Techstrong TV – May 1, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi, everybody. Welcome to the live stream that's coming to you from RSAC here in San Francisco, California 2025. Uh, we're having a great time at, uh, the conference this year.
Kind of feels like we're back to full force. Our RSAC that I remember. It's really, uh, a pretty amazing stuff.
This is the segment we're calling the analyst arc, and we're getting three of us together, my two colleagues and myself. Yep. Uh, Krista Case, uh, who covers data, data protection, identity management, all kinds of great things.
Security, right? Yeah. Yeah.
And, uh, Fernando Monte Negro, thank you. Who covers Cloud Securities Cybersecurity. Yeah.
More broadly. Yeah. So Many areas.
And then I contribute on the kind of software security side. You Are, you are too kind. You are, you are a leading force on the, on the, on the software security side.
You Know, we all, we all are, are leading forces in our Yes. That's what's good. Is that ni it's a nice triumvirate.
Yeah. Yeah. Good things.
So one of the things we, we want to try to do in our conversation is help folks get a sense of what we're getting a sense of, right? Mm-hmm. So this first segment, we're calling the vibe.
Yep. Like, what's the vibe? What are you picking up today?
Maybe a continuation of what you saw yesterday, maybe like, oh, you know, I'm kind of sensing a little different thing going on here. Ladies first go. Okay.
Sorry. You know, he's gonna call on you. He does the ladies first.
So That is very true. Very, very true. Um, so yesterday, you know, I kind of talked about the need for, for cyber resiliency.
I spent a lot of time a couple days ago with some of the storage and data protection companies yesterday, from my end was a little bit more on, on the identity side. You know, Mitch, as you referenced, that's an area that I am covering. Um, this is sort of my RSA debut on the identity side.
Um, so there's been a lot of conversations around kind of the ability to create this platform for identity security, you know, so we're seeing companies, um, start to kind of stitch together privilege, privilege, access management with identity and access governance, for example. Um, to be able to, you know, escalate and deescalate privileges in real time as needed. Um, and really kind of have oversight and control over that whole process.
Um, obviously we have to start thinking, you know, much far beyond human identities. We need to expand on the machine side. And now we have that whole age agentic ai.
Oh, okay. I know I threw the age agentic in there as well. Thank, thank you.
Just for you, Fernando. Thank you. Just for you.
I appreciate it. Um, and then we have these, these agents now coming in and kind of mucking up the whole thing, right? Because they kind of bridge the gap almost.
They act a little bit like humans, but they have many qualities, um, of machines including needing to be managed at massive scale. Um, so That's, so you've seen momentum around identity of agents themselves and that coming along, It's, it's a topic, right? Okay.
I think, I think we're still getting there. Um, but the sense that I'm getting is the vendors are getting questions from customers, right? Mm-hmm.
About, okay. It's a reality that we are ultimately going to have some of these AI agents playing an important role. Yeah, yeah.
Um, in our business processes. And so what are some of the new security imp implications, um, that are being created as a result? And how do we start thinking about addressing them to get ahead of it?
Fantastic. How about yourself? Uh, uh, we had a chance to go to do some, some, some, some meetings together.
So I also learned a little bit about identities. And one of the things on the identity side that I like that it's interesting, the, the NHI stuff, the non-human, it's interesting and ties to software security, because it seems that NHI is kind of, uh, riding two waves, right? The first, we, we were kind of already talking about workload identities and whatnot when we were talking about like service accounts and, and mm-hmm.
And then we started the microservices path, right? And now, now it sort of picks up on the, the, the, the, on the agentic side. So it's really interesting.
Yep. And, and Kristen knows her stuff, so I, I, it was nice, it was nice to follow her on this. Some of the stuff that I was looking at is, we were talking to a lot of vendors, again, security platforms a little bit more on the, on the security operations side.
Mm-hmm. Mm-hmm. And one of the defining, as we look at the market, like at how people, and, and we have data on this now, like, uh, uh, sorry, I can't quote from memory, but, uh, we just released some survey data where there is a preponderance of respondents indicating that, yeah, we want to consolidate, we want to, we want to reduce the number of vendors and so on and so forth.
And what's somewhat consistent between the, the vendors that are picking up on that consolidation. One of the things that's really interesting is that many of them have a security operations, uh, component to those platforms, right? So one of the things I'm going to be watching is how do other platforms that don't necessarily have a security component, a security operations component to them, do they build, do they buy?
Mm-hmm. Right? Uh, so that ties, uh, we are talking about the trends.
Yeah. Sorry, didn't mean to, I was just nodding a lot. And it goes back to the platform conversation that we were having here in this segment yesterday, right?
Yeah. And build by, or even have extensibility to be able to integrate with, you know, a SIM platform, for example, or XDR. Yeah.
Yeah. And, uh, and, uh, uh, I, I like to talk about the dimension that there is. It's not the platform best, best of breed.
It's a platform versus a point product. The other dimension is best of breed versus good enough. There is yet a third dimension we don't often talk about, which is, do we do it ourselves or do we bring in a trusted partner?
Mm-hmm. And I was having a conversation just at breakfast today with someone else, uh, adding a dimension of the, the, the, where the customer journey is, right? If you're a smaller organization, you're going to focus more on one type of delivery, one type of, uh, capability.
Whereas if you are a much larger company, you may have already built some of those capabilities. But now, from an economics perspective, sorry for the hands, uh, uh, that's, that's fine. You are, you are now, you are now, uh, offloading some of that to a, to a to a services partner, right?
So, fascinating conversations like this industry is maturing. Uh, it's growing. It's, it's getting better right before our eyes.
Sorry, I got excited. No, no. Hey, absolutely.
You know, something, something I've kind of been thinking about, and I'm starting to see the evolution of is AI in our space and also in, in other products and technologies, is going through this phase of kind of bolt-on, where it's not really part of the product, but it's, it's there, it's a chatbot, it's a whatever built in. And there, it seems where we're kind of entering and getting into that phase of how do we build in more AI into the technology and the workflows into whatever it might be, or securing ai. And, uh, I don't know that we're here yet, but it's like AI designed, designed for ai, or with AI is the next phase.
I don't know if you're seeing that yet, but I'm peel people talking about inklings of it that sound like that. But we're, you know, I think we're still very much of that. Let's, let's really start to get value from ai, not just feature iis, but what does it do for us, which is kind of this built in phase.
So picking up on that just for a second, I had, I, I, I had a conversation with, uh, with a platform vendor. We, we were there together. Mm-hmm.
Right? And one of the things that they were, uh, very clear on is they, oh, look, we've built this platform with, and, and machine learning and AI from the ground up. Mm-hmm.
Right? And it shows that they have efficiencies in, in, in, in some areas and so on. So Yeah, absolutely.
When I came here this week, I, I said that, uh, uh, telling myself that my mission is to discern between basically three types of ai, uh, how we, somebody has an AI message, they probably fit into one or three buckets, right? Hey, we are just AI washing, right? Mm-hmm.
To your point, it's, it's something marginally tangential to ai, oh, we are AI death. Mm-hmm. Fine.
There, there are some of those, right? Then the people who are saying, look, we are here to, uh, to use AI in our products, or we are here to, uh, support how you as a customer you are using ai. Mm-hmm.
Right? And to that extent, I think if I had to, so the, the, the, the one big news I would call out that it came out on, on on Monday, right? Is when, uh, Palo Alto announced the, the, the, the protect ai, uh, position, right?
So that's that. Uh, I, I, I would, if I had to pick one deal for the week kind of thing, I think it would probably be that one. Mm-hmm.
But exactly to your point, where does AI fit and what are we doing? And, and yes, Another big part is over and over data, data data, right? Like kind of why are we doing all this?
Right? It's, yes, it's application security. Yes, it's XDR.
Yes, it's yes, infrastructure, but it's really about data. That's what, that's what we're trying to both utilize Yes. Contextualize for ai.
Yes. And also, of course, protect. Right?
Right. You can't lose that stuff. Yep.
Yep. A hundred percent. I mean, at the end of the day, it's, um, your AI models are only as good as the data, you know, right.
That they're being trained on to start with. And then the second component is being able to, um, you know, keep your data secure, um, you know, throughout your usage of ai. So, you know, last year it was a lot about, okay, you know, if I am using an AI application, can I potentially access sensitive data that I'm not supposed to have access to?
Um, and I think this year it's been, um, you know, kind of an evolution of that conversation around, um, some of the new attack vectors that AI is creating. So absolutely, I would say data security and in privacy at the end of the day, is really at the heart of it. Um, I would say another component of the equation is the, um, kind of compliance side of side of the house, right?
So this is all happening so fast that we're still, um, developing best practices and industry standards. And so, um, I think the implication on the tools and processes that are needed for data security and privacy in this world of AI are still, you know, being learned, um, almost in, in real time. We're almost, you know, building the airplane as we're trying to fly it mm-hmm.
So to speak. Yeah. Considering we're, many of us are going in airplanes right now.
I'm not sure I like the analogy, but that's okay. Fair Enough. Fair enough.
I'll give you, I'll give you another analogy that I thought of this morning, and that was this. We're at this stage of the CEOs of the world are funding quest. They're funding exploration into the new world of ai, right?
Kind of back to the magellan's and the back to the, you know, discovering the Americas, um, where people are putting money, betting money on AI and funding people, teams, boats, ships, weapons, all the things we need, navigation systems, whatever it takes to go, we don't know what, what it is we're gonna discover. We're trying to figure out what to do with AI and whether it's real benefits, could be and will be, but we're funding those things. And then the usms of the world are the folks on the ships saying, all right, we're headed this way.
You know, compass is point in there. We think we're gonna end up in India, but we're not sure. And we'll discover what we discover.
And that's kind of the journey that we're on right there. There are things we know we want to be able to use AI for, but there's a lot we're not sure about AI either how to get there or what we might use it for. So I like, you know, we all use the airplane analogy while we're flying it.
I think that also works as a kind of applicable metaphor for this. Yeah. Oh, absolutely.
I that being fed, why let, let's continue with the discovery analysis, right? Great. Uh, where while we're doing all of this discovery with, while we're failing towards unknown waters with ai, right?
The, those ships that we've built, they also have to protect against pirates. Uh, uh, uh, so they all, They, they can't burn down while we're on Yes. They can.
They can't burn down. They, they have to be protected against pirates. Yep.
Yeah. Uh, and at, uh, uh, we have to, they ha as they stop at ports to buy supplies, they have to have the funds to do that. Right?
So there's a, there's a, there's a sustainability aspect to that. But what I'm, I'm, I'm picking up on a lot is the conversation. And, and, and you're absolutely right on, on the use of data, but the, the data and the AI conversations also gives cybersecurity as a whole, uh, a phenomenal opportunity to get closer to the business.
Mm-hmm. Right? We keep saying Yes.
How does security tie to the business, again, sorry for the hands. Um, and, and, um, data and identity, right? They are the fundamental constructs through which business inter interfaces with information, right?
Uh, uh, a marketing manager doesn't care about files on a Google share, or what they care about is, okay, are my, uh, uh, are my marketing plans faced, right? This distinction is interesting because I used to cover, still cover, right? Uh, uh, what people call zero trust network access, right?
I always thought that the end should be silent. Someone doesn't want to give access to a network. They want to give access to the applications and to the business value that you get from that connectivity, right?
So it's, um, AI and data give us this opportunity to, you know what, let's get, let's know how business works. Let's support them better. Yes.
Yep. I think they definitely are business conversations. And so it's how do we understand what the business objectives are at the end of the day, and then what tools are needed to facilitate that?
So, you know, you bring up an excellent point around kind of identities and data. So it's all about understanding who the user is, what do they need to access and why, um, and how do we, um, you know, again, facilitate that in a seamless way, um, for the user, um, without kind of getting in the way of, of that productivity. And I know obviously it's very much the same on the developer side mm-hmm.
Of the equation. I was at, um, a lunch for a vendor yesterday, and they gave out these little shift left, um, little keys keyboard, um, thing, which is, which is very cute. But, um, yeah.
So it's, um, I would say that's a very big part of the conversation. And another part of the equation is how do we, um, you know, get a, get our arms around, um, all of the different applications that our users are using at the end of the day. I had a conversation yesterday about chat, GPT, for example.
How do we really get our arms around how our users are actually using chat GPT? How do we make sure that we can lock down, you know, what they're sharing, how they're using it mm-hmm. Yep.
In a way that allows them to do their job, but at the same time does not expose our business to more risk. Well, let me, let me ask you, so kind of heads up, 'cause I want to end with a question of what, what do you think we'll be talking about at RSAC 2026? So be thinking about that in the background.
Yeah. I'll, I'll, I'll, I'll, okay. So, so give you a little chance to think about that.
Let me, let me ask you, do you think AI is getting in the, the whole focus on ai, is it getting in the way of our security job? Yes, we need to secure ai, but is it defocusing this from core business around security? Is it bringing maybe more attention to security?
Is it, is it a help or is it a detractor? I mean, what are your, what are your thoughts on that? I think it's a little bit of a double-edged sword.
Um, you know, I think on one hand it is, um, shining light on some of these very pressing security problems. Um, I would say it's also giving us new tools to get the job done. Um, so it's definitely a double-edged, double-edged sword.
Um, but I, I think at the end of the day, it does have the potential to be a net positive. Um, but it's all about how do we think about using AI to do our jobs more effectively? So for the security operations center, we had a conversation yesterday around how do we use it to almost upskill our security analysts mm-hmm.
For example, and allow a more junior security analysts to perform on a more senior level. So that's all kind of net positive, but obviously it does, um, create a lot of noise, um, and certainly introduce more risks. Great.
Yeah. On a, on a more whimsical note, I think I'm, I am not sure if I mentioned this yesterday. I'm, I'm Brazil Canadian.
The, the I, uh, ai, it's I in Portuguese, right? I is the sound you make when you get hurt. Oh, okay.
Interesting. I, So I'm, I, I, I've been dying to write a report. It's like I a I right?
As it relates to security. But, um, to answer your question, jokes aside, I think I lean more towards the, the, the, the positive side, because I've been around, like, we've all been around for a while. Like, one of the most fascinating areas I've worked in was, uh, anti-fraud, right?
Mm-hmm. And we had been using, we have been using machine learning in anti-fraud since the early two thousands, if not earlier, right? Mm-hmm.
So when we pick up our phones and we figure out, okay, uh, uh, image recognition or what that is, AI, like being used for good, they're being, are being useful in a very specific context. I guess that the challenge that we have, we, we have a major challenge right now, which is, on one hand, we have to help our senior business leaders navigate, understand enough AI to understand where AI fits and where it doesn't. Mm-hmm.
I am absolutely Okay, uh, having more narrow workflows where we can use AI to enhance the reasoning that we're doing there and what so, so forth. I am not okay, giving ai, giving an AI enabled technology a very complex problem, that humans are much better suited. Mm-hmm.
I, I forget, um, uh, someone mentioned, I, I am not going to remember the expression they, they that they used, but the, uh, someone mentioned on stage, uh, that, that, that, uh, unrelenting un unrelenting creativity of humans Yes. With the, the, the scale and, and they scale and precision of ai. Right?
I don't play, I, I, I think that the precision aspect is something we can debate, but, um, but I love the expression, right? Because yes, that's what we are trying to do. Let's find the right problems where, uh, uh, an analyst, whether they are more junior or more senior, can deploy their creativity.
And, and they are insights that are, that are difficult to code, uh, with the, the, the automated workflows, the, the, the, the, i I think a lot about security operations, the enrichment, the triage, et cetera, et cetera, et cetera. Mm-hmm. Right?
Yes, we can. So, I'm, I'm, I'm, I lean very positive with caveats. We need to understand what we're stepping into.
I, I would both, both very, very insightful. Um, I I, I always lean on the, even when it's not a pleasant experience, or sometimes it is a pleasant experience, the disruption happens. The good thing about it is that it changes the game, all right?
And that's what's happened with ai, is it brings the security topic back up, maybe elevates it, um, maybe pushes it in another dimension, but it doesn't have to leave everything else behind too, right? Um, so what, what this future, it helps us create the future in, in a more proactive and engaged way versus staying on the treadmill of, you know, defending against the latest thing and better response this and all the, all the fundamental things we still need to do. So I think it's, I think it's potentially a game changer just because of the engagement Absolutely.
That it brings to us, to that point and that point, frankly, probably like you, it keeps me engaged. I mean, I love this stuff. I love change.
And when it happens, even when I'm perplexed by it and feel like I don't get it yet, you know, I'm going for it. If, if The word perplexed upon on perplexity or, Yes. I like that.
I like that. So let's go to the, what are we gonna be talking about, uh, at RSAC, uh, 2026? I'll throw out this to start with.
One of the things I hope that we're talking about is, um, we've cracked the code on generating secure software. We see products, technologies, LLMs, uh, agents, workflows that are about not just creating more faster, but more secure higher quality around software. Um, 'cause I, I'm fearful that if we don't, you know, that mountain gets bigger and bigger every second.
We, somebody touches cursor and whatever other vibe coating and coating, uh, uh, GitHub agents, et cetera. So we've gotta address that. And I think this, I think in the next six months is the opportunity for a few companies to step up and really make a real statement and plant this flag in the ground about we're solving the security problem with code, and we could make some monumental changes.
And I hope that's what our conversation, I'm gonna predict that's what our con part of our conversation is about. What do you think the missing link is, or the missing pieces there that we should be looking out for? I think we're hoping AI solves it for us.
Yeah. And we're sort of living in the land of, you know, um, happy years that we'd like AI to solve it for us, but we're discovering pretty fast it won't on its own. Right?
And just pick, pick one example. Um, salt Security came out with a MCP security product, right? How do we protect what, what people, what's happening and how MCP is used for small, tiny example of something great, good.
That's exactly what we need to be doing, right? Mm-hmm. We need to be doing the same thing on code, right?
Because the more we expand not just the volume, but who is all creating code, more people can be creating code that don't know security mm-hmm. Just as we do today, but even even greater. So in a way, we have to, or else it, you know, it becomes its own house of cards at some point, and we can secure nothing because, you know, I don't think we'll get to that tipping point, but, yeah.
Yeah. So for me, I think one thing we haven't necessarily touched on today, um, but I do think it's gonna be very prevalent, you know, certainly over the next year is just the explosion of the potential attack surface. So obviously we've talked a lot about ai, and that's only accelerating, um, you know, the pace at which the threat surface is expanding.
Um, we have, you know, customers are using more and more SaaS applications, um, potentially hundreds that are kind of hosted in the, excuse me, that are hosted in the cloud. Um, and so how do we do things like, um, you know, really instill contextual just in time, you know, access, um, to these resources? And how do we at the same time, um, shift to kind of a more, um, preventative, um, you know, kind of stance with, you know, with our infrastructure, for example, on the data protection and recovery side.
Um, so I think those are a couple things that I'm thinking we're gonna continue to hear more about, um, over the next year. Um, in addition to circling back around to the AI side of things, I really hope we have conversations at RSAC conference next year. Good.
Good one. Good one. Good one.
Good. I, yes, I'm not, I'm not used to, I am trainable, um, um, some really kind of concrete use cases around where is AI making an impact and a difference? What are maybe some of the potential pitfalls that we've fallen into, um, and really kind of move the needle forward in a, in a very concrete material, um, way.
So those are some of the things that I'll be, I'll be looking out forward. All Right. I am, I, my, I, I'm, I'm racking my brain here.
Trying to remember, I think it was a Bill Gates quote, may have been Bill Gates or not, about how slowly things move in the short term, but how much it changes in the long, over the longer term. Yeah. Right.
I, I, I, I, I, I don't remember the quote, but I'm thinking about that. I think that RFAC conference, right? See, I got, I got it.
Uh, 2026. I don't, I, I, I think that we are not going to be seeing too much of a difference from what we've been discussing now, if for nothing else, because as, as we all know, enterprise buyers, they have lots of hoops to jump through. Mm-hmm.
Right? So any new technology that, that may have come up on the floor this week, right? It's going to take a few months to get the POCs going, right?
And after the POC is going, the procurement's gonna take a while, right? And then deployment might take a while, and then we'll still be seeing the early lessons, right? So I, I, in that sense, I think it's going to be relatively similar, but I think that we are, we are going to be talking a little bit more around what has been the actual experience with agentic capabilities across the board, right?
So perhaps we will be discussing finer point back of AI governance in the context of agentic workload. Perhaps those human, perhaps the, the discussion on the on identity is going to be more significant, perhaps the discussion of, uh, how do we contain what may have happened in the latter part of 25 in terms of some significant, uh, AI related incident. Mm-hmm.
Right? So I think that that, but we are evolving towards that, but I think that the actual change year to year is not going to be that great. Mm-hmm.
I love your sentiment about us solving secure coding. Mm-hmm. Uh, I, I I, I, I want to be a realist.
I, I, I'm optimistic realist, right? You're Pist. Uh, Yeah.
I, I, I, I think we'll be discussing similar things, right? So I, I mean, I think the, maybe a flavor in what we're all saying, especially the two of you, is, is a more in depth informed, contextualized conversation about what we're doing. Yes.
We take where we are today, the depth of what that conversation will be much Deeper. Yeah. Yeah.
Yeah. Good. Good.
And, and, uh, one of the other things we'll be navigating is what technology and fiber are in our com are intertwined with geopolitics. And, and so I think that we're still waiting to see what the consequences are going to be mm-hmm. Of, uh, uh, recent administration moves of, of geopolitical events and so on.
So I think that we may see, uh, we'll still be discussing this and, and, uh, I think we were talking about this yesterday. You made a great point about RSAC as a, as a venue for having those kinds of, of conversations. So if there's, one thing I hope for is that we continue to be that venue, right?
And, and we continue to have that conversation between the right stakeholders, public policy, private industry, and, and, and, and, and so on. Well Then be the change you want to make, right? Something along those lines.
Something Like that. So I wanted to, before we wrap up, um, I want you to talk about the, the dataset that you just launched, survey data. Um, and just for our, our listeners, Futureum offers the service called RUM intelligence, which is instead of just issuing reports, and we do a lot of that kind of thing, and our surveys and things, we actually have a massive database where we keep all of this across all of our practices and successions of generations of data, and really building up a nice, nice reservoir, if you will, data lake, data, whatever of, of information that, um, subscribers to that have access to as well as kind of more in depth reports.
And each of our areas release updates to that data set. Sometimes it's more data updated, sometimes it's expanding and adjusting the scope of that. I just re released the DevOps and application development data set about a month and a half, two months ago.
You all are just on the cusp of releasing the security cybersecurity. Talk about your kind of respective collection of what's, what's in that information. Yes.
Yeah. So, you know, to your point, Mitch, it's, um, survey work on decision maker buying criteria within cybersecurity. Yeah.
Um, we cover the gamut. So we cover application, security, cloud data, all of them. Endpoint security operations center.
We have seven technology categories. Um, and then on the, um, other side of that kind of coin is the market sizing and forecasting data. And, um, what I really love about the research is that it really keeps us grounded in the voice of the, the customer, um, and the practitioner.
That's something that I think is very important with, you know, the work that we do. And really as an industry as a whole, we start to make decisions around, you know, product development and things of that nature. So we're mm-hmm.
We're really excited to launch it. Yeah. Fernan.
Yeah. It's, it's phenomenal. Um, I, I, I say I, I'm not a data science, nor do I play one on tv, but I love data.
My, one of the birthday presents I got a few years ago, it's very simple. I, my kids gave it to me. It is a, is a little plaque that says, I have a spreadsheet for that.
Right? Oh, my, I, I, uh, I, I, I'm sorry. So I was geeking out.
Can't Confirm. He does. Yeah.
Yeah. She, she saw, she saw confirm can We We're Both laughing. Like, that is so true.
Right? And, and, and, and I think that, uh, I think that the happiest I am with would the application that I have open would be something like Jupyter Notebooks, for example. So, so I'm, I'm, so I love the data that we have.
So we, like, like Krista said, we have a, a market sizing data, and we have a, a, um, a decision maker data, and I think the decision maker was about 91, 92 questions, something like that. Yeah. And across multiple areas, so not just on application security and cloud and, and whatnot, but also how are organizations behaving?
Uh, how often does the security team interact with the board and mm-hmm. And stuff like that, right? Yeah.
So one of the, the data points that, that's freshest on my mind is we ask people what are they concerned about? Uh, and, uh, if you ask them to rank their number one thing would be ransomware and data breaches. Mm-hmm.
Fine, right? If, uh, on aggregate, when we, when you add, uh, choice one plus choice two, like top one, top two, top three, and then you add the total, the one that pops up the most would be cloud incidents. Mm-hmm.
Right? So it speaks to the variety of, uh, of issues that security practitioners are dealing with. Uh, and, um, it gives us insight.
And like Krista said, it keeps us grounded, right? Yeah. Sometimes one of the curses of, of working as, as, as analysts is that sometimes we get too far ahead.
Like, no, we're not in an ivory tower. We are here to help our, our, our buyers, our sellers, our, the people who work with us on navigating this. So the, the dataset is, uh, those two datasets, like the market sizing and the, and the decision maker are helpful, very helpful towards that.
It keeps us in the clear air. Yes. So we're not breathing our own exhaust, right?
Yes. Yes. If you will.
Yes. And, you know, I have, I'll have to find out the number, but I, it may be hundreds of thousands of data points across all of our practice areas. Oh, Collectively.
Yeah. Something like that. I mean, it, it's gotta be a phenomenal number, the amount of information we have, the tools to slice and dice and Yep.
You know, by the way, every meeting starts out with Fernando, the first five minutes, within the first five minutes is I, I wanna show you a spreadsheet for That, so, oh, no. Yeah. They, they, they is.
Am I right? Um, maybe just in time. Some, sometimes we take a few minutes, sometimes not five minutes, because we, we, we, we were making that just Depends on how patient, how much you can hold back.
Yeah. The moment. Well, Krista, I think The only other thing I might add Yeah.
Is just kind of to your point, Mitch, around all the data points across our different practice areas. So relevant to the conversation around security, because it crops up not just in our dedicated research on cybersecurity, but in our other research areas as well. For example, our CIO research we published earlier this year, it was a top, um, you know, top initiative and top concern for CIOs.
Yeah. And we had the, we, we did the, we did some research on agent AI technology overall, right? Mm-hmm.
And, uh, phenomenal paper. And, uh, in that, the area of governance and where this was most closely aligned was yes. Key priority and whatnot.
So the agen AI paper is done. Uh, the, the, the paper around the CEO insights about AI overall trust and governance come up as well. So, yeah.
So cybersecurity is everywhere. Yeah. Right.
And this was cool about ai cyber software is that touch every domain, whether it's hundred Percent Hardware and laptops, and I, PCs to cloud services and applications, data, all of it. So Never, I, I, the tagline I like to use is never a dull day in this industry. Yeah.
There isn't. Well, Fernando, it's been, uh, good, good to be in person with you for the first time. Absolutely.
We've Talked so many times over Zoom, and So one of the things I, uh, one of the predictions for R-S-A-R-S-A-C conference 2026, is we are going to have a fabulous time having this again. That's Right. Hopefully everybody's enjoyed this.
We're trying to give folks a window into what we're thinking about and hundred and then we don't have to write everything. Yes. I can say a little bit About video.
Krista has been fabulous. I've always enjoyed getting together. We've had an opportunity to be at some conferences together.
Yes. And look forward to that as well. So yes, Thank you so much, Mitch.
And for, you know, both of you, it's always a pleasure. You Bet. Safe travel with everybody.
Absolutely. And I go back to the, the, but airplane Yes. Conversations.
Yes. com, which is, uh, there's an analyst section where we have all of our, all of our research. If you're a subscription customer, you can go to the application portal, the Futurum intelligence, get access to even the deeper data, and of course, contact us.
And we're always happy to talk with folks about the work we're doing, but more importantly, the work they're doing. Absolutely. A hundred percent.
And what, what's happening in their world. Yes. So you can reach out to us.
Thanks everybody. On behalf of Krista, Fernando and myself, Mitch Ashley here with Futurum Group, uh, we hope you'll tune in, we'll find some more ways to do this kind of conversation with each other and do it in a way that you can be part of it too. So thanks for joining us at RSA, stay tuned.
There's more livestream content coming up, uh, from, we've got folks lined up to do some interviews and, and, uh, looking forward to that. But as we leave the scene, it's great to be part of you with you and part of this together. So take care everybody.
Thank you. Hey everyone. Welcome back here to Text Drunk tv.
You know, whether you've been naughty or nice. Next week is our SA conference. And, and we've got, we are in full swing here in Techstrong.
Very excited. I'm flying out Saturday. Uh, we'll be there setting up Sunday.
Monday was of course our DevSecOps event. And this year it's ai and of course it's ai, ai, cybersecurity, and app dev. We've got some great speakers.
Really, really excited. Um, I'm really excited to have these two ladies on though, because for those of you who know or have been to RSA or follow, what goes on at the RSA conference, you already know them. For those of you who don't, these are the powerhouses who run the RSA conference and have for, well, they're a lot.
They're not as young as they look. They've been doing this a long time. We have.
I know, but Yes. But let me introduce you to my friends, Linda Gray, Martin, who is it? Senior VP of RSAC, is that the right title?
That's correct, yeah. Of the conference. So I look after the conference, but I'm also chief of staff for the company too.
And let me introduce our next guest who is a powerhouse in her own rights, my friend Brita. Glad Brita. Welcome.
It's so great to have you here. It is my pleasure. Thank you, Ellen.
Always great to see you. So let me just make sure I got this right. VP content and curation for R-S-A-C-S-V-P, Senior Vice President for Service SVP.
Yeah. And Alan, we actually change the C because RSAC is all about, you know, the C is all the things. It means, um, content and communities because we have so many different communities at conference.
Okay, that's fantastic. Britta and I, I think that's a perfect role for you. You know, I was kidding around about how long you guys have been involved in RSAC, but how it's gotta be 15 years, 18 years.
Oh yeah. Easily. More than I joined in 2006 when I was responsible for RSA conference Europe.
So back in those days. So yeah, 2000. So 19 years I've been at the company.
Yeah. And Bri, you, I think I've been about 11. Yeah.
So I got you beat. I've been going to RSA since 2002. Okay.
You're the veteran here. Uhhuh, I think what, when was, what year did we do San Jose? Do you remember?
It was a 2003 or four. It was like in the middle of a downturn. It Used to rotate.
It used to be back and forth. San Francisco, San Jose oh's. Why I remember San Francisco, because it was, it was right after nine 11 and there were more people handing me resumes than they were talking about my product.
And I was so bummed. But, you know, that was a long time ago. Anyway, Britta, you mentioned the C in RSAC.
Right? It took me five years to always put the C on RSAC because I wanted to make sure people understood We were talking about RSA conference Conference. Absolutely.
But now the C is something else, or it's more, Well, it can be many things. I think that's the beauty of it. I mean, obviously the conference is at the heart of, of what we do, you know, and it's definitely central to that kind of larger mission that we all feel.
But, um, you know, the CI think is, it just kind of highlights that we've become more than a conference. There's this need for year-round learning and education and, you know, we are the epicenter of content, connection, culture, conversation, collaboration, I think. But mainly what it really means to all of us and in our hearts is community.
It's all about community. So absolutely. The sea can be many things.
Very good. Um, let's talk a little bit about, Linda. You mentioned your SVP for the, or for the, uh, conference, but chief of staff for the company?
Yes. For those people. May be a little confused about that.
It goes to the heart of the sea, if you will, but just, you know, make, let, let's close the, yeah, the loop on that one. Let me close the loop. So, um, hopefully you will have seen that recently, uh, we announced the launch of RSA C'S membership platform.
So, um, you know, it's gonna include capabilities that allow people to continuously learn, to collaborate and to communicate, um, you know, to help them on a, a daily basis. Um, so we've kind of got two parts of the business at this point. Obviously the, the conference is the center of what we do and always will be.
Um, but we do have this expanded membership platform now. So obviously an expanded team that goes along, um, with kind of building, launching, maintaining, um, and, and working with the community on that. So our company has grown significantly in the last 18 months.
You know, we have 75 employees now. Wow. And it's really important that we maintain the very strong culture, um, you know, that we have on the conference as we build this company.
And so really that is part of the role that I have as the chief of staff at the company. You know, working together with the teams, um, you know, making sure that, um, everybody is collaborating effectively and coming together as we kind of go on this journey. Absolutely.
You know, that was always one of the best kept secrets, I think, in security. It was kinda like Wizard of Ish was like Wizard of Oz, you know, that behind the black curtain there were like six people pulling the levers for this gigantic conference that the whole industry came to. And, you know, there were contractors and there was a lot of help.
'cause when you came to the event, there were, there was people all over. But the fact of the matter was, the RSA conference itself was only a handful of full-time employees, you know? That's right.
And back then you were putting on three shows, three different conferences, inces a year. I know. I dunno how we did it.
When we look back, do I? Maybe it's just that I've got older and, um, my capacity Is that No, there was a little kinda Wizard of Oz thing going on there. Yeah.
But it's that, you know, You know what I love about it though? A though you're talking Yeah. The full-time employees.
And yes, it was always surprising, however, to the heart of what Linda was talking about, community. We've always had a really large number of program committee members, folks from across the community who've, you know, they, they pick the sessions that are going to put be put together. They go through them, they edit it, they, they prepare, um, you know, recommendations for how can this be the best possible content.
And I've always loved that aspect about RSAC conference. Uh, you know, the, it really is of by and for the community. It's always been the heart of what we do.
Yeah, Absolutely. So I'd love to sit and talk about this all day with you, but we we're under, you know, we have to within time here, and it's the week before RSA conference. Indeed.
First of all, thank you both. 'cause I know you've both gotta be spinning up a million miles a minute right now. But let's talk about this year's conference.
Why someone looking out here saying, Hmm, should I go? Shouldn't I go? Yeah.
What do they have to look forward to? There is, there is so much. Where do we start?
I mean, first of all, I just wanna give a shout out to the theme of this year's conference, because I think it's one of the main reasons people should come. And it's all about community. So our theme this year is many voices, one community, and it re it's the heart of everything that we do.
And I know we've kind of mentioned that already, and that although people have different backgrounds and different perspectives and different strengths, we unified together in this mission to help make the world a safer society. And so, you know, and it's a very collaborative feeling. So of course we have 500, 600 sessions, 600 exhibitors, 700 speakers, all the stuff that you would expect, um, that people have come to know and love RSA conference for.
And we will have all of that again. But, you know, just being at the heart of this very passionate community where people wanna help, you know, they wanna lift their peers and colleagues up and they wanna share knowledge. It's just, it's such an opportunity.
We, you'll quite often hear Hugh call it, sorry, Hugh Thompson, Matt Executive chairman, the convening authority for the cybersecurity industry. And it, it really is. It's where everybody comes together.
Um, so just a few thoughts from me, Brita, you're SVP of Content and Communities. Tell, talk to us about the content for this year. Absolutely.
Event. Absolutely. Absolutely.
Um, I love all of the content. You, you, I mean, you're putting together a great seminar on Monday, right? And what I, what I love with what we put together, the experience across the week, there's a lot of things that happen publicly.
There's also a whole lot of content and gatherings and get togethers that happen for private communities, which is very important. You know, that collaboration, the, the conversations that happen at conference on, um, different challenging topics, right? Where different groups need to get together.
So we, as Linda mentioned, we have, uh, gosh, over 600 sessions, uh, spread across 29 different tracks. You know, starting on, we actually start Sunday with some closed door sessions run through Thursday with a great closing celebration. Uh, the, the sessions are available, you know, different things are open to different folks depending on what your past type is.
So that's, you know, guidance I would give folks attending. Make sure you know, when you're looking at the agenda, when you're picking the sessions you want to attend, be sure to reserve a seat, something that's really, really important to you. Reserve that seat, um, and make sure your pass type gets you into the session you want to attend.
Um, and then, you know, it's a busy week. Look forward to after the week as well, being able to go back into the library, be able to see those sessions that you're interested in. We talked about the membership platform.
There's going to be some great live groups that are available, uh, you know, conversations that will start before the event. Hey everyone, it's Alan Shimmel and we're back here live at the, uh, RSA conference covering Wednesday. We are live.
You can see behind me the activities picked up a little. I think some of the sessions are led out and there's a lot of people heading over to the West Keynote stage. Magic Johnson is going to be on keying in about 45 minutes.
And, um, there's a, Hey everyone, it's Alan Shimel and we're back here live at the, uh, RSA conference covering Wednesday. We are live. You can see behind me the activities picked up a little.
I think some of the sessions are led out and there's a lot of people heading over to the West Keynote stage. Magic Johnson is going to be on keynoting in about 45 minutes. And, um, there's, Hey everyone, welcome back to Text on TV's live coverage of RSAC from San Francisco Moscone West.
We are in broadcast LA this is our 10th year covering RSAC, and this is where the best of the best experts in cybersecurity and AI are. This week. We appreciate, welcome back to Techstrong tv.
This is Lisa Martin coming to you live from the show floor at RSAC in San Francisco when there's about 45,000 folks. This is Techstrong TV's, 10th year of covering this massive event in cybersecurity. We're having great conversations yesterday, today, which, you know, as you've been watching with leading cybersecurity experts, happy to see one of my old colleagues, Amit sent here, the CEO of DigiCert.
It's so great to see you again. Great to see you too, Lisa. Yeah, we talked about a year ago, and I'm excited to be back here.
I am too. I'm gonna brag on you for a minute. Okay.
I did some LinkedIn stalking, the author of 50 patents, 34 issued 16 pending, 25 published journal and conference papers, three book chapters, four thesis, dozens of white papers. How do you find the time to do all this and lead a company That was in the past? I had good mentors, good teammates, right.
And, uh, hey, it's a team that makes it happen. Ultimately. Absolutely.
A good, uh, being surrounded by a great team is everything. But you've been featured on C-N-B-C-C-N-N, here you are with us. What is going on at Digit?
Give me kind of the rundown since we last spoke. Well, since we last spoke a lot has happened in the industry. Lisa.
Yes. Um, you know, dig, as you know, is a global leader in digital trust. And digital trust is foundational infrastructure that makes sure that all our digital interactions are secure, they're trustworthy, they're private.
Right. Um, and this whole industry is going through a massive renaissance. Yeah.
Right. Um, let me give you a few areas where this change is happening. Just two weeks ago, uh, the browser forum passed a new mandate, which now requires digital certificates, which is kind of the underpinning of all this, uh, trust fabric.
Uh, the validity of those certificates will go down from 398 days, just over a year to now. 47 days. It's like eight x reduction.
So think about your passport if it start, you know, instead of a five year validity, if it was expiring every 47 days. Yeah. I mean, that'd be crazy, right?
Yeah. Now it's safe because if someone stole it or, uh, or if it was out in the wild, you don't have to worry about exposure. But what that means is the industry now needs fail safe automation, right?
Yes. Uh, because all of the, you know, think of all the websites, the apps, the software, the machines, Which only just proliferating exploding. Yes.
And we haven't even gone to AI agents and we'll get there. Yes. With all of these non-human identities, you know, using PKI, you need, uh, you need a system that can centrally govern it and provide fail safe automation, right?
Uh, so that's a huge change that's happening. And we're talking to many customers about how do I get command and control over millions of these cryptographic assets that might be within an organization, and they provide you secure communication and authenticated devices. Uh, so that's one huge change.
Um, and writing on top of that is this whole quantum thing, right? Yeah. So the math that secures all the trust fabric is based on these, uh, classical algorithms that are now vulnerable to quantum computers.
And we've known this for a while. Mm-hmm. But what has happened is since we spoke just this earlier this year, Amazon, Microsoft, Google, they're all coming up with their bigger, better, faster versions of their quantum chips.
Yeah. And, uh, I think, you know, we're gonna have a chat GPT like moment where one day we'll wake up and say, wow, these quantum computers are here, and all of our trust fabric based on these math problems that we deemed were secure are suddenly broken. Right?
Wow. So that's a huge, you know, um, um, uh, thing that's happening in the industry Yeah. Where people are preparing for, uh, post quantum cryptography and those standards exist today.
It's just work needs to happen to Right. Go through this upgrade. And how quickly with, based on the acceleration, I mean, and chat.
GPT was born, what, a couple years ago, two and a half years ago, and it just catalyzed this revolution. I mean, AI is not a new concept. It's been around for a long time.
Exactly. And, but once it was launched, every company had a, what's our AI story? Yeah.
We have to have an AI story. Yeah. But the good guys have access to the tools.
A bad actors have access to the tools. It's like fighting fire with fire. Exactly.
Exactly. How Do you, how do you conceptually explain digital trust to customers and what does that mean for, for them to be able to deliver the brand value that they expect that they have to deliver? Yeah.
So at least digital trust, again, is foundational infrastructure, right? Yeah. How do you know you're talking to the right bank website?
Not a fake one. How do I know that my app to app communication is secure and private? You know, you sign digital documents.
How do you know that the deed on that PDF Docus signed is going to be not tampered with and hold up in a court of law 10 years from now? Right? Right.
Uh, how do you know that the software update you got on your iPhone really came from Apple, right? All of this is based on the same PKI, the same cryptography, right? Yeah.
And so that's foundational infrastructure and, and DigiCert, you know, 90% of Fortune 500 use DigiCert, uh, to, uh, to get to that, uh, trust fabric that I talk about As that fabric undergoes changes and upgrades. How, how do you keep up? I mean the, just the, the speed with which things are going is mind boggling.
Exactly. For organizations that might not have the digital trust fabric or the visibility to understand where are all of our vulnerabilities A hundred percent. And how Do you keep up with, with the changes to the fabric?
Yeah. So, So again, step one, you need a system and you need automation, right? Yeah.
So I talk to half a dozen customers every week. Nice. And these conversations are happening where, look, even going from 398 days to 47 days, right?
Uh, now you need fail safe automation. Uh, what does that mean? That means, well, I need to be able to validate in an automatic way.
Yeah. What do I need for validation? First, I need to be able to prove that I control this domain or this machine.
So my DNS and my PKI need to work together, right. Otherwise, what's gonna happen is that two things. You won't have automation.
So you'll have humans in the loop and then it'll lead to outages, it'll lead to exposure because you weren't able to update a, you know, the PKI on a particular machine because the person was away on vacation or, you know, something else happened. So you need, uh, these two core systems. I call that electricity and water on the internet, you know, PKI and DNS work together.
Yeah. And what DigiCert one does is gives you a single platform to fully manage and automate these two foundational pieces of digital trust. Right.
So now imagine millions of machines, so many domains to manage. You can, your DNS team and PKI team no longer need to be in silos. com.
Yes, Amazon really controls it. Oh, it's 46 days. Let's go ahead and update the cert and repeat that for millions of private machines that you might have internally.
So that's kind of a huge thing that's happening in the industry. And, you know, DigiCert's leading, uh, the way with lots and lots of our customers with a change in, uh, in, uh, in standards. And that actually prepares you for post quantum cryptography as well.
Okay. Because what is post quantum? It's just new math.
Yeah. So think about, you know, back to your passport example, now there's a better passport, right? Yeah.
More tamper proof. Yeah. You know, but the underlying process hasn't changed, right?
You still need to validate, you still need to manage and automate. Uh, But the automation is Critical. That's the, that's the part that we are driving to.
Yes. And DigiCert one now supports all the post quantum standards that have been approved by nist Okay. As a fall last year.
So You're already getting ahead of the curve here. So we're already ahead of the curve, and we are many customers who are, you know, leading the way. Yeah.
And, you know, we do a survey where we go through the grief cycles, right? 'cause this is once in a third year upgrade. And two years ago when I used to talk about post quantum cryptography, most people would say, Hey, that's a problem out there down the road.
And now, you know, you have CSOs and CXO saying, what's a quantum strategy? Uh, are we prepared? Do we have, you know, an inventory of all our assets?
Do we know what, what are our crown jewels? And what do we need to upgrade first? So the conversation has gone from what's quantum to what can we do about it?
So getting proactive, A hundred percent, that's Outstanding. Because I, I always think in cybersecurity, are we always behind? Will we ever be able to be proactive with just how quickly things are transpiring and how the risk surface just continues to expand?
Yeah. Amorphously. Yeah.
And we have more data, more software, more apps. That train isn't slowing down anytime soon. It isn't.
And like, look, when you start adding things like AI agents, right? I mean, uh, customers are asking, well, you can, you know, you're helping us manage software and devices and machines. Now here's an AI agent.
This is a, you know, is it software? Is it a machine? Is it, you know, how long will it last?
Right? How long will be managed? How will it be managed?
So one of the foundational principles in security is to separate identity and authorization from the capabilities of the underlying software agent. Right? Okay.
Yep. Think about it this way, Lisa. I mean, a year from now, I might have six agents working for me.
Mm-hmm. You know, maybe I have a Zoom avatar that shows up, right? Maybe there's an agent approving expense reports or doing mundane things, but maybe I have an agent that's negotiating a contract, right?
What do I need? I need a kill switch on the agent, right? I need, uh, I need an audit log of what are the things that it, it did right.
Because ultimately, it's acting on my behalf. Right? And so I need to be able to, you know, first have a tamper proof identity.
I need to have a tam proof record of what it did. Right? Right.
And if I don't like something, I need a kill switch to be able to say, you're no longer authorized to do that. Right. Right.
What's all that? That's back to, again, PKI, right? How do I authorize, you know, we know how to authorize a machine.
We know how to say this is authentic software. Uh, you know, there are lifetimes associated with it where you can go and say, well, after 47 days, it's no longer valid. Right?
Right. So we're bringing similar concepts now to AI agent trust. Right?
Ah, where, where you can say, look, these agents are very powerful, but identity access authorization is, is, you know, is in my control. Right? Yes.
Versus saying, you know, this agent goes rogue and does whatever. It's Right. Right.
Well, the agentic AI explosion, uh, just another example of this catalyst in every industry, in every vertical, I talk a lot with chief marketing officers, um, and everyone is embracing agentic ai. It's part of their KPIs as integrated marketing organizations. So we're just gonna see that continue to explode.
But being able to, you put the right word, control, get control over it, it's not a possibility because it proliferating so fast. Well, look, again, you know, you need to combat AI with ai. We hear that thing over and over again.
Yes, we do. Um, but, you know, we need to learn from, from things in the past and be proactive and apply it. Right.
The examples I gave about separating identity and access from, uh, and being able to govern it in a way Right. Uh, is very, the governance critical is very, very, very crucial. It's not a nice to have anymore for organizations.
Yeah. It's table stakes. Yeah.
And I kinda like your proactive angle, right? We have customers who are very proactive. Uh, in fact, just a couple of weeks ago I was with Zoom and, uh, you know, uh, we work, we work with, uh, AMI, who's the president of Zoom, uh, and his team.
And you know, it's a great example of a, of a company and a customer that's, uh, very proactive about these things. So let me give you, you know, three, four simple examples. Yeah.
Um, we talked about post quantum cryptography. Mm-hmm. You know, zoom, uh, workspace now supports end-to-end quantum safe encryption.
So they're, you know, already ahead of the curve, right? Uh, zoom, uh, when Zoom clients talk to Zoom servers, they use Dig cert, PKI to kinda secure, uh, that communication. Um, now other things too, like the industry is moving to 47 day certs.
You know, Zoom's already rotating these certs now on a six month basis. Right? Okay.
Uh, their code signing certificates are being rotated on a monthly basis, and they're able to, you know, do majority of their digital trust infrastructure on a fully automated basis, you know, with, with integrations and, and, uh, and platform support from DigiCert. So that's a great example of a, you know, customer who's being proactive. Yeah.
Who's, uh, uh, who's ahead of the curve. And that's what you need in a, in, in the security industry today. Absolutely.
And like I said, it's not a nice to have anymore. It's essential. Absolutely not.
But so many organizations I think, struggle. And you probably see this in all of your customer conversations. Where do we start there?
It's so overwhelming. But knowing that there is a way with dig, for example, to enable organizations across industries, across verticals, to become proactive with something that's coming is enlightening. Yeah.
I'm so glad that you shared that story. Last question for you. I think I saw that DigiCert is on the track to reach a billion a rrr.
That is true. Congratulations. Thank you.
What's next? What can we expect next from DigiCert? Look, we just want to deliver awesome services and an awesome platform for our customers.
I think the next four years, uh, PKI and Digital Trust is going through, go through massive renaissance, right? Uh, with Quantum, with the things that we talked about. Uh, you're right.
Many customers say, where do we start? Yeah. And, uh, you know, I'm doing trust summits now.
Uh, we've hit three cities. We're gonna go to four more in the next month or so. Excellent.
And, uh, we're just, uh, you know, going and helping customers understand, start their TKI modernization journey. Yeah. Get prepared for quantum safety.
You know, figure out how do we bring digital trust in a, in the real world with AI agents, right? Those are all things. So, you know, we're very excited.
And, uh, uh, look, a billion dollars is, is is just a milestone, right? That's a big milestone. But, uh, it's not like it, you know, the race finishes there, right?
No. We just want to continue to grow and Absolutely. And Serve our customers and continue to be proactive.
I, it was so great to have you back on Tech, on tv. Enjoy. I always enjoy our conversations, but thank you for sharing what's going on with Digital Trust, why it's so foundational, how the fabric is changing, but how you're helping organizations actually get ahead of the curve.
Really appreciate your insights. Thank you, Lisa. I always enjoy our conversation.
Likewise. For, and I'm Lisa Martin. You're watching Techstrong TV Live from day two of RSAC.
Come with you from San Francisco. We'll be back with our next guest. So stick around.
Hey everyone. Welcome back to Text on TV's live coverage of RSAC from San Francisco Moscone West. We are in Broadcast Alley.
This is our 10th year covering RSAC. And this is where the best of the best experts in cybersecurity and AI are this week. We appreciate you tuning in.
I'm very excited for this next conversation. Sol Rashidi is here. She's the CEO and founder of Executive ai.
And you do so many things. Sol great to have you on text, join tv. Thank you for joining me.
Thank you for having me. I appreciate, I'm gonna brag on you a bit because I, I LinkedIn stalked you. Okay.
You have 10 patents. I do. Working on the 11th one right now.
You're a bestselling author. You're a top 50 women in tech. And love that.
I get goosebumps and this is awesome. Forbes, AI maverick of the 21st century. You're literally a maverick.
I've been lucky. I've been lucky far from it. I think with the pace of change and how everything's going from, like, we're all just barely keeping up.
I know. Um, but I was fortunate enough to get a, a few labels and titles along the way. Well, that's fantastic.
Talk to me a little bit about executive ai. You are the founder, you're the managing director, and this is a consulting practice. So it was interesting 'cause it happened completely by accident.
I've always been a C-Suite, a part of really amazing Fortune 100 companies. Um, like some of the largest firms that you've ever even heard of. Like I've always represented 'em as the chief data officer, chief data and analytics officer.
I was the enterprise's first Chief AI officer appointed back in 2016. Okay. So I've always served these companies and I've always been brought in to build the capabilities, scale the capabilities.
And so that's kind of where a lot of my practitioner experience came from. And then I left Enterprise and I discovered that, you know, I helped IBM launch Watson back in 2011. Wow.
And so from like 11 to 2015, my job was to fly around the world, work with these enterprises, help them establish their AI strategy. Yeah. Their use cases, and help them deploy.
No different than how everyone started in 2023. So I'm just watching the world kind of go. I'm like, yeah, we did this and we made that mistake and we did this and we made that mistake.
But no one's calling out their mistakes. No one's calling out the lessons learned and they're so valuable. I always say you learn from the mistakes.
Absolutely. And so, yeah, fail forward, fail fast. Yes.
But like you learn. So why should people have to go through and repeat what a slew of us, quite frankly went through nearly more than a decade ago? Yes.
So executive AI was created because I think there's a lot of C-suite executives. I think there's a lot of leaders. I think there's a lot of companies that are learning and earning, meaning they're learning on the fly, but they don't necessarily understand what the bottlenecks are.
Mm-hmm. And I say in the world of ai, you've got data infrastructure and talent. Infrastructure is all the tech stacks, the tools.
Like we've, it's not about GPUs and CPUs and workloads. Like we've solved that. Data security is a major hurdle right now.
Absolutely. And then talent preparation, because the way we're going to market with artificial intelligence, and I saw this back in 2012 and 13, it's, we're gonna do AI to increase productivity and capacity, which by default means we can run leaner. And that is never the case.
So the goal isn't to increase capacity. So you can displace employees. Mm-hmm.
The entire intention is how do you give them time to reflect and realign on the bigger business problems. So it was supposed to be kind of a side hustle so that I could actually help other organizations go through workforce preparation and data security that then turned into kind of a thing of its own. I love that.
Sometimes serendipity, right? Yeah. I love your mission.
I identify this with this as a market. I was telling you before we went live your mission about bridging the gap between the technical folks, the non-technical worlds helping pivot from this massive AI hype that we're still kind of in. Yeah.
But now it's time to talk about AI results. Share a little bit more about your mission. Why is that so important to you?
It's interesting 'cause for those of us that are in this space, like we are knee deep into it. Yeah. And you hear about all the amazing startups and what they're doing and you hear about all the tech companies that we're doing.
But we're missing the point because there's an entire ecosystem around us. Like most of the, if not all of the Fortune five hundreds. They're not tech native.
No. They use technology as an enabler, but they're not tech native. Right.
So everyone is constantly in defense versus an offense. Everyone is reacting versus responding. Yes.
And they're just trying to catch up. Yes. And so I think that's where the bridge really exists is we are in this space and we kind of understand it.
We kind of geek out on our own things. But quite frankly, it doesn't matter what amazing tools and tech we build, unless there's true adoption. Yeah.
Nothing we do is ever gonna scale. And the adopters happen to be the non-tech native, the non digitally native individuals. So I always like to say that I'm just a glorified translator.
And oddly enough, my first career, my first job outta school, um, I used to be a professional rugby player. And then I was like, okay, time to grow up. Wow.
I need to get like paid for a living so I'm not sleeping on futons and ramen noodles. And so I became a data engineer and six months in my, my boss came to me. I was like, oh my God, I'm getting fired.
I thought I was getting fired. Because he said, so you're never allowed to touch a lick of production code ever again. You can hack your way through things, but you cannot write production ready code.
He said, but for some reason, you like the business, you get along with the business and you know how to build relationships. So your job is to talk to them, figure it out, what it is that they need, translate it to us. 'cause you know, our world, we're gonna build it and then you're gonna go back to them.
Because what was happening was is the business would say they would need one thing. They would build it only to find out that's not what they meant. Right.
So I thought, I was like, oh, well I'm not getting fired, but I'm totally getting demoted. But it turned out that playing this translator between the business side and the technical side turned out to be a really, really critical asset. Because most of my positions, it's not 'cause I'm the smartest person in the room.
It's 'cause I'm the only one that understands both sides of the house. You are the bridge and I can find the common ground. So the bridge, you are the bridge.
What is that like culturally to, because when we talk about like dev stack ops and the developers and security and there's a lot of commonalities that they have, but they struggle to collaborate. How do you see the technical folks collaborating and cohabitating with the non-technical folks? What some of the magic that you've seen happen and what's essential for that cohabitation?
Yeah. I would say what's essential for that cohabitation is if our technical folks who have tremendous IQ also put just as much emphasis on their eq. Yeah.
Their BQ and their sq. You know, I would say the first big faux pot and mistake I made in my first C-suite role was I leaned and over leaned into my iq. Well, they clearly put me in this position 'cause they thought I was smart enough to have the C-suite position.
Right. But I learned that my IQ actually wasn't gonna help me evangelize or scale or help build critical mass in the things that we were building. It was my eq, my ability to read the room and the groups and the teams to understand what they were afraid of or why they were pushing back and resisting so much.
Or my bq the ability to translate our terms and terminologies and taxonomies, um, and lexicon of language into their language, which we don't do in our world very, very well. And then the SQ at the end of the day, people still believe into people. They still buy from people.
Right. And so, uh, my writing joke was at one of my employers, I went to more happy hours than I could even care for. But it built the trust.
Yes. So I would have one-on-ones with these executives, these presidents and CEOs and saying, listen, I don't get it. I don't understand it, but you do.
And I trust you. So I'm gonna give you a few of my resources. Go pilot this.
And then if quite frankly, if the response is, well, then we will evangelize and scale it. So I was like, that's all it took. Yeah.
And so what I always like to say is, you know, technology can scale efficiencies, but relationships are what scale the opportunities. Absolutely. And that's not something we really lean in onto sometimes.
'cause we just kinda like geeking out on the tools. Yeah, we do. But you bring up such a great point that so much of this, even in the age of ai, the era of AI Yeah.
Is relationship based. It still is. And it's, which I, I like that because there are soft skills, like empathy for example.
You talked about eq, curiosity, the ability to bridge gaps that are so vital to every role that some of them aren't trainable. You're born with it. Right?
Yeah. Uh, uh, but you can develop it. Okay.
Like if you put a conscious effort. Yeah. Um, you know, naturally I was always hired to be a bit of a change agent Yeah.
To build capabilities that didn't exist before. And I was in travel and entertainment. I was in music, I was in pharmaceuticals, I was in consumer products.
Well, consumer products, travel, entertainment and media and entertainment. Like music industry. They're very, very creative spaces.
Mm-hmm. And so I was always like, well we're building the amazing things. You should use it.
You've been asking for this. Yeah. But it never really cracked the nut.
And then it was storytelling helps, learning their language helps. Right. But then I realized that a lot of this is just fear-based and habits.
So I'll never forget this, but we went to a leadership conference in one of my, the, the CDO role that I was serving for this company. And I was getting massive resistance, even though what I thought we were building was amazing. And so they had me speak on stage and I said, listen, I'm not here to replace your intuition.
Mm-hmm. I'm not here to replace your experience and I'm not here to replace your relationships. But you have questions and you're frustrated at getting those answers.
Mm. So my job is to make sure that you have those insights and those data points Right. When you need them.
Right. So that you could make those bigger business decisions. So don't view me as a threat.
Yeah. View me as your enabler and supporter so that you could lean in more on your relationships and experiences, but the data points that you need, you're not getting frustrated. 'cause you have to wait days if not weeks, to be able to get them.
So I'm here to support you. So consider me a stool, you're here to step on me so that you could elevate your performance and your team's performance. Yep.
And I know my function, it is here to serve you. Yeah. And it was just amazing 'cause the presidents of the divisions and the heads of like the different functional areas, they pause, everyone stopped looking at their phone or doing whatever they were and then you like, they were just kind of baffled.
And then the week later, all the one-on-ones I had requested were now accepted. Nice. I was getting the executive assistant saying, Hey, Matt wants to talk to you.
Hey, that thing that you said really resonated. There's some ideas we wanted. Then I started getting invited to the leadership calls.
And so the goal isn't about threatening or displacing. Right. It's about elevating those that create magic.
That's a great word. I think that's what we technologists do. How do you advise perspective leaders to go from that practitioner role?
Yeah. To leadership. Yeah.
Is I imagine the languages are very different. They're very different. Yes.
You know, I moderated a panel yesterday. Yeah. Which is amazing.
We had the CISO of meta, we had the CISO of OpenAI, we had the CISO of Anthropic. Like those are my rock stars, right? Yes.
Me too. In the eighties it was like Bon Jovi Def Lepp. But now I'm like, oh's, it's Matt, I with you.
Yeah. Um, and they were on a panel and I asked them a very question and it was interesting to see everyone's responses. Yeah.
But the one thing that they had in common was they never lost their practitioner skill, but they learn how to lead and manage because practitioners, we love geeking out. We love going deep. We're kind of hard to manage.
We're a bit an, we're kind of anarchist. Um, we love our bubble and we wanna stay in it. Yeah.
But when you learn to manage and lead, and I made so many mistakes and I have to apologize to a lot of people who reported into me earlier on, I was learning and earning at the same time. My leadership style is so different than the way it was good for you 10 years ago. Yeah.
Um, that's the biggest thing. You gotta learn how to work with people and not just the people that you manage. Yeah.
Also your peers. Yes. Also the people above you.
Like, it's kind of like if you're at the middle of this vector, you've got arrows going and all. Yes. You've gotta be a compass of influence.
Um, compass that influence that takes a lot of energy and effort. Yes. It's draining.
It is. But if you can do it well, you could leapfrog forward. What, what is a timeframe that you've normally seen practitioners being able to take on the education of management of leadership?
This is not, I imagine an overnight process. 'cause there's behavioral changes that have to happen. And as people change is hard.
Change is very hard. It depends. If you're in a startup, you can do it as early as your late twenties, early thirties.
Thirties. Yeah. Um, chief product officers, you know, chief revenue officers, head of DevOps and startups like I've met anywhere from like 26 to 34.
Yeah. But you're an enterprise. The risk profile is a lot bigger.
Absolutely. The teams are a lot larger. Yes.
The revenues that are being questioned are a lot grander. Yes. And so there's an element of per not only just practitioner maturity, but personality maturity that goes into it that showcases you know, how to navigate this world.
And you're not gonna throw a tantrum if you don't get your way. What are some of the soft skills that are essential for this practitioner transformation? Yeah.
Business language. Business language. We can throw, like in the data space, we could talk about lineage and catalogs and enterprise data management and master data management, data security and InfoSec all day long that does zero for the business.
Zero. I don't even use my language in front of them. Okay.
You know, my, my pitch is always like, aren't you frustrated that it takes months rather than minutes to be able to get the information you need? I'll fix that. Yes.
But I'm gonna need six months. I'm gonna need X amount of dollars and I'm gonna need two people from your team because I need them to do X, Y, and Z. Mm-hmm.
And you'll solve that problem in four to five months and it'll be productionalized six. I won't even talk about how I'm gonna do it. Okay.
And then if I get asked, then I'm like, all right, lemme break it down for you. Sure. And then I go into my language.
Yeah. Usually they glaze over again. Say, that's fine.
We'll, I'll be your stakeholder. Here's the funding that you have approved. Here's the headcount you have approved.
Go build. What's one of your favorite stories of impact that you've made and, and in an, in a, in an opportunity like what you just described. Ooh, that's a good one.
I'm sure you have many. I do. Okay.
One of my favorite, favorite use cases for artificial intelligence is building what I call an augmented knowledge store. Yeah. For customer support, whether you're in financial services or commercial banking.
Right. There's warranties, there's offers, there's, there's so much to memorize. Or if you're in consumer products, there's a ton of product SKUs that you have to memorize.
It is nearly impossible for anyone to go through and memorize Yeah. If they're even documented by the way. Right.
And these manuals and PDFs because new service and offerings and, and warranties, like they're constantly being offered day in and day out. And so you're dealing with a group customer support that historically is not tech forward. Yeah.
Not tech centric. They've often been with the company 20 plus years. There's a lot of fear and resistance towards new tech.
Sure. But it also has the most, like the easiest opportunity because it takes six to seven months to onboard a customer service rep from getting to know the process, memorizing the products and services, shadowing a senior person, then actually to ending calls and being shadowed. Mm-hmm.
It's a long process. Yeah. That opex cost is massive.
Sure. Um, so one of my favorites was one of the companies I'd worked with that I said, listen, why are we having our customer support reps me memorizing 80,000 different SKUs? Right.
The focus should be on answering the question as quickly as possible and giving assurance to the person who's calling in to complain. Not on trying to recollect and going, um, um, I don't know. Um, um, let me escalate.
Um, um, hold please. Let me ask my manager. So it's the easiest and the most fun.
And you get to see the aha moments in the customer service reps of creating this augmented knowledge store where they're like, which one of my products are vegan? Which one has this ingredients gonna create an allergic reaction? And they'll get a list.
So as the person calling and asks a question, they have this copilot next to them not to be confused with Microsoft. Sure. But they have this assistant.
Yeah. They type the questions, they get the immediate answers, and then they're able to answer and go, and by the way, I completely understand what you're going through. Let me make sure that my response is exhaustive.
Because even though this isn't a primary ingredient in our products, I want you to be aware of the other products that have it as a secondary and tertiary that's building trust. Absolutely. And brands right now, trust is the biggest currency's.
Absolutely. So easy, so responsive. Um, and customer service reps, they don't have to understand tech, they just have to know that they don't have to memorize everything.
They're empowered 100%. Which every brand needs to have that last question for you. Yeah.
Here we are at RSAC. The, the cybersecurity landscape changes. Yeah.
Minute by minute. Okay. Probably second by second.
What encourages you about where we are in this AI era from a cybersecurity perspective? Oh, I pause because If truth be told, I'm a little bit worried. Yeah.
I think we're still very much in a defensive posture Yes. Versus being an offensive posture. Yes.
Agreed. I think there's still a lot that we don't know. Yes.
Um, our surface area of exposure is not doubling or quadrupling like it's beyond Moore's Law as we go from what we call artificial intelligence. But whether it's augmented intelligence or automated intelligence into autonomous agents where the agents are gonna be making the decisions. We're not there yet.
I'll be very honest. We're talking about it. But by the time enterprise catches up, like the risk profile for that is very, very massive.
Um, there's a lot of steps that go into it and folks aren't aware yet. Our surface area just gets vast. Right.
And right now, you know, earlier stats were saying that there was about 23%. If you talk about 2022 of attacks were cyber attacks, it's now gone up to 50%. But the stats are that by the mid 2026, most of those attacks, it's gonna increase to 75% are actually gonna be machine to machine attacks, not human to machine attacks and the detection levels needed for those.
It's just a completely different ballgame. So we're gonna have to rewrite the script fairly shortly. Yeah.
It's challenging to, to think about how to become proactive when there's still so much defense going on, so much defense, and we're all behind. Like, it's impossible to keep up with the pace of change. It, it's breakneck speed.
I know. I feel like I'm under a lake with a straw, like just trying to get grass, a little bit box, a little bit of air. Yes.
I'm in this space. Yeah. I can't even imagine what it's gotta be like if you're not.
Yeah. Well, it's been so great having you on the program. Thank you for sharing what you're doing, how you are achieving that mission, how you are the bridge between the technical, the non-technical, and really helping organizations pivot from this AI hype to AI reality.
We so appreciate your insights and your time on Textron. Thank you so much. My pleasure.
Bri Rashidi. I'm Lisa Martin. You're watching Textron TV live from the show floor of RSAC in Broadcast la We'll be back after a short break, so we'll see you soon.
Hey everyone, we're back here. Live at RSA conference in Moscone West. Kind of, you know, this time of day everyone's in sessions.
The the din dies down. So you can hear me. Um, excuse me.
I'm happy to introduce you to my next guest if you follow Techstrong at all. He's been on a number of times and he's the CEO of check marks. And if you, again, follow text jar, you know, we have a very tight relationship with check marks and we feature them a lot.
But let me introduce you to Sandeep Jahari. Yeah. Did I say it right?
Yeah. Yeah. Jari.
Yeah. Jari, Sandeep Jari. I know Sandeep actually from before Check Marks and Tricentis, and he has a long, long track record of making successful companies.
Sandeep, welcome to Text Drunk tv. How are You? Thank you.
I'm doing good. Uh, thanks for having me. My pleasure to have here.
Always. Were here a year ago. We were here two, two years ago.
Yes. We were in the same booth. Yeah.
They're giving you the same booth every year. So Sandeep, it's been about two years now with check marks. You've really, I mean, not that it needed a turnaround, don't get me wrong, but you've really left your mark in print on check marks.
We see, I see it in the personnel. I see it in the messaging. I see it in the product direction.
I see it in its standing in the market. Right. Check marks has kinda reclaimed its spot as a leader in the AppSec market.
Mm-hmm. Right. Um, but you know how it is.
If you're not moving forward, you're dying in this market. Right? Yes.
Yeah. So a lot of things going on. If you wouldn't mind share with our audience a little bit of what you see as the big things going on with check marks.
So at at check marks, you know, two years ago, uh, we launched, or four years ago, we launched a product called, uh, called Check Marks one. Yes. Which was our cloud native platform, but was, uh, a comprehensive platform.
And when we talked two years ago, we had just started mainstreaming our customers. Over the last two years, we've made incredible progress on check marks one, um, one, it now is more than 50% of our installed base, and we are scanning over 450 billion lines of code every month. Uh, we have also, it, it, it has, it is the most comprehensive platform for AppSec.
It has, um, sas, obviously SCA, but we've added malicious code, we've added secrets containers, we have added das. So it's really the most comprehensive platform, which is why most of our customers are now moving. We are at more than 50% by the end of this year.
We should be at 70 to 75% of our customers having moved. We will have some laggards, primarily government agencies and, uh, and some very large enterprises. But the move to check Marks one has been quite incredible.
It's, it's one of the fastest moves to a cloud native platform from an on-prem, uh, solution. And, uh, like I said, we are scanning literally, uh, more than a million, uh, uh, projects a month. More than 450 billion.
Almost a half a trillion. Yeah. Yeah.
We, we Lines of code a month. Yeah. Well, a half a trillion, which is, you know, rapidly increasing.
As of the end of last year we were doing three 50. So literally in one quarter it's gone from three 50 to four 50. So it's really as accelerating.
And the reason for that is check marks one is not only a comprehensive platform, but it's also a very dev centric platform. Yes. So we, uh, we have IDE plugins all the way.
So it really shifts left. And that's what's driving a lot of the increased, uh, scanning because now developers individually can kick off scans, uh, you know, as they're writing code, literally with every pull request they can scan. And that's what's, uh, driving it.
So that's been, that's been a huge, uh, huge, uh, focus for us. You know, to me it, it's riding on two very important trends, waves in the market. One is, it's a platform.
I was, we were talking, we did Techron Gang this morning. I don't know if you saw Palo Alto acquired some AI company yesterday. I need some move towards a platform.
You know, you've been in security a long time, as long as I have, you know, this security small companies make products, medium companies buy the small companies. And those products become features. Yeah.
Bigger companies buy the medium companies and those products and features get rolled into a platform, Uhhuh. 'cause with a platform, you have an ecosystem. You have the company's entire platform of things that plug in.
You have third party partners, whether it's API or however that plug in. And it allows you to do things that you can't do at just a product level. Mm-hmm.
It's that platform. So I think it's really, especially when we talk about like the move to cloud native, moving from on-prem, modern app application modernization, microservices a product, a point product, it just doesn't cover it. You need mm-hmm.
You need that platform. Secondly is the idea of who's the user of this platform. I think unfortunately the road is littered with security companies who thought they were gonna do DevSecOps Nirvana mm-hmm.
By building security products for security people that app dev would use. Mm-hmm. App dev doesn't use security products.
Yeah. It's just, that's for security people. I think a lot of companies got hung up on that.
Mm-hmm. One of the nice things about check marks, one is it is a security product, but designed for the app dev audience. Yes.
Mm-hmm. And that, that's, it sounds subtle, but it's not subtle. It's, it's a major to do here.
So I, I think that is a big reason for the success. Yeah. Actually, when I joined the company, I met with literally, uh, uh, reached out to a hundred of our CISOs and they raised exactly the two points you're saying we want, we don't want point solutions.
It's too noisy. We want a single platform. And two, we wanna shift left, move away from only security using it to developers using it.
So those were the two design centers of check marks one. And over the last two years, we have spent a lot of effort on making sure that the developer experience is incredible, because developers at the end of the day don't care much about security. They don't like security.
It's a barrier to their speed of innovation. And therefore, our job as security vendors is to make sure that while we give them the efficacy of, of having good deep security, we make it also easier. So we have spent a lot, and one of the things we've announced recently is we have an A SPM built into our platform, but the A SPM originally was targeted in, initially was targeted at the security professionals who could take feeds from all the engines and then have an A SPM to kind of sort it out and do correlations and exploitability and the like.
And what we've done, we just recently announced is, uh, we brought the A SPM capability right into the IDE again for the benefit of the developer, so that it makes it very easy for the developer to be able to remediate, to understand the priorities of, of which vulnerabilities they should be working on, and then be able to remediate. So we've also added, uh, ai, um, help, help capability in the IDE. So when you get a vulnerability, you get told how one, it explains to you what it is, and it gives you suggestions on how to remediate it.
So that's all driven towards making life really easy for the developer. So, wonderful. Not everyone watching this is a security person.
So let me ask you, A SPM stands for application, Application security. Posture management. So it, it allows you to take, uh, vulnerabilities that are identified by multiple, uh, multiple application security engines, uh, static analysis, open source and the like, and pull it all together in one area.
One place where you can do core and prioritization. So that's what A SPM does. Absolutely.
You know, you were describing the mission of trying to create an environment that allow developers to go fast and secure and get code out. And that really describes the whole platform engineering mm-hmm. Mission, if you will.
org community uhhuh on our platform engineering show. We, I did a, uh, I actually did a round table webinar, I think last week. Yeah.
With some of the check marks and other people. We get tremendous, the audience is so involved asking questions, they drive the whole thing, but it really is where the rubber's meeting the road right now. Mm-hmm.
You mentioned AI as well. Sunday, this whole show here, this here is AI uhhuh, and I get it. Everyone wants to have, you know, remember when the cloud came out, what's your cloud story?
Every VCs you, what's your cloud story today? It's what's your AI story? It's hard to stand out with 600 vendors on that floor, and they're all touting their ai.
Talk to us about the check marks AI strategy, if you will. Yeah. So, um, our, our AI strategy is multifold.
One, we are using AI and agentic, uh, products to redefine AppSec. The traditional way of doing AppSec was, like you said, the security people would look at the results, prioritize things, and then send it over to, to developers. Today with AgTech, uh, solutions, what we can do is take all those vulnerabilities, prioritize them, and allow developers with one click to be able to fix them.
So we, we are a strategy is to have agents that are targeted at different personas. One agent targeted at the developer, another agent targeted at the AppSec administrator, or the AppSec team that does the prioritization, sets the policies, sets, uh, you know, policies across different projects and the like. And the third agent targeted at executives that want to look at application security from a risk perspective.
And so we plan to have three such agents out in the market shortly. And so that's around what can we use AI to make AppSec a whole lot better? Gonna redefine EC, if you may mm-hmm.
On, on how it's used at an enterprise. And platform engineering becomes really important there, because every enterprise that I'm talking to wants to move from DevOps to DevSecOps. And you can't do that Yeah.
Without integrating this fully. So our agents will help further speed up the remediation of, um, of vulnerabilities, which is ultimately the goal of AppSec. The second part is a whole set of new vectors that get introduced because of ai, because of LLM.
So we have, uh, our research team is doing a lot of work on what are the new threat vectors that come about because of ai. And this is things like, uh, you know, uh, prompt injection or hallucinations. How do we capture that?
It's a lot of what Palo Alto bought in protect ai. Right. We actually were partnering with them as well.
Really. But we continue to have our own products on that. So, so it's both, it's twofold, if you may.
So Absolutely. Um, $700 million on acquisition, a lot of money, But everyone needs the buzz. So Buy a lot of buzz for 700 million.
But anyway, let me ask you another question, though. Again, you've been in security, you're a successful multi-time CEO. Do you worry about what are we going to do?
Will we have too many agents? Everybody has two agents, three agents, another agent here. They're an agent here, an agent everywhere.
An agent. How many is too many? Yeah.
I, I think, uh, I, I think the way to think about agents is, uh, they're really, uh, I, I know agents are defined as really some things that are operating con fully autonomously. I think that's a long ways off in that. You, uh, I was talking to a CISO of a large bank yesterday and he said, you know, for security, we actually want agents that can help, uh, resolve things.
But we don't want auto remediation. We want human intervention. So like you, like we were talking earlier, AI is one of those things which, uh, you know, it's not that AI will replace humans completely.
AI will replace humans with humans that are enabled with ai. Right? Right.
Or AI enabled humans will replace humans, not that AI will replace humans. And we think of it that way. Our developer focused agent, for example, uh, will have the ability for, uh, for human intervention where, where we think of it as you can do auto remediation.
At some point, you might be comfortable enough to be able to do that for a certain class of vulnerabilities, but for a different class of vulnerabilities. For the more critical ones, people would want some human intervention to have some oversight on it. To your question of too many agents, well, we'll see how, how these go.
Some of these agents are just AI washing. They're not really a whole lot different than what people have had before. They're presented in a different way.
Uh, so I, I think there might be a little bit of overhyping if you may. Mm-hmm. But the other aspect is that with, uh, with MCP and A two A, you will have agents talking to each other and what every enterprise we talk to are just as worried about the governance.
Yes. Around these agents where you need auditability, you need traceability. Like the bank CISO I was talking to, he said one of the main things, one, one of the big things they need to be able to demonstrate to their regulators is not just that they don't have any vulnerabilities, but the ones that they discovered, how did they resolve them?
How did they discover them? How did they resolve them? And the, is there a record of all of that?
So, um, you know, it's, it's, it's still evolving. I think it's really exciting. All the agent tech stuff where you're making it, I think of it as a dramatically simpler user interface, if you may, with a lot of intelligence built in.
Agreed. Agreed. I think of them almost as ephemeral.
Right. Because they're not, they do a specific job and when they don't doing that job, they go back into the box. You know what I mean?
Um, but I do think what you said about we will have humans empowered by ai, not humans replaced by ai. Correct. At least, at least for as long as you and I are going to be involved down the road may be different, but who knows?
Um, I mean, if you take even code, uh, you know, the, the, the, the quintessential use case of using, uh, using code, uh, coding agents, even there, the most powerful coding agents are the ones where they assist humans and humans are involved. We are not having people write things automatically without any human oversight. So absolutely.
Just one last area I want to talk return to check marks. So you've got the check marks one platform got so much going on, AppSec is such a dynamic market right now mm-hmm. For our audience out here, what do you think over the next year, we'll sit down maybe, well, we're gonna sit down in a month or two, but not in person uhhuh, but for the next year, what should we focus on?
What, where should the focus be? So, I I, the, the trend I see in AppSec is really what we talked about earlier, which is, uh, how do we, every enterprise I'm talking to is looking at consolidating their functions, uh, consolidating their AppSec vendors. And, and I think this year is gonna further accelerate that with agents that are sitting over all of these engines.
I think it further accelerates that. The other aspect is people really want to get, uh, the shift left, move, it's not yet fully happened. They're still large enterprises that are trying to embed security into the development, uh, workflow.
And I think we'll continue to see that. So at check marks, we continue to focus on the developer experience, continue to drive functionality across the platform, like we've added, uh, secrets, we've added containers, we've added das to really make it completely com comprehensive. So there's only one, I don't think there'll be a consolidation of all security platforms as you were talking about, where a Palo Alto buys up everything from code to cloud.
But we are very focused on AppSec and being the best enterprise solution for AppSec. And that's what we are focused on. That's what we hear from customers that they want, uh, especially the larger enterprises that have complex environments.
So that's what we are focused on. Love it. com.
Yes. com. com.
Sandeep a pleasure. Okay. One of the great gentlemen in the valley here, if you ever get a chance to meet him in person.
Thank you. We're live. Thank you.
We're live here at RSA. We'll be back in a moment with more coverage. Stay tuned.
Thank you. Thank you. Good morning.
Welcome to Text on tv. Day two of our coverage, live coverage of RSAC from Moscone West in San Francisco. This is Techstrong's, 10th year of covering RSAC, but of course, our fearless leader, Alan, has been coming here for much, much longer than that.
We've been talking with cybersecurity experts about really the evolution of the security landscape. My next guest is ael ti, the CEO and founder at Iron Scales. Ael, welcome to Text on tv.
It's great to have you. Thanks Lisa. It's good to be here.
I Love the name Iron Scales. It's such a powerful, bold statement. Talk a little bit about, you said you founded it about 10 years ago.
What were some of the gaps in the market at the time from a security perspective that you thought we can solve this? I, I think there were two main gaps. I think the first one was that phishing was still making it to the mailboxes.
Mm-hmm. As a security researcher and malware analyst, that was where I was finding all of the good ideas on what to investigate research. And the second is that teams were spending a lot of time dealing with this type of threats, getting them out of their mailboxes, making sure that people, um, are aware.
Uh, and there was a shift, a big shift in the, in the landscape world. Threat actors were starting to understand what the defenders are doing, what the sex are doing, and looking for new, more clever ways to fish businesses and, and employees. Phishing has evolved so fast.
It used to be clunky, basic email scams that like spelling errors. It was just obvious it was a phishing scam. 0.
Where are we now? 0 DeepFakes. It's just evolving at breakneck speed.
Yeah. 0 problem, where FedEx was mostly sending bad links and bad attachments and trying to lu employees to click on a link or download an attachment and installed some backdoor on their, um, computer. And then it really evolved, like, you know, with the security email gateway was kind of scanning links and scanning attachments and making sure that all the known threads are out of the, the inbox.
The threat actors, they evolved into sending emails with no links and no attachments. And instead of trying to hack your computer, they are hacking the business process. They're trying to make you pay a, an invoice, which is not really, it's fake.
Okay. Pay an invoice Or wire some money, or go and buy something or do do something that you are not supposed to do, um, as an employee. And when you think about what, cus what companies are using that they, in order to protect against mls, they couldn't found this email because, uh, there was nothing bad.
Yeah. They looked so normal. They looked very normal.
It was sexual, like the semi legitimate request to do, to go and do something. 0 era basically began and we realized that in order to really protect organizations and people against Phish, you really need to go down from the gateway level to the mailbox level. We have to live and breed what's happening in everyone's mailbox.
Really, really understand it, you know, what communication looks like, what what can be trusted, what can be trusted, understand language. Yes. What first time using LLMs and NLPs to extract intent out of, uh, emails and understand that these people is asking someone to pay something and really start to understand that this person really sounds like or looks like someone that's walking Like your CEO asking you to wire money or something.
This impersonation of people is scary. It's Always someone or something that you already know that You're familiar with. Exactly.
Okay. Exactly. This is kind of the basics of, uh, fishing and how you kind of gain trust and make sure that people will go and do, uh, what you're doing.
And that was the phishing two point era. And we started to implement a lot of the smart AI and ML models in order to be able to build baselines Yeah. And find anomalies and things that are kind of deviating from what we consider to be a trusted communication or a trusted, um, email.
It was proven to be super effective against the, again, the bcs, the business email compromise and the vendor account compromise. It can take over tax and all of the next gen type of, uh, phishing emails. The was really not doing a great job in kind of keeping out of the the gate.
0 World Security teams were doing a lot of manual work. You order manual work to Keep The, the hygiene of the, uh, environment and their in books as writing and running scripts, um, doing a lot of, uh, signature writing and rules writing. And they really kinda spend a lot of time with the email security solution in order to try and keep it up to date and play this kind of catch up game with the, with the trade actors.
0 we, we, we've realized and decided that it's time to really go and automate, I was gonna say automation sounds like the Yeah. The winner here, you Have to go and automate a lot of this kind of stuff that, um, they're doing from the most kind of investigative, uh, parts of the security analyst job to the even more kind of, uh, response part, which we actually go and claw back emails back from employees mailboxes. It was a novel idea.
Like, you know, it was like how you can actually go and pull back, back emails that were already, and answer was yes, you can do it if you can do it in a very short amount Already opened, Not opened. Okay. But delivered.
Delivered. Yeah. Got it.
Because we know it takes about 82 seconds from the time it was delivered to the time it's, it's opened on average. Okay. This 82 seconds.
It's a lot of time that we can act. Yes. Not to mention if we can do it in under one second, which is what we can do in 99% of the cases, then the problem, uh, goes away.
And by doing that, first we reduce risk and second, we reduce in more than 90% the amount of time the threat act that the security teams are dealing with, uh, phishing emails in order to keep them out of the mailbox. The automation is key there because you were saying, you know, the, with this rapid evolution of phishing, security teams don't have the time. I'm sure that's a full-time job for, for several FTEs to just monitor a business email account across employees across the globe and regions.
So the automation is critical there, especially because the sophistication of phishing is just going up and up and up. How is AI maybe a double-edged sword there, like leveraging it for, um, to be able to detect these really sophisticated phishing scams, but also the, the fishers having the technology at their disposal to dial up the sophistication? It's a good question.
So with the introduction of technologies like GPT for example, we've seen an increase of 1000% from 2022 to 2023 in AI generated, uh, phishing game Phishing scams. And this was 1000% Before the peak. If you look at North America, uh, alone, it was close to 2000%.
It was 1700 something. Yeah. Uh, percent, which is a, a crazy amount of, uh, emails.
And the other thing is that phishing, phishing in 2025 or even in 2024, it's not just about email anymore. Like, you know, phishing in email used to be a synonyms like no. Yeah.
Email phishing. It was like almost, uh, the same thing. Now we're seeing new modalities kind of things.
Produce voice, voice deep fake voices. That's scary Because videos so legit. Oh, and videos too.
Videos, Yes. So they're using more email to Phish employees. They can use your, uh, mobile, they can use your teams slack, zoom.
Wow. And we are seeing already, we're seeing kind of real cases That's sur that attack surface is going this. Now you need to kind of be able to look at all the communication channels and make sense out of all of it.
And detect not just AI generated stuff in the inbox, but you need to be able to detect It is text on tv. It's getaway day here at RSAC, Lisa Martin here, having had some amazing conversations with cybersecurity leaders across industries the last four days. But you know, because you've been tuning in to text on TV and all of our other digital platforms.
My next guest is a veteran of Text on tv. My first time interviewing her, I'm a huge fan. Caitlyn Sien joins us.
She is at Cybersecurity Girl. 6 million followers across social media. You should be.
Caitlyn, it's a pleasure to have you on the program. I'm so happy to be here. Talk to me a little bit about, you have a mass in a short time period.
6 million followers. I'm one of them. TikTok, LinkedIn, Instagram X.
How did you do that in such a short time period? I, I don't, I don't know. Um, so I started on TikTok originally and I really was embarrassed 'cause I've been in cyber for 12 years now and I'm like, if anyone finds out that I'm on TikTok, I'm gonna be destroyed in, in, in the office.
And, but I really wanted to reach the next generation. That was like the main reason. I was like, I want people to understand like everyone it like is needed in cybersecurity.
And cybersecurity is not something scary and they can get in and it can be fun. And we also need more women. I wanted women to see themselves.
Yes. Because when I was first introduced to cyber, my immediate gut instinct was absolutely no way I'm ever gonna be a part of this. Yeah.
I was like, I'm not a man. Yeah. That's, that's the number one reason I'm not a man.
And I was like, I didn't see myself there. Like, I just was like, that's, I'm not a coder. Like I don't, that's not where I'm supposed to be.
Yeah. And that was like the main reasons why I started. And then I started doing more education on just the general public on like what cybersecurity is and honestly how simple it can be and how it's not scary.
It does not need to be scary, but it needs to be like, the conversation needs to be had at home. And I always say cybersecurity starts at home and it's not a scary thing. It's a, it's a necessity.
It's a total necessity. Um, and so that's kind of how it started. And I, again, I only started on TikTok four years ago and it wasn't until the last two years I put started doing on Instagram.
And the reason why I was called Cybersecurity Girl is 'cause I didn't want my name on it. So I didn't have my name affiliated with it at all for the first like year and a half, two years. Okay.
So no one I worked with knew that I was doing it on the side. And then it wasn't until I got hired by TikTok and then I'm like, oh, now I can actually say it. 'cause they, they found me from my TikTok.
They found you. Yeah. So it just been incredible.
I mean, it really shows how important cybersecurity is now. Hundred percent. And how, how people really wanna know.
And the reason why I'm a little bit different is 'cause I, I like Shortform. Like I don't do long form YouTube. I don't even really do XI, it's really just been like TikTok and Instagram and Shortform is for me is so important because people don't have the attention span.
And honestly, even if they did, the general public does not wanna hear an hour long. They conversation about cybersecurity. No.
So what do they need to know? Like how is it impacting them and how can they fix it? Yes.
So like relatable, digestible, understandable content. And that's what I love to do. That's exactly what's needed.
I'm a marketer by training. I've been doing marketing and tech for 20 years. Media for, for about 10.
But people want to be educated in the simplest, cleanest way. Yeah. And you just hit the nail on the head.
Digestible, clean. How does it affect me? Right.
You know, one thing too that we're dealing with now is I was mentioning my mom's almost 80 and she's digital. She's a facebooker. She's now an Instagrammer.
I introduced chat JPT the other day. I know. I was so proud of her.
I wait for my boyfriend under the bus, but he is, he still does not know anything about chat gt. What? I'm like, I don't know if I can be in a relationship with you anymore.
You gotta educate him girl. I I I'm Trying, we're trying. We're working on it.
But we've got like five or six generations in the workforce today that are digitally active. Yep. And some of those populations are way more susceptible than others.
Yeah. So I learned a lot from you in the things that you post. 'cause you make it clean.
You make it simple. You make me go, oh, I didn't think about that. And so I teach my mom a lot of the things that I learned from you because I want her to just be, you have to, you can't just blindly trust everything anymore.
Right. We've learned that time. And again, ransomware is a household word.
Ransomware attack happens. I i the status from a couple years ago, once every 11 seconds. Right.
I'm sure that time is going down now. Right. It's only gonna continue.
But to your point, the education has to be there consistently. Right. Well, and there's two, two points I wanna hit on that.
So the first is, we also always think about our like, you know, older population of like, oh, they're susceptible. But the issue actually is the younger generation. So the older population gets hit with like larger ransomware issues.
Like they have the, the most money. But actually the most people that are getting hacked are the younger generation because they're so blindly accepting of the technology that they don't think anything of it. They're not like, meant to be skeptical of it because that's what they grew up with.
And so it's real. That's, and that was why I was like, let's reach the next generation. 'cause all these people, I mean Yeah.
They're not gonna have monetary value 'cause they can't really exploit kids point. Yeah. There is sextortion, which is a whole nother issue.
And that's like, it's awful. And we're trying to mitigate that too. But a lot of these kids are actually dealing with similar issues as the elderly, but the elderly have way more to lose.
It's Right. It's the financial hit. And then the other part is like, similar to what you said, like cybersecurity is a human issue.
Like phishing and like, like reusing passwords. Like again, the Verizon DBIR report just came out. I went on, I went to their session yesterday and they were saying 60% of all of these, um, threats and, uh, vulnerabilities are human centered issues.
So whether you reusing passwords Yep. Or access management stuff, like, and or clicking on a link. It's all like human at the end of the day.
And so that's like what I'm trying to get at. I'm like, I feel like I'm protecting the companies at at this point Yeah. Too.
Because it, the learning has to happen at home. Like when was the last, when last time you learned like, what, what did you learn? Like last, obviously you do this so you learn a lot, but like when you're at home, like how do you learn, Uh, social media?
Yep. So that thing news, everyone is losing on social learning on social media. I Through it with a grain of salt.
Oh yeah. You have to. Yep.
And but, but with deep fakes and the advancement and the sophistication of like phishing, smishing phishing, it's getting harder and harder to detect. Yes. But I like your tagline that cybersecurity starts at home.
It has to it has to. It's not a nice to have anymore. This is how it needs to be like a fabric of our lives.
Yep. And we were just talking, I don't know who it was with, but like, someone was like, yes. Oh, I know the founder of the hacking games that we were talking about how cybersecurity marketing has been such, it's been terrible.
I was gonna say a bad word. I'm not gonna say a bad word, but it's been terrible. Like we've been, we've been marketing cyber all wrong, even like companies.
Right. Like cybersecurity is not something scary. It's not like Yeah.
We just need to mar like market it to like, and bring it to the people where they're at. Yeah. And they're like, you know, online just general human beings Right.
That are like, I mean, we connected on Instagram. Yeah. It wasn't because I like met you through, you know, some Right.
Yes. Forum. Yeah.
Yeah. But, you know, so, so it's starting at home. But also another thing too is just the, the commonality of it.
And we have to expect it's there. Yeah. With, there's more data, there's more software, there's more apps.
That trajectory is just going up and to the right. And it's not gonna slow down. Nobody wants less apps or less data slower.
They just don't, We do want less op uh, less like signing in for accounts. Yes. Can we stop that?
Like I'm, I'm a fan fingerprint. I'm like, it's me. Yeah.
Yeah. Hi. I'm the problem.
It's me. Yeah. But, um, it's just such an interesting love The Taylor Swift coat, By the way.
I'm a swifty. Yeah. This is why we kinda have nice things.
Yeah. We can throw you another one. Um, but I, I just, I think that it's so important to educate folks and it has to be consistent.
And, and when we're here it shows like RSAC. We get to see so much of the technology that enables that fabric. Yeah.
And now that we're in the AI era, which, how do we secure? Yes, me too. Yeah.
There's so much potential. Yeah. But there's a lot of fear.
And so what I like to do is, let's pull out, and I think you're similarly minded, let's pull out all the positives that are there. Like, we talked a lot this week about how does software company X, YZ help customers, whether it's financial services or healthcare or automotive, become proactive Right. Against the attackers.
Right. Because technology is neutral. Good uses, bad uses, it's like fighting fire with fire.
But it's, there's never a dull moment. And we need more people like you to educate the different user generations and groups of where the risks are. 'cause they're not going away.
No. No. And I, I also like, love the, I love ai.
I think it's the coolest thing ever. And like anyone that like doesn't use ai, I'm like very skeptical around me too with my, including my boyfriend. I'm like mm-hmm.
Um, but I think there's also a conversation that needs to be had around like, 'cause people keep saying like, ethical ai, ethical ai, I am like ethical is like moral based. Like everyone has different definitions of ethical. Yes.
So I guess it's like, how do we build AI and like, like what standard like baseline standards do we need to have to say this is good versus this is bad. Right. Right.
Because we are even talking about that on like hackers. Right. Like, we're talking about how kids are, we're trying to get kids into ethical hacking versus like, you know, a lot of times kids get like pulled into the wrong thing when they're doing hacking.
But we're like, okay, at that point, what's ethical hacking like Yeah. Where is a line? Like, can you scam a scammer?
Yes. Yes. Like, is that ethical?
Yeah. Because you're still scamming. Right.
But like, so it's the same with ai. Like how are we drawing that line of like what's right and what's wrong? Yeah.
And what, what AI should be doing and what ai AI shouldn't, And that's so nebulous right now. 0 and this Japanese animation studio. Have you seen those Japanese animations that are like flooding social media?
And so the whole Have a very like, narrow lane with social media. You, 'cause all I see is like text stuff for you and because it's, it's for work. But anyways, I did not see it.
But It's, so the whole copyright infringement Okay. Challenge is there. And it's like, well, AI and, and you know, chat, DBT anthropic, all of them are te are training their models on all of this information that probably they have without permission.
Right. But how else do the models learn? So there are fine lines, but I think the challenge is it's so nebulous.
There are many fine lines. Yeah. So to your point on ethical hacking, where, where are those lines?
Yeah. It's not a, it's not a straight answer. Right.
But you also talked about people, and I always say, I had this friend called up my other show who created stickers and used to have stickers on his laptop. And one of them said, humans Yeah. Ruining everything since forever.
Right. And I loved it. But in cybersecurity, humans are, I think two things.
The weakest link, but also the biggest potential asset. Yeah. Do you Agree with That?
Oh, For sure. Yeah. And I always used to say like, you're only as strong as your weakest link.
Yeah. With every company. I'm like, I don't care what what you do, but if, if someone's clicking a phishing link, it doesn't matter any of the software they anything that you deploy.
Right. So I, I don't, I always don't understand like why companies don't spend more money on training and awareness. Granted, I think there's a lot of, uh, training awareness companies that need improving.
Agree. Um, I, I go to a lot of training and awareness conferences and stuff and I'm like, eh, can we not another fishing email See Opportunities? Please.
You see? I know, I Know. Yes.
Um, there's so many other ways to do it, but, um, yeah, I think there's so many opportunities because again, you're only as strong as your weakest link. Why aren't you spending more money on trying to like, again, educate the people where they're at? Like, why do we keep shoving training and awareness into, into corporate, you know, employees faces?
Oh yeah. Around, Hey, you need to protect corporate. Why do they care?
Yeah. Why would, why would I care? Yes.
Who cares? I mean, yeah. It's, it might, you might lose your job, but like no one, you have to get to them.
Like actually, like the impact, the impact that it matters. Like okay. How to protect your family.
'cause they guarantee you, once they start learning how to protect themselves, they're gonna start learning. They're gonna automatically protect the company. Which is good.
Right. That's The right pathway. Right.
But we're not even teaching 'em like that. No. Because it's a check the box and then there's like some fun awareness stuff.
But it's like me. So how do you, how do you advise companies to change that? Make it more fun, but to your point, go where they are.
Go to their comfort zone. 'cause people don't wanna get comfortably uncomfortable. Right.
It's Hard. Oh, very. It's cultural.
Yeah. It's behavioral. Well, that's how it, that's how I always recommend.
I'm like, okay, what, what is, what is your company culture? And if you were them, like I always, whenever I talk about training awareness professionals and people like are wanting to get into cyber, I'm like, you should start with training awareness. Yeah.
Because those is, you are the, the prime demographic people that have no idea what cybersecurity is. Yeah. And you're trying to get in and you're trying to understand, but like get understand the culture.
Yeah. Get someone in that's not, that does not care about cyber, does not understand cyber and start picking their brain and asking 'em, like figuring out how, like how you can relate to them. Yeah.
Um, because that's where you're gonna have to meet them. Yeah. And then to just assume that most people fall in the middle.
But like, you can't, as, you can't like do a check the box training. You can't. No, because I, when I worked at TikTok and I was trying to redo their internal training too, like I had to get so much oversight from like legal and like GRC.
I'm like, this training is not gonna do anything. Like, you brought me in to like, you know, spice things up with training and make it more fun and do short form videos and, and I'm like, and I can't do any of that with like, the way that you're redoing my entire like, script. That's What kind of anti TikTok mindset It was.
It was kind of weird. It was kind of weird. Yeah.
I love TikTok though. But it's, yeah. What, What has surprised you in the last few years of being cybersecurity girl and, and amassing this following who are learning so much from you?
What enlightens you about the direction that career paths are going? What's out there? That's good.
I mean, there's so many things that are out there that are good. And s honestly, so many cybersecurity people are good. Like, there's so many of us because we got in, like, we were pulled in from other people that we wanna help and mentor and like help other people.
What's um, incredible is like how many people are wanting to get in. That's good. And I don't wanna be a negative, but like now we're at this point where I get so many people messaging me being like, Hey, I've gotten this certificate, this certificate, this certificate.
And I can't get an entry level job anywhere really. So whatever they're saying about entry level roles is a load of bs. Okay.
So, because I think a lot of entry level roles are actually mid-level roles Okay. That are trying to be paid as entry level. And a lot of companies don't actually wanna train the people on site anymore.
Okay. Which is really sad. 'cause that's how all of us learned.
Yeah. I mean, all of us got into cyber. We were brought in by a mentor trained on, on site.
Right. I'm sure, I mean I'm blanket statementing. I'm sure there's a few companies out there that, but like a lot of the companies I've seen, they have like entry level, well mid-level roles classified as entry level and they want people with actual like more skills.
And there's so many people, like I get like at least tens to hundreds of people a day messaging me being like, how do I get in? I don't know what to do. And there's not really a direction yet.
So I'm really excited 'cause there's so many people that are interested in Yeah, that's good. Now we have to figure out as a even like a country or like a the world honestly. Yeah.
How we're gonna navigate this because also the, the definitions of cybersecurity are different in every company. Oh yeah. Right.
Like everyone has different teams. Like some has access management and they, they, they're, maybe they're doing the same thing. They're called something different.
So like I was trying to work with NIST and say, Hey, is there a way that we can have like 10 of the same exact entry level roles exactly the same or exactly like equal with the what you need. Like, so, okay, hey we have a SOC analyst that needs these like qualifications. Then we have like a threat intelligence person.
So I want the same titles Yeah. With like clear expectations of what they need to get. And that way, like when people are hiring entry level make, make the fortune 100 all do the same when they're hiring.
Yes. It'd be a lot easier to transition people in. It would, and then you can train them then on their company culture.
You pick them on their com your company culture best. Right. The Alignment best.
Right. Yeah. So that consistency is, is critical.
It's no longer, um, a nice to have that the, the awareness has to be consistent. Right. I been, like I said, marketing 20 years in tech awareness is key, but it can't be a one and done thing.
Right. And it has to be tailored to your audience. Right.
Right. And there are so many different audiences alive and you know, in, in the digital space today, I went to the restroom earlier and I saw a payphone. I'm like, there's still payphones around here.
Yeah. I remember having to use a payphone in high school. But I have a question for you.
Yes. What's like one thing that you would change with either like awareness or marketing in like cyberspace that you like, wish it was like already fixed? I think that it needs to be, to your point, it needs to be explained in a way that this is achievable.
Right. And it's not scary. It's not scary.
It's a massive opportunity. It's only growing. Mm-hmm.
So the opportunities will only grow. Yeah. But I think to your point, from an education and awareness perspective, I I I hundred percent on that consistency, but it has to be explained clearly.
Yeah. A lot of people like to get on soap boxes and all these acronyms suit here and there. Oh, We don't talk about acronyms.
No. Me straight. I do not say me sniff straight pushing.
Yeah. I don't even say cing anymore. They're scam messages.
Yeah. Yeah. That's what it is.
No one, if you start doing like technical jargon, their eyes glaze over Yes. And they're gonna be like, I don't, I can't even touch that. Yes.
That's not even something I wanna touch. I've learned that from my radio role where we talk to more consumers. Mm-hmm.
It's, it's how do you take com and you and I were both in the sciences, both in aerospace back in the day, and it's about taking complex topics Right. And converting them to digestible sound bites that a non-technical person can understand and go, I get it. Yeah.
Well, I don't feel like I ever was supposed to be in cyber in like a weird way. Yeah. Because I never wanted to be, and then I learned everything on the job and I still, I don't know about you, but I still feel like I never know enough.
Oh yeah. Which is the best place to be by the way. Like, I always wanna, I wanna be in a room that everyone knows something and I know nothing.
Yeah. First of all. But then I also just feel like because of that, I like had to learn weird ways.
Like I don't think I'm, like, my brain is supposed to operate the way that most cybersecurity things are, and so I have to learn it in a different way. That's good. Well, it's Not Diversity.
Yeah. It's, but which Is so Necessary. Yeah.
You Brought up earlier, you know, when you started your influence career and I that you couldn't, it was that saying like, we can't be what we can't see. Right. I do a lot of women in tech events and it's true.
Yeah. We need to have mentors out there and sponsors Yeah. That look like us, that feel like us that go, okay, I could be accepted here.
Yeah. And the older you get, the less you care about that stuff. I will tell you.
Yeah. But, Um, yeah, but it's the younger generation that we're trying to get in. Yes.
You know, it's Yes. But there's so much job opportunity. I mean, like, I I work with companies all the time that will have like different, um, programs.
Yeah. Like some, like Boomie, I'm seeing Boomie World in a couple weeks and they have, um, a veterans program. So they work really hard with, with war veterans to get them into cybersecurity and into technology.
Right. And I, I think there needs to be more light shined on things like that. Yeah.
Like there's a lot of doors and pathways. But to your point, if the employers are making it complicated Yeah. That's not gonna help that pathway become men easier.
And the other thing is, I don't know about you, I feel like as a woman, because there was like D-N-I-D-N-I initiatives when I like got in like 12 years ago, I always felt like I wa I didn't know if I was hired for the right reasons. Yeah. Even though, like I, and I, I'm not, I'm gonna toot my own heart.
I had an incredible resume. Like, I, I had three jobs in school, I had three different internships. Like I nailed my interview, but I always had that like weird thing in the pit of my stomach being like, was I only here for, because I'm a woman?
Did I check a box? Did I check a box? And then it really made me like the imposter syndrome actually really like setting a lot of times.
Yeah. And I, I actually am kind of happy, like I want as many women in this field as possible. Yeah.
But I also want the best, most qualified people in the role. Yes. And so I want to make sure, I feel like it helps with imposter syndrome too, from a woman perspective.
I agree. Like, don't hire a woman because we're a woman, hire the person for the right role and we're, we're trying to train the women to be the right woman. Yes.
Right. So I think there's like a weird, well There's also all these stats and I'm forgetting the actual specific stats, but like, like, I don't know, 80 plus percent of females, if they see a job on LinkedIn and they don't meet every requirement, they don't apply. Whereas men Oh, I got that.
Yeah. And so, and now with ai it's even more challenging because everybody wants people with AI experience. You're using AI to write your copy.
How do I set out, I use Ai, write everything. Oh, I wrote my radio hit for tomorrow morning. Right.
GR chat this morning. Yeah. It's the best.
It is the best. I I like it as a, a creative inspiration. Right.
That's how I Leverage it. I, I have a lot of good stuff going in my mind. Probably, probably you can tell with all the conversations that we have, but it, it really helps me do like a brain dump and then it helps me reorganize Oh yeah.
How I should frame things. Yes. So that's what I love about it.
Yeah. But I think for folks that rely on it, that's a different story. Yeah.
And I think I, I was reporting on this recently about like, it's a really high percentage of, of students between like 17 and 25 who are dependent on things like chat, GPT. Can You imagine going through school with that as a resource? I would be dumb.
My thesis I've would be dumb would been so much easier. Yeah. Or I would Be, that's, that's the challenge.
Are you not learning enough or retaining it because you can get it spit out you back at you in seconds. Yeah. So it's, it's a double-edged sword.
Yeah. But it's like, like I say, technology is inherently neutral. It's used for good and bad.
Right. Let's find all of the good uses and amplify that everywhere. For sure.
I feel like a sense of responsibility as, as, as a tech executive and now a reporter and media person to help more people understand how not to be afraid of things like ai. I talk about it all the time on the radio. Yeah.
Why there are risks and I want to help you be aware of them, but let me tell you all the things that it's already doing that you're interacting with that you don't know. Well, and I think I, I was talking to someone else about this, like, I feel like everyone's like, oh, buzzword ai. Buzzword ai.
But like, we need to move past the point of like, ai, because ai, even when AI was a buzzword like two years ago Yeah. It was already implemented. People just didn't talk about it.
Exactly. So I'm like, it's already like, I mean the Netflix recommendations, your Instagram, the face filters. Yep.
Your Instagram recommendation, everything. Oh, it's already already used. Technically ai depending on your definition.
And so it's like, okay, well how do we move past like, okay, AI is like everywhere it's gonna take over. Here are all the, the scary risks to, okay, let's implement this in our day because we're not gonna run from this. We can't, we can't.
It's Already Here. Oh yeah. So how do we like optimize it the most?
I think I made a video about like the four things you shouldn't be putting in like ai Lm Yes, I saw that. I saw that. I'm like, we're gonna use it.
So like, here's just FYI don't, don't be putting this information. Little rails. Yeah.
But, but then there's healthy uses of it and it's like what? Like some of the applications in healthcare Yeah. Are Phenomenal.
Yeah. Detecting skin cancer, I mean, you name it. And, and the trainers left the station.
Right. Chat. GPT was born.
It just catalyzed this movement. Yeah. Where every company that I work with either, either as a marketer or as a member of the media, we have to have an AI story.
Well, what is it? Yeah. It has to be real.
Yeah. And then you have to go, okay, here we are at RSA, how do we secure ai? Right.
It can be done. It's not easy, but it can be done. We can get proactive against the defenders.
Yep. We just have to be constantly doing it and learning and evolving. Yeah.
And the tech is evolving faster than laws and regulations. It's just such an interesting time to be alive and be working. I know.
I'm a I'm, I'm trying to figure out how the, to best optimize it honestly. Yes. Like how, what do I do to like, make sure that I'm fully taking advantage of this, like massive growth.
Agreed. So fast. Agree.
It is so fast. What's next for you? We know we follow you on at cybersecurity.
Girl, you were just in Montega. Was that the NATO youth summit? Yeah.
Awesome. Yeah. And then you came here, got stuck in Barcelona, but you came here That stuck in Barcelona, but I came here.
What's next? What can we expect to learn from you next? I mean, I'm gonna just constantly, constantly be throwing out amazing videos hopefully and educational videos.
Yeah. And I'll tell you my like future goal is to like have like a kids, like Bill and I kind of show, but for like STEM and tech and ai. Love that because I, I am, and something I talked about at NATO was like, we have so much responsibility and opportunities with these kids to make AI and cybersecurity not a scary thing and not a necessity, but like fun.
Yes. And if they're able to be like curious and play with it from the beginning, we are gonna see massive growth in that field from when they as, as they get older. Um, and so I'm like really excited about the future of that.
But I would love, I wanna do like a TV show. I'm ultimately just trying to build like a trustworthy continued to build a trustworthy brand. Yeah.
Because I do feel like it's my responsibility to be the one person that's like, Hey, no clickbait, no bs. Here's what's going on and here's what you need to do. And like, have, have fun.
So, Well you're democratizing access to all of the generations for cybersecurity. Why it should be part of their, their fabric, their personal fabric, their professional fabric. Yeah.
And why it's a good thing and not you're demystifying it and that's needed. Yeah. That's what I always say.
I always say like, I'm demystifying cybersecurity as a whole. Like in general you are careers, cyber, whatever it is. Just, that's where I wanna be.
Well keep doing what you're doing. I learn intent from you like every day. I appreciate you responding to my DM the other day.
I'm like, Caleb responded. I Felt like so cool. Oh my gosh.
I appreciate you messaging me. Of Course. Yeah.
And I wanted our audience to be able to learn from you because this is something that is just the fabric of our daily lives. Yeah. And we appreciate your insights, your time, and sharing all of your knowledge with us so consistently.
Thank you Caitlyn. Thanks so much for having me. It was my pleasure.
For Caitlyn, Sarah, and I'm Lisa Martin. This wraps up four days of coverage at RSAC 2025. Yay.
Big hand of applause for our amazing production crew with Tuck on tv. We thank you for watching. You can find all of this content by next week on the socials.
And if there's anything that you wanna watch again, lucky enough, you can do it. tv. com.
Too many, too many brands to mention. But thank you for giving us your time. We hope you've learned from our guests.
We'll see you with the next show.