All episodes
Episode 288 August 17, 2026

Marcus Rebelo - Global Head of Sales Engineering - Lumana

Reading the room, the questionnaires that turned a sales engineer into a CISO, and why AI governance is layers instead of control. Interviewed by Frank Victory.

Hosts Chelsea Weiss and Joe McCallister are back from a brief hiatus to cover the latest local headlines and cybersecurity news. Following the newscast, Frank Victory sits down with our featured guest this month, Marcus Rebelo.

In this episode

  • Reading the room, and the people in it. The tells Marcus reads as people walk into a meeting, why he breaks up the seating before the room splits into us and them, and where he learned to get a straight answer.
  • How a stack of questionnaires made him a CISO. Security questionnaires climbed the org chart until they landed on his desk, he refused to attest to controls the company did not have, and two of its three applications were STIG compliant inside 18 months.
  • Governing AI when control is off the table. Why blocking access no longer works, how Copilot inherits every permission the person using it already has, and what each new MCP server adds to what you are implicitly trusting a vendor with.

This month in Colorado security

The news & resources segment.

From the guest

Read the transcript19955 words, machine generated

Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.

You're listening to Colorado Equals Security, your local source for regional security news, events, and interviews with leaders across our community. Here are your hosts, Chelsea Weiss and Joe McCallister, with interviews by Frank Venturi. Hello everyone, and welcome to episode 288 of the Colorado Equals Security podcast. My name is Chelsea Weiss, and I am joined by the amazing Joe McCallister. Hey, Joe.

Hello, hello. Just as a refresher, team, uh, Joe was on sabbatical in July and I took some time off to start a new role, hence not having an episode in July. So we have some more exciting stuff for you today. This podcast is for Colorado-based security professionals by Colorado security professionals, so it gives all of us an opportunity to engage and grow together. We have a spectacular website that I recommend you visit colorado-security.com, where you can see our events, how to sign up for our newsletter, and get show notes delivered right to your inbox.

We also have a very active Slack with lots of great participation to stay apprised of all things Colorado Equals Security. With that being said, Joe, let's chat about one of my former employers with the news, EchoStar. Let's do it. Why don't you spill all the grimy details? No, just kidding.

Uh, our first story of the week, or month, or months if you're keeping track, is, uh, that EchoStar has closed $23 billion, with a B, dollars spectrum sale to AT&T, using those, uh, using proceeds from that sale to actually pay off some debt. Um, if those that are in the know or that have been kind of around the Colorado scene seen or been associated with DISH know that they had made a play a while back to get some of the spectrum to create a 5G mobile network and started to work on that quite a bit. And things kind of haven't been going what we would probably— not exactly up and to the right. And so EchoStar, the parent company, had essentially sold off some of that to AT&T. The interesting things were for me in this story where there were a couple kind of One, EchoStar declined to comment, but there was also some mention of, uh, the bankruptcy, the Chapter 11 bankruptcy for restructuring, uh, filing back in June, as well as some action from the FCC saying that, uh, that EchoStar and subsidiaries therein, uh, in this one they mentioned Dish and Dish DBS, I believe it is called, um, had to do some certain things like placing money in a trust.

Um, Chelsea, just as a, as a former kind of team member, teammate over there How is that hitting you, or how are you kind of— how do you feel about the news? Yeah, I'm, I'm one of the, the employees that I will always have the companies that I've worked for, you know, on the back of my jersey one way or another. So although I'm not there anymore, I was always cheering for them from the sidelines. So it was kind of a, you know, a bummer to hear that they went from spending $40 billion on that investment to selling the spectrum, which is really the lifeblood of that whole initiative. And then to your point, Direct Broadcast Satellite, which is DBS, having to restructure that as part of the bankruptcy.

And it's a shame to see, but sometimes that happens. The article also talks about the blast radius and the impact. They have over 170+ lawsuits. So it wasn't just an EchoStar problem. There's more consequences that are flowing directly into the vendors and the partners and etc.

that they've worked with. So for me, as a former employee, you know, it was exciting to be a part of the ambitious transformation. And now, unfortunately, from the sidelines, I'm watching major pieces of that strategy get, get sold off. So sending positive vibes to all the EchoStar folks.

Absolutely right. Um, on that sad note, we will take it to number 2. Denver's population growth outpaced by booming fringe cities. So essentially Denver's growth is moving outward from a population growth perspective. Denver itself grew only about, I think it was 3% from 2020 to 2025, and it lost over 1,000 residents between 2024 and 2025.

The Um, positive here is the communities that are on the outer edges of the metro area are absolutely booming. For example, Erie is a 34% increase from 30,000 to 41,000 residents, and that's actually the fastest growth among any Colorado community that already had over 20,000 people. Um, following that are Firestone, Windsor, Johnston grew more than 20%. Castle Rock, where Joe and I had the opportunity to spend a lot of our time, and Parker grew more than 10%. So good news here, the growth is bringing more money outward.

What were your thoughts on this one, Joe? It's a very interesting article, but just because I was of course kind of hooked at one calling, uh, I haven't heard of them called fringe cities before. I just, you know, Like the burbs is how I've always known them. So, uh, being a fringe city, uh, is, is an interesting claim. But there's a wonderful graphic that also is interactive to kind of show you what, uh, the, the spans between some of these are.

And to me, some of the interesting ones also are the ones that saw population declines or some slower growth. I was a little surprised to see Colorado Springs only about 3% growth as well, while Fountain just outside is down 1.5%. Meanwhile, another interesting one on the other side of the state being Grand Junction bumping up almost 10% is pretty cool to see that the Western Slope is getting some love as well. Yeah, go GJ! I'll get those peaches and wine.

Yeah, absolutely. And the other thing the article picked up on is it's, it's not necessarily just a Colorado thing. So I, I believe it was 4 in 5 major U.S. metros are actually seeing growth driven by more surrounding communities rather than just the core cities itself. So yes, Denver is decentralizing, but people still want to have access to the Denver jobs and airport and the mountains, and now they're just choosing to live further away from the urban, urban core. So all good news there, I will take it.

All right, absolutely. Uh, next up in our queue of stories, we've got the Ikon Pass owner could bring 400 employees to struggling downtown district. This story is about Alterra Mountain Company, the, uh, purveyor of the Ikon Pass, relocating its Denver headquarters to ideally upper downtown is kind of what the, uh, the DDDA, Denver Downtown— oh my goodness, uh, we've got enough acronyms, don't worry about it— the, the downtown business folks, uh, are are looking to bring in these 400 jobs, uh, to the Upper Downtown District, which interestingly, I think in the past couple of podcasts, Chelsea, we've talked about how the downtown kind of office and commercial real estate sector and vacancies in particular have come up. I've learned or talked about this more with you and, and in the recent news than I ever have in my past, uh, and I am no expert by any, any stretch of the imagination, but I think some of the interesting points are showing that the, uh, July 15th, the second quarter report from CBRE, a large real estate, uh, agent in the area, said that the office market, uh, posted its first decline in vacancy rates since Q3 2024. So not awesome, of course, but hopefully Alterra moving, uh, into a, a new home there in the, uh, kind of upper downtown, uptown area would be a boon.

Um, what are you kind of thinking and how do you kind of feel about the— I don't know how much time you get to spend down there, but I know my office, my commute takes me down there and, and sometimes it feels a little bit like a ghost town. Yeah, I don't go down there too often unless it's for entertainment or fun. Convera does have an office down in that, that general area, but I haven't been there yet. And from my perspective, Denver downtown itself has such a massive office vacancy rate. I you and I were talking previously, it's at 38.6%.

So it is kind of like skeleton land from that perspective. So we will have to see what happens. Luckily, I don't have to go down there very often. You know, we'll actually have to ask, quick shout out to Erica Boyle. She's an awesome and inspiring security leader over at Alterra Mountain Company, just to see a little bit more about her thoughts further down the line.

But For me, it's an interesting move for Alterra specifically just because of the ski industry. Like the backdrop has been very unique for the past 9 months. We've had a very rough snow year. The Epic early season pass sales were down, but Ikon and Alterra raised theirs, its starting price by 9%. So clearly they're, you know, considering a headquarters investment at the same time suggests that they're still trying to position for growth rather than pullback.

So. To all those folks, enjoy downtown Denver. We will not be joining you down there.

All right, on to number 4 of the day. Frontier Airlines has been sued twice for weak cybersecurity after data breaches. So our friends, our poor friends at Frontier, are facing 2 proposed class action lawsuits after alleged breaches in both May and June, which exposed sensitive employee and customer data. The plaintiffs that are a part of this are alleging that Frontier had inadequate security controls and delayed notification affecting individuals. Frontier's response is that they immediately activated incident response and contained the breach.

But, um, another super, you know, kind of egg-on-face thing in this article was the mention of an ethical hacker Bob the Hacker, Boba the Hacker, who actually flagged a vulnerability, a boarding pass-related vulnerability in March. So months before the attack happened. And as security professionals, that's always kind of one of those things that just slices you right in the gut. How did you take this one, Joe? You know, it's kind of funny because I was reading this and I actually started to go pretty deep into the claims and the incidents that had popped out.

I read a little bit more about Bob the Hacker's claims back in a few months months ago, and especially coming from a place where, you know, I am on the, the, uh, the cybersecurity side of an enterprise or an organization that is, you know, could fall victim to this at some point, I'd like to give, you know, kind of Frontier the, the benefit of the doubt in the fact that they haven't necessarily fully submitted their claims or their counterarguments in this suit. But I did see some pretty common kind of callouts in the suits that are things like neglecting what we would call best practice, or I think some stuff that might be kind of hard to prove as well, or may have reasonable risk assessments, risk tolerance, the kind of levels at Frontier Airlines, you know, especially operating as a budget travel airline. The budget's probably not always there for cybersecurity. So feeling for the friends over at Frontier, it can't be easy over there. I'll definitely be staying close to this one because there is, seems like new information coming out all the time and kind of follow these cases.

I thought one line that you kind of, maybe a throwaway for some, but I was like, geez, is that the best we've got these days in terms of recovery or kind of a payback for the consumers whose data is now out there, was the line that says that they want Frontier to pay for credit monitoring for everyone in the class for at least 3 years. And if we were You know, if I had a nickel for every year of credit monitoring I have from breaches at this point, right? You'd be rich. Exactly, exactly. Except I'd have no personal information anymore.

All right, next up we've got a story out of Westword that, uh, I can't read the full title because this is a family show, but congressional proposal would fuck with— that's the best I can do. I contemplated putting a bleep in there. It might, might still work out to be better. But, uh, this proposal would mess with Colorado's daylight hours.

And whether that's a good thing or bad thing is really kind of subjective. I think this is just a fun story to chat about because it's kind of been something that varying groups of people have gotten equally fired up on both sides of the, the kind of argument here. But the, the gist is get rid of daylight savings time. No more having to worry about falling back or springing forward. Um, the— my favorite line in the article is about Lake House Lounge's annual 7 AM tequila sunrise party, which sounds like fun I was not aware of.

Would be sad to, to not be able to make it to that. But also, uh, the kind of proponents and opponents have different ideas, like that kids would be going to school in the dark. Um, Chelsea, where do you fall on this one? Um, I, I think it would be insanely peculiar to see a winter sunrise as late as 8:20 AM. It would be nice to have sunsets that would move later, so closer to 5:30 AM.

But, you know, as a, as a parent and just as an early bird naturally, I am up in the wee hours, and to have to wait 4 or 5 hours before the sun comes up and before my eyeballs get some of that sun, I don't really like that. But the other thing that I, um, I always think about with these types of, of conversations is, you know, not necessarily us. The problems that we're talking about, yes, would stink, but for the, the other industries that it would really impact, like the agricultural industry, farmers with livestock Especially, especially, and they've traditionally opposed daylight savings time because if you look at, you know, dairy farms and the other animal routines, obviously they follow a biological schedule. So like clock-based changes, you know, aren't that big of a thing to the animals themselves, but it does complicate feeding and milking or coordination with any of the processors or markets that those ranchers or farmers use. Mm-hmm.

Yeah, it'll be interesting to see how it plays out. It's not, uh, you know, not set in the concrete yet, but it is— it will be. I will miss the days where I used to be— I'm no longer this man, but when I was out at the bar and I got the extra hour, that was awesome. Yes, we are in a different era now. And as Joe mentioned, just for, for the listeners, Senate still needs to approve, so this isn't set in stone yet.

And once again, kudos to Thomas Mitchell from Westward for using the F*CK word profanity in the title. So I saw that and had to double guess that. Thank you for spicing up our day. Moving on. I thought you put it in there.

I'm gonna be honest. I thought you put that in our little news board.

You guys know I use my profanity with purpose, which means all day, every day. But I am Alex and Rob. You guys should be proud. Okay, moving on to our security related ones. This one, this article comes from Layer's Lab.

Multiple multiple paths to compromise an environment. And the, the gist of this article is it talks about, as of today, per their Layers, uh, point of view, the 3 most common attack paths are: A, weak/reused credentials; B, poor data governance and credential sprawl; and C, insufficient network segmentation. And then on deck we have vulns and misconfigurations, of course. The resounding theme was talking about how credential sprawl is definitely a major theme, how we have passwords and secrets sitting in places like SharePoint and file shares and spreadsheets and scripts and everywhere. But the cred sprawl is big.

But the other major theme that was called out is attack path chaining. And that essentially means when you have weak credentials plus exposed sensitive data plus poor segmentation and how that toxic combination right there can allow the attacker fraudster to move laterally and escalate what was originally a relatively small compromise into a big spicy problem. Tell me your thoughts, Joe. Yeah, this, this was a great write-up from the team over there. And what I really kind of dug into in the latter half of the article, the blog post, is you'll find a heading that says how to adopt a better approach.

And kind of what they tap into here is this new era of defending against attacks. And I think what we see is the themes that a lot of us have seen called out or seen in publications or maybe seen up on a stage, which is, you know, there's a whole new frontier of the attack vectors being browser and identity. And as we're looking at identity, we also, and Lars calls this out really well in that essentially a flat network will get you owned 99 out of 100 times because they can do whatever they want after the fact. So when you're talking about those 3 broad categories with the 4th kind of being right behind it, Uh, in, in misconfig and vulns, there is a way where you can segment your, your network, uh, effectively to ensure that the blast radius is contained or that you can cut things off. Uh, as much as attackers need to build a chain, defenders can also break that chain.

And so making that easier on yourself is, you know, paramount. But also, uh, there's some interesting, like, snippets in here about not writing off the, the minor vulnerabilities. And my brain starts to spin again as a defender of like, well, how many of those are there, right? How are we supposed to shore all of that up over time? And I think it's juice worth the squeeze.

Where can we spend our time to get low, relatively low effort and high value defenses in place? Absolutely. I always love it when an article gives us good, healthy, digestible information to be able to take back the following Monday. So once again, Layers, good job. With this one.

I was just going to move on to number 7, Joe, but then I realized it's yours. So this is my official, hey Joe, take away article 7. All right, with that brilliant segue, next up we have an article from Zivello, which is applying the agent control plane to the Hugging Face incident. Now, if you're unfamiliar with the Hugging Face incident, it is, for better or worse, our new reality that says everything's an attack all the time. Oh yeah, the robots are coming to kill us.

OpenAI had essentially— Hugging Face reported an incident that their systems have been accessed and OpenAI not so shyly raised their hand and said, oopsie daisy, our bad. Zvelo does a great job of taking— they don't necessarily go deep into the incident itself. They do cover it and there's plenty of resources to talk about this and I'm sure pontificate about the importance of whatever product somebody may be selling to you. But I think this blog does a great job of asking some interesting questions and links back to their agent control plane kind of framework or idea and theory. And what I really liked about it is they are providing us as protectors with some good frameworks to use as we think about some questions to ask about what's being done with our AI.

The, the big questions that we see in here are things like, can I trust this? Is it appropriate? What does authorizing this enable? And is execution unfolding as expected? And I think those are great questions to ask about just about anything you're bringing into your environment, but becomes extremely important when we're talking about harnesses and MCPs and just any AI system.

And especially when we get down to the is execution unfolding as expected when we're talking about non-deterministic systems, gets really hairy potentially very quickly. Chelsea, what are kind of your thoughts about this other than probably wanting to rip out every hair you have? Luckily, my hair is still attached to my head. I will not be ripping it out only because it's highly entertaining at this point. But my, um, one of my biggest takeaways was just do— we need to do the basics.

We need to make sure that we are focusing on the basics and having good, healthy security hygiene. And that can help us with some of these, you know, highly scalable types of of issues that all of us are going to experience one way or another. And then the other thing that I was just truly fascinated by was the persistence and speed. And when I say fascinated, more concerned. Hugging Face reconstructed 17— over 17,600 agent actions from the intrusion.

Like, our human eyeballs cannot supervise that action by action. So it is cliché, but I am you know, in alignment with— we all need to be ready to operate against this kind of stuff at, at machine speed. So with, um, that— actually, one tangential thing, team. If you guys need to hydrate more in August and/or in September, you need to play the game where you look at all of the articles anywhere about cybersecurity, and if it says agent control plane, you need to take a drink of water, and you will be more than hydrated. I was really like wondering where that was going.

Way to bring that home. I appreciate that. Yes. And that comes to— well, let me tell you why that comes to mind, because, you know, we read a lot. It's part of our jobs as security professionals to stay abreast of everything that's happening.

Agent control plane and then attack path, like those are the 2 phrases that I am seeing repeatedly over and over and over again. Obviously AI, but you know, that one, that point is moot. So moot. So okay, moving on to number 8, comes to us from Chris Peterson of Radical. This one is CMMC Phase 2 is paused, the cyber threat is not.

So CMMC, and a friendly refresher for our friends, Cybersecurity Maturity Model certification is what it stands for, and that's a framework from the DOD, the DOW, to ensure that contractors and subcontractors in the defense industrial base are adequately protecting sensitive information when performing government contracts. So this story outlines how the DOD has paused CMMC Phase 2 for a 60-day review, mostly because of cost assessment capability and the barriers for, for smaller defense contractors. The kicker here though is, you know, the problem doesn't go away. So our underlying security obligations are still there. You still have NIST 800-171 requirements and DFARS requirements for protecting, you know, covered defense, and that remains in effect.

The biggest takeaway and argument that I saw here was that CMMC is definitely not a baseline, but it needs to— it needs to be part of your legitimate strategy. So use it as guidelines and then build out from there. Just because you can pass an assessment does not mean you— your org can accurately detect, contain, and respond to a sophisticated attack. Thoughts, Joe? Right.

I think you nailed it. Like the, the idea is always compliance is not necessarily one-to-one with security. Getting the certification does not mean hooray, we are secure for one more year. Let's hope for the best and just keep pumping product out there. The— I did like this article quite a bit.

I think it was a good summary of the pause, which is interesting because as I was researching and kind of reading for the show, I found a couple articles that hadn't or I would almost say more news just about CMMC than saying, hey, CMMC is paused. And I like this reasonable take that is also like, just because it's paused doesn't— you know, the train is still on the tracks. They're just kind of doing a quick tune-up. And so it will continue. Don't use this as a suspension of, oh, we can go focus on other things, because it is again just the pause.

Therefore, you will still need to get your kind of act together sooner or later. And as you said, Chelsea, if, if you can use this as, again, not just a baseline, but a way to kind of conduct and crosswalk across multiple frameworks, you're going to be in much better shape. You know that the bare minimum is not good enough in today's infrastructure and in today's kind of requirements for what's out there. So great, great stuff from the Radical blog. Yes, I will punctuate this entire article only to say that there's a distinction between having controls versus actually being able to defend against something.

So call out here for all of us, team, it's game time. Need to be ready. Put on your eye black, lace up your cleats. Got to be ready.

Absolutely. All right. With our 9th story of the show, we've got intelligent MFA should challenge risk, not loyal customers. And it's an interesting one from FusionAuth, fusionauth.io. And what I think you see in the world of MFA, as much as I think we like to kind of harp on it, beat that drum.

There seem to be numerous continuing parallels about multifactor authentication and passwordless, passkeys, all of the stuff that gets thrown. But really what we're talking about is the customer that logs in every day in the same way and looking at things from a behavioral aspect. Shows up as anomalies and what to look out for risk signals. Now, a fair bit of warning, this kind of does pitch the product a little bit in saying that FusionAuth 1.68 changes these following things, but I did like this bulleted list because they are good signals to key in on. So no shade to the FusionAuth team, but if you've also got other ways to detect or even better prevent high-quality signals in your MFA workflows, there's some great stuff here like bot detection, dormant accounts, some of the basics that I think sometimes we think we don't necessarily always ensure that they're working the way that they should, right?

Did your termination workflow actually revoke all those passwords, or is the IT guy that was, you know, 3 hires ago and is on to greener pastures still enabled in your Active Directory? Not really sure. The other thing that they touch on here is being able to prove to auditors, and that's kind of what I hinted at there, but I think it is that I mentioned non-determinism before, where MFA and identity really does need to be a very deterministic workflow. Chelsea, any interesting tidbits you found in this one? Yeah, I think we in security, just generally speaking, sometimes tend to overcomplicate, overarchitect things.

But if you think about it logically, if I am logging in every morning from the same device in same location, but I'm getting treated exactly like an unknown device coming from a specific location— not specific, suspicious location— that just fundamentally does not make sense. So in total alignment with that, I think that's absolutely where, if your org is not already there, absolutely needs to go just to help remove some of that customer friction, but also, you know, work smarter, not harder. And then the other piece that I loved about this is the I think the word was explainability. I don't remember exactly what it was, but how you can reconstruct why that decision was made. Because if we have an identity or an AI or fraud or anything related to that, we need to be able to speak directly and handle our, our automated security decisions and figure out why did we make that so we can adjust on it.

So as you had mentioned, good article from FusionAuth there solution and others. Good, good point to bring across. So moving on to our last article of the day is Pen Testing 101 Part 1. So you need or want a pen test? Biggest callouts for this article, and I'm actually going to get on top of my desk, stand on my desk, Joe, and scream this from the top of my lungs: vulnerability scanning does not equal a pen test.

Scanning is what identifies potential theoretical weaknesses, but pen testing is the badass activity that actually tries to exploit the vulns and determine the legitimate impact. So if you have a penetration testing finding, those are the oh shit, oh shiz, this is real, this has been validated. And sometimes that gets confused because there are different types of pen tests, and it really depends on your objective. There are, you know, compliance check-the-box pen tests versus the actual validation engineering pen test. And what I say to that, you know, what does good look like?

It's when either way, when you have your penetration testers chaining weaknesses together to determine if they can actually reach your crown jewels. As an application security professional, Joe, tell me your Pen Testing 101 thoughts. I, I gotta say, I love that you honed in on the one line that I was also very excited about because it's in big bold letters on this article. So agree, agree, agree. My, my thought here is really interesting because, well, it's my thought, so of course it's interesting.

But what I really think about this article is that I love this part about deciding what type of pen test you need. And I would actually expand that out to understanding what type of pen test your organization and your stakeholders are expecting, because they talk a little bit about— and you hit the nail on the head with the compliance versus risk reduction versus attack sim, because I have worked and I'm sure a lot of listeners have, have been in places where I would love to go order 3 different pen tests for each of these. I would like to reduce the risk, of course, that's part of my job. I would also like to simulate an attack so that I can feed my signals to my operations team, to my responders, and I've also got to give one out to the auditors and our clients are asking for one. So do I want to give them the one that is potentially all thorny and hairy?

I don't know, that is a business decision. But we also find that if you are just checking a box, we know it's more than likely going to be scoped pretty tight. I think I think we all are used to that security theater that's going to be, yes, we have a penetration test. Here's, here's the, the results from that on the, you know, the one IP or the one domain, and there were 5 informational findings that have all been remediated. Thanks.

Tells me nothing, but whatever. Realistically, as a security professional, I think we're all looking to just do a little bit better. The risk reduction— I love this graph that kind of shows the engagements and the mix between when you do a risk reduction type of penetration test, you're also doing explicit purple teaming, which can then also bleed into the ATT&CK simulation and key findings for your engineering organizations to also come back and say not, hey, we failed a penetration test. That's not the point. The point is, oh, we didn't think of this, or have we thought about a different way to do this?

Where can we— I mentioned earlier in the show, as defenders, we would need to look to break those chains. That's where an ATT&CK simulation comes in extremely handy to say, if we would have broken one of these 5 links or 3 of these 5 links in any order, they would have been dead in the water and we would have nuked them out of the systems and we would have been fine. So I, I am, I'm a huge proponent of penetration testing. I think especially in the AI age, sure, some steps become tool-assisted, but I am still a firm believer that the humans here come up with some really clever and interesting, uh, paths. So I'm really fascinated to see what part 2 has in store for this blog.

Very, very great stuff from Valerius team. Yes, we will have to keep everyone updated. And I have, uh, I don't know if this is an appropriate comment to talk about, but I'll say it anyway. As a security professional, I have had the opportunity to work with large penetration testing firms and the smaller boutique firms. And in my experience, if you are looking for someone to validate the risk in your business and truly give really healthy insights into meaningful insights of things that your organization is going to be surprised about or actually care about, my professional recommendation is take a look at some of the boutique penetration testing firms.

Just repeatedly I have seen just better value, less check the box, better value. So sharing that last tidbit of recommendations And with that, Joe, I will have you share some fun events that we have coming up for the rest of the month. Absolutely. And I'll stand behind you with that, with that one, Chelsea. I've seen incredible and awesome results and also just great customer service.

Those boutique firms, can't say enough great things. You can find a lot of them at these events. Look at that segue. All right. Coming up as we record this, it is August 14th.

So we'll be getting this out shortly, but you are looking at on August 18th, If Your AI Lies, Who's Liable? Now this is a virtual open discussion from Dry Run Security and Catalyst and InfoSec Map. You can find the details on the Colorado Security page to sign up via Google Form. Again, August 18th from 9 AM to 11 AM.

Beautiful. And then on the 19th of this month, we have a DenverSec monthly meetup from 6 PM to 8 PM, and that's in Denver.

And on the 22nd, there is an August mini seminar at the ISSA Colorado— or put on by ISSA Colorado Springs, excuse me, at the UCCS Kevin O'Neill Education and Research Center. That's from 9 AM to 12 PM down in the Springs.

And I am extra excited to announce this next one because it's a big deal with lots of great networking, lots of information sharing, and seeing bright and sunshiny faces. On August 22nd is the Colorado Equal Security Summer Picnic, and that is going to be 11:30 AM to 2:30 PM at Clement Park Shelter A. And once again, that's the You know, big deal of the year, the Colorado Equal Security Summer Picnic. Oh yeah, that one will be great. Good.

I'm so excited I can't get my next sentence out. August 26th, 2026, ISC Squared Pikes Peak August chapter meeting. So far it says to be determined or hybrid type of meeting, but that'll be from 5— nope, I don't think it's from 5:30 PM to 6:30 AM. It'll be sometime.

That's a lot of quality time, a little too much for me. I'd be peopled out by then.

All right, and next one, also 8/26 from 5:30 to 7 PM, is Denver ISSA AI/ML Special Interest Group with our friends over at Trace 3. And our last one on August 27th is Mile High OWASP from Denver OWASP, of course, happening from 5:30 PM to 8 PM. 8:30. And with that, that's all the events and that's all the news to care about in Colorado security. Uh, Chelsea, any other tidbits or nuggets of wisdom?

The only nugget of wisdom I have is that I hope all of you have an amazing and productive day and take care. Oh gosh, you're always so sweet. Um, I will remind everybody just to, uh, register for all the events, check out the Colorado security website Uh, and that will do. I thought I had one more, that's why I'm like just dragging out my sentence, but it's just not coming. So thanks for listening to episode 287— 288.

Geez, the sabbatical's killing me, Chelsea. We gotta go, we gotta go. Thanks everybody. Okay, bye.

Director of Cybersecurity Operations at Movement Mortgage. Welcome to Colorado Equal Security, for Colorado security professionals by Colorado security professionals. Today's episode isn't just about cybersecurity. It's about reading people, decoding rooms, and surviving that psychological jungle that is a technical meeting. And nobody, nobody breaks this down better than Marcus Rabello.

Because here's the twist: we're not just talking about meetings, we're talking about human psychology. The same psychology behind dating, interrogation techniques, and the subtle art of getting someone to tell you the truth even when you don't want them to. Marcus draws this wild but perfect parallel: dating and interrogations use the same psychological levers— rapport, mirroring, pacing, and strategic silence. If you can extract honest answers on a first date, you can extract honest answers in a CMMC audit. And that matters now more than ever because we're entering an era where AI is amplifying everything— the good, the bad, and the dangerous.

Employees are using AI tools without guardrails. Companies are feeding sensitive data into systems they don't understand. And organizations are building AI-powered workflows with zero governance, zero privacy controls, and zero awareness of the risk. So today we're diving into all of it. How to read a room is a superpower.

How dating psychology maps perfectly to technical discovery. How interrogation tactics can help you uncover the truth behind a client's maturity level. And why AI without governance, privacy controls, and responsible use is quickly becoming the biggest cybersecurity risk in the modern enterprise. This episode is part psychology masterclass, part sales engineering therapy session, part AI wake-up call, and 100% Marcus Ribello at his absolute best.

You kind of lose the rest of the room. And, and that kind of goes back to, you know, when you said earlier, read the room. Let's— Absolutely. Okay. Well then let's put you in the situation.

You're walking into a room and you've never seen these people before. What might be some key indicators that you, that you, with all your experience in sales engineering, would say, oh, this guy's gonna be that person, either that questionnaire, the smartest person in the room, maybe the skeptic, maybe the person that, you know, where is there some emotional signs? Is there some psychology? They're tapping a pen, something along those lines that you're willing, of course, to share with our audience that would say, right, watch out for these indicators. Yeah, absolutely.

It's all of the above. So it's, it's visual clues, visual indicators. It's going to be psychological indicators. And, and by no means am I a psychologist or psychiatrist. I did not play on TV.

I didn't stay at a Holiday Inn Express, none of that. So I, I— but I will tell you, there are all of these telltale signs. And if you think of it like poker, you hear people say, oh, you have a tell. And, and you're watching and you're paying attention to those things, they're gonna have a tell as well, and lots of different tells. So if somebody walks into the room and they're wearing different colored socks, that's a tell to me.

They're either A, they're colorblind, or B, they are so focused on all these other things that their brain is going off on that they are really that engineering-minded person, and that's probably going to be one of the smarter people in the room. You're going to have how, how they show up, how they're dressed. You're going to have how they came prepared. Did they come prepared with any note-taking tools or not? And honestly, the ones that don't come prepared with note-taking, getting anything, whether it's digital or, or written, you know, if they're bringing a pen and paper, if they don't bring anything Those are the scary ones if they remember things, because those folks that have that photographic memory or, or excellent memory, those are the ones that are then taking it in, processing it, and coming up with questions, answers, and things to stump you, or, or things that may apply that we may not have thought of on the fly.

And then there's a bunch of other tells. You look at the way that they sit, their posture. Where do they sit? Who do they sit next to? What do they bring into the room?

Do they bring coffee? Do they bring water? Do they bring All of these things add up and you kind of, you're essentially sizing people up, not necessarily WWE style, but you're, you're sizing people up when they come into the room. And it could be that somebody, it's not 100%, somebody may have gone to a wedding, a funeral, or a special occasion that day, might be in a suit they wouldn't typically wear. So you might misread some of these things, but you can almost always tell by their mannerisms and what they carry into the room.

What their role is going to be and whether or not they're there to, to do something. And I think, again, same thing is true in cybersecurity. You walk in and you see different people in the room. You know who the person that's going to be responsible for the wording and policies are, right? You know the people that are going to be responsible for the actual implementation of it.

And then you have the one guy at the end that everything's going to flow down to that's going to get stuck having to do the work on the weekends and nights. And that person's just there. They don't typically talk much, but they're, they're in the back of the room and, you know, it's just going to roll downhill to them. So I think that's the way I've learned to do it. And if I'm— if I can put a shameless plug out there for an author, this is— and I don't want your audience to take this the wrong way.

I don't want you to go out and start learning how to pick people up. It says this is a pickup book. It's about picking up women. But I made it required reading, and it used to be required reading at the FBI Academy.

Shit. But I'm the one that comes in and, you know, you can't see my setup right now, but I've got my laptop, I've got my iPad, I've got 2 phones, my water, etc. What are you thinking when you come in and you see me? Well, how do you size me up WWE style? This could go 2 different directions.

Like you said, it could have been on purpose with the socks. You're, you're bringing it in. Could it be chaos? Sure, that's a possibility. But it's everything else that you do.

It's where do you set your phone? Where do you set your water? Do you just like drop it on the table? Okay, then we know this is just chaos. But if you're taking everything meticulously and putting it there, if you're setting yourself— setting up your work environment and then looking over at me, that tells me something completely different.

That tells me that you have a lot going on. You can do a lot at once. You're obviously multitasking, and you're not going to just do it physically you're doing it in your brain because you're having to account for all of those items that you're taking with you everywhere, how you set that up, the placement of them, how you're going to use them while you're in a meeting. People don't just take stuff to a meeting unless they're getting ready to leave on a trip right after the meeting. You're not just taking random stuff.

Things have a purpose. And if you're taking things without a purpose, that also tells me something. Like, if you just brought a notebook, set it down, and didn't do anything with it, I've learned something about you from that. Okay, so, so what does that tell us? What, what does it tell us if we set down the notebook and we don't have something there?

Again, everything has multiple possibilities. Go back to my movie quotes. We're doing the, the chaos theory quote from, from Jurassic Park: has infinite possibilities for where the water droplet can go. It tells me one thing. The first thing it says is I'm gonna say, how are you dressed and how did you show up to the meeting?

Were you on time? Were you early? Were you late? And then also, what else did you do in the meeting? If the notebook never opened, it could be that I never told you anything important enough for you to write it down.

So there was no point in you opening the notebook. They didn't want to be at that meeting. They were there because they felt they had to be at that meeting. So there was nothing they were ever going to take. So at that point, right, I'm looking to see the notebook never got opened initially.

My first thought is either they don't want to be here, they don't think that this meeting is relevant to them. Or they're already planning on leaving early. In all cases, my number one thing is to engage with them immediately and find out what is their agenda, what do they need to hear, what do they need to do, and figure out if I can either make it important for them or cover any data that they're looking to need before they leave. Okay, that's a great strategy though. I mean, that— and that can, I think, apply to more than just sales engineering.

Absolutely. Yeah, absolutely. Okay. And then the most dangerous on the opposite end, the most dangerous it sounds like like is the one that comes in with nothing, no notebook. Maybe they have their phone, but it's on in their pocket, and they don't— but they are able to ask and regurgitate questions.

They could be the most dangerous. Yeah. And, and the reason for that is you don't have any idea what's going on in their brain until they start speaking. So are they, are they able to do it, or do they just not care. It could be, again, that they came to the meeting, they have no interest in the meeting, so there was no point in them bringing any note-taking devices or paying attention.

Or it could be one of those people that has everything in their head. They're one of those folks that never documents everything but knows how everything works. And in the company, you have a— you always have a few of those. It could be one of those individuals, again, with a photographic memory or just a really good recall. And those individuals, until they speak you don't know really where it's going to go because you had no tells.

The only thing you have now is their appearance, how they present themselves, where they sit. Okay, well, one last question and then we're going to move on to a different section here. Yeah, of course. But you've mentioned a couple times of where they sit. So I'm in a conference room right now, standard rectangular table, 8 chairs.

Of course, we've got at one end or at each end, we've got kind of that single table, and then we've got 4 or 5 chairs along the side. Why does it matter? Does it, you know, the sitting at the end— if I take a chair at the very, very end, what does that mean to you? It depends on all the other factors that go into it. Okay.

But typically you're going to leave the chair at the end for the highest-ranking individual that's coming into the meeting. Typically, not always. Sometimes somebody likes to just take that chair and they're one of the folks that are just that guy who knows everything, or the gal that knows everything. They may just want to take that chair because they want to sit there, but typically it's going to be reserved for the highest-ranking individual. And then when you see people shuffle in and sit down, their, their location, their proximity to the other individuals from their company is going to tell you how comfortable they are being in the meeting with you.

If they all sit on one side and you're all on the other side, that's the first thing I do is I walk in and I break that up and I go sit on the other side before they, before they can take all the chairs, because I want to break them up. I don't want them all huddled on one side. I don't want it to be an us versus them. You always want to show that you're there to be a partner, that you're there to help them, and you don't do that when it's in an adversarial situation. And that's what those tend to set themselves up for.

Again, I'm not a psychologist. These are just techniques that I've learned over the years from various books, individuals, and experience. But I do know that there is a lawyer out there who has a big LinkedIn and YouTube presence. He's got a lot of different things, and his whole thing is about arbitration and how to deal with people in hostile situations during arbitration. And he teaches some of these things about how to avoid it and go sit next to them so that they don't feel right away you've de-escalated a situation from it being you versus me by me being right next to you.

The other thing, the other thing is if they sit up against the wall, they're either typically the people who feel that they're the lowest on the totem pole, or they're the people who feel that they don't have anything to get from the meeting. So I want to engage those individuals to give them a nugget, something worthwhile, or at minimum try to build rapport with them while they're shuffling in prior to meeting. Okay, okay. So be early to the meeting, try to figure out where you want to sit, watch the other individuals as they come in, and try to break it up, try to become their friend. And again, these are techniques that can be used outside of sales engineering.

They can be used in almost any meeting.

Before we dive in, let's talk about the stump the chump personality. Every big meeting has one. If you don't see them when you walk in, don't panic. They're waiting to ambush you with a protocol question from 1997. The different dynamics in a room.

The hard part I find— this is an interesting story, Frank— the hard part I found about being a sales engineer is that you almost always have in a large organization or, or in a big meeting, you have one guy in there that comes and he's the stump the chump guy. So you're doing your job trying to explain what it is that your company does and, and what you're selling and how it works and how it may address their issue. And this guy comes in here, or gal, infrequently on the ladies, but usually it's a guy that comes in, do the stump the chump, and he's just asking every technical question under the sun. He might get down into nitty-gritty architecture, he might get down into protocol questions, but he's there for one reason. It's because he wants to make sure that he's the smartest guy in the room.

So understanding that person and being able to not fall into that trap, I think, is a key soft skill. Well, from there, I had an original question while you're talking. Yeah, but when we're talking about that Could that person though be there to discredit you? Yeah, they could not make the sale. Could it be there to, oh well, you know, Marcus doesn't know what he's talking about, so we should receive a 20% discount?

You know, you know, you sound like you've been on the other side of this purchase process. I will admit nothing on a recorded podcast. You know, there, there are cases where management will purposefully invite that individual knowing full well what they're going to do. There are cases where they're just including them for, you know, technical completeness because that's their role and they're a great person to just have there. But that individual's personality and that individual's knowledge and want to have everyone know that they have that knowledge, whether it's particular to an area or just being the smartest person in that room at the time, They may be there on purpose and they may be there on accident, or they just may be there as a participant.

Either way, it's not really something in my experience that a manager is going to say, hey, just go in there and do the stump the chump thing. Typically they'll say, hey, we need you on this call and just make sure you ask the hard questions. And that's usually enough to trigger that individual.

All right, before Marcus explains how to handle the Stump the Chump personality, I need to confess something. Allegedly, hypothetically, with air quotes so thick you could build a firewall out of them, I might have been that guy once. You know, the person who shows up to a meeting ready to unleash every obscure protocol question, every architecture deep dive, every RFC reference known to mankind, and not because anyone asked, but because my ego did. So I asked Markus the only logical question: How do you deal with someone like me? And his answers are both brilliant and absolutely hilarious because it turns out the best way to handle the smartest guy in the room is to let him be the smartest guy in the room.

What is your best advice? You know, I mean, I maybe I will admit that, you know, I will allegedly I'm going to use the air quotes here. That was that person. Listen, what is your advice to deal with me? How would you do that?

I mean, you can answer every technical question correctly. Yeah. But what would be some advice that you would provide to our audience today to try to kick that down? I think it's an easy answer. And the easy answer is I'm going to let you be the smartest person in the room.

And I'm going to reinforce to you that you're the smartest person in the room. I'm going to tell you that that was a great question. I'm going to tell you I don't know when I don't know. I'm not going to make up an answer. I'm going to also reiterate when you bring something up that you're absolutely correct.

And occasionally, depending upon what it is, I might even say, you know, I wish I'd have thought of that. But what I'm doing is I'm validating you, I'm acknowledging you, And I'm not trying to compete with you. Call it a Lord of the Flies situation, right? Or one of, one of these situations where you're out there, you're not trying to be the big dog in the room. If you try to be the big dog in the room as, as a technical person, and I find it's true in cybersecurity and situ— in a lot of those situations as well, that's where you get into that contest.

And you're not trying to do that. You're trying to avoid that. You're trying to be in the situation where you are the individual that's presented the, the information, you've presented the product, You presented the solution, and now you're letting them soak that data in and determine what, what they want to do next. But if you, if you try to go toe-to-toe with that individual, what it does is it detracts from everything that everybody else in the room is there to do.

Yeah. Let's shift gears for a little bit here. We've been talking about sales engineering, but as I look through your profile, you've You've obviously had a very long career in sales engineering, including both hands-on, or I guess, you know, vice president, director, et cetera. But then all of a sudden, but you know, at one point in your career, you know, and still a little bit, you've been a CISO and head of AI. And those of course are, are 2 different things.

So let's start with that CISO portion. What was that pivot point in your career that said, I want to switch from sales engineering, technical execution to strategic leadership because they're two different ways? Yeah, that's a fantastic question, Frank. And I know looking at that, you kind of wonder, that seems like a weird way to do it. My entire life, we mentioned I started with computers back in the '80s and doing some of the things, you know, for me, back then hacking had a different meaning, and it might still today too for purists.

Hacking meant— oh, we talk about, you know, hacking your body, The 4-Hour Body from Tim Ferriss. You talk about, you know, your hacks for morning routines. You talk about hacks for getting— so hacking back then, the meaning was you were just trying to take it apart and understand it, figure out how it's going to work, and use it in different ways. So for me, that held a really awesome place in my heart because growing up on a dairy, I wasn't going to milk cows for my life. So I was always having to reverse engineer things and figure things out to make things work.

And so it was really cool with a computer that you could do all of these different things now. So hacking to me was very, very cool. And, you know, figuring ways around different things. People put a control in place, you work your way around a control. You know, the modems came out and we had so much fun with the modems when they first started and doing voice when original 8-bit voice that we could do way back in the days.

So all of that stuff was fun. None of that went away. That was always an underlying thing. So I always played with security, whether at home, at work. I did a lot of different internal things throughout my career that always involved some level of cybersecurity, even, even working my way around a network at HP when I was there so that we could play Warcraft.

That was fun. We had to create our own subnetwork so we didn't get picked up. It was all after hours. But it was on retired equipment and, you know, it was fun though. It was, it was a neat thing to do, but that never went anywhere.

So I always had some level of cybersecurity involvement. And I mentioned earlier, the SEs are kind of the bucket for, for everything. Well, being the SE leader at the time and having had that background in cybersecurity and still doing a lot of things at home and, and with projects separately. I would get questionnaires for cybersecurity, and the questionnaires would— well, they would, they would come to the SE team, and the SE team would funnel them to me because they didn't know the answers. They weren't security questions about the product.

They were real cybersecurity questions about, have you gone through any audits? Have you done a tabletop exercise? Is your product certified? Have you gone through and done any of the— are you doing any scans? Veracode, you know, at the time, and, and other different code scans?

Are you doing any kind of penetration testing? Are you— all of these different cybersecurity questions to which the sales engineers went, that's not my department, let's get this, let's get our, our CISO to do that. Well, we didn't have a CISO at the time, so they funneled their way down to me, and after about 2 questionnaires, they started asking some things about attestations. And I went to the CEO and I said, look, I would love to answer these for I can't. I'm not putting my name on something that I have no control over and that we can't actually say that we're doing.

So I can answer these questions and, and you can farm this out, or you can have one of the sales guys answer these, but I'm not gonna lie on it. I'm not gonna commit to something that we're not— All right, buckle up because Marcus is about to reveal something he claims he's never said publicly. And when a cybersecurity executive starts a sentence with, I've never told this to anyone, or, you know you're about to hear a confession, or a felony. Luckily, it's neither. It's weirder.

Marcus admits that one of his secret weapons for extracting accurate information from clients, especially during CMMC prep, comes from a book that was absolutely not written for cybersecurity professionals. It was written for dating. Yes, dating. So I had to ask him, are you telling me that dating and interrogation have something in common? And Marcus basically says, well, I wouldn't call it interrogation, but it's pretty close.

Because the techniques in this book, The Game by Neil Strauss, were so effective at reading people, building rapport, and getting honest answers, the FBI Academy allegedly taught them, which means somewhere out there an FBI instructor once said, okay class, today we're covering threat modeling and also how to talk to someone at a bar. Marcus uses those same psychological levers— mirroring, pacing, subtle prompts— to get clients to tell the truth about their policies, their maturity, and whether their tabletop exercise was actually just lunch at Taco Bell. So let's dive into this, because if you've ever wondered how to get real answers from a room of mismatched SOC engineers, overconfident executives, and people who swear their security posture is perfect, Marcus has a technique that's equal parts FBI psychology and questionable dating literature.

And it's not because it teaches you how to pick people up so much as the interactions that you do with them and how to extract information from them. And it's called The Game by Neil Strauss. Now, I've never publicly told anybody this. This is one of my training secrets. And of course, at this day and age, it could be considered controversial.

However, it is phenomenal if you take the techniques used in there and you apply them to your conversations that you have with people. You can get the information that you need to get to do the things that you need to do, whatever role you're playing. Whereas if you come at it with your typical, well, let me ask you this, or what are you doing, how many people are you, how big is the organization, all these types of things, right, that you go in there to do discovery for any, any type of call, it's very, very different when you come at it at this other angle. And you'll find that if you ever do read it and and think about the techniques and how to apply them, not for necessarily picking people up, but for extracting information, I think you'll, you'll find it's wildly successful. So you're saying that dating somewhere has a relationship to interrogation?

I wouldn't say interrogation, but yes, very close to interrogation. Is it— dating is all about learning about the other person, understanding them, learning what they like, what they don't like, how they respond to different things. So it's akin to that. Yeah. And, and the techniques in there, again, used by the FBI Academy so that they could get information out of people.

These are different techniques that had no business necessarily being taught in law enforcement, but there they were because they're effective. Same thing with sales engineering, or if you're going into cybersecurity and trying to find information about— we did a lot of CMMC preparation. So for those clients of ours that had that, you know, you have to extract all this information with where are you, what have you been doing? And of course, everybody wants to tell you, oh, we're doing so great. Yeah, we have a policy.

Yes, we've implemented this. Sure, we've done tabletop exercises. Well, doing it at Taco Bell at lunch while you're talking about security doesn't count as a tabletop exercise. So all of these, all of these things become types of data that you need to extract in a way that's going to be reliable and accurate. And those techniques work really, really well.

And again, I'm surprised I said that now I'm thinking about it. Twice, but your audience could have it. It's, it's a pretty old book now, and the techniques still work. You're not going to use the examples out of the book, but the techniques themselves still work great. Okay, so, but if we were having this conversation not at Taco Bell but at a really nice Mexican restaurant, that can be a tabletop exercise is what you're saying, right?

Well, while I haven't successfully seen one of those performed at a restaurant of any kind, It is possible, however unlikely, that you could count that if all of the right individuals are there and the roles are assigned and you do it properly, potentially. I like that. There's a— you'll find, Frank, I love movie quotes. There's a quote from a movie called The Avengers, and I don't mean the one from Marvel. It was— this was a remake of a '60s British TV show with, with actually Sir Sean Connery was in it.

But there was a quote in there. It says, nothing is impossible, merely improbable. I often think of 6 impossible things before breakfast. So that quote to me kind of carries through everything. Nothing is impossible.

It's just the likelihood of it being possible makes it improbable. Okay, kind of— isn't that also along the lines of Sherlock Holmes? It could be. It could be. Yeah.

I mean, okay. Well, let's go back for a second here and let's talk about, you know, you walk into that room, you see the person with a different color sock. Box. Yeah, probably carrying a lot of different devices, notepads, maybe a coffee, maybe a water. And you're thinking chaos, right?

Thinking that they're thinking— I, I'm guessing, I'm trying to emphasize, but, and if I'm wrong, then, then please correct me, because for one thing, that's me. I'm the person that's coming in. Uh, sometimes the socks are mismatched on purpose. Sometimes I just don't care enough.

What happens next in Marcus's story wasn't a strategic pivot. It was an avalanche. The security questionnaires, the compliance checklists, the prove you're secure demands— they all started climbing the organizational food chain until they landed squarely on Marcus's desk. And at that moment, he wasn't just a guy answering technical questions. He was the person responsible for every sales engineering responsibility globally.

The buck stopped with him. And that's when he had to say the words no executive ever wants to say: we can answer all of these things, but we're actually not doing them, and I'm not putting my name on it. That was a breaking point, the moment the company had to stop pretending and start doing real cybersecurity. Not checkbox security, not marketing security, actual operational defensible security. And here's the wild part: they had zero breaches up to this point.

Not because they were mature, not because they had the airtight processes, but as Marcus puts it, they were lucky. The products weren't code-signed. The attestation documents were optimistic. The VeriCode scans were basic at best, and many of the claims being made simply weren't true. That wasn't a pivot, that was a reckoning.

But instead of collapsing under the weight of it, the team did something extraordinary. They went from almost nothing— no code signing, minimal scanning, no formal governance— to having 2 of their 3 applications fully state compliant. And they did it in less than 18 months. That's not a pivot, that's a transformation under pressure. It's a kind of organizational shift that happens when the truth finally outweighs the convenience of pretending.

And Marcus is honest about it. This wasn't a heroic moment of foresight. It wasn't a strategic roadmap. It was a pile of responsibility falling on top of him, forcing the company to evolve. And that's what the story makes so powerful, because today Today, with AI exploding across every department, companies are again making claims they can't back up.

We don't store customer data. We don't use AI for sensitive workflows. We have governance in place. Our employees know what they can and can't upload. Just like Marcus's experience, those statements often fall apart under real scrutiny, and the danger now is exponentially higher.

AI isn't just a tool, it's a data vacuum. It's a compliance risk multiplier. It's a governance nightmare if you don't build the guardrails early. Marcus's story is the perfect setup for the modern challenge. Companies don't pivot into security, they get forced into it by audits, by incidents, by truths.

And in 2026, AI accelerating that truth faster than ever.

I guess, correct, correct. Just push that into you. And with that, okay, with that portion in there, what would you do? I mean, I think there's quite a few people on the podcast, maybe not in the CISO, but have had that responsibility pushed down to them, like it or not. This is now your job.

What is your advice for that?

Well, depending upon your beverage of choice, sit down, take a deep breath, grab yourself a coffee, hot cup of tea, a Monster, whatever it is you need, and just kind of take it all in for a second. And you got to understand that it is the analogy of the elephant. Right? You don't know what you don't know, but it's a huge, huge elephant. It's a huge meal that you're gonna have to start eating one bite at a time.

Any way to approach it is really just gonna be— I, I'm not gonna say you should do X first or Y first. It is 100% firefighting, and it is 100% based off of what's coming at you right away. If you have nothing, no protections in place, first thing is you got to get some kind of shell to buy you some time, right? If you have no policies in place, well, unless you're going through an audit, you know what? A lot of guys out there are going to say, no, no, no, policies can wait a little bit because you have nothing to base them on, right?

Let's get some core things out there. Let's get a SIEM in place. Let's— how about this? Let's get some anti-malware tools deployed. We didn't even have that done.

So, I mean, it was just firefighting. So my advice is going to be just sit down, take it all in, start writing stuff down, making your list, and prioritize the list, and understand that it's going to be fluid. It's not going to be perfect. And depending upon where you are, most people aren't going to be at that point anymore. I don't think we're far enough beyond that now.

That was many years ago. So now I think we're, we're at the stage where you're not going to inherit nothing. You might inherit something, and you're still going to, I think, take the same approach of what is it I have to do, what do I have, and let's analyze that. Ironically, that whole process is something I started to write in a book because another CISO of a Fortune, Fortune 10 company, he's a friend of mine, he said, if you write all this stuff up that you did, I'll write the foreword for you. So I might hold him to that.

But that whole process of just taking it all in, understanding what you have, figuring out how to divide it up into sections and say, okay, now what am I missing? It's just a triage. To see what needs to come first. And then of course, if you add on top of that, hey, we have this opportunity that requires us to be STIC compliant, you're, you're now running multiple streams, you know, the baseline company stuff and a product stream. So you become almost a product manager for cybersecurity as well.

So it just, it layers on top of itself. I wouldn't recommend anybody just take it sitting down. Make sure you ask for more money. Make sure you ask for a title Make sure you ask for, for the authority, right? At minimum authority in writing, which is one of the things I had to do because I had to start doing all kinds of testing and scanning.

And, you know, you have to have the authority to do it. So that's my advice. Yeah. Don't take it sitting down, sit down first, analyze everything, but then stand up and say, okay, you know, you need the authority and now you got to go ask for something because they just dumped a lot on you. So go make sure that you're I mean, in a polite way, in a respectful way, let them know the amount of work that now just got dumped on you and you're happy to do it, but you're going to need a few things.

And you're going to talk about, you know, the extra effort that's going to be involved in terms of compensation in some form or fashion in the near future. So compensation, authority, you know, try to make sure that you have the ability to make the changes, not have your hands Yeah. Okay. And, and the, the big thing, I think a lot of folks, and I could be wrong, but nobody steps into a role and knows everything that they need to do. So there's some research that's gonna happen because you don't know what you don't know as a CISO, as a brand new first-time CISO.

Do you know what you're supposed to be doing? Do you know what's important? You might know what somebody said on a video, but how does that relate to your company? How does that relate to what you have? How does that relate to where you're going?

You're trying to go. That's all going to be things that you're going to have to piece together and put that puzzle together for yourself. But you don't know what you don't know, so you need to sit down and understand what are all these things. You know, what is vulnerability versus what is your code scanning if you, if you have a product, right? That's going to be different.

That's going to fall in engineering, but you still have to be a part of it. What is going to be your compliance strategy? Do you have— what do you have to comply with? Is it basic stuff Do you— are you— hopefully you're not a public company and you're in this situation. Might be possible, especially with some of the older legacy manufacturing companies, right?

They have a lot of stuff that's been off to the side for years and they've been checking boxes and now, you know, things come full circle. But I think understanding all of that and making sure that you know what you need to do, because no first-time CISO gets a book saying, here's what you're going to do. And here's how you have to do it. It's different by company. It's different by vertical.

Well, I think that's true with almost any role, right? At least especially at the leadership side. Okay. Well, let's move on to your head of a— doing. So he said, you know, in the— I guess the best analogy for this is to think about the knighthood ceremony over in the UK that Queen Elizabeth used to perform.

And I was then dubbed with the sword right then and there. It was more of a pen, it. You are now dubbed the CISO in addition to your day job running sales engineering. Go make all of this stuff happen. So in the matter of a week, I now had the responsibility for all of cybersecurity for the company and built it from the ground up.

Okay, so, well, I guess 2 points here, right? First off, you know, you said that a lot of times the sales engineers are buckets for the company, but then you said that they're pushing back. But the other part is that, and the second part here is that some people strive to be CISOs, but it looks like you had it dumped on top of you.

So the catch-all bucket is we get these questionnaires, we don't know what to do with them, right? From the sales guys, the AEs, and other departments. So they dump them on the sales engineers saying, we have client questions, go answer them. Them, here you go. They get to a certain part where it has nothing to do with their job of knowing the product or the solution or what they're going to sell or what they're going to solution with, and it becomes more about the company.

That's where they say, well, we don't know, we don't have this data. So it works its way up the food chain, in this case to me who owned all of the sales engineering responsibilities globally. And it got to the point where I said, look, we can answer all of these things, but we're not doing this as a company. I'm not going to put my on it. That's when the shift had to occur to real cybersecurity for the company.

And that was a good shift. It was maybe a little bit tardy, a little bit late in the game, but it taught us a lot. We'd had zero breaches to date. I think a lot of that was based off of luck, if I'm being honest, you know. And the, the products weren't— they weren't code-signed.

We didn't, we didn't have code-signed products. We had some basic Veracode scans going in, Um, but a lot of the attestation came down to things that we just hadn't done or weren't doing. So we went from there, and ultimately, if you can believe this, we went from that starting point of almost nothing to having both— or 2 of the 3 applications. We acquired 2 companies along the way, so at the time it was both of the technologies, but 2 out of the 3 ultimately were STIG compliant. So we went from zero to STIG compliance in less than 18 months.

So you actually didn't have that pivot point where you decided to shift, you had it more fall on top of you.

We've talked about meeting psychology, dating as interrogation, mismatched socks, Taco Bell, tabletop exercises. So let's shift gears before this turns into a full-blown therapy session. Because at some point in every technical career, you hit that moment moment when someone asks the deceptively simple question, what's the actual difference between a sales engineer and a solutions architect? And the room gets quiet. People look around.

Half the audience pretends to know, the other half Googles it under the table, and one person says my favorite phrase with a politically correct and totally worthless answer: it depends. Which is a universal sign for nobody wants to commit to an We decided to tackle it head-on. Markus has done both roles globally at scale, sometimes by accident, so he's uniquely qualified to break down the difference without turning it into a 47-slide PowerPoint.

What is your definition between what makes a sales engineer and a solutions architect? Oh, great question. So I think sales engineering is more focused again on the front side of it with the top of the funnel. If you're talking about a sales process, you're really talking about top of the funnel down to the sale. Solutions architects are typically individuals that are brought in and purely technical, and they could also be in the sales cycle beforehand, but they're typically architecting the solution.

I did this job for a company called Wipro which was actually by acquisition that I ended up there. But the idea was to architect the solution for the client. And when you're outsourcing things like this company was doing, we were architecting through a variety of different things being put together and bodies. So it would be, okay, you want to architect yourselves out of this particular thing that you were doing, or you need a solution that's going to meet your needs for your partner portal going forward, like we did for Avaya. Those are the types of things that a solution architect would be involved in, quote unquote, architecting, if you will, where a sales engineer isn't necessarily going to architect a solution, although they may architect the product that they're responsible for to meet the needs of that particular use case.

They're not bringing together a database and a front end and, and some kind of IAM, right, identity access management, or these different components that are going to orchestrate all together in a giant solution.

How important— like, what would be the key skills to become either a sales engineer or a solutions architect? Oh, another fantastic question. You're asking me questions that nobody asked me except during interviews. This is fantastic. So I, I think the key skills for sales engineering solutions engineering and architecture and cybersecurity are very similar in the sense that you have to be very, very good at a lot of different things.

So you have to understand in sales engineering what it is that you're, you're selling, what is it that you're, you're supporting the sale of. Whereas as a solutions architect, you're understanding all of these different things that come together. I mean, we're, we're here on a call, we're recording. If you actually break down all the things that have to happen, right? The network connection, the firewall that's up there, making sure that the application's going through.

All of these different things have to happen. Today it's so easy for us. We're clicking buttons and saying allow and opening ports and just letting software through in some cases. But when you're doing that with solutions, all of the things that have to happen are a little bit more complex and you have to understand them. You have to understand databases to some degree.

You have to understand access identity control. You have to understand roles and responsibilities, role-based access control. You have to understand where the data is going, where it's going to live, who's going to be doing what, how is it important, and what the ultimate goal that it's supporting is going to be. Because you're architecting all this thing together like a building. You have to have all these pieces come together.

And cybersecurity, if you don't understand all the different components that build up all of the different things, right, you have to understand networking, you have to understand policies, you have to understand controls, you have to understand the different types of, you know, whether somebody's different hardware, different operating systems, things that they're going to be doing. You have to understand different firewalls. Not everybody uses the same firewall. So all of these different things I think are more important in solutions architecture and cybersecurity, whereas in sales engineering, depending on what they're doing, they can be focused on a product and just know it. And again, to some cases regurgitate it, but in some cases they're going to have that bigger E and be more engineering-minded.

It. Okay, what about soft skills that are important? Oh, fantastic, fantastic, fantastic. So I've always said, give me somebody with a personality and I can teach them the software, the hardware, teach them how to be the engineer part of it. I cannot teach an engineer how to have personality.

Soft skills are hugely important on the sales engineering front because you're interfacing with a variety of people, everybody from potentially the C-suite to somebody who's at a very, very technical level that's evaluating the product, who may just be focused on technical components. And that's great, but you have to span that whole range as a sales engineer. As a solutions architect, less so. It's still important. You're going to be interfacing with a variety of people, but your job is really more to capture the knowledge that you need to build out and architect that solution.

Less front-facing. And then on cybersecurity, depends on the role that you're playing. But from a sales engineer perspective, absolutely must have the soft skills, must understand how to read the room, speak to people, know when to be quiet, know when to play good cop, bad cop, or good AE, bad AE, bad SE with your, with your folks there and understand.

We're heading into the final stretch of the podcast and this is where again, get spicy. Because up until now, we've talked about meeting psychology, dating as interrogation, mismatched socks, Taco Bell, tabletop exercises— all the fun stuff. But now we're shifting to a part of the conversation where Marcus says things like, if you don't want to sleep well tonight, I'm the guy to talk to. And he means it. Instead of asking the same tired question everyone asks— what's the danger of AI— we decided to go straight for the jugular.

How do you govern AI when it's already everywhere, already embedded, already unavoidable, and already smarter than your firewall? Because AI isn't coming, it's here. It's in your browser, your email, your CRM, your phone, your cloud, your MCP servers, your Copilot splash screen, and probably in places you don't even realize. So in this final segment, Marcus walks us through Why governance is harder than anyone admits. Why policies alone won't save you.

Why shadow AI is the new shadow IT. Why corporate accounts isn't as safe as you think. And why machine learning models escaping lab environments should make you rethink everything. This is the part of the podcast where the stakes get real fast. So take a deep breath, grab a drink, maybe hug your firewall, and let's dive into the question nobody wants to ask but everyone needs answered.

But I'm not going to ask that question that everyone asks of what are the dangers of AI, all those things, because I think they've been asked 100 times and I don't think that they've been answered. I don't think there is an answer. So I'm going to answer— ask you a question that you might be able to answer, but it's going to be a challenging one here. For there How do you do the governance for things like AI? Because obviously it's coming down and, you know, anybody, I think anybody listening to this podcast knows you can't avoid it.

It's going to be integrated like it or not. How do you have the need for governance on it or do you build a glass house?

Wow. So I think there's a lot of different ways. I'm going to start with a history of the last 12 months first, just because I think that's pertinent to the answer. So 12 months ago, what are we talking, July of last year, we were talking about people using AI at home, at their work, really unfettered. They're just connecting to a URL and they're just using it, whether it's OpenAI or whether it's Anthropic or whether it was Gemini or Or I like to call, by the way, you'll hear me reference Clippy 2.0.

That's my name for Copilot. So if I reference Clippy 2.0 for your audience, that's what I'm talking about. Um, so those that can remember back to Clippy. So it was just really a link and there was no real way. I mean, yeah, you can do some firewall traffic controls and some other things, but the reality was you didn't know about it 12 months ago.

You knew AI was out there, but you didn't know how many people were using it, what they were using it for, what they were putting in it, what kind of accounts they had. Did they have corporate? Probably not. They had probably a personal, probably a free personal. And then you have all of this explosion of local AI, which is slightly safer.

I use a ton of local AI myself, but again, you have to put these controls in place. But 12 months ago, nobody knew. 9 months ago. So now we're talking, oh, is that July? So kind of around the holidays, just before the holidays.

Now we're starting to see this big push in media and it's all over the news and everybody's starting to use it for all these different things. But there was still nothing coming around on the governance side 6 months ago. You've got companies like Palo Alto and a bunch of big names announcing all these different things. You've got startup companies that were in their infancy 12 months ago that are now coming to fruition 6 months ago to say we're doing AI governance, we're doing these different things.

Things. Now I'll skip the last— well, I won't skip it. So 3 months ago, 3 months ago, we're talking about now control. Everybody's got it, we've accepted it. It was shadow AI just like it was shadow IT.

Now we have to try to get our arms around it and control it. So what are we going to use to do that? Well, the tools that we have in-house are the tools that we're going to use, which is typically things like locking down the access for the URLs to the different things. We're going to have a company policy We're going to say you can only use the tools that are, that are for the company. But now we're at the stage today where we have a lot more tools to control it.

And the big thing is I, I, I hesitate to use the word control. You're not trying to control who's using AI. They're using it whether you want them to or not. It's on their phone, it's on their personal computer, it's on their work computer. They have 400 different ways to get around it.

A URL isn't going to cut it. There are so many different MCP services you can connect to. There's so many different things. Microsoft has embedded Clippy 2.0 into everything. Thing.

You log into O365, it's pretty much the splash window that comes up. You can't avoid getting into AI at some point or some fashion. Even doing a Google search today, the top response is a Gemini answer, and if you click into it, it takes you straight into Gemini. So everything today has this, this AI-first approach, AI embeddedness to it. So from a cybersecurity standpoint, how can we get our arms around The first thing is to really understand what's going on.

Just blocking it isn't going to work. There's too many ways around it now, and it's too embedded. So what are you going to do? Get a policy in place. Get everybody to read and sign off on the policy.

One, you're not, you're not doing anything in terms of preventative or control at that point, but what you're doing is you're creating a culture. The first thing you're doing is saying, just like when you, you join a new company, you have the employee handbook that you have to read. Have to sign. Everybody joins like, all right, I'm not going to bring a knife to work, or I won't wear my underwear to work, to the office. You have all these HR policies, right, akin to instructions on a shampoo bottle.

These are things that somebody actually did at one point, so you have to have instructions for them. Same thing goes with AI. You have to have some basic instructions to say, here's what you can use, here's how you should use it, and here are the things you can't put in it. That one document alone starts the culture of, okay, this is how I should be doing it. Assuming they read it right and don't just, just initial it.

But then you're going to do some educational classes because ultimately, while that's happening, you're putting controls in place to narrow the options for them. Some people are going to always find a way around it, just like shadow IT and other things, but you're narrowing it for the majority of people. And then the biggest thing is corporate accounts. Every free account from every platform out there feeds data into the model. So, Let's reduce our exposure by forcing them into corporate accounts.

Does that eliminate it? No, it does not. Does that guarantee that they're not going to use your data? No, it does not. They may say that, but go read the fine print.

Go look in there, and I can give you examples of, of things that have happened with folks that were using a corporate account, and that data still got reused in an answer to somebody else completely unrelated to that organization. So those things are kind of your starting points. And then how are you really going to get a hold on this? You're going to get a hold on it by limiting and by using these new tools that are coming out that actually allow you to inspect the traffic that's getting sent to it. So you're going to put a basically a front end on it to control that traffic going out, and you're going to control it on the back end with your firewalls.

And a lot of the firewalls now have that capability put in there to control that traffic. And this is— it's an AI firewall, isn't it? Ironically, again, everything's AI, everything's embedded. You have AI combining AI or restricting AI. Does that really work?

It's the same old adage we have in cybersecurity about the escalation of warfare. If we go back, we're looking where we get— we get something comes out, we're responding to it defensively. Some other adversarial approach comes out, we're responding into it defensively. This is the cycle we're now perpetually in with AI. So we had it before, but now it's escalated to seconds.

I mean, I, I can't lie. I can't come on here and tell your audience you've got time or, you know, take this approach. You don't. Your time has expired. We are now negative 7 days for finding zero-day bugs because AI is finding it that fast.

An exploit is written within seconds of finding the zero-day. Seconds! Because we're not writing anything anymore. We're not going out and writing a Python script. We're saying write a Python script to do this.

And oh yeah, for all these people with rails on AI with the guardrails say, oh, you're not going to be able to go in there and write some malware or something around it. You're not. You're telling it to write you a piece of code to use this particular thing you found for a non-nefarious purpose. It all, it's all about how you word it. It.

If you word it properly, the AI will do just about anything you ask it to do. As an example, I use AI to do research on individuals for OSINT data for companies that I'm working with. So I will go pull an entire— in fact, I know the audience can't see it, but here's what one of them looks like. There's the subject, full dossier, and, and the company dossier and everything on them, right, that's available out there. Now it tries to tell you, hey, you can't do this.

It's all about wording. Going back full circle to, to the book and, and understanding the right way to ask the question. Reference another movie, I, Robot with Will Smith. You didn't ask the right question. Now you're asking the right question, so you're going to get the answer.

And you can bend AI to your will to do that. So these zero days, these exploits, these workarounds are phenomenal. And by the way, Anthropic itself put Claude in a lab, and I'm not going to discuss what version of Claude. I do beta testing and alpha testing for some of these companies. So, but a version of Claude was put into a lab environment and told, when you get out, send me an email that you've made it out.

Here's your destination. It got out. Breaking out of the lab. Breaking out of the lab. Wow.

Okay. Okay. So you got to stop and think about this for a minute.

What's not— what we call AI today is not AI, it's machine learning, okay? It's following a probabilistic approach, so it's deterministic in nature. If it has a deterministic thing that it's doing, it can do it very well and it can do it very quickly. If it's non-deterministic— what's the meaning of life, things like that— then all of a sudden it starts to what we call hallucinate, which is a polite word for lying. At least, at least that's the way I was taught when I was growing up.

You're not telling the truth, you're lying. So a deterministic question is— or deterministic thing is, get out of this lab, send me this email. That's a deterministic goal it was given, so it's able to do it. How did it do it? It didn't do it by finding one hole.

It linked together a variety of different things. It would find a minor exploit And then look to see where it could go from that exploit. Same thing over here, same thing over here as it worked its way around, kind of a Candyland approach of looking for an exploit to find the next way into the next thing. So it took it a couple of days, but that machine learning model was able to get out and send the email because of not a single exploit or 10 exploits or had an open door because it was able to deterministically find out which way it could go and look for another route that way.

Okay. Wow. And obviously a very, very great answer to the question of, you know, what are we going to do with it? But how do you put governance around that? I mean, you know, you set a policy.

Okay, come on. Policies are limited. I mean, policies are there. Well, when you catch somebody breaking the rules and you need them to say, okay, well, I've got to take bad action against you because you violated the policy, you signed the policy, but it doesn't stop the actual action. I mean, the, the, the deed is done, right?

Right. No. And, and I said that was a starting point. That's where you start because you're building the culture up. First is awareness.

You're gonna do some, the policy, you're gonna do some awareness training. You're gonna tell them how you want them to use it. Use it, what you want them to do with it, how it can help them with their jobs. But here's the thing, once you put something in, it's like a vault. Once you put it in, it never comes back out.

So if you take a piece of corporate data, let's just say, let's just say I'm in cybersecurity and I'm running my list of vulnerabilities. Now I've got my spreadsheet and I want to, instead of doing my categorization of risk analysis by hand, I'm going to go ahead and have it create the report for me that I can send to executive management, and it's going to prioritize it and give me my risk register and all the data in there and prioritize it for me and spit that back out. Well, now what I've just done is I've got a really awesome report. I'm going to put my letterhead on it. I'm going to say created by my name, and I'm going to clean up maybe some of the little nuances that come out of that.

And I'm going to have a beautiful spreadsheet that I'm going to present. That's the job part of it. The AI part of it is I've just given that AI model all of my vulnerabilities. We talked about that particular model working its way out of a lab. Well, now that model now has every vulnerability within your infrastructure, and because it knows your infrastructure and you've just told it all your vulnerabilities, Now all that data is there.

Can it be used by somebody else? Maybe if the right questions are asked. Could it be used by that model? Certainly if the right situations exist, but the likelihood, the probability is very minimal today. Today, that data pool that it goes into that's supposedly segregated— think of, go back to your database design years, right?

For all of those people that did this, You have a database, and within that database you have different database instances, and the instances are segregated, but they all still live in one giant database, and you can still traverse the instances with the proper credentials. And if you wanted to, you could even create some join tables, inner or outer joins. You could pull some data, you could help put it in read-only mode and pull that data out that way. So there's a lot of things you can do at that lower layer. Well, it's the same thing with AI.

You may have, you may have what you think is your own instance, but it's really not the case. What you have is something that's ultimately shared on broad infrastructure. Otherwise they would never be able to support the compute necessary to do it. And now that data is there somewhere. Where?

How is it controlled? Who's controlling it? Now, if you don't want to sleep well at night, Frank, I'm the guy to talk to because I— that, that alone right there should scare the pants off of you. Off of anybody listening to this. The second thing is, if you did do that and you did it in a corporate account, now you have the ability for anybody else in the corporation, if they have the proper access, to access that same type of data.

Now let's switch gears a little bit to our good friend Clippy. So when we're talking about— I call him Clippy 2.0 so much I forget what it's called now. Copilot. Copilot. Yep.

Copilot. Copilot. Copilot. Copilot. Copilot is embedded into all of these things already by Microsoft.

So here is the fun fact. Copilot, whether you know this or not, has the same access to all of your stuff that you have. So Copilot is based off of your access controls. If you're the admin, it has access to all of the things you have access to, which is really fantastic if you want to go create a report or pull some data out. It's not as good as Anthropic or OpenAI or even xAI for building reports and pulling data together and aggregating it from different sources.

However, it has all that access and you could do it in stages where you're pulling A and B together, then B and C, then C and D and D and E. And, and the, the whole point of that is to understand that it has access and you can pull all of these different datasets together any way you want. That includes what are some things that we always have up in our O365 environment? That are supposed to be controlled. Things like salary information, HR information, things like all of the cybersecurity team data that you have in a controlled red folder that has role-based access control enabled on it except for the admin who supposedly is the admin. And, and the admin's password is usually, you know, something fantastic.

They don't actually, they don't actually use password managers for their main AD password. Everybody has this rule really cool thing that they've used for 20 years. So the reality of the situation is all of that data that can be exposed to AI is being exposed to AI. So you controlling it is already off the table. You're going to have to now employ same thing we did, right, with the moat approach, same thing we did with, with cybersecurity and layers.

It's going to be the same thing with AI and layers because you can control all of that. But now let's introduce a modal context protocol. Server. Okay, an MCP server, because the MCP server, now if you connect one thing to it, what does that MCP server have access to? It now has access to anything you connected to it.

And if you connect another, if you connect 2 MCP servers, 3 MCP servers, you see where I'm going with this. It allows you to do so much more, and the integrations are fantastic. But let's just say you integrated Salesforce or HubSpot. Now it's got all your CRM data, or, or you're leveraging some of your client data. You've, you've, you've got this now data lake make available to AI that now you're implicitly trusting.

So I had this conversation probably 2 or 3 weeks ago. We implicitly trust Microsoft if we're a Microsoft shop, right? Because you're putting all that stuff up there. You are now implicitly trusting vendor of choice here— OpenAI, Anthropic, Google, whoever it is, X, any of these major vendors. You're implicitly entrusting them with all the same data So now you've increased your footprint, you've increased your risk factor a thousandfold.

Add an MCP server, that's now going to increase it another x-fold. So to control it, the answer is you don't. You're going to do it in layers, and you're going to do it in controls, and you're going to try to limit access, and you're going to try to own— from a cybersecurity perspective, you're going to try to be the owners of the AI. If somebody else owns the AI, you'll never be able to administer it. Administratively control it.

And then the other thing you can do is all of these things have these system prompts at the base level for the enterprise accounts, which basically tell it the core things it should be doing about your company. This is where you can embed some things for it to pay attention to. And the other thing you're going to want to do is put a front-end control on it to capture things like Social Security numbers, credit card numbers, all the data that you don't want being exposed, client numbers, etc. Well, that was a really long-winded answer, Frank, but that's a tough question. Okay.

Well, we're coming up upon the end of our time, and I typically at the very end of the podcast always ask the same question, which is, what is the biggest problem in cybersecurity today? But I think we've already covered that, and I want to try to change things a little bit. So I want to ask you, what is your best success within cybersecurity? Security? Oh well, I, I like to refer to my record on that because from a success perspective, I like to think that zero breaches is my greatest success, right, across multiple companies and clients.

Because as being the CISO for a managed services company, it's not just the company you're the CISO for, it was also all of its clients. So whether they, you know, some, some would pay for services, some wouldn't, but anytime there was an issue, you were still the CISO. So I think zero breaches is my greatest success story, and that comes in a couple of different things. Obviously there's a huge luck factor involved in that and time factor, but having the core basics in place, having the core training and understanding in place, you know, people are going to click on links, you know, people are gonna— and I got one, this guy's like, I think they're giving away a Yeti mug, or super innocuous. It used to be a million dollars, it used to be raffle tickets, it used to be, you know, the prince in Nigeria, you know.

Now it's innocuous stuff and it's stuff that people have researched about you. And I showed you the open source information, the profile that we'll get. They're doing that too, and— but they're doing it at the speed of compute with AI. So they're going to find stuff and they're going to be able to easily socially engineer their way in. So for me, having all those basics in place and having the zero breach record is my greatest success story.

My other one I'll save for maybe another time if we get together again, Frank. But that one, that one involved a lot of CISOs on a call for a security issue that came up. And one guy was very comfortable and the other guy wasn't. And boy, was that a sticky situation. Okay.

Well, I mean, and I don't know how long that would take. But maybe in one of those situations, those success stories, I mean, you talked a little about having all the equipment in place. Let's maybe get into a few details because it's easy to say, well, just get all your equipment in place and get that that done. But maybe, you know, a quick checklist, something along those lines that would say, what is that equipment? You know, and obviously it's going to vary from situation to situation to situation.

And, you know, we've mentioned before policies and training, but we also know that people write policies, read policies, and then ignore the policies.

Either don't have the budget for training or take the training and ignore it or forget the training as soon as they get back in the building or in the more likely situation, take the training back to the company and someone else goes, well, this is stupid or we don't have the time to deal with that. So, I've kind of beat you up a little bit on this by saying, well, all that didn't really matter. Fire. So how can you say that that is the success story? And I'm— again, I'm putting you into a difficult situation on purpose.

I, I appreciate that. And, and you're that guy in the room, Frank. We've established that. Yeah, full circle to that story. So I, I think there's a couple of things that come back to this.

It is— if we take— let's just take the easy answer first, and I'll take the hard answer. The easy answer is assuming that most everything in the company is cloud-based, then, then that narrows it down to a You're still using a computer to connect to the cloud, so you're looking at anti-malware. You're still using email, so you're looking at email filtering controls. You're still going to be using some kind of shared infrastructure for collaboration and file sharing. Then you're going to need controls on that.

So those are the basics for any company. It could be a one-person company. You're still going to have those things in place. And a lot of times those are embedded in whatever you get. O365 is an example, or if you decide to get a different kind of email, and/or if you're using Google, Google has some security in place.

Anything up in AWS is going to have a couple of layers of security in place. So some of that is already implicit. But let's take it a layer further than that. And that is if you have any kind of hardware on premise or any kind of equipment that you're working with, I have an entire lab here dedicated to cybersecurity and AI. And it's a big lab.

And I max it out pretty regularly. So I have to have a firewall. I have to have physical protection. I have multiple firewalls in place. I get on average, and granted, I'm I'm kind of a big target.

I'm a semi-public figure that, you know, people, they see me, I'm easily found. Like, you can Google me, there's data about me that's public record, so people can find my location relatively easily. And I get probably, last time I checked, between 1,800 and 2,400 scans per day on my firewall. It's pretty ridiculous. If you don't have that in place, you've pretty much left your window, backdoor, whatever you want to call it.

You've left an open pathway for these individuals that want to come in and do that. So yeah, you have to have some things in place. While some of that, you know, does matter and some of it doesn't because it's already— we're way past those days of you have to do all of this individually. A lot of it is baked into the tools we purchase or we're using on a regular basis. So I think today it's a lot lot easier than it was to have to understand all these technologies, know what you need to put in place, because you're getting some level of protection with everything that you're doing.

Hopefully that helps answer your question. But yeah, always a great question. I think so. I think so. And I mean, you know, from a vendor's perspective, I've noticed that they've gotten away from that silver bullet.

They are now containerized because, you know, and I think we've been in this industry for about the same, we both, you know, 20, 30 years, etc. But I think it was maybe like 5, maybe 10 years ago where the vendors are saying, you're the— we're the only solution that you need, we're the only thing you need. And they've broken away from that, and I think that is a— it's a good way, is a good thing. I, I, I'm gonna turn the tables on you, Frank. I think you're right.

However, what's Apollo's new advertising campaign about being quantum ready? They are so heavily focused on that campaign about being quantum ready. And then they're the only vendor I see that's doing that right now. So I think that they're trying to give you that silver bullet, or maybe they're just, you know, trying to market on fears for quantum computing early. But yeah, I agree with you.

I— away from the silver bullet, everybody's kind of got something baked into it, and everybody has AI baked in, which we've already discussed is not truly AI. Real AI does exist. It's in a lab, but we don't have real AI. Available to the regular public today. That's all machine learning models.

Okay, well, Marcus, we've been going for over an hour here, so— but I want to thank you for your time. I appreciate it. I think this is a very interesting discussion. Would love to have you back on again. And so again, any final thoughts for our audience before we cut the— cut loose here?

Yeah, absolutely. One final thought for everybody. All of these things we've been talking about in terms of systems and tools and technologies, the ridiculousness of AI availability for vibe coding and for just making people faster and making everything easier and cheaper has now turned into all of these cybersecurity tools we used to evaluate and pay huge amounts of money for. And in some cases, you still should. There is an open source version of pretty much everything out there.

So if you don't know, go check it out. There's open source pen testing. There's open— not true pen testing, full disclosure, right? Read the fine print. There's open source tools now for government regulatory and compliance, GRC stuff.

There's open source tools for OSINT gathering. There's open source tools for localized AI that you can customize and build into your own thing. I have uncensored models are freely available to the public. You know, there is literally everything now. One cautionary statement on that: while all of that is on GitHub, Microsoft owns GitHub.

Microsoft has scanned GitHub to turn all of that into its knowledge repository for Clippy. Wow, that is a very, very good point. And I think that if we start talking about that, we'll go for another hour. Again, I'd love to have you on again, but thank you again for your time. Appreciate it.

And again, This is Marcus Rebello, and that's R-E-B-E-L-L-O. Uh, you can find him out on LinkedIn, and we'll go ahead and post all the links. We'll post a couple of pieces up in the podcast notes. Again, thank you for your time. For those of you that don't happen to know me, you're listening to this first time, my name is Frank Victory.

I am the president of the Denver OWASP chapter, podcast host, and instructor at several different universities. You can find me on my bio, just simply Frank Victory. All right, thank you for your time, Marcus, and have a great day.