complex. There's more demands on it. We're long past the days where the CISOs need to be the most technical person in the room. They also need to be a business person, they need to be a regulatory person. They do need to understand the future. They need to understand threat actors, et cetera. You have written about, and I love the way you talk about this, you've written about a mentorship deficit. I would love to unpack that idea. What do you think is missing and how do we start to fix it?
B
Has to start with us. I mean, to me, it's about that sort of wanting to share, you know, understand this community there. The community is there to help you. But, you know, we know that when you're a ciso, it's really lonely role, right? You've got to make these decisions. You've got to then not be able to show your stress. And so mentorship's important because when you're trying to learn to be a siso, how do you learn that maturity, that poise, that ability to. And these sort of soft things that you'd learn come from making the mistakes. And so to me, when I started writing about this, Ann and I started writing two books at the same time. Actually, my first book, the Aspiring CR&CISO, was sort of my war stories around becoming a CR&CISO and how I got there and how do you build yourself to there? And then as I was writing the book, I thought, actually, this is kind of, I Like this. But actually, how do I get other stories? That's not just David speaking, but others. And I thought, maybe I'll get 10 or 20. I ended up with 20, 28 people contributing, but so it was then how do you. And we were these stories together so they can start telling. I said, look, I really want to make sure that if Ann's providing a vignette of stories to me, I want this to be not a glossy corporate affairs thing, but more around what you wish someone had told you early in your career. And it could be different stages of your career. And so to me, that's mentorship happens at all levels, not just for the newbies, but also in mid levels. And even senior people need to learn from others. And so that's important to reinforce and give us courage to know we're doing the right thing or just validate that we're on the right track, because we are often working in the dark with very little information or incomplete information and very demanding stakeholders that want it.
A
Now, what do you wish that you had learned early in your career that someone had told you?
B
Gosh, probably many things. One thing I reflect on in my book and I see this in people I work with, good styles and good leaders are good at priority management. They're really good at figuring out what's really important. 1, 2, 3 things to do today. Now, to me, priority management and time management are not the same things. Priority management is more strategic. It's more figuring out. These are more important. Time management is all around just tactical, trying to get through the day and get the most out of your day. They are related and subtly related. But to me, the priority management piece around figuring out and being very mindful about that end, I think is important because the mindfulness and reflection helps you get to the clarity in your mind around what three things I must do today. And then I can go home or try to go home. That's important because at this era right now, we're just so busy looking at our phone, looking at devices, reading media materials, and not allowing ourselves to be bored to have time to think about things. I think that's really the key. When you have that ability to think about things and reflect on what's important, you can often make the right decisions.
A
I completely agree. And I do think that being able to focus on what's important and understand what's important is probably the most important thing because you are as a ciso, it's chaos at times and you really have to show leadership through that chaos. Do you think the mentorship gap we have today is a pipeline problem. Do you think it's a cultural problem, or do you think it's just that people are so busy they don't have to time to mentor?
B
I think all the above. Definitely. People are very busy. I had a dive in one of my books and I talked about Dan Lyon, Paisiso and had all these things coming at them. Incidents, regulatory, different demands. And there's probably one on the corner here that says coaching, developing your team. And often would say, when I did keynotes, I'd said, actually, you know what, these other things, fighting ransomware attacks, third party attacks, different things, they're getting all your attention. All right, Stakeholder management. How do you carve out time for your teams to build your teams? And you know, that sort of thing is really important. So to me, growth your team because you're only as strong as your team. And so I have a little algorithm, a lot in my career and which was as a leader, you come in and you inherit a team. Okay. You can't always get a chance to rebuild it all from scratch. So let's take an example. So Ann here, Ann works for me. Ann is really good. Out of ten. Ann is between a seven to an eight out of ten. Okay. And a good day. She can bring an eight. My job is to make sure Ann's always operating at the best level she can. And then she works with David. Now David's probably a five or six out of ten. I'll try to coach David to be a six, maybe figure out what are the points that it can reinforce to actually make him an 8 or 7. Impossible. So to me, as a leader, it's very simple. I've got to coach individuals to be the best versions of themselves and make sure they have great teamwork because they have great teamwork. My algorithm, that mathematical formula ends up with more output, more outcomes. Right. However, if I get a star player over here, John, now John's 9 out of 10, but he's got really bad behavior. It's a minus sign. Okay, so he doesn't add to it. He adds only his own piece, only as individual contributor. Now, going forward, I kind of see that the world we live in will be Ann, David and John working with bots. David and a bot, Ann. And again, how they work well together and making sure there's a positive multiplication there and that the actual AI agents being coached as well to be their best version. That's leadership in the future. How do we get all these paths to work together, get great Outcomes.
A
I love that I used to say that and I say it occasionally now, but I find I'm not saying as much that you can't put things into people that they don't have. You can make sure you're pulling everything out of them, all the skills, talents, aptitudes they have, so that they absolutely can be performing at their best. That's your job as a leader, is to help people maximize their performance.
B
And I think it's interesting, I talk about in my first book, is that in cyber or in technology roles we focus so much on what I call skills and knowledge. Right? We focus so much on accreditations and doing courses and learning things and skills and knowledge are really important early in your career. But to get promotions, it's all about your experience and behavior. How do you have the growing experience in doing a roadmap for a strategy of the next two years or an architecture roadmap, or supporting doing a fusion center in two countries or whatever it is, and that experience plus the behavior in actually saying no to things or saying no to your boyhood or saying no to your boss. That behaviour piece is what makes good leaders. And so how do we combine nutritional skills and knowledge with the experience of behaviours that are really confounding and making you a great leader?
A
Completely agree. Let's do a couple more questions. As you advise boards now and you advise leaders, what advice are you giving CISOs who are sitting in the chair and are trying to elevate themselves from being just an operational leader to really having strategic influence? What do you tell them?
B
It often depends upon that person. And what I see is perhaps some difficulties and deficiencies there. Okay. Because it be place to place. But I think clearly a lot of CISOs are sometimes maybe afraid to tell their board that this risk appetite won't be green, that actually that that things change or they're looking for some sort of NIS rating and that's maybe impossible to achieve because the whole world may change with new threats or new AI threats or whatever it is that they're occurring. So to me, often we'll talk about having the courage and conviction to do be bold in your prediction, but also then give yourself an out, right? To say, look, we need to make sure that we get here and we have bold metrics that take us in the direction that we want to go to because these metrics will help drive behavior. But we all at the same time, we also have to make sure that we understand that we need from a team sports stand, we need the whole team to work on this stuff, otherwise it won't work. So give yourself a bit of a break here because you can't take it on your shoulders by yourself and you need others to come on that journey with you. So that to me is the whole risk culture, the whole risk culture things all of us, not just my team. And so trying to reinforce that, I think to help us get in the right journey, in the right destination in
A
the end, I think that's great. So, David, I constantly tell people I'm a cyber optimist and I am, I am optimistic about the current and the future of the industry and I love to close every episode with optimism. So you've seen the challenges of cybersecurity up close for decades. What gives you hope about the next generation of cybersecurity leaders?
B
The new leaders coming through are smart. The new leaders coming through are wanting to learn and learn from others, I think, which is important. They're wanting to get input which I think is going to help them grow. But I think this whole paradigm will be completely challenging for many to be successful in. So I think there'll be definitely some self selection around saying, well, this is not what I want to do. I want to self select out. And so this is very Darwinian, I think. And I am optimistic but also then realistic around thinking there will be winners and losers here. But I think, I think if we could have the sort of broader attitude to how we want to succeed and succeed with the team and help support them because we will fall, we will fall and we will need to catch ourselves and our teams, we can actually succeed in the long term. So it's going to take a real team effort.
A
David, thank you so much for joining me today. I know your insights are going to bridge the practical, they're going to help people think more strategically and they're really solid lessons for our listeners to take away, they can use to shape the next chapter of their career.
B
Thank you, Anne. My pleasure.
A
And many thanks to our audience for tuning in. Join us next time on Afternoon Cyber Tea. You know, as I was thinking about guests for Afternoon Cyber Tea, David came to mind because he has been a ciso, he's written books on the topic, he's shared a lot of his experience on the topic, and I just wanted to make sure the audience could get insight from a really practical CISO perspective about what the job really is. Not the technology, but the job. It's a great episode and I know the audience will really enjoy it.
Guest: David Gee, veteran CISO/CIO, board advisor, and author
Date: January 20, 2026
In this episode, Ann Johnson sits down with David Gee, a renowned CISO, CIO, and author, to dissect the evolving landscape of the Chief Information Security Officer role. Through practical anecdotes, real-world advice, and hard-earned wisdom, they uncover the challenges, risks, and necessary mindset shifts that current—and future—CISOs must embrace. The conversation demystifies common misconceptions and addresses the interplay between technology, business, and human leadership in an era defined by AI, regulation, and constant cyber threat.
Timestamps: 01:07–04:00
“To fail in your first CISO role is maybe normal... trying to embrace that and reflect on yourself and how do you then step into and start to be more comfortable in that uncomfortable situation is really part of the growth.”
— David Gee [01:23]
Timestamps: 04:00–05:50
“You can’t please everybody. But also, you can’t be seen as the department of no. You can’t be saying no, no, no to everything... your job is to help enable the business and not just block things.”
— David Gee [04:15]
Timestamps: 05:50–07:21
“If you’re the Chief Data Officer, you own the classification piece, I help you with identification, and ... the CTO needs to make sure of the backups... there’s a bit of a team aspect to this... As a CISO, you will fail if you just rely on yourself to do this role and your team.”
— David Gee [06:34]
Timestamps: 07:21–09:42
“The environment’s harsh. The regulations... are definitely challenging. And you get an incident [that] could actually invoke three or four different regulations... the CISO being that technical person is important, but... the board needs to be convinced that you understand their strategy.”
— David Gee [07:41]
Timestamps: 09:42–11:27
“Your job as the CISO is not actually to be a spectator. Your job is to be in the game... making sure I’m onboarding all AI... not have this sort of shadow AI thing happening.”
— David Gee [10:32]
Timestamps: 11:59–13:10
“Boards are afraid of cyber security still... They kind of understand that actually this is a bad thing. Now, the tricky part is... what do you do about it?”
— David Gee [12:11]
Timestamps: 13:10–14:23
“Look at agentic AI to take manual toil out of your system, take that savings and put it into things like the SOC and penetration testing... accelerate that process.”
— David Gee [13:37]
Timestamps: 14:23–17:55
“Mentorship happens at all levels, not just for the newbies, but also in mid levels. And even senior people need to learn from others... That’s important to reinforce and give us courage to know we’re doing the right thing.”
— David Gee [15:52]
“Priority management and time management are not the same things. Priority management is more strategic... When you have that ability to think about things and reflect on what’s important, you can often make the right decisions.”
— David Gee [16:54]
Timestamps: 18:17–21:30
“As a leader, you come in and you inherit a team... My job is to make sure Ann’s always operating at the best level she can... in the future Ann, David, and John [will be] working with bots.”
— David Gee [19:14]
Timestamps: 21:30–22:59
“Have the courage and conviction to be bold in your prediction, but also then give yourself an out... it’s all of us, not just my team.”
— David Gee [22:08]
Timestamps: 22:59–24:14
“The new leaders coming through are smart... they’re wanting to get input which I think is going to help them grow ... we can actually succeed in the long term. So it’s going to take a real team effort.”
— David Gee [23:23]
“Embracing the uncomfortable is hard for a lot of people ... when people embrace the uncomfortable, you actually give the space for folks to help you along, right?”
— Ann Johnson [02:10]
“Your job as a CISO ... is not to be a bystander. It’s to be a leader and to partner with others, and to drive your team, not in isolation but with the right stakeholders around the table.”
— Ann Johnson [11:27]
| Topic | Timestamp | |-------------------------------------------------------|-------------| | The Theory vs. Reality of CISO | 01:07–04:00 | | Prioritization & Enabler Mindset | 04:00–05:50 | | Whole-Organization Risk Ownership | 05:50–07:21 | | The Challenge of Durable Leadership | 07:21–09:42 | | Influence in the Age of AI | 09:42–11:27 | | Board Perception & Security Governance | 11:59–13:10 | | Integrating AI Defensively | 13:10–14:23 | | The Mentorship Gap in Cybersecurity | 14:23–17:55 | | The Leadership Equation—Humans and Bots | 18:17–21:30 | | Elevating CISOs to Strategic Influence | 21:30–22:59 | | Optimism for Emerging Cybersecurity Leaders | 22:59–24:14 |