Jan 2, 2019 · 19m · a16z

a16z Podcast | Changing the Conversation about Cybersecurity

Nathaniel Gleicher · 5m spoken Matthew Olson · 5m spoken Martin Casado · 3m spoken Matt Spence · 3m spoken Sonal Chokshi · 25s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this live episode of the a16z podcast recorded at the Tech Policy Summit, experts Matt Spence, Martine Casado, Nathaniel Gleicher, and Matthew Olson discuss modern cybersecurity strategy, debunking hype around apocalyptic cyber attacks while exploring holistic defense frameworks, identity authentication, and government-tech relations.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 2.2 Guest teaching 5.7 Guest disagreement 2.3 The host pushing back 0.5
05100:0010:000:25–2:47 · The host as informed peer 2/10 Assessing Threat Inflation in Cyberspace Matt Spence prompts Matthew Olson on national cyber threat prioritization. Olson draws on his Situation Room experience to explain threat inflation and asymmetric risk, concluding with a slightly pessimistic counter-perspective.2:47–6:00 · The host as informed peer 2/10 Misconceptions and Low-Grade Cyber Threats Nathaniel Gleicher uses historical parallels to explain that cybersecurity techniques have not changed fundamentally since the 1980s. He directly debunks a widely circulated stat about small business failure rates following cyberattacks.6:00–8:07 · The host as informed peer 2/10 Washington's Holistic View of Infrastructure Security When Spence asks what Washington gets wrong about cybersecurity, Martin Casado directly rejects the question's premise. Casado argues that Washington actually gets it right by taking a holistic view of national infrastructure.8:07–10:58 · The host as informed peer 2/10 Secret Service Analogy for Network Defense Gleicher critiques common analogies like nuclear deterrence and explains why the Secret Service perimeter defense model is far more accurate for network security.10:58–14:44 · The host as informed peer 3/10 Physical World Integration and Identity Authentication Spence steers the topic toward password alternatives. Casado delivers a detailed technical breakdown of how physical smartphone sensors can be leveraged for cyber identity authentication.14:44–17:32 · The host as informed peer 2/10 Historical Cycles and Optimism in Cybersecurity The panel discusses reasons for optimism. Gleicher draws comparisons to historical defense cycles such as gunpowder and armor, while Olson discusses post-Snowden trust recovery between government and tech.0:25–2:47 · Guest teaching 4/10 Assessing Threat Inflation in Cyberspace Matt Spence prompts Matthew Olson on national cyber threat prioritization. Olson draws on his Situation Room experience to explain threat inflation and asymmetric risk, concluding with a slightly pessimistic counter-perspective.2:47–6:00 · Guest teaching 7/10 Misconceptions and Low-Grade Cyber Threats Nathaniel Gleicher uses historical parallels to explain that cybersecurity techniques have not changed fundamentally since the 1980s. He directly debunks a widely circulated stat about small business failure rates following cyberattacks.6:00–8:07 · Guest teaching 6/10 Washington's Holistic View of Infrastructure Security When Spence asks what Washington gets wrong about cybersecurity, Martin Casado directly rejects the question's premise. Casado argues that Washington actually gets it right by taking a holistic view of national infrastructure.8:07–10:58 · Guest teaching 6/10 Secret Service Analogy for Network Defense Gleicher critiques common analogies like nuclear deterrence and explains why the Secret Service perimeter defense model is far more accurate for network security.10:58–14:44 · Guest teaching 6/10 Physical World Integration and Identity Authentication Spence steers the topic toward password alternatives. Casado delivers a detailed technical breakdown of how physical smartphone sensors can be leveraged for cyber identity authentication.14:44–17:32 · Guest teaching 5/10 Historical Cycles and Optimism in Cybersecurity The panel discusses reasons for optimism. Gleicher draws comparisons to historical defense cycles such as gunpowder and armor, while Olson discusses post-Snowden trust recovery between government and tech.0:25–2:47 · Guest disagreement 2/10 Assessing Threat Inflation in Cyberspace Matt Spence prompts Matthew Olson on national cyber threat prioritization. Olson draws on his Situation Room experience to explain threat inflation and asymmetric risk, concluding with a slightly pessimistic counter-perspective.2:47–6:00 · Guest disagreement 3/10 Misconceptions and Low-Grade Cyber Threats Nathaniel Gleicher uses historical parallels to explain that cybersecurity techniques have not changed fundamentally since the 1980s. He directly debunks a widely circulated stat about small business failure rates following cyberattacks.6:00–8:07 · Guest disagreement 6/10 Washington's Holistic View of Infrastructure Security When Spence asks what Washington gets wrong about cybersecurity, Martin Casado directly rejects the question's premise. Casado argues that Washington actually gets it right by taking a holistic view of national infrastructure.8:07–10:58 · Guest disagreement 1/10 Secret Service Analogy for Network Defense Gleicher critiques common analogies like nuclear deterrence and explains why the Secret Service perimeter defense model is far more accurate for network security.10:58–14:44 · Guest disagreement 1/10 Physical World Integration and Identity Authentication Spence steers the topic toward password alternatives. Casado delivers a detailed technical breakdown of how physical smartphone sensors can be leveraged for cyber identity authentication.14:44–17:32 · Guest disagreement 1/10 Historical Cycles and Optimism in Cybersecurity The panel discusses reasons for optimism. Gleicher draws comparisons to historical defense cycles such as gunpowder and armor, while Olson discusses post-Snowden trust recovery between government and tech.0:25–2:47 · The host pushing back 2/10 Assessing Threat Inflation in Cyberspace Matt Spence prompts Matthew Olson on national cyber threat prioritization. Olson draws on his Situation Room experience to explain threat inflation and asymmetric risk, concluding with a slightly pessimistic counter-perspective.2:47–6:00 · The host pushing back 0/10 Misconceptions and Low-Grade Cyber Threats Nathaniel Gleicher uses historical parallels to explain that cybersecurity techniques have not changed fundamentally since the 1980s. He directly debunks a widely circulated stat about small business failure rates following cyberattacks.6:00–8:07 · The host pushing back 1/10 Washington's Holistic View of Infrastructure Security When Spence asks what Washington gets wrong about cybersecurity, Martin Casado directly rejects the question's premise. Casado argues that Washington actually gets it right by taking a holistic view of national infrastructure.8:07–10:58 · The host pushing back 0/10 Secret Service Analogy for Network Defense Gleicher critiques common analogies like nuclear deterrence and explains why the Secret Service perimeter defense model is far more accurate for network security.10:58–14:44 · The host pushing back 0/10 Physical World Integration and Identity Authentication Spence steers the topic toward password alternatives. Casado delivers a detailed technical breakdown of how physical smartphone sensors can be leveraged for cyber identity authentication.14:44–17:32 · The host pushing back 0/10 Historical Cycles and Optimism in Cybersecurity The panel discusses reasons for optimism. Gleicher draws comparisons to historical defense cycles such as gunpowder and armor, while Olson discusses post-Snowden trust recovery between government and tech.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 6:31 Casado Directly Refutes Host Premise

Casado openly rejects Spence's prompt about what Washington gets wrong, stating that government actually takes the right holistic perspective compared to private industry.

Hardest push from the host ▶ 2:42 Host Threat Inflation Counter

Spence interjects to counter Olson's pessimistic view, pointing out that over-inflating threats renders all warning systems ineffective.

Biggest teaching moment ▶ 4:15 Gleicher Exposes Fabricated Cyber Metric

Gleicher dismantles a standard congressional cybersecurity metric regarding small business bankruptcy, demonstrating it has no factual basis.

The host holds their own ▶ 2:42 Spence's Policy Insight on Threat Inflation

Spence asserts high-level policy expertise by citing the classic risk assessment paradigm that if everything is classified as a threat, nothing is.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Assessing Threat Inflation in Cyberspace 2422 Matt Spence prompts Matthew Olson on national cyber threat prioritization. Olson draws on his Situation Room experience to explain threat inflation and asymmetric risk, concluding with a slightly pessimistic counter-perspective.
Misconceptions and Low-Grade Cyber Threats 2730 Nathaniel Gleicher uses historical parallels to explain that cybersecurity techniques have not changed fundamentally since the 1980s. He directly debunks a widely circulated stat about small business failure rates following cyberattacks.
Washington's Holistic View of Infrastructure Security 2661 When Spence asks what Washington gets wrong about cybersecurity, Martin Casado directly rejects the question's premise. Casado argues that Washington actually gets it right by taking a holistic view of national infrastructure.
Secret Service Analogy for Network Defense 2610 Gleicher critiques common analogies like nuclear deterrence and explains why the Secret Service perimeter defense model is far more accurate for network security.
Physical World Integration and Identity Authentication 3610 Spence steers the topic toward password alternatives. Casado delivers a detailed technical breakdown of how physical smartphone sensors can be leveraged for cyber identity authentication.
Historical Cycles and Optimism in Cybersecurity 2510 The panel discusses reasons for optimism. Gleicher draws comparisons to historical defense cycles such as gunpowder and armor, while Olson discusses post-Snowden trust recovery between government and tech.

Statements from this episode (11)

Assertion Not checkable as stated
Olson: Public cybersecurity discussions suffer from threat inflation and imprecise risk assessment
“I do think we face a bit of inflation about the nature of the threat, or at least a little bit of lack of care in talking about the threat.”
Matthew Olson Jan 2, 2019 ▶ 1:32
Assertion Not checkable as stated
Olson: Small non-state groups now possess former nation-state cyber attack capabilities
“We see individual small groups of people, as you said, gaining the capabilities of what were nation state capabilities in terms of the ability to carry out attacks from just a few years ago.”
Matthew Olson Jan 2, 2019 ▶ 2:23
Assertion Supported
Gleicher: The statistic that 60% of cyberattacked small businesses fail is baseless
“There's a statistic that's been going around. It was used in a couple of cybersecurity bills recently. It was used on the Hill. And the statistic is, 60% of small businesses that get targeted with a cyber attack go out of business within six months. And in cas…”
Nathaniel Gleicher Jan 2, 2019 ▶ 4:28
Insight
Gleicher: The primary cyber threat is persistent trust degradation, not catastrophic attacks
“We tend to imagine that getting inside is the big problem, and that once they get inside, there's this risk of this big, massive institution-ending event, and that is certainly possible. But much more frequent is the steady, low-grade degradation of trust in t…”
Nathaniel Gleicher Jan 2, 2019 ▶ 5:15
Opinion
Casado: Washington gets cybersecurity right by taking a holistic critical infrastructure view
“Actually, I think Washington is kind of what gets it right, actually, like, believe it or not, like, maybe not the response you're getting, and the reason is because they take a holistic view to cybersecurity, and I think that's what we should all do.”
Martin Casado Jan 2, 2019 ▶ 6:31
Insight
Gleicher: Nuclear deterrence is a flawed analogy for cybersecurity threats
“Nuclear deterrence is built around the model of a sovereignty ending massive event as opposed to constant low-grade threat. It really doesn't map very well.”
Nathaniel Gleicher Jan 2, 2019 ▶ 8:46
Insight
Gleicher: High impermeable perimeter security fails because defenders hold internal strategic advantages
“A very high impermeable perimeter doesn't work. And in fact, at the perimeter, the defender has the greatest disadvantage. The intruder can keep trying to get over it. Once the intruder gets over the fence and into your environment, they're in an environment t…”
Nathaniel Gleicher Jan 2, 2019 ▶ 9:24
Assertion Supported
Casado: Companies can accurately identify individuals by their smartphone accelerometer gait data
“There are companies that can detect very, very accurately who you are by how you walk just using the accelerometer in your pocket.”
Martin Casado Jan 2, 2019 ▶ 13:47
Assertion Supported
Casado: Companies can map rooms using iPhone speakers and microphones via sonar
“There are companies that will take, if you have your phone out, what they'll do is they will use the speaker to send out like a hypersonic Sound that you can't hear, then, sorry, they use the microphone, the speaker to do that, and they use the microphone to c…”
Martin Casado Jan 2, 2019 ▶ 13:54
Prediction Not checkable as stated
Casado: Single-factor authentication will persist long-term despite MFA usability growth
“I think it's going to be a long time before we get rid of any single factor, but I do think that we're seeing multi-factor authentication. That means I try multiple things, like I will do the password, and I will determine where you're coming from and so I act…”
Martin Casado Jan 2, 2019 ▶ 14:52
Prediction Not checkable as stated
Gleicher: Cybersecurity defenders will eventually balance out attacker advantages
“If you look historically at technologies that have upended conflict and made it much easier to be an attacker than a defender, there are any number of these throughout history, from armor in World War II to gunpowder in sort of the 16th century in Europe, and …”
Nathaniel Gleicher Jan 2, 2019 ▶ 16:48
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.