The Exchanges

Every argument clarity score on this site is built from rows on this page. Each question and answer was assessed with names hidden, the host's own answers included, on four things from 1 to 5: directness (does it answer the question asked), coherence (do the ideas follow), precision (concrete details and clear references), compression (says a lot per word). The weighted mix (30/30/25/15) is the exchange score. A person's published score averages their exchange scores on raw tape only, at least 8 of them, shrunk toward the cohort mean. Full method →

Christina Cacioppo no published score: only 6 usable exchanges on raw tape, and a fair score needs 8+ · coarse estimate ≈4.0/5 from 6 raw tape exchanges record → ← everyone

Every exchange below was scored with names hidden, four dimensions each from 1 to 5. An exchange's score is 0.30·directness + 0.30·coherence + 0.25·precision + 0.15·compression. The published score averages the raw tape exchange scores and shrinks small samples toward the cohort mean, so five great answers can't beat twenty good ones. Produced feed rows count only toward coarse estimates, never toward a full score.

clear all ✕
6exchanges match
6on raw tape
0redirected or not addressed
Answered raw tape D 5 · C 5 · P 4 · Cm 4 4.60

Q Yeah, so what are these new attacks like?

A Yeah, so, I mean, we see some of these at Vanta too. There's a lot of impersonation. Um, it is just easier to, you know, I can think of the old way was the joke at Vanta was, if you joined the company, you would get three text messages from me asking me to buy you gift cards, but things were probably like somewhat misspelled, and you're probably wondering, you know, does a CEO really need me to go out and buy gift cards? Again, it was sort of this, you know, attack that was easy to laugh about. Um, that one still happens, but there's versions of that that are much more compelling. So CrowdStrike has recently talked about How they had one of their customers, um, I think it was the CEO, but an executive at one of their customers actually impersonated in this credible way and, you know, go ask employees that I think over video to go do something for them. And, um, so again, it's kind of, you can see there's some of these same attacks, but just way more compelling.

AI assessment note: “There's a lot of impersonation... versions of that that are much more compelling.”

Answered raw tape D 5 · C 5 · P 4 · Cm 4 4.60

Q And now, are you using artificial intelligence tools to be able to, you know, put together these reports, or to be able to address some of the concerns that we were discussing earlier on?

A We are in a, in a bunch of different ways. Um, we started building AI and from the ground up across our product. So everything from helping a company decide, uh, which security controls are best for them, given their maturity, given what their customers are asking for. Um, when there's a, you know, error or vulnerability, how do you fix that? Uh, AI is helpful for giving a, again, first pass or a suggestion for the team to take action on. And then, um, a lot of the process of these audits or requirements is just a lot of documentation. Back to the security questionnaires I talked about, um, at the beginning. Uh, there's, you know, you have to do the work, and then you have to tell people about how you did the work. Uh, when I talk to security professionals, they usually really like doing the work. That's why they got into the job. They generally don't like having to tell people about the work in a bunch of different forms. So, you know, an audit, a screenshot, a security questionnaire, and a conversation. And so one of the places we've seen AI Be really effective is again to take all that work that was done, summarize it, and put it in the right format, um, so the teams can focus on actually doing the work.

AI assessment note: “We are in a, in a bunch of different ways.”

Answered raw tape D 5 · C 5 · P 4 · Cm 4 4.60

Q Yeah, and can you talk about how that happens? So is it basically a generative AI model that's monitoring, uh, the people as they work, and then being able to sort of translate that activity into natural language? Talk a little bit about how that, how they operate that way.

A So it is definitely generative AI models, um, kind of the foundation models, plus some post-training, um, and a ton of kind of quality improvements to make sure, uh, there, there's high accuracy from security and compliance of the place where I think there is less tolerance for creativity and true generation and, you know, more, more desire for accuracy. But basically take these models and not observe, uh, what people do, but observe the outputs. Um, so what have they done? Like what was there before? What did they do? Look at the output rather than kind of the work itself. But then take those outputs and say, okay, maybe you went and, I don't know, changed a bunch of configurations in your cloud infrastructure, um, in a way that's more secure. Okay, we can take that new configuration, uh, can turn that into a policy document. So there's a standard kind of document written in sort of legalese or compliance that describes what there is. Take that configuration, um, translate it to answers for the security questionnaire. So the next time you're asked about Your cloud infrastructure configuration , you got the answer there, direct from, from, you know, the reality, um, of what's in the system live, uh, and then finally take some of, again, take that same information, map it to a bunch of compliance frameworks, and so if you're going through an audit or going for a particular, um, …

AI assessment note: “not observe, uh, what people do, but observe the outputs”

Answered raw tape D 5 · C 5 · P 4 · Cm 4 4.60

Q Yeah, what could be coming with the new AI regulations? Any sense as to what they might touch?

A Um, if you force me to bet, uh, I think a lot of it will focus on data security, and so it'll be kind of under the, you know, banner of AI, but it'll probably be a lot of the things we've talked about with data security, and I think with that, you know, think through the best practices of understanding, like, as a company or a service provider, like, what data you're collecting, why, where it goes, when you send it to a third party, um, One analogy a security professional gave me years ago was you should think of data, um, as sort of like toxic waste. Uh, you have it, you might need it, but you want to keep it contained, and if it starts leaking out, it's very hard to, um, kind of clean that up. Uh, and again, you know, someone said to me, said this to me years ago, but I, I think it's true, and so I think you're going to see these regulations try to, like, fence in that data much, much more so than, um, Again, we were doing 10 years ago as software builders.

AI assessment note: “I think a lot of it will focus on data security”

Answered raw tape D 5 · C 4 · P 4 · Cm 4 4.30

Q army of, uh, of bots that are going out and maybe doing this and for nefarious purposes, or even, um, if we're gonna have this increase in bot traffic on the, on the web, uh, it seems like it's gonna make things More difficult for just like normal companies going about their day to day. So, um, we talk about the opportunities, but what do you see as the risks?

A Yeah, there, there's definitely are risks. Um, and one stat I found interesting is over half of the fortune 500 companies in their most recent, uh, annual financial reports cited AI as a risk factor. Um, and so, right, it's, it's kind of prevalent. I think, I think about it in two ways. One, just general technology deployment. AI is a new technology. We're still figuring out its parameters. Anytime there's something new, there's a ton of excitement, but there's also just a ton of risk as we figure it out. So there's something just general there. You know, there's a story of mobile 10 years ago, maybe cloud 15 years ago, it's AI now. Um, and then there's a specific piece of these, uh, tools can create incredibly accurate text and video that looks like it's real or, you know, but might not be. And so there's a whole host of attacks that are now, again, Much easier, sort of a different magical product experience that we might all think is actually less magical or the result is, um, but those have also become much easier as well.

AI assessment note: “I think about it in two ways. One, just general technology deployment.”

Partly raw tape D 3 · C 4 · P 4 · Cm 3 3.55

Q And now we might have AI regulation that's coming. Uh, are, you know, you see the, the impact of these regulations firsthand. And as you mentioned, like, The security professionals, they're trying to work within their organizations to, you know, make sure that it doesn't slow companies down, uh, trying to comply with them. So just on a whole, do you think that all these tech regulations are, are worthwhile?

A I think, too, there's a, if you're, uh, if you're familiar, there's this great web comic called XKCD. It's like, 1520 years old. It's the stick figures. Ok, yeah, you know, XKCD. So, of course, there's an XKCD about standards, um, where basically, you know, you, there's a, you need a standard for something. The old ones don't work, so the answer is, in fact, to, like, make an 18th standard. It is never to go fix the other ones. Um, in, like, true XKCD faction, I think this is, in fact, how the world works, whether or not it's how the world should work. Um, People are constantly coming out with new standards. There's always a reason for them, right? There is a real problem they're trying to address, but it does just make the proliferation really hard. Um, I think some of the more effective efforts in the past couple of years have really focused on trying to create like an umbrella over multiple standards, or at least a bunch of mapping. So it's like, okay, fine, you're doing the 18th, but here's how it relates to, you know, 10 of the other 17. Um, so it's not like you're asking for a hundred percent net new work. Because that's just, that's just really tough for everyone.

AI assessment note: “There is a real problem they're trying to address, but it does just make”

page 1
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.