The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/DailyCyber The Truth About Cyber Security with Brandon Krieger
DailyCyber The Truth About Cyber Security with Brandon Krieger artwork

Infrastructure Resilience & Business Risk | DailyCyber 294 with Ben Wilcox

DailyCyber The Truth About Cyber Security with Brandon Krieger · 2026-06-28 · 1h 3m

0:00--:--

Key moments - from our scoring

Substance score

44 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence11 / 20
Conversational Craft6 / 20

Ben Wilcox brings two decades of experience to this discussion about how cybersecurity has shifted from reactive, tool-dependent approaches to comprehensive business resilience strategies. The conversation centers on five critical areas organizations should prioritize: identity management (particularly passkeys, Windows Hello, and application identity governance via Microsoft Entra), data protection through classification and encryption using tools like Microsoft Purview, and business impact analysis to understand how security decisions affect revenue-generating processes. Wilcox emphasizes that AI integration introduces new risks - agents and copilots now have identities and permissions that can be exploited, creating visibility gaps in tools like EDR and SIEM systems that don't yet adequately monitor agent behavior. He highlights specific threats like meeting recorders that capture confidential information without proper encryption or access controls, CRM breaches exposing customer data, and the challenge of managing thousands of application registrations with excessive permissions in enterprise environments. The episode addresses how organizations must balance leveraging AI's benefits (like Microsoft Graph for context) while implementing strict data governance, least-privilege access controls, and role-based access management before deploying these technologies.

Key takeaways

  • →Identity management must expand beyond user authentication to include application identities, passkeys, and Windows Hello to replace vulnerable password-based systems and reduce business email compromise attacks.
  • →Data protection requires active classification and encryption (using tools like Microsoft Purview) to prevent sensitive information from being surfaced by AI systems and to control what data agents and copilots can access.
  • →AI agents and copilots create a visibility gap in current security tools - EDR and SIEM systems cannot adequately monitor agent behavior or detect manipulation, leaving organizations vulnerable until better telemetry emerges.
  • →Meeting recorders and third-party AI tools collecting business conversations lack sufficient security scrutiny around encryption, storage location, access controls, and breach notification processes before implementation.
  • →Business impact analysis must inform security decisions by identifying critical revenue-generating processes and their weak links, rather than letting technology or compliance requirements drive the security program.

Guests

Ben Wilcox

Topics in this episode

Microsoft PurviewEDR (Endpoint Detection and Response)PasskeysMicrosoft Entra (Azure AD)Windows HelloData classification and encryptionApplication identity managementSIEM systemsAI agents and copilotsBusiness impact analysis

Questions this episode answers

What are the main security priorities for organizations in 2024?

The top priorities are: identity and access management (passkeys, Windows Hello, app identity governance), data protection and classification, business impact analysis to understand critical processes, and infrastructure resilience. These should be driven by business needs, not just technology or compliance requirements.

How are AI agents and copilots creating new security risks in enterprise environments?

AI agents operate with broad permissions across email, Teams, SharePoint, and other systems, and can be compromised to perform unauthorized actions while appearing legitimate. Current EDR and SIEM tools lack visibility into agent behavior and decision-making, creating a gap where attackers can manipulate agents without triggering indicators of compromise.

What's the risk with using third-party meeting recorders in business calls?

Meeting recorders often store transcriptions in unencrypted cloud storage without clear data governance, access controls, or encryption. If the vendor is breached, all confidential business information, vendor names, financial data, and customer details become available to threat actors, who can then use AI to identify and target affected organizations.

Why is business impact analysis critical to a security program?

Business impact analysis identifies which systems and processes directly generate revenue or enable operations, helping security teams prioritize controls where they actually protect business continuity rather than implementing generic solutions that don't address the organization's specific risk profile.

How should organizations manage application identities in Microsoft Entra?

Organizations should audit all app registrations (typically thousands in mid-sized companies), remove unnecessary permissions, implement least-privilege access for apps, and establish governance to prevent legacy apps with excessive permissions from becoming attack vectors for compromising email and other critical systems.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode covers five legitimate security domains and includes a few non-obvious specifics (AI agent population approaching headcount, Copilot surfacing a confidential PIP to the wrong user), but large stretches are the host restating the guest's points or sharing his own anecdotes, severely diluting the ideas-per-minute ratio. Standard advice like 'do MFA on everything' and 'one pane of glass' dominates the runtime.

our agent population is approaching the same population as our end users, where we're doing and the controls that we have in place because things do move very fast
the employee had asked, what should I be focused on today? And copilot went out and said, you know what, you're in the same group with this other employee, says he's in a PIP and it's due today

Originality

7 / 20

The five pillars discussed (IAM, data protection, BIA, tool consolidation, device trust) are well-worn CISO talking points with no meaningful reframing or contrarian angle. The AI-agent-as-identity observation is the freshest idea, but even that is not developed into a genuinely novel framework - it surfaces and then recedes into generalities.

I always like to think of things from a tactical model. Right. If you haven't done it, think about it from who can use AI. What AI? What data can AI reach out there
in 2010 it was pretty, um, you put a solution in place and you hope it does its job

Guest Caliber

11 / 20

Ben Wilcox holds a genuine dual CISO/CTO role at a security-focused firm and clearly has real client-side practitioner experience evidenced by specific incident stories. He is not a career podcast guest or pure thought leader, but Pro Arc is not a large enterprise and he is not a widely recognised industry figure, keeping the ceiling moderate.

I have a very unique role of being the CTO and ciso. So I have to think about things from a what is it that we're putting out to market
we went through static code analysis, dynamic code analysis. We had all the different tools in our pipelines to be able to look at it from a security vulnerability perspective. We did manual app pen testing

Specificity & Evidence

11 / 20

The episode earns credit for several named, concrete scenarios: a ransomware victim 13 days down and two days from closure, a Copilot ACL failure exposing a PIP, a customer running four overlapping vulnerability management platforms, and five CRM breach notifications received in one week. However, no hard metrics on programme outcomes, cost savings, or quantified risk reduction are offered, and vendor names beyond Microsoft are largely absent.

I've gotten five breach notifications in the last week regarding a CRM that's been compromised by threat actors and it's from five different vendors
four different vulnerability management platforms in their environment and they all overlap the same things

Conversational Craft

6 / 20

The host frequently answers his own questions with extended personal anecdotes (the 48-vs-72-hour backup story, the open ACL firewall story) that crowd out the guest and prevent meaningful follow-up probing. Questions are formulaic ('what's keeping you up at night?', 'any closing thoughts?') and no claim is ever challenged or stress-tested.

So identity, access, manage, it's expanding. That's number one. So three more, or actually four more areas that you're thinking about. Okay. We need to harden, we need to secure this share.
Now when you've done your business impact analysis, what's that one or two things that you found that uh, you're like, they just don't get

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker A58%
  • Speaker B42%

Most-used words

security32tools31access29data29start25sure19email18back17test16information16today15agents15side14identity14hours14different13

Episode notes

Infrastructure Resilience & Business Risk | DailyCyber 294 with Ben Wilcox Artificial intelligence is reshaping enterprise technology, accelerating innovation while introducing new security, governance, and operational challenges. In this live episode of DailyCyber, Brandon Krieger sits down with Ben Wilcox, CTO & CISO at ProArch, to discuss how organizations can securely adopt AI, manage infrastructure risk, and prepare for the next generation of cyber threats. As both CTO and CISO, Ben offers a unique perspective on balancing technology enablement with cybersecurity leadership. His work focuses on helping organizations build secure, resilient environments while navigating the complexities of AI, cloud infrastructure, compliance, and modern cyber risk. Recent discussions from Ben have focused heavily on AI governance, agent visibility, DevSecOps maturity, and the security implications of rapidly accelerating AI adoption.

Full transcript

1h 3m

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome. Welcome to Daily Cyber, episode number 294. Uh, we're almost at 300 is awesome. Got a lot of great guests coming up this year, uh, this quarter. Uh, so many great guests that are coming in and talking about different technologies and solutions and AI and cyber security and governance compliance. So make sure you share this out with your family, your friends, your colleagues, your partners, whatever that may be. Uh, because we have a lot of great experts coming on and talking about, you know, a lot of great strategies, solutions, challenges that they're going through, but also, you know, providing insights and tips and golden nuggets of what they would do in your situation and what they're going through from themselves with the organization and what their customers and clients and they're working with. So Daily Cyber I think has really grown over the past couple years to really develop, you know, some great experts and guests that come on here and just share their expertise. So I'm really excited. Which brings me today, uh, I've got Bill, uh, Wilcox. He's the CISO and CTO at Pro arc with over two decades of experience in cyber security, cloud architecture and enterprise technology. Works directly with organizations, design and secure complex, uh, environments, helping them navigate emerging, uh, threats, uh, especially at the intersection of AI and infrastructure. Now this is a big topic. I'm really excited to get in with him. So grab a coffee, grab a tea, let's hack at it. Welcome. Ben, how are you?

Speaker A: I'm great. Brandon, how you doing?

Speaker B: Pretty good. So thank you so much for coming out. Uh, lots to talk with, I'm sure.

Speaker A: Yeah. Ah, thanks for having me on. Excited to talk about the topics today.

Speaker B: Awesome. Now one of the questions I really kind of want to jump in because I know you have a lot of background, you have decades experience. How are you seeing like the industry change from year to year from when you kind of first started to like where you are now?

Speaker A: Well, you know, in the early days, what do we have? We had, ah, antivirus. We had uh, maybe a barracuda spam filter, a firewall perhaps, you know, early, early when I first started there, you know, it was early days of firewall, um, a lot of public Internet accessible computers at that point. So I think we've come a long ways. Um, when I first started really kind of getting into the cyber side of this, um, because I grew up in the business, the technology side, system integration, um, and then I really started getting into the security aspects probably around 2010. Um, and even in 2010 it was pretty, um, you put a solution in place and you hope it does its job and things look through. Uh, it doesn't always necessarily work the way that you're expecting. Um, then we started building more proactive security programs, right? Ones that, you know, hey, we wouldn't come in and just go do a vulnerability scan once a year anymore, right. We would do it continuously and start building kind of repetition, right. So, um, you know, one of the things I kept hearing from customers and I kept observing myself, we come in, we do a vulnerability assessment, a pen test, and then we get a laundry list, right? 500 items here, you got to go fix it before next year. Half the time you come back and more than half the list is still not done. It's just too immense and never contained. So I think with that repetition of getting things prioritized and stuff, over the years we've gotten better at helping be proactive with security rather than reactive. Um, I think we're continuing to do that. Um, kind of an interesting, I think, twist in all that is around 2020 we started seeing the real push of like new software, new platforms help manage all this. Right. A lot of tech coming in and what I started observing is that people started losing the fundamentals in their security programs. A lot of them, especially with the, um, they're focusing on, hey, tech can go solve this, or, um, maybe the more mature ones at compliance obligations. We're still there, but, uh, a lot of the businesses that were looking to do keep me secure, they're relying on the tech side to handle it. Well. Then they started letting go to the fundamentals of what they need to be doing internally to their business to keep things going. I was seeing an uptick today of, hey, let's adjust the way that we're doing our vulnerability management platforms, how we're prioritizing, how we're addressing the age of Mythos or um, Fable. How do we make sure that we're reactive and we don't handle a 30 day patch window the same way that we used to? That's not possible. In some ways, tech got us a little lazy and we have to go back to the fundamentals and kind of start looking at business resiliency, things that we're, um, able to do. And frankly, a lot more people had interest pre Covid to that stuff. And I'm starting to see kind of an uptick back into the basics today.

Speaker B: Yeah, just kind of the base foundation like to do the work right, not letting the tools kind of drive the program. I mean, tools are beneficial. All these AI tools and you have Your sim, you have your vulnerability management, you have your patch management. We still have to do the work. And I totally agree with you,

Speaker A: that's a big piece. Identities or any other aspect of where most of the vulnerabilities are coming in today, a tool is not going to necessarily, you don't want a tool to stop it, uh, you want it there as a safeguard. Let's do the pre work that makes your environment hardened. Let's make sure that we put the right controls in place so that you know we're not granting the keys to the kingdom when you know exposure does happen.

Speaker B: Right.

Speaker A: But that's, that's the type of work that we really need to focus on today.

Speaker B: So with that being said, like what's your top five areas that you would say for businesses that their priority for this year to start uh, working on like security?

Speaker A: Oh well there's a bunch of them in there but I think probably like um, number one still, and this has been preaching this for the last couple years here is identity. Whether it's your um, if you're in the agentic era, focusing on uh, your A.I. making sure it has identity, um, as well as looking at your users. Um, the things that have helped me sleep better at night. Right. Passkeys organizational wide. You don't have to worry about your passwords being compromised. You don't have to worry about those pesky two factor authentication phishing attempts or you're the man in the middle anymore. And those breaches which are so common these days. Um, the identity is where I would start. Right. Start getting those fundamental controls, start getting your users move to pass keys. Um, start graduating from just mfa. Right. MFA is required on everything in a trader we're still seeing gaps um, when you come in and work with customers in that space. But roll out things like Windows.

Speaker B: Hello.

Speaker A: Right. Um, that uh, gets you 50% of the way there to not using passwords anymore. Um, a passkey type of system. So um, those types of things can be really good. Um, frankly I also believe very much that um, we still see a lot of business email compromises and those types of attacks. Right, right. Those are still primarily identity driven as well. And so that being a big piece to stop it in the future, um, I think this is certainly key in there now.

Speaker B: Got a question for you. So you're talking about identity access management. Are you now looking at identity as the individual person employee but now you're also looking at identity as the application and software?

Speaker A: Yeah. Because you have these enterprise apps right. That have access to all sorts of um, roles that are um, if you were to go into just choose Entre, because I live in the Microsoft realm. But if you go into Entre and you go look at your enterprise apps, you will see that they have tons of permissions into things. The users, um, um, email systems, teams, you name it across the board, they have access. Historically the default context was hey, uh, let's let users grant themselves permission to uh, have access to these things. M and then threat actors started realizing hey, this is a big giant back door for us to be able to access environments. All we need to do is get an app key or compromise this app. Um, and next thing you know we're able to get in. Um, that happened to Microsoft a number of years ago. Um, I think it was midnight Blizzard came in and had access to some email accounts and then they compromised more accounts and came in through these secrets. Well M, if we kind of extrapolate on that, right? Every app, ah, if you take a mid sized organization, a couple hundred employees, um, you probably have a thousand different app registrations sitting in there and all of those things they're tied to vendors, they're tied to, um, maybe partners that you have. It could be uh, apps that you've written yourself and the owners have long since moved on and you have this legacy stuff sitting out there. Those are all risks and so those need to be looked at as well. And managing your app identities is certainly a big piece of that. Right.

Speaker B: And I think the challenge that you talked about, and we'll probably go into a little bit deeper is that tools like AI can incorporate into your desktop, your email, like you name it right across the board. And as we're talking about like it's not just it has access to do read, write, there's actually things you can set up it. So it's taking action, it's responding to email that, so that's that next level. Like some of the tools like uh, I mean you got your iPhone, right or your Android and it says oh they want access to your camera, your, you know, this, that and your contacts and does that. I get that and M, they're potentially pulling information. But now with the AI it can actually do more action and depending on what you're doing it can actually take an action versus this is might be pulling data and I mean we'll go to privacy and all that, you know, in a different conversation or maybe today. But with AI, I think the concern is that you might set up a script, you might set up a skill, you might set up an agent, it's doing some activity. Well, the threat actor knows how to manipulate that. I mean it's full, full open door, right? If it's taking action, they respond to email. Well, guess what? It can they compromise that some way. Now they have all your contacts, now they have all your emails, and now they can respond to it. And, and if for me, uh, and look at inch response, I'm looking for malicious activity. Well, it's not malicious because your agent's doing it. They just compromised it. Right now you're like, hold on this. There's no indicators of compromise because the agents actually respond to the emails. But we saw the Melissa's email. We don't know what's happening. But of course you could do more investigation. But right at that incident, you're looking at, it's the AI the AI is supposed to be doing. Right, but just kind of extrapolating of uh, what's possible, right?

Speaker A: Yeah. I mean, when you take that, uh, what you just described, right, there's so many inputs and outputs that are possible there and decisions being made by these agents. Right. And where's this agent running from? Right? Is it running from the cloud or is it running from your desktop like you said? Right. And guess what we have Tool, um, lack of visibility today in the security realm. Right. There's not great tools that look at agent activity on your endpoints. Not yet. I mean, it's coming, guarantee it's coming there, but there's a visibility gap. Sure, your EDR tool can see things and see the actions, but is it seeing what's happening within the agent and the context around that? Understand? Are there other threats in there? Is it being manipulated? No, it's uh, not. Right.

Speaker B: Well, as you and I know, some of the threat actor tools they use are valid tools that companies use. Team Viewer. I know that. I've been instanced. The Team Viewer is a remote tool, you know, remote desktop, rdp. Like all these are real tools. It's in the context of how they're being used. Right? So same with the agent. The agent's a real, you know, integration with your solution. It's doing what it's supposed to. And if someone manipulates it now it's the question of when, when it was manipulated, how was manipulated. And like you're saying the actual forensics now, it's not there yet where I can't call anthropic and go, hey, can you give me the logs for this? And they're like, yeah, no, we're not giving. Get a court Order like we're not. You're not giving any logs. Right?

Speaker A: Good luck raising any support there.

Speaker B: Exactly right.

Speaker A: We're not going to help you. I can't even get visibility into a bill, so they're certainly not going to help on that front. But yeah, that's a huge concern. Right. Visibility gap. And I'm very hopeful that the security vendors are going to close that up this year. Right. Better telemetry, better visibility. But until that point happens, we're kind of in this netherland, um, and hoping that our agents are doing it or putting enough controls and enough education with their end users that they're making good decisions around what they're doing with the agents.

Speaker B: Right. So identity, access, manage, it's expanding. That's number one. So three more, or actually four more areas that you're thinking about. Okay. We need to harden, we need to secure this share.

Speaker A: Oh, absolutely. The next one is like data protection. Okay. I'm a big proponent when we talk about data protection. I'm going to go with data, um, security in regards to like, you know, things like Purview. Right. Where we're able to classify, label and encrypt sensitive information. Um, I've just seen too many instances over the last couple years, especially in the era of co pilots and AI, where the visibility is there for the AI to get to it. Before we were obviously hyping through obscurity and not knowing where things were. AI has this wonderful thing called Graph that it can access. Right. Graph services all this intel and knowledge that's around. Um, and frankly it's perfect to help ground your responses and get the pieces in there, but sometimes it surfaces the wrong thing. Um, I had an example the other day where I was and had some notes that I was putting into a, uh, PowerPoint. I had great notes. Well, one of my notes referenced something regarding another company. Right. So I ended up presenting and here's this other company's name right in the middle of my presentation because I, I reviewed it, but I missed it.

Speaker B: Yeah.

Speaker A: Other company name was still in there. And the fact was, is, uh, like it was in that document. AI thought it belonged in there. Right? Right. M. For some reason it said, oh, you're representing this company. And I'm going to put it right over there in the small text. But I missed it. And it's instances like that or surfacing. Like, um, another one, we had a customer working with some copilot on and rolling it out and you know, we get a note that, hey, you know, uh, one of Our employees is accessing another, um, PIP plan for one of his co workers. Well, in looking at it, what had transpired is the employee had asked, what should I be focused on today? And copilot went out and said, you know what, you're in the same group with this other employee, says he's in a PIP and it's due today. Maybe you could help, uh, complete the PIP successfully. Improvement plan. That's certainly some confidential information that you wouldn't want to get out there. And really that was just an ACR problem. What it boiled down to is that user had access to this folder. They didn't know that they had access to it, but, uh, the SharePoint administrator or whoever was in charge of that site had the wrong permissions on there. So. So that data piece is really kind of critical across the board. It's keeping the sensitive information sensitive and letting your systems know that, hey, this is something that maybe shouldn't be touched. You could do it if it's really sensitive, grouping so that there's a label that you can't, um, leverage in certain system, or if you have intellectual property or other sensitive stuff that you don't ever want to leave. Um, and frankly, that type of governance, right, where you start having to get it in place ahead of time or as you are progressing in your maturity is certainly critical. And we've seen this realm of, I'll call it data swaps. Uh, we've stored and retained all this data for years. Um, is it useful to the business? Um, AI is showing that it's not useful to the business.

Speaker B: So one of the questions I have for you is this, that you're talking about a lot of data, data access, least privileges, kind of that. What about recorded data? I mean, I don't know if you're seeing this a lot, but I'm seeing a lot of these recorders jump up in a zoom call or teams call, and they're recording the meeting. Right. What's your thoughts on that?

Speaker A: The question is, is that a commercial version and you have the right T's and C's on the other side that protect the information from leaving your organization? Right. Those are the ones that concern me. Like recording of Copilot and staying within the company that, uh, the partner that we're working with, not a big deal. That's fine. Um, these other ones out there where you don't necessarily know if they're on the free version, is it data processing? Um, so I had to ask questions around, like if you're in this meeting, um, I'm happy to send you the transcription. Uh, um, but you know, hey, we don't allow third party m, uh, AI that we don't know to record the meeting. Right. We've had to establish some AI baselines and guidance for our employees, uh, what's acceptable, what's not. Um, and frankly that, that's a, that's certainly a concerning piece for me.

Speaker B: Mhm. I think one of the concerns for me is that depending on the meeting, right. And depending on like if you have NDAs with people and also you start talking about private information but now you have this, one of these recorders on there. You don't know unless that is like self hosted where that data is going, who's going to have access to the notes after, if that could be shared, if that's now you know, in an area where it's not secure and, or indoor encrypted. As you and I know you talked about business email commerce. Say it's sitting in someone's email and all of a sudden it has financial information, confidential information and a threat actor gets into that email and there's, they're scanning through, they're dumping that person's email and all of a sudden they have a list of their vendors, their financial information, access to what there's their systems and topology is like all that. And you really gave the Threat act our roadmap to some of your customers, uh, and your partners. Like that's my concern because again as you know, and I agree with you, like the data side we look at least privileges, you know, rbac, role based access control and limiting that separation of duties trying to control access data. But now we've got this other point of where data is being collected but I don't know if it's the scrutiny of the security is around it as it should be.

Speaker A: Uh, oh, I concur, it's probably not. And one of the things I always think about too is email's one thing at least it's internal. But now that stuff's tied into these CRMs, all these CRMs and they love to take these notes and it goes out to your customer profile and ends up in there. I've gotten five breach notifications in the last week regarding a CRM that's been compromised by threat actors and it's from five different vendors and you know, my information's out there. Um, so um, that's the type of stuff you got to worry about. Right? Because now you know, everyone wants to talk about your business.

Speaker B: Right.

Speaker A: How's your business you know what's top of mind for you, right? The typical sales 101, right? Understanding what, what, how your business is doing, how they can find value. But yeah, those recorders are leaving it out there. And you know, if you're just having vendor conversations, those recorders, um, I think it's good to understand, you know, where's it go, who's responsible, you know, is there breach notifications involved? Right? Getting these notifications, I don't know how many I haven't gotten.

Speaker B: Um, how's, how's the data store after when it makes the notes, right? Is it in plain text, is encrypted, is it easy to be accessed? Is it in the cloud like all that stuff? Is it, you know, two factor authentication? Is there role based access in it so you can set different types of like all those things would be the questions I ask. Like I don't really use any of those recorders but those are the questions I would be asking before I would ever implement it into a uh, customer's, you know, business end or you know, be in a meeting where it's there, it's like, okay, hold on because do you really know where the security, if you want to talk about this confidential, critical information and you have a recorder, do you know where that data is going? Because you might think, oh yeah, it's fine, don't worry. But like you said, what if that company, what if it's recorded in the cloud, right? You know, everyone's like, oh, it's in the cloud, it doesn't use much data, you know, it's in the cloud. What if they get compromised? It's not encrypted. Now they have all their customers, a uh, thousand plus customers that now that threat actor just download all that data, all those recordings and then with AI as we know, they're just putting AI scroll through it and say, hey look, you know, find me these companies with this information that talks about xy, their access, their topology, this, that uh, information and just give me a report and boom, you have a report now of companies that then go after. It's just, to me it's a security risk right now until people it, the tool gets more due diligence and then people do more due diligence on those tools.

Speaker A: Yeah, I mean in those tools too. Those tools should be able to do the classification just described, right? You should be able to classify that recording that meeting sensitivity. If we're having uh, um, uh, executive security briefing on an event, like probably not recording it, but if we are certainly classifying that meeting very high and making sure that everything is encrypted and so forth. So those types of things are certainly super important. I think as we look at how technology is using, it's great advantages. Um, but where's the risk and is that risk acceptable for you and your business?

Speaker B: 100%. So we got identity, access, management, we got data. What's number three?

Speaker A: Well, there's this wonderful thing that I used to do a lot of um, called business impact analysis.

Speaker B: Okay. Yeah.

Speaker A: And these bias. Right. It used to be we go talk to the business, we'd understand, you know, how they're generating their revenue. Right. What are the processes that are most critical to generating that revenue or continuing operations. Right. So at the business level. Right. Um, you know, security is important, important. But it's more important on the context of is this going to allow us to keep running? Right, right. The context of the business wants to put in. So the business impact analysis is really designed to talk to the business, understand. Right. What are the critical systems here, how are they tied together and understanding where there's weak links in that. Right. It could be something as simple as either technology redundancy. Right. You don't have the right redundancy in place or maybe there's dependencies within application to application. What that leads you to start understanding is how much um, when an impactful event happens, what is an acceptable rto, rpo, time objective or recovery point objective for that application. Things as they start becoming core dependencies and understanding where they are in your business.

Speaker B: Right.

Speaker A: Those are going to be at the very top. Right. Get those restored first. Also how to prioritize your recovery objectives on these things or plan future investments around them. It's also really good to start understanding how the business operates and if something did happen in the future because most of the time when we ever talk about backups or recovery, someone's got a plan, maybe it's tested, but none of that's really tied to a business outcome. Right. Um, how's payload get processed? Security incident happens and you get, you are in an all down event. People still need to get paid.

Speaker B: Right.

Speaker A: Um, it might not be the top priority at that moment, but that's one of those processes that needs to happen or processing what's the fail back in some of these scenarios. And you might not get through all of that in the business impact side of it, but at least you're going to start understanding where the priorities are from a tech perspective. How that aligns with business and how that impacts the business long Term, Um, I remember this was probably about 10, maybe 11 years ago. Got a call from a business that they needed an incident response. Everything's ransomware encrypted and turns out backups were impacted. Uh, luckily their cloud backups weren't impacted. But the problem was, is the recovery from the cloud. It was super long, slow, couldn't get it back fast enough. Uh, they had terabytes, um, of data that was needed to run their business. They were, by the time that we finally were able to get them back up and working, I think it was probably 13 days later.

Speaker B: Uh, okay.

Speaker A: Yeah, right. Because this is just huge amounts of stuff. They were, um, huge data pieces there. Just took too long. And frankly the cloud recovery was just way too slow. They were two days away from going out of business. When we talk to the, uh, tube owners in the company. Right on two more days, they probably would have lost their customers to contractual obligations. Um, they're starting to run problems into cash side of things. They weren't able to process anything and weren't able to get bills out. Um, so not every business has a large amount of resiliency in there. And that's really where like these business discussions start. Helping you as a security practitioner or security, um, stakeholder, understand what's important to the business. Right. How do you get your, um, you know, put the right things in place for the tech to stay resilient, business to keep running.

Speaker B: Now when you've done your business impact analysis, what's that one or two things that you found that uh, you're like, they just don't get, like they don't understand this aspect of it. And I, and I'll give you an example. Sometimes when you look at the, you know, failovers, your backups, the restoration, like you just talked about that. I know I had a customer. Oh yeah, it's, it's, it's 48 hours for us to get our backups from beam and we're gonna do that. But then we did a tabletop actually is actually 72 hours. Like, whoa, what do you mean it's 72 hours? But by time you make the request, they extract the drives, they go, they go through, they test the drives. They now do their scans on the drive, they ship the drives out. You now you're not going to get them for 72 hours. And depending if it's on a Friday and they're overnighting them, it could take, you know, a little bit longer just because of the courier and shipping. Right. Uh, they're trying to get you like by, you know, by Sunday, like if it's Friday, Saturday or Sunday, but again, still going to take time. And they're like, hold on, we were told 48 hours. And like, yeah, I think they told you 40 hours from when they actually packed the, the drives in the box purely to FedEx, whatever that may be. And they got them out. They didn't talk about the other process there, about testing, extracting the drives, testing the drives, doing the scans on the drives. What takes a day to two days in that alone. And like, whoa, I, I never knew that. I ask you is what, what is that? You know, one, two things that you found as you were doing your bias.

Speaker A: Um, probably the most common one is that the assumption, uh, that a backup is a resiliency strategy. The best way to address that is to make sure you have uh, a tested resource path tied to the business process that you're trying to do there. So, like that payroll side of it, right? How do you get payroll back up working? Um, um, that's a resiliency strategy of how to handle that, pushing it forward at least from that recovery side. And then, um, I think infrastructure resiliency is probably another big challenge because nobody knows necessarily which system matters most. Um, sometimes you end up not knowing who the owner is, um, and what the recovery sequence is. Um, and so that can be very challenging in um, approaching this is that they think that they know. But frankly, when you have another example, when you have 2000 VMs that are all encrypted, um, where do you start, right? Um, that requires thought ahead of time to be, um, getting it into the right mode. Otherwise it can be hours. Maybe you're focusing on the wrong thing altogether and you have to go pivot because now you just wasted two days, right, trying to get something up and working and you realize, hey, that's not the most critical thing that I need. So, um, going back, it's all about the business processes in there and where that is. So those would be the two things that I think are probably the most shocking most.

Speaker B: The one thing I found to add onto this is dependencies. I found as the commies, I was doing bias. They had the main system, but they didn't realize the dependent process people that drive secondary dependencies or uh, processes under that. Oh, that was impacted. If this goes down right? Uh, yeah, we have email while that. But if we don't get email, you're not getting the registration from this other vendor that you get every Friday. That's a key thing for your actual operations. Oh, hold on. What do you mean we don't have. We can't do. That's down, like now, how do you do that? Like, is it a phone call? Is it, uh, a facts, you know, what else is that process you'd go through? And they're like, what do you mean? But our emails. I'm like, no, you're down. Fully ransomware, fully encrypted. Your email is completely offline. What do you do? And they're just kind of the. Oh, I didn't. I wouldn't know. Like accounts payable, accounts receivable. Okay. You have to do payroll. That. Yeah. But you also are paying your vendors, right? And you have a certain point where you're not paying your vendors, where they start shutting down your services. Oh, hold on. What do you mean? And then this, and then trying to draw that out for them, that it's not just these main email servers, Internet.

Speaker A: Right.

Speaker B: Uh, your manufacturing, there's processes underneath where it can be impacted. That was one of my takeaways from doing a BIA with people, is like having to ask, but then what else is attached to it? But what else runs that process? And they're like, well, I think that's it. Okay, can we bring someone else in? Okay. Hey, what. How do you work with it? Oh, I actually do that. And it's very critical. They're like, you do you do that with that? You're like, yeah. And then you start making notes, like how it's all intertwined. Right.

Speaker A: One of my, um, common ones. I used to see this a lot more. I think I see it less probably because of the, um, the fact that there are more cloud native organizations today than there used to be. But it's still. There is. Hey, I have a doctor Site. Right? I have a doctor, you know, environment. Um, well, okay, so let's talk about how you're down today. How are your users going to access that Dr. Environment? Right? Well, they're going to VPN in. Well, your VPN over there is only limited to whatever it is. Right. 50 users or whatever it is. Right. Can't go through 500 people on there.

Speaker B: Right.

Speaker A: So what's your plan there? Or. Um, well, we're going to send everyone home and then they'll use, uh, you know, desktop or whatever else to get into that Virudi. Well, okay, if it's not in the cloud, how do you even scale that? Because your hypervisors are limited over there. So.

Speaker B: Right.

Speaker A: Those types of things. Right. As you're describing. Right. You haven't thought through the Full process of what happens. Right? You got an investment. Um, we used to see the netapp. Used to always sell everyone to sayouts. Used to see this. Oh, well, I got, I got a stand copy over here. That's my doctor strategy. Well, your hypervisors are over here. What are you gonna do?

Speaker B: Right?

Speaker A: Um, it's great that you got a copy of your data. Uh, you know, pick it up and move all your stuff over there and, you know, license your servers. What's your plan? So you gotta really think it through.

Speaker B: I think one of the takeaways. Anyone listening to this? I mean, Ben, you're bringing a lot of great information. Do a stress, uh, test. So I'm gonna, I'm gonna try this out for people. There's tabletop exercise where you kind of talk through it and you have a, you know, you have your lunch and you're drinking on donuts and you're kind of. Versus a, uh, tabletop exercise with a stress test. I recommend people, when they're going through the bia, the business continuity, disaster recovery, their injury response, they do a stress test. Tabletop exercise. With limited time, things are going down and really going through it, because that's what's really going to happen in the real world. Not. Oh, yeah, I talked to this policy. It looks okay. I think it's good. We're going to get. And then when the, you know, the fire has happens, you're like, what do you mean the backups didn't work? What do you mean their servers aren't coming up? You got to go through that stress test. Because if you don't. And I think that's when you do the, you do your due diligence when you go to the stress test because you really learn. That's for that example, that backup. I learned that, uh, because I had the vendor on there for the backups and we were doing the stress test. Okay, good. You have a ransomware event. This happening. Go. What do you do? Okay, you call this vendor. You got that? I'm notifying that we're getting a certain team. Great. The backups. We're going to test the backups. Great. How long is the backups going to take? Oh, it's 72 hours. And they're like, what? What do you mean? Hold on. What do you mean 72 hours timeout. Okay, we got 72 hours. I'm like, no, no, no. They're supposed to be here 48. And now discussion. I'm like, good, now we have a discussion point. Because if you're in an incident right. Now that wouldn't be good if you're down for 72 hours expecting to be up in 48. Right.

Speaker A: So, yeah, the business, if the business is expecting it. And sometimes, look, those conversations are the most valuable things that people say, right? Well, you know, it says that, uh, 24 hours is an acceptable recovery time.

Speaker B: Right.

Speaker A: What if finance says it's 4? Right. Because it's their application and something that's super critical to. Well, now you gotta go have a tiebreaker. Right? That's. That's where the CFO or whoever it is, that's the decision maker in there. You start talking about, uh, all right, if you want four, right. Today we have 24. We want four. It's gonna cost you XYZ. And is that worth it for you to be able to have it? Oh, well, probably not, right? Those conversations are good ones to have because then you're not the one that's holding the bad news. Right. Very top. So I like those things because, you know, why defer your. Uh, a lot of these things have happened in the past where organizations have set arbitrary values, or maybe a vendor did, or that person's long gone and someone gets caught holding the bag and has to then fix the problem. So those are great things to surface.

Speaker B: 100%. So identity X Men data, uh, business impact analysis. Two more.

Speaker A: All right. I am a big proponent of better unification of tools. So I like platforms. And the reason being is I think that we have as security professionals too many bespoke tools that don't talk to each other. I like the visibility that single platforms give across a stack.

Speaker B: Right.

Speaker A: And I feel like if there are certain risky areas. Sure. Add another tool on in there that you feel is like the most appropriate. Right. Like, got some customers that like to run two email tools. Right. An AI tool, traditionally AI machine learning one. Um, fine. That's great. If you have the budget for that and you can afford that, that's great. Frankly, I put my money into putting pass keys in place first. That, um, I think that unified threat visibility, right. Because we don't know that the threat actors, right. They want to move as fast as possible, and they will there. And they're living in those little blurry lines in between the different things. And AI has just made that so much more money, Right. Than having more tools where things are moving in and out and you have to go to 15 different, uh, interfaces to understand like, uh, a compromised environment. That's 14 too many.

Speaker B: You want one pane of glass?

Speaker A: Yeah. One pane of Glass, let's see what we can see across the board. Generally we have better telemetry because it's all tied together. Um, so you know, for me, when we start talking about being able to respond to threats from a SOC perspective and security analyst review single platform, I think it's certainly key.

Speaker B: One thing I'll add for people that are watching this, I recommend at least every quarter if you can, or maybe every six months and one year to do an assessment on your tools and see what you're utilizing and what capacity and utilization of those tools. Because I find a lot of times there's duplicate tools in environment sometimes go in there. It's like it's two EDRs, it's two Sims, it's two this. It's like hold on, why do we have. Well one does that and one does this. It's like did you actually evaluate the tool? It actually, this is the one you got first. It actually does that. And yeah, there might be gaps whenever but you can circumvent that or complement that by your EDR. Like why'd you get two EDRs, two SIMs, two this guys, you're spending so much money in security program where you can cut down and be more efficient, right? Like and things like that. I find where I was like okay, you're using it 50%, why not 80% utilization of that tool like in all the features and all the functions and really kind of doing looking automation and integration like all that. I find smaller M companies to mid sized companies really need to do that over and over again.

Speaker A: And frankly it's vendor push too. I, I see it a lot with vendors, right. The vendor finds it finds it finds a um, point at that moment where they think that it's the hey we can go solve this problem and get in there. Right. And now next thing you know you have um, a tool that does what you want but also has this other capability over there. Um, I was talking to someone just um, last month, four different vulnerability management platforms in their environment and they all overlap the same things. Wow. And frankly one platform, they actually have two full platforms in their environments as well. So um, you can imagine that there's cost, there's better ways to do it and frankly who's running all these tools? No one's paying attention. Um, you can't run these all with a small team. 100%. Yeah, you really do need to if you are in a full platform. I can look really across all the layers that evaluation things this year and then last one.

Speaker B: What would be your last area that people should focus on this year.

Speaker A: So once you've gone through your identities, you worked on some data protection, you've been able to do some business impact analysis and you've got uh, a great tool stack there. I love device trust. So back to the side of looking at how do we make sure that we're trusting everything from an identity perspective, treat your devices as that as well. Looking at things like intune things that can tie into your conditional access policies and make sure that your device is still in uh, a compliant state before it accesses network resources. Um, I put this at the very last piece because frankly we have great tools. If you have platform stuff, your EDR tools, they're people are compromising identities because it's way easier. We've done a great job keeping our systems up to date and so forth, but there's still a need in there, right, that ah, your system's still managed, it's up to date and it should be verified that it's company owned before accessing the environment. So the device trust can ensure that you're the right trusted endpoint. And if you're not managed, hey guess what? You don't get the access to trust of the environment.

Speaker B: With that being said, anyone watching this, make sure you go through your due diligence of configuring properly. I think that's the biggest thing too. Like I totally uh, subscribe uh, to what you're saying but you got to make sure it's, you know, you don't have an outside professional service person come in and I've seen this, I don't know if you had, they come in, they configure it, they run to a problem and also they have a back door or port open or something like that because they're doing testing but they lift it open when they, when they're, now they're done. So now a vulnerability scan comes in or pen test comes and said, hey, we found this port that's open. And you're like whoa, why is that open? Oh that looks like it's been open since, you know, three months ago, four months ago. And that hole has been open since the professional service came in because you didn't get it configured properly. So always my point of view is always do put these tools in place, configure them, have the trust make sure they're secure and hardened. But then your due diligence of validated after, if you do a vulnerability assessment right after it's configured to now confirm 100% do that after just to make sure. Because you don't want to have it. Oh, I, I trust them. It's okay. I mean, us security people is trust but verify, right? So I'm like, verify, uh, everything secure? Because I've seen that. I saw one where I, I went into a customer and the access control list at the bottom was any, any. And I'm like, who set up your firewalls? Like, okay, like, how long ago? Oh, it was about a year ago. Has anyone, uh, evaluated your access control list? No, no. The vendor, did they set it up? I'm like, you know, you don't have a firewall. No, no, we have a firewall. No, you don't. You basically have an open door.

Speaker A: And that's true with, like, firewalls entre, like, you know, these conditional access policies that are part of your identity, they are your modern firewall. That is how you're being protected. And those same mistakes happen on those, right? You literally have to go through and make sure that it's designed to the standard that was expected and that it hasn't drifted. And it hasn't drifted. Um, why has that occurred? Right, and it's what you described, right? Someone opened up something to test something, right? MFA wasn't working for this one user and I forgot to put them back and make. Include group. There's better ways to do that, number one. Number two, right, those, those drifts need to be surfaced in a manner because those are risks that might be lurking in the background, you know, and, and hopefully your pen tester finds them or whoever else you're working with. But hopefully it's not the threat actor out there that's probing, oh, 100 where that is, right? And so it's a lot to put on a pen test. I hope that to circle set. So look, look at all these little conditional areas, right? Where those rules and seeing if it matches what it should be 100%.

Speaker B: Now, I know we got 10 minutes left. About 10 minutes left in the, in the stream. Um, quick question. What's keeping you up at night? What is this one thing that you're like, passionate about keeping you up at night?

Speaker A: This year, it's AI security, for sure. I mean that. I'll give you an example. Um, I was just putting together some metrics and I looked at the agents that we have and the company. Um, we're about 500 people in size and our agent population is approaching the same population as our end users, where we're doing and the controls that we have in place because things do move very fast. And so I do have a very unique role of being the CTO and ciso. So I have to think about things from a what is it that we're putting out to market, what are our solutions that we're working with and so forth. And I love the innovation side, right? The same side I'm scared of the innovation side because there are so many, um, lack of visibility, lack of controls in place at this moment. Um, so we're trying to find that frequent balance and constantly trying to keep up with what is changing. Changing in the AI space, um, is very hard. I mean pick any day and you got something new, right?

Speaker B: Right.

Speaker A: New method, new model, um, some new capability there, some new way to do an agent, some new framework, um, and we're all learning at that. So the AI risk I think is probably the big one for me, uh, as we start moving towards more autonomy with agents. Um, but we're certainly being very cautious when it comes to how we're doing agents and making sure that people are building them in a manner that gives the right telemetry, that gives the right visibility, that keeps the human in the loop. But it's really easy to make an agent that can just go do things these days 100%.

Speaker B: Now for you as a CISO, what's the biggest AI misconception you hear?

Speaker A: Um, biggest one probably is like, hey, I don't have a good way to stop it from doing certain things. And the reality is that you do have methods. We don't have control across the board, but I'll just give an example. Um, in the Microsoft realm, we, um, help establish standards across the board of how to do AI securely, keep it within the environment, even multi cloud, and allow it, you know, the security organization and uh, IT organization to have control. Because there is a lot of value to the business to democratize the use of AI. I mean, one person writing agents for your company isn't going to be nearly as effective as, you know, how many people writing agents and getting into the hand of the end user to do that. So you really have to focus on creating the methods of how they're allowed to do the things versus just saying no. Because people will find a way to do it. That's countless. Right? You tell someone that they're going to have to go back to doing something manually after they just completely streamlined it. They can do it in an hour. And now it's going to take them 16 hours guarantee someone's going to find a way, right? That shadow AI is going to happen and people are Going to make it occur. So I think it's really important to give your organization approved methods and spending that time to kind of think about that approved method or working with partners to find, hey, what's working. Because we all need to learn from each other at this point. No one's, no one's a complete expert on what's next on AI.

Speaker B: Oh 100 and I think the, the thing for most companies need to understand is be more restrictive at first and create controls around it and then slowly start to test and open it up. Don't just kind of open up and test and just wish and see. Right? And pray. I hope and pray that oh yeah, no, we'll be fine. Because we told these people not to. Okay. Telling someone, I mean even if they have good intentions, they could make a mistake. Right? Like, and we, we've seen this, I've seen this in instant response where security engineers, senior security engineers have clicked on links in the middle of an engagement. Right. And we know it was the threat actor. Right. Like I've seen stuff like that where people make mistakes. So with AI, you're busy, you're doing something, you upload something quick, you're not paying attention. And it's also enough all the financials for the company that you've just put into AI, right? Yeah, it happens, right. So, so in my thing is that puts uh, you know, the guardrails there, put the policies in place, try to put controls, maybe even restrict role based. Right. Role based access. Right. Like kind of do that and then slowly start to build the program within the, within the organization. Right. That say for example your developer encoding, then you get your, you know, your coders do it. But they have to follow software development life cycle and there's a strict software development life cycle that they don't just trust any code. They, they don't grab something from GitHub and put it in there and run it. And then all of a sudden they put it into production and Bob's your uncle. No, you go through development, you test it in a, in a sandbox doesn't have exposure to see what it does. And then once you've done your Q and A, your end to end testing, then you can go publish it. Then you can go public. Like all those controls which most companies want to do and potentially do, I think some of them are circumventing because the speed of AI, they're like, okay, AI can do it. They must know, you know, anthropic, you know, co, like uh, claw chat, gbt. They reviewed the code, we should be fine. And just. Let's get it out, let's get out. Let's go, let's go, let's go. Right.

Speaker A: Oh, I, I have some stories on that front. I would love to save that for another day. But the, um, just the velocity of a code development is causing immense risk because people aren't necessarily thinking about. It's the same as, as the quality of your prompt input. Right? If your. Quality of your prompt input, if you're letting AI make decisions for you, then you've lost control of your security. And it's true with your code, you got to have a guardrail set, you got to have standards to find. This is how you do it, right? This is, this is what my, um, what do they want to call it, your markdown file is going to have. And this is the way that we do it. You have to ground those tools.

Speaker B: Well, I think the barrier of entry is so much lower now because I don't have to know Python, I don't have to know HTML, I don't have to know that now because I can say, hey, write me this script. I want to do X, Y and Z, and I want to automate in a script or a batch file, whatever, and then it rates it for me. It's like, okay, run it. Then you tell it to run it, and you see error, not error. Fix the error. Like you're telling this code, this AI to do all that where normal programmers and scripters would have to do troubleshooting. And I remember, like when I first went back in the day, one new code and you look at thousands of lines and that's a decimal that's off because that's the error. But it's taking you hours to go line by line to find that decimal. Well, now chat, gbt, cloud, that's doing it for you. No problem. They go through. Yeah, we found the error, we fixed it, we ran it. Now there's no error. So you, you're relying on that and more trust and faith is in vaccines, the AI tools to do that. And now we're kind of walking away. No, no, it tested it, it's good. It ran. No errors. We're good. Now we can go. And I think that's where, like I said, that's where that, that gap is. And I think that's what you're saying too, is we need to kind of still do the due diligence, we still need to do the testing.

Speaker A: Yep. Um, yeah, we've done. Because reality is going back to just being A human coder isn't possible and I don't think we're going to be heading that way. Right. People have seen the efficiencies. It's great. But we just have to get better with the tools that we have access to and start leveraging some of these other platforms out there that can really uh, make better um, decisions around what, what's a vulnerability. Because we are going to have mass amounts of code um, out there. Like that's, that's a reality. Right. Like app companies are going to build their own apps, um, whether they're production grade or not. That's a different question. But like um, the one that we, we just built a platform and it's very AI centric, did a lot of um, AI based code in it. We went through static code analysis, dynamic code analysis. We had all the different tools in our pipelines to be able to look um, at it from a security vulnerability perspective. We did manual app pen testing. Each of these things surfaced vulnerabilities that had to be fixed. Um, but some of the challenges we started seeing is that uh, these legacy tools can't keep up with the fact that some of the code necessarily changes as fast as it does. Certainly the team testing it can't keep up because the next version they get looked completely different and you're like, wait a second, what happened here? Well guess what? Uh, Copilot just rewrote everything because, because we changed the spec. Right. So it's beautiful. But now we're back to retesting everything. Then we tested also, um, M Dash, which is uh, Microsoft's new agentic dev test program, um, basically has tons of different agents, um, all in different areas and it's really able to parse it out. So we thought we had everything fixed, tons more vulnerabilities that we had to go fix because it's a new way to think about it and. Right. I think we're going to get a lot better at fixing vulnerabilities and very confident at that. The fact is that we have to update our processes and our skills to be able to do that as, um, we start moving down this direction and frankly we're not quite there yet, but I think we will see a lot this year in that space.

Speaker B: Oh, 100%. Now I know we got a couple minutes left. Any closing thoughts?

Speaker A: Uh, yeah. Um, from an AI perspective, I think we covered a lot in there, but I always like to think of things from a tactical model. Right. If you haven't done it, think about it from who can use AI. What AI? What data can AI reach out there? Think of it from a data flow perspective. That's always been critical. Um, which plugins, connectors, agents or automations are you going to approve in your organization? Um, right. We had a salesperson join about six months ago. It's the first time any, any salesperson ever asked me for an API key to our CRM. Okay, so what are you trying to do? Building an agent.

Speaker B: Right.

Speaker A: I love it, that's great. But no, you can't have that. We'll build something for you if that's where you were going. And then thinking about like, how are you going to get that visibility into those pieces, right. Those prompts, the output. Risky behaviors. Right. Do you have the tools that can do that? Um, or are you in a platform that doesn't give you that visibility and you're just relying upon your end users to make good decisions? Um, that from a security line is probably one of the really critical pieces. Right. The other stuff's all pre work and to finding where those risks are going to be allowed. But you can't see that output. There's always the things that you don't know. Those things are surfaced and then always the last one. If you start building agents in your company, when that person leaves it built that agent who owns it right forward. Because previously the uh, agent was owned by someone and managed by someone. Now, now you have this identity out there. I've already seen hundreds of agents that have, you know, are being used, but they don't have an owner. So that means that there's also no understanding of how things drift and you know, responses meeting the same business criteria that you're expecting. Is it still doing the same security grounding that you're expecting so.

Speaker B: Well, does not fall under the same kind of principle, and I think you've seen this too, is if you develop a product or service on a company laptop, it's the company's, you know, product and or service. So if you develop a process or an application or something like that, it's actually company. I feel if it's the AI, if it's, you know, if they have a corporate version of Claude and you're doing Claude and you're doing the agents and the coding and the skill set and all that, I have a feeling it's theirs, it's the companies.

Speaker A: Yeah, the company needs to own it going forward. So who's, who's taking responsibility as you exit the door?

Speaker B: Right.

Speaker A: You know, what's happened in the past is, yeah, it's An HR role that falls into it, that tells them what to do, but then it forgets that they have agents sitting out there.

Speaker B: 100 and I think that's going to be like you said another line. I'm into what, you know, when you're going through their account and restoring their data and all that and transferring over, by the way, check their AI account and go through and you're not going to have to look at how to extract the MD files for the skills and this and that. Like all that stuff. Right.

Speaker A: So valuable even. Right. Like it could be just using tokens and it's, you know, posting something to, to their email. Who knows? Um, those are all, all things that need to be looked at.

Speaker B: 100 now, best way to get a hold of you, Ben, is, is at your LinkedIn.

Speaker A: Yeah, LinkedIn. Um, username is Ben Dash Wilcox.

Speaker B: Yeah, so just on the screen. So if you guys are watching that, it's LinkedIn.com forward/in forward slash. Ben-Wilcox. And then uh, Pro Arc, uh, the website's ProArk.com. ben, thank you so much for being here. This was great.

Speaker A: It was a great conversation. Brandon, thanks for having me on.

Speaker B: Oh, you're welcome. You know, it's great learning so much information from you and just kind of going through like all the due diligence and stuff that we've talked about. So thank you so much.

Speaker A: You're welcome.

Speaker B: Awesome everyone. So, I mean that's the end of today's daily side right now. As you guys know, like, there's just so much you guys, we're going through when it comes to like cyber security and infrastructure. I mean, Ben talked about like kind of the five main things you got to look at in this, in like, in this time frame, like identity access management, data protection, business impact analysis, core thing you need to go through. If you don't understand what your business is, the infrastructure and how your business runs, you run into an issue, trust me, and an instant response. You're going to learn very quickly and it's going to be very painful. If you do that ahead of time. It's going to really help you. Uh, unifying the tools and having like a one pane of glass and making sure everything intertwines and so you have visibility across the full environment and then device trust. Being able to have a way of having the devices communicate, but also in a secure manner. Right. So they're all connected, all communicating and be able to trust. The devices in your environment are the ones that are supposed to, especially if you don't you can find rogue devices. I know. I have seen environments where someone's plugged in a router, right. And then running a server or something along the line, and you're like, how did that get there? But they had tools to be able to scan the environment to go, that's not. That shouldn't be part of our environment. And they're able to go find it and disconnect it. So a lot of great conversations we got today just to learn about just overall security. So go back, watch this again. I mean, Ben gave a lot of great information. So don't forget software. Tackle being connected as vulnerable. I'll see you next.

Speaker A: Daily Cyber Sam.

Speaker B: Sa.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • We can't - and shouldn't - fix everything [The Industrial Security Podcast]The Industrial Security Podcast · on Business impact analysis95 / 100
  • If Your MSP Says ‘All Good’, Can They Prove It?The Small Business Cyber Security Guy · on EDR (Endpoint Detection and Response)89 / 100
  • How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200MThe SaaS Podcast · on EDR (Endpoint Detection and Response)87 / 100
  • AI Is Having Its Dropbox MomentAI Proving Ground Podcast · on Microsoft Purview85 / 100
  • Responding to Ransomware Attack [Case Study] | Interview with Yannick HirtSecure & Simple · on Business impact analysis85 / 100
  • Decoding the Cybercriminal Mindset, with Ryan ChapmanThe Cyber Insider · on EDR (Endpoint Detection and Response)85 / 100

More from DailyCyber The Truth About Cyber Security with Brandon Krieger

All episodes →
  • DailyCyber 293 - Privacy-First AI, Personal Knowledge & Trustworthy Intelligence
  • Technology Strategy, Operational Efficiency & Business Innovation | DailyCyber 292 with Robert Maxwell
  • Digital Executive Protection & Cybersecurity Risks for Executives | DailyCyber 291 with Dr. Chris Pierson
  • The Future of Tokenized Settlement and Quantum-Ready Financial Infrastructure | DailyCyber 290 with Ryan Kirkley
  • Building Cyber Ranges & Real-World Cyber Readiness| DailyCyber 289 with Lee Rossey
Explore the best B2B Ops podcasts →
All DailyCyber The Truth About Cyber Security with Brandon Krieger episodes →