Skip to content

EP. 53 Mental Resiliency and Burnout in Cybersecurity with Rick Mischka

EP. 53 Mental Resiliency and Burnout in Cybersecurity with Rick Mischka

Banner advertising a talk on Mental Resilience and Burnout in Cybersecurity; man on the right, Cloud Currents logo bottom-left.

About This Episode

In this episode, Matt sits down with Rick Mischka, Senior Director of Education and Enablement at Avant Communications and a recently minted PhD in cyberpsychology, to unpack the human side of cybersecurity. They dig into what’s really driving burnout and talent shortages in security teams, why mental resiliency training can extend a professional’s career by nearly a decade, and how leaders can spot the early warning signs before it’s too late. Rick also shares practical strategies for using AI to ease alert fatigue without losing sight of the human vulnerabilities attackers still exploit. Whether you’re building a security team from scratch or trying to keep your current one from burning out, this conversation is packed with hard-won insight from Rick’s unusual path through special forces, firefighting, coaching, and cyber.

Know the Guests

Smiling man with a gray beard wearing a brown suit and light blue shirt against a teal background; professional headshot.

Rick Mischka

Sr. Director of Education & Enablement at AVANT Communications

Rick Mischka is the Sr. Director of Education & Enablement at AVANT Communications, bringing nearly two decades of cybersecurity expertise alongside a unique background as a U.S. Army Green Beret, paramedic, and elite volleyball coach. Holding a doctorate in cyberpsychology, his research focuses on mental resiliency and burnout to help organizations build sustainable security teams. Rick also hosts the Cyber Pro Podcast and serves on the board of T-REX SECURE, supporting veterans and veteran-owned businesses through cybersecurity education.

Know Your Host

Matt Pacheco

Sr. Manager, Content Marketing Team at TierPoint

Matt leads the content marketing team at TierPoint, where his keen eye for detail and deep understanding of industry dynamics is instrumental in crafting and executing a robust content strategy. He excels in guiding IT leaders through the complexities of the evolving cloud technology landscape, often distilling intricate topics into accessible insights. Passionate about exploring the convergence of AI and cloud technologies, Matt engages with experts to discuss their impact on cost efficiency, business sustainability, and innovative tech adoption. As a podcast host, he offers invaluable perspectives on preparing leaders to advocate for cloud and AI solutions to their boards, ensuring they stay ahead in a rapidly changing digital world.

Transcript

00:00 — Rick's Career Journey

Matt Pacheco
Welcome to Cloud Currents, a podcast that navigates the ever changing seas of cloud computing, cybersecurity and emerging technology. I'm your host, Matt Pacheco, and I lead the content marketing team at TierPoint, where I help businesses understand cloud and security trends to help make better decisions about their IT strategy. Today we have a fun conversation. We're going to talk about the human side of cyber security. What is that? So some of the things we talk about are like, what's driving talent shortages or skills gaps as you know them in the industry, how burnout is quietly undermining security postures, how the smart use of AI may help, and how to build out potential strategy in using AI to supplement some of your team, and how organizations can build more resilient teams before the wheels fall off.

So we're going to dive real deep into it and we have an awesome guest today. A former US Army Special forces certified EM team firefighter, champion collegiate volleyball coach, and a recently minted doctorate in cyberpsychology. Rick Mischka is a senior Director of Education and Enablement at Avant Communications, where helps a nationwide network of trusted advisors become sharper and more effective guides for their customers. Navigating cybersecurity, AI and cloud, and all the cool stuff that's going on in the tech industry. Rick's research on burnout and mental resiliency in the cybersecurity professional profession sits at a fast, fascinating intersection of people, tech and organizational health. So we'll also take a look at how IT has real life implications on every IT leader managing a security team today. Because we're all doing it. Every, every company has a, has some kind of tech function.

They're using AI, they have IT teams and secure security function, which is becoming increasingly important. So, Rick, we are so excited to have you on. Looking forward to a great conversation with you.

Rick Mischka
No, I'm excited, Matt. This should be a lot of fun. And even though I just got the new title, I still want people to know that I'm still a cyber and AI engineer at heart. So I'm still a nerd. Obviously you can see that I'm so. Yeah. So it should be a great conversation.

Matt Pacheco
Awesome. Is that Deadpool back there?

Rick Mischka
I think it is, yes. I mean, if you don't mind, I actually have a really random story. I've met Ryan Reynolds. While he was in the Deadpool costume, I was at an event in Las Vegas. They were promoting Deadpool 2, and I'm backstage watching them promote Mission Impossible. So Tom Cruise is out on the stage doing his thing. He goes stage left, exits, and all of a sudden, right next to me is this guy in his Deadpool costume. And they're talking about something on stage. And I look over at this guy, he glances, he nods, he slaps me on the ass. And he walks out as they introduce him. And I find out later that it was Ryan Reynolds.

Matt Pacheco
So there you go in character. That's awesome. I love the dedication, the costume. That's pretty cool story. Awesome. Yeah. Fellow nerd. Cool. So let's talk a little bit about your career journey and where you started, where you're at now. Tell me about your tech life and where you began.

Rick Mischka
Yeah, I mean, I started as a kid just digging into computers. One of my really good friends, he programmed the flight controls for the F22. And him and I would just nerd out, you know, back in the AOL dial up days. And then I chose a different path. I went into the military. I did a lot of coaching, I did a lot of other things. And while I always loved technology, I never made it a passion, I never made it a. A career, I guess is what I would call it. And around 2015, I decided that it was time for me to get back into technology. Somebody said, hey, you should look into cybersecurity. I think you'd be good at it. You've got a lot of really good experience and other things that would fit that.

And I had been doing some solution architecture work for some various tech firms on the side as I was kind of retiring out of coaching volleyball. Found an opportunity to go get a bunch of certifications, kind of four big certs in security, and reached out to a couple of startups immediately, was looking for an opportunity to do investigations. And one of them said, why not? I founded this company and the founder of that company was former military as well. He goes, I'll give you a shot. I'll train you on what you need to know and the rest is history. I've been in cybersecurity ever since, Slowly progressed through investigations and helped that company actually go through for merger and acquisition. Did the due diligence compliance, got really good at that component, and then went into machine learning and AI product management.

Actually supported a company that spun out of the federal government and one of the big prime contractors and got acquired by a Fortune 30 company. And so it was really cool to watch that happen, to take those patents forward, to see them be used for other things. And then I was able to get with an actual security operations firm where I was supporting kind of, you know, solutioning, what threat hunting, what incident response should look like. And then I came over to Avant and I just thought this was great. I really needed some time to just be an engineer again so I could work on my PhD research. And Avant gave me that opportunity. Avant gave me the opportunity to work with tierpoint and to work with all these really cool providers that I was able to just upskill my brain on.

And now I. I'm kind of just this crazy subject matter expert that gets to like, be on these fun podcasts and peer review a bunch of really cool articles and it's been a great journey. So, yeah, that's pretty awesome.

Matt Pacheco
And it sounds like you've done a lot of different things before you've landed where you are now. How is your experience between all the roles you've had before your special forces, firefighter, even as a volleyball coach? How has that shaped who you are now as a security professional?

Rick Mischka
You know, I think the military shapes you with discipline pretty early on. I mean, I was fairly disciplined growing up on a farm. I kind of knew, you know, get up to your chores and then go play as hard as you want. But I was fortunate to have gone through a different experience in the military where I was actually an operator, I was actually special Forces, and I was able to actually think outside the box. And so they taught me that was one of the key components is you have to be that way. You have to do it. So then lift that to the EMT firefighter piece. You're not out there alone. You're with a team. Whether you're fighting a fire or whether you're in the back of the ambulance, you have multiple people working together and take that next thing right.

Here's the story that you're kind of the connecting dots as the team I started coaching, I played professional volleyball and did very well, coached, had a great run, very successful, was able to coach with the men's national team for USA Volleyball. And all of the reasons I was successful was because I understood and I promoted the team concept. Cybersecurity, now artificial intelligence, it's a team. And I think that's the biggest thing that I've taken forward into all of my roles. But in my role now, education enablement, everyone is a team. From the trusted advisor to the tier points of the world, you guys are all a team trying to support that customer who is also on your team. And some of you are coaches, some of you are coach players, but ultimately it all comes down to let's win together.

08:01 — Cyberpsychology Research

Matt Pacheco
Excellent. So you recently completed a doctorate in cyberpsychology. One, can you tell us what that is? It sounds really cool. And two, what made you pursue that and how has it changed the way you approach your work?

Rick Mischka
Yeah, cyberpsychology is interesting. It's something that in Australia, in the Philippines, where we have a lot of security operations happening because it's a great place for follow the sun models to happen in the european Union. Cyberpsychology is actually considered a real psychology first discipline in the United States. This is one of the first universities, capital Technology University, to bring it into the United States. And it's leaning in with the technology side first. And I think that's going to change in the next 18 to 24 months. I chose to take it as the psychology first. And what my research was in was I really asked two questions. The first question was how is training being developed for cybersecurity professionals that is potentially causing a skills gap due to stress and burnout.

What are we doing in the training model? That's just not. And then the second question I asked was could mental resiliency training that is very similar to the military, could that actually promote better mental health? I found a third piece of data and it ultimately led to a third research question that was answered. And that's if we update the training, we provide mental resiliency training early on, it's very similar to what we can see success in law enforcement in healthcare and teachers in the military. But if you don't have organizational support, if they're not willing to make slight modifications and changes and promote that mental health, all of that goes back to zero. You actually see a faster burnout. And so that was really cool. I was able to find something that I wasn't looking for and get published because of it.

 

Matt Pacheco
Now that's really neat. That's really cool. So in your research and your focus, what surprised you? What, what did you find out? What did you learn that surprised you that you may have not assumed or known before you did your research?

Rick Mischka
Yeah, I think it was, I'll say what I wasn't surprised with first. I wasn't surprised that burnout is as is causing some of the skills gap because we've solved for bringing people into cybersecurity faster. Right. You don't have to have a four year degree, you can go get certifications, you can do short term boot camps. And while they're not necessarily ready for prime time, as it were. They can come into any organization and within six months be meaningful, which is great. So that's how were trying to solve for the skills gap, but within 18 months of them starting. And this was the shocking part for me. I didn't think it was going to be that short of time. Within 18 months, people were showing signs of actual burnout, not just the stress from a career in cyber or AI or cloud.

They were actually showing signs of burnout. And that shocked me. I didn't think it was that, that quick. And then the research kind of let itself down to the fact that, you know, most folks are burning out and leaving a job because of burnout within six years. So now that's causing more skills gap and the actual support of just a resilience training, a psychological approach, preparedness training, mindfulness training of any sort extended that by almost a decade. People who had come in with some form of resilience training were seeing, you know, 12 to 16 years before they were getting to that burnout stage. And so those two are the big shocks for me. Right. You know, the short amount of time and then how long the training could support their health.

12:36 — Why People Leave Cybersecurity

Matt Pacheco
Yeah. It's really interesting when you say burnout and people leaving their jobs, do you find it they're leaving the, this specific company they're at, or do you find people leaving the entire industry altogether and doing something else outside of cybersecurity? I'm curious about that.

Rick Mischka
What I saw was kind of three things, right? Those that were seeing burnout on the first, for the first time, they didn't want to leave the industry. Most people in cybersecurity have kind of a hero complex. So we, we kind of want to help people, but we want to be cool doing it. So, so first time they hit burnout, it. It takes a lot for them to really say, I'm in that phase, I need to fix this problem. So they leave the company. They leave the company and they go look for greener pastures. Right or wrong, they had to do something and ultimately they weren't getting support from their company. I do think that's where organizational support could have caught that and solved for that. Move that person into a less aggressive, a less, you know, attacking role.

You know, where you're constantly being attacked by cyber attackers for a year and let them reset their body. So that's the first one I see is people moving over from a job and just leaving, but staying industry. The second one is the exact flip of that. And it usually happens when somebody has felt burnout at more than one job. They're in their third or fourth, you know, choice. They've moved into a leadership role, you know, whether it's a CISO or whether it's a cio. And they've just hit that wall too many times and they wash their hands and they go somewhere else. They just do something completely different. Those are the ones that are hard to lose because they take all that knowledge that they've gained and they just take it with them. Right?

They, they just don't, they're just not in the ecosystem anymore. And then the third one is interesting. It usually happens after the second kind of bout of stress where the cyber security professional says, I don't want to leave cyber, I'm going to go become a sales engineer. And I can't tell you, I like sales engineers. I get it. I've always been more of a solutions guy. But we need them and we need smart sales engineers. But it's always amusing to me that they feel that's going to be less pressure and it's a different type of pressure. Right. They get to be in cyber, but then they have the sales pressure piece. And I always tell them, I go, I'd rather teach a salesperson to be a sales engineer than to teach an actual engineer to be a salesperson. And, and they laugh at that.

But yeah. So that third option is I'm not knocking it. Thank you for staying in the industry. But it happens more than it probably should.

Matt Pacheco
So, so as a leader, if I'm hearing this and we didn't invest, let's hypothetically say I'm a leader, I didn't invest in the well being of my employees, but now I'm kind of wanting to focus on it. What are some of the early warning signs that leaders should pay attention to when it comes to people starting to burn out?

Rick Mischka
I mean, I think the first thing you're going to see is just a lot more pessimism. And I think we all have it. I think all of us are pretty realistic in the world. But you just start seeing them interact less. And we're all remote now, so they're not on camera as much. They're showing up a little late to calls. They're, you know, they're still doing their job. They're still, they're still responding to whatever their main core function is, but they just aren't the person you hired, they aren't the person that's going to get it. Most, most folks in cybersecurity, most teachers, most healthcare providers, most law enforcement, they're very go after it. Right. We're here, we're here to support, we're here to help.

And, and the minute you start seeing them stop raising their hands to do that, you kind of have to think about it. The other thing that we see physically is weight gain and a lack of motivation to work out or to be active. Interestingly enough, we're seeing this weird pivot with the GLP movement. As weird as this is on a two point cloud component, you're not seeing the weight gain as much. Right. If you can go drop that weight by just jabbing the needle and good for them. I want them to be healthy, but.

If a leader is truly talking to their employees and asking them like, you and I jumped on this call and we talked a little bit briefly about just how was your week? And things like that. You can tell by the responses. You can tell, like if you ask the question, how's your family? Oh, they're fine.

Are you having family things? Is there something I can support you on? No, my family's fine. You know, little stress. Well, what do you like, ask the question, what are you stressed about? Well, I just. Too many things are piling up on my plate. Okay. Now you can get like the crux of the conversation. And so I think it really has to happen where you can catch it quick if you just ask the right questions.

17:57 — Mental Resiliency Training

Matt Pacheco
That's great advice. Those are interesting warning signs. Like you said, I did not expect to talk about GLPs, but I mean, that goes into psychology. That is the world we live in. There's probably a lot more factors we could talk about gas prices, all that crazy stuff piling up. So, so thanks for that answer. You mentioned the importance of teaching people earlier and kind of mental resilience kind of training. What does that look like in practice?

Rick Mischka
There's a lot of different ways to do it. You know, I think today mental resiliency is oftentimes correlated with meditation and mindfulness. And I don't think that's a bad thing. I think that's a very worldly way to look at it. Sometimes people think, oh well, meditation and mindfulness is some Buddhist, you know, weird pseudoscience. And that's fine if you believe that, but if you actually do the research on breath work on actually refocusing your brain, even if it's just for 30 seconds to go back to what you're supposed to be doing, that's all meditation is. That's all mindfulness is. And I think that is the core of mental resiliency training. Now, there's a lot more to it than that. There's, there's typically anywhere from five to seven different things that you focus on in mental resiliency training. The first one, however, is very interesting.

You have to want to be in that training. If you are forced into that training, there's a, like the research, my research, other people's research says that there will be a zero positive at the end of it, you will take nothing from it. So that's the first thing, and so that's the piece that's interestingly missing. If they're not ready to be in that training, there's no research. Maybe this is somebody else can go do. There's no research on how to get their mind ready for that. Right. It's a motivation issue. It's a, it's a 1% better issue. But the core of mental resiliency training is first and foremost acknowledging the emotions and the stress that you're feeling. Saying it out loud, even if it's to yourself, instantly reduces your cortisol levels.

The second thing, once you've acknowledged it, is to step back and say, can I control it? Control those controllables. And if you've done those two things, the rest of the training flows right? Then it's just about, hey, I've taught you this habit. This is the habit you're going to use to do this. And you're not going to win all the time, right? If you're in the middle of a ransomware, you're not going to win, you're going to be stressed. Right? But understanding the process, understanding the actual training from there really helps. The military does it very distinctly different than a lot of corporate companies want to provide. And I believe that in cyber, we should be looking more towards what the military and law enforcement does, because while you're sitting behind a computer, you're not seeing those attackers. You're still in a war zone.

Matt Pacheco
Very interesting. So, talked about mental resilience training, we talked about some of the, I, some of the warning signs of burnout. How can organizations, I guess, work to shift their culture so that burnout is More, you can prevent it more than an afterthought or after it happens. How do you bake that into how teams are built, managed, and your. Your kind of organizational culture, man, I.

Rick Mischka
Think, I think there are tons of programs out there that are trying to solve for this. I think if tierpoint wants to give some research dollars to me, we could probably go find answer and sell it to a bunch of companies, but might have something to say about that. The part that always intrigued me was there's three ways for an organization to really support their employees. The first is to train your leaders on how to have those conversations, to identify mental health, stress, those type of things, and then have an actual, here's a resource that can help you. You're not a bad person. You're not going to let the team down because you're stressed and burnt out. We want you on the team. We're going to go fix that problem.

And so that lack of training, of leadership, the lack of, I think every company now has a resource for it, but do you know where it's at? Do you know what it is? And I think that's number one, the second thing that organizations could do, and this is the hardest one of the three, that is be willing to shift your team into different roles. So if I'm a soc analyst, doesn't matter which tier, and I'm doing that for 18 months, give me four months to go be a threat hunter for a while. Let me go just do proactive. I'm not reacting to logs, I'm not looking at alerts.

And then let me come back for another 18 months and lift myself up into the next tier, you know, and after that, maybe you shift me over and say, you know, for the next year, I really want you to take some time and just focus on our grc, our compliance. It's going to be boring, but boring is what you need, right? And guess what? By the time, you know, you've built your team, these guys don't want to leave because they know in 18 months and 24 months, I'm going to be doing something else. And I'm going to be so much more, you know, marketable. I might hate it, but it's going to be cool. And so that's the tough one. But that's the easiest way.

It's the hardest one to implement, but it's the easiest way for a human to not burn out and for a human in cybersecurity to not leave your company. The third way is to Give them the tools they need. But more than that, it's to give them the services that can support them. There's no reason that a company should build a security operations center around six humans. Right? Go grab a TierPoint and help with their cloud security, help with their security operations center 24 7. And then your six folks aren't actively doing detect and alert, they're doing full remediation, which is far more fun. No offense to the service providers, no offense to the tier points. Right.

But, but that's the piece that I love is understand that in the case of cyber, you shouldn't necessarily just be building it yourself unless you're a huge company like Walmart or Google or whatever. They have huge socks, but they still use managed services.

24:14 — Solving the Skills Gap

Matt Pacheco
Interesting. So we talked about your existing teams, what are so. And we have a lot of conversations about the skills gap. Everyone talks about this skills gap in the context of hiring new. Obviously everyone is competing for a limited pool of talent. Like, like I talk with a lot of guests on this podcast and like every company's a tech company. Everyone's doing, everyone has some kind of AI product in the work and everyone has their security team. So there's increased competition for that talent. How do you view that skills gap and that kind of talent gap and how do you fill that?

Rick Mischka
Yeah, for me there's the easy answer. I personally think you identify people that fit your company culture. You hire them for their ability to be a part of that culture. Maybe they have a technical mindset, but they've never been in cyber. Maybe they are really good at talking to people, but they've never done a customer experience journey around cloud conversations. You can train the tech. So hire for culture. And if a company were to say we're going to hire for culture, we're going to go through interviewing processes and screw the you need five years in cyber requirement or whatever. We're going to train you for six months. We're just going to upload and front load for six months. Yes, we're going to contract. You're going to stay for so many months after. Right.

So many years afterwards or you're going to owe us for the training, but you're instantly building a whole new person. You've just solved for your skills gap and you've solved for your culture problem. So that's, I recommend that. And, and to be honest, the perfect candidate is the men and women who serve in our, in our armed services. They could come out having done nothing but being a Marine infantryman or woman, and you could train them to do almost anything and guess what? They're going to go rush through a door and they're going to knock that door down for you.

So I truly believe that those two components right there are going to solve. Now there's another piece right to finding new. And you guys might like this. Two point's gonna love this. I tell every new candidate who's coming into cybersecurity or the technology world, go work for a managed service provider. Go work for a security service provider. And here's why. You're gonna have access to all of the fun tools, not just the tool that your company is buying you for that moment. You're gonna have access to all of great minds. You're gonna have access to tenure, you're gonna have access to training. You're gonna have so many things that you're gonna see that you're never gonna see in another company unless you're going straight to aws, right? Or straight to the big companies. Microsoft. Great, that's an option. But go to an mssp.
Go to an MSP and I guarantee you will find more value quicker to make you more marketable. Maybe you'll even stay. Maybe you'll become leadership, maybe you'll move through that. So for all those companies out there who are not MSPs trying to hire, you should hire the MSP because the best talent is, is likely there.

Got. I, I truly believe it though. I truly believe it. I, I mean, I had just yesterday I talked to an armed forces veteran, 20 years Marine, he's retiring, super cool guy. I, I can't wait to see where he falls. And he's like, well, I probably just go work for the federal government. I have my clearance. And I go, does that sound fun? He goes, I don't know. I did it for 20 years. And I go, you know what's fun is if you get to play with all these cool toys that you didn't get to play with before. Yeah, that's true. And I got a couple MSSPs that would hire you tomorrow and train you on those toys. And so his face lit up, he's like, I didn't even think about that.

He goes, I was thinking about going to a company that does Department of Defense contracting. And, And I go, maybe. But man, I bet you're gonna have a blast for the next three years if you jump over to an mssp. So I, I truly believe it. I, I do tell People that.

Matt Pacheco
Love it. Awesome. And in the past you've advocated for a model of hiring one or two strong internal people and then leaning on an MSP rather than trying to build this kind of full in house security team. Can you tell us a little bit about that and what the case is for that approach?

Rick Mischka
I mean, I think it depends on the size of your company, right? I mean if you're a couple hundred person company, you know, two to three technical resources in specific areas, great. You know, if you're a thousand person company, that might be 8 to 10, you know, and so that needs to shift in scale. But what are the things that cause the company the most consternation? It's, it's the false positives, it's the alert fatigue, it's the triaging of, you know, the wrong alerts. It's vendors trying to figure out what vendors can provide you the technology.

You know, we can talk a little bit about some numbers that I did in a research study on technology versus services in a moment, but the pieces, if I, if I hire for the needs of the business, they're going to truly believe that their goals match across everything and let them manage the MSSP relationship, right? Let them co. Manage, let them go play, let them be the engineer they want to be, whether it's network, whether it's cloud, whether it's security, whether it's artificial intelligence and bring those providers in, bring those services in to allow them to continue to upscale. So I used this real life story, worked with a company, 450 employees, they had six security staff, they had 10 network staff, they had zero cloud folks. And they were told they needed to consolidate and they needed to move everything to the cloud.

I said, okay, you don't have any cloud staff, you have nobody that knows how to do that. You have tons of great network folks. And I said, ask your network team which ones of them would love to be cross trained. Six of them raised their hand, four of them were like, no, we're happy where we're at, we're getting close to retirement or something like that. And so the six of them were like, well, how long would it take? And, and I said, you know, honestly, that's probably not as long as you think. Six months or less to really kind of be in that fold. But let's go find you a cloud service provider. Let's go find you a security provider that offers you cloud native application protection.

And then your security team, let's make sure that they're involved in all of that because I've heard that two of your security folks really want to start leading some AI initiatives. And eight months into this journey, they hadn't lost a single human. Nobody left the company because they were all super excited about what they were doing. They had brought in three new service providers and last I checked, they're still in the motion of it. Last I checked, they're about 80% fully moved up to software as a service and or cloud solution. And that means that their on premise environment is no more and so much easier for them to manage. Before network engineers who didn't want to become cloud engineers, they're still needed to support the connectivity back down, they're still needed for device components. One of them cross trained into security.

So it was a win for this company, it was a win for the service providers. So excellent.

32:38 — AI in Cybersecurity

Matt Pacheco
And you said the word of the day or the word of the year or maybe the decade. AI. Some people are sick of hearing it, but we've got to talk about it. It's becoming ingrained in everything we do. And security is no different than anything else. First off, what are your thoughts on using AI to solve some of these problems in the security space as it relates to maybe alert fatigue or building your team out and things like that?

Rick Mischka
I think security has been doing it for 30 years. Right? I mean in 2019, 2020, I was a part of a team that built two machine learning models for network detection response tool, fully patent the way it actually did, the way it did its actual detection response component fully unsupervised, which was a precursor to kind of what we're seeing with Genai. And it was reaching 98.9% accuracy on unknowns. Right. Knowns are different, but unknowns. And so we've been doing it for a long time, right? Machine learning is just an early variation of artificial intelligence.

I think what we're seeing now is an advancement of that. Right? How quickly can I turn an artificial intelligence tool, a generative AI tool, an agentic AI tool, into a threat hunter, into an immediate responder instead of just quickly finding the alerts. Now I think I saw something recently that those that are using like a cloud anthropic or a chatgpt or even a Microsoft copilot to review and correlate. Logs are in that 99.8% accuracy of removing false positives. That's insane, right? You're never going to be perfect. But here's the crazy part. With security AI is only going to get you so far because nearly 80% of all breaches happen because of social engineering. And so AI is actually helping the bad actors more than they're actually helping the security folks or the staff. Because it's not the security folks that's getting hacked.

It's the accountant who just didn't watch the phishing video and then gets sniped. Right. And so that's the tough part. Right? There's two things that we're still not solving for. AI is helping a little bit, and that is the phishing, the social engineering, the smishing, those type of things. And the second is ultimately it's the vulnerabilities that we're just not closing. It's a human issue. They just don't have the humans to close that. And I'm seeing it more and more in your cloud world. Right. When we talk about cloud workloads, letting a dev just be able to spin up servers and leave them running, well, that's an access point for me to get to data, and that's a workload issue. Right. That's not something that we think about. Same thing.

If I spin up a cloud workload, if I'm using a hypervisor, if I'm using a VMware stack, and I instantly have 70 APIs connected to all of these different sources of tools that I'm using to make this database work, that's 70 gaps that I have to cover for. And so I think AI is going to help us identify those gaps, but we're still missing the problem, which is that the human has to close those gaps. Hopefully the AI could do it eventually.

Matt Pacheco
Hopefully. So, so what advice do you give organizations to kind of fill that gap? Yeah, to the human.

Rick Mischka
I tell people, one, find the professionals that know what they're doing. But mostly when people ask me about AI, we wanted to help us with xyz and I said, have you thought about what XYZ is? Well, marketing says it could do this, or security says it could do this. You should be purchasing solutions and services that already utilize some form of artificial intelligence to make that easier, because they're already taking account of that. But for your business, don't be persuaded by fomo. Don't have the fear of missing out because everybody else is rushing to use artificial intelligence. Take the crawl, walk, run approach like you would with anything. If you're building a new cloud environment, you're not just jumping straight into the running approach. You're not just turning on every cloud piece that you could. Right. You're taking that crawl, walk, run approach.

And this is the thing that most people don't realize today. Every artificial intelligence use case, if you want a true return on investment, has to meet one of three intents. The first one is it has to be able to make you money. If it can't make you money, move it away.

Or move it to the second one. Second one, is it going to save me times more important sometimes than money? And the third one, is it going to make my business more operationally resilient? So that is the cybersecurity version of it. But is it going to make my business meet its goal of continuously supporting our customers, bringing in revenue? So you see, everything kind of ties back to something with money or time. And when they do that and they think from that lens, their business cases become far better. And like, oh, yeah, you know, just removing alert fatigue by catching more false positives doesn't. That's table stakes.

But the use case could be, I want the AI not just to check for false positives, but when it finds a true positive, I want it to give me the list of steps I need to take so my human in six minutes or less can solve this problem. Man, that's an amazing use case for artificial intelligence. It saves time, it saves resilience, and if you were down, it would save you money.

Matt Pacheco
So let's talk about the flip side. So using AI, let's say, to help your team and make their jobs easier, are there any risks that it could potentially introduce as well, especially if it's implemented poorly? Anything leaders should pay mind to when they're trying to adopt some of these AI technologies?

Rick Mischka
Yeah, there's a technical lift and there's a human lift that I really talk a lot about. The technical lift is if you've turned artificial intelligence on and you haven't set it up correctly to understand what your business goals are, what your data is supposed to tell it. Or sometimes AI will tell your data is wrong. And that's good, right? You just told my business that I'm doing something wrong and I need to fix it. But the technical piece is you need to classify your data correctly, you need to govern it in a meaningful way, and you need to control how the AI is utilizing that data. So those three things right there, if you've done that, man, run AI like crazy, you're not going to lose a lot of dollars, right?

You're not going to have a lot of crazy investments that you just get lost to spend because you're going to have minor pivots that the AI is going to just make you super efficient on. On the human side, everybody's worried that AI is going to take my job. And to date, that hasn't actually happened. I actually saw a report that said for every thousand things that AI can do, right. Job descriptions that AI can do, it actually creates 3x in jobs. So if I were to take somebody's one of those thousand one of their jobs, my goal as a good citizen for AI is I'm going to take that person and I'm going to say 60% of your new job is making sure that this AI is doing its job, your old one, because you're the expert at it.

And the other 40%, let's figure out what they're interested in. And so that's the human piece. I'm going to knock on wood, but I'm going to predict that AI is not going to reduce the amount of workers. It's actually going to upskill them in a more meaningful way.

Matt Pacheco
Excellent. Back to your team and the team development. It could include AI, but it's kind of a little broader. How do you stay on top of all of the changes that happen in our industry and cybersecurity and cloud everything. How do you advise your team to stay on top of the new things? Because as we know, AI is changing, sometimes even weekly. There's constant updates and constant new vulnerabilities and new ways the bad guys are using AI. So how do you stay on top of that? What's your advice?

Rick Mischka
I'm. I'm a. I like to learn. And so I'm constantly, you know, reviewing things. I'm constantly using artificial intelligence too long, didn't read, succinctly summarized stuff, you know, making my life a little easier. But I really like two things. So I've heard this from some executives that have done this recently. And it's kind of interesting because I've heard it from multiple executives. First off, they're telling their leaders to tell their teams, let's assign somebody the responsibility of understanding what change management will look like for our team. And so change management means a lot of things, but their role is to take from their team anything that their team is hearing, because we're all hearing it, and to source the things that would help and then instantly go to the leadership and say, these three things this week were just told to me.

I think we should do a change management and change our process with this. Great, let's go try that. Let's run it for two weeks. Let's run a quick proof of concept against that. Giving somebody the enablement to do change management and allowing the rest of the team to just give ideas to that person streamlines that process. The second is I have my team, I ask them to block at least an hour, if not two. And usually I say block an hour once and then block two 30 minute segments later in the week. Block is untouchable except for customers, right? Customers are always first. But during that time you're going to go learn about something that has nothing to do with your job. Just, just go read an AI article, go to chat GPT and see if you can prompt engineer your way around.

And I know for a fact that all of my team has those blocks on their calendar and I love it. And sometimes I ask them, hey guys, I'm going to pull, I want you guys to pull that block off this week. I'm going to throw an hour on. We're going to work together, right? And I want to see what everybody's doing. So those are the ways I love to promote learning, especially AI, but also just anything. I think that's, they're so excited. One of my staff approached me and said, I think I found a really cool way to do microlearning and I want you to test this sales AI bot and see if we've programmed it correctly.

I took 30 minutes like I was doing a discovery call with a customer and at the end of it the AI's responses were so human like and the output that he had programmed it based on what we had talked about. I'm good in front of customers. I was an 89% and I was like, whoa, that's a B plus, right? So, so what did I do wrong? And it showed me all of these cool things. Like you did this really well, but you could have done this better. Like you could have asked this type of open. I'm like, holy crap. Like, that's sales 101. That's engineering 101. Like and I think we're going to develop that for the trusted advisors now. Like it's instantly going to a budget concern right now. So it's just from him digging in for an hour.

Matt Pacheco
That's really cool. That's some really cool use cases and smart way to approach some of that learning and development. Let's talk about the future a little in our time left. Where do you see the cybersecurity profession heading over the next, let's say three to five Years, particularly as AI tools become more embedded in both offense and defense. But you could talk about anything. What are your thoughts? I don't think you're going to see any major shifts in cybersecurity.

44:55 — The Future of Cybersecurity

Rick Mischka

Cyber's always been an early adopter of any tool that's going to make life a little easier. I don't want to say that we're lazy by nature, we're ingenuitive. We try to find every possible way to make our life just a touch easier. And so I don't know if there's going to be any major paradigm shifts. I think we're going to see incrementals, right. 1% Better everyday type of things. I think we're gonna, I think we're gonna see one thing that we won't prefer. I would love to see. We're not gonna see cybersecurity budgets increase. Instead, that money is gonna be going to artificial intelligence and it's gonna be going to the cloud. I think we're back in that cycle, right? Every, every few years we see this wave where people are like, well, we need to be more flexible, more scalable.

So we need to move towards a co, location or public or private clouds. And we're at that cycle again. So I think we're going to start seeing that as a bigger paradigm shift. And when that happens, I think the big thing AI is going to do is create a way for all of those clouds, the environments, the hybrid environments, all of the tools to talk better. And that's going to be, for me, probably the big shift is how quickly that the AI can be trained to take my entire IT stack and give me minute by minute data on whether that IT stack is doing what it's supposed to do.

Matt Pacheco
Really cool. I look forward to that future.

Rick Mischka
That'd be amazing. Maybe it's a bit of a futurist thing, but that'd be cool, right?

Matt Pacheco
They are very cool. If you could change one thing about how organizations approach cybersecurity from a cultural, structurally or strategically, what would it be?

Rick Mischka
Stop thinking that cyber and IT and all of the stuff you spend on your technology is a cost center. I ask a very simple question, more tongue in cheek. To every organization in the world, I say, could you do your business with our technology? I had one company say, yeah, we think we could. It was a nonprofit. And I said, okay, how do you get most of your money? Well, we get it through like a, a donation site, but we could get rid of that. We could do it by Phone. Phones are technology, Right. So we just. They tried to work every problem, and in the end, I said, unless you're keeping cash under your pillow, you're using the bank's technology to control your money. You're using. There's no way. And so they kind of rescinded, right? They're like, you're right, you're right.

But I hate to say it, like, if you're an organization and you're not realizing that technology is the only reason you're able to support your customers, then you're in the wrong mindset. Kick them out, leadership. Boot them. I don't care what you do. Like, you're not a cost center. Right. That is the biggest myth. Technology, cyber. You're not a cost center.

Matt Pacheco
Excellent. So I'm going to ask you two questions. They're sort of related, but two different audiences. First, we'll start with the IT leader. A lot of. A lot of leaders listen to this podcast. Thanks for listening. What's one piece of advice you'd give an IT leader who's listening right now and quietly wondering what their team, whether their team is heading towards burnout? What's that one piece of advice you'd give them?

Rick Mischka
I think if you're an IT leader and you're not sure if your team or individuals are heading towards burnout, they are. Right? That's the advice, is if you don't know, then they are. Then you're. You're already a part of the problem. The leaders I talk to and consult with, they know. They're actually just trying to find the way to fix it, and that's a much better position to be in. And I know that's a bit of semantics, Matt, I do. But, yeah, if somebody were to ask me, well, how do I identify it? You're already too late. Somebody in your organization is burning out. And so instead I would offer the advice around. Assume it's happening and take the time. Don't. Don't ask them if they're stressed or burnt out. Don't throw that in their face.

Take 15 minutes every couple of weeks and just have a personal conversation. Don't ask anything about work. Ask them what they are, you know, what cool hobby they're going to be doing, what their next big travel trip is. Are they saving money for some cool thing that they want to buy, Nothing to do with work. The responses you'll get are not only optimistically positive, but you're going to start seeing, are they able to give you those positive responses or if they're like, well, I don't have anything going on my kids, you know, in school. Start finding a way to get them developed.

Matt Pacheco
Great advice for someone trying to break into cybersecurity. So you mentioned this a little earlier, especially coming from a non traditional background, kind of like you did or kind of like the service men and women that may break into the industry. What's advice for those looking to break in on building both a technical foundation and mental resilience?

Rick Mischka
Yeah, so I think one, use artificial intelligence to understand what the roles are. You know, in cybersecurity there's I don't know, 50, 60, 80 different roles depending on the job title. In cloud there's more which cracks me up. I do believe that use AI to really understand what your role is going to be.

The data's there, it's easy, you don't have to google it anymore and identify, tell the AI, hey, this is the type of person I am, this is what I'm interested in. What do you think I should focus on? So use artificial intelligence to figure out how you should approach knocking on the cyber door. The second thing I tell people is if you're interested in cybersecurity, there's a couple of free or low cost certifications to see if you're interested. Right. ISC Square is a huge certification body. They have certified in cyber. It used to be $50, I think it's like $150. Now it takes six hours and at the end of it you can tell is this going to be too boring for me or is this going to be something I'm interested in?

If you are interested in, then there's two other things that I would do. First and foremost, if you're super interested, you should go and get your first certification. Should be certified ethical Hacker ceh. The reason for that is it's agnostic. It doesn't matter which field you want to go into, but it actually gives you access to labs to teach you how to be a mini hacker. Man, that's fun. You're gonna have a blast doing it.

And it's a super easy, not easy. It's tough to sit for the exam and actually accomplish it. But a lot of people are doing it in six to 12 weeks and you're doing it part time. It's not a full time position like course. The second part is network. Right. Go and talk to reach out to cybersecurity professionals. If people reach out to me and they're serious and they say can I grab 10 or 15 minutes of your time. I just want to pick your brain. And then they come to me with decent questions. I will always take that time for them. And most of the security professionals in the world will do the same thing, right? We can't give you a lot of time, but we're going to give you some time. Don't approach it as would you hire me?

Approach it as what can I do to put me in a position to be marketed to get hired by you or somebody else in the future if they do it right, if they approach us right and then they follow some of those things and they're really serious about it. I typically see them in 18 months coming back to me and me reaching out to them saying, hey, how are things going? I'm interested. You're doing a really good job. Right? So, so that's what I like to see with people is just network. Be, be confident in asking. So cool.

Matt Pacheco
Excellent advice as always. Last question for you. You host Cyber Pro podcast. Tell us a little about it.

Rick Mischka
During COVID I realized that the world was missing a networking opportunity and I wanted to build a network of like minded security technologists, professionals in the industry. And so I just started a short form podcast. It started out five questions in nine minutes because hackers never sleep. And it was just rattle it off. And then I would take the other 20 minutes to just talk and like learn about that person. I knew I was onto something when I had a great conversation with a woman named Therese. She was an amazing podcast guest. I've had her on multiple times since then. But afterwards she goes on building a cool cartoon program for 6 to 12 year olds to learn how to better cyber mindful.

And I was able to connect her with two other guests I had on and they all funded it and made it a real thing and I knew I was onto something. And so now it's a 30 minute podcast with a lot of short form stuff that we ask the kind of things and that and it's just like my most recent person was just all about how they could help veterans inside, right? I've had people talk about their books, I've had people talk about cloud, I've had you name it. And so for me I have a very rich 400 plus person network just from those guests who have been on the podcast.

Matt Pacheco
That's awesome. You got a new listener right here. So I wanted to thank you Rick for being on our podcast on Cloud Currents today. We're really had a great time talking with you. We learned a lot. So thanks for joining us.

Rick Mischka
You guys rock, man. Thank you so much.

Matt Pacheco
Thanks. And for our listeners, thanks for tuning in. Stay tuned for more awesome episodes of Cloud Currents. You can find us wherever you get your podcast and we will see you soon. Thank you.