Kip Boyle on the Evolving Role of the CISO and the Integration of AI in Cybersecurity | ROCon 2025
Kip Boyle shares his extensive experience in cybersecurity, highlighting the importance of risk management and the evolving role of the CISO. He discusses the need for speed in addressing cybersecurity threats and offers fractional CISO services to mid-market organizations. Kip emphasizes the integration of AI in cybersecurity and the communication challenges CISOs face in conveying risk in business terms. He concludes with resources for further learning.
Transcript
Hey everyone. We're back here live at Rock on the Qualys conference. Uh, I said it on the last one.
I'll say it on the first Few Risk Operation Conference. Qualys is all about risk management at risk operation centers, and I think it's a great name and I love saying rock on. So it's all good.
Let me introduce you to our next guest. He actually keynote it this morning, came out first. I actually, before we even summed Kar, the uh, CEO, I wanna introduce you to Kip Boyle.
Kip, welcome to Tech on tv. It's great to have you on here. Thanks For inviting me.
This is wonderful. It's our pleasure. Um, Kip, first of all, before we talk about what you spoke about today, let's talk a little bit about you.
Alright. Look into this camera, tell our audience kind of your story, your, your journey. Sure.
So I've been working in cybersecurity since before we called it that, right? Yes. So I was on active duty in the Air Force 1992.
And then after I got out of the Air Force, I, uh, eventually became a CISO about 20 years ago. And so I did that, uh, for an insurance company full-time for about seven years. And then I launched my own company.
So today I am a fractional ciso and my company just turned 10 years old free, and I got a team of people that's that I support. And, uh, yeah, so we work with all kinds of companies, uh, all kinds of different industries and situations. But what they all have in common is they're sophisticated risk managers.
They understand that they need security leadership, but they don't have anybody, uh, full-time in-house to do that. So the marketing people on your team would demand that you do give your company's name. Okay.
So I'm the marketing person in my company, actually. So we're called cyber risk Opportunities. Okay.
And, and, and the reason why we're called that is because it's important for cybersecurity people to realize that risk isn't all downside. No. There, there, there are reasons why people take risks, right?
Because there's things that they want to achieve. Absolutely. I've always said, look, you wanna eliminate all risk, unplug from the internet, shut down, close up your USB port.
Yeah. Your machine. And yeah.
You'll eliminate most of your risk. May not do any business. No.
But you will live in No more than a re than a person who's burying their retirement money in mayonnaise jars right. In their backyard. They're not gonna grow their nest egg.
Right. But they have, you know, managed their risk, so to speak. Managing risk, I've always felt was a, it's a personal choice, right?
Because we all have, and each organization and the people within the organization have different tolerances for risk. That's right. What they're willing to do.
Yeah. And actually, that's a big problem, to be honest, because I don't want, as a senior decision maker, I don't want people showing up to work, making decisions on behalf of the organization based on their own individual risk appetites and risk tolerances. Yeah.
I wanna tell them this is the organization's risk appetite and risk tolerance, and this is how I want you to make risk decisions. Sure. You know, this guy's a Mississippi gambler and this one hired Yeah.
Keeps it in the million eighth jar. Yeah. Yeah.
People That's great. But that's not the organization. People jumping out perfectly good airplanes on the weekend.
Yes. Working at insurance companies. Yeah.
Not a good mix. No, no. I hope they filled that out on the disclosure form.
But anyway, Kip, I I wanted to, as I mentioned, you did the, uh, keynote here too. Yeah. I'm just thinking 20 years ago as a ciso.
Mm-hmm. So, I, I'm also, I'm in security about 28, 30 years, 20 years ago, CISOs had a very ephemeral lifespan at a organization, right? Yeah.
They would come in, they would kinda set the stage, do the architecture, and, and I've had this from friends of mine who were CISOs, they would say, okay, now you got everything set up. You want to go back to being a, just a security, you know, analyst 'cause we don't need you full time. And that was the state of CISOs back 20.
Yeah. And if you're not careful, that'll still happen to you. Yeah.
Right? Yeah. And so what's missing right, is well, if you're gonna be proactive, then you have to be the one who is driving a conversation, an ongoing conversation about, it's not a set it and forget it.
These aren't risks. I can't just give you the checklist and we've pounded out and then I go and find another job. I mean, it's just not gonna work.
Right. But that's, now why do we do that? Because human beings are used to dealing with static risks.
And that's why I talked about fire as a metaphor for understanding why cyber is not Static. Static. It's innovative.
Right. It's constantly changing. So why shouldn't we be surprised when I've got to ask for more budget for a new thing to deal with a new version of this cyber stuff that I've never seen before?
You know, 2003, I, I co-founded a company in 2001. In 2003, we came out with a vulnerability assessment and management. We actually used to compete with Qualys.
Okay. And back then, and you know this 'cause you were here then. Yep.
You know, the state of the art was, you, you, you did a vulnerability scan, if you're lucky, twice a year, we would hope at least once a year, but it would generate so much bad news Right. That it would keep the team busy. Right.
For a year. Right. But I always thought to myself like, you wanna talk about set up for failure?
What a, what a a failed model that is. Well, It is now. Yeah.
I think it was then to tell you the truth, you Know, uh, but that was state of the art then, because that's what we could do. It Was Also because the cycle time between vulnerability and exploit was much, was pretty long. Yeah.
It was. So we had time. Right.
Nowadays that's not true anymore. The cycle time is massively compressed, right? Yeah.
And with the ai, uh, capabilities that are being thrown onto it, it gets even more compressed. Right? So one thing I'm telling my customers is speed is the new firewall.
Very cool. Right? Because you, you, you, you gotta keep up.
Yeah. No speed kills. Um, ki let me ask you a question.
Do you find most of your customers don't have a full-time CISO and you're playing full-time ciso? Or are you coming in as like the ciso CISO to help them with their risk management? Yeah, actually it's both.
But, but what, what differentiates those circumstances is typically the size of the organization. Alright? So you've got like mid-market organizations say somewhere between $50 million of annual revenue up to about a billion.
Okay. They're big enough and sophisticated enough in their risk management to know that they have this problem, but they're not generally resourced well enough to be able to find somebody and put them on their team full-time like me. So that's where I'm providing fractional leadership.
Okay. Now, organizations at that size, they've just come out of an era where they needed a fractional chief financial officer. So conceptually this makes a lot of sense, right?
Right. They couldn't afford their own CFO, so they got one on a part-time basis, but then, okay, now we're big enough, we're gonna hire one full-time, and now here comes, you know, a fractional ciso and now it makes sense to them that this would be the way to do it. Now for larger organizations that already have a ciso, usually what happens there is there's a dysfunction of some kind.
Right. Some something about the program's not working. Right.
They don't really know why the CISO's not exactly sure why. And so they start looking around for somebody who can help them untangle the why. Right?
So I kind of in those cases become their pit chief, right. If they're a Formula One car on the road, right? Yeah.
They're racing, they're run, they wanna win, but they can't see everything because know, so I can show up and I can help them see the total track and tell them when to come in for a pit stop, get them all juiced up and ready to go again. Yep. And then when they're fine, then, you know.
Okay, great. It's been wonderful. Take it from here.
Excellent. I got a great question that I've been thinking about for two years here from the, you know, they introduced ROCK last year, right? It put the CISO in a very kind of pivotal role, but, but I think it was always meant for the CISO to be in this pivotal role, and that is the translator.
Mm-hmm. The translator of bits and bytes and security dogma. Yeah.
For lack of a better word, translating that to the language of the board. Of the exec team. Right.
And that language is risk. Yes. Right?
And, and profit and loss. Well, that's tied into your risk. Yes, sir.
Right? Yeah. You know?
Absolutely. How is it gonna relate to profits and loss? It's the language of business.
Right. Listening to Sum MAD this morning after you, they've continued running it with running this with them. However, not every organization has a full-time ciso as you damn well know.
Yeah. There's still a lot of security people underneath that ciso Right. Who are struggling with this new dynamic, crazy world we're living in with ai and That's right.
Protect AI and everything that goes with it. How much should the person below the CISO be able to talk about this from a purely a risk management point of view mm-hmm. From a rock point of view versus the security people that you and I kind of grew up with?
Yeah. Oh, I think it's, uh, I, I would've even told you 20 years ago that this was a critical success factor. So this isn't a new thing No.
On the scene by any stretch of the imagination. But I think the context, as I said in my keynote is, is really pressing on us from two different sides now. And, and we really have to step up to this now, and we really have to get better at this.
Now, the thing about it though, is people who end up with the CISO title, they're really generally not set up for success for this. Right. I've seen it.
I'll take myself as an example. I came up through the systems, uh, part of the organization, right? I was Scotty, I was down, you know, old, old Star Trek, right?
Sure. I can make it happen. Jeff.
I was in the engine room, right? Uhhuh, I never walked on the bridge. Now, uh, that's not good for people who are expected to talk about business risk because I, I can talk about system risk, right?
But I don't know how to, so I don't know how to do that. Now, I'll also use myself as an example when I say that the reason why I got into systems is 'cause I didn't wanna deal with people as much, right? I, I wanted to deal with computers and tech, right?
So here I am growing my career now as all of a sudden I've gotta start talking to executives in the language that they understand. But there's nothing in my background that's ever prepared me for that. Right?
So, um, so those are a couple of strikes against the ciso plus the CISO has no line management authority. It's another strike against them. So in so many ways, we're not set up for success, but the better we can talk about this stuff in the language that they understand, it can, it can actually ameliorate all of that.
Right? But how do you, how does the CISO get that? Maybe it's you bring somebody on your team who's really good at it and they teach you if you are humble enough Right.
And curious enough to let somebody on your team teach you, that can be very, very good. You know, I'll tell you how I did it. I was very blessed because when I was working as a CISO at the insurance company, they sent me off to get a graduate level certificate in executive leadership.
There you go. Whoa. That, that's that right.
Game changer. That was a game changer. Absolutely.
Was It, it took the, the plumber, for lack of a better word Yeah. And may and gave him an MBA. So if I can use another old Star Trek analogy, right?
I love Star Trek. Okay. But, but you know, uh, some of the kids out there don't watch the original, this Theory.
They tell me this all the time. Yes. Okay.
Listen, so instead of being Scotty and being down in the engine room all the time, think of yourself as McCoy. Okay? Because McCoy doesn't hang out in sick bay.
Not always. No, No, no. He's there sometimes, right?
But more often than not, he's on the bridge and he's haranguing the captain. Right. And Spock, right?
Yeah. He's counterbalancing. Right?
Right. So isn't it interesting that McCoy shows up and he's not always talking about owies and, you know, medical scanners. He's talking about the mission, he's talking about what really matters.
He can still be the chief medical guy, right? Yeah. But he's also bringing this very humane aspect to the bigger conversation about where's this Starship going next, and how do we deal with these problems that are in front of us?
So I want people to be McCoy, Be next, not Scotty. Right? But don't be Scotty.
Scotty's a bad idea. You gotta Yeah. Though, when Jim and Spark and McCoy are on missions Yeah.
It's Scotty in the chair. That's true. That's true.
I I will point that out And I don't wanna diminish Scotty, right? Because Scotty's the one that gets them saved every time. Uh, Of course he does.
Of course he does. Let me ask you another question, and it goes to kind of what I was nibbling out before for everyone ciso, there are a hundred security professionals. Yeah.
A thousand. I don't know. How do we get them all to talk risk?
Mm-hmm. Right? I I, I have, you and I both have a lot of friends mm-hmm.
Who are not CISOs, but they're security professionals, right? They love to talk the finer points of software, supply chain, security, firewall, configuration, identity, and access management. Right?
Right. But that doesn't translate. How do we Yeah.
Bring it down. Well, First of all, there's no pill you can take that's No, there is no red or blue, so there's No easy buttons. Right?
Uh, and that was really my call to action during my keynote was like, look, we're in a pinch point. If you don't make this transition, if you don't choose to transition to risk, what you are great at is probably gonna get automated by ai. Yeah.
So the stakes are really, really high. And you're gonna have to make a decision whether you're going to lean into this transformation and learn how to do these risk conversations, or, and this is totally fine if you wanna do it, opt out and just sort of wait for things to change, and then you'll just, you know, sort it out later on, you'll reinvent yourself at some point. Right?
I think we're all gonna have to reinvent ourselves. You know, you, you, you bring up the AI job situation, which look, it's not, this is not just a security issue. No.
This is scaring. I think everyone, I watched a video yesterday, well, actually I saw it the, the day before from this company figure ai Oh, okay. Mil the robot.
Yeah. So they came out with figure three, their third gen robot. Okay.
Ki this thing folds clothes better than my wife. Um, it, it probably Better than you too. Oh, I don't folk books definitely better than me.
It had it working on sort of a UPS store and delivering packages. Yeah. Sorting Packages.
That's right. And I've seen similar robots putting up drywall. Yeah.
Front desk, get a hotel, checking people in That's right. To become their key. Sending them to the, everyone I think is a little bit afraid on Edge, On edge.
Better about sweet. So we, what can, so you started this, let's finish it. All right.
What can our security pros out here do to make sure that AI enhances their value Yes. Not replace that. Yes.
Yes. So first of all, in the near term, you have to think of yourself as being augmented by ai. All right?
So you have to ask yourself, what's the highly repetitive tasks I hate? Yep. Start with those because you're motivated to not do them anymore.
Right? So if it's a weekly, a report that you have to pull together and send off, or whatever it is, some, some repeatable thing that, well, that's an ideal situation for bringing AI into your workflow, right? It's just a great way to start because you wanna get rid of that task.
And, and anything repeatable is actually very good for ai. Okay. Now w what w and that's what we do with me and, and I've got six people on my team.
And this is what we do, is we've embraced this and, and I've told them whatever it is that you don't like doing, that's, that's repetitive. I want you to work with ai. Here's a subscription to, uh, you know, chatt PT, uh, and I want you to get in there, I want you to figure it out.
And I make videos about once every, every week or once every other week about how I do it. You know, I do a screen share and I go, Hey, look what I did. You know, so for the folks that are listening that are wondering, how do I do this?
This is what I recommend, lean into it. Augment yourself and just start figuring it out. Now, another thing that we do that, that is particularly important for those of us in the cybersecurity career field, you don't wanna put highly sensitive data into these public models.
So you need to learn how to do local LLMs. Okay. SLMs.
Yeah. And so if you, and so my team, we all have lo a local LLM that we can run and put all the dirty digital laundry that we got from our customers into that. And so that's another way to augment ourselves, but to do it securely.
So you're not training it though, you're just doing in No, we're just augmenting ourselves with its current capabilities. Okay. Is it a frontier model that you're just hosting locally?
So, uh, yeah, it's G-P-T-O-S-S one 20 B. That's the particular one. Right.
So everybody on my team has a Mac Studio with like, uh, 256 gigabytes of unified memory. So we can run the one 20 billion model. Sure.
And here's, here's the secret sauce that a lot of people don't understand. I can use GPT five to write the prompts that I put into the local LLM and I get great results because I'm getting help writing awesome prompts. I, I actually do a similar thing.
I, I do pre prompts. So I, I take, I, I instructed I'm about to give you a prompt. You're a prompt engineer.
Yeah. Right. You make it write its own prompt, which is awesome.
Yeah. Right. Absolutely.
Now, GPT five is a really advanced reasoning model. Mm-hmm. GPT, OSS one 20 B is not nearly as advanced.
So it needs more handholding and more scaffolding and more structure. But rather than get smart about it, just make GPT five Right. Five a precursor I that.
And that's in essence what they do. Alright, Kip, first of all, thank you so much for people who wanna find out more about what you do and follow you. I know you have a podcast.
Yeah, I do. Where Can they go? Well, I think the most important, uh, place to find me is on LinkedIn.
That's, that's kind of my social media haunt. Okay. And I think I have a globally unique name on LinkedIn.
So if you just look for Kip Boyle, I think you're gonna find me. Okay. Okay.
So that's good. But, um, but if you wanna go deeper, then you can check out my podcast, the Cyber Risk Management podcast. And the easiest way to get to that is to go to my LinkedIn profile and just scroll down and all the episodes are there.
You can click into that or just go into your favorite podcast, uh, Wherever. Yeah. Whichever you use.
Yeah. Kip, thank you so much. It's a pleasure meeting you.
Thanks for keying here. I hope you've enjoyed this. You know, it's, it's, we're, we're a little bit into going where no man has gone before to keep with our feet.
Yeah. There you go. No person has gone.
No person before. We're live at, uh, Qualys Rock on. We'll be back with more in a moment.