Watters Edge

iCOUNTER

This is Watters Edge. Join John Watters as he leads real conversations with the defenders and innovators shifting the balance of power in cybersecurity. Watters Edge is sponsored by iCOUNTER, leading the third wave of cybersecurity with the industry's first COUNTER THREAT OPERATING SYSTEM.

Episodes

  1. 2d ago

    Reimagining Cybersecurity Operations - Joel Molinoff - Watters Edge - Episode #7

    Host John Watters sits down with Joel Molinoff, COO of iCOUNTER, to explore his unconventional path from banking at JPMorgan to the NSA, the White House, and eventually cybersecurity leadership in the private sector. Joel shares how those experiences shaped his approach to intelligence, risk, and operations, and explains why today's defenders need to rethink cybersecurity processes rather than simply use AI to make existing workflows faster.   Takeaways: Take the shot. Joel's career was shaped by a willingness to try something new, from sending his resume to the NSA after 9/11 to pursuing his first CISO role without knowing exactly where the opportunity would lead.Bring intelligence into cybersecurity operations. Joel discusses how lessons from the intelligence community can be applied to the commercial sector, particularly when it comes to using intelligence to identify and reduce risk.Third-party risk is no longer an afterthought. The growing role of third-party compromise has pushed the issue from a secondary GRC concern to a central cybersecurity problem that organizations can no longer ignore.Don't just make the old process faster. AI can accelerate everything from intelligence analysis to detection rules, but Joel argues that speed alone does not solve the problem if organizations are still relying on outdated processes.Reinvent from the ground up. Established organizations have deeply embedded processes that can make fundamental change difficult. Starting with a clean slate creates an opportunity to rethink how cybersecurity operations should work in a modern threat environment.Do more with every security dollar. With security budgets increasingly under pressure, organizations need to balance near-term investment with sustainable efficiency and focus resources on reducing the most risk per dollar invested.Adversaries are innovating faster. Joel sees a growing gap between innovation on the offensive side and stagnation among defenders, making it increasingly important for security leaders to rethink how they operate.Quote of the Show: “It's really hard to reinvent yourself at the speed at which innovation is happening all around you.” - Joel MolinoffLinks: LinkedIn: https://www.linkedin.com/in/joel-molinoff/Website: https://icounter.com/Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    Reimagining Cybersecurity Operations - Joel Molinoff - Watters Edge - Episode #7
  2. Sep 10

    From Threat Intelligence to Real-Time Action - Maggie McDaniel - Watters Edge - Episode # 6

    Get an inside look at the evolution of cyber intelligence with Maggie McDaniel, whose career spans the CIA, Fidelity Investments, Recorded Future, and now iCOUNTER. From finding her first CIA job in a newspaper classified to helping shape modern cyber intelligence, Maggie shares how the industry has evolved from understanding threats to taking action against them. You will learn why intelligence needs to answer the "now what," how adversaries are forcing defenders to operate in seconds instead of days, and why AI, data, and technical skills are becoming essential for modern analysts. Takeaways: Cyber intelligence is evolving from collecting information to driving real-time action and remediation.The speed and scale of modern threats are forcing defenders to respond in seconds rather than days.Analysts increasingly need to combine critical thinking with AI, data, scripting, and development skills.Relying on historical threat intelligence is becoming harder as adversaries develop new capabilities for specific targets.Effective intelligence teams depend on collaboration, communication, and a culture built around the team rather than individual stars.Quote of the Show: “Stay dynamic as the threat moves dynamically.” - Maggie McDanielLinks: LinkedIn: https://www.linkedin.com/in/maggie-mcdaniel-466571130/Website: ​​https://icounter.com/Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    From Threat Intelligence to Real-Time Action - Maggie McDaniel - Watters Edge - Episode # 6
  3. Sep 1

    Black Hat 2026 - Watters Edge - Episode #5

    AI was the word of the week at Black Hat 2026, and this episode captures that in real time through a supercut of quick conversations recorded live on the floor. Voices from across the industry, including Cisco, SAP, Armadin, ICM Cyber, and former NSA leadership, weigh in on what stood out most this year, how they see the third wave of cybersecurity taking shape, and what they think the industry gets wrong. A clear theme runs through nearly every answer: AI is no longer a talking point, it is the water everyone is swimming in, for better and for worse. Between the excitement about agentic AI and pointed calls to get back to security basics, this episode captures where the industry's head is really at heading into the next wave.   Takeaways: Chad Skipper (Cisco) points out that frontier and agentic AI models need real security guardrails, since the same systems that make them powerful also make them capable of acting unpredictably without oversight.Donna Estren notes that AI is now touching every corner of security, from OT and supply chain to endpoint and DevSecOps, meaning point solutions increasingly need to think about AI's ripple effects across the whole stack.Greg Davidson (Armadin) makes the case that the smart move for security leaders right now is narrowing focus onto what is actually exploitable rather than trying to chase every vulnerability with a limited budget.Ken Foster (ICM Cyber) argues that agentic AI is most valuable when it is used to finally fix the fundamentals the industry has struggled with for decades, not just as a buzzword layered on top of old tools.Rob Joyce (former NSA) warns that most organizations still underestimate how fast offensive AI tooling is advancing, and that doing the basics well remains the single biggest lever for actual security.Multiple speakers flagged the same myth from different angles: neither compliance nor threat modeling actually solves security problems on their own. They are tools to help manage risk and prepare for the unknown, not substitutes for doing the work. Quote of the Show: “I think that everybody's gotta figure out how to do the basics because those are the things that are actually gonna make us secure." — Rob Joyce, former NSA  Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    Black Hat 2026 - Watters Edge - Episode #5
  4. Aug 27

    Six Month Shelf Life of Threat Intelligence - Errol Weiss - Watters Edge - Episode # 4

    Get an inside look at how information sharing became one of cybersecurity's most powerful tools with the man who helped build it from the ground up, Errol Weiss, Chief Security Officer of the Health ISAC. From his earliest days at the NSA to shaping FS ISAC in its infancy and now leading one of the most interconnected ecosystems in the world, Errol brings decades of hard won perspective on what actually keeps industries safe. You will learn how scarcity of budget and staff can become a strength rather than a weakness, why the useful life of a threat intelligence report has shrunk from years to about six months, and how third party risk has quietly become the industry's biggest blind spot. Get ready to rethink how much your organization's safety depends on the weakest link in your ecosystem. Takeaways: Info sharing works best when members believe a weak link anywhere in the ecosystem is a risk to everyone, a principle that shaped both FS ISAC and Health ISAC from their earliest days.Scarcity of budget and staff, especially in healthcare, makes shared intelligence and pooled resources more valuable than any single organization's internal capability.The useful lifespan of a well written threat intelligence report has dropped to about six months, driven largely by how fast AI is accelerating both attacker tradecraft and defender response.Third party breaches have grown from nine percent to forty eight percent of all breaches in the last three years, making ecosystem and supply chain risk a bigger blind spot than most first party security programs.Working groups organized by discipline, such as incident responders or threat intel professionals, consistently produce more practical value than top down guidance alone.Diversity of membership across regions and company sizes surfaces fresh approaches that larger, more resourced organizations often miss entirely.Resilience planning matters as much as prevention. Incidents like Change Healthcare have pushed the health sector to plan for IT outages while still preserving patient care.Quote of the Show: "The life expectancy of a really well written intelligence report, man, today, six months tops." - Errol Weiss Links: LinkedIn: https://www.linkedin.com/in/errolweiss/Website: https://health-isac.org/Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    Six Month Shelf Life of Threat Intelligence - Errol Weiss - Watters Edge - Episode # 4
  5. Aug 18

    From Rock to Rockets - Skunk Baxter - Watters Edge - Episode #3

    Host John Watters welcomes longtime friend Jeff "Skunk" Baxter, the former Doobie Brothers and Steely Dan guitarist turned civilian missile defense advisor, recorded live from Black Hat in Las Vegas. The conversation runs from Skunk's musical roots and the neuroscience of sound to his push for legal frameworks that let companies fight back against cyberattacks, closing on where AI-speed threats and offensive testing are taking network defense next.   Takeaways: Curiosity travels across disciplines. Write down good ideas and get them to the right person. Skunk's paper on missile defense, handed to a congressman, opened a seat on the Armed Services Committee.Music can be engineered for emotional effect. Specific chord intervals and harmonics trigger measurable neurochemical reactions, a principle platforms like TikTok have since applied at scale.Cyberattacks created a new, unregulated domain of conflict, letting small actors strike far larger ones without a standing army, and attribution remains the hardest part of any response.Old legal tools can solve new problems. Letters of Marque and Reprisal, a centuries-old framework for authorizing private actors, could offer a legal basis for companies to respond to cyberattacks.AI is compressing response time to nearly nothing. Femtosecond-speed attacks mean defenders need pre-built, automated responses rather than real-time strategy sessions.Every employee and every supplier is a potential entry point. Third-party breaches have jumped from 9% to 48% in three years as attackers shift toward the weakest link in the ecosystem. Quote of the Show: “Now the game is different, and now everybody is a player” - Skunk Baxter Links: Website: https://www.jeffskunkbaxter.com/Book Link: https://www.amazon.com/Rock-Rockets-Slinger-Scientist-National/dp/0063499150 Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    From Rock to Rockets - Skunk Baxter - Watters Edge - Episode #3
  6. Aug 11

    The 4 T’s of Investing - Jay Leek - Watters Edge - Episode #2

    Host John Watters sits down with longtime friend Jay Leek, Managing Partner of SYN Ventures, to trace his path from building computers in his family's business in West Texas to operating roles at Nokia, Equifax, and Blackstone, where he became the first CISO in private equity. Jay explains how those experiences shaped his move into full time investing, and shares how he evaluates founding teams, why timing now carries as much weight as team and technology, and how AI is reshaping the attack surface and the role of the engineer.   Takeaways: Evaluate teams first. Jay's four Ts framework, team, total addressable market, technology, and timing, puts team ahead of everything else, since a strong team will find a way around obstacles instead of giving up.Expect a stumble. Every company Jay has invested in has faced a setback at some point, and how a team recovers matters far more than avoiding the setback altogether.Separate testing from production. Jay's longstanding rule for portfolio companies is to never confuse a production environment with a glorified QA environment, a lesson that applies well beyond startups.Watch how teams adapt to AI first development. The role of the engineer is shifting from writing code to managing outcomes, and founders who can embrace that shift are better positioned for what comes next.Treat timing as its own discipline. Markets and technology are moving fast enough that timing now deserves the same weight as team, market, and technology when assessing an opportunity.Build from operating experience. SYN Ventures was built around partners with decades of firsthand experience as CISOs, CEOs, and founders, which shapes how they support the companies they back.Take calculated risks early. Jay reflects that developing comfort with risk earlier in a career, and recovering quickly from missteps, can meaningfully accelerate long term growth.Quote of the Show: “A smart team will jump over it, break it down, crawl around it, run around it, do whatever they need to do.” - Jay LeekLinks: LinkedIn: linkedin.com/in/jayleekWebsite: synventures.comWays to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/ YouTube: https://www.youtube.com/@WattersEdgePodcast

    The 4 T’s of Investing - Jay Leek - Watters Edge - Episode #2
  7. Aug 4

    Rise of the Third Wave - Kevin Mandia - Watters Edge - Episode #1

    Host John Watters sits down with longtime friend Kevin Mandia, CEO of Armadin, to dig into founding Mandiant, surviving the 2008 recession, and the APT1 report that put Chinese nation state hacking on the front page and reshaped the threat intelligence industry. The conversation moves through the FireEye acquisition, the hard years of stepping into the CEO role, and the eventual sale to Google, before landing on why Kevin came out of retirement to build Armadin and bet everything on autonomous, AI led security.   Takeaways: Treat breaches as inevitable rather than preventable, and build your reputation on being the trusted first call when something goes wrong.Word of mouth can outperform an entire sales team. Kevin grew Mandiant profitably for a decade largely through referrals and inbound calls.Codify what you learn from every incident. Mandiant's early internal indicator schema turned scattered forensic work into a repeatable intelligence advantage.Expect friction during a turnaround. Cost cuts and restructuring will test trust with your team, and leaders need to communicate directly through it.Move away from human in the loop detection models. AI led attacks are moving at a speed and scale that requires autonomous response.Use offensive AI capability to train and validate your defenses before adversaries ever get the chance to attack.Commit to continuous learning as a baseline habit. Every CISO and CEO Kevin talks to agrees that staying current with new tools and data sources is now nonnegotiable. Quote of the Show: “You've gotta look at your entire stack, all your tech, all your people, and get ready for the AI world.” - Kevin MandiaLinks: LinkedIn: linkedin.com/in/kevin-mandia-0a07173Website: mandiant.com Ways to Tune In: Podcast Website: https://wattersedgepodcast.com/ Spotify: https://open.spotify.com/show/033ZejaonpOuVPFh8m350w Apple Podcasts: https://podcasts.apple.com/podcast/watters-edge-1e65430c-e5c4-4c35-a520-bf0d90571f3b/id6796840936 Amazon Music: https://music.amazon.com/podcasts/4b3bebed-655d-42a7-82de-021519c4ccea iHeart Radio: https://iheart.com/podcast/340198973/YouTube: https://www.youtube.com/@WattersEdgePodcast

    Rise of the Third Wave - Kevin Mandia - Watters Edge - Episode #1

About

This is Watters Edge. Join John Watters as he leads real conversations with the defenders and innovators shifting the balance of power in cybersecurity. Watters Edge is sponsored by iCOUNTER, leading the third wave of cybersecurity with the industry's first COUNTER THREAT OPERATING SYSTEM.