Somaini's Trust Issues

Justin Somaini

With constantly increasing threats, the need for Security to innovate faster is paramount.  With more than three decades in the Security industry, I've lived through these problems and been on the bleeding edge of our industry's innovation.  Join me as we dive into what new waves of innovation that are coming at us but also look at the founding teams that are in them.  Along the way, we'll talk to industry leading experts for their unique perspective on what's needed and where we need to go.

  1. Sep 3

    EP 25: Crash Override

    Discussion with Mark Curphey, Head of Innovation and Co-Founder, at Crash Override. Summary In this conversation, Justin Somaini interviews Mark Curphey, co-founder of Crash Override, discussing his journey in the security industry, the lessons learned from past startups, and the importance of understanding customer needs in product development. They delve into the challenges of visibility in software development, the role of AI, and the significance of building the right team and investor relationships. Mark shares insights on the limitations of S-BOMs and the innovative solutions being developed at Crash Override. In this conversation, Justin Somaini and James Bond 007 discuss the intersection of AI and security development, exploring how AI can enhance security practices, the challenges posed by outdated security advice, and the importance of observability in software development. They share insights on customer adoption of security tools, the rapid evolution of vulnerability discovery, and the future of security in an AI-driven landscape. Chapters 00:00 Introduction and Background 03:03 Career Journey and Lessons Learned 05:58 Startup Experiences and Founding Crash Override 08:55 Fundraising and Investor Relationships 12:06 Product Development and Customer Insights 15:01 Visibility Challenges in Software Development 17:57 Chalk: The Core Mechanism of Crash Override 20:56 S-BOMs and Their Limitations 24:02 Future of Development and AI Integration 30:40 AI in Security Development 33:46 Challenges with Current Security Practices 35:54 Optimizing Development Processes with AI 39:20 The Importance of Observability in Software Development 43:09 Customer Insights and Adoption 45:02 Exploring Vulnerability Discovery and Management 57:17 The Future of Security with AI Keywords security, startup, visibility, product development, fundraising, software engineering, AI, Crash Override, S-BOM, investor relations AI, security development, vulnerability management, software observability, customer insights, coding practices, open source, security tools, software development, engineering best practices

  2. Aug 19

    EP 24: Jason Lish & Iain Mulholland

    Discussion with Jason Lish, CISO at Cisco, and Iain Mulholland, CISO at Salesforce. Jason Lish: https://www.linkedin.com/in/jasonlish/ Iain Mulholland: https://www.linkedin.com/in/iainmulholland/ Support the show and Donate to NCMEC: https://give.missingkids.org/TrustIssues Summary In this conversation, Justin Somaini engages with Jason Lish and Ian Mulholland to explore the intersection of AI and cybersecurity. They discuss the challenges and opportunities presented by AI in vulnerability remediation, the importance of understanding exploitability and reachability, and the ongoing issues of legacy code and tech debt. The conversation also delves into the role of AI in automating vulnerability assessments and remediation, the emerging concept of unit economics in security, and the future of AI in code generation and security practices. In this conversation, the speakers discuss the evolving landscape of technology security, focusing on the challenges posed by end-of-life products, the importance of securing AI production environments, and the role of agents in identity management. They explore the complexities of authorization in AI systems, the future of security functions, and the impact of automation on security workflows. Additionally, they address geopolitical considerations that affect technology security and the need for ongoing conversations in the industry. Chapters 00:00 Introduction to AI and Security Challenges 02:59 Vulnerability Remediation in the Age of AI 05:56 Understanding Exploitability and Reachability 09:05 Reducing Attack Surface and Code Hardening 11:59 Legacy Code and Tech Debt Challenges 14:47 Harnessing AI for Vulnerability Assessment 18:01 The Role of AI in Remediation and Code Quality 21:00 Unit Economics in Security 23:46 Future of AI in Code Generation and Security 26:59 Balancing Change and Stability in Software Development 37:24 Navigating End-of-Life Issues in Technology 41:18 Securing AI Production Environments 44:59 The Role of Agents in Identity Management 49:26 Challenges of Authorization in AI Agents 55:11 The Future of Security Functions and Skill Sets 61:07 The Impact of Automation on Security Workflows 67:19 Geopolitical Considerations in Technology Security Keywords AI, cybersecurity, vulnerability remediation, exploitability, reachability, attack surface, legacy code, tech debt, harnessing AI, unit economics, code generation technology, security, AI, identity management, automation, authorization, end-of-life issues, production environments, skill sets, geopolitical risks, Salesforce, Cisco

  3. Aug 13

    EP 23: Austin Cowan (Heidrick & Struggles)

    Discussion with Austin Cowan, Principal at Heidrick & Struggles. Austin Cowan: https://www.linkedin.com/in/austin-cowan-17186584/ Support the show and Donate to NCMEC: https://give.missingkids.org/TrustIssues Summary In this conversation, Justin Somaini speaks with Austin Cowan, a principal at Heidrick and Struggles, about the evolving landscape of cybersecurity roles, particularly the CISO position. Austin shares his journey into executive recruiting and discusses the significant changes in expectations for CISOs, emphasizing the need for technical skills and product management capabilities. The conversation also highlights the importance of hiring managers understanding these new requirements and the role of effective communication in the hiring process. In this conversation, Austin Cowan and Justin Somaini delve into the complexities of the CISO role, the challenges in hiring practices, and the importance of succession planning in cybersecurity. They discuss the evolving landscape of cybersecurity leadership, the disconnect between hiring managers and the skills needed for CISO roles, and the necessity for organizations to adapt to the increasing demand for cybersecurity expertise. The conversation emphasizes the need for accountability in the hiring process and the importance of fostering a supportive environment for cybersecurity leaders. Chapters 00:00 Introduction to Austin Cowan and His Journey 03:05 The Evolution of Cybersecurity Roles 06:00 The Shift in CISO Expectations 09:01 The Changing Landscape of Cybersecurity Hiring 12:04 The Technical Skills Required for Modern CISOs 15:03 The Future of Cybersecurity Leadership 18:03 The Role of Hiring Managers in Cybersecurity 21:10 Building a Product-Oriented Security Team 23:47 The Importance of Communication in Hiring 27:14 Conclusion and Future Outlook 30:44 Understanding the CISO Landscape 36:45 The Disconnect in Hiring Practices 41:58 The Evolving Role of the CISO 46:56 Succession Planning in Cybersecurity 51:07 Navigating the CISO Interview Process 55:50 Final Thoughts and Industry Accountability ### Keywords cybersecurity, CISO, executive recruiting, technical skills, hiring managers, security teams, automation, product management, leadership, industry trends CISO, cybersecurity, hiring practices, succession planning, interview process, industry accountability, AI security, risk management, leadership, trust officer

  4. Jul 23

    EP 22: Bluerock Security

    Discussion with Harold Byun, CEO at BlueRock. BlueRock: https://bluerock.io Harold Byun: https://www.linkedin.com/in/haroldbyun/ Summary In this conversation, Justin Somaini interviews Harold Byun, CEO of BlueRock, discussing the evolving landscape of cybersecurity, particularly in the context of AI and agentic security. Harold shares his extensive background in cybersecurity, the challenges faced in data security, and the innovative approaches BlueRock is taking to address these issues. The discussion covers the importance of governance, manageability, and the need for effective security measures in an increasingly complex digital environment. In this conversation, Harold Byun and Justin Somaini delve into the complexities of AI security, focusing on semantic analysis, intent recognition, and the operational aspects of AI agents. They discuss the importance of understanding the intent behind actions taken by AI agents, the need for contextual awareness, and the challenges of monitoring and analyzing agentic operations. The conversation also touches on customer use cases, the differences between corporate and production environments, and the future of AI interfaces and endpoints. Chapters 00:00 Introduction to Agentic Security and AI 02:12 Harold Byun's Journey in Cybersecurity 05:33 The Evolution of Data Security Products 08:39 Challenges in Cloud and SaaS Security 11:40 Transitioning to BlueRock and Active Security Models 17:05 Understanding BlueRock's Architecture and Technology 25:04 Governance and Manageability in AI and Security 32:47 Understanding Semantic Analysis in AI Security 35:17 Intent Recognition and Contextual Awareness 39:30 Agentic Operations and Monitoring 49:16 Customer Use Cases and Enablement 55:25 Production vs Corporate Use Cases 61:16 The Future of AI Interfaces and Endpoints Keywords AI, cybersecurity, agentic security, data security, Blue Rock, SaaS security, cloud security, active security, governance, manageability AI security, semantic analysis, intent recognition, agentic operations, customer use cases, production environments, corporate governance, AI interfaces

  5. Jul 16

    EP 19: Mark Crane (General Catalyst)

    Discussion with Mark Crane, Partner at General Catalyst, about the cybersecurity market, venture capital, and more. Summary In this conversation, Justin Somaini and Mark Crane discuss the current landscape of innovation in cybersecurity and venture capital. They explore the rapid advancements in technology, particularly AI, and how these changes are shaping the future of cybersecurity solutions. Mark shares his journey to becoming a partner at General Catalyst and the importance of due diligence in evaluating startups. The discussion highlights the challenges and opportunities that arise in this fast-paced environment, emphasizing the need for security leaders to adapt and leverage new technologies effectively. In this conversation, Justin Somaini discusses the critical role of founders in the success of startups, particularly in the cybersecurity space. He emphasizes the importance of product development, market strategy, and the milestones that founders must achieve to secure funding and grow their companies. Somaini also highlights the evolving landscape of venture capital and the implications of high valuations in the current market. He concludes by expressing optimism about the future of cybersecurity startups and the quality of founders emerging in the industry. Chapters 00:00 The Exciting Era of Innovation 01:11 Mark Crane's Journey to General Catalyst 07:47 Waves of Innovation in Cybersecurity 27:29 Due Diligence in Venture Capital 33:35 The Future of Cybersecurity Solutions 34:05 The Founder-Focused Approach 41:17 Milestones in Building a Company 46:05 The Role of VCs in Early-Stage Companies 55:10 Understanding Valuations and Market Dynamics 66:08 The Future of Cybersecurity Startups Keywords innovation, cybersecurity, venture capital, AI, General Catalyst, due diligence, market trends, technology adoption, enterprise software, investment strategies founders, venture capital, cybersecurity, product development, market dynamics, startup milestones, valuations, early-stage companies, go-to-market strategy, innovation

  6. Jul 16

    EP 21: Savi Security

    Discussion with Patrick Coughlin, CEO and Co-Founder of Savi Security. Patrick Coughlin Linkedin Download the Savi App Dark Side of the Boom  Scamwise - Free Scam Checker Summary In this conversation, Justin Somaini and Patrick Coughlin delve into the evolving landscape of cybersecurity, particularly focusing on the increasing threats to consumers in the digital age. They discuss the rise of scams and fraud, especially in light of advancements in AI technology, and how these developments have made consumers more vulnerable. Patrick shares his personal experiences and insights from his journey in cybersecurity, emphasizing the need for better protection mechanisms and the importance of educating the public about these threats. The conversation highlights the necessity for innovation in consumer technology to combat the growing sophistication of cybercriminals. In this conversation, Justin Somaini discusses the impact of scams on families, particularly focusing on the vulnerabilities of seniors. He shares the creation of Savi Security and its first product, Scamwise, aimed at providing digital protection. The discussion highlights the importance of building trust in a world filled with scams and the need for innovative solutions to protect consumers. Somaini emphasizes the responsibility of technology to safeguard users and the necessity of addressing the evolving landscape of digital threats. Chapters 00:00 Navigating New Threats to Families 02:08 Patrick Coughlin's Journey into Cybersecurity 18:02 The Rise of Consumer Targeting in Cybercrime 24:08 The Dark Side of AI in Scams 30:15 Understanding the Ecosystem of Cybercrime 33:30 The Impact of Scams on Families 34:56 Creating Savi Security: A Family Mission 36:18 Scamwise: A Tool for Digital Protection 39:27 Targeting Vulnerable Populations: Seniors and Scams 42:42 Building Trust in a Distrustful World 52:36 Navigating the Consumer Landscape 60:46 Innovating Against the Threat of Scams Keywords cybersecurity, consumer protection, AI scams, fraud, threat intelligence, digital fraud, organized crime, cybersecurity landscape, consumer technology, security awareness scams, digital protection, family security, Savi Security, Scamwise, AI technology, consumer safety, seniors, trust issues, cybersecurity

  7. Jul 9

    EP 20: Omar Santos (Cisco)

    Discussion with Omar Santos, Distinguished Engineer at Cisco. Omar Santos: https://www.linkedin.com/in/santosomar/ CoSAI: https://www.coalitionforsecureai.org/ Summary In this conversation, Omar Santos, a distinguished engineer at Cisco, discusses his extensive background in cybersecurity and the evolving role of AI in security practices. He shares insights on the challenges of network security, the importance of responsible AI, and the impact of open source on vulnerability management. The discussion highlights the dual nature of AI technology, emphasizing both its potential benefits and the pressing challenges it presents in the cybersecurity landscape. In this conversation, Omar Santos and Justin Somaini discuss the evolving landscape of open source security, the formation of the Coalition for Secure AI (CoSAI), and the introduction of Code Guard as a solution to enhance security in AI development. They emphasize the importance of collaboration among organizations to address vulnerabilities and the need for compensating controls in the face of rapid technological advancements. The discussion highlights the significant impact of Code Guard in reducing vulnerabilities in AI-generated code and the straightforward implementation process that can be adopted across various coding agents. In this conversation, Omar Santos and Justin Somaini discuss the evolving role of AI in software development, particularly in code review and vulnerability management. They explore the challenges of human coding practices, the potential of AI to refactor and modernize code, and the importance of eliminating unused features to reduce risk. The discussion also touches on the differences between corporate and production AI adoption, the need for centralized services for secure development, and the call to action for improving open source security practices. Chapters 00:00 Introduction to Omar Santos and AI Security 01:15 Omar Santos' Background and Career Journey 03:13 Challenges in Network Security and Maintenance 06:29 The Role of AI in Security Practices 07:11 Omar's Early Experiences with AI and Machine Learning 10:07 Responsible AI and Its Importance 12:57 Cisco's Exploration of LLMs and AI Integration 17:07 The Dual Nature of AI in Security 19:14 Current Vulnerability Management Challenges 24:40 The Impact of Open Source on Security 28:04 The State of Open Source Security 31:43 Introducing CoSAI: Coalition for Secure AI 37:24 Code Guard: Enhancing Security in AI Development 46:57 Implementation and Impact of Code Guard 53:51 The Evolution of AI in Code Review 55:11 Human vs AI: Coding Vulnerabilities 56:27 Refactoring Code with AI 58:23 Eliminating Unused Features to Reduce Risk 60:28 The Importance of Modernizing Technology 62:00 The Challenge of Unused Features in Software 64:30 Corporate vs Production AI Adoption 66:53 Centralized Services for Secure Development 69:03 The Wild West of AI Experimentation 72:33 Preparing for AI Security Challenges 75:15 Call to Action for Open Source Security Keywords AI security, Omar Santos, Cisco, vulnerability management, machine learning, responsible AI, network security, open source, cybersecurity, incident response Open Source Security, AI, CoSAI, Code Guard, Vulnerability Management, Cybersecurity, Cisco, Machine Learning, Security Best Practices, Software Development Life Cycle AI, code review, vulnerabilities, refactoring, software security, open source, corporate adoption, technology modernization, risk management, coding agents

  8. Jun 25

    EP 18: Rob Knake

    Discussion with Rob Knake, CEO and Co Founder at TPO Group and former Deputy National Cyber Director for Strategy and Budget. Summary In this conversation, Rob Knake shares his extensive experience in cybersecurity policy, discussing his journey from academia to the White House and the evolution of cyber policy in the U.S. He highlights the challenges of navigating the complex landscape of cybersecurity, the role of the National Cyber Director, and the importance of regulation in the private sector. The discussion also touches on the impact of crises on policy development and the ongoing struggle for effective regulatory authority in cybersecurity. In this conversation, Justin Somaini and Rob discuss the evolving landscape of cybersecurity regulation, the role of big banks as regulators, and the challenges faced by government entities like CISA. They explore the need for outcome-based regulation, accountability in cybersecurity, and the importance of establishing security standards. Rob emphasizes the necessity of software liability and creating a culture of security within organizations. The discussion also touches on the current state of cybersecurity in government and the future of cybersecurity policy, highlighting the mission of the TPO Group in bridging technology and policy. Chapters 00:00 Introduction to Cybersecurity Policy and Rob Naik's Background 04:08 The Journey into Cybersecurity Policy 09:37 Navigating the Cyber Policy Landscape 16:17 The Role of the National Cyber Director 23:32 Crisis-Driven Policy Development 30:52 The Shift Towards Regulation in Cybersecurity 37:58 Challenges in Regulatory Authority and Implementation 43:08 The Role of Big Banks in Cybersecurity Regulation 44:08 Challenges in Government Cybersecurity Regulation 45:57 Defining Effective Cybersecurity Regulation 46:56 Outcome-Based Regulation in Cybersecurity 49:07 Accountability in Cybersecurity 50:50 The Need for Liability in Cybersecurity 52:59 Creating a Culture of Security 55:05 Establishing Security Standards 57:00 The State of Cybersecurity in Government 67:12 CISA's Current Challenges and Future 70:59 The Future of Cybersecurity Policy 72:53 The TPO Group and Its Mission Keywords cybersecurity, policy, national security, regulation, private sector, cyber strategy, Rob Naik, NIST, cyber resilience, government cybersecurity, regulation, big banks, government, accountability, liability, CISA, policy, security standards, technology

Ratings & Reviews

3.7
out of 5
3 Ratings

About

With constantly increasing threats, the need for Security to innovate faster is paramount.  With more than three decades in the Security industry, I've lived through these problems and been on the bleeding edge of our industry's innovation.  Join me as we dive into what new waves of innovation that are coming at us but also look at the founding teams that are in them.  Along the way, we'll talk to industry leading experts for their unique perspective on what's needed and where we need to go.