Episode 467 ·

Security & IT in Critical Infrastructure with John Sudduth, CIO of the MWRD of Greater Chicago

Today we’re talking to John Sudduth, CIO of the MWRD of Greater Chicago; and we discuss what it’s like running the IT function at the largest water treatment facility in the world, their approach to cybersecurity as attacks on critical infrastructure have become more common, and how working with Rimini Street has freed up John’s IT team to spend more time on IT-related tasks. 

All of this right here, right now, on the ModernCTO Podcast! 

Learn more about Rimini Street at https://www.riministreet.com

Learn more about the MWRD Chicago at https://mwrd.org

About John Sudduth:

Results-driven IT executive with expertise envisioning and leading technology-based revenue and growth initiatives. Impressive, fast-track management career marked by demonstrated ability to build high performing teams and achieve cross-functional business objectives. Valued member of senior executive teams, contributing a broad perspective to create pragmatic IT strategies and implementation plans designed for maximum return with the lowest costs. Consistent success in guiding information technology teams in the design, development, execution, and support of leading-edge technology to solve business problems.

About MWRD Chicago:

Established in 1889, the Metropolitan Water Reclamation District of Greater Chicago is an award-winning, special purpose government agency responsible for wastewater treatment and stormwater management in Cook County, Illinois. The MWRD provides services throughout an 883 square mile area which includes the City of Chicago and suburban communities. The MWRD serves an equivalent pop. of 10.35 million citizens; 5.25 million people, a commercial and industrial equivalent of 4.5 million people, and a combined sewer overflow of .6 million people. 

The MWRD's 554 miles of intercepting sewers and force mains range in size from 12 inches to 27 feet in diameter and are fed by approximately 10,000 local sewer system connections. 

The MWRD's Tunnel and Reservoir Plan (TARP) is one of the country’s largest public works projects for pollution and flood control. Four tunnel systems total 109 miles of tunnels, nine to 33 feet in diameter and 150 to 300 feet underground, are in operation. Three TARP reservoirs are in operation and construction is in progress on the remaining 6.5 billion gallon portion of the McCook Reservoir. 

The MWRD owns and operates the Stickney Water Reclamation Plant, the world’s largest, in addition to six other plants and 23 pumping stations. Treating an average of 1.4 billion gallons of wastewater each day, the MWRD's total wastewater treatment capacity is over 2 billion gallons per day. 

The MWRD recycles all biosolids and has an aggressive outreach program.

Transcript

(Intro Narrator at 00:00:04) Hello, my friends. Today, we're talking to John, CIO of the Metropolitan Water Reclamation District of Greater Chicago, and we discuss what it's like running the IT function at the largest water treatment facility in the world, their approach to cybersecurity as attacks on critical infrastructure have become more common, and how working with Rimini Street has freed up John's IT team to spend more time on IT-related tasks.

(Intro Narrator at 00:00:33) All of this right here, right now on the Modern CTO Podcast.

(Joel Beasley at 00:00:43) Here we go. This is the Modern CTO Podcast.

(Adam Larson at 00:00:55) You're currently CIO at—do you call it the MWRD, Metropolitan Water Reclamation Department or District?

(John at 00:01:04) District. District. Metropolitan Water Reclamation District of Greater Chicago, but we use MWRD as short.

(Adam Larson at 00:01:13) Cool. So tell me, how did you initially get into technology and eventually find yourself there?

(John at 00:01:20) Oh, wow. Great question. So my journey started many years ago, once upon a time, right? Like you, I was interested in computers in high school, but my high school days are probably way before yours, I'm sure. You know, I started off in high school doing programming in BASIC and then Pascal. So, I've always liked to fix things. I've always liked electronics and ended up taking an aptitude test, believe it or not, and it basically said I would be good at two things: counseling and computers.

(John at 00:01:59) So I decided to go to computer, right?

(Adam Larson at 00:02:02) So tech leadership.

(John at 00:02:04) Exactly. You know, which wasn't a thing, believe it or not, back then. So, you know, I started my career. I ended up going to school for electronics technology and ultimately computer science. And I went to Northwestern University for undergrad and grad. And actually, before I finished college, you know, there were job offers already on the table because back in the early nineties, there were not a whole lot of computer people out there, and there were fewer who were actually going to school for IT and computers. So I ended up taking a job as a, what was called a computer technician at the time. So my job was literally taking returned computers out of the box and trying to fix them and then returning them back to a customer. So at that time, you know, Best Buy wasn't around. So people literally shipped their computer back to companies. We'd repair them and then send them back to the customer. So that was my very first job in IT, was a bench tech. So from that point, I, you know, learned a lot just from doing that.

(John at 00:03:13) I started networking. I wanted to learn networking. I went into networking back in that time. This was pre-Ethernet. So I was working on what were called token ring networks at the time. So that ultimately evolved into working on Ethernet networks and Novell. I ended up, couple of years later, working at a global law firm as a, what was called a level two computer technician at the time. So my job was basically—so it goes through these floors, level two. Hey, moving up the ladder, right? But, you know, I was basically the break-fix person to go and fix computers out on the floor. So from that point, my career, you know, really started to take off. So I went from being a level two tech to actually being a network administrator, working on at the time what was Novell 3.5 and then Novell 4, and we were transitioning to Windows.

(John at 00:04:12) So got an opportunity to learn a lot about Windows NT 3.5 and Windows NT 4. And then from that point, an opportunity kind of fell in my lap, per se. A company that I worked for needed a database administrator. Someone just left, and my boss came to me and asked me, would you be interested in learning database administration? Well, why not? So, went through some training. I learned a lot about Microsoft SQL Server, and I became a database administrator, which was odd at the time to go from, you know, a person who was hands-on hardware over to the software side. So, did that for about five or seven years and decided that I wanted to move into management. So, you know, I started looking for opportunities in management.

(John at 00:05:01) Landed an opportunity at a professional services firm where I was managing a team of one, which was myself. So, got an opportunity to actually, like yourself, build a team out at that point. So I had created a team from just myself up to about seven or eight people. Got another opportunity—my boss at the time left—to run the entire enterprise operations group. So, you know, got a promotion, bigger job. From that point, I decided that I wanted to try and break into the C-level, which ultimately I did. I was CIO for the Illinois Department of Public Health. So you probably heard a lot about them over the last few years with COVID, but yeah, I actually ran IT at that organization for about two and a half years. And then I came here to the MWRD where, as you said, we treat wastewater and stormwater for all of Cook County. So have a pretty significant offering here.

(John at 00:06:06) We actually have the largest wastewater treatment plant in the world at our Stickney location. We treat about 1 billion gallons of water per day, and we have capacity to go up to about 7 billion. So we can treat a lot of water.

(Adam Larson at 00:06:23) That's crazy. That's really cool. So was it a big learning curve? Or are you basically doing a lot of the same stuff implementing? Because you're running the IT organization for the water treatment facility, but did you have to learn a lot of specific water treatment stuff when you joined?

(John at 00:06:45) Well, yes and no. Yes, in the aspect that what I've learned over my career, Adam, is that IT is IT. So when I worked as a DBA at that firm, it was the same challenges, the same offerings in IT as it was for professional services, as it was for legal, as it was for IDPH, and as it is for MWRD. So I think IT transitions throughout industry. Now there are specific components to each industry. And with MWRD, it's the treatment side of it, or what was called our SCADA network. So that's the actual network that's completely isolated. That's the part that people, you know, bad actors really like to try and attack because they can flood the city and those types of things. So I had to learn a lot about that.

(John at 00:07:36) You know, I had no real experience in the water industry. So did a lot of reaching out, had opportunity to network with people within the industry, went to a lot of conferences, met with the people within, you know, currently within the organization—the leaders of Metro Water—and just learned a lot, I mean, to the point now where I'm seven years in, and I'm actually considered one of the industry leaders in IT for utilities, you know, not just wastewater, but drinking water and, to a certain extent, gas and electric.

(Adam Larson at 00:08:16) That's awesome. And so you mentioned in there about how, like, bad actors are starting to target critical infrastructure. Do you have a CISO at the MWRD, or are you responsible for the security apparatus? What does that look like?

(John at 00:08:31) Right now, I'm responsible, but it just so happens that I'm about to put out a job description. I'm looking to hire a CISO.

(Adam Larson at 00:08:38) Oh, nice.

(John at 00:08:40) Yeah. I'm ready to actually get those duties transitioned over to someone else. I've basically been playing the role for the last few years. So it's been a hybrid role of CIO and CISO, but I'm ready to bring someone in to kind of take our security to the next level.

(Adam Larson at 00:08:59) That's really cool. Well, you're in a good place. I'm sure we have lots of really qualified security people that listen to this because we do some pretty security-heavy episodes. So one thing I wanted to ask you about was—somewhat recently, the water treatment facility near my hometown in Bradenton, Florida, had a hack, and there was, like, a big scare. And that was kind of my introduction to critical infrastructure as, like, something that gets hacked. So I'm curious, when another facility gets hacked, what's the communication like between them and the broader industry, and how do you learn from those other attacks to shore up your security?

(John at 00:09:42) That's a great question. So the industry as a whole is very collaborative. I'm constantly at conferences. I'm constantly speaking or listening to webinars, or there are various groups that I'm a part of, like one being a group of CIOs just for freshwater and wastewater utilities throughout the entire country. We actually have partnerships with even other countries because people want to understand our operations. In some countries that don't have the infrastructure to treat the amount of water the way that we do, they're trying to learn from us, and they've kind of latched on and started to learn about how we do information security also. So, you know, it's really speaking with others in the industry. It's really kind of communicating out. I won't name the city, but there was a massive exploit at a city, and the person is part of our CIO group—the person who runs their wastewater treatment IT department.

(John at 00:10:48) So he literally put out a message to our group saying, "Hey, we're in the midst of a ransomware attack right now. Is there anyone with experience who can help us?" You know? And within minutes, you know, we're on a call, you know, helping him and talking them through it based off our experiences. So it's a very, you know, open and collaborative industry, and we really try and jump in and help each other when we can.

(Adam Larson at 00:11:13) That's really cool. So what are, like, the typical threat vectors, or how do attackers typically get into these critical infrastructure facilities?

(John at 00:11:24) So it's usually through antiquated software. So it's the traditional old exploits, right, or vulnerabilities. It's antiquated software not being patched. It's undocumented, unauthorized devices that are sitting out on your network that, you know, no one has touched in eight, ten years, but it has all these open ports or what have you. So, and then the primary way right now are through people. And that's not just within critical infrastructure, but that's across the board. Like you mentioned, the situation by your hometown, that was due to a person, you know, kind of leaving an exploit open. So, you know, those are probably the key ways: antiquated software, people, and just devices sitting out there.

(Adam Larson at 00:12:14) So do you have, like, some anti-phishing training or general security mindedness training for your employees at the MWRD?

(John at 00:12:24) Absolutely. You know, people are really the number one target that bad actors go after. So we actually have mandatory cyber awareness training that all of our employees have to go through at least once per year. We actually put metrics behind the training. We do what I've coined the term called "white phishing." So we send out, you know, mock phishing exercises to try and get people to click on things. And, you know, when they do, we actually push them to take additional training to say, "Hey, you know, this happened, and do you know why you clicked on this?" And, "Do you understand that it's...?" And it's... So, yeah, I think that that's something that's happening throughout every organization right now. I mean, if it's not, it's something that should happen at every organization right now.

(Adam Larson at 00:13:17) Absolutely. Yeah. I get emails from my CEO sometimes that are not him. And, yeah, it's definitely important to be aware. But so what would you say is like—I'll do a bad interview technique here and ask you two questions at once. What are some of the most important things that people on the front line can be doing to prevent bad actors getting in, and what are some of the most important things that management can be doing to help them? Obviously, the training's going to be one of them, but do you have any other tips?

(John at 00:13:56) Yeah. It really is to be aware. It's to understand that cybersecurity is not just an IT initiative. It's a company-wide initiative. So, you know, you as an employee of the company, it's your responsibility to be cyber-aware and, you know, to practice good cyber hygiene. So that's something that we constantly push. And that's from an individual perspective. From a management perspective, I say that as managers, we really have to push to ingrain cybersecurity into the fabric of our organization. So, you know, understand that this threat is out there as managers and try and provide the necessary resources to really combat it, to educate our staff and our employees within an organization, and to be supportive of the IT department. You know, we get beat up pretty badly sometimes. You know? So, it helps when management across the organization are all on one accord and understand that, you know, we have to have a really good cyber hygiene across the organization.

(Adam Larson at 00:15:10) Yeah. From a lot of the people I talk to and just the people that come on the show and Joel talks to, it seems like it's becoming kind of a way of the past to have IT report to finance and have more of a disconnect between security and the rest of the organization. I think especially is probably really sped up by the pandemic and remote work and, of course, then security has to be a top priority. Because when I first started here at this podcast, it was, like, a hot topic of, like, "Man, how can you convince your fellow executives that security is important?" And now it's everyone's just like, "Yeah, of course security is important." Like, that's the number one thing, of course. But so I think that's a really positive trend for sure.

(John at 00:16:00) Mm-hmm. No, I would absolutely agree. And, you know, what's really happened—and I use the analogy of a medieval castle, right? Traditionally, when we looked at organizations and IT security, it was like we were guarding the crown jewels in the castle. So we have the big fence, you know, the wall, we have the moat, and then we have the alligators in the moat, you know, and there's the keys that have actors down. But what's happened, particularly to your point with more people going to a remote workforce, is that now those crown jewels—that being the data—are actually going out with people. So you're going outside of, you know, that protected castle. So people have to be a lot more aware that if someone gets into just their computer and at their home network, that they could open up an entire organization on the back end. So that's something that we also promote and try and make sure that people understand as we went to a mobile workforce.

(Adam Larson at 00:17:10) Yeah. I think it was the CTO of Zscaler that described this really well. He said that people are transitioning from, like, a coconut security model to an avocado security model. And what he means by that is, like, the coconut just has a hard shell, and then everything's just loose liquid inside. If you get through the shell, you're in. You have everything. But with an avocado, you got, like, the shell, and then you got, like, a little bit of resistance of a gooey layer. And then on the inside of the organization, there's still a hard core of security that you can't get to, and that's, like, preventing privilege escalation and preventing movement from within the organization once the bad actors are in. He did a much better job explaining it than I just did.

(John at 00:18:01) But... No, I get it. That's a great analogy. I like that.

(Adam Larson at 00:18:05) Yeah. Well, okay. So I'd want to talk a little bit about the company Rimini Street with you because we were originally introduced through them because we had their president, Sebastian Grady, on the show a while ago. And the main thing I remember from that episode is that he gave some excellent leadership advice, and he also made a great case for using third-party software support instead of the software support that comes direct from enterprise software providers. But can you tell me a little bit about your relationship with Rimini Street and what you've been working on with them?

(John at 00:18:49) Absolutely. So we use Rimini Street for a third-party support provider for our ERP. And we've used them for almost four years now, coming into four years.

(John at 00:19:03) And the primary driver was really around increasing our customer satisfaction. And when I say customers, I mean our internal customers. Those are the customers that we serve throughout our organization.

(Adam Larson at 00:19:17) Can you clarify real quick? What are those internal customers? What are they getting?

(John at 00:19:23) So this would be our finance department, our procurement department, everyone who subscribes to IT services, which is the entire organization. Yeah. So, you know, part of our struggle was that when we were with our prior provider, we, in my opinion, could not get adequate support. So we could not turn things around fast enough.

(John at 00:19:47) So we ended up with a pretty large backlog because things kept coming up while other things were not getting resolved. So one of the reasons that I wanted to go to a third-party provider was to improve that customer service, which has worked out tremendously, honestly. So now we're at a point where we don't have a backlog because we're able to actually transition that support over to Rimini Street, and they handle it in a very rapid manner. They also provide us with a great check-in point once per quarter. So I basically meet with our account manager once per quarter.

(John at 00:20:28) We go through various tickets that we've had over the quarter. You know, they do a litmus test on how well they're performing and, you know, trying to see if there's anything that they could perform better on. So it's been a great partnership. They've worked very well with us. They've allowed us also to take part of our internal IT team and have them focus on other things while they're handling, you know, supporting our base systems or doing other support around our ERP environment.

(Adam Larson at 00:21:00) That's awesome. So, like, before, you had a bunch of IT people spending a big chunk of their time on customer service, more or less, and now that's taken care of and they can spend time on IT things?

(John at 00:21:15) Exactly. Exactly. Yeah.

(Adam Larson at 00:21:17) That's great. Was it like a big transformation implementing this?

(John at 00:21:24) For our organization, it was a big transformation. It was something that had not been done prior to my coming on board. So it was really new and, you know, with new things and with change comes angst. So there was some angst on our business side. And once we actually got in or once, you know, once I was able to convince the organization that this was the route that we needed to go, we got our partner Rimini on board.

(John at 00:21:54) And, you know, as soon as they started to chip away at that backlog, we started to build credibility with our internal customers. And, you know, to the point where it was like, oh, wow, this is great, and we should have done this years ago. You know? So they, Rimini Street, really helped us build that credibility. And, you know, it kind of reinforced that we're going in the right direction.

(Adam Larson at 00:22:19) That's awesome. I'm sure it's a problem, or not a problem, but a challenge for a lot of executives encountering inertia within their organization when they want to implement a new initiative. So what was convincing when you made the case to your colleagues to make this big change? Because that's, I'm sure that could be helpful for people listening.

(John at 00:22:45) So it was really about kind of laying out what could be. Right? It's like, we know where we are. Here's where we are. We have this backlog. We have inadequate support. But if we were to make this transition, you know, it may be a little bit painful as we're making it. But once we get to the other side, here is what we could see. And as we started to, once we decided to, like I said, make that transition, we kind of hit the low-hanging fruit and, you know, we started to build that credibility, and it just created a flywheel effect to where our customer satisfaction shot up tremendously, our internal customer satisfaction. So it's really about, you know, kind of painting a utopian picture and getting your internal stakeholders or your internal customers to really see what could be. Right? Because, like I say, you know where you are, but you have to kind of show them where you could be.

(Adam Larson at 00:23:49) So, obviously, this has freed up a lot of time for your IT team to do IT stuff. What's some of the cool projects that are going on at the MWRD that you're excited about today?

(John at 00:24:04) It's a good question. So, you know, we're at the tail end of a cloud migration. One thing that we really doubled down on was going to the cloud. So we're about 90% in the cloud right now, which is, you know, light years ahead of a lot of government organizations at this point.

(Adam Larson at 00:24:26) Yeah.

(John at 00:24:27) Yeah. We had the opportunity to implement an ITSM, IT service management solution. We were able to, by going with our managed services provider, we were able to cut our ERP support maintenance by 50%. So we basically reallocated the savings to kind of help ramp up our internal IT department. So we implemented an IT service management solution. We're also, you know, really constantly working on enhancing our security posture. So, you know, hiring a CSO. We're constantly doing vulnerability scans and that type of thing. So, you know, I'm hoping, and this is a little bit futuristic, but we're looking at possibly doing a red team, blue team type setup, you know, which could be a great project. Also, we're kind of rearchitecting our SCADA environment, the environment that, like I said, runs our treatment facilities.

(John at 00:25:26) So that's a massive project that we're currently working through right now. So we have some good things going on.

(Adam Larson at 00:25:34) That's really cool. So are you implementing any kind of IoT stuff at the facility right now?

(John at 00:25:41) We are. We've actually been implementing IoT for almost two years now. We've implemented devices out in our waterways to actually measure various water levels. So, and this is a great example or utilization of IoT. Prior to having these IoT devices, we literally had people who would row out in a boat to the middle of the waterway and measure with a stick the height of the water.

(John at 00:26:15) Yeah. And then they would write that down on a piece of paper, row back to shore, and take that paper and enter it into a computer system. So we modernized that process. We actually got some IoT technology with sensors.

(John at 00:26:39) So now where we are is we are taking that data real-time and actually presenting it out in various dashboards and utilizing the data to make real-time decisions. So we literally went from a 1940s process over to a modern-day IoT implementation. And, you know, the entire thing took about a year. We deployed about 40 sensors throughout various waterways, and that's actually continuing now. So, you know, we're really looking at modernization around that arena with IoT.

(Adam Larson at 00:27:17) Well, do you still get to give those people another excuse to get out and row and be on the water?

(John at 00:27:24) You know, honestly, Adam, it was an easy sale. If you've ever rowed out to the middle of a waterway in Chicago in January.

(Adam Larson at 00:27:33) Oh, yeah. Yeah. When you put it like that, that does seem like an easy sell. See, I'm a Florida man. So I always think of rowing as a fun activity.

(John at 00:27:50) You know, great June, July, August. But come December, January, February, not so much.

(Adam Larson at 00:27:57) Right. Yeah. It still needs to get done. Yeah. So with having these devices out there, obviously, they've got to be connected. And that's, we were talking about security earlier, that's increasing your threat landscape, correct. So how do you address the security of all of these sensors and IoT devices out on the waterways? And, also, I guess what I'm really curious about is, what is the real threat of those being hacked into? Like, what could they do if they got access to those sensors?

(John at 00:28:35) It's a real threat. You know, the threat is not an internal exploit per se, but what happens, and what people have to be aware of, well, actually, let me take a step back and answer the first part of your question. So, you know, you have to go into any implementation of new technologies with a security-first mindframe. Right? So you have to understand a security model around that device. You have to understand what vulnerabilities you may be opening by implementing this new technology and then, you know, kind of mitigate those risks. So you have to think about it ahead of time. The last thing that you want to do is go throw some stuff out there and then, you know, kind of let the chips fall where they may. And that's going to lead you to a bad situation. You have to, you know, think security-first and pick a solution that has a good security profile within it. So, you know, the second part of your question is, as I said, it's not a vulnerability that could open up the back end of our organization. The threat is around weaponizing those IoT devices. So what's happening out in the marketplace right now, and this is for an abundance of IoT devices. This includes, like, you know, home devices like thermostats and refrigerators, things that we don't traditionally think about as OT devices, but that's exactly what they are.

(Adam Larson at 00:30:05) Yeah.

(John at 00:30:05) You know, they're connected to the Internet.

(Adam Larson at 00:30:07) A Roomba. Yeah.

(John at 00:30:08) Exactly. Exactly. A great example. So what's happening is that these bad actors are dropping code on these devices, and they're weaponizing them to do DDoS attacks. So they basically, you know, get code on your device. You may not even know it's there. They own your device, and then they take, you know, 1,500 of these and point it at someone's website and bring it down. So that's kind of where the threats are right now.

(Adam Larson at 00:30:39) That's crazy.

(John at 00:30:39) Yeah. That's where the threats are right now. You know? So that's why I say when you implement those types of technologies, you have to have a security-first mindset.

(Adam Larson at 00:30:48) That makes sense. That's, man, that's really funny to think about, like an army of refrigerators taking down a website.

(John at 00:30:55) That's exactly what it's, actually, it's happened. Believe it or not, it happened. That's how Amazon was taken down. It was a botnet attack.

(Adam Larson at 00:31:03) Really?

(John at 00:31:03) Botnet attack. Yes.

(Adam Larson at 00:31:04) Oh, man. That's crazy. Wow. So I'm glad to know that you're on the case with your water sensors, and those aren't going to take down Amazon next time. But we're getting a little bit close on time. Before we wrap up, I want to ask you a couple leadership questions as you're an experienced tech leader. Is that cool?

(John at 00:31:28) Absolutely. Yeah.

(Adam Larson at 00:31:29) Awesome. So one thing I'm curious about is when you are new to leadership or new to leading at an organization, like, you're new to an organization, how do you establish yourself as a leader within the team that you're just put in charge of?

(John at 00:31:48) Mhmm. So I think the first thing that you have to do is listen. Right? Whenever I'm going into a new leadership opportunity or position, I make sure that the first thing I do is meet with my direct reports. Those are, like, the first meetings that go on my calendar.

(John at 00:32:09) Then from that point, I meet with business leaders throughout the organization to understand what their challenges are, what their priorities are. And I kind of bring those two things together. So, you know, I tease out current project struggles from my new team per se and kind of pull that into an overarching strategy, you know, from what I get from talking to the business side. But I think the key to it is really listening, understanding, you know, letting everyone know that you're not the bull in a china shop. You're not here to kind of throw everything off-kilter, but you're really here to understand and kind of push things forward. So it's really listening, understanding, and then putting together a plan after that.

(Adam Larson at 00:33:00) Nice. So since you're hiring a CSO right now, I'll kind of talk to you about something that I've had some trouble with as, like, I started as a team of one, like you talked about earlier, and grew that. And so most of the time when I'm hiring someone, like, or when I'm hiring a new role, I'm hiring someone to do a part of my job that I no longer have the bandwidth to do. And I no longer have the bandwidth to do that job well, and I definitely, like, struggle to find the bandwidth to write up solid documentation on how to do it well and find the bandwidth to train the person on how to do it well. Like, it's a lot because if you're the only person that knows how to do it, you're the only person that can train them. And you're also wearing a bunch of other hats, doing a bunch of other things. So do you have any advice for that when you're hiring someone to do a job that you currently do while you're also trying to do a lot of other things?

(John at 00:34:08) Mhmm. So whenever you're hiring, you have to find the right person for the position. So the first thing that you need to do is understanding what you're transitioning over, you know, particularly if you're taking something off of yourself and putting it into a new position. So if you, you know, you jot down, it doesn't have to be a detailed description, but these are things that I'm transitioning over to this new position. And this is even before you start recruiting. And you basically start looking for a person who has the experience to actually do those things. Right? Because you, in most cases, want someone who can really hit the ground running because, to your point, you're not going to have the time to train them. So, you know, you can't go through a 90-day training exercise. It's, you know, here are our priorities. This is what we're expecting you to do. It's like, go do it. So I truly believe in empowerment of my direct reports and, you know, in a lot of cases, their direct reports. I always say that we're a team. I mean, I was a three-sport athlete. So I believe in teamwork. I believe in that everyone has their role to play, and you find the best person to actually play that role or play that position. And that's the same mentality that I've kind of brought to leadership and IT is that we're looking for the best security person that we can find. And if I can pick that person, hire that person, I don't have to worry about it anymore.

(John at 00:35:43) Right? So it's like, you know, call me if there are any issues or call me if there's anything that you need for me to do. And I try and explain that my job as a leader and as CIO of the organization is to remove obstacles from your way. It's not to tell you how to do your job. It's to, you know, get things out of your way to empower you to do your job.

(Adam Larson at 00:36:08) Nice. Yeah. That totally makes sense. I also definitely think of my team as just like, we're all the same. We all have the same goal. Just trying to, either in my job, it's make these podcasts great for companies. And, however we need to go about doing that, whatever I need to do for you, for you to do that, that's what I'll do. Alright. So I got one more question for you.

(Adam Larson at 00:36:38) What is either a great piece of advice you received early on in your career or something you wish you knew when you started in your career?

(John at 00:36:50) Oh, wow. That's a great question. I would say it's really been a gradual learning experience. And I think that had I known early in my career that I had an opportunity to suck up knowledge from people who had been around much longer than I had at the time, that it would have saved me a lot of bumps and bruises. And the reason that I say that is because you can learn so much from people who have been a part of an industry, who may have so much knowledge within that industry.

(John at 00:37:34) Now these may not be top people. They may not be top leaderships. These are the technicians out on the floor. These are, you know, the mainframe technicians. And I really wish I would've sat down a lot more with them to kind of soak up their industry knowledge because I was a bit of a hotheaded kid, you know, out of college. I'm thinking I'm knowing everything about IT, but there are some people who have been around a lot longer than I did that I could have learned a lot more from that would have saved me a lot of headache down the road. So, you know, for anyone who's kind of coming into the industry or who's kind of new to the industry, definitely leverage your teammates, definitely leverage the people around you, and listen. And, you know, try and utilize their experience to your own advantage, not to make certain mistakes.

(Joel Beasley at 00:38:35) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.