George Kamide

speaker
99 appearances 1 recordings 1 series first heard Sep 2024 last heard Sep 2024

George Kamide’s voice in public audio — every appearance, attributed to the second.

Trend

recordings per month · last 12 months
No recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.

Appearances

newest first · ▶ plays the moment
Which is to say, like, no other humans have had to deal with this level of complexity. We're talking about code level complexity. Like, is somebody going to brick all the John Deere machines through, you know, some vulnerability? Is somebody going to ransomware just key suppliers like JBS? And so it's fine to say, like, I think I have it, but I'm going to this is my process for making sure like.
Who are you to think? I mean, no other part of the economy has ever been this complex. And that's sort of like the crazy thing about living in the present is it is always at its most material complex. And so it should be fine to be like, I don't know. I'm not certain. It's, you know, let's check that.
Yeah, there's a joke to be made about silos, given that we're talking about farming. I will not make it. But to your point about people and culture, which is a word I've probably overused this episode, is also creating a culture where people can dissent, where they can argue, where they can raise issues, right? If
If we post 9-11, try to empower literally every citizen of these United States to, if you see, say something, say something. But we do not allow that, I guess, break from the rank and file in our internal teams. Like, no, who are you junior analysts to like raise this concern? This is an obvious problem. Right.
So you're not going to tech your way out of it, but you can build processes where people can either review each other's work or they can begin to say and feel comfortable raising their hand. I think that's from and, you know, best case scenario, they're wrong. Great. And but you have like don't use that as a punishment against them.
And as long as it's, yeah, as long as it's good faith and it's not, you know, boy who cried wolf. But like, I don't, again, especially from a CISO perspective, you know, 90% of the CISO's job is not like hands-on keys. It's, it is negotiating these different processes inside an organization may, and again, procuring technology, small portion of that pie of responsibility.
And so to imagine that like the upper echelons of a security organization can keep a read on the pulse of everything is sort of delusional, right?
You actually do rely on the people who are, they're watching the logs or intercepting the packets or whatever, doing that work and then being, feeling empowered to stop the presses, push the button, whatever it is to pause and like, let's review what looks to be an anomalous event or whatever, and, or
you know just architecting your teams to have that because right now i think the way we have built our teams is built around an old-fashioned model of how we works like network switches in the basement we don't longer have that it's in the cloud right code built in-house yes but also third-party code repos And even human specialization, right? You are the insider risk manager.
You are the SOC analyst. You are the tier two SOC analyst. You are the incident responder. You're the forensic person. The volume and complexity that we're dealing with today, I think we need to learn new ways and experiment with new ways to make ourselves a little bit more agile, not in the code dev sense, but like being able to respond because
As AI tools get layered into new technologies, which they will because there's just a market pressure to do that. I don't think that the teams we have today can ingest that information that fast. I think if you're architected for human specialization and you have machines also specializing, you create enormous bottlenecks in your ability to respond, triage and do whatever else. And so, yeah.
I don't know. I think that's interesting. I think it's a hard problem to solve. I would say it's not unique to security. Entire businesses have been built around this level of human specialization. And I think the best organizations in the world will start to invest in either organizational psychologists or just new ways. You know, like we went from kind of specialists. Right.
Well, we went from like, you know, I think the most visible reminder of these changes is going from like cubicle to open office plan. Right. That was interesting. supposed to be a physical way to get more collaboration, more sharing. I would argue that didn't really work, but that was an idea that like, this is how we should organize teams or a lot of the tech in the Valley is organized very flat.
Again, they were experimenting with how do we foster innovation? Well, okay, so they're re-architecting things for innovation, delivery of product. How are we architecting teams for faster response, faster recovery, greater resilience, right? Again, like you have these teams under budget constraints and you lose one part of your team, either to layoffs or a riff or whatever.
Like, do you just completely lose all that talent or have you kind of cross-trained your team? I mean, people get sick, death in the family, serious injury. Are you telling me that if that CTI lead is out, for a couple of months like you just don't have. I don't know. Like, how do we think about resilience within our teams as well?
Stop being so Northeast. That's fun.
Yeah, I mean, Bare Knuckles and Breast Hacks will be keynoting, will be the closing keynote of Secure World Denver, October 10th. I think that's very exciting. We are keeping it pretty close to the chest, but the title of our talk is Radical Transparency. I think if anyone knows us, they know that you might need a fire extinguisher after we're done, but that's the way it goes.
It's been a very busy year and we'll just keep pushing on the culture front, really.
Absolutely. Thanks for having me.
Showing 81–99 of 99 · page 5 of 5 ← Previous