The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The Virtual CISO Podcast
The Virtual CISO Podcast artwork

Episode 159: The New Security Stack: Doors, Data, and AI With Jeffrey Friedman

The Virtual CISO Podcast · 2026-06-10 · 41 min

0:00--:--

Key moments - from our scoring

Substance score

41 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber11 / 20
Specificity & Evidence7 / 20
Conversational Craft8 / 20

Jeffrey Friedman brings two decades of visitor management and physical security expertise to a discussion on why the traditional silos between physical and cybersecurity must collapse. Drawing parallels between zero-trust principles in cyber and physical access control, he explains how organizations applying cloud-based identity management, multi-factor authentication, and behavioral analytics to physical spaces are actually implementing cybersecurity methodologies. The real urgency emerges when discussing autonomous systems - drones, autonomous vehicles, and AI agents operating in physical spaces - which introduce new attack surfaces that require unified cyber-physical security governance. Friedman emphasizes that while most organizations keep physical and cyber security entirely separate (even under different reporting structures within the CISO's domain), the operational reality of AI-orchestrated logistics, military CMMC compliance, and emerging regulations like TISAX in automotive supply chains are forcing convergence. He argues that without CISOs taking ownership of physical security risk as part of an integrated framework, organizations face unmitigated risk when AI systems can negotiate access permissions with other systems without human oversight.

Key takeaways

  • →Physical security and cybersecurity use identical authentication and authorization frameworks - zero-trust principles apply equally to badging systems, cloud-based visitor management, and identity verification as they do to network access.
  • →Most organizations fail to correlate cyber and physical security data even when systems could easily detect anomalies like an employee authenticating on a network in Japan while simultaneously badging into a U.S. facility.
  • →Autonomous systems (drones, self-driving delivery vehicles, robotic unloaders) operating in secured facilities require CISOs to manage not just the cyber layer but also who has authority to control these devices and behavioral monitoring for anomalous operations.
  • →AI-to-AI negotiation of physical access (one autonomous system requesting another to lower a bollard or open a gate) introduces a new vulnerability class where bad actors could exploit trusted protocols used for legitimate deliveries.
  • →Defense industrial base regulations like CMMC and automotive supply chain standards like TISAX are making physical security compliance mandatory, forcing organizations to apply frameworks similar to NIST 800-171 controls in manufacturing and logistics environments.

Guests

Jeffrey Friedman

Topics in this episode

Multi-factor authentication (MFA)CMMC (Cybersecurity Maturity Model Certification)Zero-trust security frameworkCloud-based visitor management systemsFacial recognition for identity verificationOkta and Active Directory federated identityAutonomous vehicles and delivery dronesAgentic AI and non-human identitiesTISAX (Trusted Information Security Assessment Exchange)NIST 800-171 controls

Questions this episode answers

How should organizations approach multi-factor authentication for physical access in a cloud-first world?

Cloud-based visitor management systems apply the same MFA principles as cybersecurity: facial recognition to verify identity, comparison to driver's license, verification of scheduling, confirmation that a sponsor exists, and contextual factors like GPS location to prevent impossible authentications (e.g., an employee badging in while authenticated remotely from another country).

What is the risk if one autonomous system talks to another autonomous system to gain physical access without human oversight?

If an autonomous delivery vehicle can negotiate with an access control system (operated by another AI) to lower a bollard or open a gate, a bad actor could exploit the same trusted protocol to gain unauthorized access using the legitimate delivery protocol without any human in the loop to validate the request.

What percentage of organizations currently correlate cyber and physical security data to detect risks?

A very low percentage of organizations are correlating physical access control data (like badge swipes) with cybersecurity data (like network authentication logs) to detect anomalies, despite both families of security typically residing under the CISO.

How do CMMC and TISAX regulations impact physical security requirements?

CMMC (for defense contractors handling CUI) and TISAX (for automotive prototypes) impose physical security controls similar to NIST 800-171, requiring manufacturing facilities and loading docks to implement structured access control, visitor management, and surveillance monitoring - areas historically uncontrolled.

What is the role of human oversight in managing autonomous drones and vehicles for security purposes?

Even with autonomous operation, humans remain responsible for orchestrating and signing off on autonomous activities - someone must approve deliveries and patrols, and the system must monitor behavioral anomalies (e.g., a vehicle traveling 70 mph on a service road) regardless of whether a driver is present.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode surfaces some genuinely interesting ideas - cross-correlating physical badge data with cyber identity to flag impossible authentications, and the risk of AI-to-AI trust enabling unauthorized physical access - but these are buried under extended drink chat, Long Island reminiscing, and a lot of high-altitude hand-waving about convergence. The idea-to-filler ratio is low for a 41-minute runtime.

I would say a very, very, very low percentage of organizations are actually putting A plus B equals C together
the information that you can get out of physical access control reveals that truth. And that you would compare it to the other side of it, which is your cybersecurity element of this person through this IP address at this network is definitely in this country

Originality

7 / 20

Applying zero trust concepts to physical visitor management is mildly interesting but has been discussed in the industry for years. The speculative AI-bollard scenario and the drug-theft-via-cyber-reconnaissance angle have some novelty, but most of the framing - physical-cyber convergence, siloed security teams, public-private partnerships - is standard industry discourse without contrarian or first-principles development.

we really just modeled it after zero trust, we really just took the considerations that cybersecurity people were taking and saying, look, you know, if I don't know who you are, you shouldn't have access to this
part of it is also, like, how do I know where the drugs are stored, right? Is that on the network? Like, is there a map on the network that I can access

Guest Caliber

11 / 20

Friedman is a genuine 20-year practitioner who built visitor management infrastructure for the World Trade Center campus and now works on military physical security programs - real operational credibility, not a thought-leader circuit rider. However, his domain is narrow (visitor management), he struggles to move beyond high-level speculation on AI and IoT, and his answers frequently stay vague when pressed for specifics.

I became a big part of supplying the solution and also the framework for managing access to the secure facilities within the campus
I've been doing it for about 20 years. I've seen a lot of different places and I've applied the same concepts and techniques. And now I'm actually in a project working on it with the military

Specificity & Evidence

7 / 20

The episode name-drops real reference points - the Target/HVAC breach, CMMC, FedRAMP IL-5, NIST 800, ISACs, InfraGard, UnitedHealthcare CEO assassination - but nearly all of these are well-known examples requiring no insider knowledge. There are no proprietary metrics, no client case studies, no dollar figures beyond a passing mention of 'a billion dollars' for a transformer, and no timelines or outcome data from Friedman's own deployments.

The POS systems that are at every single target are what got hacked by the HVAC guy that got into the cybersecurity because he got into the POS system through the local HVAC system network
CMMC is real. And other FedRAM, IL-5, these are things that are part of my journey

Conversational Craft

8 / 20

The host occasionally asks sharp, specific questions - pushing on the percentage of organizations actually correlating physical and cyber signals, introducing CMMC and TISAX regulatory angles unprompted - but spends material time on drinks and Long Island small talk, frequently summarizes rather than challenges, and lets vague claims like 'very, very, very low percentage' pass without any follow-up for data or named examples.

What percentage of organizations would actually be able to detect that?
I spent a lot of time pondering AI and AI governance and the risks associated with AI and the new threat vectors that will exist. And I hadn't really thought through very well, shame on me

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

physical46security44different19cybersecurity19system17risk16access16building14world14vehicle13network13part12long12information11facility11island11

Full transcript

41 min

Transcribed and scored by The B2B Podcast Index.

You're listening to the Virtual CISO Podcast, providing the best insight on information security and security IT advice to business leaders everywhere. Hey there, and welcome to yet another episode of the Virtual CISO Podcast. With you is always your host, John Vary, and with me today, Jeffrey Friedman. Hey, Jeff.

Hey, how's it going? Thanks for having me. Yeah, cool. I always start simple.

Tell us a little bit about who you are and what is it that you do every day? What do I do every day? Let's backtrack a bit. So I'm in New York.

I'm a labor attorney. I'm always, I was a, you know, it's a young kid into technology and things like that. None occurred. I was about 30 years old.

I'd been practicing labor and employment law for about six years, but I had a lot of friends who are musicians turned coders. And we sort of came up with the idea of doing something called visitor management, which is basically managing the people who do not have cards going into facilities in New York. So essentially New York went through a lockdown period. And I, as a labor attorney, was representing a lot of guard companies.

And so it sort of like was a weird transition of my career and getting on mission to make places safe and effectively building a business around the idea of a level of physical security about the unknown. That's basically it. You have people coming to the building. You don't know who they are.

You don't know why they're coming. They're trying to figure it out. And if you're in the position of a security guard, it's your job to protect the building from unknown risk. So essentially, you know, you basically have two jobs as a guard.

Patrol, observe things that are challenging or risky, and report. And also maintain an entrance, maintain a portal of some sort where someone can get into a facility. And basically outside of that, the other roles are to basically observe, Observe through cameras, observe physically when you're walking the building, and maybe from time to time escorting people from here to there. And I'm not talking about executive protection.

That's a different category. But essentially, the idea of physical security is keeping people out of other areas and making people safe. And so the goal was to rebuild the World Trade Center one day, right, after 9-11. And I became a big part of supplying the solution and also the framework for managing access to the secure facilities within the campus, just to go one step further.

Obviously, you can go to World Trade Center. You can walk around. You can see the fountains. You can go to the mall.

as just a person, you walk around. And they need to, as a security measure for whether it's the police department or the Port Authority Police Department, they're trying to keep everybody safe in the public areas. And then there's certain other areas like inside the office buildings and inside where vehicles go underneath buildings. We want to make sure that they're safe as well.

We wouldn't want to let an unknown vehicle underneath the building. Pretty simple. So in that, we built a program to manage the access of different people. I've been doing it for about 20 years.

I've seen a lot of different places and I've applied the same concepts and techniques. And now I'm actually in a project working on it with the military to do the same thing. Excellent. I always ask before we get too deep in the weeds here, what's your drink of choice?

What's one drink of choice? On any given day, I'd probably order Jack and Ginger. Why would you ruin bourbon? Actually, Jack and Ginger is a refreshing drink.

I agree. It's funny. I bartended my way through law school and people would always ask, what should I have? And routinely, I would say Jack and Ginger because they probably never had it before and it wasn't very popular.

And now we're going back to the 90s. And so I would offer that drink and people would be like, oh my God, I never tried this before. So that would be my drink of choice. Before that, it was Long Island iced teas all day.

I was, you know, it's so funny. You shouldn't say that. So I bartended my way through college. I didn't go to law school.

I went to engineering school and the drink of choice in those days was a Long Island iced tea. Yeah. I mean, I probably made more Long Island, I mean, you know, enough Long Island iced teas to, uh, to float a battleship probably. Yeah.

So anyway, being from Long Island, it always came up. Are you from Long Island as well? Where, where, where, where in Long Island? I'm actually from Lawrence, which is near Atlantic Beach on the South Shore, close to the Rockways.

Okay, so Nassau County. Nassau County, yeah. Yeah, I'm from Suffolk County, out sort of in the center of the island there, a little town called Center Reach. I know it.

Near Lake Rekonkama. So, all right. So, people don't want to hear us chat about it. The only funny thing about Long Island is that back in the day, I always used to joke that everyone would say to me, oh, my God, I have a cousin on Long Island.

You might know him. And I'd be like, look, I was like 120,000. Pretty big island. Yeah.

So anyway. So physical security, interesting, right? So if I say back in the day, let's say pre-World Trade Center, pre-COVID, pre-highly virtualized workforce, things of that nature, I would say physical security was a pretty straightforward practice, right? You had a local data center, you had key card access, you had video cameras, maybe a front desk that signed you in.

How has physical security changed with these increased threat profiles, with the new work model, cloud-first companies, virtualization, et cetera? Let me backtrack for a second, because I want to just explain something to your audience, which is when we were developing the context of not early days, I didn't even think about this, but when we were developing the programs for the critical infrastructure in, let's say, the mid-2010s, right, we really just modeled it after zero trust.

we really just took the considerations that cybersecurity people were taking and saying, look, you know, if I don't know who you are, you shouldn't have access to this, right? And there was a concept of we don't trust anybody. You have to prove yourself, you have to verify yourself, you have to authenticate yourself, and then we'll give you access. And we just applied cybersecurity methodologies into physical security and then created software to support that, right?

So the idea of it being a cloud-based system, which is what we're getting at to now, is simply who has access to the system is still a cybersecurity problem. I'm going online. I'm going to schedule my visitor. Well, you need to have your cybersecurity credentials to get into the system to even schedule somebody or identify somebody.

And then the process keeps going. The security officer that's signing in is also signing in through a credential into the cloud service. The cloud service also ultimately creates a data lake, basically you could say, that supports information to help you process people better. You process people that might be, might discover who's at risk and who might be at risk, who's not using the system well and how long it takes people to process.

And essentially, by using a cloud distributed system, you enable sort of the sharing of data across disparate geographies, disparate users of different roles and permissions. And there's a lot of different roles in physical security that people have different permissions. And once again, it's very similar to it's a cybersecurity model inside the system itself. Right.

That makes sense. Inside the system. Inside the ecosystem, it's a cybersecurity software, no different than like Salesforce, where people are on serving the management of sales as the actual goal, but the solution is still a cloud-based hierarchy of permissions. Yeah.

So what you're saying is authentication and authorization is authentication and authorization, like whether it's a physical model or a logic model, right? Correct. Like basically when we sign into a program, let's say it's multi-factor, right? I sign in, then I might get an SMS message and I prove that it's me because I have my phone, right?

That's a very easy sample. Whether it's Okta or Ping or any of these other identity management solutions. Maybe there's a dual authentication methodology, right? Maybe there's a third.

Maybe my GPS is also recorded. Like I'm supposed to be somewhere, like another factor. supposed to be somewhere where I'm using this and I'm not. Meaning, why am I in Japan when I should be in New York using my computer, right?

That's another authentication method. Yes, we apply those concepts, but physically a person's trying to get some into some place where they physically actually are. And then what methodology are we proving that they are who they say they are? Let's just take identity as a concept, right?

We might take their facial recognition, right? This is definitely them. Then we compare it to their driver's license. Okay, so now we're proving their identity in the physical world, right?

And they actually showed up on time. They're scheduled. They should be there at that time, not five hours early, not five hours late. And beyond that, somebody else might have sponsored them.

That person's a real person. So now you have many factors, multi-factor authentication really happening at the gate. Yep. So that makes sense.

Yeah, it makes total sense. So in a way, right, one of the things that for years we've kind of heard about this, you know, convergence of cybersecurity and physical security. So it sounds like you're kind of leaning into that idea right there where you're beginning to talk about that. So, you know, is that something that you're seeing at this point in time?

Have we reached that point of convergence from most organizations that you work with? Not in the way I just described that they're utilizing. They're not putting it all together. There's elements that cross-connect.

An example would be I using my Okta identity system or my Active Directory federated system from Microsoft as my sign tool to use other products So you see a little bit of that And that's just, it would be the same if it was Salesforce, right? If you would say that there's convergence between sales and cyber, would you say that's true? I don't really know. But what?

Yeah. So let me ask a question though. So I liked what you, I thought it was very interesting what you said a little bit earlier where you were talking about the fact that someone has authenticated with a computer in one location, and now maybe they're trying to badge in at another location, right? Which would be illogical.

So, you know, what we'd call an impossible authentication or impossible, you know. So does, would, what percentage, I guess, maybe a better question to ask, what percentage of organizations would catch that, right? Because To me, that's when I think of like beginning that convergence. It's sort of like sharing that information in a way that it adds that additional context.

I love that phrase you used earlier, context. What percentage of organizations would actually be able to detect that? Well, they could. The answer is, are they, right?

I mean, are you asking me, are they putting it together? I think there's a dream story here that we're trying to help with on this front, which is the information that you can get out of physical access control reveals that truth. And that you would compare it to the other side of it, which is your cybersecurity element of this person through this IP address at this network is definitely in this country, right? And there's something wrong and I want to set an alarm, right?

I would say a very, very, very low percentage of organizations are actually putting A plus B equals C together. And if they are, and I know a lot of organizations, it's two separate, distinct families within the security world under the CISO maybe. Because there could be a chief security officer and a CISO, or there could be a CISO who has a chief security officer reporting to him who's dealing with physical security, maybe another one with executive protection, right? And so, you know, maybe there's a group.

I'm being like fundamental about this. Let's say there's a group of 20 very important employees inside an organization that are critical to the functioning of the business and they get additional executive protection. We need to know what they are all the time. So there is that tracking.

Does that make sense? Yes. But again, that might be siloed into the reality of what they're trying to do, which is protect the families and the executives in case, you know. And I mean, if we, you know, the UnitedHealthcare CEO story has definitely like ramped up that for a lot of companies.

Yeah. Louis Mangione opened some eyes, I think. So I like what you said. So it's the same historical problem that we've always had.

We have this problem with the siloing of enterprise risk versus cybersecurity risk versus third-party risk. You're adding physical security risk and maybe even executive protection risk. If we're not looking at these in a unified way, we're putting ourselves at risk, essentially. You know, I want to say, like, I feel like I'm on the edge working on it with clients, showing them the tool sets that you can actually accomplish these kinds of goals.

And it's really not that hard, if you know what I mean, because the info is there, the data is there. So it's like the convergence of it all is available. But you're asking me how many are really looking at it. And I think that's a very low percentage.

Okay. Yeah. From a surveillance point of view, right? I mean, like I am observing what is going on between these two systems.

And there is cross value, like crossover value to observing the risk. Right. And it really shouldn't be that hard, right? So I think, you know, when we think about non-human identities like system accounts, things of that nature, right, they've traditionally lived in the world of, I'm going to call it a cybersecurity challenge to manage and validate, age out, et cetera.

Basically, in the organizations we work in, there are non-human identities that we need to manage, right? Autonomous vehicles, drones, IoT devices. Maybe even now you talk about agentic AI. How some of those are going to be physical security challenges, right?

How should organizations be approaching that risk? So, you know, this is actually very interesting because, you know, systems, large system AI that the company relies on probably needs their own sort of, you know, framework for managing the cybersecurity risk and or I'm not saying that these things are to be sentient tomorrow. But what if they were and they decided, hey, I'm going to go off the rails and go into the network? I personally, as a leader or expert, do not cross into that, figuring that out.

But what I do think about a lot is that people, drones, certain containers, autonomous vehicles are coming, and all of a sudden there are operators, like people who are responsible, that are operating these things. They're orchestrating it. There's still a person engaged in the orchestration and responsible. I have to sign off on these deliveries, on these patrols.

Like, you know, right now we have drones going on patrol. somebody's operating it, right? So it's kind of like cross-connecting that there is a human in the loop. I don't know if that expression, but there's a human in the loop somewhere and that person needs to take responsibility for administrating those autonomous activities, right?

So we're connecting the dots of like who is responsible and that there's like sign-off on what's going on. And then once that occurs, you're still, even if there's a driver or not a driver, that vehicle should behave a certain way. Does that make sense? There's a behavioral analysis of what's the vehicle doing.

Simple. Vehicle is on a service road and it's going 70 miles an hour. That's bad. It doesn't matter whether there's a drive or not, right?

So there's an observability of behavior that might indicate time to mitigate the risk. Yeah. Yeah. And that concept of physical security when it comes to devices of that nature gets really interesting, right?

Because we could talk about the physical security we just talked about. We could talk about the physical security of humans having the authority to enter, control those devices, right? And you could have physical security relating to protecting the device itself, right? You know, can someone get into the vehicle?

Can someone connect to a port on the vehicle to do something to the vehicle, right? And then you've got the idea of physical security. Can this device enter this facility, right? Can this autonomous vehicle, is it authorized to open the gate, right, and enter the underground facility?

So I guess the concept of physical security to these devices is multimodal. Yeah, I mean, we're talking about something. We're here at 2020. You probably all can't believe how quickly AI has changed the map in the last two years.

To me, and I developed technology, I feel like AI in the last year has made an incredible leap. And if it keeps going at this speed, it's very, you know, like we should have some concerns about security. And I think it's not too hard to imagine that if a organizational AI said, hey, I want to make a delivery. And the thing that's in my way is this bollard that's controlled by another AI, right, needs to go down for me to make that delivery.

I'm not even talking about this risks reality, right? That the two entities would talk and trust each other to enable the framework of the bollard to go down or the gate to open. And then the truck comes in and they pull off and they make their delivery, right? People take the stuff out and then the vehicle leaves, the gate opens, and it's all completely automated.

And it's all great because it's efficient, no people, right? Save a lot of money. But then you start to think, wait a second, if it could do the good thing, good delivery, it could do the bad delivery using the same protocol without anybody in the loop. Does that make sense what I'm saying?

Yeah, it does. And then on top of that, you said people are going to unload it. Well, you know, increasingly, if you look at what, you know, X or XAI or whatever the name of Elon Musk's latest company is or, you know, the Chinese or Boston Robotics, right? Like we're seeing robots, I mean, literal robots that, you know, we are not far from putting trucks.

It's probably happening at some places already, right? So you're really talking about, in theory, the potential for all that to happen without that it could happen without any human in the loop. That's right. So it's interesting that what we're talking about, right?

Like there is this component, like all of these things are inexorably linked, right? You know, cyber, AI, physical security. There are no boundaries, right? Like we need to work.

I guess this is a phenomenal argument for the convergence, right, that we talked about earlier, right? Let's talk about efficiency, not security for a second. What is the efficiency of a long haul truck going from, let's say, you know, Ohio to Philadelphia, right? And there's two distribution centers, right?

They both have gates, right? Because, you know, you don't want, you're trying to protect from theft. the vehicle that has no driver pulls in. It's the right vehicle at the right time.

The gate opens up and the vehicle finds its way to the dock and the dock or the bay of the dock. And then the machines come in and they pull the pallets out. And then now the vehicle leaves and goes on to whatever the next journey is. Everything went great.

Everything went amazing. Nobody even had to do anything. And the same thing could happen for a flying drone. The drone comes picks up the medication and departs Stays on path Stays on path Stays on the pathway And two computers are talking to each other from two different companies the whole time There a cybersecurity element like we don't want a bad person to get into those cybersecurity solutions and change the output, if you know what I mean, or the outcome.

So cyber is a requirement of the future of physical security. And then the second part, which is the future of physical security, is going to be very dependent on cybersecurity, if not more. We're at an ascent stage where it's not really day-to-day stuff that's happening. But, you know, I mean, we're at a highly accelerated reality with drones, highly accelerated because of Ukraine and now the Iran conflict.

Autonomous drones are happening. The battle right now about Anthropik not allowing for a lethality of its AI and why they're being shunned by the government is relevant to the fact that they don't want to have that as a consequence of autonomous decisions, right? So I think that we're on the verge of something here that probably is a must-have. You know, we say not now, but there's going to be a must-have here for sure by the CISOs to really take over these budgets, if you know what I'm saying, like take over this part of the reality of the risk and begin the concept of using their cybersecurity chops into the physical world, which is much more ad hoc, which is just much more, you take it as you get it.

It's not easy to create a framework that's ubiquitous. Yeah, this conversation has me thinking much more significantly than I honestly expected it to. I spent a lot of time pondering AI and AI governance and the risks associated with AI and the new threat vectors that will exist. And I hadn't really thought through very well, shame on me, what we just talked about, right?

That the how, like on a first pass logic, you wouldn't think AI would drive physical security to higher levels, but I think you just painted a good picture of why it does. And it's also interesting to me. So another area that I think is driving physical security, physical security's importance at the moment are some of the emerging regulations that organizations are subject to, most notably, right, in the defense industrial base, right? So all of the manufacturing facilities that are processing CUI, many of them have shop floors.

Shop floors are historically not a physically secured space or not very well physically secured, right? We've got loading docks. We've got trucks coming in and out. Often we don't have any physical restrictions to get even onto the property.

And then the other one, which also I think we're seeing more of is TSACs, T-I-S-A-X, that's in the automotive supply chain. The physical security becomes very important if you're doing any prototypes for the automotive OEMs. So I'm curious, have you yet seen those things starting to impact your business? Well, I mentioned that we work in military environments.

So CMMC is real. And other FedRAM, IL-5, these are things that are part of my journey, as they say. But I think what they're trying to accomplish is not too different than the NIST NIST 800 program and then just sort of applying it in a different type of framework. So they kind of have their own, but it's Very similar, very similar to the controls that are in this already.

And there are other regulations to consider in the physical world that are beyond cyber, which includes like FDA health regulations and OSHA and a lot of other things that are relevant in physical world stuff that you could be violating different other things than just, you know, security problems, which is health standards and rules of the road. But also remember that operations doesn't stop. There's a lot of exceptions made so that things can actually occur. Because if you just got stuck into regulations, a lot of things just stop.

And so you have to make a decision whether the operational risk of stopping or the negative impact of the operational risk is worthy of stopping the flow of the business itself, right? So enforcement of regulations is another questionable thing that goes on in this country and all countries. Like how much money are you going to put towards the teeth of the regulation? And I always use this as my favorite example is who doesn't drive 70 on the highway?

Do we say we all know, but we're practicing a different program than what the regulation is, right? Why? Why? Because it's the way it is, right?

And if I don't go, if I go 55, it's not really safe for me. No, you're actually, you're actually endangering yourself these days driving, you know, at exactly the speed limit. If you're in, at least in the Northeast and probably out in the, you know, Nebraska and Wyoming and places like that as well. Right.

So it's funny. It's like, you know, I am in this, in this world and I ponder the things that I just mentioned to you a lot. And I think that there's a lot of room for collaboration and working together. and there's a lot of distance between, you know, maybe even understanding how doors operate and doors open, how do they open, what does it mean to have a card read at a door and how does it actually, because there's electrical engineering in some of that to make it work, right?

And, you know, you can go to a building, there's panels all over and you can act, and this is also CMMC is being applied to the panels, the panels, not like what you would call like a complete, you know, cloud-based system, But at the local level, on the edge, people are let in through doors because a decision is made at a panel that's local. You need that for fire, for life safety. You need to be able to open the doors if there's a fire. So it makes sense locally.

And you may not have the internet to do it, right? So you need to have that. That's really interesting. And to your point, that's something that somebody like me who's been doing this a long time would never have been cognizant of prior to this conversation.

Well, you know, the POS systems that are at every single target are what got hacked by the HVAC guy that got into the cybersecurity because he got into the POS system through the local HVAC system network that he needed to fix the HVAC system, which sent signals about controlling heat, cold air, right? And now all of a sudden some guy got into the POS. So the breaches on the cybersecurity, we're kind of moving into the other subject that's very interesting about cybersecurity and physical security is that the physical security networks, to a large degree, are siloed in different ways, right?

They're a different network, hopefully. Sometimes they're not. Sometimes they're actually separated by, you know, like routers. Yeah, they'll firewall them off now.

But, yeah, like in the old days, right, like, you know, ITOT were completely segregated. segregated. Now, most of the time, you'll see some type of, there is some IP connectivity that's, in a perfect world, tightly controlled through firewalling and access control and authorization. Yeah.

Okay. But right. So here we are, here we are on the edge, HVAC vendor, getting access to a facility into a, hopefully a secure room where the HVAC system is, has access to the network, and that router isn't configuring well. Let's just say well, okay?

Now he could infiltrate whatever subsystem is available to that particular building. And now you're going back up through the network, right? If you're a sophisticated hacker, it's a perfect endpoint to get to something bigger than the average employee's computer. And that's everywhere.

One thing I hadn't thought to ask you, but I'll ask you, how much of what CISA, the Critical Infrastructure Systems Agency and TSA and their control over ports and energy pipelines, regs and privacy, excuse me, physical security relating to core infrastructure, whether that's water, whether that's electrical grid, how much does that drive your business and anything interesting going on there? You know, typically, this is sort of the truth amongst physical security in general.

The government does not have enough money and personnel and people to protect everything. So what they do is they create public-private partnership arrangements. Where the public company, I'm sorry, the private companies really work well with, hopefully work well with the agencies that are appropriated for each one. To figure out what to do and share notes.

It's a very interesting, non-competitive world because we're not really competing for who's got the best security. We're competing to make sure everybody's safe. So the banking industry, for example, gets a lot of value out of the agencies because this is our critical infrastructure. banking, right?

So the teams, I think a lot of the CISOs for sure are like getting together with other banking CISOs, talking about what's their liability and the federal government really sets it up as best as they can so that they can learn together, all of them, and share information together about what's on the docket for the day and other protective ways to protect each other. Because one bank's failure is every bank's failure when it comes to this kind of, Any confidence lost is just bad for all the banks.

So that also applies to the grid, right? Or water treatment plants or nuclear facilities Nuclear facilities are highly regulated by various groups and they part of the Department of Energy and part to an extent the Department of Now to War So they sort of different. I put them on a different plane because they have to deal with, like, theft of nuclear. There's a lot of things going on there.

But there's a lot of electrical substations around this country that are unfortunately or fortunately not as protected as they should be because it's just impossible. They're scattered everywhere. It would take a lot of people. You know, the outdoor facilities sometimes are subject to weather and other conditions are very, very difficult.

And so I don't know if I'm digressing here. No, no, it's an interesting. Did you see this? So it's funny you should mention the electrical substations, right?

I saw something today which really surprised me, and I'm assuming it's accurate, where Trump was talking about not bombing certain things within Iran because it would set them back. It would take them many years to recover. And apparently at the heart of electrical distribution systems, there's this one, I don't know, it was a giant transformer, like something which is custom, takes years to build, costs like a billion dollars or like some insane amount of money. So if you blew that up, it's not like they can go and get a new one and literally would largely cripple the grid.

So to your point, right? We need to make sure we're investing those dollars into the right place from a physical security perspective, right? Because, I mean, look, we're not going to stop necessarily an Iranian drone from hitting one, but we could prevent somebody from, like you said, driving up in a truck loaded with a chemical fertilizer and causing a problem, right? Yeah.

I mean, the government's basically like separated all businesses into 16 sectors. And each sector, if you looked at it independently, it would be like, that's pretty important. You know, Our economy relies a lot on hospitality. So any incident in a huge hospitality situation would be terrible, just terrible.

So it's kind of like the sectors work together to figure out what's the threat, what's the threat of the physical world. And to a large degree, cyber. Like I said, the banking, it's a lot about the cyber problem. And many of the agencies work really well hand in hand with the leaders, the CISOs, to effectuate the best plan.

and share and share look uh you know there's a lot of things that we don't public that happen to effectuate you know yeah the the the ice axe is really what you're talking about right the information sharing and analysis center i think that stands for yeah so we've done we've done a little work with some of the ice axe in terms of uh you know looking at the threat feeds and understanding you know what they might mean to core clients so i mean if you're familiar with InfraGard, which is the one that is the, right?

So that, so that, so they, they're, I think they're leaning harder towards the cyber side these days than they are the physical side. And then, you know, CESA are the same at DHS. You know, they're mostly focused on protecting because the critical infrastructure from the cyber side is so detrimental that it's something that they could actually be effective with. And when you look at the physical thing, the problem with physical security is you have to look at each facility and building separately and see the conditions of things.

It doesn't matter whether it's a stadium or, you know, a huge iconic landmark. There's just different conditions everywhere. And so it's impossible to have a static, you know, like a static framework for this is what you need to do. The other thing which is why I think is that the universe of bad actors, right?

I mean, you could literally have a teenager sitting in his bedroom in some godforsaken place who finds a path into someplace where he shouldn't be where that same individual or those tens of millions of potential individuals are not going to be able to get to proximate to this physical facility, right? or wouldn't have, I can take a grid down with a $600 MacBook, but I can't take the grid down. I would need far more resources to be able to take down the grid with a physical act.

So I think that's another reason why that emphasis is because the universe of and the amount of resources required by those individuals is so much lower. Yeah. There's also the context of information that's on the network to produce the information that will support the physical, let's just go with theft, right? You go to a healthcare facility, the most protected part of the facility is probably the obstetrics, right?

If you've ever been, like, they're pretty tight on that. They have a different, like, access system for that. And then the drug closets where all the drugs are stored. So part of it is also, like, how do I know where the drugs are stored, right?

Is that on the network? Like, is there a map on the network that I can access so I can figure out where I need to go inside the building? Or what about when do I know when are the deliveries made? Who's making the deliveries?

Where are they coming from? Maybe I could stop the truck on the way. Like, you know, if you're doing sophisticated theft of things that are very valuable, you are probably going to do your research. And that's going to be a cyber breach maybe that didn't even hurt anybody, but they got the information they needed.

Does that make sense? Yeah. In fact, if they stole that information, they could do it quietly and no one would ever know that it was stolen. Correct.

And you don't even know if it was a hack or someone shared some information, but you might have the footprints inside the network from the forensic footprints inside the network, which to a large degree for a CISO, this is like part of the bread and butter is having the systems in place to make sure you can capture the footprints. Which is, whether it's a cybersecurity crime or not, they did it on a network. You know what I mean? Like what we're thinking of is like direct attacks or phishing attacks.

But there's other corporate infiltration, corporate espionage. This is the key. It's like somebody gets to a facility and he's been there a lot of times and he figures out what people are logging in with because he's had access to the facility. Then he goes off site, figures out how to log in.

And gets anything he needs because he's pretending he's somebody else, right? He's using the fact that they only have a singular faction of identity access, right? A single factor, you know what I mean? And so now I can get online and get what I need and nobody even saw me, you know?

And I wasn't even there when it happened. And you just touched on another value of that physical cyber convergence, right? Yeah. Yeah.

In most organizations, when you do some type of incident response, incident detection, incident analysis, even determining whether an event should rise to an incident level, you're in a sim. Look, you know, that's where we're going to see this data. And if we don't have that physical security data in there as well, we could be missing a key piece of. Yeah, I mean, to a large degree, to oversimplify what my career and expertise is really about is I'm trying to figure out who's not supposed to be there, who is supposed to be there when it's not a normal staff.

So, you know, everybody comes to the, before COVID, right, everybody came to the building nine to five, 80% of the people in the building were supposed to be there. And some percentage were only there temporarily. They could actually be staffed from another office that doesn't have access to the building normally, but had to get temporary access or a vendor or a visitor to a patient, right? Has a visitor coming.

You know, there's a lot of different scenarios here. It's very hard in public venues. Very, very challenging. I tour a lot of public venues about that situation, which is you really just don't know anybody, right?

And they're coming through your facility and you might be in critical infrastructure like a train station where it's a very big challenge. So that's really my career, like looking at what we could find out about what's wrong with this picture. A little bit like where's Waldo, right? And that's also on a network.

Why is this person touching this server when that's not their job? What's going on here, right? So there's the same framework of thought process that's in the zero trust architecture is this thing that we apply in the physical world as best we can using the tools that we have. So I think that is an ideal idea, thought process to actually end this podcast on.

What you do and what we do is largely the same, largely using the same frameworks. And it even increases the idea of this convergence being a necessary evil, especially in the evolving space that we're in with some of the other issues we talked about. So this has been fun, man. I appreciate it.

I appreciate it. Thanks, John. John, thanks for having me. And I hope to meet more of your audience soon.

Yeah, well, real quick to that end. How can, if somebody would like to reach out to you, what would be the best way for them to do that? Yeah, I currently am at Jeff at Fortify and that's F-O-R-T-I-F-Y-E dot com. You can reach out to me that way and check it out or to Building AI Agents to kind of like combat some of this stuff.

But actually, you know, part of it is just we're figuring it out fast. Things are changing very fast. So I really appreciate people's ideas, concepts, things they would like to see executed that they just can't seem to figure out how to put A plus B together. I'm very fortunate that I'm around a lot of people who are basically in that same boat.

We're trying to figure out how to make places that are safer and make sure people have a great experience in the process. Visiting a building shouldn't be the worst part of your day. It should be the best part of your day, right? and have a good experience and be efficient in your deliveries and not have the hassle of security.

Less friction. God's yours, man. Yeah. Have a great weekend.

Thank you. You too. Have a great weekend. And thanks, everyone.

You got it.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why CMMC became necessary in the first place.Trust Issues · on CMMC (Cybersecurity Maturity Model Certification)88 / 100
  • Aaron McCray: Ferrari Security: Speed With GuardrailsKitecast · on Multi-factor authentication (MFA)88 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Multi-factor authentication (MFA)82 / 100
  • How to Talk About Cybersecurity to Clients & Prospects with Mark Lamb from HighGround.iothe RocketMSP Podcast · on Multi-factor authentication (MFA)82 / 100
  • The CMMC Reality Check: Gap Assessments, Documentation Overload & Why 30-Day Compliance Claims Are a Red FlagCMMC Compliance Guide · on CMMC (Cybersecurity Maturity Model Certification)80 / 100
  • The Bad Guy's Different Set of RulesSecurity Breach · on CMMC (Cybersecurity Maturity Model Certification)78 / 100

More from The Virtual CISO Podcast

All episodes →
  • Episode 158: AI Is Increasing Your Cyber Risk - Can It Also Reduce It? With Mike Armistead
  • Episode 157: AI Security: Testing, Exploits, and Threat Feeds With Marco Figueroa
  • Episode 156: AI Security: Threat Modeling & Pipeline Evolution with Jason Rebholz
  • Episode 155: Incident Response Testing in Cloud Forward Organizations with Matt Lea
  • Ep 154: How DORA Will Impact US Companies with Dejan Kosutic
Explore the best B2B AI & Data podcasts →
All The Virtual CISO Podcast episodes →