
Security You Should Know · 2026-08-04 · 18 min
Key moments - from our scoring
Substance score
55 / 100
Five dimensions, 20 points each
Organizations struggle to prove they can actually recover from cyber incidents before disaster strikes - a gap that's expensive, resource-intensive, and often overlooked until a crisis forces the issue. Curtis Simpson, CSO at Gambit Security, discusses how the platform solves this by creating a business-aligned recovery model that goes beyond traditional backup and disaster recovery tools. Rather than technology-focused point solutions, Gambit maps an organization's minimally viable company (critical business capabilities and their corresponding digital assets), then validates recoverability across cloud, hypervisors, backup platforms, and infrastructure-as-code. The platform achieves 85% accuracy out-of-the-box by combining internal signals (asset tags, netflow data, CMDBs) with external intelligence about industry requirements. Adam Palmer, CISO at First Hawaiian Bank, and Howard Holton, former CEO of Gigaom, probe the practical challenges: How does this differ from existing CSPM, backup, and DR tools? What evidence can actually be reported to boards? Gambit's answer centers on continuous assessment, identifying gaps and action plans, and tracking progress toward business-defined recovery targets - positioning resilience as a measurable, reportable, and continuously improvable security practice rather than a one-time compliance checkbox.
Gambit provides centralized, business-capability-aligned visibility across all backup platforms, hypervisors, and infrastructure recovery tools, mapping minimally viable company requirements back to digital assets and identifying gaps like missing backups, immutability issues, and IAC drift - whereas traditional tools focus on individual technology-level recovery rather than end-to-end business capability recovery.
Gambit achieves 85% accuracy out-of-the-box by combining internal signals (asset tags, inventory data, netflow information, metadata integrations) with external intelligence about industry requirements and competitor disclosures, then requires human input and validation to refine the model further.
You can report whether the minimally viable company is recoverable within defined timeframes, map recoverability to business units or regions, provide resilience scores, identify action plans to close gaps, and track progress toward recovery objectives - enabling executive-level conversations grounded in technical reality rather than assumptions.
Gambit serves small, mid-size, and Fortune 100 customers; for smaller or less mature organizations, it provides surgical priorities and clear starting points for improvement, while for highly complex environments it streamlines manual processes like immutability validation across multiple backup platforms.
Currently Gambit focuses on on-premise hypervisors and cloud environments, not mainframes themselves, but helps organizations recover everything on the periphery of mainframes - which often causes the longest and most impactful outages.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers moderate substance on the specific problem of proving recoverability and Gambit's positioning, but pads significantly with CEO pitch language, repetitive framing of the same concept across multiple speakers, and broad statements about AI and disruption that add little concrete insight. The discussion of 'minimally viable company' mapping and backup validation is useful, but the conversation circles back repeatedly without diving deeper into novel mechanics or surprising findings.
85% correct out of the box. It's a combination of what you've already done and what we learn about you publicly.
we are fundamentally telling you what are the business capabilities that matter most to you, those corresponding business systems? We're relating the digital estate back to those
The core insight - that proving recoverability is expensive and often untested - is well-established in DR/BC circles. The framework of mapping business capabilities to recovery objectives and validating across hybrid backup platforms is sensible but not particularly contrarian or first-principles. The episode does not challenge conventional wisdom; it packages existing DR problems with a vendor solution using familiar resilience vocabulary.
trust but verify model that didn't work for long in the vulnerability management space. And we eventually had to right that wrong. Now's the time to fundamentally right that wrong from a security perspective.
change, innovation and threats are now moving at the pace of AI
The guest lineup includes Adam Palmer (CISO at First Hawaiian Bank, a regulated institution) and Howard Holton (former CEO of Gigaom, with direct recovery disaster experience), both of whom bring real operational context. Curtis Simpson (CSO at Gambit) is a vendor representative and thus inherently less objective, though his background in mainframe environments adds some credibility. The mix of a practicing CISO and an experienced CIO/CTO perspective is solid but not exceptional - no Fortune 100 CISOs or operators managing multi-billion-dollar recovery scenarios.
Adam Palmer, CISO at First Hawaiian Bank
Howard Holton, the former CEO over at gigaom
The episode lacks concrete data, named customer examples, actual metrics, or timelines. While Curtis mentions 'a Finserve company' spending 'thousands of hours' on immutability validation, there are no named companies, no specific RTO/RPO targets, no dollar figures for recovery costs, and no benchmarking data. The '85% correct out of the box' claim is the closest to a metric but lacks context on what accuracy means or how it was measured. Most claims are illustrative rather than evidentiary.
we actually chatted with a Finserve company just the other day who's spending thousands of hours a year just validating immutability.
85% correct out of the box.
Howard and Adam ask reasonably pointed follow-up questions about unique capability differentiation, scope of the 'minimally viable company' mapping, human input versus automation, and board-level reporting. However, Curtis's responses are polished pitch-speak that often deflect or broaden rather than answer directly. The host does not press back on vague claims (e.g., 'AI-augmented hackers'), avoids asking about competitive comparisons, and does not challenge Curtis to define failure modes or limitations rigorously. The conversation is professional but lacks productive tension.
Can you help me understand what unique decision or capability your tool is offering that my existing tools don't already provide? Collectively?
how much of that is human input, how much of that is signal, what is the kind of automation, what's the lift expected from the team, and then how much do you stand behind the accuracy of it when something happens?
Computed from the transcript - who did the talking, and the words that came up most.
In this episode, Curtis Simpson , CSO at Gambit Security, explains how Gambit moves organizations past that guesswork by continuously mapping a company's minimally viable business capabilities and validating whether the infrastructure, backups, and recovery processes behind them can actually deliver within the timeframes the business requires. Joining him to pressure-test the approach are Howard Holton , former CEO of GigaOm, and Adam Palmer , CISO at First Hawaiian Bank . Want to know: Why do so many disaster recovery plans hold up on paper but fail the moment they're actually needed? What's the real difference between having something backed up and proving you can recover it? What is a "minimally viable company," and how much of mapping it is automated versus built on human input? What happens when your infrastructure fails today, versus what Gambit's roadmap has planned for tomorrow? What should actually land in front of your CEO or board to demonstrate recovery confidence? Is there an organization too small, or too mature, to get value from this kind of resilience assessment? Why does decades-old infrastructure like the mainframe often cause the longest, most damaging outages?
Transcribed and scored by The B2B Podcast Index.
Speaker A: Connecting Security Solutions with security leaders. Security, you Should Know, starts now.
Speaker B: Welcome to Security youy Should Know. I'm, um, your host, Rich Stroffolino. Today we're talking with Gambit Security and what they are doing in cyber resilience and never has seemed like a more timely space to be in here. And the problem they're really addressing, I think, is the key concern that we're all wonderfully discovering in real time. It's how do you actually prove recoverability? Great to say you're resilient, but how do you prove it before the worst happens Here? Helping us figure out why this is a problem and figuring out how Gambit is playing in this space are Howard Holton, the former CEO over at gigaom, um, and Adam Palmer, CISO at First Hawaiian Bank. Howard, I want to start with you. Why is proving recoverability, why is that a problem? Shouldn't that be stage one? Like, the first thing you would want to know is, can I actually recover?
Speaker C: You would think so, but it feels an awful lot like people would rather
Speaker B: prepare a new resume, so resume generating events rather than.
Speaker C: It's absolutely an rge. I've been through it a few times where we think everything is good, we go to restore after some sort of failure, only to find all of our assumptions were wrong and they're not necessarily 100% wrong, but we didn't have a clue what we were doing in recovery. And I've never had a board more interested in what I'm doing as a CIO or a CTO or a CISO than when I'm in recovery. The problem is it's really expensive. It's, uh, effectively an all hands on deck type of situation. And the fewer people I involve, the less thorough I am. The less everyone knows where their job is, the less I'm able to actually certify that this works. If I don't have people that can test, if I don't have proper procedures, if I don't have any of this stuff done, and you really kind of have to do it a lot more than once, otherwise it's never a muscle, right? And we don't need to do it 10,000 times or do a Malcolm Gladwell 10,000 hours sort of thing. But we do need to do it enough that everybody knows what the role is, everybody knows what the goals are, and we can actually certify that this stuff works.
Speaker B: Adam, what about for you? Why is proving recoverably so hard for you? I mean, are you on board with Howard here? Is it just a cost versus effectiveness spectrum that uh, is kind of impossible to manage.
Speaker D: So I think what question I have today is what exactly has been proven when we look at the recovery, you have to look at are configurations consistent? How do we evidence that our applications have actually been restored and that functionality has been tested. So for me, recovery proof can sometimes just become a marketing synonym for posture management. So what I really want to understand today is how is there evidence and proof of, of recovery? And as a regulated company, this is critically important to me to be able to establish that.
Speaker B: All right, well, trying to get answers to some of those persistent problems here, we're going to be talking with Curtis Simpson, the CSO over at Gambit Security. Now Curtis, to start out, we're going to be answering three essential questions helping us set the table here. How do I explain the value of what you're doing to my CEO? What does your solution do and what does it not do? And what is the pricing model? Can you help us out here?
Speaker E: Yeah, you bet. Thanks for that. So explaining the value does start a little bit with explaining the problem, especially when you're talking to a CEO. The reality is change, innovation and threats are now moving at the pace of AI. And the other reality is the business fundamentally demands 24, 7 availability of what matters most in addition to compliance, obligations and everything to continue to evolve on this front. In that light, and considering that security is fundamentally the digital risk management entity of the organization, we must continuously assess our ability to not only prevent but also recover from cyber disruptions and disruptions in general. Gambit is enabling CISOs and security teams to continuously assess their ability to recover the minimally viable company end to end and truly mean end to end. Gambit is not a backup solution. Rather it integrates with your cloud, your hypervisors, the backup and infrastructure capabilities that you use to actually recover infrastructure and backup end to end and provides a central layer of visibility and optimization into assuring recovery in alignment with business requirements. So not just can you recover, can you recover the capabilities that matter most in alignment with what the business actually requires from a pricing perspective, it's a base platform fee and then resource based pricing from there tiered based upon the volume of resources and obviously as you go up those, her resource costs go down. And it's not a nickel and dime pricing model, it's truly price based upon those tiers.
Speaker B: Fantastic. All right, I think we've gotten enough to to ask some pertinent questions here, so I'm going to open up with you, Adam. What are the questions? Do you have for Curtis and about Gambit Security.
Speaker D: So I think my first question is most enterprises, including my own bank, where I work, we have tools like cloud security, posture management, backup capabilities, cmdb, disaster recovery tooling. Can you help me understand what unique decision or capability your tool is offering that my existing tools don't already provide? Collectively?
Speaker E: You bet. So first and foremost, we are actually mapping your minimally viable company. So we are fundamentally telling you what are the business capabilities that matter most to you, those corresponding business systems? We're relating the digital estate back to those and then we're looking holistically across that entirety of, uh, the digital estate, mapping back to those systems. So if you've got, say, a hybrid application that's using multiple backup platforms, the challenge you have today with backup solutions is they're technology based. You're looking at, do I have this thing back up, within what time frame can I recover it, et cetera. They're not looking at it from a business capability level. We are, we're giving you centralized visibility into not just the backups, but infrastructure as code, infrastructure recovery. We're looking at this end to end in terms of the actual assets and resources that roll up to an application, whether or not they're backed up at, ah, what frequency they're backed up, whether or not you can trust those backups in terms of immutability and the security of those backups. And in addition to that, looking at elements like IAC and infrastructure replication and recovery so that you know again, that you can actually recover infrastructure data and operations for that entire application.
Speaker B: Howard, you're a man of thoughts. What other questions do you have for Gambit Security here?
Speaker C: Yeah, talk to me about this Minimum viable company, minimum viable recovery, kind of scoping and measuring how much of that is human input, how much of that is signal, what is the kind of automation, what's the lift expected from the team, and then how much do you stand behind the accuracy of it when something happens?
Speaker E: Yeah, 85% correct out of the box. It's a combination of what you've already done and what we learn about you publicly. So everything in terms of what matters to your industry, what matters to your company, how that's been publicly disclosed, whether it's your company, competitors, et cetera. We're also looking at what you've done internally in terms of tagging, what your asset inventories are telling us, both in terms of what those assets are, how they communicate with each other, et cetera. We're looking at netflow information coming from the cloud. We're looking at all of the different data points we can glean from integrations in your environment, metadata based integrations with cloud hypervisors, et cetera. And then what we're seeing in backup solutions, what we're seeing in terms of those infrastructure replication elements, what we're seeing in terms of asset inventories and will, even if you have them, if you do, um, in terms of them being up to date, BIA documentations and the like. So we'll take as much as you've got and then augment that with what we know and can see externally about who you are and what matters.
Speaker C: And then when something goes wrong, what happens? Like when my something goes wrong in my infrastructure, not something goes wrong with your platform.
Speaker E: So today we are about proactively preparing you for that event. As our, uh, roadmap continues to evolve, we will eventually become your centralized orchestration layer for the event itself. But in this moment is about helping you assess what can I actually do, how quickly can I actually do it for the things that matter most to my organization? And then being able to identify those action plans to drive you to the point where you can recover end to end business capabilities within say, an hour, if that's what the business demands. So we're looking at the actual recovery timeframes compared to your business targets, defining the action plans for those applications and enabling you to proactively prepare for that event as opposed to orchestrating the recovery from the event itself.
Speaker C: Okay, so I just want to be clear. So currently the result is something that I can think of like a runbook, a series of runbooks, a uh, recovery kind of model, whatever it happens to be. That also includes like, hey, today you're missing these seven things that you're that your industry likely needs. You need to go fix those, let us know when they're fixed, we'll then update the runbooks kind of thing. Is that accurate?
Speaker E: It's that, but it's also more than that. So let's say, for example, you've got inconsistent backup policies for a hybrid application. In some cases you've got no backups that may exist for a middleware capability. We can help you actually optimize that centrally against those varying different backup platforms. We can tell you which backups can be trusted, which can't be trusted. We can tell you to what extent they're immutable, not immutable. We're giving you insight into IAC drift that's actually going to prevent recoverability. So yes, it's about actually looking at what does this plan need to look like, but we're actually enabling you to close the gap from a resilience or recovery exposure standpoint, proactively with those stakeholders and infrastructure and otherwise such that again, you know that you're technically capable of delivering an outcome. So if you do have a compromised asset, if you do experience an AI uh, oriented insider threat, you know that you can recover an end to end application within that given time frame based upon what your backup layer looks like, what your infrastructure layer looks like. And we're fundamentally helping you identify those exposures and gaps and then the action plans that need to be taken with your partners and clients crime to actually deliver on those recovery outcomes based upon likely disruptions.
Speaker D: Uh, so one question I have is I think about that I'm responsible for reporting. And so with your tooling, what information would I actually or would you recommend that I put in front of my CEO or my board? Is there a resilience score? Is there expected downtime? Can you estimate potential financial impact? Or how do I show the confidence for them in advance that our critical services will meet our recovery objectives?
Speaker E: Yeah, great question. So we've got a number of ways you can reflect that based upon what makes sense within your organization. So firstly, we're going to give you the actual ability to say, this is our minimally viable company. Here are the capabilities tied to that that are recoverable. Here's the timeframes within which they are recoverable. For those that aren't, here's the action plans that correspond with actually moving these to the right locations. So if you've defined those business targets, great. We're helping you identify whether or not you can address those targets. So again, recover, not recover, recover within those given timeframes, understand what those action plans need to be to reduce that overall or to improve your recoverability and move it in the right direction. We are able to give you resilience scores, but we're also able to just give you that straight math in terms of can we actually recover the minimum viable company within those expectations that we have as an operation, whether those contractual obligations, compliance obligations, or just continuous business operations in terms of what we know is critically required and needs to remain critically available? And you're able to not only track where you stand today, but you're able to actually report on your product progress towards that. So here's our action plan, but here's also the actions we've taken to improve this. We're also able to give you the ability to not just understand it at a system level, but to map it back to logical business structure, give you the ability to report on can I recover end to end business units, entire regions, locations, what does that resilience score look like for them? What does recoverability look like for them? So that you can have a board or executive level conversation around what reality looks like and what you're driving towards to meet those expectations.
Speaker D: They have so the bank that I work at, we're roughly a $30 billion asset bank, but they're smaller organizations. I've worked at larger and I worked with small organizations. Is there a type of organization that's not mature enough or have a sufficiently complex environment to benefit from your tool? Or what is the type of organization? Or is there a, a level of complexity where you think that you add the most value?
Speaker E: The reality is we've got small mid size and massive Fortune 100 customers and quite frankly, we can help you validate and optimize where you think you are from a maturity perspective. If you are highly mature, highly complex, helping you understand this across hybrid applications, where it may be a challenge today, as an example, we actually chatted with a Finserve company just the other day who's spending thousands of hours a year just validating immutability. They know they need to be immutable. They have ways of validating that within their platforms. Thousands of hours though, are being spent doing that manually across varying platforms. We do that centrally, immediately, and can even streamline it such that you're just automatically addressing those gaps should you have them within smaller organizations or midsize organizations? There's often a, uh, question is where do I start? Where do I go from here? What do I actually mature? We're about giving you those surgical priorities. Here's again, what matters most and what you should actually focus on to drive recoverability in the right direction. Should you be worried about cyber disruptions? Disruptions because you're adopting AI at an accelerated pace. And in terms of who it matters to, I would say it runs the gamut of high innovators, but also just folks that truly care about resilience. If availability matters to you, gambit matters to you because you're assuring availability.
Speaker C: So with Fortune 1000 being on the list, and I'm sure this is an obvious answer, but is mainframe within your scope of capability?
Speaker E: It's a great question on premise today, but mostly hypervisors. What we're finding with most of our customers today, today is some of their most credible and sophisticated capabilities are actually around the technologies they've had for 10, 20, 30 years. And coming from that environment myself, where I was at a massive food service company years back, we knew how to recover the mainframe. We didn't know how to recover anything on the periphery of the mainframe. We didn't know what that looked like. As a whole, we're helping even those companies that were not yet focusing on the mainframe. We are addressing everything around the mainframe that commonly ends up actually causing the longest outage and the most impactful outage because again, it's been on the periphery of those technologies we've been using for the last 20 years.
Speaker B: All right, Curtis, what's one thing we didn't ask about that we need to
Speaker E: know in terms of what we didn't ask about? I, uh, think one of the questions would be around why now? We've talked about recovery and resilience for a long time. The reality is, on the cyber side or on the security side, it's always been a trust but trust model. It's never been a trust but verify model that didn't work for long in the vulnerability management space. And we eventually had to right that wrong. Now's the time to fundamentally right that wrong from a security perspective. Because today, post digital transformation, yes, we're always going through them. But post digital transformation, something matters in our company in terms of digital capabilities that can't go down because if they do, we lose customers and clients to competition. We don't maintain compliance that's required for regulatory obligations or even quite frankly, those contractual obligations that will result in loss. We today are facing this moment m where anything can go down at any time. Where we've got AI augmented hackers, we've got innovation at scale occurring through AI. Disruption is fundamentally inevitable. But disruption should not be material. This is the moment for security to truly assess and manage this risk and and minimize the materiality of disruption at scale.
Speaker B: Well, that's just about it for this episode of Security youy Should Know. To learn more, head on over to Gambit Security. If you have any feedback or questions about this show, send it to us feedbackisoseries.com a huge thanks to Howard and Adam for helping us learn more about Gambit Security. And a huge thanks to you, Curtis, for your time and being game developers. To answer all of these questions. And thank you for listening to Security you Should Know.
Speaker A: That wraps up another episode of Security youy Should Know. If you like this program, please subscribe, tell your friends and leave us a review. All companies showcased on this program are sponsors of CISO series. If your company would like to be spotlighted and interviewed by our security leaders. Go to our contact page on CISO or just email us at, uh, infoisoseries, uh dot com. Thank you for listening to Security. You should know connecting security solutions with security leaders.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.