Episode 338 ·

Tony Sager - The Center for Internet Security, & the Role of Non-Profits in Cyber Defense

Today we are talking to Tony Sager, the SVP and Chief Evangelist at the Center for Internet Security. And we discuss the role of nonprofit organizations in national cyber defense. Why we need to simplify the resources at our disposal for cybersecurity, and how we can prepare ourselves against the repeatable kinds of attacks that happen every day.

All of this, right here, right now on the Modern CTO Podcast!

To learn more about the Center for Internet Security, check them out at https://www.cisecurity.org/

About Tony Sager:

Sager is a Senior Vice President and Chief Evangelist for CIS® (The Center for Internet Security, Inc.). He leads the development of the CIS ControlsTM, a worldwide consensus project to find and support technical best practices in cybersecurity. Sager champions of use of CIS Controls and other solutions gleaned from previous cyber-attacks to improve global cyber defense. He also nurtures CIS’ independent worldwide community of volunteers, encouraging them to make their enterprise, and the connected world, a safer place. In November 2018, he added strategy development and outreach for CIS to his responsibilities.

In addition to his duties for CIS, he is an active volunteer in numerous community service activities: the Board of Directors for the Cybercrime Support Network; and a member of The National Academy of Sciences Cyber Resilience Forum; Advisory Boards for several local schools and colleges; and service on numerous national-level study groups and advisory panels.

Sager retired from the National Security Agency (NSA) after 34 years as an Information Assurance professional. He started his career there in the Communications Security (COMSEC) Intern Program, and worked as a mathematical cryptographer and a software vulnerability analyst. In 2001, Sager led the release of NSA security guidance to the public. He also expanded the NSA’s role in the development of open standards for security. Sager’s awards and commendations at NSA include thePresidential Rank Award at the Meritorious Level, twice, and the NSA Exceptional Civilian Service Award. The groups he led at NSA were also widely recognized for technical and mission excellence with awards from numerous industry sources, including the SANS Institute, SC Magazine, and Government Executive Magazine. Mr. Sager holds a B.A. in Mathematics from Western Maryland College and an M.S.in Computer Science from The Johns Hopkins University.

About The Center for Internet Security:

The Center for Internet Security, Inc. (CIS®) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit, responsible for the CIS Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. elections offices. To learn more, visit CISecurity.org

Transcript

(Joel Beasley at 00:00:01)
Hello, my friends. Today we are talking to Tony, the chief evangelist at the Center for Internet Security, and we discuss the role of nonprofit organizations in national cyber defense, why we need to simplify the resources at our disposal for cybersecurity, and how we can ready ourselves against the repeatable kinds of attacks that happen every day. All of this right here, right now on the Modern CTO Podcast.

(Tony at 00:00:29)
Here we go.

(Joel Beasley at 00:00:30)
This is the Modern CTO Podcast. There he is, the man of the hour, Tony. Hey.

(Tony at 00:00:45)
Hey there, Joel. How are you?

(Joel Beasley at 00:00:47)
Oh, fantastic. Living the dream. How about you?

(Tony at 00:00:51)
Oh, I think I can say the same. I've retired once. It didn't work, so I'm still working. But if it's a dream, you know, it's all good.

(Joel Beasley at 00:01:00)
I love that. When I was getting to research you and learn about you in our prep meeting, I was like, I love people who do that, right? They try to retire, but then they just continue to bring more value to the world.

(Tony at 00:01:11)
It's like a failure club or something like that. But no, it's all good. I'm too young to retire. I mean, I'll be 66 this summer, but I always said I love work. I've always loved work, but I could love it just as much and do much less of it. And that's the plan, is to start winding down here in the next couple of years. But, you know, it's a really exciting time to be in the business, and there's a lot going on. Actually, my youngest child is now in the business, so that's another reason to just hang around for a little bit longer.

(Joel Beasley at 00:01:39)
Do you get to have good conversations with your child about this?

(Tony at 00:01:42)
Yeah. Yeah. He actually works for us. He had joined us about a year ago. He was working with a local consulting company before, but it's boring, but it's fun to talk shop with one of your kids. I have three, and none of them went into technology. They all found their path. My oldest is the associate archivist at the Federal Reserve Bank of New York. My next one is a police officer locally here in Baltimore County, and the youngest actually has a degree in economics. So he's kind of a self-made IT guy and, you know, wanted to be a wildlife economist, save the birds, and there's not a job to be had within 200 miles of DC. So he said, too late to try this IT and security stuff. I said, never too late. In fact, we need some new blood. It's pretty clear my generation has not solved and will not solve a single foundational problem in computer security. So, you know, all the best to you young folks like you, Joel. You guys gotta do better so I can get my retirement check every month.

(Joel Beasley at 00:02:38)
Well, we're really grateful because you created the entire industry.

(Tony at 00:02:44)
I don't know. There's a running joke. Actually, we're about to release a version eight of the CIS controls. I don't know if you follow our stuff, but so I was the version zero. Literally a throwaway afternoon project. No big deal. Two-page letter to my friends at the Pentagon. If you don't know where to begin, start here. And here we are now. We've got a whole company. We got worldwide stuff going on and releasing version eight. It's a big deal. And so I started—I run a very local podcast series for CIS. I said, I'm reminded of that old gag. If I'd have known I was gonna live this long, I'd have taken better care of myself. If I'd have known this was gonna be a big deal, maybe we would have started it differently. But, you know, maybe that was actually the reason for success. So it wasn't a giant government program. It was just trying to help people get started with security. And watching people struggle with, oh my gosh, I'm overwhelmed. Thousands of pages of this from NIST and a thousand pages from there. I got five consultants, and they've given me 25 opinions. People are just overwhelmed by the problem, which is the virtue of ages. You get to see a lot of things come and go. And I just go, man, what's wrong with us here? We got more defensive tools than we've ever had in our history, and yet we're getting worse. Actually, we're getting a little better, but the bad guys are getting better faster than we are. What is it that we're missing despite all the great tools and amazing people and technology and money that goes into the industry? What is it that we're not doing? And so it's not a lack of resources. It's that we're overwhelmed by them, right? The problem is fast-changing. People don't know what to do. There's a gazillion conflicting opinions. So one of the few clever things I've done—I gave a talk in 2014, maybe, at RSA on the fog of more. And it was kind of a pun, specifically. There was a book called "The Fog of War" that I had to read at one point in my career, and it was about the early days of what was then called the information age, right, and warfighting, really high-risk decision-making in very uncertain times. And it went from the government will provide all the information to every general in the U.S. Army is watching CNN feeds of live bombing. It's like, what's going on here? And so this "Fog of War" was about the implications of that for high-risk things, specifically warfighting. And so I was trying to come up with a new theme for an RSA talk, and I look over my bookshelf, and there it is, "The Fog of War." I said, it's a fog of more, right? We're just overwhelmed. And that turned out to be—I got more mileage out of that silly little line. People still walk up to me. You're the fog guy. That was great because now I get it, that we're struggling not because we don't have resources, but because we can't figure out who to trust. So that was a really breakthrough moment for me in my early post-government career to sort of think differently about the problem.

(Joel Beasley at 00:05:41)
Can you give me the most simple explanation of what the company, the CIS, does today?

(Tony at 00:05:49)
Sure. We're a small but mighty nonprofit company, and we have essentially two lines of business. So something less than a half of the company is the Multi-State ISAC, Information Sharing and Analysis Center. So think of it as the big watch center for all state, local, tribal, territorial governments across the U.S., 11,000 member organizations. So it's all the usual things, right? A big room full of big screens and people reporting on bad things are happening in this county and that, and then the analysis, pushing out bulletins, advisories, and so forth. And then we added to that the Elections Infrastructure ISAC a little over two years ago. So that's about a third of the company that's fully sponsored by Homeland Security and funded by them. But I spend my time in what we call security best practices. So the basic model is small company, work with volunteers, sort of figure out what works, right? Track bad guys, track technology, business use of technology, figure out, and kind of back to the spirit of that first two-page letter, right? We're not trying to recreate the great work at NIST. We're trying to say within that, what are the most important things to do? And it turns out most enterprises—this is my observation over a decade or more—can't figure out where to get started. So our focus is within that, what are the most important things to do, both to deal with bad guys and to lay the foundation for defense? So we create that primarily through volunteers. We give it away, no charge, and we fund the nonprofit through a membership model. So if you want support and tools from us, no problem. Pay us a membership fee and you have that. Or you can go to most of the major security tool vendors that license our content, so Tenable, Qualys, those kinds of companies. We also have made a major push into cloud images. So if you want a thousand Windows 10 desktops configured the CIS way, you just go to Amazon Web Services or Google or Microsoft or your favorite cloud provider and get it directly from them instead. And we get a little bit of that.

(Joel Beasley at 00:07:52)
Oh, that's excellent. So you guys went and performed, created partnerships with these large cloud providers?

(Tony at 00:07:56)
Yes. Yeah. Yeah. That's the idea. We're very—I'm sorry, that was a long version of the business model. But, you know, again, most of our principles, the leadership comes from government, right, where we sort of think of this in national security terms. One reason I'm doing this in my second career as a nonprofit is that the goal is to be independent of but cooperative with the marketplace, right? So we're not gonna create the content that is gonna solve this problem. The marketplace will create it, right? But can we organize it? Can we clarify what it does in a way that then the buyer knows what to demand and the seller can provide it? So that's the kind of notion here. And because we're not a government agency, we have a lot more freedom to interact with the vendors, right? We can work directly with them. There's not the issue of the kind of contracting issues that you would have with a government agency and then the need for a bidding process and all that. So our goal is not to have the best list of things to do. The goal is how do I help people do those things, right? You can get a great top 10 list or 20 list or whatever your favorite number is from a hundred sources, right? Wait till October. Every magazine in this business will have a top five things you need to do to blah blah blah, stop ransomware or the top 10 or whatever. And most of them are basically the same if you've looked at those kind of things, right? They're all well-meaning, good stuff. Patch your systems, manage administrative privilege, et cetera. And they're all good, but they're just lists. And at the end of the day, my experience is lists don't change behavior. They're interesting to read, but you're gonna have to take the list. You're gonna have to buy a tool. You're gonna have to train people. You're gonna have to convince the auditor this was the right thing to do. There's a hundred things to do to actually solve the problem that are different than knowing what the problem is or what to do about it. So we try to look at that whole lifecycle of things and say, well, how do we equip the marketplace? How do we make the buyer demand things that are aligned with our recommendation? And so that gives us a lot of freedom to kind of work our way through the whole lifecycle and try to build these improvements in. And we do this again. The amazing thing for us is that no one has to listen to a thing we say, right? We're not a government agency. We're not PCI or ISO. We're not an international standard body. It's a really very grassroots activity that has gone from literally a two-page document to a worldwide sort of thing over quite a few years now. The original list was 2008, I think, was the first meeting. I just grabbed five friends that were really amazing friends and just said I'm giving you the whole story, you're a drill sergeant.

(Joel Beasley at 00:10:29)
Please. No, please.

(Tony at 00:10:31)
But the origin story is, at that time, I was running the major security testing organization for defense at NSA. At that time, I—and I say this with great humility, and it was such an honor—running, I think, what was, I'm sure, the biggest vulnerability finding machine for defense in the U.S. government. I mean, 750 people, something like that, right? All of them kind of doing this stuff from mathematics to computer science, et cetera. And I was making the observation I told you, right? Well, you know, all these great tools, all this great advice everybody's giving, all these great companies out there. We're getting worse. We're not getting better. What's going on? And in 2001, I got permission to release the NSA security guidance to the public through the early days of www.nsa.gov. And the agency still continues that tradition. And what that completely accidentally did was start my public speaking career. You don't go to NSA to have a public speaking career. Believe me. But people started to ask. I got interviewed, got invitations to speak. So I'd go out there and tell a story why we did this because we're good folks. Your taxpayer dollars paid for it, and we're all in this together, right? This is not kumbaya. This is like, here's our contribution, right? Well, the point I was trying to make from NSA was, we're not some mystery think tank here. We live and breathe this stuff like many of you do. And I was watching the emergence of open source and all the open standards and saying, you know, if you wanna show up, you gotta bring your share, right? You gotta bring some content, and that was my view. And so we need to show up with content, not because we're NSA, but because we're participants. So, anyway, so I get out there. I'm giving all these talks, and people started asking me these questions. It's so embarrassing, Joel, but I'm gonna tell you anyway. People would ask me these questions like, where do I start? That's great stuff, Tony, but where do I start? I go, well, you go to NIST. No, no. I can't read that. It's too much. Where do I start? My boss has a limited attention span. I only have one security person. I got a very limited budget. If I don't show some results in 90 days, I'm gonna get fired. Where do I start? And I go, oh my gosh. You can tell. I never had any responsibility to fix a problem. My job was to point people's problems out, right? Here's your failures. Good luck with that. And I thought, but those are the natural questions of someone who is actually responsible to fix the problem. I just changed my thinking completely. That was okay. Came back, grabbed some amazing friends. So the technical leader of the NSA blue team, NSA red team. So these are people that test for a living, test ourselves, right, test the U.S. government systems. Someone who's—I'm one of the few lifelong defenders that lived his career inside a national-class intelligence agency. So to me, that's like going to grad school because you get to watch how nations attack each other, right? You get to see the intelligence, the tracking of the worldwide fight, the early days of that, and then the nation-to-nation fight. So how we attack others, how they attack us. And so I grabbed somebody from there, somebody from the technology arm of NSA, and just literally five friends in the room. No big deal. Nobody leaves a room till we all agree on a small number of things that all of our friends should do. And do not do what security people do. Try to solve world hunger in one meeting, right? Do not try to come up with the infinite list and try to one-up the guy next to you with—he said five things, you come up with ten—because then you get, and I say this with great affection, you get the NIST catalog, right? 800-53. You get the list of every possible thing you ever might want to do someday somehow just in case. And, you know, that's NIST's job is to put together what I would call the Sears catalog if you're old enough to remember the Sears catalog.

(Joel Beasley at 00:14:07)
I'll correct you. I definitely am. I would cut pictures out of the Sears catalog.

(Tony at 00:14:14)
Absolutely. I mean, and it was amazing, right? When it was, especially with papers, a day thick, right?

(Tony at 00:14:19) The Christmas edition was like that. You know, no one buys everything in it, right? You select from it, and this doesn't expect you to do everything in it. They expect you to select from it.

(Tony at 00:14:28) And then they give you another large document and a risk management framework so you can intelligently select from the catalog. And that's a traditional kind of security framework, right? You're kind of on your own, and I say that again gently, to figure this out, right? What is your business risk? What's the appetite, it's called, of your managers, right? What are you connected to? What are your dependencies?

(Tony at 00:14:51) And again, my experience is that even just sort of figuring all that out is beyond the ability of most enterprises. And I say most, and I really mean most, including big funded federal agencies, right? And so the idea was, okay, don't try to solve world hunger. What's the smallest number of things to help people get started, right? Let's not, we're not going to solve peace in our time at this meeting. And I said, small number to me is five to seven. Okay, let's argue till we come to that. And, you know, this business draws really bright people, right, who are highly opinionated. So the discipline is not in adding more recommendations or more possible attack vectors. That's not the discipline. The discipline is to identify the ones you can agree on that are the most important, right? How do I get people to focus not on everything, but on a small number? So what came out of that meeting? I'm not kidding, Joel. It was very simple. Two-page letter. If you don't know where to begin, start here. And this went to the CIO of the Air Force, who's now the CEO of our company, what's called the Joint Staff down at the Pentagon, right? So these are all generals, and, you know, these are people I knew from various things at the NSA. And it was meant as a, based on our experience, if you don't know where to begin, start here. Never thought another thing about it, right? It was a very simple thing.

(Tony at 00:16:02) And then the tech leader of the blue team, he peeks in my doorframe one day, and he knocks on the doorframe. He goes, you know, the SANS Institute, and I know you're familiar with them, got a hold of our list, and they want to know if they can build a community service project around it. And I said, well, I can't actually stop them. It wasn't classified. It was what was called for official use only. I said, but let me talk to our lawyers so that we can stay involved, and let's see where it might go. And so the SANS Institute worked with a DC think tank called the Center for Strategic and International Studies and sort of turned it into roughly the form that we know today as the CIS Controls, right? So I always had five friends around the table became 5,000 people on the mailing list. You know, that's kind of the SANS style. It's very large scale, you know, sort of enlist all their alumni and the public to give commentary. And so it became roughly this thing that most people knew it as the SANS Top 20 for a while.

(Tony at 00:17:02) So that had a life of its own, and from 2008 to maybe 2012, I retired in 2012, was doing some work for the SANS Institute, you know, as a stay-at-home second career. And kind of by accident, wound up taking the project back over and, with the permission and support of SANS, spun it out into a nonprofit that we merged into the Center for Internet Security. So it was, you know, now it's in a permanent home. I mean, it was really a hobby operation. Even at SANS, it wasn't really a moneymaker. I mean, they would have events and, you know, charge people for the events, and they had classes and so forth. But it was really done more as a community service project than a business line. My view was, and SANS agreed, that, you know, if we really wanted to do something useful here, then it deserved a non-commercial home. And that was the idea, just to find it in a place.

(Tony at 00:17:56) So the Center for Internet Security, I was very familiar with from my time at NSA. They were a partner of ours. We were developing what we call the NSA security guides. You know, how do I configure Windows desktop for best security? That's what we released to the public in 2001. And at the same, in 2000, the Center for Internet Security was stood up as a nonprofit to do essentially the same thing, but as a nonprofit in the public. And they would work with companies and volunteers and so forth. So, you know, I love the idea of working with a nonprofit when I was at the NSA. So it was a perfect lineup of what we were doing with what the public was doing. So, you know, lucky me, I get to wind up here in my second act to really continue the same kind of work.

(Joel Beasley at 00:18:36) It's excellent. No, I've been following, like, a couple different people that are in the government that are pushing best practices or at least trying to help the government. And, you know, I don't have all the terminology because I don't do business in the sector. But the one guy that comes to mind is Nicholas. He is the, like, Air Force Chief Software Officer. And he's, like, I follow him on LinkedIn. I don't know how we ended up getting connected, but we did. And he is, like, just constantly helping modernize and create—he makes these posts with all these acronyms and these shorthands that are clearly things from inside the government. But he's always releasing these updates about, you know, new standards and how they're allowed to use more modern technology. And I was blown away because, you know, in my world, I can just go spin up a server on Amazon Web Services and just do the work I need to do without, you know, any sort of resistance. And it is not that way at all when you're working with the government.

(Tony at 00:19:38) No, absolutely. And I think that's, you know, and it's not that people in government are not very smart or lazy or whatever. That's not true at all, right? I mean, some of the most amazing people I know, you know, spent their careers in government and continue. But the scale is just astounding. You know, it's really big. And in some ways, I used to think, so when I started at NSA in 1977, you know, part of the indoctrination, I'll say the introductory classes you took, right, was really the role that NSA played in what came, you know, kind of what we think of as modern computing. NSA played a tremendously important role in helping fund a lot of the basic research. You know, who had bigger and more interesting searching and sorting and data storage problems than NSA, you know, in the seventies? And so the need for that kind of thing drove a lot of research that went out into industry. So, you know, part of that, it was a bit of pride, right? You know, here's what the role NSA played and really helped create kind of the computing world. That was true in the certainly seventies and eighties. I think that would have been fair. But sometimes I think, you know, government can sometimes have played a role of early adopter, and then early adopter eventually becomes stuck with the legacy baggage. You know, that is, right? You make all these massive investments in the technology of the day and, you know, the pace of change has sped up dramatically, right?

(Tony at 00:21:04) So now you see the struggle to move from kind of, I'll say, formerly mainframe-oriented, fixed plant storage, you know, all kind of stuck with some older notions of policy, right? The way you protect information is you put it on a government location with servers that are owned by the government, with human beings that are government employees with a government security clearance, right? And, you know, the point of a lot of modern technology is to abstract that away from you. I don't care where the data's stored. I don't care. You know, it's the idea is to make that simple, manageable, flexible. And so when you're in government, you know, a lot of government folks look at the modern stuff, and they go, boy, that's great, but we're kind of stuck here, you know, with all this legacy baggage that we built pridefully early. And our policies don't encourage that kind of agile move, right? They don't allow us to do that because we can't demonstrate, you know, that we have complete control of the information and that the only people that get to touch it are US citizens and all that kind of, you know. So a lot of the old policies were geographic-oriented or control-oriented, right? The model of security was about control, which often translated to physical control or personnel control or things like that. And, you know, that just doesn't, again, that is counter to what we try to achieve in modern technologies. We look for much more flexibility. I don't care where it's stored. I mean, you care that it's, you know, only available to the right people, but you sort of separate, right, the physical location and the human being that controls it from the content itself. And so that's, and I think a lot of government has struggled to sort of find its way, you know, in this modern world.

(Tony at 00:22:23) As you said, I mean, you know, young guy like you, I mean, you can build the equivalent of a massive IT infrastructure, right, with a check or with a credit card, you know, really rapidly, right, and flexibly, and spin it down, bring it back, you know, redirect it and so forth in a much more flexible way. And that just doesn't, you know, it's not really lined up well with what the government does and the scale. But I will say, you know, it's interesting that you follow the Air Force. I don't know the person that you named, but I did a lot of work with the Air Force over the years, and I always gave them credit. Air Force prides itself on being the most technical, I would say, of the services. And in my experience, I think there's something to be said there. There was a focus on technology, right, flexibility. Again, they're still, you know, working hard to catch up with the modern world. But I gave great credit to the Air Force, you know, in many public talks about things like IT management. You know, it was really the Air Force that led the way for the whole US government in things like moving away from a Wild West where every desktop is configured, you know, to whatever the local thing is, to sort of discipline at the enterprise level and recognizing that I can't just, like, say we're going to have better security, right? I have to change my policies. I have to change the way I buy stuff. I have to change the way my integrators put systems together for me. I have to make, you know, so you have to kind of look at this whole total cost of ownership, right, the whole life cycle of IT, and you have to change a lot of things to get the real benefits from it.

(Tony at 00:24:07) And if you do, then it's tremendously powerful. You could buy a lot of security tools, but if you're buying stuff wide open, you're letting your applications developers do whatever they want, right, introducing all kind of new risks, then you can never get control of that. And I think it was clear for me the Air Force was very forward-thinking and did a lot of really good work and hard work. You know, you have to convince a lot of executives to change their minds, right, to make those kind of changes. So I'll have to go back and look at what's going on there because I've lost track of it a little bit, but I'm encouraged by your observation.

(Joel Beasley at 00:24:40) Yeah. I was going to ask you, like, who are the handful of people I should be following to stay up to date on, like, the bleeding edge of what's happening in the government?

(Tony at 00:24:51) Well, I think things are changing, you know, and any new administration is sort of like fresh blood, right, in new ideas. And so we're seeing that starting to pop up now. And even NSA, right, my old organization, you may have noticed it's becoming much more public. It's putting more things out there, right, taking on a more public profile, more, like, joint products with the Homeland Security folks, the FBI. And so that's really healthy from my perspective. So, you know, I'm obviously, you know, I still have friends there. The kids that I left behind are now, like, big-time leaders and, you know, doing amazing work. So it's really, you know, just exciting to watch what's going on in places like that. I would say Homeland Security, I'm optimistic about the future there. They have an incredibly challenging problem, but there's some new energy there, some new focus, and some new big problems, right? The stuff like SolarWinds and all the, you know, the event of the week now, it seems to be every week is some major new crisis, often around ransomware like the gas pipeline stuff. And, you know, every time old folks like me think, well, this is the one that's going to convince people they really got to pay attention. And then it lasts for a little while, and the next thing comes, the next thing comes.

(Tony at 00:26:03) But, you know, you're starting to see, I think, some coalescing. So there's sort of people to watch, and I'm sure you can find all that. I would keep an eye on what's happening in government, like folks at NSA. There's a lot of momentum, I would say, around some of the ideas. So if you follow, you know, the government-y way to think about this, right? We get a bunch of August old timers and youngsters together and write these, you know, amazing reports. And, you know, the history of those is they say a lot of good things, but they go on the shelf till the next report comes out, right? You get this sort of national plan for this and national plan for that. And I don't want to make light of it because I mean, I've been involved with a lot of them, and a lot of really smart people come together. But I'd say there is momentum behind things like, follow the Cyberspace Solarium Commission. You know, that brought together a lot of folks and was very conscious of this. We have to do more than write recommendations. We have to put things into, for example, the legislative process. So, you know, people from both parties were involved in the leadership of that. And so some of those recommendations that are in there are now bouncing around in the press and are now appearing in legislation or, you know, in the portfolio of the people that are coming into government in the political jobs. So, you know, I'm optimistic that there's a sort of new life there, and all those kinds of things are worth watching. And we're involved in a number of those sort of things too, right? A lot more folks are thinking about these enterprise-level issues, like, you know, like supply chain things, right? No company on its own is going to solve the supply chain problem. These are really infrastructure problems, right? You can't hide your enterprise from, you know, the complexity of where your software comes from and where your components are, you know, what makes up a machine or IT. You can't hide from that kind of stuff in a modern business environment. And so you have to think of these more as very large-scale systemic infrastructure problems that need a, you know, a much higher-level look from both government and the private sector to figure out what to do about them. So I think people are seeing that now, and, you know, you're going to see at least honest and, I think, well-intentioned steps to try and address some of this in both funding and legislation, action by regulatory agencies.

(Tony at 00:28:17) I'm a big flag carrier for the role of nonprofits, I say, and it's not just because I work for a nonprofit. Again, this is a second career for me. But, you know, we are all completely locked into content that comes from places like CIS. But think of the Cloud Security Alliance and OWASP and SafeCode. You know, they're just nonprofits are a proven way to gather incredible talent, right, create content that's either given away or distributed inexpensively or becomes part of more formal frameworks or whatever. And I think there's a lot of power there. And so, you know, I spend a fair amount of time sort of finding our friends, right, the kindred spirits in the nonprofit community to find ways that we can work together.

(Tony at 00:29:02) And most of us, you know, people that tend to volunteer for one often volunteer for another, right? So we have, there's kind of a pool of really good people out there that volunteer to be parts of these kinds of activities. I mean, I've always said that the only reason CIS's business model is possible is because this business is full of really talented people and people of goodwill, you know, people who will contribute their time, right, whether it's to a formal thing like standards bodies or working groups that folks like us sponsor, or, you know, parts of Cloud Security Alliance's teams. There are just thousands and thousands of amazing, talented people, right, donating their time or sponsored by their company. Right? You know, given permission to spend some of their time working on these kind of projects. So I think there's a really kind of a neat opportunity, right, to organize better, to self-organize among the nonprofits, right, in alignment with what I would call the national issues. Right? What do we need to solve as a nation, as an industry? And I think that is a different approach than, you know, we need the federal government.

(Tony at 00:30:07) And again, I say that respectfully as a lifer, you know, in federal government. But the role has been shifting, and I'm not sure everyone sees that role shifting the way, you know, the way I do or some others do. That is, when you think of, when I, again, I grew up in national defense, right? And when you think of sort of fighting in physical space, you think of things like, well, a company doesn't build an army, right? We pay our taxes, we raise an army, and we go fight over there. That's not the way cyber works, right? Cyber is like everybody's involved whether they care or not, right? Every part of our economy, every person, you know, is online banking, exposing their personal information through social media, et cetera. So we all have a role to play in this, and we're not separate from the problem. We are embedded in it.

(Tony at 00:30:58) And so it's not as simple as, or not simple, it's not simple, but it's not the case where we say, okay, the federal government will just tell us what to do, right? We'll pay our taxes and they'll go fight over there. That's not the way this works. We're all involved. And so once you look at it that way, then you have to think about, well, now we're talking about sort of behavior change, right, and economic incentives. And why do people, how do people know to buy, you know, a piece of information technology that has better security properties than something else? Well, most people don't, right? They have no ability to make that kind of a choice. But guess what? They didn't have any ability to do that with electrical appliances either until we codified some things, right, through things like, you know, Underwriters Laboratory and building codes and, you know, specifications that were agreed to by the industry or demanded by a government regulatory agency. And so you have to kind of think of this as we're still early in getting organized around the risk issues here.

(Tony at 00:31:53) And we, but we don't get a hundred years to do this. We have to do this, I think, much more quickly than we have historically to think about this. But I would say, and I'm going to cartoon you a bit, so pardon me because I'm old, I get to talk cartoonish stuff. But, you know, everything we do in society that involves risk, the actions fall into one of three bins, right? Stuff you gotta do because the government tells you it's regulatory, you know, whatever, the building codes, et cetera. Stuff that the market can encourage or discourage, right? So I live out in the country, so the closer I live to the fire hall, the lower my home insurance and fire insurance rates are, you know? I can change some behavior and get some response from the market, and the market can encourage behaviors that either have higher or lower risk or, you know, can encourage positive behaviors to get me better rates and so forth and penalize me or charge me more if I engage a risky behavior. And then there's stuff that we choose to do as kind of individuals or social creatures, right? We can influence others through our behavior or the way we speak, you know, independent of what the law says. So I'm a granddad now, right? So, you know, I would never let my grandchildren ride in a car with a family that doesn't enforce seat belt laws. And I know, you know, it's not about the laws. It's about the behavior, right? You know, that I will make that choice and make it clear that that's a choice. Anyway, so traditionally in national defense, the first bucket dominates, right? The federal government, the mandatory things, we pay our taxes, that dominates. And the market clearly plays a big role in individual behavior.

(Tony at 00:33:20) I think in today's environment, in the cyber business, the market is really the driver here, right? It's about how do I empower the marketplace. To do that, I have to help people make better decisions. To do that, I might have to organize the supplier side of this, right? That is, you know, the typical consumer is not capable, right, because it's so complicated and fast changing, of deciding that this set of IT things is safer than that set of IT things. They just can't on their own. And so we need mechanisms to both organize the supply side, how people know what they're buying, and then help influence the demand. That is, you know, if consumers will demand it, the market will generally provide it and vice versa, right? You have to, you have to line both at the same time. So you see a little bit of that in what the new administration is doing. They're, you know, some stuff there just popped out today. You know, things like, and I know these are kind of simple sounding, but, you know, the equivalent of restaurant ratings, right? You know, can I say something about, well, the way this company develops software follows a higher degree, set of processes than this company does than that company does? If you could find a way to establish that, right, have the industry sort of voluntarily choose to participate in something like that, then you give the consumer some power to say, I'm going to make choices that are consistent, right, either with my perception of risk or how that might affect, pardon me, my insurance, you know, or my liability and so forth. So there's a lot of discussion happening, you know, it has been for several years now, Joel, around the role of liability and insurance.

(Tony at 00:34:56) And, you know, every year or two there's another spike. Oh, you know, insurance is really going to step into this and change the game. There's still a lot going on there that's fluid, right? So people are still trying to figure out.

(Joel Beasley at 00:35:09) Have you seen SecurityScorecard?

(Tony at 00:35:13) Uh, yes. Yeah. And so there's a whole class of tools like that. SecurityScorecard, BitSight, there's a couple others that jump, I remember. But those are useful, right? They're not complete solutions, but they're useful in that they're very scalable. So you can take kind of broad looks across the ecosystem and identify, as best you can from outside an enterprise, here are the kind of risky behaviors we could observe from outside, right? It talks to risky locations. It uses unsecured protocols, you know, that kind of stuff. And that is, that's worth knowing, right? And it can be used to affect things like insurance rates or entry into a supply chain process, right? If you score above or below a certain level, then, you know, you're too risky a partner or that sort of thing. So these are, I believe, these are all like early signs, right, of people trying to establish scalable ways to get, you know, some meaningful information around which to affect those decisions that I talked about. And so I think that's an excellent example. And, you know, we are in, you know, talking to folks like that around these kinds of ideas, right? What we do, like our the CIS Controls, what we have is knowledge of, if someone follows us, we have a pretty good idea of what's happening inside, which may or may not be observable from outside. And so the idea is if I had both, right, if I could see both, then I can bring a greater fidelity, you know, and accuracy and verification, you know, to the observations that I make. So it's worth having both. The part of this is, how do I do things at very large scale and very cost effectively?

(Tony at 00:36:55) So a traditional model, you know, again, when I grew up in, was very human intensive. You know, you have a sensitive government network. Every three years, you're going to write me a giant report. Here's your mountainous requirements. Every three years, you're going to write a giant report that says you met all the requirements, and then we're going to send human beings out to visit you and make sure you really did meet all those requirements, right? And I get it. You know, that's a kind of a traditional way to look at it. But, you know, three years is a really long time in today's world, right? How meaningful are those results the day after you've made that decision? Often not very meaningful, and it's very expensive, you know? So you're talking about a slow moving train for a fast target here and something that is really, generates very, very high costs, right, to send human beings out to visit and write reports and stuff and so forth. And by the way, what do you wind up with at the end? A lot of paper reports. And now you're trying to, who's going to read all these things, you know, and try to make sense of them and say, are we collectively getting better, or is it just, you know, are we just sort of like looking through the microscope of the ocean? You know, we're only seeing a little bit of it at a time. My mental image is, and you remember the first Indiana Jones movie at the tail end of the movie, right? The, you know, what we, Indiana says, you know, who is, where is the arc and what's happening? And the government guys say, we have, let's see, we have, people looking at it. And then, again, the challenge is, top men are looking at the arc. And then you see the video of the guy, right, pushing, you know, they nail shut the box. They're pushing it in the giant government warehouse which is stacked to the ceiling with boxes that look identical. You know, that's the image that I get of all these assessment reports. It's like, oh my gosh, you know, mountains of paper, outdated as soon as you publish them and so forth.

(Tony at 00:38:43) So I think this idea of how can I flexibly, rapidly, cost effectively make decisions, right? These are risk decisions. You know, if we're talking, you're talking to me, are you safe to bring into my supply chain as a partner? I need to be able to make a reasonable, not perfect, but a reasonable and quick and technically, you know, generated from data decision about that. Oh, and by the way, you're not my low cost supplier anymore. I need to redo that negotiation with somebody else, right, quickly, rapidly, cost effectively, et cetera, right? So this whole business of trust, I'll say, is, you know, I grew up in a world where trust was what I would call binary, right? You know, hey, you're with the government or you're not, right? You have a security clearance or you don't. You're one of our trusted suppliers or you're not. And that allows you then to kind of operate. And now you look at today and you go, you know, trust is what I would call a dynamically negotiated condition, right? I can trust you, but if I don't talk about the purpose and for how long, there's no, like, you know, binary trust here, right? The idea is that we're discussing, is the risk reasonable to bring you into my supply chain? Well, to bring you into my supply chain means there's a certain kind of data and control that goes back and forth between us, right? For example, in the retail setting, you might say, you know, our contract is not that you're going to ship, sell me so many gizmos and I'm going to stick them in a warehouse till I need them. The contract is you're going to be able to track my database, my inventory by store, and when the inventory gets below a certain level, you're just going to ship goods directly to that store. So to make that happen, right, I have to give you access to control and data paths for one purpose, to check the inventory of what you sell me. I can't give you access to all my data, right? That's suicide. That's crazy, right? So I have to negotiate the purpose of trust, and I do it for some period of time, right, for the period of the contract or until I find somebody cheaper or whatever. So you find yourself in this modern world thinking about trust as something I have to negotiate, and I'm going to have to do it over and over again, right, for maybe potentially thousands of suppliers. And again, suppliers are going to come and go depending on the business circumstances.

(Tony at 00:40:53) So for something like that, I want to do it rapidly, scalably, cheaply, right? I've got to be able to do it, you know? I don't need a 100% answer, but I sure want a 90% answer, right? Some reasonable confidence that when you say you can handle my data the way I would handle my data, I can believe that's true. And maybe it turns out to be you were lying. Okay? Well, okay. Then I have the courts, right? I have other means to deal with that. But I, you know, if I tried to get it perfect, I would spend a year negotiating every contract, and therefore I couldn't keep up with the pace of business either. So I, yeah, hope that wasn't too confusing, but it's just this idea of, you know, I have to constantly think about renegotiate issues of trust, right? And the more specific I am about the purpose, then the more I know about the data and control, right, what happens in IT space that would allow that to happen, and therefore the more concrete I can be about what my measurements are, right? How do I know that you're safe? And am I giving you the minimum data so we can execute this business agreement between us?

(Tony at 00:41:55) I first started to think about these kind of things, again, when I was still in government. The government equivalent of things like just-in-time manufacturing, right, and this dynamic supply chain, is, at least back in the late nineties, was what we call coalition warfighting. You know, it was a notion, it was actually, it was a US government policy or a DOD policy. We don't go to war without our friends. If you followed Middle East wars, I mean, these are complicated political partnerships of potentially dozens of countries, you know, all banding together for a particular purpose. And so you say, oh, and so here's my rules of war, and now you'll know why I never was worthy to be in uniform, Joel. My dad was a three-year war veteran. My rules of war were, you never go to war without your friends. That's US doctrine, right? That's the way we operate. You don't know who your friends are until the day before you go to war. That is, right, because those are political collections, right? There's arm twisting and incentives, and so there's this complicated, you know, I don't get a year to plan this out because these partners could appear at the last minute. And then third, half the partners can't stand each other, and they certainly don't trust us, right? So these are fragile, complicated things. And now, now think of your role as an IT guy trying to deal with this.

(Tony at 00:43:09) Okay. So now we're gonna potentially have dozens of countries working together. Think of this as dozens of businesses. We have some complicated purpose that we're trying to achieve together, which means data has to be exchanged. In war fighting, it's I gotta know where the good guys are and the bad guys are because I'm gonna throw expensive, dangerous things around.

(Tony at 00:43:27) Right. And so I have to have what in government speak, you'd call it a command and control picture, a common operational picture or something like that, where you'd say, okay, I gotta know where the good guys, bad guys. Can I project force safely here? To do that means you're combining things like intelligence information, radars. You know, all kinds of information is gonna be shared for that purpose during that period of time. But, you know, okay, so the US has to provide some information, but we're only gonna agree to provide this kind of information of this level of classification, not all of our information. So how does the IT guy make all that work? Right?

(Tony at 00:44:01) And so that's the government and war fighting equivalent of this complicated, you know, fast changing partnerships for some particular purpose. So that's what really got me thinking about this. That's sort of late nineties, early two thousands. And then I looked around and go, oh, the people that do just-in-time manufacturing for automobiles have been thinking about these kind of problems too. Right? And retail. You know? Now it's like, who can afford a warehouse full of stuff that sits idle? Right? You don't wanna build this sort of waste into you have to squeeze all this efficiency, and information technology lets you do those kinds of things.

(Tony at 00:44:34) But to do it, you're now changing the notion of risk and trust. Because to make it happen, you gotta share data and control. And so that's what really, I think, complicates all these things. So to me, you know, we need to give serious thought to sort of the infrastructure of managing all this kind of trust. And then I'll, but again, individual companies will struggle to solve this. Right? Most of us don't have that kind of IT horsepower and money to do this on your own. You wanna do this at very large scale. And so more of it, we have to think of it as, okay, what are the common standards that allow this? How do I negotiate these things? Right? How do I move these datas in a way that I have confidence that, you know, it's only these two parties that they get to exchange and that sort of stuff. And then so there's a, you know, kind of a technical component, and there's a business component to this too. It's supporting these business goals of rapid renegotiation.

(Joel Beasley at 00:45:24) I had a question about earlier, you were talking about, like, fighting in physical space, right, versus fighting in cyberspace. So if one country drops a bomb, it's on the news. Right? It's clear. You can see it. It's in the street. It's happening. It's out open in public.

(Tony at 00:45:38) Oh, yeah.

(Joel Beasley at 00:45:39) Okay. But if one nation attacks another nation digitally, like, who's the because we can't see it out there in the physical world, really.

(Tony at 00:45:47) Right.

(Joel Beasley at 00:45:48) Well, where do you first of all, can you find like, follow these attacks? And if so, like, where would you be able to like, I imagine it would be cool to have a news channel that's, like, able to report on these attacks that are happening because all I constantly hear in this sphere is and this is I'm not diving a mile deep into it, but I talk to a lot of different people. And I hear, like, oh, there's attacks and countries are attacking each other, and it's happening all the time. And we have an offensive and a defensive teams. And I got to talk to one of the generals down in, like, Augusta, Georgia where they're building some new, you know, cyber warfare stuff. And I'm like, yeah. But, like, where can I see this stuff, or can I not?

(Tony at 00:46:32) Well, so and it's for me, who's been around this long right? An astounding amount of information is in the public. You know, this sort of world of attacks, and what you see reflected sort of most openly are the commercial kind of equivalents to this. Right? The ransomware attacks that you see. Right? The very hot in the news supply chain attacks. But more and more I mean, you know, these are not neatly partitioned problems. And so you'll see, again, the fact that we're all essentially using the same technology, essentially all on the same network, and then all interlocked in these complicated fast changing business relationships means that no one gets to stand outside of it. Right?

(Tony at 00:47:12) So you see things like this. If you follow the SolarWinds supply chain business. Right? So, you know, the government, you know, is using sort of every imaginable commercial tool, infrastructure, you know, that you can name. And so part of the targeting, right, as countries that deal with each other is understanding the kind of environment that their adversaries live in. And then what are they dependent upon, and what is my ability to go after those? So there's always kind of an undercurrent and a sea of these things happening. It's often hard to separate sort of criminality out from sort of political activism, hacktivism, and espionage, you know, the theft of information for there's commercial advantage, but there's also for sort of national, political advantage. And so and they're often, you know, murky by design. Right? Everyone hides in the same noise of criminality and teenage joy riders and all these things that are happening all the time. And so you get some glimpses of the national fight through things like SolarWinds, right, to see, okay, you know, the speculation, the press around the you know, this is of a national origin, really a foundational part of a counterintel of an intelligence operation. And so the but these things are happening all the time, but sometimes they're hidden in the noise of criminality, you know, and all these other things that are happening all at once. So there's plenty out there to see. And it for most people, it's interesting to know that this nation's attacking this or, you know, and so forth. But it's very hard to sort out the practical implications for most companies or most enterprises. Right?

(Tony at 00:48:40) So the fact that you're being people are trying to extort you for ransomware, steal data from you. In some sense you don't care whether it's a company or a nation. You know, it's just it's stuff that you have to deal with. And so it's very hard to sort of sort through all that to separate it out. Again, our view at CIS is most people can't figure all this out. And second, they don't need to. Right? What you need to know is these kinds of attacks happen. These are the root causes of these attacks. These are the things that you need to do about it. It's interesting to know who does it, but but, frankly, as a practical matter, it doesn't mean much. A lot of what really gets sorted out, though, nation to nation is not necessarily, I'll call it, visible through the wire. You know? That is nations will spend a ton of money to learn about each other. And so what you can observe there's things you can observe through the network. Right? These packets, this string of things is this kind of an attack which gets this data and, you know, elevates privilege and does you know? And that's all true. But, you know, the business of intelligence agencies, you know, and NSA and their equivalents around the world is to connect lots of other things in addition to technology. So if you follow any of the national defense stuff, you know, the motivations of political leaders or military leaders and, you know, there's so much other information that is brought to bear at the national level to try and figure these things out. That, again, that a lot of that would be invisible to the public. Right? That these would be classified or, you know, part of a larger attempt to really understand the scope of what's going on.

(Tony at 00:50:14) So I'm sorry. That's not a real crisp answer, but it is it's important to know that there are all these kinds of things happening. But if you you could literally spend all your days just agonizing over them. Right? And it's for most of us, it's too complicated. That's part of what we try to do at CIS is, okay. That's all great, but you don't have time to read all that, the expertise to understand it all. You know, the key is, can I translate all that into action? Right? To me, the verb that really matters in this business is not sharing. You know, people say, okay. But if the government would just share everything they knew, then we'll get smart, and then we'll make the right end. That has never proven out to be true in my experience. That is sharing is important. Don't get me wrong. But the verb that matters is translate. How do I translate millions of data points of badness into a relatively small number of constructive positive things that you can do about it? And the observation is right? This is like public health or any other risk area. We're not getting hit by millions of unique attacks every day. We're getting hit by millions of repeats of a relatively small number of kind of classes of attacks over and over and over again because they work. Right? People aren't inventing new entire new classes of attacks every day. They're just churning through the same old stuff with variations on the theme and all that. Yeah.

(Tony at 00:51:26) Sure. The quickest way, just my advice, it actually just came out today. The Verizon Data Breach Investigations Report is really worth a read for anybody in the IT business. And that's not a plug for Verizon, although we do work with them. We contribute data. I mentioned we're the Multi-State ISAC, and we're one of the data contributors to Verizon. So Verizon, I'm not sure if they were exactly first, but they're sort of the pioneer here.

(Joel Beasley at 00:51:53) They're a great company. I got to I got to interview Kyle, CTO, and I had emailed the CTO, asked them to come on the show. It was about two years ago. And within ten minutes, he called us.

(Tony at 00:52:05) Oh, no kidding.

(Joel Beasley at 00:52:06) And he's like, yeah. But you probably don't want me to come on because there's some news, and I'm going to become the CEO in, like, a week or two. And there's a new CTO. So he's like, I'm gonna connect you with Kyle, and then he became the CEO. And but I just thought it was so cool to be able to, you know, email somebody like that and just get a response.

(Tony at 00:52:21) Yeah.

(Joel Beasley at 00:52:22) A response.

(Tony at 00:52:23) Well, they're you know, my history of working with it is is true. I have great respect for what they do. The Verizon Data Breach Investigations Report, basically, you know, was originally started from their incident response business, and they started to, you know, pause at the end of every year and say, what did we see? Can we summarize it? What are the trends, the categories, and so forth? And I think there are several dozen other organizations now that contribute data to them, and their data scientists are very good. We, you know, we have worked with them. I've worked with them since, I think, 2013. That's when they first started to reference the CIS controls in their report. You know? So they do a great job pulling all this together, breaking down by sectors, by types, by categories, the kinds of attacks, you know, the sort of, the it's very readable. You know? It's very accessible to take a look at. So whenever someone is just trying to get a sense for what's going on out there, I mean, that's the first place I would send them. I mean, there's great technical analysis, but they do a really nice job of abstracting it to sort of the, you know, readable by normal people, people who work in IT, particularly.

(Tony at 00:53:25) And then so this just came out, I think it was today was the release date. The CIS controls are one of the appendices, and so this is the shameless plug. You know, that is here's what they found, right, at the category level. I don't have access to all their data. We don't. But we discussed with them, again, this idea of their job is to sort of pull this together, do the, really, the heavy front end analysis to help understand, you know, the types of attacks, the categories, the classes, and then help summarize it and break it down as best they can by sectors of the economy and so forth. And then the idea is, you know, we look at that carefully to try and say, okay. How can I map that or translate, again, the key verb, into a smaller number of positive constructive things, right, that IT people can do, that policy people can do, that's really the important view? And it sort of doesn't matter who is running that attack. The question is, can we observe enough of it to understand it to do the translation into action?

(Tony at 00:54:22) So that's, I think, a very accessible starting point. It's well known in the industry, very well accepted. There are others, and many other great companies do a similar kind of analysis. I know I've personally worked with Palo Alto in the past, Symantec, McAfee, and companies like that. You know? And they're all, again, lots of data generated from whatever their business model is, serious data science, right, trying to make sense of it and pull it together. And then, um, this is a surprise for an old government guy like me. Right? They do this great analysis, and then they give it away. They give it away for nothing. Well, what they're doing, it's marketing material at some point. Right? They're demonstrating both sort of community goodwill, and also it's marketing. And because often the recommendations are it's not a plug, but it lines up with their model. Right? Whatever their solutions model happens to be. So but they all do, I think, a very nice job with those. And, you know, it's sort of a habit. Right? You try to catch up on all these annual reports whenever you can.

(Tony at 00:55:21) And for folks like us, our purpose in following them is really about translation, you know, that is we do this as a community. My view of this, Joel, and not everyone agrees with me. But I grew up in this business where we I called it the special snowflake business. Right? We're all special snowflakes in IT. You know, our business risk is different. Our connectivity is different. Our dependencies. And so, therefore, for all special snowflakes, then we all have to behave like special snowflakes. And I say nonsense. You know, 90% of what you deal with is the same for everybody. Yeah. Everyone does have unique risk because of their business and all that stuff. But if you start there, it's easy to get overwhelmed and paralyzed, right, that fog stuff. But if you focus on again, like in public health, we don't ask everyone in the economy to become an expert in disease transmission and prevention and all that. Right? We try to translate lots of complicated research and lots of understanding into a relatively small number of behaviors. You know, wash your hands. Don't cough on people. You know, get your shots. Whatever. You know, those are really the fancy way to talk about them is they were translation, complicated science and research into human behaviors that you can then ask people to do or encourage or require through the marketplace. And so that's, you know, that's the kind of model that's been driving us for years now. It's how do we can we learn from fields like public health and, you know, public safety. Right?

(Tony at 00:56:45) How do you decide it's safe to fly an airplane? Well, you don't interview the pilot. Right? You don't, and you don't inspect the plane. You count on the FAA. You count on the certifications. You count on that doesn't mean you make a perfect decision, right, if you choose to fly the commercial plane. What it means is you have pretty good confidence, not perfect, that the you know, they can't hire a pilot who isn't certified. He has to be retrained. Right? And so you count on a lot of that stuff being kinda done in the infrastructure for you. Sometimes it's not true. Right? A pilot shows up and is impaired or, you know, whatever. You know, it's not a great answer, but you have to deal with things like the courts and, you know, the regulators and so forth to help, you know, address any relief afterwards.

(Tony at 00:57:31) But, you know, we have to find scalable ways to kind of manage these risks in IT space the same way, not identically, but in the same spirit that we do things like public health and the safety of whether it's okay to drive a car or cross a bridge or, you know, get on a commercial airplane.

(Joel Beasley at 00:57:49) Yes. And you guys are leading the way over there, and we're really grateful for it.

(Tony at 00:57:55) Well, I don't know if we're leading the way, but we're trying. Yeah. Thanks, Joel.

(Joel Beasley at 00:57:58) How do you feel? We made a podcast.

(Tony at 00:58:01) We did it. Yay. Okay. Yeah, great. Thanks. You know, it was the best time, which is a conversation between people. So, thanks very much, Joel. Pleasure talking to you.

(Joel Beasley at 00:58:16) You too. Thank you so much, Tony. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected].

(Joel Beasley at 00:58:36) Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.