Skip to content
TrackPodcasts
technologyMar 18, 202625:04

When Cyber Meets Physical: Building Executive and Employee Protection Programs That Actually Work | A Redefining CyberSecurity Podcast Conversation with Roland Cloutier, Principal of The Business Protection Group

About this episode

EPISODE NOTES

The conversation that led to this episode started with a LinkedIn post -- and it quickly surfaced a challenge that security leaders across industries are wrestling with but rarely talk about openly: who is actually responsible for protecting the people inside an organization, not just the systems they use?

Roland Cloutier has sat in some of the most demanding security leadership seats in the world -- Global CSO at TikTok/ByteDance, a decade as Global CSO at ADP, and VP and CSO at EMC -- and he now advises CISOs and CSOs through The Business Protection Group. His lens is converged security: the deliberate integration of cyber, physical, privacy, and people-risk under a unified program and leadership model.

Roland identifies three patterns that typically bring organizations to him. First, an emergent crisis -- a threat against an executive, a workplace violence incident, a travel security failure -- that suddenly exposes the absence of a coherent protection program. Second, a cost and structure conversation where the CEO is tired of receiving two different risk pictures from two different security leaders and wants a single accountable voice. Third, a board-driven inquiry where general counsel or the CEO is being asked questions about executive resilience and duty of care that nobody inside the organization can confidently answer.

What makes this conversation particularly sharp is Roland's framing of convergence not as an org chart exercise, but as a force multiplier. A unified threat intelligence picture -- one that covers cyber, physical, executive, brand, and customer risk simultaneously -- enables cleaner prioritization, better resource allocation, and a fundamentally stronger conversation with the CEO. The alternative, which he has seen firsthand, is four separate threat management platforms reporting independently with no team working across all of them.

The episode also pushes into territory that most security programs have not yet mapped: employee protection at scale. Not bodyguards for everyone, but the organizational consciousness to monitor for geographic threats, proactively check in with distributed employees during major events, and build a duty-of-care posture that extends beyond the office walls into people's home lives and total risk environment. For high-risk employees -- those with keys to the kingdom, not just C-suite titles -- that responsibility extends further still.

For CISOs and CSOs wondering where to start, Roland offers a practical crawl-walk-run framework: start with shared services rather than full convergence, open the conversation with leadership, surface the gaps the business already knows exist, and build a financial and risk model that makes sense for your specific organization. The goal is a converged security program that treats people -- not just infrastructure -- as an asset worth protecting.

GUEST

Roland Cloutier, Principal at The Business Protection Group | On LinkedIn: https://www.linkedin.com/in/rolandcloutier/

HOST

Sean Martin, Co-Founder at ITSPmagazine, Studio C60, and Host of Redefining CyberSecurity Podcast & Music Evolves Podcast | Website: https://www.seanmartin.com/

RESOURCES

The Future of Cybersecurity Newsletter | https://www.linkedin.com/newsletters/7108625890296614912/
More Redefining CyberSecurity Podcast episodes | https://www.seanmartin.com/redefining-cybersecurity-podcast
Redefining CyberSecurity Podcast on YouTube | https://www.youtube.com/playlist?list=PLnYu0psdcllS9aVGdiakVss9u7xgYDKYq

ADDITIONAL INFORMATION

On ITSPmagazine: https://www.itspmagazine.com/
On YouTube: https://www.youtube.com/@itspmagazine
On LinkedIn Newsletter: https://itspm.ag/future-of-cybersecurity
Sean Martin's Contact Page: https://www.seanmartin.com/

⬥KEYWORDS⬥

roland cloutier, the business protection group, sean martin, executive protection, employee protection, converged security, physical security, ciso, cso, duty of care, threat intelligence, workplace violence, security convergence, business resilience, redefining cybersecurity, cybersecurity podcast, redefining cybersecurity podcast


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Get every episode summarized

Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

272 searchable segments. Every word is indexed and playable.

When Cyber Meets Physical: Building Executive and Employee Protection Programs That Actually Work | A Redefining CyberSecurity Podcast Conversation with Roland Cloutier, Principal of The Business Protection Group

The ITSPmagazine Podcast

0:00
25:04

Full transcript

The ITSPmagazine PodcastWhen Cyber Meets Physical: Building Executive and Employee Protection Programs That Actually Work | A Redefining CyberSecurity Podcast Conversation with Roland Cloutier, Principal of The Business Protection Group. Machine-transcribed; use the interactive transcript above to jump the player to any line.

And hello everybody, you're very welcome to a new episode of Redefining Cyber Security. I'm Sean Martin your host where I have the pleasure of having conversations about a topic that I love. The years and years I've been working on security from protection and detection and response and looking at things from an operational perspective and I've landed in a world where I believe security has a chance to do good things for the business. Not just be a department of no and of controls but actually I'll drive business value and protect the growth and the revenue that it generates. And not an easy task if you're sitting in the CISO seat and my guest today sat in that seat for quite some time and some organizations you probably are familiar with.

Roland Cluteier, how are you my friend? Sean I am fantastic and thanks for having me. It's a pleasure to have you on. I forget when we chatted last but it was a good conversation and I'm happy we have a chance to connect today. We're going to be looking at executive and employee protection programs and kind of what that means from a security leadership perspective and a business perspective and some of the things you're seeing and hearing in that world and perhaps our organizations and security leaders need to think about that stuff. So excited to have that chat. Maybe a few words about the things you've done in the past that led you to where you are now or you're up to at the moment. Sure. Well, 30 years go by really, really quick, Sean. I think what's interesting is that I actually started out on quote unquote the other side. So I came from the Air Force and their security police and anti-terrorist division and that

migrated into civilian law enforcement, federal law enforcement and then I got a lot of cases that happen to have security risk and privacy issues associated with cyber and data and all that cool stuff. So I actually went back to school to learn about cyber and the next thing I know I fell in love with cyber and second career, 20 years later, chief security officer for EMC, for ADP for a decade, bite dance and for the last few years before coming into advisory road supporting other chief security officers and CSOs in their roles. I get to do a lot of stuff and one of my passion areas of course is being a converged security leader wrote a book on it and it has been part of me helping other organizations for the past several years. Yeah, it's a good natural way I feel to establish a relationship with people and then get an understanding of what's going on, big picture driven by real stories, reality, right?

So what are some of the things you're seeing organizations struggle with that maybe not every organization realized they should be struggling with or may not realize they are struggling and can't put the finger on what it is. So you know, typically there's really three flavors of this, two are from the CSO side and one's typically from general counsel side when I'm working with customers in this area. The first is an emergent issue that happens with a business, someone threatens an executive, the CEO, workplace, violence issue. I mean, it could be one of several different things, a travel security issue with a lack of operational expertise in place and they turn to the CSO and say, you do this stuff for a living, why don't you help us and make sure we're doing this right. So it becomes, you know, sometimes a sense of urgency to figure out what an organization should be doing at what level and is often, you know, the normal knee jerk reaction and

then, you know, a pragmatic review. And the second flavor is when the, it comes in a not urgent way, but a CEO or the executive leadership team turns to a security executive on either side and says, you know, we'd like to streamline. We have costings we'd like to do and I'm tired of two different security leaders coming to me with two different sets of risk metrics, priorities, I want one throat to choke or one back to pet, I think I look at it and figure it out and create something that makes sense for me. And the third one is not much different, it comes from normally non security practitioners on either side and comes from the CEO or general counsel that says, you know, I'm being asked questions from the board about our ability to protect our executives, resiliency and threats to the business, their security, I don't think we have a good handle on it.

And I would like an external view that has done this before for large companies to help us figure figure how to do that. And that has been, you know, kind of over the last call it three years or so, the majority of the cases that have come to me. And so how, I guess, like my question is, how, as with many things early days of cyber and I think executive and high, high level employee protection programs, it's kind of a fairly new concept in the grand scheme of things. Security is not new, but relatively new compared to a lot of other things. And I'm wondering, do organizations recognize this risk or are they waiting to hear that they're counterpart or the next business sector had an issue or some news element finally

makes the mark to catch their attention? What's the awareness of this? I guess is the question. I think it's becoming more and more aware since the attacks on some business executives in the United States a couple of years ago and in ongoing cases around threats to people of high net worth. I think it becomes a consistent message and quite frankly, the level of violence perpetrated as well as tax through technology on identity and, you know, wailing and all the other things that we've seen around best type issues, it just kind of accumulates at the same time. I think convergence, in my opinion, of course, I'm slightly jaded, but is super important when you think about our responsibilities as business protection executives, right? Our jobs around ensuring the continuing operations and capability and the leadership in the go-to-market of business or an agency or whatever we do and some of that is cyber, some

of that is resiliency and some of that is resiliency and availability of the people involved in doing it. And so it all mixes together and I think from my standpoint, from my purview, is that we often think it's cost level, right? Often businesses will push in this direction and say, I don't need a CSO and a CSO and a director of corporate security in this and that and there's a lot of reasons for it, but I think a lot of people immediately go to a cost and there is obviously cost multiples that make sense. It is the leveraging of the expertise on both sides as a force multiplier and I'll give you a couple examples. So most people, especially in what we do, understand that physical security and facilities defense and public safety now has a lot of technology embedded. And whether it's gauging large, it's technical security, whatever you want to call it or it's the management of certain intellectual property defense or it's our phones or what have we.

There's an aspect of technology involved in physical security and our DevSecOps and our engineering teams have been doing this stuff for a long time. So giving them yet another discipline to add from the SOC or the CERC or the thread-in-tell platform or an operational control platform or what AbU is saying, physical security, device control management, PCEM, integration, it makes sense, right? You have a set of engineers that can provide a set of services in the existing infrastructure architecture that they know lead and manage and so you get a better quality product. Faster to a global initiative, typically these companies are global. Secondly, you get a better threat picture. I mean, at the end of the day, you get a better threat picture, right? Because there can be a threat to the business that is often you can have threat to people and the implications of that. So are people trying to steal data through an individual, are they trying to get through their homes into corporate devices or just get information to hold, you know, hold them

hostage in some way, you know, or blackmail them. I mean, there's a lot of ways to look at this. I've seen companies have up to four different threat management platforms for their company, including cyber, executive, brand, and customer, right? And they all report differently. There's no single threat view and there's no team working all the threats. Again, it gives you this ability to consolidate the data to become a real true force multiplier in seeing that visual picture, that threat, and then being able to prioritize those risks. If I go in with a clear picture about a totality number of risks associated with security to the organization and sit down and can step through them in their implications with the CEO or executive security counselor or what have you, it's a much better conversation than the head of risk, the head of cyber, you know, the head of physical security coming at different times to talk to different groups without a standardized way to prioritize,

manage, and address those threats. So again, it's a great way to do our jobs better. For me, the natural course would be the executive leadership team would have a question or a set of questions that are not siloed, like the teams are, right, they wouldn't go to security and say, give me the security risk or security positive, give me the physical team, security team, give me the challenges you're facing, they have the business view. Tell me as an organ, as a leadership team, these things, are we at a point where executives know how to ask that question across silo or what are some of the conversations and sound like, I guess. I think they're getting better, I think they know what they don't know and they're asking

people to get the answers is the way I would look at it. You know, for other people, it's just another GNA function that they have to, you know, there's just a reality to that in many cases. But most organizations have an informed board, especially public organizations or those around critical infrastructure or those that have, just call it critical jurisdictional oversight from different regulators. And so those organizations are starting to hear questions from their board about the resiliency of their people, threats to executives, threats to the company. Others are involved in different areas. You know, when YouTube had the shooting several years ago, they did a great job in sharing what went well, what went wrong, and what they would do differently with other folks in the industry. So you saw other social media companies, competitors, actually listening and learning and doing certain things. So you see this industry by industry many times.

Unfortunately, some of it pops up when there's a negative impact event, you know, we saw that a couple of years ago, you know, with the shooting in New York. And so, you know, that industry took, took a clear and different view and learned. But to answer your question, yeah, I think people are asking the right questions. And one of them is, what's the right level of security for the threat to the business and the type of people that we have working for us? I think that's one. The second one is, is how do we care for our employees when they're working on our behalf around the globe? I mean, think about how many people this week happened to be working somewhere in the Middle East for their organization and found themselves in a tough situation. Do we have the ability to provide the capability to remove our people as necessary, protect them, facilitate, transport, medical evacuation if they need it and all those things? And people are seeing this part of due care. And the last component, I would say that people are learning well is, do we have the

right organizational structure, right? Are we set up to succeed? Most informed CEOs in general councils I talk to don't have the knee-jerk reaction. They're taking a step back and saying, how do we measure the risk, apply a lens that's appropriate for our organization and that we can carry forward and continue to do that view and make those right decisions? And I think that's a great approach. Yeah. I remember it was around the time in the pandemic and there was a lot of, I'll just say unrest here. A number of years back with demonstrations and protests and whatnot. I was speaking with a security leader at one of the large banks here in the U.S. and she was describing this need to not just protect the banking systems but to protect the banking people. She wanted to ensure that her employees at the bank were safe online but also at home because

they were all working from home and perhaps in areas where there was unrest as well. And so they took this total view of how do we protect our employees digitally and from a cyber perspective but also from a physical and even a health perspective when we tie the COVID stuff into that. There's an interesting conversation I had with her a couple of times and I'm wondering, it doesn't seem like a lot of organizations have that view, right? It's, there's the system, the person gets rights to access that system and that's the stuff we're going to protect and we'll give them health insurance but that's the extent of the additional care we provide and unless you're an executive then maybe you get some detail to if you're traveling into a bad place or a risky place and we might monitor your stuff online to make sure you're not being targeted for ransomware, extortion, whatever. Where do we sit in terms of kind of softening things from the pure tech perspective to really

understanding and caring about our people? So I believe that the the best in class companies that do this do it well with a risk funds but a broader discussion on employee protection, not just executive protection. That doesn't mean have a bodyguard for every employee that's not what I'm talking about. What I'm talking about is have the conscious and capability to understand the environments that the people work in and where they live and have programs that provide a level of continuity and capability that ensures that their employees are safe, the best of the company can provide. I think that's number one and I'll give a couple examples of that in a second. And the second part of that is is when there is a higher level of threat, threat against an executive threat against a key employee or a key employee who would be targeted

because quote unquote they have the keys to the kingdom or they are the only people that understand a very sensitive part of the business is that the business takes a special view of that and understands that the employee's ecosystem is not within the four walls of the building of the office that they operate and but rather it is part of their home life. What we call their total life and how they operate and the risks on their family and their home and other things and they take an approach with higher risk issues and whether they be episodic or they be permanent because of an individual's perspective that they offer a reasonable level of do care and assistance to ensure that they have the necessary help that the company has put them in because of the position that they do that's that's kind of in that area. Now getting back to the employee area I'll give you some you know some pragmatic views of this. Maybe an organization has a capability that's watching for major events in large

populous areas that their employees live in maybe they have you know a branch in New York a branch in Nashville a branch in Atlanta branch in the Bay Area whatever it may be and their their threat intel group or their employee protection teams monitor for significant events and so not just one do they have a fire in the building are they sending out an are you okay when there is something in a geographical region that impacts a significant employee level they send out are you okay or maybe it's everyone then they have some great automation and play that says hey I know you live within two miles and you're a work from home employee of you know this major you know fired petroleum are you okay and then have assistance and operations available to help those out whether there's a few third parties or through their own internal managed service that's great now I happen to have worked in the past for you know a large multinational

that specialize in human capital management technology that focused on making sure that their people were up and up and able to help and support their their customers and so they had a massive capability initiative to be able to roll out kind of in a FEMA mode when something major have their hurricane or you know a massive disaster to go into those areas set up capabilities to get their people out of harm's way get them to a location that they and their families were safe and get operations back up and running and and and it wasn't just about the business getting up and running it's making sure their people and their families were safe and they were able to do their jobs in a safe location and so then the two helped each other and I know the employees were really appreciative of that and so were the clients so that's one example but I think there's two sides to that point absolutely well we have a few minutes left here and I want to kind of bring this back to the the security leaders who listen to this and perhaps maybe you and some of the

practitioners who may or may not see things in logs that that might make them think hmm it doesn't it didn't trigger anything from a tech security perspective but now that I'm hearing this conversation perhaps there's an employee human perspective we should be looking at as well so some thoughts and comments for CSOs CISOs that maybe thinking about this this area and may not know how to approach it with their ELT and I don't know is there are there ways to tap into the board perhaps to make some change here as well then we started the easiest level maybe it's not a segmentation in a coverage program maybe it's a shared program right maybe maybe we become service providers to each other there's a CSO on one side and a director of focus security or CSO on the other side and the CSO provides engineering and thread and tell platform services maybe there

is an opportunity for the CSO and CSO to marry up risk and threat services from a prioritization together as they go in and look at these things maybe there are opportunities for the organization to leverage executives going across each side so they have more rounded teams is often one of the things that they can do frequently and I see really great leaders and executives coming from cross-programs so that's number one number two is you know start thinking about what your business needs where they feel gaps they're going to tell I mean these this is nothing new this is something that I think we hear often and don't understand it so I have an open conversation with your leadership I have an open conversation with your CEO or or whomever and and ask you know are you getting

everything you want do you think that security risk and privacy and physical security can be providing more and if so what and then do a planning session sit back and say okay if I'm if I'm going to jump into this what are the things the businesses asking for how does it help our go-to market our customers our employees and our shareholders and then do a crawl walk run you get some news done up before and and sit back and say what are the things I can do with existing people existing programs what are short-term things that we can do as an organization to plan for a next step to to create the level of service capability that they want and then start talking about the importance of convergence and how to have a standard management umbrella risk view and service delivery and financial model that makes sense for your business I think that's kind of the best way to to start yeah yeah this is spurred by by a post you made on LinkedIn and

and I love following what you put up there and so I'll I'll link to that up that that article slash post in the show notes and hope everybody connects with you and and follows along with all the other stuff that you put out there it's good good to see it and thanks for thanks for getting back to the community and Sean thanks for having me I'm glad to cut your eye and happy to always have these chats with you so thanks so much for having the pockets likewise I appreciate you taking the time and thanks everybody for listening and watching this episode of redefining cyber security hopefully you open your mind a little bit more like it did for me and I get you to think a bit then perhaps take some actions to change how we approach security in our organization next again we're all and thanks everybody thank you

More episodes

More from The ITSPmagazine Podcast

View all episodes →