The Writing King Your Ethical Ghostwriter. Your Story, Done Right.
This entry is part 37 of 49 in the series Leaders and Their Stories

How to Get an IT Project Approved

Featuring Matt Walker on Leaders and Their Stories with Richard Lowe

Chapters

  • 0:17  Decades in IT
  • 1:34  We Did This to Ourselves
  • 3:22  Business Speak, Not Tech Speak
  • 5:38  The Psychology of Approval
  • 6:52  Selling a Cost Center
  • 8:02  Make Security Personal
  • 9:02  Train the User, Not Just the Data
  • 12:31  No System Is Fully Secure
  • 12:55  Lessons From Kennedy Space Center
  • 15:11  The Deepfake That Cost Millions
  • 19:23  The Real Problem With AI
  • 21:24  Where to Find Matt

TL;DR: What This Conversation Establishes

  • To get an IT project approved, speak business, not tech
  • Security is a hard sell because it is seen as a cost center
  • No system is ever fully secure; the only secure computer is one turned off and buried
  • Make security personal: train people about themselves, not just company data
  • Real-world attacks like deepfake fraud show why awareness has to be human

What You’ll Learn

  • Why IT projects get rejected
  • How to speak business instead of tech
  • Why security is a hard sell
  • How to make security training personal
  • What real attacks teach us

Matt Walker joins Richard Lowe (The Writing King) on Leaders and Their Stories for a practical conversation on getting IT and security work approved and done.

With decades in IT and a background that includes Kennedy Space Center, Matt explains why you must speak business rather than tech, why security is a hard sell, and why the smartest defense is making security personal.

Matt Walker is a veteran IT and cybersecurity professional whose career includes work at Kennedy Space Center. He specializes in the human and business side of technology projects and security awareness.

For more conversations like this one, see the Leaders Hub. Richard ghostwrites cybersecurity books for experts like Matt.

Host: Richard Lowe
Guest: Matt Walker
Show: Leaders and Their Stories
Format: Video + Audio
Time: ~25 min watch / ~17 min read

DISCUSS YOUR BOOK

Interview

Full transcript of the interview follows.

Richard: Hello. This is Richard Lowe. And this is the leaders and their stories. Podcast I’m the writing king and ghostwriting, Guru. And I’m here with Matthew Matthew Walker. And we’re gonna talk about how to get an it project, approved Matthew. Why don’t you introduce yourself.

Decades in IT

Matt Walker: Good morning, Richard. Thanks for having me. Yeah. I I’ve been in it seem seemingly, since dinosaurs have roamed the earth done virtually everything from teaching people how to put computers together and take them apart back in the days when 4, 86 Dx. Meant something to people. and done everything from that all the way up through cyber security, and just a a pleasure to be here.

Richard: Well, thank you for coming on the show. so the subject is how to get an it project approved any kind of it project. I know I’ve had trouble with that in the past. I was the it director, Trader Joe’s for 20 years. and getting it is considered a cost center by most companies and getting things approved can be a nightmare.

Because, hey, that’s an expense. That’s something especially considered a big expense. And the it department was also looked on as being somehow subhuman, and that always it always made it interesting. And of course we didn’t talk the language. so that was on us. So we were talking bits and bytes, and they were talking roi in business terms, and we never! We really never burst through that barrier. What have you found.

We Did This to Ourselves

Matt: Yeah. So you, you kind of hit on one of the major topics. There, we We did this to ourselves, not just over a couple of years, but many, many decades. We kind of assigned this othering to technology. In the the it and cyber realms that you you had to be a super genius to do this stuff.

When you when you mentioned when I mentioned the term cyber to people. They immediately have this image of this hooded guy sitting sitting in a darkened room. And there’s matrix screens behind him, and you know, with a couple of keystrokes he’s hacked past the firewall, and we did that to ourselves.

Yes. and and kind of elevated in our own minds, you know. Hey? We’re, you know, the stupid user syndrome snl had a skit about it for years. I can’t remember the guy’s name. No, but he was the It. Guy and he would come in move, and then he would fix their their problems.

It it’s our fault, and you can’t fix a problem that’s been created over decades in a matter of a few hours it takes time to fix that.

Matt: Yep, and threw me out of the room.

Business Speak, Not Tech Speak

Richard: And that’s when I learned he he wanted business. Speak not all the things that we use like. Okay, how long does it take to recover all that kind of stuff he didn’t care. and then he turned to my boss and he said. Why are you even doing this?

Get out of here. So my boss even got reamed for putting a project of many millions of dollars in front of his boss without any preparation. So it’s cold. And even my boss failed at the business. Speak so. It was interesting, interesting lesson.

Matt: Yeah. Yeah. Well, I I had a fairly similar story with a little bit of a little bit of a twist on it. I was. I was at Kennedy Space Center, and we were doing a presentation about the current state of security to the CIO there, who I eventually became really good friends with.

But so he’s sitting in the. He’s sitting at the head of the big table, and it’s exactly how you’re picturing it in your mind, and I’m up in the front with the big screen, with the laser pointer and going through things. And and he he like raises hand.

I’m like, I’m like, Yes, Sir Henry, what can I? What can I do for you? And he he says, Hey, so I’m I’m looking up there, and I’m just I just I don’t notice any red. Everything is either green, teal, or blue. and I’m like, Yes, sir, it’s because I know you don’t like Red.

and he he really, you know that. That made him laugh, and he kinda understood what I was talking about, so that then, later, when we got to the bad stuff it it’s it’s like we prepared him for the bad stuff it was like. See, it’s it’s not so bad. It’s just blue. So.

Richard: Interesting concept there. Interesting concept. Yeah. Now, now, I’ve learned. You know, I’m learning marketing, and it’s what’s in it for them is the important thing. That’s that’s the number one thing, when you’re talking to somebody else and trying to pitch them something which you’re doing in this case, what’s in it for them, actually, what’s in it for them personally, sometimes.

In the case of it, what’s in it for them as as a as their title what’s in it for them as their department in the company? If you don’t have what’s in it for them first, st you’ve already lost them.

The Psychology of Approval

Matt: Right one of the I read a lot of books on this kind of stuff. It’s it’s really interesting to me, the psychology of why people do the things they do and what they want. And and I was was reading this this one book, and the the guy said I could take a picture of you and one other person.

Then I can take a picture of you. With your high school graduation group at your 25, th 30th reunion whatever. And then I could take a picture of you at a Bon Jovi concert. and I can put all 3 pictures in front of you. and you know what you’re gonna look at you.

you’re you’re not gonna look at, you know all of these people and all of their stories and the background. And what’s going on. We are focused on us. It’s built into us. It’s it’s part of our DNA. It’s just the way the way that we are, and and people who can.

I hate to use the term exploit. But that’s kind of my realm people who can exploit that can get things done a lot faster than those who only focus inward. You know.

Selling a Cost Center

Richard: Right right now, cybersecurity projects are even a bigger challenge, because that’s really considered a cost center and unnecessary by most, although that’s changing as things happen.

Richard: And it’s not really very well understood outside of it, or even inside of it. we tend to alarm, make it alarming. And again, our fault, our fault, and then our bosses. They don’t want to be alarmed. They don’t want the stockholders going. Oh, my God! Oh, my God!

You know they, don’t they? So they want to tone it down. We had a culture where the stores were the important thing. So sending notes to the stores about security was not something you did. because we didn’t want to burden them with that. Well, how do you train them on security?

If you can’t talk to them about security. And it became an interesting conundrum for us. We worked around it somehow. usually through in person meetings and stuff like that rather than email blast. And but it was interesting.

Make Security Personal

Matt: It’s 1 of my kind of a sidebar to what we’re talking about here because you mentioned it. It’s it’s 1 of my one of my favorite things to talk about when I’m asked to go. Talk is is my position is you? Should we? We spend a lot of we spend a lot of time and money trying to train our users, you know.

Hey, this is our security posture. This is what you need to do to protect our data. Don’t do this. Don’t do this. Don’t do this. And we usually put this together in either a video or a Powerpoint slide that they click through with a test at the end.

And then, for some inane, ridiculous, crazy reason, we send it to them in an email with a link to click it. It just it’s it just aggravates me to no end. But in all of that no, no! Think back to what we just talked about over the last couple of minutes. Everything I just said was ours. Our stuff we don’t.

Matt: We we spend, we spend all of our training talking about our data, our protection, our.

Train the User, Not Just the Data

Matt: We never once mentioning the user. I think we we. In my opinion. I think we would be better served by radically changing the user training environment to more of a making security personal. If I teach Bob how to protect himself and his family and mom, and what to do if something happens at his house, Bob will protect my data because he’s used to it.

It’s part of who Bob is. That’s where our focus needs to be. There’s a whole train of stuff on that that we don’t need to get into. But because you mentioned it’s it’s really kind of a passionate plea of mine is. Get away from talking about our stuff and start talking about Bob, and you’ll be better off.

Richard: Right. I just had to go through one of those security thing training courses from one of the training companies that it was an hour long if you were fast. which I am because I am a cybersecurity person, and it goes through all these games that they put together, you know.

and I was just going through and saying. these things are ridiculously stupid. They they fulfill the letter of the law or the rule that yeah, these users have been through this, but I don’t see very many users, if any getting anything from it. That lasts they’re just stupid.

I don’t know what else you could do. But you, you know, take, they have a little aquarium with fish, and take take the message that you shouldn’t read and put it in the trash. Can you know? Okay, this is kind of dumb.

Matt: Yeah, see, Matt, Matt Walker’s training program would be more. Something like this. It’s like, Hey, hey, Bob, here’s you know your your 1st your 1st training program. It’s not a not an annual thing. It’s just a bit. Let’s let’s just talk about fishing for a second. Okay, typical training.

Right. Now I’m gonna send Bob a 30 slide deck on. Let’s define fishing. Let’s show you how to look through things, so you can figure out what the which one’s bad and which ones trust me, I don’t care how intelligent Bob is, or you or me, or anyone.

If someone wants to effectively trick you by using an email. They’re gonna do it. Anyone who has spent any time reading about deepfakes over the last forget 10 years year. There’s no way to tell anymore. There’s no way. So the training program shouldn’t be all of this fishing stuff.

And blah! Blah! That’s great stuff for Bob to know what you need to tell Bob, is, don’t click links that’ll protect you, Bob, when you’re at home. And you’re looking through email. Don’t click links. And you’re you’re protected from a whole bunch of stuff. By the way, don’t do that at work either.

Richard: Yep, Yup, I would. I would modify that slightly. Don’t click links unless it’s something you just asked for. like I go to my account. And I say, Okay, I want my report. You get an email right after that, although that screwed me once over because I had just sent a package from ups.

And 2 min later an email comes in that said, it’s here. It was a scam email. It was just coincidence. I clicked it. Of course, you know, I got all kinds of software that protected me and I didn’t. It’s fine. I actually think we’ve got it reversed. The user is never gonna do this? 100 right? Why don’t we make computers good enough to not have this problem.

No System Is Fully Secure

Matt: Yeah, so I I have a a slight philosophical difference in that. Because I I don’t believe you can fully secure either side of that equation. I.

Matt: No, the only really secured system is one that’s turned off, poured into a vat of concrete, and buried under 50,000 pounds of lava.

Lessons From Kennedy Space Center

Matt: Exactly so. So my my perspective over over I had a job at Kennedy Space Center. We were. We were working a desktop support contract, and one of the things that we did was we would we would monitor these these little screens, and it would pop up and tell us, when a system started beaconing a 1 of the many, many symptoms that something had gotten on the system that it didn’t want to.

But if it was beaconing to specific areas. We would want to go. Take a look at that system. And this this was in the days where you actually had to go get it. You you couldn’t just centrally, you know, and I cannot tell you the number of times that I would go to somebody’s office.

Intelligent people, some of the smartest people in the world, people trained in security. They know how to use their systems and all of it, and I would show up to pick up their system. And they would say. Didn’t you guys install antivirus on here? I should have been protected?

So the the total reliance on a system or a tool to protect you is worse. in my opinion, than having none of that. because if you think you have security, you don’t. If you think you have security, you’re more than likely you’re more likely to take risk that you otherwise would not do. You know, people with a people with a security contingent around them, don’t care about offending their waiter.

Richard: It’s true. it’s true. And then then you’ve got emails like, CEO. This, the what’s it called whale. the the spearing, spearfishing. and the one that’s targeted. And they don’t have links in there. Typically, they will say things like, Oh, I’m a CEO. And I just approved this 1 million dollar transfer and have a voicemail or something.

That’s that’s the CEO’s voice that says, Do this, and that doesn’t have a link. It has a something that seems real a deep fake, maybe even a video of the CEO saying, Can you ship this over there? And I’ve seen companies lose millions and millions of dollars, because who’s gonna say no to the CEO.

Matt: Are you familiar with the Hong Kong thing that happened couple of years ago?

The Deepfake That Cost Millions

Matt: Yeah, so so real real quick, because it’s apropos to what we’re talking about. So quick story. So so I I use Bob a lot in my allegory. So so Bob goes to work. He works in the finance department of this business. He works every day with the Cfo.

And all of these people in finance. He sees them every single day. He walks into their offices, shakes their hands, knows them. So. It’s late on a Friday, and it it was on a Friday. It’s late on a Friday. He gets a message. Pop up. Hey? Can you join this call?

He pops on the call. It’s the Cfo. He’s at home. There’s a couple of other people on the call. They’re talking about all this stuff, all of them talking about things they’ve been talking about in the office. Everything’s fine. Well, during the call they talk about this business venture that the company is going to get into, and he needs to transfer.

I don’t know how many millions of dollars to this account to get it done. He does it because the Cfo is on the call he goes home, doesn’t think a thing about it. Comes back on Monday, walks into the Cfo’s office, says, Hey, what about that deal on Friday?

Is things looking good, and the Cfo was like, what are you talking about? The entire thing was completely deep faked.

Matt: And I. I bring that story up because it it goes back to what I was talking about in making security personal. It leaders really in in this, in this age of AI, if it’s if it’s changed anything. we radically need to change the way we interact with the folks that that work for and with us.

I would not want Bob to transfer anything to anyone without seeing my face and saying, Hey, you know I should be okay, as as the Cfo. For somebody to walk into my office. Sam, I I just want to make sure. Is this is this real.

Richard: Right. right? Or some kind of counter signature, or something that’s not over that same communication or something to to make sure that it’s okay, like, maybe even pick up your smartphone and call him on a golf course. This is this is 10 million dollars we’re transferring. Is that okay with you.

Not a most likely isn’t gonna complain if if you call him about that, and if he does, he’s an idiot. Yeah, interesting stuff. yeah. And and of course AI is changing things on both sides, and the Ukraine war is changing a lot of things because it’s causing a lot of things to very rapidly grow and change and evolve.

That’s the word I wanted where I mean, they’re making a million drones a year now, Ukraine, out of plywood. Right? Yeah. And used it. You use parts that are having an effect. I mean, who? Wow, okay.

Matt: I was gonna say, that’s a that’s a different podcast. That we can definitely get into. If you would like to.

Matt: More than an hour.

The Real Problem With AI

Matt: I I think the the biggest you know. Not that you asked me, but the biggest problem that I have with with AI at this point is not, you know, the whole. We’ve all seen Terminator, and it’s not. It’s not any of that, although that that is a concern long term.

My, my biggest issue with it was we we created this gigantic engine that provides so much information and and ways to to do things, and we dumped it on. We dumped it on a populace without preparing them for it. We just made it available. Here it is. and this is the same populace who, you know, the most popular password in the world, is password with a 0.

Where to Find Matt

Matt: So we we kind of we. We have kind of strayed a little bit through a lot of cyber sec here, but to to get back to your original the original topic you wanted me to talk about. And and that was getting an it project or a Cyber Project bringing it to fruition with a a management group that is either unwilling or not knowledgeable on the subject enough to to make the decision in in my, there’s a lot of different things you can do.

You guys can go to. You guys can go type that into Google right now. And it’ll pop up an AI overview of steps you can take, and you know, show them the business impact and the cost. And blah blah! All that stuff is fine. I’m not even gonna bother to get into it.

What? My what my advice or or my what I kind of see in it is the pitch, for something like that doesn’t start at the pitch. It it starts way before that. There’s a there’s an old, an old saying that trust is built in raindrops and lost in buckets.

Raindrops take a long time to fill up that bucket, so you need to start way in advance and build up that rapport with the the management group and those who are in positions above you, so that they know they can trust you that way when something happens and you come to them that element of trust.

I’m not saying that that just automatically says, Yeah, Matt, go spend 5 million dollars. Don’t worry about it. They still have things to consider, but because they trust you already. it helps a lot. And there’s there’s 2 books. There’s 2 books that I would advise everyone to read, and they’re both by the same author.

It’s a guy named Robert Cialdini, and the 2 books. One of them is called Persuasion, and one of them is called the Art of influence. And I’m not saying that you know you need to go through your entire work career, or your personal life. preparing people, and socially manipulating them to do your will.

What I am saying is, if you read these, if you read these books and apply them with the heart that God intended you to have. You can build rapport and get things done much, much easier, especially the persuasion book. It’s it’s just gold for getting people prepared to at least consider what you’re gonna say.

Richard: Yeah, books are gold, and those those sound like really good ones to get.

Richard: Okay, okay, well, thank you for coming. How can people get hold of you?

Matt: Well, I don’t have a I don’t have any kind of social media or excuse me, any kind of podcast or anything like that. I do have my my book coming out with O’reilly, certified ethical Hacker Study Guide is about to hit, and there’s contact information. If you go out to O’reilly dot com library.

Right now you can see the book, and there’s contact info in there for for me, and I’m sure if anybody really wants to talk to me. They can contact you, and you know how to get a hold of me, and I’m on Linkedin. So.

Richard: Yeah, okay sounds good. Well, this is Richard Lowe. This has been the leaders in their stories. Podcast I’m, the writing king and ghostwriting. Guru. You can reach me@thewritingking.com and ghostwriting. Dot Guru appreciate you all listening and stay tuned for the next one. Thank you.

Quotable moments

The only really secure system is one that is turned off, poured into a vat of concrete, and buried. — Matt Walker
Share on X

We spend all our training talking about our data and our protection, and never once mention the user. — Matt Walker
Share on X

You have to speak business, not tech. That is what gets a project approved. — Matt Walker
Share on X

Related interviews

Frequently Asked Questions

What is Matt Walker’s main advice for getting an IT project approved?
Speak business, not tech. Matt and Richard both share stories of being thrown out of a room for leading with technical detail. Leaders want to hear about outcomes, cost, and value in their language, not specifications, and framing the project that way is what gets it approved.
Why is security so hard to get funded?
Because it is treated as a cost center, and its value is poorly understood inside and outside of IT. Matt explains that framing matters enormously: you have to connect security spending to real business risk and outcomes rather than alarming people with jargon.
What does “make security personal” mean?
Matt argues that most security training talks only about protecting company data and never about the user themselves. He believes training would work far better if it helped people protect their own lives and identities, because personal stakes drive behavior in a way corporate policy does not.
What do real-world attacks teach?
Matt points to cases like the Hong Kong deepfake fraud, where an employee was tricked into transferring millions, to show that no system is fully secure and that people are the real attack surface. His takeaway is that awareness must be human and personal, backed by verification steps like counter-signatures.

Your story could be a book

Every leader I interview has a book in them. If you have spent a career learning what works, let’s talk about turning it into the book that outlasts the work.

DISCUSS YOUR BOOK
ALL LEADERS INTERVIEWS

Part of the Leaders and Their Stories Hub, one of 49 leadership interviews.

📁︎ Business📁︎ Leadership📁︎ Technology

🏷︎ For Executives & Professionals🏷︎ leadership interview🏷︎ Technology Strategy