From Discipline to Cybersecurity Leadership
CIOREVIEW >> Cyber Security >> NEWS

Cambium Learning Group

Jason Stockinger, VP and CISO

From Discipline to Cybersecurity Leadership

Jason Stockinger, VP and CISO
Jason Stockinger, VP and CISO, Cambium Learning Group

Jason Stockinger brings a disciplined, mission-driven mindset to cybersecurity and technology leadership. From a skilled technical engineer to a strategic leader across multiple industries, he has built a career on balancing innovation and risk management. Currently serving as the VP of CISO at Cambium Learning Group, Jason focuses on people-centered leadership and aligning security strategies with operational goals.

I started my career with an education from the Air Force, which taught me the discipline and fundamentals I needed to succeed. When I joined the corporate world a few years later, I really had a lot to learn about solutioning technology, even though I was a skilled technical engineer. People make decisions for various reasons and not everyone can use the perfect solution. This was a particularly difficult lesson in the financial technology sector, where I saw how executives make tough choices about investing limited funding. As an engineer, I wanted the absolute fastest, most versatile and usually most expensive solution to solve technical challenges.

As I rose into leadership, those lessons of technology bests vs. reward decisions ring true to this day. You can’t always afford the best and sometimes all you need is the least functionality to get by. This approach of looking at the proper solution for the risk or reward equation sometimes is not the most secure or the fanciest application or even the prettiest interface with great reporting features. This risk-based approach is what gained the respect of my mentors and propelled me into leadership in multiple industries.

Navigating Human Barriers in Security Transformation

I think some of the toughest organizational or cultural barriers are the people you work with daily. This is also the most rewarding aspect of the work. It’s difficult to predict how someone will react to a direction based on my experience. I find myself seeking to understand why things don’t work out as planned. The military training in me, ‘take the hill,’ is at odds with the empathy that I have for people and their journey to success. I’ve found that when I try to make everyone around me successful, then the right answer materializes into a successful security program. I’m not saying it’s easy. There are challenges in balancing risk with reward. I always lead with the intent to make things better for everyone. I came equipped with 2 ears and one mouth, which translates into a methodology of listening twice as much as I speak. That’s tough when I’ve seen a problem before or think I already know the answer. I’ve learned the principle of WAIT (Why am I talking?), WAINT (Why am I not talking?), WAIST (Why am I still talking?) is fundamental to tackling the organizational and cultural barriers during transformation.

 Transformation to a security mindset doesn’t mean that we never take risk, rather it means that we know exactly where the risks lie and we have a plan for each one of them 

I’ve used several approaches to avoid disrupting operations while implementing security measures. Understanding what’s important and the impact of the security change BEFORE changes are applied is clear. Asset management is critical to understanding how your organization operates, yet many struggle with the basics. In the absence of asset management, reliance on subject matter experts, surveys, business impact analysis, business continuity and disaster recovery plans and using existing telemetry relevant to the change becomes relevant to ensuring operational uptime. Establishing security measures purely based on ‘best practice’ can quickly disrupt essential production environments. It’s possible to be agile and operationally focused simultaneously with the right data. IT Infrastructure Library (ITIL) principles should apply to security operations, as these changes typically have a broad impact. Communicate, educate and then implement.

Balancing Risk and Reward

As a security practitioner, I often see the risk in accelerating transformation in full view. Sometimes, we can miss out on the potential reward of taking risks if we aren’t open to the possibility that risk might be ok. Adopting a security mindset doesn’t mean avoiding risk; rather it means exactly where risks lie, and we have a plan to address each one. Discussing risk treatment with stakeholders is essential to going fast and transforming for impact. Acceleration without risk visibility and treatment is a recipe for disaster. Imagine a rollercoaster without speed limitations for curves, brakes, seatbelts or guardrails—not one that would be very successful.

Attracting and retaining top-security talent in high-pressure environments is a question I get asked often as a leader. It is not different from other talent pools in my experience. Top talent wants to learn and be challenged. They want to have an impact. At Cambium Learning Group, we have a saying that I’ve wholly adopted our customers and our co-workers want to be “seen, valued and supported”. They want to feel it from us. They want to know it in their core. As a leader, if I don’t attempt to do this at work every hour of every day, I’m not really leading the way I want to be led. I have found that the highest-performing talent wants to be unleashed on their work and have the obstacles removed that sometimes seemed to be around every corner. It’s my job to help them. Sometimes, help means moving aside to let them shine. With others, it’s the exact opposite. They just want to be left alone with their energy drinks, headphones and computer to rock out amazing solutions. Whatever the answer, its individual and my job to figure out what works for them.

Transformations require more communication and transparency than expected. It’s important to explain the why in transformation and to share this often. When you receive new information, being able to pivot quickly becomes paramount to ensuring that the end goal is accomplished. Also, being realistic about timing, budget, scope and quality supports better planning and integration. Be careful about what you promise vs. what you deliver.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.