July 2019: In this month’s feature Volker Rath, Head of Security Consulting Australasia at BT (formerly British Telecom), shares his story
July 31, 2019
Throughout 2019, this mini-series will interview leaders from around the globe to discuss areas of cybersecurity. The purpose is to help students and those new to the industry gain perspective and guidance from professionals in the field. These interview insights aim to kick-start or re-energise your career journey in cybersecurity. In this month’s feature, Volker Rath, Head of Security Consulting Australasia at BT (formerly British Telecom) , shares his story about: The meaning of cybersecurity and how this has evolved over his career. His motivation to pursue his passion. What, if any, information would he have liked to know starting out in his career. How he suggests others new to the field get involved. Rath enthusiastically dives into the subject. “This illustrates how cybersecurity has yet to become mainstream. This LinkedIn series is enlightening because of the numerous, global perspectives and approaches for how to forge a path into cybersecurity. We could do more to support the diversification of our field to help those with interest seek out and pursue the best path forward. This has often been thought of as a male-dominated area, to which you will always find a similar outcome. I am excited to support the diversification of our cybersecurity space as this is imperative to our success.” These are his insights. Why did you choose cybersecurity? “I was lazy as a kid because there were enough jobs growing up in Germany. I became an eager learner once I attended an IT college. I almost forgot what the word ‘learning’ meant because I was obsessed with consuming as much knowledge as I could. I began to explore and read more than I had in the past. That is how I stumbled upon my passion for computers. Shortly after college, I was about to join an internet start-up when the first dot com bubble burst and the investment funds evaporated. This ended my internet start-up career. I then received a call from a recruiter to join Symantec as a Security Consultant. I recall thinking I did not want to be known as the person that fixed computers for a living. I quickly realised Symantec had an enterprise division of consultants, and thus my career in consulting began. I was working closely with Symantec technology early in my career. While I was never enthralled with the technology, I was enthusiastic to help make security operations work at scale. I did not understand how vast the cybersecurity space was at this stage in my career. I had very little knowledge of disciplines like penetration testing, risk management, threat management, maturity assessments or security frameworks. My journey had only just begun and I was hooked!” Why do you do what you do? What motivates you as a cybersecurity professional? “It has always been about the people. I completed courses in ISO27001 to establish better risk management skills and began to develop my own tools to better facilitate security operations. I quite enjoyed consulting and the work at Symantec. I loved the travel, interacting with global organisations and engaging with senior leaders. I was fortunate to see the geographical make-up of the world and from the inside of large enterprises…an exciting way to begin a career! I began to ask myself about my purpose – what motivated me? Did I want to be a product manager? A sales person? A consultant? I continued to ask myself what was most fulfilling. I loved working with people around the globe in consulting. I was (and continue to be) motivated to help fundamentally change lives for the better.” What do you see as the biggest challenge we face in cybersecurity? “Communicating the message! This is why our attention span is so low,” laughs Rath. “Quite often I hear cybersecurity is too nerdy, and to some degree this is true; however, this perspective should not restrict our recruiting strategies to technical areas or specific concentrations. We should focus efforts to teach our professionals how to better communicate the message irrespective of their background or skill set. I recently spoke on a panel that addressed the Chamber of Commerce for Australia and Israel where only forty percent of the audience comprised of cybersecurity professionals. We had a world-class line-up of speakers that could bridge the gap between a cybersecurity issue and the real world with layers of fun facts and humour delivered to a lively audience. The crowd’s energy was fueled by the panel’s ability to deliver the message that encouraged more insightful questions with genuine curiosity – we could not get off the stage because of the crowd’s enthusiasm!” What would you have liked to know starting out in your career? “I always loved hardcore technology, the cloud and how the IT environment was architected. If I was starting out my career, I may consider four areas. Fast-pace of innovation. I never had a personal framework growing up. I could have been slightly more strategic with my decision-making. However, career structure was never my preferred style. I always tended to follow my interests. This turned out surprisingly well because of how fast cybersecurity and IT has changed in the last twenty years. This fuels the conversation that concepts are often found to be old once they are written on paper. Consider the cloud; it was not long-ago this topic was unknown to most. There were a select few that realised cloud could change the world. Now we are talking about artificial intelligence (AI) and machine learning (ML), and how they will fundamentally change our lives, our jobs and the way companies operate. Adapt to change. As a cybersecurity professional, you must be open to and accepting of change. Stay on top of past, current and future trends, especially as an advisor – always looking left, right, backwards and forward to stay abreast of the changing landscape, threats and risks. Luck plays a role. There is an element of luck to meet the right people at the right time during your career. I have been fortunate to have support from many mentors. They often gave me advice I did not want to hear but needed. This advice was never under the pretense I would act; however, at the very least think through before moving forward. This was a tremendous boost to my career. Mentor and support others. Good career advice can be difficult to come by as mentorship is not often taught in school. I find some people are often too laser-focused on their own career and spend less time mentoring and developing others. We could do a better job within the cybersecurity space to support each other and the development of our next generation of professionals – this can start with universities by teaching students the benefits of giving back. With a hyper-competitive field, we could do more together if we better supported our peers and those coming up in their cybersecurity career.” How did you identify and explore opportunities during your career? “This is a difficult question because not many people ask. I have experienced three interchangeable approaches. More than remuneration. Early in my career, I was eager to learn more about the job title and remuneration package. As my career progressed, I learned from my mentors to ask better questions. What did I want to do today? How does this job description match with where I want to be tomorrow? What was the risk involved? Was this the right employer for me? Consider expanding your focus to illicit tangible insights from better questions. Zero insider information. I would consider assessing an opportunity without having a view from inside that organisation. While challenging, consider how your perspective may change and how the types of questions you may ask may differ with this limited visibility. I had to alter my approach when I went from a vendor to a Big 4 accounting firm. I did not have a network inside these organisations and thus revised my technique to obtain answers to the questions I needed before determining the best path forward. Values and purpose. Consider the importance of alignment between yourself and the organisation. Is there similar purpose? Do the organisation’s values align with your own? By asking more meaningful questions, we can better evaluate career opportunities when they arise.” Cybersecurity is intriguing, in-demand by the market and considered as an excellent career starter. Please be on the lookout for next month’s issue of Decoding Cybersecurity: Interview Insights with Leaders as the journey continues.