July 22, 2026

Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)

Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)
Compliance Chronicles
Security at the Intersection of People and Technology with Shellie Dreistadt (Ep. 15)

Key Takeaways

  • Shellie Dreistadt CISO emphasizes that modern cybersecurity sits directly at the intersection of human psychology, motivation, and technology rather than relying solely on firewalls and access controls.
  • A successful CISO must frame risk in financial and operational terms rather than technical jargon to effectively partner with the business and push risk ownership outward.
  • Avoiding burnout in high-stakes compliance and security roles requires refusing to act as the single point of safety and instead building resilient, collaborative organizational programs.
  • Prioritizing psychological safety and open communication within a security team drastically improves threat detection, early concern raising, and overall incident response.
  • Security leadership is not about acting as the department of no, but rather enabling the broader business to innovate and move forward safely.

Chief Information Security Officer Shellie Dreistadt joins Compliance Chronicles with Liisa Thomas to talk about how psychology, cybersecurity, and leadership resilience come together in modern security programs. She shares her nonlinear path from psychology and call‑center leadership into information security, online banking, and ultimately her current CISO role.

Shellie explains why security sits at the intersection of people and technology, and how understanding behavior, motivation, and trust is just as important as understanding firewalls, access controls, and tools. She describes the realities of being a CISO today: constantly evolving threats, rapid technology change, and an expanding privacy and security regulatory landscape.

The conversation covers pushing risk ownership back into the business, framing issues in financial and operational terms instead of “tech speak,” and avoiding burnout by refusing to be the “single point of safety.” Shellie also shares how she builds resilient, curious, adaptable teams and why culture and psychological safety matter as much as any control.

Her advice for security, privacy, and compliance professionals: stay curious, stay human, and remember that cybersecurity is a marathon, not a sprint. Security is not about being the department of no—it is about enabling the business to move forward safely.

If you work in cybersecurity, information security, privacy, or compliance—or you’re aspiring to a CISO or security leadership role—this episode offers practical insight into building resilient teams and leading with both technical acumen and empathy.

If you enjoy this conversation, make sure to subscribe to Compliance Chronicles in your favorite podcast app and follow the show so you don’t miss future episodes on privacy, AI, internal audit, cybersecurity, and real‑world compliance leadership.

Frequently Asked Questions

Who is Shellie Dreistadt CISO?

Shellie Dreistadt is the Chief Information Security Officer at Papa John's, bringing over 25 years of experience spanning psychology, call-center leadership, online banking, and information security.

How did Shellie Dreistadt transition into cybersecurity?

Shellie transitioned from a background in psychology and call-center management into cyber when she helped roll out a regional bank's very first online banking website and designed its initial login and access controls.

Why is psychological safety important in cybersecurity?

Psychological safety allows team members to raise concerns and admit gaps early without fear, which significantly enhances a security team's overall readiness and incident response capabilities.

What is the role of a CISO in managing business risk?

A modern CISO must collaborate closely with business leaders to push risk ownership into the organization, translating technical vulnerabilities into clear financial and operational impacts.

speaker-0: you


speaker-1: Welcome to Compliance Chronicles, where we learn from professionals shaping the world of compliance. I'm your host, Liisa Thomas, outside Privacy and Compliance counsel an adjunct professor at Northwestern Law School, and a lifelong learner of organizational change. From personal journeys to hard-earned lessons, these are the Chronicles that Inspire and Guide. Let's dive in. Welcome back. I am delighted to have another conversation with a leader in this space. Today, I'm joined by Shellie Dreistadt. So Shellie, if I'm to turn it over to you to introduce yourself and to say briefly, your current role.


speaker-0: Sure, Liisa, thanks so much. ⁓ I'm Shellie Dreistadt and I am the Chief Information Security Officer here at Papa John's. I've been here for about three and a half years and have been in the field for about 25.


speaker-1: Tell us a little bit about that journey to lead you here as the CISO.


speaker-0: So my personal journey was definitely nonlinear. I spent six years changing my degree interests. I was going to get a degree in education. I wanted to be a nurse. Then I wanted to go to business school. Then it was social services. Ultimately, after six years, my parents were like, you have to decide because we are not going to continue to fund your education journey until you finish something. So psychology ended up. being where I landed. behavior was easy for me, but it was also fascinating. Remember now, this goes back to 1993. So technology and cyber was really not in my view. Understanding behavior, it really, it turned out to be a huge advantage. 1993 was like watershed for the internet. It's the year I think Mosaic came out, which was the first general use internet browser. So when I was starting college, we were just learning how to use email. So I had no idea that I would end up on the side of technology fighting criminals and bad actors. My journey really started in cyber around 2000. And that was before I really considered myself highly technical, but I was leading a team in a call center for a regional bank and sat right next to the marketing team and overheard that we were going to launch online banking, very first online banking website. I got kind of excited about that. I was like, well, I could probably do that a little bit. Maybe I could get a promotion out of it, honestly, because I overheard them say we're going to need a call center for the online banking website. And I thought, well, I'm already leading one call center. Let me run something different. It'll be something new to learn. I ended up getting involved in that and I ended up rolling out that call center for online banking. And in doing that, I was responsible for designing the controls for logins, usernames, passwords, managing the software vendor that provided the platform for us. That was actually my foot into security, but I've always been deeply curious about human behavior. and why people do what they do, how the motivation works, how trust is built and broken. What really hooked me was realizing that security sits right at the intersection of those two worlds, right? People and technology. So protecting system back then might've been about a firewall or access control, but it's... You also, in understanding how threat actors behave, how mistakes happen, and how the bad actors think and operate. And to this day, I'm still fascinated by the amount of creativity, persistence, and effort that these threat actors put into their craft. I think the combination of psychology, technology, and real world kind of impact is what pulled me in, and it's kept me engaged for decades.


speaker-1: Let's shift to talking about challenges and challenges that you face.


speaker-0: When I think about the challenges in this field, mean, without hesitation, the most challenging aspect is the pace and the scale of change. ⁓ Threats evolve constantly, technology is shifting rapidly, and the regulatory landscape keeps expanding, right? So we're never really done learning. And that can be both exhausting and energizing. Right? So from a leadership perspective, it means building teams that are resilient, curious, and adaptable. I can't rely on static skills of, you know, two year old playbooks. You have to create room for learning while still running a highly operational program and keep those teams motivated. I think another real challenge is navigating the complexity in privacy and security regulations. mean, Liisa, this is where we partner with you to help us kind of navigate and translate those requirements so that we can execute something sustainable inside the org. We rely on you to help us interpret those requirements, pressure test the approach and make sense of what really matters versus the noise. As a CISO, I had to stop trying to be the single point of safety. Designing control so that the organization absorbs the risk, not my nervous system. Pushing ownership of risk into the business instead of carrying it myself. I cannot be solely responsible for the outcomes. I can't control. It was a lot of ⁓ collaboration with other CISOs. which has been extremely helpful, season. So I'm in a group where we share a lot of support for one another. And number one, just learning as the years have progressed that security is not an asylum. Privacy is not a silo. It's a business risk. And so I need the business to be involved because I know one. can take that on just themselves, or you're gonna burn out. And it's not gonna make your job very fun either.


speaker-1: So it's like finding that community, the external community of people going through what you're going through, then also bringing people internally on board that you can't do it.


speaker-0: have to be very clear about here's what I mean when I say we have this vulnerability, right? It's not tech speak. We've got to talk in the business terms. Here is the financial risk of not doing this thing.


speaker-1: I think this sort of leads us to the next question, which is things from those challenges where you've learned and you've added to your toolkit throughout the years.


speaker-0: That's a great question. You know, the single biggest lesson I think I've learned over my career is resilience. And I think it's so necessary ⁓ both personally and professionally, right? ⁓ In security, something is in cybersecurity, something's always gonna go wrong. A control's gonna fail, a risk is gonna materialize, a decision will look perfect. that looks perfect and hindsight's flawed. ⁓ Resilience means acknowledging that security is not about perfection. It's about preparation, response, and recovery. Why does a requirement exist? What is this risk we're trying to reduce? How do we implement it in a way that actually strengthens the business instead of slowing it down? I think being transparent, owning the gaps. learning quickly, continuously improving. ⁓ I think when I feel safe or the team feels safe, raises concerns early, security outcomes will improve dramatically. And so the cultural piece is just as important as any technical control for me.


speaker-1: So your sociology people background must help.


speaker-0: Yeah, it does. I think about how my team, I think about my every single one of my, my team members every day. And I touch point every day with almost every single day with every one of them. How are you? Anything you need from me? Any blockers? People need to be able to vent, talk, strategize. talk about their personal things and we have to have that connection. And I think that would be true in any role and for any leader. But in a high stakes, high stress, it can wear you down. And I think people need space to be human. I need to be very intentional and clear about what risks there are and what we need to be tackling and prioritizing and not just checking boxes. and not going to bed at night, staying up all night worrying. Bad things are going to happen. What we've done is we've exercised enough of a response that we know what needs to happen when the bad thing shows up at the door, right?


speaker-1: And you can't tell what that bad thing is going to be. So you've got to exercise that muscle of working together. Any parting advice that you can share from the challenges in the lessons that you have, the challenges you faced in the lessons you've learned? This is true for


speaker-0: you regardless of your role, but as a leader, staying curious and staying human is really important to me. This field in particular can sometimes over index on technology. And I think great security leaders understand people, communication and business context just as deeply. So don't be afraid to say, I don't know. And don't lose your sense of wonder. The threats will keep changing. The regulations will keep evolving. The tools will keep improving or changing. What lasts, I think, is your ability to think critically, adapt, and build trust. Remembering that security is not about being the department of no. It's about enabling the business to move forward safely. The leaders who succeed are the ones who can balance risk, opportunity, and empathy. Finally, the last thing is pace yourself. My gosh, this is a marathon, not a sprint. Resilience isn't just a program principle, it's a career strategy. That's my parting advice.


speaker-1: Shellie, we're going to stay curious, we're going to pace ourselves, and we're going to remember the people. Thank you so much for making the time to talk to me. I hope you enjoyed this episode of Compliance Chronicles, we look for guidance and inspiration from the personal journeys of compliance professionals. ⁓


speaker-0: Liisa, thanks so much. appreciate it.