Jan 2, 2019 · 25m · a16z

a16z Podcast | Barbarians at the Gate -- How to Think About Enterprise Security Today

Gaurav Banga · 10m spoken Andrew Rubin · 9m spoken Michael Copeland · 3m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, host Michael Copeland speaks with cybersecurity CEOs Andrew Rubin and Gaurav Banga about moving away from outdated perimeter defenses toward modern architectural models like micro-segmentation and micro-virtualization. The discussion highlights how enterprise leaders can effectively manage digital risk, align security with operational agility, and adapt to the economic motivations of modern cyber threats.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 2.5 Guest teaching 4.8 Guest disagreement 1.4 The host pushing back 1.1
05100:0010:0020:001:01–3:12 · The host as informed peer 2/10 Shifting Mindsets: From Binary Safety to Surface Area Reduction Host sets up the topic by asking open questions about how executives internalize cyber threats. Guest Andrew Rubin explains the recent paradigm shift from binary safety to attack surface reduction.3:12–7:14 · The host as informed peer 3/10 Reconciling Speed and Security through Architectural Rethinking Host asks how companies reconcile speed with security and makes a smart observation linking cloud migration to security architecture changes. Guests elaborate on rethinking security from first principles.7:14–9:53 · The host as informed peer 2/10 Analyzing Unknown Threats and the Economic Factors of Cybercrime Host prompts the guests on how to handle unknown threats when attack vectors are unpredictable. Gaurav Banga educates on the economic incentives driving cybercrime and the high ROI of software exploits.9:53–12:11 · The host as informed peer 3/10 Implementing Micro-Segmentation to Contain Blast Radii Host prompts Andrew on surface area reduction and correctly synthesizes that workloads are isolated to tiny access slices. Andrew details Illumio's micro-segmentation strategy.12:11–15:07 · The host as informed peer 2/10 Protecting End-Users via Micro-Virtualization and Disposable Containers Host asks how to prevent security from slowing down end users. Gaurav uses vivid metaphors of burner phones and disposable gloves to explain micro-virtualization.15:07–17:28 · The host as informed peer 3/10 Navigating Enterprise Risk: Courage versus Foolishness in Security Strategy Host introduces the concept of courage versus foolishness, using staying on legacy systems like Windows XP as an example. Gaurav explains that enterprise CISOs must take calculated risks to reduce overall risk.17:28–19:55 · The host as informed peer 2/10 Mobile Security Realities: BYOD, Information Control, and High-Value Assets Host asks about mobile malware threats on smartphones. Gaurav politely reframes the host's premise by noting mobile is primarily an information management problem rather than a traditional malware vector.19:55–23:27 · The host as informed peer 3/10 Active Defense Debates: Continuous Visibility versus Hack-Back Offense Host asks whether enterprises should take the offense or hack back against attackers. Andrew Rubin challenges the assumption that attacks can be stopped in advance, while Gaurav explains why active defense is legally and technically impractical for commercial firms.1:01–3:12 · Guest teaching 4/10 Shifting Mindsets: From Binary Safety to Surface Area Reduction Host sets up the topic by asking open questions about how executives internalize cyber threats. Guest Andrew Rubin explains the recent paradigm shift from binary safety to attack surface reduction.3:12–7:14 · Guest teaching 5/10 Reconciling Speed and Security through Architectural Rethinking Host asks how companies reconcile speed with security and makes a smart observation linking cloud migration to security architecture changes. Guests elaborate on rethinking security from first principles.7:14–9:53 · Guest teaching 5/10 Analyzing Unknown Threats and the Economic Factors of Cybercrime Host prompts the guests on how to handle unknown threats when attack vectors are unpredictable. Gaurav Banga educates on the economic incentives driving cybercrime and the high ROI of software exploits.9:53–12:11 · Guest teaching 4/10 Implementing Micro-Segmentation to Contain Blast Radii Host prompts Andrew on surface area reduction and correctly synthesizes that workloads are isolated to tiny access slices. Andrew details Illumio's micro-segmentation strategy.12:11–15:07 · Guest teaching 5/10 Protecting End-Users via Micro-Virtualization and Disposable Containers Host asks how to prevent security from slowing down end users. Gaurav uses vivid metaphors of burner phones and disposable gloves to explain micro-virtualization.15:07–17:28 · Guest teaching 4/10 Navigating Enterprise Risk: Courage versus Foolishness in Security Strategy Host introduces the concept of courage versus foolishness, using staying on legacy systems like Windows XP as an example. Gaurav explains that enterprise CISOs must take calculated risks to reduce overall risk.17:28–19:55 · Guest teaching 5/10 Mobile Security Realities: BYOD, Information Control, and High-Value Assets Host asks about mobile malware threats on smartphones. Gaurav politely reframes the host's premise by noting mobile is primarily an information management problem rather than a traditional malware vector.19:55–23:27 · Guest teaching 6/10 Active Defense Debates: Continuous Visibility versus Hack-Back Offense Host asks whether enterprises should take the offense or hack back against attackers. Andrew Rubin challenges the assumption that attacks can be stopped in advance, while Gaurav explains why active defense is legally and technically impractical for commercial firms.1:01–3:12 · Guest disagreement 1/10 Shifting Mindsets: From Binary Safety to Surface Area Reduction Host sets up the topic by asking open questions about how executives internalize cyber threats. Guest Andrew Rubin explains the recent paradigm shift from binary safety to attack surface reduction.3:12–7:14 · Guest disagreement 1/10 Reconciling Speed and Security through Architectural Rethinking Host asks how companies reconcile speed with security and makes a smart observation linking cloud migration to security architecture changes. Guests elaborate on rethinking security from first principles.7:14–9:53 · Guest disagreement 1/10 Analyzing Unknown Threats and the Economic Factors of Cybercrime Host prompts the guests on how to handle unknown threats when attack vectors are unpredictable. Gaurav Banga educates on the economic incentives driving cybercrime and the high ROI of software exploits.9:53–12:11 · Guest disagreement 1/10 Implementing Micro-Segmentation to Contain Blast Radii Host prompts Andrew on surface area reduction and correctly synthesizes that workloads are isolated to tiny access slices. Andrew details Illumio's micro-segmentation strategy.12:11–15:07 · Guest disagreement 1/10 Protecting End-Users via Micro-Virtualization and Disposable Containers Host asks how to prevent security from slowing down end users. Gaurav uses vivid metaphors of burner phones and disposable gloves to explain micro-virtualization.15:07–17:28 · Guest disagreement 1/10 Navigating Enterprise Risk: Courage versus Foolishness in Security Strategy Host introduces the concept of courage versus foolishness, using staying on legacy systems like Windows XP as an example. Gaurav explains that enterprise CISOs must take calculated risks to reduce overall risk.17:28–19:55 · Guest disagreement 2/10 Mobile Security Realities: BYOD, Information Control, and High-Value Assets Host asks about mobile malware threats on smartphones. Gaurav politely reframes the host's premise by noting mobile is primarily an information management problem rather than a traditional malware vector.19:55–23:27 · Guest disagreement 3/10 Active Defense Debates: Continuous Visibility versus Hack-Back Offense Host asks whether enterprises should take the offense or hack back against attackers. Andrew Rubin challenges the assumption that attacks can be stopped in advance, while Gaurav explains why active defense is legally and technically impractical for commercial firms.1:01–3:12 · The host pushing back 1/10 Shifting Mindsets: From Binary Safety to Surface Area Reduction Host sets up the topic by asking open questions about how executives internalize cyber threats. Guest Andrew Rubin explains the recent paradigm shift from binary safety to attack surface reduction.3:12–7:14 · The host pushing back 1/10 Reconciling Speed and Security through Architectural Rethinking Host asks how companies reconcile speed with security and makes a smart observation linking cloud migration to security architecture changes. Guests elaborate on rethinking security from first principles.7:14–9:53 · The host pushing back 1/10 Analyzing Unknown Threats and the Economic Factors of Cybercrime Host prompts the guests on how to handle unknown threats when attack vectors are unpredictable. Gaurav Banga educates on the economic incentives driving cybercrime and the high ROI of software exploits.9:53–12:11 · The host pushing back 1/10 Implementing Micro-Segmentation to Contain Blast Radii Host prompts Andrew on surface area reduction and correctly synthesizes that workloads are isolated to tiny access slices. Andrew details Illumio's micro-segmentation strategy.12:11–15:07 · The host pushing back 1/10 Protecting End-Users via Micro-Virtualization and Disposable Containers Host asks how to prevent security from slowing down end users. Gaurav uses vivid metaphors of burner phones and disposable gloves to explain micro-virtualization.15:07–17:28 · The host pushing back 1/10 Navigating Enterprise Risk: Courage versus Foolishness in Security Strategy Host introduces the concept of courage versus foolishness, using staying on legacy systems like Windows XP as an example. Gaurav explains that enterprise CISOs must take calculated risks to reduce overall risk.17:28–19:55 · The host pushing back 1/10 Mobile Security Realities: BYOD, Information Control, and High-Value Assets Host asks about mobile malware threats on smartphones. Gaurav politely reframes the host's premise by noting mobile is primarily an information management problem rather than a traditional malware vector.19:55–23:27 · The host pushing back 2/10 Active Defense Debates: Continuous Visibility versus Hack-Back Offense Host asks whether enterprises should take the offense or hack back against attackers. Andrew Rubin challenges the assumption that attacks can be stopped in advance, while Gaurav explains why active defense is legally and technically impractical for commercial firms.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 20:07 Dismissing the premise of active offense

Andrew Rubin directly challenges the host's premise about stopping attacks before they happen, asserting that assuming attacks can be prevented upfront is an unrealistic baseline.

Hardest push from the host ▶ 21:02 Testing the limits of offensive security

Host Michael Copeland pushes back on the guests' defensive focus, re-framing the question to test whether internal process hygiene must precede any offensive capabilities.

Biggest teaching moment ▶ 17:46 Reframing the mobile threat model

Gaurav Banga clarifies that the host's concern over mobile malware is misguided, explaining that smartphones present an information control challenge rather than a primary malware threat vector.

The host holds their own ▶ 6:18 Linking cloud migration to security mindset shift

Host Michael Copeland demonstrates sharp contextual understanding by linking enterprise willingness to migrate to public clouds with their willingness to adopt entirely new security architectures.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Shifting Mindsets: From Binary Safety to Surface Area Reduction 2411 Host sets up the topic by asking open questions about how executives internalize cyber threats. Guest Andrew Rubin explains the recent paradigm shift from binary safety to attack surface reduction.
Reconciling Speed and Security through Architectural Rethinking 3511 Host asks how companies reconcile speed with security and makes a smart observation linking cloud migration to security architecture changes. Guests elaborate on rethinking security from first principles.
Analyzing Unknown Threats and the Economic Factors of Cybercrime 2511 Host prompts the guests on how to handle unknown threats when attack vectors are unpredictable. Gaurav Banga educates on the economic incentives driving cybercrime and the high ROI of software exploits.
Implementing Micro-Segmentation to Contain Blast Radii 3411 Host prompts Andrew on surface area reduction and correctly synthesizes that workloads are isolated to tiny access slices. Andrew details Illumio's micro-segmentation strategy.
Protecting End-Users via Micro-Virtualization and Disposable Containers 2511 Host asks how to prevent security from slowing down end users. Gaurav uses vivid metaphors of burner phones and disposable gloves to explain micro-virtualization.
Navigating Enterprise Risk: Courage versus Foolishness in Security Strategy 3411 Host introduces the concept of courage versus foolishness, using staying on legacy systems like Windows XP as an example. Gaurav explains that enterprise CISOs must take calculated risks to reduce overall risk.
Mobile Security Realities: BYOD, Information Control, and High-Value Assets 2521 Host asks about mobile malware threats on smartphones. Gaurav politely reframes the host's premise by noting mobile is primarily an information management problem rather than a traditional malware vector.
Active Defense Debates: Continuous Visibility versus Hack-Back Offense 3632 Host asks whether enterprises should take the offense or hack back against attackers. Andrew Rubin challenges the assumption that attacks can be stopped in advance, while Gaurav explains why active defense is legally and technically impractical for commercial firms.

Statements from this episode (12)

Opinion
Banga: Modern digital infrastructure rests on architecturally unsound security
“And unfortunately we have built that on a security platform which is not architecturally sound.”
Gaurav Banga Jan 2, 2019 ▶ 0:49
Insight
Rubin: Viewing cybersecurity as binary safe versus breached is no longer viable
“I think the aha moment for security, and it's recent, it's measured probably in months or maybe a year or two, is that this concept of being in a binary state of safe or breached is no longer a viable way to look at the world. Because with this much out there,…”
Andrew Rubin Jan 2, 2019 ▶ 1:30
Insight
Rubin: Enterprise buyers are willing to replace legacy security architectures entirely
“Consistently across the board, customers are saying to us that they're finding that there isn't a natural or easy iterative path from the architecture of the past. What Groves said about having to rethink the problem from first principles, We're actually heari…”
Andrew Rubin Jan 2, 2019 ▶ 5:31
Insight
Banga: Security strategy requires studying the economics of war and crime
“Go become a student in war and crime, what, how war and crime works, what are the economics of war and crime, and then go become a student of some of the computer science behind. That gives you the approach you need to take.”
Gaurav Banga Jan 2, 2019 ▶ 8:50
Assertion Not checkable as stated
Banga: Hacking enterprise targets is far cheaper than physical bank robbery
“Because that 10,000 dollars is a small fraction of the reward that you would earn from that. And it is much, much cheaper than trying to attack the bank in the physical world.”
Gaurav Banga Jan 2, 2019 ▶ 9:18
Insight
Banga: Security infrastructure should never restrict end-user actions
“So this is a very different paradigm shift where you're designing the infrastructure from the ground up in such a way that saying no to the end user is not an option. You are going to be secure in spite of the user being able to do wanting to do anything and c…”
Gaurav Banga Jan 2, 2019 ▶ 14:48
Assertion Not checkable as stated
Banga: Mobile devices face little malware, but CIOs lack operational visibility
“While there's not much malware exists, some malware does exist, but not much malware exists for attacking mobile devices themselves, like in the Android and the iOS case, but the more important thing is that the CIO has very little visibility and very few cont…”
Gaurav Banga Jan 2, 2019 ▶ 18:31
Insight
Rubin: Achieving perfect visibility over all enterprise devices is a fool's errand
“Every CIO's dream would be to really, truly be able to have a perfect picture of everything that can access every application and every piece of data in their environment, no matter where it is or who provided it, but it's, in a sense, it's a fool's mission. N…”
Andrew Rubin Jan 2, 2019 ▶ 19:02
Assertion Not checkable as stated
Rubin: Enterprises are pivoting to protect high-value assets over blanket control
“What we're finding is that what customers are doing is they're actually identifying what they consider to be their highest value targets. They're identifying the applications and specifically the data that is the most important asset that they have. They're fi…”
Andrew Rubin Jan 2, 2019 ▶ 19:34
Opinion
Banga: Cybersecurity legal frameworks remain primitive compared to physical crime laws
“The legal systems around cybersecurity are much more improved now than, say, 10 years ago, but they're still very primitive compared to, you know, murder and, you know, physical extortion and physical theft and glandular and all those kinds of things.”
Gaurav Banga Jan 2, 2019 ▶ 23:01
Opinion
Banga: Private companies lack the capability and justification to hack back
“And maybe nation states can do this to each other, but I doubt whether commercial enterprises should go over there. They have the means to go over there successfully.”
Gaurav Banga Jan 2, 2019 ▶ 23:18
Insight
Banga: Global CEOs fail if they retain legacy enterprise security approaches
“What is very obvious is the existing way of doing things doesn't work, and if you are not embracing change, the right kind of change, empowering someone who has, you know, got a lot of budget and money behind them, a good, clear charter of just what you want t…”
Gaurav Banga Jan 2, 2019 ▶ 24:40
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.