Jan 2, 2019 · 23m · a16z

a16z Podcast | Cybersecurity in the Boardroom vs. the Situation Room

Herb Lynn · 7m spoken David D'Amato · 5m spoken Sonal Chokshi · 5m spoken Matt Spence · 3m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z podcast, cybersecurity experts and former policy leaders discuss shifting digital security management from national security paradigms to corporate governance. The panel explores semantic definitions, weapon democratization, foundational frameworks like the CIA triad, and practical steps for boardrooms to build resilient security programs.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 24.2% of the talking time here. How this is scored →

The host as informed peer 5.8 Guest teaching 4.7 Guest disagreement 2.7 The host pushing back 4.0
05100:0010:0020:001:01–3:52 · The host as informed peer 5/10 Defining Cybersecurity vs Cyber Space Security Sonal draws thoughtful parallels between weapon gradations and modern digital protest forms like doxing and DDoS attacks. Herb Lynn educates the panel on the precise linguistic and conceptual distinction between cybersecurity as a single word versus cyber space security as two words.3:52–5:59 · The host as informed peer 5/10 Democratization of Cyber Threats and Bits vs Atoms Sonal raises the geopolitical and economic drivers behind Russian hacker activity, prompting David D'Amato to share an industry case study on financially motivated cyber crime. The group collaboratively contrasts state control over physical atoms with the rapid spread of digital bits.5:59–8:36 · The host as informed peer 5/10 Penetration Testing and the Necessity of Basic Hygiene Sonal references penetration testing in pop culture via the film Sneakers and articulates how corporate attribution carries political weight. David D'Amato emphasizes that boardrooms focus too heavily on high-profile nation-state threats rather than fundamental security hygiene.8:36–11:23 · The host as informed peer 6/10 Analyzing Real World Cyber Incidents: Dyn DDoS and Stuxnet Sonal demonstrates domain knowledge by citing Kim Zetter's definitive book on Stuxnet and its physical consequences. Herb Lynn politely corrects her assumption, noting that physical cyber damage had occurred prior to Stuxnet even if Stuxnet was the first widely recognized case.11:23–15:10 · The host as informed peer 7/10 The CIA Triad: Confidentiality, Integrity, and Availability Sonal challenges the effectiveness of threat modeling by pointing out that complex tech systems produce inherently unpredictable outcomes. David D'Amato forcefully refutes her premise, arguing that most cyber attacks reuse predictable, well-known sequences.15:10–20:36 · The host as informed peer 7/10 Network Visibility and the Human Factor in Security Sonal cites PARC research regarding usable security and human factors before engaging in a sharp exchange with Herb Lynn over reputational risk. When Lynn dismisses reputation as a general business risk rather than a cyber-specific issue, Sonal actively counters his framing.1:01–3:52 · Guest teaching 4/10 Defining Cybersecurity vs Cyber Space Security Sonal draws thoughtful parallels between weapon gradations and modern digital protest forms like doxing and DDoS attacks. Herb Lynn educates the panel on the precise linguistic and conceptual distinction between cybersecurity as a single word versus cyber space security as two words.3:52–5:59 · Guest teaching 3/10 Democratization of Cyber Threats and Bits vs Atoms Sonal raises the geopolitical and economic drivers behind Russian hacker activity, prompting David D'Amato to share an industry case study on financially motivated cyber crime. The group collaboratively contrasts state control over physical atoms with the rapid spread of digital bits.5:59–8:36 · Guest teaching 4/10 Penetration Testing and the Necessity of Basic Hygiene Sonal references penetration testing in pop culture via the film Sneakers and articulates how corporate attribution carries political weight. David D'Amato emphasizes that boardrooms focus too heavily on high-profile nation-state threats rather than fundamental security hygiene.8:36–11:23 · Guest teaching 6/10 Analyzing Real World Cyber Incidents: Dyn DDoS and Stuxnet Sonal demonstrates domain knowledge by citing Kim Zetter's definitive book on Stuxnet and its physical consequences. Herb Lynn politely corrects her assumption, noting that physical cyber damage had occurred prior to Stuxnet even if Stuxnet was the first widely recognized case.11:23–15:10 · Guest teaching 6/10 The CIA Triad: Confidentiality, Integrity, and Availability Sonal challenges the effectiveness of threat modeling by pointing out that complex tech systems produce inherently unpredictable outcomes. David D'Amato forcefully refutes her premise, arguing that most cyber attacks reuse predictable, well-known sequences.15:10–20:36 · Guest teaching 5/10 Network Visibility and the Human Factor in Security Sonal cites PARC research regarding usable security and human factors before engaging in a sharp exchange with Herb Lynn over reputational risk. When Lynn dismisses reputation as a general business risk rather than a cyber-specific issue, Sonal actively counters his framing.1:01–3:52 · Guest disagreement 1/10 Defining Cybersecurity vs Cyber Space Security Sonal draws thoughtful parallels between weapon gradations and modern digital protest forms like doxing and DDoS attacks. Herb Lynn educates the panel on the precise linguistic and conceptual distinction between cybersecurity as a single word versus cyber space security as two words.3:52–5:59 · Guest disagreement 1/10 Democratization of Cyber Threats and Bits vs Atoms Sonal raises the geopolitical and economic drivers behind Russian hacker activity, prompting David D'Amato to share an industry case study on financially motivated cyber crime. The group collaboratively contrasts state control over physical atoms with the rapid spread of digital bits.5:59–8:36 · Guest disagreement 2/10 Penetration Testing and the Necessity of Basic Hygiene Sonal references penetration testing in pop culture via the film Sneakers and articulates how corporate attribution carries political weight. David D'Amato emphasizes that boardrooms focus too heavily on high-profile nation-state threats rather than fundamental security hygiene.8:36–11:23 · Guest disagreement 3/10 Analyzing Real World Cyber Incidents: Dyn DDoS and Stuxnet Sonal demonstrates domain knowledge by citing Kim Zetter's definitive book on Stuxnet and its physical consequences. Herb Lynn politely corrects her assumption, noting that physical cyber damage had occurred prior to Stuxnet even if Stuxnet was the first widely recognized case.11:23–15:10 · Guest disagreement 5/10 The CIA Triad: Confidentiality, Integrity, and Availability Sonal challenges the effectiveness of threat modeling by pointing out that complex tech systems produce inherently unpredictable outcomes. David D'Amato forcefully refutes her premise, arguing that most cyber attacks reuse predictable, well-known sequences.15:10–20:36 · Guest disagreement 4/10 Network Visibility and the Human Factor in Security Sonal cites PARC research regarding usable security and human factors before engaging in a sharp exchange with Herb Lynn over reputational risk. When Lynn dismisses reputation as a general business risk rather than a cyber-specific issue, Sonal actively counters his framing.1:01–3:52 · The host pushing back 1/10 Defining Cybersecurity vs Cyber Space Security Sonal draws thoughtful parallels between weapon gradations and modern digital protest forms like doxing and DDoS attacks. Herb Lynn educates the panel on the precise linguistic and conceptual distinction between cybersecurity as a single word versus cyber space security as two words.3:52–5:59 · The host pushing back 1/10 Democratization of Cyber Threats and Bits vs Atoms Sonal raises the geopolitical and economic drivers behind Russian hacker activity, prompting David D'Amato to share an industry case study on financially motivated cyber crime. The group collaboratively contrasts state control over physical atoms with the rapid spread of digital bits.5:59–8:36 · The host pushing back 4/10 Penetration Testing and the Necessity of Basic Hygiene Sonal references penetration testing in pop culture via the film Sneakers and articulates how corporate attribution carries political weight. David D'Amato emphasizes that boardrooms focus too heavily on high-profile nation-state threats rather than fundamental security hygiene.8:36–11:23 · The host pushing back 3/10 Analyzing Real World Cyber Incidents: Dyn DDoS and Stuxnet Sonal demonstrates domain knowledge by citing Kim Zetter's definitive book on Stuxnet and its physical consequences. Herb Lynn politely corrects her assumption, noting that physical cyber damage had occurred prior to Stuxnet even if Stuxnet was the first widely recognized case.11:23–15:10 · The host pushing back 7/10 The CIA Triad: Confidentiality, Integrity, and Availability Sonal challenges the effectiveness of threat modeling by pointing out that complex tech systems produce inherently unpredictable outcomes. David D'Amato forcefully refutes her premise, arguing that most cyber attacks reuse predictable, well-known sequences.15:10–20:36 · The host pushing back 8/10 Network Visibility and the Human Factor in Security Sonal cites PARC research regarding usable security and human factors before engaging in a sharp exchange with Herb Lynn over reputational risk. When Lynn dismisses reputation as a general business risk rather than a cyber-specific issue, Sonal actively counters his framing.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 40.3% · guest 59.7%0:00 · the host 40.3% · guest 59.7%3:00 · the host 28.5% · guest 71.5%3:00 · the host 28.5% · guest 71.5%6:00 · the host 18.8% · guest 81.2%6:00 · the host 18.8% · guest 81.2%9:00 · the host 19.8% · guest 80.2%9:00 · the host 19.8% · guest 80.2%12:00 · the host 24.5% · guest 75.5%12:00 · the host 24.5% · guest 75.5%15:00 · the host 16.2% · guest 83.8%15:00 · the host 16.2% · guest 83.8%18:00 · the host 22.9% · guest 77.1%18:00 · the host 22.9% · guest 77.1%21:00 · the host 22.5% · guest 77.5%21:00 · the host 22.5% · guest 77.5%
Sharpest disagreement ▶ 14:48 David D'Amato Rejects Unpredictability Premise

D'Amato directly refutes Sonal's argument that complex tech threats are unpredictable, explicitly stating that attacks rely on repeatable, predictable steps rather than entirely novel methods.

Hardest push from the host ▶ 19:36 Sonal Counters Herb Lynn on Reputational Risk

When Herb Lynn argues that reputational damage is a standard business risk exemplified by Tylenol rather than a cyber issue, Sonal explicitly refuses his framing and argues that diffuse digital attackers make cyber reputation management uniquely difficult.

Biggest teaching moment ▶ 10:18 Herb Lynn Corrects Sonal on Stuxnet History

After Sonal asserts that Stuxnet was the first case where computer malware caused physical consequences, Herb Lynn corrects her historical framing by explaining that earlier attacks had caused physical damage.

The host holds their own ▶ 13:49 Sonal Applies Complex Systems Theory to Tech Evolution

Sonal demonstrates strong conceptual authority by linking historical military analogies to complex modern systems like Facebook's data ecosystem, challenging the guests' framing of threat modeling.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Defining Cybersecurity vs Cyber Space Security 5411 Sonal draws thoughtful parallels between weapon gradations and modern digital protest forms like doxing and DDoS attacks. Herb Lynn educates the panel on the precise linguistic and conceptual distinction between cybersecurity as a single word versus cyber space security as two words.
Democratization of Cyber Threats and Bits vs Atoms 5311 Sonal raises the geopolitical and economic drivers behind Russian hacker activity, prompting David D'Amato to share an industry case study on financially motivated cyber crime. The group collaboratively contrasts state control over physical atoms with the rapid spread of digital bits.
Penetration Testing and the Necessity of Basic Hygiene 5424 Sonal references penetration testing in pop culture via the film Sneakers and articulates how corporate attribution carries political weight. David D'Amato emphasizes that boardrooms focus too heavily on high-profile nation-state threats rather than fundamental security hygiene.
Analyzing Real World Cyber Incidents: Dyn DDoS and Stuxnet 6633 Sonal demonstrates domain knowledge by citing Kim Zetter's definitive book on Stuxnet and its physical consequences. Herb Lynn politely corrects her assumption, noting that physical cyber damage had occurred prior to Stuxnet even if Stuxnet was the first widely recognized case.
The CIA Triad: Confidentiality, Integrity, and Availability 7657 Sonal challenges the effectiveness of threat modeling by pointing out that complex tech systems produce inherently unpredictable outcomes. David D'Amato forcefully refutes her premise, arguing that most cyber attacks reuse predictable, well-known sequences.
Network Visibility and the Human Factor in Security 7548 Sonal cites PARC research regarding usable security and human factors before engaging in a sharp exchange with Herb Lynn over reputational risk. When Lynn dismisses reputation as a general business risk rather than a cyber-specific issue, Sonal actively counters his framing.

Statements from this episode (20)

Opinion
Chokshi: Only policy people and funding seekers use the term 'cyber'
“I feel like only policy people actually say cyber, and people trying to get research funding.”
Sonal Chokshi Jan 2, 2019 ▶ 0:47
Opinion
Chokshi: Cybersecurity is like synergy—a hated but necessary term
“This is like that word synergy, where it's like a really useful word, but everyone hates it, and there's no better alternative.”
Sonal Chokshi Jan 2, 2019 ▶ 0:55
Insight
Lynn: Cyber weapons span a continuum from mild annoyances to total destruction
“There has been a trend away from weapons that have a very large boom to weapons that have a much smaller boom. And there's a sense in which cyber weapons can do something with, just do an annoyance to somebody, to something that might, you know, destroy the en…”
Herb Lynn Jan 2, 2019 ▶ 2:44
Assertion Not checkable as stated
Lynn: Nations increasingly recognize the high operational utility of cyber weapons
“Cyber weapons are the, are weapons that are eminently usable for a variety of purposes. And one of the most interesting things of the past 10 years is that nations are starting to wake up to this. They're starting to see that these weapons are enormously usabl…”
Herb Lynn Jan 2, 2019 ▶ 3:33
Disclosure
D'Amato: Non-state criminals stole $10 million from a bank overnight in 2010
“One of the first cases I ever worked on back in 2010 was a bank that lost about ten million dollars overnight. It's a gang of criminals who were loosely affiliated with each other, who had a reasonable set of skills from their computer science degrees, from th…”
David D'Amato Jan 2, 2019 ▶ 4:42
Assertion Not checkable as stated
D'Amato: Penetration testers breached top secure facilities in under two hours
“I'll be honest with you, I was not very good, but within about a week or less, I think my best was about two hours, we were able to break into some of the most secure locations in the world. Physically and Based on information technology.”
David D'Amato Jan 2, 2019 ▶ 6:11
Opinion
D'Amato: Corporate board focus on China and Russia is a distraction
“They're simply really interested in things that are in the news. So if you look at things like China and Russia that don't impact most organizations, they want to know who's attacking and where they're from, what they're doing. And to be honest with you, that'…”
David D'Amato Jan 2, 2019 ▶ 7:21
Opinion
D'Amato: Cyber attack attribution does not matter for private corporations
“And for most organizations, the attribution doesn't matter. For the government, it absolutely matters. But as a corporation, what will you be able to do? You're not going to be able to hack back that, that country.”
David D'Amato Jan 2, 2019 ▶ 7:50
Assertion Supported
Lynn: Stuxnet was not the first malware causing physical damage
“It did have physical consequences. It was certainly not by any means the first time.”
Herb Lynn Jan 2, 2019 ▶ 10:19
Assertion Not checkable as stated
Lynn: Stuxnet alerted nation-states to physical cyber attacks
“I was totally wrong about that, because what it did was it woke states up, policymakers up, to the possibility that this was a possible, feasible thing to do.”
Herb Lynn Jan 2, 2019 ▶ 10:40
Insight
D'Amato: Integrity attacks are most devastating because they go undetected
“And integrity tends to be one of the most devastating attacks, because you typically don't know what's happened.”
David D'Amato Jan 2, 2019 ▶ 12:34
Assertion Partly supported
D'Amato: Google was the first company to publicly disclose Chinese cyberattacks
“If you walk through the timeline, you go back and start with Google in 2010, when they're the first company to come out and actually talk about Chinese state-sponsored actors. This is something the government and a lot of people knew about at the time. And it'…”
David D'Amato Jan 2, 2019 ▶ 13:11
Insight
D'Amato: Most steps in a cyberattack reuse familiar tactics
“An attack isn't made up of one action. It's usually made up of multiple actions. And so what you may see is one different action in that attack, and probably multiple, maybe 10 or 12 of the steps that you've seen in previous attacks. So in most cases, you're l…”
David D'Amato Jan 2, 2019 ▶ 14:52
Assertion Not checkable as stated
D'Amato: Cyber attackers often understand target networks better than defenders
“Most organizations don't really understand their own organization, their environment, and that in many cases, attackers understand the environment much better than the defenders do.”
David D'Amato Jan 2, 2019 ▶ 15:36
Assertion Not checkable as stated
D'Amato: Chief Security Officers commonly do not know their endpoint count
“When I asked them how many systems they had in their organization, how many endpoints they had, computers and servers and things like that, They had no idea. So that's pretty common.”
David D'Amato Jan 2, 2019 ▶ 15:58
Insight
Chokshi: Human error and psychology are always system breakpoints
“The fundamental breakpoint in any system will always be the human, the error, you know, the psychology of a person and the details related to that.”
Sonal Chokshi Jan 2, 2019 ▶ 16:36
Insight
D'Amato: Cyber attackers face no accountability, enabling endless retries
“As an attacker, I can keep trying my attack as many times as I want. So every time you catch me, I simply restart my attack because there is no accountability.”
David D'Amato Jan 2, 2019 ▶ 16:49
Insight
Spence: Advanced cyber threats are not the main threat most companies face
“The cyber conversations that often happen in this situation are more of the fad diet. You know, they're dealing with the most advanced threats to companies right now, and those frankly aren't the major threats that most companies need to deal with.”
Matt Spence Jan 2, 2019 ▶ 18:01
Assertion Supported
D'Amato: No standardized cybersecurity reporting framework exists for corporate boards
“There should be, and the challenge is right now there's no standardized way to report information to the board.”
David D'Amato Jan 2, 2019 ▶ 18:15
Insight
Lynn: Reputational damage from cyber breaches is not unique
“What I was saying is that it's not new to cyber. ... No matter whatever stupid thing you do, it damages your brand.”
Herb Lynn Jan 2, 2019 ▶ 19:26
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.