![Microsoft for Startups: The benefits of the cyber startup ecosystem. [Special Edition] — CyberWire Daily cover](https://megaphone.imgix.net/podcasts/06ca035e-2214-11f0-a9f1-7770d1a68bd9/image/0216c9cea15c53e5d2c739964a38623c.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress)
Loading summary
Dave Buettner
You're listening to the Cyberwire network powered by N2K.
Welcome to this N2K CyberWire Special Edition. The Microsoft Startup Spotlight brought to you by N2K and Microsoft for Startups. I'm Dave Buettner and today we're shining a light on innovation, ambition and the tech trailblazers building the future right from the startup trenches. This episode is part of our exclusive RSAC series where we're diving into the real world impact of the Microsoft for Startups Founders Hub. A no cost, no funding required platform built to empower startups with everything they need to grow fast and build smart. We're talking free access to cutting edge AI tools like GPT4, up to $150,000 in Azure credits, and one on one expert guidance to turn bold ideas into resilient scalable solutions. We'll be talking with founders from three incredible startups who are part of the Founders Hub, each tackling big problems with even bigger ideas. So whether you're building your own startup or just love a good innovation story, stay tuned. This is Microsoft Startup Spotlight and the future starts here. Well, welcome everyone and this is the kickoff of our CyberWire N2K special edition showcasing Microsoft for startup supported companies. We're talking about Serby Reg Scale and Endor Labs. Before we get to that, I want to welcome to the show Kevin McGee from Microsoft and FC, a very well known and renowned hacker and also an entrepreneur in his own right. Let me start with you Kevin. Welcome to the show.
Kevin McGee
Thanks Dave.
Dave Buettner
Thanks for hosting us and fc, always great to catch up with you, my friend. It's been a little while, but I'm happy that we get this opportunity to chat.
FC
Yeah, thank you. Thank you for having me on, Dave. I'm really, really looking forward to this one. This is going to be an interesting conversation, I think.
Dave Buettner
Well, Kevin, can you set the table for us here? When we're talking about Microsoft for startups, which is something that you run at Microsoft, what do you want folks to know about that endeavor?
Kevin McGee
Yeah, I think we're really focused on is looking at using the ecosystem that Microsoft's creating. Not just the technology, but the access to enterprise customers, the trust we've built up in the brand over many years, and then just our marketing machine, the big microphone I like to call it, of Microsoft. How do we hand that to founders and startup and innovators so that they can get the attention that they deserve, so we can drive innovation, so we can get innovation into the hands of the folks that most need it now? Because it's harder more than ever to get that attention. I founded my three companies in the 90s. Two successful. One I don't like to talk about using BizPark, which was the predecessor to the Microsoft for Startups program. So it's so cool to be involved after all these years. And I have that connection. And I remember working what having sort of that big ecosystem to plug into to be part of something to help accelerate my business did for me. And that's what I want to bring to our startup founders as well.
Dave Buettner
Well, fc, you have personally made the leap from hacker to entrepreneur. Can we talk about that journey a little bit? What's your origin story and what led you to where you are today?
FC
So my origin story was I was weirdly bitten by a radioactive spider. No, no, not great. You do, yeah, yeah, it happens. Didn't do any superpowers. I was working as a defense contractor. I was the head of offensive cybersecurity for Raytheon for many years. And I was getting a little bit frustrated with all the red tape. And there's a fantastic adage that says you'll never get rich working for someone else. And so it was like, hang on, I need to get, get rid of the red tape. I also need to go and make some decent money for myself. So my wife and I started a company, Sygenta. We started that many years ago and we, we took the hard route. We went with self funding. I think we put about $250 into it. I donated some computer systems and that was it. That was the start of it. And it's been a fantastic journey. It's been hard, but incredibly rewarding.
Dave Buettner
What are some of the specific challenges you remember of building a company?
FC
The biggest issues that we had, obviously being self funded was money, right? We, we struggled with money at the beginning. We had to make sure that we had enough payroll and mortgage and all of this stuff. No one was going to come and save us. So that was, that was a challenge. That was a bit of stress. And then from there on it's learning how to run a business. And that is really hard. People just think, oh, I can just be an entrepreneur. I'll just start a company, I'll start making money and then we'll get clients. There's lots of administrative stuff that you have to learn that you didn't realize when you were just an employee.
Dave Buettner
Kevin I think that is a message that echoes with probably anybody who's been an entrepreneur, who's listening, that I think for most people, they get into running their own company because they want to do the work, not because they want to tackle the day to day tasks of running a company which is its own thing.
Kevin McGee
I think that's the problem. When you make your passion your job, it can become a challenge. And really I think we look at the exits or the big IPOs or the big success stories, but we really forget the amount of work and challenge it takes to find a unique solution, bring it to market, get the attention, get the funding you need, all while figuring out how to make payroll. I remember in the dot com boom running my first company, I was interviewed for a magazine article and they said, you're the president of a dot com startup. What's the first thing you do when you come into the office? And I said it was take out the garbage. It's these mundane things that really can distract from building your business. But ultimately I think what gets us through and this is why I'm so excited about what we're building in Microsoft for startups and I think FC personifies this, is this hacker mindset is very much in tune with the entrepreneur mindset. It's experimental, it's adaptable, but it's also mission focused. And I think that's one thing our industry is so different than any other industry. We're all defenders, we're all trying to solve a problem, we're all trying to help people in organizations. So I think that unites us in a way and lets us work together more collaborative than potentially any other industry as well too.
FC
Yeah, I'd like to echo that actually. I think that the hacker mindset is actually really quite helpful in the situation of starting your own company because you don't know all of the solutions that you need when you start. Right. So when we started we didn't have a CRM, we didn't know which CRM to use. We've changed CRM now three times. Having the team around you that understand that you, you're going to make mistakes and that you're going to change things and the way things work and the way that policies and procedures are done, they're fluid. Right. You don't go in with this just set of things that you've got and you go, right, that's it, my business is now sorted out. You have to understand what you need to change and change it quickly. And I think that was one of the frustrating things when I was working for other people is you could see what needed to change but they were so gigantic you could never change them. Whereas being a small independent entrepreneurial company, we're able to just make a decision. The other day we just like, okay, we're not using Adobe anymore. That's it. We just killed it. And we're going to find solutions as we need them for other work that we need.
Dave Buettner
You know, fc, I think you have the experience of being on both sides of things, having worked for a big organization and then taking that entrepreneurial journey yourself. I think one of the challenges that a lot of entrepreneurs have is getting the attention of those big companies and getting them to take you seriously. Was that something that you found yourself up against when you're just starting out and knocking on doors or did your experience from the other side serve you well?
FC
I have to say we are incredibly fortunate. Right. So I founded the company with my wife who is incredibly good at her job and she is very well known. So we came into the industry already very well known as individuals. And because of that, a lot of people wanted to work with us straight away. So we made profit in like the first month, which is very unheard of for a lot of like sort of small startups. Because companies want to work with us, we don't spend a lot of time doing the general marketing stuff that a lot of people have to do. We have a backlog of people that want to work with us. We are very fortunate that we have enough clout, if that's the right word, to say no to certain people. Like I won't work with people that don't want to actually improve their cybersecurity because it's a waste of their time, it's a waste of my time. So having that freedom is massive and is very unlikely to happen for a lot of people straight away.
Dave Buettner
Kevin, can you touch on some of the advantages when an organization that's coming up when they partner with Microsoft for startups, I imagine having that subtitle being a partner with Microsoft helps open some doors.
Kevin McGee
I think that's the key. Having that sort of the brand recognition can really make a difference. But if you're two researchers that have spent time in the lab building your solution or whatnot, you maybe don't have those public profiles. So that's something that sort of we bring to the table, but also just bridging that gap that FC talks about is. And enterprise leaders have all this challenge. Big enterprises are risk adverse. There is a lot of bureaucracy and whatnot. But ultimately what they need to do is translate innovation into an outcome and they need the understanding of what that looks like and build the narrative for that business case to Unlock that budget or whatever it takes in terms of cultural change to adopt a new innovation strategy. So one of the things I do in my day to day role, which is what I really enjoy, and I did the reverse, I went from entrepreneurship to the large company is bridge that gap and be that translator. Innovators want to move fast. They don't want to have things get in the way. Enterprise leaders have the exact opposite problem. How do you find common ground and how do you translate that innovation into outcomes that can really build that story? And I think you'll hear some stories from some of our startups as part of the series that have really focused on understanding that enterprise challenge, taking an innovative approach to solving it, but then being able to explain and articulate that solution well, that allows that ciso, that enterprise security leader, to build the business case or change the culture to adopt it. And that's really our mission is how do we get those best ideas into market and how do we help them scale securely responsibility and just sell more faster for revenue for our startups, but also making our enterprise customers more secure faster as well too. And getting sometimes these two cultural groups to come together and speak the same language is a bit of a challenge, but when it does happen, amazing things can occur in terms of an innovation learning loop and whatnot with our startups.
Dave Buettner
Well, fc, we're going to hear from some startup founders here, some really interesting companies. What is your advice to folks who are in that situation? That person who is hungry to start their own business, they feel like they have something that's going to solve some problems that aren't being solved out there and they're ready to go. Any words of wisdom?
FC
Yeah, I'd say go for it, right? Just do it. I'm sorry if I'm going to get sued by Nike for that, but no, just actually go away and actually start it, right? So I've had many, many people come up to me and be like, hey, thinking of doing this, thinking of doing that, like when do I do it? How much savings do I need? It's like, don't put your family at risk, right? Don't mortgage the house in order to do it, but make sure you've got a little bit of money to saved up to as a, like a slush fund and then just go for it because there'll be unexpected costs along the way and you don't want to be out on the street with, with nothing and saying, hey, I've got a company now, so yeah, plan it, but then just go and do it. Don't stop because you think you can't do it. Or there's. You have to have this perfect plan. Just start it, just go and register the company. That. That bit alone doesn't take any effort.
Matt Chiode
Right.
FC
It's very cheap to start a company. You don't have to trade with that company for ages. You can just get it started, buy the domains, build small, and then it will go. That would be my advice. Just go off and do it.
Dave Buettner
All right, well, I'm looking forward to hearing the stories that our entrepreneurs have to tell. Kevin McGee and FC, thanks so much for joining us.
FC
Thank you.
Kevin McGee
Thanks, Dave. Thanks, fc.
Dave Buettner
Joining us is someone who's been at the forefront of cloud security long before it became buzzworthy. We're thrilled to welcome Matt Chiode, Chief Trust Officer at Serbi, a Microsoft for startup standout. Matt brings over two decades of deep security leadership experience, including his time as Chief Security Officer of Cloud at Palo Alto Networks. He's not just a security strategist, he's a voice in the industry. You've likely read his blogs, caught his podcasts, or seen him take the stage at major conferences like rsac. And if you're an IANS research follower, you might also know him as a member of the faculty helping shape the next generation of cyber leaders. Today, Matt's here to talk about trust, innovation and how Serbi is rewriting the rules on securing what he calls the unmanageable applications in the enterprise. So let's start off with just some high level stuff here. I mean, for folks who aren't familiar with Serbi and the value proposition here, can you give us a little bit of the origin story and what the problems that you all are looking to address?
100%. Yeah. So the origin story of Serby, which I think is probably one of the most interesting, is that our founders had started some previous companies and after they left those companies, they were doing some work and they noticed that they started using these various different SaaS tools and they would start to use them and then eventually the IT teams would come around and either shut them down or say to them, hey, these tools don't support these standards. You can't use them. So they would get blocked by it and it kept happening over and over again. Go to provision a tool, a SaaS tool, and then lose access to it. And so that got them thinking, like, why are so many of these quote unquote modern SaaS tools? Why, why don't they support these standards? And they started to research IT and what they found was that at the time it was easier for these tools to launch without support for standards like saml, scim for provisioning and deprovisioning than it was for these teams to build them out of the box. And what that created was is that from a product perspective, when they actually spoke with these companies, they asked them like, hey, why aren't you building this? They said it's because our users aren't asking for these standards to be supported. They don't care about them. And so that got them thinking. And you know the name of the company, Serby, it comes from Greek mythology. So Cerberus the dog and that dog, that three headed dog. If you look at our logo, that three headed dog in Greek mythology is what guards the gates of hell from breaking loose. And that's what we do for companies when it comes to all those applications that fall outside of the scope of their current identity stack.
Well, Kevin McGee, does this story resonate with you? I mean, I'm thinking back to any experiences in your professional career of facing similar frustrations.
Kevin McGee
Well, first off, Dave, you know, I'm a recovering historian, so I love the tie into the Greek mythology. I think it was the twelve labors of Heracles he had to steal Severus. But it certainly really speaks to this challenge because the most innovative and smallest organizations are probably those early warning systems because they're quick to adopt tools, start to see identity sprawl in these early companies. And now as big companies are starting to act more innovative and more like startups, we're seeing these challenges as well too. But we've got CISOs that have to figure it out and figure out how to protect these large organizations. So I think there's real consequences to the large organizations when we don't have just sort of compliance across and hygiene across identities. So it's a great opportunity to look at new investment, new innovation from both Microsoft's perspective and our customers.
Dave Buettner
Well, Matt, help me understand here, how widespread is this problem when we're looking across the enterprise landscape?
You know, a lot of us who are in tech, a lot of times we assume that every company is using something like a365 or a very modern SaaS app. And while they might use some of those, that's not the only type of apps they're using. We have found that even in some of the most progressive tech companies, they have these what we would call disconnected apps that they can't manage with their entre or whatever they're using for their, for their IDP and You know, this creates all kinds of different challenges, right? With these different apps, there could be no multifactor authentication, no centralized logs broken off, boarding weak audit trails. And from a. In terms of how widespread it is, we did research with the Ponemon Institute and we found that the median, the median number of these applications that exist in an organization, it's 176. That's the median, it's not the average. So 176, that means you've got organizations, you know, if you've got a multinational corporation or, you know, a large financial services company, you could be talking about having thousands of these applications that exist, again due to the diversity of the applications that exist in their businesses. So the problem is it's very widespread.
Is this more of a legacy problem? Are we finding that the new tools that are coming along, the new SaaS tools are, do they have these capabilities out of the box, or is this an ongoing situation?
You know, certainly some of them do support it out of the box. But we did other research. We looked at the top 10,000 SaaS applications and what we found was, was surprising. We found that 47% don't support two factor authentication, 54% don't support SAML, and 93% don't support the SCIM standard. And for those that aren't familiar with scim, the system for cross identity management, that is the standard that was created years ago that was supposed to be available in every app that would allow you to do automated onboarding, offboarding, you know, someone moves roles, things like that, to automatically update it in those downstream apps. So, no, this is not a legacy problem. I mean, this is why companies like Auth0 were created on the market for the SIAM start of the house. And even other companies like Descope followed on because the problem is so massive.
Well, I know you and your colleagues there at Surby are making good use of AI for identity security. Can you share with us how are you applying it?
Yeah, most of what people know about AI is typically generative AI. We specifically are leveraging agentic AI. And the best way to think about agentic AI is that it is a model that is trained on a very narrow problem set and then it can take actions autonomously based on that training. So if you call a help desk number, you get an agent on the phone. We're talking about humans here, at least for now. Very good. Or they should be very good at one thing. If you call, you know, help desk support and ask them how to change the oil in your car, they're probably not going to be able to help you with that. But they're good at one thing. So the way that we leverage that is we train based upon the applications that we need to support. And these are, you know, typical integrations with, you know, thousands of different applications. So we make use of things like computer vision, graph, neural networks, reinforcement, learning. And you know, the best way I would contrast this is when most people think about automation, they're typically thinking of like script based or rpa, robotic process automation. And RPA is extremely brittle. It breaks anytime something changes. And in the use in the case of most of these, again, these disconnected apps that we deal with, there is usually little offered in terms of things in the way of standards. And so it's super important that anything like this be multimodal. So we look at the app and we look at, hey, Is there any APIs available? Is there partial protocol support? And then based upon what's available in that app, we can leverage it with our agentic AI.
So how do you make sure that the decisions that the agentic AI is making are both safe and auditable?
That's one of the toughest challenges to solve with AI right now. We've got a number of patents that are pending and we certainly have not figured this out 100% yet. It's something that we are actively developing and working on. But there are a couple different things that we are working on and even working with some of our partners. So people might be familiar with rag, which is retrieval, augmented generation. That is something that we are leveraging with our agents and it grounds them in their responses so they're verifiable based upon our internal knowledge. But safety and auditability comes from how we wrap that AI with structured decision logging and policy enforcement. So when we look at where we're going with the platform, every AI, every agent that's taking an action on behalf of a user or system needs to be logged. The who, what, when, where and why not just what the model said. We have to remember AI is not, is non deterministic when you're doing security things with AI, it's gotta be deterministic. And so there will, you know, at least for now, there's always going to be a human in the loop. So for example, if confidence is low or risk is high, we escalate that to a human by design.
Kevin, what's your response to what Matt's describing here?
Kevin McGee
I think what CISOs are telling me they want is really just consistency. That's where the value is. And Allowing AI to ensure the policies are applied to applications that humans would forget or ignore or not even know about. I think that's where the value that Serby really brings to the conversation. And CISOs are actively looking to solve these challenges and for solutions that can do that.
Dave Buettner
You know, Matt, I know that Serby integrates with Microsoft Entra. Can you describe that combination and why that makes sense for customers?
Well, what we overwhelmingly see across customers and prospects is that they do use Entre for their identity and access management. It's already integrated as part of 365 and for us it was a no brainer to have an integration there in terms of what we do. So Serby integrates with Entre to apply governance policies again out to those disconnected apps. Now normally those apps would be outside the reach of entrepreneurs. And so we help customers take their existing investment in Entre and then be able to extend those native capabilities of Entre to those disconnected apps. So it could be enforcement of zero trust principles across all their apps, not just the ones that are integrated. There's use cases that are just as diverse as the applications are. It could be protecting social media platforms, it could be design tools, it could be a legacy application. And really with a combination of Entre and Serbe, it allows us to, to combine Microsoft's platform with Serbe's precision for edge cases and those disconnected applications.
Well, Kevin, what is Microsoft's view of this sort of integration?
Kevin McGee
Ultimately we believe in building an open identity ecosystem and Surby's innovations really strengthening that approach. It allows customers to look at the sort of the secure edge of their identity attack surface and solve for that. So ultimately we're looking to build that ecosystem platform for innovation and allow startups to build on that and find new ways to solve problems. And Serbi is a great example of that. That really leads to not lock in, but fill in to our capabilities, but also just expand and empower organizations with choice. What do they really need to solve their challenges and how do we provide sort of all of those opportunities to bring on innovation to address the modern challenges that the ciso.
Dave Buettner
Now, Matt, I'm curious. You know, in your day to day, I suppose you probably come across CISOs who, in talking to you about the products you offer, they, they say, well, our identity program is already complete. We're, we're good here. To what degree is that the actual case with the, the folks that you interact with?
I would say that, you know, it depends on the size of the company. But if I'm talking to you know, a Fortune 100 CISO that might be the case. And then I usually say ask that same question to your head of identity and access management. And then they will always come back and say, ah, yeah. And so it really depends on who you're speaking with. You know, did they come up, you know, with an identity background, did they come from an audit background? But I have not spoken to a single organization in the last four years that I've been at Surby that did not have this challenge of disconnected applications. And so I just tell CISOs to ask the question in their identity program. Just ask the question, does our existing identity investments extend to all of our applications? All of our applications. That's a great place to start.
Kevin, what's your take on that?
Kevin McGee
Well, I think the hardest place to really be successful in Identity project is Layer eight. It's really going around to each of the stakeholders and having that discussion of federated identity or cross functional discussions of how tools are working. I think the smart CISOs are starting to think in terms of ecosystem resilience, not just tool coverage. To address this challenge.
Dave Buettner
What do you hope that the takeaway for CISOs is here, Matt, as they're looking at their existing situation, what do you hope that when they're considering their identity technology, any words of wisdom or tips for them?
I would say that they need to again think in terms of how far can they extend their existing investments across their identity stack. Is it really all of their apps? That's where I would challenge them. So I would think about, talk about your identity coverage audit that what apps sit outside our identity framework and then think about it in terms of prioritizing coverage based upon risk, shared access and things like that. And then it's also thinking about a lot of times CISOs think, well, oh, does this mean I'm going to have to go out and replace my identity stack? That's not the case. That shouldn't be the case unless you're talking about a tool that's been sitting in your organization for 20 plus years. But think about tools and terms that can really help you extend your existing investments, not replace them. And certainly this is a place where we believe AI can play a big place, a big part of it as well.
We'll be right back. Next up, we're joined by a founder who's taking on one of the most complex challenges in enterprise security, governance, risk and compliance and making it actually usable. Say hello to Travis Howerton, co founder and CEO of regscale, another standout from the Microsoft for Startups Founders Hub Under Travis's leadership, regscale has built a powerful continuous controls monitoring platform that bridges the gap between security risk and compliance. Turning what used to be a static, slow moving GRC process into something real time, scalable and cloud native. Before launching Reg Scale, Travis had a remarkable run in public and private sectors alike. He served as Global Director for Strategic Programs at Bechtel, CTO of the National Nuclear Security Administration and held leadership roles at Oak Ridge National Lab and the Department of Energy. When it comes to high stakes, high security environments, Travis knows the terrain. One of the things that we want to key off of today is this report that you all recently put out. This is your inaugural state of continuous controls monitoring report. Can we start off with some high level stuff here? What prompted the creation of the report?
Travis Howerton
Yeah, so we kind of view ourself as a next generation GRC tool, what's called a continuous controls monitoring platform or ccm. We've been a leader in this space recognized by Gartner, but what we're really looking for is sort of the pulse of the community on what are their expectations around ccm, what's the state of the market? And we were blessed to have I think over 100 CISOs that were participants in this and gave us a lot of great feedback. But key things, you know, over 90%, I think it's 94% believe that CCM can improve both their compliance and their security program. Only 6% say they're secure from code to cloud, meaning their CICD pipeline takes compliance and risk into account as it builds and very few have that embedded. So it seems like we're very early days in the art of the possible for what the industry's looking for here, but that there is a lot of hope and need expressed in this market by the CISO community.
Dave Buettner
Well, let me ask you this. I mean, was it surprising how few organizations are actually embedding compliance, their CICD pipeline?
Travis Howerton
It wasn't surprising to me in that, you know, compliance has always been an after the fact, check the box sort of activity. You know, when I talk to CISOs, I always say there's no faster way to shut down a conversation in the bar than to bring up a compliance chat. Compliance doesn't equal security. It's sort of this checklist thing you've got to do. But it can be a roadmap to good security and sort of secure by design principles and embedding those and having sort of self updating paperwork is a win for everybody, not just the audit and compliance people. But also the risk folks, because my perspective on it is as people move more and more to the cloud, they take advantage of technologies Azure offers and Microsoft offers where things spin up, down dynamically. Risk can't be this after the fact manual checklist process. It's our view it's an operational imperative for CISOs to have real time visibility into risk and compliance posture as they accelerate adoption of cloud native technologies, AI technologies and other sort of forward leaning technologies in their organizations.
Dave Buettner
Well, Kevin McGee from Microsoft is with us. Kevin, I would love to get your take on this. I know you have read the report here. What are your thoughts?
Kevin McGee
It was a great connection to the early cloud journeys, I think where there's a cultural shift happening within organizations. We've always done it this way, so it's hard to change. And I get what you mean by compliance can sometimes shut down conversations. As a recovering cso, compliance wasn't always my favorite topic, I'll be completely honest with you at that point. But I started thinking when I saw some of the demos early on regscale about what we could look at compliance in a different way. How could we reframe it and how could it be a competitive advantage if we could continuously understand what our compliance posture was? What could that do to the business? What could that become as a competitive advantage overall? And this is where the space is really interesting for me from a startup perspective.
Dave Buettner
Well Travis, I mean what is the advantage of continuous controls monitoring here? What's the game changer?
Travis Howerton
Yeah, the way I've always viewed this is this is an industry that's run by consultants, advisory firm internal staff who manually do this stuff to make sure all the paperwork's in place for audits and governance processes and regulatory reporting. And it's both expensive, manual and after the fact. So what's in it for businesses is leveraging the telemetry you already have in cloud native systems in the modern API economy, then combining that with the things that AI does well, ingesting large amounts of data, summarizing it, synthesizing it for you to have a more real time view of what's happening. We think that's the art of the possible. And the cool part about it is I think it's one of the last great computer science problems to solve in highly regulated industry and that everything else is fast. DevOps is fast, CI CD is fast, AI is fast, Cloud is fast, risk and compliance moves at snail speed. And so it's. How do you get that to be at the same cadence? I think is the interesting Intellectual challenge and business challenge that we've been trying to wrap our arms around here at rightscale.
Dave Buettner
That's a really interesting perspective and insight. I mean, I think of when I talk to people about compliance. I think there's a lot of what I would label aspirational talk. People want to do more than comply, but then that aspiration kind of meets the real world. So I'm intrigued by this notion of it being the slow thing. I mean, is it an anchor that organizations are sometimes dragging behind them?
Travis Howerton
Oh, 100%. If you look at the organizations that lag behind sort of the cutting edge commercial industry best practice, for example, government will always be, it seems like years, if not a decade or more behind. Part of the reason is they have to go through these sort of complex risk and compliance, what they call authority to operate or ATO processes. Many cases banks and other large entities that are multinational have some of the same struggles. It's sort of a function of scale and size. You get so big and your operations are so dynamic that you've got to assure yourself you're not adding risk. And those risk processes take so long to execute that they just really hold back digital transformation goals for the company. So it's sort of an interesting problem that by avoiding risk in many ways in cyber, you're adding business risk of getting left behind and disrupted because of how far you end up behind others who are able to more rapidly adopt these technologies. And we think CCM is the best of both worlds where you don't have to reduce your posture. In fact, you're going to improve your posture, but you're going to move at the same speed as a commercial entity. And we think that's where the win is.
Dave Buettner
Well, help me understand what this looks like day to day for an organization that's decided they want to jump in and do this, what does that shift look like for them?
Travis Howerton
Yeah, so it doesn't really matter which framework you're in. NIST puts out a lot of different ones that are popular. ISO 27000, there's CMMC, now there's PCI, there's the Cyber Risk Institute, CRI and Financial Services, NERC, SIP and Critical Infrastructure, HIPAA, Hitrust, all these different frameworks that evolve by industry. You need certain reps and certs to do business in markets and whether it's helping you attest to controls, using our AI to author things in minutes that would have taken months to do by hand. Automatic evidence collection representing everything. Compliance is code. So you can do machine level Assessments as well as AI based assessments. Do smart, intelligent routing of things for your issues, management workflows, and then monitoring and accepting risk all throughout the process. That whole life cycle is managed by the CCM platform. And so what it looks like for a customer is sort of onboarding into the platform, getting their attestations done, connecting their tooling, wiring up the AI and then moving to a real time posture versus a reactive after the fact posture.
Dave Buettner
Kevin, what are your insights here? I mean, what are the advantages that you see when a company adopts real time compliance?
Kevin McGee
Yeah, again, I switched to my sort of board of directors hat and I've sat on a number of audit committees over my tenure as a board member. And I think there's real strategic value in knowing what your control posture is today. Not last quarter, not last year, but what it is today. And it's also going to allow CISOs to have a different conversation with boards. Fewer surprises, more clarity, more understanding, understanding of what the role of the board is in mitigating risk, accepting risk and whatnot. Again, to be able to come to the board and say, you know, here's where we are today and here are some of the challenges we're seeing and take action in real time as markets change or as a geopolitical aspects change. This is a real competitive advantage. I think this is what compliance was always supposed to be, but never has really gotten to. And we're finally reaching into the technology to solve for that and make it, make it that strategic enabler that it was always meant to be.
Dave Buettner
Travis, is there a place for generative AI in all of this? I mean, it's certainly the topic we're all obligated to discuss these days.
Travis Howerton
Yeah, 100%. And so if you look at this market I mentioned, it's historically dominated by consultants. So if you look at, I think Gartner says GRC is a $50 billion a year market. But if you add up all the major GRC vendors, you're probably lucky to get to 55 billion, much less 50, which tells you 90% of this market is really driven by services, which makes sense to me in my past lives. Running large cyber teams is a very heavy manual labor. And there was only so much you could automate. You could automate technical controls, but there's a whole bunch of controls that were very difficult historically to automate. And so because of that, because there were huge unstructured data problems, there was just no other way other than sampling and throwing humans at it, issuing periodic audit reports. But today's Nature of cloud. It's not acceptable to have some sort of object store with all your company's PII and this public. And maybe I'll find it if it's in the sample. Once a year, once every three years. When you look at it, this stuff has to be more real time. It's an operational risk imperative to make it real time. The cool parts is that all those services things, our thesis is AI is largely going to eat it over the next three to five years. And so if you look at what AI does well, synthesizing large amounts of data, writing about it, I think many of these things we're doing by humans on a sampling basis can be done by AI on a real time basis at higher quality, lower cost, and it should lower risk in the environments that adopt CCM platforms.
Dave Buettner
Can we talk about roi? I mean, what are organizations experiencing from that direction?
Travis Howerton
So if you look at jobs that you can do with generative AI using, let's say Microsoft OpenAI, behind regscale, we have things that would literally take teams of people three to six months in a conference room to build out all the attestations we can do in under an hour in AI. And so you're talking about hundreds of thousands of dollars potentially saved on these. And for companies that have many, many of them to do and maintain, you can be talking significant roi. And a core part of our CCM platform is that average you're leveraging AI in the background or automation to do tasks. You get a running ROI calculator on the back end that tells you all the manual savings avoidance that you have. And so now CISOs can take those dollars and put them towards operational excellence and hardening their environment and less towards the paperwork, check the box stuff which largely can become set and forget.
Dave Buettner
You know, Kevin, one of your responsibilities there, Microsoft, is looking for these innovative cybersecurity startups. I'm curious, what about regscale really caught your eye?
Kevin McGee
Well, I always kind of thought the GRC space was one of those kind of parts of the industry that really wouldn't benefit from innovation. And I've completely flipped my thinking on this. It is probably one of the areas that are most ripe for innovation and where I'm sort of looking for investment strategies as well too because we can sort of approach it from exactly the perspective that Travis was talking about. It's very manual. It's not only very manual, it's very inefficient and it's also just so cumbersome and so difficult for the employees. I can't imagine what it's like to get another spreadsheet to fill out or another form to fill it or whatnot constantly. So maintaining staff morale, making sure that we're using resources wisely or whatnot. This is one of those areas that it's really, I think, ripe for innovation and has been largely ignored because it's sort of the boring end of the business. In fact, I would say the GRC space is probably where most of the innovation, some of the coolest stuff is happening right now. And it's not an exact analogy, but I remember looking at the regscale demo for the first time thinking wow, this is soar but for compliance, this is something that you don't see very often. Sort of a real innovation that has a true ROI story and I think it's going to be, you know, coming full circle. That CISO telling that ROI story to the board, to executive management, to the users, that's going to change the culture. But once they really start to see the tools in action, the automation and the benefits from that automation, I think that will shift the cultural quickly and they'll see the more they'll see the benefits and just immediate results which will change the market and change the advantage for the company.
Dave Buettner
Well, Travis, wrapping up by getting back to the report here. What are the take homes for you? What do you hope folks come away from having read the report?
Travis Howerton
Well, I always say I had a boss who was my mentor, always told me the best plans start with the truth. The truth is that this area in the cyber domain is going to be eaten by automation and AI over the next five years. Like we have really strong conviction around that we all stand on the shoulders of giants. You know, we're innovating on top of some world class tooling provided by Microsoft and Azure and OpenAI that allows us for the first time to have hope. Because the first couple of decades of my career there was no hope. Like this was boring, it was painful, it was terrible, everyone hated doing it. But it was the price of admission to certain markets that were very lucrative. So you had to do it. Today I think that's changed. Now this is stuff that should become commoditized over the next five years as AI sort of gives set and forget options of how you do these things. And now it's less about manually doing all this work and spending all this money on expensive consultants. It's how do I buy down risk in my organization and repurpose all those savings I generated. The things that help protect my organization, that I can talk to our board about risk reduction and how we can get them into more markets. So we think it's a really exciting time to be in the most boring field on earth.
Dave Buettner
It strikes me too that there must be a satisfaction component to this for the employees where you're helping to remove some of these tasks that, as you say, are the boring ones, the drudgery ones. These are through automation they're able to spend their time on the things that are a lot more gratifying and fulfilling.
Travis Howerton
100% and the things that add more value to the business. You hire some of the smartest people in the world to make risk based cyber decisions for your organization and then you waste 80% of their time chasing down evidence, doing data calls, waiting outside people's office to get something who's been ignoring them for two weeks. Like it's just an insanity problem that we've had as an industry. Now instead you've got a heads up display, you know where things are at and now it's sort of where can we buy down the next level of risk? What decisions do we need to make? So you're getting more ROI out of those people. So we don't talk about it as replacing people so much as it is how do we supercharge human beings to get more out of your risk professionals? Because as much as I love AI, I don't know anyone who wants AI making risk based decisions for the strategy of their organization. Almost everybody I've talked to is willing to make the drudgery and the sort of mind numbing paperwork go away.
Dave Buettner
So Travis, when we're talking about things like Fedramp and OSCAL and these programs evolving, what are your insights there?
Travis Howerton
I think compliance as code, as the foundation for this work is the future because at some level of scale you can't handle these processes manually. And at the same time what you need is a high amount of precision in what you're trying to execute. And so the best way to do that that I know of is to structure these things. And we've been building our platform on top of something called NIST OSCAL, the Open Security Controls Assessment Language run by Dr. A ORGAS team. David Waltermeyer is now at FedRAMP have been major innovators there. But they take all these huge thousand page document spreadsheets we used to generate by hand and now there are tightly formatted xml, JSON, YAML representations of it that are machine readable. What that allows you to do is do automated assessments of these artifacts used to have to do by hand. I think of it like a compiler. And so since we're with some Microsoft folks, they're one of the biggest software enablers in the ecosystem. When I write code, I'm in a development environment and I compile it at the end, and at the end it may tell me an error, I screwed something up, I can't proceed. Right. That's kind of what OSCAL does. You can set your risk thresholds. What I'm expecting, am I inside or outside of that? Maybe it's not an error, it's a warning. I'll let you proceed, but you're still sort of out of the norm of what I expected. And so now you can dial in your risk tolerance as code, apply it to the things you're building, and have sort of a risk and compliance compiler that tells you, am I still in the safety zone of where I expected to be? Because the hard part of this industry for me for decades is getting invited to those meetings where you're asked to explain to them why you're not stupid. Because something stupid happened and at one point it was in a good state, it changed and went to a bad state and I didn't know it. Right. And so this allows you to sort of compile that as often as you want based off real time speeds and feeds and make sure you're always inside this boundary that you want. So we see it as this basis for dynamic operational control assurance. Being able to know that the controls I have are in place, they're effective, they're operating the way I thought they were. Were. And no more surprises for CISOs and audits.
Dave Buettner
Our next guest is a name that resonates across the cybersecurity world. With more than 25 years of frontline experience, Carl Mattson has helped shape security strategy for some of the most complex sectors out there. Finance, retail, and tech. Today, he's the CISO at Endor Labs, a startup laser focused on securing the software supply chain and a rising star in the Microsoft for Startups ecosystem. Before joining Endor Labs, Carl was CISO at no Name Security, where he tackled API and application security head on. His resume reads like a roadmap through high stakes cybersecurity leadership. He's held CISO roles at Citi National bank and PennyMac Financial, served on the FS ISAC Mortgage Risk Council, led the LA Cyber Lab, and even graduated from the FBI CISO Academy. When he's not leading security teams, he's been shaping minds as an adjunct faculty at the University of Minnesota for over A decade. Well, let's start out with a little bit of the origin story here. I mean, I have to say I'm enamored with the company name, but tell us about how the company started and what your mission is.
Sure.
Matt Chiode
The company started just over three years ago. Varun Bedouar at the time was leading the Palo Alto Prisma business unit. He had previously founded the company Redlock that was acquired by Palo Alto. And while he was there at Palo Alto, there was a major open source vulnerability event. And it was at the scanning of that environment where Varun sort of had the seed of an idea that scanning software is extremely noisy and error prone. And so he started Endor Labs with Dimitri Styliades, who was a counterpart at Palo Alto. So Dimitri and Varun about three years ago started the company with the mission essentially of reinventing software vulnerability analysis. We commonly have in the software industry noisy, antiquated open source scanners. And so we've eventually reinvented the scanner and reinvented the way that we look at software vulnerabilities, starting with sca, starting with open source, and now a much broader set of capabilities.
Dave Buettner
Well, I think we have to talk about AI, which I know is a big part of your technology and your product here. How do you apply AI to this task?
Yeah, great question.
Matt Chiode
So there's really a couple of ways to look at it. The first is as a company, we have a whole range of proprietary open source research that we've performed that I would call it an enrichment layer on top of the national Vulnerability Database and other vulnerability databases. That enrichment layer is really our data moat. And so when we roll out capability that sort of, if you're familiar with the concept of a rag, a retrieval augmented generation that is essentially a local data set that can be utilized by our customers in an agentic AI sort of efficient operating model that really accelerates an AppSec team's, you know, capabilities, but kind of leverages that, that data set in, in our, our new agentic AI offering. And then the second area of that is then mcp, which an anthropic protocol model context protocol that came out about six, six weeks or six months ago. That protocol really is for LLMs to talk with each other. And so we have also released an MCP server that allows organizations that use Cursor or Copilot this, this sort of code generation revolution. It's an integration pathway for those platforms that's really remarkably fast and efficient.
Dave Buettner
When we're talking about boards of directors at organizations, some of the places that you serve. Are their expectations realistic when it comes to AI? Are they prepared for the types of things that are the reality of this technology?
Matt Chiode
Oh, of course not. I think we learned that in each technology revolution is that there is a trough of disillusionment. So if you think back to the mid-1990s and the dot com sort of explosion, it was many years later before turning that into revenue became a realistic possibility. E commerce didn't blow up the moment the Internet occurred. It took a decade. So I think that what we're going to certainly see is board level expectations to push the needle and capitalize on AI. However, there are not yet a lot of examples of business models that have thrived with that kind of direction. I think it's a matter of time, but right now I think we're still in the very earliest stages of sort of value capture in AI.
Dave Buettner
Kevin G. Does that align with what you're seeing?
Kevin McGee
I spent a lot of times speaking to boards of directors, senior execs and it is exactly aligned. I mean we've really shifted from this we secure discussion, this sort of negative security discussion to hey, let's do everything with AI. Just the optimism is really refreshing, but it's challenging because how do we safely do things with AI really needs to be the conversation. So I think startups like indoor labs that are empowering this vision of AI and building in safety and security as part of the workflow are really something I'm interested in from an investment perspective, but also just a capabilities perspective. How do we make these innovative leaps but do it safely and not go back to repeat history where we've launched new technologies, run out with them to improve efficiencies, to build value, to create opportunities which organizations should be doing and then figure out how to bolt on security afterwards. So I think there's a unique opportunity right now.
Dave Buettner
Well Carl, let's talk about the security workforce themselves. When it comes to hiring and training and even retaining these people with AI, is this requiring a new skill set? Are folks having to come into the job with new skills or are organizations finding themselves having to train people up?
Matt Chiode
Both are true. I think that anybody who's a job seeker right now would best be served focusing on upskilling themselves in terms of basic generative AI agentic AI technologies, but also internally for teams, for organizations to look at at AI as a. And not just a short term fad but, but a long term capability that, that employees in the organization need to have really across the board and supporting those trainees with or those Those employees with, with the training required to sort of upskill them to a baseline level of knowledge. I think we all need to look at this as a, as an opportunity to upskill ourselves. And that's, and that, that is a actually very, very good news in terms of like the equalizing the, the cybersecurity workforce. Individual who really wrap their arms around AI capabilities and begin to master them soon will become very, very valuable to their organizations quickly.
Dave Buettner
Well, let's flip the question around. I mean in terms of the people who are looking to take these jobs, what are they looking for? In terms of security culture within an organization, what are the things that they value?
Matt Chiode
One of the interesting things that, that we see continuing to happen. Finally, let's go back to a couple years to the origin of the concept of shift left. And there was a moment in time where shift left looked kind of like tossing things over the fence back to the developers or back to the DevOps teams. And that was oftentimes a recipe for failure. And so there are certain successes, but for the most part it was not a wild success. But here we are today in a really interesting place because now we can actually with for example MCP integrations, we can put our security capabilities inside the developer's context or inside the DevOps team's context window. So really quickly we now have security technologies that I would, let's call them headless. The UX isn't all that important because the technology is running under the hood of the developer's tools or under the hood of a DevOps team's tools and pipelines. That's a great move. That is an incredible upward trajectory of possibility for remediating vulnerabilities or getting attention on security is to have those security technologies inside of the developers tools. So I think culturally what that gives the security team the opportunity to be a welcome asset at the table, not just the team that tosses vulnerabilities over the fence to you.
Dave Buettner
Kevin, I'm curious. The startups that you work with, the ones who are having success, both attracting talent and retaining them, what sort of commonalities are you seeing there?
Kevin McGee
I think startups are really becoming talent incubators. You know, what they really can offer are hands on AI security experience and capabilities development to employees. That's the real value. It comes from working from a startup. Not only is it fun, it's really a chance to explore and learn very quickly how to implement some of these, these workflows or whatnot as well. But then startups also create value at scale for customers. And I think that's the key. So it's not just learning those skills or whatnot. It's really often encapsulating some of this innovation into a product that customers can purchase to benefit from that, rather than having to source and find all those employees and develop them on their own. I think it's a much more efficient way of using talent more effectively. So that's one of the things that has me most optimistic about startups and their role in moving just workflows and cultures to this AI experience.
Dave Buettner
So Carl, you know, digging into open source software itself and how organizations calibrate their risk when it comes to oss, in your estimation, are organizations properly calibrated or are they overconfident or are they underconfident? You know, where do most organizations stand?
Matt Chiode
That's a great question. I think that organizations are almost exhausted perhaps is the word I would use for, you know, say, open source scanning that's historically produced a lot of false positives or poor quality results and incidents still occurring. And so that endless cycle of chasing this enormous quantity of vulnerabilities and particularly finding out that they're not, they're not true positives, that's an exercise in frustration and it's exhausting. And that's really where, like where we, and where we come in and clean that noise up so that it does not become exhaustive. And so I think that what that does is it frees up an enormous amount of capacity and there's a sense of relief when we can get the noise out of the open source scanner world.
Dave Buettner
You know, not all risks are created equal and you know, they have different degrees of seriousness relative to any organization's risk posture. I mean, is that a big part of what you're helping folks with here as well, of prioritizing the things that are actually dangerous to the company itself?
Matt Chiode
Yeah, absolutely. Because think of the OWASP top 10. There's a lot of risks that are not software vulnerabilities. So in our sort of open source model, there's eight risk areas. Legal risk, intellectual property risk, operational risk. So for example would be there are certain organizations whose, whose ability to be precise in their use of open source or third party licensing makes a dramatic difference in the value of the company. That's a very important feature of what we do, is to focus on all of these different aspects of risk because it isn't just the software vulnerabilities, it's all these other operational viability issues to solve for. And that's really important. For us to look at the whole context of risk of software and be able to provide different organizations of different, different shapes and sizes the insight that they need for their risk profile.
Dave Buettner
Kevin, I'm curious for your insights here.
Kevin McGee
One of the CSOs really described the problem articulately. I think that makes most sense to me. Wouldn't it be great if we made sure there are no sharp edges on our products before we shipped it kind of thing? And they were in the manufacturing industry. And this makes sense to us in IT because we want to make sure that we're pushing production code that has no errors, that is error free, but it's not really embedded in a lot of organizational, cultural approach to innovation. You know, build the application and they don't really know what's involved in it. It makes sense to leverage open source. It makes sense to leverage what's already been created and build on what others have already built to empower and move faster. But in moving fast, you know, we have to make sure we look at all the associated risks. And I think some of the ones we've, you know, discussed now are good to articulate. It's not just a matter of is a code going to break or is it insecure? You know, what are the copyrights, what are some of the other challenges, what are the dependencies? And thinking through those challenges allows us to make better decisions. The farther left we can shift that, the more secure we're going to be and the less challenges we're going to have in responding to some of these either complaints legally or actual software failures when code reaches production. This is an area that's really interesting to us, especially with our investment in GitHub and our capabilities in GitHub. How do we extend those capabilities? How do we provide more value to our customers in this space? And those are a lot of the conversations we have with Endor jointly with our customers.
Dave Buettner
Well, Carl, how do you support that desire for Velocity to make sure that security isn't the thing that's throwing sand in the gears? Or the famous saying about being the department of no, I think it comes.
Matt Chiode
Down to two touch points that we focus on that when you get them right, they become accelerators. The first is the quality of the information about vulnerabilities. Reducing false positives may sound like a punchline, but it really is a very specific thing for us, which is to understand application context and its nuance. Because when we call it program analysis, but performing that analysis gives exceptionally detailed insight into vulnerabilities. Less noise, more actionable specific information. And then the second thing is giving the opportunity to embed that scanning activity, that program analysis inside developer workflows so that developers don't have to context switch whether that's in their git repo, whether that's in their CI CD pipeline. We need to give that high quality information now, put it in the place and time where it can be actionable and with the sort of amplifying supporting information that allows the developer, the DevOps engineer, to make a great choice in terms of how to remediate quickly. And so both of those touch points give us opportunity, opportunities to really move the needle and allow those teams to move forward, move faster, just ship better software faster.
Dave Buettner
Kevin, when you look at a startup like Endor Labs, what stands out to you? Why is a company like this of interest to Microsoft?
Kevin McGee
It's velocity with visibility. I really think that's sort of the sweet spot. How do we make security a multiplier, a value creator rather than a bottleneck? And how do we remove the challenges to a great ext experience for the developers or whatnot? So they'll choose the right tools, they'll make security the easy thing to do. Because we know when security is the easy thing to do, people will do the right thing. The more difficult we make it security, the harder it is to get them to comply. So how do we really build it into the workflows right from the beginning of software creation? I think that's what really interested me when I saw the first demos of Ender Labs is that again, the, the philosophy with, but with visibility was the key thing that stood out to me.
Dave Buettner
Carl, what's your message to the CISOs in our audience here, words of wisdom based on your own experience?
Matt Chiode
Well, I think that we have to prepare everything in our organizations for the long haul right now. And I know that the world changes very quickly with AI, but, but by the long haul I mean upskilling teams, rethinking our telemetry, rethinking that visibility, rethinking that, that, that technology touch point. Because what's going to continue to happen is that there's this logarithmic increase in expectations and quantity of software and noise in the, in the environment. And if we don't start preparing for that long haul right now with a sense of urgency, we're going to get behind very quickly. If we're not already behind, we're about to fall behind. And I think that's where we need to, to be looking at that future state right now and be implementing that action plan without meeting the expectation of the board. To be clear, we need to internalize that and know that it's coming sooner, sooner or later.
Dave Buettner
And that's a wrap on this special edition edition the Microsoft Startup Spotlight A huge thanks to all of our guests Kevin McGee FC, Matt Chiode, Travis Howerton and Carl Mattson for sharing their insights, experiences and the incredible work they're doing to shape the future of cybersecurity. From tackling software supply chain risks and redefining GRC to hacking for good and building global startup ecosystems, these founders and leaders are proof that innovation thrives when community trust and cutting edge tech come together. We'd also like to thank Microsoft for Startups Founders Hub for making this episode possible. If you're a startup founder looking to level up your business with access to AI tools, Azure credits and expert guidance, this is your moment. And of course, thank you for tuning in. We'll be back with more stories, more innovators, and more reasons to believe in the power of the song Cyber Startup Community. Until next time, stay safe, stay curious and keep building. I'm Dave Buettner. We'll see you next time.
Host: Dave Buettner
Guests: Kevin McGee (Microsoft), FC (Entrepreneur), Matt Chiode (Serbi), Travis Howerton (RegScale), Carl Mattson (Endor Labs)
Release Date: April 27, 2025
In this special edition of CyberWire Daily, host Dave Buettner shines a spotlight on the Microsoft for Startups Founders Hub, a platform designed to empower cybersecurity startups with essential resources. Kevin McGee from Microsoft and FC, a renowned hacker-turned-entrepreneur, kick off the discussion by highlighting the program's offerings, which include:
Dave emphasizes that the episode will feature founders from three standout startups—Serbi, RegScale, and Endor Labs—each addressing significant challenges with groundbreaking ideas.
Kevin McGee (Microsoft) elaborates on Microsoft's commitment to fostering innovation within the startup ecosystem:
"We're not just providing technology; we're offering access to enterprise customers, leveraging the trust built over years, and utilizing our extensive marketing reach to give founders the attention they deserve."
[02:34]
Kevin reflects on his personal journey, noting how his early experiences with Microsoft’s ecosystem accelerated his ventures, a benefit he now aims to extend to new startups.
FC shares his transition from a defense contractor and head of offensive cybersecurity at Raytheon to founding his own company, Sygenta. His narrative underscores the challenges of self-funding and the steep learning curve of running a business:
"People just think, oh, I can just be an entrepreneur. I'll start a company, make money, and get clients. There's lots of administrative stuff that you have to learn that you didn't realize when you were just an employee."
[05:30]
FC emphasizes the importance of adaptability and a hacker mindset in overcoming these obstacles, a perspective echoed by Kevin:
"The hacker mindset is very much in tune with the entrepreneur mindset. It's experimental, it's adaptable, but it's also mission-focused."
[07:04]
Matt Chiode, Chief Trust Officer at Serbi, delves into the company's mission to secure disconnected applications within enterprise identity ecosystems. Serbi addresses the widespread issue of applications lacking essential security standards, such as SAML and SCIM:
"Our platform allows us to combine Microsoft's capabilities with Serbi's precision to enforce zero trust principles across all applications, not just the integrated ones."
[25:29]
Key Highlights:
Matt discusses the integration with Microsoft Entra, enhancing Serbi's ability to extend governance policies to all enterprise applications:
"Serbi integrates with Entra to apply governance policies to disconnected apps, ensuring comprehensive security coverage."
[24:21]
Kevin remarks on the strategic value of such integrations:
"Building an open identity ecosystem strengthens our approach, allowing customers to protect the secure edge of their identity attack surface."
[25:36]
Travis Howerton, Co-Founder and CEO of RegScale, introduces Continuous Controls Monitoring (CCM), a platform aimed at making Governance, Risk, and Compliance (GRC) processes real-time and scalable:
"We're turning what used to be a static, slow-moving GRC process into something real-time, scalable, and cloud-native."
[30:45]
Key Insights:
Travis emphasizes the impending transformation driven by AI:
"Compliance is going to be eaten by automation and AI over the next five years. This is the most exciting time to be in the field."
[44:26]
Kevin underscores the strategic advantage of real-time compliance:
"Knowing your control posture today, not just in the past, provides clarity and allows CISOs to act proactively as markets and geopolitical landscapes evolve."
[38:37]
Carl Mattson, CISO at Endor Labs, discusses the startup's focus on securing the software supply chain through innovative AI-driven solutions:
"We've reinvented the scanner and the way we analyze software vulnerabilities, focusing on reducing noise and providing actionable insights."
[52:06]
Key Features:
Carl highlights the importance of integrating security seamlessly into development processes:
"By embedding our scanning activities into developer workflows, we ensure that security becomes an accelerator rather than a bottleneck."
[63:56]
Kevin praises Endor Labs for their approach:
"Making security a multiplier and embedding it into workflows ensures that security becomes the easy choice for developers, fostering better compliance and safer products."
[65:26]
Across discussions with Serbi, RegScale, and Endor Labs, AI emerges as a transformative force in cybersecurity:
Travis notes the imminent shift towards AI-driven GRC processes:
"AI will commoditize risk and compliance, allowing organizations to focus on strategic risk reduction rather than manual paperwork."
[54:39]
Matt adds that AI not only automates tedious tasks but also enriches data analysis, providing clearer insights:
"Reducing false positives and providing detailed contextual analysis frees up valuable resources and enhances decision-making."
[60:07]
The integration of AI into cybersecurity also reshapes workforce dynamics:
Kevin emphasizes the role of startups in talent development:
"Startups are becoming talent incubators, offering hands-on AI security experience and enabling employees to contribute to scalable, innovative solutions."
[58:46]
The episode culminates with reflections on the synergy between Microsoft’s support and the innovative spirit of startups:
Dave Buettner wraps up by thanking the guests and highlighting the transformative work of the featured startups:
"From tackling software supply chain risks and redefining GRC to hacking for good and building global startup ecosystems, these founders are proof that innovation thrives when community trust and cutting-edge technology come together."
[67:24]
He encourages startup founders to leverage the Microsoft for Startups Founders Hub to access essential resources and support, reinforcing the message that the future starts here.
Key Takeaways:
This episode underscores the pivotal role of innovation, supported by robust ecosystems like Microsoft’s, in shaping the future of cybersecurity. Whether you’re a startup founder or a cybersecurity enthusiast, the insights shared provide a roadmap for leveraging technology and collaboration to build smarter, more secure solutions.