
Pwned: The Information Security Podcast · 2024-04-03 · 37 min
Key moments - from our scoring
Substance score
28 / 100
Five dimensions, 20 points each
This milestone episode takes a retrospective approach to celebrating 200 episodes of the Pwned podcast by revisiting key quotes and predictions from past episodes. Recorded at Mad River Distillers in Burlington, Vermont, hosts Justin and Jack pull quotes from their archives - including discussions of IoT breaches (hot tub manufacturer attacks), open source supply chain vulnerabilities exacerbated by generative AI code generation, venture capital overvaluation cycles, and the challenges of distinguishing genuine cybersecurity products from marketing hype (TUD - Technical Uncertainty and Doubt). The conversation reveals that many of their earlier observations remain prescient: water system infrastructure attacks by nation-states have materialized, the oversupply of inexperienced venture investors in cybersecurity continues to plague startups, and AI-generated code compounds security risks when deployed by developers without security expertise. They emphasize the divergence between well-funded companies with experienced investors versus those struggling in the current market, and discuss how marketing obfuscation in cybersecurity has only worsened with AI-driven messaging. The episode serves as a sober assessment of both accurate predictions and ongoing industry challenges rather than a celebration, offering value to startup founders and cybersecurity operators navigating investor relations and product differentiation.
Attacks against Aliquippa in Pennsylvania and other water management systems have shown evidence of organized nation-state and nation-state-backed group targeting of water infrastructure vulnerabilities, with discussions ongoing about more coordinated attempts to identify weaknesses in connected water systems.
Developers without security expertise use tools like ChatGPT to generate code, but cannot properly validate security; Stanford research cited on the episode shows 54% error rates when AI makes cybersecurity-related decisions, creating vulnerabilities built in by well-intentioned but unqualified developers.
Inexperienced investors often invest based on market signals rather than technical understanding, leaving them unable to understand why companies struggle when downturns occur, making them unlikely to reinvest and creating disparities between funded and unfunded startups.
TUD is the hosts' term for marketing obfuscation and complexity in cybersecurity product messaging that makes it difficult for buyers to distinguish genuine capabilities from hype, a problem they identified in earlier episodes that has worsened with AI-driven marketing language.
The EPA has allocated approximately $10 million in funding for water system cybersecurity improvements, which the hosts argue is inadequate given the scale of tens of thousands of water utilities that need security upgrades.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is a celebration/retrospective where the majority of the runtime is spent on whiskey discussion, toasts, and guessing who said old quotes. Substantive cyber observations (IoT risk, supply-chain, bad investors) surface occasionally but are thin and underdeveloped, never sustained for more than a few exchanges before dissolving into agreement and filler.
Cheers. Delicious.
It is still excellent.
A couple of mildly contrarian positions emerge - TAM overinflation and product manufacturers being a root cause of the industry's problems - but they are asserted rather than argued, and the broader framing (band-aids over root causes, IoT attack surface expanding) is well-worn cybersecurity commentary.
the total addressable market for cyber is overinflated
we're spending the money in almost all the wrong ways
There are no external guests whatsoever - this is a host-only retrospective episode. The two hosts present as practitioners with founding experience, but their credentials are barely substantiated in the transcript itself, and the absence of any outside voice severely limits the ceiling here.
I founded a couple of companies, but this was the first company and I was going off for my first round
I've been doing this for a long time, over 20 years
A handful of named specifics appear - the Aliquippa water system attack, a Stanford stat on ChatGPT cybersecurity decisions, SolarWinds' post-incident self-assessment, Glenn Bressner/Mid Atlantic Capital, and the $10M EPA water utility figure - but most discussion is anecdotal and abstract, with no dollar figures, timelines, or outcome data attached to most claims.
We saw, um, an attack against Aliquippa in Pennsylvania
54% of the time when it made a decision in that kind of sitch around cybersecurity, it made the wrong one and created something that was vulnerable
With no guest present, the hosts spend the episode largely agreeing with each other and pulling quotes from a cup; there is no follow-up pressure, no productive disagreement, and no challenging of any claim. The format is a pleasant but uncritical mutual affirmation session.
Yeah. Yeah.
That's definitely you.
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of Pwned, Justin and Jack celebrate their milestone 200th episodes the best way they can…with some good old Ransomware Rye. Join the duo offsite at Mad River Distillers tasting room in Burlington, Vermont, as they review podcast excerpts from the last few years and respond with fresh takes, all while guessing who actually said it. Check out the links below on people we reference in this episode: Glen Bressner, Co-Founder and Managing Partner, Activate VP Chris Metinko, Senior Reporter, Crunchbase News Key moments: 00:00 - Title Sequence 00:20 - Introduction 05:30 - Café Press and Hot, Stinky Soup 10:17 - Punxsutawney Programmer 15:05 - Sometimes You Should Argue the Price of Champagne 21:36 - Parsing Through Cybersecurity Product TUD 26:30 - Meat Market March 31:13 - Beyond the Badness-Ometer 34:57 - Wrap Up If you have any questions or suggestions, send us an email at pwned@nuharborsecurity.com . For general information, you can reach us at info@nuharborsecurity.com . If you like our content, please like, share, and subscribe! We’ll catch you on the next one.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Okay, so we're kicking off episode 200. We are at the Mad River Distillers location in Burlington, Vermont. Happy Mimi and Jesse hosted us here. Um, and, uh, Jack, what are we doing today?
Speaker B: Well, first off, I mean, number one, for those of you who aren't familiar with all of the episodes, all 199 of them existed before this one. Um, you may not know that we actually did episodes from the Mad River Rick house and talking with John Egan about all matters venture and cybersecurity related, as well as really tasty bourbon and rye related. Um, and this has been an ongoing part of the mystique peak of poem. Um, and I want to make sure that before we get into talking about cyber security and, um, we're going to do a little bit, uh, of McDubswell is going to be a little voice of God. We're going to go back through some key quotes over the last few months. We get a little cup full of quotes, which is pretty great. Um, but I want to take like two minutes credit where credit is due to talk a little bit about ransomware Ride a Justin Timlade special here with the Mad River Distillers, um, because it's pretty damn tasty and it may be part of the show today as well. So let's talk just a little bit about ransomware rye.
Speaker A: Yeah. Um, yeah, so initially it was kind of like a passing comment on the show, right? Um, I said, wouldn't it be fun if this existed? Um, and now dreams become a reality here. And, um, we have ransomware rye. Um, and thanks to Mimi for helping hand select a delicious barrel. Um, it's now it's receiving some pretty awesome reviews from all us custodians today, in fact.
Speaker B: And for those of you who are not perhaps in the New harbor community yet, this is something that, you know, friends and family of, uh, the company have gotten to enjoy. This is not something that's generally available. Um, everything from the artwork on the label, to work with Mimi on the mixture, et cetera, um, are all in the Viking's head here. So if, uh, you're at all interested, you know, contact your local New Harbourite, uh, and find out if you can get a swig because it's worth drinking. And I think we may drink some of it today.
Speaker A: Yeah. And I would just to add on, um, rinse Moore Rye has been great. Um, but Mad river also makes some also some other interesting things that is equally delicious. And so they actually sell their stuff online and it's a little bit more Easily accessible.
Speaker B: Um, all right, so back to the nature of the show. So it's been, uh, I've only been along for the last. I don't know how many episodes, uh, Justin had started off the podcast, uh, long before I arrived. Um, but over the last three years, uh, we've had a blast, uh, doing a pile of these episodes. Um, and what we'd like to do is sort of take a look back, right? Uh, take an objective lens to some of the nonsense that we've said over the last 200 episodes and, uh, see if any of these things still relate. Were we right? Were we wrong? You know, we like to take a lot of credit for Nostradamusing, you know, some of the behaviors that we've seen, from investment to technology adoption to some collisions inside the marketplace. But I don't even know what's in the cup. Right? So McDubs has been responsible for creating something. I don't think Justin knows either. No. So. So you're going to find out as we find out what's, uh, in here and how all these things play out.
Speaker A: Yeah. Um, so 200 episodes is no joke. We've been doing this for a while. Uh, Nostradamus is also no joke. He's gotten a lot of things right, and I'm sure some things wrong as well over the years. Um, but we kind of joke, right? Not joke, but we make light of the fact that, like, we've said some stuff over the years that have actually strangely come true. So, um, so I'm hoping that there's some of those in this cup, Right.
Speaker B: That it isn't just a complete castigation of our inability to see what's coming down the road. Yeah. Right on. Yeah. Okay, cool.
Speaker A: Um, would you like to do the honors?
Speaker B: Oh, do I get to pick the first one?
Speaker A: Yeah. Yeah.
Speaker B: Oh, that's awesome.
Speaker A: We should, uh.
Speaker B: Oh, you know, I think this is a good idea. Right? We should christen. The glasses are, by the way, Mimi, beautiful Mad river glasses. Thank you very much. These things are kicking. Um, we'll have these because I'm sure that at some point during some of these quotes, there are going to be things we shouldn't be saying concerning words that may exist in the pit of despair.
Speaker A: Yeah.
Speaker B: I'd, uh, like to toast my compatriot and fellow jabberer here, uh, for bringing me along for this beautiful ride. Yeah. My first putt. And to McDub's M. McDubs for making it all happen. Makes our jobs very easy.
Speaker A: And.
Speaker B: And we'd like to toast all of you out there who've made this kind of a blast. Because if it's just us talking, then that's Wednesday. Right. But if we're talking and you're listening, that actually makes us feel like it has some value. So here's to everybody involved.
Speaker A: Cheers. Delicious.
Speaker B: It is still excellent.
Speaker A: Yeah, yeah.
Speaker B: Wow, wow, wow, you Mad river people. We got something going on here. All right, so I'm going to go into the cup of greatness.
Speaker A: Yep.
Speaker B: McDub's.
Speaker A: This feels like a fortune cookie exercise to me.
Speaker B: It does, it does. All right. I didn't even know it's. I didn't know it's written on the sheet of paper, so here we go. Oh, wow. Your winning lottery number is. No, no, that's not what it says. All right, so this was a breach of the week. Uh, cafe Press, Hot and Stinky Soup. Um, I think Halls is going to be able to play the real quote, uh, from the original episode, but I think in general, uh, this was about an attack that happened in one of the quotes related to it being, um, a mess that was like Hot and Stinky soup.
Speaker A: So do you. Do you have that quote there? The actual full quote?
Speaker B: It's a quote from us. It says. And I thought that this was a pretty good piece to touch on, um, and some of the mistakes they had made. And I think they're largely made because of the fact that people didn't expect anyone to ever be attacking their hot tubs. Anyone to ever attack their hot tubs. Do you remember this? This. So there were two. I believe there were two, um, breaches that we talked about on this episode. Right. But one of them was the hardware software combo associated with a hot tub manufacturer. And so the people take care of it. And I think it was, uh, our. One of our earlier inroads into the Iot slash breachability of PLC kind of marketplace.
Speaker A: Yeah. So who said it? Do you think I said it or you said it?
Speaker B: Um, I'm gonna say that I said it.
Speaker A: Yeah, I think you did, too, actually, to my embarrassment.
Speaker B: Right. I think Hot and Stinky Soup is more likely to come out of my stup.
Speaker A: Yeah. Ah, there's a clever wit in the wording there, which tells me it's immediately yours.
Speaker B: Yeah, about that, because my brain doesn't work, though. Yeah. Well, let's just talk about it for a second, though, right? Because we were just having a discussion before the show because Justin and I both been getting some calls regarding water, um, system security. Right. Uh, because there's been, um, at least evidence of, uh, a more organized attempt by nation states, parts and groups to be targeting or at least identifying vulnerabilities inside water systems, inside water management systems. Right. We saw, um, an attack against Aliquippa in Pennsylvania. Um, we've seen others over the course of the last couple of years, and we've done some work on it. But I think this is, um, emblematic of the fact that there are different kinds of systems that get tapped because now they're connected to the intercast, makes them better and more useful, but they haven't necessarily been thought about too hard.
Speaker A: Yeah. Well, I mean, it's interesting. I mean, this has always been a theme and kind of thread through the industry is once it's connected, has some intelligence behind it, it's automatically open to ATT and ck, you know, and it's interesting, like, here we are now, and we're in an election year and now we're starting to hear things about, like the water system hacks and, um, same vein, this isn't going away. And as we seek a more connected society, like, this is only going to get worse.
Speaker B: Well, and it's interesting because I think about it, um, I was having a discussion yesterday with a couple of folks who understand the industry pretty well in terms of those control systems and water, and what they were saying was it's so different than private industry because, um, they're looking at, let's get some funding. And so EPA is really, really tightly involved and is trying to do the right thing. But EPA is like, we really have to get going on this. We got to do a bunch of work. Tell you what, here's $10 million. Go figure it out.
Speaker A: Yeah. Yeah.
Speaker B: And it's like $10 million is like waste paper baskets, coffee money. Right. For a lot of cyber security firms. Right. But it is, unfortunately, people don't think about there being this huge technical component to infrastructure like water. But there is. And I think we have to help and educate and all of you can help us with, uh, educate legislators, uh, educate policymakers that this is a serious problem. There are tens of thousands I found out yesterday of different water utilities out there running around. Yeah, we're all doing their best, and there's a lot of really smart people who are trying to work on. Yeah. And it's, um, it's something we have to take more seriously. So I like the hot tub thing. I think that's funny. I think it's sort of like the control of the webcam, sort of baby monitor, photo frame stuff that's happened over the last few years, so it has sort of a personal commute, um, consumer edge to it. But I think we should recognize that the same problems exist in places where the damage can be a lot more severe.
Speaker A: Yeah, I like it.
Speaker B: Super. All right, uh, that one is gone.
Speaker A: Okay, next one here. Drum roll. Uh, this is not as long as yours. All right. Oh, this is fun.
Speaker B: Okay, cool.
Speaker A: Uh, Pucksutawney Programmer.
Speaker B: Oh, yes.
Speaker A: Yeah. Uh, the quote is to think that someone could program an infinite loop into an open source package just feels right to do it on Groundhog Day. It actually does.
Speaker B: I think that's you. I think that's definitely you.
Speaker A: Yeah. Uh, I'm thinking it's you, actually.
Speaker B: Really? Yeah.
Speaker A: Yeah.
Speaker B: Well, I'm. Well, okay. Well, we could discuss why to me, because you already always have a grasp for sort of what is going on in the community, who's trying to change things, how are they consuming things? The stuff you wrote long before I joined the company on securing things like Ubuntu, all the work that went on, more technically oriented. It just feels like something you might say. Yeah.
Speaker A: And I was, well, if it was me, the only thing that I think would be a tip that it was me was that, um, it's shorter. What are you saying, Mr. No. Uh, and, uh, the word complexity isn't as high as what I've seen come out of you. Uh, but the play on words actually makes me think it was you.
Speaker B: Got it. So it's an interesting place to talk about, uh, the open source community and its impact on cybersecurity. We know we can discuss. I'll show supply chain issues which come in a variety of different flavors. Uh, and we can also talk about what's happening now with generative AI, Right. And the poisoning of models and, uh, the creation of new techniques to create inroads and vulnerabilities. Because that ecosystem isn't really, really well understood. And that whole data chain, that whole life cycle isn't really well understood.
Speaker A: Yeah.
Speaker B: So I think maybe it was a harbinger of things to come.
Speaker A: Yeah. Um, I think that part of our industry is only going to get worse from a risk profile perspective. Um, the reason being, and my thinking behind it is, um, we are more and more an interconnected society, um, and more people in an effort to speed, to market, seek, to interconnect versus to build their own. Right. So there's a little bit more of a embracing of, like, the concept of ecosystem, an integrated ecosystem, um, more of a fabric, if you will, which also Suppose is like, it's a little bit more of like kind of come as you are and a little bit more open. Um, I foresee things that more the ecosystem approach, supply chain, all of the things that are tangentially related to this are uh, owing to going to continue to be front and center from a risk profile standpoint here now and for the years to come.
Speaker B: I like that. And that speaks directly to what happened here, which was the intentional misuse of that, uh, openness of source. 1 Ah, thing I want to bring up that maybe in the couple quotes may not be right, which was the discussion we had on the fact that generative AI and ChatGPT in general is generating software for people and that there had been some Stanford research done that showed that where cybersecurity relay. And I'm going to butcher the context for the quote, but I have the stat right was that ah, 54% of the time when it made a decision in that kind of sitch around cybersecurity, it made the wrong one and created something that was vulnerable. And so to your point, more people are connecting, more people are federating good bits of functionality from different places. If now they're using um, generative AI to generate the code, we should recognize the fact that the people who asked generative AI to do that didn't know how to do it themselves. And they're really unlikely to be able to put a, uh, skeptical, uh, eye on the code that gets generated to see if it's secure or not. So to your point, now we've also got risk not just from the aggressively motivated outsider, but the accidental mistakes made by insiders using tools.
Speaker A: Yeah, I feel like uh, it's the over investment in the engine to go faster without thinking about how big the brakes are.
Speaker B: Nice, nice. Or teaching people how to drive. Yeah, yeah, right. Yeah, it's. Yeah, it's funny. I've got uh, I just got another copy. Uh, mine got lost of unsafe at any speed, which talks about the dangers the, the almost designed in dangers of the automotive industry back in the 60s. Yeah, yeah, right. And uh, I think you're exactly right. They, they have built bigger and bigger engines and nobody's like, but holy. The roads are only six inches wide.
Speaker A: Yeah, yeah, yeah.
Speaker B: Yep. Nice.
Speaker A: For sure.
Speaker B: All right, all right. Excellent. We're back to the cup of goodness. I'm hoping mine is short, but it's not. Oh, shout uh, out Glenn Bressner, formerly, uh, Atlantic Ventures of some kind. Anyway, sometimes the title of the episode was sometimes you should argue the Price of champagne. This is one of my very favorite quotes. Um, but I'm not sure if this is me talking about till I read it. You'd be much better off getting the right investor at the right valuation and get you the support that you need because at the end, everyone will be super successful. Everyone will be super successful. I don't know, I just feel like mine would be more colorful if it was me, because this is one of the like, uh, for those of you who haven't heard the episode, it's one of our earlier episodes, Mid Atlantic Capital. Glenn Bressner. Um, thanks.
Speaker A: It was a very simple quote, therefore it must be you.
Speaker B: No, not simple, just straightforward and meaningful. As opposed to me putting on the color. Well, only because like this. So listeners know, I founded a couple of companies, but this was the first company and I was going off for my first round and I knew almost nothing. And I was meeting with a guy named Glenn Bressner who was a partner in a firm. And you know, we're just talking about stuff and I think at the time I was a little bit further along with some of the other investors. And so maybe, you know, he wasn't going to get, uh, to the dance. He's like, listen, you're doing good work. Cyber security is really important. I want you to remember, never argue over the price of champagne. Right? And I think you and I had this conversation because we were talking about these hundred million dollar rounds on a billion dollar valuation and yay, let's go. Um, and we were like, wow, that this is like 2021. We're like, wow, this seems like it might be dangerous, right? You take too much money, you spend too much money, you might find yourself in a valuation hole in 2023. But, you know, and it, and, and you know, this is one of those Nostradamus things that Justin was talking about earlier. Um, but it was a great, for me, at least it was a great lesson and really, really smart. Finding the right partner. I don't care whether you're looking for a job or you're looking for an investor or you're trying to find what tech to buy. You know, picking the right partner who you share values with. Right. And that, uh, share your view of what the world can be a lot better than just having somebody pay you more.
Speaker A: Yeah, yeah. Um, let's, let's go a little bit deeper though on this. Um, so kind of when that quote was made last year, year before, um, like a lot's changed, right? And um, there's now in 2024. There's a clear difference, market difference, between the haves and the have nots industry. And there's people that I believe who have found the right investor who are still continuing to operating and thriving today. Um, and there's, I'm gonna go ahead limit, say there's only a small handful out there who actually know what they're doing. Um, there's a lot of others who opportunistically hopped into something that they're probably unqualified to do. Um, and in turn, I mean it's fine to deploy capital, but you also don't have the expertise, you've never done it before, you've never been in the industry having to scale and understand the nuances and the challenges. And I think we've seen some of those companies start to struggle here in uh, the land of expensive money and uh, higher interest rates. Rates, yeah. As usual.
Speaker B: You said something that just made me think, right. Which is if I do take on, if someone does take on that uneducated investor and things start to go sideways. Right. They invested not knowing why, but because the market said it was a good idea or they just had this gut feel it was a good idea. So they don't know why they invested. And now if things go sideways they're not going to understand why it went sideways.
Speaker A: Yeah.
Speaker B: But uh, I will, I will wager that they're not going to invest again and definitely not at those levels because now they don't have sort of the tailwind of everybody else saying it's a good idea. Now they have to justify to their limited, to the, to other partners as well. Why is this a good idea considering the last hundred million you put in is like almost worth nothing now or it's worth 50 million now. Right. So really, really problematic. And I'm wondering, uh, as you were saying, sort of have the have nots. I wonder if we find ourselves in a, uh, world in cybersecurity, particularly where you've got the haves and the won't haves. Right. They had, they had it and some people will continue to have it to your point. They get good investors, good support, good advisory function, all that stuff. And the ones who don't have that aren't going to have it. It's just over.
Speaker A: Yeah, yeah, yeah. I think that's spot on. The um, you know, it's kind of can fusing uh, I would imagine for anybody who's a startup founder listening to this and you're in the product space, you're trying to figure out how to get started. And you find someone who's willing to give you dollars, um, isn't always the person who has the most experience. Right. And so if your choice is to continue to go forward with your product with someone who doesn't know as much, but you have dollars is pretty. An enticing thing. Thing. Um, but where we are Even today, in 2024, like all investors, I shouldn't say all. There's a lot that are willing to hang out a shingle claiming to be a cyber investor. But when you ask them, like, how many. How many do you have in your portfolio? They're like, uh, we haven't found the right one yet. Yeah, well, okay, that means you have none. And you also have no experience. Like, and I, to be honest, like, I don't want you cutting teeth on. On mine.
Speaker B: Right on. Well, and think about how different cybersecurity companies are. Right? You've got what we do, help lots of people get this stuff going. A lot of different technology expertise. Then you've got companies like CrowdStrike, really good at analytics and cybersecurity and software. Software, margins. Right. And this. And what in the hell would make a great software investor good as an investor in a services company?
Speaker A: Yeah.
Speaker B: Right. It's completely. It's a very, very, very different marketplace in terms of the way you develop what you develop, how you push what you push, how you sell, what you sell. Margins. You're expecting all the rest of it. And so saying you're a cybersecurity investor, it sort of bespeaks a lack of understanding about how diverse the market is.
Speaker A: Yeah, yeah. Tough, tough landscape.
Speaker B: Right on.
Speaker A: All right, it's my turn.
Speaker B: Your turn, babe.
Speaker A: I feel like we should do, uh, like Toby Keith saying about the Red Solo.
Speaker B: Right? So we'll fill that up with ransom or why, Ryan, whoever gets the last question wrong has to be finish it.
Speaker A: It's like game of, like, hot potato here.
Speaker B: I say, well, since I started, I know you're going to get the last one, so it works for me.
Speaker A: This is a clever way. Oh, man, I didn't wear my bifocals. All right, ready?
Speaker B: Yes, sir.
Speaker A: Parsing, uh, through cybersecurity product tud. The T. But. But it's hard in the world of, like, marketing, like, mumbo jumbo. Like, how do you. How do you tell them apart?
Speaker B: Hmm? Hm. Tud. What was tud? Something Uncertainty and doubt. Threat, Uncertainty and doubt.
Speaker A: Technical uncertainty and doubt.
Speaker B: Technical uncertainty. Doubt.
Speaker A: Whatever Todd was.
Speaker B: But.
Speaker A: But the.
Speaker B: We coined it.
Speaker A: Yeah, it's a Great.
Speaker B: It's like a good idea at the time.
Speaker A: Yeah. I'm. I'm probably. I'm probably sure it was infused. Um, so, uh, in the world of marketing mumbo jumbo, how do you tell them apart? It's a great question. Yeah. Even still, like, even when we made. When we said this, um, it was a challenge then. I. I actually think it's gotten worse now.
Speaker B: Yeah, I agree. Because AI now pollutes everything.
Speaker A: Yeah. It's a giant. The giant polluter.
Speaker B: Yeah. Yeah.
Speaker A: It's tough. It's a tough landscape. It was a tough landscape then when we said it. I think it's harder.
Speaker B: Yeah.
Speaker A: Harder now, and I think it's getting harder. And, um, even when I read, even personally when I. I've been doing this for a long time, over 20 years,
Speaker B: and his beard was like this little tiny thing.
Speaker A: I didn't. Yeah, I didn't even have one. I didn't. Wasn't even shaving then. Uh, but, uh, now it's like even I look at stuff and the words have gotten better and the engineers say the right thing. But it's only now, seemingly. It's only when you try to do a technical deep dive of Tell me more. When you realize stuff actually falls over, that it's not what it claims to be.
Speaker B: I think we suffer in our industry from. Because Cybersecurity is never 100% right. We just try to aphorisms. Right. But never 100%. Historically, we've asked people, how does it work? How will you protect me against ransomware? How will you do a better job of crypto? How will you, you know, make sure you're doing good, naming, whatever. Um, and that, how. Is so Byzantine, right? It just is. And I think what we want to do, we've talked about this in a few of the, uh, of the episodes, is demanding why, like, why am I using you? What exactly are you going to stop? Don't tell me how. I don't care how. Swing a dead cat. Don't care how. Tell me exactly what you're doing. And I think that, um, it could very well be what the through line was on that episode. Right. Which is if you're a bank or statewide authority, whatever, and you're like, I need to protect the, uh, individuals against XYZ threat. Demand that vendors tell you how they're going to protect you against that threat. Like what they're specifically going to do.
Speaker A: Yeah, you know. You know, it's interesting. I immediately come back to, um, the Endpoint company we're talking to that one time, on the surface, everything sounded great.
Speaker B: Right on.
Speaker A: Great, great, great. Um, to have you come in and like, ask some really, like, technical questions which were deeper than I could go in the space. So, like, it's clearly your area of expertise and you've done it before, but to hear them respond to it, you're like, you're like, yeah, I was doing that in like 94.
Speaker B: Yeah.
Speaker A: I was like, oh, let's close the chapter of this book and move on. I feel bad, but for any customer who doesn't know that client, like, they just get sucked into the scheme.
Speaker B: Well, I just think about how much more advanced you are than most of the people that we try to help. Right. How many of them?
Speaker A: I'm not sure. I'm too advanced by. Based on the quotes that were.
Speaker B: No, but seriously, dude, I mean, um, I go to you with technical questions all the time. Right. And so we're getting a technical presentation, mid level technical from a company and it looks like what they're doing is super innovative and super cool. And then we ask them a couple of questions. And I think the questions would have been fine for even a well educated, experienced person. Think about what it'd be like for like the business focused person who used to be in charge of like financial operations or risk management or compliance, who now finds himself here and recognizes they need a better job of anomaly detection on the endpoint. And they say, so how does this work? And they say, supercalifragilistic xp. Right. And they say, awesome. That sounds great. Right? Yeah. Uh, I mean, who, where is the. Where's the recourse?
Speaker A: Yeah.
Speaker B: Because these people don't even know that. They don't know. Yeah.
Speaker A: Yeah.
Speaker B: It's kind of not fair.
Speaker A: Yeah, it's really not fair. I mean, it's. Yeah, we'll just leave it at that.
Speaker B: It's not fair.
Speaker A: I love it.
Speaker B: Cool. All right, next. Super scrupulous. There's like 600 of these things.
Speaker A: Yeah.
Speaker B: This would be the 200 and 201st episode. All right, here we go. Oh, uh, thank goodness. It's a right swipes. Meat market March.
Speaker A: All the things that happen before you go to the chapel, it's all the bad decisions. You know, you drank too much, you gamble too much. Next thing you know, there's more bad decisions and here we are. What?
Speaker B: That's definitely you.
Speaker A: For sure. That was you.
Speaker B: No, no, no, no, no, no.
Speaker A: Yeah.
Speaker B: Anytime there's a realistic appraisal of being hyper infused, it's always you.
Speaker A: Yeah. Meat market March.
Speaker B: Yeah.
Speaker A: Be market March?
Speaker B: Um, yeah, I think that was March of 2023.
Speaker A: Yeah.
Speaker B: Right. I'm assuming March 2023, or maybe March 2022, because I remember there was a period where there was a pile of acquisitions in a single month. We saw a lot of pairing off. And I think that part of the episode's theme was, check it out. People don't want to miss the bus.
Speaker A: Right.
Speaker B: They're watching people leaving the bar and they're afraid they're going to be all alone. Yeah, yeah.
Speaker A: There was, um. Geez. I'm blanking on the name of the publication at this moment, but we can post it for folks. But there was, um, an individual, a gentleman who was writing a lot from Crunchbase. Thank you.
Speaker B: Yeah, um, he's awesome. I can't remember the last name. I'll put it in the list, but he's excellent.
Speaker A: And I recall, uh, that we had been reviewing a lot of those, and he'd been writing a lot about it. Just the velocity of the industry. And this was like, one more on the heels of, uh, us being like, what the f is going on? Um, yeah. Here we are. The Reapers. Reapers, come back.
Speaker B: God. Tough, tough. And there really was this. It felt like a view that there was infinite revenue to be had, and so companies who had success were picking up other overvalued companies who had moderate success and figured they could just sell more, because, hey, there'll always be one and a half crap, tons of money to spend on cybersecurity until there wasn't anymore.
Speaker A: Yeah.
Speaker B: Right. And as business had to retrench, it was bad.
Speaker A: Which comes back to my point. I've been saying for a long time is the total addressable market for cyber is overinflated.
Speaker B: Fact. Fact. Yeah.
Speaker A: Uh, one day, when I actually have time to sit down and mathematically prove it out, do this again, and, you
Speaker B: know, maybe it's a top. It's definitely a topic for another day.
Speaker A: Right.
Speaker B: But my view is that there is definitely a limit and we're spending the money in almost all the wrong ways. Oh, yeah.
Speaker A: Uh, right.
Speaker B: If I think about why is cybersecurity so expensive? Why is it so underfunded, why there's so many empty jobs. It's because it's so much harder than it has to be.
Speaker A: Yeah. Well, I mean, I come back to, like, what you and I were talking about earlier, which is, um. I can't remember the exact example, but it was like. It was $10 million applied to, like, utilities. Right. And we're like, that's kind of A drop in the bucket. But, like, that's also a lot of spread.
Speaker B: Right.
Speaker A: On, like, should. Should that be a drop in the bucket or should it be something more, like, tangible and material? Right.
Speaker B: Yeah.
Speaker A: If we went to, like, Mimi and said, hey, I'm going to give you $10 million to buy supplies with, she's like, she's making hay for, like, a long.
Speaker B: That would last you, like, six weeks. Right.
Speaker A: But. But our industry is just kind of like we. We throw it. I feel like making the same. I feel like we throw it away.
Speaker B: Yeah, I agree. I agree. It does not have to be this hard if people said the right way to handle, um, pick your healthcare problem of choice, um, smoking and congestive lung disease and all the rest of the badness that happens. If we said, well, the right way to solve that is we're going to spend $8 trillion on more hospitals and more iron lungs and more.
Speaker A: Whatever.
Speaker B: Whatever technology used to support people who find themselves in that state. Um, people be like, can't you do something about making the disease less prevalent? Can't you help people understand that this particular habit's bad for them? And that's what you see happen in the rest of the world. In cybersecurity, we're like, wow, still vulnerable. Buy some more stuff.
Speaker A: Yeah.
Speaker B: Right. We don't go back and say, why is the operating system or the web browser or the application still vulnerable? Why is access control still so hard to manage? Why do mailers allow phishing scams through all the time?
Speaker A: Yeah.
Speaker B: We don't ask those questions. We say, I got an idea. Another band aid?
Speaker A: Yeah. Yeah. Band.
Speaker B: Ah, AIDS are expensive. And that's all you got. Right.
Speaker A: This situation calls for stitches, but a band aid will work.
Speaker B: Yeah, Exactly. Yeah.
Speaker A: All right. Um, what we say, how we doing on time here? I think we make this one our last one.
Speaker B: Yeah, let's make this one our last one.
Speaker A: All right. This is going to be good.
Speaker B: It's going to be awesome.
Speaker A: My God tells me it's going to be great.
Speaker B: Hope it's really long.
Speaker A: It's not, uh, beyond the badnessometer.
Speaker B: Oh, I like it.
Speaker A: Yeah.
Speaker B: Uh, if the badness ometer says, you've got a problem, you probably got a problem, right?
Speaker A: You got a problem, right?
Speaker B: Yes.
Speaker A: What do you think?
Speaker B: I remember this. I don't know. I don't know who the quote is. It is short enough. It could be you with your concise verbiology. It could be me because I hate the badness ometer. Right. And I think typically I use it to refer to automated pen testing. Right. If the badness omitter says your application is vulnerable, your application is really freaking vulnerable.
Speaker A: Yeah. I think it's you.
Speaker B: Hm. So Hawes is going to have to do the tally.
Speaker A: Yeah. See who scored higher here?
Speaker B: Well, at least. Yeah. Who had a better recollection of it?
Speaker A: Yeah, well I think uh. I'm pretty sure I said all of them were yours. So the fact that if you picked me for any of them then you're probably right at least one of the times.
Speaker B: Uh, but the badness ometer, that's another cybersecurity thing. Right. We have a bunch of brute force blunt tools that we use the equivalent of the wedge in terms of the tool hierarchy. Um, and so when it says that something's bad we're like oh I guess I better fix that thing. But what we really should say is it's like if smoke alarms only went off when the temperature inside the room was like 300 degrees Celsius.
Speaker A: Hey.
Speaker B: It tells us when there's a fire like. Yeah, but by the time that goes off everything's pretty crispy. Yeah. Fact. Right. But that's kind of where we're at. The tools that we have because of just the nature of the way they've evolved and people's understanding of the problem space, by the time they notice something, something's got to be pretty damn wrong.
Speaker A: Yeah. I've um, you know this but I've long been of the opinion and I think, I think, I think a lot of people hate, hate this especially product companies. Is um. Well product companies are part of the issue. Oh fact 100%. And um, because cyber is in the position that it's in people with alert fatigue. We have overspending, we have this problem and we have record spending and we still have record amounts of breaches tells me we are completely inept and incapable of making like holistically making the right solutions for the problem. And don't get me wrong, I'm not saying everybody, I'm saying there's a large percentage of manufacturers are not qualified to solve. Solve this problem.
Speaker B: Right on.
Speaker A: And uh, so because of that like you're kind of further exacerbating like the issue within, within our industry and the issues trace back to um, the, to me my opinion, my opinion. The product manufacturers.
Speaker B: Yeah. 100%. I don't know if you notice and this will be currentish at the time this episode goes out but SolarWinds just announced the results that they had been. They'd done the self security assessment following their events from a year or two ago with, uh, CISA and I think the SEC whoever manages it, and they're like, here it is. I can't find it anywhere like it says it exists. Everybody's writing about it, but I haven't been able to find the assessment to see if I believe that it's enough to see what it is. Um, but I think that that's the first sort of hesitant, stumbling kind of step towards the vendors taking responsibility for the fact that they're creating a lot of these issues.
Speaker A: Yeah, I like it, man. We should end on that one. Excellent. So episode 200 in the books. Cheers. Cheers, my friend. To you and dub as well.
Speaker B: McDub's doesn't happen without you.
Speaker A: All right, episode 200 in the books. Uh, if you are listening and watching this, thank you so much for following us. Um, again, we're at Mad River Distillers in Burlington, Vermont. Um, and thank you to the entire matter of Team Mimi Jesse for hosting us here today. If you have comments, Questions, pwned@newharvardsecurity.com. uh, and episode 200 is a big.
Speaker B: It's seminal.
Speaker A: Yeah. It's a big milestone. Um, and as such, uh, we're going to take a little bit of pause in programming, uh, conclude this season. We're going to regroup and figure out what. What, uh, next season holds for us.
Speaker B: And we'd like to hear from you. Right. So if there are people you'd like us to talk to, as Jess and I go through this and try to think about a different way to add value to the way you're thinking about cybersecurity and the way we want to talk about it. If the people you think we should be interviewing, if you think there are topics we should cover, if there's types of episodes you think we should do, we want to hear from you because you're the folks who make the whole thing happen.
Speaker A: Yeah. Awesome. And we'll get you on the next episode. Sam.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.