Skip to content

Packet Protector: Why Security Needs Infrastructure Partners

On CYBR.SEC.CAST, Packet Protector hosts JJ Jabbusch and Drew Conry-Murray explain why stronger cybersecurity starts with treating infrastructure teams as security partners.

This article is based on the latest episode of CYBR.SEC.CAST. Full episode and related article here:

Emotional Support Co-Hosts with JJ and Drew
CYBR.SEC.CAST joins Packet Protector to explore networking, security, community education, career growth, and the future of cyber collaboration!
Packet Protector’s Drew Conry-Murray and JJ Jabbusch: Why Cybersecurity Still Runs on Community
Packet Protector hosts Drew Conry-Murray and JJ Jabbusch explain why mentorship, community, and accessible education remain cybersecurity’s greatest strengths.

One of the biggest obstacles to stronger cybersecurity isn't technology. It's the relationship between security teams and the people responsible for keeping infrastructure running.

When Packet Protector hosts Jennifer "JJ" Jabbusch and Drew Conry-Murray joined Michael and Sam on the latest episode of CYBR.SEC.CAST, the conversation began as a discussion about networking, security, and community. It quickly evolved into something much bigger: why many organizations still treat infrastructure teams as order takers instead of equal partners in cybersecurity.

For Jabbusch, that's a mistake that organizations can no longer afford to make.

"Security" and "IT" may sit under different organizational charts, but the people who build and operate enterprise infrastructure often understand those environments better than anyone else. Rather than handing them a list of security requirements to implement, she argues they should be helping shape how those requirements are achieved in the first place.

It's a subtle shift in thinking, but one that could have an outsized impact on how organizations defend increasingly complex environments.

Security without context creates friction

Every security practitioner has seen the pattern.

The vulnerability scanner generates thousands of findings. The security team tells operations to patch everything. Certificates need to be rotated. SSH should be disabled. Firewall rules need to change. Logging needs to expand.

From security's perspective, those requests make perfect sense.

From the perspective of the engineers responsible for keeping production systems online, they often arrive without the context needed to understand the actual security objective—or the operational realities that make some requests far more complicated than they appear.

Jabbusch said that's a conversation she's had repeatedly while consulting with organizations and teaching technical classes.

Too often, infrastructure teams are simply told what to do instead of being brought into the discussion about what problem security is actually trying to solve.

The result isn't just frustration.

It creates unnecessary tension between teams that ultimately share the same goal.

The people closest to the systems often know them best

One of Jabbusch's central arguments is surprisingly straightforward.

Network engineers. Systems administrators. Cloud architects. Infrastructure engineers – These professionals already understand the systems security is trying to protect.

They know which legacy applications can't simply be patched. They understand maintenance windows, application dependencies, network architecture, and operational risks that don't show up in vulnerability reports or compliance dashboards.

"They're the people that are best equipped to secure these systems," Jabbusch explained while discussing the disconnect she often sees between security and infrastructure teams.

Instead of treating those professionals as the recipients of security mandates, organizations should recognize them as critical contributors to security strategy.

After all, securing infrastructure begins with understanding how that infrastructure actually works.

Security frameworks shouldn't belong only to security teams

The discussion also highlighted a challenge many organizations rarely acknowledge.

Frameworks such as the CIS Controls and the NIST Cybersecurity Framework frequently guide security decisions, but the engineers responsible for implementing those controls often have little exposure to them.

Jabbusch noted that many infrastructure professionals are simply left out of those conversations, even though they're the ones configuring the systems those frameworks are designed to protect.

That disconnect creates an unfortunate dynamic. Security becomes something that's done to infrastructure teams instead of with them.

A healthier model starts by explaining the objective rather than dictating the implementation.

Instead of saying, "Disable this service," security teams can ask, "Here's the risk we're trying to reduce. What's the best way to accomplish that without disrupting the business?"

That simple change turns compliance into collaboration.

Building the next generation of security practitioners

That philosophy also explains why Jabbusch agreed to co-host Packet Protector in the first place.

While the podcast explores topics ranging from networking fundamentals to AI agents, machine identities, cloud security, and emerging technologies, one of its primary goals is helping traditional IT practitioners become stronger security professionals. Many already possess deep technical knowledge of the environments attackers target every day. What they often need isn't another certification as much as greater exposure to security thinking.

Jabbusch believes those professionals represent one of cybersecurity's largest untapped talent pools.

Rather than assuming the next generation of security practitioners will come only from existing security teams, organizations should be looking toward the technologists already running enterprise infrastructure.

Community is part of the solution

Conry-Murray echoed that philosophy from the Packet Pushers perspective.

He explained that the network has always focused on helping practitioners understand new technologies, learn from one another, and realize they aren't facing these challenges alone. Education, career development, and community have remained central to Packet Pushers since its earliest days.

Throughout the conversation, both teams emphasized that conferences, podcasts, Slack communities, and educational content aren't simply ways to distribute information—they're places where practitioners solve problems together.

The stronger those communities become, the stronger the profession becomes.

Better security starts with better partnerships

Cybersecurity has spent years investing in better tools, more automation, and increasingly sophisticated defenses.

Those investments matter. But the conversation with Jabbusch and Conry-Murray suggests many organizations still have a more fundamental problem to solve.

Security cannot operate as a separate function that simply hands requirements to the people running the infrastructure.

The most resilient organizations recognize that security, networking, systems, cloud, and operations teams all bring different expertise to the table.

Security defines the risks. Infrastructure understands the environment. The best outcomes happen when both groups solve those problems together. That's not just good teamwork.

According to Jabbusch, it's how stronger cybersecurity gets built.

HOU.SEC.CON CTA

Latest