html, body { overflow-x: hidden; }

INTRODUCE AI WITHOUT REBUILDING YOUR IT ENVIRONMENT WEBINAR

Watch the Recording

ON-DEMAND GOOGLE'S AGENTIC SECOPS WEBINAR

Watch Recording

CrowdStrike Falcon AIDR Webinar | Securing AI Systems July 21

Get the Recording

INTRODUCING PROJECT BOB: AI-enabled Modernization of IBM i

Watch the Recording

IBM CLOUD POWERVS FOR ISVs WEBINAR

Watch the Recording

iTL:DR

GHS PODCASTS

Episode 01: Risk Management Over Tools

generated-image

 

Guest:
Tung Nguye, Director of Cybersecurity, Denver Water.

 
Episode Overview

 

Most security teams are chasing the wrong finish line. The real job is not eliminating risk or reaching 100% compliance - it's learning how to manage uncertainty, prove what actually works, and make better decisions when budgets, threats, and board expectations all collide.Shawn Gershman sits down with Tung Nguyen, Director of Cybersecurity at Denver Water, the person responsible for helping protect drinking water for roughly 1.5 million people across the metro area. Tung also serves on the National Water Information Sharing and Analysis Center Advisory Committee, and he brings a rare operator's perspective from one of the most high-stakes environments in cybersecurity.Tung breaks down the biggest red flags he hears from CISOs, including tool sprawl, "we don't do assessments," and the dangerous assumption that more controls automatically means better security. He explains why assessments should be treated as one data point in a broader risk program, not the whole answer, and why the most effective leaders focus on outcomes like detection time, operational disruption, and business impact instead of checkbox metrics.

 

You'll discover:

 

  • Why "100% secure" is the wrong goal for any security program
  • How to turn assessments into a trust-building tool with the board
  • The difference between compliance, maturity, and real security effectiveness
  • Why AI security starts with identity, access management, and permissions, not just data or endpoints
  • How to prioritize security services when budgets tighten and revenue becomes unpredictable

 

Tung also gets practical about what CISOs can do in turbulent times: how to communicate risk clearly, how to define business outcomes that actually matter, and how to evaluate MSSPs based on measurable value rather than assumptions. He shares why transparency, regular feedback, and third-party validation can strengthen leadership trust instead of undermining it.If you lead security, own risk, or need to defend your program in a world of noisy headlines and shrinking budgets, this conversation gives you a sharper way to think about what really protects an organization. Essential listening for CISOs, security leaders, and anyone trying to build a program that works in the real world.

How can we help?

Feel free to ask a question or simply leave a comment