Enhancing Cyber Resilience through Diversity and Innovation, Tech.Strong.Women. EP 35
In today’s episode of Tech.Strong.Women. Jodi Ashley and Tracy Ragan are joined by Anneka Gupta, Chief Product Officer at Rubrik. In an era of increasing cyber attacks, data security is critical, and Anneka Gupta from Rubrik emphasizes the need for strategies that ensure cyber resilience and recovery post-attack. Traditional prevention methods must now be complemented by proactive measures like protecting critical data and reactive approaches such as recovery planning. AI plays a growing role in identifying threats and automating responses, though it also introduces new security challenges. Gupta highlights the importance of diversity in developing robust security strategies and advocates for making security accessible while communicating the industry’s talent needs. Building community and mentorship is vital to enhance diversity in tech fields, a value she embodies through her teaching and mentorship at Stanford. Inspired by her engineer parents and entrepreneurial spirit, Gupta leverages her passion for startups to drive technological change and support emerging talent.
Transcript
Hi everybody. Thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech. I'm Jody Ashley, executive producer here at Techstrong, and I'm here with my co-host, Tracy Reagan, creator, and CEO of Deploy Hub.
Before I introduce today's guest, I wanna give you a quick update about what's happening here at Techstrong. You guys all need to register for our annual DevOps Connect DevSecOps 2024 event on Tuesday, June 18th. This is for all of you who didn't get to go to RSAC, and you'll get to experience our whole DevSecOps event day and, and enjoy it, um, online.
So please sign up for that. com and be sure to tune in every day for live great content on Textron tv. Hey, Tracy, what's on your mind today?
Well, you know how, um, we all know that this happens. Software companies, you know, they project features and they may not have delivered them yet, but this is something that's opposite of that. So, on a recent trip to go see a full eclipse of the sun, I downloaded a ton of, um, wait, wait, don't tell Me, which is one of my favorite podcasts.
I love that You do. They're hilarious. This stuff is really funny.
And it came up in the conversation about Google's incognito mode. I had not heard this lawsuit. I should have, I don't know why it didn't come across my desk, but, you know, I've, I've used things, I used incognito many times just to protect my browsing information and in, wait, wait, don't tell me they exposed that incognito mode, in fact didn't exist.
And so maybe you thought you were actually carefully, um, being protected by their incognito mode, but in fact, they have recently agreed now to protect that and actually get rid of the collected information they had about what you were doing when you were in incognito mode. Uh, and apparently there's a settlement out there that you can, uh, you can add if you have used incognito mode and wanna be part of this Class X soup. So there you have it.
I caught something like briefly, but I didn't read the whole article. I guess I should have. Is that nuts?
It's crazy to me. It's nuts And, and, and somehow not unexpected, to be honest. Well, I think it's funny that I heard it on Wait, wait, don't tell me because I'm sitting there like, wait, wait, wait.
Don't tell me that. That's Amazing. Alright, well, that was a good one for today.
Thanks, trace. Um, I would love to introduce our guest today, Annika Gupta. Can you, uh, tell us a little bit about yourself, what You're up to?
Absolutely. Um, thanks for having me. So I am Annika Gupta.
I'm the Chief Product Officer at Rubrik, uh, which is a data security company. We help, um, large organizations and enterprises recover their data after they've been hit with ransomware attacks, uh, which is really, um, important, really interesting, um, obviously very relevant nowadays. Um, and in my role I oversee all of our product development, product roadmap, um, and design team.
Um, on the personal side, I was born and raised in the Bay Area, and somehow I've found that I've never left. Um, I've stayed here my whole life, but probably because I'm so excited and interested in in technology. Both my parents were entrepreneurs.
Um, so I'd say entrepreneurship runs in my blood. Um, and yeah, I mean, I love working in the data space and security space. Actually, before Rubrik, I worked in marketing technology, so you were talking about incognito mode and all this stuff.
I was like, that was my world before. And like You, I Was like, not unsurprised, but not surprised, unfortunately, by that news. Um, and yeah, I, um, I married, I have a two year, almost 2-year-old son now, um, who's the center of my world outside of work.
Um, and yeah, just super excited to be here with both of you. Well, we're super excited to have you. Um, and to really start talking about, you know, I I love the, um, I don't love it, it's a necessity, but I am fascinated by all the cybersecurity that's facing us, which is one of the reasons why that incognito lawsuit was so fascinating to me.
It's like on a, in a discu in daily discussions, we, we hear on the news about, you know, we talk TikTok and, and data being exposed. Um, I was kinda shocked that Google was actually tracking that when we were asking them not to. Um, but let's just, you know, I come from the software supply chain.
When I think about security, I think about it from a, from aspects of what you're pulling into your build that you shouldn't be. And it can be very, very complex. I don't know a lot about data security.
Can you just kind of dive in and tell us where some of the real pain points are in data security and what companies should be thinking about? Yeah, absolutely. So it's a, it's a really interesting area.
Um, so there's a couple of different challenges. If you think about data within an organization, I mean, the amount of data that organizations have is continuing to grow. The importance of that data in terms of allowing people to even operate day to day is, um, is incredible That data is sitting in so many different places, so many different applications, clouds, data centers, et cetera.
Um, so even keeping track of it is really challenging. And then from a cyber perspective, as you know, um, just the, the, the frequency scope impact of cyber attacks is just growing. Uh, now a lot of traditional security has been focused on prevention.
So how do you keep attackers out of your four walls? How do you keep them out of your company, out of your environments? And of course, that is like, uh, incredibly important to invest in those kinds of technologies.
However, what we're finding is that, um, more and more is that it's not a matter of if, but a matter of when someone breaks through your preventative security measures and they actually get into your environment, they get into your systems, your applications, your data, um, and then you have to have a strategy about how do you bounce back from that. Um, there have been so many very public ransomware attacks that have happened, um, in the past couple of years that have brought down businesses, um, and organizations for weeks, sometimes months, um, or even up to a year. Um, and that is devastating for those, those organizations.
It's devastating for the customer, consumer, citizens that those organizations serve. Um, so, uh, companies and, and any organization need strategies for cyber resilience or how are you going to bounce back and recover after an attack has happened so that you can minimize the overall downtime for your business. And that's what Rubrik FO focuses on.
So, um, in some of our recent discussions, um, with, uh, some of the tech, tech strong women we've been talking to that's in this field, they talk about, um, offensive and defensive security strategies. And so of course I've been thinking about what those look like in the supply chain. Mm-Hmm.
Can you talk to us about what the, you know, what that means to you? And if there are specific strategies in data security that you might con consider, you know, this is my offensive zone and this is my defensive zone. You know, where does that line cross and what does it, what does it look like?
Yeah, It's a great question. Like, I, I kind of think of it as like the reactive and proactive strategy. Uh, so from a reactive perspective, I mean, you always have to prepare.
Like, we can't help a customer if they haven't purchased our products and implemented our products before they have an attack. So there's always some amount of preparation that's required. But from a reactive perspective, it's like, you know, when we think about data security, it's like, how, what are you gonna do after an attack happens?
What is your, um, what is your playbook? Do you have the technologies in place? Do you have the processes in place?
Do you even know what data was going to, was impacted in an attack? Do you know what to recover? Do you know how you're gonna find the point in time to recover so that you don't reinfect your environment with malware, um, or other, other, um, issues and vulnerabilities?
Um, so all of those kind of questions we put into the reactive camp, I mean, you need to, you can prepare ahead of time for it, but you need to have a reactive plan and reactive technology that can really make sure you can answer those questions quickly and then hit the button to know when to, when to restore to, and actually do that restoration as quickly as possible in a matter of minutes or hours. Um, on the proactive side of things, um, there's a question of like, you know, what we find, um, in, in the resurgence is heavily talked about in, in the security industry is often what happens is, um, attackers find a way into an organization, maybe it's through a phishing attack or through other kind of compromised identity. Um, and then they make their way through and they're looking for what are the interesting applications, what's the interesting data, um, that, um, that I can get access to?
And, uh, what we're some of the, the more proactive things that we're looking at is like that, that time between them getting in, investigating, trying to figure out like bad guys, trying to figure out what to actually do next, which systems to lock down, what data to potentially extract and potentially put on the dark web. There's a time lag. Um, that time lag can sometimes be days, um, a minutes, days, uh, sometimes it can be weeks and months, uh, where the attacker just has these in, uh, inroads into an organization, but they haven't figured out exactly what they wanna do and how they wanna exploit that organization.
And so one of the things that we're thinking about and we're, we're having our customers think about from a more proactive standpoint is saying, well, what can you do ahead of time to try to figure out, um, how to mitigate when someone gets in? And in that time when they're poking around, making it such that they don't get access to the data, that is your crown jewels. And, and the way we can think about that is by saying like, if ahead of time you can take the data that you know is most important to your organization, most sensitive, and make sure that's really locked down to just the people who need access to that data, and that it's not floating around in the ether in other parts of your environment that you don't know of.
If you can really lock that down, then you can potentially prevent that attacker from truly find, like easily finding that data and you can truly figure out, um, how to mitigate that, that attacker once they've gotten in, but they haven't actually taken a destructive action in your environment. So that's kind of some of the stuff we're thinking about from a more offensive perspective. I, you know, I, I think the reactive is probably one of the most, I think it's more critical to be quite honest.
Um, oh, Absolutely. I, I don't think, you know, I I always tell people in the supply chain, the software supply chain, we're just not gonna code scan away out of the problem. No, no.
It's just impossible. But, but we can figure out how to respond rapidly. The response I feel is so much more important, um, because it, there, there's just so many ways that, that people are getting in.
Yeah. There's so many ways that we can't think of that somebody else has thought about. Yeah.
That the, that the being the reaction and taking a, a playbook from chaos engineering, which I think is fa which is I think is fascinating. It's a really great way to think of, of things, have those game days come up with ways to see how quickly you can react and then start strategizing and really start creating those threat models to understand how to be proactive. Yeah, yeah.
Absolutely. And I think the problem is that a lot of people have thought about the proactive and actually haven't figured out the reactive in enough detail and haven't practiced it enough times to make sure that they can actually confidently react in the right way when the time comes. And I've had conversations not recently, I think it's dwindled a lot over the last four or five years, where I, I wanted to pull a panel together to talk about this.
And I had people who literally didn't wanna engage because they only wanted to talk proactive. They didn't wanna talk reactive. They're, no, our goal is to prevent, prevent, prevent.
And I was like, okay. Yeah. And, but I, I'm hearing less of that and more of the, you know, the two-pronged defense, uh, for lack of a better term.
Yeah. That you've gotta be, be thinking. And I think, yeah, more and more now, it's reactive.
You've gotta be prepared. And I think like the good thing now that's happening is that, um, organizations are no longer being judged about have they been attacked, right? It's more about they're being judged on how well they respond to that.
Um, which I think is a positive development because like in reality, no one can fully a hundred percent prevent an attack from happening. Uh, but you can, the thing that is in your control is how do you respond, how do you communicate out about what happened, what the impact was? How do you then learn from that, share those learnings, remediate, um, what you, you could have done better, um, from a preventative standpoint so that you don't leave yourself open to the same thing happening again.
And you see a lot of situations where organizations are getting dinged just because they, I mean, because they haven't really thought through their communication plan and how are they going to talk about this and how are they going to be transparent? 'cause I think that is really becoming the standard is like being transparent. And I, I actually think that's good overall.
'cause the more transparency that organizations have and share with the rest of the public, the better other organizations can use those learnings to then, uh, prepare better for the future. How long, what, you know, in, in the, uh, software world, according to Jfr, it takes 227 days to respond to vulnerability. Isn't that insane?
It's, It's crazy. There's numbers all, like any, there's so many published numbers, but all of the numbers are so crazy. But it's not, in some ways it's surprising in some ways it's not surprising.
'cause like every vulnerability, there's so many steps you have to take to investigate what's going on. What did, what did this take happen Where it's running in our world, where's where, how many steps? Where is it Yeah, Exactly.
Catch and The it in the first place. Right, exactly. Yeah.
Yeah. Finding the mitigation, finding it, because they do have to, it's gotta be mitigated. Once it's found, it's gotta be mitigated, then it's gotta be remediated.
What's the, what are the number, what are the numbers look like in, um, data security? It, it's fairly similar. I mean, there's a, a lot of different numbers floating out there.
Um, but yeah, I mean, like we look, we, you know, we track things like, uh, and there's a lot of research out there about how long do does malware sit in a system before it's detected? And that can be anywhere from days to, you know, often weeks and months. Um, you know, it's, it's scary.
And like that's time where it could be Solar Winds sat there for a while. Oh, solar winds. Yeah.
I mean, yeah, I think It kind of hid back there and was just like, I'm okay. Yeah. And then there's I doing Anything bad, right?
There's solar wind To see, Then there's like zero Dave, there's zero day vulnerabilities. Right? There's other things that are just lurking there that you just don't know.
Like they can be sitting there for years, like log four JI mean, that was a big one that was there for so long That slapped everybody in the face. Yeah. They all were spinning around off their, that.
Yeah. So what, What role do you think AI is gonna play in being able to shorten that? Even if it's just notifying you there's some malware.
It seems like AI is like the perfect tool to cut that number in half. Yes. Right.
Just identifying it much more quickly. 'cause there doesn't have to be a human doing it. It, you know.
Yeah. I think, um, I definitely think AI is playing a huge role in both identifying these issues quickly, but then helping figure out how to remediate them because, um, you know, the number you just quoted of 227 days to, to remediate a vulnerability. I mean, the, the challenge is, is that if you talk to security professionals, they're just inundated with alerts.
Oh wow. And so even if you found the alert, even if something got alerted early, how are you going to figure out which alerts to prioritize and how you're gonna actually go remediate them? And that's where AI can play huge role.
And both like helping find what, like find the alerts to begin, like figure out what to alert on, but then helping prioritize those alerts. And then hopefully as we get more sophisticated, helping automatically remediate. And if we can get to this world where like the de everything from the detection all the way through to re remediation can be automated, that is the probably the single biggest thing that's gonna make a dent in, um, in organizations facing the number of organizations facing catastrophic or semi catastrophic cyber attacks.
I agree 100%. It's the remediation we gotta auto remediate. Um, you know, it's, it, you know, we at Deploy, I've been thinking about that.
'cause we have all of the insights about here's the workflow, here's the deployment. We know how to rebuild, we know how to redeploy, let's just go find the correct package. Yeah.
So you gotta go out and look at Mitre attack and see if there's a remediation, but then you go find out that the remediation may not be the best remediation because it's pulling from a, from a repo that's not secure. So we've got a lot of work to do yet. But I believe as Jody is correct, that I I think that the, that AI is going to get us out of this, but it's gonna be a few years before we get there.
Oh, For sure. Even in our DevOps space, we don't really collect the data in the first place. Right.
It's all in scripts and it says SBOs are in text files and it's all fragmented all over the place. So we just have a lot of, a lot of work to do. And then we, on top of all that, we have ai, which has got all these large language models and those have exposure to, uh, right now.
Correct. Yep. Yeah, absolutely.
Um, it's, you know, AI is solving a lot of problems and it's creating a whole bunch of new ones from a security perspective that we're, we're all gonna have to figure out collectively how to solve. I mean, there's new research coming out every day about what are some of the challenges in retrieval, augmented generation and, um, reverse engineering embeddings and things like that. And then there's obviously all this stuff around LLM security.
There's copyright issues, there's legal, I mean, there's just a whole slew of issues that are security or I would call security adjacent, um, that we've gotta figure out around how to deploy, um, ai, um, AI products and AI applications safely. Um, then we have to also figure out how to actually remediate, like do all this auto remediation. So there's a lot of work to do.
I I agree it's gonna be a few years before we, um, before we realize that vision, but I think at least we're seeing that foundationally the technology is there too. Um, and we have some paths to, in order to be able to get to that vision. So, um, you know, there, there's a lot to think about here and where we have to, where, where we should be starting first.
Um, and you know, I think that we, as we're starting to build these large language models, yesterday our conversation was, you know, there's all kinds of problems with those LLMs. There's built in bias and we call the, you know, bias in bias out. Yeah.
Is there a threat where somebody's going in and tweaking these large language models to make them simply incorrect? I mean, what are some of the threats around, um, uh, AI and data? Uh, yeah.
I mean, if you think about the large language models, they're sucking in essentially all the data on the internet, all the data on the internet has both correct and incorrect data in there. So, I mean, you talked about bias and bias out, there's a garbage in, garbage out issue as well of, you know, how accurate is the information? Um, I mean, I think from a security perspective, if you think about use cases like code generation for engineering, you could imagine that a bunch of the code that it's been trained off of has security vulnerabilities in it.
So if you're using it with code generation and not doing any additional vulnerability scanning and checking and, and figuring out, like what does it mean for a bunch of, you know, code to be outputted from an, a large language model that potentially has security vulnerabilities in it. I mean, that's just one, one example of many of the kinds of challenges. They they definitely will because they're pulling it from code that has the it's already in it.
Exactly. It happens. That is what's going to happen.
Yeah. So I think there are a lot of challenges. I think there are still ways that, um, and I don't think it's all doom and gloom in terms of, I think, you know what some of the limitations are of LLMs, you can mitigate some of the risks around it.
Right? And, um, you can mitigate, like what, what data are you putting in? Even as a prompt, even if you're saying, Hey, don't train on my data, you know, it's a best practice.
Don't, don't put, don't be sending in PII or other sensitive data, um, into the l lm If you're thinking about like building different applications where you're augmenting the LLM with your own knowledge bases, how do you select the data that is the most accurate to feed in so that you're not, again, getting garbage in, garbage out? So I think there are mitigating factors, but we have to realize that there's a lot that happens behind the scenes. And none of us are fully gonna understand about how LLMs operate on the backend.
Uh, we can understand the high level, but we're not gonna all be LLM experts. And if, I think the main thing is to understand the limitations into architect solutions, understanding what those limitations are and mitigating for them. I don't think it's like we can afford to not use the technology, but I, I do think that we can come up with ways, um, to deploy them responsibly within, for the use cases that that can create the most value.
Well, yeah. I have never, you know, I've been in software all my career. Um, I go back, my first job we'll just say I was coding on the mainframe.
And I don't think I've ever seen, you know, we've, we have these, these waves of technology that have, that hit us over the years where, you know, you had to readjust to this new technology. But I don't really think that I've ever seen so much new technology, um, hitting our keyboards Mm-Hmm. As quickly as it is.
And, you know, I, Kubernetes, um, I knew that Kubernetes would change the way the world works. I really did. I always, I always say it the first time I ever saw, uh, how G GPUs can escalate so quickly.
I was at a, like a little software developer conference and I wanted to get up and run around. I'm so excited. I really was, but I didn't realize the impact.
It is impact because Kubernetes is a really has given birth to ai. Yeah. And at the same time, we have all the cybersecurity issues that we're dealing with.
So we really have like three waves that are hitting us. One of the ways I waves I see in the, in the database world is, uh, decoupled databases. So instead of these massive, monolithic databases, smaller little databases that are only associated maybe to one microservice or API.
Yeah. Yeah. How does that change security, uh, in for data security?
Does it make it harder or easier? Um, I think in general, fragmentation of data, which is a larger trend that we see, whether it's, you know, what you're talking about, fragmenting a monolithic database into smaller databases or recognizing that data with it. Like an enterprise's most important data may live in hundreds of different applications.
It may live in your, you might be an A-W-S-G-C-P Azure customer and have data sitting there 'cause you're building applications there. You might have hundreds of different SaaS applications deployed across your environment. You might have data centers, um, that are still doing things.
Um, and I mean, that makes being able to secure all of this data incredibly difficult because one, you don't even necessarily know, like if you asked someone in it, do you know, do you, can you say with confidence, you know exactly where all your data is in your organization, where it lives, what applications people have deployed there. I mean, no, no person is gonna say yes, absolutely. With confidence, I know a hundred percent of what's out there.
So even just having visibility into what's out there is a huge challenge. And then you talk about, well, each of these environments are very different from each other. How do you actually provide data security in each and every one of these environments where data lives, um, and provide recco, like be really be able to be that last line of defense, help recover data into each of these environments.
It's very complex. Um, so it's not, um, not a simple challenge. It's why I'm really excited about this space around data security because there's just endless frontiers of where we can go and what we can do.
And it's, it's absolutely critical. Um, we can't afford not to have this. Um, and we can't afford not to have data security for an organization's most critical assets.
It's so complex now. Systems are so complex. Their dependency maps are vast.
And that's not even thinking about like all the configurations. Yeah. Just trying to track a bunch of, uh, tables and understand that there all their configurations are consistent.
Um, it's not for, it's not necessarily for humans. And I think that it's not, And I think we'll get smarter at do, at managing it. I think there'll be some interesting tools come along in the market.
It's just really, and it's funny because right now we have all this, we have all this new technology coming up, but we don't, and we have, you know, if you put something AI in front of it, investors run to it. Right. But we don't have a lot of investments in other areas.
Is it, you know, like in security. So I I I feel like we're, and and the other thing that's I find that's interesting is the idea of DevOps. Mm-Hmm.
Has gotten old and kind of creaky. And so people aren't thinking about it anymore as a way to solve some of these problems within the pipeline. It's like the pipeline has to get resurrected in some way.
Um, but anyways, those are just my random thoughts about how much technology is being thrown at us and how behind we can get. Well, I wanna shift things for a minute. I wanna know, I'm stealing Tracy's question 'cause she does this every time.
She knows what I'm gonna ask. She always asks this. Tell us how you got into stem.
What was your journey? What made you excited about doing, doing this? How'd you get here?
So I, uh, came from a family where STEM was very much Part of, um, part of my parents' careers and life. So, um, my parents both immigrated to the US from India back in the late sixties, early seventies for graduate school. Um, and they were both engineers.
My dad was a mechanical engineer. He got a PhD. My mom was an electrical engineer.
Um, and she came to get her master's. Um, and then they stayed here and they worked in Silicon Valley in the early days of Silicon Valley. Wow.
Um, and, um, and you know, in engineering. And then eventually they each started their own companies and ran their own companies. Um, and so like growing growing up, no Overachieving in your family Growing up?
I was always surrounded by by stem and I was, um, and my mom esp, both my parents were mo very much like encouraging. They weren't, they never forced us into, into stem, but they were encouraged it and they built that genuine curiosity, um, in us. And I think that really got me excited from a very early age in how does stuff work.
Like, I was always just really interested in like, why are things the way they are? How do they work? And I think that brought me into STEM and got me excited.
Um, and then I think as I was thinking about my career and like after graduating from college, I, um, I just got, I was so excited by startups. I was so excited by the way that technology had an opportunity, had the, um, ability to change everything about the way we operate and do things. And, um, that's 100% proven to be true.
A hundred x over. Um, and I can't imagine myself working in any other space. 'cause it's just so interesting, um, and so impactful.
And do you have siblings? I do. I have a younger sister.
Um, she also works in product. Um, And I was, that was gonna be my following question. What does she do?
She works in product. She works at, um, ironclad, which is a legal software company. And she's actually working on all of their AI initiatives.
So Oh, wow. We can have a lot of relationship. You guys have some fun conversations.
Absolutely. Well, kudos to your parents for bringing in bringing up two women and having 'em both go into stem because it isn't, it's, it's not, it, that's not a normal thing, right? Yeah.
Yeah. It's Rare. I feel very fortunate.
I feel very fortunate. And it's not always easy, right? You're often like the only woman in the room, um, in many conversations, in many situations.
Um, and that just, unfortunately, it's like something you have to get used to, but it's, um, yeah, It's hard. It's not easy. And sometimes it chases women away.
Yeah. Yeah. Unfortunately it does.
Yeah. We hear that so often. Like almost every time we do an interview, it's the, I'm the only woman in the room thing, and it's just, it's exhausting when we, you know, we wanna, we wanna fix that.
I think it's just really, you know, frustrating. Do you mentor, do you, what else? You know, how do you, how do you kind of expand Your territory?
Yeah, absolutely. So I, um, I teach at Stanford, actually at the business school. I teach a product management course.
I've been doing that for three years now. And that's been really fulfilling both in terms of helping me hone how I think about product management. There's no better way to, to figure out what, you know, if you, uh, other than teaching it.
Um, and then it's also really helped me connect to students, um, in a more meaningful way and help them navigate as they're thinking about their career post school. And I've really enjoyed that. Um, and then I'm also a member of a, a, a product community called the Skip, um, which has, it's both women and men that work in product management and various product leadership roles.
Um, and that's, it's just been a wonderful community to both like connect with other product leaders, learn from them as well as, as give back and mentor, um, where people have questions and need help. Um, because not like being a product leader can also be quite lonely. You're sitting at the intersection of so many different, um, initiatives going on in an organization and having to navigate through those and not necessarily having authority over a super large team, but having to influence a lot of people.
And so that's having other people to kinda rely on, um, and, and learn from has been really valuable. You know, I mentor about, uh, maybe half a dozen, uh, women, um, and I find women are less likely to reach out for mentorship. Do you encourage that?
Oh, I do. You let them know too? Yeah.
I mean, one thing is that, oh, I often have one, someone will reach out to me for one conversation, and I always end the conversation saying, Hey, please reach out to me if I can help you in any way. Here are the ways that I think I can help you. But if you think of anything else, if you have a quick question, if you just need me to shoot me a text about something, please do that.
Um, because I worry about that same thing. And I see that the hesitation to reach out, to ask for something, to feel like, Hey, I'm not giving enough back. I'm just taking in this relationship.
Um, and I, it's hard, but it's like I get so much out of mentoring people and I always want them to realize that so they don't feel like it's a one way thing, one way street where they're getting all the value and I'm not getting value from it too. Yeah, I get that. I, I mean, I I, one of my mentors, I hadn't spoken to her in three years, and she reached out to me this week and I was like, good gracious, has been way long.
Mm-Hmm. I'm so glad that you've reached up in the meantime. She had a kid and she was off.
So now she's trying get back in, right? And so now she's like looking for mentorship again, which I understand during covid was a big problem for women. Mm-Hmm.
Um, a lot of women took on the role of homeschooling during COD and many of them didn't get back into, uh, the, the industry because it changed so much during that period of time. And I find that to be a little concerning too. So ladies out there, if you're coming back into the marketplace, there's so much, we're all learning and cybersecurity and data security and software supply chain security, that it's, and ai, everything's almost new.
And on that note, we always like every our guest to give us a book recommendation. Um, we started this because of one of our guests, uh, told us to read something called The Failure of Logic. I'm sorry.
No. The Logic of Failure. The Logic of Failure.
And it was fascinating. It was one of the most fascinating books I've ever, ever read. So do you have a book that you would, you would suggest?
Uh, I really like this book called, um, uh, sorry, where was it called? Where are you? Where we, where we are when, Ugh, I'm forgetting the name of the book right now.
Um, let me choose a different one. Um, that book is, it's, it's called, like, it's something like where, where we, uh, where we came from when, or something like that. Um, where it was, it's about, um, human evolution and human migration across, um, across continents.
And the thing that was really interesting about it is, um, I remember learning about evolution in school and, uh, and having this like, view of evolution that was very different, um, than what we know today because we've learned so much about evolutionary biology, both for humans and for animals over the past, you know, 30 years. Um, and it's, uh, it's just fascinating because I think like understanding, I've always been like interested in history. And then you think about like, the ancient history of humans and how we got to where we are and how many other human races there were, um, besides like homo sapiens.
And one of the sad truths is that we wiped out all of the other, um, homo uh, um, yes, We did homo, You know, you name it, um, species. Um, and it, you just, it it gives you an appreciation of, of who we are as a species. And I find that just very intellectually fascinating and humbling in many ways.
And that's, um, that's, yeah, that's what I recommend. That, that it was a very, very Good book. Neanderthals didn't have much, um, I think the Neanderthals wiped out, or the homo sapiens wiped out the Neanderthals, right?
Yes, yes. But there were many other, we did you hear about Neanderthals, but there were many other human species like Neanderthals that were offshoots of homo sapiens that lived weird all over, over the world. All over the world.
Weird. And, okay, I think the book is called Who We Are and where we got, how we Got Here. Yeah, yeah, yeah, Yeah.
Who we Are. Oh, David Wright. Yes.
Yes. I'm gonna have to, it's, It's also like a great book for stem because he talks a lot about how we figured out the human migration, and there's a lot of statistics and genomics and all the stuff in there that you're like, oh, this is fascinating. How we can possibly learn and know all of these things, even with just fragments of evidence of, you know, some DNA here, some bones here, some archeology.
And it's the intersection of all of these different fields that then kind of lays out the history of, of the human race. I can't wait. I'm gonna download it.
That looks like a great book. That looks really fascinating. President.
We're all related, right? Yes, exactly. Because we're all all part of the race that survived.
Yes, exactly. And apparently very aggressive. Yes.
So something else that, um, I wanted to talk about is, is, um, I know it's important to you to foster inclusivity and, and in the environment in tech, I know we've talked a little bit about women, but I mean, it goes far beyond that, right? And all of the, the inclusivity of, of bringing in every part of our, of our population and world Mm-Hmm. Into this field.
Um, what, what are, how do you do that? What are you working on? It's, I mean, I think it's a really big challenge.
Um, and I think especially in the world of security, um, we know that a diversity of voices, opinions, experiences are what's going to help us develop better strategies, better products, better processes, better teams. Mm-Hmm. Um, and the reality is, is that we have two, two little diversity in, in this area on pretty much every access you can think about.
Right? Right. Um, and so I think one is like, how do we help, how do we help make this field approachable and make people realize, Hey, I can learn this.
I can have an impact on it. Um, and I, that's why I love talking about security. I love talking about it in forums that are not necessarily like, you know, with other security experts, but like going to, um, university campuses or, um, you know, going on, you know, talking more broadly on podcasts or anything like that to talk about how interesting this area is and that, and that it is something that there's such a need for talent that people should be like, try to fig find a way in because there is, there's a plenty of need and, and we need those voices.
I think on more of a day-to-day basis from a leadership perspective. Um, how, you know, one of the things that I think really helped me in my career was having people that were more senior to me that I could approach and ask questions to. And I think one challenge is that like, as you get more senior in leadership, people are more scared to come talk to you and ask questions and get advice.
And so I try to do something where I like, just make myself like hyper approachable, um, in, in the office and to anyone that I meet to just like reduce that barrier so that I can have conversations with people, I can engage with them, I can get them interested, um, and I can support them. And, and that's really, really important to me. So whether that's just walking around the office and talking to all the people that mm-Hmm.
Are, are here, or, um, it's going to events and just like walking around and having casual conversations. I think, again, as a leader, a lot of times your, your time is so scheduled that you don't get time for more casual interactions or like going to work happy hour or something like that with the engineering team, whatever it is. It's like those, those kind of casual interactions I think are super, super important.
And I would just encourage like other leaders to think about how they can engage in more of those casual interactions because they do make, they're highly impactful. It's hard for me to realize exactly how impactful it is, but people have told me that. And, and so it's something that I'm like, I, I try to really practice very intentionally day to day.
Well, and it seems even more important now because we have a whole generation of kids and they're coming out of Covid, right? Yes. We've got these kids that graduated and now this year they're dealing with college graduation being all crazy with what's going on in the world.
And they, they don't communicate the way we were raised communicating, like, having conversations. Even my kids, they're 27 and 30 and they drive me bonkers 'cause everything's a text message and I'm like, just pick up the phone and call me. Yeah.
And I think a lot of our, our 20 somethings just don't have that face-to-face, ability to communicate. And then again, they're, you know, intimidated by someone who, who they work for. Of course.
You know, there's some of the reverse of that too, where it's just like, blah. Yeah, yeah. And you're like, okay, well then I, and I shouldn't be poo-pooing on this, but I do, um, I feel like sometimes DNI initiatives, uh, you know, when companies have like a DNI initiatives or somebody's doing DNI, it's just their way to say we're doing something.
Mm-Hmm. But sometimes I don't feel like it's getting, it's not that something's not actionable, you know, we are not act we're, we're not triggering more women through the pipeline to, to, I'm not seeing, uh, more resumes, you know, we, in, in conferences, we're not seeing more women, uh, stand up to speak no matter how much money we have spent on DNI initiatives. It's not necessarily, I don't think it's working to be quite honest.
Yeah. Something's gotta disrupt the process and I don't know what that's gonna Be. Yeah.
I wish I, I think there's no easy answer to that because I agree with you. It's like there's a lot of focus. It's great that there's more focus and attention on it, but it, I don't know how we change it.
I don't know how we get people more just in j at a societal level encouraged to go into stem, encouraged to apply to these jobs, encourage to once they apply and get the jobs to stay in those jobs. Um, really, really difficult. Um, but I do think it has something to do with community, um, and how do we help build community where people feel like they belong?
And that's just, it's a very difficult problem. I agreed. Maybe we need to have more than one female oriented conference every year.
You know, maybe the, that would help. A Grace Hopper conference is just not enough. Yeah.
Yeah. Somewhere I think like community has to be built on a local level and it, again, it's very difficult to do that at scale, but if you can, if you could build that, those local connections and get people excited and connecting on a frequent basis, I think it, it helps get through the challenges of being the only one potentially on your team that's a woman or only person in, um, at your level. Right.
Things like that. Well, and I think Covid set us back years So much so It's so many, like we were talking about so many women became the, the new teacher in their household. Yeah.
And they didn't reenter the workforce. And we are, we've, we've kind of talked with some women who are part of organizations that are encouraging those mo those stay at home moms. You can learn to code, you can learn to do all these things and do it at home.
Mm-Hmm. And you don't have to go, you know, into a traditional workforce environment. But again, it's like we've, we've backed up, you know, all these steps forward and then I think for the last four years we're trying to rebuild and I won't think we're even back to where we were in 2020.
So we'll get there. We'll, we've got programs like this to help us get out there and talk to women and, and, uh, find a way. Thank God for tech strong women.
Right. We have, we, it makes me feel Like we're changing the world. We're there are so many amazing women that we have taught, spoken to.
We know you're out there. We just wanna see you more often. Absolutely.
Well, Annika, thank you so much for being with us. We're so excited that you were able to, to carve out some time. We know you're a busy lady and, uh, we appreciate you taking time to, to be on, um, tech Strong Women with us.
We just can't thank you enough for being here. Thank you. Thanks for having me.
And everyone, um, that kind of concludes our latest episode of Text Strong Women. We like to keep going, but I get yelled at if we keep going. So I'm gonna have to call it quits for today.
But please stay tuned for more great programming on Text Strong tv, and for our next episode of Techstrong Women. Thanks, and we'll see you soon.

