The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Afternoon Cyber Tea with Ann Johnson
Afternoon Cyber Tea with Ann Johnson artwork

Building Resilience in a World of Constant Threats

Afternoon Cyber Tea with Ann Johnson · 2026-04-28 · 25 min

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality6 / 20
Guest Caliber13 / 20
Specificity & Evidence8 / 20
Conversational Craft8 / 20

Megan Stiefel, Chief Strategy Officer at the Institute for Security and Technology, discusses how organizational leaders fundamentally misunderstand their governance role in cybersecurity risk. The episode centers on four critical misalignments: treating cybersecurity as purely an IT issue rather than a board-level governance responsibility; assuming organizations are too small or uninteresting to target; false confidence that "everything is covered"; and the NIMBY mentality where board members defer to designated cyber experts rather than engaging collectively. Stiefel advocates reframing cybersecurity as a resilience challenge requiring cross-functional ownership - involving HR on workforce burnout and insider threat recruitment, procurement on vendor security requirements, and executive teams on incident response planning and recovery capabilities. She draws on her leadership of the Ransomware Task Force, emphasizing that shared responsibility across government and industry succeeds through trust, transparent governance, and tabletop exercises. For executives and board members, this episode clarifies what resilience actually means operationally: testing backups and incident response plans regularly, understanding recovery timelines, and building defensive capability collectively rather than treating security as a compliance checkbox.

Key takeaways

  • →Boards must recognize cybersecurity as a governance issue requiring direct oversight, not just delegate it to IT or CISOs, and members should ask informed questions even without technical expertise.
  • →Cyber defenders experience significant burnout from constantly viewing harmful content and working around-the-clock; boards should treat this as a human resources issue requiring recognition and relief.
  • →Organizations should conduct regular tabletop exercises and test backup recovery plans rather than just having them in place, and should preplan decision-making around ransomware payment scenarios.
  • →Third-party vendor security requirements and supply chain risk management are boardroom-level concerns that can reduce attack surface across the entire ecosystem.
  • →Resilience, not prevention, should be the success metric - organizations must assume breach and plan for rapid recovery and business continuity rather than trying to prevent all incidents.

In this episode

  1. 1Cybersecurity Governance: Leadership's Misunderstanding of Board Responsibility
  2. 2Under-resourced Areas: Near Misses, Workforce Support, and Insider Threats
  3. 3Residential Proxy Networks and Executive Home Network Security
  4. 4The Ransomware Task Force: Building Resilience Through Shared Responsibility
  5. 5Reframing Success: From Prevention to Resilience in a Persistent Threat Environment
  6. 6Board Oversight: Key Questions on Incident Response and Supply Chain Risk
  7. 7Optimism in Cybersecurity: Public-Private Collaboration and Active Defense Progress

Mentioned

Institute for Security and TechnologyCyberwire NetworkN2KMicrosoftComcastEuropolMegan StiefelDan JohnsonPhil ReinerIgorNewber DavisBrett Leatherman

Guests

Megan Stiefel

Topics in this episode

Incident response planningSupply chain risk managementRansomware Task ForceInstitute for Security and Technology (IST)Board-level cybersecurity governanceResidential proxy networksNorth Korean IT workers and insider threatsIncident response planning and tabletop exercisesAI in cybersecurityPublic-private collaborationOperational technology and active defenseInstitute for Security and TechnologyNorth Korean IT workersCISO governance and boardroom accountabilityTabletop exercisesThird-party vendor risk managementAI governance and risk management

Questions this episode answers

What are the four main ways board members misunderstand their role in cybersecurity governance?

Boards often treat cybersecurity as an IT issue rather than governance responsibility; assume their organization is too small to be targeted; believe they have everything covered; and defer decisions to designated cyber experts rather than engaging collectively in oversight and asking informed questions.

How should boards approach questions about ransomware incident response planning?

Instead of asking if incident response and backup plans exist, boards should ask when plans were last exercised, whether backups have been tested, if tabletop exercises involving ransomware scenarios have been conducted, and whether the organization has pre-decided its position on ransom payment.

What specific threat does Megan Stiefel highlight regarding executive leadership and home networks?

CEOs and executives are being shipped televisions that become part of residential proxy networks abused by malicious actors, putting the organization at risk even when the compromise occurs outside the office environment.

What role did the Ransomware Task Force play, and why was it successful?

Led by six co-chairs including Stiefel, the task force brought together 60+ organizations across government and industry to develop shared solutions for ransomware, succeeding through trust-based collaboration where participants believed the organizers had no predefined agenda and would act responsibly with shared information.

How does Stiefel define success in cybersecurity given persistent, adaptive threats?

Success should be measured on resilience and recovery capability rather than prevention alone - accepting that breaches may occur but focusing on how quickly the organization can recover, maintain operations during recovery, and build a security culture where teams feel empowered rather than fearful.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode surfaces a few genuinely non-obvious points - CEOs being shipped TVs that enroll into residential proxy networks, North Korean IT workers as active insider threats, and the idea of boards asking about near-misses rather than just incidents. However, these are surrounded by extended sections of platitude ('security is not one and done,' 'culture of security,' 'resilience') that dilute the useful content significantly.

CEOs of organizations are being shipped televisions and putting them in their home networks. And guess what happens when they do? Not good things. The set top box or the television becomes part of a residential proxy network
the idea that we have insiders who are in a range of companies around the United States and our key partners is really, really troublesome

Originality

6 / 20

The guest explicitly flags her own reliance on clichés multiple times, and the bulk of the content - resilience framing, tabletop exercises, culture of security, fear/uncertainty/doubt - is thoroughly recycled from mainstream cybersecurity discourse. The residential proxy TV angle is the one genuinely fresh concrete observation.

Speaking of cliches, I feel like it's cliche a bit to say that security is not a one and done process
I'm going to say the bingo card AI, we're back into the fear, uncertainty and doubt phase

Guest Caliber

13 / 20

Megan Stiefel is a legitimate policy practitioner who co-chaired the IST Ransomware Task Force for four and a half years coordinating 60+ organizations across government and industry - real, verifiable work at meaningful scale. She is a policy/think-tank figure rather than a commercial operator, which limits her grounding in revenue-level decisions, but she is not a career podcast guest.

I was one of six co chairs of this effort and so have had the opportunity to lead the uh, work of the task force for four and a half years now
this coalition of over 60 plus organizations that we were able to put together

Specificity & Evidence

8 / 20

The episode name-drops real people (Noopur Davis at Comcast, Phil Reiner, Brett Leatherman) and cites a concrete operational stat (doubled joint sequenced operations) and a specific threat vector (residential proxy TV shipments). However, there are no dollar figures, breach metrics, policy outcome data, or detailed case studies to substantiate the broader governance claims.

Brett Leatherman say last week or last earlier this year at RSA that they did double the number of joint sequenced operations
CEOs of organizations are being shipped televisions and putting them in their home networks

Conversational Craft

8 / 20

The host is knowledgeable and occasionally adds real texture from personal experience (segmenting her husband onto a separate home network), but the interview is predominantly validating rather than probing - claims go unchallenged, follow-ups tend to affirm rather than dig, and the host frequently pivots to personal anecdotes that eat into question time.

how does that lack of alignment maybe show up on things that don't come to the boardroom? But possibly should come to the boardroom
I wanted to say one other thing, Megan, that I think is really important. Thank you to you for mentioning that you were just part of a team. I frequently hear leaders just taking credit

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Megan Stiefelguest65%
  • Dan Johnsonhost33%
  • Narrator2%

Most-used words

cybersecurity18trust16issue15responsibility13board13network9security9cyber9boardroom9idea8organization8resilience8industry7conversation7feel7opportunity7

Episode notes

Megan Stifel, Chief Strategy Officer at the Institute for Security and Technology, joins Ann on this week’s episode of Afternoon Cyber Tea to discuss why cybersecurity must be treated as a shared governance responsibility, not just an IT issue. They explore how boardroom misalignment creates exposure across areas like workforce burnout, insider threats, and third-party risk, and why resilience, trust, and cross-industry collaboration, not prevention alone, are essential to managing today’s evolving cyber threats. Megan also shares insights from leading the Ransomware Task Force, highlighting the critical role of coordination and shared responsibility across sectors. Resources: View Megan Stifel on LinkedIn View Ann Johnson on LinkedIn Related Microsoft Podcasts: Microsoft Threat Intelligence Podcast The BlueHat Podcast Uncovering Hidden Risks Discover and follow other Microsoft podcasts at microsoft.com/podcasts Afternoon Cyber Tea with Ann Johnson is

Full transcript

25 min

Transcribed and scored by The B2B Podcast Index.

Megan Stiefel: You're listening to the Cyberwire Network, powered by N2K.

Dan Johnson: Welcome to Afternoon cybertea, where we explore the intersection of innovation and cybersecurity. I'm your host, Dan Johnson. From the front lines of digital defense to groundbreaking advancements shaping our digital future, we will bring you the latest insights, insights, expert interviews, and captivating stories. To stay one step ahead. Today on Afternoon cybertea, I am joined by Megan Stiefel, Chief Strategy Officer at the Institute for Security and Technology. Megan's work focuses on how leaders govern cybersecurity risk at scale, especially when responsibility is shared across government, industry and institutions. Megan, welcome to Afternoon cybertea. I'm really thrilled to have you on.

Megan Stiefel: Anne, thanks so much. It's great to join you. I'm a longtime admirer of the show.

Dan Johnson: Oh, awesome. Well, let's have a great conversation. Megan, Many organizations still treat cybersecurity as a technical or an operational issue, even though the consequences are really strategic. From your perspective, where do leaders most misunderstand their role in governing cyber risk?

Megan Stiefel: So I would say it's largely from a it's not my issue concern. Still, while I do feel like we have 10 years ago or 15 years ago, we were talking about, like, how do we can we ever break into the boardroom? And we've made it there, but still feel like members of the board may at times be looking around thinking, whose issue is this? Nimbyism is not the right term, but that was the one that came to my mind as I was thinking about this. So really thinking about the concern that we still think very much that cybersecurity is more of an IT issue. And so as a result, not everybody has their CISO directly in the boardroom reporting usually right to someone on the board. But when that relationship is not as prevalent, I think the idea around responsibility isn't front of mind. And so oftentimes also we think of it as a very technical issue. And so if one doesn't have expertise, does that equate to it not being someone's responsibility? And, uh, we all want someone on the board to be responsible for cybersecurity. So I think the other piece of this really is thinking about when one lacks expertise and we don't expect everyone to be a cybersecurity expert, there is the opportunity for the board to get curious and ask questions. And while it may be the case that the answers that come back are not ones that the board wants to hear, one of the ways I think about this is it's better for the board to be asking than for you to have to be answering to somebody else in response to a breach. I think there's also a concern a little bit around organizations who are thinking we're not attractive.

Dan Johnson: Right.

Megan Stiefel: We're not a good target, we're below the radar. And sadly, between obviously attacks on critical infrastructure that are now from time to time on the front page domestically, certainly they've been on the front page internationally, there's still a number of issues that arise for even small and medium sized enterprises. So we really need them to be thinking and taking steps that they can manage at their capacity level to improve and kind of take on cybersecurity as a governance issue. And then I think the fourth sort of challenge, maybe, if you will, is that the flip side of that is, oh, uh, we've got everything covered, don't worry, we're all buttoned up here. And so again, it's kind of the lack of recognition that it needs to be in the radar screen, on the screen front of mind all the time.

Dan Johnson: Yeah, I think that that's right about boards. And I actually kind of like the NIMBY correlation, though it's not exact, but it's close. Right. I'm on a few boards and I can tell you that sometimes what shows up is, oh, well, just ask Ann, she's our cyber person. And it's like, okay, well, we all need to be somewhat cyber people. Right. And I do think that there's an opportunity for us, who are the cyber people, to show leadership and to engage the rest of the board in language that the rest of the board can comprehend and understand versus just being the cyber expert in the room. And I think we all who are cyber professionals really have a responsibility to educate our peers wherever those peers are.

Megan Stiefel: Yes. I like to think of it as an opportunity, not a burden. You know, we have challenges that are opportunities versus challenges that are the things you don't want to do. I'm with you. I like to empower. Think of it as an empowering opportunity as opposed to an obligation.

Dan Johnson: Exactly. When you have that lack of alignment in the boardroom, how does that show up in real decisions about what gets delegated, what may get under resourced, or what things aren't actually brought to the boardroom? Not because anyone's trying to hide them. There's no nefarious intent here. It's just folks saying, oh, uh, you can't bring everything to the boardroom. So how does that lack of alignment maybe show up on things that don't come to the boardroom? But possibly should come to the boardroom.

Megan Stiefel: When we think about what gets under resourced or delegated, that maybe shouldn't. There are probably three sets of areas where we might look for there to be a greater alignment of the need to continue to have conversation around the responsibility around cybersecurity governance. One is kind of thinking about where there may be near misses that are opportunities to learn from success that may help us avoid the issue down the road. And thinking about how they were avoided, which may seem to your point a minute ago, not everything can make it to the boardroom, so why would we talk about what we didn't have? But I do think there's an opportunity for thinking about near misses or thinking about using, unfortunately what's happening potentially to peers in the sector to say, okay, if that were to happen to us, how well would we be positioned to withstand that type of an incident? And I think too, you know, while we are right five years past, through the COVID situation, I think the second thing I would raise is the idea around how is our workforce managing this issue? Not just thinking about how are our defenders protecting the networks, but also how much of cybersecurity and the responsibility that everyone in the organization has to support it, how much of that is on the workforce's radar and how can we, particularly when we think about the defenders, when's the last time we said thanks to them, giving them a bit of a break or a bit of a boost. Cybersecurity, as we'll talk about, I think is, you know, it's not something that ever stops. And so the drain that can be, particularly for network defenders is something that I think ought to be like other HR kind of human resources issues, something that the board is considering from time to time. The third thing that I think around kind of delegation or never reaches the boardroom is this issue around two things really. One is we're starting to look at an issue around the abuse of residential proxy networks. And I raise this here because one of the things that we've heard through our research is that CEOs of organizations are being shipped televisions and putting them in their home networks. And guess what happens when they do? Not good things. The set top box or the television becomes part of a residential proxy network and there are malicious actors abusing this. And so thinking about the role of kind of the 360 protection of our leadership team and protecting them in their home environments as well as in their professional environments. So those kind of external exposure points that can still put the organization at risk. Even if they're happening kind of outside the organization. And the fourth one really is around thinking about, on the human resources side, how are we recruiting? We might think that that's something that should be delegated to hr, but particularly as we look at the exposure that we've seen most recently around North Korean IT workers and really thinking about what our recruitment process is, because the idea that we have insiders who are in a range of companies around the United States and our key partners is really, really troublesome. And so I think that issue around how are we thinking about the insider threat issue is also one that needs to be a regular conversation.

Dan Johnson: I think those are really good examples. And, um, I want to get to ransomware. The efforts are on ransomware in a moment. But I wanted to call out a couple things you said, which is that psychological safety and recognition for our defenders, and not just the pressure of them working around the clock and trying to keep a company from being breached or responding to a breach, but also, as they frequently tell me, some of the things that are visible to them when they're actually looking at content from threat actors is stuff that is not safe, you don't want your employees to see. And I don't think a lot of folks recognize that. And I do think that that is something that at, uh, Microsoft, I know our ciso Igor, has been very focused on is burnout and something I do think the boards need to think about. The other comment I wanted to make was about resident proxy networks and just the work that the CISO at Comcast, Newber Davis has done publicly talking about it being really open and transparent, I think has raised the awareness, but we certainly do. To your point, I talked to my own husband because he wants to put everything on the home network. It was kind of a battle. And finally I gave in and just created his own network for him. Right. I just said, okay, look, I'm just going to segment you and send you away so that whatever you. Then that is the hopefully not bad network, but that's a network where stuff's going to go on that's Iot connected. And because you're insisting that the laundry machine needs to be connected, right, because I just got tired. I, uh, was exhausted. But that parallel I can take into the real world, which is we have to make solutions easier for people. You know, I knew how to set up a network that was fully segmented and secure. Anything I do, um, in the work environment or even my personal finances, right, to make sure they aren't impacted by something that could happen on that network, but your average human doesn't know how to do that. So we have to make it easier in some way.

Megan Stiefel: Yes, in some ways. Thinking about ways that we might make it easier, I just had a fifth thought, if I may, which is around the board thinking about its opportunity as a purchaser, as a demander, if you will, to require better security of its vendors and third parties. And so can we make some of these issues easier for our teammates among the team by removing their need to even pay attention to security, which of course they can't. Right. That's too extreme. But can we take some measures, make it a bit easier for them to do the things that we do really want them to focus on by leveraging the capability that we may have as purchasers of services and products to require greater security from those services and products so that fewer things are reaching our workforce?

Dan Johnson: Yeah. I was talking to another CISO over the weekend before RSA and he's trying to create an initiative that's cross industry about that supply chain risk and really building some focus on what we are all going to require of the hardware and or software vendors that provide materials. Right. You know this, it's a massive problem, but it's also a massive problem at scale. And it's kind of like you don't want to boil the ocean. So where do you start the focus. Right. And then grow from m there. It's a big one. So that gets me to one of the things I really appreciate about the work you do. Right. You don't just talk theory and you don't just talk problems. We'd love in the cybersecurity industry to surface problems without solutions. You, however, have led things like the ransomware task force that's brought leaders from across government and industry together around a really shared problem that single organization can possibly solve alone. Can you talk about that experience and how shared responsibility actually works when it's done?

Megan Stiefel: Well, the ransomware Task force is I think our, as an organization at ist, we are one of the things we are most proud of. And I think it's, you know, I want to make sure to emphasize that I was one of six co chairs of this effort and so have had the opportunity to lead the uh, work of the task force for four and a half years now. But it really was a kind of a team effort and I think the idea of teamwork is really one of the key enablers of, I think, the success of the task force. Obviously, when we build teams, teams live on trust. Trust is central to the operation of a well functioning and effective team. The idea around trust being recognizing the role of trust as a two way street and that it really requires a degree of experience for trust to grow and the relationship between trust and responsibility. And one of the things I think that we have come to be more I think is maybe not spoken about enough in the cybersecurity community, but is one of those unspoken rules is that on the responsibility piece, I trust you enough if I'm going to share a piece of information with you that you will take action on it. You understand the responsibility that you have if I've shared something potentially to protect it, but also to take action on it if you can, or to figure out kind of where can we route the information to the entity that can take action on it because of this long standing view of cybersecurity as this shared responsibility. The other piece I would say is that thinking back to kind of the team element and the trust building, we were fortunate when we developed the task force. Phil Reiner, who's the CEO of ist, called a few of us and some of the co chairs will joke that we sprinted a marathon. But we were able to do so because we had known each other for a number of years and we had a high degree of trust in each other. We had expertise in policy making and certainly from the the government side. And we were fortunate to be joined by members of industry. And I think that this coalition of over 60 plus organizations that we were able to put together, one of the reasons for its success was this idea that the participants recognized that they trusted us enough to know that we were not coming in with a predefined agenda. We didn't have an outcome that we wanted to make sure that we drove the recommendations to the participants trusted that we would be responsible in the way that we orchestrated the work of the task force. And we can talk about that if it's helpful. But the backbone of the success and the backbone I think of shared responsibility really is this idea of trust.

Dan Johnson: I think that's right and I do think that, and I'll use another little bit of a cliche, that trust starts at home. So that trust between the organization and their board has to be really, really persistent. It has to be a persistent level of trust. And we say here that trust is built in drips and lost in bucke. So it's just something I always bear in mind as we're thinking about how we create trust internally at Microsoft, but also with our customers and partners in the broader ecosystem. Given that. How do you think that executives. Uh, and by the way, I wanted to say one other thing, Megan, that I think is really important. Thank you to you for mentioning that you were just part of a team. I frequently hear leaders just taking credit. I don't think they do it even in a way that they'll just say thank you and move on. I love the fact that you talked about. It's part of it. You were just part of a team that made it work. So thank you for doing that. I think it's good modeling anyway, given the trust conversations, given the board conversations, how do you think executives should reframe success when they're dealing with threats that are persistent, threats that are adaptive, threats that are both economically and politically motivated?

Megan Stiefel: Um, speaking of cliches, I feel like it's cliche a bit to say that security is not a one and done process. It's not about compliance and checklists, that it's really about resilience. So we need to be not thinking that we can prevent everything. We have to recognize that if we take a punch, as my. One of my colleagues here says, how quickly will we be able to get back up? And so thinking about also the other cliche that we've talked about for years, right. Is that building a culture of security. But it's true, it sounds a bit trite, but it really is true that we need this culture of security. And not thinking back to kind of the earlier part of our conversation, as one of the things that's bothered me over the years is the fear, uncertainty and doubt. And while I feel like we had a period maybe a few years ago where that had a bit waned from the discourse, I feel like now with, I'm going to say the bingo card AI, we're back into the fear, uncertainty and doubt phase. But to really think about empowering our teams to recognize that we are resilient and we know the steps that we can take to make ourselves the most resilient. And really thinking through how to translate technical resilience into cultural resilience. So thinking about security, really, as it's not one and done, it's a life cycle issue. It's also kind of a heartbeat type of issue that should be constantly kind of in use. In many cases, it will be running in the background, but in some cases it really needs to be front and center for our teams. The other point I might offer is thinking about. As we think about kind of a heartbeat and we think about what makes us healthy, we have to do, we need to Eat our vegetables and get our exercise. And so thinking about tabletop exercises is a way to potentially help ourselves to be a bit adaptive. And thinking about when we run these tabletop exercises around our incident response plans, looking at the need to ensure that they are regularly reviewed and refreshed and that we are fit with them. Right. We feel like we have the muscle memory to be ready to go when unfortunately the dark day comes that there is an incident. Those are a couple of thoughts there.

Dan Johnson: Okay. And I like how you talk about resilience. I talk a lot about resilience because it's incredibly important. I talk about it, write about it, blah. I try to get that attention out there because to your point, cybersecurity is never one and done. You need to assume reach and then how are you going to recover? How quickly can you recover? How are you going to continue doing business while you recover? I think those are all important. Let's talk for one more minute about the board and then I want to talk a little bit about optimism. Based on the resilience topic and based on cybersecurity being a very persistent threat, what do you think boards should actually be asking differently of their leadership teams?

Megan Stiefel: You know, thinking about the maturity model of hopefully everybody has an incident response plan, so it's not do you have it? But when's the last time you exercised it? Hopefully everyone has backups, so it's not do we have them? But when's the last time we tested them? Have we run a tabletop involving a ransomware incident and have we thought through whether or not we would pay? What type of due diligence will we take if we're forced into a position where we can't recover from backups and we are concerned about the leak of our sensitive information or would we be willing to pay? And um, so I think thinking about the as applied challenges that will come to boards when an incident happens, I think also thinking about the strategy around you mentioned a couple of minutes ago, supply chain and thinking about our third party vendors and really leveraging where, where it's possible, this ability to demand more from third parties, obviously within reason, but looking at all the points that we can around our ecosystem to build resilience collectively so that it's not just over to kind of it. It's not just we need to think about ensuring that human resources is involved in this question around our kind of cybersecurity culture. And the other piece I would say is thinking about the nuts and bolts around how long will it take us to recover And I think the point you made a couple minutes ago about what can we keep operating while we're working to recover.

Dan Johnson: Exactly, because that's in uh, a lot of the larger breaches. That's what we've seen as being the biggest issue for companies. Well, let's talk a minute about optimism. Look, I always try to end my podcast with a nod toward optimism and I call myself a cyber optimist because I do know for every attack that is a big event and we see in the news there are literally thousands that are cyber defenders of the industry have blocked, they've stopped, they've detected early enough. What are you most optimistic about? Now that we are in a new world. Right. We are starting down this AI as both a security assist, but also AI being used by threat actors again, I'm still very optimistic and I'd love to know what you're optimistic about.

Megan Stiefel: I also am optimistic. I'm optimistic that we are being more upfront about the need to have good governance in place as we are adding these new capabilities to our suite of technology to help ourselves be more successful and productive in all the things. I think whereas previously we didn't have as much of a conversation, more open conversation around the risks of kind of the cybersecurity risk. I feel like while some may be concerned that we've over indexed on kind of the transparency around the risk that we are currently in, I think we can turn that around and say it's good that we're talking about it because we can better manage it when we talk about it. There are also kind of smaller sort of if that's kind of the high level set of optimism, maybe I think more specific examples of that would be one of my concerns since the time I left government is that we, and even to an extent when I was in government, but the idea around operational collaboration and active defense. So looking at the ability for industry and government to come together to mitigate threat actor abuse of information and communications technologies, while I will say I don't think it's gone farther fast enough, I think we're making really good progress and that gives me some optimism. I think I heard Brett Leatherman say last week or last earlier this year at RSA that they did double the number of joint sequenced operations. And kind of on that, thinking about that public private collaboration, looking at some recent progress that we've seen with our partners, Europol leading, I think actually that was a Europol Microsoft event that happened earlier this year. It was a takedown, which is great. And we're seeing more organizations in the private sector standing up units to empower themselves and their partners in having a more proactive role in. Again, kind of looking at mitigating abuse. The other piece, and you mentioned Nooper. I think she's been really, uh, leading the charge in being open about what they're seeing on the residential proxy space. And so that also gives me, while it is, you know, it's a very concerning capability that we're seeing be abused, I think the openness that she's approached it with is also a sign of hope. And the last thing I'll say is, and Microsoft was a partner with us this year and last year in the Cyber Policy Awards, which is an award ceremony that we support the organization. And looking at the number of relationships that were in that room that have grown over the years and the collective goodwill that we've established and kind of this ability to. By we, I mean the cybersecurity ecosystem, not we ist thinking about the goodwill that we see in that event and just the number of submissions that we receive for all the great work that's happening in the community that doesn't receive the attention that it deserves. Sometimes we don't want the attention. Right. But kind of coming back to some of the earlier points in our conversation and really thinking, taking time to acknowledge the hard work of members of the ecosystem and people's interest in doing so. And so that I think, too, is a cause for optimism that we are more open about how hard the work is and wanting to make sure that people who are doing the hard work are getting credit.

Dan Johnson: I think that's right. And I really appreciate you joining me today. What stands out for me is your work collectively and the reminder that resilience is not built by any single organization. It's built, as you said, by the leaders who are willing to coordinate, to cooperate, to align incentives, who are willing to share information and take responsibility beyond their own walls. So many thanks to you, Megan. Many thanks to our listeners for joining us. Join us next time on afternoon cybertea@afternooncybertea.com or wherever you get your favorite podcast.

Narrator: Foreign. This week on the Microsoft Threat Intelligence podcast, I'm joined by Aurora Johnson from Spy Cloud and Amitai Cohen from Wiz for a special Sleuth Con episode. We're going to talk about the hot cybercrime summer and the threat trends both of them are watching most closely. Head heading into the second half of this year. Be sure to listen in and follow us@, uh, msthreatintelpodcast.com or wherever you get your favorite podcasts.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your ProblemsThe Backup Wrap-Up · on Incident response planning88 / 100
  • From Services to Software: How Dual-Use AI Companies Actually Scale Inside Government | The Pair Program Ep94The Pair Program · on Supply chain risk management82 / 100
  • The Logic of Deny by Default: Building the Ultimate Security GuardrailCult Products · on AI in cybersecurity71 / 100
  • Cyber and the NY GiantsCloud Security Today · on Incident response planning67 / 100
  • Prepare, Don't Just Prevent: How Adaptive Crisis Simulation Is Transforming Cyber Incident Response - Episode 74 - Marlow Bryant, Reflex Security The Cyber Security Matters Podcast · on Tabletop exercises67 / 100
  • How CISOs Should Talk to Corporate Boards | Interview with Michelle DroletSecure & Simple · on Incident response planning65 / 100

More from Afternoon Cyber Tea with Ann Johnson

All episodes →
  • Tony Sager: The Case for Cyber Hygiene First65 / 100
  • Cybersecurity at Sea: Protecting the Global Supply Chain63 / 100
  • Code War with Allie Mellen85 / 100
  • Why Cybersecurity Fails Without Trust
  • Dawn Song: When AI Becomes the Hacker and the Defender
Explore the best B2B Engineering & DevTools podcasts →
All Afternoon Cyber Tea with Ann Johnson episodes →