The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/ExpedITioners
ExpedITioners artwork

Huxley Barbee: The modern divergence of environments and security methodologies.

ExpedITioners · 2024-01-30 · 34 min

0:00--:--

Key moments - from our scoring

Substance score

42 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber9 / 20
Specificity & Evidence9 / 20
Conversational Craft9 / 20

Huxley Barbee brings two decades of security experience - from Unix tinkering through software engineering to security operations automation at Cisco - to his role at Run Zero, a cyber asset attack surface management platform. The episode explores how the shift from perimeter-based security to distributed hybrid environments has fundamentally changed what security teams must protect. Run Zero addresses this by providing comprehensive visibility across IT, IoT, and OT devices wherever they exist: on-premise, cloud, or remote worker homes. The platform combines unauthenticated active network scanning (the Rumble technology many know), API integrations with existing tools, and passive traffic sampling for fragile OT/ICS environments. Beyond discovery, Run Zero helps prioritize risk through CVE correlation using asset details, detection of insecure configurations like exposed RDP or expired certificates, and algorithmic identification of outlier devices - which Barbee's team found correlate highly with actual vulnerabilities. Complementary to traditional vulnerability scanners, this approach helps security teams manage exponentially expanded attack surfaces with static headcount. The conversation also covers Barbee's community work organizing BSides NYC, a large-scale, accessible security conference targeting everyone from students to seasoned practitioners.

Key takeaways

  • →Run Zero combines three data sources - unauthenticated active scanning, API integrations, and passive traffic sampling - to build comprehensive asset inventories across cloud, on-premise, and remote environments that traditional network scanning cannot reach.
  • →Identifying insecure configurations and outlier devices can be more actionable than vulnerability scanning alone, as they represent low-hanging fruit that adversaries target when well-protected systems dominate a network.
  • →The deperimeterization of networks through remote work and cloud adoption requires security teams to shift from perimeter defense to continuous asset visibility without proportional increases in team size.
  • →Run Zero uses deep asset attributes (hardware, software, services, vulnerabilities, configurations, identity, controls) to predict CVE exposure without waiting for traditional vulnerability scanner updates, enabling faster zero-day response.
  • →Outlier detection using statistical correlation shows high correlation with actual risk, allowing security teams to focus remediation efforts on unusual devices that typically fall through policy gaps.

Guests

Huxley Barbee

Topics in this episode

API integrationsZero TrustSASERun ZeroRumblecyber asset attack surface managementdeperimeterizationunauthenticated active scanningpassive traffic samplingCVE correlation

Questions this episode answers

How does Run Zero discover assets that traditional network scanners cannot reach?

Run Zero combines unauthenticated active scanning on-network with API integrations to cloud and SaaS platforms, and passive traffic sampling for OT/ICS environments, allowing discovery of remote employee devices, cloud instances, and fragile infrastructure that cannot be actively scanned.

What makes Run Zero different from a traditional vulnerability scanner?

Run Zero is not a vulnerability scanner but an exposure management tool that identifies vulnerabilities, misconfigurations, and outlier devices using asset details; it works alongside traditional vulnerability scanners to provide faster CVE correlation and prioritization without needing to wait for new vulnerability check releases.

How has the shift to hybrid work changed security team requirements?

Deperimeterization eliminated the ability to rely on a single firewall choke point, forcing security teams to protect multiple divergent environments (office, cloud, remote homes) while maintaining visibility and controls across all of them without proportional increases in staffing.

What are insecure configurations and why does Run Zero detect them?

Insecure configurations are non-CVE issues like exposed RDP on public IPs, telnet running, SSH key reuse, or expired certificates - security mistakes rather than vendor code flaws - that Run Zero detects natively because vulnerability scanners do not flag them but they represent easy attack vectors.

What correlation did Run Zero find between outlier devices and actual risk?

Run Zero's analysis of its large device database found a very high correlation between outlier ranking (devices with unusual hardware or service attributes in a homogeneous population) and actual vulnerability risk, making outlier detection a useful shortcut for security teams to prioritize remediation.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode has pockets of useful operational content - passive traffic sampling for fragile OT/ICS environments, using asset fingerprint data as a proxy for zero-day exposure before vuln scanners update - but large portions are product explanation, career biography, and BSides NYC logistics that deliver zero operator value. The ratio of novel idea to filler is low for a 34-minute runtime.

we have a passive traffic sampling capability that allows folks to learn about those type of devices without ever touching them
you can identify devices that are potentially vulnerable. Right? And essentially using asset details as a proxy for that particular CVE

Originality

7 / 20

Most of the conceptual ground covered - deperimeterization, zero trust, SASE, the 'you can't protect what you don't know' mantra - is well-trodden security discourse. The most original element is the empirically-observed correlation between outlier device ranking and vulnerability risk ranking, but it is mentioned without any real depth or contrarian framing.

we've done some quantitative analysis on our very large database of devices and what we've found is there's actually a very high degree of correlation, uh, between outlier ranking and risk ranking
there's like a battle on social media right now about that mantra that you can't protect what you don't know

Guest Caliber

9 / 20

Huxley has genuine practitioner depth - multi-decade background spanning firewall deployment, software engineering, and leading a security automation practice at Cisco - but he is currently in a vendor evangelist role, a GTM function, not an active operator solving these problems at scale. The knowledge base is real but the current vantage point is commercial.

I was at a, um, Cisco Systems where I led a security practice where we were dedicated to automating security operations and incident response playbooks
this security evangelist role is very new to me and I'm trying it out and seeing what it's like

Specificity & Evidence

9 / 20

A handful of concrete data points exist - BSides NYC attendance figures, ticket price, student demographic percentage, passive scanning launch timing - but the product capability claims that matter most for operators (e.g., 'very high degree of correlation,' 'very high degree of confidence' on CVE proxying) are asserted without quantification, timelines, or named customer examples.

we had close to 800 check ins in 2023. So we're shooting for about a thousand
this was only introduced last September

Conversational Craft

9 / 20

The host (himself a practitioner as CTO of Fleet and co-creator of osquery) makes one genuinely sharp move by positioning Fleet's agent-based approach as complementary rather than competitive, which briefly elevates the dialogue. However, the interview is largely unchallenged, follows a promotional arc for Run Zero, and the second half dissolves into conference-planning logistics with no substantive follow-up questions.

we at Fleet take almost the opposite approach. Instead of looking at the network and the control planes, we get on the devices and look right at what's on the devices
And am I interpreting correctly that you do a lot of this work from the network and the control planes essentially?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B77%
  • Speaker A23%

Most-used words

security34network27devices22device18zero15conference14folks13vuln13huxley11back11community11interesting10type10help10part9cool9

Episode notes

Show notes: Today, we’re joined by Huxley Barbee, a security evangelist at RunZero and organizer of Bsides NYC. In this episode, Zach and Huxley talk about the modern divergence of environments and security methodologies. Topics discussed: Huxley’s start within the security industry. Making the industry a better place for newcomers. Chasm solutions. Comprehensive security visibility. Methodologies of collecting data (on the network). How “network” terminology has evolved. “Deperimeterization”. Modern divergence of security environments and efforts of discovery. The top 3 important components that help round out a security program. Agent-based collection compared to network-based collection. Organization of Bsides NYC. Where to get in touch: Linkedin Twitter Mastadon Bsidesnyc.org Runzero Try Fleet Fleet makes it easy to get accurate, actionable data from all your endpoints. From full disk encryption to healthy antivirus software and any query in between. See for yourself.

Full transcript

34 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Expeditioners podcast where we speak with the folks who are leading the way in IT and security. I'm your host, Zach Wasserman, CTO of Fleet and co creator of Osquery. Now on with the expedition. Hello and welcome to the show. Today we've got Huxley Barbee, who's a security evangelist at Run Zero, formerly Rumble. Some folks may know it by that name. Glad to have you on the show, Huxley.

Speaker B: Thank you for having me, Zach.

Speaker A: Awesome. Well Huxley, uh, as you know we often start this show with getting a bit of background on how folks ended up where they are today. And I know that you have a long and interesting history in the security industry. Uh, so I'd love to hear a short telling of your story.

Speaker B: Long, yes, interesting. I'm not really sure, but I will indulge you. Uh, so when I think back on my career, I think there have been like five phases of it. And by career I even include like doing security things as a hobby, you know, back when you're a teenager. So there's that first period where it was just like a lot of tinkering around the school's Unix systems and things like this, doing things that may not, uh, may not have been okay for me to do. But laws are different.

Speaker A: We're out of the statute of limitations now hopefully as well.

Speaker B: Yeah. Uh, then the second phase is when I started doing security work more professionally. And here I did a lot of deployments, firewalls, secure, uh, email gateways, uh, web proxies and so on and so forth. Also some assessment type work as well, uh, things along those lines. Alongside of this is a third part of my career where I was just a full time software engineer for, for many, many years. And that's, you know, there was a time where like software engineering was, was sort of looked down upon by security practitioners and that's totally changed over the decades. And there's like a fourth part of my career which is where I was able to bring the software engineering and the security piece together. I was at a, um, Cisco Systems where I led a security practice where we were dedicated to automating security operations and incident response playbooks. And then finally I'm in like the fifth phase of my career. I feel like where I've uh, come over to the go to market side, but it's also still evolving. Right. So this security evangelist role is very new to me and I'm trying it out and seeing what it's like and um, I'm really enjoying the part where I am able to give back to the community, having gathered, uh, all this experience and knowledge over the last couple of decades and then being able to share that back with everybody else and, um, just making the industry a, uh, better place for those who are new to it.

Speaker A: Totally. And that's awesome. Huxley. I know. Speaking of community, you are one of the organizers of BSides NYC. And we'll come back to that at the end. And very curious to hear more, more about that. To me, it is an interesting story and I love to hear you break it down into the phases and to think about all these diverse ways in which you've interacted with this industry. Um, I think that probably helps you bring some really cool perspectives to the evangelism that you're doing now. Uh, for folks who don't know about Run Zero, can you just give a summary of what it's all about?

Speaker B: Yeah. So Run Zero is the marketing calls it a chasm solution, a cyber asset attack surface management solution. What it really is the very first step that any organization needs to leverage in order to do, uh, security risk management. This is done by helping organizations understand their exposures through comprehensive security visibility, which I'm sure is a lot of words that requires a lot of explanation for most folks. Um, but I'll pause there if you want me to get into it some more.

Speaker A: Yeah. So to my understanding, it's kind of about, you need to know what you've got in your organization, in your environments, in your infrastructure. And Run Zero helps you figure out what's there and where the risks are. Does that sound aligned?

Speaker B: Yeah. You know, there's like a battle on social media right now about that mantra that you can't protect what you don't know. And it is true, technically, you don't need to know every single detail about what you have in order to protect it. Because at least back in the old days of perimeter security, right, we just threw a firewall in front of the LAN and then you're good to go. You didn't really know what you had on the network. I think more and more it is becoming true. The more details you have about the endpoints, um, on your network, the more likely you're going to have, uh, a better defense. And the Run Zero solution is able to help you identify with a great degree of detail and granularity all the devices that are on your networks. Doesn't matter what the device type, uh, up might be. It could be an IT device, an IoT device, or an OT device even. And it doesn't matter where that device is. It could be in the cloud, it could be on premise, it could be in your remote employees homes or in your factories and so on and so forth. That's the type of thing that we mean when we mean comprehensive uh, security visibility. And I mentioned before the granularity.

Speaker A: Right.

Speaker B: The depth. Right. So when we talk about an asset, it's any compute device plus all, all the details that the security team cares about. So that would be the hardware. So not just operating system, not just oh, this is a Linux box, but the hardware. Like is it an IP camera, is it network, uh, test storage, the software, the services, meaning like you know, the ports that are being listened to and so on and so forth. But not just those things. Right. Also the vulnerabilities that are on the device, the insecure configurations on the device and also identities associated with the device like who's the user that's using the device or the person that owns the device to help with remediation. And finally security controls like do you have EDR running on as many endpoints as possible? Is your vuln scanner covering everything that you care about? Is your network, uh, segmentation appropriate for your organization or are there violations for segmentation things along those lines. So those are all the details that we think are important to security teams and details that they can use, especially from an uh, exposure management perspective to do their jobs well and improve the defensive posture for the organization.

Speaker A: And am I interpreting correctly that you do a lot of this work from the network and the control planes essentially? Uh, like in the cloud, the control planes and in general over the network and network based scanning?

Speaker B: Yeah. So it's a uh, multi pronged approach for figuring out what you have on the network. One is we have uh, a lot of API integrations with multiple solutions in your tech stack. In fact this is one of the few ways that you can actually find out what's in your cloud or devices that are disconnected from the network. Right. So remote employees, they're not on your network, you can't scan into their houses. I mean you could, but if you. There's some major privacy issues with doing that. Right. So API integrations is one methodology or one data source for this type of cyber asset inventory. Another way is with. And this is why people know about Rumble. Most people know about Rumble. It's run, uh, zero formally knows Rumbo is the unauthenticated active scanner.

Speaker A: Right.

Speaker B: This is basically a way of going out onto the network without any credentials, finding out all the details you need about a device, uh, and doing it from the perspective essentially of a pen tester to gather all the information you need, oftentimes through uh, leaked sources on that device to identify what that is. And many folks are very, very surprised at how well we can fingerprint devices and how much granularity we have about those devices, even though we don't have credentials. There's a third methodology for learning about devices on your network, and this was only introduced last September. And, and it was primarily introduced to help organizations that have very limited scan windows or they have environments that have fragile devices, primarily OT and ICS environments. And these types of environments, oftentimes by policy or just um, by the type of devices, they don't want to do active scanning. And so we have a passive traffic sampling capability that allows folks to learn about those type of devices without ever touching them. It's not a full on passive network monitor, or I should say a legacy passive network monitor where you require a bunch of beefy hardware appliances to collect all the network data. Instead, it reuses the same software, uh, package that we use for the scanner and it samples the traffic in order to build, uh, an asset inventory.

Speaker A: That's really cool to think about all of the different sources that you're putting together to gather the data, uh, about the systems. And I heard you talking about the network and I'm thinking about your long career in security. And you did mention a bit the way that the proverbial network has changed and evolved. I think especially in the last few years since COVID and uh, work from home exploding and the hybrid workforce kind of becoming the norm. I wonder if, if you have any reflections on the way that those, uh, evolutions in how we work have changed the requirements or challenges for security teams.

Speaker B: Oh, it's definitely gotten a lot harder, right? This, uh, deperameterization, uh, just made things more complicated. Back in the day, all you had to do was protect what was in the office. And when you had this concrete perimeter, uh, like I mentioned before, you just throw up a firewall at a particular choke point and you're good to go. You didn't even necessarily need to know everything that was on the network. Um, I mean, you still had concerns for insider threats, right? People bringing their own devices and things like that. But still having that perimeter really helped because when you have devices or when you have controls at the choke point, you can also manage the traffic going out. So you can stop the rogue devices on the inside that way. But with deperimeterization, this gave the rise to market categories like sase for example, uh, and it's also made the concept of zero trust far more important. Right. Because people moving around and so on and so forth, and it gave rise to entire mobile security field. So while this is all happening, security teams haven't gotten larger or anything like that, and they're just inundated with more and more complexity to deal with. Um, it's a hard thing to do, but the tools that we build in our industry need to help the security teams to keep up with these type of changes. Right. Um, and speaking specifically about asset inventory, there was a time when you probably didn't need to go out onto the network to look for a whole lot of things necessarily. If you were a lockdown organization, you would just barcode every single laptop or server in the company and then you're done. Uh, or you would run a very simple tool like Satan, and then you get a pretty good understanding of what's on the network. But nowadays with this divergence of environments, it's just gotten a lot harder, and you need to have solutions that can deal with the multiple networks that a, uh, security team is now expected to protect.

Speaker A: Yeah, that makes a lot of sense to me. And you talked about this discovery and going beyond discovery as well, to identifying threats, um, and risk. You talked about this being, in your eyes, a foundational component of a modern security program. What do you see as the next most important components? Beyond when someone has Run Zero in place, what are the next components that you think help to round out a security program?

Speaker B: Yeah, visibility is all about telling you what you have, and that's good. Everybody appreciates knowing what they have, but usually you find out there's so much out there, uh, you don't know where to focus. Right. Uh, the second question that folks often want to know the answer to is what is the thing I need to focus on? What do I need to prioritize? What do I have to go after in order to help me do my job efficiently and protect my organization? So, uh, the first part is, what do I have? The second part is, what, what is bad? What is bad? What is the bad thing that I need to go worry about? And with Run Zero, there's, uh, three different native capabilities that we have to help with, uh, exposure management. Now, I want to be clear here. Run Zero is not a vuln scanner in the traditional sense. Uh, we still expect organizations to have vuln scanners. It's a very important, important part of your overall exposure management program. But there are other things that you can do that can really Help, uh, the efficiency or time to remediation, uh, when you're leveraging additional capabilities. With uh, Run zero, the first capability that we have is the ability to tell you which are the assets that are potentially vulnerable to a certain cve and doing this without having to rescan the network. The challenge often is vuln scanners. Uh, they have limited scan windows or they have scan schedules, or if it's a new in the wild vulnerability, the vendor has to release a new vuln check onto that vuln scanner and then the following, uh, vuln scan. And if it's like an O day where that time to remediation is critical, you don't want to wait a week or two weeks or even three weeks before you get to work. And with Run zero, there's the ability to use asset details. Now remember what I mentioned earlier, we have a really deep granularity of detail unlike many other tools where when they query a device they might just grab just the information that they need. With Run zero, uh, we grab everything, even if we don't need that data right now for a certain use case, we just grab everything based on asset details. You can identify devices that are potentially vulnerable. Right? And essentially using asset details as a proxy for that particular CVE, it's not 100% of the time, correct. But uh, we have found that you can identify devices that are potentially vulnerable with a very high degree of confidence. And while you're waiting for your vuln scanner to actually catch up, maybe the vuln check is being delivered and so on and so forth, you can quickly generate a list of devices to go look at, uh, as your immediate day. One Response to an O Day yeah,

Speaker A: this is a really interesting one to hear you bringing up because, uh, we at Fleet take almost the opposite approach. Instead of looking at the network and the control planes, we get on the devices and look right at what's on the devices we found. Similarly to what you're describing, folks are not satisfied with their legacy vuln scanners. I love the idea of coming at it from both directions. Be on the device, do continuous agent based collection of inventories of what's on there and what the potential vulnerabilities are, and then also come at it from the network side from what can we observe from outside the device, but also get beyond the kind of legacy idea of scanning and needing to have signatures and that kind of thing. Um, so to me this is a very interesting complementary kind of way to approach these problems.

Speaker B: Yeah, and complementary is a good word because, uh, we don't claim to be a vuln scanner. Vuln scanners are still important. They still need to be there as part of the overall exposure management program. But there are shortcuts that can help you do your job more efficiently. The second uh, native capability is something I think is in many ways more important, right? Because oday is always like make it in the news and it's like the trendy thing that everybody sort of latches onto. But potentially more important are those insecure configurations. What I mean are ah, like people still running telnet for whatever reason or RDP running on a uh, device that has a public IP address or SSH keys being reused or web services that have expired certificates? All sorts of those really easy things that should be remediated that can dramatically approve your defensive posture. But they're not, they're just left out there because the security team didn't know about it. This is not something that typically you would vuln scan for, right? There's no CV associated with this. This isn't part of the nvd. This didn't occur because a vend or introduced some insecure code inadvertently. This is just because somebody made a boneheaded decision about configuration on a device. Um, but anyway, Run zero has this native capability to go out and find those things for you and help uh, you kick off remediation on that. And then finally there's a third way which is outliers. And this is probably one of the newest things that we've introduced in like tell you what's bad on your network. Right. But first I want to um, say that when we say outlier, uh, we mean a certain attribute where there's a certain degree of homogeneity in the pool of data, right? In the pool of values I should say. And then there's some outliers. One of the most interesting ones is uh, hardware type, right? So you know, let's say you have a high degree of homogeneity, like lots of servers and lots of laptops and then you have this one IP camera or you have this one Roku box or like so you know, security programs, obviously like with any project you want to focus on the big picture first, right? And manage the large swaths of devices on uh, the network and have uh, provisions for those. And so uh, you're going to be, you know, you're going to be instituting policies for getting EDR on the laptops and so on and so forth. But the thing is though, once that's done, like once you've taken care of the Big bowlers in security program. There's still these oddball devices out there that haven't been looked at and oftentimes they fall through the cracks. And when the adversary comes upon a network where they see, oh hey, 99% of these devices are now well protected because they've got the proper security controls on them, where are they going to go? The adversary isn't going to go do the hard work and try and attack one of these well protected devices. They're going to go look for the thing that's fallen through the cracks. Oftentimes those are the same types of devices that are unpatched, unmanaged, potentially unknown and forgotten.

Speaker A: Yeah, this is like the server that some developer just put under their desk five years ago and it's still running some service, maybe it's not even used anymore. And uh, and no one's patched it in quite some time.

Speaker B: So yeah, and I mentioned this as hardware type, but it could also apply to services like oh, there's this one SMB v1 service running over here. What's going on? And we've done some quantitative analysis on our very large database of devices and what we've found is there's actually a very high degree of correlation, uh, between outlier ranking and risk ranking, like vulnerability, risk ranking. So very high chance that if something is uh, an outlier, like you have one or a few of these things, it has some vulnerability on it. So uh, it's another shortcut for the security team to say, aha, what are the things I really need to worry about? What's bad on my network? Give me that short list, let me go prioritize that.

Speaker A: Yeah, and there's an interesting analogy for us where we often work with teams where there's say uh, an organization where there's 5,000 Mac laptops and there's about 200 Windows laptops and about 50 Linux laptops of all different flavors. And it's like, well, where are you going to find the issues? It's going to be often in those rarer assets where there's less management because understandably the organization has been prioritizing the widest surface area. So it's interesting to hear that your platform does uh, an analysis to find these things. And further, really interesting that your data confirmed that the risk is actually higher on those.

Speaker B: Yeah, we weren't sure when we started down this path, but once we developed the algorithm for it we were happy to see that there was actually a high correlation. So it was a really good feature that we added in My opinion.

Speaker A: Very cool. So Huxley, I want to shift gears now to the community. And you talked about this a bit at the beginning. You've been in this industry for a long time and you're excited about giving back. Um, so recently, uh, as I understand it, you became one of the organizers of BSides NYC. Can you talk a bit more about what your motivations were to do that and, and kind of why you're, you continue to be excited about that community work?

Speaker B: Yeah, um, I, I was definitely looking for a way to give back. And um, I think there are a few ways. Right. You can teach, you can write a tool. Uh, but this was a third way, which I have never really done before. I attended conferences many times, but I've never tried to organize something. And there was an opportunity. There was an opportunity. So the B side's New York City conference sort of fell off after Covid and the founders of the conference sort of moved on, uh, onto other things, uh, just overtaken by events and by life. Um, and so there was an opportunity and I just thought maybe this is a different way, a new way that I can give back to the industry that's given me so much. And frankly, I think part of it is also just pride. As a New Yorker, we don't, you know, where's, where's the big security conference in, in, in New York. Right? Um, there are a few, There are a few. But like, this is New York City. Like we, we deserve to have like the, the, the grand scale type of conference related to this also is that, you know, some of the other conferences are a little bit more, um, limited in terms of their reach. Right. Um, they're either, you know, a little bit further out from the city center or they're at smaller venues and things like this. Uh, we are the only one that is, uh, at a large venue that is accessible to all levels of security. So 15% of our attendees from the last one are early in career or cybersecurity students. And we charged, I think 15, $15 for, for the conference. Right. We, we strive to make the conference free or very, very low cost in order to ensure that we, uh, are making it accessible to everybody that, that can, uh, students actually got free tickets when they, when they email us about it. So, uh, there's a number of reasons why, you know, I thought, I thought, uh, we needed yet another security, uh, conference in New York City, but it is actually remarkably different from all the other security conferences that we have.

Speaker A: Yeah. And that's something that I've really Appreciated about BSIDES conferences all over is this really cool combination of world class conferences and really accessible and really community oriented. And I think that there's a pretty stark difference between uh, something like an RSA and a B sides.

Speaker B: Very, very. The community driven aspect of it makes it such that there are conversations that are had at these conferences like BSides or Defcon that you just wouldn't have at RSA. Right. It also attracts um, different types of interests that you wouldn't, you wouldn't necessarily have at RSA. So yeah, for sure, 100%.

Speaker A: Um, and Huxley, you're in the middle of Planning for uh, 2024 iteration of uh, BSides NYC. Can you tell us more about what's coming up?

Speaker B: Yeah. So we are going to repeat some of the things that we uh, learned that worked well from the last conference. So we're going to have one track for red team talks, one track for blue team talks. We're gonna have another track for the other color talks. Uh, we will also have a workshop track. And uh, we will have more CTFs than last year. So we had, we had like one and a half CTFs uh, at the conference in 2023. We'll probably have like two or three this time around and more villages than before. We got a late start on getting villages, uh, at the conference but, well, we'll get a head start on that this year. And another interesting thing is we're one of the few B sides that had a entrepreneur track. So we had this in 2018. We did not have it in 2023 because I didn't want to bite off more than I could chew. Uh, but for 2024, uh, we are going to bring back the entrepreneur track, um, because it's New York and there's a lot of startups, cybersecurity startups in the area. So we want to make sure that that community is represented as well.

Speaker A: Cool.

Speaker B: And we had close to 800 check ins in 2023. So we're shooting for about a thousand.

Speaker A: Awesome.

Speaker B: For 2024.

Speaker A: Sounds like a huge operation.

Speaker B: Yeah. Yeah. But I think the one detail that you really want to hear, and this will be the first time that I'm saying this publicly, the conference will we plan to have the conference once again at uh, John Jay College. Uh, very. We very much appreciate the D4Cs program at John Jay College for supporting us throughout the years on these conferences. We uh, will be there once again over an open Hell's Kitchen in New York. And the conference date will be October 19th, 2024.

Speaker A: Awesome. You heard it here first, folks. Uh, I'm guessing then you've got a little while to prepare, uh, for the CF and the sponsorships. But, uh, things are starting to roll for 2024.

Speaker B: Yep. CFP should open in May, probably run through August. Uh, need to figure out the end date. We don't want to overlap with summer, uh, camp too much. And sponsors sponsorship kits should be ready in February sometime.

Speaker A: Very cool. Very cool. Well, Huxley, thank you. Thank you for doing this community stuff. I can only imagine it's a ton of work and it's.

Speaker B: Oh, my God, it's so much work. Oh, my God. Yeah. My wife looked at me and was like, are you crazy? Yeah. And then after the last week said, are you doing this again?

Speaker A: Yeah.

Speaker B: Yes. If that's okay. She's like, I support you. I support you. But, like, just think about, think about it, though. Just really think about whether or not you should be doing this again. I'm like, I think. I think it actually helps. So anyway, she's been very supportive, so.

Speaker A: Cool. Well, I think it is making a difference for a lot of people. And, um, it's really appreciated from community members like myself that people like you are stepping up to do these things. So, Huxley, thank you so much for coming on the show today and, um, for everything that you do both kind of in your professional and your volunteer work. Uh, BSides NYC in October. Where else, uh, should folks look out for you, either online or in person in 2024?

Speaker B: Well, in person, um, I have not started my applications to various talks, uh, around the country yet. But if you follow me on social media, you'll definitely know, uh, if I'm coming to a conference near you for a talk. So you can find me, uh, on LinkedIn or Twitter or Mastodon, the Infosec Exchange instance of Mastodon. Uh, on Mastodon, I am Uxley. On Twitter, I'm on huxleybarbie and LinkedIn. Just look for Huxley Barbie. I'm the only Huxley Barbie you're ever going to meet. So that's an easy one. Right?

Speaker A: A, uh, unique name for sure.

Speaker B: Yeah. If you want to learn more about Bsize New York City, it's just Bsize New York City, BSizenyc. Uh dot org. Um, you could subscribe to our mailer or join our Slack workspace to get more information. Or better yet, follow bcizenyc on social media. Also on LinkedIn, Twitter and Macedon. And, um, if you want to learn more about Run zero, it's R u N Z E R O dot com. There's actually a free forever community edition of the software that does all the things that I mentioned before. API integrations, uh, unauthenticated active scanning as well as a passive traffic sampling. You could download it and uh, run it in your house if you want, or run it at your company. And uh, it's um, no credit card required or anything, just download it and use it.

Speaker A: And I've done that and it's really cool to start to see all the data that the platform collects. So yeah, I recommend folks check that out and we'll drop all those links into the show notes. Uh,

Speaker B: I invite everybody to connect with me on social media. I love interacting with folks. I am an evangelist now after all. So let's have, have conversations. So come find me.

Speaker A: We've got a community guy here. Huxley, thank you so much for joining the show today and wishing you a great 2024 and to all our listeners, thank you.

Speaker B: Z.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on Zero Trust88 / 100
  • Why “Cyber Is Broken”, And Building Trust in an AI World - Karl Van den Bergh CMO IllumioCyber Go-To-Market Talk · on Zero Trust87 / 100
  • Zero Trust as a Mindset: Identity, Governance, and Access | Interview with Andrew GaultSecure & Simple · on Zero Trust83 / 100
  • Streamlining Hospitality Systems with Otelier’s Lexton RaleighEvolving the Enterprise · on API integrations83 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Zero Trust79 / 100
  • Tech Transforms: Episode 5ATARC Federal IT Newscast · on Zero Trust78 / 100

More from ExpedITioners

All episodes →
  • Marcus Ransom: The positive future of collaboration between vendors and Apple for enterprise
  • Jeff Chao: Configuration as code for efficiency and automation.
  • Charles Edge: The past, present, and future of all things computing and device management.
  • John Reynolds: Rehumanizing interactions between IT and end users
  • Rich Trouton: Declarative Device Management and a promising future for Mac Admins
Explore the best B2B Engineering & DevTools podcasts →
All ExpedITioners episodes →