#117: "ITAM is the first thing I do in a new company" - Renata Vincoletto, CISO at Civica

13 Aug 2025 · 55 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

The Tech Leaders Podcast - Episode #117 Summary

Episode Overview In this episode of The Tech Leaders Podcast, host Gareth interviews Renata Vincoletto, the Chief Information Security Officer (CISO) at Civica. Renata, who rose through the ranks in the tech industry after overcoming significant personal setbacks, discusses her journey, the importance of cybersecurity, and the intersections of technology and leadership.

---

Key Themes and Discussions

  1. Renata's Journey to Leadership
  2. Background: Originally from São Paulo, Brazil, Renata has always had a passion for technology. After facing discrimination at work for being pregnant, she chose resilience over resentment.
  3. Mentorship: A significant influence in her career was a mentor who encouraged her to pursue leadership roles in cybersecurity.
  1. Insights on Leadership
  2. Definition of Good Leadership: Renata emphasizes the importance of clarity, trust, and empowering teams. She believes in being vulnerable and admitting when she doesn't have all the answers.
  1. Importance of IT Asset Management (ITAM)
  2. ITAM and Cybersecurity: Renata argues that effective IT asset management is foundational for a robust cybersecurity posture, highlighting that you cannot protect what you do not know.
  3. First Step in New Roles: For Renata, establishing a strong ITAM process is always the first action she takes when joining a new company.
  1. Recent Cybersecurity Breaches
  2. Co-op and Marks & Spencer Breaches: Renata empathizes with companies facing breaches, noting that such events often prompt a necessary wake-up call for leadership regarding cybersecurity challenges.
  1. Cybersecurity Skills Shortage
  2. Perception vs. Reality: Renata suggests that while there might be a perceived shortage of cybersecurity skills, the issue lies more in mentoring and guiding new professionals rather than a lack of candidates.
  1. Women in Cybersecurity
  2. Representation: Renata discusses the ongoing gender disparity in cybersecurity roles, particularly in leadership positions. She highlights the need for more female role models and support networks to encourage women to enter the field.
  1. Risks and Opportunities of AI in Cybersecurity
  2. AI as a Tool: Renata views AI as a new tool that can enhance productivity and creativity but also poses security risks, particularly in data protection and phishing attacks. Organizations must adapt and develop new policies to mitigate these risks while leveraging AI's potential.
  1. Advice for Future Professionals
  2. Emphasizing Self-Belief: Renata encourages professionals, especially women, to believe in themselves and their capabilities, citing her personal experiences with self-doubt.

---

Key Takeaways

  • Empathy in Leadership: Understanding the pressures faced by cybersecurity teams during breaches is crucial to fostering a supportive work environment.
  • Cultural Change Required: Companies need to integrate cybersecurity into their culture by educating employees about risks and responsibilities.
  • Role of Mentorship: The impact of having mentors can be transformative in one’s career, especially for women navigating male-dominated fields.
  • Proactive IT Asset Management: Establishing a clear understanding of IT assets is essential for safeguarding organizations against cyber threats.

---

Conclusion Renata Vincoletto's journey and insights provide a compelling narrative about resilience, leadership, and the critical importance of cybersecurity in the evolving tech landscape. Her personal experiences and professional expertise resonate with the ongoing challenges and opportunities faced by tech leaders today.

For more information, visit [Be Digital UK](https://www.bedigitaluk.com/) for resources on technology and cybersecurity.

---

Additional Notes

  • Timestamps: Specific topics are discussed around the following timestamps:
  • 2:02 Good Leadership and Career Path
  • 12:50 Cybersecurity Breaches
  • 16:10 Importance of ITAM
  • 24:30 Cybersecurity Skills Shortage
  • 30:24 Women in Cybersecurity
  • 41:05 AI Risks

This episode emphasizes the integral role of cybersecurity in organizational strategy and the ongoing need for inclusive practices in tech leadership.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00What was your take on that, by the way, with co-op and Marks and Spencer's in quick succession was now getting hit. I really feel for them. I wouldn't like to be in their shoes. This is the worst nightmare for a cybersecurity expert, especially because that's the only moment that the board or the leadership will actually start to pay attention to the problems that you have.

0:28Every now and then, you have a conversation that really lands and where there's real connection, depth, and something genuinely memorable. And this was undoubtedly one of those moments. Renata Vincoleto is the Chief Information Security Officer of Civica, who are, amongst other things, a powerhouse in UK government and public sector technology. Hailing from Sao Paulo, Brazil, Renata discovered her passion for technology very early on in her life and followed it all the way to the UK after facing a deeply shocking setback, being dismissed from her position for effectively being pregnant. Renata chose resilience over resentment.

1:10Inspired by her mentor, she pushed forward, rising through the ranks to ultimately lead cybersecurity strategy for Civica, working on high stakes government and public sector IT programs. We discuss her empathy for the recent M &S security breach response team, why observability and IT asset management are fundamental to achieving a good security posture, the uncomfortable lack of female representation in security leadership. And we also talk about personal resilience and also how organizations should be thinking about AI and large language models from a security standpoint. I think you will absolutely love this lady.

1:52This is Renata Vincoletto.

2:02Renata, thank you so much for coming on the Tech Leaders podcast. I've actually been super excited about speaking to you. I've been aware of Civica for some time. There's so much going on in the cybersecurity space right now in light of all this innovation around AI and other things. Thanks so much for agreeing to come on. How are you today? I'm very, very happy to be here as well, Gareth. I'm very good today. As you know, we start off with a bang. The question we always start off with, what does good leadership mean to you, Renata? Good leadership for me. I think it's about creating clarity for the team and somehow fostering the trust and empowering people.

2:45I think that's the things that I think. Empowering my team to do their best, to be their best, the best version of themselves. Even when the path is not clear, you know, make sure that even in the decisive moments in a crisis, for instance, as a leader, I can be vulnerable enough to say, I don't have all the answers, you know, to show to them that we can figure out everything together. And I think that's the leadership. Absolutely. Humility and empathizing with your team is vital. Very good answer, Renata. I think that's, I completely agree. So look, can you give us a little bit of an introduction, certainly in terms of the early part of your career?

3:27Why did you pursue IT and technology as a career path? I've always been a geek. I think that that has, I've been proud, I would say, proud. Since I was very small, I was trying to open radios and videocassettes and things like that to see how they worked. Then growing up, I was fascinated by physics. That's my background. I went to university to read physics. While at university learning about physics, I was introduced to Cisco Net Academy. That was a partnership between my school and Cisco. and they were talking about, you know, providing CCNA and et cetera. And I thought that was very cool, you know.

4:12Oh, I want to learn more about this. And that was the end of physics for me because I loved it, you know, and I really wanted to do research and discover. I'm a very curious person and I wanted to study maybe cosmology, But with networking, internet and cyber after that, I discovered that I didn't need to study the space to be excited every day. That was something that led me to cybersecurity in less than six months that I was already on network engineering. I started to get more and more curious about, OK, so what's in the mind of the other people as well? Because although I am a geek, I am also, I would like to say I'm a people's person.

5:03I love interacting with people, understanding how they think, how they act. So you grew up in Brazil. Was it always the plan to leave Brazil and pursue work overseas? Or was that something that happened organically just through your career? My mother used to say that my ideas and my plans, they were too big for the country. in a way that she said that she always saw that she always knew that I wouldn't be living there next to her, living, you know, in the city. Even if Sao Paulo is a very big city, she always felt that I didn't belong there. And I agree, you know, I always see myself as a citizen of the world, you know, like that.

5:45Yeah, absolutely. And when we started, I started my career, I worked for cybersecurity at Siemens. I was information security manager for Siemens in Brazil. And then I was the information security officer for Telefónica, also in Brazil. And I was delivering training for Cisco Academy and for Checkpoint Firewalls as well. My husband was at that time working for Yahoo as a software engineer. we met at physics university and he's just like me a geek uh computer science biology and all that stuff he loved those things that's when he received a job offer from welcome trust institute in connection with cambridge university i thought okay i'm always excited about doing things different and we decided to move i got to ask you when you first moved to the uk what did you like and dislike about the UK when you first moved?

6:44It must have been things you missed about Brazil. I would say that things that I really like, it's that I can be myself. Brazilians are very much worried about appearance. You know, they love to look very beautiful and very well maintained and etc. And if you are not wearing the same clothes or if you are not wearing the style that is happening right now, people kind of judge you. So geeks are much more, I would say, well accepted here in UK than I would say in Brazil. Things that I dislike about UK, I have to say, I'm really sorry about that, Garrett, but it's the food. Well, yeah, I can imagine.

7:31Brazilians love barbecuing. I think it becomes, they're kind of famous for it, I think. That's usually what we do over the weekends. So you've had a fascinating journey from Brazil to obviously to work in the UK for Microsoft and so on and so forth. I just wanted to ask you, you obviously joined Microsoft in 2022 and then obviously you went on from there, ending up at Civica. Can you talk us through your time at Microsoft? What did you learn working for a global player in the technology space like Microsoft? What did you take from that experience? I would say that I was working for big companies back in Brazil, as I mentioned, Siemens, Telefónica, Hewlett-Packard.

8:13Those are the companies that I was working at Brazil. When I moved to UK, in Cambridge, there wasn't a big cybersecurity scene here yet. All the big players were in London. So I had to do a change in my career. And what I did was I saw the startup scene in Cambridge and I decided that one thing that I could do is to help those startups to build their IT and cybersecurity department. So that's what I was doing for probably 15 years. And it was amazing. I helped so many startups to build their departments from scratch. But then I was missing the big, big scene, global things happening to have access to cool tools that sometimes a startup doesn't have.

8:57So when I was offered a position at Microsoft, I thought it was a very good move. So I joined. I was working for them as a, it was so many things. We had a managed security services for companies that we provide for companies. But it was with a plus because we would offer a cyber architects, a cyber advisor that was in this case me, to provide services together with our managed services in our SOC. What I learned is that everything is so big. You have access to much more stuff that I, in a company, a startup or a smaller company, don't have the budget to do it. Right. But I also miss the I miss the less budget stuff because I think that allows you to be more creative.

9:54I know what you mean. Yeah. Your budget to be more creative. You've got to do more with less. Yeah. Exactly. Exactly. It was amazing to work at Microsoft. It opened so many doors. Probably I wouldn't be at Civica if it wasn't because of Microsoft. because one of the things that Civica wanted, they wanted to move to a Microsoft stack. And I was there already inside Microsoft. I had the knowledge how the tools work. I had the experience as a CIO in CISO before. Yeah, I think that was the good match. Yeah, absolutely. So I know whilst you were at Microsoft, you were doing a lot of CISO advisory stuff and obviously at IMD too.

10:38You've done a lot of working with executives to help them understand their security threat, improve their security posture and all of the related endeavors around that. So can you just tell us what executives, what leadership teams within large companies, what do they normally get wrong, Renata? What problems do you normally encounter? I would say that they are probably blind to the reality of the cybersecurity problems. Most of the time, I don't think that cybersecurity has enough voice in the boardroom. And because of that, the leaders don't get to see what's actually happening. There are so many threats happening down there.

11:27I think the internet is a wild west. Sure. And there's so many things that I could stay ages talking about. For instance, digital safety. This is something that's very close to my heart. How is the situation in the world for the kids as well, for the kids that are growing up with the phone in their hands? How is their safety? And people don't see that. They don't have an idea of what's actually so easy and so dangerous for either the citizen, for your kids, or for the company. And I think that's the biggest problem. It's the lack of probably voice in the boardroom. Right. So because of that, they don't have the cyber risk.

12:16At the top of the priority, yeah. Yeah. Yes. So you're saying security should be not just the CTO's concern, it should be everyone's concern. Oh, yeah, definitely. So the CISO should be on every board, representing or reminding everyone about the very real threat. Because, I mean, if you get your security wrong, it could wipe out your business, couldn't it? You know what I mean? You could lose all your customers. Yes, yes. So if you get it really badly wrong. And we have so many examples of that. Especially recently with the retail organizations in the UK getting hit. What was your take on that, by the way, with Marks & Spencers?

12:50I think it was co-op and Marks & Spencers in quick succession, wasn't it? What was your sort of perspective on what happened there and your view on what happened? I would say that I really feel for them because I wouldn't like to be in their shoes. I have to say that this is the worst nightmare for a cybersecurity expert. when you go through this situation, especially because that's the only moment that the board or the leadership will actually start to pay attention to the problems that you have. So my feeling is that maybe this is an alert and we even use the joke around the cybersecurity world that we can't waste a good crisis because things like this is the one that will give us the ammunition to talk to the board, to the leadership, to tell them, look, this is what could happen if you don't pay attention.

13:54So my feeling is that it could have been better. They probably could have been better supported by their leadership. I don't know, but I really, really feel for them. It's not an easy thing to do, and it's really stressful, really, really stressful. Yes. There's lots of cybersecurity people now talking about their mental health as well. Oh, really? Okay. Yes. There's even a few groups starting to discuss this more and more because some people that I heard talking to them, they're talking about, like, I can't live like this anymore. Yeah, it's a lot of pressure. To consume it. Yeah. A lot of pressure and little recognition.

14:39Yeah, absolutely. I mean, people only sort of know about what you're doing for negative reasons normally, don't they? Because if there's no problems... That's exactly it. Nobody knows. If there's no problems, there's nothing to praise you about, even though you're the reason there's no problems with security a lot of the time. So it is enough for giving you work. And that's why I feel about the Marks and Spencer people or the cybersecurity team there. because sometimes they are doing the best they can, but they don't have the right tools. They don't have enough money. They don't have the support from the leadership.

15:19And then when you get in this situation, situation like this one from them, that's when people start to talk, oh, cybersecurity. That's what cybersecurity is. And again, we can't waste a good crisis. So I'm using this in my favor as well, inside the company, trying to show and try to show in other areas as well. Look, look how important this is. Yeah, look what could happen. For serious disease. Absolutely. Especially for an organization like Civica, who are, you know, responsible for the security posture of many companies. Do you know what I mean? So if one of your clients gets hit, I suppose, you know.

15:53And we are talking about citizen data here. We are looking after NHS data. We are looking after education, schools, local government, local councils. So it is very, very sensitive and important. What do you think about the importance of IT asset management and software asset management? How important is that for having a good security posture? Understanding the risk. Fundamental. Yeah. It's fundamental. My opinion, and I keep telling that to my team, and I think my team is already tired of hearing me saying that I can't protect what I don't know. Yeah, absolutely. I can't. And a good item or a good software bill of materials or any information that tells me what is it that I have in my technology stack will help me protect you better.

16:50If I don't know which data I have, how can I protect? How can I measure the right levels of protections, you know? So this is, for me, is fundamental. It's usually the first thing that I do when I enter a company. And that's what I did when I was in the startup scene as well. The first thing that you do is category, categorize everything. Where is everything? How can I have real-time information from the assets that I have, from the IT assets, from the software assets, APIs? What are the APIs that I'm using? What are the technologies that I'm using to build my software and so on? Yeah, absolutely.

17:31So what advice do you have for CTOs then, maybe if they don't have a CISO, and in relation to IT asset management and getting there, understanding the risk profile of their software estate, what could you put in place to ensure, would you put an asset management tool in place to monitor this stuff on an ongoing basis? what advice would you give to a CTO, Renata, generally? I'm very agnostic from, you know, tool-wise. I don't care about the vendor. I care about what they are providing and how they can be helpful for me in the moment that I am. So any item, if you have money, go for the ones that are more expensive.

18:12But if you don't, try to do your best, but also always automating. Do not rely on Excel or static things. That's a nightmare. That's not scalable. You need to have something that will give you information. You give visibility constantly. There's a new area, not so new, but it's getting more and more famous, especially in the CTO area. Yeah. It is the observability. Of course. Observability is fundamental for that area because we need to have eyes on that. We need to know what's in there. And that area, for me, it's one of the most important areas that my team works with, with the engineering team.

18:56It's the observability engineers. We need to see what's happening. We need to know what's happening. So a asset management tool integrated with a CM, a very good CM with automation and a very good DevSecOps as well. and tools that can check what you have in your software, like SaaS, DAST, and things like that, that can give you the information of vulnerabilities that you have. They are fundamental for you to work, for you to have the proper view of what's happening. And probably a DLP, you know, all those tools, they work together to give you this visibility, right? Yeah, no, very well said. Fantastic.

19:39Just in terms of startups then, because it's a bit of a different situation, isn't it? But how do you, well, what advice would you give to entrepreneurs, especially entrepreneurs of companies who hold sensitive data, starting a digital first business, obviously in light of all this AI, I think AI is a huge security risk, isn't it? You know, chucking all your data into an LLM. You know, what sort of guardrails would you suggest for a startup to keep an eye on where their data is going and just making sure they maintain a decent security profile until they get a proper security person in to oversee it?

20:14I would say that if they are looking for someone that will help them with technology, make sure that this person that's helping with technology also has a cybersecurity hat, you know, because I don't think that they should wait for the possibility to have a cybersecurity person. I think that IT should start to wear the cybersecurity hat more and more. Right. Everybody, and developers as well. They shouldn't just go, I need to build a software that will do this, this and that. But they have to have ingrained in their heads, is it safe? Of course. Will be the data secure? So it has to be a cultural change.

20:59And if the new startups that are starting out there, I think that what they need is that they should put in the start of their plan. I want to have a software and the software needs to have this quality. It needs to do this, this and that and needs to be safe. It needs to be there at the beginning. They need to start to think about security by design. Yeah, of course. Everything needs to be a cultural change because a security won't work if you bring it later. you will have so much more work and it will be much more money to fix later. Of course. Instead of starting secure from the beginning. And that's why for me, I think it was so good for me when I was doing the startup scene because I was joining as the CIO, but a CIO with a CISO hat as well.

21:56Yeah, sure. So they were buying two for the price of one, in a way, you think. Because that's my passion. And so I was doing that. That was part of me. And for me, a CIO should think about cybersecurity all the time. A CTO should think about cybersecurity all the time. Absolutely. Yeah, 100%. I think, so look, I wanted to ask you, obviously, Civica do a lot of work within public sector. Now, public sector organizations are often, not always, but they're often quite, you know, maybe haven't even gone through full digital transformation yet in some cases. Obviously, have quite old working practices and didn't sort of evolve as digital first or security first.

22:41How do you impose a security structure on these organizations? What kind of problems do you encounter? I think most of the challenges are that, what you already said, they didn't go through a digital transformation. Sometimes their infrastructure is still in the last century. They didn't move to the 21st century yet. They are still, the process are still there as well. And the people's mentality, they are still using things like I want to connect using RDP or to, I want to use a connect directory to a computer instead of using the facility of connecting to a web page or an app itself. They are still using very old stuff, very old stuff.

23:32So I think that's one of the biggest problems that we have. They don't have enough hands. I think that's the other problem. They don't have enough hands. The hands that they have, they are putting on the things that they feel it's the most important. And as I said, cybersecurity, it's not on the top list of most people, most organizations. So they don't see it as important. So it's not there. So what I try is to kind of raise the bar, raise what cybersecurity actually means and how it's important. So that's kind of my personal goal, I would say. It's amazing how it isn't top of the priority list when it comes to all technology within the organization, isn't it?

24:17I mean, security threat should be top, especially for public sector, you'd think, or for any organization. But so can we use this as a segue into skills then? So obviously, prioritization is one thing, but also some people would argue, and I'd love to get your thoughts on this, that there is actually a skills shortage within the cybersecurity space right now, within the sort of compliance side of it, but also within the technical side of it as well. What are you seeing in the marketplace when you've tried to hire Renata? Do we need to do more? Is there enough training coming into this vocational direction?

24:51What's your thoughts on the whole picture in the UK right now? I think that's not a problem just in the UK. It's a global problem, right? I see this everywhere. That was one of the things that I researched during my master's. My thesis was about human aspect, the human side of cybersecurity and cybersecurity awareness. My research was kind of Brazil, as you can imagine, UK and other countries in Europe as well. And I could see that the results are almost the same. And for me, the problem is not the shortage of skills. Maybe it's more help from older people or for experienced professionals to mentor those people, to help them to where they need to go.

25:42Because it's a world that evolves very, very quickly. and it is crazy even for us that are in the field for 20 something years. Imagine for someone that's just started. And also I think it's lack of understanding of what cybersecurity roles and skills actually mean because you don't need to be a tech person to work with cybersecurity anymore. There are so many other areas that you can contribute, processes, compliance, risk, and et cetera, all those things, data compliance, everything. So you don't need to be an engineer anymore. And there is still this vision or this idea that, oh, if I want to work with cyber, I need to understand how a computer works and all the very single detail.

26:37And that's not exactly the truth. And I think that that's the biggest problem. You know, I've seen every time that I put a position, a job advertisement, I see so many people applying. Yeah. And sometimes it's even harder to find the right person because sometimes they are not really focused on one specific thing and they try to be too broad. But yeah, and I think you should find your niche inside cybersecurity and stick to it and go after it. Find what you are very good. Yes, I agree. And go for it. Absolutely. I completely agree. Specialize in something. But what I would say to that, Renato, and I think a lot of people kind of overlook this, is that it's quite different in each organization, isn't it?

27:29So for instance, if you had a security role in a smaller business, you would probably be responsible for quite a broad array of responsibilities. You'd be responsible for, I don't know, the ISO 27001 audit. You'd be responsible for the technology element and what's product, whether you get CrowdStrike or not, or potentially writing some code. Whereas in a company which is a larger company, absolutely, you're a small cog in a big wheel and you need to specialize. Otherwise, you're not really of any use to them. I mean, do you know what I mean? There's different scales, isn't there? organizational scale.

28:04Yes. And I think it's also down to your personality. You have to find what you are best. For instance, I've always been a generalist in a way. I love certain specific technologies. I love doing certain areas of cybersecurity. For instance, I love threat hunting, threat intelligence. But I've always been a generalist because I'm curious about all the other subjects. Yes. So I think it depends on your personality. I know people that they are amazing doing that specific thing. And if you give them other stuff to do, they will be okay, but they are very good at that thing. Of course. So I think in this case, obviously different companies, different size of companies, et cetera, will affect.

28:54But I think, again, you have to focus. So focus on what you are. Are you a generalist? So if you are a generalist, look for generalist positions. If you are a specialist, go make sure that you want, if you want to work only with AI security, go for it. And specialize, make yourself one of the best of them. Yeah, of course. There's so many tools out there that can help you for free to learn how to do it. So specialize on that, focus on that. You want to learn about everything, go for it as well. You can learn about everything, but then you can focus on the generalist positions that are open.

Read the full transcript

29:59capability. And on the last point, BDigital have just developed a cutting edge AI readiness assessment, which provides tech leaders with a platform they need to make well informed decisions about AI adoption strategy in 2024 and beyond. Go to BDigitalUK.com to find out more and get in touch.

30:24so according to cyber security ventures.com okay a couple of years ago they did a study a survey and basically they come to the conclusion that women held around 25 percent of cyber security jobs globally it may have gone up since then because this was three years ago but it's still not 50 50 i would guarantee you i think i think it's no no it may even have gone down i don't know but I suspect it's probably gone up, but not by much. Nowhere near as much as it should have, I think we can agree on. So my question to you, Renata, is why are there not more women wanting to get into this line of work?

31:00Or what other forces are they dealing with? I have to say that that was exactly one of the things that I was trying to understand when I was doing my master's because I was very curious about that. And I interviewed around 500 people to find out. Well, it was very small, obviously, but, and also talking to all the peoples and conferences and et cetera. I think it is the lack of, one of the things is the lack of role models. It's the culture. It comes from our houses because in our houses, we still say to our kids, oh, look, my girl, she will be a teacher. She will be a nurse or she will be something like that.

31:44And the boy will be an engineer, you know, or something similar. So I think it's cultural. It's our society that tells girls that they should do this and boys should do that. And for boys, it's the same. For instance, if a boy wants to be a teacher or if he wants to be a nurse, usually people kind of, oh, why do we want to be a nurse? Nurse is a woman's job. So I think that's the wrong approach. We should leave our kids to explore everything. And I'm very grateful to my parents that they allowed me to do whatever I wanted. Yeah, of course. I would play around with lots of things. And I'm very much like how people say in English, tomboy.

32:30That was me growing up. So for me, it was easier, right? And as you can imagine, I studied physics, right? It's not a normal thing for women to study as well. My class was 80 people, two women, right? And physics. So this is for the whole STEM area, not just cybersecurity. All the areas. And I think that's one of the things that I'm working as well, that I'm doing as well. I'm mentoring women in cybersecurity. And I go to conferences and webinars. And my goal is to say, hey, women, you also can do this. It's very cool. It's exciting. It's different. And sometimes you don't need to be the best geek or the best maths student to be able to do it.

33:24You can do in other areas as well. Oh, that is fantastic. Absolutely. So the same organization of the staff that I just read out also did another study. This was two years ago. that at that time, women only held 17, 17 % of CISO roles at Fortune 500 companies. So this is obviously in the US. I think it's probably quite reflective of what's going on in the UK as well. So 85 out of 500 positions were female, which is crazy, isn't it? You know, it's not anywhere near the split that we would be hoping for. So I suppose the question I got at the end of that, Renata, as someone who advises and mentors young female, or doesn't have to be young, but early career female professionals with ambition and things like that, what kind of things do you say to them so that they do shoot for the stars and want to be, if they're a security person, that they do fulfill their potential or fulfill their potential in terms of reaching the summit or in terms of where you are now, I suppose.

34:29You know what I mean? So what kind of thing do you sort of say to make them believe that they can get there? Because I got two daughters, And obviously I want them to achieve and I want them to get to the top of their field if that's what they want. So I'm just curious, what do you say to them so that they are ambitious and they do believe they can achieve the things that you have? That's something that I always thought. And probably I would say that that's my mom's influence. I always thought that if one person is capable of doing something, the other person is also capable of doing something.

35:01Obviously there's a few limitations here and there, But there is nothing in the world that if someone is a rock scientist, obviously he didn't, he was not born with all that knowledge. He had to work and study and focus on that. So from my point of view is if a man is capable of doing something, why I can't, you know? I have to say that before, as I said before as well, that the lack of role models, you know, that was a problem. I had a bit of problems with confidence. That was back in Brazil, beginning of my career, when I was pregnant with my first kid. I was working for a company. I just joined the company as a cybersecurity consultant.

35:54They were betting on me. So they paid me a lot of trainings. I was trained with top cybersecurity skills, with checkpoint training, checkpoint certification, Cisco certification, PKI, all that stuff that was top. It was, I'd say, something around£20 ,000 today in training. They invested in you then, yeah? Sure, in me, in less than two months. Wow. I was on probation. those three first months probation when I discovered that I was pregnant right and I was very happy of course I went to my boss yeah and told him I'm so happy I'm pregnant so excited yeah etc etc and then and they say yeah cool stuff cool stuff I was in the middle of one of those trainings imagine it was in Brazil the training was completely in English because I was the only actually Brazilian there.

36:51Everybody else was from other countries. They were from Sweden, Argentina, and et cetera. So it was in Sao Paulo, but people from other countries, because we didn't have that technology and the skills in Brazil yet, 20 something years ago. That was like a Monday. On Wednesday, I was called to the main office saying that they wanted to talk to me. I was in the middle of the training week. and I went to the office and they said, yeah, you can finish the training. It would be Friday, but after that, we are letting you go. Oh no, wow, okay. And I said, okay, that's because I'm pregnant, right? And I said, no, obviously not.

37:34It's because you are not good enough. We just realized that you are not the right person for us. We were expecting much more from you and you were not delivering. and I knew that it wasn't, that wasn't the reason. The reason was because I was pregnant and they didn't want to wait. But at the same time, that phrase that I was not good enough stayed with me for a long time. You know, so I was always doubting myself. I'm not good enough. So that famous imposter syndrome, you know, people will realize that I'm not good enough here. They will realize that, oh, she's a fraud, what she's doing here. And I had a hard time moving on from that.

38:15And I always avoided the role that I took at Civica because I always thought I won't be able, I won't be capable of doing it. And I think the role model was what changed it for me. Probably she doesn't even realize how important she was in my life. But before I joined Microsoft, I was working at Abcam. and this is what I became. She was a woman. She's a woman. And she was amazing. She was telling me all the time, you can do it. She was my mentor and I still consider her my mentor. And the day that I was offered the position at Civica, I called her and told her, I don't know what to do. What should I do?

38:58And she was there to help me. Renata, you were there for a long time already. You just need to go. You just need to grab it. You can do it. So it's hard sometimes to believe in yourself. But for me, that was fundamental. And that's what I'm trying to do to other girls, other women as well. Believe in yourself. You are capable. You can do it. And most of the time you are already doing it. Yeah, absolutely. You just don't realize it. You just don't have the recognition from others that you are doing it. I'm really, really happy. She is now the CISO at BBC. and she's amazing. Yeah, that's fun. She's amazing.

39:40And as I said, I don't know if she has, she knows how much that was important for me. But that's the type of importance that a role model and someone that, another woman, that it's already there and it's doing and I can see that she's doing, that can help. And I think that, I hope that will change in the future as we have more and more women joining as a CISO and doing this work. Renata, that was a really lovely story. Thank you so much for sharing that. I mean, obviously, what you experienced having gone through that training, that's just shameless, awful. That's awful. I mean, that should never happen.

40:20I think that's just a terrible thing to go through, a traumatic thing to go through. And yeah, but I'm so glad you found someone to look up to and a mentor who you took value from, because that's fantastic. And I think you should tell this individual one day, how important she's been in your trajectory. Maybe she will listen to this podcast. Let's see. Well, definitely. We will have to, hopefully she'll pick it up on LinkedIn or something. But look, thank you so much for sharing. Now, that's really lovely. So I wanted to ask you about AI because it's such a spanner in the works. I wouldn't say it came out of nowhere, but it was, obviously, there's just been an avalanche of interest and attention geared towards LLMs and agentic AI in the last couple of years.

41:08What kind of security risks does this present to organizations in your experience? What do we need to be mindful of from an IT leadership standpoint within the enterprise world? I think people are kind of enticed or maybe even blind, I don't know, by the glamour of the BBC. Like tempted to be, yeah, Yeah, it's carried away with the... Yes, carried away. It's like a... Oh, yes, it's a hype. Hype cycle, yes, it is. Yeah, you're right. I feel it's a hype. Yeah. AI, for me, it's just another tool. That's how I see it. And for me, we are going through the same transformation, the same paradigm, I would say, that we went through in the 70s and 80s when we didn't have computers to do our jobs, or for instance, let's get an accountant.

42:03An accountant had their jobs and they had to do all their calculations in a paper, right? They have their spreadsheets, and it was all paper, their books and so on. And then the computer came, and with that spreadsheets and Excel, everybody, et cetera, so people start to think, oh, I will lose my job because computer will replace me. no, it's just a new tool for the accountant, right? For me, that's exactly what AI is. It's a new tool for us to do our jobs. Obviously, there will be some professions that will be kind of more affected than others. But at the end of the day, what we have to do is learn this new tool.

42:45What the accountant had to do is learn Excel, you know, or in a way, or I'm just being simplistic here, but trying to explain what I'm trying to say. We have to learn this new tool. We have to adapt our work model to this new tool. And again, because people are looking at this, it's so glamorous, it's so cool and et cetera, they are not realizing that maybe they are putting too much data in there. Yeah, that's right. And that's my concern because the biggest risks for me, they are not, how can I say, they are not technical in this case. They are systemic in a way because we are facing, how people say, a perfect storm, perfect storm of interconnected supply chains, increasing regulation.

43:34And then this explosion of AI generated content that makes people, oh, this is so cool, but also makes phishing and social engineering so convincing. Yeah, of course. So I look at that as a risk and it's an exciting frontier at the same time. That's why I see that as a tool. For instance, the bad guys, let's say bad guys, they are using it. They are using it to improve their phishing, to improve their methods. And we have to do the same. So what we have to do is rely on those tools as well to be able to step up our game. But at the same time, we need to follow the regulations, make sure that we are not adding anything there that can be dangerous.

44:22But can I tell you something from the bottom of my heart? Data privacy, it's not a problem only with AI. It's a problem everywhere. We have this problem with everything. Almost everybody is exposed, completely exposed into the internet already. We can find almost anything about everywhere. I think it's a cultural change. It's a shared responsibility from governments, from not just the CISO's job, from the boards, from the companies, from the CEOs. Everybody needs to look after that, but not just because of AI stuff. I think AI just came to add to the problem. But as I told you, I already see cybersecurity as something that's undervalued in a way, you know.

45:14And AI is here just to kind of make our jobs harder in a way, but also easier in another way. But I think attack velocity is going to increase enormously, isn't it? Because you're going to be adding AI agents trying to breach security. And we have to increase the speed of the defense as well, right? With the AI agentic tools as well for defense. Yeah, sure. Because, I mean, it's difficult to ban these platforms. So I don't know, what guardrails could you put in place? How do you solve that problem so that your employees use AI responsibly? I suppose is the best word I can think of. I think it's, again, it's a commitment here that you have to have between the triad, right?

46:03People, technology and processes, right? So you have to think about the culture. So you have to teach your people how to do it and why it's dangerous. You know, I'm very much keen of just saying that don't do it. It's bad. You have to explain why. It's the same with kids. You have to do that with your kids. Explain them why it's there. So proper culture, proper culture that it's not based on fear, saying, oh, if you do this, if you click the phishing something or you fell off for a phishing, you will be going to a disciplinary something. That doesn't work as well. We have to be friends. We have to work together.

46:43So culture, awareness and education of your people, process, make sure that your policies are updated to the AI situation now. You know, that's what we are doing at Civica. We are updating our policies to incorporate that. But also you need the tools and the tools in this case, for instance, tools that are very useful for that is data protection, data leak protection tools like a DLP. You can tell on your DLP tools, depending on which one you are using. I'm okay for my people to use Jack GPT, but I'm not okay for them to use Claude or I'm okay for them to use Copilot or whatever it is. So you can restrict certain tools and allow other tools.

47:25So it depends on where do you want to put your data because prevent them to use it will be very hard. And I don't think that's the right way to do it because this is a fabulous tool. We need to use it. But you have to make sure that you know where you were putting your data. So make sure that you have a good agreement with the company that you are doing. So usually enterprise level agreements to use those tools, it will be better. So for Civica, for instance, we are using GitHub Copilot. We have an agreement level, enterprise level agreement with Microsoft. So we have that all under a specific, let's say, silo or sandbox, if you may.

48:11And our data is there, right? So you have to have those controls around what you are doing. And it's the same for the other users, because we are a very big Microsoft house. We are using Copilot for the, you know, daily tasks and et cetera. But that's allowed. All the tools are not. So we are blocking and allowing and explaining why, again, explaining why we are doing that. So I think it's a conjunction of those three things. Absolutely. Very well said. I want to wrap it up with a couple of questions I've got for you. So first of all, what excites you most and what worries you most about AI specifically?

48:54All the possibilities that we have to stop doing manual jobs or the things that are boring to do. Yeah, of course. And allow us to do more creative stuff. Absolutely. I'm really looking forward to have this opportunity. I think that's basically, because as I said, I don't see AI as the way that people say, oh, we will have, I don't know, Skynet is coming. or that's not, I don't see that soon, at least not probably in my lifetime. I don't know. But I do see that as a huge improvement in our quality of work. And with that, our quality of life as well. I just hope, my fear is that that doesn't go the other way where we will be kind of abusing that in a way.

49:47And at the end of the day, abusing people as well. And to be very, very, very honest, I'm kind of concerned about the impact that AIs will have on the environment as well. So that's another thing for another day to discuss. Yeah, sure. But that's something that worries me. Absolutely. I don't know how much we'll be sacrificing from the environment point of view to have this facility. It feels like another industrial revolution. we are going through? Yeah, but I believe so. Maybe. I believe it's that. I think it is that much of a big deal. I think it is. And I think the environmental side of it is absolutely huge.

50:32It's huge. I mean, have you seen the size of the data centers they're building in America? Yes, yes. I know Elon Musk built one, and I know OpenAI have also built one, both sort of around Texas and Tennessee. And these places are absolutely enormous. And I know they're having an impact on the environment around that area. They are. Yeah, that's a really important point. Renata, let's finish on this one then, okay? So if you're looking back, I know you've got a long way to go yet, by the way, okay? But looking back now over your career, if you were to be able to speak to your 21-year-old self, okay, and give them one piece of advice, what would you say to that person?

51:10Knowing what you know now, of course. Don't believe when people say that you are not capable. Just believe in yourself. Keep doing what you are doing. you are good enough. I think that's what I would sell my 21 years old Renata. Absolutely. Fantastic. So can you tell us a little bit about where people can find you and all the stuff you're involved with? Where can people keep track on your progress and what Civica are doing as well? I'm very easy to find on LinkedIn because you won't find another Renata Vincoletto. I think I am the only one. I like that. I'm exclusive, you know. Absolutely. So it's very easy to find me.

51:47Brilliant. And thank you so much for coming on, Renata. I've really enjoyed talking with you. Thanks for coming on the Tech Leaders Podcast. Thank you. I really enjoyed being here as well. Thank you for the invitation.

52:01So many key takeaways there. That was a fab conversation. Renata is just inspiring. I have to say, I really enjoyed talking to her. Her points about IT asset management being fundamental to your security posture. I thought that was great and so true. I also loved her empathy for the security team behind the M &S and co-op security breaches, which were very well publicized. But Renata just obviously reminded us that, you know, there are people behind these awful situations under intense pressure. And, you know, empathy is so important. There was loads more as well. But I think the standout moment for me was undoubtedly Renata's personal, very personal story of being effectively dismissed to simply being pregnant.

52:44And what I'd like to draw attention to is how she chose to respond to that injustice. Rather than let it define her or derail her even, she used it as fuel, clearly, and essentially turned the adversity into momentum, which I thought was just absolutely inspiring. And it also brought home the vital role mentors can play too. Like for Renata, having someone in her corner made all the difference. And that's true for so many of us. whether you're in a similar situation, navigating a male-dominated work environment or just facing self-doubt. You know, having someone who believes in you, who shows you what's possible can really change your perspective.

53:25It can change everything. It really can. So, I mean, it was a really moving story and a reminder that the path to the top typically is never a smooth one, I think we can say. But thank you so much for listening. I really enjoyed chatting to Renata. I hope that came across. It was a very authentic conversation. It felt very real. I hope you enjoyed it as much as I did. Please don't forget to subscribe, give us a like, share it with a friend. Any level of engagement is really valuable to us and very much appreciated. So thank you so much for listening to the Tech Leaders Podcast.

54:04This episode was brought to you by Be Digital. B-Digital support leadership teams to optimize cost and get more out of technology investments. B-Digital and the team have unrivaled expertise with technology license management and data remediation and are therefore perfectly positioned to help prepare organizations for AI technology capability. And on the last point, B-Digital have developed a cutting-edge AI readiness assessment, which provides tech leaders with a platform they need to make well-informed decisions about AI adoption strategy in 2024 and beyond. Go to Be Digital UK to find out more and get in touch.

From the publisher

Join us this week for The Tech Leaders Podcast, where Gareth sits down with Renata Vincoletto, CISO at Civica. After facing a deeply shocking setback, Renata chose resilience over resentment. Inspired by her mentor, she pushed forward, rising through the ranks to ultimately lead cybersecurity strategy for Civica, working on high-stakes government and public sector IT programmes. 

On this episode, Gareth and Renata discuss why good ITAM is crucial for Cybersecurity, the recent breaches at The Co-op and Marks & Spencer’s, and why geeks are more accepted in the UK than in Brazil. 

Timestamps:

  • Good Leadership, why a Career in IT, and moving from Brazil to the UK (2:02)
  • Lesson learned at Microsoft (7:50)
  • The Marks and Spencer’s and Co-op Cyber Security breaches (12:50)
  • The importance of ITAM to Cyber Security (16:10)
  • Is there a Cyber Security skills shortage? (24:30)
  • Women in Cyber Security (30:24)
  • The AI risks to Cyber Security (41.05)
  • Advice to 21-year-old Renata (51:08)

https://www.bedigitaluk.com/

More from The Tech Leaders Podcast

All 66 episodes
#117: "ITAM is the first thing I do in a new company" - Renata Vincoletto, CISO at CivicaThe Tech Leaders Podcast · 55 min
Listen in VO