EP439- Stop Reporting Activity, Report Risk Reduced w/James Dunlap

Phil Howard & James Dunlap

EP439- Stop Reporting Activity, Report Risk Reduced w/James Dunlap

THE IT LEADERSHIP PODCAST
EPISODE 439

EP439- Stop Reporting Activity, Report Risk Reduced w/James Dunlap

20
1 X
20
00:00 | 00:00

Short Clips

Episode Highlights

James Dunlap

GUEST BIO

In Episode 439 of You've Been Heard, Phil Howard speaks with James Dunlap about turning technology and security work into language executives understand.

James draws on leadership experience across healthcare, banking, fintech, and legal services to explain why projects, ticket counts, and technical jargon rarely tell the full story at the board level. He shows how to lead with risk reduced, value created, revenue impact, competitive advantage, and reputational consequences.

The conversation follows his path from fine art photography and medical imaging into CIO leadership, including his decision to step down from a healthcare CIO role to learn directly under a banking CISO. James also recounts leading a seven-location medical practice from paper charts to electronic records, examines the security challenge of legacy healthcare equipment, and warns that governance and accountability for AI agents are not keeping pace with capability.

He closes by reframing imposter syndrome as part of growth and explaining why credibility comes from quiet, consistent follow-through.

Network Assessment

Your monthly IT spend should be boring.If it's not, something is wrong.

Network Friction Score
BoringChaotic
Do you have provider/support numbers handy, or is it 1-800-GO-POUND-SAND?

We review circuit consolidation, contracts, security, outage visibility, billing, and future flexibility to reduce chaos without forcing change.

Circuit consolidation
Contracts & pricing
Firewall management
Outage alerts
Edge security
Billing & licensing
Boring results. Reputable savings.
Consolidation that makes sense.
Show Notes

Episode Show Notes

Navigate through key moments in this episode with timestamped highlights, from initial introductions to deep dives into real-world use cases and implementation strategies.

[00:00] James explains why IT leaders should report risk reduced and value created instead of activity.

[00:45] Phil introduces the leadership problem: technology is indispensable during a crisis but can look like a cost center when it works.

[01:55] James describes his CIO responsibilities in a Mid-Atlantic law firm and why downtime directly affects billable work.

[03:16] Security and GRC emerge as James's deepest areas of focus.

[03:40] Doctors versus lawyers: the challenge of gaining support for security spending.

[05:30] James says communicating in the language of the C-suite is an IT leadership responsibility.

[07:03] Why executives care more about business continuity and reputation than security product jargon.

[08:08] A hand-me-down Commodore 128 begins James's technology story.

[08:18] Fine art photography, medical imaging, and the move from darkrooms to digital systems.

[09:56] The early-2000s challenge of moving medical images between offices and paying for storage.

[10:52] A healthcare acquisition exposes a major information security gap.

[11:37] Social engineering and paper compliance push James toward deeper security work.

[12:28] James steps down from a CIO role to learn directly under a banking CISO.

[13:26] Why a step back can create a stronger path forward.

[16:16] The episode thesis returns: C-suite leaders think in outcomes while IT often speaks in projects and jargon.

[17:00] Watching technical meetings translate into board conversations reveals what James was missing.

[17:46] Security communication works best when it explains consequences, revenue loss, and reputational harm.

[20:26] How to define value through lower spend, reduced management burden, ROI, and competitive advantage.

[22:57] James maps the chain reaction from an exposed risk to an incident, a breach, and client notification.

[24:05] Why reputational harm can become a slow burn affecting clients, contracts, and talent.

[27:37] The legacy healthcare problem: expensive equipment can keep working after its operating system is no longer patchable.

[28:45] Governance failures, risk treatment, and the choices leaders must document.

[30:47] The paper-to-EHR project that became James's first major leadership test.

[32:20] Seven surgeons and seven locations move live over three days.

[33:03] A successful implementation helps James believe he belongs at the leadership table.

[34:52] The next major question: governance of AI agents and the data they touch.

[35:59] AI can chain lower-grade vulnerabilities, changing how teams may need to prioritize remediation.

[37:22] The possible convergence of AI and quantum computing.

[38:25] Why society is discussing the consequences of AI earlier than past technological revolutions.

[39:31] AI in legal work raises questions about authorization, access, liability, hallucinations, and verification.

[40:46] James reframes imposter syndrome as a healthy companion to challenge and growth.

[42:41] Credibility comes from quiet, boring follow-through and consistently telling the truth.

[43:13] Unglamorous work creates the experience leaders draw on when their moment arrives.

KEY TAKEAWAYS

Lead executive conversations with risk reduced and value created, not only activity metrics and technical detail.
Tie technology initiatives to business objectives, lower management burden, ROI, competitive advantage, and consequences.
Explain security as a chain from exposed risk to incident, breach, downtime, notification, and reputational damage.
EP439- Stop Reporting Activity, Report Risk Reduced w/James Dunlap
Community Invite

Private roundtable discussion. IT leaders only. No vendors. No salespeople.

🛡️ 🤖
Upcoming Topic: Cybersecurity Ops + AI
What's working, what's noise, and what to prioritize now.
Who's in
✓ CIOs, CTOs, VPs of IT
✓ IT Directors
✓ Security leaders
Who's not
✗ Vendors
✗ Salespeople
✗ Pitch decks
Takeaways get published as a co-authored piece: real insights from real leaders, with attribution.
Limited seats. Peer discussion.
No pitch.

TRANSCRIPT

439-James Dunlap
Host: Phil Howard
Guest: James Dunlap
________________

Phil Howard: All right. Welcome everyone back. We've got James Dunlop on You've
Been Heard and you work at a law firm. So why don't you just give me kind of the
general overview title, what you're in charge of and we'll go from there.

James Dunlap: Yeah. Great. Great to be here. Phil, really appreciate the
opportunity. Yes. Spilman and Thomas Battle is a premier Mid-Atlantic law firm.
really corporate law, energy law. And, my first role in the legal vertical. So I
come from healthcare banking, fintech, and, really was, interested in the
challenge. Certainly in the legal space, it's a lot like coming from healthcare.
I've worked a lot of private practices where it's a surgeon, a lot of surgeons.
So time is life or death from that perspective. and, from the legal standpoint,
Tom is certainly revenue, you bill every six minutes. So system down any
interruption, is, yeah, it's really impactful, to the bottom line. So, my role
is your typical CIO role. I oversee an internal team, diversity team of security
help desk, enterprise systems, cloud management, and then of course the managed
service provider on top of that for any, data center and any subject matter
expert, level three, four stuff we get into with projects.

Phil Howard: So if you had to pick your favorite area of it, whether it be
networking, data center, security, software development, which would be your
favorite?

James Dunlap: Yeah. Security is really where I dug deep. I'm not a nuts and
bolts guy. I come from a completely separate background. it is something I fell
into. So really, I made a decision amidst it, to take a deeper dive. once I got
a broad exposure, it was security for me, and particularly GRC. So that's really
where I dig deep and that's where my strength lies.

Phil Howard: So now I know that there's a lot of people out there that may agree
or not agree with this statement. that's one hundred percent of everybody. We've
got doctors and we've got lawyers. Which one is harder to convince to spend
money on security.

James Dunlap: Oh, wow.

Phil Howard: Because the theme my whole week was kind of offline conversations.
Okay. And these offline conversations that I'm having with other CTOs and CIOs
are goes something like this. Phil, they don't know what they need to know in
order to make a decision that's in the best interest of the company. They just
don't know. And we need to somehow make them know, the importance of X, Y, Z
right now from a security perspective. You can probably, always be a little bit
more secure. And I would say from the healthcare standpoint, you're probably
familiar with this, that, sixty four percent of all healthcare organizations got
hacked in twenty twenty five or some sort of ransomware attack. So they're
really bad. Okay. You would think that that would be enough to convince the
board of doctors to care, but it might not just be something that they see. It
might just be like, yeah, we throw some money at it or to fix the problem when
it comes around. It's what is it in the legal aspect? Or is it? I would think it
might be easier to convince lawyers that you need to because you might get sued.

James Dunlap: For me, it was definitely easier with attorneys, but I think that
goes back to what you mentioned. Your peer conversations are early on. The
challenge was me. It was communicating with the C-suite. It was speaking their
language. And that's our responsibility. We can whoa. The challenges of they
should know this. It's hard to convince them of X, y. Well, that's where our
specialty lies of, fifty percent of our responsibility is really communicating
in the language of the C-suite. And that falls on us. We can't just lament the
fact that there's a gap there and they'll never understand. Well, then you need
to really quantify what you're doing and approach it, like just with problems,
but with solutions, of course. And to be able to speak their language because
they don't want an impact on their business, they certainly don't want
reputation, impact. certainly not doctors or attorneys. Yeah. So it's becoming
of us or to make sure that communication is there. That's our responsibility.
That's certainly a lot easier for me over time. you get more comfortable, you
start to understand that your job is to align their business needs, with
technology. And it's not just a cost department. this really drives your
competitive advantage in your field. And once you identify that and you're able
to use that as a selling point, really the sky's the limit on what you can move
in my experience. but it's core to us to communicate that.

Phil Howard: I mean, I think you hit the nail on the head, a communication one
you said selling. The other thing you said in a language that they understand
that means something to them. They don't really care, whatever Arctic wolf or
which, EDR what that even means. or, Sentinel one and this and that, they just
care that you're not going to bring the organization to a screeching halt and
leave them with egg on their face. so you have a very, non-traditional or
probably is traditional. What I'm finding recently is that non-traditional is
the traditional is the norm. Most IT leaders started out doing something else
because you don't go to school to take it leadership as a course. maybe nowadays
you do. But even in earlier conversations today it was. You really don't go to
school to become a CISO and learn anything and come into an environment and know
anything about what you're doing. you've really got to kind of learn it the hard
way and have hands on experience. How did you get to where you are? What was
your first computer? What happened? what was it?

James Dunlap: Yeah, yeah. First computer was my older brother's, Commodore one
hundred twenty eight. so that that takes you back, what, just one generation
after?

Phil Howard: It was a hand-me-down. So? So it was a hand-me-down.

James Dunlap: It was a hand-me-down. It was a stand over shoulder and watch,
hours of programming to get something moved from the left to the right side of
the screen. and then it was a hand-me-down. It was the floppy drives, the whole
experience. So, as you mentioned, and I've certainly listened to, past guests on
your show, mine was certainly the traditional windy road to this I was
introduced to it, certainly in the professional space, like a drug. There was a
need and, started off as an undergrad in fine art photography. Really get to
exercise the right and left side of my brain, which is come in handy more times
than I can tell you. certainly to be able to use that creative background, but.
Like all art majors, we discover we want insurance and, regular pay. So we got,
started work, in a retina specialist, which is really tertiary eye care, retina
surgeons. And so, I was doing, medical imaging for them. And this was right
around the digital analog to digital change and literally moving from the
darkroom to digital cameras. and there at that time, we're talking, early two
thousand. You can imagine trying to push images across Mpls, local area network
storage, all the how expensive storage.

Phil Howard: Anything it was just and.

James Dunlap: All that. It was a nightmare.

Phil Howard: Let's just talk about how expensive storage was back then and how
long it did take to something. I mean, it's a simple math problem. The first
Cisco startup company that I started at, I think it was two hundred and fifty
megs of off site backup was four hundred and fifty dollars a month.

James Dunlap: That was our experience. I mean, having, being able to be in
office and pull up images from office Y, early two thousand, this was just a
Mount Everest to conquer. So yeah, the need was there. It was self-evident. They
were just blowing a fortune on MSP solutions. Certainly Cisco Solutions, we can
imagine the investment there. Synology storage, all that stuff that comes in
nice and all that that comes in with this. So certainly was an opportunity that
was right in front of me and I pivoted to quickly, got plugged in with the, it
side of imaging needs and quickly start enrolled and gain my, miss and
information systems administration. and really, it just went from there, and
started to climb vertical, really doubled down on the right certifications. And
that's really where I fell in love with security.

Phil Howard: Then what was that? What happened?

James Dunlap: Yeah. That's my second stint as a CIO, another, healthcare firm.
And they were being acquired like all private practices by the regional
healthcare conglomerate, and really got to see the gap in even from mid practice
to a healthcare system. The dreadful gap that, as you mentioned earlier, that
lies with information security, cyber security.

Phil Howard: I don't believe the statistics. I still I really don't believe
them. I think it's a conspiracy theory to sell more security services, but I
know it's not it's a twenty twenty five, like something like sixty seven percent
of all healthcare organizations experienced a ransomware attack of some sort.

James Dunlap: it's what social engineering has done to that space. and the fact
that you saw so many people attesting to compliance, but not holding themselves
to it, that's really where I knew that, all this and the other trends outside of
that industry that security was where I wanted to go deep and not just have wide
exposure, as I mentioned, not a nuts and bolts guy. I'm the first to run and get
a semi for network, for those type of things, certain cloud architecture, but
security is really where I wanted to hang my hat. So I wanted to help the
industry. I wanted to help healthcare bridge that gap. shortly after that, I
moved to banking and fintech. And of course, that industry has been under attack
since, we first started to turn ports up. So they've had the historical need and
they were so far advanced.

Phil Howard: Yeah. I mean, they're stealing so much money from us anyways,

James Dunlap: They certainly can. What does JP Morgan have? it was, one point
whatever in the millions daily of incidents or, potential breach. So their
threat vectors, out the ceiling and banking, they've been doing it for way
longer. So really, I took the risk at that point to step down as a CIO in
healthcare and work directly under a CISO in banking, no one really ever was
like, why are you taking this chance? really some people understood it. for me,
it was a great, it was a risk that was well worth the reward. really was a
humbling experience, worked under phenomenal CISO, really learned and the
foundations of GRC and got really rooted in third party risk management, all
compliance risk assessments, all your, predominant in that space. So, that was a
great move that really propelled me forward. Then, I was able to take on a role
again as a CIO, as a much stronger position than I was before.

Phil Howard: I think that's just in general, good life advice is sometimes you
have to take a step back to take two steps forward.

James Dunlap: And agreed.

Phil Howard: I have a lot of colleagues that were like, what do you mean you're
going to do this podcast thing and you're only going to do this and that. And
because I come from a very aggressive, industry, which is ISP and telecom. And,
I look at it as kind of like the good old boys network, very, very aggressive
sales, and to me, I saw so many problems with kind of the general landscape. I'm
not saying that like the eighty over twenty rule, like eighty percent of the
providers and people out there selling and consulting are pretty much mediocre
to very self-serving. And the other twenty percent, you've got good quality
people that know that, and then you've got the top five percent. And we really
wanted to take a step back and really serve the people that are using all of
these services A K, A, U and the IT leader. And what we found after talking with
hundreds of you is that many of you started out as the art major. And you grew
to a certain level. And then yours is interesting as you took a step back and
really, really kind of, I mean, it's a great story. And then we find ourselves
two decades later sitting at the executive round table. And we've had endless
patches and firewall upgrades, and people are going to hear this at the
beginning of the intro of the show anyways. and, silos that we've upgraded and,
A S four hundred seconds that are still running the ERP system, what other
things can we have? ransomware attacks avoided or cleaned up or recovered from
whatever it is paid for. Even ransom paid for. A lot of times I've heard many
people just said, yeah, we paid it. So you've got all of that and now you're
you're sitting at the executive roundtable. You've got a seat there because you
have to, because there's not anything that doesn't get done in any company
without technology touching it. But still to this day, only seven percent of the
people actually sitting in that seat are really authentically understood and
heard. And it's not an us versus them. it really is that communication piece
that you said at the beginning, but you said selling and you also said really
being able to reframe something in the language that they understand, not the we
evaluated all these EDR and we did this and that, and this is what we came up
with. And it's really important that we do this. And they're kind of like, okay,
how do you frame that? What's the best way to sell security to the C-suite in
your opinion? And let's pick the hard ones, the doctors. You've got.

James Dunlap: Yeah.

Phil Howard: You've got twenty partners in a multi-location practice, and you've
got to tell them they got to spend money on this.

James Dunlap: Right? For me, when I say you have to speak their language, a lot
of times C-suite thinks in quarters and outcomes. I t often communicates and
projects and jargon, as you mentioned, you can walk in there and talk about,
risk mitigated. You can talk about vulnerabilities managed, but, the disconnect,
is not necessarily a capability. It's the translation. I always feel like, i.t
leaders who, really close the gaps, stop reporting on activity and start
reporting on risk reduced and value created. And I think that's the terms really
that boards really care about, in my opinion. And that's really what I found
when I started to work in the banking space is how.

Phil Howard: Do you figure that out?

James Dunlap: Really, that was the, beautiful, lessons learned from taking a
step back, working my way into a higher, industry that has dealt with the risk,
institutionally far longer is I was able to watch, peers at a higher level. The
system I mentioned, I worked with the CIO, was really able to watch them and how
our meetings translated into board meetings. So you're there to talk to
technical jargons during our staff meetings, and we're one on ones. But then you
walk. You watch and you learn how that's translation translated into board talk.
that really gave me, was really put the cherry on the cake for me that, topped
off what I knew, but it exposed what I was lacking.

Phil Howard: you said, talking about value created. And one other thing.

James Dunlap: the risk reduce. Yeah. It's not our projects, our jargon that are
that we use. But really it's in the close the gap on reporting activity and
start reporting really what risk is reduced and the value created. you really
have to talk in consequences. it's that once you talk for me, my experience is
once you really explain what reputational harm is, and they're very aware of
this, obviously they've watched it in their industry. But when you put it in
terms of how it's going to impact your clients, how it's going to impact,
certainly the business that you've created in the years and decades of hard work
that you've put into it could be completely brought to its knees by an untrained
user clicking on a link that that was a clear red flag. social engineering
layered with AI now is so frightening. obviously there's great blue team tools
that we're able to use. It's a double edged sword. But the fact that, mythos was
able to crack into just an article a few days ago was able to crack really all
NSA security by chaining together low risk vulnerabilities. and that's behind
fable, which just came out. So, I think the progression that AI has brought to
the threat, once you start to communicate that, you have to be far more
proactive. It's not just about meeting a standard that you've picked, a
compliance standard that maybe is you're hold accountable to in your industry,
or one that you've just picked that best suited you missed ISO, whatever it may
be. It's not just checking those boxes. it's being as proactive as you can
layer, always layering that security. But when you can communicate it into
revenue loss and what is incalculable, reputational loss is where I've always
got the ears start to perk and the most traction.

Phil Howard: So let's go through two things. Well, first of all, what not to
talk about. I think what not to talk about would be a great list to go through.
Don't talk about projects. Don't talk about your KPIs on the activity and the
numbers of tickets that you have closed, because really all you're doing is
saying, well, I would hope so. If in other words, if you're reporting on
something that your executive team is going to look at you and say, well, I
would hope you're doing that, that's your job, then that to me would be a red
flag. Don't, talk about stuff that you should be doing. That's part of your job.
Let's talk about a value. When you talk about value created, what does that mean
to you? Are we talking dollars and cents or what are we talking about? Value
created? How are we going to report on value created?

James Dunlap: Yeah. Oftentimes for me, that's a fusion of, hey, this will lead
to value added because it's going to minimize our spend on these. It's going to
consolidate our management burden into one plane. that's kind of for me, the low
hanging fruit there. But once you start to understand that your job is to align
your IT infrastructure to the business objectives that's laid out before you.
that's when you can really start to speak to the C level language. and that's
what they, that's what they're wanting to hear. You hit the nail on the head
when it. That is what you're doing. The fact that you've taken care of high
vulnerabilities or you've mitigated, and documented your risk assessments
correctly, you've handled these incident responses correctly. That is part of
the job you should be doing. those are some, appendix in the back of the report
that you can point to, but that's nothing that you should be verbalizing when
you have the time and, of the C-suite level. So, really you need to start,
giving them the understanding of, here's the ROI over quarters in years, here's
how we're going to outpace our competitors. here's what you can talk about when
you're at your conference. And this is what separates you from others in your
industries. to me, that's the value added part that, always get the most
traction with you. Align those with the projects that you know you need. and
then it's pretty much downhill from there in my experience.

Phil Howard: one of the things that we found, again, from analyzing, it's really
thousands, but as far as shows that have been recorded, I guess we can, say four
hundred somewhat shows, but I've spoken with thousands of IT leaders over the
decades. It's not, say, in the boardroom. It's not the presentation that you
did. It's not the check box. But It's, what are people talking about after the
meeting when you're not there? And it doesn't matter that your name's attached
to it or not. But if they're talking about, some great thing that you did at the
next expo, whether your name's attached to or not, subconsciously they know your
name's attached to it and they love their IT department. I definitely brag about
our AI guy, Greg the Frenchman, because he's way ahead. So value we created like
really start feeding people things that are like the billboards in the meeting.
risk reduced, how do you communicate reputational harm in a way that matters to
people?

James Dunlap: Yeah. Really, I think that's just, you start to describe the chain
reaction. The. Okay. here's where the here's how easy the incident can start.
and that's unfortunately from twenty twenty five to twenty twenty six is,
changes by the day. But here's how easy it can start. Here's where our risk
assessment says that we're at critical or high vulnerability. Mhm. Here's the
roadmap that we need, what we need in place to mitigate that. Are you going to
give me the tools or not? Because if not, here's how quickly this becomes an
incident to a breach. And here's how catastrophic a breach can be. It's not
always as simple as just turning on your cyber security insurance, and dealing
with the incident. It is obviously the financial impact, immediate impact that
you have from loss of revenue, the exposure time, turning everything back up.
But when you have to start sending those letters out, and when you're a law firm
and you have to start sending those breach notifications out of sensitive data
to clients that are fortune five hundred companies, then that's when
reputational harm really starts to get everyone's attention. And that's where
the institution that you've spent decades building, can really be shuttered
quickly because it's a small community. When you talk about being outside
counsel to large organizations, and that's for me always the clearest picture.
There's the immediate cost. And then there's the poison that's going to take
over your organization. And that's the reputational harm. It's the slow burn
that's going to kill your clients, kill your contracts and all your prospective
clients. So in a big part of law is, acquisitions and, having new talent come
into your firm, acquiring top talent from other firms, folding in other firms.
And so once you have that stink, a stigma placed on you, then your lifeline of
new talent and, established talent with large portfolios to come over dies right
there. So when you start to speak that language and you can tie that to a direct
risk that you've exposed, the rest, as I've said a couple of times now really
starts to become downhill for me. and it's our obligation to communicate that
because that really gives the whole picture to the C-suite. You can speak cost
savings, exposure time, all that is should be quantified as much as you can. But
when we're talking about information security, for me, it's reputational harm is
the scariest, outcome for me.

Phil Howard: I think that you painted a very, very beautiful, ugly picture. at
least in the legal space. I think that I would find that harder in healthcare
because really ultimately, unfortunately, humans are very, very selfish and it
comes down to do they care? Does it affect them immediately? Is it affecting,
and from that standpoint, from a legal standpoint, yeah, it affects my personal
relationship, especially in a firm when you have a group of doctors in
healthcare and you've got large hospitals and you've got large organizations,
it's hard to kind of like to place blame or it would be easier for, I would say
like a doctor or an MD to be like, hey, look, I'm just doing my job. I'm just
saving lives. Okay. Yeah.

James Dunlap: I'm behind this institution.

Phil Howard: Right?

James Dunlap: You know what I mean? You can hide behind that a bit. Agreed.

Phil Howard: And yet they all have to be together in a room to make decisions. A
lot of times when they're part of this larger practice. And I just know because
I come from a family full of doctors and I know how practices work, and I know
kind of modern day the larger hospital businesses as well. But I've seen as of
recently some very, very smart doctors forming their own groups and investing in
their own surgery centers and things like that. And you'll see these twenty five
doctors have ownership in this surgery center, and you'll and they all have the
same miserable IT problems. They tried to migrate to epic. And you've got a
bunch of nurses and cows, what do we call those? Some computer on wheels or
whatever, sitting around with the cords unplugged and you have this mess.
Really? I find that industry to be really difficult for IT leadership to break
that boundary. and it might be because healthcare is a very, very hierarchical,
almost a feudal type of pecking order of decisions that get made with very, very
smartest people in the room with some very, very absolutely.

James Dunlap: You're dealing doctors, lawyers, you're dealing with our brightest
people in the community. Certainly that's the reputation they carry. Some don't
live up to it. A lot of them do. But yes, there's the complexity with healthcare
really stands out because here's a three thousand dollars or sorry, three
million dollar imaging machine that you've invested in that. Now the operating
system is out of date and no longer patchable, but the system works as intended.
It could work another fifteen years this way, but now you're stuck with an
unpatched operating system that the vendor may not be offering an upgrade to
because they can talk you into the next generation of imaging system. so you're
stuck with so many legacy systems in healthcare and trying to tie those all
together, keep those secure, keep the network segmented as best you can. and
those systems away from other systems. there's a really unique challenge there.
And as you mentioned, you start to fold in the fact that you can start to maybe
hide behind an institution if you're not a private practice. But for me, I
would, correlate that medical malpractice at the physician level is akin to,
governance malpractice at a legal level or at your, fintech or banking level. I
would say those things, that would really get the attention of the physician is,
not adhering to best practices, certainly being out of compliance with your
contracts, not mitigate, not identifying your risk, and giving it the proper
risk treatment, is akin to a malpractice in its own way. And thankfully, there's
been such a crackdown over the last couple of years, especially at the federal
level, where now there's really some steep and severe penalties and there's been
some large cases of that come about, as you mentioned, for large private
practices that have their own surgical centers, they're not even doing their
annual HIPAA risk assessment. So there's been some really stiff penalties handed
down. And that's really have gotten the attention in the last that I've seen
talking to my peers that are still in the industry over the last three to five
years, that's helped push that along.

Phil Howard: Just another statistic. I think like the HIPAA penalties and, from
twenty twenty five just to twenty twenty six are up three hundred and like it's
over three hundred percent.

James Dunlap: Yes, but the directors has been very vocal about the push that
we're really coming after this. And if you can't present an annual assessment,
then the penalties are going to be severe.

Phil Howard: here's an idea. Let's be like a really, really secure, law firm
that can brag about how secure they are and then go after the health care
industry for all their violations.

James Dunlap: That's right. So we know how to hold you standard because we're
keeping that standard here at our institution. Yes. absolutely. It's
frightening, when you're dealing with sensitive records like that

Phil Howard: Do you have like a hero story where you came in and everything was
absolutely terrible. you got ransomware attacks, something really, really bad.
It doesn't have to be that. It could be anything where you came in and it was
like, oh if it wasn't here, we'd be done. we would be in that metaphorical spot
where we were brought to our knees and we'd be sending out letters. Do you have
any stories like that that you have come in and saved the day from?

James Dunlap: one that pops to mind? And it's not necessarily information
security driven as much as it was change adoption. And one of the most painful
change adoptions you I've experienced in most of my space of experience is the
implementation of the electronic medical health records. going from the paper
chart, as you mentioned, the ethics, the cerner's out there or at the medium,
the small business level, which is a giant space, but that's really where I
lived out a large hero moment and really went from imposter syndrome to I can do
this was the complicated and challenging transition from decades of paper charts
into an EHR system. And really, that went from concept selecting vendors,
comparison charts. this was really all laid in my hands. And I wasn't even a CIO
yet. Really. That was just, department director, say, head of help desk, so to
speak. So, big problem. Lead at my lap. We need to move into this space and we
need to do it within a year. and really, I had great executive buy in, but you
can imagine dealing with, as I mentioned, tertiary level surgeons, it was quite
a challenge to convince them that what they've been doing has worked for them
for decades needs to be changed. And why can't this be like the way I use it?
And why can't I just write this here? Why do I have to change my practice around
a piece of software? So, that really was, my first introduction of, talking the
C-suite cost savings, exposure time, making the compromises, finding the right
vendor, holding them accountable to their SLAs, holding myself accountable to
communication outcomes, dates. And, we went practice wide in the same day. and
this was a medium sized level practice for West Virginia, seven surgeons, seven
locations across the state. We went fully live over, three days. and it was
amazing. Went from charts to iPads, and charting. The scribes and texts were
happy. The nurses were happy. the doctors were accepting and growing. so that
was really my first really full hero moment. we picked the right platform. We
picked the right implementation team. And, it was really where, as I mentioned,
it really went from me being, that imposter syndrome to believing in myself and
knowing I belonged at the leadership table.

Phil Howard: Man, you basically had all of the top three major problems that
every IT leader ever has expressed. It might or the top four. So one is training
end users, one of the top four. Mhm. Two taking decision direction in the top
four. three upgrading antiquated silos. Right. And I think the fourth one is
like selling to the C-suite or convincing the C-suite, I mean, so like, you
literally had all of the major problems in one project because everyone's got to
learn how to use the new EMR, right? you've got to change from the old way. So
you've got a bunch of end users that you've got to train people sitting at the
front desk that were used to sticking colored stickers on manila envelopes and
filing them away. and Sally and Jane in the back. I'm not trying to be
stereotypical here, but Sally and Jane in the back that are taking the doctor's
old tapes and, typing them up on a typewriter or whatever it was. I mean, I
remember that growing up as a kid. Paper files, Doctors recording into a device
and like people literally typing up it into a file. That's where we've come from
in the last thirty years. It's pretty wild.

James Dunlap: It is. Those are always the most substantial projects and they
leave an indelible mark on your professional life.

Phil Howard: All right. Final two questions. Eighteen months from now. What are
people going to be talking about. that is going to surprise everyone.

James Dunlap: I think for me, we've started that conversation now a bit. I think
it's only going to grow and that's probably governance of AI agents. And the
data they touch for me is, an alarming topic. I think, right now, most leaders
are kind of excited about what the tools can do. And almost nobody's really
asking who authorized the agent? What can it access? Where liability sits when
it acts on its own? and I think, the capability conversation there is loud and,
I think the accountability conversation has barely started for that, but it's,
coming fast.

Phil Howard: I think we have to do pen testing. And we've got so many places
that people can attack us, right? We don't know which one they're going to
choose, right? Where it's kind of like the reverse side. Like, it's easy for the
hacker. He just has to find one way where he's like, the CISO has to know all of
the ways. So maybe through agents and, agentic AI and stuff, we can have, better
outbound prevention and honeypots and attack vectors or something kind of from
the reverse standpoint, I don't know.

James Dunlap: I feel like there should be this, understanding that once you've
hit my honeypot, all bets are off. I can come after you. and so, if I'm going to
sit that out there and you're going to breach it, I feel like almost we should
be obligated or at least have the legal, leeway to start to go on the offensive
there. But, I dream, of course, that you hit the nail on the head. really is, we
have to be prepared for everything, and we're not aware of a lot of it,
unfortunately. especially when it comes to ransomware as a service, all this,
social engineering as a service, all this being. You don't have to be. You can
be the script kiddie. You can go out there and buy the service. and now with AI
being able to train low to medium grade vulnerabilities together for an attack,
that's really changed for me. what I see no longer can you just say, I'm going
to hit the critical and high vulnerabilities and maybe cherry pick some of the
mediums. I think we're moving into a situation where we're going to have to
really drill down into the medium and lows. and hopefully, AI is going to be our
big solution there.

Phil Howard: Maybe with if quantum computing is real, maybe with that mixed with
AI and, the thousands of drones everywhere and breaking the blockchain somehow,
I don't know, maybe like, we can send like, a swarm of drones to the hacker's
house within, minutes of something like that. Yeah.

James Dunlap: you and I know there's.

James Dunlap: Another eighteen months. you don't hear a lot of conversation,
feel about the convergence of AI in quantum computing. You almost hear them as
they're in their own silos. But when those two converge, I don't know what kind
of world we live in. Then, I.

Phil Howard: Think it's going to be. I'm kind of like. I heard Alex Hormozi say
something the other day about it, and he has kind of like a positive outlook on
it. He was like, look, for all the bad things that can happen with AI, there's
always going to be the outliers, right? He's just, like use it. but he was
saying almost like, I kind of, maybe I took it, maybe I'm understanding what he
said wrong, but this is my thought or my idea on it. We might get so advanced as
a human species. not Terminator two, from a positive standpoint, we make it so
advanced that money really isn't a thing anymore.

James Dunlap: Mhm.

Phil Howard: Meaning it's like things have become so streamlined from crops and
food and like just everything it's going to be just like, well, what do we do
now? It could be.

James Dunlap: Aware of this change more than pre-industrial revolution, more
than pre-internet. Were so aware of what this change is coming. it was hard for
us pre-internet, pre assembly line to know how revolutionary these things were
going to be. it was certainly under thought and perhaps under communicated. I've
never done a lot of research there in that, But I think that we're having so
much conversation on the front end of this technology, more than we've had with
any revolutionary technology before, that it really lends itself to this. Is
this Armageddon or is this utopia? and I really try to lean on the utopia side,
but.

Phil Howard: it might be.

James Dunlap: It may be a little Armageddon to get to Utopia.

Phil Howard: Yes, exactly. But the boundary is going to be power with all this
stuff, the boundaries, power. when you mentioned tokens and stuff, we can't just
have people doing stupid stuff. There's going to have to be some kind of again,
serious, streamlining of how we use these tools because otherwise it's going to
be a lot of wasted tokens.

James Dunlap: Yeah. The prediction is really asking who authorized these agents?
What can they access? Where is the liability sits? certainly when they start
acting on their own or, start to in. A big concern in law was the injection of
hallucinations, within AI, we've got a strong AI deployment with some choice
vendors. but the ramifications of AI and the legal industry are just, staggering
right now where you have, both parties submitting, unverified, certainly, cases,
there's a case I just read where the counsel and opposing counsel both had wrong
case sources cited. and they both were found They were both disbarred. I mean,
the judges are not putting up with this. So, thankfully, we have a great
oversight. certainly this is not going to get rid of the paralegals. Everything
still has to be double checked and verified, but, it speeds up production. yes.
But yes, it introduces a whole new level of risk.

Phil Howard: yeah. That's crazy. And last question. If you could go back in time
and give a piece of advice to yourself twenty, thirty years ago, whenever you
got started, what would that piece of advice be?

James Dunlap: I think, for me, it really was. And this gets tossed around a lot,
but imposter syndrome is healthy. you should feel that way. That's part of
growth. You should be always challenging yourself and putting yourself in
uncomfortable situations. If you don't want to, that's fine. If you want to stay
where you're at and you're happy, more power to you. But anyone that's reached
the level of your audience at a CIO, CSO, we've invested so much time in
education certifications into this. we're people that push ourselves, and love
to test ourselves and we love growth. So being riding that edge of imposter
syndrome is healthy. It isn't that you don't belong at the table. you've earned
your way to that table. But it's a healthy dose of of being, of knowing that
you're where you should be. You should feel challenged. You should feel humble
amongst your peers. there's a lot to learn from them. and you're certainly not
the smartest person at the table if you find out that you are, That's great.
That's a rare, accomplishment for me at least. But, stay humble. I always felt
that I did, but, for me, it was so crippling at first, climbing the ladder and
dealing with imposter syndrome, not coming from it, not growing up, ripping
apart computers, segmenting networks, coming from fine art. but I've learned
over the years that it's healthy. It comes with the role, it comes with being
challenged and growth. And that's definitely something I'd love to communicate
to myself in the twenties. It's healthy.

Phil Howard: Yeah. You got to do the work. You got to put in the the at bats.
You've got to kind of, yeah, fail forward. all those sayings. I'm a big fan of,
get comfortable being uncomfortable and every level of success is surrounded by
pain and tribulations and hard work. There is no shortcut to that.

James Dunlap: There isn't. Your credibility is built on quiet, boring follow
through. Yeah, it really is.

James Dunlap: your ability.

Phil Howard: To consistently do. Yeah. Like yes. Yeah.

James Dunlap: The heroic incident response. It's not that a lot of people can
look good in a crisis, but, it's the leaders who actually trust, are the ones
really for me that do the unglamorous work consistently, tell the truth.

Phil Howard: Showing up every day?

James Dunlap: Yes.

Phil Howard: Training, doing the same thing over and over again, like day after
day. Yeah.

James Dunlap: and when the time comes, like, just like we mentioned and talked
about the, the HR project where I got to fill the hero, your time will come
where you can draw on that experience and can shine.

Phil Howard: Mr. Dunlap, You've Been Heard.

James Dunlap: Yeah, this was great. Really appreciate it.

439-James Dunlap
Host: Phil Howard
Guest: James Dunlap
________________

Phil Howard: All right. Welcome everyone back. We've got James Dunlop on You've
Been Heard and you work at a law firm. So why don't you just give me kind of the
general overview title, what you're in charge of and we'll go from there.

James Dunlap: Yeah. Great. Great to be here. Phil, really appreciate the
opportunity. Yes. Spilman and Thomas Battle is a premier Mid-Atlantic law firm.
really corporate law, energy law. And, my first role in the legal vertical. So I
come from healthcare banking, fintech, and, really was, interested in the
challenge. Certainly in the legal space, it's a lot like coming from healthcare.
I've worked a lot of private practices where it's a surgeon, a lot of surgeons.
So time is life or death from that perspective. and, from the legal standpoint,
Tom is certainly revenue, you bill every six minutes. So system down any
interruption, is, yeah, it's really impactful, to the bottom line. So, my role
is your typical CIO role. I oversee an internal team, diversity team of security
help desk, enterprise systems, cloud management, and then of course the managed
service provider on top of that for any, data center and any subject matter
expert, level three, four stuff we get into with projects.

logo

You’ve Been Heard

You’ve Been Heard is where IT leaders stop being sidelined and start being amplified. We’re the triple-threat platform: podcast, community and vendor-neutral advisory that elevates your voice, your value, and your influence because when IT leaders rise, so does everything else.

© 2026 You've Been Heard. All rights reserved.