Loading summary
Host
Best advice I ever got in security, Go.
Netta Noman
You can't expect people to care about what they can't see. You have to light up the threat landscape for your whole organization with data, not just the security team. You got to get them to care. If they don't understand what's real and what's actually happening in the current environment, not just theoretical, they won't have anything to react to and they won't make any changes.
Host
It's time to begin the CISO Series Podcast Foreign.
David Spark
Welcome to the CISO Series Podcast. My name is David Spark. I am the producer of the said CISO series. Joining me is my co host since day one. It is Mike Johnson, the CISO of Rivian. Mike, say hello to the audience.
Mike Johnson
Hello audience. I'm glad to be here as part of said podcast.
David Spark
Said podcast. By the way, you know this show is only one of five shows on the CISO Series network and I am thrilled that we're doing this one today. As always, our sponsor for today's episode though is Native. Turn your built in cloud security controls into active operational defenses across aws, Azure, Google Cloud and oci. We will be talking more about just that. Some very cool sort of if you've got a lot of cloud instances have one way to sort of manage all of it. Native's got a very cool solution for that. But first I am going to do a product endorsement. Mike, are you ready for this?
Mike Johnson
An endorsement?
David Spark
Oh, it has nothing to do with cybersecurity.
Mike Johnson
Oh, womp, womp.
David Spark
Now it's possible there are better products than this. This is just the one I got and it's more it was an eye opening moment. So I'm going to show this to my people. I will describe it. It is something called a Kodak slide and scan. Have you ever gotten one of these things?
Mike Johnson
A Kodak? I have no idea what that is.
David Spark
Do you scan negatives or slides? So what you do? This is the little screen viewer here.
Mike Johnson
David, what is a slide?
David Spark
Okay, for those who don't know what a slide is. Very good, Mike, very good. Actually, I'm not scanning slides. Slides are these square objects or flat that had something called transparent film in them and that they were in a positive look that you would shine light through them and be able to project. We do a lot of that now through computers. But what more importantly is that it can deal with negatives. My dad was a photographer and shot a lot of photos, developed his own film, had a dark room in the basement. And what I realized, unlike today when we shoot Photos. We look at every one of our photos. But back then, if you were developing your own film, you, you would create contact sheets. Take a loupe magnifying glass, look at it. And of maybe 50 photos you took, you might develop two or three of them. And so what I'm realizing. And my dad kept all his negatives, I bought this thing, which is great. You slide negatives into it, it shows you as a positive, you press a button, it takes a digital scan of it. Now it's not wonderful because then also the negative isn't perfect either. But there's lots of great tools to clean these things up. But what I'm realizing as I'm going through these two giant books of three ring binders of negatives that my dad had is I'm seeing photos from my family and childhood that I have never seen before.
Mike Johnson
Oh, that's cool.
David Spark
It is amazing. It's incredible. I'm like, oh my. I remember this event. So just some wild.
Mike Johnson
It's just time capsule.
David Spark
It's a complete time capsule. And the thing is, it's just as I'm going through it, it's just really kind of fascinating. No one in my family's seen these before. So I'm going to be able to share this with the whole family as well.
Mike Johnson
Oh, that's very cool.
David Spark
So that's why this is a heavy. Now there are other products that do something similar, but if you are someone who has all these negatives sticking around, or slides for that matter, I strongly, strongly recommend either buying the Kodak slide and scan, which wasn't expensive, or any kind of scanning tool. By the way. There are other solutions to do that. They're all a giant pain in the butt or rip roaring expensive. This is a far more economical way of handling it.
Mike Johnson
It feels like a good balance.
David Spark
Yes, it is good. Especially if you've got literally when I'm done with this, and I'm being very selective of what I'm scanning because my dad took a lot of shots of scenery which I don't need to scan. But I'm probably gonna have about 2,000 to 3,000 photos when I'm done with all this.
Mike Johnson
Oh, so you're down selecting to 2000 to 3000? Yeah. You've got a massive collection.
David Spark
Oh yeah. If I did everything, I'd be well over. Like I'd be over a hundred thousand photos here. It'd be insane.
Mike Johnson
Wow.
David Spark
Oh, yeah. I'm definitely down selecting a lot.
Mike Johnson
Amazing.
David Spark
Yeah, so it's quite a collection. So I've been sitting on this for far too long. And it's a wonderful experience. Like, for example, one thing. When I went to summer camp, I learned how to play lacrosse. There's a photo of me and the camp counselor who taught me how to play lacrosse. And I was like. I was like, oh, my God, look at that.
Mike Johnson
You're gonna have to share that on LinkedIn.
David Spark
Yes, I will.
Mike Johnson
Like, you're gonna have to, like, share exactly that picture because you featured it. You highl a child photo.
David Spark
Let me just say I look at the photos of me as a child and I think I was a monster nerd. I know this comes as a shock to you.
Mike Johnson
Was.
David Spark
I know this comes as a. But you look at it, it's like, oh, wow. Wow, that's some serious nerd. All right, let's get into this show right now. Enough of my childhood. And I'm not, by the way, I'm not going to share endless slides with the audience, but maybe I'll pull that one picture out. It would be cool.
Mike Johnson
You've got to share at least that one.
David Spark
All right. Very thrilled to have our guest on the show who is actually a fan of our programming as well, I've discovered. So I'm assuming she's happy to be here with us as well. It is the SVP and CISO for the Estee Lauder companies. Neta Noman. Netta, thank you so much for joining us.
Netta Noman
Thank you for having me. I'm so excited to be here.
Host
Is AI going to help us or hurt us?
David Spark
Quote AI producers. This is senior level looking work without senior level judgment behind it, end quote. That's Connor Grennan, former chief AI architect at NYU Stern, who argues that companies are automating the output of expertise while gutting the apprenticeship model that builds it. So junior roles are suddenly an endangered species. Without them, it's hard to get the reps needed to develop judgment and especially in security. So if we're training staff on AI tools, but not on how to challenge AI output, are we just building faster paths to confident mistakes? And can we recreate the apprenticeship model after we've already optimized it away? I'm going to ask you, Mike, and I will just say we actually have somewhat of a solution for that because we have some that are becoming savvy in the AI tools, and then we are having others who. Who are savvy in sort of editing and approving the output from the AI tools. And by the way, it's a kind of a junior person that's figuring it out too on the sort of working with the AI tools. Interested to know what kind of model you have or you've seen work?
Mike Johnson
No. I think what you've laid out there is actually the natural way of adopting AI that we're seeing in all manner of places, including within cybersecurity, where you have the people who are entry level that are really being augmented by AI, they're able to have that much more impact than they would have had previously when all they were doing was just manually turning a crank, like push this button here, was quite often a task that an entry level person would be given. I think this is a good thing that these jobs are going away.
David Spark
Yeah.
Mike Johnson
The whole idea of just manually doing a process that a computer could take care of, who wants to do that?
David Spark
Well, but we look at all the ages of development, we get rid of processes that we no longer need to do, this is just yet another one that's scaring us, don't you think?
Mike Johnson
Yeah. And I think a good example that I saw brought out in the very early days of AI was accountants and spreadsheets. Like way back in the day, they
David Spark
did that by hand.
Mike Johnson
They would do that by hand and
David Spark
make lots of mistakes too.
Mike Johnson
The whole reason why it was called spreadsheets is because they literally had a piece of paper and they adopted that technology. And nowadays accounting is in a much better place as a result. So it's a bit of a messy transition. We'll be the first to admit.
David Spark
Essentially it takes two hands to deal with this. Yes. It's not just a. It's rarely a one person job. Nada. I want your take on this. Is it a one person or two plus person job?
Netta Noman
It's a multi person job. And I think there is this huge sentiment from all the way at the top of corporate that AI is going to replace people for sure. It absolutely will. But I totally agree with Mike's point here that it's going to replace the mundane. It's not going to replace decision making.
David Spark
Now, do they, do they truly believe it's going to replace people or replace tasks? What do you think?
Netta Noman
I think it's both.
David Spark
Okay.
Netta Noman
I think there is a desire to replace people. I mean, I see it, I see it everywhere. I hear every CISO and I mean
David Spark
there are mass layoffs because of it.
Netta Noman
Yeah, mass layoffs. You hear that, right? That's the story, that's the headline is, you know, company is going in this direction, replacing this with this. And while I get that, I absolutely understand the need to do that. Your point earlier Connor's point is valid, which is it eliminates the pipeline of future decision makers. If you take that away from the first generation, that's learning it, right? And so we've got to look at that talent pipeline and make sure that they're equipped to understand it. We can automate tasks. When we brought in Soar and other things like that, we didn't say, oh, we just need less people in the SoC. Right? That wasn't the answer.
David Spark
Which, by the way, I want you to know, the vendors were trying to sell that, though.
Netta Noman
I get that. I bought it at first, I will admit that. But I do think it's important to recognize that this is an automation of the mundane and it actually creates more opportunity for critical thinking. And the good news with the next generation and the new talent, I see it in my own team, is that they are great critical thinkers. They need to be trusted to do it. They need exposure. All of the critical thinking that Gen X millennials have is the fact that we are able to see this from that and be able to decipher it. The challenge that we are coming into today is that if we automate everything and they don't see and get exposure to how those decisions are made and why you chose A versus B or what the outcome of A would have been, they'll never get that opportunity to make a good decision. You won't have future CISOs sitting at this podcast 10 years, 20 years from now if we automate the decisions away from that. So there's got to be a balance between automating those simple tasks, even automating some level of decision making, but maintaining the human in the loop.
Host
Didn't we solve this already?
David Spark
Quote, AI agents require credentials. They invoke APIs, query databases, trigger workflows, and write to systems. Functionally, they are privileged users. Operationally, they are rarely managed with equivalent rigor. Now, this is Jacob Combs, CISO of Tandem Diabetes Care, who wrote that most organizations are roughly where they were on PAM. This is being privileged access management back in 2012. The difference is that PAM had humans attached that had to name an owner and revoked access when someone left. When something went wrong, there was a person to trace it back to. All right, this is something that's been coming up a lot now. Non human identities do not work that way. When an agent does something it shouldn't, the accountability trail doesn't end at a person. It ends at whoever the organization implicitly decided to hold responsible. And in most cases, that's a see? So not by design but because, quote, AI security defaulted to the security team before anyone defined what security owns. So I'm starting with you, Ned, on this. How do we assign real ownership to identities? These being the non human ones that outlast the people who deployed them. And can we stop accountability from defaulting to the CISO? I know all CISOs listening would like this. Every time a non human makes a mistake, what are your takes on this?
Netta Noman
Yeah, Look, I think CISOs are along for the ride on this one. The world is chartering entirely new territory. We're trying new things. The possibilities are endless, the capabilities are endless. Even the people designing it are still trying to think through what they want to achieve out of these goals. Companies are experimenting in ways that we've never really encountered before. And so the risk that companies are taking on is one we all have to do together. We all have to row together. Now, I disagree that you can hold the CISO fully accountable, solely, I should say accountable for that experimentation, because it's all one big test lab and we're all along for the experiment. And so CISOs, in my opinion, do not assume that risk. We're here to state and manage the risk right along with everyone else. As the head of Security risk and compliance, most CISOs should be stating those facts to their peers, their leadership and the board and saying, this is the risk in doing it and here's what we need to do about it. Now, how do we take that into agentic identities that are doing things on behalf? There's a lot to be foreseen here, but we have not figured this out together yet. And where each of us are testing this out with our companies, with the AI leaders of our companies, with vendors that we're partnering with, we're all trying to understand exactly what the course and the lifecycle of each of these identities could and will be. And so there's a lot, a lot of catching up that the security controls and the technologies that we use have to do in order to keep up with that.
David Spark
Excellent. All right, I take this to you, Mike. I'm sure this has come up a few times. Were there some sort of bumps in your road as you're figuring this out? And if so, could you tell us some of the bumps?
Mike Johnson
Netta said it well, which is we're all experimenting. Our companies are experimenting, multiple teams are experimenting. And I think the reality is.
David Spark
And I'm assuming you're learning from each other. Yes, absolutely.
Mike Johnson
Yes. We're learning from our peers at other companies. We're learning from our own experiments within one team might figure something out and then pass it along. This is very much frankly rebuilding the plane as we're flying it here because
David Spark
at the same time, which we don't
Mike Johnson
recommend by the way, I would caution against rebuilding a plane while you're flying it, but at the same time that's where we're at. We're deploying these products, these tools, these capabilities. We're seeing value out of them and that means that we need to keep evolving them while we're using them. We can't like shut them down and then go fix them. So I think that's really the one of the things that we've really tried to embrace is the need for the agility for making decisions on the fly and understanding which of these decisions are the one way door versus the two way door. Like the decisions that you can't step away from or you can't revisit versus the ones that you can. And that's really the key here is just make sure that you can be as agile as the rest of your company and frankly support their agility as the experiments need to continue.
David Spark
Cloud security has gotten really good at finding risk but the next shift is active operational defense. AI as we have been discussing is accelerating attacks and changing infrastructure faster than security teams can chase with alerts, tickets and cleanup. At the same time, aws, Azure, Google Cloud and OCI now have powerful built in controls for enforcement. The challenge is making those controls work consistently across clouds teams accounts and constant change. Native Our sponsor is the cloud security control plane that turns security intent into enforce architecture across multi cloud environments. Teams define the outcome once preview the impact, deploy the right built in controls and keep enforcement aligned as cloud environments change. With native security teams can move from finding risk to enforcing active defenses at the source inside the cloud itself. Native makes secure by design architecture real. Go check them out at native security and it's spelled just the way it sounds. Just go to native security. There's no.com or anything like that. It's native security and when you go let them know you heard about them from the CISO series,
Host
It's time to play what's worse.
David Spark
Netta, you know how this game is played correct?
Netta Noman
Yeah, I do.
David Spark
And now do you play along as you listen?
Netta Noman
Yes, I do.
David Spark
Good.
Netta Noman
Me too.
David Spark
All right. Now you know I always make the host answer first so you get to agree or disagree with them and this I'm very excited. We have certain regulars send us a lot of great what's worsen errors. I love that but I Love when we get a new person to send something in. So we got somebody new here, Mike, are you ready?
Mike Johnson
I'm ready for somebody new.
David Spark
And they're a huge fan as well.
Mike Johnson
So win, win.
David Spark
Here we go. It's Rajat Ravinder Varuni, who's the CISO over at Success KPI. And here are the two scenarios. All right, Scenario number one. A VP builds a customer data app on his personal AI account on his personal laptop, hosts it on a consumer platform outside of your cloud and wires it to pull live records though from your company CRM on every page load. His security attestation is, well, it doesn't store anything. You find out that from just a hallway comment weeks in after he started doing it.
Mike Johnson
All right, okay.
David Spark
A little distressing.
Mike Johnson
A little. Yes.
David Spark
That's scenario A. But there's a lot of question marks around this. A lot.
Mike Johnson
Sure, yeah.
David Spark
This other one also has a lot of question marks around it. Scenario B. One of your privileged data engineering contractors has quietly been working a second full time job for the entire engagement. He runs both jobs on the same personal unmanaged laptop and he's been logging into your production AWS account via a VPN belonging to his other employer. Now, for roughly a year, your customer data and his access tokens have been transiting a network you have never assessed on a device you do not control sitting next to whatever that other computer installs and monitors. His work has been clean. Nothing looks stolen. You only found out because an impossible travel alert fired. And now you cannot say for the last 12 months whose infrastructure data has been living on or who else has a window into it. So more questions, Mike. So which one is worse here?
Mike Johnson
It's all about the questions. So first of all, thank you for the question. What I like about this is this
David Spark
is not a flip side of the other one.
Mike Johnson
That's usually what we get.
David Spark
And it forces you to sort of do these weird balances.
Mike Johnson
Exactly.
David Spark
And I like the creativity of this too.
Mike Johnson
Yeah, no, this is great. And what I liked about the first example was we're very much seeing more and more people being able to build
David Spark
applications and do exactly what's happening here.
Mike Johnson
That's part of the promise of AI, is everybody can be a developer now if they want to.
David Spark
Even people on staff here at CISO series are doing it and we don't have any developers on staff.
Mike Johnson
Amazing. And that's what we're going to see more of. And so frankly, both of these scenarios are actually viable. These aren't like totally made up. Can't never happen type scenarios, which makes them more difficult. And so ultimately, this is going to
David Spark
be a pick one and run with it and defend it as best as
Mike Johnson
you can, as hard as you can. And so I really think in terms of what is going to happen next from when you find out about either of these, like, all right, great, I've now heard about this. What do I do? The second one, I think is the worst because you are now going to have to go and talk with your customers where you had agreements that their data will not leave your environment.
David Spark
Well, but the first one could be the same thing.
Mike Johnson
Well, the first one is your CRM platform.
David Spark
Yeah. Oh, well, that does have some customer data in it.
Mike Johnson
Well, no, no, no. So one of the distinctions that. So remember I worked at Salesforce.
David Spark
That is a CRM, if I remember.
Mike Johnson
And one of the distinctions is
David Spark
not
Mike Johnson
to some people, but one of the things that we distinctly talked about was there's customer data and then there's data about customers. And those are two different ways of looking at data. So depending on how you think about your CRM, that could be data about customers. I don't know.
David Spark
Again, that's why I told you there's a lot of questions here.
Mike Johnson
This is pick one and run with it. Right. The second one, you absolutely have had customer data crossing networks, going through environments where it shouldn't have been. And so the first one, it's unclear. The second one is very clear that you've had customer data moving through untrusted environments. And that's why I pick and run with that one as the worst example.
David Spark
No. Okay, I get where you're coming from. All right, Nada. You can agree or disagree with Mike here. What are you going to do?
Netta Noman
I think this is tough because there's a lot of ambiguity in both of them, which there usually is. Right?
David Spark
Yeah.
Netta Noman
Yeah. I think the comfort I have with the second scenario is slightly higher only because I've encountered it and the first I have not yet, at least, I don't know that I have yet you see the difference. So one is a little bit of a known and the other is an unknown. So while both scenarios are fabricated and there are still unknowns, I might be having bias because of my previous experience. I totally agree with what you said, Mike, in terms of, like, customer data and data about customers. So there's still that, like, unknown of what actually is passing. And in the second scenario, you're dealing with somebody who. They're using the wrong tools. And are they this tools that you selected for Them? No, but they're using tools. So I feel like there might be some level of not trust, I won't use that word, but assurance that there's at least a control. Now, it's not our controls, they're controls that we don't govern. There's a number of things. There's definitely sharing of data, but they're at least between two parties as opposed to some unknown that is. That's the part that terrifies me and that's the part that's literally happening. You're exactly right. We're doing it everywhere. I talked about friends at other companies in not security industry roles and they are telling me the cool things they're doing and building and just this. And I always caution them like, hey, be a little careful. You should talk to your ciso. I'm sure he or she would really need to know about this. So I think there's a little bit of that. But that's what's making me pick the second one because of it. So, you know, I. I don't think I just like every one of these scenarios that none are to going.
David Spark
So you think the second one is worse or better?
Netta Noman
I think the second one's slightly better.
Mike Johnson
Okay, first one is worse.
David Spark
First one's worse. And the second one.
Netta Noman
The first one's worse.
David Spark
Mike, you think? Yeah. Okay. You started off saying the first one's worse. Okay. But I thought you might have switched your mind. No. Okay, excellent. So the first one's worse for you and for you, Mike. Second one is worse. We have got a split decision.
Netta Noman
Split decision.
Mike Johnson
Great.
Netta Noman
I'll stand by it until I get more data.
Mike Johnson
Right.
David Spark
Which is great because there's plenty of ambiguity in these two scenarios that you could easily split decision on this.
Netta Noman
Absolutely. Just one additional word to the scenario would have shifted either of us in either direction, I'm sure.
David Spark
Very true.
Host
What's the roi?
David Spark
I know I have have many problems and I know we have a lot of risk. I don't need another tool to tell me that. What I need is something to actually address these problems and remediate all these findings. Oh my, have we heard this line again and again and again. Okay. If scaring CISOs into buying ever worked, it's long stopped working, argued Ross Hale Luke of venture insecurity. Security teams approved visibility tool budgets for years now, those tools delivered exactly what was promised. A growing list of things that were wrong. What didn't come with them was any authority to fix those things. And those same CISOs are now on record knowing about the gaps when the breach happened. So as the market shifts from selling findings to selling remediation, which I know is what CISOs want. Mike, how do we avoid buying a new category that just repackages the same problem? And when the authority to fix things still lives in other teams, does it matter what we buy? What do you think?
Mike Johnson
It's funny how much of the marketing material out there right now about the advanced models is how much they can build exploits. The reality is these vulnerability finding machines, they've been around forever. This isn't anything new. Great. They're better at it. Wonderful. But what we really need is vulnerability fixing machines. We need to move from the finding only to really focusing on fixing. So ultimately I agree with Ross here. It's long since passed that we need to focus on finding and we need to really focus more on fixing. Sure. We should still keep looking for these things. We shouldn't stop there but just tossing it over the wall to another team, what are they going to do with it? And so I don't want to be fixing somebody else's code because if I go and make a change to somebody's code and it breaks something that's on me to fix. But what I really need to do is how do I give them clear instructions on how to fix. We're test actively as of time of recording, as of time of airing could be very different, but we're really focusing on giving teams. Here's the exact change that we need you to make. All you need to do is review this, push the button to accept it and it's fixed. And so that's really, I think the future of moving from just finding to helping other teams fix so that they're still responsible for what their thing does. But at the same time, we're not asking them to go and figure out how to fix it themselves. We're showing them and making it very easy. And we all win in that situation.
David Spark
So the remediation is really creating the pipeline, showing how it can be done easily and this is actually where AI can jump in and if you are building the tools to make that happen. Neta, what do you think?
Netta Noman
Here's a novel idea. Let's not deploy code that's got bugs in it.
Mike Johnson
I love that.
Netta Noman
Let's leverage our AI so that it stops us from rushing to get things out to market.
David Spark
Well, it sounds like a Sisyphusian task if I'm pronouncing that right. Yeah, you know, you push the rock up a hill and it comes down to, you know, Two feet or something. Yeah.
Netta Noman
We are all talking about remediation, right? Finding and fixing. I have dashboards out the wazoo. We don't need more. So I totally agree with Mike here. We got it. I have information, I have visibility. I want more. Obviously I will always take more. But we're finding issues faster than they can be solved.
David Spark
Yes.
Netta Noman
And my end goal is to get a good night's sleep. And if at the end of the day knowing that the issues are being fixed just as fast as they're being found or preventing them from ever being there in the first place, that's what we need. That's what will sell a ciso. I don't need to, as Mike said, pass the ball test, fix, validate. That is very dated model. So 2005, what sells me. And don't get any ideas here. Salespeople.
David Spark
But yeah, no vendors are listening.
Netta Noman
No vendors listening to me right now. How much effort a provider has to put into a quality product that is not already riddled with daily bugs. We just accepted that as the status quo.
David Spark
Yeah, I know.
Netta Noman
Raise our bar, right? Like, let's go. The expectation, I have our tools, our software is much higher. I expect a code to come clean,
David Spark
but you know, you're fighting against. And I'm going to throw out the generic term. We've heard the move fast break things sort of model of development. Sometimes it's like, correct. If I get this out a week faster than somebody else and it's being presented to the market, even though it's not as secure as a business move, this is smart for me.
Netta Noman
Absolutely. And there's a ton of pressure. If we thought the go to market timeline was fast 10 years ago, it's way, way, way exponentially faster today. It doesn't mean that we should accept that though.
David Spark
No, no, I understand.
Netta Noman
What I'm saying is that's where security leaders can speak up and make sure. Especially chief security product officers. Right. Can speak up and make sure that we're building that in. But even still, the things that will sell to me are the things that will auto remediate. That's what I'm really looking for is auto enforcement, auto remediation. How do we fix? Instead of chasing, I want to set it and forget it. So like we said earlier, our teams can focus on the real issues. We can have them focus on things that really matter instead of going back and redeveloping or refixing code.
Host
It comes down to the fundamentals.
David Spark
Now, a recent thread in the cybersecurity subreddit asked whether security is becoming more behavioral than technical now, the most upvoted answer was it always has been. Which makes it stranger that security program budgets still read like a technical controls catalog. But as a commenter pointed out, a program stacked with awareness, training and thin detection misses as badly as one built the other way around. The blast radius of a human mistake remains a technical problem. The mistake itself is not. The problem is CISOs own both sides of that. So, Ned, I'll start with you. Can we build programs to reduce the conditions that make these behavioral mistakes likely? Meaning you can build better technology? I don't know if we can build better humans. Can we?
Netta Noman
I totally think we can't. I think we can never trust our workforce fully. We know that we should be taking the power away from these users. Recently at rsa, at esaf, I heard a Google security leader mention that in the face of the 2026 landscape, we just need to constrain. Constrain, constrain the power users have to download, to pull, to make things happen for themselves. And the expectation companies have of their users to move faster. Everything we just talked about in the last segment is higher than ever. So if that's the expectation of users, we need to make sure that their power is limited. And the old mindset I need to create, my job is to create. We have to constrain to some degree now, different companies, threat landscapes, risk profiles, risk tolerance. It's going to change that depending on the company, obviously. But you have to make it hard for an insider, you have to make it hard for an external adversary, and you have to make it also hard for just an average user. Right. That made a mistake to wreak havoc in your environment. The issue today that wasn't a few years ago is that the average users have greater access to what I like to call extreme power tools. Think like technology chainsaws or bulldozers. Yes, more than ever. And what's down the pike are things like potential weapons of mass destruction. And we have to be very careful of what they can do with those power tools. They don't realize it. The conversations I have with people, again, not in the security or even tech industry, is a I'm building, I'm vibe coding, I'm doing my company doesn't stop me. Or I'm doing it on my personal device with company data. And then there's this look of panic I give them. And we have to know and own both sides of this. It's both the user as well as the controls. And we have to shift the types of controls that we're relying on, we think, okay, administrative access and like, you know, zero trust and things like that. Where can a user go? All role based access controls, things like that. But we own both sides of it, both what they do and what they can do. So it's education and vigilance and hey, here's how to do it safely. Think abstinence, right. And then things like what they can do, what we prevent them from doing. And so we need to make sure that they're aware, savvy, vigilant, and also limited in some form. I don't think it's one or the other. I think, can they spot a fish? Cool. Great. But fish today don't look like what they used to.
David Spark
I will just say what you're describing is an impressive juggling act. And my feeling is with all juggling acts, you juggle long enough, you're going to drop a ball once or two.
Netta Noman
Yes, yeah, absolutely.
David Spark
Mike, your thoughts on this juggling act of making sort of humans allow them to make mistakes and living technology sort of build padded walls around them. Can this be done?
Mike Johnson
Well, yes, and I think to the point of extending the juggling analogy. I suppose the reality is you need to make it safe to drop one of those things that you're juggling, like the whole idea of.
David Spark
But every now and then you'll juggle a torch or a hatchet.
Mike Johnson
Right. But the reality is, by the way,
David Spark
just a little bit of trivia. I can do that. I've juggled torches, hatchets and clubs before.
Mike Johnson
I'm going to ask for a live demonstration for one of these days.
Netta Noman
I don't want to see it.
Mike Johnson
You've now committed to this. But my assumption is those hatchets are not razor sharp.
David Spark
The ones I did were not. You're correct.
Mike Johnson
Exactly right. But that's a really good example of actually making it safe to drop that thing. It's not going to harm. Okay, maybe it injures like you stub your toe or something like that, but it doesn't cut it off. And that's the things that we need to be building from a controls perspective is we need to make it safe for people to make a mistake. Neda's example of phishing, we need to make it safe so that somebody actually falls for a fish and it's not going to be catastrophically damaging to the organization either by limiting the access that that person has or. Or going with a phishing resistant authentication mechanism so that they can't actually share their credentials even if they Fall for it. They don't have a password, they don't have a way of causing that harm to the organization. And that's the juggling act is to make it so that a human can make a mistake and it's not going to cause catastrophic damage to the organization.
Netta Noman
One more thing I wanted to add just on that point is it's exactly right. One of the things all of us can be doing right now is creating those safe sandboxes, as I like to call them, where you can experiment. You're not necessarily connecting to everything, you're not necessarily putting real production data in, but you are allowing for that experimentation in a safe and secure way. That's what all of us are sort of toying with right now through this experimentation phase.
David Spark
And the experimenting is not going to end in a week or two or a month or a year from now. This is going to be continuous, like all of Cyber.
Mike Johnson
It's our new reality.
David Spark
Yes.
Mike Johnson
That's where we're at.
Netta Noman
That's life. Yep.
David Spark
So continue experimenting. Learn from each other. Learn from each other's mistakes too, as we all will do and continue to do well. Thank you very much, Netta. Thank you very much, Mike. Netta, I'm going to let you have the last word, but first I want to thank our sponsor and that would be Native. Turn your built in cloud security controls into active operational defenses across aws, Azure, Google Cloud and oci. Go to native security. It is spelled exactly how that sounds, Native security. And when you go, let them know you heard about them from the CISO series. And Mike, any last thoughts from you?
Mike Johnson
Neda, thank you for joining us. Wonderful having the conversation. I really like listening to how you think about things. I specifically want to highlight that comment that you made in the last section about building sandboxes with safe data. I really think that is something that if you take nothing else from this episode, take away, you need to go and build these sandboxes to enable this safe experimentation. And if you do that, you empower your business to move quickly and you're helping them do that safely. So I really thank you for sharing that insight. But in general, really thank you for coming on the show and sitting down and having the conversation today.
David Spark
Thank you. All right. Nada. Thank you so much for coming on the show. We loved having you on. We would love to get you back onto this show and other programming as well. I always like to ask if you're hiring. Are you hiring over at the Estee Lauder companies?
Netta Noman
Yes, we are.
David Spark
Excellent. All right. I'M assuming there's a job board that people can check out. Yes.
Netta Noman
Yep.
David Spark
Okay. Check that out and any other last words you have.
Netta Noman
I do want to leave our audience with one thing that I needed to be told recently and I want to just share with my fellow cyber colleagues here, which is we got to take care of our health and our mental well being. This is the craziest year in cyber known to many of us and I think we don't say it often enough. And when we do, we often laugh it off and say, yeah, okay, so I'm here to plug that. I'm here to plug your and my mental health and well being. It's the only one we've got. And at this point we do have to take a break. So I am hoping to take the weekend to step away from the job to put the phone down. I hope after you listen to this podcast you get a chance to do the same. Take care of yourselves.
David Spark
Excellent. Yes, go. And I also like to go for a walk listening to a podcast. So you can do both at the same time.
Netta Noman
Absolutely.
David Spark
Thank you very much, Netta. Thank you very much, Mike. Thank you to our audience. As I always say, we greatly appreciate your contributions. Send in more what's worse scenarios like the one we got today. And thank you for listening to the
Host
CISO Series podcast that wraps up another episode. If you haven't subscribed to the podcast, please do. We have lots more shows on our website, cisoseries.com Please join us on Fridays for our live shows, Super Cyber Friday, our virtual meetup and cybersecurity headlines. Week in Review. This show thrives on your input. Go to the Participate menu on our site site for plenty of ways to get involved, including recording a question or a comment for the show. If you're interested in sponsoring the podcast, contact David Spark directly at david@cisoseries.com. thank you for listening to the CISO Series podcast.
Hosts: David Spark, Mike Johnson, Andy Ellis
Guest: Netta Noman, SVP & CISO, Estee Lauder Companies
Date: August 11, 2026
This episode explores the evolving landscape of cybersecurity through the interplay between new technologies (notably AI and cloud), the enduring pitfalls of scare-based selling, and the pressing need to shift from mere risk discovery toward real, operational remediation. The panelists discuss AI’s impact on security job roles, the ownership challenges of non-human (agentic) identities, limitations of current security tools, and how behavioral security should be balanced with technical controls. Key moments include candid debates, memorable warnings, and practical insights—all fused with the show’s trademark humor and candor.
While automating repetitive tasks is a positive, over-automation without a human learning loop threatens the next generation of security leaders. Both AI tool users and those who review/approve their outputs must collaborate.
[11:31] Jacob Combs (quoted by David Spark):
"AI agents require credentials...Functionally, they are privileged users. Operationally, they are rarely managed with equivalent rigor."
[12:57] Netta Noman:
“CISOs are along for the ride...This is all one big test lab...I disagree that you can hold the CISO fully accountable, solely, for that experimentation.”
[14:42] Mike Johnson:
“We're all experimenting...this is very much frankly rebuilding the plane as we're flying it here...We need to be as agile as the rest of your company.”
Accountability for non-human (AI) identities is murky. Organizations must not default all risk to CISOs; responsibility must be collectively defined and tech controls must catch up.
Two messy, real-world scenarios debated.
Both scenarios are plausible and disturbing; the ambiguity and “unknown” in what data is exposed (and where) drive the schism in risk perception. Real-world experience often shapes risk tolerance.
Visibility alone is not enough—operational security must prioritize on remediation, auto-enforcement, and shifting left (clean code at release). Find-and-scare methods are obsolete; security needs true authority or automated fix mechanisms.
Security is both behavioral and technical: Education/training is vital, but tech controls must "pad the cell" for when mistakes occur. The solution is not just to trust users, but to limit and safely sandbox their capabilities—especially now that non-technical staff have access to powerful tools.
| Segment | Timestamp | |:--------------------------------|:------------:| | Best Security Advice (Netta) | 00:04 | | AI & Junior Roles Discussion | 07:30 | | AI Accountability & Ownership | 11:31 | | "What's Worse?" Game | 17:41 | | ROI: From Finding to Fixing | 25:21 | | Behavioral vs. Technical Debate | 31:27 | | Final Reflections & Self-care | 39:29 |
Summary by CISO Series Podcast Summarizer (Expert-level)
For industry leaders and security practitioners who missed the episode—this summary captures expert insights, actionable lessons, and the underlying urgency for modernizing both security culture and tooling in 2026.