The Security Circle

EP 189: The Trust Advantage – How Influence Beats Authority with Nathan Mills, Global Head of Security for Brinks Inc

Yoyo Hamblen Season 1 Episode 188

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 53:11

Send us Fan Mail

Podcast Summary

🎙 EP 189: The Trust Advantage – How Influence Beats Authority

What separates good security leaders from truly exceptional ones?

In this thought-provoking conversation, Nathan Mills, Global Head of Security at Brinks, shares a leadership philosophy built not on authority, but on trust, influence and curiosity. From technical surveillance countermeasures and diplomatic security to leading global teams at GE, Zoom and Brinks, Nathan explains why today's most effective security professionals are those who can connect people, build relationships and inspire action rather than simply direct it.

At the heart of the discussion is a powerful idea: ownership isn't as important as influence. Great leaders don't need to control every decision or claim every success. Instead, they create the conditions for others to succeed, recognising that collaboration will always outperform hierarchy.

Nathan also explores why growth never happens inside our comfort zone. Whether taking on new leadership roles, relocating around the world or stepping into unfamiliar challenges, every stage of his career has reinforced the belief that resilience is earned through experience, curiosity and a willingness to embrace discomfort.

The conversation also explores servant leadership, empathy, trust, AI, physical and cyber security convergence, mentoring and the future of leadership in an increasingly technology-driven world. Along the way, Nathan offers practical advice on building trust, managing diverse teams, influencing without authority and remaining authentic in an industry that often rewards certainty over vulnerability.

This isn't simply a conversation about protecting organisations. It's a masterclass in leading people.

If you believe leadership is measured by the number of people who work for you, think again. Nathan Mills makes the case that the greatest leaders are remembered not for the authority they held, but for the influence they had. 

https://www.linkedin.com/in/nathan-mills-digitalevangelist/

Nathan Mills came into corporate security through the normal channel of an electrical engineering degree and the Foreign Service. (Ha!).  He leads with empathy, kindness, and a directness that helps his team understand the role risk management plays in enabling the business to thrive.  After leaving the Foreign Service, Nathan led security operations in diverse companies like GE and Zoom and recently landed in Brink's as the Global Head of Security.  He is navigating this crazy world with his lovely wife and two young sons.  They love being outside (even when it feels like 115 degrees F in Dallas!), exploring new foods and cultures, and is driven by faith.  Say hello to him when you see him.



Security Circle ⭕️  is an IFPOD production for IFPO the International Foundation of Protection Officers

Speaker

If you enjoy the security circle podcast, please like share and comment or even better. Leave us a fab review We can be found on all podcast platforms. Be sure to subscribe. The security circle every Thursday. We love Thursdays.

Speaker 2

Hi, I'm Yolanda And welcome to the Security Circle Podcast, produced in association with IFPO, the International Foundation for Protection Officers. This podcast is all about connection, bringing you closer to the greatest minds, boldest thinkers, trailblazers, and change makers across the security industry. Whether you are here to grow your network, spark new ideas, or simply feel more connected to the world of protection and risk, you are in the right place wherever you are listening from. Thank you for being a part of the Security Circle journey..

Yoyo

Okay, so listen, a newbie, to the Security Circle podcast, Nathan Mills, global head of security at Brinks, formerly from working with federal government. We're gonna hear all about that. Nathan, welcome to the Security Circle podcast. How you doing?

Nathan MIlls

Doing well. Thank you very much for having me, Yoyo.

Yoyo

Well, it's a pleasure. Blackmail usually works, but I didn't have to do that in this case.

Nathan MIlls

Gladly.

Yoyo

Nathan, was your career always destined to be in security? Was it always heading that way, or was it purely accidental?

Nathan MIlls

More purely accidental than predestined, for sure. I grew up as a technologist, so my, my background is engineering. I went to, Texas A&M and got an electrical engineering degree. And as I was going into that field, I really thought I'd just gonna be a traditional, quote-unquote, "engineer." My dad, was a power engineer, so on the high voltage side, so I got a lot of internships around that kind of technology and was like, "Ooh, this is kind of exciting," and it makes the world work, you know? We, we hear a lot about power and everything from renewables to traditional. So I was like, "This is interesting." But as I went around and was looking at opportunities for engineers as I was graduating, there was a big sign around foreign service in the US Department of State, and it said, "Looking for electrical engineers." And I was like, "For electrical engineers in the foreign service? What, what would that possibly entail?" And luckily enough, I had just whet my appetite by studying abroad, in Europe. I studied abroad in Germany. And I was interested in, ooh, the lifestyle of overseas and really the interest to me was about learning about cultures and people and food and everything not engineering related. So it kind of caught my attention. So I applied, ended up getting the job. I got the job about a year and a half later because of all the mechanisms it takes to get into the foreign service. But I got into the foreign service as a security engineering officer. So right away, learning about the technologies around physical security. Everything from explosion detection equipment, X-ray machines, to cameras, access control. And the unique aspect of that career path was technical surveillance counter measures. So we were the badged part of diplomatic security doing TSCM work, bug sweeps, counter espionage type activities on the technology side. So that was really interesting, and something so completely unique in the technology space that it, it caught my attention and held it for a very long time. And then transitioned while inside the State Department to more program management. Still on the technology side, but I knew that there was something more. I knew there was an itch that I hadn't scratched yet. So as I looked at what was next, I was, I was mid-career in the Department of State. Mid-career, quote-unquote, as far as if I stayed the same amount of time, that's when I could retire. It's the classic, you have to be 50 years old and 20 years in. I came in early enough where becoming 50, I would be 26 years in. So it was, do I wanna stay that long? Ended up finding a job with General Electric. I figured there's no better transition out of federal government than to go work for one of the largest bureaucracies in the world. You know, I, I understand red tape already. I can, I can work inside of GE. Uh, and I got out and started working more on the security operation side, non-technical. So started lear- started learning and leading crisis management, business continuity teams, executive protection teams, GSoCs, all the traditional kind of corporate security apparatus, and learned that I was fairly good at it and I enjoyed it, and I thought my background of living and working around the world could add some context into security, not to, not to overlook the technology background, that could be very helpful to the industry, to companies. I was able to translate what I learned and what I knew into business value, and kind of took off from there. And then went to Zoom after that, became the, the head of global security at Zoom, and then most recently transitioned to Brinks.

Yoyo

You know, when you said you went to Germany, I just wanted to interrupt you and say I love a- I love a frankfurter myself.

Nathan MIlls

Ah.

Yoyo

Just such good food there, and the bread is awesome. Oh,

Nathan MIlls

man.

Yoyo

Yeah, and the beer.

Nathan MIlls

I'll tell you, if there's ever a good reason to travel the world, it's for the food, right, Yoyo? Yeah. I mean, I miss Peru more than anything else because of the ceviche and the, the lomo saltado, and the pollo a la brasa. I mean, all that stuff is... Oh, I miss it.

Yoyo

The accent's not bad e- either, Nathan.

Nathan MIlls

Ah. I can, I can fake it till you make it when it comes to languages, right? That's what you have to do. You have to just try.

Yoyo

Season yours. Um, so look, I have to go straight into Zoom. W- Zoom are such a wonderful case study to look at during COVID, because that- Yeah business model expanded beautifully, along with some other great success stories. You can't help but wonder, where would Zoom be now if it wasn't for COVID? Now, I get it, you weren't in a direct role around, you know, how Zoom were able to suddenly fill that huge gap and enable mobile working, but what was it like being in a security role for Zoom during COVID?

Nathan MIlls

Yeah. Yeah, and of course I can't speak directly for the company by any stretch, but from my, my viewpoint of working for the company, the- Uniqueness of it to me was working for a company that enables such an important part of the global, I'd say the global apparatus. It's not the global economy, it's not just spec- specifically about the finances, but to work for a company that was enabling teachers to reach out to students in a way that they could never before, for doctors to reach out to, to, uh, patients in a way they could never before, and then translating that into a global security team to say, "How can we enable ourselves by using this kind of technology in a smarter way?" was fascinating. And as the traditional, you know, you've had a lot of people on your podcast that will talk about, you know, translating work from a federal government type of no product mentality to, to a, to a business side. Being able to, to grab onto some things that may be monetized in a way or be able to, to convince customers that y- this is a product that you need to use, Zoom, et cetera, and one of the reasons why is because the physical security team is more, uh, able to secure the, the aspects of the company that maybe another company couldn't do. And what I mean by that is we're, we're proactively enabled by AI. You know, what are we doing with AI agents that can speed up time to value around traditional s- uh, sec- security workflows like ticketing or, or GSOC processes or intelligence functions, th- different things like that. So it was fascinating to me working for Zoom to work at the speed at which the company needed you to work, whereas in other cases, you're very much dictated by, you know, which, which, uh, which three-ring binder do you need to pull off the shelf to run through that SOP. You know, at Zoom it was like, "We need this done. We need it done fast. How can you do it with a, with as much accuracy as possible and keep the company safe, keep the people safe, and protect our assets?" So it was a really interesting d- dynamic case study that, to your point, probably, you know, MBA students should be writing things about, uh, for, for a long time.

Yoyo

Great story, yeah, and, and that, that agility in terms of, and not all large organizations can be that agile, but being able to be agile seems to be the key for the last six years. And I think that agility- Yeah or the application of it is certainly relevant now when we look at how tech is becoming so intrinsically interwoven with all of our security 'cause you can't be in physical security now and not really touch technical in some way. How does your experience crossing both really benefit you in your current role?

Nathan MIlls

I think it's being able to relate to the different aspects of the business. So I c- I have a comfort that I hope a lot more people are having nowadays, but I think traditionally don't have in the physical security space, of being able to communicate with our CISO, as an example, the chief information security officer, or anyone, uh, working operations of IT security, as easily as I can go talk to the chief legal officer or to compliance officers or to, you know, whoever's running the guard force program, you know, in, in a different country. I'm able to kind of translate all those things into why it's important. Defining the why is of, of course, uh, one of the key skillsets that I think most chief security officers or global heads of security need to be well-versed on and to practice as often as possible. Um, but I think that's where my technology background, engineering, and kind of that logical mindset of identifying a problem, being able to outline how to solve a problem, and then working through teams to, to, to go on that, go on that journey of solving it in a whatever way is necessary for the company, is something that I've learned through both all the way from my academic side through my professional experience

Yoyo

I've noticed certainly from my own experience there's been a reluctance for physical and cyber, you know, the CISO and the group secur- the group security chief to really be aligned. There seems to be in my background experience th- the kind of posturing, oh, cyber should come under global security. Uh, they're all protective services along with legal and health and safety, for example, and there's certainly an argument of them being under a collective protective services umbrella. But for those that are working in those separate silos, what advice can you give to folk that could be potentially struggling in this competitive space?

Nathan MIlls

Hmm. Uh, it's, it may, may be a little cliche, but I fall back on like a Stephen Covey Seven Habits of Highly Effective People mentality of seek first to understand and then to be understood. I'm a big fan of, especially when you're new coming into a role, really be curious. I think it's curiosity, and empathy are two key features of a global security leader, whether you're cyber or physical, that I think can serve you well in, in any of the industries. So once you understand a little bit more of what the priorities are of whichever team you're trying to engage with, then you're much more able to translate either your own skill set or what you know is the mission of your group to be able to assist, to be partners with. Mm. I, I also, you know, I think it's very important, and I, I think some people may think very differently about this, but I think ownership of something is not as important as influence into something. And I, I say that kind of tongue in cheek because I think we have an opportunity to, to influence by making great ideas everybody's ideas. It doesn't have to be Nathan coming in with the best idea that gains traction, and then you run with it and, "Yay, I can hold the flag that, yes, this was mine." It's more about what is the value you're bringing to the company, regardless of who gets the credit. I think we miss that a lot, and I think too many people hold onto that as their value into the company or even their career value, whereas if you get over that hump of defining yourself by that, you're gonna be much more successful, I think.

Yoyo

I think that's really profound what you've said, and I'm certainly gonna capture that, the ownership versus influence piece, because ownership leads to pillars and polarization, whereas influence leads to collaboration, doesn't it?

Nathan MIlls

It, it does. I think there's a lot of companies that work in matrixed organizations, so, you know, direct lines of hierarchy versus dotted lines of hierarchy. And, I do think that some people have a really hard time working in that environment and it, it... They need more validation, et cetera. But I think that comes from knowing your manager, managing up, and then managing down as well, being able to understand, "Hey, my, my skill set, my expertise is providing a value. I was hired for a certain reason." Yeah. And once you're at a certain level, I think you're hired because of what you can bring to the company, not just for, okay, 'cause you have one specific skill set that is your s- subject matter expertise. I think I'm coming into my newer roles over the last five, six, seven years with the knowledge that I may not be working right to the job description that I was hired for, because I think my skill set may transcend some other boundaries that I think I'll learn once I'm in.

Yoyo

What makes somebody like you, Nathan, want the top job? Because I've, I've never wanted it myself. I've always wanted to be someone's great number two, yeah? I'm like Spock- Yeah in Star Trek to Cap- to James T. Kirk, yeah? Yeah. I mean, I'm not saying I'm that clever, but, um, you know, it takes a certain type of person to want that top job. How do you... He's giving me the Vulcan hello now. Live long and prosper. Um, how, how... Like, every time you've gone into a very, very senior role, have you Is there a bit of a part of you that goes a little bit Irish that says, "Jesus, Mary, Joseph, and the donkey," like, "What have I got myself into here?" Take us through a story.

Nathan MIlls

I think we, we've talked about this before, and you've talked about it with other people, but growth doesn't happen in comfortable situations. I think you have to be uncomfortable to grow, and I still feel like I'm young enough where I still have a lot of growth ahead of me. And to do that, I've gotta be able to say, "You know what? Even though I'm maybe not the perfect person for this role based on how it was described or positioned by, you know, whether the job description or the talent acquisition person tells you, I'm gonna put myself out there and say, 'You know what? I'm interested in this company. I'm interested in maybe the manager is somebody that I've heard of or learned from in the past that I wanna work for.'" Um, I think getting the top job in any situation, whether it's your kids, kids', uh, sporting, sporting events, like you're coaching, you know, little league sp- sports at is, is very nerve-wracking too. But you're gonna grow with it. You're gonna learn from the people around you. You're gonna learn from, uh, the company. I think going into it with that growth mindset and that learner's mindset is how I've gotten over that hump of being a little bit scared and being a little bit more comfortable by saying, "Oh, I'd rather be number two so that somebody else can take the heat and I can just do what I'm good at already."

Yoyo

How is your resilience now that you have all of this global relocation experience working for different companies? What would you say to sell why being resilient is a really beneficial part of the self-developmental journey?

Nathan MIlls

And it's, it's not too different than what I said previously about growth. I think resilience comes through experience a lot of times, and- I, I, I think people don't realize they're gaining, uh, skillsets and resilience until after the fact. You know, I think a lot of times in global security teams, uh, and law enforcement, first responders, any of, any of the kind of traditional people that, you know, go toward the, go toward the bad thing first, the instinct is to go toward it. I think that kind of mentality, um, is prevalent in our industry. But even for those that sit back and, like, watch and, and observe, you gain resilience by just being around it and kind of absorbing what you're seeing. And I think being intentional how, on how you learn is a big piece of that resilience, is don't just expect that you're gonna learn through osmosis all the time. You've gotta do these things. You gotta fail, be okay with failure, and then you, you learn from it. And Yoyo, I'll tell you, I've learned a lot about myself and about my family, about being a father, about being a son, about being a husband, in my case, through all these moves around the world, and you can't replace that with tabletop exercises sometimes. You've gotta be able to experience it. And just more recently, just making a big move across the country with my family, I learned more from my kids than I, than I was able to teach because of my experience. Like, just the curiosity they have, the questions they ask. Being able to do that as an adult in a professional capacity and not being scared of asking questions that you may think, oh, I should probably already know the answer to this one, but I don't, and I, I'm not scared of saying I don't know it, I'm gonna ask it anyway. You are gonna gain a lot more from that than holding it back and just, you know, regretting it later that you should have asked the question.

Yoyo

I think you're in the state of Chuck Andrews now, aren't you?

Nathan MIlls

Oh, man. I don't know. Am I? I need to get my... I m- oh, just l- geographically, I certainly am, and I need to get the hat to go with it, but.

Yoyo

Right. But will you look as good as he does in it?

Nathan MIlls

Oh, guaranteed not. No.

Yoyo

Guaranteed not. I wanna take you through to, uh, TSCM, technical surveillance countermeasures. Sure. In my previous experience, I was quite surprised working for major global businesses how reluctant they were to consider deploying TSCM. You know businesses that have shared, um, you know, shared client spaces, for example.

Nathan MIlls

Right. Sure. Right?

Yoyo

And we know those businesses. They're consultancy firms, and consultancy firms in one office could be doing something for one major bank, and in another office could be doing something for a major manufacturer of some highly confidential, technical, under NDA, you know, products and services, doing a sprint, for example. I found it really hard to say, "Look, I definitely think we should start from zero, but we should definitely have a plan in place." But I found it really hard to influence in that way. Why do you think companies are reluctant to explore? Is it a lack of trust?

Nathan MIlls

I think it's a, it's a lack of understanding, and I think there's a lot of themes that come into global security that I think we'll uncover by me answering this question. I think it's gotta start with, you know, a risk assessment. It's gotta start with, you know, what are these risks that are concerning to the company? And some of 'em may be, hey, we've got shared walls with XYZ embassy that is interesting in our tech- not interested in our technology as a private firm. What is the risk that they may take advantage of that, or that it's a known- A known thing of why they chose that space or, you know, whatever it may be. We need to think literally outside the box of our four wall- of our six walls and say, "Who's around us, and why would that be a concern to the company?" A lot of times the risk equation becomes I'd rather be in a large building with multiple tenants because then I have some an- anonymity as it relates to, in the US as an example, traditional workplace violence threats, an active shooter or something. I think the flip side is, well, who's to say that that risk doesn't go up because you've got more companies that you don't know anything about, and who's to say that they don't have a workplace violence event that, you know, crosses the, crosses the hallway because your, you know, your front door looks just like theirs? So I mean, you have to talk about the right things to be able to assess risk, and then one of the tools you have in your tool belt to assess the risk is gonna be a TSCM. "Hey, can I, can I do a TSCM inspection of the CEO's office because there's a risk, I think, of, hey, their windows look right onto XYZ location that I think they have capabilities and techniques that could influence and could, you know, be a risk to the company." So looking at the TTPs of what your malicious actors are inside your risk profile and putting that into the, into the, uh, scope of what your business is doing. And then, you know, if you really have to and you really feel passionate about it and you're not getting traction, why not do your own personal little red team activity and try to, try to prove the point? Like, "Hey, if I'm sitting right out here and the CEO's in his office, I can use binoculars and see his screen. I can..." You know, whatever it may be. And then, um, you're able to prove it through a visual, prove it through a story, you know, back to the theme of stories, that then gets you programmatic assets that, that you need to be able to mitigate the risk.

Yoyo

Let's talk, 'cause we talked about this in the pre-chat, about the sort of centralization and decentralization of security operations. Let's talk to the benefits and the disadvantages to both.

Nathan MIlls

Okay. Yeah, I think there are pros and cons of both. Um, decentralization, you think of, you think of maybe speed to value at that local location. You- you're able to have language assets or you're able to have, uh, intelligence assets that are more ingrained into the culture of wherever that location is. Um, but I think a kind of h- I wouldn't call it a hybrid model, I don't think that's what we would say in the industry, but a centralized model of having strong governance at a centralized model that has execution at the local levels. I've heard this, um, before from somebody I consider a mentor who says, you know, it's, it's freedom within a framework. Um, and I think the ability for security leaders to be able to give their teams and their company freedom within a framework- is the most, uh, enabling function that I've seen work inside corporate security. When you, when you show trust, when you show that you have confidence in the people that you've hired and where they've been hired so that you can say, "Here's the framework that we've, we've created because this is the best for the company. We feel very confident in it. We've got an executive buy-in. Now execute off of that framework, but you have freedom in them. If you wanna do it a certain way there, a certain way here, that may make the most sense for your location, but don't go outside the, you know, the guardrails that we've created inside the framework."

Yoyo

Yeah. That's, that's incredibly important, isn't it? What's the biggest kind of career takeaway that you think, crikey, you know, I, I... Not only would I love to have known that a lot earlier, but this has been one of my core values and principles that I've carried with me since learning and understanding it?

Nathan MIlls

I would say w- uh, from a core value perspective, when you say core value, the first thing that pops to my mind is, is my family and my, my, my core values of faith, family. Um, I think we try to separate that almost too much in the global security function. And from a, from a story perspective, I get a little bit emotional when I talk about this stuff 'cause I've met too many, um, unfortunately men inside of the security function that seem to have it all put together, and then you learn through unfortunate events, whether it's the, um, the tr- the tragic committing of suicide or something like that. I've had too many, too many, once too many, but several in the last couple of years in my s- close orbit. That proves the point to me that you've gotta have the core values of what's important to you as a person first. 'Cause what you, what you look like and the image you portray inside the industry or inside your role doesn't mean much if you don't have the core values, uh, that are leading you in the right direction as a person, and I think that is hard. It's easy to say. I mean, I certainly, you know, we, we, we hear it a lot, we see podcasts. We, we hear a podcast, we, we see influencers, we scroll, we see these great messages of, "Oh, yeah, this is the perfect life if we do it the right way." But I think we, we miss the opportunity as leaders to be in front of our younger generation and our, our people that are coming up or trying to even switch into security to say, "Hey, it's okay to be vulnerable as a security leader. It's okay to have a bad day. It's okay to come into a meeting and say, 'Hey, you know what? I had... You know, my kids were sick and that was tough, so I'm gonna, you know, be showing up in a different way today.'" Especially going back to the stories of Zoom, being a, being vir- virtual, you, you get a lot less personal as it relates to how you're interacting with your colleagues and, and other people in your organization. So being able to talk about it is a skill set that I don't think we, we lean into enough.

Yoyo

It's really sad to hear your story there about how you've lost some friends in the business, you know, um, clearly highly networked friends of yours. I just... I wonder if the industry isn't providing opportunities for true authenticity if that's what you're seeing and experiencing.

Nathan MIlls

Hmm. I don't know. I, I, I don't wanna ask the industry to do that. You know, I think that we, you know- I, I think the industry is, is, is fragmented in a lot of way. There's a lot of different groups that, uh, have a lot of great things going on, and lead in, in appropriate ways. But I don't think it's an industry responsibility to, to provide that avenue. I think us as people, humans, need to give ourselves the platforms when we have the opportunity, such as maybe having the, uh, invitation to join a podcast, to, to, to tell people that, "Hey, it's okay." And, you know, you can, you can wear a, a, a bright colored shirt as a security person, and you don't have to, um, be as, uh, traditionally masculine if, if you, if you feel that that's the, the image that you need to portray. We, we have an industry full of incredibly diverse people that can give so much more than they're given the opportunity to. And so that's what we need to be able to do as, as people. And I think the industry should give that kind of framework, make sure that we're training people in the right way, and giving opportunities to a more diverse background and skill set to, to bring them in to really heighten what we do and what value we provide to our individual corporations and to our communities.

Yoyo

I'm gonna add here that I think certainly from a personal journey, I, I really enjoy not managing people now. I always thought that that was something to aspire to. I always thought I would be good and kind. Um, but managing people is really hard. It's, like, really hard. Yeah. And I don't think I really appreciated how hard it is. We all know about the common principles, don't we? About, you know, winning hearts and minds and... But ultimately, some people can be very difficult. They're just difficult in life. They're just difficult, period. They're difficult to manage. Y- you've clearly managed a lot of people in your journey, and I think most people listening who have managed people know exactly what I'm talking about. It's easy to get bullet holes in your back and knife wounds on that journey. Yeah. Uh, and, and I, I've been told, for example, by really smart people who've also got more bullet holes and stab wounds in their back, you know, "Don't trust too much." I think I have this huge issue, like, do you trust or do you not trust? Do you go in with zero trust, or do you go in and give trust in people and just lose it? What's your leadership of of managing people, um, experience tell you, and what do you think works?

Nathan MIlls

Hmm. I love that question. Yoyo, thank you for going into the, the hard stuff with- with people like me. I think that's important. Trust is a great way. I, uh, let's dive into trust a little bit. I think, um, one of the biggest lessons I've learned over the last five years is around trust. And when you go into Zoom, as an example, there's three required readings when you go into Zoom. Uh, one is, uh, Keep It Simple. A second one is Delivering Happiness. And then third, which I think is what I've gotten a lot more from than the others, is Speed of Trust, by the, the junior Covey, Stephen Covey again. And what I've learned through that, and I've used it, uh, in my own professional circles outside of just learning about it at that Zoom, I think- A lot of things are driven by trust. Um, so when it comes to managing people, I think you have to build it, you have to earn trust from the people that are working for you, and, you have to sometimes give it, you know, a l- little bit more free rein than you would elsewise, to your point of, do I worry about getting shot down because I, I gave too much trust. I, I don't live that way. I don't live, I don't live in a way, and I don't lead in a way that I feel anxious because of trust I've given. I... If trust is becomes broken, it can be built back, but if trust is broken, you talk about it and you say, "This is what I saw, this is what, uh, what impact it had, and here's what I think we need to do going forward." It's like the whole classic BIRA model. You know, you talk about the behavior, you talk about the impact, the response, a- and the action going forward. I, I l- I really like that. Um, but again, it's hard 'cause it takes time, and I think a lot of people lean on speed to value over quality of that value. And sort of that balance, depending on which industry you're in, which company you're working for, what kind of manager you have, you're gonna have to figure out what that balance looks like for you personally. But I lean more towards of the giving, giving more trust and that's usually given me more value than holding it back, uh, and worrying about it being broken.

Yoyo

Yeah, that's really interesting. But do you think your faith leads you well in this space, in the sense of, you know, there's a lot of humbleness about you. There's no outer ego that's really visible, that's gets in your way. How do you think that plays out?

Nathan MIlls

Um, absolutely. I think, I think my faith is, is, as it translates into leadership and management has been extremely important. I think mo- when I am talking to, uh, to, uh, subordinates, to people that, that work in the organization that are, uh, led by my, my, my team's mission, and I talk about my faith, I give them an opportunity to be more curious about their own. And regardless of what faith they have, uh, you know, in global teams, I, I certainly would never suggest that a certain faith is the, the most proper one to have in a global team by any stretch. But I think having a faith gives other people the freedom to, uh, make sure that they feel comfortable bringing their, their whole self to work. I mean, it's a, maybe it's a cliche of, you know, bringing your authentic self to work, but I think that's true. I think if people know that about me and they realize that I'm coming from a, a, a place like that, even if they don't agree to the same faith as I do, they know that I'm approaching it in an appropriate way. Um, and that comes a- that comes across in different ways. That comes across, sometimes it... You, you have to walk that fine line, and there's, there's the, you know, separation of church and state, and a lot of people don't wanna bring that to, to work. And I can respect that some do that, but not me. I, I ha- I talk about it and I, when I introduce myself, as in when I, just recently when I came into a new world, like, that was part of my introduction, was, "First things first. Here's a picture of my family and here's, here's, here's me talking about my faith a little bit. And that is gonna drive, you know, everything else that comes around me. And I feel very confident that I know what I'm doing as a professional, and I'm gonna prove that to you. I'm not gonna just expect you to believe it." But it's coming from a, from a very solid foundation that's very important to me.

Yoyo

I thought you were gonna add, "And here's a picture of me singing in the choir."

Nathan MIlls

That's right. Here's me doing karaoke at this, uh, karaoke joint in Japan. Yeah.

Yoyo

We know that certainly the security industry doesn't have a lot of empathy in management, and there's been a number of different conversations that there should be more empathy in management. And maybe, you know, that's where your faith enables you to be more empathetic. Let's talk about the importance of empathetic leadership and servant leadership. Why are they so fundamental for gaining trust and collaboration amongst peers and colleagues, and success, uh, for outcomes?

Nathan MIlls

I think, again, we, we, we as an industry stereotypically try to go too fast. And I think when we, when we go too fast, sometimes we make assumptions based on what other people are, are going through and thinking about and why they make certain decisions. And that often creates that what you think is the fast path to become much slower 'cause you've, you've, uh, overstepped your bounds, you got over your skis, you know, whatever cliche you wanna use. I think by using empathy to understand what people are going through and asking the right questions, you know, seeking first to understand, again, as a principle is is not only the right way to do it, I think it ends up being the fastest way to do it. And, and when you, when you're able to learn from people and understand what they're going through, you're able to manage it in a most, a, a more appropriate way for that person. And I think management has to be individual in that sense. I think too many times we think, "Oh, I've got my management style that's one, one specific style, and that's all that it's gonna take, and I'm gonna be successful no matter what if I just do that." Well, not really, 'cause if I'm, if I'm managing a team where, where Yoyo is the, the project manager or- or is a key operational person on the team, I need to manage her in a different way than I manage somebody else that maybe needs something, uh, different from me. And I have to recognize that, and I have to be willing to put the time in to, to learn what that may be. And through empathy, I think is the best way to get that.

Yoyo

But I think that's really hard for people to do, because-

Nathan MIlls

Oh, for sure

Yoyo

we, uh, the managers of people tend to get into a comfortable rut. This works, this seems to get good- Yeah results. You know, I'll use that, I'll use that. And if a manager- Yeah of people is then having to think, "Okay, I need to manage this person differently," they're potentially inviting themselves to go out of their own comfort zone, and that's not really what people choose to do, is it?

Nathan MIlls

Oh, for sure. Yeah, you don't... Again, you don't, you don't grow if you're always comfortable. So, you gotta grow through being uncomfortable. And un- uncomfortable in management goes through, "Hey, I'm gonna try to, uh, to influence in a different way here. I'm gonna, you know, choose a different time zone. I'm gonna, I'm gonna invite someone to lunch, and it's not gonna be food that I like." You know, or whatever it may be. You know, you're gonna, you're gonna... My, my wife hates when I, when I say this, but it's, you know, it's only hard work if you do it, to your point of it, it, people choose the easy way, and that's human nature a lot of times, for sure. That's, you know, practical drift. I have a, a good buddy, um, who you may know, I, I assume you do. Um, and I always like to drop his name on, on podcasts because he, he is a very good public speaker, too. Uh, Burke Brownfeld, and he talks about- Yes you know, practical drift. You know, it's the classic design principle of, of, of sidewalks is the example that he uses a lot, and he'll show pictures of, you know, you got the sidewalks that are a 90-degree angle, but where's the rut in the grass between them? It's right there at that curve, you know? People take the easier route, and how does that apply to security and our pro- and our programs? You know, let's do two- Two 30-second micro-learning videos instead of one 10-minute one, you know, kind of deal. Those types of things are gonna get more, uh, appreciation, and you're gonna gain more trust, and you're gonna show more empathy by doing it in a different way when you learn more about people and the psychology of people.

Yoyo

And it's so important in physical security because you've seen that picture of the university campus where there's a really nice pavement going around a grassy green area, and everyone's walking across the grass, and there's this kind of- Yeah trundled, muddy path that everyone's using. That's right. Even though... So when you apply those principles of that kind of least resistance from users, I suppose, especially from a physical security perspective, I think you have to do the same from a technical security perspective as well, don't you? You've got to factor in that humans, I've said this before, are inherently lazy, and the... And, and if they have an optimization brain like me, they're always gonna look for shortcuts to do something quicker, faster, better, which is why I think we've- Yeah become so addicted to AI.

Nathan MIlls

Oh, yeah, for sure, right? AI can give me the 60%, 80, 70% solution right out. Yeah, I'm gonna do AI for sure, and it's gonna sound good, it's gonna look good. And then people that aren't any the wiser will just accept it as that and say, "Yes. Okay. Move on. Let's just do that." And so to your, to your point about technical security, the physical security technologies, I think what I've noticed a lot, uh, is, you know, people taking those shortcuts, whether it's the classic propped open door because it's, uh, it makes it go faster when I'm coming in for the day or to... I went out for a smoke break, I'm just gonna prop the door so I don't have to use my badge to get back in. All, you know, all these little classic tales of best technology can be, can be, overtaken by, you know, a lazy person or a lazy, uh, process. Yeah, combining all those together, making sure you have validations, there's so many touch points that we have inside security that- If you, if you go down your rabbit hole, you can really, uh, frustrate yourself and get very, uh... And, miss all the other great opportunities you may have if you, uh, if you go after just little small things here and there. So you've gotta build this framework again, you've gotta get people accountable, you've gotta show people you're paying attention, and then, and you of course have to prove the why. Why is it that you're doing it? What are... You know, you gotta call the baby ugly at the beginning sometimes to say, "Hey, this is why things are, are bad, and, let's address it," you know? And if you're not the one to do it as a security professional, then who's gonna do it?

Yoyo

Most people that know me know I love watching videos of people falling over. There's a lot of dash cam footage at the moment. There's a lot, and you know, I say dash cam, there's a lot of, uh, Ring doorbell footage, and there are other brands- Oh, yeah out there of people just slipping up- Love it on their porches, their driveways, um, head butting their cars, and invariably they're all not paying attention. They're all, they've got their phone in their hand, but I'm a culprit of this. I was walking in a railway station down several steps, probably about, I don't know, 25 times 25 times 25 with pauses in the middle, and I f- I fell down the last rung of sort of 11 steps, got to the bottom quite embarrassed, and then still have my phone in my hand. There's a, there's something about how we're operating as individuals now. But I also followed somebody on LinkedIn who puts up security fails, and they put up a picture of a CCTV camera, and then it was like, "What's wrong with this photo?" And so you look at it, and you look at it, and it's like the IP address is written on the outside of it.

Nathan MIlls

Yeah. Right.

Yoyo

Cause someone- Who

Nathan MIlls

wants access to it, feel free. Yeah.

Yoyo

That, that would... Let's talk about show someone the doorway into, you know, the CCTV network for goodness sake. Somebody thought, "Oh, that's a great idea," because they clearly might forget the IP address of this camera, so I'll write it on the camera. So there must have been some kind of logic. But that's what we have to mitigate against, isn't it, is that intent of m- intended wellbeing, but ultimately it's massively harmful, and that's a form of insider threat itself.

Nathan MIlls

It is. It is. Yeah. So I think to, to that point, how do you, protect against that and how do you, how do you make sure that, you're building structures inside your security program that go to that, uh, least common denominator, you know, the weakest link in the chain type of thing? I think- Most security practitioners, as they get more senior, need to become experts in the governance model that they think is most effective. And I think understanding how you write policy, how you structure a policy, then a standard, then a guideline, then a SOP, the four layers there are so strictly important because then everything else you do after that can kind of tie back to it, and you're able to prove the point of, "Hey, we had a theft. Well, now we're doing the investigation. What was the root cause? Okay, we found the root cause. Hey, look, they went against one of our policies." That directly ties, we need to hold people more accountable. And then you're able to kind of create a cycle of let's get, let's get resources, let's make sure we're, we're helping people understand why we've got these policies in place, and use our own internal stories or stories that benchmarked from the industry to kind of create that beneficial cycle to the company, which ultimately, and I think you know this for sure, makes you more efficient, makes you more effective as a company, and you actually then influence the bottom line. You know, your P&L is more attractive once, you know, the right security practices are being followed, and you can prove it.

Yoyo

Funny that. Um, I love what you're saying about delivering happiness, by the way. I'm thinking, uh, Nathan, I need to find a way to add this to my signature on my email.

Nathan MIlls

Okay. Yes.

Yoyo

I'm thinking it might be a bit of a dichotomy though, because I don't think people in cyber are seen as delivering happiness, but I feel like I need to use this somewhere. Um, but look, I ask a lot of people at this stage of the podcast a five-year question. What do you think is emerging now that we haven't seen yet, that in five years' time we're gonna look back and say, "Whoa, we should have seen that happening"?

Nathan MIlls

Not seeing yet. I, I would say some people are seeing it, so it's maybe, uh, uh, not exactly an answer to your question. And AI is part of it, but the agentic piece. I think the ability to make agents do things inside of the physical security space that we haven't really thought is possible by an agent yet is probably that next stage, and I don't know what that would be. I mean, the simple stuff of if you have great data, and you have it organized, and then you can put AI on top of it to make it make decisions for you, that all makes the most sense, and a lot of people actually miss those parts. They think AI will just solve the problem. Well, if you don't have good data and it's not organized, and there's some AI that's now helping do that, so that may be another piece of an answer to your question of does it really have to be structured data? Now some of these data lake companies and management companies, you can just throw unstructured garbage to it, and it makes sense of it, and you're like, "Ooh, that can change things quite a bit too." 'Cause then you start to be able, in my opinion, leverage, leverage the technology to better understand employee behavior or to employee... and to, to better understand human behavior, which then gives you more insights into human risk. What is the risks? What are people doing that may cause more risk to the company or to a facility or whatever it may be that we didn't know before?

Yoyo

I was, uh, recording a podcast yesterday evening with Dom Morone, who's one of my AI kind of, um, advi- you know, sort of imaginary cy- uh, cyber advisors. Um, my, cyber advice board. Um- Yeah board of advisors. Crikey, I found that really hard to say. Um, and he was basically... Well, we were having a conversation around agents, and- Mm-hmm and then that conversation led into another conversation today where we realized from an HR perspective that there needs to be human accountability for every agent. Mm. Almost like a manager of the agents, like all the agents gotta have a, a human equivalent. You know, that where, where you've got documented accountability, not just two eyes, but four eyes process maybe, in case the person- Mm leaves or, you know. What we can't have is the agents existing within an enterprise and, and in the passing of time, 'cause we know this happens, we know it happens with certificate management, right? Somebody leaves, and then there's no s- there's no notification, and a zero-day incident is going to happen. And I'm thinking, I, I just see, like, years from now that this rogue agent's been there. No one's seen it for, you know, four years, and it's still been doing this. And, uh, just go, I just g- I hear this kind of thing happening in the future. It

Nathan MIlls

makes you nervous, doesn't it? Yeah. Uh, no doubt about it. Yeah. And so what does that human element look like? How do you, how do you validate that it's happening? What kind of tools are out there to help you, help you navigate that? You know, just like you're using, uh, scanners to know what's on your network, you know, how are you scanning the agents to make sure that they have access to the right things and not the wrong things, and aren't making decisions on your behalf? Yeah. And also, you know, one thing that I, I l- I've seen, and it was big in, in Zoom before I had left there too, is, you know, the, the, the, um... What do we, what do they call it there? The AI companion was the, is the Zoom product, but it was like creating your own, uh, avatar, so your own personal avatar. And what I think is gonna happen, uh, and I think this is in the network or in the, in the ether here already too, but being able to create your own model. So I have Nathan's large language model. Nathan's model is sitting over here, and hey, it's smart enough to, to learn how I make decisions, to learn how I reason. Second

Yoyo

brain.

Nathan MIlls

And for the most part, I can send it to 40%, or I can have it respond to 40% of my emails because they're, they're less consequential or, you know, whatever it may be.

Yoyo

Yeah.

Nathan MIlls

But then it's also able to tell me as an, kind of an assistant to say, "Hey, these are the meetings you need to go to personally, because those are ones that you need to make more decisions that are gonna have financial implications or risk implications based on your role and what you've taught me as your model. But everything else, hey, I can take care of this stuff for you." That is gonna be fascinating.

Yoyo

That's, I think we call that second brain, where you basically download- Second

Nathan MIlls

brain

Yoyo

yeah, you download everything from your brain into a, a, an AI. It's a bit Black Mirror, you know, it's Charlie Brooker.

Nathan MIlls

Yeah. Yeah.

Yoyo

It's, it's got, does that second brain then have an entitlement under, under certain AI rights to exist, and can it determine its own, uh, existence? Ooh, then, then we're really going into Black Mirror, uh, space. Look, I love what you said about ownership v influence. I love what you've said about growth doesn't happen in comfortable situations. I think people who've been through tough situations find that incredibly, like, they can give themselves a pat on the back, yeah? Because no one really grows if everything's all cushty and, and good, right? And I also, I also love the fact that, um, someone taught me this once, and it's certainly relevant to the physical security space, not so much cyber, but it does exist in cyber, is that not everybody wants to grow. Yeah. And you kind of need that kind of stoic stability, because if you had everybody wanted to grow, I think it, that would be in itself a very difficult situation to manage. Love the fact that you mentioned you had a mentor. What are you learning in this mentorship journey?

Nathan MIlls

I would say I have multiple mentors.

Yoyo

Cool.

Nathan MIlls

And I, uh, so to your point, I think you said this earlier too, like having your own little personal board of directors, right? You- I think that's very important for people to have- Yeah um, executive coaches, things like that. You know, look for assistance. You don't, don't think that you're above learning ever. So what am I learning right now? I would say the, the classic Mark Twain quote of, "I would have written you a shorter letter, but I didn't have the time." Being able to put complex con- ideas into concise, digestible pieces of information is what I'm learning more and more how to do. So having that executive presence of saying, "Hey, here's the extent of the program that I'm trying to get funding for or to, get influence on," or whatever it may be, "But I'm gonna send you two bullets that show you exactly why." That is really hard to do. The ability to kind of make sure that you understand who your audience is and how you curate your story for that audience in a way that is appropriate and that they remember you and your story and why it's important to them so that you get kind of what you want out of it, you know, your influence grows. That's the stuff I'm learning right now, and it's hard, but, it's something that I need to learn and I want to learn.

Yoyo

A lot of people say to me, you know, they learn a lot listening to the podcast, and I say, "Well, how... Imagine how, how much I learn," that I have got this kind of, you know, echo chamber of some of the greatest minds and thought leaders in this industry, and I get to have conversations with them. So it's purely selfish, for me. Um, but another great conversation. Nathan Mills, thank you so much for joining us on the Security Circle podcast.

Nathan MIlls

Well, thank you for having me.