
Forged For Growth
Translating Cybersecurity for Business Leaders with Michael Faas
Episode Summary How Echo Cyber helps growing companies connect business goals with practical cybersecurity leadership. Brian talks with Michael Faas about his path from studying computer programming, pivoting away from computer science after calculus, and turning a part-time IT job into a 25-year cybersecurity career. Michael explains why his work often centers on translating between technical teams and executives, how businesses can balance security with convenience, and why even small companies are big enough to be targeted. They also discuss SOC 2, cyber insurance, project prioritization, vulnerability risk, AI security concerns, and why founder-led companies often need CTO-level thinking before they need a full-time CTO. Key Takeaways Cybersecurity leadership often depends on translation: helping executives and technical teams understand each other and align security work with business goals. Security and convenience exist in tension, and the goal is to reduce risk without preventing the business from operating. Small and mid-sized companies are still targets because attackers often use automated tools to find easy opportunities rather than hand-selecting every victim. Vulnerability prioritization should consider both severity and likelihood, not just the scariest score on a scanner report. Many companies reach out for help when customers ask for SOC 2 compliance, cyber insurance costs rise, or leadership realizes they need security guidance but does not know where to start. A fractional CTO or cybersecurity advisor can help founder-led companies prioritize projects, unclog stalled initiatives, and decide what to start, pause, or kill. AI can be powerful, but companies need to understand what AI systems can access, how they are governed, and whether the output actually improves the business process. Timeline Early 00:00:00 Michael’s introduction, name pronunciation, and early path into IT 00:01:00 Starting in computer programming, switching to sports management, and turning IT into a career 00:02:00 College, career paths, and why practical ability matters as much as formal education 00:03:00 Calculus as a roadblock and the difference between theoretical and practical learning 00:05:00 Michael’s 25-year career in IT, enterprise security, and translating between technical teams and executives Middle 00:07:00 Bridging the gap between IT teams, leadership, and day-to-day business needs 00:08:00 Balancing security with convenience so the business can still operate 00:09:00 How excessive controls can push people to work around security 00:10:00 Why small businesses are still big enough to be hacked 00:11:00 Moving companies away from being the lowest-hanging fruit 00:12:00 Prioritizing vulnerabilities by likelihood as well as severity Late 00:14:00 Why companies usually call Michael: SOC 2, cyber insurance, and unclear security needs 00:15:00 Finding stalled projects and prioritizing the work that reduces the most risk 00:17:00 Providing CTO-level guidance without requiring a full-time CTO hire 00:18:00 When AI projects should be delayed, refined, or stopped 00:19:00 AI access, data governance, secure permissions, and prompt injection risks 00:22:00 Learning from failed AI experiments and evaluating whether automation is worth it 00:23:00 Michael’s sweet spot with founder-led companies from roughly $10 million to $50 million in revenue 00:24:00 Helping companies decide when they actually need a full-time CTO 00:25:00 Where listeners can connect with Michael and take the Echo Cyber assessment Links and Resources LinkedIn: https://www.linkedin.com/in/mfaas Company: https://echocyber.io

