00:00:00.160 --> 00:00:15.679
We know behind the uh the cyber or or you know folks that are wanting to attack, you know, engineering systems or SCADA systems or other OT systems or whatever they might be, there's a person with intent behind all of that, right?
00:00:15.679 --> 00:00:20.320
And so they could be doing things operationally or they could be doing through through the systems.
00:00:20.320 --> 00:00:29.039
It's still the same people with the same intent of disrupting your business, stealing your money, causing you harm around reputation.
00:00:29.039 --> 00:00:47.439
And it's really important to have that conversation in a broad sense, but also organizations, big or small, have to spend time and really determining the risk tolerances and the resources that they need to manage this challenge globally, macrally, and in an interconnected state.
00:00:47.439 --> 00:00:49.200
Hope that helps out, Doug.
00:00:49.600 --> 00:00:50.479
No, absolutely.
00:00:50.479 --> 00:00:52.479
I think you summarized it great.
00:00:52.479 --> 00:00:57.039
You can't separate them when you get to the top of the boardroom table.
00:00:57.039 --> 00:00:57.520
Yeah.
00:00:57.520 --> 00:01:00.960
It all looks like money and disruption to them, right?
00:01:00.960 --> 00:01:02.000
It does.
00:01:02.000 --> 00:01:03.039
It does.
00:01:06.079 --> 00:01:13.120
This is Caffeinated Risk, the podcast for security professionals by security professionals.
00:01:13.120 --> 00:01:20.079
Here are your two self-proclaimed grumpy security guys, Tim McCree and Doug Lease.
00:01:24.799 --> 00:01:34.719
Our next podcast guest is Joe Oliveras, the Executive Vice President, Health, Safety, Security, Environment, and Enterprise Quality at Jacobs.
00:01:34.719 --> 00:01:38.799
He's also the 2025 past president of ASAS International.
00:01:38.799 --> 00:01:44.000
Joe became the first global security leader at Jacobs in 2014.
00:01:44.000 --> 00:01:56.319
And due to his leadership and focus on risk and resilience, his role expanded to include leading the global quality team, the operational center of excellence, and eventually to his current role in 2024.
00:01:56.319 --> 00:02:09.680
Prior to Jacobs, he held increasingly responsible roles at Baker Hughes, from manager of investigations to director of security global operations to VP Enterprise Security and Crisis Management.
00:02:09.680 --> 00:02:20.000
Joe's business approach to security led to the maturity of his team's adoption of enterprise security risk management, along with business planning, strategy, and resilience.
00:02:20.000 --> 00:02:33.840
Joe has been recognized as the IFSEC top global influencers for security and fire in 2018 and identified by Security Magazine as one of the most influential people in security for 2021.
00:02:33.840 --> 00:02:39.919
He also received the Don Walker CSO Center Executive Award in 2021.
00:02:39.919 --> 00:02:44.479
And now let's check out our latest podcast with Joe Oliveras.
00:02:44.479 --> 00:02:48.400
Joe, it's great to have you on the show.
00:02:48.400 --> 00:02:50.800
Thanks so much for being part of Caffeinated Risk.
00:02:50.800 --> 00:02:52.159
We appreciate you coming on board.
00:02:52.159 --> 00:02:53.039
Thanks for that.
00:02:53.439 --> 00:02:54.159
Thank you, Tim.
00:02:54.159 --> 00:02:55.199
Pleasure to be here.
00:02:55.199 --> 00:02:57.520
And I need uh some more caffeine.
00:02:58.319 --> 00:03:03.039
I was gonna say, you know, this is we we always stock up before we start the session, so you betcha.
00:03:03.039 --> 00:03:05.039
We got a lot of questions I want to get into today.
00:03:05.039 --> 00:03:10.479
But first, uh one, I I want to thank you for the time and your service as past president for ASS.
00:03:10.479 --> 00:03:13.919
Sat in that chair myself, and I appreciate how much time and effort it is.
00:03:13.919 --> 00:03:17.759
So I just I want to thank you for the time that you spent as president for SS.
00:03:17.759 --> 00:03:18.639
You did an awesome job.
00:03:18.639 --> 00:03:24.479
I thought you know 2025 was just just an amazing year for you, and um, I want to thank you for all your service with ASS.
00:03:25.120 --> 00:03:26.159
No, thank you, Tim.
00:03:26.159 --> 00:03:27.520
It's uh it's a pleasure.
00:03:27.520 --> 00:03:36.879
Hard following people like you and you know, Godfrey and Malcolm and and uh you know JP and you know, a lot of great folks uh there historically.
00:03:36.879 --> 00:03:42.240
Um so it's an honor to be part of that group, now a past president group, but but thank you very much.
00:03:42.240 --> 00:03:47.599
And and none of it can be done without you know the volunteers and all the constituents that we serve.
00:03:47.599 --> 00:03:50.240
It's a great, great association, great organization.
00:03:50.560 --> 00:03:51.039
You betcha.
00:03:51.039 --> 00:03:53.199
We're gonna need like a coffee mug or a ring or something.
00:03:53.199 --> 00:03:57.199
I don't know what it is, but we've got to we gotta we've gotta come up with something, right, for a past president.
00:03:57.199 --> 00:04:08.000
So um one thing I did want to ask though, just to kick things off, is I'm really fascinated about the career path you've taken and where you came from and how you ended up today in Jacobs.
00:04:08.000 --> 00:04:14.000
So can you can you take a little bit and walk us through how you got from where you first started and where you are today?
00:04:14.000 --> 00:04:18.240
And I think that's it's a really cool story for the for the audience here at Caffeinated Risk.
00:04:18.879 --> 00:04:20.160
Yeah, thank you, Tim.
00:04:20.160 --> 00:04:30.959
Uh look, it's a conversation I've been having uh a lot uh lately with with people, which is uh uh you know really nice um to talk about.
00:04:30.959 --> 00:04:41.439
I you know, early, uh I kind of knew I wanted to get into security, law enforcement, investigative kind of work very early in my career.
00:04:41.439 --> 00:04:46.560
Um I'm the oldest of three um you know siblings, uh two sisters.
00:04:46.560 --> 00:04:54.079
I had no brothers, um, but I had uh a couple of cousins that were in in law enforcement, and um I was very close to them.
00:04:54.079 --> 00:05:02.000
I looked up to them, and that gave me my kind of initial uh you know, piqued my curiosity uh very, very early on.
00:05:02.000 --> 00:05:04.480
Um so um stayed in that channel.
00:05:04.480 --> 00:05:05.839
I knew that's what I wanted to do.
00:05:05.839 --> 00:05:13.439
I went to a liberal arts uh college uh here in East Texas um and uh pursued my criminal justice degree.
00:05:13.439 --> 00:05:21.759
But one that was a little slightly different um in that most criminal justice programs, way back then when I went to university, a long, long time ago.
00:05:21.759 --> 00:05:26.959
Yeah, uh it was uh you could take two paths in criminal justice.
00:05:26.959 --> 00:05:29.040
It was corrections or law enforcement.
00:05:29.040 --> 00:05:31.279
But at this one, Stephen at Stephen F.
00:05:31.279 --> 00:05:37.040
Austin University, they had uh something called um uh legal research or legal uh legal emphasis.
00:05:37.040 --> 00:05:40.879
And so I had aspirations to potentially go to law school later on.
00:05:40.879 --> 00:05:42.399
Um so I took that.
00:05:42.399 --> 00:05:59.839
And about two and a half years into the program, uh they expanded the program to actually uh introduce this whole world of private security uh that we now know private and corporate security, uh, which again began to pique my curiosity and be fascinated by it.
00:05:59.839 --> 00:06:18.480
Um I um at least uh had a good time in college, but I also was pretty mindful of making sure that uh I I took part in the appropriate studies, and so I got the honor of being recruited by or interviewed by an organization called General Dynamics in Fort Worth.
00:06:18.480 --> 00:06:20.639
It's an Air Force defense contractor.
00:06:20.639 --> 00:06:24.959
Um they came down to talk to a couple of top students at the university.
00:06:24.959 --> 00:06:27.279
I happen to be one of them, which was great.
00:06:27.279 --> 00:06:34.800
Uh, got the interview and got the job and got into this world of corporate security very early on in the government defense side.
00:06:34.800 --> 00:06:38.959
Um, really began right from the beginning, right from the basic, right?
00:06:38.959 --> 00:06:49.680
You know, how you deal with access control, how you deal with physical security systems, how do you respond to incidents, how do you monitor alarms, how do you you know do it all, which what which I thought was great, right?
00:06:49.680 --> 00:06:55.519
Because I didn't come in into some vertical, it was really a wide aperture of how to do that.
00:06:55.519 --> 00:07:02.319
Uh moved up to an analytical position, security analyst, also began running operations for several facilities.
00:07:02.319 --> 00:07:07.839
Um, and then I was recruited by NASA at the Johnson Space Center here in Houston, which is where I'm from.
00:07:07.839 --> 00:07:18.959
So that opportunity to come back to Houston, be closer to the family, um, and now instead of being on the government defense side, actually being the client on the government side.
00:07:18.959 --> 00:07:20.480
So came here.
00:07:20.480 --> 00:07:30.959
Um one of the things at General Dynamics that really I learned a lot was the investigative side, working with the historical uh office of special investigations folks.
00:07:30.959 --> 00:07:35.040
They recruited heavily out of the Air Force as an Air Force defense contractor.
00:07:35.040 --> 00:07:39.759
So um that investigative uh capability was an area I wanted.
00:07:39.759 --> 00:07:41.040
I continued to grow.
00:07:41.040 --> 00:07:58.240
I ended up being the lead criminal investigator at the NASA Johnson Space Center um, you know, over my seven-year career, uh, focused a lot on, you know, espionage, sabotage, uh, working counterintelligence, you know, work, uh risk analysis, um, even executive protection there.
00:07:58.240 --> 00:08:07.040
What people maybe don't understand is that if you come to Houston, everyone wants to come to the NASA Johnson Space Center, including dignitaries and presidents, right?
00:08:07.040 --> 00:08:07.360
Right.
00:08:07.360 --> 00:08:18.399
So our work with the Secret Service, with the Diplomatic Security Service that had protective uh responsibilities for um international leaders, um, I got very involved with.
00:08:18.399 --> 00:08:25.839
So did that over a period of time, you know, guys, and and as I was going through there, um, I wanted to go back to school.
00:08:25.839 --> 00:08:30.079
And so the decision was do I go do the law school or do I get into business?
00:08:30.079 --> 00:08:32.559
And I was seeing security, you know, change.
00:08:32.559 --> 00:08:36.639
So within the government side, there's a lot of regulatory things, right, that are happening.
00:08:36.639 --> 00:08:50.159
Um, but in the broader corporate, you know, side, there are regulatory things, there are other legal liability things, there are softer things that you've got to think about in the context of security and how that may affect you know your business.
00:08:50.159 --> 00:08:52.639
So I actually went back to get my MBA.
00:08:52.639 --> 00:08:57.759
And as I did that, and and I wanted to bring the business acumen to security.
00:08:57.759 --> 00:09:12.159
Um, learned early on that in order to kind of you know sell things, you have to be able to influence, you have to be able to understand your constituents and understand what kind of pulls their you know, pulls their strings, what's important to them.
00:09:12.159 --> 00:09:17.759
Um, and oftentimes it's the business side or it's the financial part of the business side and those kinds of things.
00:09:17.759 --> 00:09:28.000
So doing that, and then after that, I went to um, I left the government and I went to a consultative, uh global consultative and investigative firm.
00:09:28.000 --> 00:09:36.639
So I wanted to take the the skill set on the security SME and the business side and and go go practice this, right?
00:09:36.639 --> 00:09:38.159
And the advisory side.
00:09:38.159 --> 00:09:49.120
Um I was recruited initially to be one of their lead investigators and and actually from a career perspective, I actually pushed back on that and I said, look, I want to do something different, right?
00:09:49.120 --> 00:09:53.200
I've yes, I've got the investigative side, but I've got all this other security side.
00:09:53.200 --> 00:09:57.919
So let me work on the investigative and the security consultation side, number one.
00:09:57.919 --> 00:10:01.360
And then number two, I want to learn how you run the business.
00:10:01.360 --> 00:10:16.320
So I want to get involved in the marketing, the business development, the client engagement, the, you know, how do we how do we, you know, uh, you know, talk to banks about the, you know, the financial access that we need and those kinds of things.
00:10:16.320 --> 00:10:24.000
So did that, and what I learned, Tim, was that, you know, as we were servicing our clients, they're all different.
00:10:24.000 --> 00:10:29.600
I wanted all our clients to be my number one client and want them to feel like they're my only client.
00:10:29.600 --> 00:10:31.759
But you know how hard that is to do, right?
00:10:31.759 --> 00:10:33.039
You know, for for all of them.
00:10:33.039 --> 00:10:34.240
But they all were different.
00:10:34.240 --> 00:10:40.879
They were oil and gas, they were uh technology, they were the entertainment industry, they were transportation, they were finance.
00:10:40.879 --> 00:10:46.799
So what I learned was even security within that context is different in in a lot of these places.
00:10:46.799 --> 00:10:53.679
So there's some things that are that are core, and that there are some things that are different by industry or even by culture of organizations.
00:10:53.679 --> 00:10:58.000
Um did that, being in Houston, oil and gas is a big thing.
00:10:58.000 --> 00:11:01.919
I went to Baker Hughes, oil and gas, uh large organization.
00:11:01.919 --> 00:11:04.720
Um, and that probably changed my career.
00:11:04.720 --> 00:11:11.039
So taking all the investigative stuff, helping build anti-corruption programs for them, uh, doing investigative work.
00:11:11.039 --> 00:11:16.159
I met um my mentor Russ Kinsilla, who asked me, what do you want to do?
00:11:16.159 --> 00:11:18.720
And I said, I want to be a chief security officer.
00:11:18.720 --> 00:11:23.039
I was leading our anti-corruption, our investigative program there at Baker Hughes.
00:11:23.039 --> 00:11:25.200
And he says, Well, then I need to take you out of that.
00:11:25.200 --> 00:11:28.720
And I said, Oh, I'm I'm I'm precious, you know, about this.
00:11:28.720 --> 00:11:31.519
He said, Yeah, but you have all these other skills, right?
00:11:31.519 --> 00:11:46.799
So come be my director of operations, help build this program that was built vertically, build it globally, horizontally, integrated, um, and lead crisis management, physical security, investigative, just kind of help lead it all.
00:11:46.799 --> 00:11:48.080
So did that.
00:11:48.080 --> 00:11:53.039
Um, and then really the last thing I'll get to it is uh where I am now at Jacobs.
00:11:53.039 --> 00:11:58.960
I was hired to then so ended up um you know kind of uh supporting Russ in that role.
00:11:58.960 --> 00:12:02.639
And I was ready for the next chief security to be a chief security officer.
00:12:02.639 --> 00:12:04.559
That role with Jacobs came up.
00:12:04.559 --> 00:12:08.000
Um, you know, I took it to be the global security, you know, director.
00:12:08.000 --> 00:12:13.120
Um, and now I'm the EVP of security, health safety, environment, and quality.
00:12:13.120 --> 00:12:15.200
Um, there's a whole journey behind that.
00:12:15.200 --> 00:12:21.200
Maybe we could talk about that as we go, but that's how I got to where I'm at, you know, today and still loving it, Tim.
00:12:21.200 --> 00:12:22.240
That's awesome.
00:12:22.559 --> 00:12:29.279
Yeah, I I'm glad you mentioned Jacobs because I was gonna ask the question and I wasn't sure if it was legit.
00:12:29.279 --> 00:12:39.600
I mean, we we know that on this show our views represent ourselves, not necessarily our company, but you know, people tend to put those two together.
00:12:39.600 --> 00:12:46.240
With an engineering company like Jacobs, and of course Houston, it's a lot of oil and gas and things like that.
00:12:46.240 --> 00:12:50.159
There's a lot of cyber physical elements to it.
00:12:50.159 --> 00:13:14.320
And are you finding with the digital control of a lot of this cyber physical and the thing that you actually have to be in front of a piece of equipment, or you could be manipulating it electronically, is really making the whole investigation and protection extremely difficult to even design for?
00:13:15.679 --> 00:13:20.080
Well, I think you know, for me, we've got we've got you know great engineers here.
00:13:20.080 --> 00:13:35.360
I think any engineering company globally, any company today, I think we'll just take a step back from a from a cyber and from a physical security perspective, you can't have one conversation without the other anymore.
00:13:35.360 --> 00:13:54.399
Um, and at least, you know, here and where I've been, and certainly on the consultative side, you know, we really think it's really important for, you know, the cyber organizations, the global security and resilience organizations or corporate security departments to really work hand in hand with one another, right?
00:13:54.399 --> 00:14:03.279
To to proactively look holistically at what security risk looks like or what risk looks like to the to the organization.
00:14:03.279 --> 00:14:09.440
I I have this conversation a lot with with leaders about you shouldn't compartmentalize these things.
00:14:09.440 --> 00:14:15.840
You know, you have some SMEs that have deep domain experience and on both sides, you know, of this.
00:14:15.840 --> 00:14:28.159
But as you you know kind of walk up the ladder and and you think about what an executive leadership team or a board you know needs, they want that wide aperture of of understanding.
00:14:28.159 --> 00:14:32.240
And also that consistency and clarity.
00:14:32.240 --> 00:14:45.519
And so if you're if you're either the CSO that has both uh remet for uh both cyber and operational, or you're not, you know, it's compartmentalized and it's separated.
00:14:45.519 --> 00:14:55.519
The important thing is that your board in ELT doesn't always need to know all those details, they need to understand your security risk and what that looks like.
00:14:55.519 --> 00:14:56.080
Right.
00:14:56.080 --> 00:15:00.320
And these levers really pull uh left and right of of one another.
00:15:00.320 --> 00:15:16.080
We know behind the uh the cyber or or you know, folks that are wanting to attack, you know, engineering systems or SCADA systems or other OT systems or whatever they might be, there's a person with intent behind all of that, right?
00:15:16.080 --> 00:15:20.799
Yeah, and so they could be doing things operationally or they could be doing through through the systems.
00:15:20.799 --> 00:15:29.519
It's still the same people with the same intent of disrupting your business, stealing your money, yeah, causing you harm around reputation.
00:15:29.519 --> 00:15:47.919
And it's really important to have that conversation in a broad sense, but also organizations, big or small, have to spend time in really determining the risk tolerances and the resources that they need to manage this challenge globally, macrally, and in an interconnected state.
00:15:47.919 --> 00:15:49.679
Hope that helps out, Doug.
00:15:50.000 --> 00:15:50.799
No, absolutely.
00:15:50.799 --> 00:15:52.879
I think you summarized it great.
00:15:52.879 --> 00:15:57.519
You can't separate them when you get to the the top of the boardroom table.
00:15:57.519 --> 00:15:57.919
Yeah.
00:15:57.919 --> 00:16:01.360
It all looks like money and disruption to them, right?
00:16:01.360 --> 00:16:02.320
It does.
00:16:02.320 --> 00:16:20.639
Now, Tim and I were talking about this just beforehand, and a lot of people probably aren't aware, but ACES, of course, has been almost like the flag bearer for ESRM.
00:16:20.639 --> 00:16:27.679
Because in the original history, I think it was Isaac, ACES, and one other group whose name escapes me started this.
00:16:27.679 --> 00:16:31.919
But ACES just kept going and everybody else kind of fell off.
00:16:31.919 --> 00:16:41.120
And it's rather ironic that now we're talking about things like resilience and understanding your business as security principles.
00:16:41.120 --> 00:16:44.960
And it's like Yeah, we've been saying that for 25 years.
00:16:44.960 --> 00:16:49.519
Why do you think it's finally catching up that people get it?
00:16:50.799 --> 00:16:53.600
You know, that's a that's a that's a great question.
00:16:53.600 --> 00:17:05.680
Um I think there are there are probably a couple of things, and there are probably many more that I won't mention here or or or just don't have the you know the time, but a couple of things.
00:17:05.680 --> 00:17:13.200
One, when you think about the visibility of threats today, uh they're much more visible to all.
00:17:13.200 --> 00:17:14.160
Right?
00:17:14.160 --> 00:17:18.799
So so all of a sudden your your customer plate has become bigger.
00:17:18.799 --> 00:17:33.839
So before it might have just been that uh executive leadership team member, but now that HR person hears that same news story, or that employee actually hears that news story, and they begin asking, what are you doing about this, right?
00:17:33.839 --> 00:17:37.440
Um, and how is the company handling it and and those types of things.
00:17:37.440 --> 00:17:42.799
So I think we where we are today in in media, uh and all kinds of media, right?
00:17:42.799 --> 00:17:52.799
Whether it's digital media, uh direct news media, all the the back channels and all the podcasts and all the other things that we have out there, right?
00:17:52.799 --> 00:17:59.839
People are the ability to kind of see um things good and bad, uh, are more visible to everyone.
00:17:59.839 --> 00:18:02.559
There's an expectation that's created.
00:18:02.559 --> 00:18:06.799
I think today going into business is hard.
00:18:06.799 --> 00:18:09.279
It is a hard thing to do.
00:18:09.279 --> 00:18:30.400
And when you look at all of the um the different nodes that affect your business, there's just so much information that you've got to be able to, you know, consume and process and build capability to do sat do that because the one CEO can't do it and the one ELT can't do it, it's got to go through through that.
00:18:30.400 --> 00:18:30.720
Right.
00:18:30.720 --> 00:18:33.839
And I think people are beginning to understand that, right?
00:18:33.839 --> 00:18:38.319
Business is hard, and there's a there's a collective approach that we we have to take.
00:18:38.319 --> 00:18:47.599
I think also a place like the US and others, there's a regulatory environment in um regulated businesses, right?
00:18:47.599 --> 00:18:59.759
You know, if you're a publicly traded company, there are certain requirements and things that you have to to do, report on your your cyber deficiencies or threats, or you know, whatever it might be, more regulation being driven.
00:18:59.759 --> 00:19:02.400
I think about California, workplace violence now.
00:19:02.400 --> 00:19:04.480
It's not enough to say you're doing something.
00:19:04.480 --> 00:19:06.880
You have to have a plan, you have to train people.
00:19:06.880 --> 00:19:11.920
That plan has to be available to your employees for them to see and all of these things, right?
00:19:11.920 --> 00:19:12.319
Yeah.
00:19:12.319 --> 00:19:22.160
So our ability now to then also educate our business that that's a need, and them seeing that, that that's making things a little easier.
00:19:22.160 --> 00:19:25.839
But part of that regulatory piece is it's required.
00:19:25.839 --> 00:19:38.559
And many board members, when they go through their corporate director training, they're hearing about the cyber threats, they're hearing about the executive protection things, and these are things that they are being trained to ask for.
00:19:38.559 --> 00:19:43.519
Um, so you as a security practitioner, um, you need to know that.
00:19:43.519 --> 00:19:43.920
Yeah.
00:19:43.920 --> 00:19:47.839
And you need to know the tools available to you, like ESRM.
00:19:47.839 --> 00:19:56.000
And really, how does ESRM even connect into global corporations enterprise risk management programs, right?
00:19:56.000 --> 00:19:58.799
So taking because a lot of ESRM, that's what it was.
00:19:58.799 --> 00:20:03.839
Yeah, it was taking that security lens but connecting it to HR and to business and whatever.
00:20:03.839 --> 00:20:04.640
Agreed.
00:20:04.640 --> 00:20:14.400
Now you have more organizations that have a real enterprise risk management leader or C-suite person or person responsible.
00:20:14.400 --> 00:20:21.279
So I think even organizations have gotten better around this, have institutionalized things around this, and I think we've evolved, right?
00:20:21.279 --> 00:20:24.880
And I think the last thing, these things are the right things to do.
00:20:24.880 --> 00:20:34.079
Ultimately, our job is to make sure that our people are safe and secure, and that our businesses have, you know, great environments to be able to execute on them.
00:20:34.079 --> 00:20:37.759
And if you want to be in this profession, it's the right thing to do, right?
00:20:37.759 --> 00:20:46.559
So you may get some pushback, but it really is you kind of going back to the relationship, and and I'll use another word, influencing.
00:20:46.559 --> 00:20:54.000
It's your job as a leader and as a as a security organization to spend some time influencing, right?
00:20:54.000 --> 00:20:56.799
And I don't mean that in just to get what you want.
00:20:56.799 --> 00:21:08.160
No, influencing, educating, building relationships, bringing building that trusted environment that people can come to you in times of stability and in times of instability.
00:21:08.160 --> 00:21:11.359
You know, it's one thing we I shared today with with folks.
00:21:11.359 --> 00:21:15.359
When you can deliver what you're delivering in times of stability, that's good.
00:21:15.359 --> 00:21:17.359
That's expectation from the client.
00:21:17.359 --> 00:21:22.400
But when you can deliver in times of instability, that's a differentiator.
00:21:22.400 --> 00:21:22.799
Yeah.
00:21:22.799 --> 00:21:29.599
Both to your people that are working for you and the clients and constituents in which you serve and the communities that you're involved with.
00:21:29.599 --> 00:21:32.720
So hopefully that helps bring some color to that.
00:21:33.119 --> 00:21:46.079
I think highlighting bringing that capability in a time of instability, you know, they call it resilience now, but you buy this product because you know no matter what it's going to be there.
00:21:46.079 --> 00:21:50.079
I don't think there's a business out there that doesn't have at least one competitor.
00:21:50.079 --> 00:21:53.759
So yeah, differentiators are important too.
00:21:53.759 --> 00:21:54.480
Absolutely.
00:21:54.480 --> 00:21:55.279
No kidding.
00:21:55.440 --> 00:21:56.720
And and I really appreciate that.
00:21:56.720 --> 00:22:07.920
This whole idea of linking it, and this was you know, going Back, sadly, I've watched ESRM mature from way back almost 20 years ago or a little piece of paper?
00:22:07.920 --> 00:22:09.359
Yeah, on a piece of paper.
00:22:09.359 --> 00:22:10.240
Yeah, yeah.
00:22:10.240 --> 00:22:13.440
This is why you don't get security professionals in a bar late at night.
00:22:13.440 --> 00:22:15.519
That's just a bad idea all around.
00:22:15.519 --> 00:22:27.119
Um, one of the things that we caught early on, and you know, Doug and I lived this in one of the organizations we worked in, was you mentioned linking the ESRM program up into the corporate ERM program.
00:22:27.119 --> 00:22:30.559
And we had that, we structured that in one of the places that we worked at.
00:22:30.559 --> 00:22:36.319
And it was fascinating to watch how the work that we were doing fed up into the larger program.
00:22:36.319 --> 00:22:49.440
And when you go to look at what the ERM program is doing, and they're able to show the difference in the cost of the American the Canadian dollar by the penny and how that impacts the organization we were working at.
00:22:49.440 --> 00:22:58.559
Because we we traded in a commodity that was both on the Canadian and you know, had sold at a Canadian price, but also listed worldwide on American cost per barrel.
00:22:58.559 --> 00:23:00.079
That was probably a giveaway.
00:23:00.079 --> 00:23:08.720
Um it showed exactly every time there was a change in the currency between the American and the Canadian dollar, what the risk was to our company.
00:23:08.720 --> 00:23:17.279
And how we were able to show with our security program is that every time we identified a risk and reduced the risk, we were able to ensure that you were successful that day.
00:23:17.279 --> 00:23:21.519
Man, that lesson stuck with me forever, and it still does today.
00:23:21.519 --> 00:23:37.519
It's one of those, you know, it's one of the areas that I keep going back to and I'm when I'm talking to some of our clients and even mentoring some new leaders, is that you need to find friends, you need to be able to, you know, to your point, Joe, you need to be able to influence the decisions based on a business set of data, not a technical set of data.
00:23:37.519 --> 00:23:43.200
Like no executive wants to see a firewall report of how many, you know, incidences you blocked.
00:23:43.200 --> 00:23:44.160
They couldn't give a shit.
00:23:44.160 --> 00:23:45.440
That's not their job, right?
00:23:45.440 --> 00:24:03.519
But when you can tell them that today or this past week or this past month, even though we opened up an office in Spain or in China or somewhere else in Southeast Asia, we were able to ensure that our intellectual property maintained and stayed within the organization and we were able to deliver a product and we were able to meet our delivery requirements across that region.
00:24:03.519 --> 00:24:06.319
That to talk to it in that language, yeah.
00:24:06.319 --> 00:24:08.319
That's such a huge differentiator.
00:24:08.319 --> 00:24:17.759
And for people to find the right path to speak to executives on risk, I wanted to ask, how did you change your approach to talking to executives about risk?
00:24:17.759 --> 00:24:27.519
Like from when you were early in your career to where you are today, because right now you have, if memory serves, you have a really big team and you've got a lot of folks that now report up into you.
00:24:27.519 --> 00:24:37.200
And you've got more than just security, but your presentations, your discussions, your the way that you present risk or how you're addressing risk at that level.
00:24:37.200 --> 00:24:43.200
How did your message change or how did you approach it differently from when you first started your career to where you are today?
00:24:43.920 --> 00:24:52.079
Yeah, look, I think, you know, early on I was really focused on, you know, the threat, you know, down at the coal face level, right?
00:24:52.079 --> 00:24:54.319
You know, what was happening right there.
00:24:54.319 --> 00:25:00.880
You know, I didn't I didn't have the well, it wasn't that I had didn't have the I didn't focus on the ability, you know.
00:25:00.880 --> 00:25:04.559
Sometimes uh, you know, to look up and to look out, right?
00:25:04.559 --> 00:25:06.559
I was trying to solve that problem right there.
00:25:06.559 --> 00:25:14.880
And I thought also, hey, you can become more successful, you know, the more you get things right, and you go on to the next one, and you know, that's the way things were done.
00:25:14.880 --> 00:25:16.640
It was a it was a churn, right?
00:25:16.640 --> 00:25:22.000
Certainly as you go up an organization, things kind of go like this, right?
00:25:22.000 --> 00:25:34.000
So you know what you're what the span of control is, um, what your you know influencing, what the portfolio, you know, looks like first it was very technical.
00:25:34.000 --> 00:25:38.720
Then as I got into the business piece, it was beginning to understand the business language.
00:25:38.720 --> 00:25:55.279
So a lot of my time early on was really understanding their thoughts about risk from their you know uh lens, and me trying to translate that to one my security knowledge, but also my new knowledge of business and how that might affect them.
00:25:55.279 --> 00:26:02.319
Now it's gotten to a point where one, I understand their business now, and I understand the security piece.
00:26:02.319 --> 00:26:12.400
So when they're talking to me about what risk might be to them, they only see it from their lens, not just that pure one-on-one, you know, business.
00:26:12.400 --> 00:26:14.559
They don't see it from my lens, right?
00:26:14.559 --> 00:26:14.880
Right.
00:26:14.880 --> 00:26:18.880
So that ability to then broaden and shaping shape that out.
00:26:18.880 --> 00:26:27.200
So a lot of it has become teaching in a positive way, helping them broaden their aperture, right?
00:26:27.200 --> 00:26:33.599
So they see rix risk here, but they really need to be seeing it here, right?
00:26:33.599 --> 00:26:35.920
And that's what's what's changed.
00:26:35.920 --> 00:26:45.200
I think the other thing that has changed for me, um, certainly down you know, early on, it was very technical, long explanation.
00:26:45.200 --> 00:26:54.880
Now it's broader, it's certainly what's the impact and or potential impact to business, and it's crisper in its delivery.
00:26:54.880 --> 00:27:01.200
So, even from a crisis perspective, I'm not gonna go narrate what that whole scenario is, right?
00:27:01.200 --> 00:27:03.920
But there are gonna be four things I'm gonna tell them.
00:27:03.920 --> 00:27:05.920
How is this affecting your people?
00:27:05.920 --> 00:27:09.839
How is this affecting your environment in which you're operating?
00:27:09.839 --> 00:27:13.359
How is it affecting your your assets in any way?
00:27:13.359 --> 00:27:15.519
And how is it affecting your reputation?
00:27:15.519 --> 00:27:17.599
We call it a paraprocess, right?
00:27:17.599 --> 00:27:24.400
We'll we'll we'll go through that, and that might be slightly you know changed depending on, but that's gonna be consistent to them.
00:27:24.400 --> 00:27:30.799
The other thing is that they're in crisis or high events, they know that's how they're it's coming to them.
00:27:30.799 --> 00:27:31.200
Right.
00:27:31.200 --> 00:27:42.400
So we've educated them around what to expect in the content, and if they don't see that this risk that we're dealing with, you're not telling me how it's affecting my people, they're gonna ask that question.
00:27:42.400 --> 00:27:42.880
Oh, okay.
00:27:42.880 --> 00:27:48.960
Or you're not you're near you're not you're not informing me as to what are the reputational considerations.
00:27:48.960 --> 00:27:50.640
And not just from my lens, right?
00:27:50.640 --> 00:27:55.839
I'm talking to you know to other leaders on the ground that they're thinking about their reputation.
00:27:55.839 --> 00:27:59.359
So there's some structure, there's some crispness, you know, to it.
00:27:59.359 --> 00:28:05.920
And the other thing I would I would say, Tim, is uh every constituent is slightly different.
00:28:05.920 --> 00:28:06.319
Yeah.
00:28:06.319 --> 00:28:10.319
The CEO constituency versus the chief operating officer.
00:28:10.319 --> 00:28:12.079
They have different constituents.
00:28:12.079 --> 00:28:12.319
Yeah.
00:28:12.319 --> 00:28:26.240
I mean, ultimately, yes, we're all serving our our employees, our people, and our shareholders, but you know, a CEO is the board is their direct constituent, you know, as you as you know, uh Tim, and leading the board, right?
00:28:26.240 --> 00:28:28.799
And and they need to, you know, to know certain things.
00:28:28.799 --> 00:28:36.559
Whereas the chief operating officer, one of his constituents is the CEO, another one is the operations team, right?
00:28:36.559 --> 00:28:50.319
So that's the other thing around risk, is that not only how do I present the scenario, but what are the things that they might need to be thinking about for in addressing their constituents, right?
00:28:50.319 --> 00:28:52.480
So helping them around that.
00:28:52.480 --> 00:29:00.400
So in addition to the to the risk conversation, it's also guiding them into the things that how are they gonna answer this, right?
00:29:00.400 --> 00:29:07.440
And how do I help it help them, how do I enable them answering that clearer and faster?
00:29:07.440 --> 00:29:10.559
Yeah, that's how those conversations have changed.
00:29:17.599 --> 00:29:20.079
I'm gonna sneak in one last question before we let you go, Joe.
00:29:20.079 --> 00:29:31.119
It's if if you're gonna if you were gonna give advice to somebody who wants to come into the profession of security, what would you give to somebody new coming in or who wants to look at a career in security?
00:29:31.119 --> 00:29:36.000
I would I would say say yes.
00:29:36.960 --> 00:29:53.200
And and and what I and and what I mean by that is not just say yes to security, but to your point earlier, Tim, say yes to investigations, say yes to cyber, say yes to physical security, you know, say yes, right?
00:29:53.200 --> 00:29:59.519
Early on in my career, you know, when people started asking me to, you know, support safety, I said no.
00:29:59.519 --> 00:30:14.000
But then when you step back and you look at the interdependencies of safety and security into emergency and crisis management and continuity, into incident response, into how you manage the health and well-being of people, right?
00:30:14.000 --> 00:30:26.079
If we think about our jobs and security and how stressful that is, but if I can take our positive mental health and well-being aspects and and and integrate them into our security processes, how much better would that be?
00:30:26.079 --> 00:30:26.559
Yeah.
00:30:26.559 --> 00:30:30.319
So my my answer is say yes, right?
00:30:30.319 --> 00:30:43.119
Say yes to the industry, say yes to the opportunities that are presented in front of you, you know, be curious and don't think about am I a practitioner, a supervisor, a manager, executive?
00:30:43.119 --> 00:30:45.519
Go take the journey.
00:30:45.519 --> 00:30:48.160
The journey will lead you to the right place.
00:30:48.160 --> 00:30:56.000
If you're true to yourself, understand your individual purpose, my individual purpose and my business purpose lines up.
00:30:56.000 --> 00:30:57.839
It's this simple.
00:30:57.839 --> 00:30:59.599
Help other people up.
00:30:59.599 --> 00:31:00.400
That's it.
00:31:00.400 --> 00:31:04.160
And that has served me well, certainly in this profession, right?
00:31:04.160 --> 00:31:06.720
Helping people up, it aligns with that.
00:31:06.720 --> 00:31:14.480
But I think that if we stay core to our your values, say yes, be curious, experience the journey, right?
00:31:14.480 --> 00:31:15.599
That's what I'd say too.
00:31:15.839 --> 00:31:17.279
That's the perfect way to end it, Joe.
00:31:17.279 --> 00:31:18.880
Thank you so much for being on the podcast.
00:31:18.880 --> 00:31:19.680
We really appreciate it.
00:31:19.680 --> 00:31:20.880
Thank you again.
00:31:20.880 --> 00:31:21.680
Wonderful.
00:31:21.920 --> 00:31:23.440
Thank you, Jens, for inviting me.
00:31:23.440 --> 00:31:24.480
I really appreciate that.
00:31:24.480 --> 00:31:25.599
It was great time.
00:31:25.599 --> 00:31:26.319
Thank you.
00:31:26.319 --> 00:31:27.279
Thank you.
00:31:31.519 --> 00:31:34.799
Thanks for listening to the latest podcast from Caffeinated Risk.
00:31:34.799 --> 00:31:40.160
Make sure you visit our website, caffeinatedrisk.com, to stay up to date on what we've been working on.
00:31:40.160 --> 00:31:49.279
Our website has bios of our podcast guests, posts about topics we're passionate about, and even a library reference material we find valuable in the work we do every day.
00:31:49.279 --> 00:31:53.519
And don't forget to subscribe to Caffeinated Risk on your favorite podcast service.
00:31:53.519 --> 00:31:56.799
This way you'll be notified when we release our next podcast.
00:31:56.799 --> 00:31:59.759
And you can listen to our previous guests just in case you missed it.
00:31:59.759 --> 00:32:02.160
Thanks so much for listening to Caffeinated Risk.