Cybersecruity Talent Shortage, Neal Bridges – Query.AI
Neal Bridges, CISO of Query.AI, believes to fix the cybersecurity talent shortage, CISOs need to stop trying to “hire themselves” and instead acknowledge that college degrees, security certifications and previous experience no longer need to be prerequisites of entry-level positions.
Transcript
This is texturing TV. Hey everyone, welcome to another text drunk TV interview. My guests for this interview is the First Time guest I don't think we've had anyone from the company on before.
ai. I hope I got that right you did you did. You got it right Alan appreciate the intro.
Thank you very much. Not a problem. Hey, Neil, I guess let's start maybe a little bit with you.
ai. Well, give us a little bit of You background. Yeah.
No, absolutely. Thanks for having me on thanks for thanks for you know having me on the show, um a little bit about myself. I've been in cyber security for well over 20 years started back in the 90s hacking on my dad's IBM computer back in the day did a stand about 10 years with the United States Air Force where I did a lot of cyber.
It's been a good amount of time doing offensive cyber security operations for the National Security Agency also built the first functional cyber training unit for the for the Air Force where I trained most of what people you know have heard about through the Snowden links is you know, the modern day hackers at the NSA after that. I forgot out Force I spent a long time building red team type of operations for a lot of Fortune 100 companies that did a stent with a big four out of the Midwest where I built their red team and incident transformation practice and then I've LED security operations teams for multiple Fortune 100 companies in the space as well run my own business and I'm also host of The Cyber and security live stream on Twitch where we speak to tens of thousands of viewers, you know, every week, you know, regarding various types of cyber security topics and so been been doing a lot got a fortunate opportunity to come BC. So a query probably keep one of 2022, you know, two great Founders over there garage and Andrew asked me to kind of come and bring that years of experience with with cyber security to kind of help not just bring cyber security from a Cisco perspective into a budding startup and really trying security from the ground up but also bring that pract Missionary perspective to their product development side and make sure that they were building it with the with the with the end user in mind.
I love it. Excellent Man. Congratulations on a lot of those accomplishments.
Thank you mentioned queer where we both mentioned query that AI. You know just from the name, it's okay. What's the connection to see so and security?
Why don't you if you don't mind give a little Court background a little pitch to the audience about what query AI is all about. Yeah, absolutely. And this is something that's near and dear to my heart.
As you know, you've been in security for for a long time too. I've built a number of security operations teams, you know, just security teams in general throughout my career and the typical mentality right is you're gonna build a security operations team from scratches. Oh my gosh.
I've got technology all over my Enterprise. I've got to get Telemetry. I've got to get data.
I've got to get all this information so that my security analyst and my answer responders can look at all of that data and actively defend the Enterprise. And so how do we do that? We centralize all the data so that they can defend the Enterprise.
That's a very See mentality and two years ago before I ever had ever heard about query Andrew had come to me and pitched this idea of you know, you know centralized access to decentralized data without actually centralizing it into a Sim where you're bringing all the data together. So basically leaving the data at rest where it sits and being able to query that data exactly where it sits in a one unified query language and to me that was an amazing phenomenon because all the things that we deal with when you stand up security operations team where you've got 50 different query languages 46 different tools that you've got to have access to centralizing all your data and continuing to Dish money out year over year over year to centralize sim Solutions. Struck me right at the core.
And so when they asked me to come be ciso, I'd R. I was already bought into the idea. But it was also something that I would have immediately bought as a ciso in previous companies if the technology had been available to me versus the tens of millions of dollars that I'd spent, you know on Sim Technologies in the past and so it was a no-brainer for me because I was I was personally vested in the in the mission of the company and I think it's awesome that we're actually trying to break the mold away from traditional Sim technology.
Well look like you. I've been security a long time. Right?
It's almost the pendulum swinging the other way instead of just trying to bring everything into one Central Brainiac, right that is gonna make sense actionable intelligence of it, right? We we start You know analyzing the data. At its place where it happens and what needs to be taken care of can be sucked in or acted upon what doesn't can be stored or not.
And you know it just I mean we both probably know a lot of sim implementations where you know, seven figures respect and they and they failed and they just became shelfware. So they still they still fail to this day and I think that that's right. It floors me.
It's still a failure. Well, and now we well. Let's do this.
You want to get into it. We got no, I mean you look I remember when Sim meant like Ark site, right? Yeah, wait three years to get an integration into Arc site.
Yeah, and then, you know, you had the Q Radars and all that and then you got all these let's call them. com yet all these kind of devops enabled kind of Sims that are you know, basically Splunk, taking all the data in and analyzing that with security data and And I'm not naming names or anything, but it's still the same old same old. Right is it is and everybody keeps trying to build a better mousetrap, but it's the same model and it's the same shirt.
I'm very complex. Yeah hard damn thing to do. And yeah, this is this is why I'm excited for query because it's new and it's different and it's trying to fix the problem that Sim hasn't been able to fix for years.
And that we've spent a lot of freaking money, but that's not why we're here. That's why we're here today. Is it we'll talk about that another time.
Let's talk a little, you know, one of the things I have a unique seat where I sit now, right? I don't have to push anyone's product. I don't have to push anyone technology.
I listen I listen. I let people talk. So one of the things we hear a lot about is the cyber security shortage, right?
Yeah. We have 700,000 jobs open. We have a million jobs open.
We will never train enough things, you know. and there's a disconnect right? So I have kids who graduate or graduating college or just graduated last year before?
I can't tell you how many their friends called me. You know Mr. Schimo, I took cybersecurity in school.
How do I get a job? I can't get a job. Can't get a job.
No one. I don't have experience. I don't want to hire me.
I'm gonna get experience if I don't can't get a job and and you know, We're of an age Neo right when I got into security. There was no cybersecurity in school. It was basically the Porsche snook who didn't you know who got volunteered he was doing it anyway, right or he was the network.
I do it routers. Hey, that's right around if you do the firewall, too, that's right. And and that's how you got into security.
So it's different but but it doesn't seem to salt or it's doesn't seem to be solving our problem. You have some views on it. It's here I do and I'm incredibly passionate about this the you know, the live stream that I mentioned when you ask me what I do cybersecurity we speak to all walks of life of folks on a weekly basis.
And the number one question I get asked on that show. The number one question that comes into my DMs whether it's LinkedIn Twitter Instagram is like you said like you talk about with your kids, you know, and the folks that you you Mentor, how do I get into cyber security? And and what oftentimes happens is they hear these stats about 700,000 to 2 million?
I think globally, you know open racks for cybersecurity, but then they go and they take some courses or they take a certification or they get a degree and then they go and apply and then they can't get in and they're like Neil. You're a liar. Neil that's a farce there aren't 700,000 open wrecks because I'm not getting higher and so on.
I think there's a couple of problems when we talk about the talent shortage and and I've had I've had an ungodly amount of recruiters come on stream and I've put them in my hot seat to kind of talk to them about this this Talent shortage thing and it kind of kind of goes a couple different ways. Right? So first and foremost, there are tons of open wrecks.
There are no there are tons tons, but I think what happens is that the the people who come out of these education programs are really only interested in hacking. I brought I broad stroke that I understand that that's that's probably not a fair broad stroke, but the majority of them are only interested in hacking because we've done a fantastic job of glamorizing hacking and red teaming on the on the internet through TV shows and movies and things like that. So they think that cyber security is hacking And most of them want to come out of college and they want to go do a red team or a pen test or job and they think that those 700,000 jobs a job openings are directly tied to pen testing a red team and that's just not accurate whatsoever.
A lot of that has to do with you know. How we've positioned cybersecurity amongst the job Hunter. I want to flip that over.
I want to leave that there because we could get into a whole diatribe about that, you know mentality in and of itself the other side of the argument is the folks who are putting up. These job racks are misinformed and out of touch with today's cybersecurity education be a programs. They're out of touch with today's learner.
They're out of touch with today's people who are graduating high school because to your point you said it exactly when we were coming up and we're the csos now. We're the stock directors. We're the instant response directors.
We're the pen testing directors. We're the managing Partners at Big fours, when we came up cyber security was a bolt on you had to Google things you had to learn them on your own. There were only three certification programs that existed out there that you could get any type of certification on when it came to cyber security.
And so we've imparted what our beliefs are in terms of hiring on to the people that we're trying to hire and Just not the case. You said people can go to college now for cyber security which they couldn't when you and I were coming up but most people don't understand that most people don't understand the edtech space has grown from those three vendors that we talk about for to literally a hundred vendors that all provide the same level of training. I tell I tell folks this all the time when they when they let me sit on my soapbox talk about this is there is nothing special about Metasploit that Sans teaches you that CompTIA teaches you that ecouncil teaches you that offset teaches you control the same minutes Point too.
It's all the same medicine. You can learn it for free on YouTube. No doubt today you look he was afraid but here's the deal.
The most successful security people. I know were people who it was a it was a state of mental being right they like to break things and then try to put it back together in a way that wouldn't be so easy to break. Yeah a lot of security friends.
That's why you go to security conferences. You see the lock picking and you see all these are the kinds of things like that they of my generation they were into that. Yeah today.
People don't just pick up my display. Yeah, right. No, they go to the class from that exploit who somehow they hold up medically, you know, it's like break in case of emergency, but let me show you all of these other now, but here's you know, I always wonder is it a mismatch between what our schools are teaching these people and what industry wants Right.
So do you blame industry for having unrealistic requirements for these jobs? Do we blame the educators? For not giving people the tools they need is it both?
I think we blame Educators for different things right? I'll bash on Educators here in a little bit, but I definitely think our industry has failed. People around us.
Let's call spay to Spade. We have a lot of egos in cybersecurity and a lot of those egos from the old hats are what is gatekeeping a lot of folks from coming in. Oh, I got this cert and I didn't have Google to do it.
I didn't have YouTube videos. So therefore you have to go through the same pain that I went through if you ever dare want to sit on a computer next to me and that is a travesty that is a travesty the same thing can be said for degrees degree requirements left and right are being dropped. We see big four companies dropping degree big four accounting companies who are the highest regulated after surveys Oxley that are out there are dropping degree requirements because they realize that it's a gate keeping qualification that doesn't matter in cyber security.
And so I think the industry has failed itself the egos of some of the old dogs and old hats that are in this industry and I think I think that right there is the number one problem is to get out of your own head and realize that there Other ways to learn other certifications and and other ways to your point to find that creative fire in the belly to figure out a solution that isn't tied to a degree or a serve or a path out there. Let me give you two cents on that. I can see you there's gonna be a long one.
I mean we have to invite you back. We'll continue this. Here's the deal in my mind.
security people generally the whole security industry Suffered from impart suffers from imposter syndrome, right because we were always other we weren't really part of the IT team right those security people that weird freaking people here, right? Yeah. We were part of it we Yeah, we came under risk in some organizations.
And that was the CFO and that whole organization did not understand security people at all. You know, who's the weird dude in the kilt? Right?
So you had that so we were we were redhead step children. of many organizations and though we may deny it because we're hot s***, you know ego-driven Maniacs. We wanted to be accepted.
Like the same way the Ops people had Idol and itsm where the dev people had their scrum Masters and you know would have whatever the sir we wanted our certifications and we may we built up CIS SP and I look I have a lot of my friends and Jennifer Miller and others who are on the board there, you know chairman of the board for see if squared and Steven northcutted Sands was a great friend and not that they were bad organizations, but have those certifications kind of outlive there. They're usefulness here. I don't you know, what we wanted to do is build up to make this a real profession just like the It people that's notifications we had hours.
But at some point it cross the chasm and became certification for certification say you 100% right? Yeah, I get that. Hey, Don't want to bring someone in here who doesn't know, you know his butt from his elbow I get that right, but I also get that you bring people in and they learn on the job and if they're passionate about you.
Look, I'm an employer here, right? I run text strong. I will take passion.
Yeah over anything any day of the week in an employee because you can't teach passion. But this is this is where I want piggyback on that thread right? Because you know when we talk about out of touch Cisos, I think have forgotten that when they got to sit in that chair and when HR comes through and sets these unrealistic expectations because HR shoulders a lot.
I think we were to look at it HR shoulders 65 to 75% of this blame because they're trying to fit into some corporate monarchy structure of how job rolls and descriptions are supposed to be defined and outline and they oftentimes copy it case I'm going this is how we end up with three to five years of experience for an entry level role requiring a cisp. HR will come through and say well, what do you need? Well, I need this and it's usually an unrealistic set of expectations that come from the hiring manager will get to that here in a little bit too.
But they hand that off to to HR who says well if you need all of this, how much are you want to pay them? And so the hiring Angel says I want to pay them XXX, you know thousands of dollars. HR says well cool.
If you want to pay them that they have to be in this pay band which per our corporate structure says they have to have this many years of experience. To be able to get that pay scale and right that right there. There's there's no pushback that happens.
There's no slap on the face to HR that says you are defining something for the industry that that should not be defined. That way that is not been defined holistically by any level of organization that is just not reality for how we conduct jobs in the cybersecurity space, but nobody fighting sorry. com that's one of our communities right one of our sites.
Started that in 2014 devops really didn't become a thing till about 2012 right in 2014. They were looking at a higher devops people with five to seven years experience. There was doing it.
I mean, it's really yes HR. Has this kind of artificial scale if you will? But a good season unfortunately, I know a lot of Caesars who are not bad people.
Yeah, but they it's about covering your ass too. Right? And yeah, I didn't hire some raw kid who forgot to let you know watch, you know Ingress and egrets of information or something well, but if you got if you've got one kid watch it all of Ingress Ingress and I think you've got some function are you?
Yeah, you have some you got some process problems and I really just didn't interview yesterday yesterday relative to this interview where I talked about people process then technology, right? And so like, you know, if you hire somebody with fire in their belly and then give them the keys to the kingdom and forget to tell them how to protect the keys to the kingdom. That's not a fault of who you hired.
Yeah, they're certainly that too. Look, I'm not pointing fingers again, but a large part of it is also there's that the whole ciso. Profession if I could call it that it's still a relatively new.
Yes. Roll and varies from company to company and there aren't a lot of Clues. I mean the great Seasons really good sees those are great.
but there's not a lot of you know gradient as you go take this. Yeah, I would argue hard. I would argue cyber security as a whole is so relatively immature like we like this.
No, there are we're relatively immature. Would you compare us to other other career Fields? I agree with you 100% Neo.
This was the this was a 20 minute 15 minute conversation. I'm afraid we're gonna have to have you back on we we can talk about this we can talk about a bunch of stuff. Love to have yarn absolutely.
Got it kind of ended I got people coming in the waiting room. It was a pleasure. Thank you very much for having me.
Absolutely. Hey real quick before we go though. ai, that's the website right?
Yes, sir. Okay, so you go check it out. You can follow Neil there and you're wearing the twitch.
Cyber, and cyber insecurity on Twitch. All right, go check that out as well Neil. Thanks a lot, man.
We'll have you back. God take a break here. No problem.
We got to think of break here on Tech strong. We're gonna be back in a minute with some more guests. Take care.