Gary Chan is a cybersecurity executive and professional mentalist whose career has spanned more than two decades across anti-identity fraud, information security, and cybersecurity leadership.
Today, Chan serves as System Vice President and CISO at SSM Health, a multi-state healthcare system. He is a graduate of MIT with a degree in Electrical Engineering and Computer Science, and holds CISSP, ISSMP, and Certified Fraud Examiner credentials.
Chan is also the creator of Security Mentalism, which is an approach that brings together cybersecurity education and stage mentalism to teach audiences how social engineering, phishing, and other human-centered attacks actually work. He has also previously mentored cybersecurity startups at SixThirty CYBER and served as president of the FBI St. Louis Citizens Academy Alumni Association.
We spoke to Chan as part of our ongoing series interviewing cybersecurity professionals to bring you their unique insights into cybersecurity today, the challenges they are facing, and the realities of what it takes to defend complex global environments.
To kick things off, could you tell us a bit about yourself and your journey into cybersecurity?
I’m Gary S. Chan, The Security Mentalist, a Chief Information Security Officer (CISO), and a person who has always been curious about how people and systems work.
As a kid, I liked taking things apart to see what made them work. That sometimes meant breaking things that probably should not have been broken. I like understanding how systems work and finding ways to make them work even better.
That led me to computers, engineering, and eventually cybersecurity. I graduated from MIT with a degree in Electrical Engineering and Computer Science. That gave me a strong technical foundation from which to build. As my career took me through anti-identity fraud, information security, and cybersecurity leadership, I learned that technology is only part of the story. Some of the hardest security problems are human problems. Computers tend to be predictable, but people are not.
An attacker does not need a technical vulnerability if they can get someone to take an action that benefits the attacker, like sharing sensitive information, approving a fraudulent payment, or skipping a verification step. That is the reality behind social engineering, phishing, business email compromise, identity fraud, and many other cyber-attacks. My training in mediation, negotiation, and interrogation taught me to listen closely, ask better questions, build rapport, and understand different perspectives. Those skills matter every day for a CISO.
Much of my job involves translating cyber risk into business impact, helping leaders to understand the trade-offs, making the case for security investments, and finding practical solutions that improve security without unnecessarily getting in the way of the business.
Today, I serve as System Vice President and Chief Information Security Officer at SSM Health. I have also been interested in magic and mentalism for most of my life. Eventually, I realized that mentalism and cybersecurity share a lot of the same raw material: attention, perception, trust, influence, and the decisions people make when they are rushed or distracted. That connection led me to create Security Mentalism, my approach to using mentalism and psychology to make cybersecurity education more engaging, memorable, and practical.
For readers who aren’t familiar with Security Mentalism, could you tell us what it is and what you’re doing with it?
Security Mentalism is a practice that I created that combines cybersecurity, mentalism, psychology, and storytelling to help people understand how human behavior affects security.
Most people think of cybersecurity as a technical discipline, and technology absolutely matters. But many successful attacks do not require technical know-how; they begin with an attacker influencing a person. It might be a phishing email, a fake invoice, an urgent text message, a voice-cloned executive, a deepfake video call, or a convincing request to reset a password or share sensitive information.
That is why the human side of security matters. Attackers know how to use things like trust, urgency, fear, authority, curiosity, distraction, and familiarity to influence decisions. Security Mentalism lets me demonstrate those techniques in a fun, safe environment, and then connect the experience to real cybersecurity threats.
Rather than simply telling people to be careful about social engineering, I show them how attention, perception, and influence can affect what they notice, what they believe, and how they make decisions.
The goal is not to trick or embarrass anyone. It is to make cybersecurity awareness memorable and cause people to think more deeply. If someone has experienced how easily an intelligent person who is paying attention can be influenced, they may be more likely to pause before acting on an unusual request, verify a payment instruction, question a suspicious message, or use a trusted channel to confirm someone’s identity.
I use the same principles in my work as a CISO. Cybersecurity leaders must influence without relying solely on authority. We need to explain risk in terms that make sense to the business, make the case for security investments, and help leaders work through trade-offs involving cost, speed, usability, resilience, and risk.
Storytelling and an understanding of how people make decisions help me make those conversations clearer and more relevant. Whether I am discussing a security awareness initiative, advocating for budget, explaining an emerging threat, or helping an executive team work through a difficult risk decision, the goal is the same: to help people understand the situation well enough to make a sound decision. That does not mean manipulating people into a particular answer; it means respecting their perspective, understanding what they need, and communicating security in a way that is clear, credible, and actionable.
I use Security Mentalism in keynote presentations, security awareness programs, and other corporate events. I work with event organizers and planners, marketing and sales teams, and security awareness teams. Audiences can include executives, professionals, customers, and employees. I always tailor the experience to the audience to maximize impact.
Security Mentalism is ultimately about recognizing that the most sophisticated attack is not always the one that breaks the technology. Sometimes it is the one that understands people well enough to persuade them to open the door.
In a previous podcast appearance, you talked about how sales and performance skills have made you a better CISO — particularly when it comes to communicating risk and aligning security with the business. Could you expand on that?
As a CISO, you are constantly selling.
You are selling the idea that your team is doing a good job and that the organization should give you more money to keep doing it. You are selling the idea that a longer password is more valuable than the small convenience and time savings of a shorter password. You are selling a security control that might make a process take a little longer, but could prevent a much bigger problem later.
Nobody really wants to spend more money on cybersecurity. Nobody wants one more thing to do. People have deadlines. They have customers. They have budgets. They are trying to get their work done.
So, I can’t just walk into a meeting and say, “Here are the vulnerabilities. Give me money.” I have to understand what the other person is trying to accomplish, and explain why the security issue matters to them. A CFO may care about financial exposure. An operational leader may care about whether a control will slow down production. Frontline staff may care about the customer experience.
That is where sales skills help. You must listen first. You must understand what people care about, what problems they are trying to solve, and what trade-offs they are already making. Then you must explain the security issue in terms they understand and agree with.
Performance matters, too. Whether I am speaking to a board, a leadership team, or a large employee audience, I have to pay attention to the room. Are people following me? Are they skeptical? Did I give them too much detail? Did I make the point clearly enough?
At the executive level, communication and influence can matter more day to day than technical skills. That does not mean the technical skills do not matter. They absolutely do. You need enough expertise to know what questions to ask, understand the answers, and make good decisions.
But an executive is not supposed to be the deepest technical expert in every area. You have people on your team who are much deeper in certain technologies than you can be. Your job is to bring the right people together, understand the issue, simplify it without oversimplifying it, and help the organization decide what to do.
In some ways, not being the deepest expert in every detail can be useful. It forces you to explain things in plain language. If you cannot explain a security issue to a non-technical executive, then you probably have not made it clear enough yourself. That is the connection between sales, performance, and being a CISO. You need technical credibility, but you also need to listen, communicate, build trust, and help people make good decisions.
You joined SSM Health from outside the healthcare industry. What was that transition like, and how has coming in with a different perspective shaped the way you approach security there?
I was lucky that SSM Health was willing to bring in a security leader from outside healthcare. They wanted someone who could bring in new ideas and help drive innovation.
The healthcare industry often moves more slowly and more conservatively than other industries, and that is not necessarily a bad thing. There are many regulations. More importantly, people’s lives are involved. When you change a system or put in a new security control, you must think about how it affects patient care. You can’t move fast and break things because people could die.
When I joined, I had much to learn. I needed to learn the healthcare regulations, how the clinical environment works, and how security is applied in a healthcare organization. The basic security principles are the same whether you are in healthcare, financial services, technology, or another industry. The difference is in how you apply them.
For example, in another industry, the answer might be to lock something down, add another approval step, or take a system offline until you figure it out. In healthcare, that may not be realistic. You must think about the clinical workflow. You must think about whether a clinician can still get to the information they need in a timeframe that would be helpful to a patient. You must think about whether a security decision creates a new problem for patient care.
At the same time, I had the benefit of seeing how other industries handle security. I was able to bring in technologies, processes, and ways of thinking that were not as common in healthcare. I could ask questions that someone who had spent their whole career in healthcare might not think to ask.
The value has been in combining both perspectives. I had to learn the healthcare environment and respect why it works the way it does. At the same time, I could bring ideas from outside the industry and see whether they could make us better. That mix has helped us improve security while still supporting the people who are delivering care.
Third-party risk is a major challenge in healthcare. What has your experience taught you about managing security beyond your own perimeter?
I think the easiest way to explain third-party risk is through examples, because people usually understand the issue as soon as they see how much one outside company can affect everyone else.
Consider the Change Healthcare breach. It was not just a breach where data may have been exposed. It disrupted claims processing, payments, eligibility checks, pharmacies, providers, and hospitals across the country. A lot of people who do not normally think about cybersecurity suddenly understood that an attack on one company could affect whether they could get a prescription filled or whether a hospital could get paid. That is what third-party risk looks like in real life.
Log4j was a very different problem. When that vulnerability was announced, security teams everywhere had to drop what they were doing and figure out whether Log4j was in their environment. The difficult part was that most organizations did not necessarily install it directly. It might have been inside another product, inside a product from a vendor, or several layers down in the software stack. We had to find it, understand where it was exposed, decide what the risk was, and get it patched or mitigated quickly. It was a lot of work for a lot of people.
Then there was the CrowdStrike outage. That was not a cyber-attack, but it felt like one for the people trying to get their systems back online. A bad CrowdStrike update caused Windows machines around the world to fail. In many cases, someone had to physically touch the machine, reboot it, and go through recovery steps. That is a different kind of risk: the tool you are relying on to protect you can also create a major operational problem if something goes wrong.
Those three situations were different, but they all show the same thing. You can do a good job securing your own environment and still have a serious problem because of something outside of your walls. A critical vendor can be attacked. A piece of open-source software can have a major vulnerability. A security product can have a bad update.
That is why third-party risk is about more than sending out a questionnaire before signing a contract. You must know what you depend on, how important it is, what happens if it goes down, and what your backup plan is. In healthcare, that can quickly become a patient-care issue, not just an IT issue.
Security awareness training doesn’t always have a great reputation with employees. How is yours received, and what do you think makes the difference?
Security awareness training has a bad reputation because most people have sat through training that was boring, generic, or easy to forget. You click through a few screens, answer some questions, and get back to work. Or, even better, you just leave it playing in the background muted while doing other work. The training video may satisfy a requirement, but it does not necessarily help when a convincing phishing email shows up later.
At SSM Health, my team made the online training a magic show. The format was simple. We would show someone being deceived or “hacked,” and then we would explain the trick. What did the bad guy do? What information did they use? What made the request seem believable? Where should the victim have stopped and questioned it?
Employees had fun with it, and they talked about the training afterwards. That is a big difference. The goal was not just to make training more entertaining. We wanted people to remember what they saw when they got a strange email, text message, phone call, or request to change payment information.
Some employees even sent me Christmas cards to express their thanks for the required online training. That is not a normal reaction to mandatory security awareness training. It told us that people did not see it as just another compliance task.
The desire to build great security awareness training also helped lead to my Security Mentalism shows. I wanted to create something that people would choose to attend, even bring a spouse or date to see, and pay for. That is a much higher bar than getting people to complete required training.
My show is fun, and it is built around real things attackers use: trust, urgency, authority, distraction, and assumptions. People see how easily an intelligent person can be influenced, and they become more observant, skeptical, and aware — exactly what we want them to be.
It sounds like your approach has opened doors to conversations that CISOs don’t always get invited to. Can you give us an example of how that’s benefited your security program?
One benefit of my approach is that I get invited into conversations I might not otherwise be part of. Or I get invited earlier.
I use my mediator skills extensively. When I am speaking with someone, I am constantly paying attention to their emotional state and how they are reacting to the conversation. Are they frustrated? Skeptical? Overwhelmed? Interested but worried about something they have not said yet? That helps me adjust how I communicate, ask better questions, and explain my thoughts in a way the other person is more likely to hear.
When you develop a reputation as a good listener, a good idea generator, and a good communicator, people invite you into more conversations. That can mean I am in the room while an idea is still being formed instead of getting a call after the decision has already been made.
That has obvious security benefits. It is much easier to help someone think through a new vendor, a new technology, or a new business process before it is already in place. If security comes in late, we are often left trying to add controls around a decision that someone else has already made.
It also helps me learn. When I spend time with leaders in finance, operations, legal, marketing, sales, or clinical areas, I learn what they care about. Not just what that individual cares about, but the types of concerns that tend to come with those roles. What are they trying to accomplish? What gets in their way? What questions do they ask? What makes a security recommendation feel practical or impractical?
That makes me better at communicating. I can talk about the same security issue differently depending on who is in the room. A finance leader may care about financial loss or whether an investment is worth it. An operations leader may care about downtime and workflow. A business leader may care about customer experience or moving quickly enough to compete.
There is another benefit that is probably obvious but still important. I get to know other influential people in the organization. When we need budget, an approval, or executive support for something important, it helps if people already know me and trust that I am trying to help the organization succeed.
It is not about performing a trick to get someone to agree with me. It is about building relationships and being useful before there is a problem. Then, when a difficult security decision comes up, people are more likely to ask for my input and take it seriously.
What’s the biggest challenge or threat keeping you up at night right now?
The biggest thing keeping me up at night is AI and how it is changing everything.
AI is creating uncertainty in almost every direction at once. Employees are using AI. Vendors are putting AI into their products, sometimes without their buyers even realizing it. Attackers are using AI. Boards want to know what our AI strategy is. Legal teams want to know what is allowed. Security teams are trying to figure out how to protect it.
We cannot just do the same things we have always done, only faster. That is like asking for faster horses when what you really need is a car. The problem is that nobody knows exactly what the car looks like yet.
There is a lot of FUD (Fear, Uncertainty, and Doubt) around AI right now. There are also a lot of cybersecurity startups saying they have solved the AI security problem. They have not. The truth is that nobody has it all figured out. We are still trying to understand the technology, where the real business value is, what new risks it creates, and which controls actually work.
The legal and regulatory side makes it even harder. The rules are still being written. We do not always know what will be acceptable, what data can be used, what needs human review, or what will create a legal problem later. Organizations do not want to be the company that moves too slowly and misses the opportunity. They also do not want to be the company that moves too quickly and gets sued later.
That is a difficult place to be as a CISO. People want a clear answer. They want you to tell them whether they can use something, whether it is secure, and whether the risk is acceptable. Sometimes the honest answer is that we do not know yet.
But you cannot stop there. You still have to lead. You have to bring the right people together, put reasonable guardrails in place, learn quickly, and make the best decision you can with the information you have. You also need to be honest about the uncertainty without creating panic, and you need to support innovation without pretending there is no risk.
That is the challenge. We must navigate something that is moving very quickly, where the technology, the threats, the business opportunities, and the regulations are all changing at the same time. As a CISO, I need to be comfortable saying, “We don’t know,” while still retaining trust and helping the organization decide what to do next.
How do you see the CISO role evolving over the next few years?
I think the CISO role is becoming broader, more business-focused, and more tied to the organization’s ability to make decisions under uncertainty.
The old model was closer to, “Keep the bad guys out, run the security tools, and report on incidents.” Those things still matter, obviously. But the CISO now gets pulled into almost every major business conversation: cloud, AI, third-party risk, privacy, mergers and acquisitions, customer trust, resilience, regulation, and even the organization’s ability to keep operating when something goes wrong.
AI will accelerate that change. The CISO will not own every AI decision, and I do not think we should. But we will need to be in the conversation early. We need to help the organization understand what data is being used, what systems are connected, who has access, what decisions AI is making, and what happens when it gets something wrong.
The role is also becoming less about personally owning every cyber risk and more about making sure the right people own the right risks. A CISO cannot be the person who says yes or no to every technology decision. The job is to help the business see the risk, put reasonable guardrails in place, and make sure someone is accountable for the decision.
That means CISOs need to be comfortable with uncertainty. The business will ask questions where there is no perfect answer. Can we use this new AI tool? Is this vendor safe enough? How much risk are we willing to accept to move faster? What happens if an important service goes down? The answer is rarely a simple yes or no.
I also think the job will become more about resilience. We should absolutely try to prevent attacks, but prevention will never be perfect. Organizations need to know how they will keep operating, communicate, recover, and serve their customers or patients if something serious happens. In healthcare, that means continuing to support patient care.
The CISO of the future needs technical credibility, but that is only the starting point. They need to understand the business, communicate with executives and boards, build relationships across the organization, and help people make difficult decisions. The role is increasingly less about being the person with all the answers and more about being the person who helps the organization ask the right questions.
Finally, what advice would you give to CISOs who are early in their careers or just stepping into the role for the first time?
My advice to someone stepping into the CISO role is to remember that it is a leadership job first and a security job second.
You need technical credibility. You need to understand security well enough to know what questions to ask, challenge assumptions, and make good decisions. But you do not need to be the deepest technical expert in every area. That is impossible now. Cybersecurity is too broad, and it is changing too quickly.
What you do need is to understand the business. Learn how the organization makes money, serves customers, supports patients, or delivers its mission. Learn what keeps the CEO up at night. Learn what the CFO worries about. Spend time with operations, legal, privacy, HR, technology, and frontline teams. If you do not understand how people actually work, you will build a security program that looks good on paper but does not work in real life.
You also need to build relationships before you need them. Do not wait for an incident to meet other leaders. Get to know them early. Let them know you are there to help the organization succeed, not to tell people no.
Be honest about risk. Do not exaggerate every issue into a catastrophe just to get attention. People will stop listening. Explain what could happen, how likely it is, what the options are, what it would cost to reduce the risk, and what risk the organization is accepting if it chooses not to act.
And do not try to fix everything at once. Every CISO inherits more risk than they can solve. Pick the things that matter most. Make progress. Show results. Build credibility one decision at a time.
Finally, find your own way to communicate. For me, that included mediation, negotiation, and Security Mentalism. For someone else, it may be writing, teaching, mentoring, data analysis, or simply being exceptionally good at listening. There is no single personality type that makes a good CISO.
The best CISOs I know are technically credible, curious, practical, and able to bring people together. That is the kind of leader I would encourage any new CISO to become.
Learn more about Gary and Security Mentalism.