Santarcangelo Interviewed on “The Web Squeeze” – Listen In!
On Friday, The Web Squeeze posted an interview with me. We had a blast discussing backups, passwords, building more secure websites and a bit about the human paradox and Into the Breach.
I’m impressed with The Web Squeeze (http://thewebsqueeze.com/) and hope to get more involved in additional ways.
In the meantime, I really enjoyed the banter (enough to really get me thinking about getting a new show or two going) and the professionalism extended to me by Jacob and Linda.
I hope you consider taking a listen; more – share it with the folks you know in development and see what they say. Use this as a springboard for conversations.
Here is the link: http://www.thewebsqueeze.com/freelance-podcasts/into-the-breach.html
Into the Breach – Audio Series – Chapter 7 (Putting the Strategy to Work: A Pilot)
Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What you’ll find in this episode (Chapter 7)
The strategy has been revealed. The fundamentals of what is now The Catalyst Method have been shared (note: if you want the update on The Catalyst Method, contact us to learn more).
So how do you implement in a way that gets results?
In this chapter, “Putting the Strategy to Work: A Pilot,” Michael explains the basic approach – with key insights – to engaging people in the process of protecting information. Learn how to select the pilot approach that works best, build the team and plan a strategy that drives tactical and strategic success.
There is no “one-size-fits all” approach, and this chapter lays out how to make the right decisions the first time. Get a jumpstart on success with this chapter.
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
- Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
- Subscribing to The Security Catalyst podcast & blog to get more insights
- Learn more about The Catalyst Foundation Series – proven success for security initiatives to excite, ignite and turn insiders into allies who reduce business risk!
Go deeper Into the Breach with Michael Santarcangelo with EMC
Each month, EMC pulls back the curtain and provides more insights and a deeper discussion with Michael Santarcangelo about the elements in this chapter. Learn how to harness the power of their people to inform and improve the risk management process in a matter of weeks. Go to www.configuresoft.com/securitycatalyst today to register now and listen to the recorded sessions from before and get access to the latest session.
Podcast: Play in new window | Download (7.5MB)
Join the Journey — Launching Catalyst onTour and coming to your house!
If you had one hour to pack your home, your office and head out – could you do it?

Mount Rushmore, Nov 2008
What if you had three months? Six months?
Most of us answer this question with a series of questions along the lines of what, when, for how long, and why? A simple question with many dimensions and contexts for certain; a question I asked myself on a regular basis over the last five or so years.
When I worked for Accenture (back when it was Anderson Consulting; when it first developed a security practice) I witnessed something I vowed I would never repeat: managers literally watching their children grow up in pictures. This was before video conferencing was available on laptops (and is no judgement on those who choose this path), yet it ingrained in me a sense that when it came to my family (which I didn’t have at the time), I would choose a different path.
And we did.
Never alone, Tricia, my wife (and quite frankly, my soulmate, best friend and partner in this journey), decided with me that we would do things differently. It started before we had children, and evolved when we did. The simple path made sense initially – travel by car, loaded with stuff, and time in hotels. By the time we actually understood the phrase “curtain climbers,” we realized it was time for a change. I’ll share the story of how we got started with our RV in the future, but it evolved into a 40′ RV that allows us to travel in style — as a family.
Here is an article from October 2008 that captures some of the benefits: Family man (By KRISTI L. GUSTAFSON, Staff writer)
We’ve been going out for “trips” that started at one week and progressively built up to a few months. As much as we enjoy living near family, we always felt a bit sad to return to our ’stick house.” Even the kids would ask if we could stop short and stay over in a rest area, for one more night on the road. When we got home, the house felt too big, distant and we pined to get back on the road.
Lumbering home from the Talladega Super Speedway along the scenic byways of the East Coast, we engaged in the questions again – but this time we asked deeper questions and instead of dismissing the answers, we researched the answers to uncover our truth: it was time to go.
We flipped the switch. The mental one that says, “Let’s do this.”
And now after six months of final planning and execution, I’m excited to share that we are leaving our things behind and traveling the country as a family. We’ve dubbed the journey as being ‘onTour’ as it dovetails with my professional speaking, seminars and a new program we’re making available around implementation guidance.
We recently were interviewed on the NBC Today Show – and are currently on the website as a counterbalance (note: while some have sold their houses to weather the recession, we have chosen to divest our “stuff” in search of a simpler life and the ability to realize our mission):
Web only: Another family’s decision to hit the road. Nov. 4: Michael Santarcangelo explains his family’s decision to sell their house and hit the road full time. http://today.msnbc.msn.com/id/26184891/vp/33534656
Sharing Our Journey
There is more to the story – and we intend to share and inspire others to join us. In fact, we’re in the process of setting up a blog to chronicle our travels, but also to explain life on the road, running a business, “road school” (imagine learning for the whole family, as a family) and whatever else we come across. But this realization of our desire to hit the road is the outward sign of over two years of planning, thinking and preparation.
We are embarking on a journey to share a positive and needed message to the individuals, teams, organizations and communities in which we travel. We will meet people where they are – literally and figuratively – and demonstrate that it’s possible — and rewarding — to manage people, information and risk (calling it security is misleading and limited).
Put Up or Shut Up
Here’s the thing – we practice what we preach.
We have sold, donated or otherwise recycled a lot of stuff (a lot of lessons learned in that process that I hope to relate to information protection in the future) and focused on living simply. The process has been amazing – more focus on connection and moments, less focus on material things.
We are liberated.
We will chase our passions, engage with friends and make new friends, connect, learn and share. This journey is about passion, about people, about life.
Writing this, I cannot wait until the diesel is rumbling and we’re heading out — hopefully to meet you.
What does this mean for you?
It means a lot of things:
- As we travel (we have “goalposts and destination dates” but the journey is fluid), we hope to meet and engage with as many people as we can – through a variety of mechanisms. In the meantime, engage with me through twitter, skype, email, by a campfire, in classrooms, where ever and whenever.
- A renewed focus on speaking, seminars and implementation for organizations and communities (we’re mobile and able to go anywhere)
- More time to focus on the TSC online experience, including writing, podcasting and other elements to engage and influence positive change
I have more planned – and in the coming weeks and months, I will share, ask for feedback and work as a catalyst for change, an advocate for the power of people, connecting individuals to the consequences of their actions, helping to turn insiders into allies who reduce business risk.
The Freedom of the Road, the Power of The Catalyst
As we prepare to head out, we are flexible for January with plans to head West in February and March in California — and mapping our travels between the two (which oddly may make a turn toward Baltimore/DC in early February
. We have a lot of opportunity, and total flexibility. And while we have limited availability to engage – we’re actively seeking organizations that realize people are the answer, and need the guidance of the catalyst to get them results.
I can offer amazing incentives and opportunities for the right organizations…
Not sure what I do – or how I can help?
Check out the website, or flat out give me a call (the first call is on me). I have a rare blend of skills, passions and abilities, and I enjoy creating custom solutions built on proven frameworks and principles. Sometimes it’s a powerful keynote, seminar or free-form “catalyst session”
My focus is the human ecology of the organization – harnessing the power of people to turn insiders into allies who reduce business risk. Not sure how that works – call. We’ll talk. I’ll explain.
I work with companies of all sizes – and selectively support solution providers who want to differentiate and leverage the power of the approaches we have developed for their prospects and clients.
Need a boost turning insiders into allies?
Good first step is to read or listen to Into the Breach. I spent a few years researching, writing and ultimately distilling it to be an easy, powerful read. I just announced a “team inspiration” holiday pack – and it’s the perfect way to figure out if I’m a fit for your needs (if you read the book, nod your head and say – I want that – then you’re a fit).
If that’s you – give me a call, send me an email or reach out in some other way — and you just might get a chance to see the RV and spend some time with me and my family. And since we’re mobile – if you have an event where you know my approach and vision would get the results you need – call me, and we’ll find a way to make it work.
Into the Breach – Audio Series – Chapter 5 (The Strategy to Protect Information)
Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy.
This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What you’ll find in episode 6, Into the Breach: Chapter 5 (The Strategy to Protect Information)
Chapter 5 is the introduction to Part II of Into the Breach — where the focus shifts to looking at what needs to be done. I outline a powerful, yet simple, approach dubbed “The Strategy to Protect Information.”
Key is the focus on information, not data, and the three steps that any organization must follow in order to be effective. The balance of Part II explains how – but just learning and understanding the three part strategy is transformative.
After listening to this chapter, you will know the strategy and be able to apply it to your current challenge — small and tactical or larger and organizational.
The timing works well as 2010 initiatives are considered – and questions are always welcomed at getresults@securitycatalyst.com, by engaging with me on twitter (http://twitter.com/catalyst)
Unleash the full power in time for the new year: Announcing the Team Inspiration Bundle
Imagine the power of presenting a hand-signed, hard cover version of Into the Breach: Protect Your Business by Managing People, Information and Risk to a member of your team, an executive or even a partner or client to give them the very keys necessary to refresh, re-energize and refocus for an exciting year ahead.
As we head into 2010, Michael Santarcangelo and the entire The Security Catalyst team is focused on celebrating the good of people and amplifying the positive. Into the Breach reveals the insights and sets forth the path for any person or organization to follow to get results that turn insiders into allies who reduce business risk.
This is a gift that opens the doors to more and unlocks the ability to harness the power of people. More, this book can be accompanied with an eBook or audio book version – and the resources of The Security Catalyst Online to set the stage for a transformative year ahead.
CLICK HERE to order the special 10-book or 20-book package at a deep discount by December 24, 2009.
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
1. Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
2. Subscribing to The Security Catalyst Online Blog and Podcast to get more insights
3. Hire Michael to deliver guaranteed solutions for your organization that turn insiders into allies who reduce business risk
Not enough? Need more?
Go deeper Into the Breach with Michael Santarcangelo in December, courtesy of EMC
In December, EMC will release the next recording of Michael Santarcangelo — behind the scenes — to journey deeper into the ideas behind the Strategy to Protect Information. Go to www.configuresoft.com/securitycatalyst today to register now and listen to the recorded sessions from before and get reminded to download the December session.
Podcast: Play in new window | Download (12.8MB)
Into the Breach – Audio Series – Chapter 3 (Breaking the Security Diet)
Episode 4: Into the Breach: Chapter 3 (Breaking the Security Diet)
Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What you’ll find in this episode (Chapter 3)
Breaking the security diet is recognition that what happens in organizations today is more akin to a crash diet than a healthy approach to securing information. In this chapter, Michael reveals the high cost of this “fad diet” approach and shines a light on the new fad diet: encryption. However, there is a solution, and Michael explains how to break the fad diet, improve leadership and engage individuals. A pivotal chapter in the book, designed to create a fundamental change in the way organizations and individuals protect information.
Go deeper Into the Breach with Michael Santarcangelo in October with EMC
In October, join Michael Santarcangelo for a live conversation to journey deeper into the chapter. During the conversation, hosted by EMC, Michael will:
- Reveal the ideas and concepts that may have been pared from the chapter you just listened to
- Expand upon or update the elements in the chapter you just listened to
- Answer questions in a candid and direct style – focused on delivering insights that lead to results
Go to www.configuresoft.com/securitycatalyst today to register now and listen to the recorded sessions from before and get reminded to join in for the September session.
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
- Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
- Subscribing to The Security Catalyst podcast & blog to get more insights
- Checking out the upcoming schedule to meet Michael (and his family) “onTour” – as they travel the country by RV (working on Dallas, Phoenix and San Francisco, with a likely stop in Atlanta and maybe Charlotte)
Podcast: Play in new window | Download (11.0MB)
Into the Breach – Audio Series – Chapter 2 (People Just Want to Do Their Jobs)
Episode 3: Into the Breach: Chapter 2 (People Just Want to Do Their Jobs)
Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy – to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What you’ll find in this episode (Chapter 2)
Chapter 2 reframes the challenge with powerful insights about the way people “just want to do their jobs.” Michael introduces what he calls the two principles – a powerful concept about how people do their jobs, and an eye-opener that leads to improved interactions. The corollary to these principles is also explored, along with guidance on what to do about it. With a focus on individuals, Michael explains, “Compliance is not a video game” and reveals that a common approach of “exclusion” is creating more harm than good. The chapter wraps up with a discussion of “the human response to pain” – with a common example played out in organizations everywhere.
Go deeper Into the Breach with Michael Santarcangelo on September 16th
On September 16th, join Michael Santarcangelo for a live conversation to journey deeper into the chapter. During the conversation, hosted by EMC, Michael will:
- Reveal the ideas and concepts that may have been pared from the chapter you just listened to
- Expand upon or update the elements in the chapter you just listened to
- Answer questions in a candid and direct style – focused on delivering insights that lead to results
Go to www.configuresoft.com/securitycatalyst today to register now and listen to the recorded sessions from before and get reminded to join in for the September session.
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
- Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
- Subscribing to The Security Catalyst podcast & blog to get more insights
- Checking out the upcoming schedule to meet Michael (and his family) “onTour” – as they travel the country by RV (dates now in Alaska, NYC and working on Dallas, Phoenix and San Francisco, with a likely stop in Atlanta and maybe Charlotte)
Podcast: Play in new window | Download (12.9MB)
Into the Breach – Audio Series – Chapter 1 (Breach: A Human Problem)
Episode 2: Into the Breach: Chapter 1 (Breach: A Human Problem)
Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book and pick up a complete copy – to get started on your personal journey). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the first Tuesday of each month (there are 13 chapters total).
What you’ll find in this episode (Chapter 1)
Chapter 1 defines the challenge of breach as a “human problem” and begins the journey to understand how and why we got where we are today. Michael reveals how reliance on technology has masked the true nature of the problem and explains how to re-think the way technology supports the needs of people. He also suggests that a focus on breach is too narrow, and that all information must be protected.
A personal invitation to go deeper Into the Breach with Michael Santarcangelo
In two weeks, join Michael Santarcangelo for an insider’s perspective and live conversation to journey deeper into the chapter. During the conversation, hosted by EMC, Michael will:
- Reveal the ideas and concepts that may have been pared from the chapter you just listened to
- Expand upon or update the elements in the chapter you just listened to
- Answer questions in a candid and direct style – focused on delivering insights that lead to results
Did you miss the in-depth discussion with Michael about the Introduction? If so, go to www.configuresoft.com/securitycatalyst today to register now and listen to the recorded session and get reminded to join in for the August session.
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
- Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
- Subscribing to The Security Catalyst podcast & blog to get more insights
- Checking out the upcoming schedule to meet Michael (and his family) “onTour” – as they travel the country by RV
Podcast: Play in new window | Download (8.4MB)
Into the Breach – Audio Series – The Introduction
Welcome to the audio series of Into the Breach: Protect Your Business by Managing People, Information and Risk (click this link to learn more about this book). This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio version of Into the Breach, written by Michael Santarcangelo and read by the author. Join us for a new chapter released on the last Tuesday of each month (there are 13 chapters total).
What you’ll find in this segment
The Introduction explores the nature of the challenge faced by organizations around the world. As we prepare for the journey “Into the Breach”, it is revealed that breaches are only symptoms, and the real challenge is described as a human paradox. Setting the stage for a shift in thinking necessary to get results, three common myths are exposed and addressed. A powerful strategy to protect information is shared, and the clarion call to engage, empower and enable people is sounded.
A Private Invitation to Engage with Michael Santarcangelo
Build on your experience. Sign-up for exclusive invitation-only conversations [click on the link to sign up now for your invitation] with Michael Santarcangelo, hosted by EMC. Join Michael for a live conversation two weeks after each chapter is released where he will:
- Reveal the ideas and concepts that got cut from each chapter
- Expand upon or update the elements in the chapter you just listened to
- Answer questions in a candid and direct style – focused on delivering insights that lead to results
The discussion centered around the concepts revealed in the Introduction is scheduled for Thursday, July 16th. Visit http://www.configuresoft.com/securitycatalyst.aspx for more details and to get your invite!
You want more, so after listening…
After listening to this segment of Into the Breach, keep the energy going and support the shift in thinking and inspire behavior change by
- Engaging (not following) Michael on twitter (http://twitter.com/catalyst)
- Subscribing to The Security Catalyst podcast & blog to get more insights
- Checking out the upcoming schedule to meet Michael (and his family) “onTour” – as they travel the country by RV
Podcast: Play in new window | Download (9.2MB)
Security Catalyst Show – February 16 2009 – Certification & Accreditation
Welcome to the Security Catalyst Program – bringing you the ideas, insights and tools necessary to change the way people protect information. I am Michael Santarcangelo, your personal catalyst on this journey. Thanks for listening!
On today’s program, we explore Certification and Accreditation with the help of three experts who share an absolute wealth of knowledge.
A few quick notes
1. Into the Breach is available as an eBook and signed Hardcover from www.intothebreach.com Learn more about how to engage users, restore responsibility and hold people to account. In fact, this book lays out how to reduce costs without increasing risk, turn insiders into allies and manage people, information and risk better.
2. For 2009, I am excited to announce the expansion of the Security Catalyst Blog – with the awesome Catalyst Contributors. Visit the blog each day to get a fresh perspective
3. I’m in the process of revamping the podcast series for 2009. I know a lot of people are struggling – and in addition to being a voice of optimism, I’m building a team to share information and strategies necessary for making a difference this year. If you want to contribute, or if you are facing a challenge and need some help – shoot me an email: securitycatalyst@gmail.com
Stay tuned for more information.
For today’s program, I am joined by Mike Smith, Graydon McKee and Joe Faraone to discuss C&A.
Links at a glance
The presentation that started the idea for this episode: http://www.slideshare.net/rybolov/why-care-about-government-security?src=embed
Graydon, Joe, and Mike teach 2-day C&A workshop and a 5-Fridays NIST Framework for FISMA workshop for the Potomac Forum. http://www.potomacforum.org/
Graydon’s blog: http://www.ascensionriskmanagement.com/BlogOne/
Papers and presentations: http://www.ascensionriskmanagement.com/BlogOne/paperspresentations/
Mike’s blog:http://www.guerilla-ciso.com/
Papers and presentations: http://www.guerilla-ciso.com/papers-and-presentations
The most relevant NIST publications are special publications 800-37 and 800-53, available here: http://csrc.nist.gov/publications/PubsSPs.html
About the Experts
Mike Smith
Michael Smith is a Manager in the Audit and Enterprise Risk Services organization of Deloitte & Touche LLP, where he leads engagements to provide security services to both commercial enterprises and government agencies. Prior to Joining Deloitte, Michael served as the Chief Information Security Officer with the Unisys Federal Service Delivery Center based in Reston, Virginia. His scope of responsibility included both providing governance and managing risk for several data centers, Security Operations Center, Network Operations Center, and Server Management Team.
Graydon McKee
Graydon McKee is the Vice President and Chief Operating Officer of Ascension Risk Management LLC. Graydon is an accomplished Risk Management/Information Security professional with extensive experience in developing and implementing Information Risk Management and Information Security Programs to clients in both the public and private sector. He is a recognized leader in government regulatory compliance (Federal Information Security Management Act and the Defense Information Technology Security Certification and Accreditation Process compliance) and has taught the process to over 2,000 individuals representing over 600 federal government agencies and offices.
Joe Faraone
Joe Faraone is a Senior Information Security Architect with GCI Corporation, based in Reston, Virginia with over 20 years’ experience in Information Security. Joe has delivered services for numerous Federal customers including Certification and Accreditation support, Security Governance Gap Analysis and Independent Validation and Verification (IV&V). Over his career, he has served as Lead Independent Security Engineer, Manager and Architect of a managed security center for an Intelligence Community Agency, and has performed Certification and Accreditation services for several high-assurance systems.
Podcast: Play in new window | Download (30.5MB)
I prepare to depart Michigan with gifts for you
After a great week in Michigan, tonight we pack up and prepare to head to Ohio tomorrow. Friday promises to be busy and exciting – and then on Saturday, we head to Maryland (Metro DC) for a week. Which brings me to the gifts I promised:
Join a conversation, get a free copy (hardcover) of Into the Breach
First – while in Maryland, I am attending CSI next week in support of the CompTIA Security Trustmark. It turns out that a chapter of Into the Breach examines how to evaluate, build and improve “third party trust” – what we need for success with our service providers and other vendors.
CompTIA Security Trustmark is hosting a handful of “catalyst conversations” to discuss my findings and examine how the industry handles this today, and what we can do in the future. This is not a sales pitch; rather, this is an opportunity to come together and work toward a common solution.
For those invited to attend, CompTIA will present you will your own copy of Into the Breach – which I will promptly autograph for you. Drop me an email – securitycatalyst (gmail) if you want to join us.
This leads me to my second offering…
Not going to CSI? Do you want to?
CSI was generous enough to share with me two ways for you to get involved:
* I can offer (I think) a free conference pass with full access – based on response. Here’s the deal – share with me the biggest challenge you face in changing how people protect information. The best answer gets a signed copy of the book and a pass to the show (I’ll hand you the book at the show).
* If you are already planning to attend, you can get 25% off your registration with code: BLOG25
I will do my best to both tweet (twitter id: catalyst) from CSI and report on interesting talks/findings from the floor. I will also be taking a limited number of vendor meetings to learn more about the products and solutions that make it easier for people to protect information. Shoot me a note if there is a product you want me to check out and report back on.


