Federal CISO Greg Touhill discusses how the private and public sector should manage their risks when it comes to cybersecurity and IT.