• rcr icon

    Accelerated Cybersecurity Training Program

    Catalyst Cyber Accelerator

    Corporate Training

    Cyber Talent Acquisition

    Mastercard Emerging Leaders Cyber Initiative

    Catalyst Fellowship Program​

Ideas

From accounting to cybersecurity: Steve McMichael on finding the unseen path

Steve McMichael is Senior Director, Risk Operation Center at Sagard and an industry fellow in the Catalyst Fellowship Program.

I was told I didn’t fit.

“You’re a great guy, Steve. You’ve got a great attitude, but you have a business profile…” Those were the last words from his mentor in 2008 as he discouraged Steve from cybersecurity. Steve was deflated, but it wasn’t his first punch. “I decided to pivot and get on the more well-defined accounting train.”

The years passed, and along the way, he earned his Chartered Professional Accountant designation. He gained extensive accounting experience, but cyber never left his mind. And it kept consistently trending up from a side IT issue to an existential business risk. Steve started immersing himself in cybersecurity books, podcasts and blogs as ransomware stories made their way into mainstream headlines. His interest was re-invigorated, but it wasn’t clear that a professional path existed for him at current or later stages of his career.  

Then a course caught his eye. He enrolled. It was called “How to Get Your Dream Cybersecurity Job.” 

COVID struck, and he was on a stationary bike in his basement, leafing through lesson three materials when he had an epiphany moment. He saw himself on the page. It directly  connected careers in financial auditing with cybersecurity for a function called “GRC.” As he pushed his speed and the pedals picked up pace and rhythm, he didn’t know what the acronym GRC stood for — but it could be his foot in the door. 

“Suddenly, an unseen path was revealed,” said Steve. Business transformation from monolithic on-premise Enterprise Resource Planning software to best-of-breed Software-as-a-Service platforms already had accountants and business professionals upskilling for IT. Integrity was paramount to prevent fraud disasters like Enron. But so were the other pillars in the cybersecurity triad of confidentiality and availability as cybersecurity discussions increasingly made their way into Boardroom priorities.

You saw it coming as a new, growing domain. Going from fighting fraud to basically protecting organizations from other types of crime and also espionage. It’s a very compelling mission to be protecting people, organizations and the economy. How could you not want to be a part of that, right?

Driven to open up the field for others who had struggled to see a clear path, Steve developed courses on how to break in. His research and experience shaped his efforts to create space for others with diverse backgrounds. Cyber was a team sport, and its strength depended on diverse skills and perspectives. After finding his path, the long way around, he wanted to help others find theirs. “We need their help over here,” he says. “I’m here to help people find the unseen path.” But how to do it and where to focus when the breadth and depth of cyber seems so overwhelming?

“You ever heard of T-shaped skills?” says Steve. “Cybersecurity has, say, eight or ten domains. And each one is a profession in itself.” T-shaped skills refer to having specialized knowledge in one field while maintaining a broad understanding of others. “I was able to immediately add value,” says Steve. “And maybe, if I hadn’t done accounting, I wouldn’t have had that advantage.” 

Steve explains a case in the United States called CUI (Controlled Unclassified Information), which reflects emerging concerns in cybersecurity and defense. First, he says, private industry works with the federal government in the national interest. Then, you’ve got the defense industrial base. The turning point came when a fighter jet design was copied, exposing the leakage of classified information outside federal networks, and forcing regulators to formalize cybersecurity requirements across the defense supply chain beyond a self-attestation compliance model. 

Leaks like that imply that “people were kind of mailing it in and not doing the due diligence and due care GRC work,” Steve says. So, now in the United States, to avoid fraud they updated their regulations to require mandatory external audits by accredited third parties. Canada is following suit, but it’s very early innings compared to well established practices like accounting. 

He says of the Fellowship: “When it came to the Catalyst, I saw a great opportunity, and I went for it.” Steve is staying ahead by building a web system similar to cyberseek.org. This is a database hosted on an American website, and you can view job postings by state and city. It reviews all available job data for cybersecurity roles, scans it, and connects pertinent certifications to job postings. The system supports candidates in finding the right fit and completing the preparation required to transition to or enter a new sector or role. He asked himself, “Why doesn’t Canada have that?” When he asked the Canadian Cybersecurity Network if he could put it up on their website, they welcomed it. Partway through the Fellowship, the platform is already taking shape.

He also has a goal of elevating GRC, which he says is very much an underdog. He recalls covering the BlackBerry booth at SecTor, and a high school student came up to him and said, “Oh, GRC, I hear that’s a lot of paperwork.” Steve laughed. It was not the first time GRC had been underrated. He is focused on demystifying roles in cybersecurity, GRC included, so they feel accessible rather than opaque.

I think people’s careers are a really big deal. It’s serious business.

“If you can help a person move on to a position they value, you’ve helped them turn the corner.” He believes in the unseen path. He wants those interested in cyber to upskill and follow their curiosity toward meaningful work.

Nearly twenty years ago, he was told cyber wasn’t the right fit.

Today, he works at the center of governance and risk — the part of cybersecurity that determines whether organizations can prove what they claim to protect.

The path wasn’t obvious at the start.

Bio:

Steve McMichael is Senior Director, Risk Operation Center at Sagard, leading cybersecurity governance, risk and compliance programs that protect the organization and enable business growth.  Steve is engaged in cybersecurity education and research, most notably as an instructor and content creator at Simply Cyber Academy. His research efforts are supported by Rogers Cybersecure Catalyst, where he is an industry fellow.

More from the Catalyst