
SOC Unlocked: Tales from the Cybersecurity Frontline · 2026-04-09 · 52 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
Michael Myint, CISO at a DME healthcare company serving 4 million patients across 800+ US locations, brings 30 years of security experience - including 15 years in Big Four consulting - to a candid discussion about AI's real role in cybersecurity. He dismantles the common misconception that AI can simply be plugged in to handle security autonomously, explaining that it's pattern recognition and code, not cognition. Instead, Myint details measurable wins: AI-powered SOC tools filtering noise from massive telemetry volumes (SIEM, EDR, SASE data), GRC automation for repetitive questionnaires using LLMs to consume past responses and policies, and new AI agents setting up secure VM environments to gold standards upfront rather than auditing gaps after deployment. On the threat side, he flags deepfake and synthetic media attacks (voice cloning, video manipulation) as the dominant emerging technique of the past year. Myint advocates aggressive adoption of cloud-native and AI-native solutions - he's deployed an AI-powered MDR and SIEM (end of Q3/Q4) - and warns that reluctance to pilot early-stage AI startups puts organizations at existential risk, given Moore's Law is now outpaced by AI advancement every three months. His advice: identify internal champions, run pilots in willing business units, and lock in early-stage pricing before these solutions mature and costs climb.
The largest misconception is that AI works like the human brain and can autonomously handle security. AI is pattern recognition and code based on how it's trained - it lacks cognition and human-like thinking, and plugging it in without proper oversight actually introduces more risks than benefits.
AI helps filter noise and false negatives from massive telemetry volumes (SIEM, EDR, SASE data), allowing analysts to focus on true positives and critical risks. When properly onboarded with a three-layer approach (AI filtering, MSP/MDR L2 analysis, internal team review), it dramatically reduces investigation time by consolidating data and providing context in one console.
Deepfake and synthetic media attacks, where AI creates convincing images, videos, and speech patterns to impersonate real people for phishing and fraud. The technology can duplicate mannerisms and voice characteristics from minimal source material (even a LinkedIn photo or short podcast clip).
AI tools now consume past questionnaire responses and security policies to automatically populate responses to incoming compliance questionnaires with intelligence about endpoint, cloud, and data center posture - reducing what used to be hours or days of manual work to near-instantaneous responses.
He recommends aggressive adoption: identify internal champions, pilot tools with willing business units, lock in early pricing before costs rise, and recognize that organizations not keeping pace with AI advancements are putting themselves at existential risk, as malicious actors now operate as billion-dollar enterprises.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode has a handful of genuinely useful ideas - revenue-coverage framing for board metrics, three-layer SOC onboarding, and AI agents for VM gold-image provisioning - but these are buried under long stretches of mutual agreement, host anecdotes, and repetition of the same AI-is-fast observation. The ratio of novel claims to filler is low for a 52-minute runtime.
I just protected, um, $800 million in revenue for the organization by implementing these six foundational security practices, um, for that unit
leveraging AI agents to set up your VMs following a gold standard and making sure that you're preemptive about the security controls being put in place rather than doing an audit afterwards
The ideas presented - deepfakes are scary, AI isn't human cognition, fundamentals still matter, CISOs should say yes instead of no - are well-worn takes in cybersecurity circles. The revenue-coverage metric framing is the most practically differentiated point, but even that is incremental rather than contrarian or first-principles.
malicious actors is a huge business now. It's bigger than some corporations in the U.S.
security isn't necessarily entry, uh, level position. I think you have to be familiar with the environment, the network, uh, certain types of tooling, um, uh, before you can actually get into security
Michael Myint is a genuine four-time CISO with 30 years of experience spanning Big Four consulting, a large digital transformation company, and now a publicly traded healthcare operator serving 4M+ patients - a legitimate practitioner who has operated at real scale. However, this is a mid-market company and the transcript reveals limited depth beyond what a competent senior security leader would be expected to say.
I've been in information security for 30 years. Uh, this year I've spent at least half of it on the consulting side
I'm the, uh, chief Information Security Officer at a, um, DME healthcare company... We provide medical devices in various areas of home healthcare to, um, 4 million plus patients across the United States, with, uh, over 800 locations
There are isolated concrete details - $800M revenue protected, 20,000 endpoints from M&A, 10% assimilated, AI-powered SIEM deployed end of Q3/Q4 - but the majority of claims are unattributed and vague: unnamed tools, unnamed companies, unquantified improvements, and hand-waving assertions like 'malicious actors is bigger than some corporations.' No studies, vendor names, or benchmarks are cited.
we've implemented, you know, BCP doctor tests for three out of the 10 and we have a multi year plan to get 100% coverage
we have uh, acquired, you know, had this much M and A activity, um, and now we brought in 20,000 new endpoints now through the migration process, now we've assimilated, you know, 10% of them
The host is personable but consistently restates what the guest just said rather than probing deeper, inserts lengthy personal anecdotes that consume airtime, and never challenges a claim. Questions are broad and leading, and the episode's best moment - the revenue-coverage metric - is actually the host paraphrasing the guest back to him for confirmation rather than extracting a sharper insight.
So you're saying, if I hear you right, that we can't just plug it in and it's going to handle security for us, like, you know, some folks are saying on the interwebs
I love that. Um, I too have seen it, uh, seen AI and ML be very useful in those, uh, circumstances
Computed from the transcript - who did the talking, and the words that came up most.
Healthcare security leader Michael Myint joins host Mick Leach on the latest episode of SOC Unlocked to explore how AI is changing security operations, what modern leaders should expect from emerging vendors, and why the fundamentals still matter. Drawing on 30 years in information security, Michael shares a practical view of where AI is delivering value today - and where hype still outpaces reality. Together, Mick and Michael discuss deepfakes, AI-powered SOC workflows, startup innovation, board-level reporting, and the career habits that separate good practitioners from future security leaders. The conversation lands on a clear takeaway: teams should embrace modern security architectures, but never at the expense of sound judgment, strong foundations, and ownership.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Foreign. Hello, and welcome to SOC Unlocked Tales from the Cybersecurity Frontline. I'm Mick Leach, your host and guide on this exciting adventure into the SoC universe. In each episode, I have the tremendous pleasure of chatting with various cybersecurity professionals about the latest in industry news, uh, emerging threats, practical strategies to keep your organization safe, and much more. And this week I am excited to. Michael meant, uh, on the. On the podcast. So, Michael, welcome to the podcast. We are so grateful that you are here.
Speaker B: Thanks, Mick, for having me.
Speaker A: Absolutely. All right, well, as we jump in here, uh, our listeners know, our longtime listeners know, we love to hear a little bit about you, then dive into some of the, the emerging topics, uh, of today. AI will be one of them. Just, you know, as we approach rsa, you can't have a conversation without saying AI and at least a thousand times, uh, being a cybersecurity professional. So, um, we'll honor that requirement and then we'll move forward, uh, and then we'll talk a little bit about, uh, you know, the, the AS folks are looking to build their careers in cybersecurity. Would love your, uh, your. Your experience about that, your recommendations on how they should tackle that, and then we'll kind of talk about, uh, the future of things as well. Sound like a plan?
Speaker B: Sounds good.
Speaker A: Right. All right, well, um, first off, I would love if you could tell us all about your current role, um, you know, how you got here, how it shapes your organization, um, kind of your journey into cybersecurity. Sure.
Speaker B: So I'm the, uh, chief Information Security Officer at a, um, DME healthcare company. So DME Direct, uh, medical equipment. We provide medical devices in various areas of home healthcare to, um, 4 million plus patients across the United States, with, uh, over 800 locations across the United States as well. So we work with providers to identify, uh, customers and we support them from, um, bringing, uh, equipment to their homes, giving them training, and then replenishing the inventory as the need, uh, comes up, um, on a regular basis. So I've been at the organization for about a year and three months now. Um, we are heavily, uh, compliance driven because we are healthcare, um, and we are also a public company. So we have Sargonz, Oxley and other, um, public considerations to take into account. Um, prior to this, I, uh, was working at, uh, other healthcare organizations and overall I've been in information security for 30 years. Uh, this year I've spent at least half of it on the consulting side. So I worked for a number of the big four and I, uh, helped Grow practices in network security, identity access management, um, and then I did some consulting on my own for a number of years. When I finally went back to corporate uh, world uh, I took on my first role um, in a security leadership capacity at a large digital uh, transformation company. Spent about seven years there growing the program, uh, really helping our global workforce uh, take into uh, account security considerations as there was a huge uh, evolution with uh, digital transformation and uh, just security uh, in general. Um, and then since then I've uh, changed uh, across multiple companies and now I'm on my fourth role as a ciso.
Speaker A: All right, awesome. Well listen, as, as the father of two special needs kids, uh, you know, one of whom uses durable, durable medical equipment uh, on the daily. Let me just say I'm grateful for, for your work protecting uh, the companies that are manufacturing these things. You know it's uh, it's, it reminds me of goodness I'm going to date myself here a little bit. But years ago at uh, I believe it was def con when they were demonstrating uh, some of the world renowned hackers out there were, were demonst how dangerous things can be as they were hacking things like insulin pumps for example. Um, so it just. Pardon me, it's just a reminder um, that you know cybersecurity is important all over the place but particularly as it, as it relates to medical things. So um, so my thank you to you for, for your hard work to keep us safe, keep my kids safe. Certainly grateful for that. So uh, as we dive forward into some of the questions here, Michael, one of the things that we love to talk about today, as I mentioned early on we will talk about A.I. um, but what are the most uh, common misconceptions that you hear about AI and cybersecurity these days?
Speaker B: Well there's probably quite a lot and I think the largest one is that with the advancements in AI, uh that it works in things like ah, us humans do, uh, which it doesn't. Right at the end of the day it's programming, it's code, it's based on logic, it's based on recognizing patterns and it makes decisions based on how we train it. The information that we provide uh, doesn't have the capabilities uh, like the human brain to uh, have cognition and think. We're maybe getting close to it in another few decades but we'll see. But right now it's not the human brain. It definitely has a lot of compute power. Things uh, acts faster, can act faster than us but uh, it's, it's not human yeah, agreed.
Speaker A: So you're saying, if I hear you right, that we can't just plug it in and it's going to handle security for us, like, you know, some folks are saying on the interwebs.
Speaker B: No, not at all. And in fact, it probably introduces a lot more risks.
Speaker A: Agreed.
Speaker B: That it provides.
Speaker A: Yeah, yeah. No, no argument there. So kind of turning, you know, we've talked about the risks a little bit, and we'll talk a little bit more, I suspect, here going forward. But, you know, in terms of measurable, manageable outcomes, um, you know, how have you seen AI or ML make a meaningful impact in your security efforts? Have you seen that?
Speaker B: Yeah, definitely. Uh, I've been fortunate that with my current organization and past organizations as well, when AI just started, uh, coming into the picture probably a few years ago, three, four years ago, uh, we've been able to play around with it and leverage it to, uh, help in our operations and to deliver value in our business. Right. So, uh, at one of the companies where we were doing, um, research on the different types of cancer, uh, there's just millions of data to get through. And even though you have oncologists involved and, um, other scientists involved in the organizing of the data, uh, leveraging AI to get, you know, with the power that it has and speed and, uh, accuracy, depending on how, you know, the logic that you build into it. But was able to really help, um, doctors on the front line, uh, help with diagnosis and help figure out the best treatment plans for certain types of, um, you know, cancers that different patients had, uh, out there. So that, you know, that's just one example from a previous company. Uh, more recently, I think it's, uh. It's always been there to help support productivity and mostly in inline operations, uh, within it or whatever are really daily, regular tasks that are not too complex and can be repeated over and over again. Um, we see it, uh, expanding into, uh, what we do within the security, uh, practice. Right. And within the soc, Right. Where we're talking about SOC right now, um, and all of the threats, the large numbers of telemetry coming in, and we have to get through all analysis that has to be performed. AI is really helping there to filter out a lot of the, uh, noise and false negatives and helping us focus on what really matters. Okay.
Speaker A: I love that. Um, I too have seen it, uh, seen AI and ML be very useful in those, uh, circumstances. Um, certainly not on the medical side of things, but in terms of like, you know, consuming a ton of data and then identifying sort of that thread of truth that runs through that. Um, you know, we, we would call that anomaly detection in some cases. Um, really, really powerful. Love, love to hear the way that you guys are using it on the medical side of things. Um, now as I kind of transition, thinking more about the threat side of things, how bad actors are leveraging and harnessing the power of AI, um, and, and beyond that, for, for, for that example, or for that matter, you know, what's a, ah, new or unexpected, um, threat techniques that you have seen surface over the last year that concern you?
Speaker B: Yeah, I think the most dominant ones that we've seen in the marketplace, ah, last year is the use of AI to really, uh, fool people into thinking they're talking or seeing a real human being. Right. So now they're leveraging that to create images, capture images from, you know, things like this podcast, right? Images of myself and videos. And I've probably spoken long enough in just a short ten minutes or so for AI, uh, to really, uh, duplicate my mannerisms and my speech and what have you, uh, to fool others out there. The advancements in AI to um, support phishing and fraud have really made an impact last year and it's, you know, we've seen it all across the globe with some really big incidents to have happen.
Speaker A: Yeah, I couldn't agree more. Um, as one of the, one of my dear friends, FC Barker, ah, also known by his hacker alias Freaky Clown, um, he and I do, uh, a couple of different events together and he was on this podcast not long ago. Um, and one of those things is a deepfake, a live deepfake demonstration where he deepfakes me based on one photograph. And uh, it's pretty terrifying how quickly, um, and how good it is today. Um, he ends up screen scraping my LinkedIn picture, um, as we all have. That's how you have to have these things to do business today. So, pardon me. He scream scrapes that and then, um, live deep fakes me to include like having my ears right, and the side of my face, uh, which is kind of weird because you can't really see that well in a LinkedIn photo. And yet it nails it. It's pretty scary how things are coming along these days.
Speaker B: Oh yeah, definitely.
Speaker A: Um, so can you share a win that your team has had through like, you know, automation or orchestration tools? You know, we're as security leaders being asked to do more with less all the time. Uh, and so one of the ways that we find the ability to do that is through automation and orchestration. Can you Share some of the ways that you're finding success in that space.
Speaker B: Well, we're still early on and one of the areas that we're trying to leverage this right, is um, um, on the compliance side or GRC side of things for security, where we have a lot, um, regular questionnaires coming in and we're responding back with the same answers. And most of the time, right, we're referring to our policies and we have our analysts uh, looking at it, um, populating the information. But uh, the newer tools these days are able to look at past responses, uh, look through our policies, procedures, our guidelines and be able to um, and also, you know, whatever other instrumentation there is to show our posture in different areas like our endpoints, our cloud environment, our uh, data centers and what have you, and respond back with intelligence, um, to these uh, questionnaires. So that helps speed up the process and provide good amount of content. So that's one area that we're just trying um, starting to get into, um, on our side to help us with the questionnaires coming in. Uh, another area as I touched on earlier, is with the SoC, right, there's so much data to look at, um, and we're leveraging our partners that are AI empowered to get through a lot of the noise so that our engineers are focusing on the most, uh, relevant issues that are most possible, the true positives that are high in critical level risks.
Speaker A: Yeah, I'm glad you brought that up because, um, I'm seeing lots of automation both in terms of security, uh, questionnaires. That's a big area. I think that's ripe for LLMs to step in and really help consume all of the previous, um, you know, questionnaires that you've done, identify themes through them and then help forecast um, you know, emerging questions that, that we see over and over again and then answer those with consistency, uh, and automatically. So that's one area that, that we've seen, you know, a lot of, um, you know, a lot of success in.
Speaker B: And you know, I'll just add one more that I think um, is coming along as well and relatively new is um, setting up, you know, new environments. Right. You can leverage the AI agents to set up your VMs following a gold standard and making sure that you're preemptive about the security controls being put in place rather than doing an audit afterwards or assessment afterwards and finding the gaps, you know, leveraging a CNAP tool after the fact. Um, now you're, you're setting it up, uh, upfront and reducing the risks ahead of time saving time and resource need, uh, as well. So that's just ah, a new frontier and new capability that's coming out because of the power of AI.
Speaker A: Yeah, you know, it's funny you bring that up, you know, five probably about five years or so ago, you know that was, that was a separate technology, right, that you had, you had to buy, you had to implement, that would deliver, not only build but then deliver these gold images over and over and over again. Uh, and now to your point, you know, we can do that with the power of AI and save that money. That's pretty exciting. Um, but one other thing you talked about earlier about was in the SOC space, uh, leveraging AI to you know, evaluate the mountain of data that all of our telemetry, um, all of our tooling provides to us in terms of telemetry. Um, so how are you able to evaluate what's appropriate and safe, um, versus and sort of separate the normal data from the anomalous or the potentially malicious data, um, in that environment?
Speaker B: Yeah, it takes time.
Speaker A: Right.
Speaker B: When you start pursuing this, uh, there's sort of an onboarding process. Right. And so your engineers, your team data are intimate and familiar with environment, familiar with certain servers and um, other assets out there, um, within your environment that can speak to it. Um, obviously a lot of times you're going to get a lot of false positives. I mean that's the nature of security tooling, uh, that tries to tell you vulnerabilities is always starts off with a lot of false positives.
Speaker A: Right.
Speaker B: And same in the sock space. You have a lot of data being pushed, um, into your siem, data coming from your edr, from your sase, um, and it's just a lot. So whatever we can do to leverage AI to filter through that, that would be the first layer of defense. And then um, if you have uh, M. MSP or MDR in place to help you with, you know, L2, um, for all that data, doing an additional analysis, um, and then finally your own internal team. So if you have that ability to have three layers, uh, as time goes on, things sort of shift after the onboarding process and things get a lot more smoother. Um, you can trust it, be more confident in the uh, analysis and start leveraging your folks for uh, other initiatives.
Speaker A: Right.
Speaker B: There's always so much work to get done.
Speaker A: Now that makes a lot of sense. I appreciate that. Um, Michael, as you have embarked on your journey there, have you adopted or implemented any new modern cloud native solutions or maybe even AI native, uh, solutions and if so, what has changed as a result?
Speaker B: Uh, we have. So we're using both, uh, an AI powered mdr, ah, as a partner and we're also using uh, an AI powered SIM which we just uh, started leveraging, um, end of Q3, Q4 last year. So I think the benefits that we've been seeing from that, you know, is all. Some of the comments that I've already made. Right. Saving time for our folks where they were chasing, uh, a lot of data in the past. Um, more consolidated, easier view, um, more context when we're looking at things, because it's capturing information from a lot of resources and as we dig in and able to um, query or question the platform on what does this really mean? Uh, it's able to go out there and capture the information from its integrations rather than our engineers having to go to the source system, uh, looking at the logs or a separate interface to doing their investigation. Now leveraging the power within the AI, you have one console and you just could query, uh, in human language, um, to perform your investigation.
Speaker A: Yeah, I'm going to sound like an old man here for a second just because I'm going to go like man, back in our day, you probably remember this, but we, it just, we would spend so much time assembling information, uh, about an alert. So you would have to go and you know, you get this alert, this person did this thing on this system at this time. And you go, well, who's that person? What's their job? What's their role? Who's their leader? Is this appropriate for their job? And then you would go, okay, well fine, now I know a little bit about that person. What about that system? What does it, that system do and what's its role and who all has access and what applications run through that system. And you're just trying to build this uh, context to understand what you're looking at. And to your point, today, using AI, I've seen many systems are now, um, m. Many applications are now able to pull all that context together for you and present it to a SOC analyst right on moment one when you open the alert, all of that is already provided for you.
Speaker B: Yeah, I mean, and what used to take hours or maybe days to go out there and figure out that context, uh, as a human, now it's almost, it's right.
Speaker A: Oh my goodness, yes, absolutely. So, um, you know, now that you have. You said you're, you're kind of on the front end of this, but you've deployed some of these, what advice would you Offer to other security leaders who are considering transitioning from some of the legacy tech that we've all been using for 20, 25 years. You know, you've been in it for 30 years. I've been in it for a good while as well. So, um, you know, there's lots of folks looking to move from legacy tech to modern security architectures. What advice would you offer?
Speaker B: So you have to go down that this path. There's no ifs, ands or buts. Right? Just like the Internet was a industrial impact, it changed how we all businesses do business. Um, AI is changing the way cybersecurity professionals or technology, we just have to keep up with it. Right? Just like, um, you have traditional taxis in the past, um, shared rights disrupted an industry, and now we have AI disrupting, uh, technology and we have to keep, uh, up with it. It evolves so quickly every three months. We've way surpassed Moore's Law with the advancements in AI, how quickly it is changing. So you have to keep up to speed and identify, uh, places where you can pilot, where you can test it out, you know, get that trial run while within your business units, or, uh, different, you know, micro organizations and people that are open to, uh, within the business that you can partner with, that are open to leveraging these new capabilities. Uh, people see it, um, they hear about it, there's news about it. So work on those partnerships and, uh, help get those champions to try it out. You, uh, if you aren't keeping up, you're putting your organization at risk. Definitely. There's just so much advancement. Um, you know, malicious actors is a huge business now. It's bigger than some corporations in the U.S. so we have to keep up.
Speaker A: I couldn't agree more. And I'm glad you said the things that you did, because I think there's some really neat tech that's coming out today. But I also have come from big Fortune 500, Fortune 100 companies that, um, you know, at least at that time, were pretty reluctant to move forward with some of the new emerging technologies of the time. Right. You know, I remember when cloud came out, or Zero Trust, pick your favorite, like, flavor of the day that we had, we've had over the last 10 years. And there was always a reluctance to move forward with a new technology. Every, all the big companies would say, well, we'll wait till, you know, uh, our big competitor, uh, they buy it and they prove that it works for them. Then we'll get into it. Um, and what my fear is today is that there are Companies, there are emerging companies that are doing amazing things today. But our reluctance to buy something new, emerging technology is going to actually hurt us in the end because we're just, we want to wait too long, we're too reluctant to uh, adopt new technologies. Uh, have you seen that in the past? And do you think that still exists today?
Speaker B: Yeah, I think it definitely does. Right, and you make great points with uh, Zero Trust and the migration to cloud. There's still plenty of organizations out there and traditional data centers and have, or uh, hopefully right now most of them are hybrid, right? Some on prem, some in the cloud, moving more and more to the cloud just to have more capabilities. But what I do see, and there's been a lot of activity in the cyberspace in the past two, three years because of the great advancements in technology and AI in the past three, four years, uh, we have a lot of new players and I see reluctance uh, with some of the bigger organizations to try out these uh, new startups. Right? But they are very innovative. They see what's happening out there. Um, they understand, they come, you know, they, they're not straight out of college. They, they come from working in big institutions and understand the problems that we've been dealing with and coming up with solutions. Right. I mean um, after we migrated to the cloud, who knew how big some of these CNAT players would become, right? How, how large their organizations will be. Same uh, thing with the SASE or Zero, uh, trust organizations. So with these new players out there that are really uh, leaning on being AI powered and being able to manage all of this data and giving us the best uh, decision making companies who really need to look and invest. And it's also a good time because when you're uh, partnering with them at an early stage, you're getting in at a good price point because the cost will go up eventually and they'll probably end up offsetting some capabilities that we currently have. Some things that are needed now, may not be needed later. Because if you're addressing things proactively, um, you don't need to um, do your assessments and spend people power and other licenses to cover things that you could uh, nip in the bud.
Speaker A: See that right there Michael? That's the CISO viewpoint we love to have here. Because you're absolutely right. Partnering with the plucky upstart, uh, it comes with some benefits. You pointed out you can get in, especially if you get in early. You typically get in at a really good price point that will undoubtedly grow over time. But you know if you get a multi year deal at a really good, you know, really good price point, you can save a lot of money that way. Um, have you seen. I have seen at least, and I would love to get your point on this, uh, where these plucky upstarts are also eager to continue to solve use cases. A lot of times they're building this product but they don't use it themselves. Right. They might use it internally, but the product managers, the developers, they're not cybersecurity professionals. And so as security professionals, we have use cases that we can bring to them and help kind of nudge the innovation, perhaps a little selfishly, I confess. Okay, but, but nudge that innovation in a direction that benefits me and my organization. Have you seen this where you can get them to do things that maybe you could never get the upper right quadrant kids to do for you?
Speaker B: Yeah, definitely. And that's what I love about it, you know, this innovation. Past year and a half, uh, two years, uh, I myself have become more involved with the uh, startup community and there's a lot of opportunity to become a development partner, right, where you help guide the capabilities, the value of the products that they're building and new features that they're interested in. I get on calls and they're talking about potential use cases and I provide input on. I haven't seen that, uh, no, I don't see that working. Why do you see that working? Uh, as you mentioned, they're not necessarily, uh, practitioners with decades of experience. Maybe they've, you know, had some experience in it and um, you know, postulating on what, what could be and what, what might be of value. But they need experts like us or people, you know, practitioners that are operating and, and managing to provide the input and direction to say, hey, this is where we've had some issues, right? And you know, good point that you made is these large organizations, you can't even get through their help desk sometimes, right? Regardless of what kind of SLAs uh, you have and contracts you have and how much you spend. It, uh, could be in eight figures or even more and you still have a terrible support, uh, on the other side of it. But uh, these new organizations, you have a external development team now, uh, at your disposal that can build, help build, uh, along with you and, and why not put your stamp on it, say hey, I was involved in creating that great product, I think.
Speaker A: Couldn't agree more, Michael. I too have had the pleasure of being a design partner, uh, at previous companies for some of these startups. Um, and being, being able to nudge them in the direction that I thought was important. Um, you know, there, there is a lot of, uh, you know, there's a lot of pride that comes with being able to say, hey, I helped that company get or solve that problem that way. Um, so that, that's always exciting as well. So I love, I love hearing that. Um, yeah, so, all right, kind of transitioning a little bit. Um, I do want to just go back to that for a second. You mentioned Moore's Law and um, I think AI has absolutely shattered it. You brought that up. I'm, I'm simply agreeing with you that Moore's Law has broken now because of AI. But what I, I think that is, is both for the good and for the bad. For in terms of the bad, yes, bad actors are now able to scale up their attacks in a way we've simply never seen before. The sophistication is off the charts, um, you know, to, to the points you brought up earlier. At the same time, however, what I'm seeing and would love your thoughts on this just to kind of, you know, validate or you know, keep me honest here, is that I'm seeing where we've got some, you know, startups going out there and their development cycles are faster than we've ever seen before in terms like, what I'm saying is their ability to go from an idea to a minimum viable product, to a full fledged solution to a problem that we're seeing has gone from like seven years from that, that time frame used to be like seven years. Ah. And, and now it's like, can be as short as like, you know, six months, three months and I suspect it's going to continue to collapse. Are you seeing this? Am I in the, in the dark here or what?
Speaker B: No, I definitely am seeing this. And I think it was a huge explosion Last year in 25, 25 was the explosion of a lot of startups from everywhere, right from Middle east over here in the US Just, just a lot. And people are able to, as you mentioned, within months come up with an idea, um, and, and build it out. Right. Uh, not to say that they're building their MVP is not completely, you know, is completely secure and you don't have to worry about it. But as far as rough capabilities to prove that concept, yeah, they're able to do it, uh, so much quicker because sometimes depending on events, um, that I go to, I may meet a founder very early on and they're just having conversations, thinking about the next idea next time you run into them at another event which is even a year later, they have a product that they want to give you a demo on. Isn't that wild?
Speaker A: Uh, oh my gosh, that sounds like my LinkedIn DMs right now. I'm telling you, like every founder who has an idea has hit me up on LinkedIn and, and I love to partner with them, I love to have those conversations and, and speak truth into, you know, the idea. Sometimes they don't want to hear that this is an interesting idea that I would not probably invest in. But there are many others for, for every one of those, there's five. I'm like, this sounds really cool. I, I can't wait to see you build it. Um, and the thing is they are, and they're building them so fast these days that that's what, that's what gives me pause going back to the earlier conversation. That's what makes, you know, my heartbreak a little bit. Uh, for these companies, these big sort of monolithic, you know, uh, glacial paced companies that want to wait for everybody else to try things before they try them. Because we're all experiencing many of the same problems today. If some of these startups have solutions that work and we can't get out of our own way as security professionals to, you know, adopt them and solve the problems.
Speaker B: Yeah, yeah. You know, um, I kind of don't feel bad.
Speaker A: Right.
Speaker B: Like you said, they're getting in their own way. Uh, shouldn't snub you, uh, know, the new kids on the block because, uh, innovation is key. You have to constantly out there and I try to be very active in the community. I'm out there regularly talking to other peers, talking to people that are operational, uh, building and saying, you know, learning from others. Right. We, I've been in this industry for 30 years now and I'm constantly trying to learn, trying to keep pace with the innovation and how technology, uh, is transforming. We just gotta be out there, um, and you're putting your organization at risk, uh, if you're not keeping an eye open. I mean at the end of the day the fundamentals are key. You have to stick with the foundation because what was true 40, 50 years ago is true now, uh, as well. But you just have to also adapt, uh, to the new risks out there and threats out there and um, make sure that your organization is keeping pace and able to uh, react as quickly as they're attacking. Yeah.
Speaker A: So you're saying that the principles of least privilege and data minimization, those remain true even with the, as we over layer technology on top of the actual business challenges that we're trying to solve.
Speaker B: Yeah, uh, definitely. It's always, uh, you know, I've changed organizations, uh, a few times, and, uh, I always go back to the fundamentals and making sure we have the fundamentals in place. Right. And there's, funny enough, always room to grow and, uh, room to improve on the fundamentals. Right. But that doesn't mean in parallel, you can't be preparing for, uh, you know, the latest threats out there and being innovative in your approach. Right. You could put in the fundamentals, but adapt the approach to this new landscape.
Speaker A: We're kindred spirits, Michael. Uh, I have been harping on not losing sight of the fundamentals for years and years. And so that, just that, that, you know, warmed my heart to hear you say that. So that's why I wanted to double click into it a little bit. All right, well, let's move on. As passionate as we both are about the vendor community, the startup community, the exciting things, the innovation that we're seeing in that space, um, you know, we do want to move forward here. So, and to make this kind of tangible and useful for, for security leaders that are listening here, um, you know what I want to transition to maybe more around how we, we, you know, manage and, uh, and report on the work that we're doing. Measure and manage and measure the work that we're doing as security professionals. That can be hard because it's hard to say, hey, remember how you didn't get hacked yesterday? You're welcome. Uh, you know, that doesn't really work very well. So what metrics or indicators do you use to measure your team's impact on the business tangibly, measurably, and be able to report on that?
Speaker B: Yeah, I think again, some of the foundational metrics that we've been using for decades still work. They still need to be educated, understand what the metrics mean, uh, the value that it brings, and just really stick to it. Right. Uh, what is the security posture of your endpoints? How many devices are compliant, how many are not, and what's the reason why? How is your organization doing with your phishing tests? Right. How, um, good is your email security, uh, performing, or your other security tools? But when it comes to presenting the metrics to the leadership and the board, uh, one method I've used, uh, is to discuss coverage and protection. Right. So, uh, everybody understands how much revenue a certain business unit or line of business is making or how much investments are in certain parts, uh, of the business. So if you can translate, hey, we're doing these foundational fundamental things that are security best practice and we're implementing it across the organization. Now you can say, hey, out of these, uh, for example, 10 units, uh, we've implemented, you know, BCP doctor tests for three out of the 10 and we have a multi year plan to get 100% coverage. Right. So, and that, you know, that's just one example. We've uh, acquired, you know, had this much M and A activity, um, and now we brought in 20,000 new endpoints now through the migration process, now we've assimilated, you know, 10% of them into our, you know, protected environment. I like to give metrics on that coverage, right? How are we bringing in them into the fold? How are they even more protected? Uh, how do we have more awareness about it? So for these different assets and that coverage, for that revenue, at the end of the day, right, I just protected, um, $800 million in revenue for the organization by implementing these six foundational security practices, um, for that unit. And that's why I covered it.
Speaker A: Really like your approach, right, because what I'm hearing, and keep me honest here, what I'm hearing you say is that you're, you're kind of communicating the security risks and then at all of them holistically, these are the security risks that we have. And then you are slowly but surely reporting on, as you close, uh, the gap on those risks. Having a very candid conversation is what I think I'm hearing you say in terms of these are the risks, of these risks, uh, we have addressed, you know, this, you know, X percent of them already with technology and you know, processes and procedures. And then over here, these are things, these, this is the plan to address the remaining risks over this roadmap period of time. Is that a fair assessment?
Speaker B: Yeah, yeah, that's, that's pretty much the approach.
Speaker A: I love that it's going to be
Speaker B: the big gap, but what are we doing foundationally? What is our program and how are we getting coverage, uh, around this, these other areas of revenue and protecting that and income.
Speaker A: It was, and that's, that's the second piece of that then, right, Is you are, you are saying, okay, of these gaps, here's the uh, total, total addressable. You know, we'd say market, but in our world it's more like revenue that is, you know, in play with these risks. And so your, your quote unquote return on investment is really saying, here's how much of that revenue we're now protecting. Is that, is that how you're doing it?
Speaker B: Yes, that's right.
Speaker A: That's a neat way to do it. I, I think there's going to be a lot of value. Uh, I think other leaders should, should lean in here and uh, replay that, go back, listen for the last three minutes over again, because Michael's giving you a great playbook for how to solve this problem. I love it. Well done. Thank you.
Speaker B: Sure thing. I mean, it takes time to figure out organization. Organization, Right.
Speaker A: Agreed. Yeah, yeah. Because to your point, right, um, every organization is different. Their risk tolerance is different. Um, you know, what matters, the revenue, where that's made and how that's protected. All of those things differ. But this approach, I think will work in many different industries. Maybe not every industry, but in many. Definitely. Awesome. All right, Michael, I'm going to transition now because we've had a great conversation. I could nerd out forever on like the risk stuff on, you know, the AI stuff, uh, the innovation. But we've got to eventually bring this to a close. Okay? Um, so as I think about like career, there's some, undoubtedly some folks listening to this going, man, this sounds really neat. I would love to do what you guys are talking about. Michael, uh, what would you recommend in terms of maybe, maybe early career, beginning career, entry level, middle career. You're kind of that your soc analyst. You're, you know, an analyst doing, you know, vulnerability management, whatever the case may be. And then kind of later career, we've got more advanced senior folks, uh, your significant engineers or maybe managers, directors, looking to move up in each of these, you know, phases of their career. What, what advice would you give to each one? Maybe let's start with the entry level. Those folks that are looking to break into cybersecurity. How, what, what would, what advice would you give them?
Speaker B: Yeah. So interesting topic, Nick. Um, and I may go against the grain, uh, with some other security leaders when it comes to entry level. Uh, as I mentioned, you know, I'm going on my 30th year, so I'm pretty old school. And um, you know, I'm from the time where not to say that they don't or, uh, you know, that new hires don't. But put in a lot of hours, put in a lot of work, um, learning a lot. I learned on a job. My degree was in business marketing. I learned coding and um, identity and ah, network on the job and figured it out. Um, so my perspective is security isn't necessarily entry, uh, level position. I think you have to be familiar with the environment, the network, uh, certain types of tooling, um, uh, before you can actually get into security and understand what the reasons are for these technical controls and what they are doing or preventing, uh, on the other side you have compliance at grc. Um, and I think to get into that space it's helpful if hey, you have an audit background, right? You worked at a big four and you're um, doing auditing and you know how to get into that big level of detail and look at logs. Because they still look at logs, they're still doing queries against that. When you have your external auditors and they're trying to find you know, uh, circumstances where you're not following your policy. So you, you need that extreme level of detail on the GRC side and have uh, having an audit background, it is going to be, Accounting background is going to be uh, very helpful as well. I mean there is another path, uh, within GRC which is uh, security awareness training. If that topic really is of interest and you want to be involved in the latest tech or be aware of the latest technologies, get exposed at conferences and be able to train uh, non techie folks on cybersecurity, that's an avenue as well. Right. And you could help support the security organization and L and D with creating a curriculum for the organization when it comes to cybersecurity. Right. And that could be in your involvement depending on how uh, how high you want to go. But back to my point, I think you need some level of experience uh, before you start trying to get into an entry level security, uh, position.
Speaker A: No, makes a lot of sense. I wouldn't disagree with any of that. Uh, having come up through many of those same ranks, similarly started as an IT guy that bridged into uh, security and then moved up from there. Um, certainly resonates with my background and experience as well. Um, what about that middle layer? Right? Those folks that have been around a little while that are really looking to get to the next level, how do they move up? Let's say you're in, you're doing great, you like it, but you want, you're reaching for that next level. What does that look like?
Speaker B: Yeah, um, you really have to demonstrate that you're ah, a go getter, a doer, uh, problem solver and you want ownership, right? You want to advance and you're willing to say, hey, I'm going to own um, Vulnerability Management or I'm going to own security and the uh, SDLC or DevSecOps, right. I'm going to own this area. I'm going to learn as much about it as I can, uh, help our other team members and then help, um, our other partners within it, uh, within product and within the business, uh, operations, what have you, or compliance and internal audit. Like what are you going to own, right. And be that person that figures things out. You know, you want to put the plans together. You're a planner, right. You're going to go on vacation. Are you going to help plan the vacation? Are you just going along for the ride? Right. Are you the one buying tickets? Are you the one figuring out the, uh, agenda and where you're going to go and point A to point B, all the way to point Z, Right. Are you that person? You have to prove at the middle level that you are that doer that you can be counted on to figure it out. And you know, I'm all about work, life, flexibility and making time for family first. But when push comes to shove and you're needed, you're there, you're working around the clock. I mean, all of us have, many of us have been through a security incident or something came up or an audit deadline. You have to meet those deadlines and do what it takes and, and come up with a solution. Right. Uh, also key at this level is don't be just the, uh, identify your problems. Right. Say, hey, I see a risk here. These are, you know, I'm not 100% sure because I don't have the experience or the uh, uh, you know, awareness or knowledge to have a solution. But I have these two or three ideas. What do you think? Right. And come, come to, to your, uh, leadership with, with that type of approach. Um, because if you just come with a problem, we already probably knew about it and it's there and waiting for the time to actually, uh, address it.
Speaker A: You know, I'm glad you said that. And I've seen, um, there's a, there's a close cousin to that as well. The person who shoots down all the ideas. Right. All that's dumb. Oh, that never work and here's why. And, but, but never providing anything, you know, as an alternative. It's easy to shoot down other people's good ideas.
Speaker B: Yeah.
Speaker A: But in the absence of another good idea, that's the best one we have. So, you know, let, let's, let's make sure that before we, we tear something down, we at least offer an alternative. Hey, that's a good idea. You know, some challenges with it might be this. Let's. What, what if we addressed it instead like this, you know, Something like that. So too often I see that sort um, of negative Nancy's kind of approach to things. And, you know, those folks aren't fun to work with and don't typically move up, at least in my experience.
Speaker B: Yeah, I mean, some people get lucky. I think we all encounter individuals like that. And that's, that's kind of a pet peeve of mine too. Right. So, um, if they're an organization where I have control over it, things will happen. If it's their level in organization where I don't have control over it, then that's, you know, kind of environment I don't want to be in.
Speaker A: Right, agreed. Agreed. But you're hearing it here, guys. It's not just Mick M. It's also Michael. We're all saying, don't be that guy.
Speaker B: Yeah, uh, uh, as well. I see. But. Oh, yeah, agreed. Sometimes, Sometimes you just have to try it. It may sound like a bad idea. And what, it's better than standing still at no momentum, right?
Speaker A: Yes, exactly. And let's not forget that often when we do fail, we can fail forward. Right. It may not be the, the, the result, the end, the, you know, the end goal idea. Um, but it may get us, move us forward and find something that, you know, either didn't work and we crossed it off the list, or maybe it kind of works, but then we realize, oh, what we needed to do was with this additional step, and then that ends up being what got us there.
Speaker B: So that's exactly that. Right. Because it might not be visible and m. We may not be aware until that portion where it fails. Like, oh, that's something we didn't see. And now we know about it now we could go back and address that as we move forward. Um, and I've seen that happen enough times.
Speaker A: Yeah. I mean, even in big organizations, I've seen paralysis by analysis so often where they just, they, they get down in the weeds and they want to solve for every problem. But what we need to do is start moving. We need to take some steps forward, chart the best path we know right now, and then we can adjust as we go. We can. You know, just because we commit to this idea for now doesn't mean we're married to it forever. We can, we can adjust if we need to.
Speaker B: Yeah. That's the whole time, you know, why Agile became Amen.
Speaker A: I love it. All right, what about those, uh, the senior folks, right? Whether it's a director or, you know, maybe a senior architect or something like this, and they want that next level, they Want to really reach out. Maybe it's. Maybe it's to attain the CISO level. Right. Let's say we're talking to a director who's, you know, eager to get that CISO title. What. That's a very different animal. Ah. From what I know. Um, so what would you tell those folks? What are the. What do they need to do differently to really be ready for that level? Yeah.
Speaker B: You have to be open or you have to be, um, understanding and willing to take the perspective of people that are not technical, um, and really digest it and have that shape how you think. Right. Uh, I come across a lot of folks, uh, even more so when they're junior. They're just very technology focused, which is fine. And there's technical paths up as well. Right. You could become a, uh, chief architect or, you know, a VP in information security on cyber or something and stay, uh, in the technical path. But if you want to become a CISO or if you want to become a leader, that's, um, really providing value to the business and partnering with, um, your business colleagues, you have to understand where they're coming from and why they have their perspectives, um, and that should shape the decisions you make. Right. So I think that having that openness, um, not being stubborn, saying, this is what it is. This is how it has to be. No, it doesn't have to be. Right. I hope that the majority of security leaders have moved away from being the, uh, person of no and saying, hey, let me just, for the most part, agree and figure out a path forward. Right. Um, and I still see some folks that are a person of no, which is kind of weird to me in this, uh, you know, day and age, but really, uh, having that, uh, compassion and understanding and openness to go along with the business and, you know, take that perspective to define what your roadmap is going to be. Um, and you have to manage people as well. Uh, unfortunately, you're in a position where you have to do what's best for the organization and be prepared, uh, to make the necessary changes in organizational, uh, design to be more effective, uh, as a team, um, working for the business.
Speaker A: Okay. Awesome. Michael, first of all, I just want to say thanks. This was a fantastic conversation and a ton of fun. Um, but we can't stay forever. I know you've got an important job to do, so I better let you get back to it. But, uh, I. I just simply wanted to say thank you very much for.
Speaker B: Yeah, I much appreciate the conversation and opportunity. Mick.
Speaker A: It was awesome. Absolutely.
Speaker B: As well.
Speaker A: Awesome. Well, folks, this has been SOC Unlocked Tales from the Cybersecurity Front line. I'm your host, Mick Leach, reminding all you cyber defenders out there to keep fighting the good fight. Stay sharp. You're the tip of the spear. We need you out there. So thanks for tuning in, and don't forget to like and subscribe. Uh, and check out our other Sock Unlocked episodes. And with that, I'll simply say, see you all next time. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.