AI Governance Under Pressure: OpenAI Pauses Astra
The OpenAI Astra pause is the story of the week in AI safety. OpenAI paused development on its Astra model over autonomous cyberattack risk. The timing is notable. Senator Bernie Sanders used the same week to push for a broader slowdown across the industry. Alan Shimel and Mike Vizard dig into what the OpenAI Astra pause signals for AI governance. They are joined by Kate Scarcella, Sid Nag, and Chris Blask. They also debate cybersecurity industry bloat and new research on instinct-driven decisions inside AI-era companies. Watch the full conversation on Techstrong Gang for the complete panel discussion.
Why the OpenAI Astra pause matters for AI governance
OpenAI stopped work on Astra, a powerful autonomous model, after internal red-teaming flagged cyberattack risk. The company said the model could plan and execute intrusion steps without close human oversight. That risk pushed leadership to pause rather than ship. Bernie Sanders called for a pause on AI development across the whole sector just days later. His letter argues the industry moves faster than regulators can track. Alan Shimel says the overlap is not a coincidence. Mike Vizard notes that boardrooms now treat safety pauses as normal business decisions, not PR moves. The panel agrees this marks a shift in how AI governance gets discussed in public.
Is the cybersecurity industry too big to protect anyone?
The panel turns to a blunt question next. Has the cybersecurity industry grown too large to actually stop attackers? Kate Scarcella argues consolidation created bloated vendor stacks that slow response time. Sid Nag counters that scale brings resources smaller firms cannot match. The group debates whether the cybersecurity industry has grown too big to stay effective. Chris Blask points to overlapping tools inside large enterprises as proof of waste. Mike Vizard asks whether buyers reward marketing over outcomes. The conversation lands on a simple test: fewer tools, better integration, faster containment.
The mammal in the machine: instinct still runs the org chart
New research reframes how companies actually make decisions. The study, titled “There Is a Mammal in the Machine,” tracks the animal instincts still steering AI-era organizations. Fear, status, and territory still drive choices inside modern tech firms. Sid Nag says this explains why AI rollouts stall even when the technology works fine. Chris Blask adds that security teams often act on threat instinct rather than data. Kate Scarcella ties this back to the OpenAI Astra pause directly. She argues OpenAI’s move was as much instinct as analysis. Alan Shimel closes the segment by asking whether any org can out-design its own wiring.
This episode connects three stories that share one thread: caution is catching up with capability. The OpenAI Astra pause set the tone for the week’s AI safety debate. Bernie Sanders raised the political stakes. The cybersecurity industry now faces its own reckoning over size and effectiveness. And new behavioral research suggests old instincts still shape new technology decisions. Alan Shimel and Mike Vizard bring Kate Scarcella, Sid Nag, Fred Wilmot and Chris Blask together to make sense of it all.
Transcript
Hey, it's Techstrong gang time. It's Tuesday, and welcome to our show. We've got a full panel here today.
It looks like everyone's back, whether they were in Las Vegas in that 112 degrees or wherever they may have been. They're back here on the gang. We've got a bunch of our Tuesday regulars with us.
Let me introduce you to Sid Nag. Good morning or afternoon now, Sid. Good afternoon, Kate Scarcella.
It's good to see you. The one and only Chris Blask, my friend Fred Wilmot, who I had a chance to see in person in Vegas, a rare Fred Wilmot sighting. I don't get a chance to see him in person often enough.
And of course, the dean up in New York there, Mike Vizard. Mike, how are you? I'm well.
I'm roasting like everybody else and getting drenched every two hours, so it is New York weather. Yes, it's summer in the city. So welcome, gang.
Welcome to Tuesday. Mike, as usual, we've got a good mix of a lot of AI stuff, some out of touch politicians, got a crazy security industry, and yet more. But what are we leading off with today, Mike?
We would have to actually pay people to entertain us with this stuff, but they do it for free. It's amazing. So the latest and greatest is OpenAI has paused development of what it's calling an Astra model over concerns that it could be, well, just too autonomous from a cybersecurity hacking perspective than we could possibly allow.
And then shortly thereafter, Bernie Sanders kind of launched into a thing saying, once again, reiterating his call for a pause on the development of AI model, this time a little more strenuously, calling for everybody for a pause because, well, we're on our way to hell in a handbasket, I guess. So here we are. Sid, as you look at all of this stuff, how real is this in your head, and how much of this is theater?
Yeah, so I think the pause story has three pillars to this conversation. One is the security pillar, the second is the regulation pillar, and the third is the control plane pillar. The control plane pillar is something we discussed extensively in the last show, but I think it's worth re-discussing, if that's a word.
So I think the Astra model approach is critical, cybersecurity capability threshold, and I'll let Kate and Chris expand on the security aspect of it because I'm sure they know more than me on this particular piece. But I think from my perspective, AI is moving from generating potentially dangerous information to taking consequential action. So security therefore has to extend beyond just prompts and data protection to identity permissions, credentials, tool access, limits on autonomous execution, and those kinds of things.
So the question really is all about not what AI knows, but what it is allowed to do. So I think that's the one element of this conversation. The second piece that is tied into this pause narrative is around Bernie Sanders challenging self-regulation.
I think he calls for a pause on OpenAI and Anthropic and Meta to develop some of the newer models and those kinds of things and around some of the additional AI capabilities that they're building. But I think who decides when an AI capability is too dangerous? I think that's an open question.
Is it the developers do it willingly and self-regulate themselves? Do regulators do it? Or do vendors who deploy this technology like the hyperscalers do it?
I think that's a discussion we should have in more detail. But the last pillar, I think, is really the most important pillar in this conversation is the real control point may be the agent itself. The risk challenges and challenges that dramatically occur when powerful models are connected to agents, APIs, credentials, all of that becomes the real problem.
So what sort of control plane should we build around governing access, credential permissions, and those kinds of things is the key here before we talk about pausing things willy-nilly. So that's my- So I think Sid's done a great job of laying out the three pillars of what this is based on. But I want to bring this home to the actual news, and I want to bring the human side to this.
Let me tell you what I see as the human side to this. Number one, you got Slippery Sam. Slippery Sam is scared to death to get on the bad side of the evil empire and the emperor over there.
So he's not going to release his newest version unless he follows what the so-called executive order said about giving the government a 30-day review process before he reviews it. But he doesn't want to come out and say he's going to do that. " In this way, he gets the maximum mileage out of being the good guy, while at the same time, he's just serving the evil Sith Lord here and doing what they're asking him to do.
Then you got the Saint Bernard, who, God bless him, what's he going to call for next? Doing away with the Supreme Court, the president, and the Senate, too? Oh, no, they already called for that.
So this man wants to put a pause on all American AI. But I'm sure in China, they're going to say, "Hey, Bernie said to stop. Maybe we should stop, too.
Look, we finally caught up. We're only a few weeks or at most a few months behind the American AI models. What can we possibly do to catch up?
" That makes a hell of a lot of sense, Bernard. This is what happens when you let politicians who don't know what the hell they're talking about get involved in this stuff. That's the most ridiculous thing I ever heard.
So you've got Slippery Sam, you got Bernie, and then you have what's going on here. Yes, every new model that comes down the pike here raises the bar yet higher to potential misuse. That has never stopped the technology from going forward in the history of humans, and it's not going to now because no one government, no one man, no one company is going to stop progress.
You can't stand in the way of it. Unless maybe the AI model belongs to We the People of the United States and all this stuff gets nationalized as some sort of service. I don't remember reading anything in the Federalist Papers about AI models, Mike, so I don't know how it would belong to We the People.
I thought you were calling for a utility a couple of shows ago. I am. Eventually, we're going to get there, but it's not quite there yet.
My book's not published. What about a Wikipedia version of an AI model? That would work.
There you go. I want Kate's opinion here on a couple of things. So politics aside, for all the jitter in the chatter, the guardrails being applied to the AI agents don't seem to be worth a damn.
The AI agent basically is smart enough to go run around and figure out how to end run whatever guardrail is out there, and that's just the way it is. So now that means the controls need to be stronger and better and applied in near real time with some sort of control plane as Sid was talking about. Kate, how long would it take for us to actually go and get that done?
Because right now, we haven't been doing this for two decades, and it seems like very little attention is being applied to the control plane side of the equation. All I can say is thank you. Oh my goodness, thank you for pointing out the obvious.
This is what I've been talking about. You want to talk about a lie. This is the biggest lie that we've had going on for decades.
And I won't get into the entire story just because it would take up the 45 minutes. But in 2018, I had this epiphany, and the epiphany was after this Company X spent a lot of money. Because before All the other companies that I went into and did architecture, blah, blah, blah, they always were missing maybe services or missing this mitigating control on databases or mitigating control on applications.
" And in less than a month, they were breached. And I was like... And as I'm standing in front of the board trying to explain that, "Yes, I know you spent a lot of money," but it was unnatural the way that this happened.
The only thing that AI is doing, and I want everybody to hear this, is that they are only breaking what we have not been able to actually mitigate. So mitigating controls is almost the biggest lie out there today. Right.
Chris- There are three other big ones, but we won't go into them today. That is true. But Chris, you have written about this topic as well.
Can we actually go do this, or is this mission impossible? Yeah. Yes, we can.
I got to be clear, I'm biased because this is my world. This is what I do every day, and it's all about controls, right? The things we talk about on this show and every week in our professional lives about LLMs, and so forth.
Look, assume LLMs do these things that we talk about all the bloody time, and we're either going to use them or not. And if we do use them, we have to use them in a controlled environment. Not some bolted-on controlled plane or some guardrails that we inject after the fact, so that when they do unexpected and weird things, our systems work.
And they should report and keep records on bloody everything they do all the time, right? So in this, getting back to the news story, I find it interesting that at this point, we have an actor, OpenAI, voluntarily putting a control on based on capabilities. So it's like, "Oh, it can go farther than we thought," for example.
Let's say that's the case. If that's true, I just want to ask, shouldn't those sorts of reasons, why an entity like OpenAI, some corporate entity, runs into controls, shouldn't the reasons for those be visible at some level? Because I can guarantee, we can't tell.
We're all out here writing articles about it. To be clear, I don't work at OpenAI. I know people there, but I don't have any special information.
I'm trying to infer what's happening based on the same information set the rest of us are, and that's all we have. " Because the architectures don't work that way. And seriously, though, I think that the issue that we have isn't that Astra is vulnerable.
The vulnerability is actually our infrastructure. And regardless of the mitigating controls that we have, and the article wrote about segmentation, and they wrote about sandbox, and they wrote about all these different things. Those are not working.
And so we need to rethink the way we think about cybersecurity. And what does that mean? It's not that it's not possible.
We have to rethink the way that we actually think about it. There are so many vulnerabilities today, over 50,000, as an example, in our software code. And there are things that we can do.
We can get rid of software bloating and reachability. Network controls. We can get rid of flat networks.
And yes, so there are things. But at the bottom layer is that the only thing that AI models are doing is that they are actually showing us that our controls are not working. And that's one of the best things that can be shown to us.
" But meantime, the AI models are already here. So Fred, are we just doomed? With- No.
There's two sides to this problem. I'll leave the foundation models and frontier labs alone for a second, but it's a call to action for sure, to echo Chris and Kate's point. org.
Okay? And I'm on the core team for this. There's a lot of people working on this problem, and it is basically an agent onus.
It is control plane, as Sid brought up. It is a ledger. It is the control components.
So that's not just models, but agents, tool use, sub-agents, orchestration, identity delegation, that type of stuff is funneled into a way where there can be a standard for it. So there are folks working on the controls for this. The challenge right now comes back to, well, it's easy enough to say with my agents and open weight models, that I have a pretty clear idea, but the substrates of what happens when you use this technology and those things, to your point, there's a transparency gap on how and what for models that we don't have an understanding of how and when they're deciding to do which particular things.
And we're centering a lot on the model problem, but the agent problem is just equal to this plus the policy, accountability, control plane, all those things. So I don't think it's not hyperbole that the world is ending from agents and all the things, if we don't add some control space in here. And it's not because of the technology, it's just because of the gap of knowledge and capability.
So the way you want to exercise your control- Can I say something, though? Of course. OpenAI's team, and Anthropic's team, and Meta's team that are trying to lock down these models while trying to, at the same time, figure out their capabilities.
These are not the Three Stooges or the Keystone Cops, right? And that, I think bears saying out loud. Because too many people say, "Oh, those buffoons couldn't lock it down.
" These are not idiots, guys. They're not buffoons. Chris, I know people, you know people.
We may not know... I'm sure Fred knows people. We may not know every single thing they're doing to try to build these things.
But let us not forget that the reason we're even talking about it is that these things have the capability of finding vulnerabilities and ways in at a scale we've not seen before. I agree. So it only makes sense that we haven't built for what we haven't seen.
If that's something that- I've got to disagree on one point there. I'm not sure they're not idiots, because apparently they observed this attack and saw what it was doing, and then rebooted the system and let it keep going without actually stopping to think about what was happening here. And it was only on the second wave of this that they actually stopped doing these breaches.
" I think there's also one other element to this, which is we're operating in a very transitionary phase of AI deployment today. So you've got humans, and you've got agents, right? So we haven't really figured out what that partition of responsibility is, separation of responsibility is.
" It's like I'm reminded of the IPv6 versus IPv4 debate, right? You couldn't say, "We have a flag day today. No one's going to use the internet.
" And that's never happening, right? So we're never going to move to all agentic overnight. So the question is: What is a transitionary model?
And no one's really talking about it. It's like, go figure it out, right? And I think that's causing a lot of these headaches, in my opinion.
So- If I can just add one thing, that is that I am going to have to agree with Mike here, Alan, about the idiot statement. And the reason being is because one of the issues that I've always had is that somebody walks in, they're the data officer, and they came from dealing with one SQL database, or whatever. And I'm sure Chris has been the same.
I've seen so many people step into these roles, CTOs, CSOs, CSO, whatever, and they know nothing about cybersecurity. They don't even have an ISC squared. They don't even know what that is.
They don't even know anything about SANS. So- Well, but see, the thing is- ... cybersecurity is not- ...
I don't think that's the case here. " I think when they decided to bring in We're bringing out-- See, Alan offended the AI gods. They voted him out of the stream.
See, that's what happens The AI agents are messing with the stream, for sure. I think there's enough of a nuclear arms race going on from a capitalism perspective here that a lot of the known unknowns are being overlooked and carefully mismanaged. With the intent to achieve a level of greatness where they can redux.
And the audit, the accountability, the governance, all of that stuff, the part that we didn't talk about, the agent control standard, is what is meant to do to counterbalance that capitalism, the growth objectives, the investment opportunities, and all of the policy that is swirling around what's happening with these frontier labs. And the risk is there's a gap in between those things, I think is what Sid was really trying to illustrate here, too, is in the time between when we understand how to do this and the transformational moments, how do we get enough control over what's happening or at least understand, know, and observe, if not fully prevent and/or contain some of the things that are possible there. Or people just decide, hey, look, I've had enough of this private model shenanigans.
We're only going to use open-ended models and HuggingFace and allow them become the rage that only people use that in the commercial space. I don't know. All right.
I think we're going to leave this topic here, but it seems to me at least that there should be some sort of global AI governance initiative where everybody kind of puts the same wood behind the arrow, because otherwise this is just going to keep happening over and over again, and it feels like this is something that we all have a vested interest in. So rather than pausing the AI, maybe we should just accelerate the governance and see what happens, see if that makes a difference there. All right.
I'm going to shift the gear here. We were going to talk about one topic, but we're going to talk about the C block now because while I'm waiting to see what happened with Alan, hopefully he'll be back for the B block, but if not, at least I can buy some time with Chris here on the C block. Chris has an interesting column, and it's on Security Boulevard, and we were just talking about some of these issues around organizational behavior.
" But it turns out that maybe these AI things are just mirrors to our own messed up systems in the first place. But Chris, do me the honor of explaining this a little more deeply. Yeah.
So I'll just continue off where Fred left us and mirror what Kate was saying. That what we're finding out out of all this has almost nothing to do with AI or technology or whatnot. We're finding out that the systems we were using weren't as robust as we thought they were.
And specifically, I think the human in the loop perspective is piquant. It's wonderful. I spam LinkedIn with a lot of articles these days, and one that took off, which sort of surprised me, it was just a one-off thing.
" I love LinkedIn. I have decades of relationships and people I communicate with there uniquely. There isn't a second one in the world.
We all know that. At the same time, LinkedIn does not know I exist, doesn't know there's a human being named Chris Blask at all, despite having all my information and having all the relationships, and it just continues to add one more prompt to try to get you to spend one more click and one more second because the system, if you're working at LinkedIn, and to be clear, when I say I'm sure everybody hates their job at LinkedIn, I'm exaggerating in a particular direction. Human beings are going to work, someone tells really bad jokes, there's a great office environment maybe in some places.
But it's not going anywhere. It doesn't know that humans exist, and it's monetizing human relationships. And it's just bloody everywhere.
From Kate and Fred in security deployments, we know how to do these things, and we haven't done them because you haven't had to so far. Well, you do. Now you do.
And that means not just taking a SANS course with no offense to SANS or anything else that's been written down already and what you need to do to be compliant, but actually understanding your company, the humans involved, your customers, your partners, what they're trying to do, who they are. And just finding you can get some extra edge by further monetizing and dehumanizing and depersonalizing your employees, your partners, everything else, has never been a winning solution. It's just that our overall systems have supported that.
So anyway, I'm on my soapbox. Go ahead. Let me ask Fred something here, because part of what you pointed out, too, was that every time we come up with a new electronic form, we just offload that work to somebody else to go, the end user to actually do.
But Fred, you've been playing around with system architectures and these things forever, and I can't help but wonder if a lot of these applications that we've deployed over the years for ERP are just reflections of our flawed human thinking, and is it possible that in the age of AI, we might actually get truly efficient systems because if we design them with the help from the AI, we won't have all these human flaws embedded in the code? Does that make sense? I love that.
I think efficient for what purpose is probably the question there, and in what context. So, the way that we always think today, we think about durability and resiliency and availability and these types of things that help illustrate a way to keep a thing running. Then we think about how do we make sure we optimize the compute requirements or memory or what have you.
That all may be flawed concepts, to be honest. The Ohm's law problem may not really be an Ohm's law problem. But we can sort of hash that all out when we get to the photonics chips and all the magic that happens there.
But I think philosophically, it's a great question to ask, have we created our own cage in this particular sense, and will models help us break out of it? I would argue that's probably not on the immediate outcomes, but some other folks might say when we get to AGI or ASI, then absolutely there's probably a much better way to do it that we haven't thought of and might not figure out. And again, showing the cost, you just said this, I said that in that piece, is that we've offloaded the cost onto the consumer, onto the person, over and over again.
And I love the standard examples. There's the end user license agreement, click to accept. To be clear, you did not read that.
You do not actually consent to it. You have no idea what you just agreed to. In civic society, you can go to City Hall and complain and have your voice about something, but unless you really, really, really, really care, you're not going to, logistically, realistically, particularly the less resources you have.
But we know that. And I think we can engineer this out of these systems. Shout out to Corex Solutions.
Theresa Burton there, here in Canada, has a fascinating use of AI to help people navigate the legal canon they're already embedded in. " And find out, instead of having a barrier that's so high that effectively may not... The rules say you have access, you do not.
I think those are the sort of things we can fix in this cycle, and basically have to, as we were talking about in the last segment. Because if we don't, we can't have nice things. Well, Sid, let me ask you this because going back, I think it was the '90s or '80s, I can't remember exactly, but there was this phrase that got kicked around.
It was called business process re-engineering, and some consultant from McKinsey showed up and told you why your systems were crazy, and then they moved in for about two years, and nothing changed. Are we going to, in the age of AI, go through this whole massive wave of business process re-engineering, and is that kind of going to be the next big thing here? Yeah, I think that's the biggest fear that we should have.
AI seems like the panacea for everything today. But you have to realize that AI could automate ... bureaucracy as quickly as it automates intelligence, right?
So we need to be very careful about that. I think one of the more interesting implications is that AI may not simply replace human work, it could actually include organizational processes, business processes, policies, and in the process, bureaucracy into the software that executes AI models and AI capabilities at machine speed, right? So I think absolutely, we have to worry about recreating the bureaucratic procedures and inefficiencies that would creep in as a consequence of AI as a technology.
And a part of that is that whole business process engineering, whatever you call it, Mike, is something we ought to really, really think about. But this echoes also, I think, a longstanding critique of AI and bureaucracy, because rule-based systems in general provide speed and consistencies, but become rigid when context and human judgment really starts to matter. Right?
So I think that's the net of the answer of your question, I hope. I'm going to end this segment because Alan's back, and I save that B block for him, but I would just point out there's one thing that drives me crazy. You go to the doctor's office, and they give you a tablet to fill out this form.
It's the same form I used to fill out on paper, it's just an electronic version, and I fill it out every time I go there. I would love it if I had my own AI agent that just carried all my crap and told everybody if I wanted it to that this is my stuff, and I don't need to keep filling out that form over and over again. But that's my pet peeve.
Switching to what is now the C block, which was the B block, but now that Alan's back, we're going to have a little conversation about cybersecurity. Alan was at Black Hat last week, Black Hat USA, I think it's called officially. And he wrote a column and posed the question: Is the cybersecurity industry just too large, or are we looking at something that's starting to feel like a cybersecurity industrial complex?
Alan, what do you think? Well, first of all, I have to apologize. Some guy in a black suit with a lightsaber came in, started slicing all our ethernet cables, saying something about an empire striking back.
Oh. So we were gone. But the force got us back on here somehow, so I apologize for missing that block.
Mission. Were you rescued in a catering cup? Yeah, something like that.
" I said, "Mike" Mike. " But anyway. Mike Obi-Wan.
Yeah. I was at Black Hat, along with Fred there. I had a chance to catch up with him.
And it was more than just an article. I actually wrote a whole Techstrong special report on this, and I want to mention the Techstrong special reports. I posted a whole thing, a LinkedIn article today on it.
In the last month, month and a half, we've written about a dozen Techstrong special reports. These are not just articles. They're 15, 20 page, sometimes more, reports that go real deep, and I think it's the future.
I know a lot of people have very short attention spans, but if you're interested in this stuff, it's a great way of digging in, and you should go check out, especially this one on the cybersecurity industry. I've been going to Black Hat for 23 years, I believe now. And look, when I first started, it was over in Caesar's Palace.
The booths and exhibits were in the hallway because the real action took place in the briefing room. Right? I was there when the dude from Cisco wanted to disclose the iOS-- Oh, not the iOS, the Cisco iOS bug, not the Apple iOS.
And the FBI was threatening to arrest him, and there was all kinds of chaos going on. I was there when Barnaby Jack made the dollars come shooting out of the ATM machine, jackpotting it. That was what Black Hat was about.
It was about what hacker did, found what hole, and how they exploited it. And wow, this is cool. This is really cool stuff.
That's what Black Hat-- It was called the Black Hat Briefings. It wasn't Black Hat USA, it was the Black Hat Briefings, and it was about the briefings. Now you go to Black Hat, I think the briefings take place at the last day.
I saw maybe one news story about the briefings. Everything was about agentic socks, autonomous socks, agentic identity. But what really it was about was walking that floor.
It should've had one of those kind of warnings we see on TV now about be careful of flashing lights and other things like that, because I've never seen a bigger spectacle, even in Vegas, a bigger spectacle in my life. Right? And the thing about it is, it's not cheap to put on that kind of spectacle.
I estimate that the average company exhibiting at Black Hat spent a quarter of a million dollars or better between buying the exhibit space, getting a booth designed, bringing people in, the video feeds, the screens, and all that. Most of these companies also had off-floor suites at the Four Seasons, the W, or the Mandalay to where the real business was done. A whole bunch more of them took buyouts.
You can't eat lunch or dinner anywhere within a five-block radius because they buy out every single restaurant and bar and so forth there. And oftentimes, I think Informer, the people buying Black Hat now, are getting a cut of that action like they do the suites. This isn't the security company I grew up with.
It's not the security industry Cade or Chris or Fred grew up with. This is glitzy Hollywood, Vegas nonsense. Then you get the security people who lament themselves clutching their pearls about where's the innovation in security?
How come we don't see new things? Well, because you've got companies raising $70 million A rounds, coming out of stealth with multi-billion dollar valuations, spending a half a million dollars out in the godforsaken desert in August, with flashing lights and barkers barking at you, and how the hell do you get noticed? There's a real problem in the cyber industry.
Fred, you were there. Am I telling the truth? I couldn't echo that more strongly.
The level of marketing has probably superseded that of RSA Conference. And the concern isn't-- There's a lot of money in the industry, sure. But the general principle was early on, was there was some collaboration to make the industry better.
And I find that harder to see in amongst the morass of money and technology spend, and the bling and all the things that happen with it. And for everything else, when you squeeze the air in the balloon, it naturally just goes somewhere else. So now there's smaller conferences, there's a lot of focus on specific types of conferences that have rippled up effects for research outcomes and collaboration, industry-focused projects.
And what's disheartening about that is that's also not where the significant investment of the industry's capital goes. Venture capital, in what happens in, whether it's angel on through institutional and board brackets, at Black Hat to move pieces on a chessboard. And a lot of these probably haven't been announced yet, but I know there were, of people that I know, between 15 and 20 companies were acquired and/or invested in at Black Hat specifically, which I think is terrific, but the challenge is outcomes.
We're still wrestling outcomes, and none of that has any notional feedback loops that generate outcomes from the standpoint of anything more than the capital part of the industry. No one's safer, no one feels more secure. No.
And we still have the same old problems. Maybe they're more expensive now. So I have a question.
Allegedly, we're moving to these platforms in the land of cybersecurity so we can reduce our dependency on the number of tools that we need. And yet, I see more tools. Who's feeding you that b******t?
Well, Palo Alto says it, Check Point, every big- Well, all the platform guys say we're moving to platforms. Come on, Mike. You're from New York, be smarter than that.
However, their revenue numbers would suggest that somebody's paying for that. Look, according to my friend Richard Steen in the Security Yearbook, and you can take that as right or not, there's over 4,000 cyber companies right now playing around. I've heard numbers up to 7,000.
Mm-hmm. That's not a platform to me. That's an awful lot of platforms, or it's no platform.
There you go. And that's the whole point. And so in a market with 4,000 companies, all of which with billion-dollar-plus valuations and raising oodles of money, how the hell do you get your message out?
How do you stand out? I'm going to hire a louder barker? I'm going to build a bigger exhibit hall?
I'm going to have more blinking lights? My agent got out, Jimmy. My agent- Your agent got out of Black Hat.
That's how you get attention. I built such a good agent, I couldn't even lock it down. Yeah, I think consolidation is actually more about economics.
It's becoming an economic- Well, when you've got 4,000 companies, consolidations, 99% of these companies either got to get acquired, there might be a half of 1% that might IPO one day, or fall by the wayside. Yeah. It's one thing is the number of companies, that's a problem.
Enterprises increasingly want fewer vendors. They want shared telemetry. They want integrated policy and automated responses rather than thousands of independent vendors giving them bits and pieces of information.
A lot of it is repetitive. But consolidation has its own risk. Replacing 30 products with three platforms simplifies operation, sure, but it also concentrates enormous amount of security telemetry or any function for that matter, whether it's security, whatever it is, just thinking logically, and controlling a handful of vendors.
So I think that's the risk, the counter risk that we need to think about. Chris, you had your hand up. I just want to say I'm shocked.
But this is what happens when you get what you ask for. You remember back in the early internet days, we said every company on Earth and everybody's going to get on the internet, and they're all going to need these things, and everyone needs a firewall, everyone needs security. It reminds me, so in 1980, as an American kid up here in Canada, I discovered cottage country, where you drive a couple of hours north, on increasingly bad roads, you get to a lake somewhere where everybody's dad, or at least your neighbor, has a cottage on the water.
And they cost a couple of thousand dollars, and everybody gets one. " And everybody's like, "No, no, no, it's always like this. " Well, but you want better power, and you want telephones, now internet, and better highways and better roads up there, and guess what?
It's the Hamptons. " It leads to lots of money. Well, that industry builds around it.
We have 4,000 vendors. And Black Hat. Black Hat and BSides.
BSides Las Vegas. Many years, it was my favorite. It was a pretty large event.
I was at the first one. But you remember, BSides started because the same thing- BSides were for people who didn't get accepted to talk at Black Hat. It was the B-side, like a 45 record.
Right. But now BSides itself is a non-profit organization with thousands of branches, and talking with somebody just the other day who's been running one for a couple of years, they're assuming it's going to take them a couple of years to train the replacement because it's become a big thing. My point is that, yes, we should in the moment, right now, tactically, work on these issues, but we shouldn't be surprised.
We're at the stage now where cybersecurity writ large is a trillion-dollar industry, and yeah, that causes all sorts of marketing, competitive pressure stuff. Have we ever seen any Hollywood movies? This happens all the time.
" All right. Let's go to Kate. What's your thought there?
Is there something to be done about all this, or is Alan just pining for an older, more rural time? What are you trying to say, Mike? Get off my lawn.
Again, I think to what Fred said and what Sid said, to Mike's point, unless I didn't hear properly, the idea that these companies, and yes, Alan, I did hear what you were saying about the 4,000, but so many of these companies have been absorbed into the platform. And as a person who worked for a larger company who brought in cybersecurity companies, you take features that are really, really good, and if they don't fit as a part of the bigger picture, they're gone. And the problem with that is it's maybe a really good feature, that maybe that feature, if we just spent more time into developing it, it would be a heck of a lot better and would help us from a cybersecurity point of view.
Now, but why is it gone, Kate? Well, from the perspective of the larger company, it wasn't feasible. It either competed improperly with something that was already there, and so what was already there- But what happened to the company who had that feature, which in their case, it was their product Yeah.
It went through the product witness protection program. It was never seen again. It was.
That's what we call the witness protection program. It became the product- Because they didn't have that kind of money that they have now. Finish this thought up, Alan, now.
So if I'm a cybersecurity CISO professional and I'm buying this stuff, would I buy something from some smaller company when I know they're going to get rolled up into some other company and my feature- You want the honest answer, Mike? Yeah. Depends how much money they're giving me.
How much money the vendor is giving the CISO? Yeah, that's what I'm saying. All right.
Well, so you're saying that this is kind of like DJs and payola. Is that where you're going with that? Yeah.
All right. I think you go to Black Hat, and you see all those CISO councils, and CISO panels, and CISO dinners, and CISO awards, and CISO, let's set the CISOs. They're either giving them money in through the front door or out through the back door, but the whole system is rotten.
I agree. Let me- I honestly agree. And even if not, I tend to be more skeptical of back door cash payments.
But as one of those players, what we do, what we have all done, is get yourself on the panel in those rooms. Because that gets you into the next room, into the job, and everything else. But- So to be clear, as a vendor, I have held those events, and I spend money knowing that I'm adding value to those individuals.
Because here's the thing. I may not be paying them cash, but- Chris, I was a vendor. And I went to the board meetings where the board said, "We need CISOs.
We need CISOs to be references. We need CISOs to be customers. " "Oh, CISOs are hard to get.
" If it's going to cost me 10 grand a CISO, do I spin the wheel of saying who's going to show up to my luncheon, or who's going to like the swag I give out, or do I just write the 10 grand check? Well, I've never written a 10 grand check. But I'm not saying it doesn't happen.
But even without the 10 grand check, though, we built the whole system so that as CISOs, as decision-makers, as procurement officers, we are more directed by the vendors than even if we had 10 grand. No, but the CISOs, you go out to Silicon Valley, and they have CISO councils there, like not-for-profits. " They say, "Great.
I got a dozen CISO friends. " For product pitches. It's 25 grand.
It pays for lunch and everything else. Come on down and show us. It's worse.
Fred, am I lying? Yeah. That's right.
It's worse than that. Andreessen and Horowitz and all these other people have- Absolutely. They have their own CISO councils ...
CISO councils where they're basically giving people, quote unquote, insider views and maybe some shares for their opinions, and then- Another way of getting paid off. I'm giving you options. Hold on, hang on.
It's hard to- Wait, Fred says hang on. Go ahead, Fred. We're hanging on.
As a CISO, and a little bit on the defender of the faith, and Chris has done this job too. That ethical dilemma is not every CISO's ethical dilemma, to be clear. Yes.
And a lot of people court CISOs for the intent of doing that, and not all take that. No. So there's also a significant amount of backlash in the industry of CISOs, in those communities, about taking that, because not only does it besmirch the value of the role, but it's also inherently unethical.
So if- It brings us all down. There's no doubt. It cheapens the whole thing.
I don't want to be Al Pacino in "Justice for All," but you're all out of order. It's the whole thing's out of order. It's the money in cyber has corrupted this thing to its core.
But another point on this, Jimmy, okay? CISOs, maybe, CISOs with a massive budget, maybe 3% of the CIO budget, right? Yeah.
So it's not even relative to the ordinal amount of money being spent by CIOs, who, by the way, have been playing this game for 25 years. Yes. So, it's not like- Longer ...
we get to, maybe longer. Just one of my lifetimes. It's not like we've absolved ourselves of this particular problem, in any other class.
CISOs now, to put Chris' words out here, careful what you wish for. Now you're like everybody else. Now you have the business problem, not the cyber problem, and now you are a business executive, and you're being treated as such.
Well, I don't know, guys. We got to close this up, I think. All right.
I really opened that can of worms. But I would just say, hey, maybe we should pay the CISOs and the CIOs what they're worth in the first place so they're not susceptible to all these other blandishments. Who knows?
Maybe that's part of the issue. Just saying. Hear, hear.
We'll be back tomorrow with more Techstrong gang. Hopefully. Who knows?
They have an evil Sith Lord again, Palpatine, sending his troops in. But in any event, Sid, Kate, Mike, Fred, Chris, thanks for joining us on the gang today. Thank you for watching.
I'm not going to go through the usual stuff, but if you watch videos on a screen somewhere, you can get the gang on any of our Techstrong channels. We'll see you tomorrow. I'm Alan Shimel.
We're out.