AI, Cybersecurity & the Job Market Shake-Up | TSG Ep. 957
Alan Shimel, Mike Vizard, Jon Swartz, and Fred Wilmot analyze how AI and automation are disrupting the workforce and redefining global cybersecurity priorities. The panel examines the growing threat of job displacement, emphasizing the urgent need for retraining initiatives and strategic workforce development.
The conversation also highlights the importance of industry-led cybersecurity responsibility, arguing that the private sector—not government regulation—should take the lead in setting and enforcing higher standards. The gang wraps up with a lighter discussion about Halloween safety, underscoring the balance between humor, humanity, and innovation in the age of AI.
Transcript
Good day, everyone. I am the Grand Puba of ai. Who needs ai?
When you have me, you don't believe me. Watch Jensen Wong. Who would you like your daughter to date?
You're watching Textron Dan. Hey, everyone. Happy Halloween.
Wow, it's Halloween. It's Friday. What a good time to dress up.
We asked our, uh, gang members to police come in costume. Some of them didn't come, but those who did definitely came in costume. Let me introduce you to our gang members before we jump into things.
First of all, he usually goes last. We're gonna let him go first today, dressed as the Vard. What else can he be dressed as?
Sort of the emissary, Mike Ard. Mike, good to see you. Good to see you guys as well.
And this is a little nod to the Bleak Anime, where there's some characters in there. Uh, a series about Soul Reapers and some of 'em are called ards. Absolutely made your day.
Moving on to Silicon Valley, we have the Ghost of AI Future. Oh, Ebenezer. Yes, Howard.
Good friend. John Schwartz. John, good to see you.
Good to see you. I can't see you very well, but good to see you nonetheless, through the mask. Absolutely.
And then we have a, an immigrant, oh, don't tell Ice. Uh, from the Mandel, from the planet Mandalorian, it's Baba, Fred, Fred, Wilmot, Fred, Fred, if any Mass man, come over there. Don't let him in.
Fred. He's not talking. It's gonna be making for he's in character show.
Anyway, hey, we hope you're gonna enjoy your, uh, Halloween and then we hope you are gonna have some fun like we hope to have here. My my bizarre thing is all off, but, you know, and, and in honor of Halloween, we, we have some nice Halloween theme segments. We, well, the first segment anyway, we're gonna hit, I have two articles I put up for Halloween.
One is on Textron It, and it's the, uh, Halloween special, the five Scariest Things in it today. And then I wrote another article about is AI the Ultimate Trick or Treat? ai.
I'll, I can encourage you to go read both of those, but let's jump into it here. Mike, if you don't mind, I'm going to kick this one off with my five scariest things in it. Look, I, I think the scariest thing facing us all is, are you gonna have a job or is AI taking it away?
I just saw another survey out of the UK right before I came on the show today. They estimate 70% of the jobs in the EU will be eliminated due to AI and automation by 20, 30, 70%, seven out of every 10 jobs. Uh, do I believe it?
I don't know. It doesn't also say, will it create more jobs than it eliminates? Again, I don't know.
But that's a scary damn number. So that was my number one scariest thing. I'm gonna, I'm not gonna do all five.
You can go to the article. My second scariest thing though is are we gutting our cybersecurity, uh, infrastructure that the gover, the federal government has built up over these last many years talking about csa, talking about CVEs, the public private partnership, critical infrastructure. Heck, even just the will to legislate some cybersecurity governance and compliance.
Because make no mistake, there are bad guys of bad nations out there who are looking, looking to exploit us. And it's, if we don't keep up our guard, it's only a matter of time until we have a catastrophe on our hands. I'm not saying it's gonna be the end of the world, but it could be quite catastrophic.
Um, Mike, John, Fred, I don't want to take this whole thing up though. What, what's on your list of the scariest things in it and tech today, Rob? Oh, lemme do this.
I'm gonna, I can't see very well. Yeah, You can come outta costume, John. It's okay.
Yeah, Yeah. Come at I'll, I'll go back in character later. Um, I think you nailed it with theory number one and the implication of automation on jobs.
I think you said something in the story where you mentioned ai, if AI does for it, what automation did for manufacturing. We're looking at this multi-year disruption, uh, of talent and livelihoods. And I think that's already starting to happen.
It's well within motion. I'd look at Amazon and the 14,000 layoffs they just announced, and they might go up to 30,000. And I, I look at something that their Vice President of people experience.
Yes. That is her title. She said, we're convicted that we need to be organized more leanly with fewer layers and more ownership to move as quickly as possible for our customers and business.
So basically what they want to do, and I think it's gonna go beyond, far beyond them and into government and into any, any type of organization. They're looking to eliminate middle management layers. They're gonna get rid of them altogether.
Um, a friend of mine who's a consultant has been talking about this for a couple of years. He calls it this quiet erosion. Now, it's not so quiet.
You know, AI is a, I want, in a sense, kind of a convenient excuse to accelerate what already had been in motion. And, um, it is a factor. I mean, it is a factor, but it, um, Jack Gold also who I talked to, these, these cuts were basically about eliminating layers of management bureaucracy and flattening the organization.
You know, the boot, uh, productivity and agility is what these companies are obsessed about. And I think once a company like Amazon starts something like this, it opens the floodgates, I think back to the pandemic and how X took that step and started doing massive layoffs after all the buildup of, of, of, uh, of employees they had. I think the same thing's gonna happen post Amazon, and it's just gonna accelerate.
And I don't mean to be a grim, grim reaper of sorts, but I really do think AI just is playing into something that was already gonna happen. I, I don't, I'll Do, I'll I'll flip that a little bit though. I think that, oh, you know, this thing is a double-edged sword.
And I think all those folks who get laid off are gonna go find other jobs and other businesses that are gonna compete with the companies that laid them off, because the barrier to entry for being in those businesses is gonna drop. And what it takes to launch a website and kind of figure out how to be an e-commerce company isn't gonna be as hard as it was 10 or 15 years ago. And I get that there's branding issues and people have habits and whatnot, but I might argue that, you know, all these companies that think that they're gonna use AI to flatten themselves, they're also gonna find themselves competing with a host to start.
Yeah. Yeah. They're gonna lose a lot of talent.
That talent's gonna come back and bite them in some form. But I think for now, the next couple of years, the job market is brutal right now. People are clinging onto their jobs, um, whether they're happy them or not.
I think this just in Silicon Valley, at least the, the prospects of looking for a job have never been harder. I have people who've been looking for more than a year, and they're not even getting job interviews. So I'm afraid that might be part of the alarm now here.
Yeah. I just talked to, uh, um, guy who used to work for me, um, a couple companies ago, uh, in two hours, 3,700 job applications for a job that opened up and, uh, you know, of which you need to have some skillset for not, uh, you know, sort of like the standard program manager role. And so it's interesting to think about what implications that's going to continue to have.
I agree. I think, Mike, I like your take, but I think the interesting part is if a rising tide raises all boats, you defray any of the moats that make something special proprietary, and you get to ubiquity at some point in time. And I think the concern is for the next year, maybe it's easy to start a company.
It's easy to build a website, it's easy to do whatever, and then it won't be necessary for you to do that either. So the big question is, is what does an economy look like when this massive blood of super talented people is no longer operating under the behest of, you know, the normal flags? That is a very, very interesting proposition for the economy and certainly for, you know, the current state of affairs and local politics.
It's a challenge. It's a challenge. Look how many of us bought into, when, when manufacturing was being offshore and, and the US stopped being sort of a manufacturing powerhouse converted to a service economy.
What was the word we heard? We're gonna re we're gonna retrain, we're gonna re-skill all these factory workers as if somehow you were gonna take a guy working on a steel in a steel smelter for 30 years, or mining coal and turn him into a paralegal or, or something like this, right? Because that's what he wants to do.
And you know what? That retraining, taking workers and upskilling them to different roles, it didn't work so good in manufacturing. And I'm not so sure it's gonna work so good here, either, really.
I think we've got a real issue of yes, AI will create more jobs and hopefully it's gonna create a lot more jobs than it takes away. But those jobs that are taken away, and those workers may become the perpetually unemployable. And they, and it's not that they don't have skills, they just don't have skills for tomorrow's world, right?
And I, what I AmGrad more than the AI itself is the lack of leadership about these issues, right? They, we can see them coming. There's no government per se policy for retraining anybody or doing anything along this line.
It's a very laissez-faire strategy. And you know, earlier this week we talked about this notion of the industrial tech complex, and this is how that's gonna play out. 'cause all those people are out to, you know, break things and they don't really care what the consequences there are of, and there's nobody sitting on the back end of this thing going, what are the implications for the society?
Right? That's the point. I think that was, I think El you pointed that out.
I mean, these companies aren't really thinking about the deeper impact. And, um, it's, it's kind of like this reckless land rush to try to cash in as fast as possible. We'll get, we'll, we'll, we'll, we'll, we'll adjust and, and point to, and, and try to deal with.
But John, the companies garbage later, John, do the companies have a duty to think about that? That's not their job. Right?
The companies have a duty to their shareholders to maximize their return on investment and, and maximize profits. So you can't expect, and and look, I don't want to get into Citizens United and all this crap, but you can expect a for-profit company to be, uh, some sort of, you know, Plato outta Plato, some, uh, you know, benefactor of the poor and, and, you know, grow a conscious conscience, quite frankly. Oh, It will.
I mean, That's the role of government. I, and that's the role of government. Well, that's the problem you have now.
I, I disagree. I, I, I agree with you to a point. But when you cross that line is when you start building pacs to convince politicians to ignore these issues, because you find it inconvenient for your profit margins is where you went over the line.
Don't, don't, don't blame the player. Blame the game. Don't blame the player.
Blame the game. They, we should outlaw pacs. We should roll back.
Citizens United, take the money out of, of, of our politics and out of our government and the special interest. And governments, therefore the people, they're the ones who have the, the social contract and the responsibility to say, how are we gonna make sure these people eat? How are they gonna be gainfully employed?
How are they going to contribute to a successful society? Those are the kinds of questions that governments are supposed to deal with. Right?
Or are we all destined to live in the Nvidia company town working at the AI mines and factories? 'cause that's an, that's a, that's a, that's the, you know, that's Potterville baby right there. Yeah.
Well, you know, I mean, like, in, in concept, it's, it's all, it's all correct. But I think when we think about the state of the government and it's, it's integration into the tech industry and its investment into it, it's, it's just gonna accelerate all the bad things. That would be fear.
Well, may maybe it's time for a change. I think there's a couple of important things that, uh, states like Montana have recognized. Uh, corporations are not people.
They don't have the same rights as people. And that prevents an awful lot of things from, from going down this path. It's a big swing to take.
They don't have, you know, 80,000 workers from, uh, Amazon in the neighborhood. So they don't have the challenge or the luxury of what that means. But when we think about the implications, we're gonna talk about NNHI like non-human identities later.
But you know, the, the, the purpose behind the behavior of some of these very large corporations, I mean, you can't expect 'em to have a moral compass or, you know, these things. That's, that's not what's part of the capital market and free trade in the grand scheme of things. But that is shi mean to your point.
That is why you have regulations and regulators and policy and things like this, is to keep honest people honest. And I think there's a, there's some overshadowing there for sure, with the opportunities available that, that, uh, money and, and power can offer. Yep.
Guys, I got one more point on my five scariest things I want to bring up, and then we'll hop to the next, what happens if the clock strikes midnight and this AI chariot turns back into a pumpkin and Jensen Wong's leather coat becomes some tattered old felt? Well, let me give you another scenario. What if there's a another way to drive AI that's more deterministic, doesn't require GPUs and consumes maybe a third of the energy?
Well, don't be surprised when stuff like that starts to happen. It, it might, but if, if AI doesn't, all these bets were making on ai, if they don't come true, if we, if it doesn't, if it's not what, you know, all of, we, we've pinned so much hopes. We have a whole economy built around it.
It represents half of the GDP of the us. It's a $5 trillion market cap for Nvidia. All of these are made on bets that this thing is really going to rock and roll.
What happens if it don't rock and roll so good Again? You, and you're starting to see more people like Ray Dalio, people who really know what they're doing and really know what they're talking about saying it's inevitable. The big bust, and I'm, I'm not saying it's gonna have an overnight a Comes us into a depression.
Yep. Maybe, you know, we've talked about this. Maybe we are in a depression on, on a certain level, right?
'cause there's two economies. There's an AI and two Economies. Yeah.
That benefits a, Well, we, if we had any economic, you know, data, we might be able to know. But, you know, now we're blaming the shutdown. I don't, you know, we, we did this in Florida during COVID.
They just stopped publishing how many people were dead and dying and in hospitals because they didn't want you to know, and they didn't want to upset the public. 'cause after all, Florida stands for free is in freedom. I, I, I could see, you know, unfortunately, this seems to be the case with unemployment data and economic data coming out of our government again.
And, and there's a problem. So look, we gotta end this one and jump to the next, but happy Halloween, everyone. You're watching text junk.
You've earned It. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions. Your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back in. Well, maybe we're gonna go from bad to worse. We'll see.
But the president's in China this week trying to strike a few trade deals and looks like some progress was made, at least on the, uh, rare earth metals. But there's also been moves by the FCC to tighten restrictions on using, uh, Chinese equipment within our networks because, well, they've been hacking into that. And there's also a report from Associated Press was saying that, well, you know, for all the talk about China, we've been kind of ignoring their usage of cloud services and all kinds of indirect channels to acquire GPUs and everything that goes with that.
But, um, let me just jump right into this with Fred. Um, what's your take here? I mean, it seems like, you know, we have an economic conversation on the one hand and a cybersecurity conversation on the other, and they should be related, but they are not.
Uh, it's a great question. I think the FCC is being called to action after a long period of time, uh, uh, and also with circumventing the policies and requirements that maybe the SEC has put out. There's a cover list of companies, and some of these will come as no surprise.
You know, we've talked about things like the typhoons, uh, level, um, a PT, uh, adversaries and, and, and actors over a long period of time. But we've also known that in the backbone of US Telecom, we've had issues with Huawei technologies or ZTE, or we remember a little while back, uh, you know, there were super micro concerns about extra chips or processors on motherboards that were used for other types of equipment like, uh, signal channels for, you know, back hauling information to, to the China state. And so, you know, we have a, a long list of what we'll call covered entities is what the FCC is talking about.
And, and I would say this is a great opportunity for us. We've known this a problem for a long time, and we're addressing it. And yes, it is political for sure, but is certainly financial as well.
The challenge is presents, right, in addition to these companies that are, you know, uh, I would say prolific around the, around the globe, is it introduces some challenges for us in sourcing the same as what we're doing with an America first approach is, you know, what does it mean for us to produce, you know, 5G equipment here in the US and which con which companies can and can produce that information? So while the ongoing things around the FCC tightening, uh, sort of its grip on the way to think about, uh, moderate policy police, uh, a lot of the companies that are driven by this behavior, we also have some of the, the US companies doing the exact opposite, right? To your point.
And that is financially driven. So where historically we've said, um, you know, there are a set of policies and rules that we play by, you know, what we know in, in 2024, right? China bought a, an immense amount of gear to help manufacture chips, right?
Maybe, uh, this has something to do with Taiwan. Maybe it has something to do with the fact that it's a, a generous opportunity to, you know, build in an environment they may no longer be able to operate in the future. But when we think about this, this is exactly why some of the deal making around, you know, NVIDIA and, and a MD and government involvement, uh, takes its shape.
And I think there, there's some, you know, rightful outcry, certainly by folks that look at, you know, how and why are we empowering, uh, a nation that does not care about civil liberties? Um, and also, you know, institutes a police state as something that we should be operating on. And I, you know, I, you come back to the point we made earlier, like, where does the moral compass need to be in order for us to continue to build an organization or a, uh, you know, an industry that allows us to operate the way that we believe we should?
Uh, and I think that's, that's a very interesting set of, of conditions for the conversation between, uh, Xi and Trump. So, uh, love to hear you guys' thoughts. I don't see this on the agenda over there.
I see everything else from Fentanyl to immigration to, um, GPUs, but I'm not quite seeing this whole cybersecurity thing at the top of that list. And yet, you know, there's an argument that says, you know, if you take over equipment in somebody else's country, that would be known as an act of war. But, uh, the question then is, you know, are you able to say that, oh, well, some other rogue entity did that, that I knew nothing about?
Well, it's kind of like saying, I hired a bunch of privateers to go attack your country, but I, oh, I didn't know what they were gonna do. Sorry. I mean, You know, there's a different set of rules that apply to digital kinda actions than, than physical or analog, if you will.
So, you know, I, I don't know if it's quite an act of war, it's just the tit for tat of the, of the nation state espionage and nation state Cold War kind of tactics. But, but here's the thing. At the end of the day, guys, I'm a globalist and I'm a free trade person in the mold of Ronald Reagan, who's not one of my idols, in all honesty.
But you win these things by out competing, right? You gotta make sure you got a level playing field. If these Chinese telecom companies are dumping stuff below cost, they absolutely need to be banned.
And we need to enforce it. If these Chinese companies are building equipment on slave and child labor, we absolutely need to ban them, and we need to be serious about it. But I am not for protecting US industry because the Chinese or anyone else's products may be better and cheaper than ours.
That's, that's on us. We gotta do something about that, right? And we, and we need, right?
We, we can't have the government erecting artificial barriers to competitive products, even if they're strategic to us, because it doesn't make our industries any better. It doesn't make our products better. It just, it builds up a wall.
And, and, and then at some point you gotta compete in the world marketplace, right? So that, that's the point on that. My second point though is, you know, us selling the Chinese tools to, to increase their surveillance state, there some may say, is akin to Mark saying, you know, the capitalist will sell you their own rope to hang themselves with.
Right? At some point, the people in China are gonna say, enough of the surveillance, yeah, we traded prosperity, we traded getting outta poverty, we traded not being hungry for living in a surveillance state and centralized economy. But the more taste they get a freedom, the more taste they get of bourgeoisie consumerism, the more taste they get of what life in the rest of, in the West is like, the more likelihood that you'll have another tianmen square that you'll have an not a violent, maybe uprising, but much like how the iron curtain just crumbled one day, so too, will the Chinese Communist Party mm-hmm.
Because people gravitate to that. So does putting back doors into gear that is sold to the US and into our networks constitute something that rises to something we should ban? If, if you prove that that's done.
Yes. Yes, yes. I mean, look, I I, I'll be honest, I've said this before when I was at still secure and we were selling a lot to the federal, you know, to the DOD space, you know, the word in the DOD was that the mosad had back doors in checkpoint, and so they didn't buy a lot of checkpoint gear good for Cisco and back in those days, right?
Or Juniper net screen. Those were the big firewalls. Um, if that's the case, absolutely they have to be banned.
What I'd also make, you know, what's good for the goose is good for the gander. If we're selling gear into China for surveillance in China, and there are back doors there that the NSA or whoever can use, don't be surprised if we get bent, Right? But on the other side of this coin too, coin, what you do see is that when this happens, the companies in the US become less competitive, right?
They charge more for what they have, because they're kind of like, well, we got a lock on this market. Yeah. And they don't have the, to be more efficient.
And some of the companies that the Chinese compete against or well known for charging some of the highest prices in this industry. I mean, this is what Ronald Reagan, again, I, I'm not a Reagan fan, but if you listen to what he said about tariffs, go, go watch the commercial from Canada, right? Listen to what he said about tariffs.
That's exactly what it creates. It, it creates a, a, a protected industry that can quickly become non-competitive. I would say the, I would say the United States government has a duty to prevent, uh, surveilling of American citizens by folks outside the country.
Mm-hmm. And if we think about that as a guiding mission and purpose, whether it's, uh, CISA or it's any of the other programs used to do such thing, then for purposes of that specifically, it's a great opportunity for us to be able to push back and say, no, wouldn't it be nice, right? If we could say, we could trust the trading partner to not ship equipment that was compromised with back doors to us.
And so that, that in essence is also a market counterbalance. So if you can't ship, uh, unflawed software, this is gonna sound funny to say, if you can't ship unflawed software or uh, uh, unflawed, uh, hardware, then maybe you shouldn't be shipping it. So we have our own issues with this, right?
Whether it's, uh, our SaaS providers or it's, uh, manufacturers, or it's whatever the case may be. But we should maybe think about instead of like the capital market, we should maybe think about a higher standard of what it is that we build the ship and sell the people. Maybe we just need to move all the manufacturing of Switzerland.
What do you say, neutral country? They're not so neutral, they just take money from anyone. Yeah, that's true.
You know, there's a word for that blue. Um, anyway, if that's it, on this B block, let's move over to C block. We'll take a quick break here on the gang, and we're gonna come back and talk about the, sorry, state of SaaS security, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back in continuing our little security theme, but there was an open letter put forward by a company called Obsidian, and they make software that helps secure SaaS applications. So they definitely have a dog in this particular race, but they put this out in conjunction with the Cloud Security Alliance folks who are a little more neutral. And what they're pointing out is that a lot of these SaaS applications that we became very dependent upon, especially post COVID, um, the security is, shall we say, wanting.
And the joke nowadays is nobody actually breaks into anything. They just log in, they steal your credentials, and they kind of just sit there and steal your data. And these things arguably have become giant honeypots that attract cybersecurity attacks.
And we've seen a number of them get, uh, hacked and entire segments of an industry get paralyzed as a result. But John, I mean, a lot of these companies are in the valley. You know, is this something that anybody in the valley's gonna pay attention to?
Or is this just gonna be, you know, some noise in the system? Um, you know, this kind of hearkens back to the last segment. You know, unless press, unless push comes to, to shove, unless you're confronted and you're forced or obligated to do something, you're probably not going to.
So they're, they're gonna wait and see how this all bears out. But I do think there's an increasing sense of, uh, urgency or heightened threats or fear, not just from the bad actors, but the, the prospected AI agents and security estate brain. So I guess there is this push, and I, and I think the story was done in, uh, security Boulevard, but there's this push by customers and SaaS companies to ensure the SFCF measures are put in place.
So I, I'm sure there is gonna be a movement, but again, from the valley's point of view, and unless they are forced to, uh, address something, they are going to think of it as noise in the backgrounds. Um, and that's just the way things are. Given the pace and the sense of urgency, they're gonna wait for these types of things to come up later.
For now, they're just full steam ahead. Let's, let's just push AI as hard as we possibly can. All right, Fred, we have these things called AI agents that are being added to these SaaS apps.
So the number of users is gonna go up exponentially. And each one of those agents is a target. They're essentially a new type of end user that can be hacked into by the cyber criminals, or in this case, just stealing their credentials and maybe swap it out one agent for another.
So is this gonna get worse before it gets better? Definitely. Um, uh, so love obsidian, love Ben Johnson.
Uh, call to action. That's great. Uh, a lot of these controls are covered, uh, in a number of ways already today.
I think the call to action is specifically around non-human identities in the cloud, right? And it's a way to ask the right questions. Uh, any standard, right?
Without audit is just a nice set of recommendations. And there's some clear things in here to help improve. But, um, a lot of this stuff is covered in a number of other compliance obligations.
And I think you still get down to the basis of, um, you know, this is a risk management conversation and people are very willing to adopt, accept, and, uh, and own risk, where, you know, historically they might not be because the capability is so nice. So I think part of the challenge is you don't understand all the risk you're accepting when you agree to partner with a specific organization. 'cause the, the newness of what some of the agentic behaviors are, you know, even in companies that are using it, uh, effectively is, may not be fully thought out, may not be fully secure.
The, the example of, you know, 16 million documents, you know, being collected for the basis of analysis by a particular agent there, you know, there's lots of these types of things. And I think, you know, in this particular case, maybe less about whether or not compromised credentials are necessary more about manipulating the five-year-old, right? To do what it is that you want them to do.
And the access the over entitlement for non-human identities, right, is probably a real question. That's the bulk of what I think the SSCF really speaks to. And it, it's valuable.
Um, you know, until it becomes an audit requirement in, in something where an external audit, uh, organization has to pass judgment upon it, and that's coming, uh, then it'll be the case. I always think about it like this. Anything that you see on your insurance writer two years from now, it will be policy.
If this isn't on an insurance writer, now when I want to go get cyber insurance, it's not gonna be policy for two years at least until that begins to happen, because the knock on effects are so, uh, large. So I, I always, my hackles get up. I like that phrase, right?
You my hackles, get up whenever I see a self-serving kind of survey or report, you know, the SaaS security company says, we gotta do something about SaaS security, okay, captain obvious. Um, so you gotta take these things with a grain of salt and then, you know, you've got no less than Satya Nadella, I believe, calling, right? Didn't he say that SaaS is over or something like that?
Uh, he said SaaS is over because AI agents are gonna replace the ui. Yeah. But the UI is still gonna get hacked.
And that, to Fred's point, it's a non-human identity. Uh, so I think non-human identity is a new frontier in security that we have. Gotta wrap our heads around really quick, really quick.
I, and I think non-human identity supersedes and, and is much bigger than just SaaS security, frankly, A hundred percent. And, um, it is something we've gotta deal with. And it's, and it's, and it's growing right?
Now. You got all these agents before this, it was all the different containers and all the IOTs and all the, you know, the, the, the non-human identity security problem is, is a major, major problem. No doubt, no doubt about that.
Um, but you know, in terms of SaaS security, to me, I lump it in with third party security, right? How many breaches have we read about where the, the means of egress was some third party, whether it be an HVAC contractor, and I think it was Target, right? Was the HVAC contractor there, There was the, there was the Salesforce customers and the, was it SalesLoft Drift AI chat agent?
That was the compromise involving hundreds of Salesforce customers. So you're right, it was third party. And the Thing is, is these are not, these are not new problems either.
No, right? All we're doing is we're exacerbating them or weaponizing them by allowing, you know, non-human identities to participate in the, in the game. So, is it okay for you to have, you know, forever lasting SAML tokens?
Is it okay for you to, you know, there's things that we know that we deal with regularly, but now, right? Uh, there's a real call to action to solve some of these problems. And I, a I'm with you a hundred percent.
Uh, th this is the next evolution of a set of constructs, I think. And if you look at the, you know, the recommendations here, we're talking about logging, we're talking about the ability to remove controls and users. We're talking non, you know, non-human identities as well.
But we're talking about some fundamentals. And I think, uh, there's nothing new here, right? It's, it is exactly what, you know, Alan, you suggested, which is we need to find a way to deal with AI and non-human identities, uh, under the same concepts we already have.
Some of those are in SaaS, some of those are in vendors that you maybe do or do not know the level of depth of what they do behind the scenes. And you're accepting risk. You don't understand.
All of those things are current problems. And I would totally agree with that. Uh, I, I agree.
This is probably a little bit self-serving. Um, and it, and call to action for all SaaS companies. I mean, I personally would take Embridge with this.
My company doesn't do this. Uh, and we already have most of these things 'cause we operate a secure environment because we're a bunch of security nerds. So when we look at this, I'm like, yeah, sure, that's nice.
But there are probably many companies who haven't had, or, you know, spent the time doing some of those things because of the fact that, you know, they didn't grow up in the industry and they, they did just go out and spin up a company and they are doing such a thing. And so there's a lot of that. I don't have that background of knowledge to know what the right thing to do is.
And so are these recommendations useful for folks like that? Absolutely. Sure.
Yeah. Alan, is this another example of maybe where the government is advocating its responsibilities? Again, I'm not gonna take that meat, Mike.
So I, I'll be honest with you, I don't think, I don't think this is the government's responsibility, right? I, I think, so. First of all, I think it's the cybersecurity's industry's responsibility to come up with some good technology and solutions for non-human identity security and access control, right?
I, I don't look to the government to innovate there. I look to industry to innovate there. I, I think, right?
I think the government could help as part of a private, public partnership by shining a light on the problem and, and fostering discussion for, for solutions. But, you know, I, I'm not looking for a government handout on this, and I'm not looking for the government to solve my problem on this. I think they got bigger things to worry about.
I think there is a minimum level of fundamental capability that should be required to be licensed to provide a public service. I mean, I'm not saying that the government should provide that solution, but I think there's room for, um, improving the compliance mandates, and that is the floor of what's required. I mean, then it's not gonna solve the problem, but a floor is better than nothing.
Let me give you an analogy. Let, let's look at healthcare, right? Think back to when Obamacare was first instituted.
What was that? 2008, 2009, actually 2009. One of the big knocks was too many people were being forced into these, you know, high deductible, $10,000 deductible plans that, you know, the catastrophic plants, I think is what they called them, right?
Where you only had insurances if, God forbid, you had a real catastrophe, and your medical bills were way over 10 grand or something. And it was cheap. And a lot of people went for that because it was cheap.
And then they had a whole bunch of bills that no one of them exceeded 10 grand. So they wound up going, you know, and, and dead up to their ears and eventually in bankruptcy due to their medical bills. So Obamacare came in and said, okay, we're gonna offer them Obamacare and it's gonna be subsidized.
And you know, and we're gonna say that I think it was private employees can't do these catastrophic plans, right? Because they weren't real protection. They were just an illusion of, of insurance.
And that's the way it was. And, and catastrophic plans went away for a while. And of course, different political party came in and they just want people to say, yeah, I've got insurance.
And they, they made the catastrophic plans, okay? Again, and, and now more people have these catastrophic plans and more people are doing bankruptcies because of their medical bills and we're subsidized, or we were subsidizing and we're not. Now, I don't want to, I don't want to put that kind of program in place here for our cybersecurity.
It's not up to the government. I think the marketplace, if you got a, excuse my language, but if you got a s****y product with bad security and you've been burnt as a result of it, I think the market pretty quick gets wise to it and says, you know, it may be cheap, but it ain't good. And let the market win.
I mean, let the market play out. I think the cream will rise to the top and the turds will sink to the bottom. I agree with that a hundred Percent.
So, all right, then, do we need to spend more time educating yes, the buyer gas applications about what the, what's required for a standard level of security? I always felt an educated buyer was my best customer quoting my Fred Sims. I guess you gotta be from New York to appreciate that, Mike, of a certain era.
But, but seriously, that is the problem. Too many people buy that catastrophic security plan, right? Where it looks cheap or it is cheap, looks like at least, like it checks the box and then you find out it really doesn't check it.
It reminds me of a situation I ran into recently where a, a company suffered like $800,000 plus loss due to a phishing, uh, a phishing, uh, you know, uh, incident. And they said, well, the good news is, is we got a million dollars in insurance coverage. It'll co cyber insurance coverage.
It'll cover it. Well, guess what? When you read the fine print, that million dollar cyber insurance coverage only covered a hundred K for phishing incidents.
So they got a hundred of the 800 that's, you know, now I can guarantee you that company will be a lot more careful buying their cyber insurance next time for those kinds of gotchas. But that's, that's why you need to be educated about what you're doing. Yeah, but the cyber insurance is gonna get a lot more expensive as people get more careful.
'cause the cyber insurance is gonna go, Hey, we can't afford all these niceties Without charging maybe. But that's the market of work. Now, the cyber insurance says, oh, you want the million dollars worth of, of phishing insurance?
Well, let me go over your phishing policies with you and, and what are you doing to train your people and what anti phishing software you are using and, and all of these things. And that's how the market works without the government having to come in and take a 10% stake in anyone or, or be, you know, big brother. Yeah, I think, I mean, having been on both sides, like, uh, like Alan, you have as well, right?
When you look at this from the perspective of, uh, a business has to get cyber insurance as well, right? That's a table stakes to have a chief financial officer decide to be able to acquire your products is that, you know, you have done the, the needful in this case and in similar circumstance, right? If you're not asking for those questions, you know, as you do vendor analysis, right?
Then you know, hey, maybe you need a thing like the SSEF to look at and go, okay, well I should maybe ask some of these questions. But the market will regulate this. Uh, if there are things that need to be added.
And I agree that there are, uh, you know, there are already several frameworks by which the market governs right security. And, uh, without getting into whether or not I believe that equals security or whether or not, I believe those frameworks are all great, the fact of the matter is there universally auditable from that perspective, and they're consistent and universal from the controls requirements, what your control objectives are from that perspective, how you implement those control objectives are specific at almost every company. So it's, it's difficult to, you know, swing a broom and say, every single policy that we enact should look the same in every SaaS provider, or that all risk at every business is also equitable from the same stake of saying this SaaS provider introduces this kind of risk.
So I think, you know, we, we've gotta be humble enough, humble enough to know that part of the rationale behind the actuarial science, the whole reason insurance and insurance companies and brokers, uh, exist is because of this risk. And so that's their business. They guaranteed, right?
And we spent a lot of time with Moss Adams and you know, these guys Aon before they were acquired and straws and these other guys that, that talk through, what does it look like? Here's what your policy is. By the way.
Here's 387 questions, right? To figure out the level of depth of whether or not you do or do not have phishing campaign protection, whether or not you do that training. And all of those things become material when something happens, like Shimmy's example.
And I think that's the, that's the right way for market correction happen. It's the way every other industry works, right? So cyber shouldn't be any different that way.
Um, but I think there's a difference between SaaS apps consumed by an average person as a consumer and SaaS apps consumed by a business where they have somebody who is able to make those assessments. I think the average consumer is never gonna figure out any of this stuff to make that assessment. And I think in that context, there should be a higher security standard.
And maybe that is something the government sit steps in and says, Hey, you know, we need to protect the citizen is different than necessarily another corporation that is a buyer of a thing. Well, I would say, okay, but at the same time, I'd like to know why my, uh, social security number has been fraudulently used for somebody else to cash social security checks, right? There are things that are innately fundamental to every citizen's ability to operate that if for, say I were to go file for unemployment and a complaint that I filed five years ago has not been dealt with and the system is still equally insecure, I would say I have much greater concerns for what the federal government's, uh, implications for citizen safety are than whether or not they're gonna go regulate the the market, which is self writing.
Agreed. Agreed. Fred, I think you're dead on.
Hey guys, we're about outta time though. We gotta pull the plug here. We got kids that go have to get out.
Trick or treating. Remember, don't eat any candy till your parents look at it. You know, they're putting razor blades in apples.
Um, do they still do that? Gummy? Who knows?
Acid eat Gummy bears. Gummy bears are good. All right.
Hey, happy Halloween everyone. Have a great weekend. Enjoy Textron tv immediately following this.
We'll be back Monday with another great lineup for Textron Gang. Until then, I'm Alanche. We're out.



