
Cyber Leaders · 2026-05-29 · 44 min
Key moments - from our scoring
Substance score
69 / 100
Five dimensions, 20 points each
Simon Vernon has spent eight years building SANS's cloud security expertise and practical learning platforms, including the CTF (Capture The Flag) environments like Jupiter Rockets and Telnet International that let security professionals practice exploitation and defense in safe, realistic cloud environments. His work addresses a critical gap: while cloud technology has matured significantly over the past decade, organizations continue to misconfigure cloud infrastructure in ways that create easy attack surfaces for adversaries. Vernon's background - from early computer experimentation through a parallel career as a mechanic (he maintains a 35-year-old Land Rover) to becoming SANS's chief architect of hands-on security training - informs his conviction that learning by doing, not just reading, is essential for building real cyber capability. Through the ASAP platform and Boot Up CTFs, he's created scalable ways for teams to identify skill gaps and practice together, while keeping these opportunities free and accessible to underrepresented groups in security through targeted events for HBCUs, women in cybersecurity, and other demographics.
CTF (Capture The Flag) environments like Jupiter Rockets and Telnet International are cloud-based hacking platforms where security teams practice exploitation, defense, and investigation in safe spaces. SANS uses them both for individual training and to assess skill gaps within SOCs and incident response teams using the ASAP platform, helping organizations identify where additional training is needed.
Simon suggests that despite cloud technology being well-established, organizations haven't fundamentally changed their approach to cloud security architecture and configuration, continuing to create easy attack surfaces that adversaries exploit - making it an undeservedly easy target for cybercriminals.
Boot Up CTFs are free, community-based, 48-hour Jeopardy-style competitions tailored to specific demographics (historically Black colleges, women in cybersecurity, AWS practitioners, etc.), allowing participants from different regions and backgrounds to practice without barriers to entry or complex progression requirements.
ASAP (Applied Skills Analysis Platform) is SANS's analysis tool built from CTF environments that measures abilities and skills within individuals and teams, identifying specific gaps so organizations can focus training efforts on areas where additional capability is required.
Vernon has a distinct learning pattern - he retains information by doing rather than consuming content - and believes many security professionals learn the same way, making hands-on practice essential for making theoretical and academic knowledge real and applicable to actual threats.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid tactical and strategic insights about cloud security, AI adoption, and practical cybersecurity training, with specific problems identified (identity management, hardcoded credentials, policy-CEO gaps). However, substantial portions consist of personal anecdotes, banter, and tangential storytelling that dilute insight density. The core substantive content - particularly on AI's dual-use threat potential and cloud misconfiguration patterns - is strong, but padding reduces the overall insight-to-time ratio.
managing users, and just doing the basics... hard-coded credential stored in a file, stored in a server somewhere, unsecured buckets, etc. All of those traditional weak spots
attackers can scope out and identify the traits, the language, the behaviors used within an organization and become a part of that organization
Simon offers solid frameworks - hands-on learning superiority, AI as productivity tool with inherited flaws, identity as persistent cloud weakness - but these are largely established positions within the security community rather than contrarian or first-principles challenges. The specific insight about AI mimicry and neurolinguistic programming applied to social engineering is fresher, and the acknowledgment that more AI tools with more inexperienced developers may net worse security outcomes is sobering but not entirely novel. The framing is competent but not distinctive.
AI is touched by everybody. So every person in the organization is going to use AI, whether the organization wants it or not
we've also got 10 times more people without any experience writing code. So is it gonna get any better?
Simon Vernon is a genuinely senior practitioner: Director of R&D at SANS, teaches three major cloud security courses, runs the Institute's CTF exercises at scale (110+ community events annually), serves as CSO of a data center company, and has demonstrable hands-on expertise across cloud architecture, incident response, and security training. He is not a career podcast guest or pure thought leader but an active builder and operator with real responsibility and technical depth.
he's designed some of Sans's most important and successful courses, he's pioneered and run some of the most celebrated Sans experiences
I teach an engineering class, we teach an architecture class
Simon provides concrete examples (the $2M EDR/XDR breach in 2 hours via hardcoded credentials, CEO Chat GPT data breach, 110 boot camp CTFs run last year, AWS/HBCU-specific events), but lacks quantified metrics on outcomes, success rates, or validated improvements. The hardcoded credential and unsecured bucket examples are real but generic to cloud security doctrine. Specific numbers appear sparingly - mostly around event counts rather than measured impact or validated learning gains. More research citations (Opus, VeraCode, Endor Labs) come from James, not the guest.
they had a hard-coded credential stored in a file, stored in a server somewhere, unsecured buckets, etc
we ran about 110 of those events last year
James asks strong follow-up questions (on AI mimicry, implications for defenders, surface area expansion, CEO policy failures) and pushes for pragmatism rather than optimism. However, the hosts frequently veer into extended personal anecdotes (Kieran's opener on his own hacking past, discussion of Land Rovers, fictional t-shirt ideas) that derail momentum and dilute focus. Kieran's humor-driven hosting style, while personable, prioritizes banter over probing Simon's claims on training ROI, CTF measurement rigor, or policy enforcement mechanisms. The 30-second takeaway question is strong, but overall the conversation lacks sustained tension or challenge.
I'd like to say, I got a million things I'd like to say on that one
Well, I think it's flattery of the highest order, actually
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Ciaran and James sit down with Simon Vernon, Head of Research and Development at SANS Institute, to discuss cloud and AI security. As a practitioner in the field, Simon shares his experience building hands-on training, where cloud security still goes wrong, and how AI is changing attacker behaviour and creating new risks. Contact: Have questions or comments? Email us at cyberleadersnetwork@sans.org
Transcribed and scored by The B2B Podcast Index.
Welcome to Cyberleaders with me, Kieran Martin. And me, James Line. Now we're both from Sands who are kindly backing this podcast. I myself am a massive geek, and basically since I was zero years old, I've been spending my time hunting criminals on the internet.
I'm less of a techie, as anyone who watched me try to log on to this podcast recording will have realized. I dealt with cybersecurity policy and operations in the UK government and set up its National Cybersecurity Centre. But nowadays, James and I are together trying to unpack the weird, wild, wacky, wired, wireless other things, world of tech security and all the complicated things that it involves. And in your defense, Karen, opening a link for a podcast is quite technically challenging.
It really is, particularly at these unsettled times, you never know who's out there. It's HRFs are extra hard. But anyway, this podcast is a voice for security leaders. We want CISOs, security directors, and frankly everyone beyond to build up their knowledge of what works, what doesn't, and ultimately secure their organizations more comprehensively and quickly.
End of standard intro. Actually, no, that's what it says here. No, let's talk about this standard intro of yours, James. I want to talk about it.
The bit where I say my name? Yeah, I'd like to talk about your name. No, of course not. Well, which bit do you want to talk about then?
Um I d I can't remember. Sometimes I pay close attention, sometimes I pay no attention. Maybe it's that bit where you say something like, Are you or have you ever been a member of the Communist Party? Something like that.
No, it's the bit where you say you've always been a hacker since you were minus one or whatever, breaking into computers since you were a baby, whatever that is. I'm not sure I put it quite like that, Kirod. Or Joe McCarthy quote is arguably a little closer. But what I do say very often is that I'm a massive geek and I've been breaking things and making life tough for the cybercriminals for well as long as I can remember.
Well, indeed, and that's the bit I want to talk about. Fine, got it. And the spelling of my name, presume, of course, but what do you want to know? I want to know how you learned.
So I'm older than you, considerably older, several decades, I think, before we came on air, as I was struggling with my link, you were asking me about my memories of the Great Depression or the Napoleonic Wars or something, I can't remember. But when I was growing up, yeah, but I think even when you were growing up, I don't really recall many books called hacking for toddlers or whatever. So how did you learn to indulge this geekdom of yours and become the deep technical expert we know and love so well?
That's a good question. I really fell into it organically. I mean, I got a computer relatively early on. What was it?
It was actually a really old Apple Mac. I think it was a quadra. That may have been my second one. Right.
They blurred together a little bit. An early version of Mac OS. Absolutely terrible by today's standards. And look, I was there as, you know, the internet was starting to speed up.
It was, you know, predating the browsers we'd recognize today. It was CompuServe and AOL. And there were various communities running. On modems, of course, good old modems.
I can still whistle and hum and create a modem pickup tone. And uh I started participating in these communities and playing with software and learning to program. I remember my first book, as you say, there weren't many hacking books, but first book on HTML version 4 and CSS 1.0 and VRML, virtual reality modeling language.
I just love the way you're talking about this, as if it's ancient Rome and you know, this book on VRL and so on, it was like the Iliad and Ancient Greece, something, you know? It kind of feels like that at this point compared to where we are with AI and modern technology. But yeah, look, the long and short of it, so I don't take up the entire podcast of this background, is I noticed that you could kind of trick applications and code into doing things they shouldn't. And that fascinated me.
And then I ended up in a bunch of slightly naughty, but definitely not absolutely criminal forums with people figuring out, you know, exploits and vulnerabilities and malware, and well, one thing led to another. Just pointing out this is an international podcast, but there's no statute of limitations in this country. Now you're probably wondering why I'm asking you all of this. I I am.
Yeah. What's with the random questions? Isn't it supposed to be about the guests? It is.
Well, this is about the guests, because I know I'm being incomprehensible even by my normal standards, but I'm going to bet that at least one of our listeners, one of their listeners who isn't listening under duress because they're in prison or there's some court order that mandates they have to do this as punishment, they have had their massive geekdom enhanced by dealing with today's guest. Because not only has he designed some of Sans's most important and successful courses, he's pioneered and run some of the most celebrated Sans experiences, those capture the flag and other hands-on practical exercises that are continuing to produce the new generation of James lines.
Now that may be a prospect with fill you with joy, or maybe fill you with horror, but I leave that to you, dear listener. Why choose Kieran? Why not joy and horror simultaneously? But yeah, you're right.
And yes, this is where it all comes together. I see your plan now. If you've ever been to Cyber Threat, that's our brilliant threat conference that we run every year in London for hands-on geekery of the highest order, or at all sorts of different events, frankly, you will have felt and lived the buzz of some of the greatest cybersecurity experiences on earth, but at least the legal ones per our introduction. And we're going to be discussing this further with our incredible guest today.
And of course, much more of the podcast goes to standard recipe. And length. Because today we're joined by a true great. The man who not only develops designs and runs all these incredible exercises that lets budding hackers, reverse engineers, malware analysts, and more practice hands-on, but also teaches three of Sans' most important courses, all on cloud security, on which he is a deep expert, a world-renowned practitioner.
And somehow, in between that, he finds time as well to be the chief security officer for a data center company, a board member, an advisor to some nonprofits, and a highly skilled recreational auto mechanic, perhaps reflecting some of his earlier pre-cyber career in Land Rover. Starting to make me feel quite incompetent here, Kieran. He's been lauded by leaders all over the world, and he's won as well as written a lot of cyber competitions. And to be clear, the ones he won are not the ones he wrote.
He is the director of research and development of the Sands Institute, the legendary Simon Vernon. Welcome, Simon. Thank you for coming onto the show. Thank you for having me.
Much appreciated. We are delighted to have you. Now, in that record-length introduction, for which we apologize, hopefully some of it was at least deservedly flattering. Uh, when James wasn't inciting young people to cybercrime, he was talking about the way in which you develop all sorts of talent.
But I want to talk about how you developed your own skills. So we asked everybody this question. So you've been with Sans for about eight years. There's a whole community of fans of yours out there.
They've been through your Capture the Flag exercises and or they've been on your cloud security courses. But they may not know a great deal about your earlier career. Maybe, like me, not much is known about it because according to James, I was born before records began. But in your case, how did you get into this whole business and how did you end up where you are now?
Well, I'm not that much younger than you, so it's quite a long story. Go for it. Um but I will keep it relatively brief. That'll be a first in this podcast, but go ahead.
I also had uh rather a mischievous edge to me, especially uh in my younger years. My first ever computer, I think, was in the late 1980s. Wow. It had a rubberized keyboard and a tape player attached to it.
As part of the learning process of that, I spent an entire day writing this huge amount of code. I can't even remember what language it was in. And then when I executed it, a man ran up a pyramid and then down the other side, and then the program finished. And that was it.
And to me, that seemed like a colossal waste of time and energy. But he did teach me a lot of things that meant I could then explore and work out what these, you know, newfangled devices could do. I also had an exceptional teacher at my uh first high school, who was a chap called Mr. Ferber, um, who I never got the opportunity to thank, but he incited me to push the boundaries of really what was possible at that time.
He got me into things like BBC computers, he got me into electronics, and that really carried forwards everything that I did from that point onwards. So from about the age of 12, 13, if we had anything electronic in the house, it came to bits. By the time I was 14, most of it went back together. Right.
Sometimes functionally. Much to the annoyance of my parents who were very patient. Did it ever have new features, Simon? Well, I mean, new features, spare parts.
Yeah. And that then continued. Now, I did get myself into a little bit of trouble when I got to my second high school, where I had an ongoing battle of the wits with my uh deputy head teacher, who was also the IT operations manager, about who was running the school network. Ah.
And he won, but he kind of cheated because they asked me to not come back to school for a little while to give him the opportunity to bring things back into reality. If you'd been American, this would have been a Hollywood high school movie classic. It would be in the all-time list. Um we've we've missed a trick here.
It was good fun, and I have recently been invited back to the school to actually help them solve a problem. They have some students who were uh playing poker during the lunch break with the parents' credit cards. Okay. We'll help them lock a few things down.
Well, this is the sequel to the movie. So yeah, I was kind of kept away from computers for a little while. Yeah, can imagine. And I was basically told that I wasn't allowed to sit around the house all day because that was dangerous.
And so I had to be out of the house and uh I got myself a job working in a garage, and before I knew it, I was taking electronics apart in cars which were just going through this transition of having very basic electronics to having onboard ECUs. And then it just went from there, really. About five years later, I discovered that computers hadn't changed in any way. I still fully understood exactly what they were doing, and it was an off-chance chap who turned up in a garage who had a computer that didn't work.
I fixed it for him as well as several other things, and he paid me more money than I'd earned in the entire week in the garage. Wow. I realized that actually I could probably do this, earn a little bit more money, and be warm in the process. Right.
And that was it. But I still have all of my mechanics tools. I've got a 35-year-old Land Rover, which I mean, if anybody owns a Land Rover, you'll know if you want to use it, you have to fix it first. Right.
You have no idea what you just offered. That was a mistake. Just please hang on after we've stopped recording. Now, look, we've so much to get through, and we could spend the whole podcast talking about your double career in cyber and tech and computing and in mechanics.
But I'm gonna go straight to where we are now. And James, I'm sure, will ask you some very insightful questions because he's smarter than me about the role of practical learning in cyber and so on. But let's dive straight in. You and I have worked together last December.
We were in London at Cyber Threat, and I was essentially a glorified compare saying the next excellent speaker, and they were all excellent, is so-and-so. But whilst I was doing that, you were running an incredibly complicated competition for 400 people. They were all loving it, they were baffled, frustrated, and joyous in equal measure. So I'm trying to research all of this, and I encounter the phrases Jupiter Rockets, Telnet International, Control Shift Delivery, and Operational Meltdown, which sort of reminds me of the name of my brother's sort of record collection of bad heavy metal bands in the 1980s or something like that.
Now there'll be people here listening who say, I know exactly what all this stuff is, but there are others who might think, well, you know, that was also my brother's 80s record collection. So what are these things and why are they called what they are? So these are our CTF ranges that we've been building over the last eight years. So go back 10 years, I got invited onto a Sans training experiment for eight weeks where I lived in a hotel, was taught by James.
Sorry about that. And as part of that process, we also did a lot of things like hacking environments, we built systems to attack and defend, we played net wars extensively. And one of the things that I took away from that was training is brilliant. Training sets the standards and gives you the opportunity to find out things you didn't previously know.
Whereas the hands-on practical experience is absolutely critical to that learning process because you have to have somewhere to practice. And if you go into a SANS course, you will come out with a vast amount of new knowledge, but you've spent an entire week trying to listen to everything that's coming out from the instructor, and you don't necessarily get a massive amount of time to practice. Right. And it's the practice that makes things real.
Because the course content that gives you a foundational knowledge that tells you that this kind of vulnerability can be exploited in this way. And as James used to tell me, you know, well, it can be exploited in that way, but actually you can also do it in these ways as well. I'd have distinct recollection of myself on the Dunning Kruger curve, being sort of the happy and ignorant at the top, and then spending uh three or four days with James before realizing that actually I was in the valley of despair, which is where I've spent most of my cyber career since.
At least it's wet and warm down there. Well, James will have uh much more interesting and insightful follow-up questions, but I just given the story. What did you put on James's evaluation form at the end of the course? We must know.
I can't remember. I think my brain had actually melted by that point. That was Operation Meltdown. That was literally Operation Meltdown.
If I recall, it said something like, make it stop. Something about a hot butter through chicken, I believe. Ah, yes. I actually remember that, even though it was many, many years ago.
I was talking about a blind return-oriented programming exploit, which um I had misclassified in a hands-on exercise as medium difficulty, much to the amusement of the class. And I demonstrated how one would achieve it and use the phrase like a hot chicken through butter, which of course is quite close to what one should say, but a lot more smashy and messy and maybe actually a beautiful metaphor for that particular exploit technique. But anyway, look, with Kieran's weird naming obsessions out of the way, tell us a bit more about the practical hands-on things you do.
So you run these capture the flags and let people train their brains with hands-on skills and work in teams together. You've developed an applied skills analysis platform, cool acronym, ASAP, like that. And I know firsthand you're really passionate about this stuff and enabling the cybersecurity community to better itself. So, how did you get into it?
Why are you so passionate about it? And what's it all about? Um, there's a lot of big questions. Why do I build CTF?
Well, again, I have a very distinct learning pattern. If I do something, I remember it. Other people are really great at reading stuff. There's a vast amount of people who can just watch a video and then repeat something from that.
I'm a doer. That's it. That's as simple as it comes down to. And I believe a lot of people need that hands-on practical experience in order to make a lot of the theory that they're learning and a lot of the academic side of it real.
So James actually uh recruited me into SANS and then asked me to basically turn some of the original CTF environments into cloud-based platforms. And then over the last seven years, we've just run with that and gone beyond where we, I think any of us really imagined what we'd actually be able to do with a CTF. With the ASAP platform, we've kind of twisted it and we've actually turned it into an analysis platform that allows us to measure abilities and skills within individuals and with teams.
So we can actually identify gaps within a SOC team, for example, or an instant response team by challenging them in a CTF environment to solve a whole series of problems in order to be able to then focus their energy on, you know, this is where your gaps are, these is where your, you know, additional training may be required. And this is what we'd recommend you do from there. And I think that being able to play in a safe space is absolutely vital, especially in this current climate.
I received an email a couple of weeks ago from somebody anonymous who invited me to try and break into a system as part of a CTF challenge. And when I looked into it, it looked terrifyingly real. And I suspect it probably was. It was actually somebody trying to incite me to break into something that they wanted access to, which is horrifying.
But again, with the introduction of AI into security and the fact that the attackers are always at ahead of the curve when it comes to adopting new technology. You know, we have got to get people hands-on in safe spaces and being able to defeat the attackers, defend systems, and you know, we give them the opportunity to come across some technologies that they've probably never seen. I love that, Simon. I think it's so important.
And two things I draw out of that that I underline personally. The first, this this practicing as a team and understanding the gaps. It's really easy to look at individuals and their own skill profiles and forget to look at them in macro from a cyber capability perspective. And I know a lot of security leaders are now thinking more holistically about that capability and how they want to build it over the coming years, which I think is really important.
And then there's this second part of it. Do you want to practice when it's in production and the cyber criminals are doing it to you? Or do you want to practice in theory with patience and calmness and learning outcomes before that happens? And it's just such a critical thing to give yourself and your team the time to learn, to fail, to grow.
And that's what these types of activities are really about. Sorry, Kieran, I'm in your way of a question. No, let me jump in there because when Simon said very powerfully and genuinely something I'll remember, that you personally learned something by doing it rather than say reading about it. I've jolted back in my chair because I had two reactions.
One was reconsideration of life choices, given that I spend most of my time teaching in an ancient university. And number two, I'm guessing that this is one of the reasons because you do a lot of these exercises, a lot of this practical hands-on learning in the community. You do a lot of it for free and you organize it where people don't have to pay. That's a very good thing.
And I'm guessing you're trying to get people involved who wouldn't normally have the chance to show their potential. So a lot of organizations try to do stuff in the community, you know, they try to be good corporate citizens, but actually it's quite hard to have an impact. It does feel like you've managed to build a community of people who have been through these processes of stayed in the industry, have stayed in some form of the community. So, can you tell us a bit about the community aspect of this?
How did you get started? How does it work? What are your hopes for it in the future? This was a bit of a crash course during the early days of COVID, actually.
It was discussions with Sans, with James, that we really needed to keep the community together and to keep people communicating. Now, traditionally, cybersecurity people aren't necessarily brilliant at doing this. So we wanted to create an environment where people could come, they could share information, they could chat about the games or challenges. We could bring the people together to be able to talk.
And this is where we created boot up CTFs. So boot up CTFs are the community-based CTF environments that we've now expanded upon. In fact, we ran about 110 of those events last year. They're all community-based.
We run them for very specific demographics, uh, regions in the world. I've just run one, for example, for the historically black colleges and universities in the US. I'm running one for women in cybersecurity next week. We've got an AWS one coming up very shortly.
So these are all tailored towards that particular demographic, but they're also really accessible and really simple. Yeah. They are Jeopardy-style environments. There's no progress that you have to follow.
You can just jump in and jump out whenever you want. And we normally run them for about 48 hours to take into consideration different time zones. And we have built a really robust community around this. And there's tons of information that's been published, sometimes slightly annoyingly, because people document the challenges, which, you know, creates issues for us.
But yeah, I can see that. Otherwise, the feedback for them is generally very good. Amazing. Well, Simon, I could talk about CTF challenges for a long time, but we're going to resist that temptation.
We're going to move on to other geeky stuff. Could get really geeky. Kieran, you can mute if you want to or go make a cup of tea. Yeah, I'll go and do Wordle.
It'll take me about half an hour. Oh, I'll see if you can get a one-hit wonder. Look, Simon, so Jupiter rockets, the Rangers are, of course, you've said, in a public cloud. And building these massive hackable environments where huge numbers of teams can come together and practice exploitation and defense and investigative practices is quite an interesting architecture and technical challenge.
Not something that would have been very easy to do prior to the advent of many of the cloud technologies we have today. It's kind of something we take for granted in a lot of enterprise infrastructure. And if you look at your work or your courses, they're going to kind of learn a lot about how to do cloud more securely. But it is funny, isn't it, that we kind of take it for granted and yet there are still so many misconfigurations and kind of odd issues going on in the cloud.
It really by now shouldn't be a particularly sexy attack opportunity for cybercriminals, and yet it is. So cast your mind back to just over a decade or so when Kieran was in very, very late middle age and the cloud was new. I mean, at least the cloud we recognize today, just like for so many AI is now. And the sort of AI we're talking about now is a bigger change than cloud was then, I would argue, but still a lot of fretting, a lot of worry that the cloud would be like so much other technology, cheaper, better performing, but not very secure.
Some of it turns out more expensive. Tell us a bit more about your work getting on top of cloud security and what you think are some of the biggest lessons in how people have evolved their cloud design and infrastructure over the past few years. It's funny how you compare actually cloud with AI, because they're very similar to a degree in the way that they've been adopted by organizations, enterprises across the world. Cloud has been around for a long time now.
And you mentioned, you know, people still making the same mistakes as they were in the beginning. And it's true. Unfortunately, because the cloud has grown into this enormous, the most complex Lego set possible, that we are still getting some major implementation errors. And it all really comes down to education, reinforcing good practical experiences, and good training.
So, you know, I teach an engineering class, we teach an architecture class, and the same challenges that we are facing, that organizations were facing 10 years ago, are still facing today. It's just that the technology's moved on somewhat. You also mentioned things like the, you know, the cloud being this cheaper option potentially, and it turns out that's not all. Is the case.
Rarely, even. And so we're now in a situation where organizations are moving back to on-prem services and effectively just running an entire hybrid model, which again increases that complexity. And then we throw AI into the mix. By the way, Simon, I gotta tell you before you go AI, I do have this acronym, because you know we love an unnecessary acronym in cybersecurity, but I've been using it and I think you'll love it.
RINFOL. Run it now, figure out later. That's very good. Yes.
Otherwise known as it's working. Don't touch it. Back away from the machine. Many a banking mainframe I've seen.
I'll just go and check if Rinfall.com was available. Just back in a sec. I'd be careful with that one.
It might be something you don't expect. Make sure we have Safe Search turned on. I don't know how to do that. Anyway, Simon, you were going to tell us about AI.
Yeah, so AI's really, again, sort of change the dynamics of what cybersecurity is doing. We've all of a sudden got this tool that, you know, there's a lot of talk that it potentially has the ability to replace human element or human interaction. And I don't think it does. We've had a lot of talk from evangelists online that it's going to solve a lot of the problems.
I think it's going to solve some problems, but it's going to create, and it has been creating whole new problems in itself. And again, it's how organizations adopt this. Now, with the cloud, there was a lot of hesitation. Organizations were not running full speed head blind into running infrastructure in the cloud.
They were actually quite reserved about it because it was contained to the engineering teams that required you to understand software-defined networking, whereas the network engineers actually had appliances to play with and poke and prod. AI is very different because AI is touched by everybody. So every person in the organization is going to use AI, whether the organization wants it or not. And I literally had a conversation yesterday with a small team of people, and they have concerns about how AI is being used.
They've got potential data leaks that have already happened. This thing's not going slowly. The adoption for it is vast. And the policies that organizations put in place just cannot keep up.
So this presents us a whole new series of challenges. And of course, from my perspective, this is brilliant because it means A, I can now write a lot more code and be a lot more productive because that's really what AI is. It's a productivity tool. But also we can introduce that into the CTF environments and we can experiment with this.
And in fact, we did at our last cyber threat event where we actually had a phone system where you could dial up an AI bot and you had to convince it to give you some credentials. That was awesome. That was awesome. Before you and James geek out even further on AI, as I both expect and even hope that you will.
Can I just ask you a little bit about where you think AI is? I was really interested that you mostly concurred with James's framing of the cloud and AI experiences in terms of adoption, in terms of the narrative and so forth. But now you're saying, look, everybody is using it. It is different in some key ways.
And I just wanted to ask, here's a nice easy one, you know, what is AI? And what I mean by that is when you're talking about organizational adoption, you know, there've been all sorts of predictions. In the past few years, there are all sorts of predictions of where it's going. But with any technological revolution, there have been bits where expectations have been overshot.
There have been bits where things have been much slower in terms of development, and there have been things that have been predicted that haven't happened at all. And we're getting all sorts of predictions about robotics, about interaction with the physical world, about the takeover of various professions and so forth. So, where should organizations really be looking in terms of which bits of AI matter most for their effectiveness and for their security? So, from an effectiveness perspective, it really should be treated as a productivity tool.
It is there to expand or speed up processes that humans are interacting with already. The whole let AI go off and do its own thing is terrifying from my perspective. Okay. And from a security perspective, it's even more terrifying because as humans, we're really good at missing things.
Yeah. And the AI tools have been trained by humans. So people have to come to the realization that at the moment, and with the versions and with the types of AI that we're currently running, there are still going to be some fundamental flaws in there and that we, you know, we shouldn't really be trusting them with things as critical as security. That said, they can speed up a lot of those sort of remedial processes, the data hunting, etc.
And I use it, you know, we use it extensively, particularly around things like log investigation, second cloud infrastructures. It is good for a lot of those implementations, but we have to double check it. We have to verify everything it's doing. And the conversation I had yesterday with a company was they have a product development manager who was essentially blueprinting what some infrastructure should look like.
And he was then immediately sending that off to the development team in the hope that they were going to build it without really any consideration of the architecture of what was needed to be built, how it was going to be implemented, and how it was going to work with everything else. Yeah. So it was almost like they'd skipped the step to get there. Right.
And I can't resist asking you this as a follow-up, maybe even taking you back to capture the flags and practical learning and so forth. So you learn by doing, you're designing, you're bringing AI into all these exercises and so forth. So you're looking really, really closely in a really hands-on way. You know, you're doing everything short of live fire at what the defenders can do and what the attackers are doing.
What in terms of two things? One, I suppose techniques is interesting you, and that sort of cliched question about who does AI favor, attackers or defenders. What's your perspective on that? Oh, no.
Including that's a terrible question. That's an acceptable answer. Uh again, that very much depends on the individual's ethics. Yeah.
You know, what their objectives are and how prepared they are to implement some of their objectives. Yeah. Some of the techniques I've seen from the AI perspective and from an attacker's perspective is actually targeting human nature. And I think this has taken a very dark turn.
Really interesting. Yeah. We all know what phishing is, we all know what vishing is. Now all of a sudden, we've got tools that can handle things like translation.
Yeah. We no longer need to rely on poor translation. You know, the attackers can just translate whatever they want into whatever language they want. Yeah, yeah, yeah.
Which means they can write code in one language and have it compile in another language, they can write emails, they can vish. All of a sudden, it's opened up a vast area or surface of an attack that previously was, you know, getting better. If you wouldn't mind, Simon, to build on that point. Or just to interrupt.
Yeah, exactly. Well, you know, I hadn't spoken for a while and I do like attention. Bye. It is, Simon, is it's the case that a lot of the folks who are building these technical inserts and artifacts and so on aren't exactly notorious for their gregarious social skills.
And now with AI, it's not just that they can translate to other languages or have better spelling. Their ability to please people in conversations, to adapt to social preferences. I mean, that's one of the terrifying, you know, features of AI that's led to some elimination of models and the way that people have felt the need to anthropomorphize it and turn it into their friend. Well, think about what that does for our attackers who may be more technical and less human manipulative and understanding in their nature.
So it's even bigger than the translation thing, isn't it? Oh, it is. I mean, it's into mimicry. And as we know from psychological studies over the last 20 years in things like uh neurolinguistic programming, if you can mimic the behavior of an individual you're communicating with, you're more likely to be able to get them to do something.
And then this is a horrifying aspect of AI because it actually is very good at this. You know, attackers can scope out and identify the traits, the language, the behaviors used within an organization and become a part of that organization in order to then leverage further access. And we've seen this over the past six to 12 months, uh, really gaining traction, not just through phishing either, but through voice prompts, et cetera. It's getting a lot more difficult to detect.
Yeah, it is. And I'll share a couple of stats from my perspective. You could refute these violently if you like, Simon, or agree, up to you. And then I've got a couple of questions on the back end of this to try and make it useful to our listeners as they think about cloud and AI today.
You know, look, I've seen these wonderful headlines and kind of application of these technologies for defense and offense. And the obvious question is well, does the world get more secure? We we saw the huge plunge in the stock market in cybersecurity companies due to the preview release of an effect and you know, an LLM for improving code quality and reducing vulnerabilities, which, by the way, is a fantastic use case for this type of technology that I thoroughly encourage. But the details matter, doesn't it?
Because two things are true. Firstly, having more of this stuff out there, more agents, more AI, likely to increase the surface area of attack. So even if you reduce the number of vulnerabilities in your code, there's more stuff, there's more surface area, which might take us to a place where frankly we're just as exposed as ever. But there's also all this research out there, isn't there?
There's, you know, kind of Opus 4.6's vulnerability density increased 55% over its predecessor. And, you know, VeraCode kind of released a report saying security performance stays flat regardless of model size. And uh there was another one, I think it was Endor Labs, who'd said that, you know, these models that are producing these fewer false positives and improving code security also generate code that's vulnerable 25 to 75% of the time.
So I get this real sense that we're admiring the improvements, which are wonderful, and missing this bigger point that it's gonna create a ton of other baggage that leaves us in a world where we're just as exposed and frankly, maybe more exposed. Oh god, I've gone full doomsday scenario. Simon, help me out. Can you give me some pragmatism here on how you think this is gonna play out for organizations over the next couple of years?
Go for the middle ground. Unfortunately, I'm not gonna give you any pragmatism at all. I'm actually gonna reinforce what you just said. Oh no.
So the stock market and a particular type of organization actually took a tumble over the last three months, which was SaaS products. Right. So software as a service of all of a sudden their really stable consumer base has now been disrupted because anybody can write an app. So we now have a situation where the encumbrance who have spent millions in research and development over the last 10 years or so are now being phased out by organizations because they've realized that rather than pay a particular license, they can get a developer in who knows how AI works and then write a custom application for them.
And then that brings you back to this surface area of attack statement you made as well, which is yes, we have now more advanced tools in AI that can identify flaws in code, bad practices, all those kind of things. But we've also got 10 times more people without any experience writing code. So is it gonna get any better? What could possibly go wrong?
What could possibly go wrong? Yeah. It's a less than ideal situation. And I think again, it's gonna take a while for not just the early adopters to get beyond this point.
It's gonna take a while for the organizations and for the teams who are a little bit slower to pick up new technologies to get into this state, which means that actually we're probably gonna be facing a worser scenario in the next year or two than we already are at the moment before we get to an improvement state, unless there is another huge leap in the technology and an advance in the technology. Yeah, no, that makes sense. Well, look, I've I've got one more thing for you, and then I promise I'm gonna get out of the way, Kieran, because I'm hogging up a lot of time here.
I'm learning by not doing. So, much like people with a lot of AI, frankly. So, Simon, I want to get back to something practical for our listeners here on both cloud and AI. So, I give you a hard assignment.
Two points on how people need to pay attention to cloud security here in 2026. Two things that you think are particularly important that a security leader goes and checks their technical team are doing, mistakes that are common. And then two things in AI where you'd do the same and validate being used a certain way, or you've got a certain policy, or that you're looking at a certain area of technology you think matters. So for both of them, two specific things that you think are worth paying attention to that people can go check.
I'd like to say, I got a million things I'd like to say on that one. Um I mean, the two that tend to cause the most problems for organizations in the cloud is identity primarily in the cloud environment, managing users, and just doing the basics. I mean, again, I was reading an article uh written by a pen tester. He was talking about an organization that had spent, you know, two million dollars on an EDR, an XDR, they've got uh endpoint detection and response.
They had a pen test and they were breached within two hours. And they were breached within two hours because they had a hard-coded credential stored in a file, stored in a server somewhere, unsecured buckets, etc. All of those traditional weak spots inside a cloud environment implementation, they're the things you want to watch out for. And you don't need a vast array of expensive tools to do that.
You just need, you know, eyes on and some skilled professionals. The next challenge to that one then is to expand that out onto management of your on-prem infrastructure as well. And the cloud now is part of on-prem. In fact, your on-prem is gonna become your on-premise cloud.
And that is where everything is going. So, you know, handling again identity from those two distinct environments is proving difficult for organizations, especially when they're trying to drag some legacy systems along with them. From an AI perspective, oh, this is easy. You just gotta train your staff.
You've got to provide and give them incentives to use the technology appropriately, show them the potential problems and the flaws in the way that the technology is implemented, and provide them with the tools that they need in order to be able to use those resources properly. The next part of that one is manage the actual communications. I had a very, very odd scenario a couple of weeks ago where an organization implemented a very strict policy across the entire organization, made all the staff sign a document, basically went through the whole tick box exercise for ISIL 27001, Cyber Essentials, et cetera.
And then the CEO was using his own personal Chat GPT account and actually posted information about his clients in that account and created a breach. Wow. Just from that kind of default activity, it was logged in on his computer on his enterprise, and it was on a personal account on his phone, and that was it. What an incredible answer.
We could unpack that for hours, but actually it was so succinct, I suspect. Some people would just clip that bit out and use it as advice for their organization for quite some time to come. But so let me ask you hopefully a slightly easier question. It's a hard one to ask because I'm trying to bring lots of things together that we've talked about.
Love the remark about your on-prem cloud. You're talking about the challenges of AI adoption and all the complicated things we've talked about today and the fast pace of change and so forth. We are talking about an industry where quite a lot of people feel under pressure. Now, anyone who's encountered you, we can't speak to how you're feeling on the inside, but I hang around with you at conferences and you're about to go on stage.
You have legendary status in parts of the community, but you wear it all lightly with a famous cap on your head during the CTFs. You've this huge area of hinterland of interests outside of work. You get so much done, you don't seem to, on the face of it, let it all get to you. But there's plenty of talk about this industry being under pressure.
So two questions to finish off with. One is really, how do you manage to do all this with, at least in public, a smile in your face? And is there a more serious problem in an industry that you, by whatever means, have managed to avoid? There is a serious problem in the industry with burnout, and it's very easy to fall into that trap, and without noticing as well, the pressures that people who are working in cybersecurity are under.
You've got to be constantly learning just to stand still. There is often more work that is possible to actually do as a single individual, then you know, add the training onto there, and then aren't incidents on if you're in that particular part of the industry. It is really difficult, and you do just have to take yourself out of it fairly frequently. Do something that's completely, you know, outside of that environment and just keep yourself grounded.
I find it exceptionally easy, um, but that's just because I'm a massive geek. And to be honest, this is as much as my hobby as it is my job. And I am very lucky to be in such a position where I basically turn up to work every day excited. Um, in fact, I said to my wife this morning, she was leaving the house, she was like, What are you doing today?
I was like, Yes, I'm building CTF challenges today. Haven't managed to do that for about three weeks because I've been doing some other things and running some events. So, how are you getting on? Yeah.
I was great. Yeah, they were brilliant. I've had a lot of fun today. Excellent.
Simon sits in his lab like an evil genius trying to recreate the machinations of cyber criminals and then do them in a way that's secure enough that lots of cybersecurity professionals can emulate that safely. And it's a fascinating problem to build something very specifically vulnerable and not more broadly vulnerable. It's a really interesting problem, isn't it, Simon? And only you, James, with that mind of yours, could take that wonderful, upbeat, positive answer about I'm so lucky because my hobby is my job, and say, yes, you're an evil genius.
Well, I think it's flattery of the highest order, actually. It's highly creative. Evil for good, right, Simon? Evil for good.
Another t-shirt. We've got one. That would be a very good t-shirt, actually. Yeah, that's the best idea we've had for a while for these fictional t-shirts that we never actually make.
But there we go. Yeah, well, but one day we just might. There's a distinct possibility. That's probably a slogan of a company somewhere.
So apologies if I just inadvertently promoted someone or breached a copyright. But uh, if not, someone should snap that one up, I think. I'm almost worried. And this is my fault.
I've got us rambling again, just me and you, not Simon. He's been very articulate. And we might run out of time before your favorite bit, James, because I think, you know, having done cloud, AI, capture the flag, community outreach, state of the cybersecurity industry, I think we'll let him off a bit, except for your favorite bit. Go on.
We have to. One must. So look, Simon, it's only fair if we ask people to listen to us, we give them something really practical and useful at the end. So absolutely, Simon.
So we are asking you for your 30-second takeaway. It's my favorite bit. Simon, this podcast is about lessons for cybersecurity leaders. So if you've got just 30 seconds with a cybersecurity leader, what would you advise them here in 2026 to pay attention to, to ignore, or frankly, to give up their role to an AI and go and get into carpentry or motorsports?
I don't know. What would it be? Uh my recommendation would absolutely be invest in your people. They are the ones who are going to make the biggest difference.
And actually proving your security capability and not just claiming it is a massive win for anybody who's in cybersecurity leadership. My actual goal is really simple. I basically want to take teams of people into operational readiness by giving them systems to break, defend, recover, etc. But you've got to commit those resources to come and play those games so that they can practice without the pressure of somebody leaning over their shoulder, asking them, is it working yet?
Is it working yet? Is it working yet? And that is as clearly expressed a 30-second takeaway as we've ever had, and a memorable one too. Thank you very much, Simon.
It's been an absolute pleasure having you on the show. And unfortunately, that's essentially all we have time for. So all that remains for me to say, apart from thanking Simon and even thanking you, James, is to say you can leave us feedback at the podcast site, or you can email us at cyberleaderspodcast at sans.org.
Tell us what more you'd like to hear, less. Tell us anything you like. And so with that, thank you very much for listening today. Thank you for listening.
Keep cybering. So for me, Kieran Martin, and me, James Line, it's goodbye. And remember that when exploiting a binary, it's a lot like a hot chicken through butter.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.