The Human in Cybersecurity – The Inevitability Curve EP10
Chris Blow, director of cyber intelligence and adversarial operations at Liberty Mutual Insurance, joins us today to discuss the nuances of the security community, the importance of information sharing and the human value in technology.
Transcript
This is Textron tv. Hello, my name is Chris Blak. I am your host again for another episode of The Inevitability Curve, where we take topics that we're all thinking about and we look at where we've been with them, with that, maybe figuring out a little bit more about where we are today, and, uh, with any luck, get some insight into where we're going.
So with me today is a good friend, smart person named Chris as well. Chris Blow. How are you, man?
Doing good, Chris. How you doing? I'm loving life.
I'm back on the boats, right? You, you know, we're Facebook friends, you see the sagas, right? This is the first episode of this series, you know, after the boat sank during, uh, hurricane Milton and got them back up and running.
But these solar powered monstrosities and brought to you by Sterlings. Glad to see that. It, glad to see that things fared fairly well for you.
Well, they do. And like, and we're talking about in the green room, you know, everybody, you know, we're cybersecurity folks, right? You know, and anybody in cybersecurity, you know, and at your age, I won won't won't out your age, but your, you know, 15 years younger than me.
And, and like your age and a little bit below that, you know, you, you got here through an interesting path. And I won't say that, you know, somebody in their twenties and thirties, you know, today, you know, hasn't also come into security through an interesting path, because that just happens. But there are courses and things these days.
It's all these structures already built. But, you know, for a lot of us we're just, you know, hacked our way through it one way or the other and put it together. Right?
Yeah. So you some have you Some of it quite literally. Yeah.
Quick rehash of how you got into security. What was your horrible life choices did you make over the last number of years? Over the last, the last, uh, last several decades?
Yeah. Like I had, I had originally, you know, I originally, you know, got into this stuff, I guess, uh, in like, in, in my youth, uh, being nefarious with a computer. Um, very extremely grateful that, uh, of all people, my grandparents were the ones that saw that I was very, um, adept to doing things with electronics.
And I luckily had a, a cousin who was at college at the time, who was able to get a really great deal on some salvage computers, uh, that the university was cycling through. And so I am forever indebted to my grandparents, my aunt, my uncle, my cousin, my parents who helped make that, I think it was my Christmas slash birthday slash whatever else for the next like year, uh, way back when. But that led to me doing all sorts of fun nefarious stuff, uh, as several other people in this, in this large community can, uh, probably talk about as well.
That led to, like, when I went to college, um, there wasn't a cybersecurity program. Uh, I was actually being pushed to go into English by my guidance counselor because computers, like, you didn't really talk about computers. I took a couple of c plus plus courses in my high school, and that's literally all they offered from a computing standpoint besides typing.
And so like, it's not like they were gonna come to me and be like, oh, so you do, you, you do cybersecurity and you've like played with the phone system and stuff. Cool. Well, let's put you on a path of success then for that.
Uh, it was like, no, you're, you're, you're, you should do English. So, uh, I didn't do that at all and ended up cycling through a couple different majors, uh, through college. And that got me to, um, ending up in computer science, which then after I graduated, jobs were hard to come by.
Um, due to the timing of it, it was around nine 11. So, uh, my first job was not immediately, I wasn't immediately placed outta college, the one that I was supposed to do right outta college that ended up, uh, kind of fizzling out in, into the ether. So, uh, was a line cook for a while.
And, uh, then ended up getting a job as a doing help desk. And that led from help desk to doing system administration to network administration to, um, just building, building, building, building, and then moving onto the next company, building, building, building, moving onto the next company. And then that led to just going between companies, consultancy companies, consultancy, et cetera.
But yeah, it's, uh, it, it's interesting now how when we're looking, when I'm looking through resumes, uh, because I have a rec to fill, uh, you know, it's everybody degree in cybersecurity. Uh, and it's like, that would've been nice back then, but that's a, it, it's very interesting that even though it's only what, 15, 20 years difference, probably more than that. 'cause I always think I'm younger than I am and I'm not.
But so be it. I think we all do, uh, how I embrace the age. Exactly.
I'm been bonus rounds now. I mean, I've outlived most my ancestors, Hey, you can't, and you can't beat that, right? Um, but yeah, it's crazy how much has changed in the past just 15, 20 years, uh, especially in those type of organizations, You know?
It is, and that's sort of our, our, our iterative theme here, right? You know, where we've been, where are we now, where are we going, you know, in, in, in my career, you know, cybersecurity, you know, it was information security. I, I love the naming parts of it, you know, just how we've changed names over time.
You know, there was in, in, in my, you know, visibility, there's been data processing right before information technology and Right. And there was information security and then, you know, the, we, the cybersecurity wars, you know, cybersecurity word. Is there a space, you know, that was, that was a fascinating little, little era.
And, uh, you know, anything that goes from anything that, you know, that becomes widely adopted and starts out as something some small group of people are really, uh, interested in, goes through predictable phases. Right. You know, it, it's, you know, there's, there's a, a, a fair bit of, you know, there's a lot of the, the folks right at the beginning who don't really fit into to the, as it bros right?
As it all goes corporate and so forth. Um, and it, and it, it fascinates me that, that in the end, it tends to work out like, you know, that the, all the doom and gloom, you know, we're gonna have a cyber Pearl Harbor. We can, you know, take down, they'll attack the critical infrastructure, you know, and, and this to be clear, all true, right?
You know, the things need to be done. There's a lot of people need to do them. Policies and agencies need to continue evolving and so forth, but the lights are on.
I'm sitting in a boat in the ocean talking to you over a satellites, um, on a, on a Microsoft device. You know, this so far, you know, this morning at least, and that hasn't ruined my coffee. Yeah.
Knock on wood. Knock on wood. Yeah.
So you're right though. It's, uh, the, some, you talk about the doom and gloom. Um, one of the things I'll never forget was my freshman year, uh, my freshman year at college, one of the first classes in like, uh, just general computing that everyone had to take.
Uh, the, the professor came into, uh, for p****r, came into the room and walked to the front of the very large, uh, recitation hall, shut off all the lights, and gave this five minute speech on this is what it's gonna be like on December 31st, 1999, uh, after 11 59 59, and this is what you have to look forward to, and we need to be prepared for this. And, uh, just five minutes. And it, it was, we're all like, I thought this was like, isn't this just general computing?
Like, we're not gonna save the world over here. But you, you talk about things like doom and gloom like that. It's, that that was, that was the big thing.
Um, and it doesn't mean that we shouldn't have, we shouldn't have all had some sense of, are we prepared for this? Um, you know, it wasn't anything, especially at the time, like, you know, mass panic. Um, one of my, um, one of my colleagues worked at the, uh, worked at the New York Stock Exchange during that time.
And, you know, they were going through the same amount of panic there on, like, are we good? Are we sure that we've got everything up to date? Are we gonna, are we gonna be able to do business that following week?
Um, not just that following day, following week, following month, uh, the millions upon millions of dollars that were spent by companies to make sure that everything was good to go. Um, and then we all know it rolled over, and the world's still here. So good job.
Us, I guess, You know, and I, I, for, for maybe the first 20 years of my life, I considered my myself a baby boomer. So I was tactically a couple years too late for it, but I was the youngest of everything. And, you know, so I, I grew up with, with that cohort, and, you know, the, I I, I look back, one of the things that, that that sort of set me apart, you know, because I just, you know, uh, was that I just wouldn't, I, I did buy into it.
I bought into all, you know, all the, you know, what are they common conspiracy theories, basically. Right. You know, either religion or aliens coming to get us or, you know, it's a, governments and corporations are all, you know, doing the, the wireworm, we're all gonna die in nuclear war, and you can't feed enough people.
Yeah. And, but it wore off pretty quick because I, you know, started looking forward and back. It's like, well, actually we've been around for, you know, tens actually, it turns out hundreds of thousands of years.
And, uh, we tend to be still here. And, uh, we of the history, we can see over the last, you know, couple thousand, 6, 8, 10, 12, you know, 20, 40,000 years depending on you look at it, uh, there's always been vo on, you know, battle cruisers coming to destroy the earth. Um, and we're still here.
Right. And I think it does a disservice. I think it causes drag, right?
And this is, you know, let's see if we can turn the, turn the, uh, uh, conversation towards, well, you and I have spent a lot of our, our careers working on, which is sharing information, right? You know, and I think this is right inside the loop, right? You know, companies and technical people and engineers and so forth, you know, have a lot of intrinsic concerns about sharing, oh my God, the, you know, the gonna find out my thing, you know, people are gonna know I got vulnerabilities or whatever.
It's, and I think that this entire exercise that we call, you know, America Western democracy, post Greco Roman, you know, uh, um, uh, democracy Magna car, you know, that this, this free speech open source type of thing, it's, I, while I love it for, uh, for, uh, uh, personal reasons, I think it's mostly just more efficient. I think it's more competitive and advantageous to speak very, very clearly about what you can and be really clear on what your risks are. Right.
You know, does sharing this information does share threat, this threat intelligence cause me more, more problems than it solves. And just work your way through it until you get clean communications. Um, and, and, and, you know, sort of bouncing around the room on this one, but, uh, there is so much, it, it's hard not to talk about the misinformation, disinformation where we live in right now.
Right. You know, because it's such a big part of our daily lives, right. Fake news or who believes, there's no way to tell what, what information is information.
But you and I work in worlds where we share information and we know how true it is or the current working definition of fruit, you know, that's how we take threat intelligence and act on it. It's how we take supply chain intelligence and act on it. Yeah.
And we're building systems that's going to automate this, and it's gonna take actions on our behalf in, in reliable fashions. Yeah, absolutely. I think that, um, it, it's been interesting, especially all the job hopping I've done throughout my career.
Um, there's constants and one of the big constants has been around sharing information and what can be shared and how it can be shared. And it's always very tight lip, uh, even, which is extremely frustrating, especially like what I do now. Like my current role is leading threat intelligence and essentially offensive security.
And in doing that, like there's a lot that I want to share, and there's a lot that I think should be shared, but there's so much that we have to be tightlipped on. Um, and I believe my firm belief on it, at least for a lot of these companies I've worked for over the years, is just because they are behind the curve on like what the true benefit is of actually sharing this information. And they're so used to trying to protect their crown jewels, um, and try to make sure that their secret sauce doesn't get out.
That it's like, what is your crown jewels anymore? Like, do you even know what your crown jewels are? Because what they were in the nineties and the two thousands, it is not even in the early 2020s, late 2010s is not the same as it is today.
Everyone. We've talked about crown jewels in cybersecurity, information security, whatever you wanna call it, uh, for so long. And that definition drastically changes, I don't know, quarterly, monthly, uh, depending on what you, what you see.
And you have a very big reaction to that. So I'm dying to hear what you have to say on this. Oh, it's, You know, so, so in the, what was it, 2002 or so, you know, I did a, did a sim startup with a couple friends, right?
And one of the big, uh, internal arguments we got was about our, uh, using Salesforce, because Salesforce is brand new, right? And it's like, no, no, no, we should build our own CRM, this is our customer list. We gotta keep that private because that's part of our crown jewels.
And my arm was, uh, we don't have time or people to build able build and manage A CRM. Our network isn't necessarily any more secure our actual network than someone who's actually providing services for a living and hiring, you know, people to do security staff stuff. And if I had my competitor's customer list, I would, I don't know, mostly start a fire with it.
I don't care. You know, it's not that much use to me. I mean, maybe okay, don't call them, but they reference customers anyways.
They're already publishing those already know who they are. And it, yeah. So, so you, you know, I, you, you've made the point Exactly right?
People don't know what their crown jewels are. And if you don't know that, then from a security perspective and, and, and not even security to address these anxieties and allow you to more freely do business and engage with the world, you have to identify what it is you're actually trying to protect. What are the risks, you know, intellectual property in, in threat and talent, again, in, in in supply chain, you get all this corporate anxiety about intellectual property.
It's like, how are you protecting that now? Mm-hmm. You, you hiring contracts and hope.
Right? Right. It's, I think, I won't say every job that I've, that I've been at, but most of them especially, um, like obviously not so much for the, um, consultancy side of things, but any of the actual companies I've worked for in corporations, um, one of the first things I've always asked, like before I take the job, I've always asked the hiring manager is, can I have the fir, you know, like, obviously let me drink from the fire hose of whatever corporate you stuff you need me to get through as part of my onboarding process, but like, can I have a month to really understand what we're securing?
Not just like, take, take this at, at everyone's word, and you'd think that I like magically grew two new heads, and they're like, you wanna what? And it's like, no, I want to understand what we're trying to secure here, or what I'm trying to, you know, break into, if it's me doing something from an off sex standpoint, um, like it's one thing for, you know, for me to look at the, I don't know, like the magic sauce you use to make your widget, uh, but it's another thing where like, is that the most important thing? Uh, it might be to that section of the business, but if I go and talk to hr, are they gonna say that's the most important thing?
No, they're going to say that their employer records are the most important thing. Um, it, it just goes on and on and on. So like, let me go and talk to different groups.
Please introduce me to those groups and let me, let me absorb in that fashion. Uh, in fact, at one of the places that, that I worked at for a decent amount of time, um, they, they had training that a fairly decent sized group of folks within that company had to go through. Um, it's no surprise I've done work in, but like several insurance companies.
So it was underwriter training, and I asked if I could be a fly, a fly on the wall. And it was, I think eight or 12 weeks. Uh, and they reluctantly let me do it.
But I learned a whole lot about health insurance during that time, and I learned a whole lot about all the different bits and bobs that they were using as far as an underwriting process went. And that helped me when it came to security awareness. Um, I helped them develop some things around their, like security awareness, programming, education stuff, especially like for cybersecurity month, which, you know, we're currently in so topical.
But not only that, it was now I have a much better idea of what I need to go and look for as we're doing different offensive security exercises and whatnot. So, um, or even as we're building things out from an architecture perspective, like me helping these enterprise architects be like, you're forgetting important things here. And yes, underwriting isn't the only thing in this company, but it ties into so much of their whole, like, business process as a whole, that it plays a very large role, uh, especially when you learn like all the different nuances, nuances, uh, and systems that they have to go into to do some of these things.
And how it's not just like some magical one-stop shop. It's like, oh, you have this thing that you have to leave on. That is, you know, it's just like any other large business, any, it's, you have this thing over in the corner that's grossly outta date you can't do anything with because it's still running like Java version two.
1 machine, um, and, uh, you know, or it's running OS two warp, whatever, makeup your, you know, whatever funnel s you want to go with at the time. Um, but it has to sit there in the quarter and do the thing. But these people have to do this because that is part of the, you know, multi-billion dollar chain of events that goes to make the thing work.
net that has been around for many, many, many years, run by, uh, Fred Cohen, you know, the great Fred Cohen, if you know the word computer virus is because he wrote it down for the first time in his PhD thesis. You know, Fred is as detail oriented and of a person as you lever me. And he and I had a company called Fearless Security for a while that was using the methodology.
You know, if you go to all that net and click on the word protection, the upper left, you'll see this, you know, eye chart that you can click on until your brains fall out. But, you know, Fred and other folks were just Dean. And, and so the older analysts, we were the first people to put together security analyst analytics.
Well, we see the big, you know, companies PWCs and Garters and so forth doing today, they, you know, I I I've been saying this so long and maybe it's not true somewhere, but basically, uh, basically you spend $600,000 and, you know, people will slow down your business for a number of months and give you a 500 page report, um, which is better. Nothing, you know, because it, you know, when you stop it and say, I really need to understand who you are before I can even begin to tell you what you need to secure how, and Fred has, uh, has focused on this stuff. What Fearless did was basically bake that down to a day, but we couldn't get it below eight hours.
It has to be eight hours. You know, walking through this, you know, very large, you know, information system piece by piece paper. Do you do this?
If you do, do, how do you do that? Do you do this? How do you, well, you, what, who are you?
And the few times in our, in my life that I managed to go through that entire thing, everything else just gets so easy. Right? It's like, here's why we're doing this.
Because you see, you see, this is who you are. And if you stop doing these things, you don't exist anymore. 'cause you know, that's, you know, the things cost money and this is where all the money comes from, right?
Or you're, you're a government agency or whatever it is, right? You know, there's, there's a reason you are here. And without that, I hate to get cynical, but it's, you know, these days it's like, can you help me secure my company?
It's like, are you willing to, to, to stop and look at who we are? No, no, no. We just need to No, no, no.
I mean, no, it's not, yeah, You've got to, that's the thing is like, there has to be some willingness to share. There's got to be some willingness. And I even took that, um, I can't believe I'm actually gonna admit this in a public setting, but like, you know, there was two years where I apparently had a brain aneurysm and I was A-P-C-I-D-S-S-Q-S-A, ah.
And, um, We still love you. It was, it Was, well, I was already doing, so like You had to embrace your faults, right? And that's, that's what, you know, brings Healing Link.
I was, I had already previously within that same company, I was already, uh, doing like PCI pen testing. And because it was, it was there and it was something that we were doing, but they were like, we want someone technical to become a QSA. Do you want to do this?
And I'm like, and they enticed me by like, Hey, we'll, we'll go out to, um, we'll be basically do the training out at, well, RSA is going on, so like, go hang out with people at RSA and whatnot too. I'm like, sure, why not? So here I come this technical QSA, and it was very much a binary like lover hate when I went to client sites, because I wasn't just taking stuff at face value and just, and like, but I would ask them to actually explain how they do things, even if something is, I won't say that taking credit cards is simplistic.
'cause most of the time it's not, um, depending on what they're doing. But I would ask them to explain like exactly how they were doing things from a customer service standpoint, how they were doing things from a website standpoint, and where this all came together and where it then like broke apart. And once I understood that, it made the rest of the conversations and it made the rest of like, even just the evidence collection, easy peasy lemon squeezy.
'cause I'm like, cool, I need to see these 10 things. Can you bring this up and show this to me right now? And they'd be like, yeah, lemme go grab five people.
We'll be able to show it to you. Lty split easy to like done. And, uh, yeah, it's the, it's just this whole sharing of information and like, you don't have to share every single thing, but be open, just be a little bit open and that's gonna help us move so much farther.
Like we were talking in the green room beforehand about ISACs, like, is stack ISACs still exist? And they're bigger than ever and they're, it's a such a wonderful, wonderful thing to be a part of. Um, especially for my folks.
I will be the first to admit that while I might be, uh, you know, I might be a leader over, um, threat intelligence and my current employer doesn't mean that I am like some super knowledgeable person about threat intel. Um, no, I'm not. I'm really not.
I, I actually, like, I love the fact that, um, I mean there's a, my entire team is blight. You're smarter than me. But, uh, the folks that I have aligned to threat intel, wicked smart individuals that have taught me so much around what real threat intelligence is, um, and how beneficial it is to, uh, have that curated information and be able to give that curated information to specific stakeholders within your company and using things like an ISAC to, quite frankly, it's, makes it easier for us to share information because you're under that, you're under that TLP stoplight.
And we're able to take that, uh, as I'm sure many other companies are, and we're able to have real connections with other companies, um, under the guise of that, that we couldn't do before. Uh, like similar companies, similar company, so, you know, financial institution to financial institution, whatever it may be. Uh, we're able to have real conversations under the guise of that.
And that's one thing that's continuing to help move that needle in the right direction as far as sharing information and making sure that we're all aware. The, uh, go ahead. Because I'll, I'll be on the soapbox for the rest of this time if I don't, if you don't stop.
No, We think it's a good soapbox. And actually we're gonna, we're just gonna, you know, light on fire and stand on top of a dance, I think at this point because, so high sex information sharing analysis centers for those years, don't know about that, you know, came out of, uh, 1990, I always get this wrong, six or eight presidential directive that there shall be an information sharing analysis center in the private sector to work with the government. And it turned out there was a dozen, and now there there's a couple hundred, and as there should be, and as you say, so the healthcare ISAC is a good example, right?
You, this is a, a relatively significant organization now as you know, with, uh, you know, close to 50 full-time staff or just working on sharing information with, oh, I just just got these numbers, um, the, the other day. But yeah, impressive massive chunk of the healthcare space where they've got community and information is flowing in, in appropriate times. And you used to, you know, one of the, you you phrased this, I won't get it right, exactly.
But I love that sort of thing. And the way you just said it, so naturally you get the right sort of information to the right parts of your, your company in the right sort of time, right? Information sharing doesn't mean, you know, billboards, right?
You don't have to take, you know, there are things between putting it in the safe and dropping in the ocean and telling everyone. And that's, that those things in the between are, are everything we live with. And we can do that in business too, right?
And the, you know, I think, I, I think everything we're just talking about, you know, indicates strongly that the most likely future is where there's more and more of this, where comp companies and organizations are better able to figure out who they are, you know, so they can make better choices about what they should do among those things, you know, security and, and taking care of their systems, having the right systems. And I think, you know, to our sort of theme today, looking back on that, saying 30, 40, 50 years, you'll see one of the huge benefits was more information flowing more quickly. And I'm gonna use the, the dreaded acronym ai.
'cause this is one of the things I keep thinking that this generation of, of what we incorrectly call artificial intelligence has some fantastic benefits for security. And I think this is one of these, right? You, as I say, of getting anyone to stop just convincing 'em that they do have the time and you do have the time, and then get 'em to take it.
And walking through everything, you know, a security professional really knows to do a, a diligence job, uh, for them is still really hard. I think the kind of horsepower, you know, you know, lots of, lots of relatively intelligent pencils, you know, we get out of, uh, uh, AI gives us the opportunity to bring that into scope so you can get organization to say, look, you know, before I'm gonna, you know, start telling you to encrypt your ey ha you know, we're gonna go through this process that's easier and simpler. It's not that hard.
It's not that much, I guess it's not that far from the easiest you can make it today too easy enough that most people will actually do it. And once you have that, I think all sorts of systems, like from technical systems to policies primarily about who gets to know what and what you have to worry about sharing and saying to whom just get way, way easier. And the amount of drag that removes from every individual inside an organization and groups, and I, I think, I think it really is transformative.
I think we waste 90% of our effort on things that are not what we're doing. Sure. Absolutely.
We do. Um, a great example, especially from like an intel standpoint and not gonna give like all praise to AI and whatnot, but just, just optical character recognition like OCR as far as the amount of, the amount of stuff that is out there to turn into in some type of curated intelligence. Is it all gonna turn into something that's, you know, worthwhile?
No, but that's why you curate your intelligence. But if you have a much easier way to bring in some of that stuff so that you can get halfway decent summarizations within whatever tooling you're using, and you can have it spit out, like take a hundred page PDF and it turns it into four paragraphs, that's much easier for an engineer or an analyst to go through and say, yeah, this could be applicable. Maybe I need to go look through the rest of this document some more.
Um, and they can just do mad searches on keywords within that entire a hundred page PDF, maybe they strike gold and it's something that's like, this is pertinent to a part of the organization that they would've never known about this because it was buried deep within something. So trying to find some of those needles in haystacks. Yeah, I think there's a lot of benefit, Darren, we're just at the beginning of some of this stuff, and you and I both know this, this like, AI didn't just magically appear 18 months ago.
Like, but did it hit mainstream and did, you know, did it take off as far as like, you know, what we see with, with Chad GPT and all the other gts and LLMs out there? Sure. But this, it's not like this stuff didn't exist prior.
Um, we're just leveraging it in some good ways. I'm not gonna say a lot of good ways. Some, it's got a ways to go though.
Well, I, I, I think its biggest benefit, you know, to me is, is addressing time to transparency. Another one of my, you know, little catchphrases that I've just been obsessed with the last three, four, or five years because it speaks to so much. I mean, what you were saying is it makes it easier for an now could you have done that by hand?
Sure. You could always do it by hand. You know, you don't have the time, you don't have, I mean, time turns into people.
How many people do you need to read through all of that and, you know, curate that intel before it gets done to an engineer? And if you don't have control f and find in a, in A PDF, then you actually have that engineer read the whole 145. But, you know, so it's all about shorting the time.
And I don't, you know, I I, as I look into the future, honestly, I'm, I'm just right on the crux. I kind of think that maybe there is no digital consciousness. I think the actual artificial intelligence from the movies may be physically impossible, may never happen.
I mean, never, never happened. Um, which I'm not not sure if every time I say that out loud, but we're so far from that, we're not replacing people, we're replacing a lot of jobs. But you know, what we call AI right now is really, really good at brute forcing some things.
So you can give people time. And it's not that you're, you know, I can now have five less people. I mean, again, sometimes yes, but I think what we'll find is that now you can do the thing, right?
You never even thought of doing the thing. I mean, of course you can't do the thing you realize that would take a thousand people sitting there that you can't, it's not even on the table all of a sudden it's like, oh yeah, that doesn't actually take anything anymore and we can do the thing. And I think, you know, from a global security perspective, right?
You know, the, uh, I mean, shout out to the great general Michael Hayden, right? Yeah. I, I, uh, got a a hour of his time right after the Navy yard shooting, remember that in DC there was a, oh, yeah.
Navy yard. It was the day after that. And I was on a, on a, a, a crusade to convince many people inside the beltway that there was this grand, you know, visibility we're moving towards nice sax and threat intel and all that was part of it.
And General Hayden got a, you know, incredibly sharp guy, uh, as, uh, better as well, or better than anybody ask really, really good questions, right? But I, I, it's, it's, again, it all takes too much time. I mean, saying, you and I have lived our careers inside this, let's, okay, the war stories, you know, let's get this group.
We had to get authorities to do this thing, you know, as a public sector or a private sector. And it took six weeks know, just to talk about this paragraph and the exact wording of the, imagine we could do this more quickly. Imagine we can have at the nation state, uh, scale or global scale, you know, the kind of things that, you know, with you focusing on threat intelligence these days that you don't even dream of because it, we, but if you had 10,000 people, you know, analysts sorting things out, you could then get to the point, and I'm really so boxing at this point, but my vision for supply chain is that I can pick up something and this is my mouse and I'm me, right?
So I get to see appropriately if I have the rights, you know, from whoever I bought it from and whatever contract they have with whoever they bought the parts for, and all the way back to whoever made the plastic and who, you know, shovel the sand into the furnace to make the silicon chip. Right. You know, and I can see that right now.
I mean, it took way longer to say that than it should take to do that, but that implies that we can take the, because you can do that now, but it would be a six month project, but we can automate this, right? And we will, I think that's a big chunk of where we're going in the future and threat intel and security as a rides along with that. Yeah, absolutely.
Completely agree. I think that, uh, what we're seeing, we're just gonna continue to see more of this. And it's funny how you talk about like, oh, that's a 10,000 hour, you know, 10,000 person and a hundred thousand hour job, and we joke about that stuff, you know, 10, 15 years ago.
Some of that stuff in some weird convoluted way could potentially become a reality, um, because you're taking out a lot of the, I need half of those 10,000 people to do nothing but read the thing, the things 24 hours a day, seven days a week, we don't have to, we don't have to do that part anymore. Um, are the summaries that we get for everything perfect? No.
Is anything that we're doing, you know, that would eliminate what a human's doing going to be, you know, like just spotless every time? No, but it's a start and I've noticed it with My teams and we didn't trust it individual things that much anyways, Right? I mean, and humans aren't infallible, so, right.
Like we look at, uh, you know, uh, you look at things, but like the look at the latest horizon data breach, we preferred, um, continual rise in the amount of human interactions with, uh, when it, when it comes to either ransomware or extortion of some sort. The, the number, I can't remember the exact number now, but again, continues to rise for the human element part of it. So it's not like we're infallible.
So we're just by, by pushing some of this stuff off into things like ai, um, it's better than nothing and hopefully allows us to maybe progress in what we can do and helps us innovate more, helps us push the envelope more on things that used to be just like, wouldn't it be great if all this pie in the sky stuff, Right. Well, with that, uh, before we start talking about pies and skies, because you know, pies, I mean, how we go with that one ramp an hour. Yeah.
But nice to, nice to see that I'm not the only one that thinks things are going to work out. You know, our kids are grow up, the world will go on, the light will stay on, you know, most of the time. And we'll figure out the problems and we'll fix 'em.
Yep. Yep. Thank you.
So it's, Thank you. This has been great. Thanks.
Anytime. And, uh, and yeah, when you, when you know, as we're talking about in the green room, uh, Indiana, maybe, uh, one of my trips out to mom's place, we'll have to see if we can, uh, hook up there, share, share more, uh, Indiana stories. And you find, and you are of course, you're, you're one of my Disney kin.
I mean, there are very few people of more Walt Disney World than I am. Right. And, uh, the you're a Florida guy periodically, so sometime in the, in the wintertime when I'm not up in Canada, come sailing.
Yeah, absolutely. Um, run Disney season, uh, kicks off next week, so I'll be, uh, yeah, I'll be, I'll be down there a lot. Um, waking up at 2:00 AM to go run And I'll be watching, having a smoke, drinking a coffee on Facebook while you do that.
So that's a God bless you everyone. Alright, man. Thank you very much.
Thank you folks. The world. Have a good day.


