The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Cyber Security Business
Cyber Security Business artwork

Future-proofing and Storytelling

Cyber Security Business · 2025-12-10 · 30 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density12 / 20
Originality10 / 20
Guest Caliber16 / 20
Specificity & Evidence11 / 20
Conversational Craft11 / 20

Jason Loomis brings decades of security leadership to explain why the fundamentals of cybersecurity - least privilege, inventory management, data governance - remain unchanged despite seismic shifts like cloud migration and AI adoption. The real transformation isn't technical but organizational: building teams with storytelling ability, systems thinking, and cross-functional context. Loomis attributes this skills gap to education system changes that emphasize narrow technical specialization over Renaissance man generalism, forcing CISOs to train employees on soft skills that previous generations acquired through liberal arts exposure. For boards, Loomis advises a simpler narrative: position your organization's AI risk against peer benchmarks and explain your mitigation plan - a more defensible story than complex risk quantification. Building security programs today requires hiring AI-fluent engineers and selecting tools with built-in AI capabilities to automate grunt work analysts previously handled manually.

Key takeaways

  • →Fundamental security controls (least privilege, inventory, data governance) apply across cloud, AI, and traditional infrastructure - technology shifts don't invalidate core principles.
  • →Storytelling and systems thinking are now critical hiring and training criteria because technical employees often cannot translate findings to business-level communication or explain the why behind their work.
  • →Boards primarily care about revenue, cost reduction, and peer-relative risk positioning - not granular risk quantification - so frame AI security discussions around competitive parity and clear mitigation plans.
  • →Three-year security strategies are unrealistic; instead maintain directional intent (e.g., automate grunt work via AI) while remaining agile to pivot rapidly when zero-days, breaches, or business threats emerge.
  • →New security programs should prioritize AI-expert hiring and select tooling with embedded AI to reduce junior analyst workload on SIEM alert triage and detection engineering.

In this episode

  1. 1Introduction and Jason Loomis's Background as CISO at Freshworks
  2. 2AI Era Compared to Previous Tech Shifts Like Cloud Migration
  3. 3Fundamental Security Principles Remain Constant Across Technology Changes
  4. 4Importance of Storytelling in Security Leadership
  5. 5Future-Proofing Leaders Through Continuous Learning and Technical Understanding
  6. 6Changing Workforce Skills: Storytelling and Business Acumen Beyond Technical Expertise
  7. 7Planning Strategy in a Rapidly Evolving Threat Environment
  8. 8Responsible AI Governance and ISO 42001 Framework Implementation

Mentioned

FreshworksKlogixCNBC Tech Executive CouncilISO 42001NIST RMFSolarWindsKevin PoucheJason Loomis

Guests

Jason Loomis

Topics in this episode

ISO 42001AI governance modelsZero-Day Vulnerabilitiessupply chain attacksFreshworksNIST Risk Management FrameworkCNBC Tech Executive CouncilAgent List podcastSIM (Security Information Management) toolsStorytelling in security leadership

Questions this episode answers

How do you explain complex AI security risks to a board of directors?

Focus on two points: where your organization's AI risk stands relative to peers (the primary defensible metric boards understand), and what specific actions you're taking to mitigate it. Avoid detailed risk quantification; boards are primarily concerned with revenue, cost, and competitive positioning.

What security controls still matter in an AI environment?

All the fundamentals apply: least privilege access, system inventory management, data inventory, and governance oversight. AI doesn't change the core principles - it just requires storytelling to explain their continued importance and new governance frameworks like ISO 42001.

Why are entry-level security hires lacking soft skills today?

The education system shifted from Renaissance man generalism (combining technical, historical, social, and communication skills) to narrow technical specialization. Employees graduate without exposure to psychology, sociology, history, and literature that teach context, narrative ability, and systems thinking.

Can you plan a multi-year security strategy with AI and new threats emerging constantly?

No - use a Mike Tyson philosophy: have a high-level directional goal, but expect to pivot rapidly when zero-days, supply chain breaches, or business crises hit. A 3-year tactical roadmap is unrealistic; security gets punched in the face too often.

What does responsible AI governance look like in practice?

Govern first, deploy second: build an AI risk assessment model (ISO 42001 is a good framework), define clear accountability between security, legal, and engineering, evaluate risks before deployment. However, smaller organizations often bolt governance on after deployment due to competitive pressure and business risk calculations.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

12 / 20

The episode contains some substantive points - particularly on AI governance frameworks (ISO 42001, NIST RMF), non-human identity management, and the importance of storytelling for technical teams - but these are interspersed with significant filler (personal banter about age, podcast names, voice quality, tangents on education systems and parenting) and repetitive ideas. The signal-to-noise ratio is moderate; a B2B operator would extract useful concepts but has to work through considerable padding.

The basic security controls still apply. The concepts of least privilege...Are you inventorying your systems? Do you have inventory control...All these things are still applicable as they were 20 years ago.
We build AI governance model, defines what we're going to use AI for. We evaluate risk. We figure out who's accountable for oversight...ISO 42001...will help you with that.

Originality

10 / 20

The core ideas - that security fundamentals don't change, that storytelling matters, that governance must precede deployment - are sensible but well-trodden in CISO discourse. The framing around education systems' shift away from Renaissance-man thinking is mildly novel, but the overall perspective lacks contrarian or first-principles arguments. The episode mostly affirms conventional wisdom rather than challenging it.

Nothing really changes. It's still about the basics.
Every CISO is so different...almost every board is different.

Guest Caliber

16 / 20

Jason Loomis is a credible guest with genuine operating experience: a CISO at a public SaaS company (Freshworks), 20 years in security, CNBC Tech Executive Council member, and runs a podcast (Agent List). He speaks from direct experience managing a 70+ person security team, handling board interactions, and making real trade-offs. He is not a consultant or pure thought-leader, and his examples are grounded in actual organizational challenges he's navigating.

CISO at Freshworks and a member of the prestigious CNBC Tech Executive Council.
I manage a 70 plus person team

Specificity & Evidence

11 / 20

The episode includes some concrete frameworks (ISO 42001, NIST RMF) and specific operational examples (service accounts, non-human identity lifecycle, SIEMs, third-party risk management with AI), but largely avoids hard numbers, case studies, or named examples of breaches/incidents. Most claims remain at the pattern level rather than the granular level; the data points are few.

Non-human identities outnumber our human accounts with people behind them by magnet 10x, 20x.
If I say ISO 42001, they know what I'm talking about.

Conversational Craft

11 / 20

The host Kevin asks reasonable, open-ended questions and does follow up (e.g., on board dialogues, AI governance, identity management), but rarely pushes back or challenge the guest's claims. The conversation is friendly but lacks productive friction; most answers go unchallenged. The host allows long tangents (parenting, education systems, MTV) without redirecting, and the rapid-fire ending feels perfunctory rather than designed to sharpen insights.

So I'd love to know how you think this AI era compares to some other massive periods of change that you experienced.
So when you interview now, I assume you're interviewing all the time with a 70 plus person team? Are you now starting to be a bit more discerning and looking for different skill sets?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

risk28security21team14five12understand11three11jason10podcast10today10board10level10different10cisos10hire10future9love9

Episode notes

Kevin Pouche, COO of K logix, sits down, Jason Loomis, CISO at Freshworks, who shares what it takes to lead through constant change from AI disruption to shifting workforce dynamics. He breaks down why future-proofing isn’t just about tools and tech, but about mindset, communication, and adaptability. Jason also reflects on the evolving skill sets security teams need today, the realities of AI governance, and why storytelling might be your most powerful leadership tool.

Full transcript

30 min

Transcribed and scored by The B2B Podcast Index.

Welcome to Cybersecurity Business. I'm your host, Kevin Pouche, COO of Klogix. In this episode, we explore what it takes to be a future -proof leader in the age of AI, emerging threats, and constant transformation. No better guest to guide us through this chaos than Jason Loomis, CISO at Freshworks and a member of the prestigious CNBC Tech Executive Council.

Jason has decades of security leadership and... right now owns the company's entire security strategy, including AI risk. So I feel like we have a heavy hitter on the podcast today, Jason. Thanks for joining us.

Thanks for having me. I really appreciate it. I noticed in your introduction of me how you said decades, and maybe this is all in my own head because I know my own age. It felt like you said centuries.

I think I heard centuries. Maybe it feels like centuries. Well, I think that... cybersecurity should be like dog years.

Oh my goodness. Yes. So maybe it is centuries. Well.

I know you have your own podcast, Agent List, which I listened to myself. I enjoyed it. It reminds me of a podcast with a similar name, Smart List, which I also enjoy. I love Smart List.

Big fan of Smart List. And thank you for being one of my seven listeners on Agent List. That's awesome. Love the name.

Well, good. My voice is a little hoarse, so I'm glad that you are a fellow podcaster so you can carry most of this conversation. No pressure. No pressure.

So I'll sort of jump right into it with your... centuries of experience, you've clearly seen more than one massive tech shift. So I know you have done a lot of work evangelizing and really understanding and educating around AI. So I'd love to know how you think this AI era compares to some other massive periods of change that you experienced and if you can draw any parallels.

Yeah. I can draw parallels. I think with every single massive shift, you know, probably the last big one was cloud, really affected security practitioners. There was a lot of talk of, wow, it's going to change how we do security.

Other people were panicking. They were out of a job. That's a separate tangent topic to AI, maybe even a little more realized with AI. But there was a lot of talk around that tectonic shift from going on -prem into this whole cloud environment and having, quote unquote, somebody else owning your security.

The same approach that I take with anything new in security is, and it hasn't changed in my centuries. Really, it's only been about 20 years. With my 20 years in security, the only thing that's, nothing has really changed. It's still about the basics.

The basic security controls still apply. You know, the concepts of least privilege. Did I just give everybody in the company access to my AI models? Maybe you shouldn't do that.

That's a bad thing. Are you inventorying your systems? Do you have an inventory control over what you're running in your cloud? Do you have inventory control of what software and hardware you're running?

Do you have data inventory? Do you know where your data is? All these things are still applicable as they were 20 years ago to security as they are in, say, an AI environment. So to me, nothing really changes.

Probably, if anything, just my storytelling has to change. And you are a storyteller. Well, I try to be. I think that is what will make you a successful security practitioner.

And definitely a successful CISO is the ability to tell stories. Especially, I assume, to get what you want to get, correct? That is part of it, yeah. If you want to get buy -in, you want to get people to move in a certain direction, storytelling is a big part of that.

So is that a part of future -proofing yourself as a leader? So I know part of this subject is talking about future -proof, so I'd be curious what... it would mean to you to be a future proof leader in our industry? You know, it was a really good question.

I know you gave me a hint of some of the topics you wanted to cover. And when the word, you know, quote unquote, future proof came up, it made me think a lot. And I wonder if there's going to be a time in my career where I'm no longer future proof that maybe I can't keep up. So far, it's been great.

To be honest, I was a little scared when AI was making that. run at the next big thing. I was like, oh, wow, am I going to be able to understand this? I don't have a degree in mathematics.

I barely got out of calc in high school and barely meaning like a C minus. So math was not my game. And I'm like, holy crap, I got to learn models now and math. When I started digging and realized I didn't have to do that, but there might be a point in the time when I can't future -proof myself.

But for this, for anybody else who's in this industry is the way that you future -proof yourself is you have to keep up with it. You have to go learn it. Even if, and I thought about this too, what if I worked in an industry, say, you know, I worked for a manufacturing, a pulp manufacturing plant, and I was a CISO there. May not get a chance to be working with high -end LLMs and, you know, creating ML models within your architecture or your infrastructure.

But I would say reach out of that and try to keep up with going on elsewhere in the industry is the best way that you can help future -proof yourself. And storytelling ties into that because you need to understand it so you can tell the story around it. You know something in two ways. You can tell somebody knows their subject matter.

One, they could teach it. That's usually the best way is you could teach other people it. The second way is if you can tell it through analogy and you can tell a good story and analogy to people who may not understand it, like perhaps your board or some executives on your company and you have to explain to them why AI security is so important. And doing that through analogy allows for that.

But to do the analogy correctly, you really got to understand what you're talking about. Keeping up with the technology, to me, is the best way. If you were to look back, let's say, five years ago, is there a transformation you're navigating right now that you never would have expected to be navigating five years ago? Yeah.

I mean, AI potentially? You know, this has a loose tie -in to what I think are some of the negative effects we're going to see of AI, but it's not directly correlated or directly tied to it. No causation. Might be correlated.

Five years ago, I honestly didn't expect... Part of my job would be teaching foundational skills like storytelling, systems thinking, context building to technically strong employees who just never developed these skills in school or in their previous work history. I'm finding people today, my techs can execute tasks, but they struggle to explain the why they're doing it. They're struggling to convert technical findings into business level storytelling.

And often, you know, they miss things like. cross -functional context because they've been trained to solve problems and not necessarily to really understand systems. You think this is a generational challenge or just a challenge in our industry because people tend to be a little bit more technically oriented? I could probably go scrounge the internet and find evidence to back this theory that I have up, but I believe it's the...

The change of focus of our education system of getting off the idea of, you've heard of the term Renaissance man. There was this concept. My father was one of them. Renaissance man is the idea that you're not a master of none, but an expert of none, but a master of everything.

Like you want to learn a little bit of everything. And the idea that our education system, like, oh, why do I need to learn English literature? Because I don't need that because I'm going to be a programmer. All I need to go is take my math class.

I don't need to take history. which teaches you context and repeatability. And these ideas of these concepts that come over and over in human behavior and human nature actually do apply to the business world, in my opinion. So in my opinion, it's the way that our education system is refocused off of general education and more encompassing understanding things from literature, art, geography, history, and focusing just on very specific skill sets to what job you want to get out of college.

That's my belief. We've shifted away from that. I totally agree. And not to diverge from this podcast, but it's sort of relevant.

You have a two -year -old that you're now going to be molding in this world. My kids are a bit older. They're young teenagers. And I had this thought that came to me about a week ago, a couple things I'd love to do with my kids.

And one of them was around AI, which is what we're talking about a lot today. geez, should I be having my kids completely immerse themselves in everything AI right now? And the second was, to your point about communication and storytelling, I thought, I'm going to have all of my kids read that ancient but still relevant book, How to Win Friends and Influence People. Because I do think the education, and not just the educational world, but just the way people communicate right now.

Young kids is just very different. It's sort of less verbal in some ways than it has been in the past. And I thought sort of combining those two things would be really beneficial for them. Of course, I haven't done anything about it, but I think it's in agreement in what you were saying and what your hypothesis is for sure.

Yeah, I totally agree. I'm keeping, I mean, my two -year -old will, I'm not going to let him even spell AI. You're not touching it. You're not going anywhere near it.

I think it rots the brain. And now I feel like my parents were with MTV back in my day. MTV is going to rot your brain. All those music videos, they're only short four or five minutes.

What we would kill for four or five minutes attention span of a fifth grader today, right? You would kill for that attention span. Great. Well, aside from AI, which we'll get back to, what...

What other major transformations are forcing CISOs and your peers to rethink how they lead? I honestly got to go back to the last question you asked me. I think the changing skill set of the workforce and the changing focus on just technical and not business acumen or human social interaction acumen, how to behave in a meeting, how to respect your peers, how to be on time, which is not about you. It's about respect for the people that are there in the meeting that you're wasting their time.

Those kind of things I think are really becoming challenging for a lot of CISOs like myself. My entry -level positions just don't have this training when before, if you had a four -year degree, you had some psychology or sociology or one of the softer, even though soft science isn't the right term, but some soft science behind it that helps you become a more well -rounded and to me more prepared for the non -technical aspects of needing to work at an organization. So when you interview now, I assume you're interviewing all the time with a 70 plus.

person team? Are you now starting to be a bit more discerning and looking for different skill sets? So at my level, I don't interview individual contributor one, like the entry level positions or even up to some of my senior engineers. It's rare.

I will often manager sometimes key positions that are at the manager above level. So I think I've been shielded from that a lot. So I want to caveat that even at the manager and director level, I am seeing a change. I am seeing that.

I can't get good language. I say storytelling because I actually work in a multicultural team. Half of my team is, most of my team is out of India. I have a team out of Europe and the US.

So I have to work with multiculturalism, multiple languages. So it's not specifically, I don't believe it's specifically a language barrier as much as a storytelling barrier is how are you going to tell this in a way that has a narrative to it instead of just bullet points, technical aspect when you're trying to explain to me as a CISO a problem. And I give them, I said, okay, imagine you're explaining this to the CEO. Is he going to understand this?

I'm like, no. Well, your expectation shouldn't be that all the time I'm going to understand it. You're smarter than me. I hired you because you're technically proficient and you're great at what you do.

I can't do what you do. So I need you to be able to explain it to me as CISO. And I'm finding hiring and finding that kind of skill set is challenging today, more so than it was five or 10 years ago. So I think that's transforming how CISOs are thinking about.

Either how they hire, which may not be our choice, right? There's a shortage of security. So it's not like I can be choosy and just go, hmm, I want to hire this person. I'm lucky if I get good talent and I'm able to retain them for a couple of years.

So it may be how we approach training and training our employees. Right. When you think about your team, and I assume you're already planning for 2026 at this point, or you had been planning for 2026 for the past five months, Can you actually plan, given a lot of this transformation we're talking about, can you plan three years out? Listening to this podcast, it fits my bosses.

Yeah, sure. Here's your three -year roadmap. Here you go. Because I'm asked to do that.

What's your three -year strategy? What's your strategic roadmap for this? Here you go. In reality, hell no.

It is the Mike Tyson, everybody has this plan until you get punched in the face. And security of all departments, and I'm sure I'm a little prejudiced because I work in it, of all business organizations are the ones that get punched in the face the most. I could turn on a dime tomorrow and have a, you know, there was a big zero -day supply chain that luckily did not hit us, Shai Halud or something, that came out last week. Imagine that was bigger and it was a huge, like another SolarWinds type breach.

I can guarantee my strategy would shift for that three year that I had planned out. It now would be focused on something different than what it might be focused on now. So unfortunately, I think technology moves fast. And I think that's the beauty of it.

I think you need to, you can have a general sense of direction. Here, I want to improve. I want to automate a lot more. I want to be able to get rid of, you know, the grunt work that my teams are doing through the features of AI.

But as far as strategy for three years, it would be as simple as that. How I'm going to apply it is going to depend on the threat environment, the business environment of my organization, my budget. There's so many other constraints around that, that besides just keeping a high -level strategy, there's nothing I could put down on paper that's going to be realistic, in my opinion, for three years from now. Well, and it just goes to show you, you have to be adaptable to change and willing to pivot quickly.

Because people don't like change. You know, when you, even my team, oh, Jason, I thought we were doing this. And I go, well, yeah, we were, but we didn't choose this environment. This happened and now we have to adapt.

And to me, that makes our day exciting. Otherwise our stuff would be kind of monotonous. Right. Let's bring it back to AI for a bit here.

You know, I know there's this concept of responsible AI usage. What does responsible AI usage look like inside your organization? And I guess. On the flip side of that, are you seeing AI used in organizations in unethical ways?

Good question. The last one, I was like, oh, who am I pointing the finger at? I'm going to hold off on pointing fingers, but I can talk generalities. Here's how responsible AI should work.

And then I would talk about, to be honest, what the industry, what the reality is. So the truth is AI needs to be treated like any other high -risk technology. Govern first and deploy second. So we build AI governance model, defines what we're going to use AI for.

We evaluate risk. We figure out who's accountable for oversight. We did our AI risk assessments. Our AI risk profile is founded on ISO 42001, which amazingly, they move fast with that framework.

It's a really great framework if you're trying to understand just... What do I do in cybersecurity for AI? ISO 42001 framework will help you with that. You know, then we have a clear ownership between security, legal, and engineering teams for sort of this triple threat to bring into this AI governance model that we have.

Now, the reality is for most organizations, you know, it moved so fast and governance, figuring out how to govern, what to govern, especially when AI came out and there were no frameworks available. I don't know when NIST RMF came out. That's another NIST version of, hey, how do you manage risk in AI? Just to be frank, SMB, smaller organizations, sometimes have to move fast and add on governance later.

It's just the nature of how it works. So I know there's a lot of organizations out there that may be taking a riskier approach with AI because, to be honest, when it comes to business risk, and that's what it's all about. We have CISOs sometimes can put blinders on. Bad CISOs will put blinders on and just worry about cybersecurity risk.

The answer is the business risk. Cybersecurity is just one of those many risks the business has to go. And some businesses may have a risk of, you know what? If I don't get this thing deployed next month, I'm going to lose half my customer base and we will be out of business.

That's a much higher risk from might be a much higher risk in their calculation of risk management of we're not going to have jobs in a month versus do we take three months to deploy an AI governance model? They may decide, oh, you know what? We need to go with this. Yes, we understand governance is absolutely critically important.

We're going to bolt that on after the three months, come in and figure it out. So I imagine there are companies out there that are taking a more risky approach with AI implementation. Sure. We talked earlier about storytelling to the boards.

I've been in front of boards, but I haven't been in front of a board in the last 18 plus months. And I have to think every time you go in front of the board, something to do with AI needs to pop up. Are they expecting you to proactively talk about AI risk? What do they want to know from you?

Has that dialogue changed? I know in the past it was, oh, how do I translate some of these complex cyber threats to business terms for my board? AI is a business term. So I'd love to know a little bit of insight into sort of that dialogue.

Yeah. I want to start off by giving a disclaimer to the idea that I get this, how do you talk to CISOs is a question, right? People are like, how do you talk to a CISO? Or someone will have a podcast.

How to talk to CISOs? Every CISO is so different. And at best, you can probably categorize them into, I don't know, 98 different categories. And it's the same thing with boards.

There is no consistent approach, in my opinion, of my experience from all the CISOs I know is that almost every board is different. And your communication of how you communicate and what you're communicating about is going to be different. Now, in my specific circumstance, I'm blessed because I have security experts on my board. So I don't have to go.

If I say ISO 42001, they know what I'm talking about. I don't have to break down, oh, this is a international standard on blah, blah, blah, blah, blah, or tell a good story around it. They know. So for one, I'm blessed by that, having such expertise on my board.

And any board that has any technology, even if it's just enterprise and your product isn't technology, I guarantee the boards are talking about AI. Everyone is talking about it. I think the primary conversations for most boards are going to be around revenue. I mean, that's their primary concern anyways, right?

Revenue and cost reduction. Those are the two. Risk reduction comes third often. Or it's one of the three of the pyramid.

So first thing they're worried about is, hey, how are we making revenue on this? How are we going to take advantage of the benefits that AI is promising? Blah, blah, blah. It comes first.

And then it's, okay, and what are we doing around security? What are we doing around governance? For example, most boards, when you look at their agendas for their eight -hour meetings they have every quarter, what percentage of that is security? Half an hour, maybe?

maybe an hour if you're really heavy into security, but you probably get half hour out of the eight hours. So that gives you a semblance of what the board's priorities are and what they're focused on. So this idea that, oh, AI is going to take up a big chunk of talking around AI security. In my experience, there is a general story boards want to know.

They want to know, are we at risk compared to our peers? And what are we doing about it? That's the simplified story that in my experience across three different boards in the last, what, four years, five years, that's my experience is they want to know that. They want to know.

So for AI, for example, most boards would probably want to know, what are we doing about our AI risk? Are we at risk compared to our peers? And that's just a good barometer. You don't want to know, oh, I'm spending $5 million and everybody else in my industry is only spending $500 ,000.

They're going to be like, wow, why are you spending that much when everyone else gets away with $500 ,000? Are we doing enough compared to our peers? And then, okay, for these risks, Jason or CISO, what's our plan? What are we doing?

And I get that because, look, there's comfort in knowing that. You stand middle of the pack or better against your peers, especially when it comes to a problem that doesn't have a tangible clear cut solution. So I get that. It's the best metric I've found that's defensible.

Other metrics are defensible. You get into like fair and okay, I can, here's how much risk we're, you know, I have $10 million I'm carrying in residual risk. And if you give me a $500 ,000 investment, I'm going to burn down this $1 million based on these controls over. That story just gets lost, to be honest, in every board I've ever worked with.

And it's the very simpler story of, okay, here's where we are compared to our peers. Here's at least a defensible approach to that, whether it's a third party or part of your quantitative risk platform. They can tell you that to say, here's where we are. Here's what we're doing about it to burn our risk down to a manageable level.

Let me ask you this. If you were in a totally different world, you leave Freshworks, you go to an organization. that you are building a security team in a program from scratch, which this could happen. There are plenty of companies that are building programs right now and building a team.

So if you were doing this today with AI in mind, would you do anything differently than you would have, let's say, three years ago? That's a good question, and that's a tough one because I... Here's how I want to answer that. What I would probably have to do, because that's the expectation of my role, is to, I would hire AI experts that can implement AI and AI tooling and focus on only purchasing tooling that has AI -centric to reduce IC1 and IC2 interaction with the tool.

In layman's terms... If I'm going to buy a, there's a solution in security called a SIM, which is like a big log aggregator. It's a way to just, hey, send me all the data, what's going on in my environment, and I'm going to look for bad stuff happening. That's what this tool does.

Well, it often took a team of lower level analysts to go through and look at the alerts and then build these rules and detections and all this work around it. And if that can be offloaded to have AI do that, we call it sort of that grunt work of having to watch a computer screen and alert on things. I would build that and I would purchase only that type of solution and implement only that type of solution. However, I'm not sure the marketing of what we hear companies doing and building is lining up with that yet, but I'm sure it's coming really, really fast.

Yeah, I agree. And I think I was listening to one of your podcasts where you talked about sort of some of the smoke and mirrors with a lot of the product vendors in AI right now, but it sounds like at the same time. Although there are a lot of marketing hype and smoke and mirrors, the reality of a lot of this AI SOC, AI SIEM is around the corner. Yes, I agree.

Around the corner is a great way to describe it. I think it is. We found great success with one third party risk management, which is another portion of governance, risk and compliance, how you're managing risk across your vendors and your ecosystem. And ensuring you don't have risky people you're doing business with.

And we found really great success with AI in that area. So I know that there are some areas that they're doing really well with it. And to me, it's right around the corner when the ooh or the ah, when I see it. Right.

Well, another area is identity, right? Identity, like identity is always at the top of mind for many CISOs, right? For many of your peers in many different forms. And at the moment, it seems to be around sort of non -human identities, right?

So how are you adapting your architecture or your policies to account for sort of some of these non -human identities in these, call it machine -generated decisions? Yeah. I go back, use your five years question you asked earlier, five years ago. We call them service accounts, is a type of account that's a non -human identity that's used in our systems.

And it's used for like a computer talking to another computer. Well, if you look at today, non -human identities outnumber our human accounts with people behind them by magnet 10x, 20x. So we had to redesign our AI on policies and standards, our identity and access management standards, so that non -human identities are pretty much follow the same or even stronger controls than people do. Things like mandatory lifecycle management.

Often in the old way, five years ago, you would set up this account for this computer to talk to this other computer, give it a complex password, and then never look at it again in your life and think, all right, that's done. But that's not the new paradigm. In fact, those are now targets for threat actors. Threat actors can get in and target that, and they'll use that.

And because you're not monitoring it, you don't have the sensitivity around it. For example, I know when my CEO logs in from a weird location. Because I get this alert that says, hey, he's not supposed to be in Juneau, Alaska. He's supposed to be in Bangalore at a conference.

Let's go talk to the CEO. But out of the 20x, 30x service accounts, am I doing that level of monitoring with them today? No, not as good as we should be. So there's a lot of work around there.

Least privilege enforcement, especially when you're doing this thing called policy as code for least privilege. And then rotating those credentials and as much logging and monitoring around those as well. You're a pretty forward -thinking, relevant leader, Jason. What do you do to continue to stay informed and stay ahead of the curve?

Do you have resources you use, mindset? What do you do? Because this is a lot. I learn more from my team than anybody, to be honest.

One of the best career advices I ever got, this is somewhat applicable, was one of my first bosses. He said, hire someone that you can imagine yourself working for. And to sum it up, hire people that are smarter than you. Don't have the ego where like, I got to know everything and I only want to hire people and I run the show.

I run my teams with this idea that the CEO of Avis once said, if I have a yes man working for me, one of us is redundant. I need to be challenged. I need people to disagree with me. I learn more from my team every day than I do from any peer groups, any CISOs, any conferences, any podcasts, any YouTube channels.

It's my team that teaches me the most. So if you're in my position, make sure you have a smart team working for you. And if you don't, send them to a lot of training so they can get smarter. And if you need to hire, hire smart people.

Hire someone smarter than you. Listen, I love that. Check your ego at the door, right? Yes.

A lot of people think I need to be the smartest one. I'm afraid to hire someone smarter than me. What if they take my job? Well, I'm not here to be a technical savant, expert.

That's not my job. My job is to manage risk for the business or do my best to manage risk, help the business manage risk. All right. A few more questions for you, Jason.

This has been great. If you've heard any of my podcasts, I like to end it with some rapid fire questions. So some of them are a little bit more personal. They're the same five questions.

So I'm just going to fire them off and you just give me the first answer that comes to mind. You ready? All right. I love this first one.

If your CEO gave you unlimited budget for one thing. What would you spend it on? And maybe they do give you a limited budget. Training.

Training. For your employees or for the company? Oh, boy. It would go both.

80 % for my employees and then 20 % to increase my employee training budget. Yeah. Okay. Last book you read.

Yes. Notes on Being a Man by Scott Galloway. Notes on Being a Man. Great book.

Especially if you have kids. Amazing book. I do. Good suggestion.

Third, if you could instantly master a new skill, it could be a professional skill or it could be just a personal skill that has nothing to do with your career whatsoever. What would it be? Math. No, it's so simple.

Two plus two. Probably it would be data science. So I can understand more of the nuts and bolts of AI. I know to secure it, but I don't know how to build it.

Yeah, right. Good time to get your PhD in data science, isn't it? Yes, go work for Meta and get insane amounts of money. Right.

So if you weren't in cyber, what else would you be doing? Probably psychology, like a psychologist. Were you a psychology major? No, but it was when I was making my decision to go to grad school and people lapped me out the door.

I'm glad I chose my MBA instead, but my second choice was I want to go get my grad degree in psychology. I mean, what better of a business degree than learning how to understand and work with people? Was my theory at the time. It was since been disproven.

Boys and girls, if you're listening and you're deciding what what degree to get into business, go with the MBA, not the philosophy or not the psychology degree. Right. But I think what we've determined today is both are helpful. If you have that psychology background, it would help you in your job today.

Period. So read. There's tons of books on leadership psychology that you can. choose without having to spend another two years on a psychology degree.

All right, last question. What's one piece of advice you wish you had when you first started your career? You can't get this through advice. And no matter what, if somebody tells you this, you're only going to get it through experience.

Nothing is ever going to be as bad as it seems. So those incidents, when you have your first cybersecurity incident, you're freaking out, you're panicking, this is the end of the world, the company is going to go down in flames, my job is on the line, all that shit, it's... No, it's not like that at all. And the more and more you do that - Everything's going to be okay.

Yeah, the more and more you go through the fire, the more and more you get that battle -hearted readiness that I'm sure military, experienced military members get, that it's just another day at the office. So for me, every cybersecurity is no matter how critical. I'm like, yep, another day at the office. We'll figure this out.

Let's go. Another day at the office. I love that. Love that tagline.

Well, listen, Jason, that about wraps up the episode. It was awesome to have you on here. So thanks for - Kevin, this has been great, man. This has been awesome.

Thank you so much for having me. Hey, and have a great holiday season. Likewise. You too.

You can hear this podcast or any other Klogic's podcast from our website, klogicsecurity .com or wherever you can find podcasts. And you can also hear Jason's podcast, Agentless, I think in the same place as you can find this podcast. Give them both a listen and hope everybody has a great holiday.

Thanks, everyone. Thanks, Jason. Take care.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • He's Seen 300+ Sales Comp Plans. 90% Make the Same Mistake | Siva Rajamani (Everstage CEO)The GTMnow Podcast · on Freshworks95 / 100
  • We can't - and shouldn't - fix everything [The Industrial Security Podcast]The Industrial Security Podcast · on NIST Risk Management Framework95 / 100
  • Lay of the Land: How Attackers Move in '26mnemonic security podcast · on supply chain attacks94 / 100
  • Built Fast, Broken Faster: MCP & AI App Security - with GitGuardian’s Gaetan FerryCyber Sentries: AI Insight to Cloud Security · on supply chain attacks94 / 100
  • Weathering the AI Vulnerability Storm with Gadi Evron, Rob Lee and Ed SkoudisCyber Leaders · on Zero-Day Vulnerabilities89 / 100
  • Beyond Checkbox Compliance: Why GRC Must Become an Engineering Discipline ft Sheron Chakalakal, Head of GRC @ UiPathSecurity & GRC Decoded · on ISO 4200188 / 100

More from Cyber Security Business

All episodes →
  • AI Compute as a Business Risk70 / 100
  • The Path to CISO61 / 100
  • Creating an AI Security Culture63 / 100
  • Hungry for CISO Trends72 / 100
  • Evolving as a Security Leader65 / 100
All Cyber Security Business episodes →