
Loading summary
David Spark
Best advice for a ciso, go.
Terry O'Daniel
Don't build security programs around fear. Build them around credibility. Fear gets you attention for one quarter. Credibility gets you invited back over and over into the decisions before the damage happens.
David Spark
It's time to begin the CISO Series podcast.
Welcome to welcome to the CISO Series Podcast. I am David Spark. I am the producer and host of the CISO series and my co host for today's episode, one of your favorites, whether you like it or not. By the way, I think I just read a comment on Spotify that said something like David wants to disagree with Andy on everything. Or maybe it was like David. No, I think David is constantly annoyed by Andy or something to that level. I think that's what it was pretty much. And it cracked me up. It was pretty funny. Anyways, it's Andy Ellis. Principal Aduha. Andy, say hello to the audience, Good afternoon folks.
Andy Ellis
Or depending on when you are in the world, good morning, good evening, or good night.
David Spark
We are also available@cisoseries.com where you can check out lots of past episodes. Also in your podcast queue wherever you're listening to us or check out any of our other programs. We have a total of five programs on the CISO Series network. Our sponsor for today's episode is Adaptive Security. Protect against deepfakes and AI powered attacks. That is adaptive. They are a phenomenal sponsor of the CISO series. We will be talking about just that a little bit later in the show. But first, Andy, I usually begin with our little banter, but you have something that you have not told me anything about. What is it?
Andy Ellis
I have not. And I loved your open about how much you like to disagree with me or get annoyed by me. Because it plays into this one, by the way.
David Spark
It was a listener's comment.
Andy Ellis
It was a listener's comment. But I think we enjoy that play and longtime listeners know how I feel about the Dunning Kruger effect and how often it gets cited. And I think it doesn't say what people think it says.
David Spark
Explain what the Dunning Kruger effect is.
Andy Ellis
Well, the problem is what people think. The Dunning Kruger effect is that people who aren't very good at something think they're really good at it and people who are very good think they're bad at it. That's not what the Dunning Kruger effect actually says. We should just call it the Lake Wobegon effect, which is undergraduate students think that they are all above average. That's basically all that's in there. But I went reading the original Dunning Kruger studies Because I wanted to sort of take it apart and help explain why people come to this wrong conclusion. And what people may not know is the very first study they did was actually about humor. So they took their undergraduate students and they gave them a test. It was like, here's a bunch of humorous jokes, some from Woody Allen, some from a kid's puns book. And they said, do you think this is not at all funny or very funny? So one to five scale. And they saw how well you mapped against the experts. And they had invited 30 comedians to also rate these jokes.
David Spark
I didn't know about any of this.
Andy Ellis
Of which only eight comedians actually replied. Which, first of all tells you a thing. Be very careful if you can't get people to participate. One of the comedians was so far off from the other seven that they actually threw them out of the data set. So it's. How would you agree with these seven comedians? Here's what I find really funny about you not knowing anything about it. Do you know who those comedians include?
David Spark
Who?
Andy Ellis
David Spark.
David Spark
I'm in that list.
Andy Ellis
You're in that list sometime 30ish years ago, I think.
David Spark
I do, I do know about this. So I don't know where this is. Somebody had. I was one of the seven, not the eighth?
Andy Ellis
Well, no, you're one of the eight because they list the eighth. So I'm going to tell the story that you were the eighth who got kicked out.
David Spark
Hold on, wait, wait. Am I the one who got kicked? No, somebody.
Andy Ellis
I don't know. They don't say.
David Spark
So, yes. I don't remember what this is. This is decades ago. And I mean decades ago, decades ago.
Andy Ellis
Like, I want to say like 25, 30 years ago.
David Spark
I know, I never saw that, but people told me about this and I'm like, I have no memory of participating in this. I don't know.
Andy Ellis
Right. So the Dunning Kruger effect is how much you don't agree with David Spark about what is funny.
David Spark
So, okay, my sisters call me a comedy snob. Let me start with that. They do that. They call me a comedy snobby. I also, here's the other thing. This is probably when I was probably in my twenties too, that I participated in this and I was pretty egotistical about comedy. Surprise, surprise, that I thought I knew everything. But I will tell you, I had a nice wake up call. I will say this. So I used to write for Second City out of Chicago. They had a corporate entertainment division, which
Andy Ellis
I love their venue. They're fantastic.
David Spark
Yeah, yeah. But I didn't Write for the main show. They had a corporate. Like, companies would come and goes, oh, we want the Second City people to come and play at our conference or a trade show or whatnot. And we would write that comedy for that kind of stuff. Again, I came in thinking I knew a lot more about comedy than I did, and I definitely did not know the Second City way. So I was required to take improv classes, of which I'm awful at improv. If you do a search on David Spark's standup, you'll see a bit of mine where I talk about how much I suck at improv, which I'm awful.
Andy Ellis
Improv is its own special thing. Like, people don't realize how hard that is.
David Spark
It's totally. And people who are really good at it. It's awe inspiring. How good. Although the overwhelming majority of us stink at it. And the problem with most improv is that it's performed for others to watch. So we watch most people stink at it is what happens.
Andy Ellis
It's a great way to put it. So, anyway, I just discovered this. I was laughing as I'm reading the list of comedians, and you were in that.
David Spark
I have a vague. What university was this? What school?
Andy Ellis
I think this is it. Cornell, I think. Or is it Stanford? It's one of the two. I don't know.
David Spark
I have just such an incredibly vague memory of this getting involved, but it's like I completely forgot. And somebody else mentioned, like, yeah, you're in this. I'm like, what? So I barely have any memory of this.
Andy Ellis
But it's quite all right. I just thought it was funny. And so now whenever I'm talking about how bad the Dunning Kruger effect is.
David Spark
Oh, I'm sure you were amused when you saw that. Send me the link. Cause I have no idea where this is. I don't remember where it is.
Andy Ellis
Yeah, I'll send you the link to it and I'm gonna write a paper on it.
David Spark
You know, we'll post it on this episode. All right, well, thank you for bringing that up. Because, again, vague, vague memory of that whatsoever. Anyways, the voice you were hearing in the background that you heard at the beginning and was laughing along with us is our guest for today's episode. I am thrilled he's here. It's been a while he's been back, and I'm thrilled that he's joining us again. He is the CISO for UDIA, none other than Terry O'Daniel. Terry, thank you so much for joining us.
Terry O'Daniel
Thank you, David. I'm really excited to Be back. And I am excited to be here at the moment that you learned how deeply Andy is stalking you.
David Spark
And by the way, I didn't conclude a thought about like how I was egotistical about Stand up before it. Essentially I started writing for Second City and I realized I didn't know it and so I had to take improv classes. But I was thoroughly enjoying what I was learning. And in fact, I remember one of the guys who ran it, a guy by the name of Joe Keefe. Great guy. He would literally have us sit like a bunch of the writers. We would sit down and we'd examine, I swear, only 60 seconds of life of Brian or 60 seconds of the Producers and we'd dissect the comedy the hell out of it and really isolated things that I never even thought about. And we spent like 30 minutes to an hour just looking at 60 seconds of it. It was incredible. And that I wish was a class everyone could see and experience because that was an eye opening experience.
Andy Ellis
There's an author who got, I want to go look it up. Who wrote a book about this. It's about the science of humor and it's fantastic.
David Spark
Well, not for today's episode. We're going to move on.
Andy Ellis
Not for today's episode though, because we're here to talk about security.
David Spark
Is AI going to help us or hurt us?
Quote AI introduced AI new rhythm in which workers manage several active threads at once. End quote. Dataset creator Simon Willison highlighted a Berkeley HAAS study of 200 employees that found AI didn't lighten workloads. It multiplied open tasks, constant output checking and parallel project juggling. More productive, sure, but also exhausting. AI isn't just another productivity tool because it removes the natural friction that used to signal, you've done enough for today, end quote. We're pushing people to expand cognitive load since we can do so much at once. Security teams running threat intelligence, drafting reports and spinning up detection rules in parallel may be getting more done and burning through their people faster than they realize. Andy, I'm going to start with you on this. How do we distinguish genuine productivity gains from unsustainable intensity? Don't we need some of the mundane tasks to balance the higher level tasks? This is why I talk about, well, let's get rid of all the first level tasks. I'm like, well, we like to do the simple stuff every now and then. So is AI Burnout already showing up in our teams already or are we still in the honeymoon phase? What do you think?
Andy Ellis
So I think that this is Both. There's a kernel of truth here, but I think it's also a little bit overblown.
David Spark
Then.
Andy Ellis
The kernel of truth here is that once you start using AI tools, you become a manager, even if you're only managing AIs. And you should think of AIs as like fractional humans. You don't have people on, on your team that just happen to be AIs. You have these very weird idio savants who can do very specific tasks very well but require a lot of micromanaging. And if you do not know how to manage, you are going to have a lot of stress. Because this is describing the management tool set is you don't do one thing in a day. You're managing 50 people and each one of the people is doing something different. And you have to do lots and lots of context switching. And if you don't know how to do that, you're going to burn yourself out. So you need to learn to do that. Now, do you need to keep level one tasks around? No, that's foolish. What you need to do is understand that cognitive load is a stress and that you need to have decompression. And the decompression doesn't need to be level one work. No. Let an AI do its level one work and take a break. Right. You need to get away from your AIs for a bit because the challenges, your AIs aren't like employees who all disappear for lunch where you get that momentary break. So you have to figure out what that break looks like. You have to manage them in a way that is helpful to you. And maybe token management is going to be the way we do that.
David Spark
Really?
Andy Ellis
Token management is to say, wow, you only get so many tokens in a day, so you'd better space them out. As we certainly see everybody changing their pricing models around tokens.
David Spark
You thought maintaining your hours with different clients was tough? All right. Token management on top of it. Wow.
Andy Ellis
Oh my God. Crazy.
David Spark
Okay, Terry, I throw this to you. You could digest what Andy just said or take it your own way.
Terry O'Daniel
I do think I will agree with Andy. I do think there's a kernel of truth here and I think it's especially dangerous for security. And let me explain. I do think AI removes all the bottlenecks that we need to initiate tasks and that's amazing. It is not so great at helping us complete tasks. And I think that is especially dangerous for security because we operate in a highly ambiguous environment. Security is rarely done, we're interrupted all the time, and it's already a heavy mental and emotional load. So I think we're victims of our own success to an extent here. I can now pump out five reports instead of one report. That's great. But we've lost the natural pauses where we stop and evaluate. We think about priorities. Should I create the fifth report or is it more important to go back and fine tune the first report so it lands better? I think that's the problem, is that we're starting to. And this is, as Andy called out, this is one of the first problems any beginning manager has to deal with. You cannot mistake activity for impact. And I think we're seeing a massive amount of activity thanks to AI. And that's great. But where does it land? What does it actually get us? Does it make our teams look more productive on paper? Then we're actually producing the outputs that we need to and we're doing it sustainably.
David Spark
I also think, like as someone who's been playing around with AI, it just generates more. Yes, it's interesting and I only take little morsels of it here and there. But there becomes the problem of managing the AI. As you were saying, that is now a new frigging problem. Yes.
Andy Ellis
Yeah. That's a skill set that you need to have. And the problem is we don't teach managers how to be managers. Almost every first line manager that I've had where it was their first time, I had to teach them how to delegate. Right. Because they never learn. And delegation is how you have to manage AIs because you are delegating work to them. But you have to know what success looks like. You can't just send them off to go fetch a rock.
Terry O'Daniel
I think that's true. And I think we talked a little bit about burnout too. And I think burnout isn't just the amount of activity you put in. It's not just the hours worked. It's the amount of cognitive load that you're sitting with as a baseline that's been unresolved.
David Spark
Yes. That's why I'm talking about the tier one stuff you need instead of an arrest. You just need sort of that brain dead exercise a little bit to sort of ease your brain.
Terry O'Daniel
We all need the dopamine hit of checking something off the list.
David Spark
Yeah. That's why we break up our day with doing other sort of work tasks that don't use the same part of our brain.
Andy Ellis
My breakup today is I work on cooking briskets.
Terry O'Daniel
Nice.
David Spark
What's it going to take to get them motivated?
Security culture operates on Hidden rules that shape behavior more than any official document, end quote. Those quote, hidden rules are more of a readout of what leadership values pointed out. Jamie Williams of Icarus said this. So when employees route around an incident reporting, click through training or treat security as it's problem, they're following the culture, not violating. Interesting point here. He suggests polling your employees on what your security looks like and map the variance in their answers. Wide variance indicates a leadership problem. Does anyone know how wide this gap is between the security culture leadership thinks they've built and the one employees are actually living? What do you think, Terry?
Terry O'Daniel
I think the unfortunate reality is that in most organizations, leadership isn't overly invested in seeing it through to completion. Yes, I think it is something of a checkbox exercise. And I think that I've been in environments where leadership says the right things. The ground level employees absolutely want to make things better. Right. Engineers don't want to have to. Now that we live in the world of DevOps, engineers don't want to have to support a code base or an, an app that's constantly falling over or getting hacked or something like that. But hierarchical organizations are tricky at the best of times and communication flows are tricky at the best of times. And I think sometimes that message gets lost. And where I see it most is the pressure that comes down from senior leadership to middle management. Basically the folks who actually manage the resources on those teams is relentlessly geared towards velocity, towards output, towards ship it culture. And I think it is important to measure the differences to understand the delta between what we say our security culture is and what we actually observe in terms of behavior. But I would skip past that a little bit because I think you're. I don't know if it's that useful. I think you could jump straight to the observed behavior because the observed behavior shows you what leadership values.
David Spark
But okay, I want to get into that secured behavior because I know that often executives request exceptions on security policies. How visible is that to the rest of the company?
Andy Ellis
Oh, so visible.
David Spark
It's really visible.
Andy Ellis
Okay, everybody knows that that's going on. I think Jamie has an absolutely correct observation here. And I always like to point at my book. Everybody knows. I just say, oh, this is what I covered in this chapter. This is one of the places where I actually got it wrong in my book. What I have the chapter with the wrong title. So chapter 42, which is about culture, I have a pablum title. What it should have been is culture is the garden of the flowers you cultivate and the weeds you Tolerate, Right? And everybody only looks at the flowers and they say, oh, our culture is what we said as management that we planted. But if you're not pulling up the weeds, the weeds are your culture. And sometimes those weeds are bad and sometimes they're good. Like, there are weeds that are just fine, but if you didn't plant them and you don't talk about them. And so people saying, well, I'm not gonna follow the security policy. Cause it gets in my way. Right. You planted a dandelion, a sunflower, and there's dandelions all over the place. You've got a dandelion farm. You don't have a sunflower farm. Like, that's the real problem here. Now, I don't know any good executive and good manager who would need to go poll their employees to figure out what's going on. It's really obvious. It's the bad ones who don't believe these exceptions happen. I used to work for somebody who would just literally we'd say, well, we have a problem because people are all doing the X or whatever. We need to build a system to make it possible for them to do it the right way and not do it the wrong way. And he would just say, well, just issue a policy. Everybody will follows the policies. I'm looking at him, I'm like, you don't follow the policies. Why do you think anybody else would that if I just said, you may no longer do this thing that makes your job easy, that they'll listen? Like, that does not work at all. And it completely removes credibility.
David Spark
I will note that I did an assignment for Schneider Electric. They do essentially every kind of, you know, oil, chemical type, plant type security that you can think of. They were adamant, completely adamant about the fact that the management demonstrates security all the time. All the time. Absolutely adamant about that.
Andy Ellis
Yeah. No. I had a CEO who was great that I didn't have to do security awareness training to the company because he did. He would get up on stage at an all hands meeting and he would give phishing training.
David Spark
Wow.
Andy Ellis
And he would basically put up a phishing email that he had gotten the quarter that he clicked on a phishing email. He put that one up and said, this one got me.
Terry O'Daniel
Andy, you're going to make me cry from jealousy.
David Spark
I think. Yeah.
Andy Ellis
No, it was the best thing ever. And then sometimes he would be like. And Andy yelled at me and I'm like, I didn't yell at you. Come on, don't make me the bad guy here.
Terry O'Daniel
I have a counterexample I worked for a CEO who told the IT team to remove the security garbage from his laptop because it was preventing him from playing games.
David Spark
I got that once too. This was when I worked in IT years and years and years ago. And the thing, it was within a meeting and my manager told me, go to Marcia's computer, remove all her games off of it. And she, in a public meeting said, hey, somehow all my games disappeared. And I'm like,
Terry O'Daniel
glad we're focusing on the important things.
Andy Ellis
Yeah.
David Spark
This episode is brought to you by Adaptive Security. I mentioned them at the beginning of the show. They're the first security awareness platform built to stop AI powered social engineering. Now, as we all know, AI is rewriting the cybersecurity rulebook because attackers can now scale persuasion as easily as they can scale code. So the real target isn't just your systems anymore. It's human trust. We know this. Come on. If you aren't actively testing your organization against AI driven phishing, vishing and deep fakes, you're leaving a gap criminals will definitely exploit. So adaptive what they do is they run realistic simulations and deliver tailored, engaging training so your teams respond correctly when it counts. So get real training that's relevant to you at your environment, uses the actual people that you are working with and the projects you're working on. So learn more@adaptivesecurity.com it's spelled just the way it sounds, adaptivesecurity.com and when you go check them out, let them know you heard about them from the CISO series.
It's time to play what's Worse.
Terry, I know you know how to play this game.
Andy Ellis
Oh, no.
David Spark
What you may not know, and I think was emphasized in this comment that I saw on Spotify, is Andy perpetually annoys me. And I like it when my guests disagree with him. No pressure, Terry.
Andy Ellis
I like it when the guests agree with me. Terry. So just so you know, you're gonna make one of us happy and one of us sad. So you have no pressure.
David Spark
Yeah, there you go. No pressure.
Terry O'Daniel
Which one of you has the mute button?
Andy Ellis
Neither of us. That's the editors.
David Spark
Okay, this one comes from Louis Zhang of AIA Australia. He's given us lots of great scenarios. Here we go. This is interesting, this take. We've done variations, I think, of this before. So which one is worse, Andy? Is it being the one man army or one person army? As the CISO or sole cybersecurity expert? In a small organization where you hold essentially God access, you juggle every responsibility with limited resources and feel underappreciated for your expertise. I'm sure many people listening feel this.
Andy Ellis
All cisos of my generation started our career that way.
David Spark
Okay. And I'm sure many people listening are like, are they talking about me?
Andy Ellis
Yeah. A lot of startups are looking for that person as well.
David Spark
Scenario number two, working as a specialized security practitioner in a larger organization where you're stuck performing repetitively, narrowly focused tasks with little exposure to the bigger picture or opportunities for growth. This is the other half of our listeners, would you say?
Andy Ellis
Yeah.
David Spark
So which one is worth. These are two crappy situations I think many people have been in.
Andy Ellis
So this is fascinating because usually we're doing a risk management exercise of like, which one has the bigger risk for the company. Like, this feels like this is about career development.
David Spark
Sure, sure.
Andy Ellis
So which would you like?
David Spark
It is still, what's worse?
Andy Ellis
Still what's worse? No, no. But I just want to make sure we're like approaching this the right way. Because if I'm building a team, I want the second team.
David Spark
Right.
Andy Ellis
I want a team full of specialists who do their job, do it well, and I can replace them.
David Spark
No. Yeah, but that's not what it is. It's about you personally, right? Yes.
Andy Ellis
But mostly I'm setting the stage so Terry can't disagree with me by saying, well, I want the team that way. So this is about me personally. Like I have done the first one. The first one's what made me into being a ciso and I got to learn everything and I get to then later build the team by offloading work onto them. But you don't necessarily know when that's going to happen. And let's say that it did take years, so I'm going to go with that. The second one is personally worse, but I want to put a really big caveat on it, which is if you are just starting out, it's almost impossible to get the first job. So you're probably gonna end up with that second roll.
David Spark
Yeah.
Andy Ellis
And so you're gonna figure out how do you move out of it? But that's outside the bounds of the what's worse. But I really do wanna put a caveat on it to just say, right,
David Spark
but yeah, but you're stuck in that second scenario. You're stuck. First one, you're stuck. In both situations, you're stuck.
Andy Ellis
But you're going to learn so much more in that first scenario.
David Spark
Yes.
Andy Ellis
And so for your long term career and your long term prospects, the first one is significantly better than the second one. So second One's worse.
David Spark
Okay, so you say the second one is worse. All right, Terry, agree or disagree here?
Terry O'Daniel
Disagree. First one is absolutely worse.
David Spark
Yes. Thank you. Thank you.
Terry O'Daniel
I think the last thing you said is important, Andy. It comes down to where you are in your career.
Andy Ellis
Right.
Terry O'Daniel
When we started, there was no security team, Right. It was it. And you're just supposed to do the security on the side because it's important, but you don't get any credit for it.
Andy Ellis
Right? Yeah.
Terry O'Daniel
So I have been, more recently in my career the army of one or something like that at a startup. And I will say the cognitive load on a more experienced security practitioner who knows everything that's on fire and how challenging it is and how much you're trying to distribute, I think the damage to you as a human is much worse. Can you work at a crappy job pushing papers and. And work on your GitHub on the side and work on your career on the side?
Andy Ellis
Absolutely.
David Spark
Yeah.
You could have a side hustle there, too. But you're right, the first one sort of wears you away as a human being.
Andy Ellis
Right. And so, honestly, the first one works better for you earlier in your career if you can get it. But I do, you know, to Terry's point, I see a lot more companies that are trying to get senior CISOs to do this army of one job. And it's a challenge because you have people that are used to saying, no, no, I don't do scut work. I delegate that. Or I go buy tools. And they're being told, no, no, no, you don't have tools. You don't have people. Just go do this yourself. And I think part of the cognitive load is actually knowing it can be done better because you have done it better.
David Spark
Right.
Andy Ellis
And you're just not being allowed to.
David Spark
So let me ask you actually a question, both of you, because this is an interesting thing for a manager, is you rely on your people to do your work. But I'm sure there's cases where managers have employees where you are as clueless as clueless gets about what certain people do for their work, and that's happened
Andy Ellis
for many, that you're not a good manager. I'm gonna say right here.
David Spark
Right? No, no. And I agree.
Andy Ellis
But if you're clueless about what somebody is doing who works for you, you are not a good manager. You do not have to be as good as them.
David Spark
No.
Andy Ellis
Like, I had guys who worked for me who. Who could do cryptanalysis, but. And I'm never going to be the guy who does cryptanalysis but I can sit there and have a conversation about it with you. But no, I didn't have anybody that is like, oh, my God, they're a black box. I can't. I have no idea. I can't touch them. And every bad layoff I've seen was triggered by a manager who had people, they didn't know what they do, and so they laid them off.
David Spark
Right, Because. And because people feel like, oh, my boss doesn't know what I do, and they're right. And so they don't feel appreciated as a result. And I'm not saying that this is a good thing, but I'm sure this happens all the time as a team grows, as things get more complex as well. But you're right. You should be able to. You don't need to know how to do the job. You just should be able to be able to ask the right questions. And when you don't know, just simply ask about it as well.
Andy Ellis
Yeah, and here's a simple trick for you. If you're a manager, especially if you have a very large team, have a file that just has a list of everybody's name in your team, and every time you hear somebody mention someone's name about what they do, just move their name to the bottom of the list. That's it. You're just moving them in this file. And then like every so often, just look at the name at the top of the list and go solicit. What is this person doing? Why do I never hear their name? Is what they're doing valuable? First of all, it might be that you're going to find the dead weight in your organization, but what you're really going to do is you're going to find your blind spots and you're going to learn. And you're also going to teach your managers to advocate for their people. Because if there's one manager that's always their employees whose names you're not hearing, at some point they're going to be like, why does my boss have to keep asking me what they're doing? Maybe I should be volunteering.
Terry O'Daniel
That is a really crafty solution. And I'm going to take a note, but the one I came up with during COVID when I had to run remote teams. Work publicly.
Andy Ellis
Right.
Terry O'Daniel
Train your team to work in public so that your juniors can learn from your seniors years if you're going to hold it.
David Spark
So what do you mean by that? Work publicly virtually. Because you're hitting a very critical concern I have about remote work. Explain.
Terry O'Daniel
Yeah, so everything from explaining what you're going to do and why, explaining how you're going to do it, explaining the specific typing out the specific command you're going to put in the cli, all of that, the package, this is how Juniors. When you can sit next to someone
David Spark
so you, like, would you put in like a. You put in some repository, or you
Andy Ellis
just do it live in your chat, in your Slack messages.
David Spark
Yeah, yeah.
Terry O'Daniel
You do it in your daily standups. You do it in Slack. You have whatever you have. As a way to say, just as if I were in the same room as someone, I would say, hey, I'm gonna work on this thing. Do you want to lean over and see what I'm working on? That's how we train juniors in person. I think the only way to do that in a remote team is to just dive as deeply as you can into the transparency and the thick skin of working in public and being humble enough, everyone, to say, oh, crap, I got that wrong, or I would have done it this way, or something like that.
David Spark
I'm glad you brought it up because this is one of my number one concern about remote work. And I always make this reference if people heard this before, but when I was in college, I was interning at an agency, actually a marketing agency at the time, and there was an amazing salesman there. Just. He was phenomenal. He never sat down and taught me anything at all. But I just watched him operate. And just watching him, I learned so much. And you realize that if we were working remote, I wouldn't have learned any of that.
Andy Ellis
Yeah, it's a huge challenge in the distributed era. And one of the things I would do, like, I would have a question for one of the architects on my team, and I didn't know who the architect was. You know, some executive came and said, oh, we're working on Project Anaconda and we need your input. I'm like, I know you've already talked to one of my architects. I want to know what they said. So I would just go into the Slack channel for my whole team and be like, hey, does anybody have any context on Project Anaconda? Now, I could have gone to the head of architecture and be like, hey, who's the architect on this? Or I could even guess who it was based on the vp. Like, we had architects assigned. But now the architect would respond in front of my whole team. Here's the context of Anaconda. Here's what they're asking to do. Here's the advice I already gave them. Here's probably why they're escalating to you. Here's what advice I would like you to see give them. And so all of a sudden, the whole team got to see this dynamic. They got to see the head of the team values the authority of people inside the organization. Here's how to do clear communication. And they would learn a little bit about Project Anaconda the same time.
Terry O'Daniel
And going back to what David said earlier, I think it was David, that we don't. Or maybe it's you, Andy. We don't train security engineers on how to be security leaders.
Andy Ellis
Exactly right. So you're modeling the behavior for them that you want out of them, and you're teaching them how to do the job.
Terry O'Daniel
Exactly. And I try to do that as well. I'd say, hey, I'm preparing a board deck. Let me show you what I'm going to put into it, where I got that data, why I'm putting this in. Joe would ask, well, what about this thing? This is super important. And I would explain, you're right, Joe, but it's like one level too deep and the board won't get it when it gets to this stage, then I'm going to be able to talk about the outcomes and blah, blah, blah. Absolutely. That is the training that we get. And because it's an asynchronous mechanism, people can look at it, catch up. If you're working later in the day, you can catch up and understand the context. I agree with you, David. I think there is a real danger in remote work. And I have seen teams where, you know, people could blissfully just work in their corner and do their work or not, and no one really knows. But I think it is an opportunity for people to be transparent and humble and say, gosh, I didn't know that that worked that way. I've been doing it this way. Or to Andy's point, hey, that's weird, because I heard this other thing about Project Anaconda and someone asked me to work on this piece. Maybe we should align and make sure we're not going in two different directions.
David Spark
They didn't think that through all the way, did they?
AI will not replace leaders, but will expose them not by what they decide, but by what they choose to ask. The issue isn't that AI isn't draining empathy from decision, it's revealing whether empathy was ever there, argued Chris Bohm of eris. You can't blame the LLM when it leans into how you frame a question. Bohm's larger point is that AI strips out the friction, the team debates, the uncomfortable conversations that used to act as a safeguard against shallow thinking. Oh, we just went through exactly this exercise, and we were using Claude as well. So going on says now decisions arrive in seconds, clean and defensible and sometimes completely disconnected from human impact. And in fact, I am tired of the sycophantic attitude of ChatGPT and Claude. You know, everything I say that is so perfect, it's great. You really got it on the money.
Andy Ellis
You are so brilliant, David. I know you've never heard this in your Life, and now ChatGPT can't not say it.
David Spark
I know. In fact, there's actually. I just saw. I haven't listened to it, but there's an episode of the Daily. That's the New York Times podcast about AI helping people be less lonely. And I can totally see it if people believe it. So I'm going to throw this to you, Terry. So the prompt is the Leadership Act. How do we protect against LLMs turning our blind spots into strategy? Because that's what I feel it's doing. What do you think? Agree or disagree, by the way? Well, I agree with the theory.
Terry O'Daniel
I do think that LLMs exacerbate organizational and leadership challenges. The real danger is that they do it in a very clean and polished way. And I think as humans, we have a natural tendency to. If the output looks clean and polished, we tend to think, oh, someone must have put thought into this. Someone put effort into this. And it makes it really easy for weak, unchallenged reasoning to suddenly become the strategy.
David Spark
Yes, yes. So we went through a series of iterations because we're developing some themes for CISO series, and we were constantly questioning Claude, and it's not like we were looking for the answers out of Claude, but it was just we were using it as a tool purely for brainstorming, and that's it. And that's what I think AI is great for in terms of creative pursuits, is not getting the answer. But it's like I just need some ideas. Ideas to hit me, for me to bounce off of them. What are your thoughts, Andy, here?
Andy Ellis
So I think that there is a slight misconception here that leaders actually listen to the people around them before making decisions. Let's just be real honest. In most organizations, people make gut decisions and then they go around justifying them. And I think we've all been in those conversations where the leader walks in for our opinions and yet walks out with the exact same decision they walked in with, despite having heard why it's an awful idea.
David Spark
And let me qualify. I try very much not to do that because I tell my team, I say, please tell me how I'm wrong. I want you to shoot bullet holes in this idea. So I do want to know these things, right?
Andy Ellis
And so some leaders are fantastic at this, or at least tell us they're fantastic at this. And if you're already doing that, then you can ask AI in the same fashion. Like, if you're used to saying, tell me why this won't work, then ask AI to tell you why it won't work. So if you are prompting in the same way that you were leading with humans, then you should actually get some comparable outputs, I think from AI, you're likely to get better reasons why something is bad if you ask for it, but you're less likely to get clever insights because it's just the gestalt of what humans have said. So you're going to at least do it as the sort of most common practice, which means if you were worse than that, it'll be really good at telling you, hey, don't be worse than that. But if you're expecting it to give you the home run, no, it's not going to do that for you.
David Spark
The advantage is it's operating because normally we start with a blank slate and we're like, I don't know where we're going to begin. And AI allows us to not start with a blank slate or even evolve like it's giving us stuff.
Andy Ellis
Right. But it starts you on a path that other humans have always been on. That's the important thing. It's not going to take you trailblazing and do something totally novel, but it will take you down the path that lots of folks have gone down. If that's a successful path, that's great.
Terry O'Daniel
And as you said earlier, it's based on the prompts you put in.
Andy Ellis
Yep.
Terry O'Daniel
Right. I can see the output. I don't necessarily know where you started from. What prompts did you put in that's going to heavily change what the output becomes?
David Spark
Coming up next, the AI model you downloaded is really just code from a stranger, and, well, heck, hardly anyone stops to check what's inside.
This AI governance and AI security tip is sponsored by Speakeasy.
A team downloads a popular AI model from a public website, adjusts it with external data, and puts it to work without ever checking what's inside. Here's the problem. The model is largely a black box. It includes the program itself, the trained model, and the data it was trained on. Any one of them can be tampered with before it ever reaches you. A malicious model can run hostile code the moment you open it. If someone quietly corrupts the training data, the model can carry hidden, harmful behavior that ordinary testing will never catch. The fix is to treat AI you bring in from outside with the same caution you'd give any other third party software. CISA and the nsa, along with international partners, published joint guidance on deploying AI securely built. On exactly this point, the AI you didn't build yourself and the data behind it has to be secured. And Mitre keeps a free public catalog called Atlas that documents how attackers actually go after AI, from tampering with the supply chain to poisoning the data it learns from. So know where your AI comes from. Treat it the same way you'd vet any vendor, stick to reputable providers, and open anything unfamiliar in an isolated test environment before it ever touches production. An AI model you can't vouch for is just one more untrusted piece of software running in your business, and you already know how that story tends to end.
Go to Speakeasy.com to see how leading enterprises are scaling AI solutions securely with the Speakeasy AI Control Plane. Walk a mile in this ciso's shoes
Quote Loyalty is not a static trait, but a dynamic human response shaped by perceived fairness. End quote. Now this is Christopher Burtis who pointed out in CS Online that we get into trouble because trustworthiness and loyalty are not the same thing, and loyalty runs both directions. Too often organizations are quick to throw departing employees under the bus. Doesn't make those that remain feel any better. Now, when the organization stops holding up its end, employees stop holding up their so we're kind of alluding to that at the beginning of the show. So how do we build insider risk programs that account for the full lifecycle of the employee relationship, including what happens after someone walks out the door? This is a good point. So Andy, I'll ask you if a company's security posture depends on loyalty, what happens when an organization is the one that broke that trust first?
Andy Ellis
And I think we've been seeing this a lot lately. I just read on LinkedIn and I haven't sourced it. No, it's for real. About a fairly well known company that did a layoff and just all of the affected employees could not log in that morning. No communication to them. They're reaching out on LinkedIn to their managers to be like, hey, what happened here? Do I get laid off? Or are we having a company incident where our Laptops don't work, and that's a problem. Like, there used to be some norms around this. I've had to deal with lots of layoffs in my career and I've had to fight with hr. Like, we once had hr. It was like, well, we need to revoke people's badge access because we're afraid they'll do something physically in the building, but we want to leave them with laptop access for two weeks. I was like, no, no. Same amount of time. Like, I'm fine with two week notice and they can come into the building because I'm more worried about them stealing data than coming in and doing something violent. But if you think that they're violent and risky, then we'll revoke everything at once. But that's on you.
David Spark
But that's actually, that should be for a whole other episode. How do you handle offboarding? That doesn't make their experience when they leave violent towards you. Yes.
Andy Ellis
You do it gracefully.
David Spark
Yes.
Andy Ellis
You said, this is a business. We're letting you go. And you do it in a graceful fashion. And there's a lot we could spend hours on how to be graceful.
David Spark
Yes, I know this is a whole other episode is what I'm saying.
Andy Ellis
But what's happened is companies have lost that grace. And what's really exposing is, look, your company was never your family. They were never your friend.
David Spark
Oh, I know they want you to
Andy Ellis
believe that, but they at least used to pretend. And now it really does feel like the gloves are starting to come off more and more that they're not even pretending to be graceful and the ways in which they're doing things. And now not everything is graceful. Like, there are mass layoffs that are done gracefully, but people still get pissed off at them. The business decision of whether or not you're employed is not where the grace comes in. It's in how they treat you in executing on that decision. And I think as employees, we need to separate them. But I think what's starting to happen more and more is people are saying, oh, if this is how I'm going to be treated in the future, now, this is my expectation, how should I protect myself against that transaction when it happens? So I think I'm not worried about after somebody has left. I'm worried about what they do in anticipation of the lack of grace they're going to see on the way out the door.
David Spark
Yeah. Cause they'll see it happening to their friends. Yes. Well, but okay, so these are multiple things because only people think about what they would do at the moment of being let go, that very moment. But you need to think about like what you just said the before. If they witness bad behavior, how are they going to protect themselves? I know I have done this and others of saving your data well ahead of time. Yep.
Terry O'Daniel
Yes, of course.
David Spark
Yes, we have all done it. And then, I mean, I think this piece, Christopher Burgess, brings up a good point of like, what is their behavior afterwards? I mean, it could ruin your employment brand if you talking smack about the company to Terry, what's your take? Take it from any angle here.
Terry O'Daniel
There's two real challenges here. Speaking as a security professional rather than someone who's suffered the slings and arrows of organizational corporate culture. People don't separate company culture and security culture. It's just one thing.
David Spark
Yeah.
Terry O'Daniel
If you're an employee, how you're treated by the company, just, it all blends together. It all blurs together. And I think if you create a sense of distrust, if you create an expectation of humiliation and depersonalization on the way out the door, you're not only telling people you can't trust this company, but you're telling people that the messages, the policies, the standards that the company has given to you aren't to be trusted either. And then I can't do my job.
David Spark
I want you to know that. There's a woman who ran human resources for an agency I used to work at. And when I was leaving the company, when I had quit, I was essentially pushed out. But when I quit, she came and goes, now you're not taking any of the data with you? And I said, no, of course not. So fast forward multiple years and I run into her at an event out here and she starts coming to my event and I actually introduced her to the audience. You know, 80 to 100 people come to her. And I go, this is Kate, who used to run HR at the company. She asked me when I quit if I took any data with me, just so everyone knows. And Kate, I did.
Andy Ellis
Yeah, I don't even know where to go with that one.
David Spark
David Company doesn't exist anymore, by the way.
Andy Ellis
Okay, that's. That's helpful. That's good. I'm going to tell your current employer they should worry about you taking data.
David Spark
Yeah, go right ahead, tell them. All right, we have come to the close of the show. Thank you both. This was a ton of fun and a super sized show for that matter. Thank you very much. Terry, I'm going to let you have the very last word here, but I want to thank our sponsor and that is adaptive security protect against deepfakes and AI powered attacks. That's adaptivesecurity.com I want to ask you, Terry, are you hiring over at your company, Udia?
Terry O'Daniel
Yeah, Udia is hiring both security engineers and DevOps folks, we'd love to chat with you if you are interested and you can find me on LinkedIn at the LinkedIn URL with Terry O'Daniel at the end.
David Spark
Well, we will have a link to it on the blog post for this episode. And I'm assuming you guys have a job of some sort. Yes, yes, yes.
Terry O'Daniel
If you go to udea.com, i'm sure you can find it.
David Spark
Go to the job board first. Look and then tell specifically Terry the job you're interested in. There you go. That's how it works. Don't just say help me find a job.
Andy Ellis
Oh, come on. Hey Terry, help me find a job.
David Spark
All right. Thank you everybody. Thank you, Terry. Thank you, Andy. And thank your audience. As I always say, thank you for your contributions and for listening to the
CISO Series podcast that wraps up another episode. If you haven't subscribed to the podcast, please do. We have lots more shows on our website, cisoseries.com Please join us on Fridays for our live shows, Super Cyber Friday, our virtual meetup and cybersecurity Headlines. Week in Review. This show thrives on your input. Go to the Participate menu on our site for plenty of ways to get involved, including recording a question or a comment for the show. If you're interested in sponsoring the podcast, contact David Spark directly@Davidisoseries.com thank you for listening to the CISO Series podcast.
Episode: With AI, I Can Now Be Pulled in 5x More Directions at Once!
Date: July 21, 2026
Host(s): David Spark, Mike Johnson, Andy Ellis
Guest: Terry O'Daniel, CISO for UDIA
Theme: Navigating productivity, burnout, and leadership in security teams in the era of AI
This episode tackles the evolving reality of security work in the age of generative AI, focusing on how AI impacts productivity, cognitive load, and workplace culture. David Spark, Andy Ellis, and guest Terry O’Daniel explore whether AI is truly helping security professionals or just accelerating burnout, delve into the hidden realities of security culture vs. policy, dissect the new demands on leadership, and discuss managing insider risk across the employee lifecycle. Listeners also get actionable insights on managing remote/async teams, the nuance of offboarding, and practical AI governance tips.
Memorable Moment:
Andy reveals to David on-air that he was listed among comedians in the original Dunning-Kruger study, a fact David barely remembers, producing much laughter and mutual teasing.
Dunning-Kruger, Revisited:
“I just discovered this…I was laughing as I'm reading the list of comedians, and you were in that.”
– Andy Ellis [05:38]
AI & Burnout:
“You become a manager, even if you're only managing AIs...You need to get away from your AIs for a bit because the challenges, your AIs aren't like employees who all disappear for lunch.”
– Andy Ellis [09:34]
Security Culture Reality:
“Culture is the garden of the flowers you cultivate and the weeds you tolerate. And everybody only looks at the flowers…and say, oh, our culture is what we said as management that we planted. But if you're not pulling up the weeds, the weeds are your culture.”
– Andy Ellis [17:02]
The Human Cost of ‘Army of One’:
“I think the damage to you as a human is much worse. Can you work at a crappy job pushing papers and…work on your career on the side? Absolutely.”
– Terry O’Daniel [25:05]
Remote Team Transparency:
“You do it in your daily standups…just as if I were in the same room as someone, I would say, hey, I'm gonna work on this thing. Do you want to lean over and see what I'm working on?...the only way to do that in a remote team is to dive as deeply as you can into transparency...”
– Terry O’Daniel [29:13, 29:46]
AI Exposing Leadership:
“AI will not replace leaders, but will expose them not by what they decide, but by what they choose to ask.”
– David Spark [32:45]
Offboarding, Loyalty, and Security:
“If you create an expectation of humiliation and depersonalization on the way out the door, you're not only telling people you can't trust this company…but I can't do my job.”
– Terry O’Daniel [44:39]