The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/No Password Required
No Password Required artwork

No Password Required Podcast Episode 74 - Shane Tews

No Password Required · 2026-06-22 · 52 min

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality8 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft7 / 20

Shane Tews brings three decades of experience navigating the intersection of technology and policy, starting from her unlikely role introducing lawmakers to Internet concepts in the 1990s at VeriSign. Today at the American Enterprise Institute, she covers a sprawling mandate - cybersecurity, AI, data protection, encryption, broadband deployment, and the entire network stack - taking a deliberately hands-off approach to regulation that prioritizes outcomes over prescriptive technical standards. Her core insight: legacy system vulnerabilities persist because organizations layer new security tools atop outdated infrastructure without updating underlying systems, creating "fulcrum points" for attackers. Tews identifies a critical policy-practice gap: consumers vastly underestimate their exposure while undervaluing their personal data, partly because information's monetary worth remains invisible to them. She advocates for transparency mechanisms - emoji-based permission summaries, micro-payment models - that would make data flows tangible. The episode explores why federal breach notification standards remain fragmented across 50 states, how CISA's reauthorization limbo strips liability protections companies didn't realize they'd lost, and why generational divides (her mother can't grasp why her phone connects to her finances) resist conventional cybersecurity messaging.

Key takeaways

  • →Organizations accumulate technical debt by layering new security tools over unpatched legacy systems, creating easy entry points for attackers who exploit gaps in updates.
  • →Consumers dramatically underestimate their exposure because the value of their personal data remains abstract and invisible - making them bypass native security elements.
  • →The 50-state breach notification patchwork creates compliance confusion; Estonia and Lithuania demonstrate faster response times because their legal frameworks align, while the U.S. carries legacy complexity.
  • →Effective technology policy should regulate outcomes and behavior, not prescribe specific technical standards, because regulations cementing technical details quickly become obsolete.
  • →CISA's reauthorization limbo stripped liability protections from companies in critical infrastructure without their awareness, exposing a major gap in policy communication.

Guests

Shane Tews

Topics in this episode

Legacy systemsMulti-Factor AuthenticationTechnical debtCISA (Cybersecurity and Infrastructure Security Agency)American Enterprise Institute (AEI)VeriSignISACs (Information Sharing Advisory Councils)ICANNencryption policybreach notification standards

Questions this episode answers

What caused the fragmentation of breach notification standards across U.S. states, and is federal harmonization possible?

Each state developed its own breach notification standard, creating 50 different requirements. While Estonia and Lithuania achieve faster reporting (4 hours) due to aligned legal frameworks, the U.S. faces legacy legal complexity. CISA's multi-stakeholder process and ISACs help share breach information under liability protections, but full federal harmonization remains difficult because states maintain independent regulatory authority.

Why do companies using outdated systems remain vulnerable even after implementing new security tools?

Organizations buy new security products but don't update or maintain legacy systems attached to them - a problem exacerbated by IT budget constraints. Attackers exploit these unpatched systems by laying dormant and slowly taking over the network. Technical debt accumulates because updates stop happening while the old system stays connected.

How much do everyday consumers understand about what happens to their personal data?

Most consumers don't realize their data has monetary value to criminals who sell it through third-party vendors, so they bypass security protections. Generational gaps exist - older users struggle to understand concepts like multi-factor authentication tied to their phones - and transparency mechanisms like emoji-based permission summaries or micro-payments might help people pay more attention.

What is the American Enterprise Institute's approach to technology policy?

AEI's economic side, where Tews works, covers cybersecurity, AI, data protection, encryption, broadband deployment, and the network stack. Rather than deep specialization in single topics, Tews "rides the top of the wave" to identify intersections and inform policy that regulates outcomes rather than prescribing specific technical requirements.

Why do regulations cementing specific technical standards become problematic?

Technology moves faster than regulatory processes (which take 18 months to create standards). Once technical requirements get locked into regulations, they persist for 10 years even after the underlying technology evolves, making it difficult and time-consuming to update frameworks.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

There are some genuinely useful points buried here - regulating outcomes not inputs, ISACs and liability indemnification, the CISA reauthorization liability gap, and calendar invites as an attack vector - but roughly a third of the episode is the 'lifestyle polygraph' section with zero substantive content, and the rest skims broadly without drilling into anything actionable. The signal-to-noise ratio is poor.

you want to legislate or regulate the outcome, not the input
One of the big um, attack spectrums right now is calendar invites which it breaks my heart because I love getting a click through

Originality

8 / 20

Most takes are standard policy-circle commentary - EU vs US regulatory philosophy, generational gaps in cyber awareness, patch management analogies. The Draghi Report framing of Europe's tech problem as a banking system problem is the freshest angle, and the DeepSeek compute-cost debunking is interesting but underdeveloped; little here would genuinely reframe a practitioner's thinking.

The problem tech for Europe is the banking system. They don't have that same innovative cycle in the way that they finance things
they just discounted the almost billion dollars worth of compute they had beforehand. They just didn't put that on the ledger

Guest Caliber

13 / 20

Shane Tews is a legitimate, long-tenured policy practitioner with genuine credentials - White House, VeriSign, AEI, ISAC formation, and active Google AI testing access - not a recycled thought-leader. However, she is primarily a policy communicator and generalist, not an operator who built something at scale, which limits the practitioner depth.

I was the first person to go to the Hill and explain to Capitol Hill and explain the Internet to a lot of people
When I was at VeriSign, we were, uh. A lot of the people I worked with worked on creating what they call the Information Technology Information isac

Specificity & Evidence

9 / 20

The episode has a reasonable spread of named entities - TSMC, Huawei, Draghi Report, CISA, Lithuania's four-hour reporting, Google Spark at $100/month - but almost no hard metrics, dollar figures, or case study depth. References are dropped and moved past rather than examined, leaving specificity at the level of name-dropping rather than evidence.

There was a report that came out, I think it's probably four or five years now ago called the Draghi Report
I was at an event with, um, this lovely woman from Lithuania who was in cyber, and she goes, I don't understand you guys. We can report in four hours

Conversational Craft

7 / 20

The hosts ask competent but mostly generic open-ended questions and rarely push back or demand specifics; the one bright spot is a sharp follow-up on agentic AI identity management after an employee departs. The lifestyle polygraph section consumes a significant portion of the runtime and is pure filler with no professional value whatsoever.

And how many agents did they have running? Right, if it's a, if it's a big, if it's a big consulting firm or something
If a major cyber attack hit some critical infrastructure tomorrow. Right. Do you think that governments are ready to respond to it?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C80%
  • Speaker A16%
  • Speaker B4%

Most-used words

policy20system20shane17back17cyber16different14phone14security13call13level13information13house13technology13first13problem13internet12

Episode notes

Shane Tews - Non-Resident Senior Fellow at AEI and the person who explained the internet to Capitol Hill No Password Required Season 7: Episode 7 - Shane Tews Shane Tews is a Non-Resident Senior Fellow at the American Enterprise Institute, where she focuses on cybersecurity, privacy, artificial intelligence, and internet governance. She is also President of Logan Circle Strategies, a strategic advisory firm working at the intersection of technology and policy. Before her think tank work, Shane helped introduce modems to the George H.W. Bush White House, walked the halls of Capitol Hill explaining the internet to blank-staring legislators, and spent years at VeriSign helping shape the foundational frameworks of how the internet would be governed. In this episode, Shane traces her unlikely path from the Bush administration to becoming one of Washington's most trusted voices on tech policy. She breaks down why regulating outcomes rather than inputs is the only sensible approach to technology governance, why the US and EU are operating from fundamentally different innovation philosophies, and why a national privacy bill is long overdue.

Full transcript

52 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to no Password Required. I'm your host, Jack Clavy, a cybersecurity attorney at Carlton Fields, Pennsylvania, Tampa, Florida. And with me is, I'm, um, Kaylee

Speaker B: Melton, the Director of community programs and events at the Cognitive Security Institute and the Bob Ross of InfoSec.

Speaker A: We just finished a great conversation with Shane Tooze. Shane is a non resident senior fellow at the American Enterprise Institute. She focuses on cyber privacy and Internet governance. Uh, she's also the president of Logan Circle Strategies, a, uh, strategic advisory firm. Um, also working on Internet and cybersecurity issues. Kaylee, what stood out to you the most in the conversation?

Speaker B: I think the thing that stood out to me the most was that people still don't really know who to call, when or what to do when they get themselves in a cyber incident. Um, and I think that applies within a lot of organizations, but particularly on the personal, individual or family level. You don't really know what to do when you have your identity stolen or your information is part of a breach and things like that. There's not a solid helpline that everyone knows that you can call.

Speaker A: Yeah. I think she also shares, um, she echoes a theme that I talk with a lot of my clients about and other folks in the industry about. When we talk about policy, a lot of times we're talking about laws and regulations passed by federal or state governments. Right. But also there's this layer over that in the United States and in other countries of private contract, when a person uses an app or an Internet service, they're agreeing to terms of service between them about what's going to happen to their data and they're going to get disclosures and they have choices. And similarly, if a company or a government is hacked or they might have obligations to keep certain security standards or obligations to tell folks based on contracts that they signed. So it's not just what the government does, but it's also what private parties do when they're having these, um, when they're agreeing about what's going to happen with data. So really cool, layered discussion. We have heard a little bit about what Kaylee and what I took away from this discussion, but let's hear what Shane had to say.

Speaker C: This is no Password Required, a Cyber Florida podcast presented by Threat Locker.

Speaker A: And we are back. Our guest today is Shane Tuze. Shane, welcome to no Password Required.

Speaker C: Thanks for having me. I really appreciate it.

Speaker A: So we're going to talk today a little bit about, about your role and about how you got to kind of where you are. But one Thing that uh, interests us is you were exposed pretty early on to high level policy stuff. You were in the George H.W. bush White House. How did your time in the White House shape your understanding of technology policy and its long term impact?

Speaker C: So I was very lucky, really. Just right out of college I worked for the, um, first Bush administration. And uh, when I moved I was over with the Secretary of Transportation, which was fantastic. I still talk to all those people. Um, two years. Two years. Then I moved to the White House. And when I got there, the office I was in was called the Office of Cabinet affairs. And they had a cabinet report that they did every week. That was a look back and a look ahead. That was the primary, um, audience was the President. But then other people read it and when I got there, they were retyping the reports and I was like, hey, there's this thing called a modem, let's check it out. And they said, no, this is the White House, we can't do that. That would like cause a security breach. And I was like, ah, you know what? I just had to find one person to be like, let's give it a go. So I plugged in the modem. Um, everybody eventually agreed to it except for the Department of Defense and I think the Department of Justice. And so we worked around that. But I mean, I was just like. And so it was a thing that would start on Wednesday. I would have to curate these, uh, you know, my colleagues when they came in, and then we would.

Speaker B: This.

Speaker C: The one that's so funny in hindsight was, um, the Office of Science and Technology Policy, which is so prominent today. OSTP would always send these like huge reports about cool stuff they were doing. But this particular administration, no one was really ready for that. And we would get it down to a paragraph, like those five pages. I always felt bad with them. I was like, oh, this poor ostp. It's so hard.

Speaker A: Computers, important, Internet, who knows?

Speaker C: So I left there, uh, and um, went to Capitol Hill and just saw, you know, this was still like, it was PCs on the desktop. Um, and then, um, eventually went to another job and then went to work for a company called Verisign that runs the domain name addressing system.net and.org, and this was in 2001. And it really was. I was like, I was the first person to go to the Hill and explain to Capitol Hill and explain the Internet to a lot of people. And they would just sort of blank stare at me, a lot of them, and I just hand them my business card. And say, if this comes up, just feel free to reach out. And like, two years later people would call me and be like, hey, you're that Internet girl who came in. Like, I have a problem now. Can we talk about it? And it's funny because people still like, I'll run into people and they'll be like, I was a junior legislative correspondent and you came in and like explained the Internet to us. So it wasn't that I had any background in. I'm, um, not an engineering by training, but I spent a lot of time with them and I just was, you know, the main thing about doing, um, the kind of work I do is asking a lot of the right questions. If you can get there, or at least asking a lot of questions, you get to the right question. And I learned a tremendous amount. But the key thing was really understanding what the, um, you know, as we now would think of m as guardrails, but, you know, the borders of what technology could and couldn't do. And there was every once in a while, and we still run into this in legislation, and we're seeing this with some of the child online safety laws is, or the proposed legislation is. They just want things to. It's like that's, that's actually interference in a parent child relationship. Have you tried the settings? You know, like. So, um, it's been a really interesting path to get to where I am. I feel very fortunate. But yes, early on I, it was very analog to answer a long, long answer to your question. Very analog.

Speaker A: But it's that mixing of, you know, we've all kind of experienced it and a lot of our audience has to. Where you're there to talk about something that has to do with technology. And then people also assume you're the person who can also run the technology. Right. Like, you know about Internet policy. But hey, here's a modem.

Speaker C: You know, I'm definitely, I'm definitely the help desk for every person above me and my family. Actually, when I go out to Colorado, where my dad saw the family's from, it was a joke because I had my aunt and my uncle be over there. I'd be like, I'd walk in the door from the airport and say, just get all your phones, lay them out. I'd nobody change their password since last time I was there. I would just dial in and I'd, I said, I'm not talking to you until we update. And like, I would uh, update all of their phones and then I would say, now what's the problem?

Speaker A: Is that, you know, going back to the early days of Internet policy, right, not necessarily the use of modems by the White House, but the actual policy that they were starting to put together. You know, what was that era getting right and maybe what was it getting wrong that you're sort of happy didn't get pulled through?

Speaker C: Well, the main thing, um, that actually I was party to, but not actually in the White House when it happened is a lot of credit to the Clinton administration. Around the advent of the Internet coming online and deciding that the government should not be the center of how that would work. That they created the multi stakeholder holder process which is trying to bring every level in. So you have that, uh, you know, the people that architected the main stuff, which was really cool. I've gone out of my way to meet like every person who, you know, was with TCPIT and HTTP and uh, then the bringing in the civil society, you know, people to think about freedom of expression. And um, in icann they have something called the non commercial users constituency, which means they don't necessarily have money at stake, but they have skin in the game is the way I, I think about that group. And then intellectual property, um, you know, things like the MOV studios. You know, early on we went through the whole thing with the, you know, eventually recording, um, artists with, um, you know, different things on there. And so it was a lot of, you know, how we got the policy right was trying to figure out how hands off we could be. And to this day though, I would say it's, you want to, you want to legislate or regulate the outcome, not the input. So it's very important that you look at the. The goal is something that you're trying to change, most likely behaviorally, but you are not doing that via, uh, hard edge. Here's what we think the technology should or shouldn't do because the, as we've seen, especially now, right. You know, we're to blow right past whatever those uh, things are in the regs and if they get cemented in, it's very hard. It takes a long time to break that up to get to where we are in current technology.

Speaker A: That's exactly right. Like specific standards of conduct that sit in regs that take 18 months to create and then you're stuck with them for 10 years even though the technology's moved on.

Speaker C: Yeah, definitely seen that in, um, areas. I mean, luckily we got part of encryption. Right. But now they're trying to break that. So, um, yeah, it's really fast. You know, some of Them are really hard to move on. I mean, and there's, you know, you think about, um, I can't. I'm going to drop his name at the moment. But, uh, you know, the first gentleman who had went to prison over something that, you know, Trump ended up pardoning him. I can't give his name, uh, because, you know, what he did seemed so obscene at the time, but now it's like something that's kind of like, you know, not. Not that we don't disprove it as much.

Speaker A: Right, right. Yesterday's conduct is today's norms in some degree, about Internet behavior, for sure. Um, one of the things that comes up. I'm a cyber security lawyer, uh, and so one thing that comes up from time to time is what. What the standard is when a company is breached. Right. And there are 50 states now, and there's 50 standards. Some of them are close to each other, some of them are identical, some of them are different. You know, what do you, you know, have you ever looked at the idea of this, you know, one federal standard or one community standard we all agree to, to kind of harmonize what's going on here for this? Is that something you've ever looked at or have an opinion on?

Speaker C: Yeah, I've actually spent a lot of time on that. Uh, I was. When I was at VeriSign, we were, uh. A lot of the people I worked with worked on creating what they call the Information Technology Information isac, um, Information Sharing Advisory Council. And the. The main reason why you have an isac, especially in the tech space, is for that indemnification on liability. So you want to be able to share information. We're definitely learning this again with the, um, advent of Mythos with Anthropic, is how fast can I get this information out there so other people don't suffer the same harm that I might have been through? However, I don't want to make public a lot of the information that, you know, might come out with that initial breach response, uh, because it would be harmful, you know, either to your constituents or your clients or, you know, to the. To the actual, um, you know, system. So there's always a fine line, but I always, I think in the bookends in my head, years ago, I was at an event with, um, this lovely woman from Lithuania who was in cyber, and she goes, I don't understand you guys. We can report in four hours. And I'm like, you can, like, walk across the country in a day. You know, like, it's. Yeah, I mean, I Love that you guys are that organized. Um, but also, you know, you get, like, Estonia, too, is another one actually, you know, still the corner case of, you know, when. When the Russians attacked Estonia, that they went fully digital with their government. And they're very, you know, they did it very cleanly. And we like to look at them as a model, but they can get a very fast reporting mechanism because they're. A lot of their legal constructs are, um, in alignment. We have so many legacy issues, as I'm sure you are aware of, with the legal work on one thing that came up with the advent of this challenge that we've seen around, um, the Department of Homeland Security on cyber security that the organization they call CISA M and the holding up of the, um, reauthorization of CISA is. I was talking to one of the lawyers and said, uh, for one of the companies said, does your company know that they're currently not covered why CISA is in this limbo state? You know, they've lost that liability protection. Uh, and she's like, no, no one's brought it up. That's fascinating.

Speaker A: That's incredible. Yeah. Um, so tell us a little bit about what you're doing now. What is the American Enterprise Institute, for those of us listeners who don't know what it is? And can you share a bit about what you do there?

Speaker C: Sure, absolutely. So, um, the American Enterprise Institute, or as most people like to call it, just aei, has two sides of the house. We have foreign and defense policy, which is, um, a lot of people know AI for. It's a real strong house. I spend time in the cybersecurity space, but I don't do the hardened elements of that. Uh, even though there's a lot of crossover, especially now on when we look at trade law and the fact that the Internet doesn't have borders. So, um, the foreign policy, and I spend a lot of time on that as well, but I'm actually on what is considered the economic, the econ side of the house. And so I, um, you know, I'm working on technology policy. I cover a vast area, which is fascinating. Um, most of the people, I kind of say I ride the top of the wave. I figure out enough to try to be helpful, where a lot of people I deal with are very, very deep on these individual topics. I'll give you a quick rundown. So we talked about cybersecur, security, tech and trade, artificial intelligence, which is, you know, eating the world right now. Uh, data protection, which we refer to often as privacy But I think of it as data protection. We can legislate, um, and regulate privacy as more of an emotion about how you feel about your information. Um, encryption is becoming very hot. We're having some challenges with, uh, Canada right now on encryption. Broadband, uh, deployment was much more of a conversation, um, under the Biden administration, where they were, you know, spent trying to spend a lot of money to see who needed a, you know, finish out that connection loop, which the. Where, you know, the Trump administration is finally getting that money out the door. And I think we've connected everybody. I think we've done a pretty. That's kind of a joke, but I think we've. We've gotten there and then, um, the whole network, uh, stack. So chips are getting. Chips and memory are, you know, getting the real, um, highlight right now. But I really follow kind of every element of the network stack and how that gets pulled together. So. And then all the, you know, all the elements of policy that go into those things.

Speaker A: When it comes to cybersecurity policy in particular, what are some of the misunderstandings that you're seeing now from organizations and stakeholders?

Speaker C: So going back to, uh, Mythos, the thing, I think is a net positive. There is a lot of this has been broken because of the way we layer onto legacy systems. And don't we kind of buy the new shiny thing. It's kind of like clothes in your closet, right? You buy the new shiny thing and it's in the front of the closet, and you wear it a lot. And every once in a while you have to dig the bed. You're like, I forgot about that. And that is so often the case with, um, you know, we think of as like, you know, you've got vendor debt, you've got all these different ways that your system gets into technical debt. And a lot of that is just. It gets. It doesn't get updates. Is the biggest problem is people stop updating it, but yet your system's still attached to it. And those are very easy fulcrum points for bad guys to come in and, you know, lay in wait. They might get in there. They'll wait a little bit so they're not too obvious, and then they slowly overtake your system. So the idea of Mythos being able to, you know, and other. I realize other companies have things that are just not getting so much attention. Uh, is that it really shine like a black light on a lot of these flaws. And now they. There's an obligation by these companies, especially under their contracts with their, um, clients in, um, in the, uh, both, not only in the consumer but in the enterprise space that they need to patch those, they need to fix those things. And they, um, some of them, some of them, it's like in the government, you know, we have certain departments that we have people that are like, they speak language but it's code because you know, nobody knows how to like update, you know, from a. To where we need to get to go. So that's, that's a lot of it is just trying to figure out, you know, um, you know, what it is that you have in front of us. You know, we're as. I'm a big Apple consumer so I'm, I'm very, and I'm very disciplined about my updates. Did one last night. Uh, you know, a lot of people just don't think about that and they don't understand why the technology is not doing what they want it to do to function. So um, it's a, we need to keep, you know, as consumers of it. It's good to stay a little sharp. But you also, if you have an IT department, they need to also have the budget to be able to do that. Because a lot of times that's the problem. And I think a lot of C suite attention on this issue in the last month will hopefully get people so they can get their whole system, you know, up and in shape.

Speaker B: So my, uh, my career has been a lot about trying to talk to your average everyday person about cybersecurity and why it's important to do X, Y or Z, why they need a good password or need to use multi factor and things that um, I'm curious from your perspective, what is the gap you see between how much people, everyday people think they're protected versus how exposed they actually are?

Speaker C: You know, I'm going to take it. Some of it's a little, and this is probably more on a personal level, I see it's generational. I'm now managing my mom's finances and uh, because a lot of her accounts are attached to her cell phone, I have put multi factor authentication on anything that's financially oriented. So I have to have her next to me with her phone and I bring my computer out and like to have lunch and I'm like, mom, let's do the bills, let's go through all this stuff. And then she'll walk away with her phone like, mom, I need your phone. She can't understand like, what does my phone have to do with this? And I'm like, yeah, uh, you know, like, so there's a whole era of people that are never going to come on, come online the way we'd like to about this. They just don't quite understand it. Right. And then there's others that just don't understand what's at risk. And this is, I don't know that we'll ever be able to change this paradigm but the idea of the um, you know, you give away so much information and you don't realize that it's valuable to someone because they're willing to steal it. They, they sell it to each other, you know with third party vendors and even the, you know, the initial first party um, intaker of the information and if we can ever change that dynamic so it has a better um, you know, even if it's a micro payment attached to it, I think people would pay much more attention to the kind of information that they flow into the system where it goes. And I'm one who, I actually read the terms of service and terms of use and you know there's, I've always said and I've talked to the app association who has no interest in doing this but I'm like, we need the apps to show up with like three emojis or whatever they are that tell me like right up front I sell to third parties. Like so I just know that I might be fine with that but I would want to know it before having to get to page 36. And then um, you know the other things about you know, what am I giving access to? There's so many times and a little bit got fixed when Apple did their update with um called it AT T. I can't remember it stood for a bit. You know, like now every time something asks for permission, it needs to ask permission because I put that in my settings for the camera, my contacts, my calendar. Uh, the reason why some of those are important just, just aren't natively to how people think about these. One of the big um, attack spectrums right now is calendar invites which it breaks my heart because I love getting a click through when I'm invited to something to just be able to drop that on my calendar. But apparently so do the criminals who realize that that's generally not you. Once you're at that level you've gotten a, you know, if you pre permissioned all this, you know, and then they can get in there, then they use that to you know, get into your network. So you know, it's, it's hard because it's also a moving target. So as I'm sure You know, like you're always trying to explain most important things. People are getting the scam calls. They're starting probably as I tell my mother, the bank, the bank is not calling you. They're not going to. How often does the bank call? Not often, Mom. So don't like hang up and tell them that you're going to call them back and then call me. That's what we end up doing.

Speaker B: Yeah. What is the biggest disconnect between this reality of what's happening for people, everyday people on the ground and uh, the world of cyber security policy?

Speaker C: I think, um, the fact that going to Jack's earlier question, there's so much at stake and it isn't uh, inherently obvious to people. So they don't, they bypass a lot of the native security elements. We're seeing this actually in um, the European Commission has um, just an open comment, uh, period right now. But uh, it's really focused on Android. But it involves anybody who has an operating system saying that you have to give permission, you have to give permission for anybody to have access to everything that's going on in the operating system. And when that happens you end up breaking those levels of trust that most consumers have learned about their phone. So they tend not to, they, they don't, they think it's pre permissioned so they, you know, they've done this before that they don't realize now that these apps are going to come in and you know, whatever it is that they've decided that they need to have, you know, access to, um, you know, that they, you know, the reason why I give my location is because I'm a big user of Google Maps or I want Uber to be able to it, but I don't necessarily want any person who happens to have an app that I download, have my, my location information. So you know, we've got to figure that out and it's, it's back. It's one of those challenges that tech has sort of created for itself because it's so user friendly and we're used to plug and play that we don't have to explain how things work. But now that they're breaking that trust cycle, we're going to have to go back and explain when you make these decisions to go out of the, we'll call it out of the, you know, the, the basic network of where you've normally gone to get these things. Be very cautious and thoughtful about what it is that you're putting on your phone and what they're going to do with it. An example is. And I kind of, I don't know, it kind of weirds me out. And I love the fact that Instagram knows this about me, but I am one of those people that goes to museums and I take a picture of the art and then I take a picture of the little tag next to it so I can remember the name of the painting. And, and there's an app for that. Instagram serves it up to me. And they're like, there's an app. When you go, you know, it'll just do this for you. And at first I'm like, oh, didn't realize I had a problem that I needed to solve there. But if I wanted to, problem solved. And then I'm like, what else does the app do? So I went and looked it up, and it's a little squishy on what happened because I'm like, a lot of these are just truly Trojan horses. You know, you put them on your phone and I mean, there's weather apps that do this. All they do is suck information off your phone and sell it to a third party. And people just. I showed my phone to a person of mine who's, um, just, she's like, here's five things you got to get off your phone right away. And it wasn't even for a cyber security thing. She was doing it from a m. Privacy perspective. So that, I think is the, the key. That's where, um, Jack, you asked earlier about, you know, the, the 50 laws. That's the one challenge I think we have where we really would be better off with a national privacy bill. Uh, it's, it's just tough because your phone, you know, I live in the, you know, I, I, I cross the border into Virginia or to Maryland. I do a lot of state hopping. And, you know, if my phone is going to have a very hard time changing the permissions every time I drive 15, you know, miles to all of a sudden have different things that it has to remember. And, um, a lot of times I just like, I like the settings that I want, I don't want to have to go through the permission of that every time. You know, I move around as well as we get into the challenges, especially with, or the European laws and the California laws have kind of dictated to the rest of the world how this is going to go. So kind of taking to heart the challenges that we have with consumers. Let's think about that. House Energy and Commerce Committee in Congress is working on a bill right now that I've made some comments on. And you know, the key thing is think that the privacy is very important, but the security part is as important because those two things have to go hand in glove.

Speaker A: Can we talk to just pivot to government cybersecurity readiness too? Because that's something that Cyber Florida follows, um, a fair amount. I mean, if a major cyber attack hit some critical infrastructure tomorrow. Right. Do you think that governments are ready to respond to it? What do you see about government readiness at this point?

Speaker C: Point, no. And, uh, it has to be almost kind of like, I'm going to take choose. You guys are in Florida, so I'm sure you do a lot of, you know, like hurricane drills or. I'm from the Midwest, so we did tornado, uh, drills. Right. You. And I am, um, you know, I can, I know what it feels like when a tornado is coming on. Like, I, you just, it gets really calm. Um, the color of the sky changes you. And if you don't see these things coming forward, you don't know how to immediately protect yourself in a situation. And it's very similar to that. A lot of people don't know that they've been breached. They don't have the, the, even the moat created to make sure that their systems are not in play. And then they don't know what to do about it. And that, that's both from a business and as a, um, as an individual user, you know, something happens, you don't know who to talk to. Do I, do I call the police? Do I call the FBI? Do you know, like, who, who am I supposed to engage on this? So having a plan, especially for, uh, corporations and having that plan well known, even if it's a, the best thing you do is don't do anything yourself, but contact the IT department as soon as possible and contain where you think the problem is so it doesn't spread quickly. And for consumers, there's kind of learning those key points as well. I know October, um, Cybersecurity Awareness Month, so I write about it a lot then. Not that most people know that they're supposed to celebrate that in October. Uh, but it's an idea to remind. Put all those reminders back out there, like things that people just need to be cognizant of. And right now it's more text messaging driven, um, than it is email still harbors the most malware. Um, but, you know, now text messaging is kind of causing that same problem because everybody's on their mobile device.

Speaker B: How, um, how do the US and the EU approaches to tech policy differ in, In Ways that matter.

Speaker C: That's a really good question. Um, we are an innovation society so we believe in allowing people to go forward. Their major measurement is, is if you do something that seems to make sense, somebody will fund you. And so we have kind of that um, that market value driven that is in the way that our tech works. And, and that's actually why we're doing so well in United States versus other countries will set China aside because they get kind of self funded by the government. But the idea is if it makes sense we'll, and you know a lot of these venture capitalists know that, you know, eight out of 10 may fail but the two that they do are going to do very well. And our system is designed for that. There was a report that came out, I think it's probably four or five years now ago called the Draghi Report that he, this gentleman, um, in Europe really pointed this out and he said we need to change our banking system. Which seems odd when you're like what's the problem with tech? And the problem tech for Europe is the banking system. They don't have that same innovative cycle in the way that they finance things. And so it's very hard to get funding. So that's why you see a lot of these company uh, founders either moving to the United States or selling to larger companies in the United States. So that's part one, the second part, besides the lack of um, funding opportunities they believe in, uh, you need to, it's a nanny state. They like you to ask permission before you move forward with things. And I mean a long time ago when we were working on RFID tagging, I was in a meeting in Brussels and they were explaining to me that this wood table that was, we were meeting around because it had an RFID tag on it, it would be considered um, RFID hazardous waste. And I was like, it's a wood table. I mean it's, why wouldn't you recycle this wood table? And they're like, because it has this, this electronic thing out here on the corner now, you know, deems for it to be. And so I always take that as kind of a visual in my head because now it's a virtual version of that where they're saying you have to, you know, you have to do all these permissive things ahead of time and you have to discuss it with us, you know, either with the, the nation state or the European Commission or the, you know, a member of the European Union before you move forward. And I'm like that's A lot of regulatory hurdles. Uh, I might go do something else. I mean, first of all, I can't get the funding. And then you're gonna tell, you're gonna mother, may I into how I have to manage all these things. And they, for American companies and their way of discipline is funding. That's why you see these astronomical, uh, fines that they're doing for what they call the, you know, Magnificent Seven is. That's the only way that they are getting attention. Because these, these smaller finds, they were like, these are a nuisance, but it's a risk that we take in being in business. And now they're like, whoa, these numbers are huge and we didn't do anything wrong. Well, all we did was service your clientele in Europe. And now you don't like that because you don't have companies that do the same thing, which goes back to the banking problem, right? So it's this. There's a full cycle that needs to be fixed in Europe. And it isn't that they're not smart enough to have great tech. They need to get their own barriers out of the way so they can compete against us or any other place that they wish to compete against.

Speaker B: Do you feel the US is leading on tech policy or reacting at this point?

Speaker C: Um, depending on where you're looking at the stack, I'd say a little both. We're still very much leading in, um, you know, an artificial intelligence, I guess, would be like. The best way to, you know, look at it is we look at what happened with the Chinese and, you know, they. There's the whole idea that Deep Seq came to the market with very little capital investment. And that was a false narrative because the company that started it actually had built their own network operation and server, um, system for their. They, uh, basically had a version of a venture capital fund. And then they built Deep Seek on the back of that. So they, they just discounted the almost billion dollars worth of compute they had beforehand. They just didn't put that on the ledger. And then they said, oh, look, we did this for just a couple million dollars. And you're like, well, not really. You know, you had, you had to buy the CPUs, the GPUs, you know, the data centers. You had to use energy. All that was not in the equation. But what they did was their distillation model where they, you know, they also just sort of grabbed, you know, a lot of smart technology that was going on at the time. And we've seen a lot of stories in the last couple Months where there's one of them. It doesn't matter. I think it was Quinn. But, um, they were. They, um, they asked, if you ask it, it thinks it's Claude, because it is trained on so much Claude material that if it's like, oh, no, no, no, no, I'm Claude. And you're like, you're not Claude. You're a, you know, you're, um, a dupe. And just to put it in a girl parlance when it comes to those things. So, um, it's an interesting situation because, you know, again with that idea of we're investment forward, we're innovation forward, but we're competing with the Chinese in an environment where, you know, the, the government picks winners and they, uh, choose. They tell people how they want that money invested. And you know, there's. Their whole system is different than ours, but they definitely pick a horse and they, they give it money to run. Right? And we saw that back in the network operation days of, um, with Huawei. And now we have this challenge where we kind of gave the Chinese a lot of things that we just didn't want to do. We were happy to do the innovation cycle, but, um, you know, when we look at chips that' TSMC in, um, Taiwan is still the number one chip manufacturers. They chose to become experts in this, and they are amazing at what they do. And we can do some of that in the United States, but not at the level of expertise that we see going on in Taiwan. Um, Chinese are doing very well, but they, but they can. Basically what they do is they brute force. They don't necessarily have a small size, but they can put multiple items together like chips or whatever, you know, memory elements that allow them to have the same compute power. And it. Sometimes the reason why we wouldn't do something like that in the United States is it becomes very, um, energy power hungry. And they just don't have those same barriers to entry than we do. So we're not really working in. I hate the phrase level playing field. I feel like people only say that when they're losing. But, you know, they um, is like, we're not starting at same same. Right. You know, we have all these different variables and levers that, that put us in possibly a disadvantage. If you want to look at that. It's like a foot race. But the Americans are really the ones that are coming up with these amazing, innovative elements. But the other thing we've seen, um, is that China has done it as they do. They emulate a lot of things. They came over Here and really studied our education system as to why so many people in China wanted, they didn't have these things coming out of their, you know, their decades of communism and they've now emulated the Ivy League in a lot of places. And so, you know, there's very prominent places to go to school in China now. So while we're setting up these barriers to entry to bring in this very high level talent that used to come here to the United States, now they're happy to stay in China, in a lot of cases they have is an education system that is just as strong in the areas that they're interested in. So we have to add that to the equation.

Speaker A: Sticking with AI a bit. You've written about AI features shifting from AI features to AI coordination. Can you tell us a little bit about what that means?

Speaker C: Yeah, the um, moving from just the fascinating with the romance with the learning language bottles, which I think, you know, I'm probably still stuck in that phase, you know, I'm just having so much fun with it, uh, into the agentic and having the bots that can all connect with each other. You're definitely, um. From a cyber security perspective, we need to think about where we're putting the layers of permission and the number thing that gets people's attention is do you know, you give it a version of a credit card. How much credit are you? Uh, not in token credit but in. If you say plan a trip to Germany and are you going to let this agentic agent have a $10,000 limit or a zero limit or. There's lots of things that come into play there that we don't have the mechanisms, which part of that is, is, is regulation. Because now you're asking the financial uh, you know, institutions to come to the table about how we're going to manage these. Good news is that has gotten the attention of the J.P. morgan chase, the different, you know, cap ones, they're all very interested in this and would like to see that we can use the current financial system to partner with the agentic AI, um, agents. But then there's a whole another world that says like banking's old school and we need to work around that. So it's a really interesting area to watch. The other thing is again that like the um, the permissions that we talked about, you know, it's, you know, I've set up like, I'll set up something on my system and then I'll let it run in the background and then some. Sometimes I'm like, what, wait, what's going on. Oh yeah, that's right, I forgot I said yes to that. So, um, you know, as we want it to like be our own personal assistance and do all this work or you know, create these task bots inside, you know, organizations, there's a lot of upside to that, but you needs to go in with a risk analysis of, you know, when and where should you be able to safety wall something off or not give everybody that's their permission to do things. Um, long standing, you know, thing in, in cyber is the people that tend to do the most damage are the ones that are leaving. And so you have to be very careful about as people walk out the door that you cap and off their, you know, their permissions on systems because a lot of times they just don't turn them off. Right.

Speaker A: And how many agents did they have running? Right, if it's a, if it's a big, if it's a big consulting firm or something and it's one person and they have four agents working for them and they leave and no one turns off the, the, the agentic identities, they're still running.

Speaker C: Yeah. And that, that goes back to what I was talking about with the, you know, vendor debt and the technical debt is you have, you know, exactly that and you're like, and then the next guy comes in and they don't leave the recipe on what they did. And so they either decide to like trash all of that and so that's just that sunk cost out the door or you don't, you're not able to like layer into it. So there's, there's lots of things that need to be thought through at the IT level. Again, it's that plug and play that makes it seem so easy and seamless. But you have to think about both the risk and the cost on that.

Speaker A: All right. As we look forward to the next 10 years or so, what's, what's one thing you think policymakers really have to get right?

Speaker C: I think we need to be cautious but not step in the way of progress with artificial intelligence. I think we are really at a change agent moment. I think what it allows us to do is think at a whole another level on multiple things. And I, I think we're just scratching the surface because humans like everything to be about themselves. It's just our nature. So everything that you want out of AI right now is much, you know, 360 focus on you or your family or you know, what can you do? The, the idea of how we bring this on societally to like, just a lot of things that can be automated that may feel at the beginning. I mean, the calculator is always the easiest example, right? Like, everybody's like, no, you can't just type this in. My kid won't know how to do math. And now we think nothing of the fact that, you know, you can do all this. Um, um, you know, you get in your spreadsheet and you do a lot of math things, and the spreadsheet is, is, you know, I mean, the problem would be if stress rate's wrong, you know, then you would stop, you know, trusting it. But we are, we haven't gotten to that level with AI where we have a trust like we do with the calculator. And we're like, it's just, it's going to always give us the right answer. And, um, but it's also good to know, you know, the how, how you get from A to B. And so, uh, we also have to do, especially, you know, looking at students in education, making sure that it, it's not that you just want the answer, you want to know why you're asking the question. So there's, there's a lot of layers on that one. And, and I'm seeing, going back to the question about 10 years, very cautious. Understand, uh, parents are concerned about this and that their kids are being educated and learning, but what they're doing is they're cabining off the resources of bringing more compute into the classroom. And I think that needs to be thought about in a different way. I mean, that what it's doing is these kids are going to show up on the job market not having the skill sets that they need to be, you know, in a place where they can really exceed succeed?

Speaker A: Yeah. Well, we're going to take a short break now. When we return, Shane will go through our lifestyle polygraph. Stay with us. You're listening to the no Password Required podcast.

Speaker C: We cover cyber security and a lot of other stuff.

Speaker A: Foreign.

Speaker B: Welcome back. As many of you know, the lifestyle polygraph is a test used by the federal government to determine if a person is worthy of learning some of our nation's most important secrets. Here we use this technique for slightly lower stakes to determine whether our guests can join our fantasy cybersecurity squad. Shane, are you ready for the lifestyle polygon graph?

Speaker C: I'm willing to participate. I don't know if I'm ready.

Speaker B: Good answer. All right, first question. Have you ever pulled an all nighter just for a project you were excited about? Not because it was required.

Speaker C: It's been a long time since I've done that, but I can remember the time I did it and it was in college.

Speaker A: Some people, I've heard some people who like when they move into a new apartment or a new house or something, they stay up until all the boxes are unpacked and all the art is on the walls. And I've never done that. I mean I've lived in my current house for 13 years and I think I still have boxes packed. Are you an unpack the boxes person, Shane?

Speaker C: Well, if you have boxes you haven't unpacked, you should probably just throw them away, not look at them. Um, I do eventually unpack them all but I don't always do it in that. I don't in that. Yeah, I know the people you're talking about and I'm not one of those them. But uh, yes, eventually everything should get in its place and out of the box.

Speaker A: I admire that. Are you inbox zero on your. On your email inbox kind of similar thing or do you let it accumulate?

Speaker C: I. I have. Well, it's on my phone. Um, I pretty much have 20,000 emails is normal for me. And um, I have. I have eight different email accounts for different reasons. And there's one that I try to get it down because it's like there'll be things hidden in there that I have to find.

Speaker A: Okay.

Speaker C: Um, but they're all on different operating systems which was very frustrating.

Speaker A: That's something I would like to try. I have not tried the agentic um, like an outlook agentic to go through my. My current 8400 emails and say hey what. Which of these should I probably have responded to? I would like to try that slightly

Speaker C: different thing but on the same idea is with um. I love my Gmail account because you can now like I was just. I did a trip and I said go through and create an itinerary and because I use Gmail for all those things, I only had to change like one word. It had my entire itinerary. It all of my record locator numbers just all from the Gmail account. I can't say I can do that on some of the others.

Speaker A: Yeah, it plays nicely. That's exactly right. Yeah. And I think like that that has been one area where in my personal I've been. I have been playing around with the different kinds of AI is trip planning. It's so far so good because it's just doing the thing that I would have done like looking through TripAdvisor reviews for restaurants and Finding out what time museums open up. I know the path it's taking and it's the same path I would take. So I'm okay with trusting it for some of that stuff. But I've been harder on more nebulous work tasks to trust the AI agent because I don't know the path it would be taking.

Speaker C: I was just out at the Google I owed Google Developers Conference and the thing that's coming out is something called Spark and it's going to be a tiered thing. So it's a hundred dollars a month for a while and everything. It'll migrate down eventually Espeons will be able to use it. But it's. It is wanting to keep you inside the Google ecosystem, which I'm fine with. I uh, you know, opt in. But they. It's really going voice to the, you know, the, the Google system. So all these examples on stage were plan my weekend. Um, you know, they have, uh, somebody was having a block party. So, you know, here's the five things I need to get done. Make sure I give a list, blah, blah, blah, blah. And they all had these very. But it was basically, it was a lot of offloading life and it was. I've been fortunate to be at the Google I o several times. This is the first time where I felt like, okay, all these executives like got a hold of these toys inside the lab and they're like, I can really use that and now can it order me a bouncy house and I need a rental car. I'm like, it's. That's real life. Like those are things that we do need to get done. And if they can get done more efficient, we can do other things that we like to do or, you know, better. So no. But to answer yourself, I can't get to a zero box.

Speaker B: I can't.

Speaker C: I'd love to.

Speaker B: Okay, question number two. When someone tells a bad joke in a meeting, do you fake a laugh or just stare at them?

Speaker C: I probably fake a laugh.

Speaker A: Yeah.

Speaker C: Just to be polite. I'm from the Midwest. Yeah.

Speaker A: There are definitely times when, Right. It's, it's. I don't. It's not an offensive joke where I'm trying to like, like what is it? Like make a point or stand up for a principal. It's just I want this interaction to end and the easiest way for it to end is for me to give a. Uh.

Speaker C: You're especially a lot of, you know, being. We're probably both around a lot of people that are very smart and sensitive that's a great conversation about something that other than you're like, okay, I'll just politely laugh at your joke and then can we move on?

Speaker A: That's right. Or there's someone who's beginning, like someone got coaching that they need to begin a conversation with a joke. And they're. For them, it's just. They're just trying. They're moving on and then they go

Speaker C: have any inherent human skills to know how to even launch that. That's. Yeah.

Speaker A: My, um. So my kids gave me, because I think they know the humor I have, they gave me for Father's Day last year, these cards that are dad jokes.

Speaker C: Okay.

Speaker A: And so I have been using them. One of them, this is the one that popped up. This is, is. People keep telling me I'm addicted to brake fluid. People keep telling me I'm addicted to brake fluid. But I can stop anytime I want. Right. Like that's bad. That's a good example of the social laugh you guys both gave me there.

Speaker C: I want to know if it's like cards of humanity. Are you like adding to the deck now?

Speaker A: If I have a good one, I write well. I would tell that joke slightly different there here. So I could tell it as a one liner.

Speaker C: But it was cards against humanity. Yeah.

Speaker A: Oh my gosh. Yeah. No good. Exactly.

Speaker B: Okay, third question. Do you ever talk to yourself when planning or problem solving? And if yes, is it serious self talk or more like a running commentary?

Speaker C: I have a running commentary in my head at all times. I mean, it just doesn't stop. The one thing I always tell m myself, I don't really want to write an entire show, but I could do treatments if I could just watch a scenario unroll in front of me. And um, then I keep going my head like, here's. Here's six ways you could make that really funny if you did a version of this. Yes. The voice in my head is very busy.

Speaker A: Have you ever thought about fiction writing, Shane? Have you ever done any fiction writing? Or. I mean, you've seen so many things, you could probably inform a whole lot of stuff.

Speaker C: So, um, in a very baby version of this, two things have collided in my world. I'm very lucky that Google has put me on a team to, uh, test some of their AI tools. And there's certain things I am not great at. I'm not an overly creative person. And it's. The Google Omni, which just came out is basically voice to visual, uh, so you can ask it to do things. And so they've asked me to Test it. Actually, I've got a thing with the tester team tomorrow. And the first, the first time I did, they asked me if I could just ask really bad things and try to break it. And I was not mean enough to try to break the AI and then this one. So I, I say it's two things because I got that opportunity to do this because I have permission into the system. But I, um. A lot of times on my social media, I put that in. It's used to be hashtag no. I just say, um, Shane on a plane. And it's because I do get the fortune. I love to travel and I do get to travel a lot for work, but I don't always tell people where I'm going. But people. It just is a, it's a conversation starter. Like it came the event I was at last night, somebody said, oh, you're not on a plane. And then I know that I'm a social media. They're also on my social media feed, which isn't. I'm very permissive. So a lot of people. My social media feed. So I've taken the Shane on the plane. A friend of mine said, you know, I have a lot of nieces and nephews that I have to read books to and why don't you just write when you go, like, just do top five things when you're in Berlin or Tokyo or. I just. Actually, I just. The one I'm working on using the Google Omni is Shane on a train and doing the Cradle of Liberty tour, uh, starting in, uh, Boston and then going all the way down to Williamsburg. And what's been interesting about that is just creating the, you know, the concept and what I, what I as an adult would like to read to my nieces and nephews because we both learn. Um, and then doing the Omni part of it is it's interesting to see what it retains and what it can change and what it holds. But the name Shane, most people, people think I'm a boy, so it immediately makes me a boy. And then I talk to it and we make it into something else and then. And then what it's willing to kind of move through or not. So it's been a fun, you know, multitasking way of me to learn more about AI but also do my thing of not fiction, but children's books if I ever get there.

Speaker A: Creativity getting an outlet out.

Speaker B: Yeah, I love that so much. Uh, sort of. Related question number four. Is there a type of music show or movie that you secretly love but people Might not expect.

Speaker C: So I got to Breaking Bad really late and loved it. And you wouldn't necessarily know that for my personality. Um, I'm just finishing Peaky Blinders, which I know I'm late on that one, but my sister keeps talking about it and there's like one left in this season and I just don't want to watch it because I don't want it to be over.

Speaker A: Oh, I know that feeling. I know that feeling.

Speaker C: But I know they have another season coming. I actually, I watch the bear because every. So a lot of things I won't even know about until they win an Emmy m or a Golden Globe. And I'm like, okay. The bear is so. I don't know if you, if you've watched it, it's. It makes you anxious. There's so much stuff going on and the arc on the characters are really interesting. So they get to the very end and you don't know at the end of this that they did announce another season. But the last thing is it could be a play. It is so well done. It is three in the very moment, last moment. There's four characters that are in the back of this restaurant. And, um, this guy Richie plays a full arc and he brings up Singularity, which there's no way at the beginning Richie would have known anything about Singularity. But I went back and watched the whole thing again because now that you know what happens, you can watch it without that angst of it all is gonna go crashing down. And it's really good. Like it's, it's just a fantastic show. So, um, you know, those are. And I know I could spend that same amount of time watching a movie, but somehow I just get sucked into that Netflix vortex and you just.

Speaker A: Some of these things are so good and the care that's put into them is better than a lot of movies that, that are out there now. Right. Some of these hour long dramas now, particularly on some of the streaming services are, are the investment level in them too. And the work product is so good.

Speaker C: Yeah. And you know, it's nice. Like when Apple came in, they do everything. It's a quality product and so they've upped the game and you know, so there's a lot of things that were just, you know, some of the streaming services are just buying old series, but I get it. There's, you know, it's super low, um, capital investment for them and high return. But the, um, shrinking, drinking the apple, which is, which I didn't know was going to end and it was nice. They kind of tied everything into a bow. But it was a really nice end of the day. Like, it was happy. Like, it was, you know, you. You started to really like some of these characters that were quirky. So it's. Yeah, that's fun.

Speaker A: Oh, it's great.

Speaker B: Okay, final question. If you were on a reality or game show, which one do you think you'd totally dominate?

Speaker C: I'm totally gonna to dodge on this question because I don't watch reality TV at all right away. Like, I've. Queer Eye for the Straight Guy. Liked it first season, didn't care about the sex season. Uh, Rent the Runway one with, uh, Heidi Klum. One season. I couldn't. Second season, couldn't care. Uh, cooking shows. I really. Why these people want to be yelled at by a chef. I don't get it.

Speaker A: Take a beautiful thing and ruin it. I don't. Cookie shows. I've never done it.

Speaker C: I don't watch them. As a kid, I did watch, um, more, uh, game shows. My sister really wanted to go on Family Feud. I really. And she got us through the first level. Like, we did the interview, and then they didn't pick my family, but we were like, none of us wanted to do it except for she. It was like, okay, we'll do the interviews.

Speaker A: My. My father was on the $64,000 pyramid or whatever it was the. But early on, that was what it was. And. And I think he. He won enough. He was a grad student at the time, and I think he won enough on the show to. To, like, pay the. The co. Pay for my. My older sister's birth, I think. And he got a year supply, I think, of Shasta Cola. That was it.

Speaker C: That's our only generous family man, because I probably would have bought a car at that age.

Speaker A: That's true. Whatever he does, whatever it was. So I'll get that details when I seeing him in a week or two. I'll get the details again. But I've never gotten. Never gotten far enough on something like that. I'm. I'm similar to you. Shame. But I'll watch when there's a new hook on a reality show. I might watch the first couple episodes. But once you see the hook, I don't understand coming back for season two, I think the hook's kind of cool, but, uh, I can actually come up

Speaker C: with better things in that head that's talking to me all the time. I'm like, let me rewrite the end of this. Yes, exactly.

Speaker B: All right, Jack, what do you Think. Does Shane have what it takes to join our fantasy cybersecurity squad?

Speaker A: She does. And Shane, I don't believe we have uh, any fellows, any policy fellows on our cybersecurity squad at this time. So you will have the entire landscape. Landscape, wow. Fantasy cyber squad to play with as you need. You can set policy. Our policy recommendations for our fantasy cyber.

Speaker C: Do you say that wisely? Next thing you know you're gonna be like, what's this outline? Wait a minute, hang on to me.

Speaker A: Well, thank you so much for joining us today on the podcast. If our listeners want to connect with you out there, see more about what you're doing, how can they, how can they find you and how can they do that?

Speaker C: So um, AEI.org is our think tanks website and we have a section on technology policy every day. It's not always me. I have about 10 other scholars that I work with that are fantastic in what they do. Um, we also have techpolicydaily.com a sub um, area in that and then I'm at, you know, shane.twosi.org it's one of those emails I can never get down to zero. So go ahead and add yourself into there and see what I have to, what we can talk about.

Speaker A: Throw it into the mix. I like it.

Speaker C: So at shane twos on DX and um, and I love a good LinkedIn channel check if somebody ever wants to link in. Happy to do that.

Speaker A: Excellent. Well that brings us to the end of our show. Thank you so much everyone for listening. For the entire no Password Required team, I'm Jack Clappy and we'll talk again soon. Thanks for listening to the no Password

Speaker C: Required podcast presented by Threat Locker. No Password Required is produced by Cyber

Speaker A: Florida and a special shout out goes

Speaker C: to our friends at Carlton Fields and Reality they shift. For more content, follow us on social media at no Password Pod and visit our website@cyberflorida.org pod.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Eat your security vegetablesAdventures in DevOps · on Technical debt88 / 100
  • Applying Agentic AI to the Supply Chain, Building Systems to Withstand Chaos, and Leveraging your Curiosity w/ Pooja Brown @ Inventry.aiEngineering Founders · on Legacy systems87 / 100
  • Mo (Mohammed) Saadat from StratahubEnergytech Startups · on Legacy systems86 / 100
  • Tax Time 2026: How ATO protects your financial dataWith Interest · on Multi-Factor Authentication85 / 100
  • Episode 106: [Value Boost] When AI Isn't the AnswerValue Driven Data Science · on Technical debt85 / 100
  • Salesforce Team Risk: The Leadership Gap That Breaks OrganizationsThe Hiring Edge · on Technical debt81 / 100

More from No Password Required

All episodes →
  • No Password Required Podcast Episode 73 - Mudita Khurana
  • No Password Required Podcast Episode 72 - Madeline Sedgwick
  • No Password Required: Next Gen - Ep. 2 - Tim Kircher
  • No Password Required Breakout Room with Fagan Afandiyev
  • No Password Required Podcast Episode 71 - Cynthia Wrye
Explore the best B2B Engineering & DevTools podcasts →
All No Password Required episodes →