Episode 420 ·
Ransomware, Cyber Insurance, & Cybersecurity Strategy Today with Dale Gonzalez, CPO at Axio
Today we’re talking to Dale Gonzalez, the Chief Product Officer at Axio. And we discuss how ransomware completely disrupted the cyber insurance industry. How Axio allows you to assign solid dollar amounts to cyber risk at your organization, and why having empathy on your career journey will help you get back up after failures.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Axio, check them out at https://axio.com
In case you missed it: check out the other episodes we've released with executives from Axio:
- Interview with David White, Axio's Founder and President
- Interview with Rich Caralli, Cybersecurity Advisor at Axio

About Dale Gonzalez:
The short version:
Technology enthusiast, evangelist and serial entrepreneur. Excited by the creative process, building products, building teams and building companies. I am happy with the success I've achieved so far but eager to do more.
The long version - ask me over beers.
Specialties: Product design and development, needs analysis and requirements, team construction and process design
About Axio:
Axio is the leader in SaaS-based cyber management software, which empowers security leaders to build and optimize security programs and quantify risk in financial terms. Axio360 is the only cyber risk management platform to align security leaders, business leaders, and Boards of Directors around a single source of truth about their most critical corporate risks. Since 2013, Axio has been a trusted partner to many of the world’s leading critical infrastructure, energy, manufacturing, and financial services companies, helping drive better visibility and decision-making about cybersecurity priorities and investments.
Transcript
(Intro Narrator at 00:00:03) Hello, my friends. Today, Joel is talking to Dale, the Chief Product Officer at Axio, and they discuss how ransomware completely disrupted the cyber insurance industry, how Axio allows you to assign solid dollar amounts to cyber risk at your organization, and why having empathy in your career will help you get back up after failures. All of this right here, right now on the Modern CTO Podcast.
(Joel Beasley at 00:00:35) Here we go. This is the Modern CTO Podcast.
(Dale at 00:00:47) I started because my dad brought home an Apple II. So I had no interest in—well, no interest. I didn't know that you could be a computer programmer. You might as well be an astronaut. Yes, there are astronauts. Yes, there were computer programmers. They all wore short sleeves, worked for NASA or IBM. When I'm a kid, my dad brings home this thing because he's a college professor, and I just loved it. Wanted to play with it immediately, wouldn't put it down, thought it was the greatest thing ever, wouldn't let him have it back.
(Dale at 00:01:19) I go to college, Emory University, degrees in psychology because I'm going to be a lawyer and then ultimately a politician. While I was there, I was like, oh, there's this Carter Center of Emory University. I'm going to go try to work for the Carter Center. They said, "Well, the opportunity that we have is for someone to be our technology department, to be our programmer." It's like, "Okay, that's me." They said, "Well, we use IBM equipment. You know IBM equipment?" I'm like, "No." They said, "Well, our primary development environment is dBase. You know dBase?" I'm like, "No." I said, "But I don't care because I know I'll pick it up." They said, "Okay." Which, in retrospect, was probably not a great decision that they made, but thank goodness that they didn't have programmer tests then. I did that all through college and was still going to go to law school, was still going to be a lawyer, took the LSAT. I was like, "Well, let me work for a law firm for a year before I go to school because I've got massive debt." I worked for the law firm, again, dominantly doing programming, computer searches on their systems to unearth evidence that we were going to use in support of litigation. And everything else about the law firm, I hated.
(Dale at 00:02:28) So I said, "All right, can't be a lawyer. I'll do the next most obvious thing, which is to be a musician." And I tried to play guitar and sing, had a band. We managed to play clubs and bars and never got further. And then finally it was like, "I wonder, can I be a software developer?" So applied for a job, got a job. Again, this particular company was like, "We don't want you to have had experience because we want to teach you the way we do things here. We're concerned that if you have experience, you will come with a bunch of preconceptions and you will want to impose your views on this process, and we want our process." I go in, I take their training, which was two weeks. Then I'm a member of the team, then they want me to lead the training, then they want me to lead the dev team, then they want me to lead two dev teams.
(Dale at 00:03:24) I was like, "This is really great, but I want to be a developer. I'm not a manager, I'm a developer," so I actually left that company. Started as a code librarian because I had been partway through a Novell CNE course, and through a series of strange staff turnovers, after they'd gone to their third VP of development, somebody asked, "What does that guy do?" He pointed at me, and they said, "We think he's the Windows developer." I was like, "Yes, of course I'm the Windows developer." Then I ended up leading that team, and then I did a series of startups after that, which caused the whole, "Oh, now I'm the head of 100 people." It was not terribly different than the way that you got to where you are, in a sort of charismatic set of just passion, opportunity, and taking that step and it being a wonderful outcome.
(Joel Beasley at 00:04:14) Were you working at the startups, or were you founding the startups?
(Dale at 00:04:18) I was a founder at four of them. At this company where I eventually was running development, I got into a discussion with the CTO then. He believed very strongly that the next evolution for the product should be something else. The head of marketing liked my idea better than he liked the CTO's idea and said, "Why don't we just leave and start a company?" Fortunately for both of us, neither of us knew what the heck we were doing, because had we known, it's a little bit like having a kid. If you truly knew exactly what you were signing up for, you would never do it. So that ignorance was—we were like, "Yeah, how hard can it be?" So we left and started a company that was a Salesforce automation product that was web hosted, the very first of its kind. And we were having to deal with, like, how are we going to deal with hotel modems and dial up? And do we have to provide modem cards to the people that are using it? Built that company and ended up selling it back to the company that we had left. At the time, I started another company. The guy that I had met over the course of that startup experience said, "Hey, listen, I want you to come and start a company with me."
(Dale at 00:05:33) I was like, "Oh yeah, okay, I'll start that company." We grew that company and ended up selling it. It was in the mobile internet space, so AT&T was our customer. I supported the Capitol Police in the U.S. Senate with a messaging app that ran on our impager. And then after that, I had a brief startup that fizzled immediately, which is probably fine. And then it's 2008, and I was going to start another company. I was like, "Yeah, this is easy. You just step outside your front door and you say, 'I'm a founder.' Money pours from the sky immediately, and you get to start another company." It was 2008, and so the money spigot had been turned off, unbeknownst to me. And luckily I had a friend, a relationship who said, "Hey, Dale, I know that you probably don't want to do this for long term, but why don't you come and run engineering for me?"
(Dale at 00:06:24) And this was at SecureWorks. It was my first experience running a dev team that was security focused, and I started with eight people. I ultimately had 100 some people. Dell bought the company. After Dell bought the company, I transitioned from being head of engineering there to being head of product strategy there. So got to design sort of what the next gen products that the company's going to have are going to be and how are we going to approach the market. And got that to a fun spot and then was like, "Man, I work for Dell now. I need to be back to something that's different." I had a brief stint as a CTO for a publicly traded company, Concurrent, which, interestingly enough, provided the operating system for the Aegis missile defense system. That's my brush with military background. That company decided to divest itself and to go in different directions. Then I did another startup where I was—now I'm coming into a startup where my responsibility was to try to recast their product strategy in an attempt to get the company sold. That was Damballa, which was an Internet security product that used AI to detect infected endpoints without requiring agents on them.
(Dale at 00:07:43) It would look at their pattern of DNS traffic and go, "That's a weird pattern of DNS traffic. It doesn't match human DNS activity. I bet that endpoint's infected," so be able to target those endpoints. We got that company successfully sold, had to do something else, and along came Axio, which, the company was a services business interested in starting up a software product, a SaaS solution. And that's what I do now.
(Joel Beasley at 00:08:06) How did you meet the team at Axio?
(Dale at 00:08:09) When I was head of product at Dell, I had this idea that Dell should offer all-you-can-eat incident response. So one of the challenges that CSOs face is budgeting for things. It's really sort of interesting, right? You would expect that their biggest challenge is preventing, but to some degree, their biggest challenge is budgeting. And if they had a price certain—I know it will never be more than X—that's almost more important than having X be small, at least for certain large companies, because if you can budget for it, you can address it. You can cope with it.
(Dale at 00:08:44) So I was like, "All right, SecureWorks, we should have an all-you-can-eat incident response program, so then the CSOs will all know how to budget." I was having these conversations with folks, and they were saying, "You know, we're not comfortable that, even though you've done the modeling, we're not comfortable that this won't result in us being out a tremendous amount of money if something really horrible happens. Can we backstop it with insurance?" As it happened, I was sitting on this advisory council, Business Executives for National Security, and we were working with the Department of Energy on this rewriting of one of the maturity models. It was the C2M2. And Dave White was sitting right next to me, and I was like, "Yeah, I have this idea, but I need to know an insurance guy because I don't know anything about insurance or how you construct policies." And he's like, "I know a guy."
(Dale at 00:09:33) And so that's how I met Dave, and then that's how I met Scott. And Scott was incredibly generous. You talk about relationships and just sort of trying to provide value and letting things happen from there. This guy—I'm just some schmo, I was sitting next to Dave on a panel—and he's like, "Sure, I'll take you around and introduce you to all the key insurance people in New York." And so I met the heads of almost everything, trying to build this bespoke, weird thing that ultimately never happened. But it did result in me meeting Dave and Scott. So there you go.
(Joel Beasley at 00:10:09) That's awesome. Yeah. That's typically how some of the best things happen in life. You're going for something really focused on it, really believing in it, and then you get something great, but it's not exactly what you were after to begin with.
(Dale at 00:10:21) That's almost—that has happened every single time, right? Have a dream, be passionate about that dream, but don't fall so in love with it that you don't see what's on the edges of it, or else you're going to end up disappointed. Right?
(Joel Beasley at 00:10:36) Yeah, for sure. So Axio, when did you join? How much has it grown since you've been there? Tell me a little bit about your experience there.
(Dale at 00:10:44) So I've been there for five years, and when I was there—gosh, man, what were we? Maybe 10 people? We're probably 40-some now. The company was just services folks. It was Dave and Scott and a handful of people that Dave and Scott knew, and it had no offices. It's funny because it had no offices then. I was brought on to construct an office to hire a dev team, so no developers, no product people. "Come onboard, Dale, find a place for our offices, hire people to populate and staff those offices, and build us some product, and let's go."
(Dale at 00:11:24) I did that. We had a dev team. We grew the dev team. We have offices in Decatur. Now, of course, COVID happens. We've got an empty office in Decatur. We're back to being distributed. I have developers all over the U.S. The idea that I would build an office and worry about what do the desks look like, where is the coffee maker going to go, and how am I going to hardwire water into it, which are all decisions I made and had to—like, I plumbed the coffee maker into the wall and hung the TVs and all the rest of it. Now all of that's like, "Maybe we should just sublet that thing, turn it into an apartment." So yeah, it's been a ride.
(Joel Beasley at 00:11:59) Yeah, I was having a conversation—I can't remember what the beginning of it was, but the end of it was pretty interesting. If you're a CTO or you're a founder, you're in this position, there's nothing that's off limits. I was talking to one—I think it was the CTO of Walmart at the time—and I was like, "What type of problems are you facing? Because I don't know what type of problems you would face at that level." And he's like, "Oh, we're trying to figure out—we're hiring 2,000 engineers this year and we've got to figure out where to put them. And I'm basically like a real estate agent and buyer." Because you have to just adapt to whatever the challenge is in front of you.
(Dale at 00:12:40) You are absolutely right. And it's funny because I think that—I don't know if you guys can hear my dog chewing his toy, but hopefully—
(Joel Beasley at 00:12:48) That's your first suggestion. Talk about the dog. Yeah, talk about the dog.
(Dale at 00:12:52) He's awesome. Wyatt, my COVID dog. A lot of people, I think, when they found themselves shut in, decided they wanted to be shut in with something. And so, poof. I've always loved dogs, and I like Wyatt too. As a CTO, I think the number one—apart from just, if you're not passionate and in love with technology generally, you're making a horrible, horrible career choice because that's all you are—then the other sort of key qualification is you need to have a strong opinion about almost everything, but you need to be prepared to abandon that opinion as soon as it's clear that you're wrong, because you're going to be wrong a lot. In fact, you're going to be right on Tuesday and wrong on Wednesday, or you're going to be right on Tuesday and that's going to be true for six months, and then you're going to be wrong. You can't not have an opinion. The worst thing in the world is you go, "Oh, so CTO or Chief Product Officer, should we do X or should we do Y?" "Well, you know..." That's not what you're for. You're for, "I firmly believe that everything should be containers. We need to containerize everything. We can't possibly deploy in the old way." And then now you have to say, "I firmly believe that while there's a place for containers, we really should be looking at serverless."
(Dale at 00:14:07) You cannot have no opinion, but you cannot refuse to just jettison it, because if you can do neither one, then you're just not going to make it very long.
(Joel Beasley at 00:14:19) Yeah. Someone once said, "Strong opinions loosely held." Right? That's fantastic. Yeah, fantastic. Well, other than plumbing, what's your role like today at Axio?
(Dale at 00:14:33) Yeah. It really is fantastic. So my job sits—I'm a Chief Product Officer now and not a Chief Technology Officer. I think, largely, that distinction is historic more than it's anything else. Particularly within the context of startups, I think oftentimes the CTO role, as distinct from the CIO role, was given to the person who, yes, you're a technologist, but you're more focused on how you intend to take that technology and expose it to whoever your core customer is versus how you intend to take technology and push it back into the organization, right? So you could think about the CIO and the CTO standing back to back, one looking down into the organization, the other looking sort of out onto the horizon. Ultimately, people started to think, "You know, there's more to a product than the tech stack. There are the pricing aspects of it, and there's the way that you market it, and there's the way that it's talked about, and the messaging, and the way that the inside sales team cooks with it, and the objection handling, and, and, and, and, and, and." People started to think, "You know, perhaps it's the case that we need someone with a scope that at least pushes the edges out towards some of these other boundaries."
(Dale at 00:15:48) The CPO, I think, was born as a result. People look at the places where there are hard lines between functions and end up sort of creating C-level titles that are designed to smoosh the edges of those lines. So still responsible for tech and tech stack, but also responsible for what are we going to apply that tech to? What is the core problem that we think that we can uniquely solve? How do we talk about that problem, and how do we differentiate it? That differentiation sort of goes in both directions. It's how do we talk about it differently, but how do we do something differently? You must have both. The security space is full of folks that do extremely different things that use the exact same words to describe it. And so it's incredibly hard sometimes to understand what's on offer, but also why you would want one thing versus another thing.
(Dale at 00:16:46) And so, frankly speaking, my role is to try to do both of those things: build things that are truly unique and different, and talk about them in ways that makes it clear how they're unique and different, and then respond to how that's dealt with. Right? Because frankly speaking, oftentimes your initial idea is wrong. You know what? I think CSOs need better calendaring and scheduling.
(Dale at 00:17:10) Then you'll discover, no, in fact, that's not at all what they need. What they have are competing requirements as it relates to compliance and audits, and they need a way to address that. Or they need a programmatic system for handling certain things or justifying the decisions they're making. That's me. That's what I do.
(Joel Beasley at 00:17:28) Very cool. Now I know a lot about Axio now after live listening to David's episode. Funny story. And I don't know if we can cut this out or not. We can decide later.
(Joel Beasley at 00:17:39) But so I had messaged with David and then I quickly just typed in, like, Axio or whatever on Google to learn more about the company, and Axios came up. Right? So I thought he was the CEO of that. Right? And so I've gone around for like four weeks, whenever his episode was being done, four to six weeks.
(Joel Beasley at 00:18:03) Because we connected pretty well because I'm staying currently in Hendersonville, which is right next to his hometown where he grew up.
(Dale at 00:18:11) I'm not sure where that is.
(Joel Beasley at 00:18:12) Yeah. And so we were talking about that and whatnot. And so I was so excited and I was telling everybody I saw, every time on the TV that a news channel referenced an Axios article, I was like, I know that guy. I was telling my wife.
(Joel Beasley at 00:18:27) I was like, it's so great. And then I'm in the prep meeting to do this, and I'm like, it's not the news company. This is so exciting. I'm gonna tell them about, like, how I see them all the time. And I think it's important, and we might want to leave this in simply because, like, some people, when they hear you guys, and they're like, oh, great. A-X-I-O. They're gonna type it in, and they might get the Axios as an answer.
(Dale at 00:18:51) Yeah. In fact, we have gotten some very hysterical flames on Twitter as a result of, like, I can't believe that you think that the Squad is not, and then, like—and we've gotten some inbound emails of people that are just like, how can you take this? And I'm like, well, frankly speaking, we're here to help you with cybersecurity. Totally understand your point of view on politics and why you would be angry, but I'm not a part of that anger. At least, I'm only a part of it recreationally, not professionally. Now, here's the upside though.
(Dale at 00:19:29) We got a lot of inbound traffic, a lot of inbound traffic, specifically from the healthcare space around our tools that help with the NIST CSF. In large part, it was because they found us on the NIST CSF government resources site, and they clicked on us because our name starts with A. That's good. We're at the top of the list. The list is in alphabetical order, and they're like, I don't know. There's one. Click. So it's a little bit like the old phone book, AAA Plumbing. So sort of sad that Axios exists, but pretty awesome that we start with A.
(Joel Beasley at 00:20:07) I love it. I love it. No. That is so cool. Somebody had come out about a year ago with a podcast and they just titled it CTO CTO, like, just so that they would be the first if you type in CTO. But the algorithms were smart enough to understand listeners and stuff like that. So for like a day or two, they were there and then they just dropped back down.
(Dale at 00:20:28) Yeah.
(Joel Beasley at 00:20:28) I was like, oh, that's so great. This is exciting. Okay. So what's the problem? Like, let's get, let's work a little bit, do some business stuff here. Why do people use your product? What problems are they facing? How do they find you guys?
(Dale at 00:20:43) Yeah. So let's start with the why they use it and what problems they're facing. I think that we have reached a moment in cybersecurity when we all realize that this is, in fact, not a problem that we're one product away from solving. I think for a long time, the idea was that, hey, listen. All I got to do is rack one more appliance. Okay. Our IDS wasn't enough. Let me add an intelligent AI-oriented detect. Oh, that wasn't enough either. Let me add an Iron Gateway in front of my mail server. Oh, that wasn't enough? Okay. How about a web app firewall? We were always one pizza box away from having this whole problem knocked. Ultimately, we determined there's not enough rack space in America for us to iron our way out of the problem.
(Dale at 00:21:34) That means then that you have to start to treat cybersecurity as a programmatic issue, not as something that you solve with a piece of technology. So if you think, as an example, right, nobody looks at sales and goes, you know, the problem with sales is we don't have good contact managers. But as soon as we get a contact piece of contact management software, our problem with sales will be over, and we can just move on. Right? They all recognize that, yes, you need Marketo, and yes, you need Pardot, and yes, you need Salesforce.com, but you also have to manage your salesforce programmatically. You have to have processes and all the rest of it. Therefore, you need tools that support those processes. What Axio provides are tools that support the process of running a cyber program. That's benchmarking it, baselining it, planning improvements to it, then, as importantly, justifying those improvements and beginning to talk about the benefit side of things. Another interesting thing about security, generally, is we have perfect vision into the cost side of things. We know who we're negatively going to impact. We know how much that negative impact is going to cost. We are always the no people. No. You cannot have that port open. No. You cannot use your own device. No. You cannot, like, just no. You may not use USB.
(Dale at 00:22:52) So our life is filled with these moments where our job is to make your experience with technology less good than your experience at home. Like, when I'm at home, everything just works. When I'm at home, I use my devices. When I'm at home, streaming video. Well, when you come to the office, pal. But in exchange for that, we make vague statements about, well, it's safer. Well, I'm trying to defend us. Well—and never before were we able to put quantified hard dollars against that. Well, our risk increases by a $100 million a year if I let you plug whatever you want into your laptop. And likewise, frankly, we used to treat cybersecurity almost like hygiene, like brushing your teeth. Of course you do it. It's just good. Right? You want to be as safe as you can. Nobody says, well, I mean, how clean is clean enough?
(Dale at 00:23:46) You just say, you have to be clean, fully clean, utterly hygienically clean. And really, cybersecurity should be treated like all other forms of security, which is there is a cost to that security. It needs to be justified by the value it brings. The restrictions on the business need to be in exchange for some hard dollar value. My tool is designed to help people get to that, understand that, and then be able to make good decisions about it.
(Joel Beasley at 00:24:26) Racking more kit. So do you—I'm assuming you have a product. Do you build some sort of software system that helps with all of this? Tell me about that. What's the name of that?
(Dale at 00:24:36) Absolutely. So it's a SaaS-based platform that has three modules. One, to help you measure, baseline, and plan improvements to your program based on any number of assessment methodologies and frameworks. Another that lets you build models of cyber risks so that you're connected to your business so that you can say, if ransomware hits us, this is how we imagine it. This is what we think it will cost us and where those costs are going to come from. And another that lets you model your insurance portfolio and it actually extracts language in it and highlights those places where there could be language that would cause an insurance policy that you think is going to cover you to not cover you because of an exclusion. And then that platform pulls all those things together to give you this idea of, we should make these changes in this order because it will return this benefit. We'll get this value as a result. And yes, totally SaaS-based platform, modern technology, cloud-hosted, built using containers, built with Docker, Kubernetes, Mongo, etcetera.
(Joel Beasley at 00:25:40) That's awesome. I like MongoDB.
(Dale at 00:25:42) Me too.
(Joel Beasley at 00:25:43) And I didn't know all of this. I think it's pretty interesting, not to be like a commentator, but I think it'll do really well. And here's why. Like, in the market, I see a lot of assessments, like scorecard-type things. You know, I see those things out there. They're pretty common. I see a lot of products that, you know, they're the answer, their protocols or their rule sets, you know. Some of them doing some pretty cool stuff, but I haven't yet, until now, seen one that handles the business conversation side of it, and it seems like that's what you guys excel at.
(Dale at 00:26:25) That's precisely what we want to do. So I have kids. I have two kids in high school and one kid in college. The kids in high school used to be in traditional sort of everyday American schooling. When they got to high school, the school went and shifted to IB, so International Baccalaureate. The kids moved from ABCDF grading to number nine to six. When it was ABCD, they would come home and say, Dad, I got a B. Oh, that's pretty good. Now that they're International Baccalaureate, they come home and they say, Dad, I got a six. I'm like, oh, okay. A six. Is that six out of 10? Is that six out of a 100? Am I supposed to be super excited? I have no context. Yes, they have a score. Right? They have been quantified. Without any sort of context for it, I don't know whether I should be excited about that or not. And I think a lot of the existing sort of measurement frameworks that are out there are doing exactly the same thing. Right? They say, you know what? In our view, you're a 373. Yay. Boo. Crap. Like what—how am I supposed to address that?
(Dale at 00:27:33) I think that most folks, if I say this is going to cost you $100,000, I don't need to contextualize that for you anymore because you know whether that's a huge deal, not a huge deal, how that fits within your business, how it doesn't. We think that, you got it, that, A, cybersecurity is a business problem. Because it is, it needs to incorporate everybody in the business, and it needs to use the language of business, which, as it turns out, is currency.
(Joel Beasley at 00:28:04) I want to go a little bit deeper, and now I've got questions. Okay. Okay. So let's talk about, like, company, like, Security Scorecard. As far as I know, they evaluate risk. When I was talking to them, like, primarily, the way I would use it is, like, I could go get my security scorecard that would help me get through the process. Like, I've done a couple integrations with, like, Fortune 500 companies, and it's super long, and the bound of paperwork's crazy. It's supposed to help, like, you know, give a credit score for your security risk. No doubt. But what I just—what I learned from your modules, I mean, it's like you guys are adjacent, or but, like, is that correct? You're adjacent. You're not direct competitors, but—
(Dale at 00:28:45) Security Scorecard is interesting. We know those guys. We met those guys. Security Scorecard's—again, this is a member of the whole, we all use the same language to describe very different things. We all talk about, oh, I quantify risk. We're all going to talk about quantifying. We're all going to talk about risk. Right? And yet, what they're doing is evaluating a combination of your external surface, so what do you look like to the hacker, and giving you a number that is designed to effectively summarize everything they see. Right? The highest fidelity description would be for me to go down the list and tell you, you have 15 ports open. You have unpatched servers. But that conversation is obviously going to take a long time to have, and so it's easier to say you're a 417. The people in your peer group average around 450. If I tell you just those two things, well, at least you know, should you do something? Should you not do something? Should you feel good about yourself? Should you not? What you don't know is, what things should you do and how much is it reasonable for it to cost before you decide not to deal with it? How good is good, or how bad is bad? Is it just that your peer group are all even worse than you? Or is it—so in fact, let me give you an anecdote.
(Dale at 00:30:01) We had a CISO that used a previous platform. They measured and they got a number. First of all, this number scale was between zero and five. The entirety of the universe of things that they could measure fit between zero and five. The reason that's a problem is that then they got the entire board and everybody in the company excited about this idea that they were currently, like, a 2.3, and they were gonna raise that score. So then they were a 2.3, and they became a 2.7 based on this scoring over the course of a year. Guy goes to deliver to the board. Hey. Listen. We were 2.3. We set this objective and we became 2.7. And the guy goes, wait a minute. That program cost us $10 million. Are you telling me that every point-one improvement is basically a $3 million exercise? $3 million for point-one? That seems terrible.
(Dale at 00:30:59) So sure. And there are two problems with this. Right? One is that they just picked the scale that compressed everything into this range that's like, it's not—you're not paying for decimal places. You're paying for all the things that contribute to that decimal place. And if I multiplied everything by a thousand, now you'd be happier. Right? If I said, oh, no. No. No. No. That was 300 points of improvement, not three-tenths of a point of improvement, not three-tenths of one of an improvement. Right? But the other thing is, really, really, even if I did that, it's still smoke and mirrors, chicanery. Right? If instead I said that $10 million of investment offset $100 million of risk, now would you be upset? You would not. It wouldn't matter whether I said that $100 million was 0.1% of a score or 10X of a score. The net of it is you know.
(Dale at 00:31:52) And or if I multiply my scale by a million, like, again, if I said, oh, if that $10 million of investment offsets $100 million of risk, it's good. If that $10 million of investment offsets $10 million of risk, then I have another product for you instead. You just give me all your money, and now there's nothing for the other, the bad guy to steal, and you've set off all your risk at a dollar-for-dollar. Right? So that's the judgment that we feel like people need to make and why our tool ingests things like Security Scorecard and tries to attach it to dollar values so that you can start to have conversations that way instead.
(Joel Beasley at 00:32:31) Well, that's pretty cool. And then if they don't have—if they haven't done, like, a Security Scorecard-type thing, your baseline improvements module, one that you described, would, like, allow me to pick, like, oh, measure this against, like, NIST standards or whatever it would be.
(Dale at 00:32:43) Exactly. Right. So we think, frankly, that it almost doesn't matter where you start. If you're going to do this work well, you're gonna need a combination of things. You're going to need outside-in automated understanding of what your attack surface looks like. You can choose a tool like Security Scorecard. You can choose a tool like BitSight. You can choose a tool like Fortify Data. All of these tools have their pluses and minuses and I'll let them compete. We're interested in all of them. We're engaged with all of them. You do need to have this understanding of what you look like from the attacker's perspective. But you also have to have an understanding of what you look like from inside. That from inside can and should start with what your people think about what you look like from inside. Now, ultimately, you're probably going to want to integrate some of the tools that you have that provide telemetry to inform that internal view.
(Dale at 00:33:37) But you can start by just asking your people, "Hey, listen. How well do you think we do at X? How well do you think we do at Y?" Most of the time, if they're using it for their own benefit, they're pretty honest about what it is. Then the last is you have to take both of those things, outside view, inside view, and you have to associate it with the risks that you're actually facing.
(Dale at 00:33:56) What are you defending against? What are the operational consequences of that defense? Therefore, how much is it going to cost you when those defenses fail? That's where you can start to go, "Alright. Where do the improvements really need to come from?"
(Dale at 00:34:09) You're not chasing a score now. Right? You're chasing a dollar value.
(Joel Beasley at 00:34:13) I like it. It's smart. I really do. The three modules—baseline improvements—I was taking notes, by the way, if you heard me typing. Okay.
(Joel Beasley at 00:34:21) Baseline improvements, models of cyber risk, insurance policy understandings, things like that. Do you have different names for these three modules?
(Dale at 00:34:29) One's the assessment module, the other's the risk quantification module, and the last is the insurance analysis module. Something that I didn't touch on—I talked around it but didn't get to—is that once you know what something's going to cost you if it happens, you can start to treat it. You can stop thinking of it in terms of hygiene and start thinking of it as a business problem. That opens up the door to things like, "Well, should we just insure against it?" If you think about it, my house is uphill from a tiny little creek. You might be surprised to note that it's not on stilts.
(Dale at 00:35:06) Now, if I wanted to be 100% certain that there will never be any water in my living room, I should put my house on stilts. I'm pretty sure if I got it on 18-foot pylons, I could be absolutely certain that unless Noah floats by in the ark, there's never going to be any water in my living room. However, the chances of that happening are so desperately remote that it's ridiculous for me to approach it with an engineering exercise. Right? So what do people do about that?
(Dale at 00:35:40) They insure against it. Like, it's possible that my house will catch fire. It doesn't happen every day. It hasn't ever happened. My house, you might be surprised to learn, is not made exclusively out of asbestos.
(Dale at 00:35:54) It's, in fact, made out of all kinds of flammable materials. Again, because the appropriate approach to the risk is just to insure against it. But you can't do that unless you know the economic consequences of not just defending yourself, because you'll never know whether the insurance is worth it if you don't. Right? So that's where we bring the insurance module in, attach it to the quantification module, and you can start to treat risk like you do everywhere else.
(Dale at 00:36:19) Right? There are stores in the mall that have jeans on tables in front of the store, not even inside. Right? Is there a risk that some of those jeans are going to get stolen? Yeah.
(Dale at 00:36:30) In fact, they call it breakage. They don't even call it theft. Right? It's called breakage.
(Dale at 00:36:37) It's marketing breakage. They know that if that many people are gonna pick up those jeans and walk into the store and buy them and then notice a scarf and a belt, it's worth it to them. There are jewelry stores in that same mall. They, weirdly, do not put diamond rings outside the jewelry store on a table, because the breakage in that case is too consequential. So how do you know which one you are?
(Dale at 00:37:05) Right? Is that piece of cyber tech jeans, or is it diamonds? The only way to know is to have quantified it in operational terms. Then it makes sense whether, "Is it okay if our jeans are outside the store, or is it not okay that our diamonds are outside the store?" And like I said, it used to be that the poor CISO, the answer was always no.
(Dale at 00:37:26) That stuff is staying inside. Right? Because my job is to make sure that nothing breaks. Well, now it's like, give and take.
(Joel Beasley at 00:37:35) I like it. That's good. You got really good analogies. It's pretty cool. I'm curious.
(Joel Beasley at 00:37:43) You sparked something in my mind when you were talking about insurance. If you build your house to newer model and you put firebreaks in on the walls a few feet up, you're gonna get a little discount for that insurance. And then the insurance kinda starts shaping the construction industry because you want these discounts. How is the insurance for this risk starting to shape what's happening in the security industry?
(Dale at 00:38:08) That is a really insightful question that you just asked me. And it is, in fact, a thing that has just now started. So back in, what was it, 2012, 2013, I remember at SecureWorks, we were desperately hoping that we could convince insurers that they should basically provide discounts to SecureWorks customers. And the reason we were doing it is because we were trying to put a price on the value of our software. And again, when nobody knows what cybersecurity is benefiting them, it's very hard to price things.
(Dale at 00:38:47) "My tool is $200,000 a year." "Why should I pay $200,000 a year?" "Well, because you'll be safer." "How much safer?" "Are you guaranteeing that I will never have a cyber incident?" "Well, no, I could never do that." "Oh." Then we thought, "Oh, well, maybe the insurance company will say, 'Well, I'll give you a $300,000 discount on your insurance policies if you'll use SecureWorks.' Now we know that the value of our services is at least $300,000." But the insurers were never interested in doing it.
(Dale at 00:39:19) In part, they were like, "We need you to place a value on the risks that you're protecting against. We don't have any understanding about what we can expect cyber to cost these companies, and we also have no understanding about what elements actually make for a less risky company versus another." So in the fire industry, which has been around forever, fire insurance is one of the most ironclad and regulated types of insurance there is because it's been around forever. Right? So they know you need sprinkler heads.
(Dale at 00:39:51) They have to be this far apart. You want shingles that are made out of this material and not that material. The firebreaks have to be this far and not that far. In Chicago, the wiring has to be running conduit, not up the wall, and on and on and on. Right?
(Dale at 00:40:06) They know that, so they know how to value the presence of those construction improvements. For the longest time, cyber had nothing like that. And then we went through this heyday period where cyber insurance policies came about and people were making so much money with them that it was in nobody's interest to look too carefully at it. Folks were just paying money for these policies and receiving almost nothing in return. And they were practically giving them away at the door if you were willing to come in and get a quote on something else.
(Dale at 00:40:37) So then there was this thing that you guys probably, not being insiders, haven't heard about, but it's called ransomware. And as it turned out, ransomware ended up being reasonably consequential, and it ripped like a brush fire through the insurance industry. Right? It was as impactful to the insurance industry as nine-eleven was to the property insurance industry, which, if you think about it, nine-eleven caused a lot of trouble for a lot of folks that insured a lot of things in downtown New York. Ransomware is that but wider, that but worse.
(Dale at 00:41:18) Now, as a result, one, the insurers have gotten a lot smarter about what makes for good risks and what makes for bad risks and what pieces have to be in place. What separates the folks for which—first, everybody is in the ransomware bucket. Everybody has got blood pressure. Everybody has got some sickness, something that could cause their demise eventually. There are some folks that are going to die immediately, and there are some folks that are going to die after they're 102.
(Dale at 00:41:45) Now, the insurance industry is beginning to tease out, "How do we know which one you are?" Right? "Ah, you don't have privileged access management. Ah, you have open RDP ports. Ah, you use VDI or you don't use VDI."
(Dale at 00:42:00) Because of that, they're starting to be able to place a value. They have to because they can't afford not to, and they can't afford not to cover cyber. They're starting to be smart enough that they can. Now they're beginning to talk to us about, and we are talking to them. "Hey, listen. We can work together to help our clients with a really challenging problem, which is to convince you that you should insure them. And it will ultimately be better for everyone." So, in fact, we have a couple of folks that received breaks on their premiums by virtue of the fact that they use the Axio platform and could describe not only where they currently were, but what their plans for improvement were. And I think that you're gonna start to see—and you've started just outside of Axio—you've seen this with a couple of other products too where it's a combined policy plus tech stack, which is getting at the same idea with a slightly different composition, which is rather than give you a discount if you have tech, I'm going to give you the insurance and the tech as a bundle, which, you know, maybe it's just because that's not my company.
(Dale at 00:43:04) But I think that my approach is better because I think it provides better flexibility. For the same reason that I wish my car didn't have a map anymore, it would just use my phone. My phone updates itself all the time. It's modern. I can replace my phone more easily than my car.
(Dale at 00:43:20) If my car would just use the tech stack in my pocket, everybody would be better. My phone, I upgrade every four or five years. Right? I think that this idea of looser coupling that provides one thing to rev at a pace that's much more rapid than the insurance policy pace is a better plan, but ultimately that's what's happening. People are coming to grips with this idea that you need, that the insurance industry has to be smart about cyber, that they need to incent it.
(Dale at 00:43:47) There needs to be market incentive for folks to do improvements in their cyber programs. Otherwise, they won't. Right? In fact, you're disincented in the market to improve your cyber program. Right?
(Dale at 00:44:00) So everybody recognized the incentive has to exist, that the intelligence has to exist, and that the friction associated with the transaction has to be removed. And that means exactly the coupling you need to do.
(Joel Beasley at 00:44:12) Yeah. That's interesting. I was thinking, so you're telling me—and I just wanna better understand—there are some insurance companies that will provide some type of security software? Because that sounds so problematic because, like, let's say I'm an insurance company, XYZ Insurance, and, like, what? I say, "Okay. If you buy SolarWinds," like, I don't know your configuration. I don't know who's managing it. I don't know the setup. Just because you purchased a license, it, like, you know, it doesn't make a whole lot of sense.
(Dale at 00:44:39) It works at the small—alright. So if you imagine that you're replacing nothing, and remember I mentioned that my kids might be coming in. They're here. Yeah. So, the noise—yeah. Welcome to the welcome to my podcast, Jada. If you imagine that you're at the small end of the market and that you're replacing nothing or a very limited tech stack, and you imagine that you're dealing with a set of potential configurations that is more constrained, you can see how it might work. Hey. Look. It's a little bit like, should everybody that wants a good living room video experience go and buy component-based home theater?
(Dale at 00:45:20) Probably not, because what they'll end up with is a pack of wires, amplifiers, and stuff just everywhere, and they'll still not be able to watch TV. It's 100% fine for them to get a soundbar and a reasonably good flat screen. And you just use HDMI and be done with it. No. You don't need a warming amp and all this other stuff.
(Dale at 00:45:38) Right? On the other hand, if it really was the case that you wanted the ultimate experience in your living room, and you can afford it and you have the experts for it, now there's another solution that will deliver a much better ultimate outcome. I think that some of these insurance-plus products are focusing on the folks that need the TV and the soundbar. They're not doing what you were pointing out, which is, "How are you going to know the acoustics of the space? How are you going to figure out where to put the preamp? How are you going to deal with all the space constraints? What about, you know, what are you going to do with the ceiling?" And all of those types of questions that cyber often brings up when you are mid to upper end of the market.
(Joel Beasley at 00:46:14) Yeah. You can definitely see the progress happening. Four years ago when I got my—I got business owner's policy for the area I was renting and a couple other things with the business, and it was literally like, "Oh, check this box for $1,000,000 in ransomware coverage." And I was like, "That makes no sense. Like, I'm just gonna check this box." I was like, "These guys have no idea, like, what this is." And so I checked the box and then, like, you know, two years go by, nothing. And then, like, year three, I get the questionnaires. And I was like, "They finally caught on. They were just givin' it for a couple years."
(Joel Beasley at 00:46:49) They were getting hammered by ransomware attacks. I even had this one guy on the show, like, maybe two years ago or so. He had a company and what they were doing—they were the company that their customers were the insurance people. And so when they were having an attack or something, they would go down to this company to negotiate with the terrorist essentially, or the cyber criminals. I don't know what you call them.
(Joel Beasley at 00:47:14) And just to try to negotiate down or get the data first, see if they could get the data back. Second, negotiate down, check if it's like an internal job, you know, if they're trying to scam the insurance. So I can definitely see how it was like a tidal wave that hit the insurance companies.
(Dale at 00:47:29) So here's an interesting thing. It didn't just land on the cyber policies themselves. This is the crazy part. So inside there, there is another policy type that was effectively given away, like as a sweetener. "Please come and take our other policies, and I'll give you this one policy."
(Dale at 00:47:46) It was kidnap and ransom. Kidnap and ransom policies, obviously, they were initially intended to cover the, "Oh, if your executives find themselves in Juarez and things go south, we'll pay for the activity associated with trying to extract your executives from Juarez." Well, it didn't take long for someone to go, "Hey. This is called ransomware. Right? Like, we're having to pay a ransom."
(Dale at 00:48:13) Right? "We should use our kidnap and ransom policies." And in some cases, these policies had massive limits for free because nobody expected—just most people don't send their executives to Juarez. So why not just have the policy? Right?
(Dale at 00:48:30) And now all of a sudden there were these huge payouts and everybody's going, "Wait. Wait. Wait. That's not what we meant. We take it all back."
(Dale at 00:48:36) You're seeing exclusions being written and premiums going up and the insurance company struggling, grappling with the world. I feel for them. Any time you deal with rate of change problems, you create systems that are very hard to manage. Policies, legislation, they operate at one time cycle, at a particular time cycle. One is very, very, very slow.
(Dale at 00:49:06) The other is just very slow. In part, it's because insurance policies interface with government regulations. In order to get a policy into the market, you have to talk to at least 50 individual state boards of insurance, plus the feds. That creates a particular rate of change. On the other hand, ransomware changes in seconds, and they can be extremely responsive to market dynamics.
(Dale at 00:49:32) Right? So, "I've encrypted all your stuff. You should pay me back." "Okay. I will." "God, that sucked. I should have backups." "I have backups now." "I've encrypted all your stuff." "Too bad I have backups."
(Dale at 00:49:48) "I've encrypted all your stuff, and I've left the back door in, and I'm not gonna tell you where the back door is unless you pay me." "Okay. I'll pay you." "God, that sucks. Okay.
(Dale at 00:49:57) I need gold images for all my machines. Alright. Now I'll reimage." "Okay. I've kept all your data."
(Dale at 00:50:05) And if you don't pay me, I'm going to release it, and you're going to be the next Sony where all your starlets are going to know that they were being bad mouthed. And so you see that, basically, they're able to change their business model and respond immediately every time, and that's happening on a less than a month cycle. So you've got this thing whose rate of change is practically daily, and you've got this other thing whose rate of change is at best yearly and more like every four years, and the two interface. It's tricky, right?
(Joel Beasley at 00:50:41) They'll adapt. They will. And they'll have to. Yeah.
(Dale at 00:50:45) Software, I think, provides the differential. And this is precisely why I think that a looser coupling is more interesting, right? So if the insurance company says things, and by the way, I feel the same way about legislation, if instead of mandating a particular—thou shall have SolarWinds, thou must not have SolarWinds, thou shall have privileged access management—you mandate a framework.
(Dale at 00:51:10) We ensure the use of currently defined best practices is determined in some way. We ensure the presence of staff and programs designed to make sure that you're doing whatever the right thing is all the time. Then that language creates this differential. It allows, basically, this thing to turn at one rate and the threat to turn at another rate, and the software and the process in the middle provide the link.
(Joel Beasley at 00:51:37) That's brilliant. I'm really happy with my team. They told me after the prep call that you were awesome, this would be a great interview. And I was like, for sure.
(Joel Beasley at 00:51:46) I want to wrap up with a leadership question, inspired by Patrick over at Claro MDSL. Their episode that we talked about—they do expense management. I'd never seen another company that did this, but they might be a million, so you can tell me. But they essentially track expenses and do expense management for multiple companies.
(Joel Beasley at 00:52:04) And then now they have this new layer of data of what different people pay, and they do something with that data. I'm not entirely sure. But we were talking about leadership. We were talking about being humble. And I'm curious, are you a humble type leader? What's your emotional reaction when you hear humble leader?
(Dale at 00:52:27) I love that phrase. I think it's a little bit like servant leadership. The tricky thing with humble leader, as well as the tricky thing with servant leader, is that there's something about leading that begs you to be the opposite of that, right? Like, it's not the humble person that says to themselves, I have the right to run everything.
(Dale at 00:52:56) What you end up having to hold within yourself is this understanding that you've been granted this opportunity. It's not just for no reason. It's because you are who you are. But a part of that is an acknowledgment that everyone contributes and that you can't do it by yourself, and that a leader is—otherwise, just go be a solo artist, right?
(Dale at 00:53:18) Like, it's fine. You must incorporate other people's feelings, and that requires a tremendous amount of humility. I had a CEO, and he said to me, "Hey, Dale, you're going to make 200 decisions every week, and one of those decisions is going to matter, and you're going to get two of them right. So you need to be really careful that you're getting data from everywhere else and that you're not worried too terribly much that you feel like you have to directly control all the things that are happening."
(Dale at 00:53:57) I think if you try to incorporate those thoughts, then you get what you want. And then the last point on that from my own experience is, you can succeed as an utter and complete jerk. Like, you absolutely can. You can be a total and complete tyrant. You can rule with an iron fist, and you can succeed by virtue of your strong personality and people's just unwillingness to fight you. And you can succeed as a kind individual that cares about the people that are working with them and deeply wants them to succeed too, and is hoping that their combined success will buoy that person up too. But I'll tell you, when you are the tyrant guy, if you slip, you will find no one supporting you. And so you better be right every single time. You better do nothing that makes—because people are excited to see you fall.
(Dale at 00:54:53) On the other hand, if you're the type of person that feels like, "Hey, look, I'm going to win this by having people better than me around me that, for whatever reason, want me to be the front of it," then when you slip, people are there for you, want to support you, want you to do well, are rooting for you. I'd much rather have someone root for my success than root for my failure, is all.
(Joel Beasley at 00:55:18) And I love that in the professional world, that's becoming less and less popular. Like, there's more awareness now than ever of how obtuse it is to be a tyrant.
(Dale at 00:55:33) Right, right. It's just not—ultimately, it's just a bad strategy. It's just strategically bad. Like, Machiavelli would be the first to tell you, right? Like, you really want—you cannot preserve fear forever in a free world. And so the last thing you want is for people to root for you to fail.
(Joel Beasley at 00:55:53) That's good. I'm going to ask you another one. Do you have time for one more?
(Dale at 00:55:56) Yeah, absolutely.
(Joel Beasley at 00:55:57) Let's say that I was on your team. I'm just maybe a manager or a leader on one of your teams, and I wanted to stand out to you because I wanted more opportunity in my career. What could I be doing that would catch your attention?
(Dale at 00:56:16) For me, that's—I love that question. For me, frankly, and it might be—look, I want to calibrate this where it is highly dependent upon what it is that's important to the company and what the key objectives are. But when you're talking about startups in particular, I want people that take initiative and take risks. Frankly speaking, I want people that take initiatives, take risks, and are willing to challenge me. I recognize that that requires a tremendous amount of trust and requires a tremendous amount of faith, because almost everybody I've ever worked for has told me, "Hey, listen, Dale, I really want you to call me out if you feel like I'm making a mistake."
(Dale at 00:56:56) And almost none of them meant it, right? What they wanted was the confidence that I wasn't a yes person, not me actually calling them out. But I really mean it. So I'm looking—look, I hire—my job is to hire people that are smart with opinions. My job is to make sure that the company is not dependent on me being right every time. And so I need people to take risks, take initiatives, and are not afraid to tell me that they think I'm making a mistake. Believe me when I say I want those things. So do those things, and we're good.
(Joel Beasley at 00:57:33) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.