The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/CISO Stories Podcast
CISO Stories Podcast artwork

Critical Infrastructure: The Risk Hiding in Plain Sight - Jason Manar - CSP #225

CISO Stories Podcast · 2026-06-08 · 31 min

0:00--:--

Key moments - from our scoring

Substance score

43 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft6 / 20

Jason Manar brings 16 years of FBI cybersecurity supervisory experience to his current role as CISO at Kaseya, where he supports small and medium-sized businesses and MSPs protecting critical infrastructure. The conversation centers on a sobering reality: over 90% of the U.S. economy depends on SMBs, many of which operate in the 16 critical infrastructure sectors - healthcare, financial services, energy, water, food and agriculture, and others - without realizing it. Manar highlights the threat landscape shifts driven by AI capabilities, particularly vault typhoon nation-state targeting and the democratization of attack toolsets that elevate unsophisticated actors to mid-tier threats. He shares a cautionary FBI-era case study where a company ignored tabletop exercise findings about inadequate resiliency plans, subsequently suffering a ransomware incident that cost tens of millions of dollars and took 2.5 months to resolve. The core message: vulnerability now equals exposure due to AI-driven vulnerability discovery, making assumed breach posture, identity management (including AI personas), crown jewel identification, and continuous resiliency testing non-negotiable. On newer models like Claude's Mythos, Manar views them as legitimate evolutionary tools - not hype - that lower barriers to vulnerability discovery for defenders and adversaries alike.

Key takeaways

  • →Small and medium-sized businesses serving healthcare, financial services, water management, and food/agriculture are critical infrastructure whether they realize it or not, and must operate from an assumed breach posture.
  • →The combination of AI toolsets and generative models is accelerating threat actor sophistication, transforming low-level actors into mid-tier threats and mid-tier actors into advanced threats at unprecedented speed.
  • →Vulnerability now equals exposure in the modern threat landscape because AI makes vulnerability discovery radically faster; acceptable remediation timelines will shrink every 3, 6, and 12 months requiring continuous roadmap updates.
  • →Resiliency and incident response planning must be grounded in business impact timelines and crown jewel identification, tested through tabletops - inadequate plans discovered during exercises will likely fail during actual incidents.
  • →AI models like Claude's Mythos are not hype but legitimate capability accelerators that lower technical barriers for both defenders conducting vulnerability discovery and adversaries, making government and critical infrastructure readiness essential.

Guests

Jason Manar

Topics in this episode

Incident response planningIdentity managementCISARansomwareVault TyphoonKaseyaCritical Infrastructure SectorsNation-state actorsTabletop Exercises (TTX)Resiliency Planning

Questions this episode answers

What are the 16 critical infrastructure sectors and how do small businesses fit into them?

The 16 sectors include communications, critical manufacturing, defense, energy, commercial services, financial services, food and agriculture, government services, healthcare, information technology, water and wastewater, and others. MSPs and small/medium businesses have heavy footprints in healthcare, transportation, wastewater management, food and agriculture, and financial services, often without realizing they're classified as critical infrastructure.

How is AI accelerating cybersecurity threats according to Manar's FBI experience?

Professional-grade attack toolsets previously available only to highly sophisticated actors are now widely distributed via AI, enabling low-level actors to operate at mid-tier sophistication and mid-tier actors to reach advanced threat levels. This acceleration compresses the timeline for defenders to respond, making current resiliency and patching strategies insufficient.

What should a company do if a tabletop exercise reveals inadequate resiliency plans?

Based on Manar's case study, companies that ignore tabletop findings risk catastrophic downtime - his example saw a firm offline for 2.5 weeks after ransomware when they could have recovered in days, costing tens of millions. Organizations must have conversations with the board and C-level about acceptable business impact timelines and prioritize resiliency initiatives accordingly.

Is Claude's Mythos just hype or a real security threat/tool?

Manar views Mythos as legitimate, not hype - it lowers technical barriers for vulnerability discovery, enabling non-experts to identify known and potentially new vulnerabilities. However, this same capability benefits both defenders validating their security posture and adversaries, making critical infrastructure readiness urgent.

What is the relationship between vulnerability and exposure in modern threat environments?

Vulnerability now equals exposure because AI-driven discovery makes vulnerabilities transparent and exploitable at rapid speed. This means acceptable remediation timelines will continuously compress; windows acceptable today will be unacceptable in 3, 6, and 12 months.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode surfaces a couple of genuinely interesting ideas - AI up-levelling threat actors across tiers, and a speculative 'no patch Tuesday' future - but they are surrounded by heavy padding, filler phrases, and standard CISO boilerplate (crown jewels, assumed breach, tabletop exercises). Insight-per-minute rate is low for a 31-minute run.

What used to be categorized as very low level non sophisticated actors. Now with AI toolset having um, having the ability to gain um, such efficiency that they are now a mid tier actor.
vulnerability is now just equal exposure, um, because of the transparency that a lot of these AI models have and discovering vulnerabilities

Originality

7 / 20

The 'no patch Tuesday' secure-by-design future is a mildly interesting provocation, and the tiered-actor AI up-level framing is memorable, but almost everything else - assumed breach, resiliency rings, crown jewels, geopolitics driving threat activity - is well-worn CISO circuit material with no contrarian angle.

Can we imagine that, you know, uh, there comes a day that you know, we may not even need a patch Tuesday, and that everything that comes out um, you know, is going to be in a state, I don't want to say of perfection
You're taking mid tier actors and because of this tool set, um, they are now becoming a very advanced actor. And you're taking the advanced actors um, that have had knowledge and experience and tool set and already existing tool sets and potential zero days and you are up leveling them to something that we haven't seen yet.

Guest Caliber

13 / 20

Jason Manar is a genuine practitioner - 16 years at the FBI in cybersecurity supervisory roles and first-ever CISO at a major MSP - giving him real, relevant authority. However, the conversation fails to extract the depth his résumé promises, leaving much of his direct operational knowledge untapped.

Over a thousand different intrusions. Uh, took that experience of working with some of the best CISOs and best companies worldwide.
I was the first ever CISO at Kaseya. Been there for about five years.

Specificity & Evidence

9 / 20

The anonymised ransomware case study provides the episode's best evidence - concrete timelines and dollar-range losses - and a handful of real references (Vault Typhoon, CISA advisory, Iran-linked group count) add credibility. Too many other claims are speculative or unattributed, and the absence of named companies limits verifiability.

It took them uh two and a half weeks uh before they got back online. They were offline and uh, were impacted every day millions of dollars by being offline.
it cost them tens of millions of dollars, almost on the verge of hundreds of millions of dollars

Conversational Craft

6 / 20

The host asks broad, leading questions, rarely follows up on specific claims, and closes with the obligatory 'advice to your 18-year-old self' question that wastes the final segment. There is no genuine pushback, no drilling into FBI case specifics, and no challenge to vague or speculative assertions.

So that sounds doom and gloom too,
what advice would you give your 18 year old self, Jason Minar, if you could just give some out of everything?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B73%
  • Speaker A27%

Most-used words

critical25infrastructure22small13back12state11frankly11ciso10businesses10technology9seeing9stories8sure8almost8level8jason7medium7

Episode notes

In this episode, former FBI cyber leader Jason Manar joins us to unpack the state of critical infrastructure security and why small and medium-sized businesses are more connected to it than they realize. From power, telecom, healthcare, finance, and supply chains, Jason explains how hidden dependencies can turn "not our problem" into a business-stopping event. With his FBI perspective and CISO experience, Jason shares what organizations should understand about risk, resilience, and protecting the systems we all quietly rely on. Visit for all the latest episodes! Show Notes:

Full transcript

31 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: South Carolina is proud to present this month's CISO Stories program hosted by yours truly, Jessica Hoffman. This is a show where CISOs share tales from the trenches and unpack leadership lessons learned along the way. Listen to previous CISO Stories podcast episodes@cisostories podcast.com the Cyber Risk Collaborative is a unique membership community enabling cybersecurity leaders to work together in a trusted environment. To learn more, please visit CISO Store Stories podcast.com forward/crc. Greetings. Greetings everyone. Welcome back for another month's episode of CISO Stories Podcast. Got my new friend Jason Bernard with us, uh, who is hanging out in beautiful Miami, Florida. I want to talk about that CISO Kaseya, uh, FBI for 16 years in the cybersecurity supervisory role. I know you got a lot of stories to tell, but I'm going to ask you for one special one here in a minute. But thanks for hanging out with us. I know you're a busy guy. Uh, what's up? How you doing? Tell us a little bit about yourself.

Speaker B: Um, I'm great, as you said. My name is Jason Menar. Uh, had the honor to serve this nation in the FBI for uh, right at about 16 years. Did it in many different capacities. I really got to see the good, bad and the ugly worldwide. Over a thousand different intrusions. Uh, took that experience of working with some of the best CISOs and best companies worldwide. Some of those best practices as well as what you can imagine are some horror stories that you run across as well. There's companies that weren't doing it right and I came over to the private sector where I now work for Kaseya as the ciso. I was the first ever CISO at Kaseya. Been there for about five years. And uh, I get to work with small, medium sized businesses as well as MSPs worldwide in securing their critical infrastructure, um, on a global scale. So it's um, really been blessed to work with some really, uh, bright minds throughout the industry. And I'm happy to be on here, uh, talking to you today.

Speaker A: Thank you. Thank you. So, yeah, this month's uh, theme is State of Critical Infrastructure Security. So that's near and dear to my heart as well. Being a public servant most of my career. You as well. Um, and now you're with uh, MSP or supporting the small businesses as you mentioned. So, you know, uh, let's talk about that for a second because when we think about small businesses might not think critical infrastructure, but obviously every company here, whatever the industry is, has dependencies. There's a supply chain, uh, what have you seen or what, what are your recommendations or when you talk to your clients that think, oh, I'm a small business, I'm not, you know, major infrastructure, critical infrastructure, I don't need to worry about things like that.

Speaker B: Yeah. So over 90% of our economy um, is basically on the head and shoulders of small to medium sized businesses. And when we think about critical infrastructure, it's critical infrastructure that's broken up into 16 uh, different categories. Right. And those categories most of us have heard about communications, critical manufacturing, we think about that as critical infrastructure all the time. We think about the defense industry, the energy industry and energy, energy services, um, you know, dams, energy. Right. But then there's commercial services, um, there's financial services, there's food and agriculture. Right. Government services, health care, public healthcare, um, information technology and then water and waste and I probably left out a couple in there. I think there's nuclear regulators, material waste, um, and um, and I think energy may be broken up into two different sectors. But when you start looking up uh, across that section the MSP community serves, uh, a heavy, has a heavy, heavy footprint in the healthcare industry, in certain transportation, uh, definitely wastewater management, food and agriculture and financial services. Now there's are, don't get me wrong, there are many MSPs that will uh, support directly government services and government facilities. But when you see especially the small and mid sized businesses, uh, think about your mom and pop health care, right? Dentist offices or very small doctors offices. Same thing with state and local uh, governments. When we're starting to talk uh, about information technology and the information technology uh, around those departments. And then uh, you think about the financial services, msps, uh, do a large amount of business as well as there are many mid sized financial uh, service organizations uh, that Kaseya helps. And so we have about 4 exabytes of information that's constantly flowing in from you know, all these different critical infrastructures and uh, critical pieces. So we obviously work with our customers and we obviously work uh, with regulators uh, from around the world to ensure that what we're seeing that they're aware of as well as we're making sure that our customers know um, some of the latest threats and evolving trends that are out there.

Speaker A: So what would you say to these small and medium sized business leaders that they should be aware of or concerned about when it comes to that supply chain dependency, especially in the critical infrastructure like you just said.

Speaker B: Yeah, yeah. So wow. Couple things that they should be uh, that are I think noteworthy I um, think we saw in 2023 and 2024, uh, vault typhoon Attribution. It's um, something that I think an advisory went out uh, around February or March, uh, of 2024, uh, where we saw nation state actors uh, really targeting you know, critical infrastructure. And then um, we saw that continue um, where uh, in 2025 and 2026, I think it was actually 2026 we saw it continue uh, with uh, the FBI and other uh, government agencies uh, saying that there were around 50 to 60 Iran linked groups that were actively targeting critical um, infrastructure. And I think CISA put a publication out about that. And so I would tell everyone, uh, especially that has anything to do with critical infrastructure that uh, you know we seem to see an uptick in activity and we seem to see an uptick in adversarial activity uh based on any kind of geopolitics, um, uh, that happened to be uh, going on at that time, at that point in time. And you obviously see it this year uh, with the Iran war. And so you have to make sure that uh, you are getting information on um, what, what those uh, nation state threat actors are targeting. And right now what we're seeing is uh, we see a lot of targeting of known vulnerabilities. And um, that will probably come back whenever. If we actually start dipping our toe into the AI discussion here today. Uh because we see uh, the ability of the threat actor um, to gain information about not only known but zero day vulnerabilities, um, in a way in which quite frankly we've never attributed or seen before. Um, thanks to uh, thanks to some of the generational technology that we've seen.

Speaker A: Yeah. And being abreast of all the current events, especially from a supply chain, I mean some of those things we just can't do anything about it. These small business, medium and large businesses just can't do anything about it in some of these instances where the critical infrastructure is impacted from a supply chain perspective. But curious. Times change. But do they really? Almost like we repeat history. But you've been out of the FBI for about four years now after serving almost what, 18 years or 17 years. So where. And that was right around when CISA was starting to get their feet wet. And you know we're figuring out what those critical infrastructure sectors are which 16 now they want to say 17 for space. I don't think that's official yet, but I uh, think almost any business can fall under that sector from a supply chain perspective for sure. So what do you think from when you were in the FBI four years ago. And that list of critical infrastructure and the impacts to small and medium businesses. Where do you think that we're doing better now or maybe even have more challenges?

Speaker B: So let me start with the challenges. Uh, the challenges is everything is speeding up. Um, think about it in terms of uh, professional sports. Everyone that I've ever talked to and whatever professional sport that they're currently in. Uh, you talk about um, going from high school athletics to college athletics and then to professional athletics. And they talk about how the speed in each of those um, various evolutions of their career um, was huge when they first entered um, whether it was high school, college or whether it was a professional sport. And you can kind of understand that, right? You're playing people at a totally different level. And what we are seeing because of the technology expansion and rapid expansion in AI is you're seeing exactly that. You're seeing professional tool sets that used to only be available to a small subset group of very highly sophisticated actors, um, now being distributed very widely across all actors. And so I think it was Anthropic's um, CISO that said it best. What they are seeing out there in the environment is what used to be categorized as very low level non sophisticated actors. Now with AI toolset having um, having the ability to gain um, such efficiency that they are now a mid tier actor. And you're taking mid tier actors and because of this tool set, um, they are now becoming a very advanced actor. And you're taking the advanced actors um, that have had knowledge and experience and tool set and already existing tool sets and potential zero days and you are up leveling them to something that we haven't seen yet. And so what all that does is that really accelerates what our response efforts have to be and what our posture has to be. And it really accelerates where we have to be within our security posture as a team. And so those are, those are some of the challenges. Now that's kind of the glass half empty scenario. Um, now the glass half. Right, right now, now the glass half full scenario is because it is accelerating us and because it is if you will, essentially airing a lot of people's dirty laundry if you will, with state of um, you know, vulnerabilities with state of um, tech debt. What, what is happening and where I think that you may be able to get within a couple of years is can we imagine a world where we have to um, be so quick, um, when something is published to correct it, that you're essentially publishing something that does not have you know, vulnerabilities in it. You actually have quote unquote secure by design technology. Can we imagine that, you know, uh, there comes a day that you know, we may not even need a patch Tuesday, and that everything that comes out um, you know, is going to be in a state, I don't want to say of perfection, um, but almost uh, to a ah, level that quite frankly we haven't seen here and we've only hoped for. And so I think we're seeing that inflection point where you know, companies are coming to the realization as well as, as well as security uh practitioners that these remediations are going to have to take so quickly that you're almost going to have that real time technology to do it at some point in time. Obviously I'm talking about 18, 24 months out if we continue to evolve the way that we have within AI uh technology. But that would be a uh, totally new um, landscape and opportunity for us and something that quite frankly we, we've wanted. But again we will have to evolve for these evolutionary factors that we see, um, that the adversary is, is, is causing us to evolve. And, and there's likely going to be some short term pain with that um, within the next you know, 12 months where you know, we, we see several large scale events, um, until we understand the new operating um, speed at which, or the new speed at which we have to operate.

Speaker A: So that sounds doom and gloom too,

Speaker B: uh, but well, okay, so imagine you're 47 to 50% more efficient and that you're able to solve more problems. Right? So that in and of itself isn't necessarily doom and gloom. Um, but we see technology helping to augment the workforce in ways where uh, we are able to create better, faster products. Um, now it still comes right now at somewhat of a learning curve and cost as we are setting up these new technologies. But we are seeing um, a very substantial multiple and people being much more efficient and their quality of work going up with these AI ah, uh, technologies and um, it's a very exciting new world in which we live.

Speaker A: I agree with that. Uh, just knowing, I don't know every organization, their security posture obviously, but from my experience being an auditor and talking to colleagues, we all have deficiencies in generally the same areas as 10 years, 15 years ago. Access control, you know, log management, continuous monitoring, um, et cetera, et cetera. I'd say access control really and phishing of course is the window to all the things. So I appreciate that. It's very exciting AI and it's at the consumer level. So we're able to pick it up. But not all small medium businesses have the budget for that or maybe the people that can support that like a larger organization. So in that case they're not probably ramped up or they're ready or they may not even have money to um, hire an M. M.S.P. um, so on that note too, just from an AI perspective what are some things that maybe we need to start doing as a, as a society, from an organizational perspective start doing to get prepared for this? And, and the fact that we rely so heavily on critical infrastructure. Is there anything we can do to be resilient? Should the US Go down? Should Verizon go down, should our Microsoft Teams go down? Which totally that happened to me during a huge tabletop, virtual tabletop in January which was not fun because we couldn't do what we needed to do. Um, so like those type of things I think we should, all businesses should be concerned about but those small medium businesses that you work with and that a lot of our listeners work with or working for, you know, what, what can we share with them now for them to start preparing for impacts or disruptions that are caused by their critical infrastructure.

Speaker B: So, so I think within your question, you've answered your question in many ways. Um, so you're talking about resiliency. And so we are at a time where I think it's almost unfathomable that um, you can have a ah, thought process of you're quote unquote never going to be hacked or you're never going to be compromised. And so if we are in a state where it's an assumed breach or an assumed compromise, you fall back to resiliency, you fall back to a ring or onion layered approach, um, where you know detection is key, speed of detection is key, um, and obviously protection uh, of uh, what your critical infrastructure is as an organization. So that means you have to know what those crown jewels are. You have to know what those critical pieces um, um, in an assumed breach are. You have to make sure um, that you're doing a solid job on identity management and that is identity, identity management of you know uh, real you know, human beings and quite frankly uh, you know uh, your, your, your AI Personas and other uh, non human Personas and uh, that you are treating those uh, like right and that you are tracking uh, what those, those accesses are and that you have the proper structure in place. So what I would say is, is it's really having a real understanding of what resilience Means and taking a really hard look during those tabletop exercises as um, if you have tested that resiliency thoroughly enough to meet what your organizational needs are. Uh, because at the end of the day as you experienced in this tabletop exercise there are situations that you may or may not be prepared on depending upon um, the level of maturity of your resiliency plan and your irp, your incident response plan. Mm mhm.

Speaker A: So when you.

Speaker B: I go ahead.

Speaker A: So I was going to ask, ask you about your FBI stuff to tell us a story that would align. I think that would be cool. You don't have to tell us all the details but I mean you dealt with a lot of issues, incidents, breaches that impacted critical infrastructure.

Speaker B: So, so we really did. And so I won't be able to say uh certain names but uh, when I was with the FBI some of, some of the more challenging and actually some of the more frustrating things were being able to see the writing on the wall. And there was a certain company um, that did a majority of their business required them uh to be online. And I was a part of their tabletop exercise as law enforcement. That will be from time to time. And within this tabletop exercise it was very clear um, that they had not prepared a resiliency plan um, that met the timelines that they needed um to not sustain considerable loss, meaning that it would be likely. And we pointed this out during the incident that um, in their current state of security uh maturity that they, if they incurred an intrusion that they would likely be down for a number of weeks yet when you talk to their board and their board was a part of this uh TTX and you talk to their CEO um at the time they said well you know uh, we have a three day window or a five day window and unfortunately what happened within a matter of eight months uh was uh, we were called back, uh they experienced a ransomware event and uh, because uh, they didn't have the necessary resiliency preparedness plan, uh it took them almost a uh week to uh, get aligned uh with their board and an IR provider, incident response provider. It took them uh two and a half weeks uh before they got back online. They were offline and uh, were impacted every day millions of dollars by being offline. Um and uh, and then it was a matter of restoration, uh and they spent about two and a half months um, going back and forth on quote, um, unquote critical restoration because they didn't have a good understanding of, of what their crown jewels were or where to start from first and so at the end of the day, um, you know, after talking to CEO, after talking to some of the board members, they would have given anything to have gone back in time and reprioritized some of the initiatives that they had, um, because it cost them tens of millions of dollars, almost on the verge of hundreds of millions of dollars, um, for quite frankly a remediation that after they got their playbooks together, after they got uh, some systems in place that they could have dealt with, you know, within a matter of uh, days or even a week or two instead of rolling on for several months and impacting the business. And so I tell everyone that to say if you're not having conversations about, you know, impact to the business and um, you're not having grounded, uh, understanding of, um, quite frankly, how long the company that you're with is going to be exposed because we are living in a time where vulnerability is now just equal exposure, um, because of the transparency that a lot of these AI models have and discovering vulnerabilities. So it truly is a conversation of how long do you want to be in a state, um, to where you could potentially be breached with known vulnerabilities. And then it's a conversation of, you know, how much money it will take to get, uh, that window down to quote unquote, what an acceptable level is for your company. And I would, I would venture to say whatever that acceptable level today is, it will be shorter in three months, it will be shorter still in six months, and it will be shorter still in 12 months. And so it's a revolving, uh, conversation that you're going to have to have, uh, with your c, uh levels and with your board.

Speaker A: That's a great takeaway. And I was just having this conversation. The roadmaps that we're doing now and forecasting with our tools, with our ATT and CK surface, everything is changing so rapidly. We can't just say, here's our roadmap for 135. Not saying that's blindly. You know, things change obviously in the industry, but it's. The change is so rapid right now. So Mythos, hype, hype or not, what do you think?

Speaker B: I don't necessarily think it's hype. I've talked to enough people that have access to Mythos right now where um, it is doing many of the things that they are quite frankly able to do with earlier models, uh, but they're able to do it, um, with. With very limited prompting, whereas before they would have to be very specific in the prompting, uh, uh, or they would have to have ah, additional requirements, training, etc. Etc. For the model. So I, I think there are things that it is doing right now um, that again create less of a barrier, a technical barrier for people to use it and potentially do nefarious and, or good things with it. Right. I mean imagine you're able to unleash this model, have someone uh, that is you know, uh, not even necessarily um, the top level, uh, application security person in your organization is able to effectively, you know, uh, run Methos within your company to identify, you know, not only known but potentially uh, new vulnerabilities that exist and then, and then have you remediate against those. But what we're also seeing is it is affirming if you will, really good practices uh, by uh, CISOs and by companies. So some of the CISOs that have this right now that I'm talking to, they're able to validate the work that their vulnerability and their securities teams done, you know, in the past and, and basically show the board and others uh, where their investments uh, have really uh, paid off and how they are prepared for this. Um, others have showed where there's potential underfunding in certain areas. So I don't think it is um, just hype. And I also think it's worth pointing out Mythos was not created to be a security tool. It was just the next evolutionary step, um, in their model. And what they found was that it had the potential to be uh, maliciously used. And they went directly uh, to the government and others and said hey, uh, let's, let's pause, let's look, let's make sure that we have a plan on, you know, how we roll this out and um, make sure that you know, quite frankly that we are ready and the government is ready and taking it all the way back to critical infrastructure. Critical infrastructure is ready for these new technologies because at the end of the day we know that it's not just um, Claude that is developing these type of technologies, it's other nation state, um, and quite frankly uh, adversarial countries that are developing light technologies.

Speaker A: I feel like we just always get back to gloom and doom. Although I'm living on hope that's, you know, that's what we do. Uh, that's not going to answer all your problems and secure your systems and organizations infrastructure. But uh, yes, thank you Jason so much. We are at time, but I always like to ask my guests this question. You have a fantastic background. Again, if I could do it again, I would be in The FBI Secret Service Cyber Unit. That sounds like so much fun. Um, but what advice would you give your 18 year old self, Jason Minar, if you could just give some out of everything? You know, it doesn't have to be cyber related, but what piece of advice would you give 18 year old Jason right now, if you could?

Speaker B: Yeah, so that's really interesting because I have a daughter that is turning 18, graduating from high school. And so I put myself back there and think about, uh, what I thought were challenges and problems. Um, lean in to what you find interesting and lean in to what you're good at. So early on I always loved cyber and I loved being a quote unquote techie even before I was, um, but at 18 years old I resigned, uh, to the fact that that probably wasn't necessarily in my cards. And um, not that I would ever trade anything or any of my experiences. Um, but I think had I leaned in earlier, um, I would get the same enjoyment out of the enjoyment that I've had even talking to you for the last 25, 30 minutes. And uh, sometimes I think, quite frankly, we sell ourselves short. And so believe in yourself, do not sell yourself short and dig in. We are in a point of time in history where we have more knowledge at our fingertips and resources to learn whatever we want than we ever have before. It does not take a PhD or a college degree to dive very deeply into various areas, um, and to have a knowledge and skill set that, quite frankly, our ancestors would have killed for. So lean in, um, be that hero in your own story and, um, make sure that you're the one at the end of the day that is constantly learning, ever evolving and ever ready for whatever comes our way in the future.

Speaker A: I love that. Imposter syndrome is real. Circular learning is beautiful. Everybody, no matter the age, take this advice because we have a lot of work to do. Never going to stop. Jason, thank you so much for your time today. Good luck with everything. We appreciate your service with the FBI and the great things you're doing with Cassera. And uh, we will see everybody back next month. Please make sure you tune in and check us out. Thanks, Jason. Thanks everybody. Thank you. Thank you for tuning in for this episode of the CISO Stories podcast. Please subscribe to the CISO Stories podcast and you will receive a new story each each Tuesday at 10:00am Eastern Standard Time. We'll see you next week for a new episode. Thanks for joining.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why CMMC became necessary in the first place.Trust Issues · on CISA88 / 100
  • Building a Cybersecurity Culture in Your Company (Encore)The Backup Wrap-Up · on Ransomware86 / 100
  • Reframing Cyber Risk with Jane Frankland MBEBCG on Compliance · on Ransomware84 / 100
  • Practice Makes Progress in Cyber Resilience with Jim Bowie, VP and CISO at Tampa General HospitalHybrid Identity Protection Podcast · on Ransomware80 / 100
  • Insider Threats: How to Properly Conduct a Cyber Investigation from a Threat WithinLowenstein Sandler's Executive Compensation and Employee Benefits Podcast · on Incident response planning75 / 100
  • Brett Gailey on Cybersecurity Myths for SMEsMarketing for SMEs · on Ransomware71 / 100

More from CISO Stories Podcast

All episodes →
  • IAM for MSSPs: The Hidden Risk of Blind Trust - Dustin Sachs - CSP #224
  • Cloud Security: The AI Effect & How to Proceed - Richard Marcus - CSP #223
  • From Alerts to Action: Making Public - Private Threat Intel Actually Useful - Ian Washburn - CSP #222
  • Beyond Vendor Risk: Real-Time GRC, AI, and Protecting App User Data - Jadee Hanson - CSP #221
  • Keys Without People - John Heasman on Cleaning Up Non-Human Access - John Heasman - CSP #220
Explore the best B2B Ops podcasts →
All CISO Stories Podcast episodes →