The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Marketing/CXO Spotlight
CXO Spotlight artwork

Palo Alto's CSO: Your Security Strategy Is Outdated. Here's How to Build One That's AI-Proof

CXO Spotlight · 2026-07-20 · 1h 1m

0:00--:--

Key moments - from our scoring

Substance score

66 / 100

Five dimensions, 20 points each

Insight Density14 / 20
Originality13 / 20
Guest Caliber16 / 20
Specificity & Evidence11 / 20
Conversational Craft12 / 20

Jesper Burke Olsson brings a unique perspective shaped by 17+ years in military IT security, his role managing Maersk's response to the NotPetya attack, and now advising CISOs across Northern Europe at Palo Alto Networks. The episode unpacks why compliance-driven, resilience-focused security strategies fail in an AI-augmented threat landscape. Olsson distinguishes between business AI adoption and cyber AI maturity - highlighting a dangerous asymmetry where attackers leverage AI acceleration before defenders deploy it. The core insight: attacks now transition from access to impact in under 60 seconds, a pace no human-led SOC can match. This creates compounding vulnerabilities across identity, data sovereignty, shared responsibility models, and non-deterministic AI outputs. Rather than accept this fragility, Olsson presents the Imagine-Invest-Improve framework: the Cognitive phase (creating strategic optionalities through "what if" scenarios), the Invest phase (allocating 80% to core security infrastructure, 20% to high-risk innovation), and the Improve phase (continuous adaptation). The conversation is essential for any CISO, CIO, or enterprise technology leader rethinking security strategy against AI-native threats.

Key takeaways

  • →Resilience is table stakes, not the goal - organizations need antifragility, which embraces disruption and requires process-to-technology coherence, not just mature tech stacks.
  • →AI doesn't just speed up attacks; it creates non-deterministic, unpredictable outcomes (like a chatbot suggesting recipes) that traditional rule-based security controls cannot handle.
  • →The gap between business AI adoption and cyber AI deployment creates asymmetric risk: attackers operationalize AI faster than defenders, with Palo Alto seeing attacks reach impact in under 60 seconds.
  • →An 80/20 budget split (core infrastructure vs. high-risk innovation) embedded as cultural practice allows security teams to adapt to volatile threat landscapes and AI-driven change.
  • →Strategy failures stem from business ambitions disconnected from cybersecurity strategy, which is disconnected from execution - leaders must align business outcomes, security strategy, and tactical effort to bridge these gaps.

Guests

Jesper Burke Olsson

Topics in this episode

Palo Alto NetworksCyber resilienceNotpetya attackSOC automationAI-powered attacksAntifragilityThreat actor TTPsShared responsibility modelsBusiness AI vs. Cyber AISub-60-second attack-to-impact timeline

Questions this episode answers

What is the difference between cyber resilience and antifragility in practice?

Resilience focuses on pre, during, and post-incident response but assumes predictable disruptions. Antifragility embraces unexpected disruptions and builds adaptive, adjustable systems that learn from them - requiring tight alignment between technology, processes, and digital dependencies to avoid fragility.

How are AI-powered attacks different from traditional cyber threats?

AI accelerates attack sophistication, scale, and speed - Palo Alto has observed attacks transitioning from access to impact in under 60 seconds, a pace human-led security teams cannot match. AI also creates non-deterministic outputs (unpredictable actions like unintended features) that rule-based controls cannot prevent.

Why is there a gap between business AI adoption and cyber AI readiness?

Organizations deploy AI for business acceleration faster than they adopt AI-powered security tools and processes, creating asymmetric risk where attackers operationalize AI-driven attacks before defenders can detect and respond at the required speed.

What does the Imagine-Invest-Improve framework do?

Imagine (Cognitive phase) creates strategic optionalities through "what if" scenarios; Invest allocates budgets 80% to core security, 20% to high-risk innovation; Improve enables continuous adaptation to volatile environments - providing ambidextrous leaders a structure to balance operations and innovation.

How should organizations budget for both stability and innovation in security?

Apply an 80/20 model: 80% to core security infrastructure (foundational defense), 20% to high-risk, high-reward innovation initiatives - this embedding as cultural practice enables teams to adapt dynamically rather than becoming brittle.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

14 / 20

The episode contains substantive ideas about antifragility vs. resilience, the imagine-invest-improve framework, and specific AI security risks (data poisoning, integration security, agent proliferation). However, roughly 30-40% of runtime is biographical narrative, throat-clearing, and conversational filler that dilutes insight density. The core frameworks are explained but not deeply unpacked with operational examples.

attacks where from access to impact is less than 60 seconds
if the plan is on a computer that's unavailable, it's of no use

Originality

13 / 20

The antifragility concept (drawing from Taleb) applied to cybersecurity is relatively fresh, as is the articulation of business AI vs. cyber AI divergence and the imagine-invest-improve framework. However, resilience-based thinking is already mainstream in security circles, and much of the guest's reasoning about AI acceleration of attacks is now conventional wisdom in the industry. The framework borrows heavily from agile and operational principles without strong differentiation.

antifragility as the goal, not the resilience
business AI is accelerating a lot faster than cyber AI

Guest Caliber

16 / 20

Jasper is highly credible: CSO at a $127B market-cap leader (Palo Alto), managed Maersk through NotPetya (one of history's largest cyberattacks), former NATO advisor and military police officer. He has practitioner depth and executive influence across Northern Europe. He is not a pure thought leader but an operator with real incident response pedigree.

chief security officer Northern Europe at Palo Alto Networks
managed security at Maersk drilling through the Notpetya attack. One of the most destructive cyber attacks in the history

Specificity & Evidence

11 / 20

The episode includes concrete examples (NotPetya incident, Maersk drilling, anthropic MCP server compromise, chatbot recipe suggestion), specific metrics (60-second access-to-impact, 33-50 cent ratio per AI dollar invested), and mentions of frameworks (CIS controls vs. ISO 27001). However, most examples are illustrative rather than granular; the guest rarely provides named clients, quantified outcomes, or timelines for when these patterns emerged. The data-poisoning and AI dataset recovery risks are conceptual rather than case-studied.

In Palo Alto networks we've seen attacks where from access to impact is less than 60 seconds
every dollar you put into the AI you will have to spend between 33 and 50 cents on the dollar

Conversational Craft

12 / 20

The host asks genuine follow-up questions and pushes for practical application (e.g., 'In practice, not in theory' on antifragility, asking what works with CFOs). However, many questions are soft, allowing long biographical tangents early in the episode. The host occasionally mirrors back understanding rather than challenging or probing contradictions. There is little skepticism about claims like the 33-50 cent rule or pressure on vague statements.

What's the difference? In practice, not in theory
What's the argument that actually works with a CFO or the board?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B75%
  • Speaker A25%

Most-used words

security68data55technology19point18start18organizations18almost17conversation16cybersecurity16cyber15military15organization15imagine15investment15strategy14different14

Episode notes

Jesper Borg-Alsson, Chief Security Officer for Northern Europe at Palo Alto Networks, explains why your current security strategy is built for threats that no longer exist. With 20+ years managing security at scale from NATO toNotPetya incident response to advising Fortune 500 CISOs, Jesper reveals the gap between resilience (the floor) and anti-fragility (the framework that wins). He shows why organizations need to embrace disruption rather than just survive it, and what makes one vendor chosen over another when every competitor claims identical features: the ability to turn threat landscape volatility into your competitive advantage.Jesper's pattern: when complexity explodes, he builds frameworks that separate signal from noise and connect security directly to business outcomes. At Palo Alto, he works across Northern Europe advising CISOs on the specific shifts required for AI-era threat landscapes where access-to-impact now happens in under 60 seconds.Key Insights:■■ Resilience is the floor, not the ceiling. You need controls before, during, and after incidents. But mature compliance frameworks fail when process dependencies aren't mapped to digital systems.

Full transcript

1h 1m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Is that a technology problem or is that a thinking problem or is that a strategy problem?

Speaker B: I think, uh, it's a mix between a strategy problem almost. I wouldn't say awareness and education, but it's very close to right. I need to ask you a question, Mr. M. CEO. How long ago were you breached? And he said, oh man, it's been a couple of months only.

Speaker A: And thought you spoke about antifragility as the goal, not the resilience. What's the difference? In practice, not in theory, it's great

Speaker B: to have a plan, but if the plan is on a computer that's unavailable, it's of no use. Uh, but if the phones were software based and on the computers which aren't working, how are you going to communicate? In Palo Alto Networks we've seen attacks where from access to impact is less than 60 seconds.

Speaker A: Welcome to CXS Spotlight. I'm your show host Chira Kanijo and today is one of the most important topic that we'll be talking about ever. Cyber security. Cyber security in the age of AI is one of the hottest thing and the most compelling thing that is going on right now. Um, but in most of the conversations we have had so far, one pattern is coming up is that everybody's trying to build cyber resilience. But cyber resilience is not enough anymore with the threat that we are faced with. And um, this is conversation that every chief information security officer or anybody, anything to do with cybersecurity and enterprise tech has got to hear. And that's why we have a special guest. He's the chief security officer Northern Europe at Palo Alto Networks. For those.001% of the people that don't know. Palo Alto Networks is one of the most valuable CyberSecurity company around $127 billion in market cap and almost touches every single Fortune 500 or Fortune 1000 company. Now the guest is Jasper Burke Olsson. He's a military police veteran, former NATO advisor, managed security at Maersk drilling through the Netpachia attack. One of the most destructive cyber attacks in the history with over 300 million plus in the damage. Um, he now advises chief information security officers across northern Europe on something most security strategies ignore. Which is why resilience is not enough. And that's what we're going to uncover today. Welcome Jesper. Welcome to the show.

Speaker B: Thank you so much and thank you for having me. Um, I'm a bit uh, humbled by uh, the approach here but uh, I look forward to the conversation. Sirak. Thanks.

Speaker A: Awesome. Jesprada. Uh, first things first, I think a phenomenal journey arc, uh, from the military, NATO to man managing the aftermath of what's been called as the most destructive cyber attack in history. And now being the chief security officer at Palo Alto. Can you walk us through that journey we, uh, were talking about earlier? But I would like to hear that again.

Speaker B: Yeah, of course I can. And pretty proud to share as well, because it's one of those journeys where, um, nobody saw that coming, more or less. Right. I was a bit of a troublemaker when I was young, so I joined the military at a very young age. And then I was selected for military police training. And. And let's just be honest, at that point in time, no one really had beliefs in me making it. But then I really. I think I found my niche there. You know, there was something in being a military police officer. And then later on, um, I became one of the bodyguard team leaders, uh, in there. And everything started evolving around the security of people and using the ability and skills that you get was around security and securing others, protecting others. And that really resonated with me. So I took that on as almost like a personal passion goal of mine, that if I in a position where I can use skills and ability to secure and protect others, that's what I want to do for the rest of my life. Now, doing that for a, uh, uh, couple of years and having some experiences and learning that soldiering also carries an impact. Right? Not just for me, but also for. If I wanted to have a family and everything, going abroad on some of the dangerous hotspots in the world. And keep in mind, I'm going back to the mid-90s here, so there were a few of that. I realized that there might be another pathway to this. Um, and luckily for M, me, I was also quite geeky. Um, so I had a knack for technology, and there were a couple of people that noticed that. So they pulled me into the IT agency of the defense at the time, um, and I had the opportunity to work with some of the brightest minds from both the systems architect perspective, communications, uh, infrastructure, and then M, of course, the security aspect of it. Because when you deliver IT services to, you know, the hotspots of the world, to military operations, to critical infrastructure and national security systems, um, then security is. Is the core of it, right? So. So that was sort of my. My start on it. And then as time go by, I. I then became one of the security officers that we had in the IT agency. And I leveraged that skill to start building out the frameworks and the knowledge that you need to grow security organizations. And that's when someone pinged me and said, hey, you know what? Uh, Maersk might be, uh, a good place for you. We had a cup of coffee. We had three cups of coffee. And then finally it was like, okay, uh, I think I've sort of reached the inflection point of my military career. I probably can't change a lot more in this structure that I'm in. And the conversations we're having is starting to repeat itself. So I thought, hey, it's a good opportunity for me to help more organizations than just the one, and it's a good opportunity for someone else to step in and change everything that I've been building for the past 17, 18 years or something. Um, so erupting a bit in the legacy. So I joined Maersk, and as you said, interesting organization with a very interesting case to work on. And my intent actually was. And then I'll shorten it down a bit so I can catch my breath as well. But the intention was actually I'll join the organization. I'll just go over in the corner, work on information security, not really having any responsibilities outside of information security, and just focus on it. And that was the intent. A couple of months in, the Caesar in the house came over to me, and he said, I hate to do this, buddy, but, um, I just got a good offer. So, uh, here you go. Here's the keys to the kingdom. Oh, I'm sure you will, man. Is fine.

Speaker A: And then.

Speaker B: A great start for me in a, uh, in a new organization, very different from where I came.

Speaker A: Um, and then.

Speaker B: Yeah,

Speaker A: how about. What about your role at Palo Alto? What. What is that about? Can you talk a little bit about that?

Speaker B: I can. Yeah, I can. So it was, um. It was one of those. I had a really good traction in. In Merc, so I wasn't ready to. To. To leave, actually. But then a friend called me, and he said, I think someone in Palo Alto Networks knows you because they've written a description for a role that you might really like. And I'm like, okay. And he sent it to me. Um, and I could see that this is about influencing and working on strategies with multiple companies, not just Palo Alto Networks, but actually going out and helping other organizations in looking at what is important. And I usually phrase it like this. If I can help an organization actionable, you know, move from a cybersecurity strategy or a business strategy to a cybersecurity strategy, and then down to the actual Effort that makes sense for the business. I would happily do that. But sometimes I also come in and then I look at what are you doing? And then linking it back into business, uh, ambitions. And in between that we start building the cybersecurity strategy. So depending on the maturity level of the organizations, I help formalize and standardize, you could say, across the cybersecurity strategy life cycle. This is a super fun job, to be honest. You get to meet a lot of very knowledgeable, very skilled people at very different maturity levels, not individually, but in the organization they're in and how the organization perceives them and the activities that they're performing as well.

Speaker A: Right? Yeah. So uh, I think this is very interesting. So you work with chief information security officers or the security leaders of these companies every day, right?

Speaker B: Yes.

Speaker A: And when you look at how most organizations have built their security strategy, what's the specific thing that tells you that this was designed for a threat landscape that no longer exists? Or so tell us, give us the dibs on what are you learning by looking at the languages?

Speaker B: Yeah, so if I look at the broader picture, obviously there's a bit of a difference between industries. Some are super compliance heavy. Right. I mean financial industry is a great example. Uh, critical infrastructure organizations in the bigger space, like energy, um, very heavy on compliance as well. So that is a clear driver for the security strategy, which unfortunately very often doesn't mean security is done for the business ambitions, but it is done for achieving the check marks. Right. Um, and that is a very interesting conversation to get into. But on the, you know, on the, on the broader industry, cross industry perspective, I would say it's, it's very much building towards the resilience mindset. So what are the things that we can do before an incident and how do we operate during an incident? And then most organizations luckily today are linking it to the post incident. So what are we doing after as well? And um, I uh, like that resilience mindset. I've been a big advocate for it for a long time, I talk about it a lot. But we are at a changing point, an inflection point right now where that's simply not enough anymore, to be honest. Mhm.

Speaker A: And how do we define that? Like is that a technology problem or is that a thinking problem or is that a strategy problem?

Speaker B: I think it's a mix between a strategy problem and a. Almost, I wouldn't say awareness and education, but it's very close to right. Because more and more organizations are, and we talked about that just before going on to the Point podcast, right. We talked about how organizational leaders are now becoming more and more aware of cyber security topics. Um, and you know, a funny story, the other day I met a CEO of a company and we were having a conversation, you know, just a casual conversation. And all of a sudden, because we were talking about what it does, I do and how I help organizations, and I could tell that there was knowledge to be gained from this CEO here. And he started talking cybersecurity terms. He was using like, threat actor names and how they operated and TTP and expressions like that. And at first I was like, was this CEO? I mean, is it a tech company? No, it wasn't. Um, I can't share the details of the company, unfortunately, but it was just one of those interesting conversations where it suddenly made me think that, I need to ask you a question, Mr. CEO. Um, how long ago were you breached? And he said, oh, man, it's been a couple of months only. And so there you have. That's the reason why he knew everything about cyber security. And I told him, honestly, I wish more CEOs were like you, pre event.

Speaker A: And he was, yeah, adversity is a great teacher, but so is watching that beside you and not happening to you. So I think there's a learning there, absolute for. For a lot of people.

Speaker B: Yeah, yeah, absolutely. He told me as well that had I only known what I know today, but five months ago, oh, what a bliss.

Speaker A: Super. So let's help. Let's help other. Let's dig a little bit deeper. I saw you spoke about antifragility as the goal, not the resilience. And, um, most CISOs have spent years building this resilience, right?

Speaker B: Yes.

Speaker A: What's the difference? In practice, not in theory. Like, what do you really mean by that?

Speaker B: Yeah, it's interesting. One thing is there's the, you can almost call it the academic approach to it, where the, you know, the hyper thinker, um, when you look at resilience, it's centered around something that happens right pre, during, and post, um, and you start building constructs that will support you in this. I'm not saying it's bad. I'm just saying there's another level of this because we are moving into a very volatile future and state of, uh, most of our organizations, right? We have, uh, politics that are changing things. We have economics changing things. We have so many things. And technology, of course, with AI and the coming of future agentic AI, if not already here, um, that is changing a lot of things. And that requires a much More adaptive and a much more um, adjustable approach from a cyber security perspective as well. And this is why I introduced the anti fragility and my mindset around, around it is let's embrace that things are going to disrupt us. There's going to come, you know, activities and events that uh, we've never thought of and it's going to completely blow us away for the first couple of minutes and hours and maybe days, hopefully not weeks. And then we start responding to it. And we have to take that into considerations around systems as well and the technology we use, how fragile is the ecosystem we have? And here, um, I'm not talking about ecosystem from a technology perspective. I'm also thinking about it from a process perspective because I still see a lot of organizations that have the most mature cyber resilience or operational resilience framework. And then you're super dependent on a single business process for a single outcome. But they haven't tied it to the digital dependencies. And that means there's fragility in there and we need to figure out a way to change that aspect a little bit and figure out how and what can we do around this. So that was part of the conversation we had at ah, the Docker forum.

Speaker A: Got it. So I got it. Like what I understood is that resilience is sort of the floor, not the ceiling. Like it's the table stakes that you need to have. The second thing is that um, tech stack may be mature but if the process isn't there then to have that fragility sort of in your overall processing system, then it can struggle. But here is what I keep hearing from a lot of CIOs even that they know that AI is changing the threat landscape, but they don't know specifically how. Like not the general thing, like um, AI makes the attacks faster. I think everybody appreciates that by now. But what has actually changed in how attackers operate that the most security strategies are not accounting for today?

Speaker B: Yeah, that's a really good question. And I think most leaders today have understood that AI can do exactly the same for uh, cybercriminals as it can for any business or any individual. Right? It can accelerate and optimize efficiency and everything related to that. So that in itself doesn't really change a lot of things. What does change though is the way we look at what we want to get out of using AI and how we use it. Um, you can almost compare it to when we started on the self made application or SaaS application journey. Right? We do the same with AI. Now, are we going to develop it ourselves or are we going to rent it from someone and pay a subscription for it? And that in itself is not very different either. But how it connects to data and how we are now accountable for the outcomes of it is very different from the SaaS applications as well. Right. So we are now looking at that technology architecture is shifting because we're using new elements of technology. Most likely we don't have all the skills needed in our organization to support all of these new technologies. So we'll have an increased risk, uh, um, for a period of time until we have the skills. So that is one angle of change. The other angle of change is we are now working very dynamically with data and we have to validate all of the outcomes of how that data is now translated into new outcomes as well, which inherently brings another risk as well. Are we capable of understanding the difference between two outcomes? One might be the very correct one and the specific one we intended. The other one might be slightly askewed. Uh, so this is back to if we have not defined what AI actually means for our business, then we might have a challenge in defining the outcomes we want with AI as well. And I'll come back to the definition. If we don't understand and define the outcomes we want, how do we set the guardrails and the constraints around it to ensure that it doesn't drift and it doesn't do things that we don't want it to? I can give you an example of a chatbot from an insurance company that all of a sudden was able to suggest recipes for customers. It's not intended to do that. It shouldn't do that. It shouldn't be connected to recipe databases. But it was because they trained it on open source data. So that is some of the challenges. Now, I mentioned. Oh, sorry.

Speaker A: No, no, please go ahead.

Speaker B: I mentioned the definition. And one of the reasons is, um, I'm seeing this divide happening right now between business AI and cyber AI. So business AI is accelerating a lot faster than cyber AI is. And what I mean by cyber AI is the adoption of AI technologies to actually secure the other AI. Because like, we just agreed on, AI being used by cybercriminals will increase their performance in similar ways that it will for, uh, you and me or for organizations adopting to it. That means attacks are happening faster at scale, with a bit more sophistication, maybe even. And if we still rely on people to respond to it, that is really going to challenge us in the future as well. I mean, we have Tons of examples of this in the cybersecurity industry in general. In Palo Alto networks we've seen attacks where from access to impact is less than 60 seconds. I haven't met any human led security operations team capable of identifying it, detecting and preventing and everything that you have to do, then responding to it and then being able to prevent it from happening again at the same time somewhere else at that pace. That's hard. You need different tooling.

Speaker A: Yeah. You know, um, in a lot of my conversations I want to sum this up in a way that I've been hearing about this and because I love the definition that you and the separation that you did. What? Uh, and I'm sort of watching it like a spectator. Like um, earlier in enterprise tech we would say what's your threat vector surface like? You know, what's the surface like? And we would say internal system. External system. Yeah, that sort of compounded with the whole cloud and SaaS thought process of shared responsibility, of wait, you have the access, you host the data cloud and everything. Right. I have to say, I don't think people realize how much exponential compounding just happened with AI. Um, because I'm listening to what you're saying. The fun compounding is that now you not only have identity and access management, shared responsibility or hosting shared responsibility, your data itself beyond identity is you don't know where it is and where it is coming from. Yeah. Then the compounding is it can give non deterministic answers like a recipe. It's not like yes or no or give me my data based on the rules. It is non deterministic.

Speaker B: Exactly.

Speaker A: And then the compounding that you're saying is that it can work at warp speed of action to impact in 60 seconds. So it's. The problem is magnanimous to say the least. Um, but I think what would help, I think we have created enough pain here. What would help is that you developed a framework and that's what I saw. And I want that framework of like imagine, invest, improve, what, what. Can you please talk about that framework?

Speaker B: Yeah, yeah, I can definitely try. And this is exactly what I wanted to do. Right. I wanted to bring leaders to um, in AI, for, for, for, for that matter, we talk a lot about the ambidextrous leader.

Speaker A: Right.

Speaker B: The one that's, that's um, capable of standing one foot securely grounded in daily operations. The other foot is more loosely but still grounded in innovation and the speed that the business has um, to re, innovate or reinvent themselves sometimes. Right. And the ambidextrous leader of the future needs something to lean on as well. So this is why we had the conversation both um, before and during the Drucker forum around antifragility needs something, right? I mean our management principles, our structured models is quite robust. Robust, right. They're built to resist, um, and that just means that once you hit that breaking point of it, you risk a collapse of it. You can always think about this as a concrete building, right? It can take a lot of pressure and a lot of beating and a lot of wind and a lot of water, but when it hits the breaking point, it's going to fall down. Right? And this was our approach to antifragility. And to sort of get out of that, we said, okay, we need a couple of phases here, at least three phases to get us to the next point. And the first phase, and you mentioned that imagine, right, this is we call the cognitive phase. Um, so we're not predicting the future. The whole focus is around creating optionalities. So almost like everything you do and everything you try to achieve, you apply the but what if scenario. I'll give you a very tangible example. If you're discussing a future business idea, um, in the company, try bringing in someone who only has one purpose and that is to drive the conversation in a different track. Try to ask the question that takes the conversation in a different track to challenge the organization as well. And this you can use in um, security context, in operational context, in business opportunity context as well. Right? So this is the imagine part where you start having a strategic anticipation with options in the future. Now the second element is invest, right? This is where we start talking about resources and allocation of this. Um, and this is where obviously for any organization you will be driving some sort of, and I call it cost excellence because it's positive laden, but you will typically you will be having cost as some element in your strategy. Either reduction of cost or balance of cost or adequate spending, something like that. I like to call that, um, um, Cost excellence principles. Right? So in the invest part we, we talk a lot about how you can invest very heavily in the core of your business. So for instance in the security technology that is required to have a secure and stable foundation for the organization to move forward on. But you need to have an allocation for high risk, high reward innovations in any business function you're in. Doesn't matter if you're in finance, if you're in hr, if you're in the security team, imagine setting. Um, I'm not saying this is a recipe for success, but if you run for an 80, 20 model on this, so you say 80% of your budget is going towards the core of it. 20%. This is the high risk, high reward innovation. This is how you change and move forward and become adaptable and adjustable to the volatile environments that you find yourself in. And it becomes a cultural, almost a cultural shift. Because if you're constantly focusing on what should be our uh, innovation now, having it almost as a workshop kind of theme for the teams as well, both in the executive layers and in the strategic leadership, but also at the operational level, people will start to adapt more and more. So you can talk about, you know, some of the key questions that you would ask here. Are we investing in efficiency or are we investing in redundant capabilities that allows us to be agile? That is towards the anti fragility. Now the third leg of the framework is the improvement point. This is where um, we take every element, everything that happens as an opportunity to learn and improve, every error we make, every uh, uh, business opportunity that fails, every strategic ambitions that slows, um, for whatever reason, every failed product launch or product definition, all of that is used to improve all of us. So being open to discuss, and I'm a big advocate for that in general being open to discuss our failures as much as our successes. Right. I mean I can share the example of when I tried to force an organization into an ISO 27001 certification after realizing that, okay, so no one in it is ready for this and they actually, I need to interpret every single instance of this when I introduce the ISO control sets as well. There must be an easier way. And I find the CIS controls to be a lot easier to implement because it's written by IT people for IT people. So it was like, okay, I know we spent six months on this, but now we're going to spend 30 days on implementing this instead of M. That's a failure you learn from and you continue to improve on. Then later we can go for the ISO certification. Right. Just one example.

Speaker A: Yeah.

Speaker B: So again, some of the cultural questions that you would tie into this is how do we actually look at failures? Is this something that we try to put in the drawer, hide away, don't talk about it, or do we actually harvest it for additional insights where we can talk about it? Because that drives again towards the antifertility mindset here.

Speaker A: Yeah. Um, one thing I find very interesting in your experience, if I go back to Maersk, um, drilling. Right. Yeah, Think of it that way because we should talk about real examples for a company to be able to solve this, um, think like this, that um, offshore drilling environments where security failure is not just what the data does, it's physical safety risk as well in my mind. Right. So many enterprise security strategy treat OT sort of as or operational technology as someone else's problem. It is my problem. Right. Um, can you think about this principle being applied to a real scenario like this?

Speaker B: Absolutely.

Speaker A: Like how would they think about it?

Speaker B: And it's quite interesting you mention it because that is actually a solid component in most safety frameworks when you operate in ot heavy environments. So every time you have a safety failure, there has to be a lesson learned that is part of the compliance frameworks for it. So if someone drops a tool, you have to have a lessons learned sessions on this because that brings risk for people to, you know, have a tool dropped on their head or something. So you go through a lessons learned loop where you talk about how did we end up in a situation where a drop tool infringes a risk on people below us. And then you start introducing this is one of the reasons why hard hats are required at uh, construction sites, for instance. Right. Is also one of the reasons why when you worked on an oil rig, you will, every time you go out of a doorway, you look up before you move your body fully out because it's so into your personality after it.

Speaker A: Right.

Speaker B: This is antifragility. Imagine applying that towards your organization, applying it to other areas. It doesn't have to be as extreme environment where you know, an oil rig obviously operating off the coast somewhere, harsh environment, very dangerous, uh, setting for everybody. Right. So everything you do is safety related, but from a technology perspective as well. If the technology acts differently than we intended it to, or we um, um, thought it would, predicted it should, then what do we learn from it? Right. Going into that phase? Almost like a manual behavioral analysis phase. Right. And I think that's how we should think about it, to be honest.

Speaker A: And how long does that imagine? I feel like, um, imagine is one of the most important aspect. I'm connecting what you said earlier about the outcome comes predictability and not being hard about it, being fragile about it. Almost like what if analysis, that is your imagine phase. And I guess that phase informs the rest of the invest and you know, the rest of the phases as well. How long have you seen somebody trying to do that? Um, does it take usually?

Speaker B: So it varies a lot if you want to be. And I can give you a very specific and very easy example actually for, for everybody to leverage today, maybe not today, maybe tomorrow, then but if you take um, and again cybersecurity lens here, if you take uh, an incident that hit uh, uh, media, it could be. Well we talked about AI earlier so. And anthropic has openly shared how uh, threat actor compromised infrastructure through the use of MCP servers. Right. So the technology used in the AI uh ecosystem. If you take an incident like that and you convert it into almost like a tabletop exercise for the executive team in an organization, you say okay, so what if, let's imagine that we are now anthropic, this, this is happening to us. There's uh, a threat actor that operates within our environment and they're using our tools against us. Is there any way where we would actually be able to see that? Is there any way where we could detect the entry point of this? Because at first it looks like normal behavior. So are we looking at when behavior changes? Who's looking at that by the way? Who's accountable for that element? And that's an easy way to have the imagine session at a very low key. No investment is required at this point. This is just a uh. Let's think out loud about this scenario. You can also align it to. Has anything changed from our last incident? When was the last time we had an IT or service breakdown or something? What did we learn from that and what did IT change in our business, in our processes? And then you will find that a lot of organizations um, just being very open and blunt here, a lot of organizations do not have a link from that IT service disruption or degradation to a clear learning to a uh change. So I think that's, that's probably a good way to start it easily.

Speaker A: I mean, yeah, this is so similar to how I think about the simple agile mindset works, about the storyboarding, then doing your sprints and having a feedback loop. Isn't that what we are really talking about? That plan, all your scenarios, those are your story points and storyboards and then go execute them. Invest in that and learn from everything and improve with the feedback. So that's it.

Speaker B: Now we're coming back to the flywheel effect of feedback loops. Right, right, right.

Speaker A: Okay. Uh, one cool question. Uh, because of self interest I'm here in North America, you're there in northern Europe. One of the, your market in my opinion is one of the most security mature market with the GDPR and being first to implementing things for privacy, security and things like um. So in your position for one of the largest cybersecurity company, when you compare how organization there in northern Europe, think about Security versus what you hear from US Enterprises. What's the gap that you observe from your vantage point?

Speaker B: Yeah, that's, that's a very good question. Strong question, actually. I think in, in Northern Europe, a lot of organizational and a lot of leaders, uh, apart from being very international in the communities, there is a lot of different cultures that they cater for. They're very pragmatic and you know, in, in, in a. And I say that in a positive meaning, even though it looks different on my face. But I mean it positively right. They've ever pragmatic. They will go, like we say, straight to the core of the business. And, and, and they're immediately focused on what's the return on investment on this. Not at a high scale. On every little. This is not.

Speaker A: You're talking about.

Speaker B: Yeah, Northern Europe. Yeah, in Northern Europe. Northern Europe, unlike that, very specific to the point. So this leg of the activities that we're going through, what is going to be a return on investment? Is there going to be an investment and then is there a return on investment on this and then they take the next step. So it' an iterative process they go through that can be quite heavy sometimes and sometimes it slows them down in the decision process as well. Whereas a lot of the US based companies are very holistically approaching this and looking at, okay, so there's a, there's a significant investment. What's the return on investment on this? Um, and how soon do we realize it and what does it mean in the long term? And I'm not saying that Northern Europe isn't doing that, but they're doing it afterwards. And in America, a lot of the US Companies that I've talked to, uh, the other way around, they start with the high level and then you go to the. I was about to say nitty gritty. I didn't mean it like nitty gritty. But then you go to the, to the details and the specifics. So I think that's a big difference actually also in how you have the conversations and what has to be done at each step. Suddenly, you know, you, you have to have everything clearly defined first in Europe, whereas in the US we can define it together afterwards.

Speaker A: Okay, okay, so, so Europe is more incremental and tactical in detail first. Us, uh, is sort of more, um, North Star. Let's figure out the North Star and we'll figure out the details as we go along in the strategy. Okay, very cool. Super. I want to move on to a topic, uh, closer to the framework because if somebody's Trying to follow this framework of building, um, antifragility in their company because now they want to be able to respond to AI attacks and everything else on the planet. Um, I think one of the hardest thing for somebody in the power of position is to get that budget.

Speaker B: Yes.

Speaker A: Um, right. Because budget planning conversations are happening right now. Uh, they need to justify shifting spend from like reactive security tools, like you said, towards building this kind of anti fragile capability. What's the argument that actually works with a CFO or the board? I want to take advantage of you having this vantage of talking to so many people so you have so many data points. Tell us what works with the CFOs and the rest of them.

Speaker B: Yep. So there's a couple of conversation tracks that I typically have. One is AI forces AI to be in use. Right. It's not the fear of missing out anymore. It was last year, everybody wanted to invest in AI because everybody else was doing it was the notion. And at that time I actually compared it to when my daughter came to me at a young age and said, I want a phone, dad, because all the other girls have phones. Um, and then you start realizing, no, they don't. Similar, um, that what happened in AI last year.

Speaker A: Right.

Speaker B: Um, this year is slightly different. Um, I think it's important to understand that AI is happening all around us for everybody, individually, organizationally and politically as well. Right. And everything we do in that space is requiring us to do certain steps to be able to actually move with that pace as well. So if you are investing in AI, which I'm assuming that you are as a professional organization, whoever it is tapping into to the podcast today is, then you also need to invest equal amounts almost to securing it, unfortunately. Um, because it moves so fast and it can very quickly be that point in time where you receive a phone call, the reception, the one phone call that you're going to hate the most is, hey, this is Auditor X who's accountable for the outcomes of that AI solution. And you want to have a clear answer to that, but you also want to have the evidence that supports you towards. You did everything you could to ensure everything is in order and buy the books and following all the rules and everything. And it didn't do anything it wasn't supposed to. Right. So investing in AI requires investing in securing AI as well. The other compelling, um, argument that I very often use is, and we had this discussion in a world of academia not long ago, where I recently finished a study on this as well, where we were talking about AI and The impact it has on data, not data from, uh, we feed data into the AI as such, but part of it, but data in terms of recovery. So most organizations today will use AI with a link to sort of the three overarching data elements, open source data, uh, uh, proprietary data or hybrid somewhere in between. Right. Um, and the challenge is not using the data as such. The challenge is safeguarding the data set so it doesn't become poisoned or influenced by others that you did not intend for it. Because that can alter the outcomes of the AI solutions you're using. Right, but what if something happens with the data set? Let's say you have a ransomware attack and they encrypt your whole data set and you don't want to pay the ransom, because that's generally the advice, don't pay the ransom. So you lose the data, but that's okay because you have a backup in place. So you restore the data from, uh, a backup. The challenge with that restoration process is it does not cater for, it's a very strict IT or technology process that you follow. Right. But it doesn't necessarily cater for AI from a training data or inference data perspective. So what you actually risk now is reintroducing some of the data points that the AI model has already learned from. This means you're actually doing reinforcing on some of the terms and some of the data points in there. Meaning that you, uh, actually somehow introduce sort of a bias into it and that means you will, over time you might risk degrading the performance. So when will you realize this if you have not invested in the security around this and understanding all of this. So I'm not talking about investment here from a. I want to go out and buy this technology. No, I'm talking about investing the time to understand what this would mean for you with the existing processes you have in place. What would it mean if I had to restore the data sets for the AI? Will we lose some of the outcomes? Will it alter some of the outcomes? How is this going to impact us? And that usually requires an investment in skills and data analytics. Sorry, that was a very long answer. But, but it's one of those talking points that not a lot of organizations are talking about yet, but I think they will.

Speaker A: And so if I'm, I'm applying for security budget, then I have to show the art, uh, of the impossible in a way that this is all the things that can go wrong and happen. Is there a simple, uh, rule of thumb maybe, like if you're investing, um, x amount in AI for innovation or improvements then some percentage of that should be around building the governance and security around it. Could there be a thumb rule like that or.

Speaker B: Not yet, but I think we're closing in on it. I talked to a few professors around and we discussed it uh, in a smaller group of executives and the outcome was based on the learnings currently and what we've learned in the past 12 to 14 months. I would say the investment looked like every dollar you put into the AI you will have to spend between 33 and 50 cents on the dollar to continue um, the life cycle of it. So after deployment that's going to be your almost towards the run cost of it. Right. So I think that's probably the closest we are right now. It includes a lot of the elements that I've already talked about. You know the continuous improvement cycles and the storage and the life cycle management in general for the um, uh, uh, for the ecosystem and the data sets as well. It doesn't pinpoint security costs directly but I think that's going to be the next natural step of this. Right, awesome.

Speaker A: Okay, let's move on. Let's say I'm the enterprise uh, tech security leader in across the world. I could be anywhere. Um, I'm very curious to find out that what are the buzzwords or not just buzzwords. What are the most strategic investment areas in cybersecurity that Jasper hears that the leading companies are talking about? I Want to know. 1, 2, 3, 4 are the hottest area where investments are actually going today in cybersecurity.

Speaker B: I think observability and visibility across ecosystem. That's definitely one of the big investment points. Um, understanding what you have in your ecosystem from both a data stream perspective. So you can start having different data streams for different purposes because this leads to the next very big strategic conversation you might have in the enterprise which is data investment planning. So how much of your proprietary data are you willing to invest in this AI experiment? That's uh, a good conversation and that requires observability and visibility into data streams. Big investment point. The second big one would be data security. A lot of conversations around how do we then structure and govern security uh, around the data sets themselves, whether it's hours, uh, rented data or borrowed data, whatever we call it, how do we then keep it safe and secure um, from whatever risks there might be. Um the third element would be integration security. So with the introduction of AI agents we are going to see a web come over the ecosystem, the digital ecosystems in the enterprise and part of that will entail a lot of your existing tools. There will also be a lot of new technologies and new tools coming in. So it expands your internal attack surface significantly. And then the AI agents, the more efficiency you want out of them, the more direct integrations you provide them. And the integration security is one of the elements where we haven't been focused in the past. I would say we've talked a bit about API keys and secrets and stuff like that. But this is also one of the areas where a lot of organizations fail from a security perspective today. Right. So imagine what happens when you introduce one AI agent and your business processes start depending on it. Then you introduce a second. Now you start seeing a return on investments. You introduce a third, a fourth, a fifth, a tenth. And now you open it up so your employees can have their own personal agent. Imagine the web you're going to have and then focus on what will happen if a cybercriminal decides to cut some of the integrations or listen in on some of the integrations.

Speaker A: Right? Yeah, yeah, yeah. I think um, the third one is, is, is something that I relate to very, very much, which is the integration one that you said. Because I don't think people, ah, or experts still understand this, that it is not just about the agents that an enterprise is builds. Um, all the systems that we built, whether it was a SAP, Oracle, CRM, erp, anything that we expose externally was built for human beings. Right. If I need to be in business next year, I need to prepare this for agents to be able to access it. Otherwise I'm, I'm not relevant in the times. Right. That means I will have to have an agent exchange layer that will interact and expose my data to every external agent. And that is a very different beast in itself. If you think about it that, you know, you're speaking about the uh, internal agents. I'm thinking even if I don't build an agent, the rest of the world, my partner, my supplier, my customer, is building an agent and want their agent to be able to access me. So that means I need to be working on this layer and who's going to protect this layer. So uh, I think uh, yeah, that's the thing that I feel like is very relevant.

Speaker B: And then imagine when the agent starts building new integrations themselves because it's a more efficient way and you didn't confine it and constrain it at first.

Speaker A: Yeah. Okay, cool. Now I'm not the security expert at the enterprise tech. Now let's imagine I'm a security company. Company like A partner or IT company like Palo Alto or maybe a service company. I want to know uh, from your lens that uh, what do you think is like happening in the market? Where should people focus on? Is this. The three things are the offerings that people should double down on. Is this what's resonating the most in the market?

Speaker B: Yeah, I think so. I think the observability where you are able to, and you see the cybersecurity industry going in that way direction as well is how can you sort of break down the view of the AI solutions that are being in place, so detecting and discovering um, models in use and data sets that are being accessed and users accessing different uh, tools and solutions both internally and externally. I think you're seeing a lot of investment into that area and a lot of interest and driving towards that area. Um, this is an area where we're heavily invested in as well. Right. The whole AI runtime security, um, environment. So that's definitely one industry, um, response to uh, all of those needs. The other element is you are seeing an uptick in general around identity security because all of a sudden we realize that hey, if agents are behaving more and more like humans, but in real time, milliseconds of activities, we have to be able to assign it an identity so we can differentiated from other activities in the environments that we operate in. So identity security is uh, another huge part of uh, the industry focus right now. Um, and I think that last leg is probably going to be. It's not that big right now. It is in early stages, but I think we're going to see more and more of it. And this is around data security. Imagine um, if you're able to split data at the creation point, you can split it into business data, needs, operational data and security data. If you do that split in, then it will also allow you to segregate the data streams and that means a compromise of the security data can be protected, a compromise of the operational data can be protected and a potential compromise of the business data could be protected because now we know what data it is. Now it's not just a chunk of data being hauled somewhere centrally. It also allows us to build for the anti fertility that we talked about earlier that now you can actually run the business data to a certain location, uh, where it has a distinct purpose. So purpose led data hoarding almost. Right. So I think that's going to be.

Speaker A: You almost gave the offering name to a lot of companies over there.

Speaker B: Yeah, I haven't seen the solution yet, but I Would love to, to see it.

Speaker A: So, all right, I'm going to switch, uh, you know, my role again. I'm a security practitioner, um, millions of security practitioners out there, I'm speaking for them that um, they're watching this and asking do I still have a career in five years when everything is changing so much with AI, uh, help them and help me understand which skills does AI make irrelevant and which ones does it make more valuable so that our community can focus on those.

Speaker B: That's a really good question. I love that. I love working with academia in general and you can probably tell um, by some of the examples I had, um, and the feedback I get from a lot of students and they're looking to, we want to go into the cybersecurity, uh, career path. So we're training ourselves on all the latest uh, threats and trends and everything. And I always tell them, and this is why I use this example to answer your question, I always tell them this, that if you focus on what has already happened, um, you're probably not going to have a job in two years when you're uh, finalizing your education. You should focus on what's coming and prepare yourself for that. So we know AI is coming, AI is coming to the security teams as well, right? So educate yourself towards AI, understand how it changes technology from an architectural perspective and understand what AI can do for a security operator. And this takes us back to if you're used to doing data correlation, I mean I grew up in spreadsheets, right? You had log data from somewhere, from this system, from that system. If that is where you are at the moment, moment right now, then focus your, your energy towards how can I use AI to, to do some of this stuff for me. Because that is, is going to happen eventually, right? All security tools are moving in that direction with a built in co pilot that you ask questions in, in natural language and it will respond with recommendations, maybe even playbooks and everything to you, right? So understanding that, educate yourself on the, the, the new and upcoming security technology. But the biggest differentiator for security professionals today is get close to business. You need to understand what it is you do and how it connects to the business ambitions. So if you're doing something that isn't connected to the business ambitions and doesn't support, maybe even doesn't propel it forward, how can you get to that point where you can help accelerate business ambitions that will ensure you have a career for now and for as long as you want?

Speaker A: Right?

Speaker B: If you can make business your driver from a security Perspective, you become the enabler of the business, and that will ensure your job future.

Speaker A: Yeah, very well said. Very well said. Okay, um, I have two questions left, and both are personal now. Not about, um, not about, uh, the security market per se. There may be some relation that we can drive from there. One is that, um, I have done few podcasts with the security leaders and uh, funny enough, I'm seeing a correlation between a lot of military professionals. One of the best conversation I had was with, I think, uh, Alfredo Hickman from Obsidian Security and then with Mark Brady from kbr. And almost everybody had this military, Marine Corps, uh, sort of background. Uh, is there a certain thing that gravitates the protectors towards this? Because the role is still theater, right? Protecting the country, protecting the citizens, and now protecting organizations. What is this? Do I have a confirmation bias or there's something real behind. No, I am.

Speaker B: I, uh, actually agree. I meet a lot of security leaders who has, uh, a military background. Um, and I think one of the elements is we're very passionate about our jobs, but we also carry, um, a few elements that I think a lot of people who haven't served in the military will have to achieve, uh, some other way. Right. One of them is strict discipline. Strict discipline is something that you. It can very easily translate into, uh, a value skill during an incident. If you follow strict discipline, you follow, you know, the protocols and what you've agreed to do, and it will help you to define, you know, those, uh, uh, processes that you need during incidents. And at the same time, most m. Former military people have, um, a higher threshold for stressful environments.

Speaker A: Right.

Speaker B: So operating under the stress of a cyber incident, if you compare it to the stress that you've experienced in the military, especially if you've done service tours or tour of duties, um, nothing really comes close to that. Right. So I think that gives an advantage in some cases, but those are very, very closely tied to the military aspect. The other thing I think, and this is not because everybody can achieve the skills required for it, right? But I think it's also around the notion or, uh, train as you fight and fight as you train. So continuous focus on, if we do this enough, it's going to be easier for us when we're in the position of actually needing it. And I'll share one of the learnings from the Notpetya incident in Mascores that, you know, it's great to have a plan, but if the plan is on a computer that's unavailable, it's of no use. Uh, it's great to have a call out list where all the phone numbers on. But if the phones were software based and on the computers which aren't working, how are you going to communicate? I mean all of those elements.

Speaker A: Right.

Speaker B: Start thinking about it and then practice, practice, practice. Because the more you practice the easier it is when you find yourself in the fight.

Speaker A: Yeah. I think honestly for a lot of military professional, first of all, thank you for the service that you do and thank you for choosing to even in a commercial setting, still playing the protector role, which is very important and sometimes underappreciated. So thanks for that. Um, my last question is that um, how do you see. I think we spoke about a lot of fear. Um, and in every security conversation I feel like they're doing some fear mongering of this is going to go wrong, this is next thing is going to wrong. What excites you about this market in next three years? What are your two or three things that is really exciting for you to look at? Um, happening. Good.

Speaker B: Yeah. Oh, that's a great question. I think the thing, the one big, the big thing that really excites me is how more and more executives are getting cyber savvy. Right. They're starting to understand the dynamics of the cybersecurity world. I really love that because that means that you're going to get a lot more engaging conversations and they have a lot better grounds for understanding sometimes when, I mean, let's face it, sometimes we are too geeky when we start reporting as uh, security professionals, operations upwards.

Speaker A: Right.

Speaker B: And when we report in metrics they've never heard about. Right. So, so I'm really excited about starting to get qualified questions back. Even the question, what questions should I ask you that I haven't asked you already? I love that question. Right. And then I can give them an opportunity to, to or at least I can try to educate them at least to, to next round of questions they can ask to me. Right? So that's the one big thing that I'm really excited about that is changing. The other thing is everything that's happening around A.I. uh, great promise for a lot of things and I think we're going to see a lot of learning opportunities and uh, I talked about it earlier. There's going to be tons of failures. Right. Embrace them. Because we are at that point in time where a lot of those failures are going to happen so fast and it's going to be really hard to figure out what actually went wrong because we're experimenting all the time. So we'll move on, move on, move on. But it has a unique opportunity for us all to learn a lot from it and then continuously improve. So that's the second element. The third element is very technology based. And now it becomes geeky. I love Quantum. Uh, Quantum is going to be so much fun. And, uh, it's gonna. I know. And back to what you said about the fear mongering. I'm not gonna go into the wolf cries or anything, but anything that has the potential to change how we see the world, how can we not love that as technology? Minds and passionate people. Right?

Speaker A: Yeah. And who knows? It's a great equalizer against the speed of attacks for AI. It is. It is a great, great leveler to protect us from.

Speaker B: Could be.

Speaker A: Yeah.

Speaker B: I mean, it can disrupt everything from, you know, medicine to communication to everything. Right. So I'm really excited about that part. It's going to be so much fun.

Speaker A: Yeah. And this conversation was so much fun. So thank you so much. Jesper. This was one of the best cybersecurity conversation I had and I hope everybody else enjoyed that. But I wish you and Palo Alto the best. Uh, and thank you for being and so gracious enough to share all the knowledge that you.

Speaker B: Thank you so much for having me. And, uh, anytime, anywhere, give me a ping and I'm happy to jump on again. Especially if we're talking about Quantum. Think about that for another term. But thank you so much for having me.

Speaker A: Absolutely. We have to come back to that.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Cyber resilience87 / 100
  • Steal Big Tech's Playbook For The Worlds Best Comp PracticesFNDN Series · on Palo Alto Networks87 / 100
  • Why 95% of AI Projects Fail and How To Beat the OddsModern Business Operations · on Antifragility82 / 100
  • 401 Access Denied Podcast Ep. 120 | Bridging Borders: How INTERPOL Tackles Cybercrime Worldwide with Craig Jones401 Access Denied · on Notpetya attack82 / 100
  • Building Action1: Mike Walters on Patch Management, AI Vibe Coding, and the Power of FocusCult Products · on AI-powered attacks81 / 100
  • Ep. 8 CISO Sebastian Goodwin on Advising DSPM and Automation StartupsGenealogy of Cybersecurity - Startup Podcast · on Palo Alto Networks81 / 100

More from CXO Spotlight

All episodes →
  • 10 Acquisitions. 10 Legacy Systems. One Year to Transform and Deploy AI90 / 100
  • This CIO is Making Her Entire Enterprise AI-Ready | 29M Students, Cambium Learning Group71 / 100
  • A Top 10 CISO on How to Actually Sell to a CISO (and What Vendors Keep Getting Wrong)76 / 100
  • An AI Just Out-Hacked 2 Million Humans. She Decides What Happens Next | Nidhi Aggarwal, CPO HackerOne80 / 100
  • Why Strategy Is the New Operating System - C1's CSO on the Bold Moves That Matter
Explore the best B2B Marketing podcasts →
All CXO Spotlight episodes →