
15 segments available
Enterprises large and small run their applications and infrastructure at a whole new level of agility and speed. But unfortunately, security doesn’t like speed. “The faster you go, the harder it is to understand what is happening and to protect your infrastructure,” says Andrew Rubin, CEO and co-founder of cloud security startup Illumio. So then how do we rethink the architecture of the past to acknowledge the way business happens today? If you want to start tackling the shifting landscape of business and security today, “Go become a student of the economics of war and crime,” suggests Gaurav Banga, CEO and co-founder of Bromium. If going slow is not an option, what can and should we do?
Andrew Rubin introduces the concept of 'barbarians at the gate,' highlighting the unprecedented level of online threats faced by enterprises today. He emphasizes that our entire existence, from banking to healthcare, is now digitized, yet built on a security framework that is fundamentally flawed. This segment sets the stage for understanding the urgent need for a new approach to enterprise security.
"welcome to the a 16z podcast I'm Michael Copeland and we are continuing our discussion of security and we are lucky to have Andrew Rubin CEO of a loomio and co-founder and along with Andrew Gough Bang..."
Rubin discusses the shift in mindset regarding security, moving away from a binary view of being either safe or breached. He argues that with the current landscape, it's almost assumed that breaches will occur, and the focus should be on reducing the attack surface once a breach happens. This segment highlights the evolving nature of security conversations in enterprises.
"means that never before have we had so much online court encode computerized or every existence every aspect of our existence how we invest how we get paid how we do health care how do we deliver powe..."
The tension between operational speed and security is explored as Rubin explains how enterprises are prioritizing agility. He notes that the faster enterprises move, the more challenging it becomes to maintain security, creating a friction point that must be addressed. This segment emphasizes the need for security solutions that can keep pace with rapid business changes.
"be breached and you may not know it right away and what we're hearing more and more now is this concept of how do I reduce the surface area of attack when I'm breached that's a very different security..."
Gaurav Banga discusses the necessity of re-evaluating security architecture in light of cloud computing, mobile technology, and increased reliance on the internet. He stresses that security must adapt to these changes and be designed to support faster operations. This segment underscores the importance of innovative security solutions that address modern challenges.
"so go for you guys how do you address that tension between going fast operations and you know security we've been talking about this how you know you need to respect security but you need to get thing..."
Rubin shares insights from customer feedback indicating a willingness to rethink security from first principles. He highlights a significant change in enterprise attitudes towards security, where customers are open to exploring new solutions that address contemporary challenges rather than relying on outdated models. This segment illustrates a pivotal shift in the security landscape.
"problem and it turns out that it is I mean we let the message of hope it does turn out that you know it is possible for human innovation to come up with such a design which is more sophisticated a mor..."
The conversation shifts to the challenge of anticipating unseen threats in a rapidly changing IT environment. Banga emphasizes the need to return to foundational principles to understand the evolving threat landscape. This segment focuses on the importance of proactive security measures in an era where the nature of attacks is constantly changing.
"change in the enterprise of the customer mindset that goes chicken Jolla I guess with with this shift to the cloud right I mean they're they're willing to look at that in terms of running a business a..."
This segment explores the shift in security assumptions from a binary perspective of safety to a more nuanced understanding that breaches are likely. It discusses the importance of assessing the potential damage from attacks and how organizations can prepare for incidents by reducing their attack surface and understanding their vulnerabilities.
"warden crime is as old older than mankind as old as mankind why do you want to look at it so the way you want to think about this is go become a student and war and crime what how war and crime works ..."
The conversation shifts to how security should be integrated into the infrastructure from the outset rather than being an afterthought. This segment discusses the concept of micro-segmentation and how it can help organizations minimize their attack surface by treating individual workloads as separate entities, thus enhancing overall security.
"attack because there's a premise that security functioned in a very binary world for a long time Security's job was to keep you safe and safe inherently meant that nothing was wrong and of course when..."
This segment focuses on creating a secure environment that empowers users while maintaining safety. It discusses the use of virtualization to isolate untrusted applications, allowing users to interact freely without compromising the entire system. The analogy of disposable gloves illustrates how controlled environments can enable safe exploration of digital spaces.
"attack go after you guys there again there's this idea that wow its security it's gonna slow me down it's gonna be a pain in my arse you know how do you make sure people use it and how do you advise y..."
This segment contrasts courageous decision-making in adopting new technologies with the foolishness of clinging to outdated systems. It discusses the risks associated with maintaining the status quo in security practices and emphasizes the necessity for organizations to embrace change and adopt innovative solutions to address evolving threats.
"where you're designing the infrastructure from the ground up in such a way that saying no to the end-user is not an option you are going to be secure in spite of the user of being able to do one thing..."
The discussion turns to mobile security, highlighting the unique challenges posed by smartphones and tablets as vectors for attacks. It addresses the limitations of traditional security measures in mobile environments and the need for CIOs to gain visibility and control over mobile devices. The segment emphasizes the importance of identifying high-value targets and securing critical data across all access points.
"to fire somebody right or smart is realizing that things are changing go through this process of selecting and deciding what is good but could be good taking them to the paces and moving that move int..."
In this segment, the conversation focuses on the proactive approach to security, questioning the assumption that attacks can be entirely prevented. It discusses the increasing frequency and severity of attacks and the importance of understanding the organization's assets and vulnerabilities. The segment emphasizes the need for a comprehensive understanding of security threats to effectively mitigate risks.
"it's in a sense it's a fool's mission number one because it's hard to drill that kind of control over an organization nowadays and number two because it's somewhat antithetical to the way that the bus..."
The conversation shifts to the complexity of securing dynamic and scalable environments. The speakers emphasize that visibility leads to knowledge, which is crucial for effective protection. They highlight the challenges organizations face in maintaining an accurate understanding of their assets and the need for continuous adaptation in security strategies.
"premise of the question right and what we're finding is that the the definition of proactive is to actually understand exactly what it is that you have where it's running how these things are talking ..."
In this segment, the speakers discuss the necessity for security models to evolve alongside changing business infrastructures. They argue that security must adapt to the speed and agility of modern enterprises, and that the definition of 'winning' in cybersecurity is about enabling business continuity and competitiveness rather than simply defeating threats.
"there's been a lot of security thrown at a lot of organizations without really truly understanding what it is that it's protecting because as Gaurav mentioned a few moments ago you know the world's go..."
The final segment emphasizes the importance of embracing change within security strategies. The speakers stress that risk must be managed intelligently and that security leaders need to empower their teams to innovate. They conclude by reiterating that the landscape of cybersecurity is constantly evolving, and organizations must be prepared to adapt to maintain their competitive edge.
"lot of technical work to do in that and then also we have we have very primitive controls across countries we don't have the Interpol equivalent if you will if we don't have the nation state donation ..."