Mar 1, 2019 · 16m · a16z

Security Markets: The Lay of the Land

Joel de la Garza · 15m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this Andreessen Horowitz presentation, security partner Joel de la Garza analyzes the structural flaws and economic misalignments in cybersecurity, outlining how CISOs can shift from legacy reactive defenses to cloud-native, built-in security models.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 0.0 Guest teaching 0.6 Guest disagreement 1.0 The host pushing back 0.0
05100:0010:000:00–3:18 · The host as informed peer 0/10 Opening B-Roll of Cat Receiving a Treat The guest delivers a presentation on software eating the world and security industry incentives with no host interaction. Host-side scores are zero due to the monologue format.3:18–5:37 · The host as informed peer 0/10 Evolving Adversarial Threats: Cryptocurrency, Ransomware, and Cloud Misconfigurations The speaker details evolving threats like crypto-mining and cloud misconfigurations without active host involvement. Host scores remain zero.5:37–9:22 · The host as informed peer 0/10 The State of Security: Perception versus Reality The guest breaks down Verizon breach statistics showing phishing drives most breaches while the moderator only interjects with passive agreement.9:22–11:25 · The host as informed peer 0/10 CISO Tool Fatigue and the Role of Cloud Security The guest explains CISO fatigue with next-gen tools while receiving minimal interjections from the audience/moderator.11:25–16:38 · The host as informed peer 0/10 Future Outlook: Five-Year and Ten-Year Cybersecurity Trends The speaker outlines long-term trends including cyber insurance and zero trust architectures in a presentation format.0:00–3:18 · Guest teaching 0/10 Opening B-Roll of Cat Receiving a Treat The guest delivers a presentation on software eating the world and security industry incentives with no host interaction. Host-side scores are zero due to the monologue format.3:18–5:37 · Guest teaching 0/10 Evolving Adversarial Threats: Cryptocurrency, Ransomware, and Cloud Misconfigurations The speaker details evolving threats like crypto-mining and cloud misconfigurations without active host involvement. Host scores remain zero.5:37–9:22 · Guest teaching 1/10 The State of Security: Perception versus Reality The guest breaks down Verizon breach statistics showing phishing drives most breaches while the moderator only interjects with passive agreement.9:22–11:25 · Guest teaching 1/10 CISO Tool Fatigue and the Role of Cloud Security The guest explains CISO fatigue with next-gen tools while receiving minimal interjections from the audience/moderator.11:25–16:38 · Guest teaching 1/10 Future Outlook: Five-Year and Ten-Year Cybersecurity Trends The speaker outlines long-term trends including cyber insurance and zero trust architectures in a presentation format.0:00–3:18 · Guest disagreement 1/10 Opening B-Roll of Cat Receiving a Treat The guest delivers a presentation on software eating the world and security industry incentives with no host interaction. Host-side scores are zero due to the monologue format.3:18–5:37 · Guest disagreement 1/10 Evolving Adversarial Threats: Cryptocurrency, Ransomware, and Cloud Misconfigurations The speaker details evolving threats like crypto-mining and cloud misconfigurations without active host involvement. Host scores remain zero.5:37–9:22 · Guest disagreement 1/10 The State of Security: Perception versus Reality The guest breaks down Verizon breach statistics showing phishing drives most breaches while the moderator only interjects with passive agreement.9:22–11:25 · Guest disagreement 1/10 CISO Tool Fatigue and the Role of Cloud Security The guest explains CISO fatigue with next-gen tools while receiving minimal interjections from the audience/moderator.11:25–16:38 · Guest disagreement 1/10 Future Outlook: Five-Year and Ten-Year Cybersecurity Trends The speaker outlines long-term trends including cyber insurance and zero trust architectures in a presentation format.0:00–3:18 · The host pushing back 0/10 Opening B-Roll of Cat Receiving a Treat The guest delivers a presentation on software eating the world and security industry incentives with no host interaction. Host-side scores are zero due to the monologue format.3:18–5:37 · The host pushing back 0/10 Evolving Adversarial Threats: Cryptocurrency, Ransomware, and Cloud Misconfigurations The speaker details evolving threats like crypto-mining and cloud misconfigurations without active host involvement. Host scores remain zero.5:37–9:22 · The host pushing back 0/10 The State of Security: Perception versus Reality The guest breaks down Verizon breach statistics showing phishing drives most breaches while the moderator only interjects with passive agreement.9:22–11:25 · The host pushing back 0/10 CISO Tool Fatigue and the Role of Cloud Security The guest explains CISO fatigue with next-gen tools while receiving minimal interjections from the audience/moderator.11:25–16:38 · The host pushing back 0/10 Future Outlook: Five-Year and Ten-Year Cybersecurity Trends The speaker outlines long-term trends including cyber insurance and zero trust architectures in a presentation format.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 1:55 Security industry anathema critique

The speaker forcefully criticizes the information security industry, comparing its pricing model to a car dealership demanding extra cash to keep a new vehicle from bursting into flames.

Hardest push from the host ▶ 6:49 Moderator passive interjection

In a keynote monologue without actual host counterarguments, this brief interjection represents the only host-side utterance in the segment.

Biggest teaching moment ▶ 6:20 Phishing statistics reality check

The speaker educates the audience using Verizon breach data to dispel myths about advanced zero-day exploits, showing basic phishing causes 93% of breaches.

The host holds their own ▶ 8:28 Moderator verbal acknowledgment

As the transcript is a presentation rather than an interview, this brief acknowledgment marks the sole active host presence rather than substantive pushback.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Opening B-Roll of Cat Receiving a Treat 0010 The guest delivers a presentation on software eating the world and security industry incentives with no host interaction. Host-side scores are zero due to the monologue format.
Evolving Adversarial Threats: Cryptocurrency, Ransomware, and Cloud Misconfigurations 0010 The speaker details evolving threats like crypto-mining and cloud misconfigurations without active host involvement. Host scores remain zero.
The State of Security: Perception versus Reality 0110 The guest breaks down Verizon breach statistics showing phishing drives most breaches while the moderator only interjects with passive agreement.
CISO Tool Fatigue and the Role of Cloud Security 0110 The guest explains CISO fatigue with next-gen tools while receiving minimal interjections from the audience/moderator.
Future Outlook: Five-Year and Ten-Year Cybersecurity Trends 0110 The speaker outlines long-term trends including cyber insurance and zero trust architectures in a presentation format.

Statements from this episode (12)

Opinion
de la Garza: Traditional security industry runs counter to actual security
“So for a long time now, the security industry has existed as kind of an anathema to actually making things more secure, and this has been incredibly problematic with a lot of the things that have happened in terms of the way that the industry has developed.”
Joel de la Garza Mar 1, 2019 ▶ 1:05
Assertion Not checkable as stated
De la Garza: Leaked AWS credentials led to $500K in unauthorized mining
“There's one company that I heard of that checked their credentials for AWS into their GitHub repo on accident, mistake that people make. Within a couple of hours, they had run up about 500,000 dollars of AWS compute charges as people tried to mine Bitcoin.”
Joel de la Garza Mar 1, 2019 ▶ 3:52
Prediction Held up
de la Garza: Ransomware Will Evolve to Target Cloud Infrastructure Data
“On the ransomware space, I think the, one of the interesting things that I've noticed over the last couple of years, we've yet to see a variant of ransomware that modifies your data in the cloud, right? So cloud-aware ransomware it's something that we've heard…”
Joel de la Garza Mar 1, 2019 ▶ 4:25
Assertion Partly supported
de la Garza: AWS Employee Misconfiguration Caused Hosting Provider Data Breach
“There was a hosting provider that had a breach of their data that was caused by an, it was actually an AWS salesperson, had misconfigured the permissions on their S three bucket and had a bunch of customer confidential data inside this bucket, which then got d…”
Joel de la Garza Mar 1, 2019 ▶ 5:03
Assertion Partly supported
De la Garza: Venture capital invested $7.6B in cybersecurity in 2017
“Last year there was about 7.6 billion invested by venture capital firms into cyber security alone.”
Joel de la Garza Mar 1, 2019 ▶ 5:50
Assertion Not checkable as stated
De la Garza: Hiring a junior security engineer takes up to 6 months
“In the Bay Area, it can take upwards of six months to find a junior level security engineer.”
Joel de la Garza Mar 1, 2019 ▶ 6:10
Assertion Partly supported
De la Garza: Phishing and pretexting account for 93% of breaches
“If you actually look at the data and you go to the Verizon breach data, which is usually the basis for a lot of these claims, you see that phishing and pretexting are about 93% of those breaches.”
Joel de la Garza Mar 1, 2019 ▶ 6:38
Assertion Partly supported
De la Garza: Advanced nation-state malware rarely causes breaches
“You don't see sophisticated advanced nation state malware. You don't necessarily see APT in anywhere of the top causes of breaches.”
Joel de la Garza Mar 1, 2019 ▶ 8:18
Opinion
De la Garza: Security industry spending fails to address root causes
“From a spend perspective, the security industry hasn't done a great job when you look at what we spend all of our money on in addressing the actual root causes of the breaches.”
Joel de la Garza Mar 1, 2019 ▶ 8:39
Insight
Joel de la Garza: Most cybersecurity tools solve problems created by other products
“Most products that they build are built to solve problems with other products, right?”
Joel de la Garza Mar 1, 2019 ▶ 10:01
Assertion Not checkable as stated
Joel de la Garza: CISOs deploy Chromebooks to eliminate endpoint antivirus
“So when you talk to some of the more forward-leaning CISOs in large organizations, they're rolling out hundreds or thousands of Chromebooks, right? They don't need to run antivirus on those endpoints.”
Joel de la Garza Mar 1, 2019 ▶ 10:30
Assertion Not checkable as stated
Joel de la Garza: Talent shortage prevents CISOs from trying new security tools
“Finally, the other thing that you'll hear is that security skills shortage is a driving force of what most CISOs do. So you'll, you'll talk to them, you'll try to get them to look at new technology, to consider new alternatives, and they just don't have the bo…”
Joel de la Garza Mar 1, 2019 ▶ 10:54
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.