The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/CyberMAYnia
CyberMAYnia artwork

43 The Hidden Power of Cybersecurity with Rotem Bar

CyberMAYnia · 2025-06-02 · 37 min

0:00--:--

Key moments - from our scoring

Substance score

39 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality6 / 20
Guest Caliber10 / 20
Specificity & Evidence9 / 20
Conversational Craft6 / 20

Rotem Bar brings nearly three decades of cybersecurity experience spanning tech, finance, and operational technology environments. Rather than positioning cybersecurity as a department that restricts business activity, Bar advocates for repositioning security leaders as organizational enablers who use security requirements as catalysts for broader business improvements. He illustrates this through a concrete example from an OT manufacturing environment where upgrading endpoints to meet security baselines tripled production throughput - transforming a 30-minute batch process into 10-15 minutes. Bar emphasizes that CISOs should focus first on process formalization and organizational discipline before investing heavily in new technology. He also addresses the challenge of AI adoption in regulated environments like healthcare, arguing that blocking tools is futile; instead, security teams must understand and secure how employees will use AI anyway. The conversation explores how security can become a business lever rather than friction, why large enterprises struggle with decision velocity compared to smaller organizations, and how to build acceptance for continuous security change rather than demand transformation overnight.

Key takeaways

  • →Frame security budget requests around business benefits beyond compliance - packaging infrastructure upgrades as efficiency gains dramatically increases approval odds and demonstrates security's value as a business enabler.
  • →CISOs should prioritize formalized processes, exception management, and organizational discipline over technology purchases; a $100K investment in process maturity typically delivers more value than upgrading a firewall.
  • →AI cannot realistically be blocked; instead, security teams must establish secure ways for employees to use AI tools, such as landing zones with monitored access, while acknowledging that determined users will find workarounds anyway.
  • →Security awareness and policy adoption improve when organizations accept continuous change as normal and implement changes incrementally aligned with company maturity, rather than attempting year-one-to-year-13 transformations in 12 months.
  • →The CISO's core responsibility is bringing organizational discipline and formalized processes - without this foundation, the security leader must work excessive hours managing chaos that should be systematized.

In this episode

  1. 1Rotem's 25-Year Cybersecurity Journey and Passion for Teaching
  2. 2Shifting Cybersecurity Perception Across Industries: From Cost to Enabler
  3. 3Demonstrating ROI and Business Value Through OT Infrastructure Upgrades
  4. 4Process Management and Organization as Cybersecurity Foundations
  5. 5Policies, Procedures, and Cultural Alignment in Security Programs
  6. 6AI Adoption: Security and Scalability Challenges
  7. 7Managing AI Risk in Healthcare: Wife's Diabetes Business Case Study
  8. 8Scaling Security and AI Adoption in Large vs. Medium Organizations

Mentioned

May BrooksRotem BarChatGPTMicrosoftGoogleAppleMicrosoft 365OpenML

Guests

Rotem Bar

Topics in this episode

CISO strategy and ROI messagingProcess formalization and organizational disciplineAI adoption in regulated environmentsCybersecurity as a business enablerEndpoint protection and infrastructure upgradesSecurity policy development and maturity modelsChange management in security programsLarge enterprise decision velocityChatGPT and generative AI governanceCloud and hybrid infrastructure security

Questions this episode answers

How do you get executive buy-in for cybersecurity investments when the business is profitable without them?

Reframe security requirements as business catalysts for improvement rather than pure security costs. Connect the security need to efficiency gains (e.g., endpoint upgrades that enable faster processing) or revenue enablement, and position the CISO as a catalyst for modernization rather than a cost center demanding budget.

What should a CISO prioritize when they have a fixed budget - new technology or process improvements?

Prioritize formalized processes, decision-making structures, and exception management before technology. Most companies struggle to manage ongoing procedures and decision-making, and fixing those foundations delivers more value than incremental technology upgrades.

Is it possible to block employees from using AI tools like ChatGPT?

Blocking AI is not realistically feasible - employees can screenshot outputs, describe prompts verbally to AI, or use personal devices. Instead, establish secure landing zones with monitored access to AI tools for approved use cases, acknowledging that some AI usage is inevitable.

How do you implement security policies without overwhelming employees with too much change at once?

Implement policies incrementally aligned with organizational maturity and culture rather than mandating large leaps. Establish the expectation that security continuously evolves, so employees accept ongoing policy updates as normal rather than viewing them as disruptive shocks.

How long does it typically take large enterprises to adopt new security tools or technologies?

Large enterprises face significant integration hurdles; even straightforward integrations like adding a remote access company can take four months or longer due to big procedures, decision-making complexity, and bureaucratic requirements.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

A handful of actionable ideas surface (OT batch throughput tripling after a security-driven upgrade, process management outperforming technology spend, AI data-storage risk framing) but they are buried under extended small talk, mutual validation, and the pop-quiz segment. The insight rate per minute is low for a 37-minute runtime.

each batch cost them around 30 minutes. Around 30 minutes. And the actual work was 10 minutes... when they upgrade the computer, instead of making half an hour, uh, batch, they work for 10 to 15 minutes batch. So that give them like triple the work
if you take this money and put it on the process management thing, it's gonna be much more value to you than any other thing. Okay. Even upgrading the firewall.

Originality

6 / 20

The dominant frames - 'department of no vs. enabler,' 'cybersecurity as business supporter,' 'you can't block AI like you blocked the Internet' - are well-worn industry talking points. The binoculars metaphor and the AI CISO prediction add minor novelty but nothing genuinely contrarian or first-principles is argued.

And I've seen it in other, in, in other organizations as well. I've heard it from other guests. So I think it's, it's a wonderful way to sort of reposition Cyber security less as a cost center
we tried that back in the early 2000s to block the Internet... What makes you think it'll work today?

Guest Caliber

10 / 20

Rotem Bar is a genuine practitioner with ~25 years of CISO experience across OT, finance, and large-scale enterprise environments, which gives him real credibility. However, the conversation is conducted as a casual chat between friends and does not draw out the depth of that experience beyond a couple of anecdotes.

I'm, um, working on cybersecurity, something like around, uh, 25 years, maybe 26 around that
you've been a CISO in various companies, from small to very big companies... We're talking about hundreds of thousands of employees worldwide and plants and critical... assembly lines

Specificity & Evidence

9 / 20

The batch-processing story (30-minute batches cut to 10-15 minutes, tripling throughput) and the lawyer backup system (five encrypted clouds, 5% daily-change ransomware tripwire) are genuinely concrete. Most other claims, however, are unattributed and vague - companies are never named, the $100k budget scenario is hypothetical, and industry comparisons lack data.

each batch cost them around 30 minutes. Around 30 minutes. And the actual work was 10 minutes... instead of making half an hour, uh, batch, they work for 10 to 15 minutes batch. So that give them like triple the work
if more than 5% have been done daily, he's going to stop. The back end says, listen, I think there's a ransom right here

Conversational Craft

6 / 20

The host rarely challenges claims or probes for mechanism and evidence; most follow-ups are validating agreements or personal anecdotes. The pop-quiz segment consumes several minutes with zero substance, and the overall tone is a friendly chat between colleagues rather than a disciplined interview designed to extract insight.

What are the, some of the differences that you see in the perception of cyber security in different industries?
And I really don't think it's a trend. I think it's, it's really a revolution.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B59%
  • Speaker A41%

Most-used words

cyber25security23cybersecurity19different18today15ciso12podcast11understand11problem11information11story10completely9change9computer9crazy8policies8

Episode notes

In this episode of CyberMAYnia, I sat down with cybersecurity expert Rotem Bar, who brings over 25 years of experience to the table. We talked about how cybersecurity is too often seen as a blocker, when it should be recognized as a true business enabler. Rotem shared powerful insights on the challenges of scaling security in large organizations, how AI is changing the game, and why understanding your data risks is more important than ever. His message is clear: if you want to adopt AI, you need to start with your data. We also touched on creative ways to approach cybersecurity awareness and what it really means to lead security with purpose. Rotem’s story is a reminder that cybersecurity, done right, can bring structure, clarity, and real value. This one will get you thinking. Don’t miss it.

Full transcript

37 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Cyber talks with the brightest minds in cyber security, discussing risks, AI emerging threats, workforce challenges, and more. With your host, May Brooks.

Speaker A: Hello, hello, hello, and welcome to another episode of Cybermania. Welcome. With me today is a good friend, a, ah, wonderful podcaster, Rotem Bar. Rotem, how are you today?

Speaker B: Hello. I'm great, thank you so much. Me?

Speaker A: Yeah, it's. Well, we had a discussion yesterday on something completely different and I said, wait a minute, why have you never been on my podcast? I'm on your podcast every few weeks.

Speaker B: Yes. And that's you, one of my panelists, uh, like the ongoing panelist in my podcast in Hebrew. And I'm m shocked that you haven't

Speaker A: invited me here because usually I try to invite people I don't know, but I decided today to invite someone I do know because I don't know everything. I don't think I know everything. So now we're gonna change that.

Speaker B: Yes.

Speaker A: So as always, we'll start this conversation with you telling us a little bit about you, yourself and your crazy story in cyber security.

Speaker B: So I'm, um, working on cybersecurity, something like around, uh, 25 years, maybe 26 around that. And I was always working on security, on development of software and uh, infrastructure. And it was always a mix for me. Like, I really like technology and cyber was something that I can, you know, go into it with both hands, something really, really good because it has so many different challenges that no other thing have. Except now AI, obviously, which is another podcast.

Speaker A: But that, Yes, a whole different story.

Speaker B: A whole different story. And what happened here is that I'm working all my life in tech and cybersecurity provide me the ability to work with tech and people. It's like mixture together and that bring me to something really, really nice and I really enjoy. Wake up in the Morning says I work in, in cyber.

Speaker A: Yeah. So that's amazing. And I think that your passion is something that we both share this passion for this industry. And it is something that has been very evident in your career throughout its entire path. This is the podcast that we do that the AI podcast. And the Cyber With Friends podcast is something that it's not your first podcast. You had a podcast before. So you've been basically contributing to this community for so many years. So can you tell us a little bit about what first even initiated that idea of giving back and teaching and doing a podcast and other things that you do?

Speaker B: Well, I think in the last 15 years now I'm lecturing, uh, uh, almost all the time for students, uh, Regarding, uh, cybersecurity. And I really like to make the session enjoyable for everyone. That mean that I add personal m. Stories that I have been dealt with, weird, uh, stories and all the things that if you work in the industry, you have some. And I really enjoy to tell people what to do, how to do it, and teach them new ways of thinking, change their mind. You know, one of the biggest thing I teach people is change the mind of what you think a CISO is. Most people think that a CISO is one thing, but in the end, they go to work and they see it's a completely different thing. And in most cases, it needs to be third thing, obviously. So I need. What I really want to do was tell them what is need to be done, change their minds to something much better than what they thought they need to be done.

Speaker A: That is fantastic. And you've been a CISO in various companies, from small to very big companies.

Speaker B: Yes, very big ones.

Speaker A: Very big companies. We're talking about hundreds of thousands of employees worldwide and plants and critical. Well, not critical infrastructure, but critical, uh, assembly lines and things like that. What is the biggest change that you see when you look, because you've been in different industries and you've been in the tech industry and the finance industry and the, let's go traditional OT industry. What are the, some of the differences that you see in the perception of cyber security in different industries?

Speaker B: I think the biggest thing in perspection is people take cybersecurity in the way that it's not supposed to be taken. It's like a pill. You know, you need to take it in the morning, but you take it afternoon, but you need to take it in the morning, sir. So cybersecurity is the same. You need to take it in a different way. Most people see cybersecurity as something that constrain you, tell you what, not to be done. Things that, uh, said, you know, there's rules, regulation, policies. It's. It's the words that says, stop doing everything. Like, listen to me, man, you cannot do that. It's like, uh, the New York policeman says, put your hand on the wheel. Nope. Yep, Exactly. So I think cybersecurity is different as I think the way that we see now. Cybersecurity, with all the changes that we have, it's an amazing industry that change all the time, is that now we have all the knowledge, all the technology, and all the people that actually do things differently. And when I say differently, I'm definitely going to the way that cybersecurity as something that inhibit work go to go to be an enabler, like business enabler, work enabler. And I always think about, you know, when we talk with old people and old people generally fear about giving their credit card over the phone, over the over or in an app. But we are the youngsters.

Speaker A: We're not the youngsters anymore, dear.

Speaker B: We're not the youngsters anymore. There is so many apps that have my credit card because I trust them and I understand what is the risk regarding how to, and how to manage that risk. And they don't know how to manage that risk and that they block everything. So I think that regarding that, and when we see cybersecurity and an app is a good idea, because if you trust an app because of its cyber security, because of whatever they are doing right, this is something that can help the business. And this is from the outside, not even talking about from the inside. Okay. Yeah, the inside is a different story altogether.

Speaker A: Yeah, it is. And in one of our previous conversations we talked about your time in an OT environment and you gave a great example about how M. I wouldn't say you m managed to actually measure the ROI of cyber security, but you did manage to change the perception of upper management and how they perceive cybersecurity from a monetary point of view.

Speaker B: Okay, so there is a few stories I gonna, I gonna share one. Okay, there is one story that I've gone to do a risk assessment to a company that have a lot of old equipment, like a lot of old equipment. And I've done all the risk assessment, you know, risk assessment, everything bad, bad, bad, worse, worse, terrible. Criticality. Yeah, exactly. And I, I go to the CEO and he's, he, he talking, uh, when, when he talked with me, he says, okay, I understand there is a lot of problem, there's a lot of gaps here. What can I do? And I told him, listen, the first thing you need to do is understand that it's going to cost you a lot of money. It's not a simple patch. And I, I, I can hear his conversation with himself that more everything is run, everything is running. Okay, I'm making good money. And this guy in front of me asked me for a lot of money. Uh, I don't like it. The body reject everything. And in the end when I talk with him and explain him, listen, it's not that we, you have all the old equipment, all the old equipment is not optimized, is not good, working really, really fast. So when you go and have like nothing going to be here in the Next two weeks or three weeks. So let's make like three year plan. And in that three year plan, let's change things, let's upgrade the plan, let's make more money. Okay. Use me as a, uh, catalyst and not something that says, okay, I need to throw a lot of money because of something called cyber. Don't use that. Use that as something good that we want to invest to get more money. And cyber is only the trigger for that.

Speaker A: I mean, it's the driver. Yeah. And sometimes when we update something or upgrade something to support cyber requirements, we actually get other benefits. And this is something we also talked about that you had to upgrade some of the endpoints and they were running slowly. Yes, but it's a great story I

Speaker B: wanted to show you. This is the company that actually works Rocket, and we have like a, uh, an old plant that have batch processing. And the computer was so, so old, like 10 years old. And it wasn't moving like the mouse, you know, like moving. It says, just a second, just a second. Okay, now like that. And what happened there is that each batch cost them around 30 minutes. Around 30 minutes. And the actual work was 10 minutes. So the batch was a lot of computing running. Uh, click here, click there. And because of the computer is so slow, they cannot do that. And when I arrive, I start asking the question, okay, this is an old computer, it cannot run the endpoint protection. We need to upgrade that because there is a minimum requirement now. And they said, okay, now cyber have the budget, so let's upgrade the, the computer. And when they upgrade the computer, instead of making half an hour, uh, batch, they work for 10 to 15 minutes batch. So that give them like triple the work on the same thing, only replace the computer and a, uh, small endpoint production for me.

Speaker A: Yeah. So that is, I love this story because it shows how cyber security. I'm not sure you, maybe you did think that this will be a benefit of this upgrade, but sometimes we don't even think that way. And maybe we should start thinking that way, that if we require a budget for something, in this case an upgrade of an endpoint, what are the other benefits? Because if we can try and build a story around the other benefits, our chances of getting that budget increase so much. And seen that in, and I've seen it in other, in, in other organizations as well. I've heard it from other guests. So I think it's, it's a wonderful way to sort of reposition Cyber security less as a cost center. M more of a value creator or a Business supporter, not just a business enabler. Because one of the things that I always, we always talk and we had a lot of conversations around being business enablers and not just being the no people, the department of no. But being the department of. Yeah, but. Yeah, yeah. Which is okay. But it's not just being an enabler, it's being a supporter. We should support the business. If the business wants to go in a sim, in a, in any direction, it doesn't matter uh, which one. And even if we think there will be a lot of cyber security requirements involved in that direction, isn't it our job to find a way to do it and not tell the business, oh, no, we can't do that because of this, that and the other.

Speaker B: You know, let's think about something completely different, okay? Most of the businesses today, like even big business, even big companies have really problem, manage their ongoing task, ongoing procedures, okay. Like really, really problem with that. And as a person that, you know, uh, side story, as a technical guy, to try to talk about things like with human things, like I needed to let you know, like a surgery to, brain surgery to implants.

Speaker A: That's their language.

Speaker B: So today when I go to a company and I talk with a CISO and I tell them, okay, you have $100,000, okay, what you gonna do to them? Most of them gonna say something regarding technology. Okay. And in most cases they are completely wrong. Completely wrong. Because in most cases those company has really struggling to manage how their decision making, how they're using, uh, how they manage their exceptions, how they manage their uh, uh, ongoing processes. So if you take this money and put it on the process management thing, it's gonna be much more value to you than any other thing. Okay. Even upgrading the firewall. Okay. Like that. It's like crazy thing when you take a, uh, company and try to formalize it. And I think one of the biggest, biggest thing that cyber security can provide to a company is organization. It can organize thing because cybersecurity, hate chaos. Like hate chaos. If you have, if you're cybersecurity specialists, if you are CISO and you have chaos managing the company, you're doing really bad job. You need to do something really organized. If you don't do that, consult with something that actually someone that actually do that, ask friend, talk with me or me, start with something. But CISO need to be organized. Is the only single person in the company that everyone depends on them that it's. Everything is organized. And if it's not organized, he need to work extra Hours for that.

Speaker A: I couldn't agree more. I remember that. I remember that when I started doing policies and procedures, I sort of looked down at it because I was a techie. I used to configure the firewalls and do the pen testing and suddenly they wanted me to write policies and procedures. And I'm like, yeah, yeah, I can write whatever, but it doesn't work that way. People used to ask me when I was back where in the day there was, I was a consultant, people asked me, can you give me a set of policies? Yes, I can, but it will be completely irrelevant for a set of policies. Today you don't need me, you need ChatGPT. And I'll seek for uh, password management policy. And it will give you a great template for a password policy. But building it, formalizing it as you called it, to my organization, to this specific organization, to what they can handle and what they can't handle.

Speaker B: What is with the culture of the company?

Speaker A: Exactly. With the culture, with the maturity of the company. If I come to a company that never done and we'll stay with passwords that doesn't have a, uh, pulse with policy or has a very simple password policy, six characters, no complexity whatever. And suddenly I tell them from tomorrow morning you have to do 12 characters and high complexity and two factor authentication. There will be. What is going on? Have I resigned and joined a new company and no one told me? It's too big of a gap. And I've seen it in awareness as well. People would come to me and tell me we never had a security awareness program. Now we want to do everything. We want to do this and this and this and wait. You need to learn to walk before you learn to run. You can't just come and bombard people with new policies and procedures and ideas and things and try to take them from year one to year 13 in 12 months. It doesn't work.

Speaker B: Definitely gonna say that the best, like the, the sweet spot of what you said now is starting running with the people and make them understand that security is always changing. So tomorrow morning something new is going to happen. Something new is going to be on uh, their desk. Okay. The password is changing now there is a new policy here, policy there and they going to accept that. So when we take our organization and people are much more acceptant that their acceptance rate is much better regarding the security, that CISO is doing a really good job.

Speaker A: Absolutely. And you talked about the technology that always changes. So I try not to say AI in every episode, but I think this Time we have to. Because uh, I think one of the first conversations I had about security and AI and AI in general, like the acceptance of AI as a trend that is in our lives, I think it was with you.

Speaker B: Let me ask you a question. An AI, uh, is a cloud based operation.

Speaker A: Yes and no.

Speaker B: So I'm gonna ask you another question.

Speaker A: Okay.

Speaker B: If you go to a company, if you go to a company and you ask them, okay, using uh, any AI, any AI like ChatGPT, are you a cloud user? Are you using cloud based uh, products?

Speaker A: Yeah. So that's it.

Speaker B: So that question is no more irrelevant because everything is interconnected because I have my own infrastructure inside and my semi owned list, uh, infrastructure outside. So everything is connected.

Speaker A: Exactly. And even if it's not today, even if I don't use cloud per se, if I use a single cloud provider, a single. I have, I don't know, Microsoft 365. I'm using AI whether I like it or not, because they're using. So I want to ask you about this shift because you adopted AI and we have so many conversations around AI. We're both geeks. I think you're a bigger geek than me. I'm not sure. Thank you.

Speaker B: I don't know if it's okay, but thank you.

Speaker A: I don't know if it's a compliment, but you started really diving into AI in the early days of. No, I think it was November 22nd.

Speaker B: Right, stuff like that. Uh, actually I actually used like open openml and like yeah. 10 years ago when I was programming and trying to, to find similarities in pictures and work some with, with some of those uh, module. But AI as we know that. Yes, from, from that.

Speaker A: Yeah, I think that, I think that that concept of AI. Well no, the concept of AI is not new but the adoption of AI as like commodity, that is very new. So what drew you? Because you really adopted it in your business as well, in your wife's business as well as part of the, let's call it tech stack. And you've made this adoption very quickly. What enabled you to do that?

Speaker B: I think the assurance that whatever I do, I do in a secure way. And once you solve that fear, you can run really, really fast, you can be really creative and you can fly. Okay, so I'm going to give you something even more specific. My wife business, she have uh, business tripping people with diabetes. Diabetes. And uh, this is like health, uh, information, it's like really critical. But they, they, she need to work with AI because everything is scaled like everything Is scaled. What do you do? How can you make the, the usage of AI secure in one side, but in the way that it's not gonna harm those patients? Okay, so once you solve that problem, because this is a problem, many people don't know this is a problem. But once you understand it's a problem and you can solve that, like everything going to be much more secure and better. Then she can fly and do crazy thing, like crazy a thing. And she can work with employees, be like um, uh, GPT is like, like you know, for specific things and work, add more automation and build everything in the company in a way that it's scalable, secured and can give you the ability to think ahead and not what happened before. And this is what business need to be done.

Speaker A: I agree, but we both done the same for our own business. In your case, for your wife's business as well, which are smaller businesses. You also use a lot of automation in the business, you know, both your businesses. So it's easy for me to say it's, it's actually very different to have someone that I know on the podcast. I might, I might start doing that. It's, it's very different. How do you scale that? That? I think that with a startup or with smaller companies, family owned businesses, it's more flexible. Especially when you do things from a security point of view. I remember starting my first company, starting Helena, um, back in the day, like the first thing, because I'm a security professional, the first thing was, hmm, should m I do this or that? Um, this one is more secure. Yeah, it's going to cost me 10 doll a year. I don't care. I don't care. And from day one I had backups and procedures and policies, uh, some of them written, some of them not backup policies, restoration and like everything that you would expect in a big company because I came from big companies. The question is, can you scale that flexibility, that adoption rate that you can do in your own business, in smaller business, in the lodge? And you were again for huge companies, how can you scale that to large environments?

Speaker B: No ma'.

Speaker A: Am. No ma'. Am. No, no ma'.

Speaker B: Am. Definitely no. Big companies have big problem, big procedures, big decision making. You know, when I was working in a really big company and we want to use to bring a, uh, company that will help us making uh, remote, uh, remote access for computers. That company needed like four months just for integration. Okay. And this is like an easy integration. It's really, really hard when you have like a really big enormous company. It's like really, really big, uh, really really hard. So it's not the same. I gonna say that if you're talking about small and medium businesses, like medium, I think up to 1,000 people, it can be much more easier to do things like I'm looking at cybersecurity as binocular. You know when the ciso, when someone sits with the CISO and says, okay, I can't see, I need to do something, this is the thing I need to do. And the CISO go and adjust the binocular up, uh, to the point that you can see clear and then you can run. There's no problem with security, you can come and ask, listen, I'm not sure it's going to fix you, but once it is adjusted the binocular, you can see clearly far, far away.

Speaker A: Yeah, well I agree and I disagree because I think, well I agree about very big companies. I think that it takes some time to even map out where the vulnerable and where the opportunity lies. Even I want to adopt a new technology and in this case we talked about AI, but I think it's true for a new initiative. We had the same. We still have many companies that do not utilize automation to the extent that they can, which is a shame in my eyes.

Speaker B: But even for the minimum that they can.

Speaker A: Yeah, like for a lot of people, they think the only thing I can do with automation is email sequencing. Uh, no, no, I mean, yeah, it's absolutely, use it for email sequencing, it will make your life much easier. But no, you can do so much more with automation. Um, but when we're talking about medium sized companies, sometimes they're afraid to take a decision. And I've talk to a colleague a few months ago, maybe two months ago, and they decided as CISOs to block AI altogether. And I looked at him and I was like, dude, we tried that back in the early 2000s to block the Internet. I generally have like white lists and it didn't work. What makes you think it'll work today? Like every last night my daughter comes up to me and tells me, mom, do you know this AI tool? And she showed me the AI tool and I'm like, no, never heard of it. And she wanted me to buy her the premium account. So I was looking at it and had to go into there's an AI for that. Find the alternative, see which one is best. The one she had is actually fantastic. So I decided to buy it, uh, for content revision and everything for her schoolwork. And they actually blocked it at school and I was like, why? Why? It's a tool but it's impossible to block AI how will I block AI?

Speaker B: You know, I've talked with a friend of mine, is a CISO of a really big bank like two, uh, weeks ago and he told me, listen, we blocked all the AI that can, that can be work. We have a special uh, landing zone for charge p. T And I provide that specific account or uh, account account to specific people that actually need this for their work. But that's it really small, small scale. And I'm, I'm over the front with him and says okay, but you understand that they don't need the computer to use AI and he says what do you mean? They literally picture the screen and send it to AI and he tell them what, what he sees and now ask the question. And he's like, oh yeah, I didn't thought about that one. So yes, it's A.I. a.I. Is everything. And when we see the publication and the events that Microsoft, uh, Google and Apple are giving now, everything is AI if like two years ago it's like a small AI and last year it's like some, you know, AI this year everything is AI Like I think Microsoft is going to change their name to Microsoft AI or something and Google something. It's like that crazy.

Speaker A: And I really don't think it's a trend. I think it's, it's really a revolution.

Speaker B: Do you know how would you understand that this is a really revolution that's going to stay Because AI was a buzzword two years ago and now the next buzzword is msp. Okay. It's also connected to AI So we understand that even the next buzzwords is connected. Yeah. So that's, that's crazy.

Speaker A: Anyone listening to us hasn't adopted the AI into their lives yet. What advice would you give them?

Speaker B: I will definitely tell them that AI is a game of data. Okay. It's not about the process of the data, but the data. Where the latter uh, lays, where is the, where the data rest. So if you using AI you want to understand that you need to provide it a lot of information. He need to store that information and then retrieve it for you. Okay. Leave the part about the processing, okay. Because this is something that is critical for big businesses. It's not critical for small and medium. Okay. And let's talk about the specific regulation like heap or something like that. But specific talk about, let's talk about the storage, the storage itself. We can, if we are using ChatGPT, like free ChatGPT or free Gemini or whatever. We don't control that storage. It's there for us, but it's also there for them to use. Okay. Yeah. So it's okay if you have homework and you upload that homework and you help them with that, no problem with that. But if you upload your information, where you live, what you do, Credit, uh, card. We're not going to save in credit card, but information about your family, specific information about you, medical information that I saw people. Yes.

Speaker A: Upload. Yep.

Speaker B: That can be used again. If someone asks ChatGPT or Gemini, he will give them your information because you gave them that information. So you cannot control this information. I understand that today, uh, there was a nice commercial that people sent me like two years ago in German. In Germany, that nice couple taking picture of the, of the kids. And uh, they published online and after a few days it was harming the kids because they open, they build a module about the kid. Now they know how they're going to be, how they're going to be growing up and crazy, crazy thing. We're not talking about that. This is like completely different thing. We're talking about actually your data. And this is, this is what crucial. Um, and yeah, every business is different. Every, every business need to see different risks. For example, I have a brother that is a lawyer and I integrated in on his system, uh, an application that backup all this information to five different clouds, all encrypted. So if whatever is going to happen, whatever is going to happen, he going to have at least one backup and that system also have the ability to see how many changes that were done. So for example, if more than 5% have been done daily, he's going to stop. The back end says, listen, I think there's a ransom right here.

Speaker A: Yes, fantastic, fantastic. Um, I will share that at the end of today's, um, episode. I'm going to upload a little nugget that Rotten created because he knows that I love security awareness and phishing and like, if you really want to make my day, send me like sophisticated phishing, email or fraud or whatever that these are things that make my day. I'm now researching one that is fantastic. I'll share with you later. Um, it's, it's really good. It's like so sophisticated. I love it. Um, so Rotten created a song for, for phishing and security awareness. And I'll put it at the end because Rotom creates a lot of songs actually. You should, uh, share your entire album.

Speaker B: I actually have, uh, my album. It's uh, yeah, it's called Cyber. Cyber Vault Zero. It's a. It's an album only about cyber security. And that album, literally, I took my brain out and put it over there. There is a lot of things that I shared over there. Some people tell me, like, oh, my God, no one talked about that. Okay. Like the Cyber Maze, for example.

Speaker A: It's a song about one of my favorite.

Speaker B: Everything today is a certificate. And in the end, people need to work to understand how things working. So I have. I have the. I think the best and more famous song I have in the album called the Clue, the Siso. Okay. It's a country song about the siso that doesn't know that he's been hacked. Yes. It's, um.

Speaker A: Yeah, it's a lot of fun. And I'll put. I'll put the link to the album at the bottom of this episode. I think people in the cyber security community will enjoy it only for those who think that cyber security is not creative. Yes, we can be very creative, especially with AI Because I don't know how to draw, but I make beautiful pictures

Speaker B: using AI So I just gonna say I'm. I have wrote the lyrics. AI only done the. The music.

Speaker A: Yeah, yeah. But it's fantastic and it's a lot of fun. And every episode of Cyber With Friends and AI With Friends, we deal with a new song. So thank you for creating that because it's always a lot of fun listening to those songs. Fantastic. Um. Rotten. You know that every time we finish one of these episodes, we have a very quick round of pop quiz. Short questions, short answers, whatever comes to mind. Are you ready?

Speaker B: I'm, um. Ready.

Speaker A: You're ready? I'm gonna make your life harder.

Speaker B: Hmm. A cow.

Speaker A: A cow. No. Um. If you hadn't chosen a career in tech, what would you be doing today?

Speaker B: Probably. Probably something related to creativity. I like to write. I love. I like to compose songs. I like to create things like creativity. I think maybe I was a writer for some, I don't know, star, uh, tech, novel, something like that.

Speaker A: Then AI would have, uh, stolen your job.

Speaker B: See, no, it was inside the novel.

Speaker A: Okay.

Speaker B: I was predicting that.

Speaker A: Okay, fair enough.

Speaker B: Yeah.

Speaker A: Um, make a cybersecurity prediction for the next five years.

Speaker B: For the next five years. Wow. I think that companies will adopt an aiciso.

Speaker A: AI ciso. Like a specialization.

Speaker B: Yes. Yes.

Speaker A: I like that. I like that. Okay. We'll explore that in one of our next conversations. Okay. Um, if you could describe your cybersecurity journey in one word, what would it be?

Speaker B: Fun. I really like working in Cybersecurity. And I think that cybersecurity can be really rewarding. Uh, regarding how you manage the daily work, uh, if you stuck on, uh, the same thing over and over, you're not doing something good. Cybersecurity need to exploit your mind.

Speaker A: Name someone who opened the door for you in your career when you least expected it.

Speaker B: Wow. I'm gonna say. I'm gonna say, um, I'm gonna say a guy called Aria Zuckerman.

Speaker A: I don't know he.

Speaker B: I do. You don't know. He's not in the cyber security world. And he believed me in when I was really, really young. And here he's one of my mentors. Uh, I think that today he's a developer for C or something. And he was my manager for a few years, uh, in, uh, OT integrator. And the way that he saw things in life was something that gave me so much inspiration. And he opened not once but two doors for me in my life. And I'm really, really glad that I've met him

Speaker A: last. But m. Not least, if you could go back in time, what piece of advice would you give your younger self?

Speaker B: No problem. Buy Nvidia stock. I had.

Speaker A: Buy crypto.

Speaker B: You know, a funny story about crypto in 2008, 2009. And I was, I was a geek on that time. Really, really heavy geek. And someone invented like completely different than now. Yeah, completely. And someone invented like a screen server, like sati, that when the computer is on screen, server is, is mining for cryptos. And I mined like a crypto a night, every night. It was a one bitcoin. Okay. And I've done that for at least, at least a month or two. Okay. But that's it. This is the last time I've sold this coin and the computer hard drive, it's all gone. And today I'm gonna say don't throw it away. Don't throw it away.

Speaker A: Yes. So that's two pieces of advice. Fair enough. Rotem, thank you so much for joining me today. It was a pleasure. Um, I will have you back on the show because we only touched not even the tip of the iceberg. There, uh, are so many other things that we can and we will talk about. So thank you for joining me. And for those listening, don't forget to subscribe and I hope to see you here next time on Cybermania.

Speaker B: Cybermania.

More from CyberMAYnia

All episodes →
  • 42 How Rainer Rehm gets paid for his hobby
  • 41 "Speak less, hear more" - Sujit Christy's insights from 3 decades in the industry
  • 40 "Why would you want to do that?" Insights and Perspectives by Owen Connolly
  • 39 You Can’t ‘Turn On’ Security with Matthew Rosenquist
  • 38 Making Things Happen: Bidemi Ologunde Creates His Own Opportunities
Explore the best B2B Engineering & DevTools podcasts →
All CyberMAYnia episodes →