- Cybersecurity Ecosystem Show
- Posts
- Cybersecurity Finally Grew Up: A Late-90s CISO on Governance, the Real Labor Gap, and AI as Your Second Skill
Cybersecurity Finally Grew Up: A Late-90s CISO on Governance, the Real Labor Gap, and AI as Your Second Skill
From the Cybersecurity Ecosystem Show conversation with Jim Mapes, practicing CISO, advisor, and adjunct professor

Ask Jim Mapes what cybersecurity is getting right and he'll warn you first that it's a slippery slope. Half joking: "We don't want to say too much good stuff. We still need funding."
Then he gives an answer most practitioners wouldn't lead with: governance.
Jim has been doing this since the late nineties, back when the term was information security, the tool was antivirus, and the access model was whatever Windows NT would let you get away with. He is a practicing CISO, an advisor, and an adjunct professor who has taught in boot camps and university programs. That range, from the trenches to the classroom, is what makes his read on the industry's maturity worth your time.
"Remembering back to the late nineties, you couldn't get a meeting with the CIO, let alone leadership," he said. Today, cybersecurity is a standing topic at the ownership and board level, and governance has its own category in the frameworks: NIST added it in the 800-53 revision 5 series, and CSF 2.0 made it a function of its own. "Without that, we never really had the organization. And if you can't get the business behind what you're trying to do, then you're not going to be able to do what you're trying to do."
Here are the biggest lessons from the conversation.
Companies don't exist to be secure
Jim's framing of the CISO's job starts from a sentence that sounds like heresy and is actually the whole strategy.
"Companies and organizations, they don't exist to be secure," he said. "The primary thing is what their primary thing is. Security is what's helping enable them to do that with the least amount of risk possible."
For years, he argues, the industry got this backwards by holding on to a technology-first focus. The shift that changed everything was treating technology as the thing that solves the business problem rather than the thing that is the problem. Security stopped being a backwater that works with IT and became a holistic question: where does the business want to go, and how do we help them get there with the least technology risk possible?
He is blunt about what the old way produced. Check-the-box reviews, a policy read-through, a report once a year. "We all know that wasn't good enough, and that largely got us to where we were."
Thank ransomware for your seat at the table
So what actually forced the change? Jim's answer is uncomfortable and convincing: the adversaries did it.
"Ransomware made an equal victim out of everybody," he said. "You can be healthcare, you can be government, it doesn't matter who you are. Even if you don't have any confidential information whatsoever that an adversary wants, you can still be a victim of ransomware. Because the money is in getting your systems back."
Boards did not suddenly develop a passion for access control. They watched organizations with nothing worth stealing get shut down anyway, and the risk became real. Phishing did the same thing at the individual level. Then the pandemic finished the job: remote work pushed the security perimeter into everybody's home, onto the same machine as everybody's 14-year-old kid, and for the first time executive leadership planned a major business move with the cybersecurity group in the room from the start.
Jim wants listeners to appreciate the size of that victory, because anyone who joined the industry in the last decade inherited it without seeing the before picture.
How do you talk to the board about cyber risk?
Jim's answer starts with respect for the audience. "I've always said CEOs and CFOs are the best risk managers in the world. Because they have to be. Every single decision that they make has a risk and reward attached to it."
The problem was never that business leaders couldn't handle risk. It was that security people opened the conversation in the wrong language. "The real limitation has been how we open that conversation. How do we translate that technology risk into a business risk with a business impact and a business solution behind it?" Budget meetings went badly for a reason: the security team threw terminology at the business "like word salad," the business came back with "cut that by half," and the right response, how much risk do you then want to accept, never landed because nobody could price it.
His best metaphor of the episode is a card game. Business leaders already know how to play. "They knew what risk was, they knew how to assess that. What they didn't know was the value of the hand that they were holding. Should they continue with that? Should they fold?" The security leader's job is to tell them what their cards are worth.
That is exactly the job Rivial's platform does for banks and credit unions: cyber risk expressed in dollars, tied to the systems that carry it, so the board can weigh the hand they're holding the way they weigh every other bet.
"We kind of gave up on humans"
The sharpest self-criticism in the episode is about how security treated employees for years.
The industry's big push, Jim recalled, was total transparency, but ubiquitous: "It's everywhere, but you don't see it. Because if you did see it, you'd mess it up. So we're gonna do it all for you in the background, and you just keep on doing what you're doing and be uninvolved."
Uninvolved employees turned out to be exactly what phishing needed. So awareness training came back, people got measurably better at spotting phish, and the industry relearned something it should never have forgotten: security is not the security team's job alone.
"If you're expecting five guys to protect a company of hundreds of people, how the hell are you gonna do that? You can't. It's an unrealistic expectation."
His diagnosis of where programs stand now is worth writing down. "We were starting to win battles up in the boardroom and with the executive leadership team, but we were still missing the middle." Culture is how you stop missing it, and the payoff shows up in his AI discussion below: in a good culture, an employee who wants a new tool comes to security and says, I want to use this, I don't want to produce a risk, what do we do?
A history degree, no ego, and the community advantage
Jim's own path in is a case study for the skills conversation. He came up through a campus IT job that paid his way through school, then into IT, then into security because "somebody had to take care of viruses." His degree is in history, and he insists he has used it. "It gave me a unique skill set compared to a lot of my counterparts. Assessment and analysis, writing capability, speaking capability. It was finding a position and defending it by finding the information and data that I needed. Those were all critical skills that really propelled me more towards leadership."
Back then, the security person was expected to know everything, and everyone assumed they did. "The fact is, we didn't know more than anybody else that we were working with. And I was always very careful not to let them think that I did." His survival tools were asking questions and checking his ego at the door. "The egos kill you. They really do. You've got to be able to accept the fact that it's okay you don't know everything. You can't."
What covered the gaps was community, on Usenet then and in practitioner circles now. "We back each other up with information, with our skill sets. It's one of the big advantages that we have over our adversaries." The role itself has matured the same way: the CISO is no longer the most technical person in the unit but the person who understands the business, its use of technology, and the team skills required to protect it. Jim's prediction for the next step: eventually it all wraps under the chief risk officer.
Is there really a cybersecurity labor shortage?
Taylor put the internet's favorite complaint to him: there are supposedly hundreds of thousands of open roles, yet entry-level candidates can't get hired. Jim's answer is more precise than the usual takes.
"They're absolutely right about that," he said. The entry-level tier is saturated, filled by the first waves of graduates from the same boot camps and degree programs everyone is still coming out of. The openings that stay open are one tier up. "Some of the big gaps we see out there, they're trying to hire engineer-level folks. Those were positions we still didn't have enough people of more senior experience to fill."
The fix he prescribes is the one every other profession already uses: structured experience before the job. Psychology graduate students do field work. Medical students do rotations. Cybersecurity students mostly don't, and Jim thinks the partnership between educators, businesses, and government to change that is the most valuable move available. He pointed to his friend Ed Vasko, who built a cybersecurity workforce institute at Boise State, as proof of what that looks like done well. And hiring managers have every incentive to participate: "Give me somebody who's got some skills and background, I have no problem helping them get experience, because I could use the help."
Two more pieces of advice for people breaking in. First, get the four-year degree, because without it you hit a ceiling around manager level, and director and above increasingly requires one. His hack: "Get the job, go to work for a company that offers tuition reimbursement, and get your degree while you're getting all the experience."
Second, and this is the line to remember: "Learn a second skill right now. It's called AI." Every board is pressuring every company to adopt AI and cut operating costs, and almost nobody can answer the follow-up question, which is what the risk is and how to reduce it to something acceptable. "If you can come in, help a company figure out what they need to do with AI, and offer a means by which to govern it and reduce risk on it, that makes you very, very marketable."
AI is the new dot-com, without the extinction event
Jim lived through the last mania, and he hears the rhyme. "Everybody suddenly needed to have an e-commerce site, even though they didn't know what the hell e-commerce was and they sold nothing. They needed to have one or they couldn't be a company anymore." He doesn't expect AI to end the way dot-com did, but he does expect a reset.
What he has no patience for is colleagues planning to ban their way through it. "Some of them are saying, no, there's not going to be any AI. And I said, are you gonna die on that hill? Because you most certainly are if you maintain that kind of attitude." He watched the same stand fail against cloud computing. "You're not gonna stop it. If you don't give them a means by which to do something secure, they're gonna find a way to do it around you. Even if you lock it down at the computer, they're doing it on their phone. And I've seen it."
The alternative is the culture he described earlier, where people bring the tool to you before they use it. And the payoff he's chasing is the productivity flip: "You spent seventy-five percent of your time doing absolute BS just to do the 25% that you really loved. Now all that stuff can be done in an automated fashion, albeit maybe with a review. What does that do for productivity? It'll send it through the roof."
The next maturity: data classification
Asked for his closing take, Jim named the least glamorous control in the book as the next frontier.
"One of the greatest things that we really need to ratchet down, and this is gonna be the next area of great maturity in cybersecurity, is data classification. The schema, and actually finding that truly enforced. And probably data loss prevention, which needs to have that data classification solidified and enforced."
The logic follows directly from AI. You cannot protect business information flowing into AI tools if you have never decided which information is which. Classification plus enforced DLP is what makes secure AI use possible rather than aspirational, and it is where he and Taylor are taking the follow-up episode, along with data governance.
Put the guardrails in writing first
Jim's AI position reduces to one move every organization can make this quarter: give people a secure, sanctioned way to use AI before they invent their own, and put the rules where everyone can read them. If you don't have that document yet, don't start from a blank page. Download Rivial's free AI Security Policy Template. It is an instant download, no sales call required, and it turns "we should have a policy" into a policy.
And listen to the full conversation with Jim. His take on the Gen Z workforce alone is worth it: his daughter submits graduate school papers from her iPhone, works collaboratively from wherever and whenever, and he argues the companies that adopt that model, with AI doing the heavy lifting, will be the ones that get the most from the next generation, prickly shivers about the risks and all. You can connect with Jim on
LinkedIn at linkedin.com/in/jimmapes.
Here are the key takeaways from this blog:
Governance was the win: cybersecurity went from no meeting with the CIO to a board-level topic with its own function in NIST 800-53 rev 5 and CSF 2.0, and that organizational backing is what makes everything else possible.
Companies don't exist to be secure: security enables the business's primary thing with the least risk possible, and technology-first framing is what kept the industry unheard for years.
Ransomware bought the credibility: it made an equal victim of every organization, and the pandemic put security in the room when leadership planned remote work.
Tell the board the value of their hand: executives are already expert risk managers; translate technology risk into business impact instead of word salad, and price it.
The labor gap is one tier up: entry level is saturated while engineer-level roles go unfilled, so internships and work programs, a four-year degree on tuition reimbursement, and AI as a second skill are the way in.
You can't ban AI, so govern it: blockers will be worked around on personal phones, and the sustainable path is a culture where people ask first, backed by data classification and enforced DLP.
The Cybersecurity Ecosystem Show connects practitioners, investors, vendors, regulators, and everyone in between. New episodes drop weekly. Subscribe so you don't miss one.
Reply