Richard Parry: Well, thank you very much for inviting me. I'm looking forward to the discussion.
Logan Willans: Happy to have you.
Michael Collins: Would you please start by summarizing your career journey? Now, what led you to law enforcement and then ultimately to corporate security?
Richard Parry: So I knew from a very young age that I actually wanted to go into law enforcement, probably from age 15. So I set my sights on my college studies being in criminal justice. went to Northeastern University. I was part of their five-year co-op program. So I spent one co-op semester working as a supervisor for a security company. spent two years working as an intern for the Wakefield Police Department and then got a full time appointment to the Reading Police Department in my fourth year. I became a sergeant in nineteen eighty two and worked as a night shift commander, and then I had an opportunity that presented unexpectedly to go into the private sector. And during that time law enforcement was in kind of a transitional stage and and I was getting a little bit, I think cynical, was probably the way to describe it. And I didn't like that. the thing that culminated is I had made an arrest Caught two guys in a convenience store, took them at gunpoint, over two thousand dollars worth of cigarettes and bags that they were getting to steal. They went to court the next day and the judge basically put them on probation and sent them away. and at the time, and being, relatively young and not having the same level of maturity that I do now, bothered me enough that I felt like I needed to do something different. so I had the the newspaper, saw this ad for position up a task as a security manager, went, interviewed with the with people there. They made me an offer So I went in and I spent probably about twelve years doing DOD and intelligence agency type work for task and for Raytheon. I was recruited to become the first head of security for Iron Mountain. and I built their corporate security program their safety program. Also started their information security program, in conjunction with their CIO at the time. did that for about eight or nine years and got recruited by Novartis Institutes for Biomedical Research. And in that function, I had not only the physical security and the information security, but I also managed scientific data quality. And it was basically intellectual property protection, the ability to record scientific discovery for patent prosecution and defense. And then they threw me in charge of archiving and records management because I had Iron Mountain in my past. And gave me that as well. that position, unfortunately, due to some restructuring, got eliminated. So I had the opportunity at that point to start my own company, something that I always thought about doing. So I started Secure Solutions Consulting. I became a licensed private investigator for Massachusetts and was actually doing quite well. I had started focusing on schools, and basically private schools because I felt they were underserved and did some work for there. But I also got connected with Mimecast, I was actually working that and had just signed that contract when I got a call from Hologic they liked me enough to hire me. So for the first year of my employment with Hologic, I was actually doing two full time jobs. It was a lot of fun. But Hologic was my final job, probably the one of the best corporate jobs I've ever had. and happy to have retired from there with what I built.
Michael Collins: That is amazing. I'm excited. There's a lot to dig into. one of the things that stood out looking at your CV is the technical organizations. every organization you've been a part of is IP rich, you know, sophisticated life science companies or defense contracting and technology. what kind of impact does that have on a corporate security professional's role?
Richard Parry: Well, I think what I looked for was a company that had purpose. and so I would never have become the chief security officer for a company like Philip Morris, for example. And nothing to disparage Philip Morris. But there isn't a higher purpose in what they do. And everything that I do, I need to have some level of figuring that I'm contributing somewhere to the betterment of something. What it means from the corporate security function, is that you quickly understand that there's much more to the physical security function and the way that that has to meld with other business functions in order to be successful. And building relationships becomes key and understanding and becoming conversant in technology is key. So I became a certified information security manager while I was at Iron Mountain because we wanted to start an information security program. And I'm not the dial and button guy, right? I need support in in the technical lens of things. I know enough to be dangerous. I know enough to be conversant. and to talk reasonably about stuff. But being able to manage the function and being able to talk to folks in a way that allows you to communicate your expectations, your needs, and then to have the understanding of what they're trying to accomplish is critical when you're in a tech rich environment.
Michael Collins: wanna ask you, about the transition from public service to the private sector. You talked a little bit about that and some frustrations that you had at the time. what was that like? Was that a difficult transition? did you
Richard Parry: So yes it was. I was a pretty big fish in a relatively small pond when I was in law enforcement, right? I was a sergeant on a department that had about 45 people. everybody, around town would know me. I had a lot of authority. and then when I went into corporate security, I was a small fish in a in a bigger pond. it took me a while and some counseling, I'll put it that way, to lose some of the swagger. and to realize that I needed to change my mindset a bit. I've never lost the law enforcement side of what I did. I've stayed involved as there's still elements of that that served me well. but it was a change and it was a financial change. I made money on overtime and now I was on a fixed salary. So I took a pretty big risk by doing this. but what I really had to understand was that I needed to move from being what probably was more of a teller to being somebody who was more of a collaborative partner. and it wasn't always easy.
Logan Willans: You got your certified information security manager certificate, so you learned to speak the language of IT. Did you feel like your counterparts, like your CISOs, learned to speak the language of physical security? and honestly.
Richard Parry: honestly, I think that it tends to be more one sided. I think that there is still an assumption that anybody can do security, right? And what gets lost in that, are some of the nuances and some of the things that make a mature security organization mature. So I would say that it was more incumbent upon me to be able to speak their language and understand, then to be able to educate them where I saw potential gaps in their understanding. so while my relationships were always positive, they were always cooperative, they were always mutually beneficial, it was more incumbent upon me to understand the language of technology than for the technicians to understand the language of a of a physical security program.
Michael Collins: Dick, is law enforcement or military backgrounds important for corporate security?
Richard Parry: it certainly can be helpful, but it's different this is the other thing that I learned when I transitioned from the DOD and Intel community into more of the private sector. A corporate security function cannot be a rules-based function unless you are mandated by something like the NISPOM or some other regulation. And even in that regard, you still have to develop the other side of security, which is the business side. so I think it is can be very helpful. I think it can give you some solid understanding, but it isn't the be all and end all. And one of my personal frustrations over the course of my career was the value that gets placed on people who have spent careers in Law enforcement, federal law enforcement, and get moved to the highest levels of a corporate security function without being able to demonstrate a solid business background. you can have a discipline. Right, your discipline can be technical security, information security, physical security, it can be executive protection. But if you don't understand business, you're not gonna be as effective as you could be.
Michael Collins: What do you feel are other misconceptions that others in a corporate environment have about the function?
Richard Parry: I think that there's still, unfortunately, that we're the badge and gun guys. But the reason that I think holds up as the thing that people think about first is when you take a look at a lot of corporate security functions, the first person someone encounters when they enter a business is a security officer or a security receptionist. It's the person who's there to validate that you're supposed to be at the business. They are potentially the most visible folks. And they are important. But again, what needs to happen for corporate security leaders to be successful is for them to start to build the relationships elsewhere in the organization so that they understand the business, Ultimately, what a corporate security function should be doing is enabling a company to take risks. No company succeeds unless they can take risks. And any company that's standing still is going backwards by definition. The CEO of Iron Mountain used that quote once, and I've never forgotten it. So our job has to be to educate folks about taking risks, allowing them to take risks in an educated manner. if you are a corporate security function that has a tendency to say no as the first thing out of your mouth. Then you're probably not going to be as successful as if you say, tell me more, or tell me why, or how can I help, or what do you want to get to? And being able to say, I'm not sure if this is the best way to get there, but let's talk about other alternatives, makes you part of that business discussion. And when you can talk like that, and when you can be the person that isn't selling FUD, but is instead telling people, look, if you make more money, I make more money. Let's go figure out how to do this. you've added incredible value to your team and to yourself as a business asset.
Michael Collins: That balance has come up in these conversations a few times, how do you possibly strike that balance you're judged on the security and safety side?
Richard Parry: Well, so it's corporate security's art and science. There's people who have technical understanding, it's great and you need them and it's critical. People who have good emotional intelligence, people who can understand broader impact, I have a mantra that says more security is not better security. And at the end of the day, it may not even be close to what a company needs or even wants, because every company culture is going to dictate the level of risk that they are willing to assume. And some are higher risk tolerance, some are lower risk tolerance. while as an organization you're kind of measured in the negative, right? When nothing happens, you must be doing well. it becomes hard because if nothing happens, then why do you need the money that we gave you in the budget? when I first went to Ho Logic, there was a situation where our CEO had been threatened, the board of directors had prohibited him from traveling. we had the threat contained and that was good. But I got asked the question as we were going through this, what's the right budget for executive protection? And I said, I don't know. They said, Well, what do you mean? I said, I don't know what he's gonna do. I said, if I tell you that I need six million dollars to protect our CEO, and in that year he doesn't die, was that the right number? I mean, again, it's about what is he doing, where is he going, what's he want, what's he comfortable with, and then you build those things as you go along. So, Cost related to security, while you always measure it by the fact that nothing has happened, you have to be able to articulate risk and the continuum of risk that may be faced. So it's a lot like an if-then question. So if this happens, then this is a likely result. And here's the things you can do to mitigate it. So it's constant discussion. If you're not continually evaluating what is happening in your environment and the external environment that influences you, things around the world potentially, if you're a global company, then you're not doing your company the service you need to do. On the other side of that is the things that you can do, which is cost avoidance. So the cost avoidance things are like building the brand and counterfeit protection. When I was at Whole Logic and started looking at what they were doing, and I put together a presentation because there was $3.5 billion worth of product between eBay, Alibaba, all of the sites you can think of where we had Whole Logic products that were being offered for sale, not by us. And when it was shown to our CEO, he said, don't ever bring me a PowerPoint that has this kind of a decimal point mistake. I said, what do mean? He said, it's probably three hundred and fifty million, right? I said, No, it's three point five billion. And I showed him the spreadsheet. And it was eye opening, right? Now, not all of that stuff is important. So, we had to filter out the things that were actually critical to the success of the business, and what would protect our brand and what things were potentially counterfeit as opposed to, used things being sold, et cetera, but The idea is that through that we were able to demonstrate actual cost avoidance. So we stopped one point two million dollars of sales to a company that had never bought a product from us, but they were buying parts so they could service our equipment. We took that counterfeit off a market because they were good, but we were able to reduce that. So this cost avoidance is reputation protection. like an insurance policy, right? You buy an insurance policy hoping nothing ever's gonna happen, but if it happens, you're there. That's kind of a corporate security analogy. We're the insurance policy in some aspects, but we can also be the cost avoidance team. And other aspects.
Logan Willans: it sounds like a security leader's role is to enable strategic risk, but who owns that risk when things go wrong?
Richard Parry: ultimately if it's your recommendation, you've built that recommendation based on the consensus of others. So there's not a single point of, an individual who says who becomes blamed, when things go wrong. if you have failed to provide the information, you know, reasonable way or in a factual way, or if you've not done your due diligence in the presenting your side of the case, then yeah, you need to bear responsibility for that. And integrity and honesty is one of the biggest parts of this function, being successful and standing up when you've made a mistake or you haven't done things that you should have done and owning up to that, regardless of the consequences, is critical. But I think that A corporate security function isn't the corporate security department making decisions. It's a corporate security department providing intelligence, more than information. There's way too much information in the world. distilling that into intelligence is an art. And then being able to present that to an organization, and as I said before, the continuum of risk, that here's what we're seeing. If this happens then you can predict this, that sort of thing. I spent lots of time talking to our international colleagues, I had people calling me to tell me what was going on When you work in an organization and we had what, 7,500 people and probably Three thousand of those were internationally based and out on the field. That's three thousand sets of eyes and ears that can give me information.
Michael Collins: That's great. what are the departments and roles that you're communicating with regularly when you were in that role?
Richard Parry: so in any environment, you know, it's the HR team, it's the legal team, it's the facilities team, it's the IT team. And those are the folks that, you got to start to build relationships with in order to understand the impacts of things that you want to do, programs, strategies, in the next layer is the business impact. So these become your business leaders, whether they are, sales leaders, division presidents, the folks who are, helping create product quality teams, those sorts of folks to understand where their challenges are, where they're trying to get to, what's the next product introduction look like if you're in that kind of an environment? what's the next big event that's going to be happening for the company? You know, we manage security for events and meetings as part of this function too. and you can't sit at your desk and you can't read the intelligence reports and you can't, take a look at badge swipes and cameras and expect to, address business needs. Those tools are critical and essential. But again, it doesn't build to the broader strategy of what the business is trying to accomplish it's gotta be incorporated for other things. So building relationships as high as you can in the organization. I was grateful that I reported one level below the CEO in this organization, but I had relationships with all of the division presidents, with general counsel, with the COO, with the CFO, and the head of quality, all of those folks are people that I had personal professional relationships with and could talk to at any time about anything that I wanted to know or things that I wanted to let them know about.
Logan Willans: when you mentioned
Richard Parry: Yes.
Logan Willans: CFO, in the context of asking for money, if you're brought on as the CSO of a mid sized corporation and they asked you to cut the security budget, where would you look first?
Richard Parry: well the first thing I'd have to do is to go and understand where money was being spent. So I would ask for a breakdown of the budget. I would take a look at what functions the corporate security department was being asked to support. I would then try to analyze where we might be inefficient. Because sometimes cost savings can be not just cutting budget, but creating efficiencies through things. So I can't say there would be one thing. it's not a secret that the most significant cost for any security budget is typically the security officer's positions, right? It's manpower, it's hours, it's overtime. But there may be other places where you would find, spend that wasn't commensurate with the return. so being able to analyze ROI is pretty important as a corporate security professional, as a business professional. It's a critical skill.
Logan Willans: is there any kind of like directionally areas you'd suspect? Have you ever seen places that were like too excessively staffed, or like an executive protection program that was not kind of compatible with reality that didn't like actual threat level?
Richard Parry: What I think I've seen more of is organizations that have stuck with a particular program or a particular vendor for years without actually evaluating whether or not that's the right vendor and they're giving you the best bang for the buck. It's very hard to change security staffing vendors, you know, security guards. it's one of the hardest things a corporate security function does, in my opinion. particularly if it's been a long term relationship. you have a lot of folks who are in the facility that people know, and some of the best relationships that are developed are between the security officers and the staff. but I think is probably one of the biggest misses for a lot of functions is not evaluating long-term vendors to see if they're still viable and competitive. ideally if you're gonna change a security vendor, you're able to retain the people you want to retain and that's happened in the past for me, but it is exactly that. It takes a lot of time to bring folks on and to manage well because they are so integral to the smooth daily day-to-day operations of the business. now getting down to the very tactical level outside of a strategic viewpoint. The tactical execution of getting people in and making sure that, places and and things that need to be checked on rounds are done and people understand who's who. here's the things you never talk about, or here's the people who require the most hand holding, And so it's tends to be a transient employee population, just because, oftentimes we always tried to pay more than the average because we wanted to retain people. We found ways to reward people through on the spot bonuses, gift cards we used to do year end bonuses for certain folks, based upon their performance. so once you build that strong team, you want to keep that team intact. the only reason that would get into changing security functions is when the management group let me down. and fortunately I had to do it a couple of times. None of which were pleasant. But a lot of things that you probably as a corporate security executive or a leader, you probably don't know about what happens at that ground level.
Michael Collins: Important are external relationships, particularly peer relationships. You had a leadership role in ACES. are there organizations and peers and other companies that you were able to collaborate and sort of soundboard with?
Richard Parry: Yeah, it's it's I think it's critical. I was a member of ISMA too, which is the International Security Management Organization. I was a member of the ASIS CSO leadership but relationships in this business are everything in my mind. we had even a small group when I was at Whole Logic that banded together with area medical device companies that we could talk about things that were happening and share some experiences. and I think that it's always good to have somebody to bounce ideas off of. And it's always good to solicit other opinions. And it's important to me to always remain teachable and to always remain open. And I'm fully aligned with being responsible for if I make a decision, I'll own that decision. But I want input from everybody, even the people below me, about some of these things that are going on. everybody who's ever worked for me, I've told them I don't want yes people. I will never hire a yes man. If you cannot give me your own independent opinion, I don't want you working for me because yes people will lie to you by default. They just will. So I want to hear the background. I may not Take the advice, or I may, but I want to hear it because what you have to say is important. So the relationships from a professional standpoint between peers, law enforcement, wherever you can build these things, are critical. Relationships outside the profession, I think, are even, I want to say more important, but are equally important because
Michael Collins: Hmm.
Richard Parry: they provide you perspective that sometimes security people don't have. I've traveled so much in my career. And I can tell you that if I don't know somebody in a country, I can call somebody who knows somebody there. it's that kind of a thing that gets you to a place where, it's allows me to go in and to create. valid factual current information on a particular situation based on somebody who's actually living that life right now. And we actually, had an experience with that in twenty twenty five with the twelve day war that was just essential to the success of that mission.
Michael Collins: Are you able to talk about that, Dick? We'd love to hear more.
Richard Parry: Sure. Yeah, so in June twenty twenty five, Israel bombed Tehran. They were starting to target the the nuclear sites. we had an employee unbeknownst to me at the time in Tehran, and we had an export license to do business with certain medical devices. And this is an individual who was a Lebanese citizen but residing in, I believe, the UAE, but was on business in Tehran. And she was in a hotel near where the bombings were occurring. We had developed a relationship with the international sales team and prior to this for a couple of different things, which was critical to this success of this mission. So her manager called me early one morning to tell me, she's in this hotel, the bomb's going on, what do we do? we reached out to our international security provider and This is a little bit of a shame on me, but came to find out that they were not able to support us in Iran in any way. had no resources, had no capability. basically they said, shelter in place until we know more. I'd been through a whole bunch of this stuff. You know, I've had enough life experience to understand that sometimes shelter in place, while it sounds good, isn't necessarily the best advice. this woman was very nervous, but I will say she was composed, she was smart, she was a world traveler. we had a lot of conference calls with her with her boss, with other folks. military came to the hotel, told them to stay near the hotel. We provided all the advice about staying away from windows, getting to stairwells, all of the places you heard bombing, that sort of thing. But what we realized is that we had to figure a way to get her out. I have a colleague that worked for me who has significant experience at the State Department and with the Marine Corps, and he has been in the Middle East and he knows that area. so we decided we needed to find a way for an extract the first thing we wanted to do was to get her out of Tehran, right out where the mediate bombing was. So We knew that the bombings were occurring largely at night. So the next morning we were able to use the commercial team to get to the customer team. And we were able to use them to get her to a safe house about thirty kilometers north of Tehran. and it was part of the community. She had built the relationships with the vendor herself, so they knew each other, And we just took advantage of that and the fact that they knew the ground, they knew what was going on. We kinda knew from our own intel when bombings would be happening, So the next day we got her to that safe house, which was great. The next thing we needed to get her out of the country because we knew that they had started going and interviewing folks and rounding up individuals who were not Iranian citizens She wasn't a highest profile risk, but she wasn't necessarily in a safe environment. They happened to have a family that was visiting, and they were trying to get back to Turkey as well. So we established a ground route. We loaded them up with supplies and we sent them over to Van Province, Kirikuk, But we were able to get them there. We wanted to get them past the sites where a lot of the bombing was gonna occur. We'd identified all the nuclear sites, the military sites, the route that was going to be taken. We provided them with Expectations, for example, you may see because you're going to be passing at this time, there is a military site that's, five kilometers west of where you're going to be traveling, you could potentially see explosions of that sort of thing. So between What we could provide from an intelligence perspective, what we could provide because relationships had been built with our commercial team, the commercial team had been relationships with the customer. Ultimately they got to that border the next morning. They crossed the border, they got in the van, she got to a hotel. took a couple of days, but we're able to fly her back to her residence back in the UAE. So it took our travel department, it took our commercial department, my security team. all of those folks to be able to pull that together. And so the point being is that A, make sure you understand what your vendors can actually provide for you. The second thing is that the work that we had put into building those relationships, establishing the credibility with our teams, they would listen to us, they knew what we, had to offer, that they were in a position to also assist because of the relationships they had built, resulted in a very successful security mission. And I'm so proud of that, not because of anything I particularly did, but because we were able to function as a cohesive group to address a problem that didn't have an answer right away. I'm very pleased with the way we were able to pull our resources together. And I'm obviously very happy for the outcome that she was, home safe and she was very grateful for that. So it was a great experience, a learning experience as well.
Michael Collins: Hmm.
Richard Parry: but also one that bore out the things that I have always believed about relationship building. And not necessarily having to be the person with all the answers, but being somebody who can help facilitate an appropriate response to solve a problem.
Michael Collins: Yeah, incredible story, an important lesson. you talked about owning responsibility and just thinking about the stress that security leaders hold and that burden of responsibility. How is that managed by you and your peers? how do you handle stress?
Richard Parry: From the stress side, you gotta have a sense of humor, and you gotta have a thick skin. you can't take things personally, first of all. I learned this from the law enforcement piece, you have to be able to separate what you do from who you are. and I remember giving that advice to One of my kids who was in the military who was actually in boot camp when nine eleven happened and wound up going to Baumgartner, Germany, and then 18 months in Iraq as a cavalry scout, and reminding him that, what you do is not who you are. And the stress of these things in terms of internalizing this, there's a stress that causes performance, and then there's a stress that causes personal anxiety. So the stress that helps you perform well is great. And those are the things you want to have. Where you start to feel stressful about what's happening, you have to have again the relationships with other people to talk to them Cause I will bet I don't want to bet my retirement. That's too important. I'll bet you a cup of coffee. there's nothing unique in what's happening to folks. I'm not the first person that did an extraction. out of a country with a hostile environment that didn't have the resources readily available. There's always things that other people have gone through. You just need to reach out and and talk to other people to be able to understand again perspective and context in these things. And one of my favorite expressions too is that nothing lasts forever. So while you may be thinking of something at the time you may feel stressed, it doesn't last forever. Don't, believe that it will and it won't. Will impacts From things happen and last for a while, yeah. And hopefully that those are not long-term negative impacts. unfortunately for some people they are, because there are people who have gone through horrific situations, right? Very stressful situations and seen things that they cannot ever unsee. I'm in that same category. But again, if the best you can do is to recognize you're not superhuman. No corporate security guy has a big red S under their shirt. and just recognize that you're human. You've got feelings, you've got emotions, it's okay. If you're upset, it's okay. You gotta cry, it's okay. You gotta scream at something. Don't make it your wife, but you know, find an inanimate object. but yeah, you need to be able to recognize that you're going to have reactions and you're going to have emotions, and it's all okay. if you're an emotionless robot, You're not the right guy for a corporate security function because at the end of the day this is all about people.
Logan Willans: I think that was great advice on managing stress. And we all can take a note out of that, even if you're not in security, just separating yourself from what you do.
Richard Parry: It
Logan Willans: I do have a question in practical mission, like keeping people safe. It seems like a lot of security might be caught in a compliance trap, like ticking boxes to satisfy auditors. rather than focusing
Richard Parry: huh. Yeah.
Logan Willans: on like the nuts and bolts of security. Would you agree with that? And if you agree, how do you keep
Richard Parry: I I
Logan Willans: security grounded?
Richard Parry: Yeah. So I think it depends. on the industry you're operating in. So clearly in a regulated industry, you're going to have to check boxes. whether it's, the FDA or the DOD or an intelligence community. There are boxes that'll have to be checked. But what I found, especially in the DOD experience, and this was, a pretty valuable lesson, and that even though the regulation says something, the way you meet that regulation can be creative and can be focused on how you, best serve the needs of the business. I think that Outside of that, keeping security grounded about its basic mission is keeping people safe, a lot of that is the tone at the top from your leadership, right? If they value employee safety more than anything else, it's a good way to keep those your programs grounded in basic effective blocking and tackling security programs. one of the things that sometimes gets missed in this is the basic blocking and tackling of security. we overlook that, I think sometimes. And 'cause it's very easy to get caught up in the whiz bang technology. I think it's a great tool. I think it can be used, but we can become over reliant on technology, we lose the human touch. if you disengage from the relationship piece of security to focus on the technology piece of security, you've missed something critical to basic human nature, but also I think to the success of your program and how you're perceived as a leader.
Michael Collins: That perfect segue. how did you see security change over your career? specifically in your function or just broadly corporate security? I'm sure technology and culture and all that, but it'd be great to hear some examples.
Richard Parry: Yeah, so obviously technology always changes, right? I mean, you go from some very basic stuff. when I started as a security office, I had an old detects clock with a key that you had to turn in a piece of paper inside that made the marks and stuff. So, now we're on to all kinds of new and fancy RFID stuff, which is great and efficient and I love it. I think what changed the most for me was that A bit about the fact that corporate security was something that anybody could do. when I first started in corporate security, it used to be in a couple of cases the dumping ground for people who didn't fit anywhere else. if you couldn't make it as this, we'll put you in security. And so you'd have a ton of administrative tasks that you'd try to assign people to do. very tactical, no sense of any kind of a security strategy let alone a business strategy and I think as I've seen over the years and one of the things that's been important to me what I'll call the professionalization of the corporate security function. the fact that we have engaged with industry leadership in a new way that our professional organizations are creating meaningful certifications like the CPP or the CISM and and many others. although sometimes I think we have, certifications just for the sake of certifications, which I'm not a big fan of. But I think what has happened is that we have become and we have worked hard. And my colleagues and the people before me have worked hard to pave the way for us to become a legitimate business function, a participant in business decisions and in the growth of the business, where we can actually create value for the businesses in which we operate. And that I think is the biggest change that I've seen over my career
Michael Collins: what are things that you feel are overhyped? in the changes that have occurred within security or things that are maybe underappreciated. are there any others that stand out?
Richard Parry: So you know, I think the thing that is kind of underrated is the whole concept of access control and visitor control and management insider threat, I think is a big deal. it touches to insider threat, it touches to workplace violence, it touches to a bunch of things. we tend to be once you're an employee, you're family, right? Come on in, you know, help yourself, make yourself comfortable, that sort of thing. we need to get a little bit more of the be responsible about Hey, where's your badge? Or, you know we have a requirement to swipe when you come in through this door, those sorts of things that I think we tend to overlook. people wanna be friendly, people wanna be nice, And we have to be a we have to tile that down a little bit to become a little bit more protective, What I think is overhyped is technology. I really feel like we're in a position where there I don't want to say that there's necessarily an excessive reliance on technology, but I think that the value of technology as a corporate security solution has to be carefully weighed because at the end of the day it still comes down to people. I absolutely love technology. I think it's wonderful. But again, more security isn't better security. I think proper application and understanding your threat environment, your threat context, and helps you make those good decisions. everything that I ever did, I had to pass three tests. It had to be rational. It had to be logical and it had to be threat appropriate. And if I couldn't answer all three of those questions when I was going to deploy a program or suggest a strategy, I didn't do it. if it fails one of those, it's going to fail. it's not going to be value add.
Logan Willans: I thought that was great how you're pointing out how there's a duty to also look at the employees themselves as a degree of risk. Obviously you have a duty of care to protect them, that's one function. But also another function is to protect the business itself and that insider threat is a real thing. My impression is that the culture today might be fighting you on that. And correct me if I'm wrong, but companies these days are practically begging employees to come back to the office, What would you do as a security leader? How would you talk to the CEO about this kind of issue?
Richard Parry: it's a little bit like inviting people to your home. you're not gonna just let anybody into your home. You're gonna wanna know who they are and why they're there. Access control and visitor control is just knowing about who's there. Do you want them there? are you allowing them every place or just certain places? You're not gonna invite a guest to your house and say, Hey, go up and take a nap in my bed. certain places you just don't want folks to go or won't be for whatever reason. It's the same thing in the corporate environment and you just need to kind of make it relatable to folks. I think you're inside, you wanna bring people in, you wanna do games, you wanna do all of that. That's great. the insider threat piece. Is not only about the visitor control of visitor management, but this is where you need that close collaboration with your IT environment and with the CISOs to understand what they are looking at from the place that they control access to technology and data and areas and zones of where people can be and can't be. You invite only those people you want, it's the same thing at work. That's what trying do.
Michael Collins: what other events were memorable in your security career or maybe you know back in law enforcement? Is there anything that you reflect on even today?
Richard Parry: I think, part of what I reflect on routinely and and throughout my career is the opportunity that I've had to do good and to help people. especially in those things where there have been crisis situations, I know that I'm very effective in crisis management. I can be that logical voice of reason, kinda calm people down, get things done. I think nine eleven was a huge one. And I remember watching the events unfold, hearing about the first tower hit, watching the second tower hit. I was with Iron Mountain. but we also had a business to run after that and a large part of our business relied on air traffic and transport. And we worked with our local teams to create what we called the Pony Express, where we rented a whole bunch of trucks and we started doing ground shipments and we kept the business running and that was great. and nobody suffered, nobody was hurt in that, terrible tragedy. but it was An opportunity again to become a real business partner to bring a level of expertise, as well as a way to introduce a level of sort of calmness and realizing that this is something that can be managed. We can scale security to whatever we need to do. there may be something that is unexpected, but it doesn't catch you off guard. It doesn't keep you from doing the right thing if you're doing your job the way you need to, and this is why you need to understand your business fully so that you are prepared. To be able to be nimble and flexible and responsive when things come up.
Michael Collins: That's great. What are you up to today, Dick? the consulting work that you do.
Richard Parry: So I have one organization that I do periodic consulting with. it's called More Than Words. It's actually
Michael Collins: Mm.
Richard Parry: a youth-based organization that my oldest son worked for a time. Wonderful mission where they take kids who are potentially at risk or kids who are coming out of the juvenile justice system. They teach them business, they run a bookstore, thrift stores, they're based in Boston. when I started, they had one location at Waltham, started working for them. They now have, I think, three or four locations. so I love working with them. I love their mission. it's kind of a call me when they need me kind of thing, which is good. when I had started the company, established a couple of relationships with some attorney firms for some private investigative work, looking at some other, potential consulting opportunities. But honestly, I'm kind of enjoying retirement. So I have things that are not work related. I've had a couple of invites to apply for some full-time positions that I just have no interest in at this point in my life. I work when the time comes and I reach out to folks who I've known to see if they need some support. I've got an event management company that I've done some work for in the past. I'm not looking to build I'm more than happy to help whenever and I love what I do. and so when those opportunities come I get to pick and choose and take advantage of those things and do the stuff that keeps making me happy.
Michael Collins: That's great. one more question, please, we didn't talk about investigations, but the fact that you have investigations work, did that come up in your corporate security career? Did you invest internal investigations or similar work?
Richard Parry: yeah. yeah. Managed a lot. When I was with Hologic, we bought a company called Sinoshore. Sinoshore is a medical aesthetics company. and so one of the devices that they had used something called a pack key, Basically, what it was a USB device that you inserted in the machine and it had a certain number of clicks on it. Every time a patient came in, they'd do a treatment, a click came off of that device. Well, counterfeit products started showing up in the market. So I started digging into it. I found the source out in Utah, and one of the commercial guys and I went out, we confronted the guy, he admitted it. We got him to stop and we actually kind of flipped him because he had built this with some dark web intelligence stuff as well. So we had a feeling that it was still gonna be out there. and sure enough it wound up showing up. We changed programs, we changed a lot of stuff, but it still wound up showing up. Anyway, probably two and a half year investigation. at that time I had narrowed it down to an individual in California who was a medical doctor. who I believed was the source for this. we, however, divested ourselves from the company. So I wrote up my report, wrote up my conclusions, had all the evidence pointing to this guy, left it with the general counsel there. two years later, the FDA arrested this guy, six million dollar fine, three and a half years in jail. I have my report, I have the news article, it's the same guy I identified. I'll never get credit
Michael Collins: My god.
Richard Parry: for that. That's okay. but it was I remember our general counsel at the time came running up to my office and said, Dick, you gotta see this and they showed me and I looked at the report and it was just like, Yeah, I knew it. I had it right, So I had the self satisfaction of even though I didn't get to, be involved in the bust, I was right on my conclusions.
Michael Collins: I am so glad I asked that question. that's the you know, bench of books that I'm reading. It's just all investigations and fraud, detective stuff. Any other stories or or interesting work in investigations broadly?
Richard Parry: there's been a number of things. we've done a lot of stuff with fraud. I've actually have a case coming up in federal court with an individual who set up funny companies and was diverting product from Whole Logic to sell on the gray market. So we worked with the postal inspectors on that. we were able to track down, where these things were going, to help them build up the case for this person. he was working also doing the same thing with Johnson and Johnson. So they had a bigger stake in it than I did, but they were able to make an arrest on that. So it was just really interesting because you started to dig in, you realize what we identified in that process is Hologic had a very poor process for processing and validating address changes. So all this guy had to do was to go in and change the change the address for a company that was legitimate to a place he wanted stuff sent to, and we sent it. So we were able to secure our processes better as a result of those findings. And I think that's a one of the things out of investigations obviously is being able to find areas for process improvement. And that's been good. So that was another one that was kind of fun and successful.
Michael Collins: That's amazing. Dick, this was fantastic. Really enjoyed the conversation. Thank you so much for being our guest.
Richard Parry: Thank you.
Logan Willans: of this really appreciation. Yeah, this was super fun.
Richard Parry: Well, Michael Logan, thank you very much. I've enjoyed the conversation very much.
Logan Willans: Thank you, Dick.