Assertion certainty 4/5 debate potential 2/5

McKinnon: Unlike CISOs, corporate boards still assume they have not been breached

Todd McKinnon · a16z Podcast | Making Security More Useable · Jan 2, 2019 · at 20:34

Todd McKinnon is the CEO and co-founder of Okta, an identity management company. He is contrasting how security executives versus CEOs and board members perceive internal cybersecurity breaches.

0:00 / 0:22exact quote · 22.9s
▶ Watch the full episode on YouTube → 720p mp4 · rendered on demand · StarZero watermark
“What we see is that, that, like earlier, I was talking about the CEO board level and then CIO chief security officer, We see that the CIOs and the chief security officers, they understand that, that they've likely been breached and they're very into monitoring and so forth. Senior level people, more senior than that, CEOs, boards, they, their mindset is, we've never been breached.”

quote is from the automated transcript, cleaned for reading: filler sounds and stutters are removed, nothing is rephrased. names can be misheard (the analysis reads context, assessments check outside sources). how →

More from Todd McKinnon

Insight
McKinnon: Winning in cybersecurity means moving forward, not achieving zero breaches
“I think that if you think about, winning is not zero breaches. I think winning is moving your organization forward.”
Todd McKinnon Jan 2, 2019 ▶ 24:04 a16z Podcast | Making Security More Useable
Assertion Not checkable as stated
McKinnon: Board cybersecurity focus spiked recently while CISO concern remained consistent
“One of the things that we've seen, it's the people that are chief security officers, or security professionals, or even CIOs, their level of vigilance and their level of concern about this over the last 18 months is pretty consistent. What's clearly changed is…”
Todd McKinnon Jan 2, 2019 ▶ 2:10 a16z Podcast | Making Security More Useable
Insight
McKinnon: Forcing inconvenient security protocols on end-users is a losing battle
“I think it's an uphill battle to try to get, especially in the modern era of IT, to try to get users to do something that is inconvenient or out of band. I think that, and what we see in our customer base and the prospect base that Companies in IT departments …”
Todd McKinnon Jan 2, 2019 ▶ 5:22 a16z Podcast | Making Security More Useable
Insight
McKinnon: Enterprise IoT security must anchor to individual human identities
“And ultimately, it's going to go back to a person. The person's going to want to consume the data or understand where that asset is, and that's why we think that having that logical map all the way back to the person is very valuable.”
Todd McKinnon Jan 2, 2019 ▶ 14:49 a16z Podcast | Making Security More Useable
Assertion Not checkable as stated
McKinnon: Major security breaches are usually caused by simple administrative errors
“If you look a lot of these cases, ah, these breaches, it was, Very basic things that were used or problems that were used to take advantage of these networks or these systems, and it was just simple stuff that wasn't cleaned up.”
Todd McKinnon Jan 2, 2019 ▶ 17:46 a16z Podcast | Making Security More Useable
Insight
McKinnon: Enterprise security requires tiered data classification to balance risk and speed
“I think companies need to have that kind of framework. Maybe not that formal, but they have to define what's super sensitive, lock that down in a way that's commensurate with the sensitivity of the information, and then think of it like concentric rings outsid…”
Todd McKinnon Jan 2, 2019 ▶ 22:13 a16z Podcast | Making Security More Useable
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.