Leadership and Lessons: Building Cyber Resilience Beyond the Security Checklist
CISO Circle Stefanie Hoffman ,Patrick Coughlin began his career analyzing asymmetric threats in the wake of 9/11, watching advanced attack methods migrate from government targets to Fortune 500 boardrooms and, increasingly, the kitchen tables and living rooms of everyday people and families. After co-founding TruSTAR and leading teams through acquisitions by Splunk and later Cisco, he experienced firsthand the operational shift from a 45-person startup to a Fortune 100 with 90,000 employees supporting tens of thousands of customers. Now co-founder and CEO of Savi Security, Coughlin breaks down why resilience cannot be managed through a NIST checklist, how AI is opening cybersecurity careers to non-traditional talent, and why genuine leadership and empathy drive high-stakes mission success.
Stefanie Hoffman: How has your background in national security and cyber intelligence influenced the way you approach corporate cybersecurity, and now consumer cybersecurity?
Patrick Coughlin: I started my career researching security in the early 2000s, in the wake of 9/11. All security focus then was about national security: how we protect government agencies and our national interests from digital and physical threats; from sophisticated nation-state enemies and transnational terrorist or cybercriminal organizations. Then over time, elements of that threat landscape bled over into the enterprise, and by the time we got into the 2010s, cyber security and risk in the digital world had become a board-level issue. Publicly traded companies, large private enterprises, and even small and medium-sized businesses were thinking about their risk posture, and how they were protecting their assets in the physical and the digital world.
What I've seen in the last couple of years is the same kind of sophistication and scale that we saw targeting the three-letter of government agencies, and later large corporations, which has shifted again.
Not to say that protecting the government and enterprise is not as critical now, because it is. But the consumer is way behind when it comes to cybersecurity innovation at the precise moment that cybercriminals are finding it cheaper, easier and more profitable to turn their crosshairs to them, and at an unprecedented scale.
Hoffman: What is the one thing the private sector could learn from the way the government handles intelligence, and vice versa?
Coughlin: The private sector moves much faster than government. The speed at which the threat moves today requires speed on the defense side. And private enterprises do much better at letting intelligence flow to the places where it needs to go.
The flip side is that some of the best people I've worked with in the government had a real passion for the craft of creating intelligence products that could significantly move policy and decision makers. In the enterprise, we have an AI agent comb through and find the threat. In some ways, that's great. But what the government process does is force you to create a well-thought-out product, and to draw fat lines between the priorities of the nation, the raw data, and the insights that are coming out of it. Then wrap that in a point of view with clear recommendations and actions that are backed up with logic and data and handed to a decision maker who determines the course of action in-the-moment.
Intelligence professionals in the government are very good.
My fear would be that as we move more toward AI, we lose the craft of really serving up thoughtful strategic decisions.
Hoffman: What are some tried and true tactics you rely on to translate complex cyber threats into a language business leaders can understand?
Coughlin: It's notoriously hard to articulate value in security. How do you measure the value of the programs that you're running. Is it in breaches prevented? In counterterrorism, is it in the absence of mass casualty events? It's very abstract and hard to consume as an enterprise or agency.
I find that working in stopping fraud, which is also a key part of resilience and adjacent to security, has a more obvious economic value associated with it. You can talk about dollars and cents, in terms of what the average fraud event looks like. For security, I believe that where we are going will require us to talk not just in terms of how well we stop the ‘bad’ but also how well we prioritize, elevate and accelerate the ‘good.’ Here's what we stopped, but also here's what we enabled. And where you can, tie it directly to dollars and cents, or money saved or made, talk as much about the programs that were enabled and what the experience was for customers or internal stakeholders in the language that the business understands. Make it as much about productivity as it is about controls and guardrails implemented.
Hoffman: Splunk’s State of Security report highlights that organizations with mature digital resilience recover significantly faster from disruptions. How has the definition of resilience changed in the last five years, and what is the biggest mistake companies make in trying to achieve it?
Coughlin:
It's a philosophy built on principles, process, people, and products. It’s something that you're always working toward.
It's hard to have a resilience checklist that you complete. You start with a philosophy recognizing that resilience is a value that's worth having, and build that into principles and ultimately, metrics and initiatives to improve those metrics. Then you execute those initiatives through processes and implementing products that help you move the metrics that matter. It's always evolving — what your environment, industry, and footprint look like, your maturity level, and how much you can invest. You’re constantly revising and tuning your approach to resilience. And if you don't have an approach or a resilience philosophy, or you're waiting for the checklist that tells you what to do, then you’re tackling the problem in the wrong way because resilience really has to be a cultural value.
Hoffman: What is the most significant blind spot you had as a founder that you only realized once you were on the other side of the acquisition?
Coughlin: When TruStar was acquired, the company had about 40 or 45 people. We were doing about $5 million in ARR. We had about a hundred very meaningful customers, meaning brands that you would recognize.
When I got to Splunk, Splunk was doing $2.5 billion in ARR, with 14,000 customers and 8,000 employees. And then Cisco later was doing $50 billion in revenue with 90,000 employees. So, I got to see these very different levels of scale. And it was really important to me that when TruStar was acquired, I didn't become a founder who just threw up his hands in frustration with being a part of a big company. Instead, I leaned in. There was so much to learn from the jumps in size and scale from TruSTAR to Splunk and from Splunk to Cisco. While I may have been frustrated at times, I appreciated every step of the journey and the new people and new situations that helped me learn along the way.
When you're in Silicon Valley, often you believe that if you just build the best products, then the business will come. Some of that ethos is true. But to get to any level of scale, you need a really sophisticated and elaborate go-to-market machine; how you position the product, package the product, price the product, deploy the product, and build champions and the story you tell around the product.
All of these things matter as much if not more than the product itself. I saw world class examples of how you bring a product to market at places like Splunk and Cisco and how you get legions of people lined up around the mission of the customer.
Hoffman: Cybersecurity is a field defined by talent shortages. Should we shift the mission from finding the perfect candidate to building the perfect team? And if so, how?
Coughlin: There's no such thing as the perfect candidate. The perfect candidate is a fantasy You want to build a world-class team that moves with the state of the business and the threat. In the startup world, things move even faster and the job you hire a person to do will evolve all the time. This also happens in large companies, particularly in times of big changes like an acquisition, and what we need and want from our people and our teams changes too.
In these times of change, communication that errors on the side of overcommunication is critical. One tool I like to use is resurfacing job descriptions. There used to be a time when I would create a job description, hire the person, and then never look at it again. I like to bring that job description back up and look at it with the employee on a regular basis. We can use a “start-stop-continue” framework to evaluate how we might update it to reflect the needs of the business and then we look at it together and ask the tough questions like “Is this updated description right for you? How might we align it to your growth opportunities and career goals?” I find this works for me, but I encourage others to find their own ways to overcommunicate, surface challenging conversations and ensure everybody is on the same page.
Hoffman: Do you find yourself looking for softer skills, or qualities that are not as tangible to build out your team?
Coughlin: Previously in cybersecurity, the number of letters you had after your name or how many certifications you achieved had a direct bearing on your career trajectory. Things like certifications are still helpful indicators of commitment and career focus, but one of the positive things that AI is doing is bringing down the barrier of entry into cyber security. We look for people who have a passion for the mission and demonstrate creativity and commitment to working with cutting edge tools to accelerate your work. Some in the industry will cling to the certifications and standard tokens of achievement of the past as better judges of talent, but I believe AI has more potential to broaden the tent of people who can contribute and participate in the mission.
Stefanie Hoffman: What is one leadership lesson you learned from leading teams in complex environments in both the US and Middle East that you still apply to your work now?
Patrick Coughlin: I worked with a guy in the Middle East who personally picked up everybody who joined the team when they landed at the airport, no matter what time they landed. He didn’t want to wait until they checked in at the hotel or for a breakfast meeting the next morning. At the time, I thought it was kind of crazy and a bit of overkill. After 15+ hours on a plane, most people don’t want to get in the car with their new boss right away. But I later came to appreciate that he was really showing a level of care. From the moment you stepped your foot into the environment, and you associated yourself with a mission and a team and you felt cared for. That stuck with me, and I think it translates no matter what the team, or the mission the team is working toward.
To learn from leaders on everything from national intelligence to building and growing a successful startup, please subscribe to the Perspectives by Splunk monthly newsletter.