
Securing the Realm · 2026-08-03 · 37 min
Key moments - from our scoring
Substance score
59 / 100
Five dimensions, 20 points each
Bruno Lecoq brings 20 years of Microsoft experience to his role leading BIMO, a cybersecurity and compliance provider focused on SMBs (10-1,000 users). Rather than blocking AI adoption, he advocates for active governance - monitoring which tools employees use, establishing monthly training programs, and implementing compliance controls. BIMO's approach includes creating security skills to test and red-team internal agents, enforcing policies like preventing agents from performing destructive actions (deletes, sending emails), and managing identity governance for agentic AI. Lecoq highlights the business tension between innovation velocity and cost control, noting that Microsoft's new AI pricing has forced BIMO to slow deployment. He also emphasizes how AI adoption is forcing cross-departmental collaboration (finance with sales, for example) and enabling non-technical staff to build functional software applications. The conversation touches on identity verification challenges when agents operate on behalf of humans, the risks of AI slop in communications, and the need for specialized red-teaming skills to test agent behavior - a discipline still in its infancy.
Don't block AI tools; instead, implement governance to monitor what's being used, have ongoing conversations about necessity, and remove tools that duplicate existing capabilities or pose genuine risks. Blocking drives shadow adoption on personal devices.
Establish clear rules such as preventing agents from deleting data (only proposing deletion for human approval), ensuring agents run under service identities rather than human identities, and running monthly reviews with security skills that test for bias and breaking attempts.
Rising consumption-based pricing forces companies to slow innovation and make deliberate choices about which Copilot version to use or whether to use free alternatives, leading to more tool proliferation and governance complexity.
Domain experts from the business (lawyers for legal agents, finance staff for financial agents) are better at finding domain-specific vulnerabilities than pure security specialists; this requires a shift from traditional penetration testing teams.
Compliance tools like CUA currently require human identity to run, which conflicts with the goal of agents operating only under service identities; this is a technical limitation that systems have not yet solved but may change within 6 months.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains moderately useful practitioner insights about AI governance in SMBs - particularly the shift from blocking to governing AI, concrete BIMO examples like 46 agents, compliance tiering, and identity challenges with agentic AI. However, much of the discussion meanders, repeats points, and lacks the density expected: there's substantial filler (throat-clearing, vague statements like 'it's just interesting,' long pauses), and several tangents don't build toward novel conclusions. A practitioner would extract 3 - 4 actionable ideas but wade through considerable padding.
So my first thing was don't block it, do the governance. And then after that is now you know we have to again if I think in the world of Microsoft, then you have to, you know, work about copilot.
So we have every month the the team meet the governance team of AI meets again, review all the agents. So again, now we have our our skill that try to you know give us a report of you know was it Well where any agent bias, where any agent you know kind of you know, try to so and we had to stop two agents last month because we saw they were going kind of wrong.
Bruno offers some fresh, pragmatic perspectives - particularly the 'don't block, govern' framing and the specific technical challenge of agents unable to use CUA (Conditional User Access) with human identities. The live hiring scenario to defeat AI-assisted interviews is practical. However, most broader themes (zero trust, security as culture, AI as accelerant, governance frameworks) are well-trodden. The episode rarely pushes into genuinely contrarian or first-principles territory; it confirms conventional wisdom more than it challenges it.
I didn't know at the speed it will be taken. Some people run with it, some are you know slower to adapt technology. So again it's you know you got the full game bit of type of people, but to be honest I have been amazed what people are now doing.
So now we are like, okay, this breaks down our model because from our perspective, we don't want any agent to have human identity. Okay? but the system yet is not there yet to what we want to do and what Microsoft allows you to do.
Bruno is a solid mid-tier practitioner: 20 years at Microsoft, founder of BIMO (a real SMB-focused cybersecurity firm), demonstrable compliance credentials (ISO 27001, SOC2, CMMC, EPA), and active deployment of AI agents in production. He speaks from direct experience, not theory. However, he is not a household name, hasn't scaled to unicorn status, and operates in a relatively narrow niche (SMB compliance). His seniority and relevance are clear but not exceptional - a strong regional operator rather than a category leader.
I am Bruno Lecoq. I'm a French guy based in Seattle. So from my background, I worked 20 years at Microsoft before creating BIMO. And from BIMO, what we do, we do cybersecurity and compliance for SMB, so companies from ten to a thousand users in the US.
So from a so from a perspective, so for the listener from a BIMO perspective, we are already ISO 2701, SOC2, CMMC, EPA compliant, and we are now working on our ISO 4201.
The episode includes some concrete examples: 46 agents at BIMO, 8 levels of agents created, two agents stopped last month for governance failures, live hiring interviews, Microsoft Secure Score (70% benchmark), and Windows 365 deployments for ephemeral agent execution. However, critical data is missing: no customer numbers, revenue impact, or cost figures from the new Microsoft AI pricing that Bruno mentions as a pain point. Most financial and scale metrics are absent, and many claims remain vague ('some amazing stuff,' 'very different level of agent').
So today at BMO we had 46 agents running.
we had to stop two agents last month because we saw they were going kind of wrong.
The hosts (Josh and Chris LJ) ask reasonable opener questions but rarely dig deep or push back. They nod along ('Mm-hmm,' 'Yeah'), offer soft observations rather than sharp follow-ups, and allow Bruno to wander into anecdotes without steering back to the central claim. Chris does make a few good strategic pivots (asking about domain-specific testing, identity verification, the deep-fake hiring scenario) and occasionally references his own experience, but overall the conversation lacks the rigor of a true interview - it plays more like a friendly chat where the hosts validate rather than interrogate.
Okay, so that that's really interesting. So it's interesting to hear about BMO and what you focus on where you come from. And obviously you're very highly certified and it sounds like things have changed.
I I liked what you mentioned around breaking down kind of those barriers within the organization. I guess it's a little bit trite, it's something people have been saying for a long time, you know, breaking down silos.
Computed from the transcript - who did the talking, and the words that came up most.
Bruno Lecoq spent 20 years at Microsoft before founding BEMO, where he runs compliance and AI governance for small and medium businesses. In this episode he explains why blocking AI tools fails in practice - staff use them regardless - and what governing that use looks like: zero trust for smaller organisations, keeping AI costs under control as Microsoft's pricing shifts, and continuous compliance. We also talk about where security teams go from here as AI picks up more of their work, and the new risks that arrive with the tools, deepfakes included. Bruno's examples come from his own clients - AI changing how departments work with each other, and how companies oversee what staff do with it.
Transcribed and scored by The B2B Podcast Index.
Josh: So hello and welcome to another episode of Securing the Realm. So as usual, we've got another guest on today. Now I've been excited about this one for a few weeks now, ever since we met. So I'd really like to take the opportunity to introduce Bruno, who's gonna be our guest today.
So Bruno, do you wanna introduce yourself to listeners? Bruno Lecoq: Hello, so I am Bruno Lecoq. I'm a French guy based in Seattle. So from my background, I worked 20 years at Microsoft before creating BIMO.
And from BIMO, what we do, we do cybersecurity and compliance for SMB, so companies from ten to a thousand users in the US. Josh: Excellent. I think that's a very interesting topic for a few reasons. you know, the the demands and the disruption that is a kind of occurring across the industry landscape is very different depending on the size of the organization you are.
So in terms of kind of getting down to first principles, what is AI to you? Pretty broad question, sorry. And you know, in terms of security and governance, what does that mean to you in your Bruno Lecoq: So from a so from a perspective, so for the listener from a BIMO perspective, we are already ISO 2701, SOC2, CMMC, EPA compliant, and we are now working on our ISO 4201. We are in the middle of the audit.
Okay, so it's got a perfect process. So what has been for BIMO? So today at BMO we had 46 agents running. Okay, so again it's a How do you manage this agent?
How do you so for the program? We first opened, so we started a year ago, and we first had Bimo in a company. We first decided, hey, we are going to make kind of Bimo compliance, not compliance, AI monitoring, and we are going to train as a company. So we started and every month was you know first was what is AI?
So again, co-pilot, and after what was you know prompting, what was we all took training as a level. And then before the new right the new pricing for Microsoft, it was easy to just give to everyone in the company. And it was interesting to just see the innovation that came and people creating, you know, very different level of of agent, different power, and it's kind of how Josh: Mm-hmm. Bruno Lecoq: we have pushed AI within the company.
Chris LJ: Okay, so that that's really interesting. So it's interesting to hear about BMO and what you focus on where you come from. And obviously you're very highly certified and it sounds like things have changed. But to you personally, what does AI or artificial intelligence mean now?
And what might have been meant ten years ago to you? How's that definition changed? Bruno Lecoq: I think you know, I feel like you know, I feel like I have been part of many revolutions from computers to internet to cloud. And I think from an AI perspective, I feel like a rat on a wheel because just change just Chris LJ: Mm.
Bruno Lecoq: change at a very big speed. So if you say, you know, again, a year ago we are not even doing AI, and a year later, again, I have agents running and we have compliance, and again, we have a process of we have eight different levels of agents a week. From the BMO perspective, we have you know level one, two, three, four, five. Based on that, there's a different governance.
So again, it's and I have no doubt in 12 months from now we will do stuff differently. So it's just I feel like it's how do you catch up with you know the news, how do you catch up with the technology, the you know, new things mixed with pricing, mix with compliance, and you know, yeah. So for me, the AI is It helps my anyone in a company to do stuff faster. some some some of the time from an automation, sometimes better, but while you still have to watch that not everything is correct.
So I think you it's so it's cannot be so it's and different majority of the employees, some are AI engineers, but some are just you know just someone in fine that you know, so it's all you know mix of how you you finger cross. Josh: Yeah. Chris LJ: Okay, that's interesting. So clearly AI's made a big impact on kind of the way that you work.
I guess one of my questions would be when all of this started, were you expecting this particular rate of change? Does this change from the previous technology revolutions that you've sat through, that you've worked in? Bruno Lecoq: I didn't expect so it's for me it was an amazing live experiment because again I didn't know and BMO we are you know 30 people. I didn't know at the speed it will be taken.
Some people run with it, some are you know slower to adapt technology. So again it's you know you got the full game bit of type of people, but to be honest I have been amazed what people are now doing. It's just you know stuff that you know now you you will t I cannot turn off AI. There is no way that of course if we had to turn off the server, but I feel like I will go back ten years back.
You know, it's just now it's just part of you know, I have my report in the morning, I have my status on the you know, how is tech support doing? I mean there's a lot of you know, agent running, just so you take it for granted now already, and it's only a year. Josh: Hm. Yeah, you and what you're kinda showing here is that it is truly everywhere.
And like you said, it it's very hard, if not impossible, to switch off. So it it's really changed the kind of working environment around it. With Bruno Lecoq: Yes. Josh: that in mind, how do organisations think about their governance in all of this?
Or how should they be? Bruno Lecoq: So I think for me there is you know, I I see with my you know with my customer, many of my customers say, Well, you know, I'm not worried because we're not using AI and then we are like, you know, you would believe you are not, but I can tell you give Josh: Yeah. Bruno Lecoq: me five minutes and I will show you how many people are using AI in your organization, you know. And then when you show them the report, they're like, shit, I didn't know.
And then they wanna block then they wanna block everything. And always like, Yeah, you can block, but you know, if someone wants to use they will use their personal computer. So From my perspective Chris LJ: Yeah. Bruno Lecoq: is don't block it, govern it.
You know, do put a governance to it. And again, it's good. So you know again. So I will use it, I will talk to be more from a bimbo perspective.
We look every week, everything from AI, what is being used, and we know we control what is allowed, not allowed. If we see a new one, we have a conversation. Do we really need this one? Not this this one.
And if not, we remove it, you know, we block it. So it's kind of it's a conversation and it it It brings sometime conversation of someone in sales using AI to do that, and you're like, you know, you can already do that with what we have. you didn't know, you know. So it's it's just an ongoing conversation.
So my first thing was don't block it, do the governance. And then after that is now you know we have to again if I think in the world of Microsoft, then you have to, you know, work about copilot. But even from co-pilot, you have copilot, copilot, co-work, you have so many different, you know, version of copilot. Like I don't know, you know.
So okay. People have to understand it. And then after that is do you just use AI as a I would say an advanced Google search? Or do you want to go into the agentic AI and create your own AI and what does it mean to you know?
Chris LJ: I like the pragmatism there. I mean, I think it's really important. It's the same with I guess data loss prevention in the past. At the end of the day, you can't stop someone memorizing things, walking out the door and typing it into their mobile phone.
So it Bruno Lecoq: Yes. Yes. Chris LJ: really is better to enable people and focus on, as you you mentioned, the leadership and how and how you're encouraged that. I guess you mentioned that you have a lot of agents running internally.
Did they start Planned or is it on aga an organic growth within the organization? Okay. Bruno Lecoq: Organic growth. Organic growth again.
So it was, you know, we gave them a tool, we still continue our monthly meeting, our monthly training, and people you know talking. And again, you have some that and they do some amazing stuff and some that don't care too much, and it's it's okay. You know, it's not you know, or some are I would say advanced users of engine created by others, you know. So it's but I think it's it's amazing how the teams you know work and What this force even from a BMO, it forces what some you know sometimes to say, hey, hey, stop.
We have to kind of redo the full workflow. Like AI showed us again. What I felt for me the event of AI is AI doesn't know the boundary of finance versus sales. It's just it goes across the goal.
So you have to kind of sit down and say, you know, which so it forced some cross division discussion. how we could do stuff and I think AI helped us redo stuff at at a five five pretty fast pace. Josh: you've touched on something interesting there around having to reach across departments. so one thing I've been wondering about is will the IT or the security department or any other kind of business unit you want to kind of call out be the same?
Will it even exist a few years from now or will it be kind of a convergence and divergence of other different departments and lines of business. Bruno Lecoq: Yeah, I think again it's just you know the same way as internet change how businesses run, I think yeah it would be the same. It just goes a lot faster and I see from my customers somehow it will not touch me and I feel like whoa you are very you are going to if you don't go into the main wagon right now, you are going to be left behind.
You know, it's not a question of do you have to it's it's not a question do have to use it is how fast are you going to use it because otherwise your competitor will do it. And how fast are you going to reorganize your company? My issue on that Chris LJ: No I was Bruno Lecoq: today is I felt like like on my side, the new pricing of Microsoft is now having an impact at BMO from the innovation because now I have to slow down. Because now I you know to control my bill, you know, before it was easy, I know what the bill was every month.
Well now it's just like, Chris LJ: Yeah. Bruno Lecoq: shit, what will be the bill at the end of July? Chris LJ: And I guess you want to proactively govern that by looking at what costs you might want to put in place. But also that's going to lead to more proliferation.
If someone hits their limits, they're gonna try other tools, other trials. Yeah. Bruno Lecoq: Yeah. And I think it's it's also for people now to think, okay, well maybe for that I will not use co-work.
Maybe you know, just we which version of copilot do I use? Maybe use the free one for that part and use the you know, you know. So it's again it's a it's a learning at the speed of you know. Chris LJ: I I liked what you mentioned around breaking down kind of those barriers within the organization.
I guess it's a little bit trite, it's something people have been saying for a long time, you know, breaking down silos. But Bruno Lecoq: Yes. Chris LJ: how much are you finding this is building an understanding of what your colleagues might do in other parts of the organization? Is this leading people to understand each other's roles as well as just redevine resign redesign the process?
Bruno Lecoq: Yeah, I think it again I I will talk in from our small company. It was just interesting from people that were not used to working together or crossing, they are realizing, hey, you know, my agent could do this and the other person, well, but you don't think about this and this. why I didn't even know. Okay, let's you know, so again it's just interesting and now they do the automation together.
There's a finance person talking with sales and just you know, it's just like before it's just you know, it's sales will do their thing, sales, you know, finance will do, and it's just you know So it's you know it's well I think also we are a tech company, so again I think you know the mindset is also maybe different, but it's just for me sitting and seeing the result like yeah, I just after our call I have my monthly business review with the whole company. And there is a a person that I you know I didn't know went into you know cloud and completely re rewrote a full program, you know, a full software application that you know And did on his own, came back and he's doing a demo to the company and you're like, Wow and again people are realizing, shit, I could do that too.
So and you know so it's just you know, it it gives IDs, it gives you know. Chris LJ: So Josh, everyone is a professional vibe coder now. Bruno Lecoq: Yeah, yeah. Josh: Professional is a loose term in that context, I would say.
But you know Bruno Lecoq: Yeah. Yeah. But again, I feel like before, and again, this is this is what's very dangerous because now people feel like they can just write software and always feel like, hey, Chris LJ: Yeah. Bruno Lecoq: hey, be careful because you know you don't know if it's secure, you don't know.
Yeah, there's other things, but what I would like is just to see the people that were not deaf before and just you know realize, whoa, I can write a piece of software. Whoa, you know, just you know and the advantage that I saw at Bimo, these are the people that leave the process. So like before. Someone had to write a spec, you give it to a dev, and a dev will try to code based on what was written.
Well, now the person coding is the one that needs it. So there is not Chris LJ: Yeah. Bruno Lecoq: the trans loss in translation. So again, it's just like when we saw the first version of the of this software, we're like, whoa, shit is much better than the one we had before.
You know, and it's someone that was not a dev. So it's again just a you know for me. Interesting. Chris LJ: Yeah.
one thing that that has made me realise is software engineers and architects have really they they've worked at the coal face, so they've really kind of got all these bruises, they've learnt what works, what doesn't work. And we talk about going from unconsciously incompetent, you know, all the way through to consciously competent and across those four stages. I'm feeling now like a lot of people may not respect the craft of software engineering. I now feel like actually some people you go t one of two ways.
You either now think you're an expert or you realise you have so much more to learn and it's leading a lot of people to go back through and learn those kind of basic principles. Bruno Lecoq: Yes. Yes. Josh: Yeah.
Chris LJ: how is that affecting security? How are you seeing people have the same interest in maybe some of the security concerns that might underpin their software? Bruno Lecoq: Yeah, we are now so for my you know so I will take in two things. So for I know for our compliance, we have to create skills and a skill that we attach to every agent, and the goal of it is to test every single agent against you know being I would say making sure that you know doesn't try to ask questions to break so we try to break the agent with the with the skill.
So it's kind of and our next skill will be to add Security. So right now the tool was done for internal only. So we are not as concerned because it's not something open. Like for me, my if it was open to the public, I will have I will not let it go, you know, for just something completely created by AI out of out of scratch.
For internal, internal, I'm less concerned because it's just you have to be logged in, you have to be, you know. But again, so this is part of our agent creating the skill, the skill that runs automation in a back to Right, June or go through it. Josh: Yeah. I that brings us to a kind of a interesting point, or at least brings me to something that I'm now starting to think about a lot as well with customers.
So the whole trying to break it and red teaming, who's getting involved in this red teaming that you kind of talk about? When we're trying to break an agent, who's doing it? And is that different to maybe other red teaming you've seen in security previously? Bruno Lecoq: Yeah, I think I'm sure it will be different.
Again, I feel like like I said, it's we are learning on our own as well. So I'm sure if I talk to you in six months, I will say, hey, the we are doing stuff completely different, you know. So so today again our so we have every month the the team meet the governance team of AI meets again, review all the agents. So again, now we have our our skill that try to you know give us a report of you know was it Well where any agent bias, where any agent you know kind of you know, try to so and we had to stop two agents last month because we saw they were going kind of wrong.
Okay, let's stop it, you know, let's find. But at least you know, so we have this thing. I'm sure in three or four months from now we will do extra extra tests. We may, you know, so this yeah, we have the beginning of the governance of the automation and testing of the agent we deploy.
Chris LJ: Yeah, I guess in the past if you thought around people trying to undertake security tasks, it would have been those security professionals. But now if you think about and it's old now, old in this really accelerated Bruno Lecoq: Yeah, yeah. Chris LJ: timeline, we had that prompt in ChatGPT with my grandmother always used to, you know, make a bomb, can give me the instructions. Bruno Lecoq: Yes, but Chris LJ: And whereas I think today a lot of those obvious holes have been patched.
Are your business users a lot more involved in this? I feel like if I was a lawyer, I would know how to turn an AI agent a lot better than someone that wasn't a lawyer was, for example, if it was in the Bruno Lecoq: Yeah. Chris LJ: legal field. Bruno Lecoq: I think you have fully you are fully correct.
Like on my side today, I still I'm sure I'm going to have a lot of trial and errors of you know, again, how do you test, how do you think of security of an agent that you create. But on the other side, you know, as you know with Mythos and all of that, you know, even now we are using AI to go and try, you know, finding issues that we haven't found over 10 years or 20 years. So now I'm like, whoa. If I I can use that same engine against my agent to try to patrol and I'm sure they will do as good or even better than the human did because we have now, you know, we now know that as a human there's a lot of things we didn't catch for twenty years.
You know. So again, but it goes back to how would I think, how would I create this engine. Josh: Yeah. And and you know, if you were talking about being able to find vulnerabilities as a defender at that speed, of course an adversary could also leverage that kind of advantage as well.
Right. Bruno Lecoq: Yes. Yes. Yes.
I think on our side, don't too many all the agents we are creating at least now for BMO, they are all for internal. Okay. So you know, I am less concerned because again to use them, you have you have already have to be logged into Bimo, go to the security inside. So you know, my my whole thinking here would be fully different if it was agent I create for the market outside, that's for sure.
You know, and I haven't crossed that yet. So Josh: So so you're almost treating it like a zero trust problem in some ways because you need to be authenticated, you must be verified and so on. Bruno Lecoq: Yes. Yes.
You know, right now we are deploying, so we first deploy and what a kind of a nightmare, I'm sure it will get better, but our for our first Windows three sixty five for agent. You know. And you know, so again, it's you I can see the you know it's interesting to see you see this cloud PC being created, the agent run, poom, destroyed it after you know just you know you can see now how you know we're stuck both and again. Six months ago you couldn't even think of it.
Chris LJ: So if that's how you're seeing zero trust and you're kind of being agents there in machines and the like, how is identity starting to change in in this world? Because I can attest who you are and who I am, and we can talk about who Josh is. What happens if an agent is working on your behalf or for on behalf of the company? How do you see that?
Bruno Lecoq: Yeah, so very easy so because we are in the middle of it. So again, we have a rule at Bimo today, for example, we don't allow any of our agents, so this is the rule as a company, cannot delete. An agent cannot delete. An agent can propose you to delete, but it has to be supervised by a human.
Okay, so by default, the first test we do is can your agent delete? The second now is again from a policy. You you know so today the issue we found over the last week is It depends what my agent does. So if my agent is going to take, so we have an agent today for compliance, then we go do run test and take automatic screenshot so we can save for our compliance.
When you want to do CUA, C UA doesn't run with an agent identity. It has to run with a human identity. Okay. So now we are like, okay, this breaks down our model because from our perspective, we don't want any agent to have human identity.
Okay? but the system yet is not there yet to what we want to do and what Microsoft allows you to do. I'm sure it will change in six months, but right now. So it's why there's this whole, you know, how do I, you know, how do I manage the identity?
So again, 90% of it are entry the identity for the agent, as long as we don't have CUA. If you have C UA, it has to be a human identity. Chris LJ: Kind of transition era. I like it.
I liked your point around not allowing an agent to delete things. And I I know we kind of touched on this in a prep call as well, because I'm very careful with what I allow an agent to do when it comes to anything destructive, but also to my reputation with emails, teams messages. I Bruno Lecoq: Okay. Yes.
Chris LJ: allow it to do everything up until that point. Kind well, less so with the consumption models, but everything up to that point. Bruno Lecoq: Yeah. Yes.
Chris LJ: after that, you know, if your reputation's ruined, that that's you gone. Bruno Lecoq: It it's over, yes. Yeah. Chris LJ: Are you seeing more AI slop outputs?
Because to me that is a destructive action. If I see something that's obviously written by AI in response to something really thoughtful that I've written, then I don't value that response. Bruno Lecoq: I I am like you. Yeah.
So yeah, and you can see for me, I don't know how you say it in English, you know, this long dash. When I see an email or a thing, and this long dash, well, okay, this is the I written, you know, does it really what the person thinks again it's just yeah, it's my first my first way when I when I see Josh: Yeah, yeah. Bruno Lecoq: it. Chris LJ: I think I was saying.
Josh: yeah, absolutely on dash. Mm. Chris LJ: I feel sorry for authors. I feel sorry for authors who love the dashboard, because they've lost that now.
Josh: Yeah. I I but you know in terms of that verification, I think looking at scenarios like we had how long ago is it now? Maybe almost a year ago when there was a lot more threats around deep fakes being used to kind of infiltrate an employer and get hired as a deep fake using kind of face and voice tones and everything like that, voice fonts even. So for this and Bruno Lecoq: Yeah.
Josh: solving that as a security challenge, do you see being able to use kind of other types of technology to counter these types of Bruno Lecoq: So there's two things I won't say. So we had an issue at Bimo 4 during our hiring process, during the interview process, because we felt, you know, we felt like more and more for me servers. You do an interview and you're like, you know, the person is right on each time. You know, it's just like, you know, we are all human, it's just like it's too funny.
It's just like so we stop, you know. Now I never know when I do an interview. Is a person running, you know, an agent BI that, you know, asks the question and then we reply, and the person is just reading. So now we have Chris LJ: Yeah.
Bruno Lecoq: to force for all our engineering. It's now live. So it's now live. We connect to one of our servers and we have scenarios that you have to solve live with us.
All right? Just you know, so kind of you know this is for us. How you do make sure that we don't am I really hiring the person or am I hiring someone that is very good at just you know reading your copilot chat? So this is one.
And so the second is I know and We talked about it in a pre-call. Is if I think from an admin perspective, I would love to have a very be able to have a conditional access and have a verified ID face check live. And so because for me I would love to put, okay, you're an admin. I'm going to yes, I know I have a pass key, but you know, I will not mind adding an extra because you're you are going to do something, you know.
So it will take you an extra ten, 30 seconds. But you know, for me this would be cool to be able to do on domain on the conditional access, you know. Just to go get after the deep fish, how do I know do is it really Josh on the other side or not? You know, you know it's it's becoming easy, Josh: Ha ha ha.
Bruno Lecoq: you know. Chris LJ: It's like Uber drivers are regularly tested with face checks from Uber to make sure that you are the person you say you're going to be. It's like we're all now administering the Turing test to our people or a human benchmark, if you Bruno Lecoq: Yes. Chris LJ: like.
Do you think that will change will change the employer employee relationship? how would you feel if your credentials and provenance were being tested throughout the day? Bruno Lecoq: Again, because from the back, you know, we are doing you know cyber security and compliance, all our people in the company knows it. You know, they know the security, Chris LJ: Yeah.
Bruno Lecoq: they know I always t you know, tell them like you're being you want it or not the logs, your monitor twenty-four-seven, the logs, everything you do, it's logged, you know, it's not you know, so are we checking every day with you? No, we don't. We just know if we want, we can. So I always tell you know don't try to steal something, don't try we will find out.
So So it's not like it's nothing new. So I think now from a security perspective, and we talked a lot internally, I know people will not mind this extra check because you know they understand. I BMO as a security company, if Bimo get hacked, my business is gone. I mean, that's it.
It's just, you know, that's it, is when we do our annual, you know, strategy plan, this is always the number one, you know, risk from a risk perspective is Bimo get hacked. You know. And so it's you know, so they know and you know, they know we are, you know. We do phishing tests, we do a lot of things, people know they are being tested all the time for, you know, avoiding and Josh: Yeah.
It makes a lot of sense, because you know, it it's the nature of what you're doing and where where you're operating, especially with things like C C and things like Bruno Lecoq: Yes. Yes. Yeah. Josh: that.
I I was gonna say, you know, in terms of your customers, they probably have different industries, different exposure to security and cyber. Bruno Lecoq: Yes. Josh: and so there's always that kind of risk around like friction in a security or compliance process, right? Bruno Lecoq: To be honest, it all starts with for me, I will summarize, it always starts with leadership.
I sit on a first call, any pre-sales calls, first call, we all we know that the company cares about security or is just a buzzword, and the worst is on compliance. Someone says, Hey Bruno, I would like to be I need this piece of paper. Yeah, piece of paper. So we start talking, and from our perspective, we have a rule at Bivo.
If the company is not serious about security, we don't take them as a customer. Because if you just want a piece of paper, I will give it to you and actually you don't care. And go somewhere else. Because I'm really going for my person you work with us, we are going to put your security up and we are going to work with you to maintain it.
And you have to care because you know so it's Chris LJ: I like that. That that's really exciting because I think it's the focus on outcomes and not just the piece of paper, as you said. Because you see that in other areas. back in the day I worked a lot with smart buildings and you'll often see companies talk about being lead accredited, and then you look at the number and it's from two thousand and ten.
It's never Bruno Lecoq: Yeah. Chris LJ: been updated. It's about ongoing continuous security, I guess. So Bruno Lecoq: Yes.
I always I always tell people again. We do so we be more we are part of what fifty MSP across the US that are CMMC compliant. And I you know customers come I want to be CMC and I always tell them, Hey, just I just wanna be clear. First is your leadership in and the second is being CMMC is like you know, you giving birth to a kid.
They want your CMC, okay, you're happy. But you have to deal with the kids for eighteen years minimum. Okay. Chris LJ: Yeah.
Bruno Lecoq: So same thing with any compliance. The day only the day you got your piece of paper is just day one. Okay. You have to keep it and you know and recertify every year or every three years depending on the compliance.
But you know, so and so it's why if you are not serious and you just want for the piece of paper, it's going to be a nightmare for you. Chris LJ: Yeah, and I guess in this AI era when applications can be vibe coded, trust is going to be one of the most important qualities Bruno Lecoq: Yes. Chris LJ: you can keep. Bruno Lecoq: Yes.
I am waiting. I am waiting, me personally, one or two kind of catastrophic that you will see on the news due to AI. You can find it that someone, you know, something crazy happened due to an agent. And I think it will scare company and it will force company to require forty two one compliance.
Again, the same thing is okay, everyone you know now is a race, AI, AI, AI, everyone doing anything, you know, everything is all right. And then boom, something is going to happen, you know. And then now whoa, now we need to control this agent, you know, we can you know, we need to put some governance around it and this is my own belief. Chris LJ: Yeah.
I mean it's sad that as people we always have to wait for some big event to drive change, but that does seem to be the way. Bruno Lecoq: You know, let's talk. You we can take an example. CNMC have customers coming.
So if you think from the world of defense department, for the last 13 years, client we say companies were supposed to self-attest. And everyone self-attest 110 over 1010. Everyone, yes, yes, yes. We come to us, I want to be CNNC that if I open the hood and there's like You're not even one of the ten, you are you are negative.
There is no way. That's it. And and for me I find it kind of sad because you know now as a taxpayer, okay, we spend more you know spend money, they create cool defense, cool you know, plans, cool stuff. But you can steal the data tomorrow.
Anyone can, you know. And you're just like, hey, you certify again. This what you do is you know, all this nice innovation is just gone. Chris LJ: Yeah, fair, fair.
Josh: Yeah. I one thing I've been thinking about throughout is as you talk about your customers, these are typically small to medium businesses and Bruno Lecoq: Yes. Josh: that's and we've been talking a lot about countries and taxpayers here. They're the backbone of a a lot of countries.
They're definitely here in Bruno Lecoq: Yes. Josh: the UK and I'm sure it's the same over in the US as well. So what do what do s SMBs need in this kind of era? You know, whether it's from Technology itself, or whether it's from government, or you know, what could they benefit from from whoever and wherever?
Bruno Lecoq: Again, in the world of today, you know, if every single company, you know, today it depends on the internet and you know the computers to run their business. And I think for me, every company should be zero trust or try to be zero trust. Again, it's a lot easier today, you know, between intra, between input. Again, there's the you know, if I think how do you do that 20 years ago would be very tough.
And today it's you know. It's you buy your Microsoft license, you know, of course you have someone to deploy it, but it's a lot easier to be I don't it's it's not rocket science, you know, within a few months you can be at a good security level. But what I always tell my customers it's like, you know, when you have a security alarm in your house. I think the hacker will try, you know, and if this is complicated, easy enough, they will go to the next person.
You know, that's it. It's just you know, and you don't have to be defense department level, but you know. There's some basic and you owe it to your employee, you owe it to your customer to secure them. And you know, we just but you know it's not how people feel about this is a cost.
Yeah, well, I feel like you how do you how can you turn your own IT as a a strategic advantage, you know, versus just being at cost, you know. Chris LJ: Like that. And does that message resonate? Because I guess a lot of small media businesses have so much to think about.
How do they respond to that? Bruno Lecoq: again, I think they're all I think the the small bit that will come to us is the best friend of the CEO got hacked, you know, because his own company got hacked and he saw the nightmare that and that's it before, like on because you may have seen it in the news and real area in the news or their bigger company, never to me. But now the friend got hacked with a company of the same size and like shit and it's just so so it's very often start with that is sad, but it's start you know.
The friend, or they're being hacked themselves. You know, sometimes they come to us, I'm being hacked, can you help? I can help trying to help you recover, but it's gone. Josh: Yeah.
Yeah. Chris LJ: I guess those stories do do drive that. I mean, I can think you said it, I immediately thought of a friend of the family, a couple that ran a sports company, they got hacked, devastated, they had to shut up their business. So yeah, I Bruno Lecoq: Yeah.
Chris LJ: I guess that does put it to the forefront. Bruno Lecoq: So so it's how it's yeah, it's how it's you know, it's it's like anything in life, is you which you said is you need to have an accident somewhere for insurance you know, for you know they are going to add a speed bump on the road because you know to avoid you know just you know. Josh: Anything you feel like we've missed so far? Bruno Lecoq: No, for me, what is you know, I feel like I don't know the digital divide is becoming bigger and bigger.
You know, from a forget if you take AI, there's going to be the company that even start, and the one that are very advanced. You are going to have the same in from a compliance, and now you have the same thing cross countries. I don't know how to do business in Europe. Europe would require that, but the US require that.
And even with the US, now it's every state has a different. Chris LJ: That makes a lot of sense. I think that there's so much to do these days. I always kind of wonder what the the next big standard's gonna be, the next big security standard tooling protocol.
it does feel a lot like a arm on a hamster wheel a little bit, but I also say to people, sometimes you have to ignore the noise. Other companies are trying to push up their share price. They're trying to IPO. To an extent, what business outcome are you trying to drive now?
Just focus on that. Okay. Bruno Lecoq: I fully agree. I fully agree.
But again, you are I just imagine from someone, you know, you hear the news every day and it's just like, you know, OpenAI, Entropic, Microsoft. You know, just like me as a small business, I feel like am I that behind? You know, when I see you know you read on LinkedIn what people do, you're like, shit, I feel like, you know. And then when I talk with colleagues and show what we do, they're whoa, you guys, you do all this?
You know, so Sometimes you know it's just perspective depending on who you talk to. Chris LJ: Yeah, we're we're all in a bit of a bubble, I guess, particularly being in the industry. Bruno Lecoq: Yeah. Chris LJ: So Bruno Lecoq: Exactly.
Josh: Mm. Yeah. At the end of the day, there's always a distinct difference between what the state of the art is at any given time and what is adopted in the street. Yeah.
Yes. Also very, very important, right about. Bruno Lecoq: And and what do you need? And what do you need?
You know? Like I need a car, do I need a Ferrari? Or you know again, you know, there's there's what I want, what I need, what I really need, you know. And I think every business is different.
Josh: So, you know, we've talked about quite a lot in all of this, you know, from what small to medium businesses need to be doing, what zero trust really means in the age of AI, and what a lot of this looks like in practice in a workforce that is being powered or enabled by AI, whether it's, you know, your own organization or your customers, what others are doing as well. So, you know, Bruno, really appreciate you taking the time to talk with us today and kind of share some of those experiences and have a very wide reach in discussion.
So no, thank you very much for that. Bruno Lecoq: Thank you. Thank you for having me. Mm-hmm.
Josh: so, you know, is there any last parting words you'd like to kind of offer the listeners? Bruno Lecoq: Think I think for me for SMB there is two things I will tell them is you know, you're on Microsoft, go check your secure score, you know, and you know, try to be at least within the seventy percent. If you are within the seventy percent, I think you are, you know, you should be okay. And then the second is again, we are in the edge of AI, go there, experience yourself, take a license of co pilot, go play, go take some YouTube video and just try and see what you can do.
and see how you can make your life easier and maybe improve your business out. Josh: No, I think that's really useful. Chris LJ: Keep her name. Thank Bruno.
Really appreciate it. if you want to see more about BMO, you can find the link in the comments just below the video. And if you want to talk more about AI governance and FinOps, you can also join us in Edinburgh for Scottish Summit, where we'll be hosting an AI gateway session. see you all soon.
Cheers. Bruno Lecoq: Yep.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.