1
00:00:04,640 --> 00:00:08,320
Welcome to the live episode of 
Crying Out Cloud, The Wiz 

2
00:00:08,320 --> 00:00:11,720
podcast that will make you 
laugh, cry and reconsider all of

3
00:00:11,720 --> 00:00:16,120
your cloud security fears. 
We're excited to host it as a 

4
00:00:16,120 --> 00:00:19,240
collaboration, as Adi said, with
women in security and privacy 

5
00:00:19,480 --> 00:00:23,640
and live at RSA as a panel 
featuring three really 

6
00:00:23,640 --> 00:00:26,920
fascinating leaders. 
I'm Eden Aftali. 

7
00:00:26,920 --> 00:00:31,360
I am a product manager and Co 
host of Crying at Cloud at Wiz, 

8
00:00:31,920 --> 00:00:35,320
and I'm really overwhelmed with 
excitement to be here, both with

9
00:00:35,320 --> 00:00:38,240
remarkable leaders and coming 
together in person, which we 

10
00:00:38,400 --> 00:00:41,840
don't get to do very often. 
In front of you. 

11
00:00:41,840 --> 00:00:45,040
You have the head of security 
engineering, a threat 

12
00:00:45,040 --> 00:00:47,240
intelligence director and a 
research leader. 

13
00:00:47,560 --> 00:00:52,160
And I think that is precisely in
the cohesion of these three 

14
00:00:52,160 --> 00:00:56,320
perspectives that lies the 
ability to really drive 

15
00:00:56,560 --> 00:01:00,880
effective security. 
And so before we dive into how 

16
00:01:00,880 --> 00:01:03,400
together an individually, we are
driving the world of security 

17
00:01:03,400 --> 00:01:06,960
forward, I would love to 
introduce our distinguished 

18
00:01:06,960 --> 00:01:09,600
panelists. 
Nicole Dove is the head of 

19
00:01:09,640 --> 00:01:13,480
security engineering for the 
Games division at Riot Games. 

20
00:01:14,520 --> 00:01:18,240
Yes, absolutely. 
She sits on the board of Women 

21
00:01:18,240 --> 00:01:21,720
in Security and Privacy. 
She won the 2024 Teammate Cecil 

22
00:01:21,720 --> 00:01:26,080
Village award and the 2022 EWF 
Women of Influence Award. 

23
00:01:26,320 --> 00:01:28,200
She is currently writing her 
first book. 

24
00:01:28,200 --> 00:01:33,360
Very exciting learning 
cybersecurity and host the Women

25
00:01:33,360 --> 00:01:38,880
in Security and Privacy podcast 
On My Left Alone. 

26
00:01:38,880 --> 00:01:41,560
Shindle serves as the vice 
president of AI and Threat 

27
00:01:41,560 --> 00:01:44,800
Research at Wiz. 
He has initiated and contributed

28
00:01:44,800 --> 00:01:47,120
to multiple community projects, 
including the cloud 

29
00:01:47,120 --> 00:01:50,200
vulnerability database in the 
Cloud Threat Landscape project. 

30
00:01:50,520 --> 00:01:53,560
And I'd like to say he's the 
person that I text OMG to every 

31
00:01:53,560 --> 00:01:55,520
time something crazy happens in 
the cloud. 

32
00:01:57,240 --> 00:02:00,320
And we also have shared to 
Grippa, who is the director of 

33
00:02:00,320 --> 00:02:02,680
threat intelligence strategy at 
Microsoft. 

34
00:02:05,840 --> 00:02:08,960
She was named cybersecurity 
woman of the year in 2022. 

35
00:02:08,960 --> 00:02:13,400
And yes, previously she served 
as VP of threat research and 

36
00:02:13,400 --> 00:02:17,120
detection of proof point. 
And I know particularly Amitai, 

37
00:02:17,120 --> 00:02:20,520
who is my amazing Co host 
regularly is very jealous not to

38
00:02:20,520 --> 00:02:22,760
be hosting you on this specific 
episode. 

39
00:02:23,000 --> 00:02:25,240
They're it's Twitter. 
And we miss you, Amitai. 

40
00:02:25,240 --> 00:02:26,560
Yes. 
Shout out. 

41
00:02:27,520 --> 00:02:30,720
When we start episodes, we call 
it cloud confessions. 

42
00:02:30,720 --> 00:02:33,680
It's to get to know the people 
on the podcast a little bit. 

43
00:02:34,200 --> 00:02:38,520
So to kick it off, if you were a
cybersecurity vulnerability, 

44
00:02:39,000 --> 00:02:47,400
what type would you be and why? 
I would be critical Internet 

45
00:02:47,400 --> 00:02:51,920
facing really really heavy 
stuff. 

46
00:02:52,040 --> 00:02:55,320
Love. 
I would be a supply chain 

47
00:02:55,320 --> 00:02:57,840
vulnerability because I'm deep 
and complex. 

48
00:02:58,480 --> 00:03:01,200
Oh, I like. 
I feel like you knew what your 

49
00:03:01,200 --> 00:03:03,760
answer was going to be. 
He listens to the podcast. 

50
00:03:03,760 --> 00:03:07,400
This one comes up sometimes. 
I would definitely be a browser 

51
00:03:07,400 --> 00:03:10,040
vulm because I feel like those 
are retro, old school and 

52
00:03:10,040 --> 00:03:13,000
classic. 
Good good answers. 

53
00:03:13,000 --> 00:03:14,600
Even what variability would you 
be? 

54
00:03:15,120 --> 00:03:19,040
I'd be a zero day because I 
come, I'm hectic and I messed 

55
00:03:19,040 --> 00:03:24,560
things up. 
OK, And one more little question

56
00:03:24,560 --> 00:03:28,920
to warm up the stage. 
What is your most unusual hobby 

57
00:03:28,920 --> 00:03:31,080
that has nothing to do with 
cybersecurity? 

58
00:03:34,400 --> 00:03:39,560
Oh, I'm obsessed with astrology.
My sun sign is an Aquarius. 

59
00:03:39,560 --> 00:03:43,000
My Venus sign is an Aquarius. 
My Mars sign is an Aquarius. 

60
00:03:44,080 --> 00:03:52,000
I am fully dead in style. 
That's what matters, baby. 

61
00:03:54,800 --> 00:03:57,520
Amazing. 
I am learning to fly a plane. 

62
00:03:57,840 --> 00:04:00,840
No way. 
Yeah, I am studying to get my 

63
00:04:01,240 --> 00:04:05,280
single engine private pilot 
license because all I want to do

64
00:04:05,280 --> 00:04:07,440
is fly to coastal towns. 
Remark. 

65
00:04:07,440 --> 00:04:10,120
Food and go to the spas. 
Amazing. 

66
00:04:10,120 --> 00:04:12,440
I think I'd even trust you to 
take me on a plane. 

67
00:04:13,480 --> 00:04:14,680
Risk averse. 
OK, cool. 

68
00:04:16,959 --> 00:04:20,839
For me, it's collecting retro 
soccer shirts from the 90s. 

69
00:04:21,519 --> 00:04:23,760
He's really good at it. 
If you become his friend, he'll 

70
00:04:23,760 --> 00:04:26,720
even send you one. 
Also send him to to Eden like I,

71
00:04:26,760 --> 00:04:29,200
I think every time when when 
they say like something that I'm

72
00:04:29,200 --> 00:04:32,200
excited about just Eden is like 
their reviewer. 

73
00:04:32,200 --> 00:04:35,160
She she has to approve. 
Yeah, either they take it worth 

74
00:04:35,160 --> 00:04:37,360
like 200 bucks and now and 
that's like bad. 

75
00:04:37,360 --> 00:04:38,160
Team bad. 
Team Next. 

76
00:04:39,360 --> 00:04:41,040
Do you wear them or you just 
collect them? 

77
00:04:41,040 --> 00:04:43,000
You wear them. 
OK, yeah, but I mean not, not 

78
00:04:43,000 --> 00:04:47,400
like 4 hours say, but yeah, but.
Nice. 

79
00:04:48,320 --> 00:04:51,360
Let's start off with the topic 
of global collaboration. 

80
00:04:52,000 --> 00:04:54,680
Knowledge sharing is crucial in 
the world of threat 

81
00:04:54,680 --> 00:04:58,280
intelligence. 
No single organization, company,

82
00:04:58,280 --> 00:05:00,600
security tool can know 
everything on their own. 

83
00:05:01,640 --> 00:05:04,800
We'll start with you, shared As 
a threat intelligence leader, 

84
00:05:05,160 --> 00:05:08,720
how do you build and maintain 
collaborative relationships with

85
00:05:08,720 --> 00:05:12,640
other organizations? 
And asking this, I think it can 

86
00:05:12,640 --> 00:05:15,440
maybe sound straightforward, but
particularly challenging when 

87
00:05:15,440 --> 00:05:17,760
some of these companies may even
directly compete with you. 

88
00:05:18,280 --> 00:05:21,560
Sure. 
And I think that's a really, 

89
00:05:21,560 --> 00:05:24,360
really important part of keeping
the world safe is having threat 

90
00:05:24,360 --> 00:05:26,640
intelligence that's shared. 
Because ultimately we want 

91
00:05:26,640 --> 00:05:28,640
everything we know in the 
intelligence space to be 

92
00:05:28,640 --> 00:05:31,360
actionable. 
If it's not actionable and it 

93
00:05:31,360 --> 00:05:34,680
doesn't lead to threat actors 
being disrupted, it's not threat

94
00:05:34,680 --> 00:05:36,600
intelligence. 
Threat entertainment. 

95
00:05:37,040 --> 00:05:41,520
And I love entertainment, but it
doesn't get me closer to being 

96
00:05:41,520 --> 00:05:45,120
more scared. 
Yeah, We live in an industry of 

97
00:05:45,120 --> 00:05:47,360
people that are a little 
squirrely, a little weird, a 

98
00:05:47,360 --> 00:05:49,040
little anxious and a little 
freaked out. 

99
00:05:49,560 --> 00:05:54,840
And I think the best way to get 
great collaboration is to lean 

100
00:05:54,840 --> 00:05:57,880
into that and build trust with 
people one-on-one. 

101
00:05:58,240 --> 00:06:00,320
I'm a big fan of analysts to 
analyst. 

102
00:06:00,760 --> 00:06:03,240
We have lots of sharing programs
at Microsoft. 

103
00:06:03,240 --> 00:06:07,400
We have a variety of options in 
every direction to share massive

104
00:06:07,400 --> 00:06:10,200
amounts of threat intelligence. 
Analyst. 

105
00:06:10,200 --> 00:06:13,120
Analyst is the most effective 
because it has the relationship 

106
00:06:13,120 --> 00:06:16,880
behind it and you can trust what
that person says and does. 

107
00:06:16,880 --> 00:06:22,360
I've been coming here to RSA for
23 years and those relationships

108
00:06:22,800 --> 00:06:26,160
are what build the trust over 
and over, repeated year after 

109
00:06:26,160 --> 00:06:28,400
year. 
And in the gaming industry 

110
00:06:28,400 --> 00:06:31,160
specifically, what is 
collaboration look like? 

111
00:06:31,720 --> 00:06:34,560
So I think about collaboration 
on a couple different levels. 

112
00:06:35,480 --> 00:06:39,920
The first thing I'm focused on, 
it's the underpinning of my 

113
00:06:39,920 --> 00:06:44,440
role, is building Riots First 
Global Business Information 

114
00:06:44,440 --> 00:06:47,640
security office. 
And the goal of that 

115
00:06:47,640 --> 00:06:52,280
organization is to make sure 
that we are not only keeping the

116
00:06:52,280 --> 00:06:55,640
lights on from a security 
perspective, but that we have a 

117
00:06:55,640 --> 00:06:58,840
keen deep understanding of 
what's happening with our game 

118
00:06:58,840 --> 00:07:00,880
teams, right? 
Like they're doing more than 

119
00:07:00,880 --> 00:07:03,240
just keeping games on. 
They're innovating and they're 

120
00:07:03,240 --> 00:07:06,200
building new features and there 
are new events and experiences 

121
00:07:06,200 --> 00:07:08,880
for players. 
And we want to make sure that we

122
00:07:08,880 --> 00:07:11,360
have capabilities from a 
security perspective that 

123
00:07:11,360 --> 00:07:12,920
support where the business is 
going. 

124
00:07:13,360 --> 00:07:16,480
And then if we don't, we can 
build those or buy those. 

125
00:07:16,800 --> 00:07:21,000
Another layer of my role is 
doing exactly some of what you 

126
00:07:21,000 --> 00:07:24,440
mentioned, and it's talking with
other information security 

127
00:07:24,440 --> 00:07:27,560
officers at other games teams to
understand what their threats 

128
00:07:27,560 --> 00:07:30,240
are, what their challenges are, 
and what are some things that 

129
00:07:30,240 --> 00:07:32,960
they are doing really well. 
And sharing that information 

130
00:07:32,960 --> 00:07:35,760
helps us just to be more 
advanced and secure as a 

131
00:07:35,760 --> 00:07:38,560
collective because ultimately 
we're all focused on player 

132
00:07:38,560 --> 00:07:40,760
experience. 
Amazing. 

133
00:07:41,120 --> 00:07:44,760
And do you find that like 
service providers or strategic 

134
00:07:44,760 --> 00:07:47,560
partners in that or there really
are just vendors that you work 

135
00:07:47,560 --> 00:07:51,680
with? 
If there is anybody helping, 

136
00:07:51,680 --> 00:07:55,360
keeping the lights on, keeping 
the toilets clean, right, 

137
00:07:55,360 --> 00:07:59,240
cooking the food in our 
cafeteria, in my opinion, you 

138
00:07:59,240 --> 00:08:03,040
are a part of us helping create 
great experiences for players. 

139
00:08:03,440 --> 00:08:06,360
And so we have a responsibility 
to treat you as a strategic 

140
00:08:06,360 --> 00:08:10,200
partner because it's it's just 
just a part of the the culture 

141
00:08:10,200 --> 00:08:15,280
at Riot to to just keep 
everything great, our campus 

142
00:08:15,280 --> 00:08:18,480
safe, right? 
And just making great, just 

143
00:08:18,480 --> 00:08:20,240
making Ryan a great place to 
make games. 

144
00:08:21,080 --> 00:08:24,840
And alone, what about in the 
world of the cloud age? 

145
00:08:25,320 --> 00:08:27,840
You guys have worked on projects
like the cloud threat landscape,

146
00:08:27,840 --> 00:08:30,440
which I think would be cool to 
share a little bit more about. 

147
00:08:30,680 --> 00:08:33,280
Can you tell us how that is an 
example of how you're working 

148
00:08:33,280 --> 00:08:36,240
with the larger, broader 
cybersecurity community? 

149
00:08:36,600 --> 00:08:39,039
Yes. 
So the clouds friends, the 

150
00:08:39,039 --> 00:08:43,320
Threat Landscape project is an 
open project where we decided we

151
00:08:43,320 --> 00:08:47,280
had our own internal database of
information and Intel about 

152
00:08:47,600 --> 00:08:54,120
threat actors 0 techniques and 
and like incidents where these 

153
00:08:54,120 --> 00:08:57,760
these actors were detected and 
we decided. 

154
00:08:57,760 --> 00:09:01,840
So we first built it internally 
to try and, and, you know, just 

155
00:09:02,160 --> 00:09:05,640
to, to build our own knowledge 
and also develop the program 

156
00:09:05,640 --> 00:09:09,960
according to, to the techniques 
that these attackers are using. 

157
00:09:11,040 --> 00:09:13,000
And, and we decided to share it 
with the world. 

158
00:09:13,000 --> 00:09:18,360
We, we felt like our mission is 
today is not only about, I mean,

159
00:09:18,360 --> 00:09:21,960
is how we can help the threat 
intelligence community to move 

160
00:09:21,960 --> 00:09:25,680
forward to the cloud age because
we see different types of, of 

161
00:09:25,680 --> 00:09:28,640
indicators in the cloud, 
different types of IO CS. 

162
00:09:28,840 --> 00:09:32,160
So today it's sometimes about 
subscription ideas that 

163
00:09:32,160 --> 00:09:36,280
attackers use in order to access
other environments. 

164
00:09:36,280 --> 00:09:40,240
You have like many different, 
like kind of more novel IO CS 

165
00:09:40,640 --> 00:09:43,320
and we say our mission is to try
and help and also like it's, 

166
00:09:43,320 --> 00:09:45,400
it's true, some of it is true. 
Really showing with the 

167
00:09:45,400 --> 00:09:49,760
community and the discussion 
that we want to start on like 

168
00:09:49,760 --> 00:09:53,400
how threat intelligence should 
look like in the, in the new 

169
00:09:53,400 --> 00:09:55,840
cloudage. 
I mean, the, the, the, the 

170
00:09:55,840 --> 00:10:00,720
traditional IO CS are still 
critical, but I think we, we 

171
00:10:00,720 --> 00:10:02,160
believe that there is room for 
one. 

172
00:10:02,160 --> 00:10:04,400
This is why we share this, this 
project. 

173
00:10:04,400 --> 00:10:06,880
We wanted to share that the 
knowledge and we also want to 

174
00:10:07,160 --> 00:10:12,920
try and see how how TI looks 
like now and with like this 

175
00:10:12,920 --> 00:10:17,360
different type of actors who are
operating in the cloud. 

176
00:10:17,880 --> 00:10:20,800
And do you see it with the rise 
of like AI and machine learning 

177
00:10:20,800 --> 00:10:22,880
technologies? 
What are the new threats that 

178
00:10:22,880 --> 00:10:25,920
you're seeing that are, you 
know, specifically targeting 

179
00:10:25,920 --> 00:10:28,680
LLMS and other cloud based AI 
services? 

180
00:10:29,200 --> 00:10:30,640
Yeah. 
So of course, I mean, you can 

181
00:10:30,640 --> 00:10:33,760
trust the the hackers, the 
attackers that they will try to 

182
00:10:34,120 --> 00:10:38,280
find how they can like they 
finance the yeah, they're more 

183
00:10:38,760 --> 00:10:41,520
financially motivated. 
The actors that would then I'm 

184
00:10:41,520 --> 00:10:45,320
sure sure they can can share her
insight about that. 

185
00:10:45,320 --> 00:10:50,000
But we've, we've seen a new type
of like actors, we call it, or 

186
00:10:50,120 --> 00:10:54,720
new type of campaigns that are 
now called LLM jacking, trying 

187
00:10:54,720 --> 00:10:59,760
to find the LLMS and AI services
that are just exposing the 

188
00:10:59,760 --> 00:11:03,880
Internet and kind of they're, 
they just LLM and, or using AI 

189
00:11:03,880 --> 00:11:06,200
can be expensive. 
They are trying to find all 

190
00:11:06,200 --> 00:11:09,720
these exposed instances and kind
of build their own services on 

191
00:11:09,720 --> 00:11:14,600
top of these expose LLMS. And 
then someone, it might be your 

192
00:11:14,600 --> 00:11:17,960
company who pays the bill, but 
they actually get the, the money

193
00:11:17,960 --> 00:11:21,440
for, for the services. 
So this is 1 type of campaign we

194
00:11:21,440 --> 00:11:23,040
actually see. 
It's like the activity there. 

195
00:11:23,040 --> 00:11:26,560
We estimates like millions of 
dollars every month. 

196
00:11:26,640 --> 00:11:28,320
So it's it's a. 
Check your bills. 

197
00:11:28,520 --> 00:11:30,640
Yeah, check, check. 
I think that, yeah, that's only 

198
00:11:30,640 --> 00:11:34,440
usually for for cybersecurity, 
one of the best places to start 

199
00:11:34,440 --> 00:11:38,000
is actually with your if you 
want to find threat, check your 

200
00:11:38,000 --> 00:11:41,000
bills. 
So this is 1 type of campaign 

201
00:11:41,000 --> 00:11:45,120
that is that that or campaigns 
that we see in that are 

202
00:11:45,120 --> 00:11:47,400
interesting. 
Think a part of that we see of 

203
00:11:47,400 --> 00:11:50,520
course in the phishing domain, 
we see that attackers I think 

204
00:11:50,520 --> 00:11:54,440
that's probably the most common 
use of AI because you can create

205
00:11:54,440 --> 00:11:58,000
like easily create so many 
different phishing emails. 

206
00:11:58,000 --> 00:12:02,520
Also other types of scams that 
are easy to create with with AI 

207
00:12:02,520 --> 00:12:05,880
and and I mean, yeah, attackers 
know how to leverage the new 

208
00:12:05,880 --> 00:12:09,520
technologies sometimes faster 
than us, the defenders. 

209
00:12:09,520 --> 00:12:12,960
And This is why like our mission
is also to understand how we can

210
00:12:12,960 --> 00:12:17,240
leverage AI to fight all these 
new techniques. 

211
00:12:17,240 --> 00:12:18,960
And I definitely believe that 
there is room for that, 

212
00:12:19,120 --> 00:12:21,160
especially now with like identic
AI. 

213
00:12:21,160 --> 00:12:25,320
The new types of like modern 
Infrasodard can definitely help 

214
00:12:25,320 --> 00:12:27,880
teams with better detection and 
actually more efficient 

215
00:12:27,880 --> 00:12:29,840
processes. 
Totally. 

216
00:12:30,720 --> 00:12:35,280
For you guys, the gaming world, 
what do you like what? 

217
00:12:35,480 --> 00:12:38,640
How do you see the threat actors
are adapting to the unique 

218
00:12:38,640 --> 00:12:41,040
aspects of gaming companies and 
how are they? 

219
00:12:41,400 --> 00:12:43,080
How are they going about it 
these days? 

220
00:12:44,440 --> 00:12:48,160
It's interesting when I think 
about threat actors and their 

221
00:12:48,160 --> 00:12:50,960
tactics, I don't know that 
there's really anything new 

222
00:12:50,960 --> 00:12:53,520
under the sun. 
They're just leveraging AI to do

223
00:12:53,520 --> 00:12:57,200
it faster, slicker in the gaming
space. 

224
00:12:57,200 --> 00:13:00,640
One of the things that we see a 
lot of is our threat actors 

225
00:13:00,640 --> 00:13:04,920
really attempting to infiltrate 
the natural ecosystem of gaming,

226
00:13:05,240 --> 00:13:07,680
right. 
So account takeovers is is a big

227
00:13:07,680 --> 00:13:14,400
thing actually getting inside 
the game and fooling around with

228
00:13:14,400 --> 00:13:17,280
with the the financial 
transactions with the the 

229
00:13:17,280 --> 00:13:19,880
microtransactions within the 
game is is another piece. 

230
00:13:20,680 --> 00:13:24,240
But typically, even if we look 
at the big attack that happened 

231
00:13:24,800 --> 00:13:28,880
at Rockstar or actually used to 
work, interestingly enough, it 

232
00:13:28,880 --> 00:13:32,120
was the same old traditional 
social engineering, right? 

233
00:13:32,120 --> 00:13:34,640
Network penetration, stealth 
movement. 

234
00:13:35,240 --> 00:13:38,000
So I don't know that they're 
necessarily doing anything new, 

235
00:13:38,760 --> 00:13:41,000
but they're leveraging 
artificial intelligence and new 

236
00:13:41,000 --> 00:13:42,840
technology to do it a lot 
better. 

237
00:13:43,080 --> 00:13:45,360
Which makes us have to do it 
even better on our end. 

238
00:13:46,640 --> 00:13:50,000
And shared from your vantage 
point at Microsoft, what do you 

239
00:13:50,080 --> 00:13:52,560
see as the most significant 
ships that are shifts that are 

240
00:13:52,560 --> 00:13:55,600
happening in the threat 
landscape kind of high level? 

241
00:13:56,520 --> 00:13:59,440
I think the threat landscape is 
always moving, as Nicole 

242
00:13:59,440 --> 00:14:01,520
mentioned, like there's not 
always necessarily something 

243
00:14:01,520 --> 00:14:04,320
new. 
A lot of times when we cut off 1

244
00:14:04,320 --> 00:14:08,200
Avenue like disabling macros in 
office, they find something 

245
00:14:08,200 --> 00:14:09,920
else. 
You know, I feel like we're 

246
00:14:09,920 --> 00:14:13,400
really seeing a a significant 
decline in malware. 

247
00:14:13,400 --> 00:14:15,640
It's just not as popular as it 
used to be. 

248
00:14:16,320 --> 00:14:19,720
Vulnerabilities are really back 
up at the forefront for access 

249
00:14:19,720 --> 00:14:23,200
these days as well as vulnerable
network devices. 

250
00:14:23,200 --> 00:14:26,800
We absolutely see a significant 
amount of nation sponsored 

251
00:14:26,800 --> 00:14:31,000
threat actors compromising small
office Home Office routers. 

252
00:14:31,000 --> 00:14:34,760
So you know, one of the messages
that I'm constantly on the drum 

253
00:14:34,760 --> 00:14:38,600
beat for is if you have not 
rebooted and updated your home 

254
00:14:38,600 --> 00:14:42,800
router in a long time, you may 
be a launching pad for Russian 

255
00:14:42,800 --> 00:14:46,960
or China based threat actors. 
That's where they like to have 

256
00:14:46,960 --> 00:14:48,960
their source IPS is out of 
residential. 

257
00:14:49,320 --> 00:14:53,480
If you've got parents that never
update their tech, don't let 

258
00:14:53,480 --> 00:14:58,360
them be used as, you know, a 
vehicle to do attacks against 

259
00:14:58,360 --> 00:15:00,120
critical infrastructure and 
things like that. 

260
00:15:00,800 --> 00:15:03,640
That's definitely your parent, 
the parents generation to go 

261
00:15:03,680 --> 00:15:06,840
forward. 
I and sometimes I meet very 

262
00:15:06,840 --> 00:15:12,160
young people that also are not 
super, you know, I think kind of

263
00:15:12,160 --> 00:15:15,480
a different topic, but I think 
that when I was coming into 

264
00:15:15,480 --> 00:15:18,040
tech, I thought, oh, everyone 
will be like me. 

265
00:15:18,040 --> 00:15:19,840
The next generation, everyone 
will be like me. 

266
00:15:20,320 --> 00:15:23,200
They will have their like deep, 
deep knowledge. 

267
00:15:23,200 --> 00:15:26,920
They will be Colonel hackers. 
They will be so in this because 

268
00:15:26,920 --> 00:15:30,480
we're paving the way for them. 
And I think what really happened

269
00:15:30,480 --> 00:15:35,640
is that it became similar to the
way that I think of my 

270
00:15:35,640 --> 00:15:38,200
television. 
I point and click at it. 

271
00:15:38,400 --> 00:15:40,800
It's not something I deeply to 
be able to understand. 

272
00:15:41,120 --> 00:15:44,240
And I think that there is almost
this sandwich generation that is

273
00:15:44,240 --> 00:15:48,800
deeply technical and those 
before and those after have sort

274
00:15:48,800 --> 00:15:51,040
of started around it. 
That's interesting. 

275
00:15:51,600 --> 00:15:55,440
And I saw, I saw I think a funny
tweet exactly about that, like 

276
00:15:55,600 --> 00:15:59,280
that even 10 years ago, in order
to be a hacker, you had to, you 

277
00:15:59,280 --> 00:16:01,640
know, to do. 
Yeah, to, to know kernel way 

278
00:16:01,960 --> 00:16:03,600
really good. 
You had to, I mean, you're the 

279
00:16:03,680 --> 00:16:06,680
ACLASLR. 
You had to cope with all of 

280
00:16:06,680 --> 00:16:08,920
these techniques. 
And now with AI, it's like just 

281
00:16:09,320 --> 00:16:11,920
or with, you know, MCP, just, 
you know, come on, give me all 

282
00:16:11,920 --> 00:16:14,040
the data from from here. 
That's what, yeah. 

283
00:16:14,040 --> 00:16:15,880
Vibe hacking. 
Just one prompt and you get 

284
00:16:15,880 --> 00:16:18,200
everything you need. 
I, I think that that's something

285
00:16:18,200 --> 00:16:21,520
too for, for people to kind of 
wrap their heads around with AI 

286
00:16:21,640 --> 00:16:25,840
is most of us started, if you're
near my age, you started with 

287
00:16:25,840 --> 00:16:28,680
command line interface, you 
started with CLI, right? 

288
00:16:28,680 --> 00:16:30,960
We're typing at the computer and
we're giving it commands. 

289
00:16:30,960 --> 00:16:33,320
And then we got a gooey, right? 
We got a graphical user 

290
00:16:33,320 --> 00:16:35,360
interface. 
We could click, we could point, 

291
00:16:35,360 --> 00:16:38,960
we could see things. 
We now have a third interface 

292
00:16:38,960 --> 00:16:41,440
into our technology and that's 
natural language. 

293
00:16:41,760 --> 00:16:45,160
That's simply asking it a 
question, talking to it, you 

294
00:16:45,160 --> 00:16:51,280
know, Jarvis from, you know, 
like from Marvel, like it really

295
00:16:51,280 --> 00:16:55,280
is getting to that point. 
And so that new interface is 

296
00:16:55,280 --> 00:16:59,760
something that's really 
important to understand what it 

297
00:16:59,840 --> 00:17:02,840
offers to people that aren't 
necessarily deeply technical the

298
00:17:02,840 --> 00:17:04,240
way they would need to be for a 
CLI. 

299
00:17:04,680 --> 00:17:07,160
And angry I think, I think it's 
a great point and I say I feel 

300
00:17:07,160 --> 00:17:10,400
like this year in RSA this is 
part of the discussion with many

301
00:17:10,560 --> 00:17:13,319
both since we're in the city 
where most of the large AI 

302
00:17:13,319 --> 00:17:16,440
vendors are and we're. 
At Ground Zero for the 

303
00:17:16,440 --> 00:17:17,800
nightmare, I know. 
Yeah. 

304
00:17:17,800 --> 00:17:21,920
And I feel like we're in a point
where we, I mean, if maybe in a 

305
00:17:21,920 --> 00:17:25,720
year from now, next RSA, we look
inside like some of the products

306
00:17:25,720 --> 00:17:28,319
and the products that won't have
this new interface, we look like

307
00:17:28,560 --> 00:17:32,600
look like the pre iPhone age 
that they look and they see 

308
00:17:32,600 --> 00:17:36,960
like, OK, how did I use this 
Nokia phone? 

309
00:17:37,120 --> 00:17:39,520
I saw an iPod last week and I 
was like whoa. 

310
00:17:40,960 --> 00:17:43,440
Yeah, it's like a completely 
like a whole new different 

311
00:17:43,440 --> 00:17:45,240
interface. 
And like we, we should adapt. 

312
00:17:45,240 --> 00:17:47,800
I think both. 
I mean, I mean the, the product 

313
00:17:47,800 --> 00:17:50,760
vendors, but also like for 
everyone who runs the security 

314
00:17:50,760 --> 00:17:53,960
team, like try to think and with
like the MCP service now it 

315
00:17:53,960 --> 00:17:59,160
becomes easier to adopt this, to
adopt this, this new interface 

316
00:17:59,480 --> 00:18:01,880
faster. 
And I mean, we, we hear it like 

317
00:18:01,880 --> 00:18:03,760
from everyone. 
They just want to have their 

318
00:18:03,880 --> 00:18:06,480
like, I just want to open my 
browser and have this text 

319
00:18:06,480 --> 00:18:08,920
interface and I, I want to like 
control everything. 

320
00:18:08,920 --> 00:18:13,920
Like the job is experience for 
my cybersecurity operations, so 

321
00:18:14,520 --> 00:18:17,440
it's a very exciting time to be 
in. 

322
00:18:18,120 --> 00:18:20,680
In this time, another thing, 
we're seeing a lot of our code 

323
00:18:20,680 --> 00:18:27,280
and supply chain attacks. 
We've seen a lot of this 

324
00:18:27,280 --> 00:18:29,920
concerning trend. 
If you listen to the podcast, 

325
00:18:29,920 --> 00:18:32,280
you hear us talk a lot about 
these attacks. 

326
00:18:33,160 --> 00:18:37,120
I'm curious, since GitHub is a 
Microsoft company, I'm curious 

327
00:18:37,360 --> 00:18:39,680
what your perspective shared is 
on these threats and what 

328
00:18:39,680 --> 00:18:44,000
Microsoft and GitHub are doing 
to combat and what looks like 

329
00:18:44,000 --> 00:18:47,080
increasingly sophisticated 
versions of these attacks. 

330
00:18:47,440 --> 00:18:50,160
Sure. 
I think that software supply 

331
00:18:50,160 --> 00:18:54,320
chain is sort of a frontier 
that's been around since, you 

332
00:18:54,320 --> 00:18:56,560
know, the biggest flash probably
was SolarWinds, right? 

333
00:18:56,560 --> 00:19:01,320
Like getting into code that is 
from a vendor that is used 

334
00:19:01,320 --> 00:19:04,640
across a variety of downstream 
customers. 

335
00:19:05,120 --> 00:19:07,760
That's absolutely something that
threat actors focus on. 

336
00:19:09,040 --> 00:19:13,440
One of the examples in terms of 
code supply checking that that 

337
00:19:13,440 --> 00:19:17,440
Microsoft and GitHub both do is 
that we actually do use AI to 

338
00:19:17,680 --> 00:19:20,640
review code base looking for 
credential pairs. 

339
00:19:20,760 --> 00:19:23,480
Hard coded credentials are one 
of the number one mistakes that 

340
00:19:23,480 --> 00:19:28,800
you see in vibe coding and high 
level software engineering both.

341
00:19:29,920 --> 00:19:35,680
The issue with that is, if you 
think about it, you can't really

342
00:19:35,680 --> 00:19:40,280
write an effective regular 
expression to find every type of

343
00:19:40,280 --> 00:19:43,440
credential pair. 
Microsoft alone uses 41 

344
00:19:43,440 --> 00:19:48,480
different types of keys, 
certificates, cookies, all kinds

345
00:19:48,480 --> 00:19:50,880
of different capabilities to 
authenticate. 

346
00:19:51,440 --> 00:19:56,680
And with AI, we can ask it to go
look through code and say, find 

347
00:19:56,680 --> 00:20:00,680
me something that would give me 
access for a code review. 

348
00:20:01,560 --> 00:20:05,880
Threat actors can also do that. 
So we're in a race against time,

349
00:20:05,880 --> 00:20:09,280
as we always are as defenders, 
but we're actually leveraging a 

350
00:20:09,280 --> 00:20:13,800
lot of AI to make that software 
supply chain safer because it is

351
00:20:13,800 --> 00:20:15,440
really as well geared towards 
that. 

352
00:20:15,480 --> 00:20:19,520
It's not well geared towards 
emotions and human things, but 

353
00:20:19,520 --> 00:20:21,560
it is quite good at looking at 
code. 

354
00:20:22,800 --> 00:20:25,880
Totally. 
And Nicole, for you guys, do 

355
00:20:25,880 --> 00:20:29,440
these supply chain code 
repository threats factor into 

356
00:20:29,440 --> 00:20:32,680
your security priorities? 
Absolutely. 

357
00:20:33,120 --> 00:20:37,400
And I actually see it more of a 
people challenge or a people 

358
00:20:37,400 --> 00:20:41,720
opportunity because we have 
people who are coding, right. 

359
00:20:42,040 --> 00:20:46,040
We have people who are at maybe 
third party developers or 

360
00:20:46,040 --> 00:20:48,400
studios, right, that we're 
working with to help create 

361
00:20:48,400 --> 00:20:52,120
these experiences. 
And so not only do I want to 

362
00:20:52,120 --> 00:20:55,280
validate the integrity of the of
the code, but what I really want

363
00:20:55,280 --> 00:20:58,600
to do is shift the thought 
process of the engineers and the

364
00:20:58,600 --> 00:21:01,200
people who are doing that work, 
right? 

365
00:21:01,200 --> 00:21:04,680
I want them to always be 
thinking about, you know, Co 

366
00:21:04,680 --> 00:21:08,160
repositories and how we're 
protecting that information, how

367
00:21:08,160 --> 00:21:11,240
we're working with third party 
vendors, how often we assess 

368
00:21:11,240 --> 00:21:14,000
them, right? 
Even if we have a game that, 

369
00:21:14,080 --> 00:21:16,040
hey, maybe we decide we don't 
want to develop this game 

370
00:21:16,040 --> 00:21:19,840
anymore and there's a partner, 
strategic partner that we're 

371
00:21:19,840 --> 00:21:21,720
leveraging that we want to move 
to another game. 

372
00:21:21,720 --> 00:21:23,920
How are we thinking about the 
scope differential? 

373
00:21:24,240 --> 00:21:26,240
And then how do we make sure 
that we're evaluating them 

374
00:21:26,240 --> 00:21:29,800
appropriately? 
So it's definitely a part of our

375
00:21:29,800 --> 00:21:35,400
evolving security strategy. 
We may look at this for games in

376
00:21:35,400 --> 00:21:38,640
development one way, a live game
a different way, but we're 

377
00:21:38,640 --> 00:21:41,680
definitely always focused on not
only the code, but the behaviors

378
00:21:41,680 --> 00:21:43,880
of the people who are managing 
that code. 

379
00:21:44,160 --> 00:21:46,080
I like that you called it an 
opportunity. 

380
00:21:46,400 --> 00:21:49,400
How do you kind of do that shift
with the actual people? 

381
00:21:49,400 --> 00:21:52,440
How do you instill that culture 
with your developers? 

382
00:21:53,280 --> 00:21:56,920
So initially when I start 
engaging with the games teams, I

383
00:21:56,920 --> 00:22:00,000
don't want to talk about 
anything security, right? 

384
00:22:00,200 --> 00:22:03,680
I just want to get to know them.
I want to get to know what they 

385
00:22:03,680 --> 00:22:05,000
do. 
I want to know what they're 

386
00:22:05,000 --> 00:22:07,120
excited about. 
I want to know feedback from our

387
00:22:07,120 --> 00:22:10,200
players and I want to understand
their priorities, right? 

388
00:22:10,200 --> 00:22:13,560
Because first and foremost, that
is what's important, right? 

389
00:22:13,560 --> 00:22:16,800
We are not a security company. 
We are a games company and we 

390
00:22:16,800 --> 00:22:20,400
need to make games. 
But then once I began to 

391
00:22:20,400 --> 00:22:23,640
understand and you know, kind of
their methodology, their 

392
00:22:23,640 --> 00:22:29,640
priorities, what they're excited
about, then I'm better 

393
00:22:29,640 --> 00:22:33,920
positioned, right, to make a 
recommendation or figure out a 

394
00:22:33,920 --> 00:22:36,800
way that I can help them do all 
the things that they're planning

395
00:22:36,800 --> 00:22:41,200
to do that they're really going 
to do anyway in the most secure 

396
00:22:41,200 --> 00:22:43,400
way, right? 
And so if I don't lead with this

397
00:22:43,400 --> 00:22:47,880
heavy hand of security, but I 
lead with a process or a mindset

398
00:22:47,880 --> 00:22:50,880
of business 1st and then 
wrapping security around that, I

399
00:22:50,880 --> 00:22:54,080
get a lot more collaboration. 
And I think it's very much 

400
00:22:54,080 --> 00:22:56,320
appreciated. 
So it, it's not security for the

401
00:22:56,320 --> 00:22:59,560
sake of security, but it's 
essentially, and this is 

402
00:22:59,560 --> 00:23:01,520
something I steal from my 
manager all the time. 

403
00:23:01,680 --> 00:23:04,200
It's tell me what you want to do
and I'm going to tell you how to

404
00:23:04,200 --> 00:23:06,680
do that in the safest way. 
And I think they appreciate that

405
00:23:06,680 --> 00:23:07,640
very much. 
Yeah. 

406
00:23:07,800 --> 00:23:10,440
I think that's also the trend 
we're seeing of democratizing 

407
00:23:10,480 --> 00:23:11,960
security. 
So we're we're all. 

408
00:23:12,320 --> 00:23:15,200
Yeah, because if you don't, 
they're going to go around you. 

409
00:23:15,640 --> 00:23:18,560
And do it filming it anyways, so
might as well do it securely as.

410
00:23:18,600 --> 00:23:20,200
Well, collaborate totally. 
Yeah, so. 

411
00:23:20,720 --> 00:23:23,040
You didn't, I know you're the 
host, but I have a question for 

412
00:23:23,040 --> 00:23:25,560
you about that because I know I 
mean you've built as I've been 

413
00:23:25,880 --> 00:23:28,920
recently kind of like a 
gamification experience. 

414
00:23:28,920 --> 00:23:32,800
So I think it really connects to
how like you try to help 

415
00:23:32,800 --> 00:23:35,440
security teams with this 
mission. 

416
00:23:35,440 --> 00:23:37,880
So maybe you can about your. 
Experience in my non podcast 

417
00:23:37,880 --> 00:23:39,280
job. 
One of the things we added in 

418
00:23:39,280 --> 00:23:42,920
Wiz that I helped build is 
gamification of security. 

419
00:23:43,160 --> 00:23:48,240
So it's fun, fun to kind of get 
to these rewards. 

420
00:23:48,240 --> 00:23:51,040
So while you're doing whether 
it's the development team or the

421
00:23:51,600 --> 00:23:54,360
the SEC OPS team and they're 
doing the things they need to be

422
00:23:54,360 --> 00:23:57,400
doing anyways, so we reward them
with badges and streaks. 

423
00:23:57,560 --> 00:24:00,960
So it's kind of the opposite of 
gaming, adding security. 

424
00:24:00,960 --> 00:24:03,200
It's security, adding gaming. 
And I think that we learn from 

425
00:24:03,200 --> 00:24:05,120
you guys and how to do that so 
well. 

426
00:24:05,200 --> 00:24:07,800
So yeah. 
Security is fun, right? 

427
00:24:07,840 --> 00:24:09,320
Yeah. 
Security is fun. 

428
00:24:09,680 --> 00:24:11,960
When the people on this stage 
are here, it's a little bit more

429
00:24:11,960 --> 00:24:14,160
fun. 
Maybe we're biased, but. 

430
00:24:15,200 --> 00:24:19,360
Everyone in the room is, so it's
OK alone. 

431
00:24:20,000 --> 00:24:22,720
Your team has come up with a 
really, really fascinating 

432
00:24:22,720 --> 00:24:26,200
research and been at the 
forefront of identifying some of

433
00:24:26,200 --> 00:24:27,760
these supply chain 
vulnerabilities. 

434
00:24:28,720 --> 00:24:31,520
First of all, I'm curious what 
like technical limitations there

435
00:24:31,520 --> 00:24:35,200
are of traditional threat 
intelligence that we used to be 

436
00:24:35,200 --> 00:24:39,800
doing when it comes to finding 
these new types of attacks and 

437
00:24:40,000 --> 00:24:42,480
how you approach that? 
Yeah. 

438
00:24:42,480 --> 00:24:47,480
So I think if you are looking in
the like recent, like 2 notable 

439
00:24:47,640 --> 00:24:51,680
supply chain attacks, one is the
EX utils, one ability and the 

440
00:24:51,680 --> 00:24:57,360
other one is the TJ action, the 
TJ actions incident. 

441
00:24:58,080 --> 00:25:01,360
I think both of them are coming 
from a place that like 

442
00:25:01,840 --> 00:25:05,640
traditional TI doesn't cover. 
So if we look at a GitHub 

443
00:25:05,640 --> 00:25:10,520
actions space, it's it's a like 
a whole new or relatively new 

444
00:25:10,520 --> 00:25:12,520
concept. 
And you're using an, an 

445
00:25:12,520 --> 00:25:15,720
organization use this like open,
open actions. 

446
00:25:15,720 --> 00:25:18,880
And the attackers in this case 
were actually able to target a 

447
00:25:18,880 --> 00:25:22,280
specific organization because 
they knew that they use this 

448
00:25:23,440 --> 00:25:27,560
specific action. 
And, and I think that when we're

449
00:25:27,560 --> 00:25:30,680
talking about these new type of 
threats, we have like different 

450
00:25:30,680 --> 00:25:34,960
components in the supply chain. 
And one of it can, can be the 

451
00:25:35,520 --> 00:25:40,200
like the, the GitHub actions and
like we should find ways to, to 

452
00:25:40,960 --> 00:25:44,520
first make sure that teams are 
aware of the risks coming from 

453
00:25:44,520 --> 00:25:45,720
them. 
I'm sure now with the DJ 

454
00:25:45,720 --> 00:25:51,360
actions, this incident can like 
help team and also like products

455
00:25:51,360 --> 00:25:54,960
cover more of these areas. 
And we should think about, we 

456
00:25:54,960 --> 00:25:59,560
talked about sharing data. 
How do we share this data? 

457
00:25:59,560 --> 00:26:02,880
And, and that that is, I mean, 
if you look at some of the 

458
00:26:02,880 --> 00:26:07,440
reports, even like by CSI or by 
other security vendors, what do 

459
00:26:07,440 --> 00:26:11,040
you usually see is the, you 
know, the file hashes, the the 

460
00:26:11,040 --> 00:26:15,360
IPS of that the attackers are 
using, but you don't see other 

461
00:26:15,360 --> 00:26:18,080
types of the indicators that 
might be part of the attack. 

462
00:26:18,080 --> 00:26:20,920
So I think like as an industry, 
we should think how can we 

463
00:26:20,920 --> 00:26:24,720
create maybe new formats, new 
standards to share all of these 

464
00:26:24,760 --> 00:26:28,080
novel IO CS. 
And we should also try to 

465
00:26:28,080 --> 00:26:31,960
rethink where where the attacks 
might come from. 

466
00:26:31,960 --> 00:26:35,280
And that it's not only from the 
places that we used to know, 

467
00:26:35,280 --> 00:26:38,280
it's now from. 
Yeah, from these actually from 

468
00:26:38,280 --> 00:26:42,360
like a compromised like 
libraries and we've seen that I 

469
00:26:42,360 --> 00:26:45,600
think that's something that 
executives was an amazing 

470
00:26:45,600 --> 00:26:48,680
example. 
It's been an operation that the,

471
00:26:48,920 --> 00:26:53,960
the, the like an actor behind 
the terrain for four years 

472
00:26:53,960 --> 00:26:58,120
really tried to be Yeah. 
Like they, they, they joined as 

473
00:26:58,640 --> 00:27:05,320
a maintainer for a very popular 
library, tried to add malicious,

474
00:27:05,320 --> 00:27:10,640
like they, they kind of build 
their credibility there and to 

475
00:27:10,640 --> 00:27:13,400
the point where they were able 
to add malicious code to one of 

476
00:27:13,400 --> 00:27:18,040
these like very popular and like
frameworks and library. 

477
00:27:18,400 --> 00:27:22,200
And I think that this is an area
that's, I mean, that there's no 

478
00:27:23,480 --> 00:27:26,800
focus there like from both like 
every Social Security and we're 

479
00:27:26,920 --> 00:27:28,720
just starting to see it. 
And I think that the attackers 

480
00:27:28,720 --> 00:27:30,960
know that. 
And This is why there are I mean

481
00:27:31,080 --> 00:27:35,320
using these as as like their 
initial access, the new initial 

482
00:27:35,320 --> 00:27:38,120
access vectors. 
How do we in terms of like 

483
00:27:38,200 --> 00:27:42,160
sharing the sources of 
intelligence around this, what 

484
00:27:42,160 --> 00:27:45,640
are your guys's favorite like 
juicy data sources? 

485
00:27:45,640 --> 00:27:49,120
Like where is your go to? 
What are you reading? 

486
00:27:49,120 --> 00:27:52,840
What are you looking up? 
And also in that vein, how do 

487
00:27:52,840 --> 00:27:57,200
you even keep your teams 
informed? 

488
00:27:57,920 --> 00:28:02,480
A lot of my preferred learnings 
are probably a little informal 

489
00:28:02,480 --> 00:28:07,000
and non traditional, right? 
So we're, we're a very big Slack

490
00:28:07,000 --> 00:28:08,960
shop. 
And so we have like our own 

491
00:28:08,960 --> 00:28:12,280
infosec, like private channels 
where we're sharing a bunch of 

492
00:28:12,280 --> 00:28:16,000
articles and things like that. 
There are a bunch of folks on 

493
00:28:16,000 --> 00:28:20,760
LinkedIn who do like, you know, 
daily cybersecurity tips and 

494
00:28:20,760 --> 00:28:23,840
tricks and what's in the news 
that I find really, really 

495
00:28:23,840 --> 00:28:26,600
exciting. 
A lot of times it's really just 

496
00:28:26,600 --> 00:28:29,240
talking to a lot of people in 
the industry about what's 

497
00:28:29,240 --> 00:28:31,920
happening, whether it's with 
their company, somebody in their

498
00:28:31,920 --> 00:28:35,480
industry. 
But really, the informal bits 

499
00:28:35,480 --> 00:28:39,400
are the juiciest for me. 
I like a sassy Twitter thread 

500
00:28:39,400 --> 00:28:42,240
where like something's happening
and like following it as if it's

501
00:28:42,240 --> 00:28:45,720
like the Real Housewives, but 
it's not. 

502
00:28:48,200 --> 00:28:54,200
What about you guys? 
For me, I love of an indictment.

503
00:28:55,640 --> 00:28:57,880
They're so beautifully well 
written. 

504
00:28:57,920 --> 00:28:59,600
A lot of times they have 
pictures. 

505
00:28:59,600 --> 00:29:03,160
Sometimes if they're foreign 
threat actors, they'll have mug 

506
00:29:03,160 --> 00:29:06,760
shots, passport photos. 
I tell people all the time if 

507
00:29:06,760 --> 00:29:09,160
you want to get into threat 
intelligence, start reading 

508
00:29:09,160 --> 00:29:13,720
those indictments because they 
really show you the walkthrough 

509
00:29:13,720 --> 00:29:15,880
of the attack. 
And so I absolutely love those. 

510
00:29:16,200 --> 00:29:20,880
And I also really love virus. 
Total comments you can't just 

511
00:29:20,880 --> 00:29:24,320
look at the score you need to 
get into the comments because it

512
00:29:24,320 --> 00:29:28,280
is you know if you've ever heard
the sort of the the joke, you 

513
00:29:28,280 --> 00:29:30,680
know in the dating world, any 
app is a dating app if you try 

514
00:29:30,680 --> 00:29:34,720
hard enough any app is a 
security and threat intelligence

515
00:29:34,720 --> 00:29:37,160
sharing app if you try hard 
enough and virus. 

516
00:29:37,160 --> 00:29:38,320
Totally. 
I'm taking that goal. 

517
00:29:38,520 --> 00:29:43,040
That's amazing, whether you're 
looking through comments or 

518
00:29:43,040 --> 00:29:46,440
talking to people, it's almost 
like a different skill set of, 

519
00:29:46,600 --> 00:29:48,520
you know, being on your toes and
learning. 

520
00:29:48,520 --> 00:29:51,160
And it's not like I, I went and 
I got a degree and now I'm 

521
00:29:51,160 --> 00:29:53,280
informed. 
It's a constant learning. 

522
00:29:53,280 --> 00:29:56,280
And I think it kind of begs the 
question, what are maybe 

523
00:29:56,280 --> 00:30:00,000
overlooked skills to success and
threat intelligence? 

524
00:30:02,080 --> 00:30:09,440
Anxiety, if you feel a little 
freaked out and stressed out all

525
00:30:09,440 --> 00:30:11,480
the time, please come work with 
us. 

526
00:30:11,520 --> 00:30:15,920
Please. 
We have jobs to monetize your 

527
00:30:15,920 --> 00:30:22,000
stress. 
Capitalism will monetize your 

528
00:30:22,320 --> 00:30:25,560
disorder. 
I think that it's really 

529
00:30:25,560 --> 00:30:28,400
important that people who have 
that little sense in the back of

530
00:30:28,400 --> 00:30:34,320
their head that have a little 
bit of spirit of suspicion, we 

531
00:30:34,320 --> 00:30:40,280
welcome you, tap into it, use 
it, and most importantly, 

532
00:30:40,280 --> 00:30:43,640
containerize, isolate and 
firewallet only to your job. 

533
00:30:44,000 --> 00:30:47,880
Don't let it jailbreak into your
personal life. 

534
00:30:48,440 --> 00:30:50,400
It's good. 
It's like a therapist. 

535
00:30:50,400 --> 00:30:53,040
You're like, use it here, get it
out of your system, make the 

536
00:30:53,040 --> 00:30:56,280
money with it. 
Make the money with it and then 

537
00:30:56,280 --> 00:31:01,520
enjoy your life. 
I, I think that the, I mean, I 

538
00:31:01,520 --> 00:31:06,640
completely agree with that. 
First adding another skill that 

539
00:31:06,880 --> 00:31:09,680
I'm trying to find like for 
people in my name is like just 

540
00:31:09,680 --> 00:31:12,320
curiosity. 
But I think that's curiosity. 

541
00:31:12,320 --> 00:31:17,760
I mean, if you see someone who 
is, who can become an expert, it

542
00:31:17,760 --> 00:31:19,200
doesn't matter what the domain 
is. 

543
00:31:19,200 --> 00:31:21,960
I think that there is a very 
special skill of becoming just 

544
00:31:22,480 --> 00:31:25,640
really research him, 
investigating something to like 

545
00:31:25,640 --> 00:31:28,600
the point that you know 
everything about his domain. 11 

546
00:31:28,600 --> 00:31:31,720
Great example for that is Mirav 
from from our team. 

547
00:31:31,720 --> 00:31:34,160
Like she, she actually wanted to
be a museum guy because she 

548
00:31:34,160 --> 00:31:37,680
loves art and like, she and like
whenever she says something new 

549
00:31:37,680 --> 00:31:40,200
that she likes, like in in a 
month, you know that she'll 

550
00:31:40,200 --> 00:31:41,920
become like the top experts for 
that. 

551
00:31:41,920 --> 00:31:44,160
The second part of the story is 
that Schindle convinced her to 

552
00:31:44,160 --> 00:31:47,320
come work for what is she was 
deciding the three jobs that he 

553
00:31:47,320 --> 00:31:49,160
convinced her. 
Yeah, yeah. 

554
00:31:49,200 --> 00:31:55,040
So lucky for me, she's not she 
chose not not the odd carriers. 

555
00:31:55,040 --> 00:32:00,680
You might go there later. 
But yeah, so like you can see 

556
00:32:00,920 --> 00:32:03,640
with with many of of I think the
people in the team, they also 

557
00:32:03,640 --> 00:32:06,680
have like whether whether it's 
like a hobby or just like a 

558
00:32:06,680 --> 00:32:11,440
topic that they can just, you 
know, research to a point there 

559
00:32:11,440 --> 00:32:14,800
know everything about it doesn't
really matter what is it. 

560
00:32:14,800 --> 00:32:17,840
I feel like when you know what 
how like good looks like or what

561
00:32:17,840 --> 00:32:21,760
deep really like deep knowledge 
looks like, you can apply to to 

562
00:32:21,760 --> 00:32:26,520
other other domains. 
A couple of things. 

563
00:32:26,520 --> 00:32:31,120
It's it's two eyes for me. 
I think the first is influence, 

564
00:32:31,520 --> 00:32:33,120
right? 
Because Sharon mentioned this 

565
00:32:33,120 --> 00:32:35,280
earlier. 
It's really about taking this 

566
00:32:35,280 --> 00:32:37,320
intelligence and making it 
actionable. 

567
00:32:37,840 --> 00:32:42,080
And the way I talk to somebody 
and finance about a threat, it's

568
00:32:42,080 --> 00:32:44,440
going to be very different than 
the way I talk to an engineer 

569
00:32:44,440 --> 00:32:46,720
about a threat. 
So really understanding your 

570
00:32:46,720 --> 00:32:50,240
audience and and framing it for 
them in a way that will drive 

571
00:32:50,240 --> 00:32:54,680
them to take action. 
The other pieces, this is 

572
00:32:54,760 --> 00:32:56,840
engineer statement on time. 
Well, what do you want me to do,

573
00:32:57,200 --> 00:33:00,280
right? 
And it's the innovative problem 

574
00:33:00,280 --> 00:33:04,080
solving because threat actors 
are just becoming so much. 

575
00:33:04,320 --> 00:33:07,160
They have one job, right? 
All of us work in security. 

576
00:33:07,160 --> 00:33:08,920
There are a million things that 
we have to do. 

577
00:33:09,640 --> 00:33:12,640
And a lot of times there may be 
a fix that we have in our minds 

578
00:33:12,640 --> 00:33:18,240
that might not be as easy or as 
ideal for the teams that need to

579
00:33:18,240 --> 00:33:20,720
implement this. 
And so we've really got to be 

580
00:33:20,720 --> 00:33:24,720
able to be adaptable and stay on
our toes and figure out a way to

581
00:33:24,720 --> 00:33:28,120
get to a solution in a way that 
may not be what we initially 

582
00:33:28,120 --> 00:33:30,640
thought or how we would have 
traditionally saw for something.

583
00:33:30,640 --> 00:33:33,720
So really being able to 
influence people to take things 

584
00:33:33,720 --> 00:33:36,560
seriously and take action, and 
then helping them figure out new

585
00:33:36,560 --> 00:33:41,080
ways to solve new problems. 
Another amazing thing you do is 

586
00:33:41,080 --> 00:33:45,320
run your podcast, which if you 
haven't listened, you should 

587
00:33:45,320 --> 00:33:47,040
listen. 
And if you're listening to this 

588
00:33:47,040 --> 00:33:49,840
podcast, we'll also link it so 
you can check it out. 

589
00:33:50,200 --> 00:33:54,760
And I'm curious kind of maybe 
more shifting to the realm of 

590
00:33:54,760 --> 00:33:58,720
women since it's focused around 
women in security and privacy. 

591
00:33:59,000 --> 00:34:02,320
What do you think are based on 
your conversations and also your

592
00:34:02,320 --> 00:34:08,320
own experience, what patterns, 
like are, you know, the most 

593
00:34:09,159 --> 00:34:11,480
helpful for women in this 
industry and things that are 

594
00:34:11,480 --> 00:34:15,120
holding maybe us back that you'd
love to see kind of fade away? 

595
00:34:15,239 --> 00:34:18,880
Yeah. 
So I get the opportunity to 

596
00:34:18,880 --> 00:34:25,040
interview so many amazing women 
and there are some things that I

597
00:34:25,040 --> 00:34:29,000
see as a consistent thread and 
even some of these I am guilty 

598
00:34:29,000 --> 00:34:33,000
of. 
One thing is that we downplay 

599
00:34:33,040 --> 00:34:36,080
our talent so much, right? 
We want to keep our heads down. 

600
00:34:36,080 --> 00:34:39,480
We just want to get the work 
done and that's an important 

601
00:34:39,480 --> 00:34:42,520
element of it all. 
But we also need to be more 

602
00:34:42,520 --> 00:34:45,280
comfortable and sharing our 
success, right? 

603
00:34:45,320 --> 00:34:49,320
There's nobody will know the 
great work that you do unless 

604
00:34:49,320 --> 00:34:53,719
you tell them. 
And it, it takes courage, right?

605
00:34:53,719 --> 00:34:56,719
Sometimes to be able to, to 
position yourself to say like, 

606
00:34:57,040 --> 00:34:59,560
yeah, I'm a badass. 
I did that and that's good. 

607
00:34:59,560 --> 00:35:01,880
And here's the value, right, 
that I created. 

608
00:35:05,800 --> 00:35:09,320
The second thing is, you know, 
there is a shift that we're 

609
00:35:09,320 --> 00:35:13,040
seeing more women studying 
technology in STEM fields. 

610
00:35:13,040 --> 00:35:15,960
We're seeing a lot more women in
the cybersecurity industry. 

611
00:35:16,240 --> 00:35:20,160
But we are seeing the statistics
taper down as we go more senior 

612
00:35:20,160 --> 00:35:22,640
in organizations. 
And I think there is a 

613
00:35:22,640 --> 00:35:25,880
responsibility that that our 
organizations have, but at the 

614
00:35:25,880 --> 00:35:27,920
same time, there are things that
we can do as well. 

615
00:35:29,040 --> 00:35:31,280
And we've got to put ourselves 
out there, right? 

616
00:35:31,280 --> 00:35:34,120
Like I hear a lot of folks 
complain, like, oh, you know, my

617
00:35:34,120 --> 00:35:36,160
manager, I'm smarter. 
I haven't, you know, I have more

618
00:35:36,160 --> 00:35:39,200
experience. 
OK, Then apply for those roles, 

619
00:35:39,200 --> 00:35:40,440
right? 
Put yourselves in those 

620
00:35:40,440 --> 00:35:43,840
positions, stretch yourself, be 
courageous and put yourself out 

621
00:35:43,840 --> 00:35:46,000
there. 
And I think by just being 

622
00:35:46,000 --> 00:35:48,960
involved in communities like 
Women in Security and Privacy, 

623
00:35:49,560 --> 00:35:53,640
where, you know, it's a space 
where we really encourage women 

624
00:35:54,240 --> 00:35:57,880
to advocate for themselves and, 
and help them figure out 

625
00:35:57,880 --> 00:36:00,680
different strategies to advance 
in these industries. 

626
00:36:00,680 --> 00:36:03,040
And it's really important 
because Women Edge is awesome. 

627
00:36:03,800 --> 00:36:06,800
Absolutely, yeah. 
And I, I think also even just 

628
00:36:06,800 --> 00:36:09,920
reflecting the way I see it is 
also the, the more you see other

629
00:36:09,920 --> 00:36:13,160
women around you at any point, 
the more encouraged you are to 

630
00:36:13,160 --> 00:36:15,720
do that. 
So thank you for doing that work

631
00:36:15,720 --> 00:36:18,120
because it it brings other women
along with you. 

632
00:36:18,120 --> 00:36:22,560
So it's awesome. 
OK, So Morav was one example of 

633
00:36:22,560 --> 00:36:26,560
someone who wanted to be a art. 
What was it? 

634
00:36:26,560 --> 00:36:28,160
Do you want to do museums? 
Yeah. 

635
00:36:29,080 --> 00:36:33,360
Museum tour guide, yes, but 
shared Something I learned about

636
00:36:33,360 --> 00:36:35,680
you when we first spoke is that 
you started your career at art. 

637
00:36:35,680 --> 00:36:39,600
School, yes. 
Very cool. 

638
00:36:40,560 --> 00:36:43,800
Curious to know more about that.
But also it's definitely not a 

639
00:36:43,800 --> 00:36:46,840
traditional background, not that
I think there's one traditional 

640
00:36:46,840 --> 00:36:49,160
background to be here. 
But can you talk a bit about 

641
00:36:49,160 --> 00:36:53,800
your journey from there to today
and kind of actually maybe the 

642
00:36:53,800 --> 00:36:56,920
unique perspectives that coming 
from that background gave you? 

643
00:36:57,160 --> 00:37:00,440
Sure. 
So I had a computer since I was 

644
00:37:00,440 --> 00:37:05,160
12 and I loved it. 
And I, you know, was heavily 

645
00:37:05,160 --> 00:37:09,760
into BB, s s and doing all of 
these, you know, networking, 

646
00:37:09,760 --> 00:37:14,160
early Internet, dial up things. 
And I never thought that that 

647
00:37:14,160 --> 00:37:16,400
was a career path. 
I didn't understand that that 

648
00:37:16,400 --> 00:37:19,720
was a profession. 
And I wanted to go to art school

649
00:37:19,720 --> 00:37:21,080
and I wanted to be a 
photographer. 

650
00:37:21,800 --> 00:37:25,960
I wanted to specifically be a 
tour photographer for Morrissey,

651
00:37:25,960 --> 00:37:32,440
specifically seeing him Tuesday.
That was my goal. 

652
00:37:32,440 --> 00:37:34,440
That's what I wanted to do. 
And I went to school for that. 

653
00:37:34,440 --> 00:37:38,160
And I found that Fine Arts 
school. 

654
00:37:38,760 --> 00:37:41,840
And just a point of 
clarification, people frequently

655
00:37:41,840 --> 00:37:44,360
asked me if I went to school for
cybersecurity. 

656
00:37:44,680 --> 00:37:49,760
I started College in 1996. 
There was no cybersecurity 

657
00:37:49,760 --> 00:37:54,080
degree in 1996. 
In fact only 20% of homes in the

658
00:37:54,080 --> 00:37:57,800
United States in 1996 had 
Internet and it was dial up at 

659
00:37:57,800 --> 00:38:00,680
that time so that was not an 
option. 

660
00:38:01,800 --> 00:38:04,400
I want to point out though 
something about people from non 

661
00:38:04,400 --> 00:38:10,360
traditional backgrounds. 
Fine Arts school is a brutal ego

662
00:38:10,360 --> 00:38:16,480
death experience. 
It will put you in the ground if

663
00:38:16,480 --> 00:38:21,200
you're not strong because you 
show your work to your peers and

664
00:38:21,200 --> 00:38:24,160
you have them critique you on a 
regular basis. 

665
00:38:24,920 --> 00:38:27,720
And that is something that I 
think most people in tech are 

666
00:38:27,720 --> 00:38:33,080
not really accustomed to is 
saying here is my work, no 

667
00:38:33,080 --> 00:38:37,880
commentary, no guidance. 
Here is my work, judge me. 

668
00:38:38,800 --> 00:38:41,080
And it really changes the way 
that you think. 

669
00:38:42,320 --> 00:38:45,800
It also brings you a 
requirement. 

670
00:38:45,800 --> 00:38:51,400
It forces you to be new, novel 
and never before seen art. 

671
00:38:51,400 --> 00:38:55,440
The art world demands something 
that has never been done and 

672
00:38:55,440 --> 00:38:58,960
never been seen every single 
time. 

673
00:39:00,160 --> 00:39:05,600
That mindset is a very threat 
actor psychology mindset, and so

674
00:39:05,680 --> 00:39:08,320
being able to change your 
tactics until you get what you 

675
00:39:08,320 --> 00:39:11,880
want, change, get what you want,
change, get what you want, I 

676
00:39:11,880 --> 00:39:15,280
think has been really beneficial
foundationally for me to be 

677
00:39:15,280 --> 00:39:18,440
successful. 
New novel and never before seen.

678
00:39:18,440 --> 00:39:21,240
I think that that is the note 
we're going to end this on. 

679
00:39:21,240 --> 00:39:24,760
And I feel very grateful to all 
of you for joining us here 

680
00:39:24,760 --> 00:39:27,080
today. 
And it's been fascinating for me

681
00:39:27,080 --> 00:39:28,880
on stage. 
So I hope for you all listening.

682
00:39:28,880 --> 00:39:30,840
It has been as well. 
So thank you so much.

