GIỚI THIỆU VỀ TẬP NÀY
When Georgeo X. Pulikkathara joined iMerit Technology as CISO, the role came with infrastructure responsibility attached. His solution was to take the CIO title too and fund security controls directly from that budget. It's a structure he'd spent years viewing as a conflict of interest (CIO manages toward ROI, CISO manages toward risk), and this episode is his case for when it works. He also lays out how he presents security budget to boards: tied to specific revenue deals, never to abstract risk ratings, with three solution options already on the table (the premium version, the cheap version, and the one most organizations actually choose) so he never has to go back for emergency money mid-year.
He shares PFC Romeo, the military decision framework now embedded in his IT org: Problem statement, Facts (objective only, no opinions), Considerations (political, emotional, who's going to take it the wrong way), Recommendations (always two viable options, not one good and one bad). He walks through his tiered security architecture, anchored at Tier 0 with identity and MFA through production cloud environments and CI/CD pipelines, and explains why he operates from the assumption that attackers have already bypassed endpoint protection tools like Defender ATP and are targeting identity and production infrastructure instead. That assumption comes from experience: when an AI company became a client, his team detected 13 North Korean threat actors in a single week, running IP proxies and AI-generated faces to get past HR screening that most organizations aren't built to catch. He closes with the 2016 interview at Santander Consumer Bank where the CSO laughed so hard at his five-year CISO prediction that he refused to hire him, and what Georgeo built in that window to prove it right on schedule.
Topics discussed:
Using CIO budget to fund security controls directly
Building financial fluency through a 4-5 month SMU program pre-C-suite
Real-time back channel coaching IT leads during live client calls
Tiered security model anchored at Tier 0 identity with endpoint bypass assumption
Tying board security asks to specific revenue deals with three solution options
PFC Romeo framework for structured team escalations and decisions
Physical printed incident response plans for ransomware network lockout
Detecting North Korean threat actors through IP proxy and AI identity controls