The Wired Garage with Pops | Digital Innovation

From Music to Cybersecurity with Matt Godsted

Hosted by Brian Clayton and Steele Harding | Digital Innovation Season 1 Episode 22

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 33:28

s1e22 2026_0310 tech From Music to Cybersecurity with Matt Godsted

In this episode of The Wired Garage, host Steele interviews Matt Godsted, a strategic leader in cybersecurity and a passionate musician. They explore Matt's journey from technology to music, the importance of mentorship in IT, and the complexities of cybersecurity architecture. Matt shares insights on how different industries influence cybersecurity practices, the global risks posed by AI, and the balance between business needs and security. He emphasizes the need for effective communication and partnership between security teams and business units, as well as the importance of frameworks and metrics in measuring security effectiveness.

Takeaways:

  • Matt's journey began with technology, influenced by early computers and movies.
  • Music and technology have both played significant roles in Matt's life.
  • Mentorship is crucial in IT; it shapes careers and opportunities.
  • Cybersecurity architecture requires a broad understanding of business strategy.
  • Different industries have unique cybersecurity needs and challenges.
  • AI presents new risks that require careful management and understanding.
  • Balancing business needs with security is essential for success.
  • Effective communication of risk is key to security's role in business.
  • Frameworks like NIST guide cybersecurity practices and governance.
  • Measuring the effectiveness of security involves understanding business impact.

Keywords: cybersecurity, mentorship, technology, music, leadership, AI, risk management, business strategy, IT architecture, industry influences

Sound Bites:

  • "AI is a business driver and enabler."
  • "We need to protect our customers' data."
  • "Is it serving the business well?"

Chapters:

  • Introduction to Matt Godsted and His Dual Passions
  • The Journey from Music to Cybersecurity
  • Understanding Cybersecurity Strategy Architecture
  • Balancing Business Needs and Security
  • Frameworks and Principles in Decision Making
  • Measuring Technology's Impact on Business




Support the show

SPEAKER_02

I worry that companies in a in a in a mad dash to kind of get ahead or to keep up, you're gonna inadvertently expose something to AI that you didn't intend to expose. Or that your models are compromised, or that there's been some kind of you have you're introducing hallucinations and that's getting out there. I've I've given uh a few talks before on responsible and ethical AI and some of the the very, very public wonders that have happened because people trying to get out there as fast as they can. McDonald's with the infamous 250 McNuggets of the drive-thru, because they try to get they try to get AI out of into a drive-thru kiosk faster than than they were ready to do it. There was a a grocery retailer that were putting AI recipes out there, and somebody asked for an aromatic drink recipe, and and it came up, and a third of the recipe was bleach and a third of it was chlorine. And it said, here you go, here's an aromatic, refreshing summer beverage. You know, reasonable people are not going to make that recipe, but they they were so quick to get it out there to get to just be on the edge to be competitive.

SPEAKER_01

Beyond that, Matt gives back as a mentor with the Inter Alliance, a nonprofit helping students discover the IT industry here in Cincinnati. In this episode, we'll talk about Matt's origin story, leadership journey, and cybersecurity architecture applied to the real world. Hey Matt, thank you. Pleasure to have you. Let's get started. So I have the privilege of knowing you a little bit more intimately than our guests listening. And so I really want to start off with this question. What came first for you? Was it technology or music? And then how did one influence the other over time?

SPEAKER_02

Uh technology first. Um, though I did not start with an interest in technology as a career, but um my first computer, uh, for those I'm I'm dating myself for sure, but uh TRS 80 from Radio Shack was 1984. Like a lot of kids, I was influenced by um some of the movies at the time, specifically war games. I wanted to hack. So that was my my first computer. You know, I had a little cassette player. That was your that was how you how you got data off of it. Uh then uh so fast follow in get uh 1987 is when I first started my first guitar. My first band was in 1989. But kind of abandoned the technology thing for the music thing. Uh so yeah, I don't know how they influence each other over time. There there is a certain thing that you you know you think about with technology and music and they're very technical. I don't know that that was related in my case. I just uh had had an interest in both and pursued them both.

SPEAKER_01

That's uh that's surprising to me. I would have thought that it that you got bit by the music bug first. Um stash of guitars behind you there.

SPEAKER_02

But that's cool. Those are just that the uh the re the real arsenal is is in the basement and uh sort of a recording or a rehearsal space. So did not I did not do this down there.

SPEAKER_00

So I'll send this I'll send you a picture though of it. So who were your like early influences, either in technology or music?

SPEAKER_02

That's a great question. So I guess with music, early on it probably wasn't a specific guitarist per se. I love you know everything from Angus Young to Segovia, right? To Paul Gilbert, more recent, um uh to Eddie Van Halen. I mean, there's a lot of different ones. Um so I think it was probably more the music alo along the years, a lot of the usual suspects from the 80s, hard rock, ACDC and Zeppelin, and the a lot of the things they hear. But I would say that a number of different influences I was always a big fan of, like real music. And anything that was that was you'd get up there and gritty, and even later years like the Black Crows, just absolutely just love that really hardfelt music. Yeah, it was interesting, probably right around the time I graduated college, I sort of gave up guitar for several years. Um, and it wasn't until I probably late, you know, probably 2008, I picked it back up again. I sold all my gear. Literally, I was like, I'm never gonna, I don't know that I'm ever gonna be a guitar again. I got into interested, and that's why I kind of fell into IT. There was no time. I sold pretty much everything I had. And then when I kind of was re-inspired by it and we just really wanted to get back into it, uh, had to buy all that stuff all over again. So became kind of pricey. Uh so and there was actually some really great stuff that I had sold that I really regret. I really um some great tube amps and some things over the years. So influences in IT, I think that probably, you know, my very first job out of college, try just trying to figure out what I wanted to do and uh land in a in a job, just kind of the basic stuff and and first first office job. And I was one of those guys when they first, when Windows first came around, and you're moving away from mainframes and got my first PC in an office environment. And I started, I'm one of those guys trying to get around things. I'm trying to explore and one of the the person that was over the IT team at the time versus getting penalized for that, actually saw the potential and actually took a chance on me and saw the potential that I had, brought me into IT. And it was literally, it was the perfect time to get into it because probably four or five years later is when the industry really got flooded with people getting into IT. So I got in like just in the right time. So probably there's one of the people in my life that really influenced and changed my life was the person that saw the saw the potential in me and invested in me and got me into IT. It's such an early, an early part of my it's really cool.

SPEAKER_00

Yeah. I we're we're thinking about doing a series here soon just on mentoring only, because I think if you're successful at all, it's like the the old saying behind every good man's a good wife, you know, kind of a thing. Behind every successful like technician, IT guy, there's a mentor who guided them. And it if you didn't, you know, I think everyone has that story of someone, you know, that said, you know, they they turned them with that someone would say the pivot point in your career on how to either treat people, treat technology, whatever it is, agreed. There's definitely a mentorship that's happening.

SPEAKER_02

Yeah, I've also been been over the years, I realized or a long time ago, skills can be trained, but personality and the drive and what you know, how you fit into the team, you can't, that's not as easily taught. And I know a number of times where I had to fight for people that I wanted to hire that probably met 30% of the technology requirements, but met 100% of like of the team fit, of the of the perfect person for the and for the team and how they would just really adapt. Give them two to three months and they're gonna learn those skills. That's really where I have the where I have most satisfaction in a leadership role is bringing in those people that really just want a chance that you know are gonna be really great fits. And probably if you say it takes them six months to learn this skill or that skill, they'll probably do it in two. And they ended up being the the probably the highest performers and the probably the ones on my teams that were really seen as as contributing the most were the ones that just were given that chance and the that you knew were gonna be the right cultural fit. And and that's and that's part of mentoring too.

SPEAKER_00

Yeah, I I've always lived by that because someone gave me a chance when I first started, right? You know, I my wife always says, you know, I can fling bullshit like anybody, right? So when I first started, yeah, right, you kind of stretch what you can do. And and then I had my all shit moment when, you know, I was going from an IT like uh help desk technician. They said, Well, your IT manager's being like, Oh, you're gonna be the IT manager. And I'm thinking, oh my gosh, you know, but he sat with me and they mentored me. And I think that's what I want to do in my career, and I think I've done now with some s several people in my career was just give them a chance to to, like you said, just to flourish and and do well and make make you look good. And I think it does it goes well with vendors too. I mean, your vendor relationships are the same way. Those people like bleed when I bleed, smile when I smile, all those sort of things. I'm in a journey with you together. It's all it's all part of that. It's definitely a people's interest.

SPEAKER_02

I 100%, 100% agree. Because that's these are the ones that that are gonna be out there representing you. You're as a as a leader, you're not gonna be in every meeting. You're not gonna be out there representing, you're not gonna be on all those outage bridges, you're not gonna be the one always the face of. And you and it's it's hiring the right people that have the right soft skills, that can talk to the business, that can can explain things, technical things in the non-technical way. Most and sometimes, especially in the outage bridge situation, the ones that can reassure and the ones are like, hey, we're gonna get this, we're gonna fix it. We understand the impact, it has our attention. Um, so I think that's another piece is the soft skill that sometimes is overlooked, um, that I think is so important when building really successful teams. I'm also a big believer in hiring people that are smarter than you, um, which for some like guys like me, that's not not a stretch. But um just really bringing in the the people that are really gonna excel and and really just saying, hey, if you say that five years from now your career goal is to have my job, do it, please.

SPEAKER_00

Cause that's just that's that's yeah, I was told there was a uh mentor I had early on. He like never sat at the end of a table, no conference room table. We sat like in the middle, right, middle left. He was never in like the nine, three, six, nine points, right? He was always on the edge. And then interviews or reviews, you know, your employee reviews, he sat next to me, not at the at a desk across from me. And just things like that that really mean a lot to people. It takes the pressure off and lets people know that you're in the room together and I'm not just leading it, and everyone's just listening. And I think I think that goes a long way. It's like it's like Eddie it's like Van Halen, right? David E. Roth might have been the front man, but you know, when you think of Van Halen, who do you think of? You think of the guitarist Eddie Van Halen, right? And I think that's the kind of way you need this. You need everyone in their position, but you know who really is is kicking that group. It's you know, EV.

SPEAKER_02

It it's funny when you say that, but at the heart and the soul of every band is probably the drummer. Yeah. Very oftentimes, unless it's rush, oftentimes they're the ones that don't get a lot of the they're not out front, they're in the back, but they without them, I mean, that nothing is gonna sound right, especially if it's not if it's not a drummer that can keep time or is is off a little bit, it's gonna throw everybody off. Yeah, you're right. A singer, a singer can singer can screw up a lyric, guitar player can screw up a lead. I can speak from experience in that in both of those regards, but if if the drummer misses is off time, uh just even the hair, yeah, the song stops and everyone is off.

SPEAKER_01

No, you're right. You're right. Speaking of, or or you miss eight bars and they adjust and then they they they keep you right on time. Yeah, right, right on time. So speaking of that journey, kind of transitioning here, we have we have the influences, somebody took a chance, and that really helped you flourish, that sparked your IT career, and we have where you are now, skipping a whole lot of things that we'll come back to. But when somebody asks what a security strategy architect is and what you do, how do you explain that or how would you explain that? What is the type of things that you do now? And I'll I'll I'll kick it over.

SPEAKER_00

Almost like to your neighbor, right?

SPEAKER_02

Like without the jargon, right? Without a lot of tech tech speak and jargon, right? Right. It's a really it's a great question. It's probably the one role in security, I think, that you can talk about it without jargon. Um, because it's a pretty unique role um at at Kroger. Uh so we have within Kroger, we have many functional pillars and and functional teams, cloud security, identity access management, incident response, all the things, right? And each of those teams have their own incredible engineering talent that's on the teams, and they have they have people on each team that focus on strategy. So as the broad cyber strategy architect, I'm a I get the privilege of being able to look at the future landscape, the broad cyber risks for Kroger and looking at the like at three from a three to five year lens and looking at, you know, what are the things that are going to impact us from a broad lens that are not necessarily targeted on one particular function within security. I like, I love working with each of our teams to look at the what their strategies are, but because those often can bubble up into what's our kind of what's our broad security lens for Kroger. Many of the things from a cybersecurity perspective don't fall under one particular function within cybersecurity. So I get to look at how to tie all that together. Like a great example is AI. That that that's something that affects every aspect of cybersecurity, that affects the business. That's a business driver and a business enabler. So from a strategy perspective, we look at AI broadly as a and in that regard. When you look at up you know, quantum computing, that's that's coming. That is going to be a cybersecurity risk that's going to not necessarily fall into one particular area. That's going to be another thing from a strategy perspective. So we're able to look at the landscape, we're able to work closely with our business and understand, better understand what the business strategy is and what the potential roadblocks are there or what potential things that could impact the business. The better we understand our business strategy, the better that we can from a from an overall cyber strategy align and do what we can to accelerate our most important business initiatives. Um, and take some of those broader strategies then and go down one level to the functional security teams and give them what they need to help them develop their own individual strategies. Does that kind of make sense if you were my next door neighbor? Would that would I have lost you or would you have cracked a beer and walked out like three minutes ago? That was great. Okay, cool. I live and breathe it, so sometimes it's like, well, that kind of makes sense, but you know, some people I probably would have lost.

SPEAKER_00

You you you've worked across manufacturing, financial data analytics and large-scale retail. How have those, maybe each of them had different plays, but how have they shaped your approach to technology and security, you know, and and how you handle it? Uh one sort of like music, your influences and security, which of those had the more heavy of an influence, or what influenced you?

SPEAKER_02

So I love the question. I love uh because I I oftentimes talk about that from a from a not necessarily cyber related, but when we talk about like the mentoring thing, like interalliance and and talking to students and they're asking about, you know, like, hey, what will you have, what would you do? And a lot of these things translate no matter where you are. Every company, regardless of industry, is gonna have a cybersecurity function depending upon the size, but you're gonna be focused on all of the different things that every company, identity access management, all of these things are the same. But from a cyber lens, depending upon the industry, at the heart of it, it's all about protecting what are the key assets, the key data assets of that company. That's gonna vary. Yeah, with manufacturing, it's gonna be protecting, you know, whatever your mission critical systems are that keep the operations running from incidents that could impact production. So a malware incident or a ransomware incident that could potentially shut down production. That's gonna be the things that protecting those key systems. I would imagine in manufacturing there's gonna be, depending upon, but it could be uh some kind of uh your data that's you consider your crown jewels. Like these are the things that that's unique to us as a manufacturing business. Those are gonna be things you're gonna want to focus on cybersecurity lens. The functions are gonna be similar, but it's all about the differences in data. So that's what kind of makes everything unique. And financial services, it's gonna be your your customer financial data, data analytics and retail, especially retail. It's gonna be your your customer data, it's gonna be probably the heart of what you do. Kroger is unique because it's his manufacturing and it is custom, it is your retail aspect. So you we look at protecting the data um from a customer data perspective. We don't that we treat that highest level of confidentiality, which means it's gonna have the highest scrutiny and the highest um security controls that we can that we can put in to protect it. Uh in manufacturing, there's gonna be things that we consider crown jewels that are recipes. You know, the things that we that we produ that we produce in our manufacturing facilities that are we consider our crown jewels. And uh I I will also say that from a customer data perspective is that is the highest most level of importance because from a customer trust, we lose that and that it that absolutely negatively impacts our business. For those that remember the the infamous target breach of 2013, some of us in this industry don't ever stop giving that example because um that was something that that could have impacted their that did impact their their reputation. Um they moved on, they they recovered, they they went on, but we still talk about it. And it's so hard to recover reputational damage and and recover that trust of our customer. So our customer data, we really go do everything we can to protect that because we really want to protect our our the customers. Um whatever the company considers to be its highest level of confidential data, whether that's crown jewels, whether that's you know customer data, what it's all gonna vary. Each industry is gonna obviously have different regulatory considerations as well. PCI, you know, if your financial services steel can recover, remember some of those from a financial services perspective. You have um New York DFS and highly regulated industries that's gonna come into play too. But at the heart of the question, and the heart of all of it, it's gonna be just whatever the key data assets are of your company. The rest of it is all gonna be, I would imagine, pretty simple.

SPEAKER_00

Yeah, in financial my my personal information, I think it's almost like it's a long-gone conversation over kind of existence in a sense. But when you look at globalization with some of the superpowers or the m minor powers, I guess you would say, is coming around. What do you think of with like uh taking over cars, taking over power and water? You brought up war games, you know, where they they would you can misconstrue happening and and not really happening, but makes you engage, you know, in in a fake war, but you now you really engage, sort of like with Venezuela or something, right? So what are some of those things that keep you up at night when you think we're a global company as well, and some of these other powers are you know always trying to find or get information from us? But what keeps you up at night with those and it takes it to another level where it's almost a pandemic level, you know if I'm trying to ask that question.

SPEAKER_02

Is there like it's just broad this broadly?

SPEAKER_00

Yeah, what do you what keeps you up at night at more of a of a pandemic re uh risk that's could be happening soon or it's you're seeing happening, or you know, we've lived through a few things, but what's what do you think is the next big with AI going on? What do you think is the next best big risk that we need to be watching for?

SPEAKER_02

I do think with the way the the acceleration of AI, I don't know if it's to keep me up at night, but it is one of the things that I feel is so broad and it's and it's happening so fast. Um I do believe AI is one of those things that that 10 years from now we'll not be talking about it anymore.

SPEAKER_00

Right.

SPEAKER_02

Back, you know, 20 years ago, cloud computing was all people could talk about. You went to any conference and it was all cloud computing. And like, oh my God, this is such a game. This all of the things, everything was just focused on that. Well, guess what? And it went away. Virtualization was the same way. That was like, oh my gosh, this is like, what do we do? And then it just became routine, it just became a matter of business and technology. And I think AI will get there, but it is definitely it is different because of the learning capability of it, the high potential for error, that it's probably one of those things that does keep me up a little bit more, only because I feel like that there is such an accelerated pace for companies that want to get out there first. And it is so competitive. And you look at any industry and people look at the companies, look at their peers and what they are doing. You know, it's very easy to do it in retail. And so look what your competitors are doing. I worry that companies in a in a in a mad dash to kind of get ahead or to keep up, you're gonna inadvertently expose something to AI that you didn't intend to expose. Or that your models are compromised, or that there's been some kind of you have you're introducing hallucinations and that's getting out there. I've I've given a few talks before on responsible and ethical AI and some of the the very, very public wonders that have happened because people trying to get out there as fast as they can. McDonald's with the infamous 250 McNuggets of the drive-thru, because they try to get they try to get AI out of into a drive-thru kiosk faster than than they were ready to do it. There was a grocery retailer that were putting AI recipes out there, and somebody asked for an aromatic drink recipe, and and it came up, and a third of the recipe was bleach and a third of it was chlorine. And it said, here you go, here's an aromatic, refreshing summer beverage. You know, reasonable people are not gonna make that recipe, but they they were so quick to get it out there to just be on the edge, to be competitive. You're introducing things that you didn't intend to and you without having a man in the middle, those risks are out there more so than the risks that we saw with you know cloud computing 10 years ago and virtualization 20 years ago. So those are the things that I that worry me, especially, especially like small to medium-sized businesses and nonprofits, you know, the ones that are really trying to that don't necessarily have the time have the money to hire in the right talent and the expertise. They're just trying to compete and get it out there. Those are the ones that I worry about a lot because those they're most prone to do something and inadvertently put data out there they didn't mean to, or again, introduce bias um and put themselves in legal harm.

SPEAKER_00

So and those are the companies that need that support, right? That uh across the businesses in your region, the alliances of just training and education and news, and you know, because they can't afford the big vendors or the big experts, you know, and don't to be hired in. And yeah they're taking chances on things. And even though they I wouldn't say they're a competitor because they're nonprofits, but you have to share some of this because they can they can doom your world as fast as any competitor could, right?

SPEAKER_02

And they're just trying to they're just trying to stay trying to keep up, they're trying to be relevant, they're trying to be competitive. It's just without with without knowing about what goes into protecting it responsibly. Cybersecurity is one aspect of it. But at the end of the day, it it is it really is understanding AI and how models can be influenced and and injections and and just all the heinous stuff that can happen. Um it just it's easy though to like we gotta get this out here. We gotta get that, forget it. Let's cut some corners, we can do that. And that's probably the stuff that concerns me the most.

SPEAKER_01

So I kind of to that point, when you've got this burning rush and burning desire to get stuff out there, how do you tactfully kind of tread and create balance in business need and security need? When you say no to a project on security grounds, for example, how do you turn that into a productive conversation instead of a roadblock?

SPEAKER_02

That's a uh that's a good question. I th I feel like that we've really evolved over the past several 10 years or so, let's say. Getting out of security, just getting out of the business of saying no. That's not the business that we want to be in. I feel like 10 several years ago it was security was sort of set apart from the business, and we assess the risk, you assess the things, and you're like, no, that that's not happening. So come back when you have something more secure, come back when you have a better solution. We're not in that business. Certainly, regulated data is in scope, sure, that could absolutely be a no, but it's gonna be a it's gonna be a no but. It's gonna be we need to what can we do to get past the risk that we are seeing that that we see that the risk is not worth it. It's all about measuring risk, and it's all about communicating that risk to the business and understanding what the risk appetite is of that business. It's gonna, it's gonna depend. Um so companies and businesses have to take risks. If they didn't, they would not stay in business. You have to take risks. We in security have to go along for the ride with the business to understand what those risks are and help them measure what their risk, what their risk without putting the company at risk and without putting the looking at all the potential regulatory, there's operational risk, there's rep, there's reputational, there's financial risk, there's all these things, making sure that they understand what those factors are and to give them the data that they need to make an educated decision. We will certainly weigh in. There's going to be scenarios where we would say, no, but this is what we need to do to get you where you would need to be. Or we may say, here are here are the risks, as long as we're you're willing to accept that from the business, then we've we've given you what that is, and here's our recommendations to kind of get things, whether that's in-house developed solutions that that don't quite hit the market from a dev sective, or if we're looking at our third parties. But the conversation needs to be centered on risk and partnering with the business so that they just better understand what that is. It has to be around that. And then yeah, most importantly, it's it's working with them to remediate whatever that is to get them to the point that security can get behind it. Um, and then just working with them the whole way, just so that the biggest thing is education and so that they understand what it is that they're getting into. And again, there's gonna be times when it's gonna be a no, but it's gonna be a no but. Let's but let's get you there. Because we just don't want to be in that business of saying no. We really want to make sure that it's a partnership all the way, all the way through.

SPEAKER_01

So if I want a new guitar, it's no but got it. That's like partnership.

SPEAKER_02

The new guitar thing is usually that is a flat out no. And the the risk is that you have too many guitars and you need to go find another hobby that's cheaper. It's just one more.

SPEAKER_00

So take an industry out of it. What frameworks or principles do you you kind of depend on or use in your decision making? Like one example I ran into was my first ISO audit. They asked me, why don't isn't change and or why isn't security involved in your change management workflow? And we didn't. We only went to security when we thought it was something maybe that security needed to talk about or see or do. But they said no. And every change, security should have a checkoff point because you really don't know always where those risks are, and they're always in tune with that. They're watching the roadmap. And so what kind of frameworks and principles have you used sort of to guide you? I know that there's frameworks are not, you know, they're best practices, but what have you leaned on?

SPEAKER_02

Predominantly NIST. We've just least recently gone from 1.1 to 2.0, which introduced govern as one of the six functions, one of the now six functions. It really does a great job of everything from you know detection all the way through recovery and now through governance governance is such an important part of it, but it it really does apply across the board for for what we see at Kroger. We we really do um that pretty much is doesn't go let's say like where we are with NIST, doesn't necessarily lead into the strategy, but we also know from a functional perspective, this is where we need to be. We don't aspire to be the measure to rate as a five across the board. We cost doesn't make sense. If we were Fort Knox, if we were, you know, financial services or something like that, we may say we'd probably aspire to be a you know four or four and a half. Right finding that sweet spot that makes sense financially, the financial investments and security, as well as the operation, the the um operational aspects of being that secure. So like right around three, three and a half is it is really where we want to be from in this perspective. That is really everything that we drive for from a you know, for operationally, for where we want to be from a business standpoint, from a recoverability standpoint, everything, you know, business continuity, instant response, um, all the way it's through you know how we look at our other functions with that security.

SPEAKER_00

Yeah, because the most secure technology is the one turned off and business can't run that way. Unplugged. Yeah.

SPEAKER_02

Yeah. I think there's a lot. There are people, I mean, we there's less, there's more risk adverse and there's less risk adverse. And yeah, there's certain parts of our compliance areas. Maybe maybe like, you know what, maybe just unplug this shit and we'll be we'll be a lot better off. Like, okay, that's that's fair. That's fair. Then now we get back to the whole taking risks thing. And we don't we won't exactly sell a lot of canta beans if if we unplug all our stuff.

SPEAKER_01

So from a security perspective, how do you measure whether a platform is serving the business well instead of just being technically elegant? Are there any specific metrics or signals you might pay attention to?

SPEAKER_02

Yeah, really at the end of the day, getting back to the business, kind of leaning heavily on your like your BIAs, your business impact analysis, understanding what business processes you have and are most important, and then what applications or what platforms support those processes. It's really, it's it's hard because you you can absolutely get application sprawl, just like in you can get server sprawl. It's um you can have vaporware, you can have shelfware, you can have things that people buy, think, hey, this is really, really cool. Only to find out it hasn't been used in five years, but yet you've been, you know, spending a lot of capital hosting it in your data center or a lot of you know opx hosting it in your Azure cloud, only to find out it's not been used. So I think that continuously working with the business and updating your your BIAs and understanding the dependencies on those business. What are those dependencies within your business processes, meaning what applications support it, so that you can make sure that they're still they're still in use, they're still serving that that purpose and they're not over or under-architected, because I think that that is also incredibly important. You have a number of times where the BIA can validate if you have the right level of high availability and the right level of security embedded in your applications. Um, there are, you'd be surprised that uh you have active, active solution across two different Azure instances, across two different regions, full failover and five nights of availability only to find out that the business process that it supports. They the business said it could be down for three weeks and nobody would even know. It's really important to make sure you're level setting that. The opposite can be true. You can have something ambition critical application that was architected because they didn't have the money to buy to invest in and the right level of capability or high availability for it. Um, when it comes down to it, is it serving the business well? It's making sure that the recovery time objective of the business process matches the service level agreement of the application. And if you have those things aligned, you're gonna know. From a metric standpoint, having done metrics for years and years, reporting on metrics and every single month you're showing one flat line that shows 100% availability, that there's no value whatsoever in that. You really look at the performance of the business. You look at is it meeting the service level agreements of the business? And is it meeting the business's service levels with whoever their customers are? Thing can be up, thing can be showing a high level of availability, but if it's not actually the performance metrics, I mean I I would more look at you know what it is seeing the results of the business. And that's where it requires getting out of the the bubble of IT and and getting back to the business. I think those the the platform that we've delivered is it actually is it doing that for your customers? Having those conversations is important.

SPEAKER_01

I think that goes back to security as a business partner and advisor there. Yeah. So I'm gonna close us out here. Uh that has been a pleasure talking with you. We heard a little bit about your origin story, how you get into IT, some of your influences in both music and your professional career, building systems, principles to live by, and then we also talked through some of that cybersecurity strategy in the real world. Um, and I think that was a wonderful picture that you painted about how security can be a business partner. It's not just a team that says no to everything, and they really work with you to get you across that finish line. Thank you so much. Yeah, thank you. Looking forward to speaking with you in the future.

SPEAKER_02

I really appreciate the invite. It's great talking to y'all and hope to do this again sometime. Awesome.