Jan 2, 2019 · 28m · a16z

a16z Podcast | Getting Security Right Isn’t as Hard as You Think (But the Effort Never Ends)

Orion Hindawi · 21m spoken Michael Copeland · 4m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, host Michael Copeland and Tanium CTO Orion Hindawi discuss why effective enterprise cybersecurity relies on continuous basic IT hygiene, operational alignment between security and IT teams, and executive-level accountability rather than quick-fix vendor tools.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 3.0 Guest teaching 4.5 Guest disagreement 2.7 The host pushing back 1.5
05100:0010:0020:000:00–2:11 · The host as informed peer 2/10 State of Cyber Attacks and Surface Area Expansion Host cites recent news stories like WikiLeaks and the Sony hack to ask if cyber attacks are worsening. Guest reframes the issue, explaining that better telemetry makes old threats visible while expanding internet surface areas increase exposure.2:11–6:46 · The host as informed peer 3/10 Cyber Hygiene vs. the Magic Pill Myth Guest dispels myths around Hollywood-style nation-state attacks, stressing that basic hygiene like patching and multi-factor authentication stops most breaches. Host contributes by extending guest's exercise metaphor into a magic pill analogy.6:46–11:44 · The host as informed peer 4/10 Bridging the Gap Between Security and Operations Guest discusses organizational friction between security and IT operations over change risk versus urgency. Host probes whether operations fears broken functionality or if security lacks operational context.11:44–16:58 · The host as informed peer 3/10 Executive Mindset Shift and the Target Breach Lesson Guest strongly refutes the notion that breaches are good business for security vendors, describing post-breach enterprise behavior as panic-driven rather than strategic. Host guides discussion toward board-level mindset shifts following the Target breach.16:58–24:00 · The host as informed peer 4/10 Tailoring Security by Scale: Small Business vs. Global 2000 Guest dismisses industry hype regarding insider threats and nation-state attacks, pointing out that 98-99% of enterprises should worry about kids with Google exploiting unpatched flaws. Host synthesizes this insight with a meteor metaphor.24:00–28:03 · The host as informed peer 2/10 Continuous Security Management and House Analogy Guest uses a house remodeling analogy to emphasize that many enterprises dangerously alter infrastructure without knowing basic asset inventories. Host steers the conversation to a reassuring wrap-up on manageable security habits.0:00–2:11 · Guest teaching 3/10 State of Cyber Attacks and Surface Area Expansion Host cites recent news stories like WikiLeaks and the Sony hack to ask if cyber attacks are worsening. Guest reframes the issue, explaining that better telemetry makes old threats visible while expanding internet surface areas increase exposure.2:11–6:46 · Guest teaching 5/10 Cyber Hygiene vs. the Magic Pill Myth Guest dispels myths around Hollywood-style nation-state attacks, stressing that basic hygiene like patching and multi-factor authentication stops most breaches. Host contributes by extending guest's exercise metaphor into a magic pill analogy.6:46–11:44 · Guest teaching 4/10 Bridging the Gap Between Security and Operations Guest discusses organizational friction between security and IT operations over change risk versus urgency. Host probes whether operations fears broken functionality or if security lacks operational context.11:44–16:58 · Guest teaching 5/10 Executive Mindset Shift and the Target Breach Lesson Guest strongly refutes the notion that breaches are good business for security vendors, describing post-breach enterprise behavior as panic-driven rather than strategic. Host guides discussion toward board-level mindset shifts following the Target breach.16:58–24:00 · Guest teaching 5/10 Tailoring Security by Scale: Small Business vs. Global 2000 Guest dismisses industry hype regarding insider threats and nation-state attacks, pointing out that 98-99% of enterprises should worry about kids with Google exploiting unpatched flaws. Host synthesizes this insight with a meteor metaphor.24:00–28:03 · Guest teaching 5/10 Continuous Security Management and House Analogy Guest uses a house remodeling analogy to emphasize that many enterprises dangerously alter infrastructure without knowing basic asset inventories. Host steers the conversation to a reassuring wrap-up on manageable security habits.0:00–2:11 · Guest disagreement 1/10 State of Cyber Attacks and Surface Area Expansion Host cites recent news stories like WikiLeaks and the Sony hack to ask if cyber attacks are worsening. Guest reframes the issue, explaining that better telemetry makes old threats visible while expanding internet surface areas increase exposure.2:11–6:46 · Guest disagreement 2/10 Cyber Hygiene vs. the Magic Pill Myth Guest dispels myths around Hollywood-style nation-state attacks, stressing that basic hygiene like patching and multi-factor authentication stops most breaches. Host contributes by extending guest's exercise metaphor into a magic pill analogy.6:46–11:44 · Guest disagreement 2/10 Bridging the Gap Between Security and Operations Guest discusses organizational friction between security and IT operations over change risk versus urgency. Host probes whether operations fears broken functionality or if security lacks operational context.11:44–16:58 · Guest disagreement 4/10 Executive Mindset Shift and the Target Breach Lesson Guest strongly refutes the notion that breaches are good business for security vendors, describing post-breach enterprise behavior as panic-driven rather than strategic. Host guides discussion toward board-level mindset shifts following the Target breach.16:58–24:00 · Guest disagreement 4/10 Tailoring Security by Scale: Small Business vs. Global 2000 Guest dismisses industry hype regarding insider threats and nation-state attacks, pointing out that 98-99% of enterprises should worry about kids with Google exploiting unpatched flaws. Host synthesizes this insight with a meteor metaphor.24:00–28:03 · Guest disagreement 3/10 Continuous Security Management and House Analogy Guest uses a house remodeling analogy to emphasize that many enterprises dangerously alter infrastructure without knowing basic asset inventories. Host steers the conversation to a reassuring wrap-up on manageable security habits.0:00–2:11 · The host pushing back 1/10 State of Cyber Attacks and Surface Area Expansion Host cites recent news stories like WikiLeaks and the Sony hack to ask if cyber attacks are worsening. Guest reframes the issue, explaining that better telemetry makes old threats visible while expanding internet surface areas increase exposure.2:11–6:46 · The host pushing back 2/10 Cyber Hygiene vs. the Magic Pill Myth Guest dispels myths around Hollywood-style nation-state attacks, stressing that basic hygiene like patching and multi-factor authentication stops most breaches. Host contributes by extending guest's exercise metaphor into a magic pill analogy.6:46–11:44 · The host pushing back 2/10 Bridging the Gap Between Security and Operations Guest discusses organizational friction between security and IT operations over change risk versus urgency. Host probes whether operations fears broken functionality or if security lacks operational context.11:44–16:58 · The host pushing back 2/10 Executive Mindset Shift and the Target Breach Lesson Guest strongly refutes the notion that breaches are good business for security vendors, describing post-breach enterprise behavior as panic-driven rather than strategic. Host guides discussion toward board-level mindset shifts following the Target breach.16:58–24:00 · The host pushing back 1/10 Tailoring Security by Scale: Small Business vs. Global 2000 Guest dismisses industry hype regarding insider threats and nation-state attacks, pointing out that 98-99% of enterprises should worry about kids with Google exploiting unpatched flaws. Host synthesizes this insight with a meteor metaphor.24:00–28:03 · The host pushing back 1/10 Continuous Security Management and House Analogy Guest uses a house remodeling analogy to emphasize that many enterprises dangerously alter infrastructure without knowing basic asset inventories. Host steers the conversation to a reassuring wrap-up on manageable security habits.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 22:24 Dismissing insider threat priorities as a waste of resources

Guest forcefully rejects industry obsession with advanced insider threats, calling it a waste of company resources when almost no enterprise has handled basic patch hygiene.

Hardest push from the host ▶ 8:16 Challenging security vs operations conflict premise

Host pushes back on guest's broad framing of team friction by asking whether operations fears lost functionality or if security simply fails to understand operational realities.

Biggest teaching moment ▶ 22:00 Exposing Global 2000 basic hygiene failures

Guest educates the host with blunt statistics, explaining that 98 to 99 percent of Global 2000 clients have not completed basic security hygiene before chasing esoteric threats.

The host holds their own ▶ 23:09 Nation-state attack as meteor metaphor

Host demonstrates strong domain synthesis by reframing guest's explanation of unpreventable nation-state attacks into an apt meteor metaphor.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
State of Cyber Attacks and Surface Area Expansion 2311 Host cites recent news stories like WikiLeaks and the Sony hack to ask if cyber attacks are worsening. Guest reframes the issue, explaining that better telemetry makes old threats visible while expanding internet surface areas increase exposure.
Cyber Hygiene vs. the Magic Pill Myth 3522 Guest dispels myths around Hollywood-style nation-state attacks, stressing that basic hygiene like patching and multi-factor authentication stops most breaches. Host contributes by extending guest's exercise metaphor into a magic pill analogy.
Bridging the Gap Between Security and Operations 4422 Guest discusses organizational friction between security and IT operations over change risk versus urgency. Host probes whether operations fears broken functionality or if security lacks operational context.
Executive Mindset Shift and the Target Breach Lesson 3542 Guest strongly refutes the notion that breaches are good business for security vendors, describing post-breach enterprise behavior as panic-driven rather than strategic. Host guides discussion toward board-level mindset shifts following the Target breach.
Tailoring Security by Scale: Small Business vs. Global 2000 4541 Guest dismisses industry hype regarding insider threats and nation-state attacks, pointing out that 98-99% of enterprises should worry about kids with Google exploiting unpatched flaws. Host synthesizes this insight with a meteor metaphor.
Continuous Security Management and House Analogy 2531 Guest uses a house remodeling analogy to emphasize that many enterprises dangerously alter infrastructure without knowing basic asset inventories. Host steers the conversation to a reassuring wrap-up on manageable security habits.

Statements from this episode (11)

Assertion Not checkable as stated
Hindawi: Detection Improvements Are Surfacing Previously Hidden Breaches
“We're getting better at detecting that we've been attacked, and so I think a lot of customers have invested in detective mechanisms so that they can see that bad things are happening, and I think we're actually surfacing a lot of stuff that used to happen, and…”
Orion Hindawi Jan 2, 2019 ▶ 0:34
Insight
Hindawi: Enterprise cybersecurity will never be solved by single quick-fix tools
“Truth of security is it's never been that way, and it'll never be that way. You have to do You know, eating healthy and exercising every day if you actually want to keep secure.”
Orion Hindawi Jan 2, 2019 ▶ 6:06
Assertion Not checkable as stated
Hindawi: Top 10 cyberattacks in 2018 stemmed from basic IT hygiene failures
“The truth of the matter is, if you look across the 10 biggest attacks this year, all of them tied back to pretty mundane things that the organization knew they were supposed to do that they didn't do.”
Orion Hindawi Jan 2, 2019 ▶ 6:18
Assertion Not checkable as stated
Hindawi: Large Enterprises Can Remediate IT Security Flaws in Minutes
“You really can do something in an hour across the largest environments in the world if everybody gets together, you've got the right tools, and you're pushing as hard as possible. And I know that sounds hyperbolic to a lot of people because many people are goi…”
Orion Hindawi Jan 2, 2019 ▶ 9:19
Assertion Not checkable as stated
Hindawi: Someone Inside Knew About Every Major Cyber Attack Before It Happened
“If you look at every one of the attacks that we saw, somebody in that org knew something was wrong before it happened. They just didn't have the latitude to escalate it. They didn't have the ability in the organization to effect change.”
Orion Hindawi Jan 2, 2019 ▶ 10:02
Assertion Not checkable as stated
Hindawi: Big companies spend 10x more on security than 5 years ago
“You look at a lot of these big companies, they're spending literally 10 times more on security than they were five years ago.”
Orion Hindawi Jan 2, 2019 ▶ 12:56
Insight
Hindawi: Customer security breaches do not actually benefit security vendors
“So, there's this concept in our industry that it's good for security companies when their customers get breached, and it's actually not true.”
Orion Hindawi Jan 2, 2019 ▶ 13:33
Opinion
Hindawi: Target built one of the best security organizations post-breach
“We have some customers, and I think Target is a great example of one of them, that are extremely thoughtful and were thoughtful in the aftermath of the breach. They spent a lot of time building a real lasting structure, and I think they've done one of the best…”
Orion Hindawi Jan 2, 2019 ▶ 15:09
Assertion Not checkable as stated
Hindawi: Only 1-2% of enterprises are ready to address insider threats
“I think maybe one or two percent of the companies that we've walked into, Really should have started talking about insider threat when we got there. The other 98, 99%, They weren't through the just block and tackle stuff, and it's so fun to talk about insider …”
Orion Hindawi Jan 2, 2019 ▶ 22:17
Insight
Hindawi: Nation-state attackers will always succeed against commercial enterprises
“I mean, I think serious people in security have realized a long time ago that Given infinite time and infinite money, a nation state will come at you and will succeed. The reality of the situation is very few companies, very few, are equipped to actually deal …”
Orion Hindawi Jan 2, 2019 ▶ 23:16
Disclosure
Hindawi: Many enterprise clients lack basic awareness of their IT assets
“And many of our customers, before we walk in there, don't have any idea. They don't know how many subnets they have. They don't know how many computers they have. They don't know what's running on those computers. They don't know where their data is.”
Orion Hindawi Jan 2, 2019 ▶ 26:56
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.