Somaini's Trust Issues

Justin Somaini

With constantly increasing threats, the need for Security to innovate faster is paramount.  With more than three decades in the Security industry, I've lived through these problems and been on the bleeding edge of our industry's innovation.  Join me as we dive into what new waves of innovation that are coming at us but also look at the founding teams that are in them.  Along the way, we'll talk to industry leading experts for their unique perspective on what's needed and where we need to go.

  1. Jul 23

    EP 22: Bluerock Security

    Discussion with Harold Byun, CEO at BlueRock. BlueRock: https://bluerock.io Harold Byun: https://www.linkedin.com/in/haroldbyun/ Summary In this conversation, Justin Somaini interviews Harold Byun, CEO of BlueRock, discussing the evolving landscape of cybersecurity, particularly in the context of AI and agentic security. Harold shares his extensive background in cybersecurity, the challenges faced in data security, and the innovative approaches BlueRock is taking to address these issues. The discussion covers the importance of governance, manageability, and the need for effective security measures in an increasingly complex digital environment. In this conversation, Harold Byun and Justin Somaini delve into the complexities of AI security, focusing on semantic analysis, intent recognition, and the operational aspects of AI agents. They discuss the importance of understanding the intent behind actions taken by AI agents, the need for contextual awareness, and the challenges of monitoring and analyzing agentic operations. The conversation also touches on customer use cases, the differences between corporate and production environments, and the future of AI interfaces and endpoints. Chapters 00:00 Introduction to Agentic Security and AI 02:12 Harold Byun's Journey in Cybersecurity 05:33 The Evolution of Data Security Products 08:39 Challenges in Cloud and SaaS Security 11:40 Transitioning to BlueRock and Active Security Models 17:05 Understanding BlueRock's Architecture and Technology 25:04 Governance and Manageability in AI and Security 32:47 Understanding Semantic Analysis in AI Security 35:17 Intent Recognition and Contextual Awareness 39:30 Agentic Operations and Monitoring 49:16 Customer Use Cases and Enablement 55:25 Production vs Corporate Use Cases 61:16 The Future of AI Interfaces and Endpoints Keywords AI, cybersecurity, agentic security, data security, Blue Rock, SaaS security, cloud security, active security, governance, manageability AI security, semantic analysis, intent recognition, agentic operations, customer use cases, production environments, corporate governance, AI interfaces

  2. Jul 16

    EP 19: Mark Crane (General Catalyst)

    Discussion with Mark Crane, Partner at General Catalyst, about the cybersecurity market, venture capital, and more. Summary In this conversation, Justin Somaini and Mark Crane discuss the current landscape of innovation in cybersecurity and venture capital. They explore the rapid advancements in technology, particularly AI, and how these changes are shaping the future of cybersecurity solutions. Mark shares his journey to becoming a partner at General Catalyst and the importance of due diligence in evaluating startups. The discussion highlights the challenges and opportunities that arise in this fast-paced environment, emphasizing the need for security leaders to adapt and leverage new technologies effectively. In this conversation, Justin Somaini discusses the critical role of founders in the success of startups, particularly in the cybersecurity space. He emphasizes the importance of product development, market strategy, and the milestones that founders must achieve to secure funding and grow their companies. Somaini also highlights the evolving landscape of venture capital and the implications of high valuations in the current market. He concludes by expressing optimism about the future of cybersecurity startups and the quality of founders emerging in the industry. Chapters 00:00 The Exciting Era of Innovation 01:11 Mark Crane's Journey to General Catalyst 07:47 Waves of Innovation in Cybersecurity 27:29 Due Diligence in Venture Capital 33:35 The Future of Cybersecurity Solutions 34:05 The Founder-Focused Approach 41:17 Milestones in Building a Company 46:05 The Role of VCs in Early-Stage Companies 55:10 Understanding Valuations and Market Dynamics 66:08 The Future of Cybersecurity Startups Keywords innovation, cybersecurity, venture capital, AI, General Catalyst, due diligence, market trends, technology adoption, enterprise software, investment strategies founders, venture capital, cybersecurity, product development, market dynamics, startup milestones, valuations, early-stage companies, go-to-market strategy, innovation

  3. Jul 16

    EP 21: Savi Security

    Discussion with Patrick Coughlin, CEO and Co-Founder of Savi Security. Patrick Coughlin Linkedin Download the Savi App Dark Side of the Boom  Scamwise - Free Scam Checker Summary In this conversation, Justin Somaini and Patrick Coughlin delve into the evolving landscape of cybersecurity, particularly focusing on the increasing threats to consumers in the digital age. They discuss the rise of scams and fraud, especially in light of advancements in AI technology, and how these developments have made consumers more vulnerable. Patrick shares his personal experiences and insights from his journey in cybersecurity, emphasizing the need for better protection mechanisms and the importance of educating the public about these threats. The conversation highlights the necessity for innovation in consumer technology to combat the growing sophistication of cybercriminals. In this conversation, Justin Somaini discusses the impact of scams on families, particularly focusing on the vulnerabilities of seniors. He shares the creation of Savi Security and its first product, Scamwise, aimed at providing digital protection. The discussion highlights the importance of building trust in a world filled with scams and the need for innovative solutions to protect consumers. Somaini emphasizes the responsibility of technology to safeguard users and the necessity of addressing the evolving landscape of digital threats. Chapters 00:00 Navigating New Threats to Families 02:08 Patrick Coughlin's Journey into Cybersecurity 18:02 The Rise of Consumer Targeting in Cybercrime 24:08 The Dark Side of AI in Scams 30:15 Understanding the Ecosystem of Cybercrime 33:30 The Impact of Scams on Families 34:56 Creating Savi Security: A Family Mission 36:18 Scamwise: A Tool for Digital Protection 39:27 Targeting Vulnerable Populations: Seniors and Scams 42:42 Building Trust in a Distrustful World 52:36 Navigating the Consumer Landscape 60:46 Innovating Against the Threat of Scams Keywords cybersecurity, consumer protection, AI scams, fraud, threat intelligence, digital fraud, organized crime, cybersecurity landscape, consumer technology, security awareness scams, digital protection, family security, Savi Security, Scamwise, AI technology, consumer safety, seniors, trust issues, cybersecurity

  4. Jul 9

    EP 20: Omar Santos (Cisco)

    Discussion with Omar Santos, Distinguished Engineer at Cisco. Omar Santos: https://www.linkedin.com/in/santosomar/ CoSAI: https://www.coalitionforsecureai.org/ Summary In this conversation, Omar Santos, a distinguished engineer at Cisco, discusses his extensive background in cybersecurity and the evolving role of AI in security practices. He shares insights on the challenges of network security, the importance of responsible AI, and the impact of open source on vulnerability management. The discussion highlights the dual nature of AI technology, emphasizing both its potential benefits and the pressing challenges it presents in the cybersecurity landscape. In this conversation, Omar Santos and Justin Somaini discuss the evolving landscape of open source security, the formation of the Coalition for Secure AI (CoSAI), and the introduction of Code Guard as a solution to enhance security in AI development. They emphasize the importance of collaboration among organizations to address vulnerabilities and the need for compensating controls in the face of rapid technological advancements. The discussion highlights the significant impact of Code Guard in reducing vulnerabilities in AI-generated code and the straightforward implementation process that can be adopted across various coding agents. In this conversation, Omar Santos and Justin Somaini discuss the evolving role of AI in software development, particularly in code review and vulnerability management. They explore the challenges of human coding practices, the potential of AI to refactor and modernize code, and the importance of eliminating unused features to reduce risk. The discussion also touches on the differences between corporate and production AI adoption, the need for centralized services for secure development, and the call to action for improving open source security practices. Chapters 00:00 Introduction to Omar Santos and AI Security 01:15 Omar Santos' Background and Career Journey 03:13 Challenges in Network Security and Maintenance 06:29 The Role of AI in Security Practices 07:11 Omar's Early Experiences with AI and Machine Learning 10:07 Responsible AI and Its Importance 12:57 Cisco's Exploration of LLMs and AI Integration 17:07 The Dual Nature of AI in Security 19:14 Current Vulnerability Management Challenges 24:40 The Impact of Open Source on Security 28:04 The State of Open Source Security 31:43 Introducing CoSAI: Coalition for Secure AI 37:24 Code Guard: Enhancing Security in AI Development 46:57 Implementation and Impact of Code Guard 53:51 The Evolution of AI in Code Review 55:11 Human vs AI: Coding Vulnerabilities 56:27 Refactoring Code with AI 58:23 Eliminating Unused Features to Reduce Risk 60:28 The Importance of Modernizing Technology 62:00 The Challenge of Unused Features in Software 64:30 Corporate vs Production AI Adoption 66:53 Centralized Services for Secure Development 69:03 The Wild West of AI Experimentation 72:33 Preparing for AI Security Challenges 75:15 Call to Action for Open Source Security Keywords AI security, Omar Santos, Cisco, vulnerability management, machine learning, responsible AI, network security, open source, cybersecurity, incident response Open Source Security, AI, CoSAI, Code Guard, Vulnerability Management, Cybersecurity, Cisco, Machine Learning, Security Best Practices, Software Development Life Cycle AI, code review, vulnerabilities, refactoring, software security, open source, corporate adoption, technology modernization, risk management, coding agents

  5. Jun 25

    EP 18: Rob Knake

    Discussion with Rob Knake, CEO and Co Founder at TPO Group and former Deputy National Cyber Director for Strategy and Budget. Summary In this conversation, Rob Knake shares his extensive experience in cybersecurity policy, discussing his journey from academia to the White House and the evolution of cyber policy in the U.S. He highlights the challenges of navigating the complex landscape of cybersecurity, the role of the National Cyber Director, and the importance of regulation in the private sector. The discussion also touches on the impact of crises on policy development and the ongoing struggle for effective regulatory authority in cybersecurity. In this conversation, Justin Somaini and Rob discuss the evolving landscape of cybersecurity regulation, the role of big banks as regulators, and the challenges faced by government entities like CISA. They explore the need for outcome-based regulation, accountability in cybersecurity, and the importance of establishing security standards. Rob emphasizes the necessity of software liability and creating a culture of security within organizations. The discussion also touches on the current state of cybersecurity in government and the future of cybersecurity policy, highlighting the mission of the TPO Group in bridging technology and policy. Chapters 00:00 Introduction to Cybersecurity Policy and Rob Naik's Background 04:08 The Journey into Cybersecurity Policy 09:37 Navigating the Cyber Policy Landscape 16:17 The Role of the National Cyber Director 23:32 Crisis-Driven Policy Development 30:52 The Shift Towards Regulation in Cybersecurity 37:58 Challenges in Regulatory Authority and Implementation 43:08 The Role of Big Banks in Cybersecurity Regulation 44:08 Challenges in Government Cybersecurity Regulation 45:57 Defining Effective Cybersecurity Regulation 46:56 Outcome-Based Regulation in Cybersecurity 49:07 Accountability in Cybersecurity 50:50 The Need for Liability in Cybersecurity 52:59 Creating a Culture of Security 55:05 Establishing Security Standards 57:00 The State of Cybersecurity in Government 67:12 CISA's Current Challenges and Future 70:59 The Future of Cybersecurity Policy 72:53 The TPO Group and Its Mission Keywords cybersecurity, policy, national security, regulation, private sector, cyber strategy, Rob Naik, NIST, cyber resilience, government cybersecurity, regulation, big banks, government, accountability, liability, CISA, policy, security standards, technology

  6. Jun 11

    EP 17: Jacques Benkoski (USVP)

    Discussion with Jacques Benkoski, General Partner at U.S. Venture Partners (USVP) and author of The Market Entry Strategy. USVP: http://www.usvp.com Jacques Benkoski: https://www.linkedin.com/in/jacques-benkoski-ab9133/ The Market Entry Strategy: https://a.co/d/0b1W3euC Support the show and Donate to NCMEC: https://give.missingkids.org/TrustIssues Summary In this conversation, Justin Somaini interviews Jacques Benkoski, a general partner at US Venture Partners, discussing his extensive background in engineering and venture capital. They explore the evolution of cybersecurity innovations, the impact of AI on software development, and the intricacies of due diligence in venture capital investments. Jacques shares insights on the challenges entrepreneurs face, the changing landscape of technology, and the importance of understanding customer needs in the investment process. In this conversation, Jacques Benkoski and Justin Somaini discuss critical aspects of startup growth, particularly in the cybersecurity sector. They emphasize the importance of understanding unique value propositions, navigating market entry strategies, and recognizing valuation traps that can hinder a startup's success. The discussion also highlights the need for founders to be disciplined in their approach to funding and market differentiation, ensuring they target the right customers and avoid unnecessary pitfalls in their growth journey. Chapters 00:00 Introduction to Jacques Benkoski and His Journey 08:04 Transitioning from Engineering to Venture Capital 12:09 The Evolution of Cybersecurity Innovations 19:59 AI's Impact on Software Development and Security 30:03 Due Diligence in Venture Capital Investments 34:57 Understanding Unique Value Propositions 46:11 Navigating Market Entry Strategies 55:14 Valuation Traps and Their Implications 62:44 Key Takeaways for Founders and Security Leaders Keywords venture capital, cybersecurity, AI, software development, market entry strategy, entrepreneurship, innovation, investment strategies, technology trends, business growth unique value proposition, market entry strategy, valuation traps, cybersecurity, startup funding, founder-led sales, go-to-market strategy, customer differentiation, venture capital, business growth

  7. Jun 4

    EP 16: Opal

    Discussion with Howard Ting, CEO and Co-Founder at Opal Security Opal: opal.dev Howard Ting: https://www.linkedin.com/in/howardting/ Support the show and Donate to NCMEC: https://give.missingkids.org/TrustIssues Summary In this conversation, Howard Ting, CEO of Opal, discusses the evolution of identity and access management, sharing insights from his extensive career in cybersecurity. He highlights the challenges of managing access and authorization, particularly in the context of modern development practices and the rise of non-human identities. Ting emphasizes the need for a unified access platform that can handle both human and agent identities, advocating for just-in-time access management and fine-grained authorization to enhance security and efficiency in organizations. In this conversation, Justin Somaini discusses the evolving landscape of identity and access management, emphasizing the importance of automation, AI integration, and continuous auditing. He highlights the shift towards just-in-time access models and the need for organizations to adapt to the increasing complexity of managing both human and non-human identities. The discussion also touches on the challenges of delegating authority to agents and the future of company building in a rapidly changing technological environment. Chapters 00:00 Introduction to Identity Management Challenges 03:13 Howard Ting's Journey in Identity and Cybersecurity 05:55 The Evolution of Authorization and Identity Solutions 09:04 The Shift Towards Just-in-Time Access Management 11:49 Understanding the Role of Agents in Identity Management 15:02 The Future of Authorization: Fine-Grained Control 17:53 Building a Unified Access Platform 21:07 Integrating Identity Solutions in Modern Enterprises 23:56 Automating Access Management Processes 29:27 Automating Access Management Workflows 33:29 Just-in-Time Access and AI Integration 36:17 Continuous Auditing and Risk Management 39:40 The Evolution of Identity and Access Management 42:52 AI's Role in Identity Management 47:12 Navigating Non-Human Identities 51:57 Delegating Authority to Agents 56:06 The Future of Company Building and Identity Management Keywords identity management, access control, authorization, cybersecurity, just-in-time access, identity governance, cloud security, fine-grained permissions, automation, identity solutions identity management, access control, AI integration, just-in-time access, continuous auditing, non-human identities, agentic identities, automation, risk management, security innovation

  8. May 22

    EP 15: Alex Pinto

    Discussion with Alex Pinto, Associate Director at Verizon and Manager of the Verizon DBIR report. Verizon DBIR: https://www.verizon.com/business/resources/reports/dbir/ Alex Pinto: https://www.linkedin.com/in/alexcpsec/ Support the show and Donate to NCMEC: https://give.missingkids.org/TrustIssues Summary In this conversation, Justin Somaini speaks with Alex Pinto, the Associate Director of Threat Intelligence at Verizon, about the Verizon Data Breach Investigations Report (DBIR). They discuss Alex's background in cybersecurity, the importance of the DBIR in guiding security programs, and the extensive data collection process that informs the report. The conversation also delves into current trends in cybersecurity, particularly the rise in exploitation of vulnerabilities and the challenges of vulnerability management. Alex emphasizes the need for collaboration and data sharing in the cybersecurity community to effectively combat threats. In this conversation, Justin Somaini discusses the evolving landscape of cybersecurity, focusing on the distinctions between phishing and pretexting, the rise of social engineering attacks, and the impact of AI on cyber threats. He emphasizes the importance of understanding human factors in security processes and the necessity of robust controls like MFA and effective backup strategies. The discussion also highlights the need for innovation in defensive measures and the importance of community collaboration in addressing cybersecurity challenges. Chapters 00:00 Introduction to Trust Issues and Guest Background 09:46 The Verizon DBIR Report: Overview and Importance 19:45 Data Collection and Collaboration for the DBIR 29:52 Trends in Cybersecurity: Vulnerability Management and Exploitation 37:47 Initial Access Vectors: Credential Theft and Pretexting 40:09 Understanding Phishing and Pretexting 43:04 The Evolution of Social Engineering Attacks 48:44 The Role of AI in Cybersecurity Threats 55:44 Innovations in Cyber Defense 61:45 Key Controls for Effective Cyber Defense 69:40 The Future of Cybersecurity and Community Collaboration Keywords cybersecurity, Verizon DBIR, threat intelligence, vulnerability management, data analysis, initial access, credential theft, pretexting, machine learning, security trends phishing, pretexting, social engineering, AI in cybersecurity, cyber defense, ransomware, MFA, vulnerability management, cybersecurity trends, community collaboration

Ratings & Reviews

3.7
out of 5
3 Ratings

About

With constantly increasing threats, the need for Security to innovate faster is paramount.  With more than three decades in the Security industry, I've lived through these problems and been on the bleeding edge of our industry's innovation.  Join me as we dive into what new waves of innovation that are coming at us but also look at the founding teams that are in them.  Along the way, we'll talk to industry leading experts for their unique perspective on what's needed and where we need to go.