Bridging AI and Asset Security: Curtis Simpson on Managing Exposure with Armis
Curtis Simpson, CSO at Armis, discusses the importance of understanding connected assets and using the Armis exposure management platform to prioritize security. Curtis addresses the challenges CISOs face with AI, advocating for its adoption while managing risks and shadow IT. He emphasizes the need for effective communication with executives to align security with business objectives.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. I am really happy to have our next guest on.
His name is Curtis Simpson. Curtis Simpson. Curtis is the CSO Chief Information Security Officer over at amis.
Curtis, welcome to Tech Drunk tv. How are you? I am doing great and thanks for having me.
It's my pleasure. So, look, I, you put these up in the background, I guess we're gonna start with that. Talk to us about these pictures back there.
Yeah. I, I love graffiti art, so it's, uh, a number of graffiti artists that I like and enjoy. And I actually got these through a service called Display where art artists can actually sell their art and have them printed on metal posters.
So yeah, it goes back to a love that I have in, it just supports the artist community overall. Very cool. Alright, so we already know a little bit about you.
There You go. Let's hear some work. How, what kind of journey did you go, were you on to wind up here at ciso?
At, uh, amis? Yeah. I've been in, uh, security and technology for over 25 years.
Most of my time was spent in the enterprise world. I actually grew up through the ranks starting in basic IT roles. I was a hacker as a kid, so I always had a passion for security when it became a reality in terms of being able to do that in the enterprise world.
I did, again, grew up through the ranks, eventually became global CISO of, uh, fortune 54 operation where I was the first, um, fortune 100 customer of armes. Very much embraced really the technology in the early days. So yeah, moved from customer CISO to, um, the CISO of the company and have very much enjoyed that pivot from Fortune 100 to the actual tech base.
Good for you. So this is your first foray into the, into the vendor side of things? Very much so.
I'm sure it's, it's been And how, how long have you been at it? Uh, six years now. Fantastic, man.
That's great. Yeah. Um, you know, it, it's, I always say it's a great thing when you have a former customer come on board because, you know, they, they took the job, not just, they didn't take it for the money, they took it because they were really into whatever it is you're doing in this case with armor security.
So it, it's a testament to them that you, you know, made that leap, crossed that chasm, if you will, and, and have stayed on six years too. That's, you know, that there's something to be said there as well. Good for you.
Yeah. The vendor space, six years is more like 20 years. Yeah.
Sounded it like dog years. Exactly. I've been there, done that was most of my life.
Yeah. Um, Curtis, I think most of our audiences at least heard of amis. You can't go to blackout without seeing all kinds of amis stuff there and everything, right.
The banners and ads and so forth. Um, but there, there might be some folks out here who've never heard of amis or not familiar with amis, some folks who slightly familiar with arm. If you had to, you know, give us sort of the condensed pitch of, you know, who's amis, what they're about, what problems they solve, that kind of thing.
Yeah, for sure. Amis is the exposure management platform and what does that fundamentally mean? Well, we truly help you understand all of the connected assets within your environment.
Not just what they are, but why they matter, how they actually run your business, how they're exposing your business, and fundamentally how you should be prioritizing your efforts based on where you're most likely to actually be attacked, where your business is most likely to be materially impacted. And then we facilitate the ability to remediate and mitigate at scale, maximizing your investment and enabling your ability to actually explain to the business how you have reduced risk, how you are reducing risk to the business, and where you have material gaps that you need to close through additional investments, et cetera. Love it.
Excellent. com, correct? Yep.
And for someone out there wanting to get more information or engaged someone who maybe already knows ARM and says, yeah, I've been meaning to talk to them, what, what's their best way to contact you? Yeah, very much. Hit the website and you'll, you'll be greeted immediately with how to get ahold of us and engage with us further.
Excellent. Um, and I'm just trying to read the small print here. com.
Yep. Okay. You're correct, Curtis.
Thanks for all that. Let's now pivot over to our topic of discussion today. You know, I did a webinar this morning and it 50 minutes past the hour I had to make an announcement and said, this is a record.
This is the longest we've ever gone on an hour long webinar without mentioning AI in two years, three years. I mean, you, you, you can't take three steps without tripping over it, especially in the tech world. Yeah, right.
We've all got a little AI bunkers and maybe for good reason, for good reason, but ai, like other trends that have come before it, have put CISOs kind of between a rock and a hard place. You don't wanna be the people who say, no, you don't wanna be the anchor weighing down the progress of the organization in, in probably the biggest disruptive technology we've seen in a generation. Mm-hmm.
Or more. But when stuff hits the fan, it's your butt on the line. Right.
And, and that a hundred percent, and you know, and unfortunately that is the, the plight of the ciso. So what's, what's a good CISO to do? Yeah, it is, it's uh, it's at the intersection of exactly what you've just described.
So the reality, if I look back to that landscape I used to be in with within that Fortune 100 landscape, what has generally happened in most of these environments is there's a set of AI technologies that the IT organization has embraced in. They're rolling out to the organization, but then there's all the shadow IT within the organization in terms of the tooling that people actually want to use. They go out and adopt on their own, et cetera.
I think one of the most important things for CISOs to really explain to the business is this one is one of those situations where, first of all, you get it. You understand that you have to embrace ai, you have to be able to show where you're already embracing AI together in terms of it has made selections of technologies. You've partnered with them to really secure those technologies so that people can do what they need to while also making sure that they can't see more than they should do, more than they should, et cetera.
But one of the things that we need to quickly explain is there is this shadow IT element that has rapidly been moving faster than we have to allow people to, or that are, is ultimately allowing our data to be shared in ways that we don't want. That's potentially exposing our business to things that we're not okay with. But what we need to be very clear on is that what we're rapidly doing, partnering with it, is understanding why people have went in that direction.
We're embracing the needs that they have through the tooling we've either already selected or will be selecting so we can get our arms around this so that we're not pushing back. 'cause to your point, this is one of those things where the risk is likely going to get ahead of us and we're gonna have to pull it back. It's just the nature of the beast.
What we need to explain to our business is we get where they are, we get what they're doing, we get why they're doing it, we're learning from what they've already done. We're building a more secure ecosystem that actually delivers on their needs. And what's gonna have to come downstream is as we're doing that, we are going to have to start preventing people from using the things that put us into a place of problematic situations where we're overexposing ourselves.
But again, it's a matter of walking people there and explaining that we understand we're enabling the business, but also managing risk as quickly as we possibly can in a very structured but reasonable manner. Very fair academic view of it. I firmly believe in pragmatism in the security space.
If you're not a pragmatic security leader, you're gonna have to become one Or get outta the kitchen. Exactly. Exactly.
That's kind of where we are now. But here's the good news. 'cause I'm an optimistic, pragmatic, pragmatic person.
Here's the good news. AI can be our friend in some ways. Oh, 1000 AI can empower us to have better security, to be more secure, to have better controls, more visibility, go faster, do more.
Right? And those CISOs who look at AI as just sort of a problem that I gotta box in are missing perhaps, you know, one of the biggest benefits they've ever seen in their careers, which is harnessing AI to be more, do more. Oh, Without question and I couldn't agree more.
It's, it is, it's the reality that yes, the business needs it and they're going to consume it and they're going to embrace it and evolve with it. But security needs to as well from so many different perspectives. Like one of the things I've said for years is we've constantly been obsessed with this general staffing problem we have in security.
Yeah. We're never gonna have as much staff as we want to have. It's the reality, it's the nature of the beast.
We've long since talked about automation, but it's been a challenge to embrace. It's not anymore. The reality is, is you can actually embrace and adopt automation at a scale that allows your people to actually do more with less, have more fun doing the things, uh, in terms of building out processes and capabilities to do the things they don't want to do anyways, and actually be more effective, do it more safely, build more enterprise grade capabilities.
This is our opportunity to actually build the programs we've been trying to build for years, including, but not limited to stitching all of our solutions together in a more cohesive manner than we've ever been able to before to the value of our overall programs, and again, to the benefit of our teams that actually have to do this work every single day. Absolutely. You know, getting to the, getting to the messaging part of it, I think one of the things that I've seen personally, and it, and it transcends security, it goes through all it is leadership, not encouraging the use of AI by the troops, if you will.
Now, I'll tell you something like other, you know, like other trends and that we've seen come through the guys down here, they're using it if they think it helps them, if they, you know, oh, I've seen it with open source, I've seen it with wireless access. I, I've seen it with so many shadow it, the whole shadow IT thing right down here. People are gonna use what they want to use, but if the messaging from above is, Hey, we want you to experiment with this.
We think there is great things you'll be able to do. There are some new tools that are coming out there. The only thing we ask is no one's gonna slap your wrist for experimenting, for, for seeking more knowledge, for looking for new solutions.
But we gotta, we've gotta be able to organize this and, and, you know, make sure that we know what's out there, what's in here, what's being brought in. You know, we've gotta be able to manage it. No one's gonna say, you know, don't use ai, but we gotta, you know, it has to be organized.
It can't be chaos. And so avoiding shadow AI security, I think is part of the CISO's message as well. Yeah, a hundred percent.
Is it, it really is about creating that safe sandbox fundamentally, yeah. That people can play in safely. And that's the message we need to be bringing is that we're helping to build the safe sandbox because we, we firmly and, and rec, we understand and recognize the fact that this stuff's changing every single day.
People need to learn how to be able to use it. They have to be able to play, but they need to be able to do so safely. So it is about purposely creating and messaging the safe sandbox.
And to your point, we've done it. So you can do all of those things, but do it safely and really help people understand that when you use your own credit card and you go pay for a service that we're not in control of, you're not necessarily safe. You're putting yourself at risk, you're putting the business at risk, you're exposing data.
We understand why you're doing it, but this is why we've built this sandbox and what we need to be really good at this. Some of the best technology leaders for a long time now have really embraced feedback. There have to be effective feedback loops in terms of what do you feel you don't have?
What do you feel you're unable to play with? What do you feel you're unable to deliver? Because the thing that never works from the technology perspective is picking a tool and just shoving it down people's throats because we picked it.
That's what we funded, that's what we have selected. And then almost closing our ears to the feedback of the troops. We have to continue to listen.
This is gonna be a continued evolution. Our product stack will change, the tooling will change, but it has to change in a way that people feel heard. They feel like they can evolve with this evolution as opposed to feeling like we're constraining them just for safety.
I agree. I, I agree a hundred percent there. Um, we're running low on time.
Curtis, let's tie a bow on this. CISO's out here watching this. Give them three things, five things they could do around messaging and not beyond messaging, even a action to kind of embrace this age of ai.
Yeah, to your point, the first thing is be confident in the fact that well actually be brief. First of all, as we always need to remind ourselves when you're talking to execs, you're talking to boards, you need to quickly summarize that you understand what the business is trying to achieve, which also means you need to figure that out. One of the most important things is the CISOs to actually have the relationships with the executives, the peers, et cetera, to understand the problems they're actually trying to solve.
You need to be able to relate then back to the larger group that you understand those problems. You are embracing the partnership with the larger technology group to solve those problems through ai. You also need to be able to express that You either have visibility or will have visibility capabilities to understand where perhaps the business is overexposing themselves, um, whether that's through shadow IT or through the, the tooling that has been enabled so that you can reign in the risk without impacting the experience.
And then you've gotta report how this is progressing. So in terms of what have you already enabled, what are some of the risks that you see in terms of where we're potentially putting ourselves at risk as a business? What are you doing to, to impact that?
I stress all the time that as you talk to the business at the executive and the board level, it's critical that you speak to them in terms of what is most important to the business, both in terms of operations and strategy, the risk that is specifically affecting operations, strategy, brands, some of those key elements of business, what you've already done to reduce it, what you're doing next to reduce it, and where you need the partnerships within that larger audience to continue to reduce it. We always need to interact with the business that way. It's not about technical metrics, it's not about any of that stuff.
And anyone who struggles to do this, one of the things that I always like to stress is learn from others that you see already do it well. Even if they're in functions like finance, hr, et cetera, learn from them. Take their materials, steal the way they message it.
Like practice what you already see as successful. Don't try to recreate a wheel you don't necessarily understand. I love it.
Great stuff man. Curtis, thank you very much for coming on. I appreciate it.
It's always good to get an update from amis as well. Don't be a stranger here. Come on back man.
Will do. Thanks for having me. All righty.
Curtis Simpson, CSO amis on how CSOs can better message and work. Make AI your friend, not your enemy. We'll be back here with more on text Drug tv.
We'll be back.