threat_intelligence2529 wordsRead on Arc Codex

CISO Conversations: Noopur Davis

Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. Comcast, founded in Tupelo, Mississippi, in 1963, is now a global media and technology company headquartered in Philadelphia, Pennsylvania. It has offices in North America, Europe, Asia, and Australia, and a global workforce of around 180,000 people. Noopur Davis is the organization’s Global CISO, leading multiple security teams distributed around the world and a total headcount of around 1,500 security team members. Davis is not simply the Global CISO of a major enterprise. She is also a former President of the United States Appointee to the National Security Telecommunications Advisory Council at the White House, a member of the board at Regions Bank, a board member at Entrust, and an advisor to the investment firm NightDragon. But her route to this elevated position when starting as a developer is far from typical. The route to cybersecurity leadership Davis never had a pre-planned structured career plan. Rather, she is a person able to recognize, adopt, and adapt to new opportunities as they arise. “I began my career as a software developer,” she said. This was with Intergraph. “I loved it. I must have done more than my 10,000 hours as a software developer” (referencing the ‘10,000 -Hour Rule’ outlined by Malcolm Gladwell in his book Outliers: The Story of Success). With increasing expertise and experience she began to develop and lead software teams as well as code. By 1999 she was director of engineering, leading multiple teams across multiple sites, with a growing interest in the mechanics of how teams and knowledge workers operate. Then came one of those opportunities that she recognized and adopted. She left Intergraph and became a senior member of software engineering process management at Carnegie Mellon University. “This was the time of the agile movement, with a focus on people and teams from an engineering viewpoint, but also on people-empowerment to make the best decisions for teams.” The Agile Manifesto was authored by 17 leading software practitioners in 2001. “The software engineering institute at Carnegie Mellon did a lot of applied research,” she continued. “Whenever we came up with an organizational method, we would work with the best organizations in the world to test them. We worked with Citi, with Microsoft, with the Naval Oceanographic Office, Lockheed Martin, Hewlett Packard and others.” “We learned about organizational behaviors and software engineering. How do you build a hypothesis, especially for something that is hard to measure like software or cyber? How do you set up experiments where the subject is very people-driven? And then how do you motivate those people? There was a lot of work in this area. And then I got into cyber.” This was also the time when cyber was emerging as a profession, including within Carnegie Mellon. Bill Gates wrote his famous trustworthy computing memo, which he circulated to all Microsoft employees on January 15, 2002. “He came to Carnegie Mellon and said, ‘Hey, can we work on this together?’ And I got pulled into that because I could still code. That’s how I got into cyber. So, it was really not anything I had planned. It was very happenstance – but I loved it.” By now, through this happenstance, Davis had become an expert software developer and an experienced and knowledgeable leader with a growing understanding of and interest in cybersecurity. It was the ideal launchpad for leadership in cybersecurity – not because it had been planned, but because she took opportunities that interested her as they arose along the route. She moved directly from Carnegie Mellon into cybersecurity in 2011, not as a security team member, but as VP of global quality at Intel – a position with responsibility for product security, security incident response, product and process quality, enterprise agility, and product lifecycle frameworks. In 2016 she joined Comcast as SVP of product security and privacy, became corporate EVP, chief information security and chief product privacy officer in 2021, and global CISO and chief product privacy officer in 2023. “My first CISO role – and this still just boggles my mind – was with a Fortune 30 company.” Help along the route Most senior executives become senior executives through the execution of a planned or at least intended career path. When already existing senior executives recognize such a career plan, they frequently become mentors and offer advice on how best to proceed. Davis, unlike many other existing CISOs, did not have such a plan, and she did not benefit from the advice of career mentors. Instead, she learned from experiencing her own teachable moments – which she effectively turned into ‘memos to self’. She gave an example. “In my early career I just wanted to code. It was like a drug. I could just sit for hours in front of a computer and write code, and I would get into a strange mental state.” It sounds like ‘the runner’s high’ of euphoric well-being, reduced anxiety and altered perception. But the result was that for years she resisted taking on a leadership role. Until, that is, one manager said to her, “You have to be open to trying new things. Try it. If a year from now you come back to me and say I want to go back to being technical, okay. But look, this company has a lot of really good technical people. We also need really good leaders.” She was persuaded to try it. “And I never looked back. I found I love doing leadership. Leadership is also fun.” She stopped shying away from new opportunities. She outlined a second, but earlier teaching moment. At the time, she lived in Alabama. Her parents lived in Pittsburgh. Her father became ill and her mother couldn’t cope. She decided she would have to move to Pittsburgh to help her mother. This was before the internet and when desktop computers literally covered the entire desk. “I called my boss and said, ‘I’m going to have to quit.’ He made me talk to our SVP, which alone was daunting for a young engineer. But I still remember what he said: ‘Noopur, take care of your dad. Doesn’t matter for how long. We’ll ship your machine to you in Pittsburgh. Work when you can, but we want you to stay with the company.’” In her own words, she did what she was told, but worked her butt off. “I would come home from the hospital and then I would just sit and work. Because ‘Oh my god, he’s trusting me!’ I became totally loyal to that company, and it was probably the biggest lesson I ever had in the power of empathy when working with others.” Techie or businessperson? Noopur Davis hails from a serious technical background. How does she feel about the growing belief that CISOs now need equal facility with business skills? “It’s absolutely essential,” she said, “because one of the core functions is enabling the business. In all the time I’ve been a CISO, I don’t think I’ve ever said we can’t do something that the business needs to do. It’s always, ‘Okay, understood. Now let’s figure out how to do it in as safe a manner as possible.’” That isn’t possible without the business nous (American ‘street smarts’) to know what is needed and the technical nous to know how to achieve it securely. “Now, am I as good at reading a really dense investor and tax statement, as I am in code? Probably not, but I totally do P&Ls. I’ve done those for a very, very long time. I understand the basics – more than the basics – in finance and business. But the part where it gets to the very esoteric things, that’s not my area of expertise.” What she has learned has been learned on the job. “I’ve taken all the management courses available from the company, and I’m a great believer in the value of training. I think training education makes you better at whatever you’re doing.” She comments that many of her colleagues (other CISOs) take time out to do MBAs. She hasn’t done this. “Would it have helped me? Probably, if I had done an MBA. Actually, I shouldn’t say ‘probably’. I am sure it would have.” Management style A key characteristic of Davis is that she is a ‘no-drama’ person. She considers this to be an important trait for CISOs. “The CISO deals with the kind of things that can just scare the [synonym for ‘bejesus’] out of an organization. We’ve been in some pretty intense situations here, but I don’t think I have ever just lost it or made my peers or my boss or others lose it. You can and should, in a very calm, no-drama way, explain the gravity of the situation. You’re working with super intelligent adults, and they will understand. If you present in a calm way, their reaction will be, ‘Okay. I understand. How can I help?’ instead of ‘Oh my god, the world is on fire. I have to jump in. Everybody has to jump in.’ If you let that happen, there will be 10 people all trying to drive a single situation, and that just leads to chaos.” That calmness in putting out fires is also helpful in preventing fires. “If I go to my CEO and explain calmly that this horrible thing is going to happen to the company if I don’t get x amount of money to prevent it, I will get the money. CEOs don’t want to put their customers at risk.” The message here is that if you present genuine requirements, ethically and without drama, you can usually get what you need. It’s a slightly different style with the security team. “Just be open with the team. Be happy in front of them, crack jokes with them, and be sad in front of them if you need to – but again, no drama. All human emotions are good to exhibit because that’s how you build strong relationships. A sense of humor is one of those things.” She has her own approach to team selection. The binary view is a simple choice between 10 discrete but highly talented team members; or one cohesive team. Davis wants both. “I would always pick a team that can work cohesively over individual superstars. But you don’t have to choose between them. We have individual superstars at Comcast. A brilliant individual contributor is the person who may come up with the next big idea; a cohesive team is how things get done. Some of the most brilliant ideas will just sit on the shelf if there isn’t a team to make them work and get them adopted.” Put simply, security needs individual brilliance combined with teamwork; but the brilliance just has the edge. It is the CISO’s responsibility to make the two aspects work together in harmony. “Individual brilliance on its own will only get you so far. My global team has more than 100 patents, and I love that. But it’s cohesiveness that makes them work and makes them stick.” In reality, although with overall responsibility for a globally dispersed team of 1,500 security practitioners, Davis only personally recruits the individual team leaders for the different geographical locations. Here she has one overriding principle: hire great people who hire great people. Handling burnout Burnout is a constant concern for security practitioners. It is common and difficult to prevent. It is almost certainly caused by the relentless stress of working in cybersecurity aggravated by other personal and unknown circumstances. It is effectively the result of an ongoing imbalance between work and play. Davis thinks that it is the CISO’s task to restore that balance by insisting on downtime to alleviate the stress that cannot be eliminated. She gave an example. “We were given access to the best AI frontier models in the world, but only for a short time. So, I told the team working on this, ‘We only have two months, but this is a great opportunity. I’m going to need you to work weekends and evenings if you can.’” Of course, they all wanted to. However, she continued, “As soon as this is over, you will all have a week off that you can take in any way and whenever you want – a series of three-day weekends or a single week off.” She cannot solve the stress side of the equation, but she can and does seek to rebalance it in the play side of the equation. What keeps Noopur Davis awake at night? By now, you’ll not be surprised that there’s not much that keeps her awake. It’s not that security crises don’t happen; it’s because she’ll just deal with them when they do. “I sleep very well because there are things you can do and things you cannot do. Right now, I know I’ve done what I can do. The team has done its best. The company is doing its best.” That doesn’t mean she does nothing. “We’re never happy with where we are. We always want to get better. There’s always a long backlog of things to do to get even better. Something will always happen; but when – not if – it happens, we’ll deal with it. We know what to do. We’ve done it before. We have the muscle memory. We’ll get to the other side. It may be a mess, but we’ll clear it up.” It is this confidence in both the inevitability of security events and the inevitability that she and her team will handle them that stops her fretting about the job and staying awake at night. “In fact, while we’ve been talking, I got a message from one of my deputies saying, ‘Urgent. Call me’. I know it’s urgent because the message says so. I’ll call him as soon as we finish here. I know it’s something important or he wouldn’t have messaged me. But I also know that step by step, we’ll solve it.” In a nutshell Noopur Davis’ career is best summarized in her own words. “The biggest thing I’ve always done is not worry about having a grand plan and just to be there when there’s something interesting and that I think is fun. Twice in my life, I’ve taken pay cuts to do something new and different, and I’ve never regretted it. There are people out there who are very successful when they do the plan, the career plan, but I’m not one of them.” Don’t be fooled by this laid-back attitude. Being able to recognize something new, interesting and fun, being able to adopt and excel in a new direction, being able to continually add new strings to your bow, all require a high level of personal intelligence, natural skill, and deep dedication to the current job in hand. Related: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW Related: Russ Kirby – Passion Is the Antidote to Burnout Related: Andreas Gaetje – From Economics to CISO at Körber AG Related: Tarah Wheeler, Cybersecurity Leader, Thought Leader and Original Thinker

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.