Paul Blahusch is the founder and president of B&A Cybersecurity Consulting. He is a former federal cabinet agency Chief Information Security Officer (CISO) with over 25 years of experience in cybersecurity leadership, specializing in safeguarding information systems and data. He has a proven ability to enhance organizational efficiency while managing substantial budgets and ensuring compliance with regulatory standards. Paul has expertise in developing and implementing comprehensive cybersecurity strategies, including zero trust frameworks and risk management initiatives. He is committed to fostering a culture of security awareness and readiness and is passionate about leveraging technology and best practices to protect critical assets and support organizational missions.
In addition to his work with B&A Cybersecurity Consulting, he is the Cybersecurity Advisor for the Consortium of Universities of the Washington Metropolitan Area, a Mission Critical Fellow, and a frequent speaker at cybersecurity conferences.
1. Complete this sentence: “Before you buy any new security tool, first...”
Determine if it makes you better and, if so, how you can afford it.
2. What’s one rule you enforce on your team that other teams would find strict?
I stressed scrupulous adherence by the cyber team to all organizational policies: budget, procurement, HR, physical security, and more. If we expected organization personnel to follow our cybersecurity policies, the cyber team should lead by example across the board.
3. What’s a number or ratio that guides how you allocate budget, headcount, or your own time?
I’ll go with my own time. There is an ongoing mental calculation. Whatever is urgent and important gets attention. Generally, that ends up being what is most important at the moment to help protect and ensure business success.
4. What’s one line that works when asking the board or CFO for a budget?
Here is how this will pay for itself, through efficiencies, reducing or eliminating duplicative solutions, lower insurance premiums, and other savings.
5. What should a CISO cut from their program tomorrow with zero regret?
Do this exercise. Ask your team to tell you what activities they do that don’t appear to have value, and to estimate how much time they spend on each. For example, this could be a long-standing report they prepare that no one up the org chart ever comments on. Evaluate the results. Eliminate based on least value and highest cost. No regret.
6. What’s your 60-second test for whether a vendor pitch is worth your time?
Tell me what problem I have that this helps solve, or how this makes me better, more secure, more efficient. Why would I want this? And tell me how I can have this within my current budget, whether by replacing or reducing something else, lowering cost elsewhere, or another option. How can I afford this?
7. What’s one meeting, report, or process you eliminated, and what replaced it?
I killed maintaining the five-year cybersecurity strategic plan document. It was a bloated, time-consuming, never-referenced, obsolete-as-soon-as-it-was-published, costly product. We replaced it with annual tangible and trackable goals, combined with shorter “sprint” objectives throughout the year.
8. In the first 10 minutes of an incident, what’s the one action teams most often skip?
Using the playbook. They often get so quickly engrossed in the technical details of the incident, determining the where and how, that they forget to open the playbook. This can lead them to miss important steps defined in the playbook, like preserving evidence, documenting a record of the incident, and establishing secure communications.
9. What’s one question every CISO should ask their team this week?
How can I best help you be successful? Is that by being a sounding board, getting you needed resources, providing top cover for an initiative, or providing a decision or approval?
10. What’s a phrase or framing you use to translate a technical risk for executives?
Executives are familiar with evaluating risks of all types. Frame technical, or cyber, risk through a similar lens. Namely, how it will impact the business.
11. What’s your best tip for surviving the CISO role in exactly five words?
Remember, business success comes first. As a C-Suite executive, my role isn’t to provide cybersecurity. Rather, it is to make sure the business is successful. The primary way I, as CISO, contribute to that success is by directing a cybersecurity program that keeps cyber risk at an acceptable level to the business.
Get more tips from CISOs working in various industries:


