Optimizing Security Strategies with Andy Ellis – CISO Talk EP 41 (Part 2/2)
In episode two of a two-part series, CISO Talk hosts Mitch Ashley and Jennifer “JJ” Minella, continue their conversation with Andy Ellis, former CISO at Akamai and current operating partner at Weill Ventures. They delve into topics like building security teams, adapting to change and the impact of AI on the security landscape. Andy emphasizes the need for organizations to understand the value they aim to produce and to align their security efforts with that objective. He discusses how AI, particularly large language models (LLMs), can change the dynamics of software development and security, ultimately advocating for a shift toward safety engineering to minimize attack surfaces and improve defenses. Andy also shares insights from his book and offers guidance on how to navigate the evolving cybersecurity landscape.
For more information and to follow Andy Ellis’s insights, you can visit his LinkedIn or Twitter profiles (@CSOAndy) and subscribe to his newsletter at https://duhaone.substack.com/ . Andy’s book “1% Leadership: Master the Small, Daily Improvements that Set Great Leaders Apart” can be found at various book retailers, and he also has an audiobook version, narrated by himself, which offers an enriching experience for the readers.
Transcript
Hi, thanks for joining us on CISO Talk, not our regular introduction, but this is actually the second half, part two of a two-part series interview that JJ Manila and I did with Andy Ellis. Andy Ellis is a former CISO at Akamai, and uh, he worked there for a number of years. He's currently at Weill Ventures, his operating partner there.
We're gonna talk about some different things here. One, one of the main things we're gonna discuss is how to build your security team. Some of the lessons that he's learned from that, a lot of it went into his book.
Um, and also how do you, do you hire people for skills? Do you hire 'em for learning ability to hire 'em for their adaptability? What's the right mix?
How do you make sure you're building not just the right team you need now, but the one you're gonna need down the road? You're gonna join us in progress right now in our conversation with Andy. I want to take a little bit of time and touch on your book and your thoughts around building security teams, security organization, I mean, all of your, your wealth of experience.
I'm sure you did some things right and you learned some lessons the hard way. Um, I did, you know, what, what are some guidance and sort of tips or pointers you would help people with? How, especially today?
'cause everything is changing, right? It's not like you create this static organization and we're all good. We just kind of keep an eye on the lights and, you know, we're happy.
We're far from that. So at a high level, you should understand the value that your organization is trying to produce because that's what organizations exist to do. And so all leadership, all management exists in that context, which is your people bring energy, you're using that energy to create value.
And most of what leaders do is screw around with that energy and waste it. And so most what you're trying to do is like, how do I get people to bring more energy? So how do I make it that, look, if you've got a 90 minute commute to get into the office, why am I forcing you to return to work?
Because that is energy that I'm p*****g away. 'cause you're not just gonna give me, you know, three hours a day for free. Like that's gonna come out of the energy you would've given of doing work.
Mm-hmm. Um, you know, how do I build an inclusive workforce so that you're not looking around every day going, you know, do, do they really want me here? I'm the only woman in the room and, you know, and, or I'm a parent and I get all these meetings at 8:00 AM and 5:00 PM how am I supposed to get my kids to school?
Right? So building, and that's just like support the individual and then it's how do you make sure that you're developing people so that they can produce better value with their energy and aligning them to the right work. Um, but the biggest one I like to give people is when someone leaves your organization, never replace them.
You do not want to try to bring in that same person. It, once you believe that, first of all, it teaches you that when you have somebody, everybody in your organization should be training the people around them to do their job partly so they can get promoted. Like, oh look, if I don't need you to do the job of a, you know, security engineer, I can promote you to senior security engineer.
'cause we taught other security engineers. But when somebody leaves, you take their money and you say, what do, what gap do we really have? What can I really go use this money for?
And often it, you'll be surprised, I like to go ask my team, um, you know, what should we do with this money? And there was the year in which every one of my direct reports said, go get yourself an administrative assistant. I said, that is the most valuable thing we could, we could have out of that money is somebody to manage your calendar and to manage like the things that you do.
And actually, I did the math and I'm like, oh look, an administrative assistant cost a sub substantially smaller fraction of what I was making. And I looked at how much of my work just went onto the assistant, literally paid for herself just in productivity for me, let alone the rest of my team who could say, Hey, I need to meet with Andy. And she would make it happen that day, like reducing friction.
Um, or it's a program manager because you need somebody to go coordinate with engineering to fix problems because your researchers are great at finding problems, but they're not so good at the people skills. So high level, when you look at building an organization, like figure out what you're weakest at and get better at that 'cause because getting better at what you're strongest at isn't the value multiplier for an organization. Like for individuals.
It's fun. Like, we like to min-max, we like to be the best at something, even if it means we're not good at something else. But for organizations that creates really huge gaps that destroy value.
And I have a like weekly newsletter. If people want like very short tips, they can be on my weekly newsletter and get these really short pithy tips once a week. Well, I refer to JJ as our CISO whisperer.
Um, how does, how does Andy's recommendations jive with, with, as you talk to CISOs and security organizations? Oh, um, I, I think Andy's approach is different, which is why I like talking to Andy different in a good way. Um, and you know, one of the things I've really appreciate, appreciate about Andy just as a human through the years and a leader is that, you know, if you talk Andy, he's very direct.
Uh, he's very clear. Um, it may, it means sometimes he may seem very blunt. Um, but it comes from a, a place of, of grounded and, and sort of like empathy and compassion.
Like he's is explaining, you know, these are the things to consider when you're building and developing a team. You're not encroaching on them trying to, you know, live their life and, and handle family obligations. And just being aware of that.
And so I think, you know, how he approaches a lot of problems is intuitive and comfortable to me. Um, and so I I look to him for a lot of guidance. I think it is a lot of these are areas that a lot of CISOs are struggling with because they, you know, they're, they're, they can't say, well, I was a, a CISO of a, a fortune, you know, rated company for X number of years and you know, I've, I've been through the battle.
I've proven myself and, and built these teams and checked these boxes. And I think a lot of CISOs are, um, even without the title, but, but a lot of people with the title even came out of a different pedigree and a different background. And they, they came out of a world where we've been told as usually as technologists and professionals we're supposed to have the answers.
Andy said, you know, let me show you how smart I am. Let me show you how right I am. And I think to be a leader, not a manager, not a, you know, but to be a leader with humans requires you to have a different approach and a a different way of dealing with other people around you, um, with projects, with skills.
Um, and so I think that that Andy's further down the path with his, um, with his guidance. And I think a lot of us are trying to catch up to that and, and take that wisdom and things like, you know, a lot of the little, the little pithy comments, um, and notes that come outta the book and that weekly email are just great. 'cause it's a, it's a short little thing and it's almost like, um, having the little calendars when we used to have the little, the little like real, the paper calendars where you flip the thing and it gives you some little, the quote of the day mo Yeah.
A quote of the day. Um, it's wonderful to just kind of reset your mind and go, I don't have to be the smartest person. I don't have to know everything.
I don't have to be right. I have to educate myself and develop my personal skills to make the right choices for the company myself and my team. I love that summary of that, of my, of my book and the philosophy.
'cause that's absolutely what it is. 'cause let's say that you could follow JJ around for like five years and document j's leadership stocks. She's a great leader.
You see her in a lot of different places. You could have this template for how to be jj and the only person that template would be helpful for is jj, right? If you tried to take that template and said, everybody follow this and go be a leader.
Like you don't have j's personality and experience and like you have different styles. Like there's pieces you should take out of it and say, oh, I like how JJ does this. Can I do that?
But you shouldn't try to be someone else. And too much of the leadership training that we try to give people is, oh, read this autobiography and be like this person. And that's not really helpful.
So it's just get a little bit better. You don't have to be the best at anything, but find the things you're not great at and get better at those. I think if you're always the smartest person in the room, you're in the wrong room.
You didn't, you didn't hire well. You know, that's really truly what your goal is. You know, there are a couple other things I wanted to run by you, Andy.
One is, I think one of the roles of leaders is to, I call it the raise periscope moment, is looking ahead. We, we kind of know from some experience and wisdom, hopefully we have, we kind of have a sense of, of these things happen or, or going to happen, um, potentially. But let's let somebody's gotta look forward a couple, couple, you know, months, years, whatever it is, down the in time and say, okay, where, where are we gonna be here?
And what, what is likely the issues we're gonna run into that we might help smooth out to make the path easier when we get there or respond, uh, differently if we need to. And the other one is, is not teaching people to be, I want to be X but helping people understand, uh, how to change because our environment changes. You may wanna be the best at that X, Y, z you know, zero trust architect, blah, blah, five years.
It may not be that it may be something else, right? Or, or we, we do that differently today. Mm-hmm.
And now let's talk about where, where we really need your skills. 'cause that's, that's changed. So every one of those kind of, somebody went away.
Is there a time to rethink and redesign position organization, little or large, but change is, change is a big thing and if you're not preparing for it, your folks are not prepared for it. Yeah. So it's the, one of the ways I look at it is that you can try to look into the future and it's really hard.
Like crystal balls are very muddy. But what you can do is recognize that the future will be different than today. Mm-hmm.
And be ready to recognize the changes it happens. So you don't have to be the best forecaster to be like, oh, the world has just changed. What do I need to do about it?
Let's take open ai, right? That all of a sudden large language models are a thing and everybody's like, oh my God, like, and we can use this. And really all a large language model is, is computer-based outsourcing.
Like everything you ask OpenAI to do is something you could have outsourced to a human. Now you can outsource it to an ai. And look, I have my slides generated by a company that, you know, has low paid workers, uh, in Indonesia.
And I have to do a lot of work on the slides when they come back to me. They do great design work and then I have to tweak them. OpenAI basically lets me do the same thing for content.
I can outsource it to somebody who can write lovely 12th grade English, but does not have any, doesn't have the same insights I do, I've gotta do work on it. But if you're sitting, when open, when OpenAI becomes a thing and saying, oh, I don't have to worry about this for a while. Like, that's the change moment is when you see the world's about to change and you say, what am I going to do to pave the road?
And I hate when people say put up guardrails, because that's what everybody goes to. They say, well, how do I put up guardrails? And the answer is, if you put up guardrails where there isn't a road, it doesn't matter.
'cause people are driving cross country, the first thing you do is pave the road, then you put up the guardrails. And as security professionals, how are we actually enabling the business by saying, here's how they'll use it. Like how many people, when they got asked, what should our open AI policy be?
You know, or talk to their C M O and said like, here's what open AI is good and bad at let's ignore leaking of secret data. 'cause the C M O doesn't really care about that yet, yet, but let's talk about brand damage for, oh, we had to open ai, go write all of our blog posts, but nobody proofread them, right? No, we have open AI and it's like having five outsourced, you know, content writers.
But we still need a content manager and we still need to run the past, you know, content marketing and product marketing to be like, is this the message we want to get across? And then we could say, okay, now that we've done that, when you're gonna talk, put, put out a blog post about something material, you have to think about like, is this disclosed accidentally? Because, you know, a week before it became public, you handed your s e c filing to open ai, right?
Mm-hmm. But if that's the first conversation you have, people gonna be like, we would never hand our s e c filing to open ai. Like, we all know somebody will do, Somebody will do it, Somebody will do it.
But first let's build the road for how to use it before we put up the guardrails. So a good example because, you know, open AI and LLMs, uh, the, you know, very large ones like that versus ones that are a little more na narrow or domain specific. Mm-hmm.
But even so, it's like you, it's the first draft. Don't treat it as a finished product. You, you want to then absolutely adapt it and you can prompt engineer it to get it closer to what you want, but you still need to make it yours.
Right? So you aren't gonna take the slides coming back from an overnight work that's been outsourced and just plop those in your, your talk that day. Right.
You want to Yep. Make sure it's saying the what you wanna say the way you wanna say it. Yeah.
And there's a great quote from George Marshall that applies to this whole concept of being ready for change. That didn't make my book, but it was one of the propo, one of the, I had a list of quotes I was gonna put in from other people that none of them made, almost none of them made the book, but I've got a, a sheet of them and it says, keep your witts. And he, he's, he's given this to junior officers and he says, keep your witts about you and your eyes open.
Keep on working hard. Sooner or later the opportunity will present itself and then you must be prepared both tactically and temperamentally to profit by it. Mm-hmm.
And so what he's saying is like, build your skills, have a lot of capabilities, and when that moment comes, you have to recognize it. You have to have the skills to exploit it, and you have to be willing to put in the work, which is drop what I'm doing and go do something else. And what's amazing is people who, who live this, who do it, get a reputation as being forecasters.
Like, people are like, wow. How did you see that change coming? Because you were ready for it.
The answer is because I was ready for everything. Mm-hmm. We had in our, in our disaster response plan at Akamai, we had scenarios for different types of disasters.
And one of them was what we called the slow moving zombie apocalypse because we actually cared about outcomes. We didn't care about the scenarios, but we had an auditor who was like, you have to give real scenarios here. And we said, well, what if we had some reason that our building was available, but people couldn't get to it.
Our employees were stuck at home, but could work. So it's not like a blizzard where they're stuck at home and they're out shoveling snow. No, they're stuck at home and they're bored.
So we said, we called it the slow moving zombie apocalypse, which is, they're zombies, they're slow moving, they're not actually a threat to you. Um, but you have to work from home for an extended period of time. And we, we had a disaster response plan for that.
It looked an awful lot like C Ovid 19. And so there are people like, well, how were you prepared for it? And the answer is, well, like we had just looked at like, how do we have the infrastructure that let people work from home?
And how do we make those decisions? Because people have to work from home all the time. Like in New England, in fact, there's one day a year that basically every company, nobody comes into work the first, you know, bad snowfall of the year, you do not drive.
The roads are a disaster. Everybody works from home. Okay.
If I'm ready for that, I'm actually ready for Covid as a company, right. If I say, I want you to be able to work, but if I said, oh, look, I'll just take the day. Nobody actually will work.
Well now you're not gonna be ready for something like Covid in the lockdowns. I thought you were gonna say, you know, like the day after the Patriots won, or, Oh, actually, actually the worst days for, for productivity in Boston Sports is not the Patriots. It was actually the, uh, a L C S in 2004 when the Red Sox beat the Yankees the last four games because they were down three, nothing.
Oh yeah. Remember that? And game four through seven went to like 13 to 15 innings.
So like, wow. People were up until two, 3:00 AM watching these games. And they were, they were the zombies.
Like you had to be prepared. So it's, but it's days like that where like, I had people who were coming in like the fir first time. Like they show up for like a 9:00 AM meeting.
I'm like, why do we not just cancel this, this, these meetings? Like, why are we having meetings during playoffs in the morning when we know people are gonna be up late? Like, we're not gonna get any useful productivity out of you, so let's cancel 'em.
Well, we're, we're running close on time. Um, you mentioned, we kind of got into the AI field. Just I appreciate your thoughts on how do you think AI changes the security world for security people?
So I think AI is gonna change things, and we have to be careful when we say ai, like are we talking about LLMs N L P expert systems? You know, there's so many different pieces of AI and we haven't even gotten to general purpose ai, which is really what I would pay attention to. But I think that there's a lot of innovations that have happened that are about accelerating value production.
And you can think about open source means that developers aren't writing as much code, they're just inheriting code. Um, but as a security professional, the same amount of code is going out of the door often with more vulnerabilities because it was written by some rando in Nebraska who might or might not be actually maintaining this anymore. Um, cloud did the same thing for us.
Like, oh, look, we don't have to deploy infrastructure because it's just sitting there for us, right? DevOps was, oh, let's get rid of, you know, the, the painful waterfall program code is getting out faster. I think we're gonna see the same thing with AI that LLMs let people write code faster.
And almost every code writing platform now has an AI assistant to help you with writing code. The faster things get written, the faster they get deployed, the more work there's gonna be for security teams. So what about the other side of this, which is that, um, you know, I've, I've spoken to, to people and I, I think, you know, like everybody else in the world outside of the tech and cybersecurity, we've seen things creeping in.
We've seen social media with, you know, facial recognition algorithms to auto tag post. We've seen, um, things with AR and vr, uh, technology in the headsets. But I, I think I'm just now learning and understanding how far and how trainable some of these are when they're loaded with kind of custom, custom, custom content.
If, if you would, like, you're, they're taught almost like you would teach a student or a professional and grooming them for, for a certain, um, kind of role, whether it's offensive or defensive. And so, you know, talking to researchers and hearing how some of them have, you know, taken these platforms and, and llama and trained them based on capture the flag scenarios and, you know, actual inputs and outputs from that and, you know, tuned each one for different skillsets and then almost pit them against each other and building these, these kind of digital virtual worlds. You know, I'm kind of concerned about how, how quickly we, because the whole change, uh, the whole change thing, which is how, how fast are we on the defender side gonna be able to adjust and use and build these tools against protecting, uh, protection against the offensive attackers who are going to be developing them who have nothing else to do.
Right. So I think our goal should not, should be, to not be in that job that I think the model of security as defenders is a losing proposition because the, the attack surface we have to defend is growing so fast. And as you just noted, the adversaries have better democratization and scale than we do.
Our job needs to be to be getting out of the role of defense and into the role of safety engineering and working with the developers to do it right. You don't want to have a big attack surface you on a minimized, hardened strong attack surface, which means we have to change the way software is built and deployed. And it's not that we're trying to cover for it after it's out there, right?
The more security defenses we need to add is just, it's a complexity problem that just points out that we're, we're sort of chasing the wrong thing. Mm-hmm. And so my vision and it, it's never gonna happen, but that our career field should go away and be just a subset of quality or safety engineering.
Like, oh, let's help make sure things are going right. When you think about Zero trust, and I'm a huge fan of Zero Trust, and I know the name like kind of exploded, but if you look at like, you know what Google Beyond Corp did, what we built at Akamai was about changing the attack surface to minimize the things we had to defend. It was not about building better defenses.
It was, oh, let's make sure that all authentication is cryptographic, not memory-based passwords. Let's make sure that that authentication is tied into the application and not just the network substrate. Like let's do all of these things that are good safety engineering, and now we don't have to defend against a whole category of attacks like an adversary who's coming after, you know, login isn't going to win because unless you have the certificate that's on every device, like you can't social engineer login at that point.
So you have to eliminate the avenues of attack. And I don't think we're focused on that enough. Yep.
Aj I think we need to label this part one of 10 or something. Do we get Andy back here? I'll happily come Back.
We'd love to have you back. I wish we had another hour, uh, to keep going, but yeah, it'll be fun and things will have changed by then too when we Absolutely. It'll be cool.
I'll say that last Andy you had was completely wrong and here's the new way to do it. Yeah, Yeah. We have some updates.
It's, it's the, uh, the next, the second edition of the book, the Andy book. So. Well Andy, thanks so much.
Um, where can folks follow your, your newsletter, your daily, um, email, that kind of thing? Yep. So easiest place is go find me, I'm c s o Andy, whether that's LinkedIn or Twitter or Instagram, uh, Mastodon, blue Sky, you name it.
I'm, I'm pretty much everywhere. I'll admit I don't post on all of those fringe networks that often. Uh, my newsletter, it's both on LinkedIn and on sub stack.
com. You can subscribe to the newsletter, but I do post it every Monday morning on link on Twitter, like it comes out and then I retweet it. So you can always just wait for that and, and then follow it.
And of course you can find my book everywhere you buy books. Um, or you can get the electronic version or the audio book, which I read. So if you've enjoyed listening to my voice, maybe you get the audio book.
Great voice. You do have a lovely, a lovely reading and announcer voice, Andy. Thank you.
It's very, there's some good audio engineering as well. And I had an amazing producer, like a professional audiobook narrator was in my ear the whole time I was reading the book. Mm-hmm.
Oh wow. And so he would literally stop me and he's like, I don't like the way you said that sentence. You put the emphasis on the wrong word.
I think this is what you're trying to get across. Here's how you should think about saying it. It was amazing.
Like I upleveled so much in that 11 hours of recording in my book. Oh, wow. Oh, and Mitch, I think on a, on a subsequent, uh, we'll have to have Andy back soon and, and look at his in-home studio, which is pretty impressive as well.
Okay. I'm all game for you. Yeah, I've got a whole green screen studio about 10 feet behind me over here that I can do video recordings in.
Sounds wonderful. Yes, very. It's a show and tell on gear.
Well, thanks again Andy, jj, always fascinating and fun and, uh, I thoroughly enjoy doing these with you. And, and thanks for bringing Andy to us and reconnecting. So we'll figure out when we can have you back.
So thanks everybody for watching tuning in and be sure to check out Textron tv. There's a lot of other episodes for CH CSO talk and other programs too. So have a good day.
Hope to see you soon.



