The CISO Scarlet Letter: How a Breach Actually Builds Your Resume cover art

The CISO Scarlet Letter: How a Breach Actually Builds Your Resume

The CISO Scarlet Letter: How a Breach Actually Builds Your Resume

Listen for free

View show details

Zach Lewis has spent his career asking for things before anyone offered them. In this episode of The New CISO, he joins Steve Moore from Black Hat in Las Vegas to trace a path from fixing neighbors' laptops to running IT and security for a university — and to explain why he wrote a book about it.

The origin story is a series of conversations most people never start. A few weeks into a new job at a college, with the CIO gone and his own supervisor out the door, Zach walked into the interim CIO's office and said he could carry more. He was promoted days later. When the director of technical support announced he was moving, Zach said he wanted the job before it was posted, then shadowed the man he hoped to replace. The theme holds: if you want something, say so, and make sure the deciders know it.

One move breaks the pattern. A former boss invited him to a nearby college that needed its IT department rebuilt, five minutes from the house and weeks after his first child was born, and he said yes without asking why the rebuild was necessary. A team of twelve was down to two. Six months of interviews produced no hires. He worked overnights, burned out fast, and left for his old employer the first day back from winter break. His advice now: treat the interview as an advisory engagement — why is this role open, where did everyone go, what is the root cause.

Back at the college he became director, then CIO, then built a security program from nothing — and when he pitched hiring a CISO, leadership said there was no budget for another chief officer and asked whether he could just do it himself. He said yes. In April 2023 the institution was hit by LockBit. Zach walks through the morning it surfaced: hours of ordinary troubleshooting, a recovery that collapsed hours later, and a readme file in the hypervisor he knew was bad before opening it. Three calls followed — cyber insurance, the FBI, and his wife, to tell her this might be a resume generating event.

The conversation sharpens when Steve presses on the book's most contested line: would Zach trade everything the breach taught him for a guarantee he'd never face another one? He doesn't dodge it. That stigma is exactly why he wrote Locked Up — attackers trade notes about what works, defenders stay quiet, and the silence helps the wrong side. His closing advice: ask for things, remember it's reciprocal, and use the tool instead of being used by it.

Key Topics

  • Asking for the role before it is posted, and what tends to happen next
  • The questions Zach wishes he had asked before a job that went wrong
  • Interviewing as an advisor rather than a candidate
  • Building a security program from scratch, then being handed the CISO title
  • The morning the LockBit ransom note turned up in the hypervisor
  • Three phone calls: cyber insurance, the FBI, and his wife
  • Holding the circle tight, and the debate over when to notify publicly
  • Why announcing too early can force you to restate the numbers
  • The stigma around breaches, and why attackers share more than defenders
  • Writing Locked Up on a chapter-every-ten-days deadline

Guest Bio

Zach Lewis is CIO and CISO at University of Health Sciences and Pharmacy, and the author of Locked Up, published by Wiley with a foreword by George Finney. He began in desktop and systems administration in St. Louis before moving into higher education, holds the CISM and CISA certifications through ISACA, and led his institution's response to a LockBit ransomware attack in April 2023.

GET A DEMO:

👉 Get a hands-on demo of the Exabeam products: https://www.exabeam.com/demo

🔔 Subscribe for more product demos and cybersecurity insights!

ABOUT EXABEAM:

Exabeam is the leader in Behavior Intelligence for the agentic enterprise. As organizations deploy digital workers and confront machine-speed adversaries, Exabeam applies agent-powered analytics to understand and govern the behavior of both human and non-human insiders. With integrated Exabeam Nova cybersecurity agents, Exabeam delivers flexible, industry-proven solutions for insider threat coverage of humans and agents and faster, more accurate threat detection, investigation, and response (TDIR). As the pioneer of user and entity behavior analytics (UEBA) and the innovator behind Agent Behavior Analytics (ABA), Exabeam is trusted by more than 3,000 enterprises worldwide to reduce risk, secure the digital workforce, and accelerate security operations. Learn more at www.exabeam.com.

Exabeam: Stop Insider Threats. Human or AI.

CONNECT WITH US:

X: https://x.com/exabeam

LinkedIn: https://www.linkedin.com/company/exabeam/

Blog: https://www.exabeam.com/blog/

adbl_web_anon_alc_button_suppression_t1
No reviews yet