Rich Bates

Senior Advisor, Cybersecurity & Risk

“At my heart, I am a Servant Leader. I am not here to thump you on the head and tell you, “This is wrong.” I
am here to be your guide.”

Rich Responds to Key Questions

Why do compliance programs fail even when organizations check all the boxes?

Because Cybersecurity culture needs to be baked in, not sprinkled on. Too many orgs implement Cyber programs by shouting; “Do This!” instead of explaining why. Take the time to explain why we do this and what your employee’s role is

What's the difference between fractional CIO support and just hiring consultants when you need them?

Consultants are task oriented where fCIOs should be embedded. They should sit in on your leadership meetings, your All Hands, they should look just like one of the gang. This requires trust building and team learning.

Some defense contractors dread CMMC. What makes the difference between a painful process and a manageable one?

First mistake they make is thinking it’s just an IT project. It’s not. CMMC is a whole company, One Team –
One Fight program. And it *is* a program, not just a once and done project. They also need to have a firm grasp of what their current business processes are. CMMC should enhance the process, not break it.

Where do you see executives waste money on cybersecurity?

They allow tools to be bought with no real plan or resource to get them working properly. Also buying
multiple tools that do the same thing. Why buy Symantec if you already have Defender in your tenant?

Clarity over jargon. Substance over spin. Integrity, always.