Exploring Cybersecurity Trends and Community Connections with Andy Ellis | RSAC Conference 2025
This discussion with Andy Ellis covers the evolving role of Chief Information Security Officers and the challenges they face. The impact of artificial intelligence on security practices is examined, along with the introduction of Minimus, a company focused on reducing software bloat.
Transcript
Hey, everyone. We're back here at RSA, we're wrapping up our Tuesday coverage, and this is the part of the show where we get to talk football. No, we don't.
No, We don't. I'm only kidding. We've already talked football.
You weren't privy to it. I can tell you all about it. Andy came with a cheat sheet full of things a Patriot fan would say to a Steelers fan.
We then look from ai, of course, we then looked up on AI things the Steelers fans can say to a Patriots fan, There weren't many. Right? But let's face facts.
Neither one of us are in the Super Bowl this year. No, we're not gonna be this year. Anytime real soon.
Maybe next year, maybe the year after. But I sound like a Jets fan. Hope Springs eternal.
It does. The Jet fan. God bless them.
Anyway, you know, one of the nice things about RSA is I get to see my friends. I, I've been in this community a long time, and there are some people I, I just, it's good to see it. It gives me, um, I don't know what the word is, but it, there's a Yiddish word probably.
Yes. Naus. I don't know if you know what that is.
But anyway, to see these people, this guy's, one of them, Andy Ellis, I could embarrass him and tell you, uh, he's a Hall of Fame cso. He was the head of security in Akamai for 20 years. He then started a career as a, as a venture capitalist, as his mother would tell her friends.
My son's a venture capitalist. And, um, it's been instrumental in advising a bunch of startups into successful paths. Some have exited, some are continuing grow, still going to grow.
Yep. But more than that, Andy's also, you know, we talk about community. Andy's a a steadfast member of the community.
When you, whoever you go to in this cyber world, and it, even though there's 40,000 people here, it's a, it's a tight community. They know him. They know what he stands for.
And, and it's, it's good things. Right? It's quality.
It's, it's the right thing. So happy to call him a friend. He's my only Patriots fan.
I'll be honest with you. Who's a friend now? Maybe.
I've got a few Pat's friends. Will Herman, I'm looking at you anyway. Um, Andy, welcome.
Thanks For having me, Alec. It's a pleasure to have you, you, and I'd say Alan is, might actually be my only Pittsburgh dealer fan friend. Well, I, I don't, I couldn't understand that.
We are a, a, uh, A tough breed to like, we're A tough punch. We're a tough punch. But the draft is coming to Pittsburgh.
I'm going. It is. It's fantastic.
Yeah. It's gonna be a fun, a fun week or a fun three days. Anyway, but Andy, no more seriously.
No. Football. Football.
Let's talk, let's talk security. Yep. Um, of course, I think I interviewed you last year and your book was just out.
Yep. You got copies here. What's been doing since.
So people still love the book. 1% Leadership. And I decided I should write something about security as well.
That makes Sense. And instead of doing a book, I'm doing it as you know, mini eBooks. And I tested the waters last year with, uh, the first 91 day guide for a ciso.
Okay. So it's, you know, I called it How to ciso, which, uh, was fascinating. A bunch of CISO friends are like, that's insulting.
They call it How to ciso, but most folks really loved it. It's like simple. I, so Practical Action.
It reminds me of remember Rothman's book? Yep. The CISO's Guide or something like That.
Yeah. And so I wrote another one over the winter, which was the idealized CSO job description, which I wrote after consulting with a company that had a cso. They were Series D.
It was a director of security. And when I talked to all the executives around them, I realized they all had a different belief of what the CSO job was. And this person was doomed to fail.
And so part of my job was to write down this job description and say, here's what you collectively are expecting, and that's not fair. Right. Um, and I looked at it and I said, this is great content.
So I wrote it and I published it and said, this is what your organizations might be expecting. Have a conversation. Um, and Helen Patton and I just gave a talk to the CSO bootcamp, organized around it.
Really very cool Walk, walk through our career paths, how different they were and how we sort of were like Pokemon, collect all the jobs along the way. Uhhuh. Uh, and that you might not have that opportunity as an aspiring CISO today because you're in organizations that have structure and so you have to make those job changes.
They don't come organically. Absolutely. com, which Is very Cool.
A place to collect these, this content of these, a Whole collection of Books. As a CISO or aspiring ciso, I got two quick things I want to pick on. First of all, tell the truth.
Did you use AI on it at all? No. Everything there, my words I've shared with CISOs and gotten feedback from them or experts in very specific fields, when I was talking about the SaaS environment, I talked to a bunch of founders I know in the SaaS space to make sure that I was keeping abreast of innovation.
Mm-hmm. But everything there are my words. Do you think AI couldn't help you?
So I think that AI could help me, but for the way I write would not be a value add. Okay. Since I'm a professional writer and I write everything in my head and the act of writing is quickly, um, AI doesn't provide a lot in a space that I know what I'm talking about.
I have used AI before. What I'll often do is I'll have AI write a first draft, and then I just go in and I rip it apart. And what I end up writing looks nothing like.
So I do backwards. I write the first draft And then you let a AI edit It, then I upload it. Yeah.
And say, make a punch here, make it this. Make. But it's interesting.
Secondly, though, you know, talk about the description at ciso, job description. Yep. I think especially early on when the rise of CISOs was first, you know, becoming a thing, that was one of the biggest problems.
The fact of the matter was most people were hiring a ciso, were hiring a security architect. Right. Who was going to come in.
It's kind of like, I don't know if you ever took, um, epistemology in college. Yes. Right.
Where, so there's different theories of what God is and what one of those theories is God's just kind of sets the rules. Yep. And then let's, he set the rules for, you know, the four laws of physics, of nature, whatever.
And, and lets it play out whatever be will be. Yep. It was the same kind of thing hiring a ciso.
Yeah. We're going to, we're gonna set the rules, we're gonna architect the policy, see what happens, the process, and then we don't need the CISO anymore. Let 'em go be a security admin again.
Yeah. So I think that what what happened was you, you had a bunch of security people who were all technically savvy. Mm-hmm.
And then whichever one did not p**s off everybody in the organization became the ciso. Right. It was, but their Lifespan was this short, It was very, it was often very short because they went around p*****g people off.
Like they thought their job was to eliminate risk rather than enable the business to make better risk choices. Right. You don't even manage risk.
Like as a ciso, your job is to help other people manage risk, manage the Risk. I, I agree with you, but we, we seem to have evolved. Yes.
Beyond that, I think most understand now what a CISO does. I, I would say one of the biggest problems I find, like what separates a good CISO from a Okay ciso. Yep.
They all generally have good security knowledge, right? Yes. I mean, that's kind of a given.
It's their ability to translate it to business talk. Right, right. Is where the issue arises.
Yeah. I like to say that, you know, one of the core process skills is obviously project management, but reverse project management, which is what I call business perspective. Which is when you're trying to manage a project, you're trying to get something done and you run a foul of other stakeholders, you need to be able to reverse and say, what do those other stakeholders want?
That's all that business perspective is, is saying, oh, I want to release safe software. They want to release software fast. These are intention.
How do I get us both to agree to release safe software quickly? Because if I'm trying to slow things down, I'm in direct opposition to them. Yep.
And so that's, I think that when people say business perspective, that's what they need to understand is if you're in a room and somebody who's not, you proposes a thing and you can model the argument that somebody else will make against it. You have business perspective. Agreed.
I brought up AI for a reason. Yep. It wasn't just to see how you write Just 'cause it's the talk of the show floor.
Everything Is ai. No, you can't, you can't walk from a, a dark tile to a light tile here without tripping over. No, you can't.
But how is AI affecting the role of the ciso? And maybe we could see a short ebook on this. So I think, well, there's a bunch of books on the show floor.
You can get written by AI about the role of ai. It's a Well, but Yeah, we want an Andy one, not an AI written One. So sort of here's my, my take on that, which is AI is changing our jobs in a couple of ways.
One of the ways is our companies are embracing AI very quickly. And that's can be a huge problem for us if that's what's going on. Um, but that's not the only issue.
Right. The issue is also like our jobs are changing. AI makes people faster.
Yes, it does. And but it also hallucinates 'cause people have focused on gen ai, they've forgotten about automation as a piece of ai, reductive analytic ai, pattern Matching ml. That's all ai, 20 years of history there.
The other thing I think people need to think about is where are there places that AI is just taking a hard problem and glossing over how hard it is? And maybe there's different approaches. Like I see a lot of companies in the vulnerability management space where like, oh, we'll use AI to do better prioritization.
And why aren't we talking about how do we just minimize vulnerabilities in our work, in our place entirely. Yeah. Right.
And that's, I think that doesn't require ai. That just requires no minimization of our footprint. It's funny you brought it up.
I I got a pitch from someone, actually, I I think we spoke about it on Textron Gang today. A new company, mini Minimus. Minimus.
You saw this. So I, I was at Suson, uh, maybe a month and a half ago down in Orlando. I drove up.
Yep. You know, they did a new thing with their Linux distro where they've taken your typical Linux Yep. Packages and stripped out all the bloatware, all the unnecessary stuff.
Right. Hardened it. And so now if you download those distros directly and packages directly from suse, you got a a Right.
Smaller footprint. Smaller footprint secured thing. It sounds, that's what Minimus is trying to do.
So Is doing. So I went and I talked with them. Um, did you, full disclosure, they're one of our portfolio companies.
Are they? But They were, I didn't know that I, to God, They did, they did so great in stealth that I did not know what they were doing. You didn't know That either.
Okay. Yesterday morning. There you go.
They wanted to be completely secret. So, uh, so I got to go meet with him today. Like, what are you guys doing?
You have my money's crazy. I swear I did not know Andy Woods involved. They really, they did a fantastic job.
It's the the x twist lock team Yes. Are Doing that. That's exactly what it's, and It's, there's some similarities in that approach.
Right. It's, it was fascinating was when they briefed me, I'm like, oh, there's no brainer. 'cause this is what I did at Akamai.
Like when my first job was secure our servers, I said, well, why do we have things like GDB on a production system, get rid of development tools? And it's similarity to the approach the, there's two big differences like suse great. I'm glad they did that.
Um, challenges you have to use their distribution. Well no, this is the year of Linux on the desktop. This is Linux, this is the year.
Oh. Um, is focus on the application. Oh, you want an engine X?
And the problem is when you install Engine X, like the dependency tree is every possible use of Engine X. So it doesn't help if your OS was okay, you just added on an application stack that's not safe. So first of all, get rid of all the things you don't need to run engine X in a production environment.
And then the second, which is the one I really love is chase that dependency tree. And the way it currently waterfalls up is if you have a five layer dependency. Yeah.
The fourth layer included the fifth layer. At some point in the past, the third layer included the fourth, et cetera. And so your fifth layer might be eight months out of date by the time it gets included here.
Even that's What dependency trees work, even Though, even though they have updated since that's not how the dependency tree currently works. And what they do is they rebuild the package against everybody's latest. So now instead of going five to four to three to two to one, they go 1, 2, 3, 4, 5, everything Left to right versus right to left.
Exactly. Now let me ask you a question though. Mm-hmm.
Because No kidding. All kidding aside, now you and I spoke last night briefly on the shelf floor. You did mention, I forgot it was you who mentioned it.
That's how old I am. But it wasn't me who brought it up on text on gang. Mike Vard actually wrote a story about them on Security Boulevard today.
I believe. My thought was though, so are they going to take everybody's stack individually and and do this on a per engagement basis like that? Like they're gonna say, okay, let me read your No.
So they're just a new distribution. So they're making, it's just their distro it They're doing. So you basically can get the minis latest got x got, and it is clean and you don't have to worry about it.
26 instead of 1 2 7, then you can go say, okay, that's what I want. And oh look, I see that I'm inheriting two vulnerabilities because I'm on an older version. But now you only have to worry about those two and not the 97.
You would've had had you just taken it with its normal dependencies Now. So there's a Linux distro with the Nginx. Um, I don't know that it's a Linux distro.
I think it's more of a container wrapped package I dig in on. Oh, it's a Containerized. Yeah.
Like more of what you're doing in an AW WS style environment. Yeah. I have to look into the details on how it works at the OS layer as well.
So I'll be honest. Well, if it's containerized, it's probably more in a cobe environment. Yep.
Could be serverless. Um, so now, 'cause my, my question was where's the scalability? It's great if I'm doing n engine X, there's a lot of other stuff out here.
Right. But once you're saying, okay, I could do that as a container, I could literally, literally take anything, containerized it, containerize It, And and make a, a minimus distro of it. Yes.
Right. That's interesting. And that's What they'll do Interesting for You as their customer.
Right. You now don't have to do it. Like this is work that anybody in theory could do, but the scale of the work doesn't make it worthwhile.
I don't know if everyone could do it, Andy, because I think unfortunately most organizations don't have the knowhow. Right. You, you'd have to buy the knowhow To harden it.
Yeah. Find it. You know, what's, what do I need?
What do I don't need? I would rather trust that to someone who knows what the hell they're doing. Yep.
And you should. And so I think what I love about this is yes, they use some AI in how they're doing the minimization, but it's AI alongside a human, not AI replacing a human. Mm-hmm.
But it's changing the game a little bit. 'cause now it says, look, you have a thousand problems, let's just eliminate 950 of them. Right.
Whereas everybody else is saying, we'll find out of out of the thousand, like the 12 that matter. Right. Well if we can eliminate 950 And you can only focus at 50 lot easier, that's a lot easier.
Exactly. I, I agree with you. Now I understand.
'cause the way vis, I honestly, I got a cheat sheet for today's Textron gang. Yep. And the way the cheat sheet read from Mike ARDS article was this was a SaaS solution that was, you know, taking the, the risk out of packages.
Right. And I couldn't understand how you could scale It. Nope.
No, it's not a SaaS package. In fact, one of the things they implement because they're security focused first and so they understand the security buyer is you can take the distribution directly from them or you can have them push the di distribution to your repository so that you're, you're only pulling from your own repository. And this, I can't believe somebody coming outta self did it.
They have it way for you to sneaker net it really. So if you have an air gaped network that you want to take their images to, you can take your thumb drive and move the images over, put them into your own repository and distribute from there. You know What else?
Just thinking out loud. You could probably just generate an s bomb of of it at the same time. In fact, they have the S bumps so you can look and see exactly what is in Yeah.
Everything. And so you produced your sbo. That's nice.
Yep. That's nice. You don't know the website off top of your head, Do you?
Yeah. io and like anybody can just go sign up. Like you can get a personal account and start using minimus today.
And I'll tell you the Twistlock guys. So Cheny, remember Cheny was one of the Twistlock. Yeah.
She wasn't a Twistlock guy, but she was one of your Twistlock and she's also one of the angel investors I believe. Is she? Yeah.
Well I would imagine. 'cause she's friends with them. Look, Twistlock was, I think maybe I'm wrong, but one of the first cloud native, they really work, uh, security companies that were out there.
Yep. Bought early on by Wasn't a Palo Palo Alto. Yeah.
Palo Alto bought them early on. What a great story. Andy.
It all came together here. It did. It's it's fantastic.
No, it was, it was really an experience for me on Monday morning when it's like, oh this is a company I've backed. I didn't know what they were doing. And a marketing like high risk, high reward option to come out of stealth on the first day of r of RSA.
But they got picked up. Vard picked him up. Yep.
We spoke about it on the gang today. Here we are talking about it. Yep.
That's good. It's good for them Standing out from the other 600. Yeah.
And I think they're giving away a mini Cooper as well. People go for their booth and like scan the QR code, put in your information and one person will win a mini Cooper I put in mine. But I'm pretty sure that like if I win they're gonna be like, We're Gonna pick somebody else.
You gotta pick. Yeah. Yeah.
No friends family. No friends and family. Now I do know that Mike ards wife loves him Mini Cooper and I wonder if that's why he wrote the story.
It might be maybe he Was there. He hasn't asked me to go over there. Anyway, Andy, we're about outta time man.
Where can people follow you? So They can find me on Twitter or LinkedIn. I'm CS O Andy.
com. com. That's the New one.
This is the new one. Um, and you can also obviously follow Wild ventures And in football season you go to Gillette Stadium, you'll see him in there. He's the guy with the funny jersey with the chemistry of, of what it needs to blow up a ball.
I retired that one. Oh, you retired? I had the ideal gas law jersey.
Um, I got that one autographed so I retired it. It's autographed Brady's lawyer. Really?
In the deflate gate case. So Jeffrey Kessler? No.
Now I'm wearing one that says Rael with the number 18 underneath it Guy. Very nice. Good for you.
Alright, that wraps up RSA day. Well I feel like I've been here all week, but it's only RSA day one. Well, we'll be back tomorrow with more.
Thanks for joining us. This is Techstrong. I'm Alan Shimel.
We're out.