An Interview with Dr. Joanne Martin, CISO and WITI Hall of Famer

Marian Cook

  • Share:    
Dr. Joanne Martin is currently President and Chief Information Security Officer (CISO) in residence at Vicinage, a boutique cyber security services firm comprised of independent cybersecurity executives. Previously she had a 30-year career in various executive roles at IBM, including VP, Technology and VP, IT Risk / Chief Information Security Officer (CISO). She has also been inducted into the WITI Hall of Fame.

Cook: As someone whose career has straddled the strategy-focused and the operational, is there any leadership principle that you consider central to success?

Martin: Yes. My personal motto for a long time has been 'Chance favors the prepared mind' and my career trajectory has certainly treated me to a great deal of chance opportunities. What enabled me to recognize them was the preparation I had made, things I had explored, curiosity that led me to get underneath things and really understand them.

What holds this together is, of course, belief in yourself. It is what empowers you to actually take that first step off the mountain into something new. Even having someone you respect think you can handle an assignment is not enough. You have to believe it. Once you do, you can begin breaking things down into actionable parts and begin. Having the opportunity, having the preparation, recognizing the moment is all for nothing if you cannot act. The bigger and more radical the opportunity is, the truer this becomes.

Cook: And, once you are at the new frontier, what is your "leadership mechanism" for getting organized for success?

Martin: Prioritizing is key, no doubt about it. My role as CISO at IBM certainly taught me that. With a mix of employees and contractors with different devices and over one million potential points-of-entry, you cannot protect everything, so we had to determine our highest priorities and put our resources against those.

This was big, powerful learning for me. My immediately previous position was strategy-focused and now I was being asked to step into operations and perform. I attribute the success of that assignment to the foundational technical preparations in my career to date, which enabled me to ask the right business questions. That is the heartbeat of how I work - prioritizing to focus the effort, and then boring in with the right questions.

Cook: Even managing a deeply technical discipline you believe business savvy was an essential ingredient in your leadership?

Martin: Without question and for two reasons.
1) IBM as a business has nearly limitless intellectual property that is essential to its employees and contractors that needs securing without overly limiting access; and

2) IBM sells technical products, software, and services. Being lax with basic issues like security would reflect poorly on our approach to technology, potentially undermining confidence in our market offerings.

Part of taking a business leader's view of our security landscape was remembering the point of our technology is to deliver productive experiences for the users. We have to be mindful of the experience our solutions are delivering to the users - whether they are employees, partners, contractors, or others.

Cook: What would you consider your toughest test of leadership-in-action?

Martin: It would have to be the assignment to deliver the e-commerce engine for in the late 1990's. This was the beginning of web commerce and there weren't any roadmaps for how to do it. We started with two people and inside of two years, we grew to 400 people. One and a half years into it, we realized our output was based on heroes, not on sustainable or even repeatable processes. We had to move our internal processes from Capability Maturity Model level 1 to at least level 3 for our effort to be sustainable, no mean feat when we were already an international team to begin with. When we were also directed to outsource support to India, we worried that the whole operation was not going to hold together well.

What we discovered was our move toward CMM 3 made us more process-disciplined, which enabled us to outsource support to India, both of which enabled us to keep all the essential pieces of our effort hooked together. It turned out to be a very positive experience when we thought it looked crazy at the start.

Cook: And the career implications of this view of leadership?

Martin: The principles circle back on themselves. If you believe you can do it enough to step off the mountain and open your current state of preparedness to the wider world, you can do it and will figure out what you couldn't have known at the beginning.

Hardly anyone with a job description expects candidates to have every single attribute and experience they are asking for. The best people want challenge, want to stretch. What's consistently amazing to me is how different men and women can be about these inevitable shortfalls. If there is a job with 10 qualifications, women will tend to see 2 that they don't have and disqualify themselves. Men, on the other hand, will tend to see 3-5 that they have and say 'I can do that!'

It goes back to what I said before: believe in yourself. In career planning, as in managing large corporate initiatives, 'leadership begins between your own ears.'

Marian Cook is currently the head of IT for a midmarket healthcare market leader of products, services and education for the pathology market. She leads the 100 person IT division and has a major Oracle R12 implementation underway. Among her many accomplishments she was once the Network Director for WITI Chicago and is currently on the Chicago's Mayor's Council of Technology.