Cyber Security Business · 2025-08-18 · 27 min
Key moments - from our scoring
Substance score
52 / 100
Five dimensions, 20 points each
This episode brings together Kevin Pouchet and Ryan Spellman to examine the five most pressing trends affecting CISO strategy in 2025 based on research from dozens of security leaders. The conversation moves beyond headline-grabbing AI discussions to address the persistent challenge of identity sprawl - how organizations struggle with multiple identity systems across cloud services, applications, and new AI tools, creating blind spots in access control and lateral movement risks. Spellman emphasizes that defenders currently have an advantage with AI, but warns that as AI agents become more sophisticated and widespread, attack surfaces will expand. The episode tackles the consolidation pressure CISOs face, driven by both hype cycles and economic headwinds; over 30 survey respondents reported budget freezes or decreases, forcing critical evaluation of tools like GRC platforms and DLP solutions that often fail without proper foundational data practices. Beyond tools, Spellman stresses that building lasting security culture requires instilling ownership and pride among employees - moving beyond phishing tests as a sole metric - while maintaining baseline controls analogous to fire safety in a pizza restaurant. Organizations need to approach security as continuous investment rather than compliance checkboxes, recognizing that effective, frictionless controls (supported by frameworks like NIST AI RMF and ISO 27001) ultimately improve business relationships and customer trust.
Rather than bringing security in at the end, the best CISOs use a 'yes, and' approach - engaging early and often with AI stakeholders and positioning security as an enabler that will make experiments secure, building controls in from the front rather than retrofitting them.
Identity sprawl refers to the proliferation of different user account systems and identities across applications and cloud services that can't be unified under single sign-on, creating weak points where compromised credentials can expand blast radius and enable lateral movement throughout the organization.
Over 30 survey respondents reported budget freezes or decreases due to economic headwinds, forcing organizations to scrutinize whether existing security tools are delivering actual value and driving tool consolidation pressure.
These tools often fail because organizations lack foundational practices - GRC requires proper data classification, evidence collection, and process documentation, while DLP requires good data understanding; without these foundations, the tools become expensive and underutilized.
Phishing testing is an effective technique but alone is insufficient; building real security culture requires fostering employee ownership and pride in the mission so people genuinely care about not clicking malicious links, not just viewing it as a compliance metric.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode covers legitimate CISO priorities (AI governance, identity sprawl, tool consolidation) but delivers them largely as high-level trend summaries without deep analysis. While specific frameworks (NIST AI RMF, ISO 4001, NIST CSF) are named, there's minimal concrete guidance on implementation. The Copilot/permissions example is concrete but isolated. Most content rehashes existing conventional wisdom about AI risk, identity management, and budget constraints rather than surfacing novel insights an operator wouldn't already know.
The best CISOs from our survey were engaging early and often with the AI-focused stakeholders and they're starting from a position of yes and, where the and is, and we will make it secure.
if I cut DLP down to whatever I'm getting through Microsoft, maybe I could free up and have an FTE and maybe some funds
The episode relies heavily on established frameworks and recycled analogies (pizza place for compliance burden, WWII bomber survivorship bias for blind spots, teaching to the test for phishing). While the food analogies are consistent with the host's stated preference, they don't generate fresh thinking - they're pedagogical devices applied to conventional problems. The core trends (AI governance frameworks exist, identity has always been important, consolidation cycles repeat) lack contrarian positioning or first-principles questioning.
Think of a pizza place. At the pizza place, you've got smoke alarms, fire extinguishers, and special insulation around the ovens.
the planes that came back, you know, they noticed that the gunshots that hit the planes didn't seem to touch the engines
Ryan Spellman is a Managing Director of Consulting at Klogix with ~20 years in security, providing relevant domain experience. However, his value is primarily as an internal company resource and trend synthesizer rather than a practitioner who has built transformative programs at scale at major enterprises. He references survey data from 'several dozen' CISOs but doesn't cite personal track record of major incident response, breach prevention, or large-scale transformation. The guest is competent and credible but lacks standout operational credentials.
Ryan Spellman, who's our Managing Director of Consulting here at Klogix
I've been doing this for nearly 20 years
The episode is sparse on concrete data and examples. One strong case study (Copilot accessing sensitive HR files due to poor permissions) is mentioned but never unpacked. The survey findings reference '30+ respondents' with budget freezes but provide no other metrics, timelines, or company examples. Frameworks are named (NIST AI RMF, ISO 4001, NIST CSF) but not quantified. No dollar figures, incident timelines, or adoption rates are provided. Most claims remain abstract - e.g., 'identity sprawl is a huge challenge' without specific metrics on exposure scope or blast radius impact.
they discovered that the agent had access to some of the most sensitive personnel files of the company, all due to poor permission management teams, right? A link had been shared. Anybody who has access to this link can have access to these files.
over 30 respondents who we interviewed saw their budget freeze or decrease
The host asks reasonable opening questions but rarely pushes back or probe deeply. Follow-ups are surface-level and accept Ryan's answers at face value. For example, when Ryan discusses GRC tool utilization challenges, Kevin doesn't ask for remediation specifics or failure examples. The conversation reads as a friendly internal company discussion rather than investigative interviewing. There's minimal productive disagreement, tension, or clarification-seeking. The host frequently compliments Ryan ('great question,' 'huge thanks') rather than challenging claims. The episode feels more like a consulting firm marketing conversation than genuine peer inquiry.
It's a great question
Well said, Ryan. Huge thanks for all the insight.
Computed from the transcript - who did the talking, and the words that came up most.
Kevin Pouche, COO of K logix, sits down sits down with K logix's own Ryan Spelman, Managing Director of Cyber Risk, for a deep dive into the most pressing CISO priorities shaping the second half of 2025. Drawing on research from K logix's conversations with dozens of CISOs across industries, Ryan breaks down five key areas defining modern cybersecurity leadership: AI governance, identity sprawl, business alignment, tooling optimization, and building a lasting security culture. With nearly two decades of consulting experience, Ryan offers both strategic perspective and practical advice on how CISOs can navigate these fast-moving trends with confidence. Schedule a call to learn how these trends impact your business here: Read our blog about 2025 CISO Trends:
Transcribed and scored by The B2B Podcast Index.
Welcome to Cybersecurity Business Podcast. I'm your host, Kevin Pouchet, COO of Klogix. On today's episode, we'll take a closer look at the evolving priorities of CISOs as we move through 2025. From new technologies to shifting business demands, security leaders are facing some of the most dynamic challenges we've ever seen.
Fortunately, to break it all down, I'm joined by a friend and colleague, somebody who spends every day working along CISOs to help them navigate these challenges. Ryan Spellman, who's our Managing Director of Consulting here at Klogix. Ryan, welcome. Hey, thanks for having me, Kevin.
It's awesome. I mean, as I was saying that intro, I can't believe we're talking about... trends moving through 2025 and we're more than halfway through the year. Oh, yeah.
I think that's just bananas. And, you know, we're recording this at the beginning of August and it's I can't believe it's the end of summer. At least here, we get a few more weeks until their kids go back to school. Ryan's in Orlando right now.
Is that where you are, Ryan? Yep. And the kids go back to school next week, actually. So it's a busy time at the Spelman household, that's for sure.
But it is crazy to think about. It's August, right? I mean, how much time has gone by and how much time is left? But there's a lot of great surveys that were done earlier this year, and I think the findings for them will keep carrying forward.
Good. Well, one thing I hope to hear out of Ryan. are food analogies throughout this podcast. Ryan loves his breaking down cybersecurity with very easy to understand food analogies.
And who doesn't like a food analogy? So I'm hoping to hear some of these. I got a few. Don't worry.
It's the thing that everybody can understand, right? Everybody's got to eat. So it makes sense. Everybody loves food.
So before we dive into detail, Ryan, talk to us. about what you're seeing in 2025 so far as the biggest trends shaping how CISOs approach cybersecurity. Well, Kevin, in our survey of CISOs that was done earlier this year, we talked to several dozen of them, actually, in the part of putting this research together. And we identified some key trends that are taking up a lot of attention.
They are, in no particular order, AI, identity, keeping pace with the businesses' needs from a security perspective. consolidation and optimization of tools and awareness. So if you followed a research in the past, some of these may not be too surprising, but taken as a whole, this is a real shift in some of the things that we've seen since firewalls and phishing. Well, let's dive into some of these.
So AI, obviously this is something that everybody wants to talk about, the good, the bad. When organizations start experimenting, let's say with AI, internally? How are CISOs getting involved to ensure those efforts stay secure? You can use AI and practically develop your own application now.
So I think there's this fear that it could be the wild, wild west if somebody doesn't take control. Yeah. I mean, that's that vibe coding concept that you hear everybody talking about. But it really starts with being aware and involved in these experiments.
Too often, security is being brought in after they've begun. In fact, some people even... advocate that, right? They say, bring security at the end.
And I think in my experience, that may be too late, right? The best scissors from our survey were engaging early and often with their AI -focused stakeholders. And they're starting from a position of yes and, where the and is, and we will make it secure. We'll take those efforts to do things the right way as opposed to doing things the fast way or the efficient way or the cost -effective way, right?
They're trying to build security in at the front as opposed to at the end. Man, I think information security professionals are now sounding like therapists, right? That's big in the therapy world. Don't use the word but, use the word and.
Yeah, that's huge. I mean, digital therapy, right? Digital therapy. Well, talk about AI governance, Ryan.
How are CISOs responded to new frameworks like the NIST AI RMF? You know, and others, I know you're a big framework guy. What role should... security plane shaping that strategy.
I love me a good framework almost as much as I love a good food analogy. So there's a lot of talk on this AI risk management framework and its European counterpart, ISO 4001, right? These are popular frameworks that are being utilized to help organizations assess how they're doing with regards to AI. It's not really a matter of if, but when people start asking more and more about how are you aligning with these frameworks?
We're already seeing chatter from clients. We're already having conversations with clients about this. And it's something that much like, you know, NIST CSF or ISO 27001 is likely to become an important part of any good cybersecurity program is how are you aligned with these AI governance frameworks? It's not, I don't think there's firm requirements yet in the sense of like regulations or there is Colorado dropped a regulation with a safe harbor for ISO or NIST AI.
So I imagine there will be some more requirements or some more references in law. But I definitely am starting to see more customers asking their suppliers and partners, hey, if we're using you for AI, how are you aligning with these two standards? So it's definitely a matter of when, not if, these frameworks become an important part of any good CISO strategy. Who has the edge, Ryan, in this world of attackers that are leveraging AI, assuming defenders are intelligently leveraging AI as well?
Is it a zero -sum game? As I talk to some of my threat intel peers, they say, you know, that the bad guys are using AI and they're getting frustrated with it. Same as corporations are getting frustrated. They're not seeing returns on their investments.
So I think thinking of the nature of this business, the defender is going to get the better benefit of AI because AI is going to resolve a lot of these simple processes. You know, hey, reviewing mobs or events, right, to free up time to focus on confirmed threats or going after things that they really need to be concerned about. Whereas for bad guys, the platforms aren't. Well, they have guardrails installed to prevent things like, you know, write phishing emails and like, although they can be jailbroken, there's not a lot of resources available to them and their process is a little bit more bespoke.
So I think the edge is for the defenders right now using AI, but that's really because of the sort of purpose built and tactical focus of the AI being utilized. As we start seeing agents appear in more places and doing more things for organizations, I don't think that's going to be the case. I think you're going to see a lot more focus in on. You know, how can AI agents be compromised by bad guys?
And that's going to open up a can of worms. We could talk about AI all day long, and sometimes I do, but let's move to what might not be grabbing headlines, but I think it's even more of a real -world problem right now for CISOs, and that's what's old is new again, and that's identity. And specifically... identity sprawl being a huge challenge for CISOs.
And maybe you can talk about that a little bit. Why is this a huge challenge and a huge topic right now, Ryan? Yeah, you hit it right on the head there. You know, this is an old challenge that's come back, right?
So I remember during COVID, it was identity is the new perimeter, right? Because all these users were getting, you know, forcing to log in from home. So people had to think about it. And they put together more controls around it, right?
But I think the problem is, is identity is, And this is what we identify in our survey is that this concept of identity sprawl, right? But I'll kind of step back a quick second here because when we think about this, why is identity such a big deal? It's about the blast radius, right? What does a person have access to?
How can they go laterally in an organization? What are the issues around it? If an account is compromised, if that identity isn't properly set up, properly managed, secured. right?
That blast radius can get very big, very fast. So I think the reason why there's a return to focus with identity is partly due to AI, right? You have all these new identities with AI, but also partly because you have an unawareness that if a compromise occurs on an individual, do I clearly understand what the full focus will be after the fact? And the answer for many of our CISO partners is no, I don't.
And that's not a comfortable answer, which is why identity is coming back to the top. And is this partly... have to do with just the increase in platforms and more so cloud services? Yeah, that's identity sprawl, right?
Right in the rip there, right? This is the spread of different identities, you know, all the different user account systems, the applications. It's a huge deal for the biggest companies because it's not easy for them to mandate SSO across the planet. But even your midsize companies are struggling with those edge cases or the business unit that's using some specialized tool or application that can't sync with Okta.
or what have you, right? That's really the risk areas here is that, you know, I have radiation software that I need to use. And if there's no single sign -on, well, it has to plug in the internet. It's accessible to the internet.
Now you effectively are at a weak point that your identities are only secure as that one application because they're still using the same emails, still using the same account, still using information, but there's no special protections on it. And that's a real concern. So bringing this back to AI with the flux of AI and all the non -human identities, Looking forward, what do CISOs need to prepare for? Yeah, they need to prepare for more granular role and permission management, which is unfortunately a big part of why identity is hard, right?
Understanding who should have what and why and how can it be maintained is difficult because everybody who works in an organization needs to have access to different pieces of information. But Copilot and those kind of AI tools, they're... They're kind of like water through an organization. I have a horror story for a client that enabled the copilot as part of a pilot, you know, air quotes, but they discovered that the agent had access to some of the most sensitive personnel files of the company, all due to poor permission management teams, right?
A link had been shared. Anybody who has access to this link can have access to these files. Well, that person was part of the copilot pilot group and everything was available. So sensitive information like bonuses, salaries, et cetera, were accessible to anybody.
who asked Copilot for that information. And that's only addressable by really understanding these roles and permission management, which really gets into the weeds of most organizations' identity structure, which is not easy. That's not something you can just throw people at for a little while and fix. This is a technology, this is a process problem, and it's a resource problem.
And it's not an easy fix, which is why I think this is rising to the top again. Let's move on to security keeping pace with the business. And let's talk a little bit, Ryan, about how security can keep pace, right? We know security is never done, of course, but how can CISOs frame cybersecurity as more of an ongoing investment as opposed to get trapped in sort of point -in -time spends, which could make their job and life much more challenging?
Yeah, you're absolutely right. I mean, so this is where that yes and is a good trick, right? If you're a CISO, yes, you know. yes, and we're going to try to help do these different activities or, you know, yes, and we're going to try to enable the business.
But I often use an analogy referencing one of my favorite things, which is a food restaurant. It's right there for you, KP. Pizza place. Think of a pizza place.
At the pizza place, you've got smoke alarms, fire extinguishers, and special insulation around the ovens. Why? Because when working with fire, you have to invest in patrols to prevent the place from burning down, right? When working with data, a similar mindset has to apply.
You wouldn't cut costs at a pizza joint by not replacing fire extinguishers and cutting power to smoke alarms, right? You're not going to say, yeah, those extinguishers, they're 17 years old a time, right? You're going to have to keep them up to date because you don't want really bad things to happen. And because you're dealing with fire, you have a responsibility to do that.
So similarly, if you're working with data, you have to keep certain controls at a minimum all year round, prevent something terrible with data from happening. Now all I can think about is pizza. I know, it's afternoon. How about CISOs?
Again, if you talk about avoiding a trap, I think some CISOs treat security like a checklist to satisfy compliance. Talk about what the downside of that is. I know sometimes it can potentially be easier to justify budget if it's a compliance -related topic, but that tends not to be the right type of budget. What are your thoughts there?
It's a great question. If you take that pizza place analogy one step further, there are a lot of benefits that come from managing the heat in a pizza place, right? So let's pretend that the smoke alarms and the fire extinguishers, that's your compliance checklist. You have to do that.
Code requires it. You have to secure your business with that. But then, you know, if you have a lot of seating in your restaurant, do you want your customers to just bake in that heat? I mean, it's pretty hot in a pizza place, especially in the summertime.
Do you want them breathing the smoke as things get burned? No. You want them to have a comfortable atmosphere. And pizza places that are well run...
Have even more creature comforts to let you forget that the fact is that there's a thousand degree oven just 10 feet away. You might see it, but you're not going to feel it. Managing cyber risk in a same way that is seamless and demonstrates maturity will make your customers, i .e.
air quotes, you know, your real business customers and partners more likely to come into your restaurant. So having strong security, having controls in place, having controls in place that are not creating undue friction, that are effective, right? The cheapest method may not be the most effective method or the best method or the most impactful method. These are the ways you can justify and say, hey, I know we have to do these things, but if we do these things better and the right way, we're actually creating a better experience for everybody, still being in security and doing it in a manner that demonstrates our ability and competence to deliver on what we have to do.
Job one is make sure the place doesn't burn down. Same thing, make sure that we don't have breaches with your data. That's job one for a lot of businesses now, especially those businesses that consume a lot of data in healthcare, finance, personal services. demonstrating that their competency is like having two pizza places to choose from in the summer.
The one that has AC running and the one that doesn't. The one that has AC running is going to be busy. The one that doesn't is going to be empty. So that's my second food analogy.
Two for two. There you go. One of the trends that I think we've seen each year over the past few years is consolidation or a push to optimize existing security tooling. Right.
We all know there's thousands of companies in our space right now. We've heard a lot about security teams trying to simplify their environment. So from what you're seeing, like how much of a priority is this consolidation right now, Ryan? And what do you see it as driving it?
Yeah. So I've been doing this for nearly 20 years and there's a cycle, right? As much as you've seen yourself, people buy tools, the final tools work, and they consolidate tools, right? That's the hype cycle around things.
I think this time around, there's a little bit more pressure from the actual business cycle. So I'll share one of the findings from a survey is that over 30 respondents who we interviewed saw their budget freeze or decrease. And that's likely due to these economic headwinds. So it's not a surprise people are trying to get the most out of their tools.
So while I definitely think certain categories of tools are feeling that whole cycle of, hey, this is new, new features, new ideas. Let's try this out. Okay, that doesn't work. Let's consolidate to what does work.
I actually think there's a lot more pressure right now because of the business cycle, right? We're seeing, maybe not a recession, but we're seeing some economic contraction. And people are asking hard questions like, hey, we bought this, you know, whiz bang tool two years ago. Is it really delivering for us?
Does it really do what we need to do? And I think that's definitely pushing on people because I can't remember a survey where we had such a high number of people facing a budgetary freeze in a while. are bigger than a breadbox, so to speak, that have traditionally been a little bit more cumbersome, a little bit more challenging to fully operationalize. Are you seeing CISO shift their investment strategies with sort of these traditional tools?
Well, let's dive into those tools in particular, right? So GRC and DLP. And those two, I think, are definitely victims of that tool -focused cycle more than the business cycle. I think it's pressure, but DLP has gone through cycles.
you know, needed. Then it was a pain. Then people said, well, let's find other solutions. And now it's coming back again.
It's in a cycle. But I think that cycle is putting pressure on it saying, you know, hey, this is a really hard tool to get right. And it can get expensive very fast. So people are taking a critical eye to it and saying, hey, if I cut DLP down to whatever I'm getting through Microsoft, maybe I could free up and have an FTE and maybe some funds.
Right. And same thing for GRC. GRC is like, well, I've got all these obligations, got all these requirements. The GRC vendors will share a lot of great features and a lot of them make your life easier.
But if you're not well positioned to utilize that tool, if you're not well positioned with the right understanding of frameworks, the right evidence that you collected, you're going to spend a lot of time setting things up with an empty restaurant. And, you know, use that metaphor again, right? You're going to have a lot of tables, but if you don't have the chef and the kitchen staff, you have nice tables, but you don't have what you need. And that's what GRC suffered from.
Too many people didn't have the right protocols, processes, and deliverable documents beforehand. And now they're looking at these empty boxes, looking at these tools and are getting the job done and struggling to fill the justification for why they need to keep spending the money for this tool and the time that they put into it to make it worthwhile. And DLP is to some extent the same problem, right? If I don't have good data classification and good understanding of my data, how can I really do DLP?
And those are areas that, you know, I think a lot of people are recognizing that maybe I'm not ready for DLP or not ready for GRC and I need to sit down and really think about what I'm using these tools for. When it comes to... detection tooling. Sometimes there's this notion that security teams could be over -reliant on their detection tooling.
Is this true? And what are some of the signs that indicate a team might be overly reliant on their current detection tooling? Yeah. So I think there are some security teams that forget that what gets measured gets monitored, but there are things that are hard to measure that need monitoring.
And that's where I think there's that that fear about, and I over -rely on my detection tooling, right? If I, if I have, you know, CrowdStrike everywhere, is it really protecting me? Yeah, it should be, right? Same for Sentinel -1, same for insert your detection tooling.
But if you didn't have the package or you don't have the deployment that it covers your IoT devices or cloud applications, are you missing things, right? You know, there's that famous study from World War II where the planes that came back, you know, they noticed that the gunshots that hit the planes. didn't seem to touch the engines. And they said, okay, we'll put armor everywhere but the engines.
They didn't realize that, you know, the engines that got shot were the ones that didn't come back, right? So if you're not seeing things, then you can't really say your detection is really covering it. And that's where I think there's a concern. All quiet here because we're not seeing signals and signatures, but bad guys are going to find those areas that are blind spots and exploit them.
And that's where your real risks happen. I think that there's a feeling of, I'm not seeing everything I need to see, but I'm overly reliant on the tools I have to be confident that security is in place. Okay. The last trend I want to explore with you could be the most powerful.
It's something that I've talked about before on more than one occasion on this podcast, and it's culture, awareness, and leadership. And I know, Ryan, you've spent part of your career traveling around the country talking to organizations about this exact topic. Talk for a few minutes about what it takes to build a culture that endures beyond just the latest threat or the existing compliance cycle. Yeah, exactly right.
And I think there's an attitude a lot of citizens that it's hard to get through and it has been hard. It's hard to get people to care. And to your point, you know, when I travel the country meeting with states and cities and companies about security awareness, that's one of the key things that differentiated that aware. from a less aware company to say that is ownership.
When people feel like what they do matters and including what they don't do, they're not clicking links, then security will follow. And that's not easy to instill and create. And that times requires more than just the CISO. But when it's achieved, people are less likely to click links and less likely to fall prey to social engineering because they care.
And that's where, you know, I don't think we have statistics on it, but anecdotally, I find that smaller organizations. where there is a sense of pride and ownership by the employees and the teams tend to do better against phishing testing because they do care, right? They're not just like, I'm a cognitive machine. Who cares if I click the link?
It's not my problem. No, they do care because they feel tied to either the mission or the business or the opportunities that they see there. And that feeling of ownership is a cultural trait that I think in a lot of ways is not considered by security teams when they put together their slides and their PowerPoints, et cetera. But it's something they need to really talk about.
Like, this is why it matters. This is why it's important. This is what the impact is of failure. And when people own that, if people understand that, that makes a big difference.
Well, you mentioned phishing tests. I think when I bring this topic up, you know, you tend to hear the same response from certain companies. And they talk about how great they fared in their phishing test. And they use that as sort of a litmus test to measure awareness.
Is that really building a security culture? What's missing? I can't imagine that is a complete equation. Yeah, we've been doing phishing testing for years, and it still is an effective technique for the bad guys, right?
So I think, unfortunately, phishing testing leads people to just learning one mechanism, right? It's almost like teaching to the test, right? So it's just great, but then you don't really understand how to think about the concepts. So I always encourage organizations to perform phishing testing.
You should not do it. But try and vary it up with texts, phone calls, other things, right? And explain why you're doing it. I see too many organizations say, we do a phishing test once a month.
Do you follow up after it to explain why the phishing test was something to look for? Do you follow up with people who passed and failed about what they need to learn from it? You know, a phishing test is kind of like, without that, is almost like a pop quiz without a lesson. Sure, you kind of figure out who's been paying attention in general.
But those who really need help or are not quite sure why they got the answers right are not sure why they failed and even less sure about how to get better. So I think we need to really make sure that when we say we're doing phishing testing, it's coupled with we do phishing testing and we do awareness training for all. And when we do phishing testing and we do explanations of why this matters, or we do phishing testing and we vary it up so that we're showing people that the bad guys don't just try one method.
They also do SMS texting. They also do... social media. They also do phone calls, right?
They're going to try to come at however they can and you need to be prepared. And again, that goes back to the ownership. If people understand that their failure could lead to some real impact organization and they feel ownership and the success of the organization, they're going to want to learn. They're going to want to learn how to defend themselves and they're going to be better equipped to address those things.
So Ryan, question, when you think about these trends that you're seeing throughout 2025 and some of the challenges that go along with those trends, how can Your organization, Klogix Consulting and Advisory Services, how can your organization help? Yeah, it's a great question. And I think it's something that a lot of our clients have these issues in small scale, big scale, different ways. Typically, the way we usually diagnose this is with an assessment, right?
So if we're talking about AI, we'll do an ISO 4001 readiness assessment. So helping you understand your alignment with that governance framework. When it comes to identity, we tend to look at this from a programmatic review because identity doesn't have a firm. standard to adhere to is different for every organization.
And this is where our approach of coming in, meeting stakeholders, reviewing tools, processes, and procedures, and then understanding where you are today and where you want to go becomes so critical, right? We have experts who know all about these different systems and different ways to utilize them and achieve those business goals using identity in the right, smart, effective way. We approach it from that perspective. When it comes to just generally keeping pace with business and consolidation optimization, We actually have a whole process around that called our technology rationalization, which is a great way for us to come in, look at how you're doing against specific control areas of security, and kind of map out which tools are working for you and which tools are not, right?
Leveraging the vast amount of information that Klogix has from working with so many different providers and solutions, we, as well as our own research and our experience with other clients, we're able to help you triangulate and say, you know what, maybe we don't need three of these, or maybe we only need one of those, or maybe we actually can work with this tool set to actually address this gap here. We put that together in a nice package and hopefully help you identify some savings.
And last but not least, our team does a lot of user awareness training, whether it's helping you augment your program with newsletters, additional material, flyers, posters, or whether it's speaking on October Cybersecurity Awareness Month webinar, which we are absolutely happy to do for any Kaleidos customer. And in fact, I will go so bold, KP, as saying, if you want us to join you for one of your webinars, we will do a complimentary to any Kaleidos customer. We do that for folks, right?
We do webinars, presentations, and the like. But it's a great way to bring outside expertise to raise awareness about these issues. And that sometimes is really powerful, right? People who deal with this on a regular basis, dealing with threat intel, incidents, tabletops, et cetera, can bring some really interesting stories to an audience that would love to just learn more about why they should care.
Again, owning it, understanding their impact, that's helpful from having those other perspectives. So that's a lot of the ways we can help people approaching these trends. And we are currently engaged with many different K -Logic clients on exactly that. Which is why a lot of these findings didn't surprise me.
We're seeing this across the board. Well said, Ryan. Huge thanks for all the insight. That about wraps up today's episode.
So I want to thank you for sharing with our listeners. My pleasure. It was great having you. It was fun.
Yeah, definitely. And you got your food analogies. You had three food analogies. Well, if any of these food analogies or trends resonate with any of the listeners out there and you'd like to take the conversation further, you can set up a 30 -minute call with Ryan.
He'll take a deeper dive into some of these topics and talk through really what they mean for your organization and how his team specifically can help. There's a link in the show notes and you can schedule a time specifically with Ryan or just head to our site. klogicsecurity .com.
You can also find and listen to all of our podcasts. So for now, thanks again for listening to Cybersecurity Business, and we'll see you next time. Thanks, Ryan.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.