Marina opens with what makes municipal security distinctive. Raleigh's team secures roughly two dozen departments, each with different services, regulatory requirements, and workforce realities, including seasonal staff, part time staff, and workers under 16. Her calendar might move from planning and development to emergency communications to Raleigh Water in consecutive hours, which she loves, because understanding how the city serves residents is how her team gives departments the risk information they need to make good decisions as stewards of taxpayer dollars. She describes a shift over the past year and a half toward desiloing critical infrastructure, pointing to the water system attacks she says were widely publicized in late July, and the collaborative network she has built: one of her first calls goes to the Wake County CISO, with close ties to state IT and to CISA, the FBI, and DHS. She stresses helping smaller towns where one person may also sit on the council or serve as the weekend janitor, because as she puts it, we can't be in the basement with our hoodies on.
The center of the conversation is how Marina leads through AI-driven change. She shares four principles: govern at the speed of change, which means her team moved incident response plan reviews to quarterly; read the adversary and use AI to defend; institutionalize the middle, since AI is not going to save us or kill us; and prepare for drift, with quantum already bearing down. She notes her security team has had a seat at the table from the start of Raleigh's AI work, testing frontier models and guardrails before enterprise rollout. On vendors, she asks existing providers about AI observability first, then talks to startups, wanting a partner rather than a vendor. She quizzes vendors with eight identity scenarios, such as telling a human using their own credentials from an agent using delegated ones, noting that identity was always the real perimeter. She notes two of five AI governance vendors she was monitoring got acquired within six weeks, and advises holding out for one year contracts when possible, citing Gartner's guidance.
The back half turns to people. Raleigh is switching awareness training partners to one that generates customized content with AI, because generic vendor content can't keep up with what employees face. She shares a favorite story from new employee onboarding, when an HR colleague described the best feeling in the job: reporting a phishing simulation and getting the congratulations email back. Marina also shares her own path, from a decade of teaching to breaking into development in the early 2000s through business analysis, and offers mentoring advice for women in cybersecurity: bring your own folding chair, be your own best advocate, and learn to tell the story that wins budget in finance's language. She closes by keeping human beings at the center of everything her program does.
Resources mentioned in this episode
This episode is brought to you by CyberLynx.
CyberLynx is a Bethesda managed IT and cybersecurity company. Local techs you know, not a call center. Month-to-month. 24/7 intrusion detection.
We help growing companies with managed IT, help desk, backup and recovery, and a fractional CIO.
Talk to us at https://cyberlynx.com/contact, info@cyberlynx.com, or 301-798-9170.
Why You Can't Commit to One AI Provider Anymore with Matthew Sanders - Ep 242
Your Internal Network Is No Longer Trusted with Michael Foster - Ep 241
Shared Governance in the Age of AI: Keeping the Institution Safe with Bill Guerrero - Ep 240
Guest: Marina Kelly, CISO of the City of Raleigh Host: Matthew Connor
Matthew Connor: Matthew Connor here, host of the Cyber Business Podcast. Today we're joined by Marina Kelly, CISO for the City of Raleigh. Marina, welcome to the show.
Marina Kelly: Thank you. I'm glad to be here.
Matthew Connor: It's great to have you. Before we get too far in, a quick word from our sponsors.
Sponsor Break — CyberLynx: Hackers are using AI to conduct machine-speed attacks. Is your security keeping up? CyberLynx sells industry-leading AI-powered cybersecurity solutions that detect threats in real time, so you know about an attack before the damage is done, not after. Learn more at cyberlynx.com.
Matthew Connor: And now, back to our show. Marina, for those who aren't familiar, can you tell us about the City of Raleigh and your role there as CISO?
Marina Kelly: Yes, welcome to the City of Raleigh. Most people are really surprised to find out we are the thirty-ninth largest city in the country. I don't think people realize how large we are. We are the capital of the state of North Carolina, and we sit at one of the points of the Research Triangle Park, along with Durham and Chapel Hill. So we have a very large and thriving tech community in this area, which means we have residents who are also very tech-savvy, and the city has a really great reputation for innovation and forward thinking, and for how we can best serve our residents, our businesses, and our visitors. We are a very popular visitor destination as well, and we love the city. We're also home to North Carolina State University, go Wolfpack, and Shaw University, one of our historically Black colleges and universities here. Meredith College is here, so we have a lot of variety in both business and education, as well as absolutely beautiful trails and parks. We have Dorothea Dix Park here in downtown Raleigh, which is going to be much like Central Park in New York City, an incredible visitor destination. So lots of amazing things are happening here in the City of Raleigh, which makes my job even more interesting. We have about twenty-three or twenty-four different departments here in the city, and you can think of those departments as separate business verticals. They all do something different and provide a range of services to the city. Our team is responsible for cybersecurity across that whole stack of departments, so we work collaboratively with our colleagues from across the spectrum, we get to know how all these things work, and we help apply any regulatory or statutory requirements they may have in relation to cybersecurity.
Matthew Connor: First of all, I think the tourism board will be very pleased with your response, well done. And secondly, it dawns on me that it sounds like you have the challenge of being the CISO for an enterprise as well as twenty-four smaller organizations all at the same time. Because for a lot of enterprises, you may have a number of departments and verticals, but you kind of have full control over those, and it would seem that's an easier job when it's all one enterprise, versus the city, where I get the impression it's like, I don't want to say herding cats, but, yeah, say herding cats. It seems like that would be a lot more challenging because of the collaboration that needs to happen, versus the control you have in an enterprise. Is that fair and accurate?
Marina Kelly: I tell my friends who are CISOs and work in a single vertical, and I don't want to in any way disparage the work you do if you're working in a single business vertical, those themselves can be incredibly challenging, but there is a unique challenge that comes with working in a city or county government that offers these very unique services to residents and businesses. When I look at my calendar, I can be talking to planning and development, and then the next hour I'm talking to emergency communications, the 911 team, and then Raleigh Water. So any day, it's never the same, and I love that. It's one of the reasons I got into technology, I love this dynamic nature, I love learning about how we provide these services to our citizens. As I like to tell people, I am never going to be a lifeguard with our Parks Department, that's not my career path, but it's important that I understand that process from a cybersecurity perspective, because there are unique challenges that come with seasonal workers, part-time workers, workers under the age of sixteen. So our job is to understand the business the city does, and to help them find the best path forward, providing information and knowledge around risk so they're making the best business decisions they can. We are stewards of the taxpayers' dollars, and so it's really important that they're getting as much business information as they can, including cybersecurity risk, so they're making good choices and we can continue to provide good, effective services for our residents.
Matthew Connor: It sounds like a tough job. Even if you consider security awareness, pushing that out to such a diverse organization is a bit of a challenge, and then not to mention the actual operations of securing them. So kudos to you for taking on the challenge, even from this distance it doesn't look like an easy job, but it sounds like you really enjoy the dynamic nature of it, instead of just having one business to deal with. It's interesting, because when people hear "cities," we immediately think of critical infrastructure, and when you think of New York, LA, Miami, DC, these are all large targets with larger budgets and larger staff, so they have more resources to do the job right. And correct me if I'm wrong, but it seems like as you move down and get smaller, the job gets more challenging for the CISO in those smaller cities, counties, and towns. Imagine a small town that's got a water treatment plant, and that's it. You don't have nearly the budget or the manpower, though generally they have a decent budget, it becomes a really interesting challenge. So when you're talking about critical infrastructure in such a city, what's the approach? Everybody is acutely aware that it's something we need to be, as a nation, hypervigilant about securing and doing right, and it comes with a lot of challenges. So strategically, big picture, how do we go about that as a nation, as cities? If you're not in it, it seems like there's a lot of scary stuff that can happen for people if it's not done right.
Marina Kelly: One of the things I've noticed over the last year to eighteen months in this space is this very important move around desiloing critical infrastructure. In the past, a city or county's infrastructure was their business and they didn't want to talk about it, but what we're finding is that we, as CISOs and cybersecurity leaders, have to talk about this. The attacks on the water systems at the end of July are a really good example, they've been widely publicized, and people were rightly concerned. The geopolitical situation impacts our cybersecurity situation, especially in critical infrastructure, so being able to have these discussions with fellow CISOs and cybersecurity leaders across county and municipal governments across the country has been really important. Knowing what they're seeing, understanding what novel approaches they may be coming across, and getting that information out the door as quickly as possible. We work incredibly closely with our state and federal partners. My first partnership is actually with the CISO for Wake County, where Raleigh is located, she's one of the first people I call if we see anything going on, and she does the same for me. We have a very open dialogue about what we're seeing in our spaces, because if one of us is getting hit, most likely the other one is getting hit, because of not just critical infrastructure, but how connected these systems are across state and local government now. So we have a very strong relationship with the CISO for Wake County, she's incredible, and a really strong relationship with the CISO for the state of North Carolina and her team at the North Carolina Department of Information Technology, which is an incredibly critical relationship to have. We also have really strong relationships with our federal partners, whether that's CISA, the FBI, or the Department of Homeland Security. We work really hard to build those relationships and understand what is happening across the cybersecurity landscape, so we can take that information internally here in the city and understand how it might impact us. The challenge of working in city and county governments at this level, as you said, is when we deal with our smaller counties and cities, many times, as we like to tell people, there are small towns in North Carolina where there's one person responsible for it, and that's not the only hat they wear. They may be on the City Council, they may be the weekend janitor. These smaller towns and municipalities have the exact same threats and issues that we do in a city like Raleigh, where we do have a team, and a City Council and city manager's office that's incredibly supportive of cybersecurity. It's not that they're not in those spaces, they just don't have those resources, so we work really hard in partnerships. One of the great things I saw when I signed in on a couple of calls after the water attacks in late July was this encouragement to reach out to your smaller compatriots, make sure they're okay, see what you can do to help them. That's the approach we need to be taking now, it's got to be collaborative, we've got to help each other, we've got to share what we know, we can't be siloed, we can't be in the basement with our hoodies on. Although I do have one member of my team who I'm pretty sure lives in a hoodie, but he doesn't sit in the basement. But knowing that the world of cybersecurity has changed in the last twelve to eighteen months with AI, it's also changed because of the geopolitical threats growing around us.
Matthew Connor: Well, you raise a couple of really interesting points, and I'd love to dive into both of them. Let's start with the AI transition. I do think you're right, in the last twelve to eighteen months the landscape has changed dramatically because of AI, both for the bad guys and for the good guys, and it's really important and challenging for everybody to keep up with what's going on and how you stay modern against these modern threats. Just one example, we already mentioned patching, and patching used to be something you could rest your hat on, okay, cool, we're fully patched, we're good, and it made sense. Rewind twenty years, and if you were breaking into something, you had to be some sort of elite hacker to find the vulnerability and have that zero-day exploit. Today you just need a keyboard and AI, and you can have a novel zero-day exploit. So I think the landscape has shifted dramatically, where we can't really safely rely on patching like we used to, and that makes cyber hygiene and the fundamentals that much more important. But it also means you can't bring a knife to a gunfight, right? If the bad guys are using AI, we have to use AI to counter that. And part of the challenge is there are so many new AI products, there are AI governance issues, there are privacy issues, there's so much to consider that it can be overwhelming for the CISO who's like, I do have a day job, I have other things to do besides exploring all the products out there, because there are ten new ones every five seconds. So what is the approach the modern CISO has to take to stay up and current and be able to fight fire with fire, instead of saying, well, we're in a five-year or three-year contract on our old stuff, so we've just got to wait it out? I'm not sure that works anymore, especially when you're talking about critical infrastructure. So how do you balance that?
Marina Kelly: Well, you don't sleep a lot. And no, seriously, it is a challenge. Funny story, I went out in early December of last year to have knee replacement surgery, and when I came back to AI, it was literally seven weeks. It's that fast. So one of the things is that you have to change how you work as a CISO in this space. There are four things I tell others that, for me, I've found to be true. First of all, you have to govern at the speed of this change. The idea that you're writing a policy or a standard and you're going to check it annually, just throw it out the window. We've moved our incident response plan reviews to quarterly because of how quickly things are changing. At that speed of change, you have to look at these policies and standards much more rapidly, and your change approval board processes, all these things have to be adapted to move at this speed. And so again, you're right, we're holding this weird tension, the fundamentals are still important and we still have to do that, but we also have to do this at the same time, so changing governance is really important. Second, you have to be able to read the adversary. Again, to your point, they're using AI, we have to understand how they're using AI, and then we have to be able to use AI to help defend our organization. That has been a really interesting dynamic here in the City of Raleigh. We have actually been really lucky in information security, we've been at the table from the beginning, which is not always what we see happening in organizations when it comes to AI. We've been there early, we've been able to work with these tools before they get out at an enterprise level, to understand how we have to harness frontier models, for example, and what guardrails now have to be in place, what is different about working in an AI space, while also being able to blend this in, because eventually AI becomes the technology, that's where we'll be living. Third, we have to institutionalize the middle right now. There are these giant pendulum swings, either AI is going to save us or AI is going to kill us. Let's be honest, it's not going to do either one, we have to live in the middle, we always land in the middle, and that's where we have to work from. So it's about helping your organization through that dynamic of what are we really looking at here, and how do we pace that in a way that is going to be adaptive and adoptive for the organization. And then finally, you have to prepare for this drift, it's going to keep changing, this is not going to stop, and quantum is bearing down on us as well. So adapting and changing our infrastructures, from our governance to how we even structure our personnel, is all up for discussion now, because it changes so many things. So those four principles are what I'm finding is working for me as a CISO in a very chaotic space.
Matthew Connor: It makes perfect sense, I think that's really great advice. One of the things I get really excited about, because we are in that transition time, is that I find it exhilarating. A lot of people don't like change, and that's why we see those extreme views of, it's going to kill us or it's going to save us. And I think you're spot on, and not enough people really say this, it is going to be somewhere in the middle, it's not going to be on the extremes because it never has been, and it's doubtful it'll be any different this time. As we start seeing AI growing and changing, we see really cool stuff like self-driving cars, where just a couple of years ago it was a cool assist, it was interesting, a few years before that it was dangerous, like a drunk toddler, and now it is statistically eight times safer than the human driver, which is a hundred percent accurate, I've seen it myself. I think that's a really great physical-world example of how AI has grown and changed and improved, and you can see the trajectory of where we're going. It makes it pretty obvious, we've always had this vision of flying cars and self-driving cars, but the technology wasn't there, and now we're on the cusp. And I think the same level of technology applies when we get to cybersecurity, where we're not there yet, but you see it in a lot of the industry-leading products. You take a look at things like Darktrace and Abnormal Security, where you're using machine learning that's been around for a long time, a form of AI, in the right way, to provide defenses against these modern attacks, and it's super cool to see that level of improvement. Is it the end-all, be-all, where you push a button and everything is secure? No, not even close, we may never get there, but where we are now, just like the frontier models, is so much cooler in these last six months than it was six months before that, or a year before that. I'm an AI optimist, so I do think the good guys ultimately win, but it is an arms race, a game of cat and mouse, we cannot just rely on old techniques, we have to constantly keep evolving and keeping up with the times, which is in and of itself challenging. So the challenge is, I'm a big fan of the Gartner Magic Quadrant, and some people say yes, some say no, but how else do you, as a security professional and a leader, filter through all the options out there, because there's only so much time in the day? Which of these are we going to try or examine? I think this becomes a real-world issue for leaders, how do we filter through all these products to get down to the ones we're going to evaluate, and the ones we're going to choose. So what's your advice, the filtration in this modern-day onslaught of products?
Marina Kelly: Actually, one of the things I find works really well, because the challenge we have in this space is that it has moved so quickly that vendors have not been able to keep up with it. So as we stub our toe on something, our first ask is always to our existing vendor set, do you guys have anything for observability in AI, so we can see what's happening? Some do and some don't, and some have it coming. And then what I'm seeing is that when it comes to this AI space, you're going to have to get out of your comfort zone of working with legacy vendors and actually talk to some startups, because sometimes they're the ones who not only have a product that can address where we just stubbed our toe, but are able to more rapidly evolve their products and build partnerships. One of the things we always talk about when I meet with vendors is, I don't need a vendor, that's very easy. What I need is a partner, someone who's going to listen to our situation, because working in a city, especially a city like Raleigh, we have some unique challenges, so having a product that's flexible enough, and a partner that's willing to work with us to understand it, is what we have to find. At conferences, when you walk the vendor floor, go talk to some of these startups and see where they are in this space and where they're going. We are a Gartner client, and when I have these discussions with my analyst, they are very blunt that right now there's no one product or platform to rule them all, you're going to have to bring a group of products together to do AI governance now. But that is changing so rapidly that between my first discussion and my second discussion six weeks later, two of the five we were monitoring got bought. So there's going to be a lot of M&A activity in this space, and you still have to continue to move. To your earlier point, you cannot just sit there and wait for it to shake out, because nothing is waiting. Our employees aren't waiting, our residents aren't waiting, everybody's moving at this speed, and it has expectations. So you have to build these relationships, and these relationships take longer to build, and you do have to do your research. But one of the best research tools you can use is honestly a frontier model with a great prompt, to help do that research of the current landscape and vendors in this space, to understand where you're even ready to start, because they do seem to be popping up like mushrooms. We have a running joke on our IT team that we could just be building our own products and selling them and then retiring, which of course we can't do, the city would own them. But it feels like the dot-com era again, it feels like cloud again, we've seen this play before. If you've been around long enough in this space, we know what's going to happen, it's that hype cycle Gartner talks about. But you do have to be able to ask the right questions. Identity is a really good example of what has significantly changed under AI. People used to say your network is your perimeter, and now we know, nope, it was always your identity that was your perimeter, whether you wanted to admit it or not. So I actually enjoy sitting down with a vendor to talk about their products, and I ask questions like, okay, how in your product can I tell if an action was taken by a human using their own credentials, versus an agent using the human's credentials that have been granted, versus a human who's been granted agency by an agent, versus an agent who's granted agency to another agent? I go through a list of eight scenarios of identity that, from a digital forensics standpoint, we now have to be able to trace back to understand what really happened. And you get some really interesting responses from vendors right now, either no one's ever asked us those questions, or here's how you do it, but it's looking through the logs, or we do have something, but it's only this subset of those questions. So you have to be flexible, you have to be willing to say, you know what, sometimes I may have to go with a startup and evolve with a startup at this point, because the legacy vendors, that's how they're doing it, they're buying a lot of these startups and bolting them on for you. So I'm enjoying this, it's great relationship building. My background is application development and database administration, I'm not a network person, I came through IT a different way. I did my master's degree at UNC Greensboro, I was fascinated by AI, we were already talking about that when I did my degree, and I've just been fascinated watching this evolve and understanding it from the computer science lens of what's really happening. So maybe that's why I land more in the middle of this, again, it's not going to kill us or save us, I understand what it is. It's just fascinating to talk to vendors because I understand where they're coming from, I've worked for these vendors before to help build and design these systems. So it's a whole new world, you never have the same day twice, you do the best you can, and you reach out to your colleagues and talk to them about what they're doing, which is also very important right now.
Matthew Connor: I think that's really good advice, and you hit the nail on the head there. When interviewing these different vendors, what's really interesting is how, and I don't want to say all, but a lot of legacy vendors, I don't want to say they're resting on their laurels, but for so long this large ship was built this way and works this way, and it's really hard to turn a large ship quickly. So I think there's a middle ground. I love startups, however, I'm personally a little more reluctant, because I know ninety-five percent of those will not be here next year or the following, and I don't want to invest time and money into something that maybe doesn't make it financially, or gets gobbled up and changed, or gobbled up and snuffed out. So I tend to land more in the middle on that, not that one is better than the other, I'm just a little apprehensive, but I love the space. And I think what you said was really great, when interviewing these vendors, talking about how flexible they are, how willing they are to make changes, and how quickly they can do it. I think the modern vendor needs to be as nimble as a startup, because why the hell aren't you? You've got AI, you can just as quickly develop this feature that's being requested, as a startup. So either you want to do that or you don't, or fundamentally, because it's a legacy product, you simply can't add these things, and it's just fundamentally not going to work for the future anyway. But for an AI-first vendor, I think you've nailed it, that's the question. I don't care what your size is, I want to know, when I have this idea and this need, how quickly can you implement it? And if the response is, oh well, we don't really do that, or it's going to be really hard, and if the salespeople are saying this, then you know it's never going to happen. And at the same time, if a salesperson says we can do it in six hours, take that with a grain of salt. So how do you balance that, because salespeople will say anything to get you to sign the contract that says we're not making any damn changes to this contract or this product for you? Is there a balance, do people try to put it in the fine print, will salespeople just tell you anything? I think you're onto something and I think people should be doing that, I think that's the modern way, but how do you guarantee that what the salesperson says is what the ops people are going to do?
Marina Kelly: You do get to become a bit of an expert in startups and entrepreneurs and understanding series funding and that sort of thing. One of the things I always look at is, where are you in your series funding, who is backing you? I'll ask our existing vendors who they're watching in this space, and sometimes they'll tell me, sometimes they won't. But when you get to the contractual part, one of the things you'll find is that a lot of these startups no longer offer direct sales, because they're lean. They do not have a sales department, they have a marketing department. So you're going to be going through some type of contractual relationship discussion, and if you're in government, you may be the first government client they have, and that's a whole other beast when it comes to procurement. So making sure you read the contract is key, and one of the things we've done here in the City of Raleigh is develop our own contract template that we put in front of a vendor, and if they're willing to work with us on that, that's where we would prefer to be. And because we work in government spaces, we also have certain contractual vehicles from other government entities that we can use to help us. The challenge is always going to be that you can't go into a contractual discussion with a company that's going to take you six months right now, because by the time you get through it, they may have been acquired, the product may not be there anymore, or the product you needed at that point may no longer be the product you need, and so you just end it and say, you know what, I'm going to go over here now, because this is where we need to go. It's fun. One thing I enjoy about this space is that it's also an opportunity to change some of the ways we've done business in the past when it comes to our tools. And Gartner is recommending right now, do not sign more than a one-year contract. They're going to offer you some really great deals for three or five years and that sort of thing, and sometimes you may not have that choice, that may be how you can afford a product right now, but if you can hold out for the one-year contract, do that, because you may need to change. And again, it's working internally as well, to understand how you're going to learn to swap products out faster. In just the last couple of months, we're switching out our security awareness training and phishing simulation partner, so we've had to learn how to do a very quick switch, to take advantage of a product that allows us to create our own content in real time using AI. This is really important, because that's what we know works for security awareness training, it's got to be customized, it's got to speak to your employees. A lot of these legacy vendors' content can't keep up with that, but we can, if we create our own, because we know our employees, we know what they're saying, we know what they're having to face. Our job is to make sure they have the tools to fight back, they're our first line of defense. We don't have a very large information security team in the City of Raleigh, but I count all forty-five hundred employees of the City of Raleigh as members of our information security team.
Matthew Connor: And I think AI makes it so a small team is now a much larger team, that's just the reality. The mental load that existed for any information worker three or four years ago, even last year, if you leverage AI properly, you're doing far more and you feel a lot better about it. The juggling and keeping things in your head, what's stressing you, that's a problem now, as far as I'm concerned, and for the majority of the modern workforce, the goal should be to offload that worry, am I replying to all these things, is something falling through the cracks of my fifty things on my to-do list and all these projects, is it all happening and are we on time? Why are you stressing, let AI do all of that, and I think that makes the workforce so much happier and so much more productive. I think it's the greatest thing since sliced bread, it's phenomenal. But I'd like to go back, I know we're cutting it close on time, but you said something that was really great for me to hear. You said that the county and state CISOs were both women. And I think what we see in the field is that it's a really challenging industry as a whole for women. I've got two daughters, one is graduating from the University of Maryland as a computer science major, and she's got her job offer next year at Bloomberg as a software engineer, and what I've seen is a really challenging environment for women. I'm surrounded by these really strong and powerful women, and they've opened my eyes to the world, and I get it. You grow up and the world treats you a certain way based on who you are, and often we don't really get to see the world from somebody else's perspective, and I'm starting to see the world more from this perspective. To hear that, I think, is really fantastic, because I know there are so many challenges to get there in the first place, and the environment, I don't think, is really conducive to it. So I'd like to spend a little bit of time talking about this, because I don't think it gets nearly enough attention, and I think it needs to come from this side of the table more than your side, the guys need to hear more. Not how you can be an advocate, but they need to have their eyes open to what's really going on, not just the world as it appears to us. So I'd love to hear your story, your thoughts, and your advice on that, if you don't mind.
Marina Kelly: One of the great things about living and working in Raleigh is that we have this amazing group of female CISOs who work in this space, both in government and private industry, and we have built relationships because of that. The CISO for the State Board of Elections is a woman, one of the main people in cybersecurity in the UNC system is a woman, our Department of Employment Services' CISO is a woman. We recognize each other more quickly because there are fewer of us than you'd expect. It's kind of a running joke when we go to a conference, you never have to worry about getting to the bathroom, because there's never a line in the women's bathroom, since there are not as many of us in these spaces. To your point, why that is is a whole issue of history and opportunity and things like that. I do a lot of mentoring, a lot of mentoring of women who want to work in this space, and the things I tell them that are important, and how I got where I am. I started out as a classroom teacher, I didn't even start out in technology. I was a classroom teacher for ten years, and then decided it was time to really follow what I wanted to do, which was computer science, and so I did my master's in computer science. I do not recommend doing a computer science master's if you didn't major in computer science as an undergraduate, but you can do it. And I came out in the early 2000s to a space where it was really difficult to find a job as a woman in development, it was very much that developer bro culture. So sometimes, and one of the things women are great at, is looking at the situation and determining a different way in. What I was good at, because I had been a classroom teacher, was that I could write well and I could listen. So my foot in the door was actually being a business analyst and project manager, because I could write well, and because I was a trained developer and database administrator, I could write for our clients, but I could also write the documentation that needed to go to our development teams. It didn't take long for developers to realize I knew what I was talking about, and that's where I grew my career, in this space, instead of being a developer. And as I was able to grow in that space, I was able to grow into leadership roles, because again, I had this unique set of skills. That's what women often bring to the table that I think people don't understand, we do often bring this really unique conglomeration of skills from our experiences. A lot of the women I know who work in this space, who are CISOs now, didn't start out as technologists, or if they started as technologists, they started in things like electrical engineering, so they had a strong technical background, but were able to layer onto that their ability to build relationships and communicate. Those are the skills that are going to be really essential for CISOs moving forward. There's this amazing debate that happens in this space right now, about whether you have to be a technologist to be a CISO, because there are some really amazing CISOs who are lawyers, who come from a governance perspective versus a technology perspective. I believe you don't have to have been a technologist, but you do have to have curiosity and the ability to learn about technology, because you do have to have technical discussions. For example, if I'm talking to a department and they want to use tablets in the field, I have to be able to talk about how we authenticate a tablet in the field so that it doesn't log out in the middle of whatever is going on, and how we do all that, understanding near-field communications and that sort of thing, to understand what we could use to help them. So there is some technology that goes with it, but the other thing is hiring really good people who are also amazing technologists to help you carry that. You should never consider yourself the smartest person in the room, and if you've done that, you've hired wrong. But for women, know that being a woman can actually be a strength and can make you stand out from a crowd. And sometimes you may have to speak louder. I always love Shirley Chisholm's quote, that if you're not given a seat at the table, then bring your own folding chair. Sometimes that's what you'll do, you insert yourself into spaces where you know you can have a positive impact and people will notice. I don't care if you're male or female, doing really good work without being able to share that you do really good work is not going to get you anywhere. You have to always tell people, you are your sole, single best and consistent advocate, and being able to do that, you still have to stay humble, but you have to be able to talk about how what you've done in your workspace has had a positive impact on the organization, and build those relationships so that others can see it. And don't let your gender hold you back from anything. I grew up with three sisters and a father who I always said was the first feminist I ever knew, because he knew his daughters could do whatever they wanted, and he was going to make sure of that. He made sure we had access to activities, and that we went to school, and that we were going to college. I knew I was going to college the first day I started kindergarten, that was made very clear to me, you're going to college. All four of us went to college, all four of us built different careers. So building relationships, knowing that this can be more challenging and more difficult, but having others to lean into to help get you through those harder times. Know that you are unique in what you do, and that you have to be able to tell that story. Being a storyteller is another really important skill for a CISO, especially when you're trying to get budget, because your budget and finance group does not want to hear how many password resets you did last week, even though you know how important that was and you understand that impact. They don't care, because it's not what they understand. Being able to speak to them in their own language, their own vernacular, and tie it to a business outcome and risk, is what you're going to have to be able to do. So find your tribe, lean into your tribe, build those strong relationships. Never let anyone tell you that you can't do it, unless you want to be an Air Force pilot who's colorblind, because that's not a thing. But otherwise, you can do pretty much anything you want to. It will be more challenging, and there may not be a straight path to it, you may have to veer off and come in and out of it. In my career, I have moved jobs to move up, and sometimes that's what you have to do. I've gone between public and private throughout my career because that was the path that let me build my leadership skills and build up to becoming more of a CTO and then coming into the CISO role. Very few of us have straight paths anymore. Understand that you may change careers, it may come back to this, but stay curious, stay hungry, and don't let anybody deter you.
Matthew Connor: I absolutely love that. And I think the challenge, especially in the technology world, is that one of the things that attracts us to technology is the technology, and so we tend to be a little geeky, men and women, we like the technology, it's fun, that's what drove us there. I think that can often be a distraction from the more important, as you said, communication and relationship-building skills. Those skills, I think, are paramount for everybody in every industry, and should be the foundation you build off of, because without them, you can be the greatest engineer, the greatest technician, the greatest operator, whatever it is, and as you said, you're your own best and only advocate and you have to be good at that, because if you do great stuff in a vacuum, it doesn't matter. It's not going to get you a raise, it's not going to get you any recognition, you're just doing great stuff, and if you're working for a company, you will make somebody's company richer and them better, but it will not benefit you. Not that we should only be out for ourselves, we should be working toward the common goal, but you've got to have those communication and relationship-building skills, which you put so eloquently. I think that is phenomenal advice. I can't thank you enough for coming on and sharing all this with us. I'm going to give you the last word, if you want to add on to that, please do, but I think that was just so well said.
Marina Kelly: Well, thank you. I'll end by saying this: cybersecurity touches everyone, whether they know it or not, and part of our job is helping people see themselves in cybersecurity, whether that's in the job they're doing, or at home, as a hybrid worker, understanding how their own home network setup can impact cybersecurity. This is becoming more and more relevant to people, and we often see cybersecurity and privacy conflated, and that's okay, because they're very similar in what they're trying to do, both regulated, both important spaces. So helping our employees here in the City of Raleigh see themselves as security champions and understand the positive impact they have every day. I always get tickled when I talk to people. I just did the new employee onboarding session on Monday for this month's new employees, and one of the people from HR, who was leading it, said, we were talking about the phishing simulation tests we do here in the city, and she said, one of the best things that will ever happen to you is when you get a phishing simulation, and you hit that report-phishing button, and a few minutes later you get back the email that says congratulations, you did catch it. That will be some of the best feeling you ever have. That's important to people, they need to feel a part of it, especially in the public sector, where that servant heart is what often drives us to this space. It ain't the money, it's this need to do good. So I think if we keep human beings at the center of everything we do, even though what we do is very technical, very regulated, it's still, at its core, that what we are protecting is those data points that make up a human being. And if we don't lose that, then I think we make the best decisions in how we create and evolve cybersecurity programs.
Matthew Connor: Well said. As always, Marina, I cannot thank you enough for coming on today, this has been an absolute joy. But before we go, can you tell everybody where they can find out more about you and more about the City of Raleigh?
Marina Kelly: So if you want to know more about the amazing City of Raleigh, NC, you can check us out at raleighnc.gov, that's raleighnc.gov. And no matter what Ocho Cinco tells you, it is Raleigh, NC. If you want, feel free to find me on LinkedIn, I'm very active there, I love that, it's another great way to build community. So you can check me out on LinkedIn, and I'm always happy to talk to people about cybersecurity, give advice, and collaborate, which, again, as we said very early in this podcast, is a key component to having a successful cybersecurity program.
Matthew Connor: Well said, Marina. Thanks again, and until next time.