Jan 2, 2019 · 30m · a16z

a16z Podcast | Making Security More Useable

Vijay Balasubramaniyan · 12m spoken Todd McKinnon · 11m spoken Michael Copeland · 5m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, host Michael Copeland speaks with Okta CEO Todd McKinnon and Pindrop CEO Vijay Balasubramanian about how modern enterprises can balance robust cybersecurity with seamless user experience. The discussion covers evolving threat landscapes, executive risk management, voice biometrics, and strategies for making security an intuitive, foundational part of organizational culture.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 2.3 Guest teaching 3.4 Guest disagreement 0.6 The host pushing back 0.6
05100:0010:0020:0030:000:53–2:55 · The host as informed peer 2/10 The Changing Threat Landscape and C-Suite Focus Host Michael Copeland frames the opening topic around high-profile corporate security breaches. Todd and Vijay explain how C-suite and board-level vigilance has drastically heightened in response to target attacks like Sony and Target.2:55–4:56 · The host as informed peer 2/10 Aligning Business Operations with Security Requirements Host asks how organizations balance operational speed with security posture. The guests outline how security purchasing power is shifting to higher executive tiers and global fraud functions.4:56–8:20 · The host as informed peer 3/10 Driving Security Adoption and Developer Training Host offers a metaphor about security access yielding the 'full burrito,' which Todd humorously clarifies. Vijay contributes insights into grassroots developer training and call center verification usability.8:20–13:03 · The host as informed peer 2/10 Consumer Tech Design Cues in Enterprise Security Host inquires about usability philosophies across different interfaces. Guests detail consumer security cues like TouchID and explain biometric voice tracking and contextual metadata in Pindrop.13:03–19:05 · The host as informed peer 3/10 Okta's Identity Graph and Contextual Access Control Host prompts about securing physical assets and addresses human failure in breaches. Todd and Vijay educate on least-privilege access model enforcement and logging monitoring.19:05–21:25 · The host as informed peer 2/10 Executive Mindsets and Internal Breach Detection Host asks if enterprise leadership assumes bad actors are already inside. Todd highlights a sharp disconnect where CISO teams assume breaches while CEOs falsely believe they are untouched.21:25–23:50 · The host as informed peer 2/10 Tiered Information Sensitivity and Proactive Security Host asks how policy can remain flexible yet proactive. Vijay illustrates overreaction risks with an anecdote about a client locking down a non-sensitive proof of concept post-Target breach.23:50–26:45 · The host as informed peer 3/10 Redefining Security Success and Cross-Industry Defense Host asks if security is a winnable game or the wrong question entirely. Vijay explicitly rejects the 'cat and mouse' cliché, reframing the dynamic as a much tougher 'cat and dog' struggle.26:45–30:29 · The host as informed peer 2/10 The Future of Security and Episode Conclusion Host concludes by asking about the future user experience. Vijay humorously teases the host about finding personal information online, followed by warm wrap-up pleasantries.0:53–2:55 · Guest teaching 2/10 The Changing Threat Landscape and C-Suite Focus Host Michael Copeland frames the opening topic around high-profile corporate security breaches. Todd and Vijay explain how C-suite and board-level vigilance has drastically heightened in response to target attacks like Sony and Target.2:55–4:56 · Guest teaching 3/10 Aligning Business Operations with Security Requirements Host asks how organizations balance operational speed with security posture. The guests outline how security purchasing power is shifting to higher executive tiers and global fraud functions.4:56–8:20 · Guest teaching 3/10 Driving Security Adoption and Developer Training Host offers a metaphor about security access yielding the 'full burrito,' which Todd humorously clarifies. Vijay contributes insights into grassroots developer training and call center verification usability.8:20–13:03 · Guest teaching 4/10 Consumer Tech Design Cues in Enterprise Security Host inquires about usability philosophies across different interfaces. Guests detail consumer security cues like TouchID and explain biometric voice tracking and contextual metadata in Pindrop.13:03–19:05 · Guest teaching 3/10 Okta's Identity Graph and Contextual Access Control Host prompts about securing physical assets and addresses human failure in breaches. Todd and Vijay educate on least-privilege access model enforcement and logging monitoring.19:05–21:25 · Guest teaching 4/10 Executive Mindsets and Internal Breach Detection Host asks if enterprise leadership assumes bad actors are already inside. Todd highlights a sharp disconnect where CISO teams assume breaches while CEOs falsely believe they are untouched.21:25–23:50 · Guest teaching 3/10 Tiered Information Sensitivity and Proactive Security Host asks how policy can remain flexible yet proactive. Vijay illustrates overreaction risks with an anecdote about a client locking down a non-sensitive proof of concept post-Target breach.23:50–26:45 · Guest teaching 5/10 Redefining Security Success and Cross-Industry Defense Host asks if security is a winnable game or the wrong question entirely. Vijay explicitly rejects the 'cat and mouse' cliché, reframing the dynamic as a much tougher 'cat and dog' struggle.26:45–30:29 · Guest teaching 4/10 The Future of Security and Episode Conclusion Host concludes by asking about the future user experience. Vijay humorously teases the host about finding personal information online, followed by warm wrap-up pleasantries.0:53–2:55 · Guest disagreement 0/10 The Changing Threat Landscape and C-Suite Focus Host Michael Copeland frames the opening topic around high-profile corporate security breaches. Todd and Vijay explain how C-suite and board-level vigilance has drastically heightened in response to target attacks like Sony and Target.2:55–4:56 · Guest disagreement 0/10 Aligning Business Operations with Security Requirements Host asks how organizations balance operational speed with security posture. The guests outline how security purchasing power is shifting to higher executive tiers and global fraud functions.4:56–8:20 · Guest disagreement 1/10 Driving Security Adoption and Developer Training Host offers a metaphor about security access yielding the 'full burrito,' which Todd humorously clarifies. Vijay contributes insights into grassroots developer training and call center verification usability.8:20–13:03 · Guest disagreement 0/10 Consumer Tech Design Cues in Enterprise Security Host inquires about usability philosophies across different interfaces. Guests detail consumer security cues like TouchID and explain biometric voice tracking and contextual metadata in Pindrop.13:03–19:05 · Guest disagreement 0/10 Okta's Identity Graph and Contextual Access Control Host prompts about securing physical assets and addresses human failure in breaches. Todd and Vijay educate on least-privilege access model enforcement and logging monitoring.19:05–21:25 · Guest disagreement 0/10 Executive Mindsets and Internal Breach Detection Host asks if enterprise leadership assumes bad actors are already inside. Todd highlights a sharp disconnect where CISO teams assume breaches while CEOs falsely believe they are untouched.21:25–23:50 · Guest disagreement 0/10 Tiered Information Sensitivity and Proactive Security Host asks how policy can remain flexible yet proactive. Vijay illustrates overreaction risks with an anecdote about a client locking down a non-sensitive proof of concept post-Target breach.23:50–26:45 · Guest disagreement 3/10 Redefining Security Success and Cross-Industry Defense Host asks if security is a winnable game or the wrong question entirely. Vijay explicitly rejects the 'cat and mouse' cliché, reframing the dynamic as a much tougher 'cat and dog' struggle.26:45–30:29 · Guest disagreement 1/10 The Future of Security and Episode Conclusion Host concludes by asking about the future user experience. Vijay humorously teases the host about finding personal information online, followed by warm wrap-up pleasantries.0:53–2:55 · The host pushing back 0/10 The Changing Threat Landscape and C-Suite Focus Host Michael Copeland frames the opening topic around high-profile corporate security breaches. Todd and Vijay explain how C-suite and board-level vigilance has drastically heightened in response to target attacks like Sony and Target.2:55–4:56 · The host pushing back 1/10 Aligning Business Operations with Security Requirements Host asks how organizations balance operational speed with security posture. The guests outline how security purchasing power is shifting to higher executive tiers and global fraud functions.4:56–8:20 · The host pushing back 1/10 Driving Security Adoption and Developer Training Host offers a metaphor about security access yielding the 'full burrito,' which Todd humorously clarifies. Vijay contributes insights into grassroots developer training and call center verification usability.8:20–13:03 · The host pushing back 0/10 Consumer Tech Design Cues in Enterprise Security Host inquires about usability philosophies across different interfaces. Guests detail consumer security cues like TouchID and explain biometric voice tracking and contextual metadata in Pindrop.13:03–19:05 · The host pushing back 1/10 Okta's Identity Graph and Contextual Access Control Host prompts about securing physical assets and addresses human failure in breaches. Todd and Vijay educate on least-privilege access model enforcement and logging monitoring.19:05–21:25 · The host pushing back 0/10 Executive Mindsets and Internal Breach Detection Host asks if enterprise leadership assumes bad actors are already inside. Todd highlights a sharp disconnect where CISO teams assume breaches while CEOs falsely believe they are untouched.21:25–23:50 · The host pushing back 0/10 Tiered Information Sensitivity and Proactive Security Host asks how policy can remain flexible yet proactive. Vijay illustrates overreaction risks with an anecdote about a client locking down a non-sensitive proof of concept post-Target breach.23:50–26:45 · The host pushing back 2/10 Redefining Security Success and Cross-Industry Defense Host asks if security is a winnable game or the wrong question entirely. Vijay explicitly rejects the 'cat and mouse' cliché, reframing the dynamic as a much tougher 'cat and dog' struggle.26:45–30:29 · The host pushing back 0/10 The Future of Security and Episode Conclusion Host concludes by asking about the future user experience. Vijay humorously teases the host about finding personal information online, followed by warm wrap-up pleasantries.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%30:00 · the host 0% · guest 100%30:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 24:54 Rejection of cat-and-mouse cliché

Vijay directly corrects the conventional premise by asserting that cybersecurity is not a cat-and-mouse game where attackers are weak, but a harder cat-and-dog struggle.

Hardest push from the host ▶ 23:50 Questioning victory condition premise

Host explicitly pushes back on standard victory narrative by asking whether 'winning' is even the right question to ask in modern cybersecurity defense.

Biggest teaching moment ▶ 20:34 Executive expectation disconnect

Todd educates the host on the operational gap between CISOs who assume active internal breaches and CEOs who naively assume their company is untouched.

The host holds their own ▶ 14:33 Citing TouchID mainstream adoption

Host grounds the usability trade-off discussion by bringing up Apple's iPhone fingerprint scanner as a tangible model for enterprise adoption.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
The Changing Threat Landscape and C-Suite Focus 2200 Host Michael Copeland frames the opening topic around high-profile corporate security breaches. Todd and Vijay explain how C-suite and board-level vigilance has drastically heightened in response to target attacks like Sony and Target.
Aligning Business Operations with Security Requirements 2301 Host asks how organizations balance operational speed with security posture. The guests outline how security purchasing power is shifting to higher executive tiers and global fraud functions.
Driving Security Adoption and Developer Training 3311 Host offers a metaphor about security access yielding the 'full burrito,' which Todd humorously clarifies. Vijay contributes insights into grassroots developer training and call center verification usability.
Consumer Tech Design Cues in Enterprise Security 2400 Host inquires about usability philosophies across different interfaces. Guests detail consumer security cues like TouchID and explain biometric voice tracking and contextual metadata in Pindrop.
Okta's Identity Graph and Contextual Access Control 3301 Host prompts about securing physical assets and addresses human failure in breaches. Todd and Vijay educate on least-privilege access model enforcement and logging monitoring.
Executive Mindsets and Internal Breach Detection 2400 Host asks if enterprise leadership assumes bad actors are already inside. Todd highlights a sharp disconnect where CISO teams assume breaches while CEOs falsely believe they are untouched.
Tiered Information Sensitivity and Proactive Security 2300 Host asks how policy can remain flexible yet proactive. Vijay illustrates overreaction risks with an anecdote about a client locking down a non-sensitive proof of concept post-Target breach.
Redefining Security Success and Cross-Industry Defense 3532 Host asks if security is a winnable game or the wrong question entirely. Vijay explicitly rejects the 'cat and mouse' cliché, reframing the dynamic as a much tougher 'cat and dog' struggle.
The Future of Security and Episode Conclusion 2410 Host concludes by asking about the future user experience. Vijay humorously teases the host about finding personal information online, followed by warm wrap-up pleasantries.

Statements from this episode (16)

Insight
Balasubramanian: New technologies without built-in security fail instantly against basic fraud
“A lot of, you know, new technologies, when they get introduced without security paradigms in place, they immediately break at the basic onslaught of a fraudster.”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 2:00
Assertion Not checkable as stated
McKinnon: Board cybersecurity focus spiked recently while CISO concern remained consistent
“One of the things that we've seen, it's the people that are chief security officers, or security professionals, or even CIOs, their level of vigilance and their level of concern about this over the last 18 months is pretty consistent. What's clearly changed is…”
Todd McKinnon Jan 2, 2019 ▶ 2:10
Assertion Not checkable as stated
McKinnon: Security, not ease of use, now drives Okta enterprise deals
“So maybe two years ago was more we were being brought in because it made it easier, and now more often we're being brought in because it makes it more secure often from higher people in the organization.”
Todd McKinnon Jan 2, 2019 ▶ 3:50
Insight
McKinnon: Forcing inconvenient security protocols on end-users is a losing battle
“I think it's an uphill battle to try to get, especially in the modern era of IT, to try to get users to do something that is inconvenient or out of band. I think that, and what we see in our customer base and the prospect base that Companies in IT departments …”
Todd McKinnon Jan 2, 2019 ▶ 5:22
Insight
Balasubramanian: Security must become as fundamental to developers as scalability
“Most people, when they talk about, okay, when we put the solution, it shouldn't break as soon as we have 100,000 users hitting the site, right? It's a, it's ingrained in everybody's mind that you need performance, scalable code. What we need to do is add to th…”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 7:56
Assertion Supported
McKinnon: Apple Touch ID dramatically increased iPhone passcode adoption rates
“They've turned on passcodes and more people are, have their phones locked now than ever before because they made it easier. You didn't have to type in that code and now they have a fingerprint reader.”
Todd McKinnon Jan 2, 2019 ▶ 9:01
Assertion Partly supported
Balasubramanian: Pindrop verifies identity using voice emotion, urgency, and device fingerprints
“We look at a variety of things, right? We look at your voice. We look at the device that you're coming from, and, you know, the fingerprint that's, ah, inbuilt into it through a variety of ways. We look at things that your voice is doing. Emotion, duress, urge…”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 11:27
Insight
McKinnon: Enterprise IoT security must anchor to individual human identities
“And ultimately, it's going to go back to a person. The person's going to want to consume the data or understand where that asset is, and that's why we think that having that logical map all the way back to the person is very valuable.”
Todd McKinnon Jan 2, 2019 ▶ 14:49
Insight
Balasubramanian: Gaining network or personnel access is simple for motivated fraudsters
“Getting access to the network or getting access to a person within an organization is really, really simple for a motivated fraudster.”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 16:43
Assertion Not checkable as stated
McKinnon: Major security breaches are usually caused by simple administrative errors
“If you look a lot of these cases, ah, these breaches, it was, Very basic things that were used or problems that were used to take advantage of these networks or these systems, and it was just simple stuff that wasn't cleaned up.”
Todd McKinnon Jan 2, 2019 ▶ 17:46
Assertion Not checkable as stated
Balasubramanian: Enterprise customers now operate under the assumption they are breached
“Yeah, I think, you know, whoever we talk to makes the assumption that they've been breached. They've been breached, ah, they have to have great monitoring systems to understand the extent of the breach, you know, what's, what's going out, right?”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 19:18
Assertion Not checkable as stated
McKinnon: Unlike CISOs, corporate boards still assume they have not been breached
“What we see is that, that, like earlier, I was talking about the CEO board level and then CIO chief security officer, We see that the CIOs and the chief security officers, they understand that, that they've likely been breached and they're very into monitoring…”
Todd McKinnon Jan 2, 2019 ▶ 20:34
Insight
McKinnon: Enterprise security requires tiered data classification to balance risk and speed
“I think companies need to have that kind of framework. Maybe not that formal, but they have to define what's super sensitive, lock that down in a way that's commensurate with the sensitivity of the information, and then think of it like concentric rings outsid…”
Todd McKinnon Jan 2, 2019 ▶ 22:13
Insight
McKinnon: Winning in cybersecurity means moving forward, not achieving zero breaches
“I think that if you think about, winning is not zero breaches. I think winning is moving your organization forward.”
Todd McKinnon Jan 2, 2019 ▶ 24:04
Assertion Supported
Balasubramanian: The Dropbox breach actually resulted from reused credentials from other leaks
“We saw this in the entire Dropbox leak, right? Like everyone said Dropbox had been compromised, But what these fraudsters had done had figured out username, passwords, and all these other breaches that actually worked on Dropbox.”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 26:05
Insight
Balasubramanian: Knowledge-based authentication factors are no longer sufficient for identity verification
“It just can't be because of the fact that I know your mother's maiden name, or I know when you were born, right? That clearly is not you.”
Vijay Balasubramaniyan Jan 2, 2019 ▶ 29:55
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.