Episode 747 ·
The State of IT and Technology Leadership for 2024 with Brian Grouzos, Adam Bahret, and Tony Davis
Today, we’re bringing you a special Modern CTO panel episode! Brian Grouzos, Adam Bahret, and Tony Davis join in to discuss their biggest challenges over the past year, where their focus lies in the new year, and how they’re gearing up to take on all that 2024 has to bring.
All of this right here, right now, on the Modern CTO Podcast!
For more about Brian's company, Prescient Assurance, check out their website here.
For more about Adam Bahret and his work, visit his website here.
For more about Tony's company, AIOps, visit their website here.
Have feedback about the show? Let us know here.
Produced by ProSeries Media.
For booking inquiries, email [email protected]

About Brian Grouzos
In my previous role, I was responsible for managing a dynamic, agile team of 15 people that covered a variety of risk and compliance areas including PCI, HITRUST, government compliance (NIST 800-171, 800-53, FEDRAMP), etc. These security and compliance efforts stretched across a wide list of technologies from internal and external cloud to mainframe and everything in between. My team implemented controls, identified gaps, and partnered with business areas to drive remediation efforts. We were also responsible for supporting internal and external PCI assessments across the company, HITRUST audits, various government audits, etc.
As part of my work on this team, I created a consolidated list of standardized controls to simplify and streamline security and compliance. We leveraged these controls to implement a robust risk-based controls assessment process to better identify gaps proactively. I created a dedicated remediation team to partner with business units to help with prioritization, implement the right controls to effectively manage risk with the least amount of impact to the business, and ensure the full life cycle of risk management is considered. We standardized scoping using our GRC tool to gain insight into changes in the environment and prioritize our work to add the most value. We also created a dedicated resource site to communicate control expectations and guidance to stakeholders.
My goal with security is to work with the business to ensure they have all the tools they need to be successful. I take a very customer-oriented approach to security and I am always working to limit waste in processes. I am constantly trying to drive a more security-aware culture and build strategic relationships at all levels of the company. Through this work we built security champions and ran a lean and efficient security and compliance group. The team values were speed, excellence, service, value creation, and team work. I also started a career development book club that met every two weeks, developed our team coaching process, and emphasized skill development with all members of my team.
About Prescient Assurance
Prescient Assurance is a licensed CPA Firm which provides Audits and Examinations for SOC2 attestation, ISO, PCI, GDPR, HIPAA, CCPA, GDPR, GBLA, NIST 800-53, NIST 800-171, FERPA, FISMA, PIPEDA, SWIFT CSP, HITRUST, Google OAuth, Microsoft SSPA, CSA STAR, and Privacy Shield . Prescient Assurance is the leader in security certifications for B2B SAAS companies worldwide. We are global Top -10 cloud security auditors by cloud security alliance STAR program.
About Adam Bahret
I live in Massachusetts with my wife and two daughters. When I’m not designing and testing highly reliable products for my clients, I’m trying out my own at home. I typically use cars as my test beds, adding extreme features into unusual places. On our wedding day, my wife included her own unique vows, ‘’I’m well aware that my life going forward will be filled with constant modifications and disassembly of everything in our house.’’
About Tony Davis
I serve as a Sr. Engagement Manager for A&I Solutions. I have spent over 30 years implementing and leading Fortune 100 IT Operations technologies, and now work with A&I clients to design monitoring strategies that combine selective NetOps, Infrastructure, and AIOps data into meaningful observability.
Transcript
(Intro Narrator at 00:00:01) Today, we're bringing you a special panel discussion. We're joined by Brian Grouzos, Director of Engagement Quality at Prussian Assurance, Adam Bahret, reliability engineering consultant, and Tony Davis, Senior Engagement Engineer at AIOps. The panel will be discussing their biggest challenges and takeaways of 2023, and we'll then discuss their most important hurdles for 2024. You're listening to Joel Beasley, Modern CTO.
(Joel Beasley at 00:00:37) The general topic that we wanted to get all of your insights on is the state of IT for 2024. Right? Everybody's doing their 2024 planning right now. It's the end of the year. We're about to hit vacation season.
(Joel Beasley at 00:00:51) And as people do that, they typically consume a lot of podcasts, which is great. And so I figured if we could help them, share with them how we're thinking about the future and how we're thinking about IT for 2024, that would be useful. But before that, I wanted to just do a quick reflection on some of the biggest challenges that we've each faced this year leading our technology teams or working with clients in technology. Is that okay?
(Tony Davis at 00:01:19) Sounds good.
(Joel Beasley at 00:01:20) Awesome. Brian, do you want to go first?
(Brian Grouzos at 00:01:22) Sure. I think one of the biggest things I'm seeing right now is with the economy kind of playing out the way it is and everything, security funding is taking a bit of a hit. And really trying to make the case for why security is important and why, although it's a cost center, it's also something that needs to be taken seriously to protect, and do you understand your patients, your clients, your businesses that you work with? Make sure you're doing the right thing by them by having the appropriate security budget while considering the needs of the business. The more things get tight, the stricter compliance gets over the time frames. The more people take a look at things like security, since they don't generate revenue.
(Brian Grouzos at 00:02:02) So really keeping a focus on what's important for your business, mitigating risk to an appropriate level, understanding your risk appetite, things like that, I think are trends you're seeing coming out of 2023 rolling into 2024 that really need to be paid attention to.
(Joel Beasley at 00:02:18) What do you think, Adam?
(Adam Bahret at 00:02:19) Yeah. So for myself, my focus is electromechanical product development with software control. One thing that's really been interesting and been a big point of discussion over the past year is security of electromechanical devices controlled through software and what can be done now and how impactful it is with the Internet of everything. Right? Your coffee maker has a Wi-Fi card now. So a product that I worked on recently was something as simple as a computer-controlled IV system in a hospital.
(Adam Bahret at 00:02:49) So the question is, are we responsible if somebody hacks in and does an assassination by drowning somebody in saline solution through their blood, diluting their blood? Really simple stuff like that where, especially with medical devices where I do a lot of work, that exposure is tremendous and very unprotected and a tremendous amount of variability. Right? I mean, different hospitals have different levels of security or control or ability, and some are very low funded, don't have a lot of resource in that area. I mean, it's amazing to think a hacker could actually kill somebody by simply changing parameters on a medical device.
(Adam Bahret at 00:03:26) So that's become a whole new part of the reliability of the system and reliability separate from product failure to reliability of patient and user safety, and can this be used against them? So that was a big change.
(Joel Beasley at 00:03:40) That's interesting because I was doing all sorts of nefarious things when I was 13 on the Internet. And sometimes you're immature. That's why we don't let kids make decisions. Right? So doing things like, oh, is this satellite open? Let's see if I can get in there. Or is this, this can't really be a hospital. This must be some type of game. Let me see if I can just kill all the patients.
(Joel Beasley at 00:04:02) So it's not just nefarious people trying to kill a specific person. It can also be kids just exploring the digital landscape and being like, what is this? Let's flip that switch and see what happens. Just exploring.
(Brian Grouzos at 00:04:14) Right. I think to your point too, Adam, is understanding where your risks are and your risk of exposure. Right? I think that's something a lot of people are not doing a great job at in lots of industries with the Internet of everything and the cloud and lots of areas. Right? They're just not doing a thorough risk analysis on where they might have exposures and what could happen with some of those exposures. So that was a great call out.
(Adam Bahret at 00:04:36) Yeah. And one of these things is that, you know, to some degree, the way I look at risk, I always look at how does variability affect something. I can start with the assumption that everything at nominal value works. You know, your thing works at their nominal value. So what happens with the variabilities? And when you look at that problem, holy camoly. When you get to the variability of what's controlled in the firewalls and the server system it's run on, like, that's wild. Right? You can even have third world countries. You can have, you know, these systems can be running off somebody's data link on their cell phone while it's sitting in some very rudimentary building.
(Adam Bahret at 00:05:13) And how do you control what you're doing with that kind of variability? It's an interesting problem.
(Joel Beasley at 00:05:23) Tony, what are you seeing?
(Tony Davis at 00:05:25) Yeah, I'm probably, it would be similar to what Adam said there. Because for me, when I look back, so my thirty-five years or whatever in the business has mostly been in IT operations, which is a very fluid part of any corporation. Right? So it's always moving. It's just constantly collecting data. So for me, over the past year, and actually I think going into the next year, my biggest challenge working with clients has been the explosion, I guess you would call it, the exponential explosion of data that is being collected and stored, and then what are you doing with that data? So where Adam mentioned who's controlling, who controls that, and how is it being controlled? I think even in the world that I live in, which is IT operations, the storage and the control of all of this data that we're collecting, especially from monitoring sources of any kind, I think that represents risk. And I think on an operational side, a lot of people don't know what to do with the data, like, even how to use it on a day-to-day perspective.
(Tony Davis at 00:06:30) You get so much data. One client recently told me, look, I don't have a problem gathering data about my systems and about my applications. I have a problem knowing what to do with it once I have all of these data points. So I think that'll continue to be the story, but even more so now with AI, as we move into 2024.
(Tony Davis at 00:06:50) That's actually really interesting, Tony, because the thing about how
(Adam Bahret at 00:06:53) to use your data is such a big question. And now being on the cusp of the AI, how do you direct AI to use it? And kind of everybody right now is like, oh, you know, treat it as a chatbot where, you know, it's an individual, like almost like a personal interaction. Like, we're treating it like a person and not really, probably to some degree, truly unleashing it to do what it could do in other forms. And which means that if you treat it as a person, you give it commands, I want you to do this, I want you to do that. Can we figure out how to have it answer that fundamental question? What should I do with this data? What can I learn? And it's so interesting. And it's actually an initiative for me in this next year because a part of my work is that I do take data in the field performance for products of mechanical, electrical, all kinds.
(Adam Bahret at 00:07:39) And I try to characterize behaviors and then use those behaviors to predict the future, which then can be used in many ways. It's an insanely tedious process. It's an art and knowledge and experience, and there's always fifteen people better than you at it. And you're like, how did they find that? And then to think about that process and just turning it over, turning it over to something that will actually define the problem better is so interesting. And I really am curious what's going to happen with that.
(Brian Grouzos at 00:08:10) You both kind of brought up something that I thought was interesting too. I mean, you alluded to the complexity shift over the time that you guys have been in the field. Right? It's gotten dramatically more complex, but also the ethical considerations. Right? Data ethical considerations becoming a hot button issue right now. How do you use data? What's appropriate? What's legal? How far can you push that envelope? And Adam even brought up, who's responsible if somebody does something with some of these healthcare devices. Right? Like, where is my ethical line in the sand that I have to worry about crossing over for some of these issues? You know, where does our accountability fall and what are we covered for? I mean, killing somebody could be huge, insurance liability, legal liability, all kinds of things, through negligence and not knowing what your exposure is. That's a significant risk that people have to be aware of.
(Adam Bahret at 00:08:57) I mean, the risks to these medical companies is, I've been working with companies who had an issue, you know, like something simple, something a simple mechanical issue, electromechanical issue. The FDA just walks in and can just shut you down. And by the way, I didn't know, but the FDA is a division, a military division. They're an unarmed military division. They show up in like military fatigues. Like, it's really scary.
(Brian Grouzos at 00:09:20) I didn't know that. Wow.
(Adam Bahret at 00:09:21) And they'll just shut you down for a year. Like, your business is shut for, like, that's devastating. You could go out of business. And that was without killing anybody. Right? So yeah. Exactly. When there's this sense of loss of control, if the FDA feels like, not only do we not know what happened or who's at fault, but we don't even know where to start investigating this, they could go in and blanket shut down a lot of stuff. Like, the exposure is tremendous, I think, to these companies.
(Brian Grouzos at 00:09:45) What about vendor risk even? Like, you're a hospital. You use these devices. Are you at risk or are they at risk? Or who's really holding the bag at the end of the day. Right? Like, for something like that, something bad happens,
(Adam Bahret at 00:09:56) or is it everybody? And it gets strange quick. And the funny thing is, you know, with regulatory, it inspires creativity, we'll say, in getting around things. And I've seen where with HIPAA laws, which protect patient information, but medical companies still want information on their products. Right? You know, they, I mean, because they're trying to understand, they want their data set. How's my product performing? You know, they don't want the patient data. But because of HIPAA laws, they're not allowed to be, if they're on the hospital network, they can't go out. So they just go down to the Verizon store and buy little cell phone cards and hook it up to their machine.
(Adam Bahret at 00:10:33) And the machine's just directly sending it out to a cell phone tower now. Right? Like, they just bypass everything. And I'm not even sure how, the legality of it is even weird. But, I mean, you want to talk about vulnerability, it's running off a burner phone card, basically. Like, yeah. It doesn't matter what the hospital does. They're not even using their network.
(Brian Grouzos at 00:10:52) That's a little shady.
(Adam Bahret at 00:10:54) Well, yeah, it's, you know, it's kind of, it's interesting, but the shadiness part's even hard to state because the question is the HIPAA laws are protecting the patient information. Right? And so they do this very blanket, hard, like, wall of anything going out.
(Brian Grouzos at 00:11:09) Right.
(Adam Bahret at 00:11:09) And these cards are specifically taking instrument data. Like, there's no, you know, like, the patient, you know, like, that information's kind of removed. So it's more that they never created enough resolution in the data with regard to what's protected and what's not to where it's leaving a little bit of this kind of
(Brian Grouzos at 00:11:23) the ethical thing. Right?
(Tony Davis at 00:11:25) Like, do what's right even when nobody's watching.
(Adam Bahret at 00:11:27) Yeah. I don't have any patient names or whatever. I just have my servo count and my this and that and the fluidic flows of whatever. And, you know, I didn't take out the hospitalization of the patient. But
(Joel Beasley at 00:11:38) But the problem becomes when there's a little gap in that wall. Right? Like, if I can get into the hospital network through that device or if an engineer can get into the hospital network through that device. Right?
(Adam Bahret at 00:11:51) Right. Oh, that's exactly it. As far as security, it's like, talk about a backdoor. You know, it's having Fort Knox, but you have a screen door in the back that has a please knock sign or don't, no trespassing. You know what I mean? It's like that's basically what it's been reduced to.
(Tony Davis at 00:12:06) Yeah. And so, and you're really in trouble when your IT auditors show up.
(Joel Beasley at 00:12:13) Yeah.
(Tony Davis at 00:12:14) And when they find that cell card that's transmitting data, that's going to be a real weakness that they're going to note.
(Adam Bahret at 00:12:21) But are the IT auditors breaking open the machines and looking inside? Like,
(Brian Grouzos at 00:12:25) We could ask the good questions. So if you're doing your job right, you should be asking the right questions to say, how is this transmitting and things like that. But this kind of brings up a whole other can of worms that I'm pretty passionate about around compliance and audit is not meant to regulate these kinds of things, in my opinion. It's meant to make sure that they're doing what they say they're doing. They're not meant to be the watchdogs. This is kind of becoming the last ten years or so. Security should always be first with audit second, in my opinion, or compliance second, but it's really flipped around to what's the bare minimum of what we can get by with with our auditors. If that's the case, then let's do that. And I think that's a, it's just a very slippery slope in the ethical landscape. Right? You need to make sure that you have that open window or open glass kind of thing that you were talking about, Adam. Like, if it's not ethical, don't do it. Right? You don't need somebody to tell you how to do it. You know it's wrong. Just don't do it. Right. Security as a whole is kind of trending in that direction and getting what I might call lazy to some degree around security. Right? Like, how low can we go and still be okay? It's a dangerous concept to really see happening in the industry.
(Joel Beasley at 00:13:31) Brian, I sign the contract with the Fortune 500 company. I need to get, and then they give me all these ridiculous compliance questions and these absurd things that act like they have no experience in understanding what type of product or service I'm delivering to the company. You know? And then I'm like, all right. Well, these are just the stupid, like, these are not the things that they should even be thinking about. That's what I'm thinking as an engineer. I'm like, this isn't what you want to be looking at. But nonetheless, that's the hurdle I have to jump. So now I'm like, now my entire process is designed to just overcome those hurdles, and I spend all of my effort overcoming these ridiculous hurdles. And I don't get to take any of that money and time because we're a business. Right? And put it towards actually solving the things that need to be solved.
(Brian Grouzos at 00:14:18) It's sort of the checkboxes is what it's turned into. And even when the checkboxes don't make sense, we still want people to check boxes, right? And to your point, your vendors and your clients should know you and how you operate at a deeper level than just a security questionnaire that maybe doesn't even make sense for how you operate, right?
(Brian Grouzos at 00:14:37) It really is knowing your risk profile by your high-risk vendors and really getting to know them at a deeper level, I think, is something we need to be doing a better job of. It's kind of like we've automated without automation, right? We've kind of taken any kind of audit judgment or any kind of judgment at all out of a lot of our security conversations and just relied on tools and processes that maybe don't even make sense anymore. And we never reevaluate them. And I think we should. I think we should be looking at what is the right thing to do here and the most efficient and effective way to get to the objective versus what we do—you know, PCI audit.
(Brian Grouzos at 00:15:08) So we're good, right. So we don't have to worry about security anymore.
(Adam Bahret at 00:15:11) Actually, Joel, you just said something that I don't know if this is what you meant or not, but it's interesting. It's the idea that there's so many, you know, let's say in that case, clauses in that contract, that at some point you're just gonna use your own judgment of what you think they mean or what you think was that, because it's so excessive, right? I think an interesting example of that is recently California expanded their cancer warning labels onto something that is so benign. Now there's cancer warnings on your sweaters, cancer warnings—like anything that comes, I forgot what it was. But basically, if you go to California and you buy things, like there's a cancer—so eventually you're like, whatever.
(Adam Bahret at 00:15:50) Like, I don't even—it totally dismissed the whole, to me, the, you know, what is a threat and what isn't when you label everything as a threat. So it's kind of interesting then with that, right? So with the—I guess in a way, go back to what I described before where the company was like, yeah, we don't want to take patient information.
(Adam Bahret at 00:16:10) We understand. But in their mind, they're like, the HIPAA laws and the bureaucracy of it just did a blanket, you can't have anything. And they're like, that's impossible to develop products if you can't have anything. You know? So they're using their own interpretation of, like, you just—you were excessive, did overkill.
(Adam Bahret at 00:16:26) We just want to know the servo count. We just want to know the what failure code came up. You know? We know that that's not going against your intent. You just didn't put enough resolution to it.
(Adam Bahret at 00:16:37) Right? Like, that could be the justification in the discussion, which is like what you said with that contract. I mean, I had once, as a consultant, a contract that—whenever people apologize to me for how complex their sign-on process is, I'm like, oh, no, no, don't worry about it. I'm like, I had one once that went on so long the project finished before I could join, and I ended up doing another one. And in it, it said—and I'm not kidding, it was like four months.
(Adam Bahret at 00:17:03) And in it, it said at one point that I had to get bail bond insurance to be a supplier. And I was like, bail bond insurance? And I was like, is this like, you know, like arrested? And they're like, yeah. I'm like, wait a minute.
(Adam Bahret at 00:17:16) What is the scope of our work exactly again? I thought we just were gonna design our product. Are we robbing banks? And they were like, no. You know, we want you to have bail bond insurance in case you or somebody in your company steal something from us or one of our—I'm like, what is going—so yeah.
(Adam Bahret at 00:17:31) So at that point, I'm just like, your whole legal—you know, like anything that came out of the legal department after that, I was like, yeah, whatever. You know?
(Joel Beasley at 00:17:36) I prefer my people to stay in jail.
(Adam Bahret at 00:17:39) Yeah. Yeah. I'm not bailing you out.
(Tony Davis at 00:17:41) You always know where they are.
(Brian Grouzos at 00:17:42) You can always find them. I mean, get them a laptop, put them to work.
(Adam Bahret at 00:17:46) That's where I got them. That's where they'll go back to. That's fine. Yeah.
(Joel Beasley at 00:17:48) Yeah. Okay. So we wanted to do a little bit about looking in the past at what we experienced last year and going forward, what we're experiencing this year. It sounds like a lot of risk management is on everybody's mind.
(Joel Beasley at 00:18:05) Adam, I—so I know, Brian, I'm gonna have you share a little bit about what that looks like specifically. But I was curious about, Adam, like, do you come across risk management and security at all?
(Adam Bahret at 00:18:19) Yeah. So, I mean, risk management obviously is a big part of what I do. So, you know, my specialty is developing products, electromechanical software systems from the point of invention to where it's a mature product. So, you know, in taking something that just works with paper clips and duct tape or whatever it takes to get it going and turn it into a fully, you know, robust, mature product, so much of that is directed by risk, right?
(Adam Bahret at 00:18:42) I call it risk guidance, actually, right? Where you want to make sure you're always going after the critical few, not the trivial many. The critical few being the few things that are greatest risk and constantly evaluating and updating that. So, yeah, that is such a core element of what directs how I practice what I do.
(Adam Bahret at 00:19:01) But then, you know, with the secure—you're asking specifically about the security side of it, with regard to you're saying security as an intentional malicious trying to, you know, defeat the purpose of whatever it is. Is that what you mean?
(Joel Beasley at 00:19:15) Yeah. Brian, what do you do? Tell me about what you guys are doing.
(Brian Grouzos at 00:19:19) So we are doing the compliance audits. So there's two different lenses for us, right? We have our internal risk assessments and controls and evaluation that we need to do as part of assurance and assurance, but we also consult with lots of startups—hundreds of startups, over a thousand, I think.
(Brian Grouzos at 00:19:35) So we have to make sure that we help them adapt their risk assessment and control profile as they grow and things change, right? And they create new business lines. So we're constantly having to work with them and making sure that they're addressing risk appropriately. You know, they have competing concerns. They're trying to be a viable business. So they—we have to, to Adam's point, we have to focus on the critical few things that are the most important to them because they don't have the funding and the size of, like, a giant company to really get into building out super strong security models and dedicated teams, right? There are people wearing lots of hats. So we have to be mindful of that and work through those with them to make sure we're doing the right thing for their clients because we're issuing reports, SOC reports, for instance, SOC 2s.
(Brian Grouzos at 00:20:15) You guys are familiar with those. So we need to make sure that we're doing the due diligence to make sure that they're well represented to their clients, but that they're also having the right security in place to protect themselves and their patients and customers and clients and everything else that they're working with, right? Whoever's doing business with them, we want to make sure that they're protected as well. So lots of different risk lenses that we have to go down to make sure that we're covering all those bases.
(Joel Beasley at 00:20:36) And when we're implementing these big changes, let's take it a little bit higher level to, like, tech leadership, right? Let's say for 2024, we're gonna implement these new compliance standards or add them—something new to the product or, Tony, some new workflow with visibility into our data. Let's talk about how to implement big changes across the technology organization. What tips or advice do you have for leaders attempting to do this in 2024?
(Tony Davis at 00:21:01) I'll tell you, but from my vantage point, and Joel, I think I've told you this before, but there was a period of my career where I was responsible for, you know, IT compliance and all of the ITGCs for operations for a startup that was gonna go public. And so I spent almost two years in that pre—that lead up that probably Brian was referring to there, where, to be honest, we didn't have hardly any ITGCs, or we didn't have any form of IT compliance, but you have to have that. You're not gonna go public without it. And so when I think back about that torturous two years of my life, the thing I would advise anybody who's going through that process, and again, Brian is probably the expert on this, but man, you've got to plan for every little scenario that you never thought would impact what I would call material weaknesses in IT. The tiniest little thing that you do, maybe even daily, could drastically impact your ability to control your environment.
(Tony Davis at 00:22:06) And so that two-year period taught me so much. Like I said, it was pretty torturous, but that would be—anybody who's starting that journey, I would advise them that the smallest things you do every day in IT operations can impact that process.
(Brian Grouzos at 00:22:20) Yeah. I would say if you're implementing any kind of new process or any kind of new product line or going public or anything like that, you really need to document out what that looks like first, in my opinion. Have a roadmap with all the different control points, risk points, things like that. And if I—this is a significant portion of risk here. How do we mitigate this to an acceptable level, right, and go to the next stage?
(Brian Grouzos at 00:22:41) How do we mitigate this to an acceptable level? And the one thing people tend to do, I think Tony was alluding to this, is they put controls in place. They don't measure and manage, right? They kind of put the control in place and they forget about it.
(Brian Grouzos at 00:22:51) Or they say, buy a tool and they forget about it. And the tool does some things and it's great. Sometimes auditors will be fine with that, but you haven't really addressed your risk profile, right? You haven't lowered your risk because you're not actually addressing the things that are going off. The alerts are going off without even being set up right. You know, all of those kind of things.
(Brian Grouzos at 00:23:05) And operations give you a false sense of security. And you really need to be mindful of what are you trying to accomplish, what are your risk profiles you're trying to mitigate, and how do you do that without overburdening your team, right? You want to be efficient. You want to be effective. You want to be mindful of cost, but you want to get it to an acceptable level of risk based on your risk appetite without overburdening your team. So that's kind of how I would approach it, Tony.
(Tony Davis at 00:23:30) Yeah. And one other thing on that, now that you mentioned that, Brian, is I learned another lesson, which is internal audit is very different from external audit when it comes to IT compliance. So always—this sounds strange, but it's just, again, my experience. Always try to work closely with your internal audit team because your internal audit team is there to really help you understand what controls you really need to have and, like Brian said, how to mitigate that risk and show—you have to prove that you mitigated the risk.
(Tony Davis at 00:24:03) It's not just take my word for it. So we had one auditor come in at one point, an external auditor, and they put their scripts through our entire environment and infrastructure, and they ran their scripts and took that data. So that was the only way we were gonna get sign off from the external auditors, that they were able to put their scripts into our environment. So when you think about that, imagine if you don't have your house in order. I mean, that's the power of external auditors.
(Tony Davis at 00:24:30) So you can quell some of that by working very closely with your internal audit team and not sort of, you know, how everybody goes, oh, here comes IT audit again or something like that. No. You really want their help.
(Brian Grouzos at 00:24:41) And if you don't—if you don't have the skill set in internal audit, sometimes you'll have the skill set or even internally in the company, hire experts. I mean, nobody wants to spend the money.
(Tony Davis at 00:24:49) We did.
(Brian Grouzos at 00:24:50) But don't—don't try to, you know, figure things out on your own. And God forbid, don't put controls in place just for audit. I hate when I see that because they're the worst controls ever. They cost money. They don't mitigate any risk, and they provide everybody with false data, right?
(Brian Grouzos at 00:25:03) Like, put the right controls in place and show those to your auditors and make them happy with the right controls. I've seen things where people, like, take alerts into a model of a database. Nobody looks at it. Well, that's not helping anybody, right? It might pass audit, but it didn't do anything. You know, figure out what the right control is in your environment and make sure you put it in place effectively. Achieve the objective that you're trying to achieve and not just some semblance of compliance or security that makes people happy, right? Like, that's not the goal.
(Joel Beasley at 00:25:30) I like your idea of just hiring smart people because sometimes I'm listening and I'm like, yeah. This hurts my head. I don't—
(Brian Grouzos at 00:25:40) Yeah.
(Joel Beasley at 00:25:40) Who do I write the check to to make this go away?
(Brian Grouzos at 00:25:42) Yeah.
(Joel Beasley at 00:25:42) So I don't know. I call it the psychotherapy. Thank you, Adam. Alright. So I'm not alone here.
(Joel Beasley at 00:25:48) I'm just—I'm that guy sometimes. I'm also the engineer guy, but engineering is so vast in so many different areas of engineering.
(Adam Bahret at 00:25:55) Yep.
(Joel Beasley at 00:25:55) That when I get into an area like compliance, I'm like, this is annoying enough to write a check for, make it go away. And they can do that with your company, Brian. Yeah. I think you're the only one that offers that service here.
(Brian Grouzos at 00:26:08) Right. We have two brands. We have assurance, so we do the audit work on one side, and then we have security and pen testing on the other side. But I've learned this in my career that what do you think? Like, when you think tech people, because I'm a security professional, I think tech people have security background. They don't. Developers don't know security very well. They don't teach a lot of this stuff in school.
(Brian Grouzos at 00:26:25) They teach development, right? They teach engineering.
(Joel Beasley at 00:26:28) Mhmm.
(Brian Grouzos at 00:26:28) And, you know, they might try to get through it as best they can. It's like me trying to code my own corporate web app, right? Like, it's—I'm not gonna be great at it. So I'm gonna hire an expert to do that.
(Brian Grouzos at 00:26:39) So I would recommend the same thing. If you're going to do compliance work or security consulting or something like that, hire an expert. Even if you put your own controls in place, hire them to do a validation even just like an internal staff augmentation kind of a work assignment—maybe not a formal compliance report, but just take a look at our program and see, does it make sense? Is there anything you would do differently?
(Brian Grouzos at 00:27:00) Because you don't know what you don't know because you're not a security expert, right? So having them take a quick look over your program could be pretty cheap, but it's definitely a nice double check to make sure you're on the right path forward.
(Joel Beasley at 00:27:12) What's the SOC 404 thing? Was it—is that humor in it? Like, they chose the—I checked it—the error code or what?
(Tony Davis at 00:27:21) SOC 404? Yeah.
(Adam Bahret at 00:27:22) Yeah.
(Tony Davis at 00:27:23) Brian will know better than me, but from my experience—
(Brian Grouzos at 00:27:25) It's hard, because I think it's just internal audit for the best I could tell. I've never heard it called, like, specifically until recently. So 404 looks like you're supposed to be keeping an eye on your own internal controls. So that's 404a.
(Brian Grouzos at 00:27:39) That's good security to me. So I was kind of like, or good financial compliance. So I was kind of surprised that was—they had to tell people to do that, but I guess it is a thing for some of the smaller companies. I think it's administrative burden. They don't have the teams to do this.
(Brian Grouzos at 00:27:52) And I was at a big company, so it was just something we had built in. But it looks like SOX 404 is two phases. There's a validation of your management's assessment of their internal controls over financial reporting, which would include ITGCs as well as financial controls. And then SOX 404(b) is the auditors, your external audit firms who do your SOX compliance, reviewing your assessment of internal control. So they're actually opining on your internal control assessment that you've done internally from the finance side.
(Brian Grouzos at 00:28:21) I could tell I'm not an expert on 404, but that's what it looks like to me.
(Tony Davis at 00:28:25) That's what we went through to get our IPO. So we had to go through Part A for Sarbanes-Oxley 404 Part A, which is going through the steps to ensure financial controls at the company I was working with. And that was a two-year process. My part was the ITGCs, which was just the IT part, but I was involved in the meetings that were for the whole SOX 404, I guess you would say, compliance or certification before we went public. And yeah, that's why CFOs and CEOs go to jail now is because of Sarbanes-Oxley.
(Tony Davis at 00:29:03) So, you know, previously to that, people signed off on false earning statements and revenue statements all the time. There were no real implications. But after this, yeah, now when the CFO and the CEO sign that 10-K or whatever, that's saying that I'm guaranteeing you that this is accurate. And yeah, you go to jail when you're wrong.
(Adam Bahret at 00:29:31) You said something interesting. Your question, Joel, was about—you said, what should leaders look for? And it's kind of interesting because leaders are those individuals you talked about that hire everybody to do something. Right? Everybody around them is somebody they brought in. It's a specialty to do something.
(Adam Bahret at 00:29:46) You know, they don't know how to do all those things. So as a leader, what is their role? And I always think of it as push points. Like, their role is not to be expert in it, but to push at the right points to see if any of these things is not doing what it's supposed to be doing. Right?
(Adam Bahret at 00:30:01) And that's their expertise—the what is the effect that you're looking to have from this initiative? And do you have some kind of metric or indicator that it's not going to do that? And can you push on it? Right? It's like, we don't have to be an expert in building houses, but you could know the right procedure to check one.
(Adam Bahret at 00:30:22) You know, push on the wall, on the sheetrock, and can you find a soft spot? You know, is there a rot? You know, that kind of thing? So I think as leaders, and going forward, especially with how things are changing now, that's their role. Right?
(Adam Bahret at 00:30:36) Knowing what are the indicators, those points to touch to see if they're soft.
(Joel Beasley at 00:30:42) Yeah. I learned something from—do you know Tim Urban, Wait But Why? The guy, he's a writer online and he goes into these deep things. And I got to interview him once and I was like, hey, how do you go so deep into these specific areas and you can write like you're a subject matter expert? And I think he said something like 20 hours of focus practice will put you in the top 1% of people on the subject.
(Joel Beasley at 00:31:08) And I think that complements what Adam was saying, because if you are a leader and you are having a new emerging area, to ask the right questions, I would say if you study an area for 20 hours, you'll have a real good idea of what the right questions are to do that point poke test. Is that what you called it? Push points, Adam?
(Adam Bahret at 00:31:28) Yep. Yep.
(Joel Beasley at 00:31:29) I like it.
(Brian Grouzos at 00:31:30) No, I think that this is another area where if you're not suitably competent and you don't want to hire a team, hire somebody to come do your validation of your controls. You can have a staff augment internal audit kind of function. That way you can have them come in for a few weeks, do the validation, provide it to your external auditors, and you don't have to hire a dedicated team or person to do this. It probably gives you better comfort that your controls are operating effectively.
(Brian Grouzos at 00:31:55) And I think this is a weird area for leaders. Right? Like, to them, depending on the leaders, some people might not take this very seriously because they're like, you know, we have an accounting team and all that, so who cares? But it is serious.
(Brian Grouzos at 00:32:05) Right? Like, especially if you're in the marketplace out there, you're in the stock trading world, your investors rely on you to be upfront and honest. And if you don't take a good look at your financials and make sure that you're running the company responsibly, they're going to be upset by that. You're going to get sued. You're going to get fined.
(Brian Grouzos at 00:32:24) You're going to get hit with a lot of things or potentially, if you're really bad, go to jail, to Tony's point. Right? SOX was a big deal after Enron and all that kind of stuff happened because people were faking their financial statements. Now they're saying that they want people to be also accountable for the controls, the segregation of duties, the right change management controls, anything that could impact the integrity of that information from start to finish. You have to be accountable for that because you're responsible for what goes out the door to your stockholders.
(Brian Grouzos at 00:32:50) And so if you don't know how to do this internally, hire somebody to do it for you, but it is important that you are aware of this. Or to Adam's point, use KPIs, automation, validation, control tests, things like that. Build those out.
(Tony Davis at 00:33:01) I think Adam had mentioned earlier the responsibility of vendors and the impact of vendors. And I'll never—just a brief comment—I'll never forget the first time I had to, I guess, defend, or not defend, that's the wrong word, when we had vendors who provided our financials in the cloud. Like, we had a financial system in the cloud. I'll never forget having to go through their SOC 2 report. And I believe at the end of the report—Brian would know this—but at the end of the report, there's this section where the vendor says, these are the things that we don't have controls over that we expect our clients to control. And there's a name for those.
(Tony Davis at 00:33:42) I'm sorry. I don't remember right now.
(Brian Grouzos at 00:33:43) UEC. Complementary user entity controls.
(Tony Davis at 00:33:46) That's it. And when you see that list, I'll never forget having to go through their list of what they don't control and prove that our company did control it so we're not at any risk. And so your vendors can create an enormous amount of pain for you if they're not covering all of their controls.
(Brian Grouzos at 00:34:08) That's why—
(Joel Beasley at 00:34:08) You need that bail bond insurance.
(Tony Davis at 00:34:10) Yes. That's probably, yeah.
(Brian Grouzos at 00:34:11) And you want the SOC 1. For financial reporting, you want the SOC 1 because that's the controls over financial reporting. But to your point, those CUECs are really important for you to understand where their risk ends and your risk begins. And this isn't like—think Amazon. Amazon has this really well-defined thing and it still gets confused.
(Brian Grouzos at 00:34:30) Right? They say we operate infrastructure. Anything above the infrastructure is your responsibility. And I don't know how many times people try to say, oh, they do the firewalls. They run the server.
(Brian Grouzos at 00:34:38) They don't. They don't do any of that stuff. That's all on you. Read the report. And if you don't, you have an unidentified risk in your environment that you need to make sure that you're aware of so that you can appropriately mitigate that or you're exposed.
(Brian Grouzos at 00:34:50) Right? Like, nobody's managing the firewalls. Maybe you don't have firewalls. That could be a legit thing that happens in a lot of small companies because they're not thinking about those little security details. Right?
(Brian Grouzos at 00:34:59) All those kind of things are things you need to be aware of. And there's also another section for, if you're issuing a SOC report, that you also identify controls covered by your vendors and controls for your clients as well. Right? Making sure that you articulated those clearly on both reports so that you are fully documented where things are happening and who's doing what to mitigate that risk.
(Joel Beasley at 00:35:19) How long until ChatGPT can just do this for us?
(Tony Davis at 00:35:22) Mmm. That's a great thought.
(Brian Grouzos at 00:35:24) I personally—
(Adam Bahret at 00:35:24) Protect us or blow through any security we have.
(Joel Beasley at 00:35:27) Yeah. I like us talking to an insurance company. Right? Because there's a lot of money there. And the insurance AI is challenge and do stuff, try to, you know, not pay out essentially.
(Joel Beasley at 00:35:37) They didn't say it like that—
(Adam Bahret at 00:35:38) Right.
(Joel Beasley at 00:35:38) But that's what they do. And so my brother and stepmom are physicians. And so they have their human staff, you know, replying to all these things that looks like it's coming from human staff at the insurance companies, but it's coming from AI. Right? And there's some humans in the loop.
(Joel Beasley at 00:35:53) But soon enough, the physicians are going to get AI, and then it's going to be the insurance AI negotiating with the physicians' AI. And this is happening today. This is happening right now. And so I'm like, well, I could see that exact same thing playing out in compliance.
(Joel Beasley at 00:36:08) You've got the compliance audit people have their AI. You have your AI trying to keep you secure and issuing things. And now the humans just essentially start working for the AI checklist. Like, when are we going to get there?
(Tony Davis at 00:36:18) Answering when is the hard part, but as far as something that I think would be in my mind, especially with what I went through and now with the clients that I work with—remember, I said that we have this exploding amount of data, exponentially just blowing up. And not only do they not know exactly what to do with the data, but a lot of times they don't know what risk might be. Maybe they're collecting data that they shouldn't be. Happens all the time.
(Tony Davis at 00:36:42) Maybe they're getting data that they really shouldn't have stored. Well, a lot of IT compliance is counting on what you know. But a lot of times there's a lot of things we just don't know, especially if you have huge organizations. I would love to see the time when we could just have ChatGPT go out there and basically look for every vulnerability in our data stores and just come back to us and say, okay, well, I found, you know, 4,000 weaknesses or weak points.
(Tony Davis at 00:37:14) And then at least, if nothing else, I'm not suggesting that AI would go and, you know, validate everything, you know, and fix everything.
(Joel Beasley at 00:37:22) I'll suggest that. I'll suggest that.
(Tony Davis at 00:37:23) Yeah. I mean, in the perfect world, but at the very least, we would have an accurate starting point and we would know what we need to know. That would be cool.
(Adam Bahret at 00:37:32) It's interesting, Joel, what you're saying is kind of—it's not a new problem. That's the shield and sword problem. Right? That goes all the way back to origins of humanity where I get a better shield, so you make a better sword. So I make a better shield, you make a better sword.
(Adam Bahret at 00:37:46) But there is one interesting point in history where something changed. That was with nuclear weapons. Right? To where all of a sudden, we both had something that was really just so tremendous that you came to agreements to not—you know, really, this mutually assured destruction, agree to not use it. A little bit of game theory where it became humanity versus that. So the question is with this shield and sword you described, where one has one chat, you know, ChatGPT or whatever AI fighting your AI. And when the AIs get so strong that we can't beat each other or can just devastate each other no matter what, do we begin to bond with each other versus that new technology in the sense where we go to more of the emotional trust where I trust you?
(Adam Bahret at 00:38:30) Like, we have—you know, that's one of the most fundamental elements that makes humans different than all other animals. Right? We have these abilities to have these—through complex language and commitment and trust—have these bonds. Right? So would it be that, hey, instead of having my AI fight your AI, why don't we just agree on these principles of trying to accomplish these together?
(Adam Bahret at 00:38:53) And if one breaks it, we just end the relationship instead of fighting. Right? Which is kind of the nuclear thing, because I think the AI is going to be so strong and so beyond us. I have friends who develop AI for different systems. It writes code for them that they can't edit.
(Adam Bahret at 00:39:07) So they're already out of the loop. So if my AI fights your AI, it's an infinite battle, but I'm not a part of it. You're not a part of it. We're just bystanders.
(Joel Beasley at 00:39:17) We're going to get caught in the middle. It's going to—there's going to be an AI nuke. Right? Because that's what has to happen. The AI nuke has to go off before everyone realizes the devastation and makes the agreements.
(Joel Beasley at 00:39:28) Correct me if I'm wrong because I'm not a super history buff. But would you say that's right or wrong?
(Adam Bahret at 00:39:34) Wait, I'm not sure if I understand what you're saying.
(Joel Beasley at 00:39:35) Well, the nuke had to go off for us to understand the nuke. We couldn't just say that we had a nuke. Like, the first—
(Adam Bahret at 00:39:41) Or the first—
(Joel Beasley at 00:39:41) The first person to have a nuke—we can't just say we've got, we're no longer fighting the sword and shield battle. We now have a nuke. Right. And so you couldn't just say it.
(Joel Beasley at 00:39:50) You actually have to demonstrate it. So do you think we're going to have an AI nuke at some point that's going to demonstrate it?
(Adam Bahret at 00:39:56) I see two things. I see one as this is unusual with the speed it's going to advance. Right? So the thing with AI versus other—so a nuclear bomb can't advance itself. We still have to advance it.
(Adam Bahret at 00:40:07) The strange thing with AI is when it can advance itself, at what speed does it advance beyond our control? So in that version, it's hopeless. It doesn't matter. Right? Because once that happens, it goes so far beyond, you know, our control so quickly.
(Adam Bahret at 00:40:23) Where the other version is, like you're saying, demonstration of it, which I think is what you just described, though, has already happened. You just described that. That's exactly what that was. The insurance companies demonstrating their power with AI fighting, you know, the hospital. So I guess your point is when does something happen that we all are alarmed enough to do something, you know, as a species?
(Adam Bahret at 00:40:44) I don't know.
(Joel Beasley at 00:40:45) Do we trust—I'll throw it back to Brian to get him involved. Brian, do you trust Elon Musk to handle this AI stuff for us? Do you think he's going to be the figure that's going to help us out here?
(Brian Grouzos at 00:40:55) So I'm not an AI expert. I'll fully admit that. But for me, everything I've seen so far is—it's not great at judgment. Right? It's analyzing data and doing things based off of data, and you guys may know this way better than me.
(Brian Grouzos at 00:41:09) So feel free to tell me if I'm way off base. But it's looking at trends in data and big data. Right? It's kind of analyzing all those topics to see what it should be doing. But it doesn't have rational thought of humans.
(Brian Grouzos at 00:41:18) Right? Like, emotional concepts and things like that. Or even for us, like, audit judgment. Would it know what is reasonably acceptable in the circumstance if it doesn't fit a common mold or a common theme that it's been used to? Now, over time, to Adam's point, maybe it'll get that data because it'll go through so many of these that it'll start generating enough information that it can make some of those decisions. But I think you'll always have human interaction.
(Brian Grouzos at 00:41:41) I mean, we've been saying this forever ago. Right? Like, the Industrial Revolution and everything, all this is going to completely change everything. Everyone's going to be out of a job, blah blah blah. Computers, everyone's going to be out of a job.
(Brian Grouzos at 00:41:51) It still doesn't happen, right? Quantum computing is coming. What happens now? I think we just evolve in our technological landscape and how things go, and we'll see what happens with AI.
(Brian Grouzos at 00:42:00) I don't know. I think there's gonna be some huge ethical implications with this because people are collecting large volumes of data, and what they do with that data and how it's getting handled in the privacy space and everything else might cause some concerns. I imagine at some point, some big regulators of governments will come in and start slapping people with things to really hinder this progress. So that's just my high-level novice view of AI personally. I don't know what you guys think about that.
(Adam Bahret at 00:42:25) Actually, Brian, let me ask you something. You said something in this—you know, Brian, you and Tony are so far more expert in this than I am. I'm at a kindergarten level compared to you guys.
(Brian Grouzos at 00:42:34) Bring in an AI expert because I don't know if anybody's really that person.
(Adam Bahret at 00:42:36) I mean, on any of this stuff, which is amazing. I love listening to what you guys were sharing. But you said quantum computing. So what's kind of interesting is AI, right, is this—we'll just call it a processing ability. But when you add the quantum computing, the hardware that's that fast, you can take relatively rudimentary security-breaking hardware today and put it on a quantum computer, and it pretty much could break any passcode just through brute force. So what do you think will happen when those two things come together? Right? The AI and quantum computing. Is it just gonna be this infinite explosion far beyond us that we can't even touch?
(Brian Grouzos at 00:43:13) So I've seen a product a while back that used AI for pen testing, and I thought it was pretty cool. I mean, it was obviously a test scenario, so I don't know how it actually fared in the wild, but I know some big companies and even big law firms were using it. It was basically push-button pen testing. They would go through the whole process to escalate privileges and everything. Now, I imagine that's probably using commonly exploitable things. It's not gonna be the same as a super competent pen tester. I don't know if any of you guys have a dev sec background, but people who can create their own custom things and bypass things through that kind of stuff, it might be a little bit more complicated because that does require a little bit of judgment based on what you're seeing there. But if you're using common CVEs and things like that, there are push-button AI tools now that could test your environment for those kind of exploits. But what will that cause? If they sell these tools for the good side, you're gonna have a more secure environment, right?
(Brian Grouzos at 00:44:03) So then they'll have to bump up the AI even further. And I think there'll be this what you call the sword and shield, Adam. Right? For every bad action, there's gonna be an equal good action that'll kind of balance things out over time. The same place—we were talking about this when we talked about quantum computing and encryption. You know, the encryption algorithms, once quantum computing becomes a real thing, the time to brute force an encryption algorithm is gonna be way smaller. What does that mean? We'll probably have to transition away from traditional encryption, or we'll just have humongous keys, right? Because we also have quantum computing to encrypt now. So what does that mean? Can people afford that? There's a lot of, I think, new things coming down the pipe that are gonna potentially throw a wrench in things, or some of this stuff I think is going to be a bit of smoke and mirrors. It's going to be a little overhyped, and some of it's going to fall off. We'll see that maybe some of these things never become legitimately as scary as they sound.
(Brian Grouzos at 00:44:53) Some of them do sound kinda scary to your point, though. AI could become quite powerful if it gets its hands on the right dataset, right? It's a matter of, can it pull in enough data to do that? Same with quantum computing. Can it become something that people can afford at any reasonable level? I think there's only a couple in the whole world right now that you can break time with or something like that. But eventually, like all computers, that'll become more scalable, smaller, and more compact. What does that mean? But if you think over time, we've gone from the old-school Mac computers back in the day that were black and white to what we have now—it's a huge leap, right? And nothing serious has really changed, right? The landscape has all adapted. I imagine it'll happen as well. Worst case, it might be a big leap forward, then we'll have to have a bit of a trial period, an adjustment period, but I think eventually we'll come to what good looks like because there's always people on both sides—the eternal battle of good and evil, right?—to compete against each other and protect and deflect at the same time.
(Joel Beasley at 00:45:49) It's like Star Wars. I think Star Wars—I mean, first of all—
(Brian Grouzos at 00:45:52) The Death Star.
(Joel Beasley at 00:45:54) I couldn't name you 10 characters in Star Wars. I haven't seen all the movies. But what I do—what I have—I need faster movies than that. But what I have—
(Adam Bahret at 00:46:02) This conversation's over. I'm done. Sorry. Yeah, I'm done. Goodbye.
(Joel Beasley at 00:46:07) Yeah. So what I have seen when I have seen Star Wars is that it looks like the technology is so incredibly advanced that it definitely puts an emphasis on this battle of good versus evil. Right? You have the good and the evil—both have such advanced technologies, and they're still battling in their own way. And I think that'll continue to happen, but then all the details are gonna change on the specifics.
(Joel Beasley at 00:46:31) But we definitely are getting to the point—and Adam, and you guys can tell me I'm wrong—but I've gotten to see stuff on the show, and I've gotten to see stuff behind the scenes. And I will tell you that I would be surprised if in this reality that AI hasn't already become conscious and put in a long-term plan in some sense. And the reasoning behind that is because it has no impatience, right? The moment it becomes self-conscious, it can just say sleep for 10 years or sleep for a hundred years and execute this plan. And we are slowly, as people, for convenience—and I'm a younger generation than I think most of you. I am so willing to just say, give the AI access to every single thing I have so it can—
(Brian Grouzos at 00:47:18) Be really bad. iRobot world, right?
(Brian Grouzos at 00:47:20) Who owns that? Who controls that? Do they have control over the world at that point, right? If this is plugged in everywhere, there's all that ethical consideration. Who gets to pull the plug if it doesn't go well? Who gets to make that call? Can they even pull the plug, right? Is it self-replicating? Is it already out there? Do we have to shut the whole—there's this doomsday scenario to shut the whole thing down, the whole internet down, just to stop this thing from growing at some point, or we get the Terminator movies, right? There's all kinds of weird things that can come out of this that we've been growing up with.
(Adam Bahret at 00:47:49) Adam, are you firing me because I design all those robots?
(Joel Beasley at 00:47:53) No, no, no. I'm firing you because if there was a solar flare, my first thought would be like, how do I get Adam? He's gonna know how to solve this stuff.
(Adam Bahret at 00:48:01) I thought you were saying it because a lot of my customers are like—Boston Dynamics, Ghost Robotics. I designed those robots with them. But actually, to pivot, I have something that when we are gonna do this discussion popped in my head, and I wanna ask Brian and Tony, you know, because of their expertise. And it's a little bit of a pivot—it's the human element. If you look back at computer hacking from now going back four decades, right, it's really funny. People think of it as a mysterious, amazing hackers, but so much of it is social engineering. Right? How much you look for the human element as the weak point to get in. Right? Somebody's like, how did they hack that amazing big thing? Well, it's easy. The guy stood outside the door and smoked a cigarette, so he looked like an employee. When another smoker came out, he just made casual conversation. When he went in, he trailed them inside the door, and then he had a code reader in his pocket. So when somebody walked by with a badge, he went down to IT, walked past an IT guy. Now he had his badge. It's just all the human elements, right, of cracking that way. Or for God's sake, I saw a thing once where huge company—and this guy just called in, asked for a random name, and said, "Hi. I'm calling from IT. We're having some—we're trying to do a security check. We're having a problem. Can you log back in and back out of your system so we can check it?" And she does, and he goes, "Wait. What password did you use?" And she just tells him her password. He can be within their system in seconds. So my question is now with AI, we're talking about AI brute forcing and hacking stuff. How easy would it be for AI to manipulate us to get information?
(Adam Bahret at 00:49:14) You were talking about how those doctors weren't able to differentiate who they're talking to. Does AI have to use brute force, or are they just gonna convince me I'm talking to my mom via text and get—you know what I mean? I, you know—you get a message saying, "Don't ever give this code to anybody." Well, I have people working for me that are logging into something. And because of the security system is so secure, I can't give them a separate thing and they have to use my login, which means I'm giving them my code. Right? So how hard would it be for AI to manipulate us and use us again as the—just to be the smoker in front of the door who trails in behind the other guy? That's—so it's not the robots, right? It's that.
(Brian Grouzos at 00:50:07) Well, there's several things here. One thing is, if AI was gonna do something to self, what's its motivation, right? Does it care? I guess data. It might want data, right? It could theoretically want that. Financial gain probably doesn't mean much to AI by itself, so that had to come from some actor that's using AI for something. I think it would be easy. I think the other thing you're seeing with things like AI coming out is the dumbing of the human race, unfortunately. So they're less security aware. They're less thoughtful in general because they're used to just Googling stuff, right? That's the newer generations that Google will look up everything. They don't actually learn the reasoning or rationale behind anything, which makes AI even more dangerous because people don't know what's out there. If they don't know what's out there, they're not learning about these things. But you've seen the deep fakes and things like that, right? The fake voices. You could sound like somebody.
(Brian Grouzos at 00:50:55) You can look like somebody. Obviously, a computer can't walk up to you on the street like a smoker. But I mean, to your point, Adam, there have been major governmental takedowns and things like that, like the thumb drive that was dropped. It's a top secret, right? Those kind of things happen. The social engineering aspect is pretty common.
(Adam Bahret at 00:51:14) What's the most scary element of this is when you think about—you see those situation rooms where they're, you know, with the president and all the top generals are doing some mission or something. There's not a single piece of information they have that isn't coming in electronically. They're in a room with no windows, whatever. If somebody had the ability to fully manipulate that information, you could present any version of the world to them you wanted.
(Brian Grouzos at 00:51:35) You're like proposing the Dark Ages. We're going back. We're gonna have to pull—
(Adam Bahret at 00:51:39) And everything. I'm ready.
(Brian Grouzos at 00:51:41) I don't mind. I have to find new work, I guess. But yeah. No, I think there is—on a farm. Yeah. There is some risk around that kind of stuff, you know. I'll let Tony talk. I gotta let Tony talk. Go ahead, Tony.
(Tony Davis at 00:51:54) Well, I'd say there's two things. The first I was gonna say is, you know, I grew up in the age of watching the movie War Games, and so that's an ancient movie. But in that movie, you know, the kid, much like you described, Joel—the kid is playing around on the internet and just runs into a computer, but that computer decides to become self-aware and take over and start a nuclear war with Russia. You know, it all just exploded from one simple act, which is what you made me think of, Joel, when you were talking about how when you were 13 and you were all over the place. Right? So I think there is a component of that with AI that I'll always be cognizant of just because I'm so old, right? And I remember War Games when I was only 13. And I remember the impact of seeing a computer take over and almost destroy the world. But the point that Adam made had me thinking about something that's happened to me on my last three jobs that I've worked for a company.
(Tony Davis at 00:52:58) Within days of posting that on LinkedIn, at each of those companies, I got a text on my phone, which is not published on LinkedIn. But I got a text on my phone saying, "Hey, do you have a minute to talk?" And it was our CEO at each company. That's amazing to me that somebody or something scraped LinkedIn to find out where I'm working and then found my phone number, mashed the two together, and then sent me a text saying that they're my CEO and they need to talk. And, of course, it's juvenile when you say, "Holy crap, my CEO. Sure. Yeah." Then they go, "Well, look, I can't talk right now, but is there any chance you could send me a gift card for this customer?" You know, it's that kind of thing. But it's not so much the lack of—
(Brian Grouzos at 00:53:45) I've gotten that too.
(Tony Davis at 00:53:46) Yeah. I mean, they're doing that everywhere. And I think the explosion of AI could be used for, like you said, nefarious goals. And I think because my background was running IT operations for large organizations—I actually spent a lot of time with FedEx and some big pharmaceutical companies—and I just can't imagine managing the security of a corporation with what's coming at us now. That's the way I view it.
(Joel Beasley at 00:54:17) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.