The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/The Security Repo
The Security Repo artwork

AI, Automation, & Humans' Role In Security: A View From Rsac 2026 With Jeff Man and Dwayne McDaniel

The Security Repo · 2026-04-01 · 43 min

0:00--:--

Key moments - from our scoring

Substance score

38 / 100

Five dimensions, 20 points each

Insight Density9 / 20
Originality8 / 20
Guest Caliber7 / 20
Specificity & Evidence7 / 20
Conversational Craft7 / 20

This episode captures two seasoned security professionals reflecting on RSA 2026 and the rapid mainstreaming of agentic AI in security operations. Dwayne McDaniel, principal developer advocate at GitGuardian, and Jeff Mann examine the shift from theoretical AI discussions last year to immediate operational urgency around credential theft, PyPI ecosystem compromises (Trivy, Kicks, lightLLM), and machine-speed attacks. The conversation centers on whether automation and AI will finally close the skills gap in security, enabling real-time defense and multiplying workforce capacity through tools like ChatGPT for scripting and threat investigation. Both speakers emphasize the critical distinction between using AI as genuine problem-solving infrastructure versus treating it as another checkbox compliance tool. They reference the Cloudflare CISO's insight that AI represents the "last best chance" to defend in real time, alongside the allegory of three stone cutters - differentiating between those paid to cut stones, craftsmen with superior tools, and builders constructing cathedrals. The episode tackles reactive security budgets, governance-as-conversation (not vendor platforms), and the necessity for humans to understand business impact and systems-level thinking (invoking John Willis and Edward Deming's theory of constraints). Real threats discussed include AstraZeneca and Salesforce breaches, minute-long dwell times, terabyte exfiltration speeds, and potential self-advancing automated bots stealing tokens to fund further attacks.

Key takeaways

  • →AI and agentic automation must be viewed as tools for solving real security problems and building defensive capacity, not checkbox compliance features or ways to avoid human judgment.
  • →The industry remains stuck in reactive, slow-moving governance patterns from 20 years ago while attackers operate at machine speed with minute-long dwell times and automated token theft.
  • →Security leaders need to shift from task-level thinking to systems-level thinking and business-impact awareness, understanding how decisions affect the entire organization rather than just responding to isolated alerts.
  • →GitGuardian focuses on credential visibility and secret management, addressing the core problem of hardcoded credentials and access control across development ecosystems.
  • →The human element - gut instinct, business understanding, and the ability to recognize what doesn't look right - remains irreplaceable even as machines accelerate data processing and detection.

Guests

Dwayne McDaniel

Topics in this episode

Agentic AIZero trust architectureSOC automationGitGuardianCredential managementPyPI ecosystem attacksTrivy breachCloudflare CISO perspectiveEdward Deming systems thinkingJohn Willis DevOps philosophy

Questions this episode answers

What is the biggest security threat emerging at RSA 2026?

Agentic AI and credential theft spreading through the PyPI ecosystem (affecting Trivy, Kicks, and lightLLM), combined with machine-speed attacks that can exfiltrate terabytes in minutes and potentially involve self-advancing bots stealing tokens to fund further ecosystem compromise.

How can AI actually help close the security skills gap?

AI can automate repetitive tasks like manual CVE lookups, vulnerability database queries, and reachability checks, multiplying the workforce capacity of existing analysts and enabling level-one SOC elimination through better automation and decision support.

What does GitGuardian do?

GitGuardian provides visibility into hardcoded credentials and secrets across codebases and ecosystems, helping organizations index and manage what credentials have access to what resources.

Why is governance not something you can buy as a platform?

Governance is a set of conversations, agreements, and risk-understanding decisions that require human judgment and organizational alignment; tools can support governance work, but they cannot replace the human dialogue and decision-making required.

What is the main risk of treating AI as a compliance checkbox?

Organizations may assume technology solves security problems without integrating security into business strategy, operations, and risk management, perpetuating the false belief that tools alone can secure an organization.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

9 / 20

The episode contains a handful of genuine ideas - automated self-funding credential-stealing bots, the Cloudflare framing of AI as the "last best chance" to close the skills gap, and a systems-thinking critique of security budgeting - but these are buried under lengthy RSA small talk, anecdotes, Star Trek tangents, and a farewell monologue. The insight-per-minute ratio is low.

My big fear is automated self, uh, self advancing bots that keep paying for themselves with stolen tokens so they can steal more tokens so they can keep advancing into the ecosystems
we're still mostly stuck in being reactive... we're moving almost the government speeds

Originality

8 / 20

Most takes - security-as-checkbox, people-process-technology, zero trust isn't new, AI as automation - are well-worn. The framing of Goldratt's The Goal as proto-zero-trust architecture is a mildly fresh angle, and the self-sustaining bot hypothesis is interesting, but the episode largely recycles conference-circuit consensus views.

believe it or not, it's a book about zero Trust architecture just 30 years before that even was ever said out loud
I can't sell you governance. No one can sell you governance. Governance is a giant set of conversations and agreements and risk understanding

Guest Caliber

7 / 20

Dwayne McDaniel is a Principal Developer Advocate - a vendor evangelism role - at GitGuardian, and Jeff Mann is a security consultant and podcast host; neither is a CISO, operator at scale, or practitioner who has built and run large security programs. Both are thoughtful practitioners but not the senior operators who have done the thing at enterprise scale.

I'm a principal developer advocate at a company called Git Guardian
I've been doing information security more from a consulting advisory perspective for the last 30 years

Specificity & Evidence

7 / 20

There are sporadic specifics - the PyPI credential-stealing spread, name-drops of AstraZeneca and Salesforce, PHP Stan, 6,800 Drupal modules, and three concrete book recommendations - but most claims about dwell times, machine attacks, and attacker speed are stated without sourcing, and the RSA Cloudflare talk insight is paraphrased loosely with no data behind it.

the trivia breach, then it spread to kicks and now, uh, light LLM. And if you go to any of the trackers out there, it's spreading through the PyPi ecosystem like mad right now
dwell times of minutes. Uh, will start exfiltrating terabytes of data. Uh, don't believe me. Ask, uh, AstraZeneca. Ask Salesforce

Conversational Craft

7 / 20

The table-turning format (guest interviews host) is a mild structural novelty, but the questions are soft and generic - standard RSA impressions, what-are-we-getting-wrong, and a rote four-question closing sequence. There is no meaningful pushback, no challenged assumptions, and the host frequently delivers monologues longer than the guest's answers.

I have to ask, since you're at the RSAC conference, how's it going this week? Anything new and exciting?
what are we doing wrong in our industry and what are we doing right?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B55%
  • Speaker A45%

Most-used words

security52back17show15last13level13automation13first12machines12world11access11part11technology11question11saying10jeff9help9

Episode notes

In this episode of the Security Repo Podcast, Jeff Man and Dwayne McDaniel unpack the shift in cybersecurity from talking about AI as a future concept to confronting agentic AI as a present-day security reality. They explore what the industry is getting right and wrong, from automation’s potential to help close the skills gap to the ongoing danger of treating tools, compliance, and governance as substitutes for critical thinking. The conversation also turns personal, with reflections on security careers, favorite tools, timeless advice about access and trust, and Dwayne’s announcement that this chapter of the Security Repo Podcast is coming to a close. About Jeff Man: Jeff is a respected Information Security advocate, advisor, hacker, evangelist, mentor, teacher, international keynoter, speaker, former host of Security & Compliance Weekly, co-host on Paul's Security Weekly, Tribe of Hackers (TOH) contributor, including Red Team, Security Leaders, and Blue Team editions, and a member of the Cabal of the Curmudgeons.

Full transcript

43 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hey everybody. Welcome back to another episode of the Security Repo podcast. As always, I'm your host, Jeff Mann. Want to thank everybody for their likes and subscribes as we travel together on this journey through learning and understanding security. This week I have a very special guest and I'm happy to have him on the show. Please welcome Dwayne McDaniel. Dwayne, why don't you introduce yourself and tell us how you got into security.

Speaker B: Oh, thanks, Jeff. I'm excited to be here. Thanks for having me. I'm a big fan of your show.

Speaker A: Thanks.

Speaker B: Um, I am Dwayne McDaniel. I'm a principal developer advocate at a company called Git Guardian. Um, I'm at the end of RSA recording this, so if I sound a little bit like I'm pitching my product, I'm trying not to, but I'm very much in that mode. Um, we help people get visibility into their hard coded credentials out there in the world. So that's the world I live in. Um, uh, finding secrets, uh, indexing secrets within vaults and things like that. So that world of like, what gets access to what, that's kind of where I live in security. My background actually came from, uh, the platforms, DevOps, uh, some developer tooling. And I became a developer advocate about a, ah, decade ago. Uh, 2014 was the first time I started doing the role and um, I, uh, love it. I help, I see my entire job in life is to help people figure stuff out. Five words. If I'm doing that, doing my job and I, and if I'm helping you figure something out today, Jeff, then I'm definitely doing my job today. So thanks for having me.

Speaker A: So, uh, I have to ask, since you're at the RSAC conference, how's it going this week? Anything new and exciting?

Speaker B: Well, there's always new and exciting things. Um, uh, it's a different mood this year. I, I, I feel like, uh, that just to be honest with you, uh, last year felt a little blah. We're going on. AI is becoming a thing this year. Ah, a couple things to note. Um, AI has become real agentic. AI became real, uh, in the last year. It wasn't something in the future. Now it's like something we have to deal with with security. And it's a few things have happened. The trivia breach, then it spread to kicks and now, uh, light LLM. And if you go to any of the trackers out there, it's spreading through the PyPi ecosystem like mad right now. Credential stealing. What's going on that's happening in the background on top of all the good conversations at the show. Uh, if anything, besides San Francisco, which I did right before RSA and RSA itself, they're a good reminder that people are doing all of this. Like, people are behind security. So we're doing the good stuff and we're doing the bad stuff, but we're just people. At the end of the day, we're human beings, and it gives us a chance to have those conversations. Uh, I, I think my favorite part of RSA has been so far an, uh, event, uh, from futurecom, our futurecon. They put on bourbon banter. And it's my favorite thing every year. And one, I love Bourbon. One, I love Bourbon. But two, it's, uh, just the quality of the conversations I had with operational technology people. Uh, I met a guy who's literally, uh, helping his company get rid of fake employees from North Korea. And, like, what that day to day looks like. And it's not, not selling each other anything. We're just, hey, I'm struggling with security. You're struggling with security. How, how are you doing it? And can we help each other out? And that feels inspiring and good. So I feel very excited. If I seem a little manic right now, it's because I, I am. I absolutely love what I get to do for a living, and I love the people that are doing it, like yourself. How's your RSA been?

Speaker A: Yeah, big reveal. I was also at the RSIC conference. Um, yeah, I've been going for quite a few years, and I think two, uh, years ago is when AI sort of first started bubbling up and people started talking about it. And it was very much forward thinking, oh, yeah, yeah, we're doing it, or we're going to be doing it, or we've been doing it for five years. Last year, it seemed to be more getting built into the products and the service offerings, um, but still very, very much hypothetical. It almost seemed my, my view of the vendors last year, uh, collectively was there's almost a sense of desperation. We've got to fit AI into the conversation somehow. And then this year, as you said, Agentic has become much more the mainstream and, and vibe coding. And, uh, now there, there's certainly been a shift to, oh, we, we've got to deal with AI. It's here now from a security perspective. And so me, the shift in the conversation was, it's here now, it's here to stay. How do we secure this thing? So I know on the show we always like to ask, uh, a couple questions like, what are we doing wrong in our industry and what are we doing right? And I guess I would ask that question to you to get your opinion, but also, uh, as a part B to that question, what do you think we're getting wrong and what do you think we're getting right? Um, if you lay over the AI agentic, uh, you know, part of the

Speaker B: whole conversation, uh, that's not a loaded question at all, Jeff. Um, but no, I, I appreciate that, honestly.

Speaker A: I mean, it's kind of a question that demands being asked right now.

Speaker B: It really does. Um, I think my favorite thing I saw at rsa, like, I love going to the actual talks. Um, for those of you who've never been to RSA conference, yes, there is a giant expo floor. Yes, it is a lot of vendors trying to sell things to each. Uh, but there is some real, really, really good analysis and intelligence being shared throughout these sessions. I, uh, went to one from Cloudflare, the uh, CISO of Cloudflare and the head of some other part of security of Cloudflare, but like the two top, most level Cloudflare, and they said it very succinctly. AI provides us the last best chance we have to close the skills gap in security and actually possibly get to a point where we can defend in real time. And I loved that because if we do nothing else with all this AI, we can automate all the things. Why am I logging into virus total? Why am I, uh, logging into any system to see a CVE score? Why am I saying, is this reachable? These are things I could mechanize with the script. And honestly, I ain't got time to write that script, but does chat, GPT does. And if it works and it's a script and it adds to my abilities like any other automation, that's a good thing. And I think we should be embracing as, uh, hard as we can, automation in security. And notice I didn't say the word AI there. Um, AI is just a way to automate and if we see it as a tool. My second favorite thing I heard in all RSA was a, ah, joke, um, an old story, I guess. That's not really a joke, it's a allegory, I guess. Um, a guy walks up to three stone cutters and it goes up to the first one and says, what do you do? And he's like, they pay me to cut stones. I cut stones because they pay me. And he goes back to work. It's like, okay, goes the second guy. It's like, what do you do? He's like, I am an artisan. I'm a craftsman. I have the best tools. My tools outshine everyone else's. I can carve any shape. I make the smoothest stones. I know techniques that no one else knows. I've been doing this for a long time. I am an artisan. And he goes back to making carbon stone. Goes up. The third guy who's working harder and faster than the others, he says, what do you do? And he looks up briefly and says, I'm building the cathedral, and goes back to work. And we need. We need to be building cathedrals. And if we're not, if we're using AI Just to use AI to be smart, um, for you. But if we're using AI to help us build and solve problems or build solutions that solve real problems, I think there's an optimistic future there. Now, the downside to this. What have we gotten wrong? Is we're still mostly stuck in being reactive. Ira, uh, Winkler, a few years ago, gave a talk that stuck with me, and it made me rethink basically everything I do in. In the world of security, uh, called your security budgets is a horse's ass. It's a great talk. Uh, m. No matter how you feel about Ira, uh, uh, he. He's, um. No more said there. It's a great talk. It's, uh. We're built. We're still building our security programs the way we did 20 years ago. And we're moving almost the government speeds. I mean, governance is in what some. What we do with the GRC especially. And we're just moving slower than reality is keeping up. And we're not allowing budgets. I'm not saying everyone. I'm saying in general, what I'm talking about. When I talk to audit people, GRC people at the show, it's like, what are you doing about this? It's like, well, we're waiting to hear. And like, if you're waiting to hear instruction, if you're waiting for someone to explain this, if you're waiting for the problem to become more real, that you can put a rule around it, you're. You're. You've already lost. The attackers are not waiting. The attackers are using this at speeds that were inconceivable before dwell times of minutes. Uh, will start exfiltrating terabytes of data. Uh, don't believe me. Ask, uh, AstraZeneca. Ask Salesforce. We're seeing machine attacks right now. That, uh, my big fear. My big fear. Jeff Just to get real with the audience and you. My big fear is automated self, uh, self advancing bots that keep paying for themselves with stolen tokens so they can steal more tokens so they can keep advancing into the ecosystems. And I don't know if that's what we're seeing right now with the Pypy ecosystem, but I hope not. I hope that's not what we're seeing already. I know I said a lot.

Speaker A: Um, no, that's good. And, and what I'm hearing from what you're saying and sort of applying over uh, you know, my experiences over the last, well in total over 40 years. But I've been out in the private sector uh, for 30 years and you know, 30 years ago at the beginning of this whole thing, uh, that we now call cyber security, it was companies that were just starting to get onto the Internet because they, it was the new frontier and how could we engage in commerce, how can we make money on the Internet, how can we exploit it, take advantage of it? And so I was building some of those as you referred to 20 year old archaic policy defense first type of um, programs. Um, but uh, I used to use uh, an analogy, ah, similar to the stone cutters or more simplistic. And I'm old school, I like to do things by hand and I like to have control over it. The war games mentality, you never want the machines to take total control. Um, so I just simply used to talk about here, I'm going to hand you a palette and some, some paints and here's some brushes and here's a canvas. You've got all the tools now go paint a masterpiece. And obviously not everybody has the skill set. So there's a uh, there's a simile somewhere between your story and what I used to say. But uh, what I'm hearing you saying in terms of catching, I almost hear we have the opportunity to catch up. Now. I acknowledge that automation is necessary if we're going to have any clue, any sense of winning, uh, winning being uh, either not being breached, not suffering the breach or at least minimizing the damage caused by a breach or a compromise. Uh, so I almost feel like the rise of AI and the awe automation that, that, that has AI in it is giving us sort of the last fighting chance to catch up and, and maybe stay afloat in the, in this, you know, huge game. I started my career back in the uh, with the government during the Cold War where it was this, the analogy was always it's a game of cat and mouse and in some ways we could probably still use that analogy but just keeping ahead of the neck, the bad guys and the adversaries, uh, and of course with so much more complexity these days and so much more speed if nothing else, where we absolutely have to use the, the agentix and the AI and and the best automation tools that we have to offer. I, I still hold out hope as a crotchety uh, old curmudgeony old timer that um, it's. If we have all that automation and we have all that technology in place to hedge our bets and to better our uh, posture, there's still a need for understanding what it all means. There's still a need to recognize, detect and respond. Obviously the automation is going to do a certain amount of that. But um, I'm still kind of old school to think you want the two person control turning the keys before you, you, before you, you know, set off World War iii.

Speaker B: Abs Absolutely. Um, it's strange but I'm feeling more optimistic today than I was feeling more optimistic today than I was even a week ago. Just from all the conversations like six days straight of B side San Francisco talking to all the practitioners, seeing what people are really doing out there and then at RSA having the back channel conversations where people are talking about eliminating level one sock. Uh, we're talking about automation and multiplying the workforce through uh, through these, these channels and through the automation. Um, it's strange but I feel like we need, still need more people in security. They think there's still a giant gap. And before I really did feel like well what are the people that are up and coming doing? And if you're out there trying to like learn how to zero day and learn what a buffer overflow is, these are still good things you're going to need to know. But I think we've shifted and it's shifted very fast. And I don't know if enough people are talking about this that it's more important to understand the business impact. If you, if we do this, what other systems get affected if you can do systems level thinking, uh, strangely enough the older I get the more I agree with John Willis over in the DevOps community. I've never not agreed with them but the more I think it's true, like he wrote a book on uh, the wisdom of Edward Deming and systematic thinking thinking about the whole system. All you do, if you put a constraint in one part of the system, all you do is create a different constraint somewhere else. If you solve that one, it's a game of whack a mole. And if that doesn't describe security, I don't know what does. But it's the people that can step back and say, I'm the human AI told me this. My alerts over here told me this. I have to make a decision right now. That decision affects the human beings that I work with. What do I do? Empowering people with more information, the right information to act with more urgency is good. And I think we need to start training people to think bigger than just what's in the. What's. What am I looking at at the prompt? What am I looking at at this machine level? Bigger. What is this affecting? What. How does this affect the cathedral? If I'm, um, to use that analogy from earlier, but I think I feel optimistic. I feel optimistic we can get there really now.

Speaker A: Optimistic that we can. I love the phrase and I hear it all the time, you know, at rsa and I talk to lots of vendors and so on and so forth with the podcast that I'm a part of. Uh, everybody talks about winning and I always think, what do you mean by winning? Um, I think in a commercial sense, if I was going to answer the question, or an economic sense, it means staying in business. Business and hopefully staying profitable. Or if you're a non profit, you know, making a difference and making an impact in the way that you want to make that impact. Um, again, being an old timer, you know, a lot of the things that you're talking about and a lot of the things that I'm seeing is the new ideas. You know, something like, uh, you need to focus on the data. You know, it's all about the data. You need to have zero trust and, and focus on that. Or you need to have a larger picture, as you were just saying. I Learned that stuff 40 years ago when I was working for the government. And I've been trying to explain that to people in the private sector, the customers that I've had over the last 30 years of doing security consulting. Um, so I chuckle a little bit that these things are finally coming into vogue and it's a good thing. And I guess I should think it's. I do think it's a positive thing, but there's also a part of me that's like, I, I've been saying that all this time and people just weren't listening. And where I'm, I'm not usually. I was, I was optimistic last year coming out of rsa. I'm a little bit more neutral this year. But, uh, where I was Optimistic then. And where I would place my optimism is that we're finally getting around to taking security seriously in a business sense and, and not simply running around and thinking that all I have to do is drop some sort of technology in place to enable the security to make it go away. And this comes from. I've been doing compliance for over 20 years. Um, it comes from an attitude of what's the bare minimum I have to do to do security. I think more companies are finally figuring out that they need to integrate a security plan into their business in order to survive. Not, not just win, but maybe, you know, live, survive. Um, where I, where I think we're still getting it wrong, where I think that, ah, we still have work to do is to, to convince more organizations to, to, you know, start thinking bigger and thinking more holistically about the security as it applies to the business. And where I'm, uh, pessimistic or cynical or concerned. Is that because automation is a term that you used and AI is sort of the umbrella for all the different things, that's another technology, that's another automation. So I'm concerned that people are going to think that we have this now, much more powerful technology and we're going to get back to, well, it's doing it for us so we don't have to think about all the other things involved. I guess that's where my m. I guess I'm concerned. That's the word I'm looking for. I'm concerned that it's another level of automation that's just going to reinforce this bad habit of thinking that technology is going to solve all my security problems in an org. At an organizational level.

Speaker B: It reminds me so much of, well, to quote a great speaker I heard once, uh, uh, he said something, security equals compliance. He said it, I think in a, in a, um, clickbaity fashion. But, uh, oh, yeah, that was you. That was you. You gave that. Oh yeah, that was me.

Speaker A: And I actually said compliance equals security.

Speaker B: I'm sorry, you're right, you're right. But you did something that, an object lesson in it that stuck with me. Really, it did. Uh, uh, where you asked the room, what does security mean? You got like 12 different answers. And you're like, you're not wrong. You're not wrong. I was like, what does compliance mean? I was like, we did the thing. And that really struck me because if we see it as compliance, we see as a checkbox. If we see it as we got the tool, therefore we're safe. We've gotten it completely wrong. But hey, what can I do to be safer? What can I do to mitigate, uh, what's going on in the world and make a plan? And you wrote that plan down and then you said, I did these things on my plan. That's a good idea. That's a really good idea. It's something I've been saying a lot lately is I can't sell you governance. No one can sell you governance. Governance is a giant set of conversations and agreements and risk understanding. And it goes so far beyond the computer. It's how, how do we make ourselves together, work and put policies and processes in place? That's governance. Do you use tools to help you do that? Yes. Yes, you do. And there are great tools out there that can help you do that. Um, but thinking I'm going to buy a governance platform misses the entire point. And that's what can still concerns me at the industry. But man, that's always been the case. That's true in DevOps. That's true. And everything I've ever worked, my tool magically solves your problem as every vendor's promise. But the reality is, if you're willing to do the work to try to solve the problem, we have tools that will help you along your journey. That's true of everywhere I've ever worked. And we have to have that human level conversation. And as I getting back to my optimism, I saw that level of human understanding and like, aha. Moments this week of people being like, we can't beat the machines now. The machines, the machines have won. The machines have won. What do we do? Oh, wait a minute. We're all, we're all humans. What can we do that the machines can't do? What should we be doing as humans? And I've really started to see that level of conversation emerge. And that's, that's what's driving my optimism.

Speaker A: Yeah, we have this machine, uh, in our head that we have not yet been able to, uh, completely replicate, uh, in a technology sense. Certainly we lose on speed and we lose on the ability to sort data and search data and find answers. But there's a, there's a level of cognitive ability that we have, plus other things that go into how we make our decisions. You know, you sort of mentioned the gut and the feeling, um, or you were inferring that, you know, sometimes you have to go with your gut and because you have a sense that something is about to happen or something just happened or that doesn't look right and you need to do something about it, um, I'm, I'm optimistic that we're going to catch up. I'm, I'm concerned that we're gonna, you know, the collective, we are gonna fall back into thinking that the machines are gonna do all the things for us. It kind of reminds me of an old Star Trek episode. And I'm, I'm an original series Star Trek kind of guy. I never can remember what the, the name of the episode is. Um, but the premise is they come across this planet in this solar system that's been having a war with this other planet for like centuries. And it's, the war is completely, uh, fought by computers and, and computers on both sides doing computer simulations. And every once in a while, uh, you know, you're. All the citizens were, uh, wearing like this little necklace and the light would light up and it means, oh, you just got killed in a, you know, a war game. And so they had, both sides had agreed, uh, to honor this. You have to go to some facility where basically you're executed and your life is ended. And they did, because they didn't want to destroy their culture, their buildings, their society, people. Yeah, not so much. Um, and of course the Enterprise and Captain Kirk came in and said, that's stupid. So he pulled the plug on the whole thing. He said there's something dirty and nasty about war that automotive you to stop it. And, uh, maybe that's not the best example, but I just, I can just see where we're going to get to the point where the machines are fighting the machines and maybe we become collateral damage. I mean, that was the warning, the prophetic warning of Star Trek back in the 60s.

Speaker B: Um, love star Trek.

Speaker A: Yep. Ah. As, as the viewers and listeners have hopefully, uh, figured out by now, we kind of turned tables a little bit on this episode. Uh, and, uh, hopefully they noticed this

Speaker B: is the first time listening to this show. They would have no idea. Jeff.

Speaker A: That is true. So, uh, Dwayne and I were talking last week and he was telling me about this podcast and I said, hey, you should have me on sometime. And we came up with, with these ideas since I do another podcast, it's called Paul Security Weekly, where we often interview people. I said, hey, have you ever been interviewed on your show? And Dwayne said, no. I said, well, let's turn tables. So, um, shifting gears a little bit, getting to know you a little bit, uh, any, any advice, anything you want to put out there, uh, for your listening audience. And then you have a similar tradition as we do on our show to Ask a set of questions to close out the interview.

Speaker B: Um, the best advice I can give anybody out there in the world personally, um, is to one, go to security conferences. Uh, go, go to conferences. Go talk to practitioners. Go talk to people. The only reason I sound like I know what I'm talking about at all is I am constantly quoting people who are much smarter than me. I'm standing on the shoulders of giants and just trying to replicate what they say in a way that made sense to me. And hopefully it's helping other people. Uh, there's a specific book, there's a bunch of books if you talk, I read constantly. Uh, there's a bunch of books I could recommend. But the, the two that I think are the most relevant to today's conversations are one, believe it or not, Elliot Goldratts, uh, Elliot Goldrat's, uh, the Goal. It's, uh, what, um, the Phoenix Project is based on. The Phoenix Projects is good. Phoenix Projects is good. If I recommend three books, I'd be third on the list. Uh, but the Goal is about systematic thinking. It's about manufacturing. But manufacturing is what we do. We build software factories today. That's how software gets built. Um, and if you can think in systematic thinking and see where controls go, you see where, um, choke points are, you see where the bottlenecks are, you see what constraints mean. Believe it or not, it's a book about zero Trust architecture just 30 years before that even was ever said out loud. Uh, because it's about the concepts of control and flow. Um, and the second book is from our friends over at the Cloud Native Foundation. Um, plenty of computer foundation called Spiffy. Uh, or it's called Solving the Bottom Turtle. Uh, it's the Spiffy IO book. It's free, it's 198 pages. It is a fascinating read, and it will make you reexamine the way you think about how identity works across trust boundaries in our architectures. It literally changed my life. Um, and I couldn't recommend that book more if I just couldn't recommend it more. And the third one, the, ah, third one would be. Then Phoenix is the Phoenix Project. Um, it's so good. But if you read the Goal first, if you read the Phoenix Project and then read the Goal, you're like, this is just. They just rewrote the goal with DevOps instead of manufacturing. And they did. But Gene Kim, they did a great job. Don't you do a great job? It's a great book. But, uh, those are the three. And if you got More time. Read, uh, the entire Dune saga, the first, uh, six books from, uh, Frank Herbert, uh, God Emperor Dune has my favorite quote that I use all the time. Um, what is the danger? Why did the Butlerian Jihad happen? Why did we have to destroy the thinking machines? God Emperor Lido gets asked this in the fourth book, and he says, what do such machines do? They allow you to do things without thinking. Doing things without thinking. There's the real danger.

Speaker A: Yep. And the whole idea of zero trust architecture, as you said, it's not a new idea. I mean, you know, uh, and boiling it down to critical thinking and so on and so forth. Yeah. I mean, maybe we just needed to have a, um, clever marketing campaign and a buzz phrase like zero trust and to get people to start thinking again. The temptation, though, I think for most people is to just tell me what I need to do. Don't make me think about it, because that makes it sound too complicated. I did a talk many years ago where I had a slide where I put up the classic three legs of the stool. In terms of how we used to talk about data or information security, maybe it applies to cyber security, but the idea that it's people, process and technology and a combination of all, all three, and the, uh, the illustration of it being a stool is that they need to be equally balanced. And clearly they have not been equally balanced. But I added a fourth leg to that. You can, you can spend all your life worrying about those three things, but to imply that you need to think about it, I added a fourth leg being purpose. Know why you're running around trying to figure out all the other three things. In fact, I interviewed, um, uh, this past week at rsa, interviewed the CEO, uh, and the president of rsa. Not the conference side of rsa, but the people that are still building stuff side of RSA because they disbanded a couple, um, divested, I think it's the term that they used a couple years ago. And uh, I was telling them about that, uh, concept, uh, and I started by saying, you know, when you think of the classic three people, process, technology, I, I have concluded after all my years, what is, what is looked at the least and what fails the most is process. And the president, who's more the technical, technical of the two, he said, well, I think it's people. And I said, well, maybe it's semantic. How about people don't follow the processes? And he said, okay, you got me. So anyway, uh, I think the bottom line, I think we're. But what we're both agreeing on is there's, there has to be some critical thinking in the thought and decisions made. I mean even with the, the promise of AI, not uh, everybody at every level of organization, not every type of organization can afford to do all the things that they need to do. Uh, especially if you thought you, you know, go into the vendor floor and you think you have to buy one of everything you can. But uh, so you have to, you have to make some decisions and you have to make some risk based decisions which is what this is all about. How much can you afford to spend or not spend the likelihood that something good or bad is going to happen? Um, that's what keeps us all in business. It keeps me in business as a consultant. I go in and try to get people to think about what the decisions are that they're making and how they want to uh, uh, satisfy uh, a particular security requirement or compliance requirement. Anyway, that's a little bit about me. Um, are you ready for, for your own four questions?

Speaker B: I actually am and I didn't pre think these, so you're going to hear some raw takes on this. Honestly. Weirdly enough I've never thought about the answers to these myself. So let's go.

Speaker A: We, we have the same experience uh, on our show with our uh, what we have is the five security five questions for Paul Security Weekly. All right, number one, what is your favorite security command line tool?

Speaker B: It's technically not a security tool but it is a command line tool and that is PHP. Stan. I'm an old PHP dude. I'm from the Drupal and WordPress world. That's where my platform days were and phpstan was my first exposure to static analysis. Why I understand what static analysis tools do is because of php, Stan. Uh, I used it in a project years ago called uh, the Drupal 9. The Drupal 8 readiness project project. It's still on GitHub. I did a really dumb thing and I installed every module you could possibly install at the time over uh, 6800 modules, uh, into a Drupal site. Yes, that's bloated as it sounds. And see saw if from Drupal 7 to Drupal 8 is this module ready to go into the system? And in the process I really deeply understood how the analysis worked with the rules engine was. So when I first did move over to the security world it was like oh, this is just PHP stand applied to looking for this patterns versus that pattern. And to this day it's still my favorite. I don't run it anymore. I Don't develop PHP anymore. But thank big shout out to Matt Gallman, uh, Galman, uh, out there, who.

Speaker A: But do you work at the command line level anymore?

Speaker B: I open the command line every single time I'm at work because it's just so much more efficient to do so many things.

Speaker A: Cool. Um, all right, what's your favorite interview question that you've been asked?

Speaker B: Interview, like job interview? Um, I wrote this question. I don't know why I'm sounding surprised, but job interview question, um, is that open ended? Uh, why, why us? Why, why do you want to do this? And every time I've ever been asked that and I didn't have a good answer, in my heart, I knew that was the end of the interview.

Speaker A: Right. But we're, this was supposed to be a job interview question. Got you. Oh, yeah, yeah.

Speaker B: No, no, we, we got there, man. Um, but no, it's, it's true. If, if you don't have the passion. I, I had a old boss of mine, Gary Nakamura, uh, years, uh, and years and years back who believed in me. He literally saw the fire and the passion. He's like, why, why here? I'm like, you're on the forefront of technology. You are literally delivering something that I think is important and I want to

Speaker A: be a part of this.

Speaker B: And he said, you're not qualified to do this job, but the want to is more important than the can do. And he gave me a shot. And that's literally how I started my career in tech, uh, my proper career in tech. I'd worked a few measly other jobs other than that, but that was my first career move. Uh, because he saw that I was passionate. And if you have that passion, you chase that passion and someone has that passion, give them a chance. Uh, they might, it might not work out. Can't guarantee, but the want to is so much more important than the can do.

Speaker A: Good answer. Um, what is the best security advice that you could give to someone?

Speaker B: The absolute best security advice, in my opinion, is to understand how the access is happening. That's a very broad thing and it applies to every system you'll ever interact with. If it's you logging into a website, understand how that works. If you're logging in through webauthn flows, understand how webauthn works. It's not that complicated once you actually see it on paper. If, uh, you're using OAuth based flows, OIDC, just, just have a concept of that and just realize that the machines are doing that at millisecond speeds billions of times a second across what we've built in this Internet. And that is the core of so much of what we do in security is is this entity allowed to talk to that entity? How does that conversation. That's what PKI is. That's what RSA literally is at the core of it. Does this allow to access that? Uh, and I think not enough people think about that day in, day out as like, how am I secure at access? They're thinking, how am I securing my app? That's great and all, but if I can't. If I can access your app, then you should worry about that. If I can't access your app, you just limited entire area problem. Like when I used to build Drupal modules and teach people Drupal. Um, I would say, all right, everybody make a circle with your fan and put it down on the table. You're looking at the most secure thing you can ever possibly build in the entire world. That's not. I can't attack that. There's no way that can go offline. It's not online. But that's the safest thing ever. Uh, and think about access from that point out.

Speaker A: Right. And I, uh, hear in your answer, you're reflecting again what we now call zero trust architecture. But, you know, why do we have identity and access? And then why is that an issue? I mean, on our show, we've boiled it down. Uh, it's been a couple years, uh, since we talked about it on a particular episode. But it all boils down to, you know, what are the biggest weaknesses? And it's still user id and it's still trust. You know, so it's access, it's trust. And it's built when I was, you know, cutting my teeth, learning all this stuff working for the Department of Defense back in the late 1900s. Um, back then, we called it authentication and authorization. To me, I don't know why they haven't needed to change the terms, because I get those terms, but whatever works. Whatever gets people to a level of understanding, I guess. All right, so sort of a variation on what's the best advice you can give? Wrong answers only. What's the worst security advice you've ever received?

Speaker B: Nobody knows it's there. We're fine. Um, security through obscurity. Uh, through obscurity. Um, I can't even begin to tell you. Back in my WordPress days, the number of people is like, oh, I literally just moved where the login page is, therefore the bots won't find it. I was literally told that by people who built websites for a living, for other human beings. And it horrified me because they didn't know what fuzzing was. Uh, this was before I was in security, but I knew what a fuzzing pool was. Uh, it's not that hard to find all the endpoints. The Internet works that way. And I knew that fundamentally. And I would just tell them, like, just because your house doesn't have a front door doesn't mean there's not a door. It doesn't mean there's not a window. There's doesn't mean I can't get in. And I. I hate to keep harping back on access, but literally, that was the worst advice I had ever heard. And I heard someone say that, um, in a conference, like, not on from stage, but, like at a party. And I was just, like, horrified by that. And to this day, it, like, stayed with me. It's like, oh, no, no, I just moved. I just moved the login page. Like, that's. That's not security.

Speaker A: Yeah, again, 30 years ago, companies would think they were hiding telnet access by, you know, putting it on a high port and. Same thing doesn't kind of work. Well, our time's winding down. What. What are your final thoughts? What are your last thoughts? What are your parting shots for the. For the audience?

Speaker B: That's a meaningful question this time around, Jeff, because if you made it this far, I'll probably cut this part out and, uh, put it as a standalone episode or standalone, uh, video. Uh, but everyone that's made it this far, thank you very much for being in with us on the security journey. Uh, if you've been with us in the days where Kazar was my co host, been here. If you were here with us in the early episodes, the Mackenzie Jackson started this show, uh, and it let me co host with him, and it took over. We've learned so much together, but all things must end. And I am ending this version, this variation, this season of the Security Repo podcast. Let's call it a long hiatus. Let's call it an unplanned, uh, pause. And one day, maybe we'll come back. I have other video projects planned. I have many webinars, I have many guests I want to interview, but I want to do it in a slightly different format than this particular show. And I'm very excited about the future for what I get to learn. I have learned so much, and I am so grateful for every single person who's listened. I'm grateful for every single guest I have had. Only reason I sound like I know what I'm talking about at all is because I am, um, listened to so many amazing, talented people who've literally just opened their, open their hearts and said, this is what I believe. And sometimes I disagreed. Mostly I thought this was amazing. We have learned together, and that's why I keep saying we're together on this learning journey. And thank you for being part of that with me. It's meant so much. And Jeff, thank you so much. Thank you so much for hosting today and being my guest and my host for this episode.

Speaker A: Well, I, uh, appreciate the opportunity to be with you before you closed it down, because that was my first question or first comment to you was, oh, you should have me on the show. Sometimes, since you do a podcast, um,

Speaker B: I made it happen.

Speaker A: The audience didn't hear a whole lot about me. That's fine. You can find me on Paul Security Weekly or just simply securityweekly.com. we're a series of different shows. The paulsecurityweekly.com has been, uh, broadcasting over 20 years now. I've been involved for the last 12 years or so, um, similar conversations. We sort of approach things a little bit differently from, uh, the perspective of the hosts that we have. And we have a, we sort of have a, A cadre of hosts that come on when we can. I'm sort of the, the resident old timer, grumpy old man, had the DoD background and, and, uh, I've been doing information security more from a consulting advisory perspective for the last 30 years or so, at least out in the private sector. But I had 12 years of DOD experience to, uh, uh, to tack onto that. Um, so, yeah, we're in, we're in this brave new world where agentic AI is becoming all the rage. And it's, it's, uh, getting to the point where I've sworn not to ever touch it. And, uh, that's just a personal thing for me. Um, but one of the things, one of my takeaways from RSA this week is okay, I at least need to be conversant on the issues, especially the issues of what do we do with it from a security perspective. I highly suspect that, uh, the security issues haven't changed. Uh, it's just the application and how do you deal with it, with this new form of technology and its capabilities, that, that's, that's, that's where I'm, I'm committed now to doing a little bit of research. So I, when somebody asks, I can at least give them a decent answer beyond I never touch this. I don't. And to qualify I don't have a real use for it. I don't do coding in my day job. I try to educate people on the fundamentals of security and I don't see how automation is ever going to help that. Uh, but that's a little bit of it on me. Uh, I congratulate you Dwayne on uh, having done this show uh, for quite a while and uh, you know, based on our conversation you've got a lot more to share with people. It's just going to be in a little bit of a different format. So look forward to seeing what you're producing uh, in the days and weeks and months to follow. So keep looking for Dwayne and uh, thanks, thanks again everybody in the audience uh, for being part of this show.

Speaker B: Thank you very much Jeff. Goodbye everybody.

Speaker A: Right, over and out.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Decision Logic: The Difference Between an Answer and a DecisionThe AI Forecast · on Agentic AI87 / 100
  • KYA Won't Always Protect You. The Real Risk Is the Swarm!Fintech Conversations & Insights with Efi Pylarinou · on Agentic AI86 / 100
  • Agentic AI in Sales: What Business Leaders Need to KnowScaling with AI · on Agentic AI86 / 100
  • EP284 Closest Alligator to the Canoe: How Transforming SOC Became P0 for Lloyds BankCloud Security Podcast by Google · on Agentic AI85 / 100
  • AI Is Ready for Government. Is Government Ready?The So What from BCG · on Agentic AI84 / 100
  • Beyond the Simplistic Narrative that AI will Replace Software with Mahesh RajasekharanSaaS Scaled · on Agentic AI83 / 100

More from The Security Repo

All episodes →
  • Avoiding Operational Chaos While Defending A Credit Union With Data Classification - John Wallace
  • OIDC And IAP In Production: Scaling Startup Security For Deepfake Defense - Talia Smiley
  • The PCI Ultimatum -Thrift Store OSINT, and "Lost Media" with Dwayne Edwards and Mike Radigan
  • From Annual Checkbox To Continuous SDLC Testing: Operationalizing AI Pentests - Andy Dennis of XBow
  • Why Compliance Isn’t Governance & How GovOps Rebuilds Trust Boundaries - Mike Schwartz
Explore the best B2B Engineering & DevTools podcasts →
All The Security Repo episodes →