AI Challenges and the Call for Data Privacy Accountability – Tech.Strong.Women. EP37
In this episode of Tech.Strong.Women., hosts Jodi Ashley and Tracy Ragan are joined by Harman Kaur, VP of AI at Tanium. Harman shares her remarkable career path from the Air Force to a pivotal role at Tanium, where she unexpectedly transitioned from an HR position to engineering. She delves into the complexities of enforcing cybersecurity regulations and accountability, particularly in the wake of the recent Supreme Court Chevron decision. Harman highlights the urgent need for enhanced automation and AI to manage the overwhelming number of vulnerabilities organizations face. Additionally, she urges consumers to demand greater accountability from companies regarding data privacy and ethical AI practices.
Transcript
Hey everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer here at Techstrong, and I'm here with my co-host, Tracy Reagan, creator, and CEO of Deploy Hub.
Before I introduce today's guest, I wanna give you a quick update about what's going on here at Techstrong. com. And be sure to tune in every day to Techstrong TV for great shows and interviews.
Hey, Tracy, what's on your mind today? Oh, so much mind today. I don't even know which, which thing that I should pick first?
Oh, Goodness. Google's, uh, announcement that their greenhouse gases have, uh, increased by 50% because of all the processing power we need for ai. Mm-Hmm.
The Supreme Court's Chevron decision, which has, could have a big impact on cybersecurity. Um, as we all know, uh, you know, the Biden administration has put some new regulations out there, the requirements for SBOs, and the Supreme Court just threw all of that kind of back in our face and said, people who are specialists in this area shouldn't make decisions. Instead, let's let the judges make those decisions, which is the same thing that's going on in the medical industry, right?
So it's a weird, and then we have open ai, which everybody's using, got hacked. Their, their training models got hacked all at the same time. So we have such a perfect storm going on, not don't need to mention what's happening in politics.
So, yeah, I'm not sure which one's more important to talk about, but I think that everybody should know that this stuff is, oh, and there was a major vulnerability in open SSH, uh, I just didn't have to mention that, which everybody uses open SSH, right? So, yeah, there's a lot going on, but I think that the most important thing, and maybe we can have this as a discussion starting point, is this, the Supreme Court's, uh, Chevron, um, decision and how it impacts regulation and will it impact cybersecurity? I believe it will.
So that will be my first question to our, our guest today. Alright. Yeah.
There's, there's way too much going on in the world to keep track of right now. It's, it's a little nuts. And then, yeah, don't even throw in politics 'cause that'll just make your stomach hurt.
Well, I'm excited to introduce our guest today, um, Harman Carr. Sorry. Harman, tell us a little bit about yourself.
Thank you for having me first and foremost. Um, so my name is Harman Carr. Uh, I lead all things AI over at Tanium.
Um, so at Tanium is, is a kinda a real time platform for IT operations as well as security. Um, and I'm responsible for helping introduce as much automation, as much AI as we can and leverage AI as much as we can, um, for helping things like cybersecurity, which is obviously top of mind everywhere right now, like you mentioned. So please, let's talk about how cybersecurity, where you wanna start.
You Had, And let us, let's just talk about, you know, the, the, this change in the way we're the government is able to enforce sort of best practices around cybersecurity, especially I, I'm, I'm assuming they should be able to enforce some regulations around what people deliver to the US government. Um, and by the way, we did not, um, everybody HARM is also an officer in the, uh, US Air Force. So this has gotta be something that is on topic, uh, for anybody who's working in any kind of defense.
Um, where do we go? Uh, will the government still be able to require better and tighter cybersecurity practices from, uh, IT organizations delivering software to the government? And, uh, of course they can enforce their own government practices, but it will that continue?
Will the government still be able to protect itself? And will the Chevron decision, say regulation should be decided by the, by the courts? Yeah, it's definitely an interesting time, um, in terms of like imposing regulations and where the accountability lives.
Uh, especially I think with this administration, we've seen a number of different things that we haven't seen before. And I think about this, like from the perspective of AI quite a bit, where obviously there's a lot of newness, right? There's a lot of unknown, and there's not a lot of experts, especially in government and all those areas that are imposing policies of when, when is it time to introduce something from a policy perspective?
Worse is, are we hindering innovation as well, right? Like, that's the question I've been like, sort of playing with a lot, especially with like recent decisions of does this actually make sense or are they right? Like, maybe we should put the decision, the responsibility back onto, I, I don't know.
I, I don't know what the right answer is. Um, but I do know that one thing is clear, which is we do need a clear level of accountability somewhere has, there has to be a clearer level of accountability somewhere. Um, whether it comes from the government side, wherever it comes from, we do need that.
I think that's been lacking in this domain for a while. We have organizations like csep, for example, right? They send, they put out notifications of here's things that are vulnerable that you should really care about, but who's really imposing that?
Who's actually taking those things and applying them to their organization? Something I think I've continuously asked that question is like, where is the accountability? Yes.
And our organizations, our large enterprises delivering software out to we as consumers. Do, do you believe they have the correct motivation to be accountable? I mean, if you're not, if you're really not being required, of course, if you have a major breach, there may be a lot of embarrassment Mm-Hmm.
But look what we've seen Boeing go through. Yeah. And they're still alive and kicking, right?
Um, so there's something to be, there's something to think about here if we're saying judges should decide if regulation is legal or not. I mean, that's a really weird place to be because judges don't know anything about cybersecurity. They have no, they have no knowledge about the space any more than they have knowledge about what's right medically.
So I, I I, I feel accountability is important too, but I also feel like we've got this is, this is something that could impact us five years from now when companies have stopped worrying about generating an SBO or looking for vulnerabilities. 'cause they don't have to be accountable. I mean, I think we're getting into an age and into a phase where accountability doesn't matter so much.
Otherwise we may not have some of the, um, problems we're having now in the political arena. So maybe accountability doesn't matter anymore. I mean, you're right, maybe it doesn't matter anymore, but it has to, right?
Like, you're right. Like organizations. Boeing's a great example.
And there's a number of big tech companies we can name as well over the last couple of years. Um, you know, that have done things that weren't in the favor of a general public, if you wanna kind of look it that way. But again, it goes back to like, who is being held accountable is a fine, sufficient enough at the end of the day, whether it's a judge making the decision, whether it's experts making the decisions, I don't know.
Right? I think we're getting into really interesting territory now. It's a lot of these organizations are getting fined for, like, think if we, like GDPR for example, came about, if we gotta protect everyone's information that was enforced, organizations were getting fined.
Maybe they did some stuff to make sure there was better use of our information. But at the same time, I don't feel like my information's any better protected before and after. I don't know if you do.
I, I just feel more annoying that every time I go to a website and I have to click do I do, I want them to sell my information. Like, but I don't feel like my information has changed. I still get the same number of notifications on my, you know, credit score of, you know, this has been exposed, that's been exposed.
Um, so I, I think it's a really tricky area. Like, especially as we head into ai, which is like where accountability is almost fleeing, where does the accountability really live? Well, when you talk about accountability, I think it, when the whole AI thing started, it, it gave me the, it made me uncomfortable.
When you think back about what we've gone through with social media, like nobody thought about what impact it was gonna have. And years have gone by and we all see, you know, the fake news, what it, how it impacts our children and our girls and our teens. And I felt like at the beginning of all this AI stuff, people were kind of jumping in early saying, okay, we need to think about it.
But again, I just don't know how much work they've really done. And, and what's a fine, I mean, if you're making a hundred billion dollars, what kind of a fine is really gonna impact you? I don't think finding findings gonna work.
So yeah, I think there's such a, such a rabbit hole to go down when you think about, okay, who's gonna fine? And then we have a court now who clearly leans one direction. So they wanna, so that changes the whole game too.
'cause who, who would've thought, I mean, when you, if you were following the news, I don't think most people thought that this ruling would come down the way it did. And so now everybody's scrambling going, wait, if, like you said, if the court has the right with no experience Mm-Hmm. You know, to me it's like a bunch of 75-year-old white dudes sitting in Congress telling me what to do with my body.
It did. It's the same thing. You know, and I don't know, I i finding who's gonna be accountable is, is pretty difficult.
Yeah. I think as consumers, I think we've gotta get smarter. I think the, at the end of the day, ultimately the power is with consumers.
I think asking for better accountability, asking, demanding and saying, I want to understand how my information is being used by your organization. I want, you know, this sort of clarification. Like, I think those are things that consumers have to start driving.
'cause ultimately those are the biggest constituents. Like judges aren't going to be able to make the right decisions or a decision that's always favorable with the consumer's needs or vice versa. Even if they were experts, you know, they may be myopically focused on something.
Um, so I think for me, like a big thing is, is really being educated and aware of what's going on around you so that you can hold these organizations accountable and have a voice in a, I would hope that that would happen. Mm-Hmm. But I don't have a lot of, I have wishful, like that's where I think power of social media can be positive to your point, right?
Like in saying, Hey, here's something that's going on that we should really be talking about. Maybe it's not on big news. Um, but it's important to our com, it's important to our country, It's important to our country.
But if you look at the, the whole TikTok example Mm-Hmm. Um, we had, uh, one of our early episodes we had Janie, Jamie Thomas, who is in a high level position at IBM and works a lot with the government. And we chatted a little bit about, uh, this, that, that particular problem.
And she was like, it's a real problem. But if you speak to most Americans, they would say, no, you can't take my TikTok away from me. I don't care if they might change my attitude about the Chinese and make me think they're the best thing since sliced bread.
Um, or any other attitude that they want to infiltrate and change behavior. Uh, that it's okay. So we do have to have a smarter, um, consumer.
I just don't know how to do that. And you know, what might be our saving grace is Europe. Because if companies are building software that they wanna sell outside of the United States, they're going to be required there.
There's regulations around that. But that doesn't mean that data. Well, it could, that does, because even data that's stored in the us, if the, if it's being consumed by, uh, somebody in, in Europe, it will have to have those European regulations applied to it.
So it may be that we're, we're losing our leadership role in terms of decision making about what needs to be done. And that's not gonna be done by us anymore. It's gonna be done by Europe.
I think that's the way we're gonna go. Yeah. I mean, we're lacking behind in the enforcement part of this, right?
Like Europe is driving a lot of enforcement, like organizations, when I, as you know, spend time in Europe and go and talk to those organizations, well, even about AI or automation, they, their questions are fundamentally different than what's being asked in the us right? The US is very much focused for the right reasons, which is right. We, you know, how do we adopt this?
How do we innovate faster? And things like that. Where Europe, it's a little bit more of a pragmatic of, okay, how do we protect everyone's data?
How do we understand what the model is doing? How do we understand the implications of the model, right? So I think as a society, they have changed a little bit of how they adopt technology, how they view technology, to your point.
Um, because they've had a couple of examples of where they've had, they've had to actually enforce those types of things and they've been held accountable where for us it's still kind of, it's fine. We'll deal with the consequences later. So yeah, Let's put kick kick the can, kick the can down the road, right?
Kick the can down the road. Let's not deal with it. But I think the balance is somewhere in the middle, right?
Like, we cannot hinder innovation. It's still important. We still wanna be forefront of these things.
We don't wanna get reg regulation always get in the way of that. But at the same time, we can't let everything run wild and keep kicking the can down the road, like you said, with every single Thing. Well, I hope that organizations continue to be worried about at least vulnerabilities in their code without having to be regulated for it.
So let's chat a little bit about vulnerabilities. You know, we have seen a massive increase and, um, in CVEs over the last several years. I think in 20 may in those, these numbers may be wrong, so please don't quote me on them.
But I think in 2022, we were around 14, 15,000 vulnerabilities being reported. And now we're up to around probably 33,000 this year. Mm-Hmm.
This was projected. That's a big, that's a big difference. Um, how, uh, you know, you're in the space.
How are companies responding to it? Are they thinking about it? Do they want to be accountable?
Do they wanna keep vulnerabilities out of their software? Are developers understanding enough? And what do we need to automate?
Yeah, I, so organizations, it's interesting. Five years ago the conversation was just tell me the most vulnerable ones, the most important ones, right, that I should care about, and I'll fix those. Um, because fixing those vulnerabilities does take time.
It requires resources. Obviously it can also introduce an interruption to your organization. So it was always just tell me the most important one and I'll fix that.
And then over the years, what we've realized is it doesn't matter, obviously severity does matter to some extent, but if you're going to be breached, you could be breached by something super simple that you didn't think was very important and something you didn't think needed to be addressed. Mm-Hmm. And now organizations are saying, oh my God, how do I actually fix everything?
'cause that seems like a really daunting task. I'm not getting more resources to fix those things. Um, so, but I, I need to address it.
I need, and it's becoming a actually a board level discussion in the sense of organizations are being measured on it. CISOs are being measured on it, CEOs are being measured on it. There's l SLAs that are enforced now.
Um, when they're having, uh, they're contracting out kind of their vulnerability and risk management. Um, they're being held accountable a lot more. But there's still a missing link, which is the automation piece of it, of how do I actually fix these things and how do I fix 'em with confidence knowing that you're not going to cause issues in my organizations when you're patching them, A server is not gonna go out that's going to interrupt everything and have to stop everything.
Um, I think that conversation is becoming more and more prevalent now, and hoping into introduction of like AI and automation helps us sort of make a leap forward that, you know, we went from 14,000 to what you said about 33,000, 35,000 now. And I'm hoping now, even if that number grows to a hundred thousand by the end of next year, wherever that number lands, we don't care. That number is irrelevant because we're able to stay ahead of actually addressing these vulnerabilities in organizations.
Um, that's the level of change that, you know, from attaining perspective that we're hoping to have through AI and what we're introducing and what we're working on from automation, A hundred percent deploy hub is right there with you. Mm-Hmm. You know what?
Get the data so we can start auto remediating all stuff. Correct. Exactly.
And can, you know, we should think about, and I, the way I see it too, um, is I don't believe for a minute we can code scan our way out of the problem. Mm-Hmm. Can't do it.
It's never gonna happen anymore that we can test our way out of anomalies. And the, the whole idea around chaos engineering and, and the SRE space applies so well to this problem. So if we can figure out how to ad address the problem and stop, you know, Carolyn Wong, who I adore, and if you haven't watched some of her sessions and we, we interviewed her, she talks about offensive and defensive security measures.
Mm-Hmm. Of course you wanna have the shield, you wanna keep people out of your system, you wanna defend your system. But when somebody's in the house, you need a Ozzy Mm-Hmm.
You really do. So that is offensive. Right.
And I think that the, the theories around chaos engineering is often learn to address as quickly as possible. And according to Jfr, in case our listeners didn't know Mm-Hmm. Harman pointed out, it takes a long time to address a vulnerability.
It's a little over 220 days for a, for each vulnerability. And that is insane. 220 days it takes to address a high risk vulnerability.
So you certainly can't address the low risk of the medium risk, which may ultimately impact you as much as a high risk because of how you've deployed it or how you're consuming it. So we have a problem, Houston, we have a problem and we certainly, we gotta fix it. We really have to start addressing it in a more, uh, I would say holistic approach.
We've gotta have defense and we have to have offense. I think it's, I have a really funny story about that. I, so I was in the Air Force and I had just gotten to this new unit and they were, it was a cyber unit and they had all the tool, every tool you can think of under the sun for cybersecurity, right?
For, and it was all sort of, you know, if we get breached, here's the 18 different tools that we can employ. And I'm sitting there thinking, why do you have so many? Like, do you really need all of them?
They're like, yeah, yeah. What if like, you know, this, we get breached this way and that way, and they're going on and on. And I said, what about like, simple things like patching and who do, how do we do compliance scanning?
And all those questions, like really simple, basic like IT ops, they're like, yeah, yeah, yeah. We, we have a tool for that, a tool for that. You know, and I'm going, do you see the fundamental problem with security is you're standing here and making sure that there is like 12 guards at the door, but no one cares about the windows that are open in the back.
Like, no one is worried about that. There's even a roof on this house, but everyone's standing at the door. I think it's cybersecurity.
We've always thought of this domain is like fighting something. Like let's focus on their step for that, which is like making sure even really simple things are done. Um, and for, and, and it's interesting to me, even in 2024, right?
Patching is still an issue in organizations. And I always joke, I'm like, I, by the time I am outta this interest, I do not wanna hear about patching. Like that shouldn't be a conversation that should be inherent to how we do business today.
It's a huge, huge problem that we can't even patch organizations, um, and address those vulnerabilities that are piling up. And that's why that number scares us of it hates 33,000, now it's 35,000. It's only gonna climb, Uh, with a modern, uh, you know, modern architecture with microservices.
What companies oftentimes forget Mm-Hmm. Is that if you have o open SSH in every single micro that you have out there, you have to patch every single one. Now, I'm not saying monolithic is better.
I think, uh, a decoupled architecture is certainly the way to go. But we have to pivot in the way that our DevSecOps and our automation, we have to pivot in order to start, start addressing the, the problem and my complaint about the DevOps community in general is that we have our, we have our workflows, Jenkins, CircleCI, whatever you're using GitLab. But we haven't fundamentally changed the way we see how we deliver software.
No. And the architecture has drastically changed. So now we just have literally thousands of workflows that's pushing this data across.
We're not keeping track of what it's doing, and we have no real way of saying the, this is the blast radius of this one vulnerability and this is what it means to your organization. And by the way, how do we automate the fixing of it? And I think ultimately, I hope companies like yours and mine and other security com people who are addressing security, we can get to a point where we're competing against who's doing the, the auto remediation the best.
Right. As opposed to showing us the, the garbage that we have on the table. Right.
We know we have this hairball. Okay, great. Thank you for letting me know.
Oh my God. I joke about that all the time. It's like there's so many tools out there that just tell you that things are wrong.
Like, I think we need that. Like I think we're aware that things are bad in our enterprises, so how do we make it better? You know, it's interesting.
You talked about not a lot has changed in the DevOps and SecOps space. What's the general reaction you get when you talk about SBO m to different organizations? Is it a little bit of a tear in the headlights?
Like what's the, what do you usually get The reaction? I would say it's a quiet response. Mm-Hmm.
And they know they should be implementing it, but it is a major undertaking to Mm-Hmm. To update. And I tell people this all the time.
CloudBees supporting their Jenkins, um, CloudBees solution, which is a SaaS solution. Mm-Hmm. They manage about 90 million workflows a month.
Okay. So are we really thinking that with manual interact, manu, we manually have to update every single workflow just to put SBOs in there. We're not talking about all the other types of security we should be doing repo scans, signatures, all the other pieces that are critical for putting those guards at the door.
And then when they do go through the window, we have no way of really, that Is the best analogy I have ever heard. I am really, I'm grabbing that. That is a great analogy.
It's No, I agree. Even after I really thought Log four J was our crisis, where everyone was going to be worried about SBOs and say, you know what? This is no longer a nice to have and we should get to it.
This is necessary. We need to understand everything that's in these libraries and we need to index it and we need to keep it updated, not just do it once. But again, it's, I, I'm seeing the same reactions, which is a really soft, like, yeah, we should do it.
I'm like, do we really need another sort of event to convince us that we really need it? I think at this point it's pretty much solidified that we need to do this. But yeah, we'll see when organizations are getting on board.
So here's an interesting, um, experience I had. I was at a conference recently, I won't say what conference it was, and I won't say who I was talking to for fear, I will embarrass somebody. Um, it was a room full of guys.
And I brought up this idea of, you know what, we have an open source project TIUs that we're working on consuming SBOs and normalizing the data so you can actually see what's happening. Every single time a single, uh, microservice or API is updated to start actually seeing the data and addressing vulnerabilities in real time. And you know what their concern was?
Hmm? The, the amount of data and the transactions. Okay, these people were from tech industries, I came from the financial industry.
So data is not something that I'm afraid of. 'cause you know, think about how many times you process a credit card and all the security that's already built into do to to that, right? Um, so their concern about SBOs and dependency management and check tracking vulnerabilities had more to do with who is gonna pay for managing all of that data.
And I'm thinking, gee, you know, there's so many ways to do it. Blockchain normalizes things. There are so many ways that we could create NFTs that are small, that really provide us some history that we could actually start building into large language models.
And all they thought about was, it's impossible. It's too much data. Oh my God.
I've had to, it's interesting you say that. So the way like Tany was architected, we tried to do as much as we can on the end point instead of bringing things back centrally to obviously, you know, to avoid that data collection problem, introduce latency, all those things. So we do everything we can on the endpoint itself.
Um, which means we reserve a small kind of, um, memory on the endpoint. So a couple of gigs on the endpoint. I remember having conversations with large organizations, you know, very high profile leaders is going, so you're gonna reserve three gigs on the end point to do all this.
I'm like, we're concerned about three gigs. I'm like, come on. I don't think that should be the worry here.
Like, I have a lot more questions. You're right. I think it's just, I think it's just patterns that we've heard.
We used, obviously that used to be a concern. Like, and it was a valid and legitimate concern. Luckily we've overcome that a couple of decades.
It used to be big right here. Yeah. It's, yeah.
It's interesting. It is. Organizations are kind of battling with as space and resources.
I'm like, Hmm, I don't think that's the right place to stay. Well, I, I think where we are in this industry is we are at a place where Dev Rail is gonna be, is really important. And I hate to use the term education because it's not about taking a certification course.
It's about doing outreach and it's about making security front and center to not just developers, but SREs and everybody. We all have to get in the game together to start solving the problems. So I hope the Devra can can increase around this.
And we have many more, um, conferences. The open SSF has their SAUCE conference. So there's, there's stuff going on.
We just have to get it all pulled together and, uh, address it in a more holistic way and think about, you know, offensive and defensive techniques and chaos engineering and large language models and AI and, and really get us out of this mess. But it's gonna take us some time. It is going to take us some time.
But I think this is where I, this is the most optimistic. I felt that there is actually going to be some sort of change. And that change is coming adjacent to like the core problem, which is through AI organizations are being asked the questions of what are you doing with ai?
How are you governing ai? And obviously we've seen the government obviously releasing, um, um, guidance around that as well. So they're asking these questions, which then they're asking those questions of the vendors and you know, that they're using and saying, what are you doing with ai?
How can we use ai? And I'm hoping that that conversation helps sort of propel all of these adjacent conversations that we've been like saying, we should do this, we can do this. Maybe we can forward finally one, it'll free up some resources to actually do those things a lot quicker and faster.
Uh, but the other thing is like, we're gonna start thinking about problems in a different way for the ones right? We're not gonna think about problems the same way, like you mentioned, like DevOps stack ops haven't changed in a long time, but I really hope this decade is when they actually fundamentally change, like passion and compliance scanning hasn't changed a long, long, long time, but I finally hope it does actually change. Um, but I'm hoping this is like sort of the movement that drives that change.
I hope so too. I mean, I, I'm on the board of the technology oversight committee of the Continuous Delivery Foundation, and I've worked on this little project called CD Events. Mm-Hmm.
Which is basically events event-based, uh, DevOps processing. I'm sure that people in this industry say don't say CD events three times, otherwise Tracy will show up because I talk about it so much because I believe it is the way to disrupt the, the, the DevOps process so that you could say that if this event occurs, we're gonna automatically generate an SBO m and SBOs at different levels. You know, you're gonna have an SBO m even at, at, at a, at, at an infrastructure layer.
So we do need to change and I'm, I'm, I'm hoping for that. So everybody check out CD events and Yes. Say it three times and I could show up.
Alright. So I wanna shift a little, yeah. I wanna shift a little.
So you are an officer in the Air Force, correct? Mm-Hmm. Yep.
How is that, how did that career develop and how did that get you to where you are? I, a little bird told me that you have a, a unique story about that. The experience.
I do. Yeah. So I was, yeah, I was in the Air Force, um, and I was active duty and knew that I wanted to make the transition over into the private sector.
Um, wasn't really sure what I wanted to do. And I was quite young and I was, and it's funny, my first reaction was, you know, everyone's like, what do you wanna do after? I was like, I think you just wanna go have fun.
Like this military thing was hard. And um, I was part of this like cyber intel unit and they were in kind of a midst of a big transition in the type of like work they were doing. And they were trying to figure out how they were going to, what they called secure, the afna, the Air Force Network.
And one of the technologies they brought on board was Tanium. And it come, these technologies come under some sort of like other names. It was, I had no idea what Tanium was at the time, obviously.
And they brought it on board and um, and they actually referred to it as a weapon system. It wasn't even, didn't even know what it was that we purchased this new technology. It's gonna do all these things and we need people for it.
I wasn't working on the technology or anything and I said, for what people? For what? And they're like, can you request people to come work on this technology?
And I said, this is like the eighth tool I've seen you guys buy, like I sense tool was coming again. Yeah, yeah. And I was like, oh my God, um, what are you actually gonna do with it?
And they had all these ideas and I was like, mm, I don't know. Like I'm not convinced to go through all this to find, you know, get all these resources. And I had a really cool commander at the time.
He said, what if you sit with them for two weeks and if they can convince you that we need it, um, then you'll do, then we will get the resources. And I said, sure. And so, you know, I start looking at what they're doing, what they're working on.
And funny enough, a pretty high profile admiral was coming and they were gonna show him this technology and they're like, you should watch what's gonna happen. They prepped this whole demo for him. It was like a script.
I felt like it was like a, you know, they had rehearsed a whole show for him. He comes in and he goes, I wanna know everywhere across the Air Force, anyone is storing passwords in clear text. And I was like, no, we can't do that.
There's no way. And I was like, that wasn't part of their script. I'm like, I'm like sweating for them.
And They're Like, no, we can find that. And my like, jaw is on the floor. I was like, oh my God, what did we get ourselves into?
And so they're sure enough, they do a search, uh, of finding anyone that's storing like password txt or a password docs file anywhere on their desktops in Clearex. Sure enough, uh, you know, obviously a lot of results come back and his face is red. I am going, oh my God, we just found this information just a couple of seconds.
And then he turns around and goes delete it. And I was like, please don't do that. These people are not gonna be able to log in.
And so, but he, he said, you know, you have 15 minutes to help everyone clean up storing passwords in ClearTax. And sure enough that happened. And just from that simple, like asking question, getting that data back and seeing that decision, I was like, this is so cool and this technology has a lot of potential.
That was my first introduction. I still didn't know what Tanium was. Um, months later when I had actually decided that I was going to transition out of active duty into the reserve side, um, I came across like Tanium and I applied for an HR job because I really, I wanted to have fun.
Remember? Um, so Hr, that's not fun. What are you thinking?
In my head? Low stress, you know? But it also fits every stereotype for women in the workforce.
I'm just calling, I'm just calling b******t on that choice. Yeah. Well, I, not I say marketing and hr.
Come on my, You know, it's funny, my interviewer at the time, he also called b******t In The middle of the interview. He goes, hr, um, he's like, no, uh, do you wanna be what? You know, at the time they had field engineers that they hired and all these field engineers they hired were at the director level.
So they never hired anyone that was any sort of lower than that. He said, what if you're a first sort of like entry level field engineer? I was like, I don't even know what that means, but that sounds good.
And I, and and little did I know, like this was like a whole experiment behind the scenes of like, can we actually hire entry level people and like, can we build them up and things like that. Ah. And um, so that's how I, my, I came about to actually coming to Tanium was like this thought I was applying for an HR role and got convinced halfway through the interview because they cannot go into hr.
Well, Kudos to the HR folks. That's awesome. Yeah.
Seeing what your, uh, clearly your talent and the depth of your knowledge was. That's, that's a fun story though. And how long have you been at Tanium?
Seven years. So seven years. Done a different roles.
I went, uh, did the field enduring stuff. I was a, uh, regional vice president for that organization for a bit, uh, for a couple years. And then I went and did chief of staff role for supporting our chairman as well as our CEO, um, kind of team around product management, product strategy work.
And then leading now, um, our product and engineering org on working on AI initiatives. She's ready to be president of the company Trace, don't you think? Oh, I think she should.
She's got it all, man. Please. She's done it all.
Or maybe she should come up with a really brilliant idea and go start her own company. That's what I'm looking for. There you go.
I wanna see more women in those seats. Absolutely. I agree.
So, so thank you for your service. Number one. I I have a military family.
Um, what, just because the, the service that my, my brothers and my father did are different. What do you do when you're in the reserves in, in the role that you have? Like what is the reserves party you go to every year and on the weekends?
Yeah, so it's actually, so I am part of a rescue unit. So what we do is actually, uh, over water risk, not just over water, but any rescues that Coast Guard can't reach because of air refueling limitations. Wow.
Um, that's what we do here in the states. And then overseas, obviously we do rescues out of AORs that require us to go long distances. It requires us to air refuel.
Um, so my unit was actually just in Jordan when all those attacks happened. So there were part, so we are, so that's our fundamental sort of role is just everything rescue related. There's only three units in the Air Force that do that.
So it's a pretty niche kind of cool mission to be part of. But my role specifically is I'm more on the operation side. It's actually interesting.
I'm not on the, uh, tech side in the air force, which is actually a really cool balance, I'll be honest. 'cause it challenges your brains in different ways. Uh, being here is looking at super technical stuff and then going there and it's really focused on how do you move things forward and is such a large organization, um, from a policy perspective, from a change perspective, all those things.
Um, so it's a much different role. That's Really cool. So did you go to USC, you, you, you got a master's from USC, correct?
Mm-Hmm. I did. Yeah.
Did you, did You do that before you went into the Air Force or in between? How did you fit those both in? That's my question.
We dig up the good stuff around here. You Really did. Yeah.
So, uh, I for some reason decided it was a great idea to do an MBA at the same time as working full time. Um, so I did it at the same time. Yeah.
Over a pandemic, which, you know, just really, uh, it was great timing. What else did we have to do, right? Yeah.
Why not get an MBA because we couldn't go anywhere. Didn't go anywhere. Yeah.
It's funny, I actually applied that year with all intentions ready to resign. Didn't obviously know a pandemic was coming, applied to USC, uh, it was between a couple of schools and was like, can't wait to go live in LA and so excited. And then comes like the world crashing down shut.
I was like, and you know, all my, no, all my friends are scared. I was like, wait, I shouldn't quit my job. They're like, no, you shouldn't quit your job right now.
That doesn't sound like a good idea. But I was like, I have already started this MBA program. Like do I not quit my job now?
Um, so every semester I think I told myself like, next semester, you know, the world will open up, the pandemic will be over. I'll quit my job. Never dead.
So I tortured myself, which I do not recommend. I do not like it is not recommended at all. But it was overall it was a great experience though.
I would think so I would think, um, I think you probably did it at the exactly right time. And I'm sure that you, you're, you're not quitting your job was the best move you, you could have made. I Think so actually I think it worked out really well.
'cause I feel like I got to experiment live with everything I was learning a little bit. And then right after I graduated from my MBA, uh, you know, I started the TRIVA staff role, which forces you to look at an organization every perspective. And I was so binary in how I thought before that.
'cause everything was very technical, right? Um, so the MBA kind of forced that and then I had to put it in practice, be like, oh, I remember this. Um, you know, so it was, it was a really, I'm glad I didn't quit my job now in hindsight, as much as I wanted to every single semester, I would.
I would think that too, that, um, Tanium would've wanted you to get your, your master's. It would be something that they would've encouraged. Yeah, absolutely.
Oh yeah, I, sure. I think it was more so just the workload on both sides. I wanted to do both things justice, and I think I was able to, for the most part, given that there was a pandemic, there was no other distraction for ones I was in traveling.
My role requires a lot of travel. But that during that time, obviously no one traveled. And, um, school schedules were a lot more accommodating as well, just given the nature of the pandemic and things like that.
Yes. Um, so it all like lined up perfectly Well, and I got to meet you briefly at RSA and I don't know if you remember, but Mm-Hmm. We did a, we are working with, uh, rum, who's our company that, um, we are becoming part of currently.
And um, Harman is being interviewed, I believe by, was it Shera? Yeah, Shera. Yeah.
So Shera did an inter, a couple interviews with you. So Mm-Hmm. I got to briefly say hello.
So when your name popped up on my radar for an interview, I'm like, score. Mm-Hmm. I'm grabbing her.
I think you're a great inspiration for young women to Absolutely. To follow a path. And I think it's hilarious that you applied for an HR job.
Consider your background. You know, I, I, it's, it's really comical now, but I think back, and I was having this conversation with my parents. So we, I was born and raised in India.
I spent most of my childhood there. And the first time I ever saw a computer was when I basically came to the us um, which was in the middle of high school time is when I really had an experience with computers. And I remember people asking me, what are, you know, that's the age where people start asking, what do you wanna do?
You know, where do you, what do you wanna study? And I remember saying, I just wanna be a receptionist. Like I would be so cool to sit at a computer all day.
Like, those things look so Fast. I be, that went over like a ton of bricks with your parents? No, They were stoked because they were, yeah, they Were like, Working in an office sounds like a great, it's a Great idea.
They all work blue collar jobs, they're like, yes, you should work in, they also have air conditioning. I think that was my parents' reaction. There was Air conditioning score.
Yeah, I would imagine. But you knew you wanted to work in front of a computer. That is the key.
Yeah. I did know that you wanted to be, you were interested in being in front of a Computer. Yes, I knew that part, but it's like receptionist, that sounds like a good job.
And what was your favorite, what, what did you major in in undergraduate? I think you said, I think it said on LinkedIn that you, you were in Hawaii for that, which is kind Of cool. I was, um, yes.
Not by choice, but very thankful for it. Uh, so I was stationed there 'cause of the military. Um, so I decided to go to college there, there as well.
So I studied information systems. So it was a blend of computer science and business. And did somebody encourage you to do that or you just said Yeah, this is Yes.
Who did that? Oh Yeah. Oh, uh, I decided I was going to be, I was gonna go law school at some point.
Um, and I think that's a pretty typical like initial sort of like, I don't know what I wanna do law school. It's like a great idea. Um, and I was about six months away from graduating and I met this, he was, it was kinda like a mentor and I had just met him and he said, what are you studying?
And you know, we just had this really random conversation we never talked about. And I, he knew I wanted, had some career aspirations in the Air Force, but he didn't know what I wanted or what I was interested in. I said, I'm getting a degree in law, a pre-law and I wanna go to law school.
He said, don't do that. He said, get a degree in something technical and you seem like you're really interested in technology, you talk about stuff like that all the time. And I said, oh, okay.
Like you. And I think part of it is because, and like women didn't do that, right? Like none of my friends were interested in technology.
None of my friends were pursuing that. My circle wasn't that. And so it never occurred to me that it's something that I could just do.
And even like I think back and like why didn't I think about going to medical school? It's like I just didn't think it was possible. Like, and it was the same thing with this sort of like, and so I literally, the next day I showed up to my counselor's office and I said, I wanna switch majors.
She said, you're supposed to be filling out your grad applications, like petition to graduate. And I said, I think I wanna switch majors. And she said, you know, you're gonna be here for another year and a half.
I was like, I don't care, that's fine. Like this is something I'm interested in. So I switched my majors and you know, it was between um, a couple of different things and what made the most sense for me at the time was I wanted the exposure and understand, obviously learn computers and take those computer science classes.
Um, but I also wanted to learn how the world worked. And I think like that business side of that really gave me that I understood like, okay, you can build great software but you have to go sell that software too. Like, you know, and you have to be able to market that as well.
So it was a really cool degree and I don't think, at least at the time, it wasn't very popular. People either did computer science or they did just did a business degree. Not a lot of people did sort of this blend.
And I think it's becoming more and more popular and I think it's really, really powerful. Um, but yeah, that was my, the, that was the reason I decided to study, Which makes the HR thing even more bonkers. But it's okay, we all go through these phases.
You ended up where you should be. Yeah. And anybody and anybody interviewing you for any company could have looked at that resume and said, you know what?
I got you pegged for a different role. I doubt. I'm not even sure you'd seen my resume.
It was just the conversation and what we were talking about. He was like, so do you ever HR rule open? He's like, why do you care?
Great. Yeah. Oh, That's amazing.
Well, we are, we are, you know, over like always, which I love. Um, this was just a fantastic conversation. I'm so glad that we had you and we, we like to have fun.
I think this was, this was one of my favorites. Um, you've, you've the most amazing personality. Um, you Kim, you just like, no matter what it is, it just keeps coming and I just keep moving and bouncing back and forth.
So thank you so much for being here. I'm really excited. Theres yeah.
Harman, you were great. And one last question. Do you have a good book recommendation?
Oh, we, for us, Uh, yes. Right now I am reading um, the Obstacle is The Way and it's so good. It just talks about, basically I think a lot of books focus on like how to be successful.
This book book talks about how do you actually go through the hard stuff and why it's so important to go through the hard stuff instead of avoiding it. Wow. That is a great recommendation for today.
'cause we have a lot of obstacles and how do we get through those obstacles and come out better, right? Yes, absolutely. Well great.
Thank you so much for being here. I gotta thank Jessica Bettencourt, she's my buddy and, uh, she found another awesome interview for us. Um, love working with her.
So thanks to everybody for watching today and um, we look forward to seeing you on our next episode of Techstrong Women. Thanks for being here. Have a great day.
And don't forget to tune in to Techstrong TV every day, five days a week. We're online now. We just started a week ago, so you can watch new content every day.
Thanks for being here. Bye guys.

