
Roland Cloutier
Loading summary
A
You're listening to the Cyberwire Network, powered by N2K.
B
Hi, I'm Brett Arseneault, Chief Information Security Officer at a little company called Microsoft. Recently I was approached by some customers who are really struggling with the complexities of the security threat landscape. In particular, just looking for practical advice with the increase in threats, with the changing landscape and digital transformation that's going on, people were really trying to understand from experts what could they do practically that would actually help them in this new threat landscape we're living in today. I realized how fortunate I am to have met with some of the sharpest minds on this topic, whether it's competitors, vendors, internal Microsoft people, government people who all share a vision for a mission on how to better protect ourselves. This created an opportunity to take some of those learnings and share them in this podcast series. Hopefully you'll find this interesting. I know I'll learn a lot from it. Today I'm joined by Roland Cloutier, Chief security officer of ByteDance and TikTok. Roland is an accomplished leader and author with over 25 years of experience in the military, law enforcement and and commercial sector. He is one of today's leading experts in corporate and enterprise security, cyber defense program development and business operations protection. Roland joined TikTok a little over a year ago as the Global Chief Security Officer. He is accountable for leading and delivering security risk and privacy protection programs for the world's fastest growing social media and video sharing platform. Prior to joining TikTok, Roland spent 10 years as corporate Vice President and Global Chief Security Officer at adp, a global provider of comprehensive and payroll services and human resource management solutions. Today, Roland and I are going to talk about resiliency and effectively planning for future cybersecurity demands while securing the present, which is one of the primary topics in his book Becoming a Global Chief Security Executive Officer. Roland, the only problem I have, of course, is had you written this book 20 years ago, you could have saved me a lot of hassle, my friend.
A
Well, I had to wait to get all the tips from you, Brett.
B
You lie when the truth would serve you better. I love it. Hey, listen, welcome to the Security Unlocked. Roland, I'm super excited you're here. Obviously we've known each other for a while. We share experiences all the way back to New Hampshire. For any of those you don't know, it's just an upside down version of Vermont. Super exciting. Well, I start with your first remembrance of our getting together and then I'll share mine.
A
Oh, you know, I think this dates back to when you weren't a ciso. I think you were coming out of it in the CTO's office. And I had gone to Redmond as a chief security officer for a CISO conference, and they were announcing you as the new guy. Had to be like, 20 years ago. And we, we hit it off and figured out we were two guys from New Hampshire that made it out, and we're doing big things. So it's been a while.
B
Yeah, it has, actually. That's funny. I forgot about that. I was. I spent years as a CTO on the product side and then moved over into the operations side. So it's a. The industry, the career, the roles, everything has evolved quite a bit. I guess we say we met too, too long ago.
A
Very true.
B
It's amazing. But seriously, I mean, you've always watched your career, even before this, when you're at EMC and a bunch of other things. You've done amazing work. And I think, like I said, the role of security is so different now than it was a long time ago. There's a sort of a common theme about many of the people in security that are practitioners have a background either in law enforcement or military, and that's similar to you. And one first, thank you for your service, but maybe a little bit of how you got into the security in the first place and you know what you're doing now.
A
Yeah, it's funny you say that, Brett, and not too long ago, it wasn't like that. I mean, you didn't, you didn't necessarily see former law enforcement in court cyber positions. What I think makes it so interesting for men and women coming out of the military or government service in this space is really two things. First and most fundamental, most of the great practitioners, whether they're former military or government or not, they love what they do. I mean, they have a true passion for protecting their fellow citizens, the world in which they live in. I love service and I love serving others. And I think the excitement I get around about consistently be able to meet the needs of our general society in this area, match up to that career field. And the second major area is really about the discipline of protection. And whether coming from an investigations background or a global protection or the military, you learn core concepts in being able to defend something, whether it's a base or country or the principles of government. You've learned some real critical skills growing up through that world, and, and you can pretty easily convert those into how you protect a company or how you protect the data center, or how you protect an Economy. So I think those two things have served me well over time and that's why I think a lot of people are drawn to this career field from government first.
B
Roland, thanks for sharing those two perspectives. I think that's super helpful. I think good friend of mine once told me, if you can find a place where your advocation meets your vocation, you've sort of reached the nexus in, in your life. And so super glad that's worked out for you. I feel as well here that this is a mission. It's not just about the role. And so it's great to know that we're doing something good here, which is, we hope anyway, it's super helpful. What are some of the skills you really lean on the most from your time in the service? Because you think of the juxtaposition of the two things. I'd love to, love to get some corollaries there.
A
From my perspective, it's really super easy. I think first and foremost is discipline. If you're in this business, you've got a lot of stuff coming at you. You have to make decisions, you have to be consistent in the way that measure and think and execute. You're under a lot of pressure all of the time. And that self discipline on being able to prioritize, be able to breathe, to be able to take that information in and you know, and take it one step at a time is super important. And. And I think I really got that from my time in military and government. The second thing is, I wasn't kidding before. There's some basic things around defending things, right? We talk about in cyber and information security, defense in depth. They had that like back in the Roman days. So when you're in the military and you're learning doctrine and you're learning security methodology for defending nuclear assets for a country, you actually learn a lot of those principles and they can just be really reapplied. And the third thing for me, and everyone's a little different, but I learned leadership, I think as an nco and I wasn't an officer, I was an NCO and was working my way up the ranks and then in, into federal law enforcement. You have to learn to lead humans, right? This is a difficult job. There's never an end. There's always a pile in front of you and you're leading people that want to go up that hill and charge that hill with you. And to do that well, you have to be educated in leadership. And I think one of the things I like most about this job is leadership. And I'm fortunate that I've had insanely great leaders along the way, starting in my time in the military and law enforcement. And I've been able to carry that through and help educate others. A quick side note. A great CISO once told me, we were talking about how to measure your career, and this was probably 15 years ago, at least. And he says, I measure it by the number of CISOs I've placed out in the world. And I've always thought that's really, really interesting. And it's something I keep in the back of my mind. And I think I'm up to something like 19 CISOs that have worked for me in one capacity or another and now are CISOs out in the world. And being able to create those leaders is exciting to me.
B
No, that's a great way to think about it. It's a great way to measure success. Obviously, if I could lean a little bit on that again. In your book, Becoming a Global Chief Security Executive Officer, you share the experiences about how to advance the organization's security program architecture. And we've talked about that, but we also really talk about how you effectively plan for the future demands of leadership in global security. And people talent is a huge part of that. The output you're just talking about is awesome, but then there's the input and the growing demand on need for skills. So how do you think about identifying those examples of future demands and how you really deal with that?
A
It really all starts with the business. That's why that. That play on the words of Chief security Executive officer. Right.
B
I tried to. I tried to get the annunciation right on executive officer. Hopefully I didn't miss it.
A
No, I mean, it's perfect because all, you know, people give it a. Like, that's a weird way to, you know, put CISO or CISO in a book. It's all about how do you impact the business you're serving. And that business can be an agency or, you know, a public or private company or school, it really doesn't matter. But, you know, the point is you're there in service of a business, some sort of business. And what I wanted to be able to document is this concept of business operations, protection, and being a business security person and ensuring that you have this level of understanding of what you're trying to, you know, accomplish through the eyes of the business. And so a lot of the book is based on how do you build things that support that mechanism. There are a few areas that I'm already obviously passionate about. There's the Area of convergence, which means why have 15 different security groups report into 12 different sections of the business up to 7 different leaders who all compete for the same budget across the same board and the same risk organization, so on and so forth. So I believe convergence is a mechanism to give transparency to the executive leadership and the board of a company. It enables you to prioritize across all aspects and disciplines of security, risk and privacy operations. I would start there secondarily. I think risk is a big discussion here, right? Many, many organizations have risk organizations, enterprise risk organizations. But the reality is as a security leader and practitioner, we're all in risk. And so how do you formulate a portion of your organization to look at the controls that you've committed to, to the efficacy of your ability to defend those controls? And how do you measure, monitor and measure risk against those to prioritize? Like all those are important. So I think two big topics for me is always going to be convergence and risk.
B
You know, it makes sense. And I, you know, isn't just jabbing you on the executive thing because I think if you look at the role 10 years or even five years ago, it's radically different and sort of pushing on our New Hampshire heritage and bucolic pictures. And you think about the role the cfo, which was at one time an accounting position and now it's a business leadership role, or the cio, which is a business leadership role. And security, I think you've nailed it has really changed in the last, I'd say five years. But I'd love your perspective on when you think it really sort of changed into that view. But on this topic of executive leadership for securities, it is relatively new. I mean, relative to being a role of deeply technical people, to really evolving to a risk and business leader. And I think what precipitated a lot of that change, you think in say the last decade.
A
Yeah, I said you were probably closer with the last five years. I think that's when we've seen it. And it's because of the massive impact of major technical disruptions which within global ecosystems of businesses. And if you think about any day current business, it is a massive digital ecosystem. You have your supply chain, your software chains, your delivery mechanisms. You can't even go to a mom and pop store in the middle of a city in East Kabumpu somewhere and they're actually entering their orders for the week online. This is the way the world has turned to. And the larger the organization, the more that technology has just become at the heart, soul and core of how the organization operates. And so these disruptions you've seen when you see over 50% of the world transport impacted through a cyber attack on a shipping company in Europe, those are big numbers. And so I think people are starting to realize, like, hey, what do we do if. How does this impact us if. And responsible leaders in executive management in these companies have said, we have to have a change. Security does have to have a quote, unquote seat at the table, but we have to have the right people in that seat to be able to truly understand the risk and how we counter that risk. The other thing is, I think education's getting better, Brett. I'm seeing a lot of people come out of these, what used to be technical information security undergrad programs, now with these business impacting postgrad programs that you see major universities like Maryland or uc, Naval postgrad. Right. They're turning out not just good technology leaders, they're turning out good business leaders and understanding the business impact. So the level of practitionership is going up. The level of transparency and impact to business organizations is really being solidified through, unfortunately, real acts that we're seeing. And quite frankly, you're seeing. We were some of the founding people. You look at Steve Kay, who started one of the first CISOs. We're really the next generation down from that. So this is a short lifespan. We're talking less than 20 years of true executive leadership in this security risk and privacy area. So we're just growing. We're maturing where CIOs I say were 10, 15 years ago.
B
Yeah, no, it's a great analogy. And I like, I like your comment about the importance of the technology transformations regardless of the business. And since you brought it up, I'll do a shameless plug for Cheddar's in Littleton, New Hampshire, the largest candy bar, longest candy bar in the world. And they actually do their orders online as well. So if you're in Littleton, go up and get some candy from Cheddar's. So while we're. While we're on it, not many people would know that off the top of their head. So I figured I'd throw it out there. But I do think, speaking of northern New Hampshire, which many would consider to be a different sovereignty than southern New
A
Hampshire or Massachusetts, above the notch versus below the notch. Very different parts of the world.
B
Exactly, exactly. And I've lived on both sides of that notch, and I understand. But I think if you take sovereignty beyond the state level and you think Microsoft operates globally, TikTok operates globally, how do you navigate the balance of protecting your customers data and maintaining trust with them relative to the sovereignty requirements? Because it's so different in Germany, Asia, go to US, South America and different parts. I'd love to hear your views on that as a person running a large global organization.
A
First you need partners. You don't do this job alone. You don't do this in the COVID of darkness and figure things out. You need other leaders in the area of privacy. You need leaders in the area of, you know, legal and regulatory requirements to help really decipher the daily change in how individual sovereign nations make decisions about protecting their consumers. And really that's all it is. I mean, this is about, yes, it isn't about national defense in some ways, but most of these are based on protecting consumers. So you need to understand those first and foremost. Secondarily, I think a lot of organizations, and certainly we are taking the focus on how do you regionalize the concept when you think about, you know, what was originally GDPR and the move to other things. But how do you start to develop your business in such a way where your data residency, your data management, your data transferred is managed in a regional format, where you're developing global teams that understand that this is how our business will operate in the future, and you're constructing products that understand and operate in that same way, instead of just security and privacy imposing requirements on top of products. You have this by design mechanism, right? Security and privacy by design built into the product regionality. That's our approach, that's how we're doing it. But it takes a lot of partnership and a lot of education and it's
B
going to get more complex, right? Increasing regulatory pressure and a lot of other, like I refer to as digital xenophobia. We have to keep working on how we manage in that world. So I think that's. I love your idea of partnership for sure. And I love the regionalization. I think one of the things, for me that's probably most interesting and I think you're uniquely qualified to answer, like, we really try to drive a culture of security where everyone has what role and what they're accountable for. Like, not everyone's a security person, but everyone has security as part of their job. And obviously when I think about it, you know, ensuring our developers and engineers are doing all the right things. You think about your career from tech company, financial company, to, you know, social media company. How do you think about consistently driving a culture of security? I mean, it's the fifth page in your book on driving Accountability, which I love. So how do you think about it across that spectrum?
A
I think you said it, it's all about the culture. Stupid, right? Like, I mean, that's how it was explained to me. And by the way, it's the number one thing that I have to be reminded of on a constant basis when you're dealing. Like you, you know, you know, you guys are what, in 136 countries or something like that, We're a little behind you, but you know, we're, you know, you're in 86 countries around the globe doing service operations in like 40 something countries. And every culture is different. So you have to understand the culture. But the one most important thing that I think that has been able to bridge that gap, no matter if it's culture or language or what have you, is context. And what I mean by that is, you know, if you just explain something to someone like why that is bad, if that happens, you know what could happen how would impact the company, the organization, their job, and you give them for instances and they get educated on it, they consume that and they want to do the right thing. 99.98% of the people in the world want to do the right thing. So when you educate them and you spend as much time explaining the criticality of what they need to do in that context, they'll do it for you. And you can bang them over the head with PowerPoints and click here and phishing tests and validation within the sdlc and you can make them take education moments around, you know, by design integration. But at the end of the day, if you spend time with them, person to person, human to human, educating them, they become your best proponent in the company.
B
Certainly building an army of advocates is always a great thing to go do. I try to balance like how much do they need about security versus how much do we enable them, like we say, like to help developers fall into the pit of success. Like how do you think about that as a way of thinking about it?
A
So I think the, what you have to explain to them is a downstream residual impact and provide them with the tooling as a mechanism by how they do their job natively. Meaning if you ask them to go out of their process, if you ask them to go out of their pipeline, you're going to have problems, right? Because what are you doing? You're re engineering the way that a 4,000, 10,000, 50,000 person workforce actually operates. You have to integrate yourself with their tools, teams, you have to have backend integrated applications that provides them with the Information within their documentation, within their lanes. You have to do the hard work up front or should I say out back to push it to them so they don't even know it's happening. Right. You look at some of the cool technologies today that when you're doing in code prior to submission validation of like the OWASP top 20 and pops up in front of the engineer and oh, by the way, would you like to take the course? Right? Like that is fantastic. These, you know, these organizations that are implementing those are making their lives easier. And when you get into the the QA within the CICD pipeline and security becomes an embedded part of how that goes into the measurement of quality within the business, that changes everything when you go from measuring it as a security flaw to a quality flaw. That's how engineers think. That's how they need to understand it. So the better a security portfolio can integrate into that engineering concept mindset and just have people inside the organization and doing this type of work for you. I think the better you become and the more integrated you become.
B
I love then from security to quality. I think that's a great way to think about it for sure. One of the other points, you're going to transition a little here. Obviously it's been an interesting year plus with a lot of global situations going on with pandemic, social injustice and all the other components. But one thing that's for sure is we have a different way of working going forward. Many companies are having a different way. We've learned we can be productive, more remote than we were before, and still be secure, et cetera. I'm curious what you personally have learned from some of these recent incidents that have gone on and how you think about securing the new hybrid workplace. It still shocks me today that I look at the Data and only 18% of enterprise entities are using MFA as an example. So how do you think about the hybrid workplace going forward and what just some of the key learnings you've had?
A
Well, not having worked at home for more than two weeks at any time in my life, I did not realize actually the amount my dog sparked. So that was a good learning experience. No, on a serious note, I think from a pure work perspective, as a quick reminder, I changed jobs in the middle of the pandemic. You know, it was right at the beginning actually, before it really exploded. Had a month off. I came back in April of 2020 and the world was a different place. So I actually didn't meet anybody for a year. Everything was remote. I didn't have the context, I didn't have those personal relationships, so doing that remotely was a pretty big deal for me. Learning how to manage teams, learning how to integrate and really learn personalities through remote mechanisms was new for me. Some people have done that all their lives, but it was certainly new for me. But when it gets into the context again of protection, boy, that came interesting, right? You used to have 400 campuses around the world you were protecting and all of a sudden you had 100,000 endpoints or 200,000 endpoints you were dealing with and that becomes your zone. So, you know, I think the zero trust model has done a, you know, have been a big success for us as we think about protecting what really matters most and that's the data. So how do we, how do we put zero trust capabilities not just inside our product, but within our enterprise itself? As you think about the future of where this is going, some of these concepts of, you know, brick and mortar defense and tiered integrated enterprise defense really moves out and, and potentially these hybrid cloud work environments I think are going to be great. I mean, I know you've been experimenting with them, we've been experimenting with them. How do you get that endpoint For a user to actually be in a protected cloud context, data is not leaving the building, so to speak. It's always operating within that protected area. I think the zero trust ability around things like multi factor authentication on the back end, I mean certificates are back in a big way, right? Like you know, integrated authentication with, you know, PKI infrastructure. To do some of these really cool things gives you that high level of assurance and authority. It gives you detailed audit that you forget you can even get out of a system sometime. But now that will provide it for you. Down to the data element level. I think those are some great things. And you know, listen, I look at it like this. Our business is going to change every day, every month, every year. We're going to be replanning for the products it's going to deliver, the formation of the type of business we are, JVs digital ecosystem. So this is just another change in how we need to take a step back, remodel our protection defenses and then go out and retool for the coming year.
B
Yeah, I think it'll be, it's, you know, as you pointed out, I forgot that you started there during that period. So not, not connecting with folks in the normal way or to say the usual way, not normal, but the way you used to is definitely a different way of thinking about it. I think for us we've always talked about people being productive and secure, and now it's really taught us a lot about what does it mean to be productive, secure and healthy, both physically and mentally. And I think that's going to be a big part of how we recalibrate our workforce. And thinking about how to make sure we can do all three of those at any given time, that'll be pretty fun. And as you said, I think remodeling is the term you used, and I'll remember that, but I won't share that with my family. I can't take another remodel. So this is probably the fun part of the podcast. If you haven't had fun so far, did you take up any new skills or interest during the Pandemic? I know you have the Russell Wilson Terrier, so I just, I thought maybe I had to get up something new along the way.
A
You know, I started this new job and building this new organization in the middle of Pandemic. I don't even remember the last year. So, no, I haven't done anything new. You know, it's. It's one of those things where my bride keeps telling me I need to get a hobby, but I'm not there yet. So I'm taking ideas and the winner gets a nice TikTok t shirt. Just saying.
B
Oh, I'm going to have to do that. My daughter is. As you know, I've called you for TikTok advice, and my daughter is dying for a TikTok shirt. So we'll put our heads together and come up with something for you. What book are you currently reading, besides becoming a Global Chief Security Executive officer? And what's one book that you would recommend? And you can recommend that one if you want.
A
No, that's okay. Let's see. This is going to be funny, but I'm trying to. When I read a book, I disconnect. So recently I have been reading. I have not been reading business books. I'm on the path of all the James Patterson books right now. So I'm now with Kill Alex Cross, a nice crime thriller. My background, I like crime thrillers. So it gives me great ideas for work. I mean, how to investigate things, of course I was gonna say. But, you know, I'm often asked about the different books, and there's so many books that practitioners can read that are just fantastic. I'm going to throw it out there. That's a blast from the past. I'm not even sure who owns it. And I'm not, obviously, I'm in the van in my backyard right now. So, you know, I can't go to the bookshelf and get it. But a lot of times what practitioners ask about is how do I communicate better? How do I explain what I'm trying to articulate about a critical issue? And there's a very simple book, it's a short read, I think it's called how to say it with Charts. It's a yellow book and I go back to it all the time out of, out of the thousands of books I have. And I say that because it gives practitioners an understanding of way the human brain works, of how the, you know, how they can look at pictures and images and charts, visuals and consume information. And I oftentimes it's hard for us to take a complex risk issue and turn that into an easy visual that a non practitioner can actually digest and understand, even at especially its executive level. So I often tell people that ask that question, go read that book. It's a great way for them to take a second look at how they're delivering information.
B
No, that's a great recommendation. I think on that note, that's like when you really become, you realize you become an editor like you like the USA Today version of Give me a pie chart or a graph, right, Instead of the 20 page doc or the RTFM component. So no, I think, I think it's totally fair though. It turns out good advice from counsel in my house was you could have 10% of the people understand 100% of your security job or you could have 100% of people understand the 10% and you'd be way better off in the ladder. So start drawing with a crayon more often. I think that's probably a good thing I should keep in mind myself. So here's the big call to action that every person on the podcast has to actually answer. This is the practical advice. So tell the audience in priority order, what are the three things you'd recommend security leaders can do today to plan for the future while securing the present? Three things that you would tell people to go do after this call.
A
Okay, number one, value chain risk assessment. Number one thing you can do to understand your business. We talk about this concept of business operations protection. How do you protect the business if you don't know how to make money? If you don't know how they deliver product to market, how they actual, you know, monetize things, go figure that out. Figure out the subsystems and do a prioritized risk assessment in each one of those areas. And not only will you Secure your business now, but you'll build those relationships and a capability to quickly assess changes in the business for it's going in the future. So that's, that's number one. Number two for executive leaders, do a three year staffing plan. I know that sounds crazy, but if you can get a three year view on your business, we're going to E commerce, we're going multinational, we're doing what have you understand the technology areas. And the reason I say this is because the way that you deliver your services are through people, it's through your team, it's through the job families you create, you recruit and you put to market. And so if you still have firewall engineer ones, you're probably a little behind the mark here, right? You know, if you're thinking about cloud, next generation, API analyst, defense, if you're thinking about jobs like that, you're probably on the right track. You need to create those positions, train the people you have now to be in those positions and start recruiting down the pipeline two to three years out with universities to make sure you have the right people. So that'll help you in the, help you now and will help you in the future. And I think the third is go back to school. And I don't mean, you know, necessarily go back to, you know, go get a postgrad. But education is a lifelong need. Our businesses change, our worlds change, our understandings change. We all have bias. Take a step back and assess your gap areas and then go take an online course, go take a certificate course, go to a symposium on whatever, it doesn't matter. Go learn something new this year that you can bring back to yourself, to your business and to your team. And I think if you can do those three things, you'll be pretty successful over the coming years.
B
No, that's a great list. I love it. And I think on that last one in particular we refer to a growth mindset. And I think at least one of the things I think that's amazing about this profession is every day you learn something new. And much like my math degrees, whatever I'm doing now makes me realize what I was doing before seems a lot easier. So basically it means that I really don't. Every single time you take a class it just further shows you how much you don't know. And then that reaffirms my 16 year old view that I know absolutely nothing. So I just keep pushing down that path of confirming that I know nothing. But I do think that's a great point though, I think and you raise a great thing. You don't have to go to a class you don't have to go to, you know, in on prem you can. But you can also do like a Lynda.com class or, you know, it's great learning. I learned the best way to make a sous vide steak on TikTok. So I mean, there's a lot of things in different ways you can learn. So I love that. I love those three things. So thank you so much, Roland. Of course. I appreciate the time and the lovely view you have on what will help a lot of our listeners. I hope be more effective and practical and great. Security leaders. Executive security leaders.
A
Well brought up. Thanks for the time and I really appreciate having the chat with you. It's always fun. And remember, you too can always make tiktoks to impart your knowledge on all of us.
B
Ah, you know, we should follow up. I figure how to go do that, I gotta be, you know, get. Get a little more learned in this space. Maybe that's my learning to go do. I appreciate it.
A
All right, thanks, Brett.
B
Yeah, take care. Have a great day. Good. Thanks for listening. I look forward to our next episode. And remember, stay safe and stay secure. Sam.
Podcast: Security Unlocked: CISO Series with Bret Arsenault
Host: Microsoft
Guest: Roland Cloutier, Chief Security Officer at ByteDance & TikTok
Date: July 30, 2021
Episode Title: Developing Influential Security Leaders: Roland Cloutier, TikTok
This episode brings together Microsoft CISO Bret Arsenault with Roland Cloutier, the Chief Security Officer for ByteDance and TikTok. The conversation centers on the evolving role of security leaders, building resilience while managing current and future cybersecurity demands, and the importance of developing new leaders in the field. The discussion also offers practical approaches for organizational security and effective leadership in a rapidly changing digital landscape.
Backgrounds in Security: Both hosts reflect on their shared roots and diverse professional paths, highlighting that many leaders have military or law enforcement backgrounds. Roland shares how a passion for protecting people led him into cybersecurity.
"Most of the great practitioners, whether they're former military or government or not, they love what they do... They have a true passion for protecting their fellow citizens, the world in which they live in."
– Roland Cloutier [03:57]
Transferable Skills: Roland emphasizes discipline, foundational defense tactics, and especially leadership as core strengths from his military experience, noting that leading people is central to success in cybersecurity.
"There's never an end. There's always a pile in front of you and you're leading people that want to go up that hill and charge that hill with you. And to do that well, you have to be educated in leadership."
– Roland Cloutier [05:55]
Measuring Success: Roland shares that he measures his impact by the number of CISOs who once worked for him and have since advanced into leadership roles themselves.
"I think I'm up to something like 19 CISOs that have worked for me... and now are CISOs out in the world. And being able to create those leaders is exciting to me."
– Roland Cloutier [07:48]
Role Evolution: Security leaders must understand and serve the business, not just provide technical solutions.
"It's all about how do you impact the business you're serving... ensuring that you have this level of understanding of what you're trying to accomplish through the eyes of the business."
– Roland Cloutier [08:45]
Key Pillars:
Changing Expectations: The CISO role has moved from a technical specialist to a true executive leadership position, paralleling the evolutions of CFOs and CIOs.
"Security... has really changed in the last, I'd say, five years. It's really moved to a business leadership role."
– Bret Arsenault [11:07]
Education: There’s an uptick in postgrad business education for security leaders, reflecting the business-critical nature of the role.
"They're turning out not just good technology leaders, they're turning out good business leaders and understanding the business impact."
– Roland Cloutier [12:23]
Complexities of Operating Globally: Roland discusses the regulatory variations across jurisdictions and the need for strong partnerships with legal, privacy, and regulatory teams.
"You don't do this job alone. You need other leaders in the area of privacy... to help really decipher the daily change in how individual sovereign nations make decisions."
– Roland Cloutier [14:56]
Regionalization and Privacy by Design: Advocates for building regional and compliant data management into products from the outset, not as an afterthought.
Context and Culture: The power of context in security education—personal, relatable stories and direct human interaction drive behavior change globally.
"99.98% of the people in the world want to do the right thing. So when you educate them... they become your best proponent in the company."
– Roland Cloutier [17:10]
Integrated Enablement: Security has to be woven into workflows and development pipelines (e.g., secure-by-default tooling). Don’t ask people to step out of their processes—embed security tools natively.
"If you ask them to go out of their process... you're going to have problems. You have to integrate yourself with their tools."
– Roland Cloutier [18:56]
Security as Quality: Success comes when security is viewed as part of software quality, not just compliance.
Remote Leadership: Roland shares personal challenges onboarding virtually and the need to develop new collaboration skills.
"I actually didn't meet anybody for a year. Everything was remote. I didn't have the context, I didn't have those personal relationships, so doing that remotely was a pretty big deal."
– Roland Cloutier [21:18]
Endpoint Security & Zero Trust: Shifted from protecting office infrastructure to managing thousands of remote endpoints; champions Zero Trust architecture, MFA, and persistent protection.
"You used to have 400 campuses around the world... and all of a sudden you had 100,000 endpoints... That becomes your zone."
– Roland Cloutier [21:18]
Ongoing Adaptation: Reframes the constant evolution—security programs must be continually remodeled and retooled for changing business and workplace environments.
Value Chain Risk Assessment
Three-Year Staffing Plan
Continuous Education ('Go Back to School')
On Leadership Legacy:
"I measure [my career] by the number of CISOs I've placed out in the world."
– Roland Cloutier [07:47]
On Security Culture:
"It's all about the culture, stupid, right?... What has been able to bridge that gap... is context."
– Roland Cloutier [17:10]
On Integrating Security:
"When you go from measuring it as a security flaw to a quality flaw, that's how engineers think."
– Roland Cloutier [19:44]
On Remote Leadership:
"I actually didn't meet anybody for a year. Everything was remote."
– Roland Cloutier [21:18]
Roland’s Book Recommendation:
"How to say it with Charts. It’s a yellow book and I go back to it all the time... helps practitioners understand how people consume information visually."
– Roland Cloutier [26:28]
This episode is a must-listen for aspiring and current security leaders. It weaves together personal leadership journeys, practical strategies for modern cybersecurity challenges, and actionable advice on talent development and business alignment. Roland Cloutier’s pragmatic recommendations and focus on cultural and continual learning highlight a modern, holistic approach to security leadership.