Addressing the AI Bubble and Ethical Challenges in Cybersecurity | Shimmy Says Ep. 23
An AI bubble is emerging, raising concerns about unethical practices like CISO payola, where vendors pay CISOs. The decline of ethics in business is highlighted, stressing the need for a code of ethics for CISOs and vendors. The role of CISO councils is discussed, along with the potential for influence and ethical dilemmas. The industry is urged to take responsibility and eliminate unethical practices to safeguard the integrity of ethical CISOs.
Transcript
Hey everyone, it's Shimmy. Um, I'm doing a Special Friday, shimmy says this week. 'cause I, I did one yesterday.
I don't know if you caught it. It was about what I'm calling an AI bubble, right? And people don't want to call it a bubble.
Fine, but that was yesterday's. Let me tell you about today's, today I want to talk about what I'm calling CSO payola. I wrote about it on Security Boulevard.
I think the article ran Monday and then we discussed it on the Textron Gang, which ran today, earlier this morning. Um, it really, there's a stench in the security market and, and this has been a long simmering problem, but I think it's really risen to new heights. And I, I think part of the reason it's risen is that overall I think we're seeing a decay of our morals and ethics in business.
And it's due to a lot of reasons. But, you know, we're not gonna get into those reasons today. I want to define the problem.
What I mean by cso Paola is it, it's a range of different activities. It ranges from the far worst example. And this is not new of vendors paying CISOs or other important decision makers in organizations, flat out paying them cash or some other con former compensation for them to use the vendor's solution within the organization.
And as I said, it's not a new problem. We've seen this historically in business, but it was always treated as something that was wrong. I, I've known, I've known executives who, executives who have lost their job over it.
Theoretically, executives, especially at a public company or a fortune company, should register with the company if they have any sort of compensatory interest in a potential vendor. And they should be precluded from the decision making process. But that's a ra relatively easy case to navigate.
It's a kind of bright line. There's blurrier lines that have popped up and dimmer lines that have popped up. For instance, a lot of VCs have CSO councils where they bring in prospective portfolio companies or existing portfolio companies and they haven't pitched to, to CISOs.
And you know, the CISOs give feedback and look, the CISOs are giving their time and giving their expertise in the feedback and they should be compensated. The question becomes though, is there a quid pro quo? Is that CISO's organization then being pitched by the companies who pitched the CISOs?
And if so, are the CISOs declaring that they interacted with that company and maybe were compensated for interacting with that company and therefore precluding themselves from that decision making process? 'cause if they're not, I, I'm not saying it's illegal, but I think it crosses a, a law, an ethical line, and it's just a way of buying influence. Now, there are plenty of VCs who run these CISOs councils and they're all above board.
The CISOs, as a matter of fact, tell vendors they're precluded from selling to their, to the CISOs organization as a result of it. And that I applaud them for it. But there are plenty of the CISO councils that don't run like that, and the CISOs are making money.
And then these people come into the CISOs organization as a friend of the ciso. These vendors do. There's other examples of this though, again, variations.
The CISOs themselves have cut out the middlemen. They form their own CISO clubs. And if a vendor wants to pitch a ciso, well they could come down to the club and, you know, there might be a 25,000, $50,000 fee and I'm gonna have 10 or 12 of my CISO friends here and you could tell us about your, about your solution for the 25 or 50 grand.
And you know what a vendor's out happy to do that 'cause they spend that much money on marketing. If they're gonna have 12 CISOs ears for 25 or 50 grand, it might be worth it to them. But the issue then becomes what, what else is involved in it?
What's the quid pro quo there? What's, what's, what goes into that money? Do these CISOs now take these vendors pitches back to their own organizations?
And are they involved in buying decisions from the vendors who compensated the CISO club? Again, if that's the case, I think that's an ethical line crossed we shouldn't have that. And this isn't, as I said earlier, it's not just ciso, sometimes it's people one, two levels down below the ciso.
Sometimes it's the CIO. It could be, you know, anyone in this food chain who has decision making process. Um, we need, we need some sort of code of ethics.
And, and it's not just on that side of the house. It's not just on the buyer side of the house. The vendors themselves, they're under so much pressure to produce revenue.
Every vendor we speak to always says, who? Well, who's your target audience? Oh, we want to talk to CISOs and, you know, security buying decision makers, that that's who they spend literally hundreds of thousands, millions of dollars trying to reach.
So if they have an opportunity to reach them, and maybe it does cross a little bit of a line, what stops them from wanting to do that? What stops them from doing that? The vendors, you know, if we're gonna have some sort of code of ethics here for CISOs and, and decision makers, we need a code of ethics for vendors as well.
You can't buy, I mean, and this is a game that's been going on, you know, since the age, the dawn of time. But buying influence like that, where does it cross the line? Where does it become bribery?
Where does it become wrong? As an organiza, as an industry? We've gotta clean up our own act here.
We've gotta do something about this. There are too many good CISOs out there, ethical CISOs, morally upstanding people who are gonna be painted with this stinking brush. And so I'm asking the industry, what are we going to do to clean this up?
What will, there's enough CISO organizations out here. What is your organization gonna do? Vendors, what are you doing to show that, hey, we, we play by a set of rules where it's not, can I, can I grease the skids here and give you some sort of stock options?
Or, you know, the advisory council. That's another way this game is played. We have got to, we've, we've got to clean it up ourselves, otherwise someone's gonna clean it up for us.
That's shimmy. I hope you've enjoyed this. If this rings a bell to you, reach out to me on LinkedIn, speak up about it.
Let's do something about it. Says Shimmy says.





