Cybersecurity Perspectives

S1:E2 - Bonus - Departing Blackhat, Thoughts from the Airport

Paul Marco & Owahn Bazydlo Season 1 Episode 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 15:28

Black Hat’s biggest lesson this year is not about AI, it’s about control. Paul and Owahn unpack fragmented security stacks, why “agentic AI” is just the latest rebrand of old identity problems, and what defenders actually need to do to reduce risk without drowning in hype.

From the airport after five intense days in Las Vegas, they break down the real conversations happening on the vendor floor, the SMB-sized gaps that enterprise tools keep ignoring, and the one startup that genuinely stood out with file-level and even page-level encryption at a price smaller teams can actually afford. Along the way, they trace how prompt injection, model poisoning, and over-permissioned agents map back to the same control failures security teams have wrestled with for years.

You’ll hear why Paul is so done with AI being slapped on every booth and every pitch, why Owahn keeps pushing the idea that security has to be treated as a connected control web, and how both of them see the same core issue from different angles: isolated tools don’t create resilience. Standards, policy, process, people, tech, and service all have to work together.

They also dig into one of the most important shifts in cybersecurity right now - treating agents like identities, cataloging what you actually have, and building a program that starts with operations, governance, and business impact instead of chasing the newest shiny product. If you’ve ever wondered how small and midsize organizations are supposed to keep up, or how security can become a business enabler instead of a cost center, this conversation gives you a sharper way to think about it.

The episode closes on the part most people miss at conferences: the hallway conversations, random dinners, and unexpected CISO chats that often matter more than the giant booths and flashy demos. Essential listening if you care about practical cybersecurity, smarter buying decisions, and what actually works once the hype cycle fades.

SPEAKER_02

Alright, there's a check. It's coming through clear. You check. Is it coming through clear? Yeah. I'm so happy to be here with Paul and Crypto.

SPEAKER_00

Ha ha exactly. Only for out of this. So Wow. She's just a travel companion. Doesn't matter. Anyway, dude. So we're in the airport. It is uh it is time to make the trip home. It's been a very, very long five days in Las Vegas. Black Hat is gone, the booths are shut down. I think this is the time to debrief, man. Like, what'd you love? Would you hate? Would you learn? Tell me a little bit about your experience at Black Hat.

SPEAKER_02

Yeah, so for me, the one thing I took from it is this concept of we can't be fragmented anymore in our control set. The big thing is one of the topics were agentic AI, which I have a caveat around a lot of that. I don't know what that term still means, but I do understand the concept of what it means to be disconnected from your controls, right? And we've worked really hard on what does it actually mean from a cybersecurity definition of what is control. Yeah. Right? We have our six elements between standards, policy, process, people, tech, and service. Right. And this is now starting to reinforce what we've been developing over the years to say we may be ahead of the game in the sense that one element of control will never keep you secure. Yeah. It's more or less the the accumulation of what you have, right? So the sum of the total rather than the counter individuals.

SPEAKER_00

Like every like walking through the vendor floor, really cool tech out there, by the way. Like met some cool vendors, also met some vendors that I'm pretty sure we're bullshitting everybody, but whatever. We won't we won't get into that here. But um, you know, I agree, like everything is so like it's like these hyper verticals, right? Like this little segment of this type of a control of this particular use case, pulling it all together is tough, especially when you try to walk up to these vendors, especially as a small, medium-sized business, and they're like, Yeah, sorry, minimum contract's $250,000. And I'm just like, okay, thank you for hanging out with me. Can I have a question away? Like, like, I'm not sure what to say.

SPEAKER_02

Right.

SPEAKER_00

You bring up the agentic thing, I think that's my biggest pet peeve for this year. Um I think I'm over it. Like, I'm so past it. There used to be this thing where I would go to Vegas with friends for a bachelor party or whatever else. The joke was you you could stop anywhere in Las Vegas, look around, and you will always see at least two bars. Dude, I could stop anywhere in Black Hat, and I would see at least 85 references to AI or Agent Tick or LLF. Like, it was just overwhelming. It was literally everywhere. I think we're at the point where like we're past that now, right? Like, everyone gets it. It's transformative tech. Yes, it's amazing. It can be applied in very, very unique ways. But like, do we really need this thing to be like just screened to chew from every angle? I don't know. I I think I'm getting a little salty if I'm being honest.

SPEAKER_02

Yeah, and my bigger thing is how do we apply it operationally, right? It's one thing for large organizations to buy product, but I still don't see the breakdown into operational rigor and actually reducing risk over time, right? I think there were great talks in terms of how do we stay ahead of this difference between the attackers having literally the advantage in a financial perspective, right? They can do so much more with less in terms of financial commitment, but our small, medium-sized businesses in the 42500s still have to spend a ton of dollars to be able to do that, right? Because we have to have it vetted, we have to ensure that it does certain things, cardrails, and that's just where it becomes really a difficult proposition. I'm not seeing new solutions of how we actually, as defenders that have small budgets, how can we compete?

SPEAKER_00

How do we stay up for it's actually causing new problems? Like, so I went to this really, really cool talk hosted by an organization called The Table. And basically, they brought in these industry experts, and it was a really small, intimate conversation. And one of the major things about this is talking about how do you wrangle in agents? Because now everyone's just created an agent, right? But what's happening is people are creating agents, these agents are being over provisioned with permission, they're being given all of this access, and then no one is really like following up or checking to make sure they're doing the right things or that they're not being abused. And one of the things that was super interesting about this talk, what I took from it is that cybersecurity is cyclical, right? The problems that we had 10 years ago are now the same problems, they're just rebranded, right? Like SQL injection is now prompt injection, SEO poisoning is now model poisoning, and the agentic problem is actually an identity problem. It's the exact same problem we had with service accounts. People would just create a service account to do a very specific thing and then make it freaking domain admin, or give it global admin and be like, oh, I only needed to talk to this one server and move this one file. Well, you better make a global admin and give it all every permission in the directory, and like that's what's happening with these agents. But we have to start to treat them like an identity. And that was a very cool talk.

SPEAKER_02

And it's super interesting the fact that how we're going back to a simple list or a database structure allows you to catalog those things. We have to take time to actually catalog what we're using, whether it's AI bots, whether it's server accounts, whether it's user accounts, whether it's actual assets. Like we have to start to think about, we can't move away from what actually structures us from our control perspective, right? We don't always have to chase the newest and best and all these things. Sometimes we have to take a step back and say, are we actually getting a good foundation? But the one thing I thought from a vendor, you know, we don't try to spout vendors on this podcast, but my bigger thing was DLP. There was one unique vendor that started looking at files and say, I don't care about any transmission, I don't care about where your data resides. I can actually control you at the point of contact of creation, right? Word documents, PDFs, Excels, and you can limit that down to the actual data element, right? Not just a structure. And that was really cool. And their price point was literally SMB worthy, and that's really important.

SPEAKER_00

I know, I know we said we don't want to talk about vendors, but I feel like this one is worth a shout out. I know exactly who you're talking about, and they were probably the most inspiring company I looked at. This with you, this was Honey Cake, right?

SPEAKER_02

Yep, yeah.

SPEAKER_00

Alright, so so for those of you listening, here's like Honey Cake's brilliance, and like I think it was part, like for me, this was like a breath of breath of fresh air. In you know, passing these million dollar booze with like the lights and the lasers and and the people dancing and like all these things. There was this like tiny little company in the A startup in the in the startup section, and no glitz, no glam, but this this guy, this company, they solved a very simple problem. And I encrypt at the file level. We have to assume at some point your data will be lost. Can we protect that data so that it can actually be encrypted, right? And then you don't have to worry about it because you have full control of the file no matter where it is, because they have to reach back out to them to get the certificate fair. Now, here's the thing I loved about this. That alone is a great idea. They took it a step further and they allowed you to encrypt parts of the file, pages on a PDF, columns in an Excel workbook. Like the application of this at that level of granularity, at that level of control, was inspiring. And to your point, super transparent pricing, right? Solved the problem, accessible to everybody. I downloaded the app today. I legitimately downloaded the app. I want to play with it. Dude, I'm gonna play with this like crazy. So, yeah, like that for me, that was a super bright spot for me. I'm so glad you brought that up.

SPEAKER_02

And like, again, we are an SMB, right? We don't we don't make any qualms about that. That's what we love to service, that's what we love to focus on. And I was a little dissuaded at the focus of enterprise here, and you know, a lot of vendor booths just wouldn't even give me the time of day, but it's inspiring to see that this community overall is really caring, right? We want to tackle problems and we want to try to bring that to organizations in which they don't have capability, and that's again like that's the whole purpose of this entire podcast is bringing perspectives to let us think differently, right? How do we establish solutions to problems that we can't solve today, right?

SPEAKER_00

I think I think that's for me, that's the kind of the last bright spot that I want to talk about here is this concept of community, right? And like we talked about that when we were walking on the first day of the show, right? Like that was the very quick intro episode, and now here we are talking about community and like meeting people. Some of the best meetings I had happened off the floor in a random elevator, right? Or meeting at a bar the next day. Like we talked to that one guy who's doing the thing with command and control. We met a random CISO in another hotel where we stopped for dinner. Like, these are the things that I will never dissuade or discount because those organic conversations, just meeting smart people, was amazing.

SPEAKER_02

No, to your point, too. The last conversation I had was at again a random restaurant that we were at with a CISO of a really large supply chain company, and organically said, hello. And that spun up into a like a 30-minute conversation between the three of us, and it was not sales-oriented, not anything that we do, but just what are the things that you're facing? How do we have a conversation that we actually talk about? Like, that's honestly that's the goal of what this entire thing should be about. Um, and hopefully we can kind of spread out a little bit more, right? We don't have to go to Vegas for these things anymore, right?

SPEAKER_00

Well, I mean, that's the point of this whole show, right? Like, let's let's meet people across the spectrum. I don't care if you're a two-person startup, I don't care if you're the CISO for a Fortune 100 logistics company. It doesn't matter. Like, let's just get those perspectives. It's so funny because like you talk about meeting that random CISO and like super nice guy, love that conversation. There are vendors that would have killed for those 20 minutes. They would have literally like given away their children for that opportunity, and we just stumbled into it just to have a great conversation and just to meet someone as a practitioner. For me, that was a bright spot of this particular event, bringing those people together. I had an amazing time this year. Of course, I started this by bitching a little bit, but I think that's just me venting to get away from this AI, LLM, like you know, agentic hype. But I think at some point we'll get past it. The last thing was cloud, now it's AI, we'll figure out what the next thing is and we won't have to worry about it anymore.

SPEAKER_02

Yeah, and for me too, it's just like it's honestly going back to know what you have, know what you actually operate in and make interconnection points, right? So if it's email, you gotta bring that back into SIM, you've got to understand what's my EDR. Like, you can't make isolated controls on their own. You have to bring that back in, interconnect, right? Even talking about EGOC or risk management, you it's always gonna flow from the tech, usually. Yeah, but how do we start to interconnect tech with all of our other control elements in our capacity? And that's something that I think people are starting to come around with, right? It's important to do things like standards review, it's important to understand my identity management that equates to my network traffic, right? Like we've got to start to build that web. That's why I think, again, it's really stupid and elementary, but that's why spiders are really successful at capturing what they need to do. Because they have a web that's interconnected, it's not isolated, right? So that's always been a thing of my like passion of ecosystems and interconnecting, because isolation doesn't work.

SPEAKER_00

Yeah, dude, you bring you like you spurred another memory that was actually super interesting because it is clear that I have drank the talus poolet, right? I mean, of course, outside of being a co-founder, what I what I've learned is I cannot think about cybersecurity any other way right now. And it was apparent through a very organic conversation, I met with his other CISO, who was uh he's a CISO of a Canadian healthcare company. And interestingly enough, he grew up in operations, in cyber operations. So, like, exactly where I grew up, right? Security operations center, detections and response, like that was his gym. And it was funny, like, because I was sitting there and he was like, ah, hey, nice to meet you. What do you do? Told him about Talos, and told him about this concept of the control stack, and the more you connect to, the better it is. And like, we talked about this conversation, this problem about SMBs, and how SMBs and SMEs, like, really they know that they need to do cyber, they want to do cyber, everyone wants to do it the right way. The big problem is you just don't know where to start. Where do you start? And then his immediate reaction was, oh, you start with operations, you have to start with tooling and EDRs and like technology. And I like had to pause for a second because I agreed with him partially, and I was like, Well, dude, like you I I that's not what I think is right. Like, you have to look at the whole thing, you have to look at what's driving the program, can you enforce it? What are the rules of the road, right? Translation, directives, policy, and standards, right? And he's like, I'll fight you. He was joking, of course. I mean, maybe not.

SPEAKER_02

I don't have a black eye, but whatever exactly.

SPEAKER_00

He didn't actually fight. But he's like joking. He's like, I'll fight you on this right now, options the first place, they have to have technical control. And I paused for a second and I told him. I was like, and you you know the story of like the with the the breach and the the you know I I won't get into that now, we'll save that for a later episode. But like I had a transformational moment where I stopped thinking about technology as the primary control, sort of thinking about the whole ecosystem. And in this moment, I looked at him and I said, Look, man, here's what I'll tell you. I grew up where you grew up. I ran enterprise grade security operations programs globally. At the end of the day, the best programs I ran are when I had visibility into risk, when I had visibility into the company's drivers, when I had an understanding of the standards, those were the best programs I ran. Before that, it was all just very haphazard technical control, what worked, what didn't work, and then it turned into a holistic program. And like you bringing that up right now is crazy because I totally forgot I had that conversation and it was so impactful.

SPEAKER_02

Well, it's it's interesting that you say that because for me, if we can articulate how this impacts the business, or how do we actually make this in which we can afford, but then also reduce the risk, like that's the other jump that I think this podcast has been really started to address is how do we make the technical an actual business generator? So many people forget about how cyber can actually be a business generator if done right.

SPEAKER_00

Yeah, right?

SPEAKER_02

So much time that's always chasing, oh, I have to do a pen test, I have to do this, like and envelope that into how you actually start to articulate your controls so your customers feel more secure about what's getting done.

SPEAKER_00

Yeah, right. Alright, dude. I like honestly, like in in retrospect, kind of last thoughts. The conference coming to Black Hat for the first time.

SPEAKER_01

Yeah, I mean, Kennedy, we had a complimentary pass, like definitely the full pass is worth it, I think. Yeah, the complimentary pass is a little difficult.

SPEAKER_02

Right. Um, but honestly, getting around a community of people that care to do albums at Cyberfaces for businesses, it's really inspiring. I got really invigorated to be around this community again. Like I feel thankful for it. Again, not everything I wanted, but really, really looking forward to getting back and seeing what we can do, right?

SPEAKER_00

Yeah, uh honestly, definitely some inspiring moments. Met some very cool people, had some very cool conversations, walked about 11 miles a day, so I feel like I got my steps in, which is great. But honestly, this was an amazing experience. I'm super glad we did it.

SPEAKER_01

I can't, dude.

SPEAKER_00

Absolutely.

SPEAKER_01

Until the next one.

SPEAKER_00

Well, I think we should probably stop fucking off and go catch our flight so we can actually make it home to series. But uh, yeah, man. All right, talk to you soon.

SPEAKER_02

Peace.

SPEAKER_00

All right, later.