The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Cyber Security Matters Podcast
The Cyber Security Matters Podcast artwork

Prepare, Don't Just Prevent: How Adaptive Crisis Simulation Is Transforming Cyber Incident Response - Episode 74 - Marlow Bryant, Reflex Security

The Cyber Security Matters Podcast · 2026-06-29 · 36 min

0:00--:--

Key moments - from our scoring

Substance score

47 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality10 / 20
Guest Caliber9 / 20
Specificity & Evidence10 / 20
Conversational Craft8 / 20

Marlow Bryant brings a unique venture-capital-to-founder perspective to building Reflex Security, an adaptive crisis simulation platform that addresses a critical gap in incident response preparedness. Drawing on his experience as VP at March Capital and Clear Sky Security Fund - where he invested in companies like Expel, Spy Cloud, and Together AI - Bryant observed a consistent pattern: organizations don't lose on the exploit, they lose on the response. Traditional tabletop exercises are static discussions that fail to build organizational muscle memory; Reflex replaces them with AI-driven simulations where adversaries adapt to every decision in real time. Bryant emphasizes that incident response is fundamentally a high-judgment, high-context activity where gaps emerge not in technical execution but in human coordination, organizational resilience, and the critical first 72 hours. The platform targets CISOs and security teams preparing for breaches, where regulatory bodies, boards, customers, and press evaluate organizational competence - not the vulnerability exploited. Bryant's background in comedy, venture investing, and working alongside former CISOs like Jay Leak, Jamie Montgomery, and his co-founder Casio shapes his philosophy: persistence over perfection, learning from failure, and building teams that operate effectively under uncertainty.

Key takeaways

  • →Companies fail on incident response execution, not on the exploit itself - and only the response is remembered by boards, customers, regulators, and the press.
  • →Tabletop exercises as static discussions don't build true organizational resilience; AI-driven adaptive simulations where adversaries react in real time create the muscle memory teams need.
  • →The clearest gap in incident response is not technical skill but organizational coordination: individual star players can hide systemic weaknesses that fail under actual breach pressure.
  • →Hiring early-stage security talent should prioritize judgment and passion for solving the problem over perfect credentials, with focus on people who show persistent commitment before an offer.
  • →Incident response preparedness is not a compliance checkbox but a strategic lever: while exploit windows shrink, organizations can control their response variable through deliberate practice.

Guests

Marlow Bryant

Topics in this episode

Incident responseOrganizational resilienceTabletop exercisesReflex Securityadaptive crisis simulationAI-driven security testingbreach responseCISO preparednessincident detection and containmentExpel

Questions this episode answers

Why do organizations need to practice incident response beyond just having a response plan?

Reading a plan in a conference room and living through a breach are fundamentally different; only real reps build the organizational reflexes and muscle memory teams need to execute under pressure, which is where most breaches actually go wrong.

What is the main difference between static tabletop exercises and Reflex's adaptive crisis simulations?

Traditional tabletops are static discussions where the scenario doesn't change; Reflex uses AI agents that react and adapt to every decision the team makes in real time, creating realistic pressure and forcing teams to make high-judgment calls.

What are the biggest gaps Reflex discovers in organizations' incident response capabilities?

The clearest gaps appear in the human and organizational layer - not technical response - including unclear authority structures, confusion over who can declare a breach, poor communication chains, and individual star players masking systemic weaknesses.

What did Marlow Bryant learn transitioning from venture capital to founding Reflex Security?

The customer is the ultimate test, not fundraising; venture dollars follow customer traction, and founders must filter conflicting advice while learning to manage investors, co-founders, and teams through radical uncertainty.

How does Marlow Bryant approach hiring early-stage talent at a security startup?

He hires for judgment and passion over credentials, prioritizing people who show up repeatedly and demonstrate commitment to the problem before receiving an offer, and who can operate effectively with incomplete information.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode contains a handful of genuinely useful IR-specific observations - decision authority gaps, tribal knowledge as organisational risk, the data-set ownership angle - but roughly half the runtime is career retrospection, comedy anecdotes, and generic founder-journey advice that adds no B2B operator value.

no one yet owns incident response as a data set. No one can tell you, well, why did this incident take us four hours to resolve and why did this one take four weeks? That is still tribal knowledge
there is a difference between individual skill and organizational resilience...you have like a top decile team...those people can hide a huge risk

Originality

10 / 20

The framing of IR as a structured data layer and the parallel to automated pen testing are fresh and worth hearing, but the core thesis ('response matters more than prevention') is well-worn in security circles, and the startup/VC-to-founder section recycles very standard narratives.

A tabletop...is basically just a people pen test
this goes the way that automated pen testing did a few years ago...they were able to turn a point in time pen test into continuous tested

Guest Caliber

9 / 20

Bryant is a credible insider - VP-level VC in cybersecurity, now early-stage founder - but he has not personally managed large-scale incidents or operated as a CISO; his practitioner insight is largely secondhand and the company has only just landed its first customers.

I started as an investor in the space. You know, I've worked alongside former CISOs building their next big thing my entire career
we only just landed customers. Next is how do I build customer success?

Specificity & Evidence

10 / 20

There is one solid data point (IBM's 60-day containment figure), named references to specific companies and individuals, and a concrete regulatory list, but the product's own outcomes are absent - understandably, given the company's stage - leaving much of the IR argumentation as assertion.

It's about 60 days and that number hasn't moved in the last five years. It's gone from like 75 days to like 60
You've got the SEC with a four day disclosure rule. You've got Dora, NIST, SOC2 are all getting stricter

Conversational Craft

8 / 20

The hosts ask reasonable topical questions and do follow up on specific tabletop gaps, but there is no meaningful pushback - no challenge to whether Reflex's simulations demonstrably change outcomes, no probing of competitive differentiation, and extended time given to the comedy and career-origin tangents that dilute substance.

what are some of the gaps that become particularly obvious?
how do you see the tabletop market developing specifically over the next three, four, five years?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B77%
  • Speaker A17%
  • Speaker C6%

Most-used words

incident22response21part21tabletop14security13today13team13founder12reflex12first11interesting10build10founders10building9side8become8

Episode notes

Join hosts Harry Baldwin and Matt Rose in episode 74 of Cyber Security Matters as they sit down with Marlow Bryant, co-founder and CEO of Reflex Security. This engaging conversation explores the evolution from static tabletop exercises to dynamic, AI-powered crisis simulations that adapt in real-time to team decisions. Marlow brings a unique perspective to cybersecurity, having spent nearly a decade in venture capital as VP at Marsh Capital and Clear Sky Security Fund, where he invested in cybersecurity and AI companies including XL, Spy Cloud, Mitigate, Accurate, and Together AI. His diverse background includes an unexpected stint in stand-up comedy, providing valuable insights into reading audiences and adapting communication styles.

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to the Cyber Security Matters podcast. Your hosts today are, uh, me, Harry Baldwin and Matt Rose, two members of the Nuco Cyber team. And we're delighted to be joined today by Marlo Bryant, co founder and CEO of Reflex Security. Marlowe has had a fascinating journey into cyber security. Before founding Reflex, he spent nearly a decade in venture capital as a VP at, uh, March Capital and Clear Sky Security Fund, investing in cybersecurity and AI companies including xpel, spy cloud, Mitiga Accurate, and together AI. He is now building Reflex Security, an adaptive crisis simulation platform that replaces static tabletop exercises with AI agent driven simulations where the adversary reacts to every decision the team makes in real time. Welcome to the show, Marlowe. Great to have you here.

Speaker B: Thank you so much, Harry. Great to be here.

Speaker A: Yeah, looking forward to it. Um, today we'll be covering all things you people and the cybersecurity industry. But to get us started, we always love to ask people, how did you get into the cybersecurity industry in the first place?

Speaker B: Yeah, uh, it was really by luck. I started as an investor in the space. You know, I've worked alongside former CISOs building their next big thing my entire career.

Speaker C: Right.

Speaker B: My, my first venture gig, I, I was a newly promoted associate at Blackstone. And, uh, I left Blackstone to join Jay Leak at Clear, uh, Sky Security. Jay was the former Blackstone ciso. It was just looking for a hungry kid to write his memos. Uh, I wrote dozens of them for him. And that's, that's where I, I learned what it means to really drive an investing thesis. So, you know, I think the, the pattern that we, that kept showing up in the deals that we did. Right. We did a lot of deals together. And, um, the, the pattern I take from it is companies don't really lose on the exploit.

Speaker C: Right?

Speaker B: The exploit is always going to be new. Where they lose is the response. Everyone remembers how you responded. They don't remember how you were exploited. The teams are just failing to execute under pressure. Right. So now, uh, I've been on the investor side and it's time to take the mantle of building on the problem side, building on the founder side. That's where I'm, that's where I'm at now.

Speaker A: Fantastic. And look, I know Matt has got lots of questions about your career so far, so I'm going to hand over to Matt now.

Speaker C: Thanks, Harry. And, uh, yeah, great to hear. It's such an interesting route that you've, you've made, Marlowe. I'd love to dive a little bit deeper into, you know, your early career and how that shaped you today and your, your future direction. So, um, I think you've alluded to a couple of, uh, influences already, but is there anything that stands out or anybody along the way that you would put down as some of the biggest influences on your career?

Speaker B: Yeah, uh, the, the quote I think about is from George Kurtz. I saw him on stage one year, and, uh, I love the, he had a line. There's no compression algorithm for experience, and that line has really carried me for a few years. I think what he means by that is, for me, as a former investor, you can invest in a space or you can be the one to solve it, and one of those is infinitely more rewarding than the other one. And I think part of it is also you, you, you do learn the common, the common patterns in a story. And that is, that is part of the strength that I bring to, to reflex as well. But there's something about learning that lesson in real time that really strengthens your conviction, what you're doing, you know, so when, when I think about moving from the investor to the, uh, to the founder seat, it really is. Yeah, look, I, I, I'm no longer working on the compression of. Oh, uh, let's, let's look at the 12 deals that we did this year. This is, this is the one thing I'm doing for, for years, right? And I think part of the unlock for me was my co founder. You know, I met Casio a couple of years ago when I was looking for my next gig. Uh, he took me to lunch. He told me about this problem. We ended up having lunch for, like, three hours, and he, he showed me what he, what he built. Right. So this is another, uh, you know, I worked for Jay. I worked for, for Jamie Montgomery and Jed Lighthizer at March. And then I meet another former ciso, Casio, who's, uh, who's really excited about building his next big thing. Um, and something dawned on me that day. You know, I think I've, I've got a knack for finding former CISOs who want to build something new.

Speaker C: And, um, was that, was there a particular moment that stands out that you, you were, uh, you made the decision to move from investing to starting something else. What was, uh, what was the moment? What was the realization that this is what you wanted to do?

Speaker B: It was, it was really a, uh, you wake up one day and you want to actually apply it. Right. Uh, I mean, when I think about the founders that I've had an opportunity to invest in you. I mean, you both meet so many founders and you think, wow, there's such passion behind what they're doing. And I was so curious to learn that lesson on my own. You know, I was so, I was so curious to say this is the ultimate challenge that I want to, that I want to take on. Right. And there was, there was some moment where it was like, this is it. I, I've got to do this. You know, I, I looked at, uh, you know, I looked at my investing career and I don't know what it was one day where I was just like, I gotta pause this and really focus on, on building a company. And I really want to call it reflex security.

Speaker C: And from your time in investing to your experience now, are there any lessons that you've taken from your investment experience, uh, into being a founder? And are there any lessons that you would suggest other founders take on board from that experience?

Speaker B: Yeah.

Speaker A: Um,

Speaker B: I would say fundraising is not the ultimate test. The customer is the ultimate test. The venture dollars are going to follow. And that's something I, I honestly couldn't tell you when I was an investor. I really learned that once I came over to this side. You know, I think as a vc, it's a very intoxicating business. You know, I mean, from, from the investor standpoint, it's a very intoxicating. Oh, these companies are growing really fast. And it is so easy to think of the world in dollars raised, exits made in. And the, the customer traction that a company has is. It was one of five T's that I had on my framework, right? Like the framework I had for any investment team tech tam Traction terms. Traction is the important part. That's the part that the founders are all really excited to build. Right. I mean, it is something I have to remind myself now on the side is that it is so easy to mistake investor calls for progress because it does feel like you're doing something. And you know, the, the way you tell a story, that it lands with this audience, that, that is really invigorating. But the truer test is, is this customer going to buy my product? That's the part that I'm really excited to build next. I mean, I have such a deep respect for the founders that I had an opportunity to invest in. I think about Dave Merkel at Expel, I think about Vipple at, uh, Together AI. I think about Rohit at, uh, Excel Data. And there's one thing in common with all of them is there's just a relentless focus on the customer. On, on this specific problem and the funding rounds are just kind of a, it's a byproduct of it. It's, it's certainly important to the story. Uh, but now that I'm, I'm living it there, there is something about building the business that being in the boardroom really never teaches you. And you, you have to, you have to learn it yourself, you know, So I, I, I thought for years that my job was grading the founder. And it really isn't, it really isn't that it's the other way around. I mean, I, it turns out I was, I was learning a lot from them. You know, I think I, the way I'm, um, I'm carrying myself for this business now, it's kind of like, oh, yeah, what would Merck do? What would Vipul do in this sort of situation? You know, I'm blessed to have that behind me. Uh, but yeah, this is simultaneously the hardest and the coolest thing I've ever done.

Speaker C: Yeah, you just, you answered my follow up question there. But I was, I was kind of wondering kind of how you personally found that transition from the investment side into more of the vendor side of things. Um, it sounds like, you know, you've already learned some lessons along the way. Um, but how did you personally kind of find that transition?

Speaker B: Something that was really interesting being on the side, right in the pitch calls that I've been on with, with, with VCs is I, I heard myself giving me advice from just, you know, my, my former friends and colleagues that, um, that I pitch reflex to. I realized, wow, I've, I've given that advice before, right? Why not? Why not build a PLG motion? Why not do this? Why not? And I realized, like, wow, I, I, I hate that there's, there, there, uh, there is so much advice that others are giving you. And I think part of the challenge of being a founder that I didn't appreciate previously was everyone's going to give you advice and it's your job to filter it. It's your job to figure out how you're going to conduct yourself in the face of it. Even when you raise a seed round, there are going to be people who tell you, no, you got to raise it sooner, you got to raise it later. Uh, you got to get this first. Uh, don't hire your first VP sales until you're in a million. ARR. Everyone's, everyone's got a heuristic for you and it's your job to translate that into what does it mean for, for me. And my business here. Right. I think one of my mentors told me early on, you got to figure out how to manage your, you got to manage everyone. You're going to manage your investors, you're going to manage your, your, your co founder, you got to manage all of these relationships here. Everyone's got a heuristic for, for you.

Speaker C: And away from cyber security. We've spoken at Lakes before a little bit about your comic background. Uh, and I think that is always very interesting to hear about the different range of backgrounds that founders can have. But I'd love to hear a little bit more about some of those experiences as a comic and if you've brought any of those into your kind of professional life too.

Speaker B: Yeah, yeah, 100%. So quick, uh, background on that. The first time I was on stage, May 2022 and since then I've done something like two dozen shows across LA, New York. Uh, I used to do Fridays at the Comedy Store for a while. I've bombed more times than I'd like to admit and stand up. Really. There's so much that is in parallel with the founder journey. I mean it really teaches you to read a room, it's teaches you how to handle silence. Um, it teaches you how to recover, you know. Objection. Handling is a, is a big part of it too. Uh, for, I mean on stage it's hecklers and for founders, it's every customer you, you encounter, uh, cutting just ruthlessly to the punchline of what you're, you're talking about. All of that directly maps to the sales you're doing. We're, you know, founder led sales today. The, the investors you're pitching. Um, one of the, the lines I learned early on was the rule in comedy is you, you have to make people laugh every seven seconds and then you die every 10 seconds. On stage, the audience is always going to be asking you what's next? What's next? What's next? You know, the, the laugh is, it's not as long as you think. Even for me, I'm a, I was a novice comic doing, you know, five or ten minute sets. That is a long time. Someone's gonna make you laugh for five minutes. Uh, then it really is a long time, you know, and you have to do that at the comfort level that you have with your friends and family off stage. You're doing this in front of complete strangers and trying to make everyone in that room laugh at some part of it. And the, the bridge to the founder journey that I'll give is, look, failure is A part of the craft, it is a part of this journey and it is something you have to be prepared for.

Speaker C: Yeah. I mean when you frame it that way, I'm surprised you haven't run into more comics turned founders because it does sound like the, there's, there's so many lessons that you can learn from, from, from comedy. Uh, um, but I know that Harry has some questions more focused around talent in our next section that he'd love to ask you, so I shall hand over the mic to him.

Speaker A: Yeah. Thanks Marlowe. Thank you, Matt. Where's the, where's the best crowd? Marlowe, from a comic perspective, you said you performed a few places I would.

Speaker B: Los Angeles comedy, uh, store is great. You know, I think everyone there is there to have a fun time. New York is, is actually quite tough and there's something to be said about the, the lines that you, you uh, write down in LA do not hit the same in New York. It's just, it's a different audience and you know, I never went on the road like uh, like some of the more famous comics did, where you got to go to small town America to do, to do your stuff. But that is an even bigger bar to reach.

Speaker A: Yeah, I'd imagine that it's kind of like in the north and south of the UK but on a, not totally another level. Ah, but no, it different because people in London would laugh at some things, but people in the north would not laugh at the same things. Probably.

Speaker B: Yeah.

Speaker A: Um, so no. Interesting. And thanks for sharing more about your, your background and your career so far. Um, we've got to talk a little bit about, about talent. Um, you're an early stage founder. How are you thinking about building the first Reflex team?

Speaker B: Yeah, that's a great question. I think this is the, the toughest part of the journey is the earliest hires. Right. And we, we over index on judgment and passion over the skill. And here's what I mean by that. I, I really need early people who can make great calls with bad information. We don't have that much information right now, but what I need is someone who can operate with that sort of uncertainty. So I'll give you an example of some of the first hires we made. Ron Dilley, our field ciso. Uh, he had worked with us as a contractor for like six months and he, he famously says on some of our customer calls he was like, I, I would push a broom if I could join Reflex. That's, that's what I want to do here. You know, he saw our product and you know, he was the former CISO of Warner Brothers. He had seen, uh, he had seen incidents go sideways. He had put together his fair share of, of tabletops, and he really wanted to help us shape the product. You know, there's, and there's something to be said about, there's something to be said about the people who just continually show up for you before you even make an offer. That is, those are the people that I index the most on. You know, I think a lot of the, the promising hiring conversations we're having today, it's not people that we outbounded. It's. It's people that came to us and continually showed up and said, I, I really like what you're doing. You know, uh, that's, that's what happened with our, our first engineer too, Sheldon Pang. He, he, he took a whole course on, on instant response and tabletops before he joined us. Right. That was, uh, that was the, the weekend reading before he joined us. And he, he's an incredibly productive engineer. Um, yeah, so far the team is, you know, four full time, you know, eight including contractors and even the contractors that we work with. I'm, I'm really appreciative of.

Speaker A: Yeah, very cool. I mean, well, look, I'm, I'm, I'd love to revisit this podcast in a year and see how, see how, uh, things have changed. Right. Um, I think it's also interesting, right, because the roles that they're doing today might be very different in a year's time. Um, how do you expect, you know, roles of, of people at the business now to change over time? And, you know, how do you think people can generally adapt to that?

Speaker B: I'm going to paraphrase from Christina Advanta. She, uh, she said this recently, which is you are actively practicing leadership on people and you are going to get it wrong. And that really helped me because you're making these hires for the first time. You don't know where this is going to go in a year. Um, it is, it is hard. I don't have a fixed spec for a lot of the things that we're doing right, and that's why we, we index on judgment, we index on, on passion, because that's what, that's what I need to show up right now. Um, the, one of the things I, I ask in a lot of my one on ones is just what do you hate about this gig? What do you not like about, about what you're doing right now? And I mean, that gives me intel on where I need to hire because something that. Something that one of my employees hates is going to be something else that some. That someone loves. This is. Oh, this is project management part of the job. This is my bread and butter. You know, that's. That's what I want to hire for in the future is just the things that my current people don't like to do.

Speaker A: Yeah, no, it's interesting. I think it's a good way of creating a really rounded team as well, because you need that kind of diversity of thought in hiring, particularly at an early stage. Right. Um, where people can bring. Bring different perspectives. Tell us about the culture that you envisage at Reflex in, you know, in the years to come.

Speaker B: Yeah, I've thought about it a lot. I don't even think, uh, I've told Cass here about this, this line, but the, the mantra I keep with me is persistence over perfection. I mean, you know, from the. The comedy career, from other places I've been, failure is a part of the craft. I'm not interested in the perfect resumes. I'm not interested in perfect people, and I'm interested in their persistence. You know, I'm interested in people who keep showing up when it's really, really hard. You know, we have had in. In the short time that we've been a company, we have had real personal hardship on the team. And I am really impressed with how we all show up for each other. Right. When. When the going's tough because it doesn't. Doesn't get easier.

Speaker C: Right.

Speaker B: I mean, we. We only just landed customers. Next is how do I build customer success?

Speaker A: Yeah, yeah. Now it's.

Speaker C: You've got.

Speaker A: You've got to look out for each other, especially when it's a. It's a small group. It's powerful stuff. Honestly, it's, uh, it's really interesting to hear you talking, um, and culture and what you're trying to build from a people perspective at, uh, ah, Reflex. Um, got to talk about the tech now. I think it's really interesting, uh, perspectives you have on the industry and an interesting problem you guys are trying to solve. Um, you've said in previous conversations we've had that the problem is not just the exploit, it's how the organizations respond. Can you talk us through what that means and what you mean by that?

Speaker B: Yeah, absolutely. We all know that attackers are getting faster. Right. Mythos is only a, uh, boon for part of the industry. Uh, the time to exploit has collapsed. And when you look at it from, uh, if I was to boil the job down very Simply you have two levers. As a ciso, you can. Lever one is find it, fix it, patch it. You can keep spending on doing that. And the exploit window is going to keep shrinking anyway, so you're going to have to keep getting faster and faster. Or there's lever two, which is get good at being breached. Get good at the incident response part. Right? The breaches are inevitable, but the response is a variable that you can control. And uh, actually the response is what everyone is going to grade you on. You think about your board, your customers, the press, the regulators. Nobody is, nobody cares what the exploit was. What they care about is how you are conducting yourself in the first 24 or 72 hours. And uh, the question that we have for a lot of the customers that we work with is how are you actually preparing your incident response rate? Are you, are you talking through the response plan in a conference room or are you doing the reps? Because reading the plan and living through the breach are two different things. Only one of them builds a reflex.

Speaker A: Yeah, and I love the name as well. The name really, really pays homage to that, that way of thought. So I can see why that, that loops into what you're doing. Um, why are tabletop exercises such an important part of improving security posture on the whole, then. I know you kind of spoke little bit then, but, but give us a bit more on that if you can.

Speaker B: Yeah, yeah, absolutely. It, it took me a, A, um, it took me some time personally to, to grapple with why, why is this important. And I, you know, I think what you have to do is ask about the why, uh, the tabletop is still just a tool, right? AI is still just a tool. The question underneath why you're doing it is just why does it incident preparedness matter at all? Right? Why, why are we, why do we do it in the first place? NIST recommends it. SOC 2, HIPAA, uh, they all recommend some, some form of testing your instant response plan. And why is that? They, they all. It's because they, they. Every CISO knows what I just said previously. It's just, just no one remembers that exploit. They're all going to remember your response. You better, you better know that it's, that your team's ready for it, right? Um, the, the part that is unsolved yet is the human response after a breach. You know, when you think about, um, the time to average, time to contain. You know, IBM has their, their famous report for it. It's about 60 days and that number hasn't moved in the last five years. It's gone from like 75 days to like 60. Um, there are so many factors that go into that, but the primary factor when you, when you think about it is just this is a high judgment, high context activity. It's very easy to get wrong. You know, who is in charge when you have a breach like this? Who can call it a breach? Who can call this an incident? Who is it allowed to talk to? The regulator? That is where the breaches go sideways. And it's one part that no one has really figured out how to instrument yet.

Speaker C: Right.

Speaker B: No one has figured out how to own the part that decides whether an incident becomes a breach, a catastrophe.

Speaker A: Yeah, fantastic. I mean, I was, I was going to follow up with, you know, from those tabletop exercises specifically. Um, what are some of the gaps that become particularly obvious?

Speaker B: Yeah, yeah, it's, they show up in places you, you don't really expect. Right. The technical response. We encounter a lot of teams where the technical response is excellent. There's a human layer that no one has really spotted yet because a lot of the industry is still, um, doing preparedness as a discussion rather than as a practice. And I, I would say the clearest pattern is there is a difference between individual skill and organizational resilience. Right. Um, there, there are some teams where you're, you have like a, you have like a top decile team. You have, you have one or two people that are just excellent and actually those, those people can hide a huge risk where you have the confidence that you have an A player, you know, star Knicks team that is ready for the playoffs, and then you, you get on the field and you choke. We all, we all know what happens, right? There's, there's systems that you can build around this and we are interested in measuring that system. We're not interested in measuring individual capabilities. So the recurring gaps that we can spot with a platform like reflex that you can't really get from today's tabletop. One is decision authority. In, in many incidents you have a shifting decision authority in the incident because it's just not clear who's supposed to be taking charge here. Two is notification order. Are you notifying regulators on time? Um, when should I pull in my insurance provider? Um, it's, it's all simple stuff but just gets forgotten when the lights go out and you know, you've, you've got nerves. Right. Containment, uh, versus recovery is a big theme in, in some of the tabletops that we do where you, as a very strong technical responder, you may get tunnel vision on Fixing a technical problem but miss the bigger picture of the recovery where you think about the comms, regulators, you know, the comms to customers, it's tough. And you know, the final point that

Speaker C: you,

Speaker B: I think you can already kind of see from this is just there's a lot of tribal knowledge in, in, in the form of incident response right now that is very helpful, but only to one person is not yet organizationally helpful. Uh, what we want to do is, what we want to do is kind of instrument that for the entire organization. You know, that, that's, that's the part that we really want to solve for organizations who are just doing the discussion based preparedness today. Want to get you to simulation based preparedness.

Speaker A: Yeah, yeah, no, I mean it's, it's, it's fascinating to be honest with you. And um, we, and Matt and I have had lots and lots. We've done 70 plus episodes of this podcast now. And there's always a two letter word that we uh, that we talk about or has been definitely recently and that's AI. Um, we haven't spoken about it so much, um, you know, with just yet on this podcast. How do you expect AI to impact the future of incident response and maybe specifically through the lens of kind of tabletop exercises as well?

Speaker B: Yeah, I, uh, I'll tell you two things. The second one is, is a bit bigger, but in the near term you can now AI can simulate behaviors well enough that you can use it to simulate an incident. Right. That, that is what we are building now. It's, I'm using AI agents to pretend to be an adversary, to pretend to be a stakeholder. The press, the regulators and everything that each have a personality, each have um, actions that they take independently of the people that are. In the tabletop exercise, we had a tabletop where the attacker was going beyond the human team to other agents in the background to extract information about uh, about the environment. Um, which is really interesting. You know, you can kind of see it in the transcript there. But these are things that are going to happen in a real incident where you are going to have things beyond your purview that are going on in the background. Whether you choose to respond or not at a certain second is what changes the game. So if you can create this realistic simulation of, of an incident, you can dramatically improve the way you do incident response. And the analogy I like to give is you think about a, you think about your tennis coach, you think about your golf coach, right?

Speaker A: Uh,

Speaker B: they can only give you good feedback on your backswing if they're literally watching you do it, you have to be there. You know, you cannot. Security teams do not have that today. There are very few ways to watch someone, uh, swing, you know, swing a racket.

Speaker C: Right.

Speaker B: There are very few ways to do that. And the few ways to do it are an expensive incident. You know, you don't have to wait for that. AI is supposed to change the way we even conduct yourselves. Right. I mean everyone is using AI for a, um, as a, as a coach, as a therapist, as a, you know, as legal counsel. Um, yeah, we put all that in the platform so you can see yourself make the decision before the incident occurs.

Speaker A: Yeah, right.

Speaker B: I would say the, the bigger idea beyond that, it's, that's kind of near term, in the long term, we, you have to think about is there are thousands of thousands of incidents every year. There are thousands of tabletop exercises that each person is, each team is doing. No one has structured data on that. No one has structured data on the decisions that are made under pressure. We want to become that. You know, every, every large security company has owned some data set in security. No one yet owns incident response as a data set. No one can tell you, well, why did this incident take us four hours to resolve and why did this one take four weeks? That is still tribal knowledge. Uh, uh, if you can build that sort of intelligence layer, you can become a decision layer. You can become the sort of data that is training an agentic incident responder. You can become the data layer that is, um, that is training new SOC team hires even. That is an ultimate vision for AI in this space.

Speaker A: Yeah, absolutely. I think it's really intriguing how it's going to impact incident response and how, yeah, how it's impacting incident response today. Um, if you were to, I know it's so difficult. No one's got a crystal ball. Um, how do you see the tabletop market developing specifically over the next three, four, five years? And where do you expect to see it go?

Speaker B: Yeah, we, we already have a, a mandate for it. Right. So I'll tell you where it is today and what I think the future is going to look like here. So the, the mandate is, you know, three. I mean it's no longer nice to have this as a requirement. Right. You've got the SEC with a four day disclosure rule. You've got Dora, NIST, SOC2 are all getting stricter about how you test your incident response. Cyber insurance is grading incident response maturity when they renew your policies. So this is, this is a board down, uh, Activity. This is an underwriter down activity. Now we know we're going to have to shift the way we do this at some point. Right. The primary way you, you test, your instant response plan is just that, preparedness, uh, discussion. It's a tabletop exercise. And yeah, no, no one wants to do that because it doesn't achieve the ultimate goal. It's not actually, it's not actually a tennis coach watching you do the swing and you need to get to that. Right. So here's where this goes. In a few years, I think this goes the way that automated pen testing did a few years ago. Um, you think about the, the big winners in the space, they were able to turn a point in time pen test into continuous tested. Right. Um, that is very powerful and that's, that's the direction we should be going. You can see this in the same way, right? A tabletop. If we had one CISO who told us, yeah, uh, tabletop is basically just a people pen test. That is what this is. It does, does this incident responder know what they're doing when the lights go off beyond the plan? Because you, you rarely have time to consult it. And yeah, no, when, when the lights are on, when it's, you know, Game seven of the, um, of the NBA finals, you're not, you're not going to pull out the booklet, right? That's where this is going. There's, there's a sort of continuous resilience that we're moving to. Um, that is only possible when you have agents that help you simulate it.

Speaker A: Yeah.

Speaker B: So the, the tabletop is really a wedge decision layer is a, is a destination that we're trying to get to there. Um, so you can, and a rehearse. You, you, you build a learning loop and then you build better decisions in the long run.

Speaker A: Yeah, no. I'm going to wait to ask you about the basketball finals after the podcast. So listeners won't be able to get any previews into that, but I appreciate you giving insight into, um, into the technology and about table talks, where you see the market going, what the challenges they solve. It's really intriguing and it's, it's one that I think a lot of people will be watching, um, over the next, over years to come. Final question. Um, it's always the same. What one piece of advice would you give to someone entering the cyber security industry? Marlo?

Speaker B: I, I thought about this one for a while. I'll give you a football quote. Um, this is one of the Penn State football coaches. I, I'm a, that's my alma mater. Um, you're never as good as you think you are and you're never as bad as you think you are either. Uh, so know, conduct yourself accordingly.

Speaker C: Right?

Speaker B: There's I, I think that's both for, you know, investors who want to become founders and CSOs who become, want to become founders or you know, anyone really

Speaker A: in the industry because it's, it's a roller coaster journey, right? There are moments where you feel red hot and on top of the world and there are moments when you feel right at the bottom. Um, I get that and I think that's a great, great bit of advice to keep, keep yourself level headed throughout that, throughout that journey. Um, thank you very much for joining us Marlow. It's great to have all your thoughts and insights. Um, thank you for joining us today.

Speaker B: Thanks for having me.

Speaker C: Thanks Marlow.

Speaker B: Good man.

Speaker A: Thank you very much.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Cyber Ranges, Attack Simulations & AI: Proving Cyber Readiness | Interview with Lee RosseySecure & Simple · on Incident response86 / 100
  • Stories from an Expert Threat Hunter with Taz WakeCyber Leaders · on Incident response82 / 100
  • The Journey to VP of Marketing Ops - Kimi CorriganRevOps FM · on Expel82 / 100
  • Ep 116: Ask a CISO with Steve ZalewskiLevelUp Cyber · on Incident response79 / 100
  • #168 | From Chaos to Clarity: Change Management, Strategic Simplicity, and the Networking Muscle You Never Built w/ Iryna Lambrianides @ClarLeman Tech Leadership Podcast · on Organizational resilience75 / 100
  • Ep.31 Aaron Gracey | The Leadership Conversation Every Business NeedsBe You Start Now · on Organizational resilience72 / 100

More from The Cyber Security Matters Podcast

All episodes →
  • AI, Patch Management & Endpoint Security: Mike Walters on the Future of Cyber Security - Episode 73
  • AI Agent Authentication & the Future of Identity Security - Ep. 72 - Brian Bell, FusionAuth
  • Fix It, Don't Just Find It: How AI Is Finally Solving Vulnerability Management - Episode 71 - Dominik Richter, Mondoo
  • Securing the Agentic Endpoint: How Manifold Is Building AI Detection & Response - Episode 70 - Mike McKenna, Manifold Security
  • AI Is Making Social Engineering Unstoppable, Here's What You Need to Know - Episode 69 - Bobby Ford, Doppel
Explore the best B2B Engineering & DevTools podcasts →
All The Cyber Security Matters Podcast episodes →