About David Czeszewski
David Czeszewski, Senior Vice President and Chief Information Officer at Perdoceo Education, discussed his approach to cybersecurity and IT leadership in a September 2022 panel. He stated that he eliminated the dedicated information security team, making security a responsibility for all employees through performance objectives and bonuses. Czeszewski said that cyber insurance has become difficult to obtain at reasonable rates, as insurers require measures like multi-factor authentication. He noted that his board is "very advanced in cyber" and that he reports to them quarterly, adding that projects related to cybersecurity are typically approved.
In earlier podcast appearances from September 2020, Czeszewski described his response to the COVID-19 pandemic, including adding 1,700 computers in four days and purchasing mobile hotspots to enable 100% work-from-home by March 21, 2020. He said that Amazon Workspaces was critical to this transition and that the company's culture, set by leadership, contributed to a smooth shift. Czeszewski also discussed his leadership philosophy, emphasizing the importance of balancing "challenge, compensation, and culture" to retain talent, and advised that executives should give direct answers rather than lengthy explanations. He described the CIO role as requiring technical, business, and people management skills, and said that during the pandemic, technology enabled the company to maintain operations and potentially save jobs.
Source: AI-verified profile updated from David Czeszewski's recent appearances.
Browse all interviews →
Transcript (31 segments)
M
Moderator0:05
We want to now focus on the CXO panel. The goal is to have the CSO from Motorola Mobility, Richard Rushing, and Dave Czeszewski, CIO of Perdoceo, talk about the state of security, what's happening in the world of security, what their jobs are like, the problems they're trying to solve, but also what is working. A lot of stuff in security is very hard and doesn't work great, so when customers are doing something that works well, we want to share it with the rest of the group so you can get some best practices and hopefully something actionable after this event. Chris will run it. I just want to take a moment to properly introduce these guys. They both have long tenure in their organizations, which is very rare. That speaks to the fact that they must be doing something right. So first, please welcome Dave Czeszewski, CIO of Perdoceo Education Corporation, for over 21 years. He brings a very technical perspective, advises the venture community and startups about technology trends, and has a strong background in security. Also, let's welcome Richard Rushing, future information security officer at Motorola Mobility. Richard has a long background in security with companies like Siemens, GE Capital, and VeriSign, and for the last 13 years he's been building a world-class security organization at Motorola.
D
Dave Czeszewski2:40
So, I have those here. I apologize because I was prepared for this meeting. The number one priority is to keep the trains running. Besides innovation, besides projects, you gotta keep everything going. That's number one. Number two is to manage risk: compliance, cyber, operational, corporate. That's number two. Manage the money well; you can't spend too much money. Probably number one, and I didn't put it here, but provide excellent student support. We provide online education for about 45,000 students paying us money. Very much like Netflix or other SaaS companies, provide excellent support when they need it, deliver on projects, focus on culture, and drive innovation. That's what I just listed are the objectives I give my CEO, and that gets distributed to my team. So those are my top-of-mind concerns.
R
Richard Rushing4:44
It kind of changes depending on how rapidly it changes, and it changes within a reasonable window. Are we out of the log4j thing? No, I don't think so. That's part of the issue: the goalposts get moved all the time. But the classic is that our parent company, Lenovo, has visions of being innovative, providing innovative technology and services to support businesses and consumers worldwide. That sounds like a nice fantasy, but at the same time, it's about customer data, supply chain to make sure everybody has PCs when they need them, especially in the world of COVID and supply chain theatrics. We're a total organization of 71,000 people doing $60 billion in revenue. You can imagine there are a lot of different parts and pieces across four business groups. We're trying to manufacture that Motorola is the number three cell phone manufacturer in the world. Congratulations. I tell everybody, can we move back down the line because that makes us less of a target? If you're in the top three, you're always the target. So you run into different things: protection of intellectual property because things we create and make are very dynamic and can be leveraged. We operate in 147 markets around the world, so there are huge risks. We manufacture in 14 different locations globally. We want to be seamless as part of security, and that's the hard part. I don't want to create friction—everybody uses that word, so they need to come up with a better one—but especially where our gross margin on products is typically around 3.5%, if you add friction, that becomes 1.2%, so every product you sell you lose money. That doesn't work. As far as innovation, we play a large part in biometric facial recognition. Would you rather type your password 14 times to log into your PC, or swipe a fingerprint or be recognized by your face? Or always-on connection using 5G networks to have your laptop always connected to the corporate network without VPN shenanigans. The Internet is a dangerous place; it was in the 1990s and the 1970s. Dealing with that is critical, and how you deal with it is more important than ignoring it. How I do something about it is the big concern.
M
Moderator9:01
I appreciate the fact that you're slowly helping us get rid of passwords. I didn't want to ask about challenges you guys are facing that maybe you don't have an answer for or a gap in the market. Where do you see the challenging side? What are the barriers?
D
Dave Czeszewski9:41
For us right now, cyber insurance is a big deal. Just trying to get cyber insurance coverage at a reasonable rate seems very difficult. The insurance companies figured out they're taking on too much risk, so they hired the right people to do the right analysis to figure out the risk. So that's number one. Number two, cyber in general. New acquisitions as we acquire companies that add to our portfolio provide challenges. My corporate function wants to keep everything the same, and as you acquire, that's difficult because it's expensive to convert. Why change the acquiring company if you don't have to? Cyber insurance is really different now. A couple years ago, they would just underwrite whatever, made the environment right for criminals to attack, and then they got paid. Now they're like, we're not going to pay, so you're paying two, three, four times the premium for 50% coverage. That's a big problem. My team feels that because insurance companies got smart—they hire people who know what they're doing—they're evaluating your risk externally. It's probably the best pen test we've ever had, and we had to react, which is good, but they're not going to insure you unless you're 100% with MFA across the board: VPN, email, Teams, Zoom access. MFA, MFA, MFA—that's what they want. That's my biggest concern right now. But the biggest challenge in a CIO world is keep the lights on first, make sure stuff doesn't go down, then make sure requests get handled, projects are done, and manage money and risk. If you don't get the trains in on time, you're going to get fired. Once you do that, everybody can give you credit and build upon that. When I started, our load time for web applications was 10-12 seconds; now they're below a second. Get the easy stuff off your plate and figure out how to improve the business. If you have stuff dragging you down on the easy stuff, you're never going to improve.
R
Richard Rushing13:54
I always carry around two sticks with me for your exact question of wider things. I use it all the time in senior leadership: I need people and I need more money. Those are the two things that always come up. Why? If I want to do more, what am I supposed to ask my people to stop doing? That's my choice. Either I ask you to stop doing something, or you don't mind working 80 hours this week, and that's your other answer. If I do that, staff will leave. So I need more people. I need money because the Internet is a dangerous place and it's not getting easier to attack. There are tons of holes, and I have to plug them with technology, a solution, or a service. If the budget last year did 10% of the holes, guess what? There are 10 more new holes that have popped up. Cloud, API, you can name them all. I need money to do it because I either stop doing something or I continue doing things but need more. I need people and I need money. It doesn't work any other way. If you have money to spend, there's a people element to that money. You have to do things, and doing things costs money, and it costs people. You just don't magically reduce things. Like energy, it just transfers and moves around; it doesn't really reduce.
M
Moderator16:05
Are you seeing that, since we've seen so many high-profile attacks, the board or senior management is more sympathetic and allowing more money to flow?
R
Richard Rushing16:30
Definitely. For the last few years before COVID, I was like, this is the golden age of cybersecurity. I've been doing this my whole life and in executive roles for most of that. The hardest part was always convincing senior management there was a problem until around 2014 when the Wall Street Journal, Forbes, and Fortune had articles daily about attacks. Then Microsoft, Google, Facebook, Bank of America got hit. They said, wow, those are huge companies with huge staff; how are we going to compete? You're not. So you solve the problem of convincing them there's a problem, but then they want a plan and to know how you'll execute it. As long as you have that plan, they're on board. If you just say, I need $10 million, and they ask what for, and you say I don't know, that never works—except maybe for marketing guys.
M
Moderator17:56
Dave, are you seeing more money flow with all the visibility into security?
D
Dave Czeszewski18:15
Anytime I put a project towards cyber, it's approved. The best thing about being a publicly traded company is that the board is personally responsible if we get breached. So they're very interested in getting that stuff done. But to be honest, our board is very advanced in cyber compared to most. I'm very honest with them about our situation—it's good, but we could get breached tomorrow. We're one week away, so we have to be prepared. I report to the board every quarter on cyber, and then every two or three months to the entire board. Our board is very interested because, quite frankly, their asses are on the line.
M
Moderator19:42
You mentioned that if you put 'cyber' in front of anything, it seems to get approved. Is there a magic phrase when you go to the board?
D
Dave Czeszewski20:00
It's whether it's a nice-to-have or a must-have. When I go to the board, credibility is key. I've been in this business for 36 years, with my company for 21, CIO for nine, and divisional CIO for two. When I go to them and say this is a must-have, we usually get it. But the CFO and CEO approve before I even take it to the board. They trust me when I say it's a must-have or a nice-to-have. A nice-to-have doesn't get done. Abnormal came up as a must-have within a week, so we did it. Credibility is paramount. You're a businessman first, a technologist second. Always the business first. You're there for the fiduciary responsibility of the company and your customers, and your investments must be in line with their best interest.
M
Moderator21:55
Richard, is there a phrase that pays for you?
R
Richard Rushing22:12
No phrase, but there are power points. We define high-level risk buckets: brand security, customer data, factory shutdown. We align projects around those. We typically work on 20 to 30 projects annually, but I list 40 items that are part of the big buckets. Some items I'm not covering, and I highlight that. They ask why it's red, and I say, 'We're not doing anything about that.' They ask why, and I say, 'I need people and money.' That's my two sticks. Then I show a chart with likelihood and risk. For example, factory shutdown from ransomware: last year it was lower because ransomware hadn't reached critical mass. Now it's up, so what's going to bring it back down? What's my arc of risk acceptance? If I show it above that arc, they want to know how it will come down. I say this project here will lower that if you give me a million and a half dollars. They say okay. In three slides, they get it. When you simplify and visualize it so they can understand, you're not arguing pricing or deployment. It becomes a simple conversation: is this the right thing to do? You say it's the right thing to do, and trust handles the rest. Then they say, 'Can you make a couple of these red things not red?' and you say, 'More money.' It helps.
M
Moderator25:04
You've both touched on prioritizing risk. Dave, you mentioned Abnormal Security as a success. What are some things that have really moved the needle for you?
D
Dave Czeszewski25:39
ServiceNow—we were the number two customer in Chicago back in 2009. Cohesity for backups. Abnormal, of course. There have been a lot of things we've adopted quickly, like Varonis, which I think we were number one in Chicago, helping with file security. Adapting slowly to Azure was good because a lot of people rushed to the cloud. We did it with business sense, tested things out. Email was slow, but now we're about 50% cloud. We'll eventually get there, but only when it made sense. It wasn't a board strategy of 'go cloud by X date.' Operational risk is very important to me, eliminating it on IT projects. My team hates when I ask, 'What value is it for the business? Is it an IT project that makes our lives easier, or a business value project?' Often it's a value project.
M
Moderator27:50
Richard, what about on your front?
R
Richard Rushing27:56
We did a couple of things pre-COVID, ahead of the curve. We focused on endpoints as the weak link. We had over 100,000 endpoints on our network that come and go, and we didn't have much control besides AV or patching software. So we took ownership of the patching process from IT. We used the same tools but wanted to own it because we didn't believe they were doing the job well enough. We really focused on endpoints, from patching to everything else. We also went back to the classic of taking a step back and getting basic hygiene right. Before you clean, you need to know what you actually have on your network. If you don't know that, how can you protect it? That includes vulnerability scans—are you just scanning the data center, outside in, or inside out? We took that step. As a hardware company, you can just imagine, if you need a new computer, there are boxes of them. You take one out, it has no software, isn't on the domain, and now sits on the network in disrepair. One of our big successes was creating a security ecosystem early on. All the tools have to interoperate. If I decide to block a hash or IP address, it's one place, one button, and it goes everywhere. It's not just that everything logs correctly. You have layers of security that work together so if I need to stop something, I can do it at multiple places. For example, blocking on the firewall worked until everyone went home. Then you can't block on the firewall for endpoints. So you decide: is the AV, EDR tool, or Windows firewall the right place? It depends on what you're trying to do. That was a big win, saying all tools must interoperate. I remember when no tool interoperated with anything.
M
Moderator32:32
You're touching on operationalizing security, which is so missing from many organizations. What tips and techniques are you using? What's the secret sauce?
R
Richard Rushing33:12
I appreciate the focus on operationalizing because it's often overlooked. Part of it is considering how many FTEs it takes to run a system. I've had products that require three FTEs when I don't have that. If something needs more than a half-load of 20 hours a week to keep it running, that's a problem. So operationalizing includes how much time and care and feeding something needs. Does it do automated updates for clients? How have you not figured out that I don't want to have to load your software on every endpoint? That simplifies it. Also, look at the thought process in the dashboard. How many clicks does it take to get to the data you need? One click, two clicks, three, four, then export to CSV? That's not operationalizing; it's a pain in the ass.
D
Dave Czeszewski34:56
The best thing I ever did was eliminating the information security team. I made information security everybody's job and put it into objectives and performance bonuses. It had nothing to do with structure. Now everybody thinks about it, and nobody blames information security for not doing their job because I blame the owners for not doing theirs. We went from 2015 to now, and we're a hundred-fold better. It's making everybody responsible for their own job: software development, QA, email, AED, information security, network. Everybody was blaming that they don't have enough, but it's all our jobs, so just get it done.
M
Moderator36:36
That leads into creating a culture of security and finding and retaining talent. Dave, how do you create that culture?
D
Dave Czeszewski37:23
Security is everybody's job. It has to be built into everybody's job. There's no such thing as a security person—there are people like Tony who operate security-focused tools, but everybody needs a security focus. To attract talent, you sell people on your mission. We're in education, graduating first-time learners and their families to go to college—people who never even knew what college was. They're changing their lives. That's the mission. You could work for anybody. We lost a person making $X who went to ServiceNow for a 50% increase, then got recruited to Facebook for another 50%, and hates their job because there's no mission. We provide people who change their lives through education. Society is better for us.
M
Moderator39:28
Richard, how do you create that culture and attract and retain talent?
R
Richard Rushing39:41
There are multiple ways. You have to have a mission or direction, but you also need to claim your wins and the hard work people do. In security, it's all about what broke. You never talk about all the stuff your technical infrastructure stopped. You highlight what got through. On an average week, our data center in Chicago blocks over a billion bad attempts. People are amazed, but they want to crack me open for one thing that got through. You have to win and be passionate. Also, discover what your individual team members' missions are. What do they want to be when they grow up? Do they want to manage people or not? You build around their goals. I give a training budget of $15,000 per team member to spend how they want. In my tenure at Motorola, going on 15 years, the core team I adopted 15 years ago is still with me minus one person who retired. People get to retire and come back as consultants.
D
Dave Czeszewski44:11
The role is becoming much more strategic. If you don't hit your revenue goals, you get fired. If you don't hit your technology goals, you get fired. That shows the importance of the role now. I agree 100% on culture. Our average tenure is 11.5 years. You do that by treating people with respect. The job is important, especially in an online revenue community where we're a SaaS-based application. If you don't deliver, you're going to get fired.
R
Richard Rushing45:34
We got dragged into this from a security standpoint. Other departments like sales and marketing present their wins—revenue targets, how much money they made. They don't say how many deals they lost. Marketing talks about impressions, not how many people didn't click. We inverted our newspaper. Instead of page one showing all the stuff we stopped, we take page six, the obituary, and show who died.
M
Moderator46:30
If you could go back to the start of your career and tell that person one thing, what would it be?
D
Dave Czeszewski47:25
I learned more about what not to do than what to do by observing people. I built my career from learning what not to do. There were some outstanding people I learned from, but it was also about what not to do.
R
Richard Rushing48:09
Don't blow up at board members. Do not use the f-bomb in board of directors meetings. Also, you have to take risks. In security, if you get paralyzed by 'what if this could go wrong,' you never act. It's never 100%. Also, simplification. Drop things down to the lowest common denominator. For the last couple of years, I've used time. My staff works 40, 50, or 60 hours. When log4j came, everyone worked weekends and Christmas. The CFO says they're salaried, so it didn't cost money. But the time did. Those 4,000 hours could have been used for other projects, so all projects are delayed. Unless you tell someone to work 60 hours now, how do you fix that? More people—my two sticks—to balance it out. Otherwise, all my projects are a month delayed.
M
Moderator50:24
Thank you for providing an incredible perspective. You have a lot to offer. Thank you for sharing your stories.