Back
Gregory Johnson
Executive Chairman, Franklin Resources Inc

How Security Awareness Drives Business Enablement With Greg Johnson

🎥 Mar 14, 2023 📺 Omnistruct ⏱ 41m 👁 195 views
The vast majority of US SMEs do not have enough awareness of cybersecurity issues, and a lot of them fall prey to phishing and other attacks because of this. Greg Johnson believes that security awareness needs to be the norm for business, no matter the size. With his team at Webcheck Security, they are driving business enablement to organizations through cybersecurity solutions and education. Learn more about Omnistruct at https://www.omnistruct.com Learn more about Greg Johnson at https://www.webchecksecurity.com In this episode of Pineapple on Pizza, he stresses the importance of cybersec...
Watch on YouTube

About Gregory Johnson

Gregory Johnson, executive chairman at Franklin Resources, has spoken publicly about workplace culture, investing philosophy, and the platinum market. In a 2019 speech, he contrasted American and Japanese business cultures, describing TD Ameritrade as emphasizing work-life balance and individual benefit, while characterizing Japanese workplaces as having longer hours, formal breaks, and a group-oriented, long-term mentality. He has also discussed Benjamin Franklin's influence on his company, stating that Franklin's emphasis on frugality, simplicity, and staying the course applies to both investing and running a business. In earlier appearances, Johnson discussed the mutual fund industry and Franklin Templeton's global strategy, noting that the company had focused on building its business outside the United States for 25 years, particularly in countries with emerging middle classes. He also commented on post-financial crisis regulation, saying that while new legislation had slowed, the backlog of rule-writing had put pressure on regulatory bodies. Separately, as president and CEO of Wellgreen Platinum in 2014, Johnson described the company's progress in developing a platinum project in the Yukon and expressed a bullish outlook on platinum and palladium prices, citing falling mine supply and strong demand fundamentals.

Source: AI-verified profile updated from Gregory Johnson's recent appearances. Browse all interviews →

Transcript (59 segments)
N
Narrator0:00
Imagine opening your email to find years of history deleted. Only a single email remains: a ransomware request for two million dollars. You think to yourself, how could this happen to me? You see, there's two types of companies: those that have been hacked and those that will be hacked. The weight of responsibility comes crashing down on you. It's the sort of responsibility you feel when your family is craving a delicious pizza. You finally open the box only to find the most cringe-worthy topping that you mistakenly ordered: pineapple. Join Pineapple on Pizza podcast as John and George, along with guest executives, discuss the most common and craziest cybersecurity risks, followed by actionable tips and strategies that can be implemented to protect your cyber risk. Pineapple on Pizza is hosted by OmniStruct.
J
John1:11
Welcome to another episode of Pineapple on Pizza. Today we have an amazing guest who is CEO of Webcheck Security, a member of the Tabernacle Choir, and grandfather of six children and four grandchildren. Welcome, Greg Johnson. How are you?
G
Gregory Johnson1:24
Fantastic, and thank you for allowing me to be here today.
J
John1:29
Pleasure to have you here. So we've got one question that we start off with with all of our guests, and hopefully you can help us out with this: if cyber risk was a pizza, with the crust being the framework, what's the riskiest topping you have seen, and what topping would you equate that to?
G
Gregory Johnson1:45
You know, this will seem really silly, but for most organizations, and I'm talking most of America's small and medium enterprise, so that may range from 5 million or maybe 50 to 100 million in revenue, but the biggest risk topping is that they don't have a cyber program. They don't have policies, they don't have an incident response policy, and so when they get hacked, they go into fibrillation, you know, like a heart attack, and they go, 'What do we do?' That's the big piece of pepperoni on this one.
J
John2:23
Sounds to me more like that's the crust. Most of them are missing the crust. All they're doing is throwing toppings at it and it's just falling to the bottom of the oven.
G
Gregory Johnson2:30
Yeah, you know, we could have fun with this. The way you've learned it, there are a lot of them that don't have security awareness and they open themselves up to phishing. But the bottom line is a lot of these problems could be solved if they just had that framework to follow and they understood what the best practices were and they were documented and then held accountable to it. And that's what most organizations, I think, are missing today.
J
John2:56
Great. So with that being said, the crust, you know, if they're missing the crust, how do you see or what can you give me an example of a customer that maybe or somebody that you've seen where they've missed that framework and where it really helped them out to create that?
G
Gregory Johnson3:11
Yeah, absolutely. And you know, usually, John, it comes in the form of business enablement, right? So in other words, business is kind of flying along, we're doing fine, we're making some sales, you know, we're swimming along, and then all of a sudden they land a big fish or even a whale. And I'll give you some examples. So we had a mortgage company that had some technology stack, as you can imagine. Mortgages are now, banking is finally starting to gravitate more towards technology. It's taken them a while. We were still sending faxes a few years ago, right?
J
John3:45
Absolutely.
G
Gregory Johnson3:47
So as that world has matured, a lot of companies aren't prepared for what's coming. So they landed a deal with Costco, and Costco came back and said, 'Hey, we're excited to offer your mortgage services to our clientele nationwide. And by the way, New York, the state of New York has these specialized financial services regulations and you need to meet them. Our security team will be in touch.' So what they sent was a spreadsheet, big spreadsheet, to the client and said, 'Here, fill this out.' And that's a scary moment for most businesses because they think they need to meet all of the criteria on that, and frankly, they don't know what a lot of it means, whether they have the controls, whether they don't have the controls, whether the controls are applicable, and most of the time they don't have the policies to back them, right? And so that's when they would turn to our company, Webcheck Security, to help them out.
J
John4:46
So that's a great example. So business enablement, in order for them to be enabled to do business with Costco, they've got to meet the New York State financial regulations, right? And that's kind of a common story. A client will go out, and it doesn't have to be GE or Costco, it can be a smaller 50 million dollar organization that has just a little bit more mature cyber program. The company comes along and says, 'Hey, we're going to be invoicing you by this portal or somehow we're going to be connecting to your system providing some such and such a service.' All of a sudden the company says, 'Oh, we need to assure or ensure that you're secure, so here's our vendor program management program, fill out this spreadsheet.' And that's kind of where the rubber starts to hit the road, is that business enablement concept, if you will. Does that make sense?
G
Gregory Johnson5:39
It completely makes sense. We've seen that as well, and it's definitely that scary moment of, you know, am I going to be able to keep that revenue or am I going to lose that revenue because of a cybersecurity issue or an insurance issue or something along those lines. And that's what brings it to the fore that most organizations, particularly small business where they ought to be concerned about cybersecurity, or even medium enterprise, they just don't know what to do. They've got IT and it's concerned with security, but IT, as you know, and cybersecurity are really not the same thing. One is business du jour, IT gets business rolling and operational, and you throw in some technologies that hopefully are keeping you secure. But security is a lot of things. I like to equate it to Thanksgiving at my grandma's, right? So if you think of Thanksgiving at grandma's, there's pumpkin pie, there's apple pie, there's mincemeat pie, there's pecan pie. What's your favorite, George?
G
George6:41
I get asked that every Christmas. There's a lot of pie there, right? I always go for the pumpkin pie.
G
Gregory Johnson6:51
Pumpkin or pumpkin chiffon, there's even pumpkin cheesecake. But my point is this: if you think about a pie and all of these different pieces, they're all important. You really can't have grandma's Thanksgiving dinner without them. And cybersecurity is that way. It's not just one piece of technology and one IT guy or gal saying, 'Hey, let's throw on CrowdStrike and we'll be safe,' right? CrowdStrike, cell phones, whatever, they're great endpoint products. But what about your incident response policy? What about your HR onboarding and offboarding policy when people leave with keys to the kingdom, right? Who retires those and what's the policy there? What about data encryption? What about network segmentation? Yada yada yada, vulnerability management, penetration testing. All those are important pieces of pumpkin pie that have to be there in order for business to not only continue and have succession and continuity, but anyway, all that to say that it is cyber program management.
J
John8:01
And I think that's become more apparent as the frameworks have come out, the SOC 2s, the NIST frameworks, and all these other things to help try and organize those and make them more standard so that they're easier to follow specifically on the cybersecurity side and make sure that things aren't missed. I think that truly helps the executives understand, you know, within this framework, 130 controls or whatever, it makes it much easier than just nebulously spending money or throwing money at it and hoping that it works.
G
Gregory Johnson8:37
Yeah, and that's a good insight in my mind because I've been involved with it for so long. As we were discussing before the call, I worked for A-LIGN, which has now hit 100 million in revenue, and they do a lot of assurance services, right? SOC audits, ISO 27001, PCI, HIPAA. I also partner with Arc360, which is a CPA firm, Johanson Group, which is a CPA firm, the Moss Adams. We do penetration testing and advisory services for all of those and many more. And what's interesting is that some of those certifications are merely that, they're kind of check boxes, right? And you can kind of tailor, for example, a SOC 2, it's good to have a SOC 2, but it's really, if you're doing a Type 1, it's just a review of the design of the control, so you can convince your auditor that the design of your cybersecurity program is okay, and it's not really following a framework. On the other hand, what most businesses don't realize, right, and this is what I've kind of learned over the years, is that there are these best practices frameworks, and they're not rocket science. So take CIS for example, they've got an Implementation Group 1, and then a kind of intermediate Implementation Group 2, and then an Enterprise. So a business that has nothing can start with just the basics, Implementation Group 1, and they can be a lot more secure tomorrow than they are today just by following that best practices framework. So with a lot of organizations, it's just education, right? It's just helping them understand that there are a lot of smart guys out there that have developed these best practices based on years of practice and observation, and if you adopt these, you're probably going to be okay. So anyway, just some observations there.
J
John10:34
Absolutely, and we're seeing the same thing. So it's great to have that acknowledgment of the market and where things are going, and we need to find that quick education way of helping more CEOs and more boards understand that that issue exists and that they may be putting their revenue at risk, as we talked about earlier. Absolutely. What, tell me this, what events do you go to to help educate these? Do you run your own events to educate CEOs, or is it something where you're doing speaking engagements, are you going to events to meet these CEOs, are you just relying on your marketing? How do you educate?
G
Gregory Johnson11:16
Yeah, well, there are several ways. One is we have a robust channel. We love the channel, meaning managed service providers, managed security service providers, and MDR companies, managed detection and response companies, as well as, as I mentioned before, CPA firms. All of these will bring us in and they will white label or resell our services because it's not their core competency. So in other words, you take a CPA that's doing the SOC 2 audit, they can't be the CSO and write the policies and then audit those policies, right? So we'll partner with them to come in and we can put a CSO in there for, you know, 250 or 300 an hour, which costs them a lot less than half a million to have a real CSO, and these are real CSOs by the way, but they can use them as little or as much as they want during the month and help them, educate them. So we go to a lot of events that are channel-oriented. So Channel Futures in Las Vegas, MSP Summit in Orlando, there are so many channel organizations. We've just become involved with the CompTIA organization, and they have a ChannelCon that we'll be going to later this year, I believe it's either in Vegas or San Diego, I don't remember which one. And so there's that, right? There's channel-focused shows. But we decided early on, about three years ago, I guess not early on, but three years ago, we decided let's do a cybersecurity summit. And we were just coming out of COVID, Utah was one of the more progressive states in kind of relaxing in-person events and so forth. And so back in 2021, we held our first annual Webcheck Cybersecurity Summit, and we basically invited anybody outside of Utah or inside Utah, obviously mostly local focus, but we had people coming from out of state to have this wonderful full day of cybersecurity with a keynote speaker. We had Jack McCauley, who was one of the Oculus founders, for example, did a keynote speech. We had CEOs, we had breakouts on writing policies in the organization, Web3, NFT, and we're doing it again this year. So now we're in the third annual Webcheck Cybersecurity Summit. This year is going to be a lot of fun. It's on, for your listeners, mark your calendars for April 27th. That's when it is. If you go to our website, webchecksecurity.com, and just click on events, they'll see it there. In fact, I think there's a pop-up that says, 'Hey, learn more,' or you can make it go away, whatever. But that's going to be a fun event this year. We've got DeepSeas presenting on threat detection and some of the latest in cyber analytics. We've got, speaking of CompTIA, Juan Fernandez, who wrote the Security+, A+, Network+ security exams for CompTIA, is going to be the keynote speaker. A wonderful gentleman who built a multi-million dollar series of MSPs and sold them off, and now he just wants to help people. Very exciting individual, has his finger on the pulse of cybersecurity and what it takes to succeed there, and so he's going to be a keynote speaker. Anyway, so we do that, right? We've also had some of those events in San Diego and Arizona. But aside from that, lots of webinars, podcasts like this. This is a wonderful podcast to educate people about cybersecurity and how we might serve them. And then we have our own branded podcast, John, called Vistas. And Vistas is mainly cybersecurity-focused, but occasionally we'll deviate and we'll talk about entrepreneurship and leadership, growing organizations. We'll talk to successful leaders of cybersecurity companies and ask them not only about their product or service, but what they did to grow and where they see the market going. So lots of fun. We've got a lot of initiatives going, and I've probably missed a dozen. We want to start kind of lurking in Reddit, maybe doing some Reddit chat sessions and things of that nature. So that's kind of where we're at right now.
J
John15:56
That's great. I mean, it sounds amazing. We may have to come take a look at it ourselves. That would be, yeah, if they're not there. All right, I have to point out that, you know, we ask this event question quite frequently, and I still haven't heard anyone say RSA.
G
Gregory Johnson16:17
So really? Yeah, I will say it's, you know, it used to be big and sexy, and it's still big and sexy and big and expensive. And you kind of walk around and all the big cybersecurity vendors, yeah, that'll show up and do the same old song and dance. And you know, it's different strokes for different folks. We've gone some years, in other years, this year we're not going. In fact, we're having our cybersecurity summit pretty much on the last day of RSA. I haven't run into too many conflicts, so yeah.
J
John16:49
No, I'm pretty sure that's where I picked up COVID. I went to the one right when COVID was breaking, so I remember hearing about that. A lot of RSA attendees coming back with the good old bug. But I guess I picked up a virus while I was there. Yeah, anyways. So Greg, do you read books, and if so, are there any that you would recommend?
G
Gregory Johnson17:19
Oh my gosh, I'm a voracious consumer of books, and a lot of my book reading I do on Audible these days because I find I'm driving so much and I can get so much more time. One of the books I love is called The Compound Effect by, I think it's Darren, is it, Hardy? He was the editor of Success magazine for many years. And it basically is the principle of small and simple things done consistently every day is what leads to greatness and success. One example that kind of stuck with me, I'm kind of a fitness buff, I'm 60 years old, but I deadlifted 425 pounds yesterday, right? And I work out every day. And one of the things he says in the book is he tells the story of three guys, right? So speaking of fitness, and he says, so if one guy decided that he wanted to lose weight and so he ate about 60 less calories every day, the other friend decided to just kind of, I'm good, status quo, so he did nothing, kind of your control group, and then the other guy decided I'm just going to eat a bowl of cereal every night. So I'll eat healthy when I'm hungry, a healthy bowl of cereal, but he was eating kind of an extra 60 calories. So after a month, no difference, right? After three months, right, the guy who restricted his caloric intake was starting to notice some pounds fall off, and the other guys were pretty status quo. But you fast forward another 18 months, and there was a 120-pound differential between the one that was eating the bowl of cereal every night and the one that had started to reduce his calories by about 60 calories. And that's a great example of small and simple things done every day. And so his whole book goes into that. I love that book. One I'm reading right now, or consuming audibly, is called Change Your Brain, Change Your Life, and it's by a Dr. Daniel Amen. And he's a psychiatrist that back in about 1989 started scanning brains with a SPECT, single-photon emission computed tomography type technology. And what they do is they shoot you with a radioactive compound that then when they image the brain, it shows where the blood flow is. And what they found was that all of our problems, ADHD, depression, bipolar, anger, lack of libido, whatever, a lot of it stems from brain damage. And he learned how to look at the brain and then be able to treat the sections of the brain with nutrition, medication, there's a spiritual component, a counseling component, and he would watch those brain portions light up or if they were overstimulated to normalize. Fascinating book, so I'm reading that. One of the best cybersecurity books, though, that I've read in a long time is Sandworm. Have you heard of it? It looks like George has.
G
George20:42
Yeah, sorry, my little one just arrived home, so he's gotcha.
G
Gregory Johnson20:47
So yeah, Sandworm talks about the Ukrainian power grid going down and the big transport company Maersk, and all these big companies. Essentially, it was Russia, and it was kind of the precursor to the war that's going on now. They did this, was back in 2005, I believe, so it was a while ago. But Russia's been playing with cyber warfare for a long time. Fascinating book, gives you a lot of insight into what's going on in Ukraine right now. And then I've written a couple of my own books, John. I have a book out called Testing and Securing Web Applications, of which I'm a co-author with Ravi Doss. I call him Professor Doss, he's written about 10 books. And between the two of us, we discuss kind of the whole cybersecurity framework that has to support secure web applications, from infrastructure and algorithms to pen testing to threat hunting. And it even goes a little into ISO and some of the frameworks we talked about. So there's that. And then I've got a contract to write a new book, and I won't share the title just yet, it's kind of a fun surprise, but it's more geared towards the general public, kind of like Sandworm, only talking about how we're being spoofed by hackers and the whole ransomware epidemic. It'll be an interesting book. I've just barely started that, so I won't predict when that will come out, but I'd like to get on the ball here and get it done by the end of next quarter. You can say no George R.R. Martin kind of things, you know, and I'll get it done before the pandemic, I'll get it done.
J
John22:33
The Song of Ice and Fire, right? All right, I look forward to the new book, and when you do get that out, please let us know.
G
Gregory Johnson22:41
Thank you, yeah.
J
John22:43
Then let's hop back on and we'll talk about it.
G
Gregory Johnson22:45
Absolutely, I look forward to that.
J
John22:48
So Greg, what excites you about the future? Got you drinking. What excites you about the future of cybersecurity frameworks?
G
Gregory Johnson22:56
There's a lot of exciting things going on. As you guys know, the big chat right now is ChatGPT. And sometimes it's interesting how buzzwords and buzz technologies, I'll call it a buzz technology, maybe it's a technology, but it's a buzz technology because it's kind of pop culture right now, right? Everybody's talking about how is it going to hack us, how are we going to incorporate it into cybersecurity. If you think back to the whole blockchain thing, right? Blockchain was going to be the answer to cybersecurity. Would you agree with me? It's probably not.
J
John23:27
Yeah, it may be, I mean, maybe part of a solution, but it's not the solution.
G
Gregory Johnson23:33
Exactly. It's a cool technology and it's very valid in different scenarios. And of course, the whole cryptocurrency, and you could go off and talk about how all of the stocks and the cryptocurrency values have gone down, and that may be just a thing. It doesn't mean crypto is dead by any means. But I think what the community realized is that there have to be controls around the servers that run the cryptocurrency and do the mining, and the cybersecurity principles still apply. And basically, anything that has ones or zeros can be hacked eventually. And so that leads to the next thing, which is ChatGPT. So AI is coming into play, and AI has always been a kind of a buzzword, right? A lot of companies, especially in the threat detection realm, will say, 'Well, we've got AI, our SIEM, security information event manager, it has AI, it'll find the threats,' you know. Well, that's BS. It'll find some of them. But you know, AI essentially still today is mostly heuristic algorithms. Yes, they learn a little bit, but we're not to the point where Isaac Asimov had iRobot yet, right? If you saw the Will Smith movie.
J
John24:48
Yeah, absolutely.
G
Gregory Johnson24:51
Well, ChatGPT has a series of interesting algorithms. Now Google's upped the ante, and because Microsoft made a significant multi-billion dollar investment, now Google's claiming we've got an AI that we're putting into the Google search engine. Kind of reminds me of when they bought Ask Jeeves, right? So this is the next generation of Ask Jeeves. So there's that. You combine that with quantum computing now, right? And quantum computing's still out there. I mean, China has it, the US has it, IBM has it, Dell, some of the big manufacturers are playing with it. And when we'll see that come more into mainstream, it's probably still going to be a while. But when you start to combine that with AI, then it presents an interesting red team and blue team scenario where hackers can use the technology to think faster than a human can respond, and then manufacturers, vendors are going to have to start creating, so you take your CrowdStrikes and so forth of the world and DeepSeas and Arctic Wolf, they're going to have to start incorporating the same technologies to defend as fast as the spears can be launched, right? So there's some exciting things happening out there.
J
John26:16
I would agree, and I agree also that most AIs, what are called AIs, are just maybe simple algorithms that, you know, are in AI clothing, how's that?
G
Gregory Johnson26:28
Right, right, right. And they're scary too, because, you know, are they moral, are they amoral? Basically, when whoever's programming them is programming the algorithm and the arrays, you know, so if it's a serial killer, then you're going to have serial killer algorithms.
J
John26:49
I think there was a scientist that sometimes speaks at some of the cybersecurity conferences, I can't remember her name, but she's essentially in the research area of what essentially is these artificial intelligence and where it really is. And I remember this was a number of years ago, that she said that AI is right now about as intelligent as an earthworm in terms of its equivalent to the human, right? And it does get better every year, but they said it'll be as maybe as smart as a German Shepherd in about 25 to 35 years. And so the concept there was, you know, yeah, there's still no such thing as 100% secure, and there won't be for a while. If you really trust a German Shepherd to drive you down the road in 25 years, that's your choice, but right now you've got an earthworm and an automated vehicle driving you down the road. And so it's up to the programmers to program that earthworm properly, because you need to program the parts where the intelligence is lacking. I'll never forget that statement of, you know, it's about the programming and artificial ethics in programming.
G
Gregory Johnson28:06
And that's an interesting metaphor, you know, which means that, you know, John and George, long after we're dead, the AI will kind of evolve to the level of my six-year-old granddaughter, maybe. I don't know. Who knows.
J
John28:22
Or any one way or the other, yeah. But exciting times. You know, the other thing that's been exciting is to watch the evolution of endpoint protection. You guys remember when it used to be antivirus and it was Norton, right? Then Symantec jumped on board and bought them, and then you had all these other companies like Malwarebytes and, you know, Windows Defender, and they all started to evolve from basic antivirus to look for malware, anomalous code, and file integrity checks. And, you know, it's been interesting to watch that whole technology begin to evolve as the hacks have gotten more sophisticated, right? And we're not done yet. I have a friend, Peter Bybee, I don't know if you've heard of him. He was the CEO of a really neat company based out of San Diego called Security on Demand. You guys heard of it?
G
Gregory Johnson29:38
Yes, yes, I have. And a while back, so he was an MSSP, let's go back 17, 18 years ago. And you know, at some point as the industry evolved and the SIEM thing came out, he started managing QRadar instances. So that's been around for a long time, that's kind of old boxy technology, but it's robust, it works. And so he did that. Then at some point, he found these scientists in Poland that had developed this really cool algorithm based off of something called rough set math, and implemented called approximate query, which would take all of the log data from a system and represent it digitally in a metadata layer. And then the technology, if you could figure out how to ask the right question, it would pull back anomalous results. Well, he bought that company, and what happened was, so you take basic SIEM and regex, regular expressions, and the known knowns, right? And you run logs through it and it says, 'Oh, there's a signature for this thing we know, so go fix it,' you know, it's a Log4j, whatever. But what about zero-day stuff and all of that? So this technology is kind of next level because it identifies a lot of that stuff. So he bought that company based out of Warsaw, Poland, and the PhDs that went with it, and applied it to threat detection and response. And now he recently sold that company to the Nautic Group, who then went and bought an EDR company, Booz Allen Hamilton's MTS threat detection company, and now it's called DeepSeas. Right? So it's been exciting to watch how these MDR companies have kind of grown up and started to add services and AI, and in the case of formerly Security on Demand, the advanced query technology that finds more of the anomalies than Curator would have done back in the day. Right? So that continues to evolve, which mostly helps higher medium and enterprise clients. You don't get a lot of small businesses buying threat detection. They'll just grab CrowdStrike and stick it on their machine like I do. We all work mostly out of our homes, our pen testers, our CSOs. We make sure they have VPNs, we make sure they have Sophos or CrowdStrike, and that's pretty good for us. But you know, you get an organization that has a lot of infrastructure, they've got to have the threat detection, particularly if they're warehousing data, even if it's in AWS, it's got to be monitored. So those technologies are really exciting, guys, and it'll be interesting to see where they go.
J
John32:32
Well, great. So Greg, tell us a little bit about yourself. You said you were located in Utah, is that correct?
G
Gregory Johnson32:42
Yeah, yeah. So I'm a guy that has been married for 38 years and has four kids, one girl and three boys. And I lift weights, play racquetball, and I sing in the good old Tabernacle Choir on Temple Square, which has been broadcasting for 94 years straight through radio stations and now on the web everywhere. In Europe, just picked up the television show. I'm on TV every Sunday morning, you'll see me upper right-hand corner with the bass section on something called Music and the Spoken Word. It's a lot of fun, you guys should tune in.
J
John33:18
My next question, which was, would a bass, tenor, where are you?
G
Gregory Johnson33:24
I sing low bass in the choir, and that's been a lot of fun. We're actually going to Mexico City this, in June, I believe it is. We've got some concerts lined up down there. And except for COVID, the Tabernacle Choir has sung at every presidential inauguration. They've usually been invited and kind of dubbed America's choir. So that's fun. I've been doing that for about five years, and that'll come to an end soon because when you turn 60, they say, 'Here's a nice plaque and thanks,' you know, and then you're out. But other than that, you know, I'm passionate about providing cybersecurity solutions for our clients from a governance perspective. And if our organization doesn't do it at Webcheck Security, we'll pull in partners that do. And I've been doing that for many years. So, you know, as you mentioned before the show, I worked for A-LIGN. I've worked for SecurityMetrics, which is a big PCI, payment card industry compliance firm. I was there for six and a half years. Then vice president of business development at A-LIGN. And in 2018, I was working with Secuvant, which was one of these managed detection and response companies like DeepSeas. And you know, they had their customers saying, 'Hey, can you do pen tests?' And they'd say, 'Yeah, we've got this partner we outsource it to.' And I went to the CEO and said, 'Hey, I have a number of acquaintances that I've used in the past that are fantastic engineers. I've been thinking of starting a company. Let me take these deals and run with them.' And that worked out really well. So that company kind of funded the upstart of Webcheck Security. And believe it or not, COVID was a fuel for the fire for us, because I got laid off from that. One day my boss said, 'You know, we're losing customers. It's one of the first things to go and budgets are cut is MDR, the thousands of dollars of monthly managed detection and response.' So I decided to take it from a boutique company to a full-time endeavor. And the executive vice president who worked there came with me. You know, I convinced him, 'Come on, Jeff, you got to come over here, let's do this.' And we're not looking back. It's been a great ride, largely in part to great partners. But we're just having a blast, guys, and growing up. So live in Utah, I love the outdoors, you know, I love to kayak, I love to hike. Obviously, I'm not kayaking right now because the lakes are all frozen, but...
J
John36:10
I'm curious, with your contributions to the choir, do you play any musical instruments or anything like that, or just is this just the vocal cords for you?
G
Gregory Johnson36:19
I used to have a rock band when I was in high school, and the guitar has kind of been a hobby off and on throughout the years. I can still play. Played the trombone a little bit in college. It's a hard instrument to keep up. It's kind of like, 'Come on kids, gather around the trombone, let's play some Christmas tunes.' It doesn't work, right? So I've kind of let that go a little bit. But yeah, I play a little bit of piano, a little bit of, kind of a jack of all trades, master of none. I actually minored in music, but that was voice, vocal performance. So I guess voice is my primary instrument.
J
John36:54
Nice, excellent. So from a career, let me ask you a question. If you can go back in time and give your younger self advice, what would it be?
G
Gregory Johnson37:05
You know, I think what I'd say is get your MBA, and then look at starting a business a lot earlier than I did. But it's easy to say that now, right? Now it wouldn't make sense for me to get an MBA because, not that I know it all, right? Everybody can stop, and there's a lot of great stuff, a lot of business analytics that I would learn, but it would cost a lot of money now to go back and it wouldn't give me a big ROI because I'm already the CEO of a successful company, right? Having fun and enjoying it. But what I would do is I would learn more earlier, and then learn more instead of just going to work in something I enjoyed, I would look to learn more and then start a company a lot earlier, which would lead to more career satisfaction, the ability to bless others' lives more, you know, employ other people, donate and give to the community earlier on than I am now, and just kind of have a little bit more life satisfaction. But then again, you go through life and you kind of figure things out, and at one point certain things click. So would I have changed anything? I don't know. I mean, I was pre-med at BYU, I was going to be a doctor like my dad, and then at one point I realized I don't know that I like sticking needles in people and, you know, feeling for veins in their arms. And I realized I had a gift for languages. I served an LDS mission to Milwaukee, but speaking Spanish, and I learned the language really well. And so I got a degree in Spanish translation, which has kind of helped me in business and writing and so forth. So I don't know, that might help you on that trip to Mexico City.
J
John38:52
Yeah, definitely.
G
Gregory Johnson38:57
Well, great. But that would be it. I'd say younger self, you know, get serious, maybe stay in school a little bit longer, and then learn, go to work not to just earn money, but go to work to learn. And try different positions, don't be afraid to apply for more positions within large corporations or whatever, and you'd probably find an acceleration of where you wanted to be earlier.
J
John39:23
Great. So Greg, where can people find you?
G
Gregory Johnson39:26
Well, if they go to webchecksecurity.com, they can reach out to us. We have forms on just about every page. There's an email, get in touch at webchecksecurity.com, and I get those as does some of our biz dev team, but I'd be happy to respond. Or they can go to LinkedIn, Greg Johnson, just type in Greg Johnson and Webcheck Security, I should pop up. Connect with me, and they can do the LinkedIn messaging, I respond to those as well.
J
John40:00
And then you also have the podcast. Tell us what that one is.
G
Gregory Johnson40:02
And then we have Vistas. So anywhere that podcast, for the most part, the major platforms, Spotify or Apple Podcasts or whatever, if you go out and search for Vistas by Webcheck Security, there you go. You can, in fact, I've got to release the one for this month, we haven't released it yet, so we'll be doing that soon.
J
John40:26
Excellent. We'll have to check that out when it comes out.
G
Gregory Johnson40:30
Yeah, yeah, it's a fun podcast. The music is sponsored by a really neat band that my son happens to be part of called Suit Up Soldier, that can be found on Spotify and Apple Music. And it's just a neat podcast, so.
J
John40:45
Great. All right, Greg, well, I appreciate your time with this, and it's a great insight. It was definitely eye-opening for some of the frameworks and some of the things that you've done in the past, and we really appreciate your time on this. For our audience, thank you for listening. If you've learned something today and laughed, tell someone about this podcast. And there it is, this has been another great episode of Pineapple on Pizza with your host John and George. We'll see you next time. Thanks for joining.
N
Narrator41:18
Great episode of Pineapple on Pizza. You can find show notes, links, and resources by visiting omnistruct.com/blog. And a huge thank you to all who are preventatively protecting organizations from cyber threats.