Ethics in Cybersecurity: Addressing CISO Vendor Relationships | TSG Ep. 908
Alan, Mike, Jon, Ira Winkler, Fred Wilmot, Jack Poller and Lisa Martin, CMO Advisor for the Futurum Group dive into an emerging payola scandal roiling the CISO community before discussing the degree to which back doors into IT environments might ever be closed.
Then the gang debates the merits of a MIT report that finds 95% of internal artificial intelligence (AI) projects have failed.
Transcript
Hey everyone. There's something rotten in the cybersecurity business, and we're gonna talk about it here today. Ciso Paola on Tech Strung Gang.
Hi everyone. Happy Friday. It's Alan Shiel and we're here to do Textron Gang.
And man, I've got a loaded, a loaded gang handpick people because we've got some important stuff to talk about today. I, I mentioned the CSO Paola issue. I think it's, there's a stench rising from the cyber industry that we need to address and we need to address it head on, and I've got some great cyber friends to talk about it with, but we, we've got more than that to talk about as usual.
Let me introduce you to my, it's, it's a lo I feel like we're loading the Supreme Court, our loaded gang for today. We've got, uh, returning, she's been away a few weeks from us, but our friend Lisa Martin, our cyber triumvirate, uh, Fred Wilmot, Jack Poller, IRA Winkler, welcome gentlemen, and our editorial team, crackerjack editorial team, John Schwartz, Mike Ard, the, the Bernstein. And, uh, I forgot Bernstein's call wood word, Woodward wood word of of, of the tech world.
So, so lady and guys, I wrote about this last week. I, you know, it, it's been the, the stench has been wafting through the cyber channels for a while now. I saw it a lot at Black Hat, though.
I've spoken to a bunch of people about it. I've seen a lot of LinkedIn posts around it. Not a lot, but enough.
And it's something that I, I think we knew was always has been there. I just think that somehow along the way, and maybe it's because of our present situation where we, you know, we used to worry and think bribe bribery was wrong, and we used to have like ethics rules and, and ethics seems to be gone the way along with the diversity inclusion and all of that stuff. But in cybersecurity, we got a, we got a CSO payola problem, we've got different levels of stench and wrong.
And here's how I, I look at it. First of all, there's just a flat out what I call bribe. I'm a CISO at a global 2000 company, and this extends all the way up, by the way.
But I'm the CISO at the Global 2000 company, and you are a security vendor and you spend a good chunk of your marketing outreach dollars trying to reach CISOs. And you say, you know what? I got a ciso, I don't wanna lose them, Mr.
Ciso, what do I gotta do to have my product selected for your company? And it may not be flat out cash, though. I think sometimes it is, it may be a bribe in the form of can you be on our, our advisory panel and you know, we're going to, uh, give you some stock options.
We're going to give you some, we'll pay you for being on the advisory panel. We'll, we'll give you some other perks, right? Yeah.
How, Sorry, Hear me out. So that, that's, that's almost benign, right? Then worse than just someone giving you pure money.
But then there's other flavors of this. There's CISOs themselves who have said, let's cut out the middleman. We don't need someone to give us an advisory panel.
We'll form our own CISO group and we'll have vendors who wanna come pitch us and we'll charge those vendors 25 grand, 50 grand, a hundred grand, depending how many CISOs I got. And for that a hundred thousand dollars they're in our club and they could tell us about their products and do their companies know if I picked that product or not? Well, that's wrong too, right?
It's just another kind of wrong. And then there's different variations up and down this, this whole thing. We need a code of ethics for ciso.
And it's not just the CISOs. I don't blame just the CISOs. First of all, it extends beyond CISOs, up and down.
It goes to CIOs, it goes to people below the sea level, anyone who has decision making. But I blame the vendors too. The vendors are so desperate to get these accounts, and they all wanna meet the CISOs.
And once they meet the ciso, they wanna land that fish in the boat. And sometimes you gotta put out a lot of chum. I'll throw it to the panel ira.
I know you want to go first. Well, yeah, and let me be very clear, and I will be, you know, disclosed. I am on advisory, um, panels for companies.
None of those companies, by the way, I use as a vendor, just to be upfront with you. You know, I hope, and I was approached by one, a company recently, and it's like, well, we went to as an advisor, but our advisors are limited to customers. I'm like, no way in hell.
And that is a problem in this industry where people think it's the Silicon Valley way for the most part, that you have a Silicon Valley company and what do you do? You throw them stock options for mm-hmm. Something like this.
If you happen to be there, there are ethical ways to do this, you know. And again, for example, when I, I will, again disclosing I will, I'm on the advisory board for CSafe, an awareness related company. And when my company was looking for awareness, I basically said, here are four vendors, which were legitimately the four, four vendors.
And I abdicated any decision making responsibilities to the head of GRC and said, I'm staying out of the evaluation process. I'm staying what? You know, all that sort of stuff.
And they made a decision. It was the decision I frankly liked. I didn't tell them what my decision was or whatever.
But that's how it is. The outright bribes, there's no, I mean, I think it's a crime, frankly. If you are, if you are an executive of a public company and you throw business to someone and get a, that, I think there's SECI Think it Used to be, it used to Be a crime.
I don't know. I'll leave it there. I can go on for so many different ways.
But, um, you know, I, I'll, I'll leave it there. 'cause I've been asked that I turn down in some because of implications. But at the same time, if you do it right and you're hands off, I will only be, uh, on an advisory board that I do not have decision making ability over.
And if I have, I abdicate my responsibility for that. Jack, some other folks in here. Jack, how much of this are you seeing or hearing, or can you confirm what Alan's talking about?
Yes, and this, this gets my, you know, this is one of those topics that I think gets a lot of people's chili on fire. Mine, particularly, uh, as an industry analyst, I talk to a lot of vendors and customers, and I hear it from both sides. And as Alan said, there is a big stench.
And for me, it, it really ranks wrong because for many years, the industry analyst industry has also been accused of being paid to play in order to get ranked in, in a vendor competitive match quadrant wave or whatever. There is this perception that it is paid to play when it is very clearly not. And, uh, you know, one of my mentors, Steve Dusi, the founder of ESG, said, if you wanna get ranked higher, upper, and the right, build a better product, right?
It's not about paying the, the analysts. And the same thing from the vendor perspective. If you really need to get attention of the, the users build a really good product.
The CISOs that are soliciting, and I've heard this, uh, as Alan said on LinkedIn, and in a couple of private back channel conversations, the CISOs that are doing this are violating their employment contracts by soliciting business, right? That means that they have dual loyalty. So you have a loyalty to their main employer and to whoever's paying them for business.
And that typically violates your employment contracts at a C level, if not a regular employee. So there's a, you know, aside from the broad, broad aspect, there's a whole lot of legal and ethical implications that really bother me. And it's eroding the trust of buyers and the cybersecurity industry.
And I think that's the really big challenge, is the origin of trust overall. Agree. Yep.
Fred, you're a, you're a c you were a ciso, right? You've been on both sides of this way in here. So I think this started from a good place.
Um, you know, and the YL venture sort of a approach, which is if you wanna really get a good understanding about product market fit and product validation, you surround yourself with a bunch of people that understand the problem clearly. And what that, as an example, has evolved into is sort of, uh, you know, ciso super groups, which, you know, in Avan, um, you know, status of access and, and gatekeeping, right? Provides a vehicle for people to take other opportunities aside from just the access part of this problem.
And the, there are little title pools of this all over the place. Um, and talking with some good friends this week, actually, this is a topic that, you know, high integrity CISOs, you know, vehemently have an issue with. Because ultimately, if you want a seat at the table, right?
And every CISO wants a seat at the table, uh, this will quickly as an industry remove the access of CISOs to have seats at the table because of it. And, you know, the, the conversation about where CISOs fit with respect to CIOs is also, you know, relatively, uh, impacted here. So, uh, on the vendor side, um, you know, a, a as a startup, right, how do you maintain your integrity when you're trying to get something that you believe is useful as a product or valuable in the market or what have you.
If you don't know the secret knock, if you don't have the funding or the wherewithal to, to grease skids, to influence, to, you know, go to Iceland to have these, you know, a cool CISO outing to talk about whatever war stories and as this glitter associated with it, you know, it's, it's a tough spot. So, you know, when you think about the best product doesn't always win. You know, now an organization has to have some realization that their best product may not be winning in that particular case.
And that organization that, you know, that CSO may represent is possibly losing some sort of quantitative value that helps reduce their risk. So, I mean, it's pretty rotten. And I think that some of the folks that are at the top of this echelon see this as a potential and is significantly influencing damage to the industry reputation for the role itself, and has implications across the market segmentation for the best products winning today.
I think that been here, I'm sorry, what? Mike? I said, Lisa, you wanna jump in here?
You keep nodding your head. Yeah. Yes, yes, yes.
So, so I, I totally agree. I think, I think that that Jack and front hit it on the head. What I was thinking about this is that you wrote in trust factors.
Jack talked about when relationships are cloudy, no pun intended or, or not clear, that can lead to skepticism and mistrust. And that can make it challenging for other ethical vendors to build credibility, to establish meaningful relationships. Another thing, Fred, you had talked about was damaged brand reputation for those unethical vendors.
And that can lead to negative publicity, lost credibility, but it also helps to, or not helps, but it also can overall, even for the good guys, decrease credibility of marketing messages. When, when those CISO vendor relationships are cloudy or opaque marketing messages from vendors, even the good ones can be viewed with skepticism or they simply won't land. So if that payola comes to light, CISO's organizations may question the validity of claims of accuracy of data from other vendors and question their motivation.
So I think, and I also think ultimately this can have a negative impact on sales and revenue, which is critical for organizations. So I think that, um, from a messaging perspective, from a marketing lens, that's what I saw with this. Would, Would that, Alan, Alan, I a, go ahead.
Um, can I ask you a quick question? Sure. Um, so this has Been around, or it's been lurking in the shadows, and I'm wondering now that we're hearing more about it and we're talking about it, is this a byproduct of social media exposing things that used to go under the radar?
Or are we just normalizing scandalous behavior given the circumstances? I mean, I think if I were to answer that, because we're not the, like Fred touched upon this, but we're, there's the VC element to it. He mentioned YL Ventures in starting that.
Now, YLI know them, I'm not on their board. I think they're an ethical group of people. Knight Dragon, for example, also has this, you know, my company was in the process of raising funding and Knight and, sorry, so one of the VCs was put trying to figure out, and they put us in front of a group, one of their, you know, a group of their advisors.
And essentially what happened was, yeah, they took a look and they had, they gave feedback. The issue though is how are these people being rewarded? Because the most valuable thing a CISO has is their time.
And I'm not saying rewarded, like, you know, I want, I demand money. But what happens is, like, so companies like YL, like Night Dragon, like teammate and others for their villages or whatever they call them, they have events that are frankly not sponsored by the vendors, but are sponsored in some level of reward. And it's kind of, I don't know if you say it's murky to be part of this, but you don't get any direct compensation.
Like apparently other groups were accused of in the VC world. I had one CISO who once wanted, when I said, do you wanna look at my company's stuff? The guy sent me a link for, I think it was $2,500, but it was for a charity.
'cause he appreciated the fact his time was valuable and he wasn't taking the money himself. Now, is that questionable? I, you know, I understand the intent, but you know, at the same time, we're paying to get in front of him, you know, for a way that's whatever.
He didn't get it directly, but it, there, there is the, I do recognize the fact his time was valuable. Was that the right way to approach it? I'm not sure.
But again, there's a difference between, I would have to say a group of CISOs saying, pay us to come in front of our group, which is, I mean, I don't know where that money goes, which is a big question, but, you know, you have to look at the time factor for CISOs, the reward, direct compensation, indirect and so on. And it's a very complicated issue to do it right, and even do it along, like just stay kind of, sort of off the line. And, you know, and again, to Fred's aspect, how do companies, I mean, I get like literally 30 messages a week saying, we'd love to run our product by you.
Like entrepreneurs are doing this. Like, Hey, if I gave 30 minutes to everybody, it'd be a full-time job at this point. Yeah, It, it would be.
And that, and that's a dilemma. It's a legitimate ira, the legitimate thing that you're talking about. But let me, John, let me go back to your point about why now.
Why now, I will tell you that historically, I know people, friends of mine who were CISOs at large companies, Yahoo, other companies who were tainted with Scandal in that they got pitched, they got buy buyback for picking a particular product, and they kinda left. And they had to go, you know, in the finest US tradition of the time they had to go into rehab and, and rehabilitate themselves. And they came out fine on the other end of eventually, but it used to be a, a pretty clear line of what was wrong.
It's been eroded. YL Ventures is a upstanding group. I I know the guys, you know, Jo and the rest of the team there, they're good people.
The Night Dragon is, what's his name, Dave de Walton them. Yes. Good people.
Mm-hmm. But what you've set up is a system where vendors will literally do anything to reach CISOs in the cyberspace. And, and I don't think this is just confined to cyber.
I think the same goes for CIOs. It may even go for CMOs. Right.
Well, let me just say, sorry, my, I I need to go on this rant just for a quick sec. Go ahead. I think there's too much.
So there is, there are some CISOs who are their bulk of their entire cybersecurity program. But I think the biggest problem is vendors need to understand that they need to become magnets and be able to pull people in and not just go for CISOs, but go for the people in the middle. Because when I was chief security architect at Walmart, I'm the wrong person to come to, even though everybody was harassing me.
Because it's the people at the lower levels who understand the needs. And you gotta find those people, people you won't give a squishy toy to are gonna be the most valuable people, let alone the CISO you're gonna give cash to. And so you need to un they need to understand, really, a legitimate company lets the bottom, you know, ha pushes vendors from the bottom up.
Yep. So we Wait, wait. We all get the, that there's an issue here, but now the thing I'm not hearing is what's the fix?
What do we need? So I I I, what I think we need is some sort of ethics code for C-level people. And we used to have these things that I didn't get a chance to finish my thought.
I'm sorry, sorry about My thought is, is that we, I as a society, as a civilization, especially here in the us, have seen a tearing down of our ethics, a tearing down of what is acceptable. People used to be civil. There was, there was a code of, of, of conduct a moral clause, if you will, of how one does business and what's right and wrong.
And this has, this hu this whole, that's all been torn down. It's all been torn down. And just go on your, your favorite social media thing and, and say whatever the hell you want.
And whether it's right, wrong, a lie or not. And that contributes to the moral turpitude of our whole situation here. Right?
We need a code of ethics for CISOs, Alan. There's a, there's a hell of a lot more money involved now too. I being Well, There is, there is.
That's what I was gonna say. This, this, this goes beyond the CSOs. I think we also need that code of contact for a conduct, excuse me, for ance.
Yep. One of the big issues here, and you know, you guys asked about why now, why now is because the cost of doing business is getting more expensive to show up. Ira mentioned squishy twice to show up at RSA among 650 or 750 other vendors, vendors on the convention floors at a minimum 50 k for a small startup, if you're, you know, if you got, you know, it's 50 k just to, to show up on the show floor, a hundred to 150 K for the event.
If you can get in front of five or 10 key vendors for 20 for, sorry, customers for 20 k, that's an easy ROI question for the vendors, right? From a, a marketing and a, and a sales lead perspective. So we need the vendors to take on some ownership and responsibility and say, we are not going to participate in any play to play activities as well.
That, yeah. Let me challenge you there, Jack. I think that's you, you can't ask vendors who are solely, uh, focused on generating revenue, have investors that are solely focused on generating revenue, have scale problems that require generating revenue to take an ethical approach to how they sell when, you know, the other side of the fence is not ethically, uh, consuming.
It's a really hard, it's a bitter pill to swallow to make that statement. But I would agree. I I think it has to be both.
I don't think, I don't think it can be one or the other, both sides of all sides of the problem, right? Yeah. I mean, but the fact is, a lot of this is criminal.
I mean, we're sitting here arguing ethics. We shouldn't have to argue ethics when essentially bribing somebody of bribing an executive of a fortune of a publicly traded company, let alone fortune ranked. Is there.
And even in private companies, it's still technically bribery and it's still kind of borderline criminal if we're even talking border. I don't think we need a code of ethics. You know, it's wrong to approach someone and say, well, let's kind of sort of do hide the money or whatever.
You know, it's, it, it, sorry, I'm just, I just don't accept the debate that it's ethics. I, I argue it's kind of criminal in some of the cases. Are there, I I agree with you.
It is criminal. If you had a criminal system that was gonna pursue that kind of thing. But when, when you have a Congress that does inside a trading based upon insider, not insider, when you have a Congress that trades stocks based upon perhaps confidential government information, and it's not just Congress, it extends to all of government.
You know, again, this is all, none of this happens in a vacuum. Mm-hmm. It's a societal issue.
We live in a, there are no rules laissez-faire, you know, this is, this is the proverbial give the capitalist enough rope, they'll hang themselves. Well, I mean, there are other choices for people. Like, for example, one business model is cresting way former CIO of Blackstone, and he gets CISOs together.
And much like, it's kind of in a similar vein to CISO society or mer uh, Merlin's thing, where they have panels of CISOs they bring together not compensated, and then they bring the vendors to present to whichever CISOs are there. And then their model, this third party vendor is essentially taking the profit, doing the matching the companies have to pay. There are legal models for doing this.
Yeah. No, there are legal ethical ways of doing it, but who's the policeman here is my question. I mean, in, in theory, yes, there should be a policeman for doing this.
The reality is these crimes are hard to detect. They're not in many cases above the line crimes, which is unfortunate. But, you know, I mean, these products should be shunned.
Like, if a vendor has said, Hey, take it, you know, we'll make sure we send you on a trip or something. I'd be like, hell no. And then I would blacklist the vendor.
You know, it's, We used to do things like that. Guys. We're counting up on the 25 minute block here on this a block disturb.
Alright. You know what? We, we will, we will discuss this more.
Ira, Fred, Jack, I, I've, look, you know what? I'll be honest with you. I think it takes a set to come out here and talk about this openly.
And I appreciate the three of you coming out here and talking about this openly, right? Because all four of us, we, we live in that, we live in this community and we all have friends who, who are on both sides of this, probably, unfortunately. And, and, you know, physician heal thyself.
As an industry, we need to heal thyself with this. I am going to, and I, I know you are hooked in with the good folks at RSAI am as well. I'm gonna ask them if we can't do something at RSA next year about this.
Hmm. Well, deadline is Monday, I guess so. Well, I'll, I'll they always extend, you know, but I'll, I'll call, I'm, I'm gonna write to our friends there today because this isn't done.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And the next block is, well, cybersecurity related as well.
But the UK government has said is it's no longer interested, I guess in getting a backdoor into the Apple iCloud. And this has also been an issue here in the United States where government officials are saying Nvidia should have some back doors and a kill switch. And this conversation comes up almost every two or three years, I feel like.
But Fred, um, what's going on here from your perspective? Is this kind of a serious conversation or is this kind of noise in the system? Um, great question.
I think it is pretty much noise in the system. You know, in, in 2018, we had a huge upheaval about, uh, super micro devices that had, uh, erroneous chips on the motherboards that Apple and Amazon had to answer for to the federal government. Uh, you know, we know about Huawei, we understand that there are a number of vendors and chip manufacturers that have questions and are issues and backdoors are in essence, you know, something that I think ha have political fervor depending who's in, um, who's in, who's in the o uh, the Oval Office.
But the additional part of that is the assertions of things like, uh, terrorism and, and, and, uh, sexual abuse and things like this are the reasons for having that. We already have full transparency as part of the five eyes amongst the organizations who would be concerned about it. So I think there's a little bit of saber rattling.
Also, we've created some distance, uh, with England, unfortunately. And so this is one of those, you know, do we or do we not sort of press the buttons here? And I think that's really sort of a political sentiment more than anything else.
Mike. Hmm. Jim, what's your take here?
Because, um, we also hear concerns that, you know, gear come outta China has unknown back doors in it, and we don't know what goes on with that. And, um, is this gonna be one of those, everybody's gonna want their own backdoor because well, it's and cyber espionage savvy to do so. I think the a, everybody wants their backdoor.
They've always wanted their backdoor. We have as, as Fred mentioned, we have mandated backdoors in our telecom industry for five eyes. And that was what was exploited by salt typhoon.
So the, the concept that a backdoor is just for the government is false. A backdoor is a backdoor that anybody can access, not just the government. I think the concern, the big concern I have and a lot of people have is that the, the British government's desire was to get access to what's app and signaling, you know, apple iMessages quote unquote for terrorism.
But once you mandate a destruction of end-to-end encryption on a messaging platform, you've mandated destruction to end-to-end encryption for every platform everywhere. Which means now all of your cloud end-to-end platforms are no longer end-to-end. They all will have back doors in them.
They have to, because that's where the data for iMessage or whatever is stored, right? And all these things is on the cloud platform. So now all your business requirements to have end-to-end encryption and not have the cloud service provider have access to your encryption keys is gone.
So does that mean the end of cloud services for England? And I would venture to say that if, if Amazon and Microsoft were, and Google were aware of this, you know, were serious about this, they would say so that they would come out and put a stake in the ground and say, Hey, you, you implement this stuff. We just won't have hot services for you guys, particularly for the government services.
And I think that would help put an end to this. Well, I don't think that's ever gonna happen. Nobody's gonna say, I'm sorry, Mr.
Government who potentially gives us billions of dollars a year. We are going to exclude you from doing business with us, or we're gonna give up an area of the world. The reality of the situation is, from my past perspective, how I, I worked for NSA, let me disclose that, and how many people remember the clipper chip arguments in all this where it originally started.
I mean, I remember like, you know, like everybody arguing about the clipper, we do have, fundamentally, here's the issue. We do have legitimate concerns that everybody wants to hear about getting into terrorist communications. And the reality is, everybody is up in arms in general.
There's the pendulum. Everybody's up in arms until there's a terrorist attack. Then everybody's like, why didn't you do something?
And it's like, well, we didn't have this. It's like, why don't you, it seems like law enforcement should have that capability and everybody swings the other way. 999% of the people just don't care if people have a back door.
And so the government wants it, the government's probably gonna get it because they have the finances and they have the ability to put restrictions on a company. And that is gonna drive the company to make decisions as long as it's somehow defensible by, have never seen a company actually put their stake down and keep with it and still be in business to this day without changing that. You know, IRA, the only people I ever heard b****y moan about back doors was the government themselves, right?
When I first started selling to the federal government, you know, the, this was security stuff. The, the rumor, you know, the, the, the u this, the US federal government, especially the DOD would not buy Checkpoint, would not buy Checkpoint, and Checkpoint was kind of the first big Israeli cyber company security company. They wouldn't buy Checkpoint.
'cause the rumor was the Mosad had a back door into Checkpoint, and so they wouldn't buy it yet, didn't stop Checkpoint from being, you know, the second most popular security company at one point out there, right? And, you know, and, and, and really setting the mark in the firewall market. Um, but other than the government, no one seemed to care.
You know, and I think I was right. You, you know, you'll get some privacy people who get their panties tied around their necks about it until something bad happens. And then you go the other way.
And you know, like after nine 11, for instance, and, and allow, you know, Leo to do whatever they want. Is it not caring or is it just not knowing? Because Lisa, I can imagine a conversation that goes something like, well, suddenly some buddy in Italy wakes up and says, wait, let me understand this.
Trump has a kill switch for our IT environment. I think what's really important here from a reputation management perspective is transparency. And that's one of the things that we're not getting because transparency demonstrates a commitment to addressing the concerns, to maintaining a positive brand reputation.
We talked about trust in the earlier segment, and I think by openly addressing allegations, providing reassurance, these companies have to build trust with customers and partners. They have trust with customers and partners. It can be eroded with this and stakeholders.
So I think what they need to be doing is really approaching and addressing security concerns that can differentiate them from competitors, help them maintain the trust they've already earned with customers, with existing customers, and help them earn trust with prospective customers. But it always goes in marketing and, and for really across any organization, I think that transparency is currency these days. And that's one of the things that we're not saying.
Well, Lisa, could I ask you a, you know, legitimate, what I think is a legitimate question. How is a company saying we adhere to British law? You know, not being transparent, not eroding trust.
I mean, saying we are going to snub British law would, I think, be more of an erosion than the other way around. I agree with you. I understand what you're saying there.
I think that, but from an, from an end-to-end encryption perspective, if companies are saying, we're not gonna do this, you guys can have it. You guys can't have it. It's, it's undermining trust globally.
And I think that's where reputation damage, branch damage can happen for an organization. It needs to be blanket and where it can be so that that trust is maintained. And people understand, like the, the, those of us, like me, your data's protected.
It's not gonna be shared with the UK government. It's not gonna be shared with this organization. I can't hack into your iCloud and get your information.
That's what people need to feel secure about. Yeah, I wanna, I want to come back to some, I really wanna touch on some of the stuff that Jack talked about, but Lisa, what you're talking about is piercing a veil that isn't really, I mean, there's a lot of artificial sentiment about what that actually is versus what it's, and I think you're right, but you know, if, if you told everybody the world was ending tomorrow, right? Um, what happens, right?
Chaos disorder, mayhem, whatever, the world may end tomorrow, right? Or, you know, as my mom loves to say, everybody wants to go to heaven, no one wants to go to tomorrow. In this particular situation, everybody probably has some understanding of what it means to compromise, you know, their, their privacy.
Uh, we have a whole set of infrastructure set up in EU now that really makes it hard to do business. The cost of doing business is as much a factor here as anything else. But something that Jack said that is really important to talk about here, this stuff exists, right?
And whether or not it's, it it's accessible to different organizations or to different governments. If you look at what's going on in the CHIPS Act right now, if you look at the potential investment in Intel, if you look at the potential, you know, requests by, by our government for Nvidia, there are many more things at play here about global territory. And I think that's the piece, right?
Jack touched on this briefly about what that means, but the integrity of who's doing what type of, of, uh, trade craft, uh, and analysis on that data is something that we've already established a collective to, to support, uh, as a, as a country. Everything that is outside of that is literally outside of that. So when we have conversations about whether or not you can put something in Telegram, which we don't own, right?
That's a conversation. When we have a conversation about Zuck and his AI premises and the things that go with it, that's a conversation. What are we allowing China to do as a result of that, which we've talked about before.
Um, but I, I think there are several things here and every time we talk about how do we think about the transparency, super good call out, Lisa. That's what every American or every citizen wants to know. There are just some things that are never going to be true in those terms that we will never understand.
And that's why I say it's piercing the veil. Yeah. Randall, Um, one more question, Alan, which is the, the regulations in the EU that exist today, like GDPR and particularly on data sovereignty regulations were inspired by the US Patriot Act after nine 11, which gave the US basically the ability to pierce encryption and get access to European company company data stored in US cloud service provider services because it was owned by US cloud service provider.
And so the reaction was, well, we need data sovereignty and we need to have that stuff stored in outside of the US in the EU so that the US government can't get to it. The irony here is now they want to get to that very same data themselves. Yeah, it is ironic.
Guys, I, we gotta, we went too far and too long in the first session. I gotta add this one, I apologize. But we, we've got one more, uh, block coming up here.
We're gonna talk about AI misfire. We can't have a show without ai. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey folks, we're back.
And is Anna alluded to, we are talking about AI misfires is a much talked about report this week from MIT talking about how nearly all the AI projects, at least the internal ones that they tracked felt, and people are saying, well, is this another indication that this AI stuff maybe is not just over hype, but maybe, uh, just not quite. It's the promise and the vision. John, you covered this.
What's your take? You know, so I have mixed feelings about this. You know, the 95% gets your attention, of course.
So MIT has this report, which has since had metastasized it kind of into, uh, roiling the markets. It prompted Sam Altman of all people to warn of an AI bubble. There's even some naysayers, or some would say short sellers referring that NVIDIA's results are gonna fall short when it report next week.
Um, this, this report basically says that 95% of generative AI pilot programs that companies have little or no impact on the bottom line, but there's a lot of nuance to the reports. An issue isn't really the quality of the AI models, but this learning gap for tools and organizations, in particular, these flawed enterprise integration. There's talk of the impact, the negative impact of shadow AI and the ongoing challenge of measuring AI's impact on product and productivity.
It, it's, in a sense, it, it, one executive I talked to, um, a gentleman from Sitecore said, the high failure rate isn't a sign that Gen AI doesn't work. It's a sign to most organizations that's still learning how to make it work. There's also some sentiment of thought that the areas the money's going into or the projects that are going into are the wrong areas to invest in and to get products or productivity from.
So we've got this, this whole kind of report kind of overtaking and creating a new narrative. And I, I spoke, uh, yesterday to Daniel Newman, our, our fearless leader. And he, um, he has very strong opinions and I think it, it's, it, his opinion is that this, this report basically has had far too much influence.
Again, you know, it'll probably be forgotten within two days and the Marcus will correct themselves. But I think there, there still is some doubt about ai. There's a lot of murmuring still about this AI bubble since so much money's being put into it and being invested in it by big tech in particular.
It's an, it's an interesting touchstone. The timing of the report was really good in terms of maximizing, uh, coverage of it and, and raising some issues. Hey, Lisa, what's your think here?
Because it did royal in the markets and all the marketing people are probably flipping out. You know, guys, I'm gonna come at you from a marketing perspective. I have the luxury of talking to CMOs every week.
I've spoken with about 20 recently. I had 10 of them over for dinner last week. They're marketing is a great use case.
We have a, we have a CMO Payola problem with Lisa. No one paid, I wanted entire thing, Alan, no Paola here, sorry, I'm your girl. But basically everybody's adopted AI and marketing, not just to improve productivity, but another thing that I'm seeing is enabling sales.
A lot of CMOs are now owning the SDR function. Um, so it's improving alignment with sales. It's creating more compelling content that converts.
They're overhauling web pages, they're overhauling microsites, they're delivering marketing generated pipeline faster, which impacts revenue. I had the CMOs of Snowflake, Dynatrace, Nutanix next week, my episode with CrowdStrike Drops, and they talk about how they're leveraging AI as a force multiplier. It's helping marketing and sales move faster.
It's helping them focus on more strategic tasks. What they need to do and what they're responsible for doing is elevating the ROI impact of that pipeline and revenue to the C-suite, to the board, to really clarify where from a marketing lens perspective, these AI marketing councils that a lot of, a lot of CMOs are, uh, leading, are leading to a richer audience targeting. It's more effective marketing, and that contributes to pipe and it contributes to revenue.
Could I So Yeah, go ahead, Alan. Sorry. Well, I was, I just wanna make a clear point.
The clear point is we're talking generative ai. People are saying ai, and the problem is that AI has, I hate the word ai, but algorithm AI models have made vast improvements across organizations all over the place. And what we're talking about is a very specific branch of AI being generative ai, which is the unique building of content.
And there people are just playing, and I'll leave it at that, but we need to make that clear distinction. Yeah, generative ai. Look, I was on a webinar last week where people were talking about generative of AI in the past tense that we've moved on, you know, to agentic.
But I, I've written a few articles about this one. One is in the notes here about ai, or you're fired two CEOs through different approaches. I wrote another one last week and I, I remember it ended with Keep calm and keep, you know, and AI on, uh, McKinsey had a very similar survey, not quite 95% failure already.
I think they only had an 80% failure. It Was 80% Yes, at McKinsey. So clearly were there smoke this fire.
But, uh, you know, I, I get a shimmy says yesterday on this where I said, you know, quack, quack. If it quacks like one, it's one. I've seen bubbles before.
There's a bubble. No doubt there's a bubble. com era in terms of internet companies and, and internet, you know, ways of doing things.
I think think what we have is an extremely overhyped overheated situation where I don't give a crap how good this stuff is, and I don't care whether it's generative or ml or or agent. It cannot live up to the hype. It can't, you Can't certainly, I mean, we just, uh, there's this Ai and so there, there's gonna be people disappointed.
There's it happened, right? Wasted it gonna be fallouts, there's This, yes, it's a bubble. Those Are meetings.
You know, there's two things to think about here. One, particularly for the studies, and one is the way we present 'em. When you look at the studies, the real question is what is the definition of success for the MIT study?
It was simply a, a revenue contribution, right? Bottom line. Bottom line.
But a whole lot of what AI and gen AI is doing is not directly immediately measurable by the bottom line, because what it's doing is changing the way you do business, the way you operate, particularly the way marketing teams operate, right? When you implement, when we went to an implemented, um, automated marketing, right? And with market, uh, with all the different marketing tools, we didn't see a bottom line contribution for a while.
It takes a while for that stuff to show up because it's changing the way you do business. The second thing is, with all of these types of studies, as it goes back to the old news adage, if it bleeds, it leads, right? And, you know, shoot for a 94, 5% number structured study.
So you get a big headline grabbing number. And that's what we did. And I take that all with a grain of salt as somebody who creates these studies, right?
Is you really gotta understand the size of the study, what it was targeted at, what they were seeking to figure out. And the one thing I think the study pointed out, which John mentioned, is the applicability of generative AI and other forms of AI to different business functions. And what it can do is very hard for people to understand right now because it's revolutionary, not evolutionary, right?
com was, and as the transition to the cloud was, it takes a while for people to figure out how to apply this revolutionary new way of thinking about doing business. So the report about AI being overhyped is overhyped, is that what you're saying? Absolutely.
Imagine that. Absolutely. Hey guys, I gotta pull the plug, man.
We're way over time. What a, what a fantastic panel. What a fantastic discussion Panel.
Thank you, Fred, Jack, IRA, Lisa, thank you. Thank you. Of course, John and Mike as always, thank you.
Thank you for watching. Hey, if you're, if you're p****d off about this Cecil Paola thing, do something about it. Say something.
Um, we'll be covering it more here. But we've got a full Textron gang coming at you. Uh, excuse me, A few text, full text on TV coming at you immediately following.
Enjoy your Friday. Have a great weekend. You know, summer's almost over.
Don't let these last couple weekends go to waste. We'll see you here Monday on the gang.



