What we talked about
Andrew Scott is Field CISO at Todyl, where he bridges executive decision-makers and cybersecurity programs for mid-market and SMB organizations. With over a decade of experience across IBM, CrowdStrike, and Recorded Future, he has built security operations programs, led threat intelligence teams, and advised Fortune 500 companies and Federal agencies.
Show notes
A railroad security director once told Andrew Scott something that caught him off guard: “If an APT wants to get us, I can’t do anything to stop them, so I just focus on the fundamentals.” Scott didn’t disagree. His entire approach to cybersecurity is built on that same honesty: you cannot stop every attack, but the organizations that get picked off are almost always the ones that skipped the boring work.
What we covered
- The most common security gap Scott encounters when walking into a new organization is not a missing tool, it is missing governance. Organizations have typically bought their way to what they think is security, accumulated too many tools that do not integrate, and have no documented process for who owns what when something breaks. He calls this the place where “programs of all sizes and all maturity levels continually fail.”
- Scott draws a sharp distinction between security enabling a business and security restricting it. Projects that introduce friction without aligning to business goals get deprioritized or abandoned, and when that happens, Scott says, the security initiative effectively failed before the threat did.
- He uses a simple pressure test with executives: if I remove technology from the equation entirely, ransomware, outage, whatever, how long can your business operate, and what does that cost per day? That single question, he says, “paints a very clear picture immediately of where we need to start managing risk.”
- On AI and defenders: Scott is skeptical of organizations that rush to AI-enabled security tools without having logging coverage, identity access management, or basic patching in order. “AI can’t solve our way out of that,” he said. The underlying infrastructure has to exist for AI to have anything useful to analyze.
- For threat actors, AI delivers the same benefits they want from any efficiency tool, speed, scale, and volume. He noted that from initial compromise to data exfiltration, research from firms like Palo Alto Networks now puts the window at between 30 and 70 minutes. That timeline, he said, forces organizations to plan for containment, not just prevention.
- Moody’s recently updated their credit risk models to treat cyber events as equivalent in severity to hurricanes and other catastrophic events. Scott cited this as the clearest signal yet that cybersecurity is now a business valuation issue, affecting insurance, funding, acquisitions, and credit ratings, not just an IT cost center.
About Andrew
Andrew Scott is Field CISO at Todyl, where he advises mid-market and SMB organizations on building security programs through Todyl’s managed service provider partners. He has spent over a decade in cybersecurity leadership roles at IBM, CrowdStrike, and Recorded Future.
- LinkedIn: https://www.linkedin.com/in/andrew-s-8b691729
- Website: https://www.todyl.com
Episode 149 of the PreVetted Podcast.
Full transcript
Federico Ramallo (00:00) Welcome back to the pre-vetted podcast where we spotlight extraordinary people and remarkable talent reshaping our world. Today I am joined by Andrew Scott. He’s a field CISO at Todil. He brings over 10 years of cybersecurity leadership across companies like IBM, CrowdStrike and Recorded Future where he builds security operation programs, led threat intelligence teams,
and advise executives at federal agencies and Fortune 500 organizations. He’s now helping Toddles partners build stronger security programs and navigate real business risk. Andrew, welcome to the show.
Andrew Scott (00:43) Thanks for having me, Federico. Appreciate it. Glad to be here.
Federico Ramallo (00:47) I’m honored to have you here today.
Andrew Scott (00:50) I that man. Yeah, looking forward to our conversation. I know our early ones have already been great. So I think this will be a good continuation exactly.
Federico Ramallo (00:57) Yes, yes, I think it’s going to be a lot of fun. So can you expand a little bit more about what you do?
Andrew Scott (01:05) Yeah, absolutely. It’s kind of what is a field CISO, guess, you know, a new role, so to speak, I think in the industry. My job is really to be a bridge between what, you know, kind of end user C level or CISO. So really the organizations, whatever it may be, financial services, healthcare, mean, fashioning, what have you, really those key executives and decision makers and being that bridge and that advisor on how do they build
and think about their security program, maybe risk management, how they need to be architecting and delivering that, right? Or think about where they need to have like gaps or leveling up and how can they achieve that with what, you know, my company Total does in terms of our security platform and what we do and how they’re working with service providers and MSSP, even running it themselves possibly. So I really kind of work on both sides. So not only
advising, but also really being that champion of our partners and the clients back into Total. So really listening and hearing what the market needs, where things are going, where executives are seeing their paths forward as a business, and then really helping inform how Total really supports them and meets them in terms of what we’re building. So it’s a really cool role to be able to kind of work both sides, but I like to see myself as just really that bridge between multiple different parties.
truly best enable and protect businesses of all types and sizes, but how can we do that collectively and collaboratively? And so my role really is as kind of an overall consultant and executive advisor.
Federico Ramallo (02:37) interesting so you’re both on the technical side and on the business side
Andrew Scott (02:42) Yeah, correct. Yep. you know, it’s, it’s, it’s an interesting mix for sure. Right. So, you know, kind of both, you know, work very heavily with our product and our security and our engineering teams, but also our customer success and our sales teams and those of our service providers. Right. So total is unique in that we really support the channel primarily. So that means MSPs, I a service fighters, MSSPs, even distributors or bars or others, but really helping guide them as well. And kind of their thinking of how they’re.
advising or building those programs they need to do on behalf of customers or how they interact with them and get organizations the capabilities they need.
Federico Ramallo (03:20) Right, right, that’s very interesting. I was telling you about the book that I’m writing and one of the things that I talk about in the book are kind of, you know.
talk about is my origin story, right? It sounds like a superhero, but anyway. While writing the story, I remember that I joined Microsoft when I was 16 years old and they kind of built a position for me and it was technical sales.
Andrew Scott (03:39) Hahaha
Federico Ramallo (03:52) technical presales, right? So I was doing something, know, different area, but similar, you know, kind of doing technical things, on supporting the business side and the sales side. So it was very fascinating, but I wanted to build stuff. And that was the reason I left, because I wanted to build stuff. And it was, you know, a teenager that was not allowed to go to the consulting side, right? Because, you know, I mean,
Andrew Scott (03:54) Thanks.
Right, right.
Federico Ramallo (04:18) it was just too risky for them, right? So I understand that, know, still, you know, it’s something that I remember with a little bit of sadness, right? Right.
Andrew Scott (04:30) Exactly, right? There’s
only a certain level you can actually put in front of customers. A 16-year-old may not be the best choice, even if you could do it. But absolutely, I get you.
Federico Ramallo (04:38) Right, right. And
then I start remembering like some stories of, you know, having access to service that I technically I shouldn’t have access to, but they gave me access. I could do demos and things like that. And people love it. And the CTOs wanted to bring me as, you know, to build a prototype into production. But then, you know, I hit that wall, right? Yeah, yeah, yeah.
Andrew Scott (04:59) Yeah, exactly right. Yep. Yep.
Federico Ramallo (05:02) So, you know, coming from cybersecurity, I think you would appreciate that story, right? Yeah. So, tell us a little bit more about what does TORI do and who is it built for?
Andrew Scott (05:07) Most definitely,
Yeah, great question. So totals, really, think we’re really here to democratize, I think, cybersecurity programs to organizations. So how can we bring enterprise security programs and capabilities to the organizations that most need it? So our really focus is primarily, again, with that MSP, MSSP, or kind of focus, but it’s who they serve. So that really being the mid-market organizations.
maybe the SMB as well, but really these organizations that do not have the enterprise budgets, but still have enterprise problems, right, and challenges. And so we really consolidate a lot of different capabilities. like endpoint security, simulant observability and analytics, SOC service, governance for compliance capabilities and platforms, as well as kind of secure access service edge and kind of cloud security and identity. So we actually bring all of this together.
So it’s really built to say, look, how can we best manage risk in this threat landscape where threats are moving super fast, it’s really difficult to keep up? How do we make sure that the dollars go the furthest and really being able to easily adopt a security program where increasingly service fighters and others are that kind of resource that organizations are going to either, hey, I need it outsourced, I need some help, or I’m just gonna turn the keys over to someone completely.
So that’s really where Total started from is really making sure that we can meet the larger market that really needs this capability. But historically, it’s not been able to afford all of the enterprise solutions and point solutions. And we’re seeking to really make that easier so businesses can really protect themselves, their business initiatives without that undue pain of budgeting, financing, staffing, etc.
Federico Ramallo (07:00) Right, right. Because the surface attack is similar to bigger companies, but startups have much less budget to work with, right?
Andrew Scott (07:10) Exactly, right? mean, it’s the same. It’s, know, we like to say like it’s, you know, attackers are opportunistic. They are going to go after the weakest link. So you don’t have to necessarily like that saying you don’t have to outrun the bear. You just have to outrun your friend. It’s how can we most effectively make it more expensive and tough to target you to compromise you as an organization and that, you know, attacker is simply going to be like, they’re not going to waste their time in a really difficult.
you know, kind of organization, they’re going to move on, right? Obviously there’s some definitely targeted attacks against Fortune 500s and governments just because of their stature, their role, et cetera. At the SMB and mid-market space and small and medium enterprise, it’s really more of a volume game and opportunistic to where, how can we make the biggest impact as an attacker to target as many orgs? And so you really want to level up your posture as best you can to make it more difficult because they’re not going to waste their time.
they’re gonna go wherever the weakest links are. So, yep.
Federico Ramallo (08:08) Right, right.
And at the end of the day, well, the way that I see this security is with infinite money and infinite time, you can break into anything, right?
Andrew Scott (08:18) 100%. It’s funny, you know, in one of my past roles, I was doing some work for one of the big railroads here in the United States and their director of security said something that at the time sort of caught me off guard, but I was like, well, no, it’s absolutely true. And he noted, he’s like, if APT wants to get us, I can’t do anything to stop them. APT being nation state actor, advanced persistent threat, like just a very advanced adversary. So he’s like, so I just focus on the fundamentals.
that 80-20 rule. I have to make sure I’ve got structure, program, process, full coverage, visibility. I have to do everything I can, but at the end of the day, if someone wants to get in, they’re gonna get in. And that’s just part of doing business, like part of just doing business on the internet. There will always be risk, and we have to accept that. But it’s what risk tolerance level you have, and how are you gonna move that forward. So that’s exactly right. We’re never gonna be without it. You could have…
Unlimited budgets and try to protect yourself, but something still going to probably get through. So it’s just how do we do the best we can with what is at our resources available and how do we best align that with where we need to go as an.
Federico Ramallo (09:26) Right, right. I always give this example to some startups when, you this looks how old I am, right? But people used to ask me, know, WordPress, you know, can I use WordPress as a CMS? And I say, yes, but it has, you know, you have to keep updating. The effort to keep updating it, it’s so hard because the surface attack is so big, right? But if you have a static website,
Your surface attack is zero or almost zero. So if you have a low budget, go with a static website. The additional red tape of working with that is worthwhile. And how often do those startups update those sites anyways?
Andrew Scott (10:12) Yeah, absolutely. And I think you’re getting at the core of really where I think business needs to security, right? There’s a lot of conversations out there about like, CISOs really speaking the language of the board and, know, kind of really, I guess, kind of getting a part of my role, right, is really understanding that CISO lens from like, what are like a company CISOV or kind of CIO even, or kind of just decision makers that need to brief a note or brief a board. But it’s what really are the business goals?
Right? Security never drives a business. It enables it. But you never want to be restricting or hindering the business either. And that’s where you get pushback, right? Projects will always fail if the moment becomes clunky or the moment it becomes, you know, not, you know, aligned with business goals, it drops off. And so I think that’s really where, to your point, like the website example, even just from a, you know, technology and, know, software delivery standpoint, is like, Hey,
Is this effort worth it for where our business needs to go? And then if so, what security protections do we need to have in place and to what level? What are we willing to work with, right? And I think that’s just that key consideration that organizations of all types, especially those that are running security, maybe you’re just a one man shop or a woman shop, you’re responsible for your organization security or you’re a provider. Do we really understand the business of
what we’re building, doing, producing, serving, et cetera, and what makes that business tick. How do we make money or what is our mission? And if we can’t deliver that, right, then we need to, you know, kind of adapt and address that and really seek alignment there because then you’re to get your buy-in, but you’re also not holding that business back, which is the absolute sort of, you know, death wish, I guess, for security initiatives, ultimately.
Federico Ramallo (12:06) Right, right. Yeah, and the best example I’ve been thinking about this thing is organizations that change password very often aggressively, they’re more exposed, right? Because people are going to try to find patterns, right? Like at a one, at a two, at a three, right? And even if you put more complexity, eventually that becomes posted.
on the
Andrew Scott (12:28) Yeah.
Federico Ramallo (12:29) monitor, right? So what’s the point, right? So the same thing happens. There is a threshold of how much the business can tolerate the friction of security, right? Yeah. And I use the word tolerate because it’s coming from not understanding the importance of the security, right?
Andrew Scott (12:33) Yeah, absolutely.
Yeah, I mean, it’s always been sort of seen as a cost center, right? You know, I’ve got to spend money on something that I don’t know exactly see the day to day, you know, kind of ROI or turn an investment on like, where’s the money going? Should I, you know, spend less? you know, but yeah, I think it’s really, that tolerance of like, okay, I always like to say, look, if you’re doing business with technology, what happens if I take that away? Right? So thinking about, you know, disaster recovery, business continuity. If I remove security, you’re sorry, excuse me, technology from the equation.
Federico Ramallo (12:52) Right.
Andrew Scott (13:17) I like a ransomware event, third party risk, know, kind of downtime and outage even. Let’s say just interruption to business, locking up, you know, we can’t access something because, you know, whole networks are broken or down or unavailable. What happens? And it’s kind of amazing to see sort of the wheels start to move. I’m go, God, I haven’t really thought about this before. So yeah, I mean, I think that’s, you know, a key element of guiding the business is, or think about a business is what happens.
If we remove technology from the equation, just how does your business work? Where are those efficiency, you know, gaps? Where does your, can you make widgets? Do you have contracts or other things you can’t fulfill? And then what does that mean for you? Right? Your tolerance level could be like, I’m okay with all of that. Well, that’s it. That’s a choice. That’s a risk-based decision. Some will say, no, I can’t stand any of that. And that’s where I think that’s just really, what’s really cool is that business risk is different for every org.
Federico Ramallo (14:05) Right.
Andrew Scott (14:12) and every org views their own entity and the world they live in in a different way. And I think that’s what keeps security fresh. But also we have to be adapting to that and guiding based upon these shifts and how we’re educating, kind of working with our peers, our kind of providers, our leadership, you know, and even the people under us, let’s say, to really address and adapt kind of how we need to be tolerating risk as it changes throughout time.
Federico Ramallo (14:40) Right, right. I mean, I think the best way to that I’ve been able to understand security from the business perspective is similar to insurance, right? The what if scenario, right? And then the other one is liability and compliance, right? So I’ve been involved in HIPAA compliant projects and
You know, we have to jump through hoops, you know, just to fulfill the liability, right? Sometimes it’s not the most, it’s not optimizing for security, but it’s, know, what is the good enough effort we can do to reduce our liability, increase the security, right? But, you know, there’s a trade-off of how much the business can actually support, whether it’s friction or budget, right?
Andrew Scott (15:27) Yeah, absolutely. mean, I think even compliance, unfortunately, know, mean, HIPAA, for instance, like, again, you know, we can have like large organizations, absolutely, because the exposure and the audit potential is so large, but smaller, let’s say healthcare entities. I mean, it’s really unfortunate, but I’ve had some conversations where some are like, yeah, I’ll wait to take the fine and the audit. I’m like, this is negligent, but it’s a decision you’re making. And I, at some level, have to respect that, that that is your risk tolerance level.
Federico Ramallo (15:49) You
Andrew Scott (15:57) And it’s really just, I think about education, how is, you know, things shifting, right? How is, you know, wiggle or compliance liability and exposure or assurability even changing even how are the threats changing? Are we okay with the potential of a breach and then the subsequent, you know, audits and compliance and regulatory violations? That may be a risk you’re willing to take. Okay. Right. But I think it’s that just, you know, self-education, but also the need to how we…
educate others either in our orgs that we work with or that we’re serving and how we account for, you know, those shifts and changes that need to be made. Because it’s never static, right? It’s always evolving and adapting. And I think that’s where ongoing risk management, even just as basic as, hey, that technology, what if I take it away? I read the news and saw these types of threats, what would happen with us? Just even just simply asking that, just to start with, can really inform how you think about.
your own posture and your wrist tolerance levels. Yep.
Federico Ramallo (16:58) Right, right,
that makes sense. So what is the most common security gap you see when you walk into a new organization?
Andrew Scott (17:06) Governance. It’s not sexy. It’s been skipped, I think, a lot of times because it’s not fun. I think organizations in general have unfortunately bought their way to security or what they may think is. But because of that, they may have overstretched security teams, lack of process and workflow. It’s also
too many tools and too many different capabilities or things that don’t integrate really create and lack a process as well. Like that governance component I’m that just creates more stringing complexity, I think, than a business wants. And that’s where I’m seeing security programs just of all sizes and all different maturity levels just continually failing. Like, again, we started talking just, what does the business do, right? Miss CSF, cybersecurity framework 2.0 entered, introduced that govern function where it’s like just,
What does your organization do? What are its key obligations, liabilities, responsibilities? Like what are its crown jewels? Like it’s gotta be at that. And then what’s the process by which we have workflows for analysis, patching, systems configuration, identity access management? Like that’s where I see a lot of it just break down is we don’t have good process. And I think there’s great opportunities for automation, right? AI to be used for this stuff.
But unfortunately, I see a lot of organizations and skipping the foundations and basics and going right to, I’m going to buy another tool to get myself out of this problem. When you’re only really compounding it, you’re not solving the core symptom. Right? That is that. And that’s where I think the governance of it. And that’s where, know, identity sprawl or protection gaps or other issues to start to grow. And it can be really tough to wrap your hands around and correct that if it gets too far out.
Federico Ramallo (19:01) Right, right. it’s part of governance, the plans if everything goes wrong, and the mitigation plan and the risk mitigation. And there’s another one, I don’t remember the name. It’s what happened, how do we reduce the risk of happening and how do we reduce the impact of happening, right?
Andrew Scott (19:21) Yeah, so like business continuity business impact analysis stuff like that and then like recovery like a lot of people talk about how can we respond to an incident? How do we recover like how much? Downtime and like what is our like return to operations timelines? They’re like how fast can we get back up to speed or maintain that? Yes, so that’s a key part of the governance I think but that’s like really like the security the security strategy for the organization
Federico Ramallo (19:24) Right.
Andrew Scott (19:46) has to understand, I think, some of those tolerance levels and ask those hard questions before you can then start building process. And I think that’s the other gap is people are like, we’re going to go build process right away or do these things that we think, but we haven’t aligned with actually, well, what do we need to be delivering? Like when I started on my consulting career, you know, one of my managers had always said, and it stuck with me for my whole career, like just asking the client or the customer. And then it’s like also internal customer.
your own leadership, your own peers, what does success look like? Right? Like, what does good look like in your eyes? How does security support the business? Assume we do invest. What does a secure business look like to you, Mr. CFO, COO, CEO? Right? And with that lens, then we can start building that process and building our program. But otherwise, we may be introducing the inefficiencies for the organization or just complete misalignment.
you haven’t really solved anything, you’re actually making it worse. So I just think like that that first step is absolutely asking those questions and then like, okay, then how do we evaluate downtime or other things that may be a result of that? And that could be a huge exercise, but I also think it doesn’t have to be. And so it’s like, let’s just go to our profitability and loss sheet or the P &L quote to cash.
How do we make money? How much money do we make a day? To my point, like, if I take technology away, what does that do to revenue? Or what does that do to our finances? If we were down for three weeks, or three days, or three weeks, how much runway do we have? And that just really paints a very clear picture immediately of where we need to start managing risk from, at least from a cybersecurity standpoint.
Federico Ramallo (21:34) Yeah, I think that the most simple question of who does what, know, because when something happens, when there’s an issue, then you see people running around without a clear responsibility of who should react and what should they do, right?
Andrew Scott (21:39) Yeah.
Well, yeah, mean, you exactly like, you you mentioned insurance, right? Where people are, you know, okay. You know, so I think like many organizations that have physical offices, they have a fire suppression system. You probably have a quarterly fire drill. You know who the captains of the different groups are. They’re going to escort people out and you practice it and everyone’s okay with it. Hopefully we never went after exercise that actually in real life. So why do we do the same? Why don’t we do the same with our data and technology, right?
So that idea of like an incident response plan, you never want to be dusting that thing off or figuring it out during an incident, right? So I think it’s part of just there’s like, you know, a tabletop exercise, always a good one, just like scenario driven, there’s plenty of platforms or, you know, kind of resources out there. I think even just quickly pressure testing certain, you know, very like micro table, mini tabletops, like how do we handle a business email compromised incident where someone got another unauthorized access?
I don’t know what we do like it doesn’t have to be this huge exercise. We can start with just simply asking basic scenarios and questions and like who owns what as part of the incident response cycle. And I think that’s where a key part of governance is aligning to a framework, right? Really make sure you know the framework, whether it’s NIST, CIS, you know, whatever, right? Just get started, but have that structure that like, OK, I’m going to follow best practice.
we’re going to commit to this because that helps you really streamline and then know where you’re kind of falling down or maybe you’re excelling, you’re doing great. But I think that’s a good gauge as well that I would never, I would always encourage everyone to start with, find a control framework, unless you’re regulated and have to avoid certain things, right? And commit to it because you’re going to have to sooner or later and it’s going to make your life lot easier.
Federico Ramallo (23:41) Right.
Andrew Scott (23:44) going to help structure everything else from there. yep.
Federico Ramallo (23:48) Right, right, that makes
sense. And how do you see AI changing the threat landscape for both defenders and attackers?
Andrew Scott (23:58) Yeah, great question. mean, so Defenders is it’s it’s definitely a lot of meaning moving things a lot faster, which is great. They can infer and learn to these evolving threats. I think there’s also a risk from defenders that I mentioned I’m big, you know, kind of back to basics fundamentals guy, right? Right? If we don’t have a strategy or
foundational components of like systems administration and identity access management, just who’s getting rights and policies and really adopting these principles or patch meeting and management, just these various functions. If we’re not taking care of the basics, AI can’t solve our way out of that. Like AI is, I may be oversimplifying, but I think it maybe needs to be that level because there’s so much adoption of it.
both as a business but also, this next security tool’s got AI baked in. Absolutely. But we are introducing the idea of information systems. We’re introducing another technology component into the environment. A human is bringing that in. AI didn’t just magically appear, right? know, a bot, an agent or bot, hopefully not, right? Unless someone else installed it. But we’re using it for a certain purpose. Okay, so we’re introducing it. What is that purpose for?
And I think that’s really got to drive when we think about defense or how business is using AI, those questions and kind of preparation needs to be done before we introduce a tool to support defenders. Cause otherwise if we have like visibility gaps and logging gaps, AI is not going to solve that problem. Right? on the flip side, like for threat actors, I think
AI threats, if anything, is exactly what we all are seeking from AI too. It’s efficiency gains, it’s speed, it’s scale, it’s volume, because we all want to do more with less and faster. And so, yes, there’s a lot of talk about, know, cloud mythos, know, kind of massive vulnerability and exploitation or kind of findings, like sure, that could definitely happen.
Federico Ramallo (25:58) Right.
Andrew Scott (26:09) I’ve been watching it closely over the last couple of weeks since it started to surface, I think also, deepfakes and other things, and I’m like, okay, these are all very real relevant concerns, but we haven’t even figured out how to prevent regular phishing, must-less AI-enabled phishing emails. We keep falling victim to this as an industry. how do we, let’s be realistic, I think, about the threats.
Federico Ramallo (26:32) You
Andrew Scott (26:38) that are most impactful to the business and really try to get those foundations and fundamentals down before we worry about the catastrophic kind of components because yes, it could happen, but if we can’t even defend against the basics or kind of the everyday attacks, we’re certainly not going to be able to defend against a bigger kind of impact event as maybe less likely as it may be. So I think that’s for cyber, you know, kind of AI.
threats for like how threat actors and adversaries are using it. They’re using it to automate, you know, reconnaissance and monitoring and scanning of environment. They want to craft better and adaptive phishing emails or social engineering or words. They want to be able to understand and assess data or environments more quickly once they’re in. It’s everything we’re trying to do just, you know, because of businesses. But I think that’s the key where people need to really double down and say, okay.
How am I defending against these more kind of components there that of how he is actually being used?
Federico Ramallo (27:44) Right. I’ve seen some interesting developments on people exploiting using more complex AI tools to attack that now they can mimic humans better. And that makes it harder to detect. Right.
Andrew Scott (27:53) Yep.
100%. I think, you know, AI is definitely getting there. I mean, is there full end to end fully autonomous attacks all the way through the kill chain? I mean, I think that’s debatable depending on the research and reports that you’ll read. ⁓ I think the bottom line is yeah, absolutely. Right. The ability to expedite or kind of fast track, you know, kind of attacks, exploitation, know, kind of, you know, compromise their environment once you’re in. Definitely.
Federico Ramallo (28:10) Right.
Andrew Scott (28:28) I think that’s where there was an important statistic that came out that I think everyone needs to kind of really take to heart. So like whether it was Palo Alto Networks or like Boozal and Hamilton, all of them are really, everyone’s really finding, there’s been good reports come out that from the time of initial compromise, right, initial access to when data is stolen is between like 30 minutes to 70 minutes. That’s incredibly fast, right?
And so I think it’s like, look, do we almost have to assume that we are going to get compromised in some way, whether it’s credentials, vulnerability was exploited, maybe it’s a supply chain attack, phishing email, whatever, right? Someone’s going to get into our environment. And so it’s like, how do we now then hold them, like limit that blast radius and really practice response, containment, right? Like practicing as a response there.
How do we start to address that? And it doesn’t mean we can’t prevent in like hardened environments, but I think it’s also that speed that we have to be acknowledging and accept. And then that lets us drive then now what actions do we need to take and how do we plan for this? Simply is it too fast for humans? Absolutely. And that’s where I think AI is so powerful to fenders, but we can’t assume the AI enabled tools are just going to solve this for us.
we have to have the underlying basics to support the AI.
Federico Ramallo (29:57) Right, right. I thought that by this time we will be having more of a Skynet situation. mean, robots attacking robots and then kind of turning on us. And it’s more of we have fishing situations, instead of for humans here, for agents, right? Because now we’re delegating so much to them, right?
Andrew Scott (30:07) Yeah.
Exactly right. mean, I think that’s the other, you know, kind of aspect too. If we talk about, you know, threats, I mean, I was talking about really the lines of questioning and I think decision making and governance around, okay, how will we as an org use AI? How do we not necessarily demonize it and make it, you know, it’s good or bad, but like, let’s just open up the conversations about what does reasonable business aligned AI use look like? And then, okay, how do we secure it? Because
If we introduce AI agents in, it could be working with its parameters. It could be given data, but if we’re not thinking about the structure and what its purpose is, it could be operating completely within what we’ve scoped it to be or what its purpose is. It’s not malicious or doing anything intentional, unintentional, but it may be going bananas and like sharing the data out. It could be connected to other things because we haven’t really thought about system.
know, kind of network design and the way that this needs to operate. It’s at your point, right? Like AI agents and other things. I want to say like, there’s that risk that they could be compromised, but I think more so it’s like, look, are we unintentionally introducing insider risk, I guess, from a non-human identity of an agent? Because we simply haven’t thought through adequately what this function is and what the guardrails and output looks like. And how do we know when it’s going awry versus not?
Federico Ramallo (31:36) Yeah
Andrew Scott (31:48) I think that’s another big component that orgs maybe need to think through as well.
Federico Ramallo (31:53) Right,
right. mean, the organizations are delegating so much, you know, power to the agents. You know, we used to have human in the loop kind of things. And now people are saying, everything looks good. Let’s, you know, let’s optimize, right? Which kind of makes sense, right? And then now they have so much power. They have so much access to so much data that then it starts to become an issue, right? A risk.
Andrew Scott (32:20) Yeah, I mean, even like, you know, kind of Microsoft or others have been like, yeah, we’re using AI to code a majority of, you know, certain functions or components. Like it worries me because I’m like, okay, if we’re trusting it to do, you know, kind of coding code, I mean, maybe it’ll be doing it better than humans, maybe, but there’s at least that like, please have some sort of QA before you push to production. Cause like what happens if the agent’s like, awesome, I’m to push this into production and you take.
there’s an error or some issue and it takes entire environments or functions offline. Like, can you roll it back? I don’t know, hopefully, right? But like, yeah, exactly. Like, I don’t know if it’s like Skynet, but if this thing, we start trusting too much into AI and really investing it there, it’s almost like, look, we have to sort of, where is that point of no return in AI use where can we…
Federico Ramallo (33:02) You
Andrew Scott (33:18) reverse course and roll back to a certain healthy state or other things if it’s suddenly taking more action for us. Yeah, I don’t know what the answer is there. Because it’s definitely bringing benefits that can’t be denied for sure.
Federico Ramallo (33:27) Right, right, I mean…
Yeah, I’ve seen people using more agentic coding into their workflows, into their coding workflows, having agents that are now pushing PRs. And now developers are just reviewing the code rather than spend more time reading than writing code, right? Because you have smarter and smarter agents, which kind of makes sense. But then on the security side, you know, we…
We don’t know how much are these agents thinking about that, The friends first, right?
Andrew Scott (34:03) Yeah, absolutely. And even there, it’s like we’re introducing something needs to be considered that, let’s say I was doing the coding and the development engineer, right, is reviewing the code.
they understand where the AI bot is built, right? And is they, they able to identify where it does or does not work? Well, the code could be perfectly written, but maybe it’s doing certain functions that aren’t what other integrated components or business functions require. so are we just like, does the developer have that sort of QA capability, right? And knowledge of what is producing to know what good looks like. Again, from a security component too, like
Is this going to be introducing more variables or other things for us that we’re concerned about? It could be perfectly written, but it could be perfectly written to like, you know, open up entire environments or stand up whole stuff that we don’t even know about, right? You know, it makes me think about, you know, cloud design. Last thing you want to be doing is having to re-architect the cloud to make it secure after you’ve already deployed it. Cause you’re probably going to unravel a lot of stuff there, secure by design. Like let’s have that conversation ahead of time.
to make sure we know what the output’s gonna look like. And I think that’s another component of like what a good security program looks like. Engaging security, like development business lines, like, you know, IT, you know, hopefully you have good relationship with IT, but like, I think business leaders, you know, IT development, other groups that may see security as like the group that says no, right? Or tries to hold things up.
it’d probably go a lot faster if we just reached across the aisle and said, look, I’m starting this initiative. I at least want your take because it’s their responsibility that sees those responsibility to, you know, ultimately best manage risk within what resources they have and share upwards. And so if they’re always broad enough to the fact, you’re always going to be kind of on your heels and that will slow down, you know, business and development. If you kind of wait,
Right? Because then security is going to have to interject. And so I think that reaching across the aisle, like that communication is where I really see where security programs work. Definitely that governance, but I think that culture of openness, communication, collaboration, and being willing to bring security into it early because it’s an important part of doing business on the internet now. But not doing that just stalls out business initiatives.
And then everyone’s unhappy. Right. And I think that’s where I see really that culture of keeping security as part of that process. And as a key component that you’re hardening your environments to drive business forward versus waiting for an impactful event or, know, we didn’t have security, so we couldn’t get the SOC 2 or the CMMC certification, what have you. Shoot, now we can’t compete for those contracts. Like that’s a direct business impactful event. Right. But.
That’s what needs to be part of that conversation.
Federico Ramallo (37:07) Right, right. mean, thinking that I think it’s similar to quality, right? I mean, we think of quality before we start writing the code. And I start teaching my team to do that. And we save so much time and effort, right? The rework, it’s invisible. We don’t see it. And the same thing happens with security, right? If we think of security before we start writing code, right? How can we make it secure by design, right?
Andrew Scott (37:07) Yep.
Yep.
Federico Ramallo (37:33) then we can save so much effort further down the line.
Andrew Scott (37:36) Absolutely. Yep. Good to read more.
Federico Ramallo (37:39) Yeah, and at least we can make conscious decision of taking, increasing that attack surface, but it’s because we need it, right? ⁓ And not because we haven’t thought about it, right? I’m still shocked or surprised by how cloud code source code was exposed, right? Because I don’t know if you read this story, but it’s the…
Andrew Scott (37:48) Yep.
Federico Ramallo (38:01) npm package has a map true flag and that expose the whole source code, right?
Andrew Scott (38:09) Yeah,
I mean, it’s these basic small system configurations or flags or other things that unfortunately have huge ramifications, right?
Federico Ramallo (38:18) how that series of mistakes happened, right?
Andrew Scott (38:21) Yeah, mean, exactly. It’s kind of we were talking about it. I don’t know. It could have been either one. Could have been both maybe, you know, but I think that just begs the question of like how humans and AI work together in whatever function, right? There has to be that human oversight, but also human input to begin with. And then we have to not simply just blindly trust AI, whether it’s for business development purposes, whether it’s for software engineering development, or if it’s for like security, like
What is this telling us? think that human skill set and knowledge and sort of curiosity, that human element cannot be replaced yet. And I think that’s incredibly important. like AI is not replacing us, but I think it really puts an onus on deeper critical thinking, planning, understanding what AI is delivering to us. And what does this mean for us or an organization or what have you?
Federico Ramallo (39:20) Right, right. So we’re almost running out of time, so I want to ask you one last question. It’s about what advice would you give an engineer manager that it’s running a team and maybe they’ve been overwhelmed with their backlog, they haven’t thought about security as a priority, what advice would you give them?
Andrew Scott (39:27) Sure. Yeah.
yeah, I mean, it’s, it’s kind of what I already hit on, but I would, you know, if, someone hasn’t really thought about security yet, but maybe it’s starting to come up, I would go with the business and I would, I would start with the business. Like, what is it that we do? What have our, which of our, you know, technologies are crown jewels. What functions do they do in terms of what the business output or like how they contribute to things? you last thing you want to do is be.
focused in the wrong areas. But then like security, either maybe there’s a security person or security team that you should be interfacing with. like reach across the aisle, right? As I said, go grab coffee. I just want to start that relationship. Security practitioners would really appreciate that. Love that. Because they’re drowning too, right? And they want the organization to really, frankly, be open.
and talk to them, but often security is of silent on the side. It’s also something like not a lot of people may understand what goes on in the cybersecurity risk management groups. But I think it takes two to tango, as they say. I think it is also the responsibility of security staff, professionals, leaders, or those who are responsible for managing risk to
Proactively understand the business right and so that’s where I don’t think you know for that engineering leader, right? I think definitely creating that that relationship really making sure that you’ve got for your initiatives that you’ve got buy-in and commitment from Security side to work together, but I think at its core right everyone gets busy. Everyone’s doing things all day long It’s really important to like take a step back. I think What is it we do here?
as an organization and within my role, right? If I was acting as that person, right? Or our function, what is it that we are contributing to that ultimate business or mission function? And then how do I need, what dependencies do we have on other people? And I think that’s really the importance of managers and especially mid-level management of managing side to side.
Right? Where, you know, often I see security programs or others, you’ll have direction from the top. You’ll have people doing the work at the bottom, but the gap is really in the middle. Right? And so I think it’s not only, how do we understand the business kind of up, but also what are we asking down below? But like, what are the other dependencies of other groups that we work with and the importance of those, that mid-level management to really collaborate and work together and create that culture there where it’s like.
We’re not each trying to manage our own little function separately. We’re not competing with each other because it’s the ultimate business goal that’s unifying us. But that does start from the top. The C levels have to drive that down, that that is the ultimate goal. And that empowers those mid-level managers and leaders there. But I think that’s what I would say for an engineer, right? And I recognize it’s kind of a little more theoretical, but I think it starts with that. We could figure out what the security…
initiatives or tasks or functions or whatever need to be. But time and time again, if we’re not aligned with the business needs, if we’re not really speaking that common language together, it will often fail, right? Or just not be as effective. And I think that would solve so many challenges that organizations have of just that culture of openness and collaboration there centered on ultimately what does that organization does.
Federico Ramallo (43:32) Right, right. I think that on the…
the current environment we’re living where AI is automating a lot of processes. Automation is a double-edged sword, right? It helps you automate, but also it expose your security risks as well, right? And having these agents, attackers that can now automate and behave like humans increases that risk much, much higher. I think it’s much more important in today’s…
time to think about security.
Andrew Scott (44:08) 100%. You know, I saw the last thing I’ll put on is I saw Moody’s the big credit rating agency. They did some modeling of their own, right? And looking at how cyber events, you know, really impact core financial stability of businesses. And they actually updated their models to treat cyber risk as an actual
Equivalent catastrophic event. So Moody’s the credit rating agency that drives how markets are evaluated, right? How investment gets made on maybe insurers view risk is openly saying, hey, cyber risk is now at the level of like hurricanes or other things. The impact of business, of technology and security on business and managing against this is a business imperative now, right?
and the way that organizations value themselves, we’ll go seek funding, we’ll get acquired evaluations, we’ll just simply get insurance, or even, you know, of valuation numbers and credit ratings. All of that plays a role now that with how fast things are moving, cybersecurity has to be part of how businesses are planning for their future. If you’re Fortune 100, if you’re the government serving a mission, or if you’re a
20 person, small and medium sized business, it’s all sort of the same. We have to be answering these questions for ourself. But I think ignoring it is even worse.
Federico Ramallo (45:40) Amazing, very interesting insights. Andrew, thank you very much for joining us today.
Andrew Scott (45:47) Of course. Yeah. Thank you so much for having me, Federico. Appreciate the conversation.