Securing the Agentic Enterprise | Interview with Charlie Lewis
Welcome to Secure and Simple Podcast. In this podcast, we demystify cybersecurity governance compliance with various standards and regulations and other topics that are of interest for consultants, CISOs and other cybersecurity professionals. Hello. I'm Dejan Kosutic the CEO at Advisera and the host of Secure and Simple Podcast. Today, my guest is Charlie Lewis from McKinsey and Company Consulting Company, and he's a partner in McKinsey's Connecticut office and leads the firm's cybersecurity and technology resilience work across North America and Europe.
Dejan Kosutic:He has published several articles on cybersecurity, and one of the latest ones is called Securing the Opportunities for Cybersecurity Providers. So in today's podcast, you'll learn how will this cybersecurity provider market change in the near future and what should CISOs do about it. Welcome to the show, Charlie.
Charlie Lewis:Thanks for having me. Really excited about this conversation and this topic, especially with everything that's going on today in the security world.
Dejan Kosutic:Great to have you here. So, you know, your article argues that the next phase of growth of these cybersecurity solutions will actually not come from, I would say, completely new product categories, but from actually that it will reframe the existing categories, which is kind of surprising, I mean, because AI tends to change everything, all business models and technologies and so on. So how did you actually reach this kind of a conclusion?
Charlie Lewis:Again, and you're right, right? Our conclusion is that this next era of cybersecurity is, it won't be defined by new categories. It will just be defined by reinvention, right? Reinvention of identity, reinvention of detection, security operations, right, response, thinking about vulnerability management now with Methos and Glasswing, right around these autonomous systems. And so if you think about the success that the cyber market has had, and our numbers show it at about a $220,000,000,000 market globally, the likelihood of it growing at about 13%, roughly 13% CAGR over the next several years, right?
Charlie Lewis:But we do actually believe that unlike these prior waves, we will not necessarily see new market space. We will just see the role of agents in these autonomous actors in the enterprise requiring shifts in existing control planes to account for agentic AI, but those control planes do tend to remain the same.
Dejan Kosutic:And one of the emphasis in your article is around identity management. So what do you see will mainly change when it comes to identity management?
Charlie Lewis:So as we think about this, and again, what's fun about this article is it was published before RSA, and we try to get these perspectives out before RSA. But boy, a lot of things have changed since RSA. But one of the conversations that we still have, although interestingly enough it's not as frequent, is that non human identities are really becoming the next cybersecurity frontier. And I agree, I think this is actually one of the most important concepts in the article. So if we take a step back and we think about what is sort of a typical identity access management program, right?
Charlie Lewis:We typically think about you have employees, you have contractors, you have service accounts, Within there too, you have your regular users, then you have your privileged users. And so now you think about taking what is a sort of a sheer number and you think about we have maybe thousands, tens of thousands, perhaps millions of agentic identities that are operating, right? And so what you start seeing now is that every company is about to become the manager of a massive digital workforce. And so as we go from here with long lived identities, stable permissions, periodic reviews, we now have agents that will be created dynamically. They may be destroyed or turned off dynamically.
Charlie Lewis:Their permissions might be constantly changing. And traditional IAM just was not designed for this. So as we sort of take a variety of different agents and say you were to have a customer service agent, see a lot of Agentic builds there, you take a fraud investigation agent, maybe a financial or finance reconciliation agent, and then procurement agents, and you put all of them together, they all now start interacting. And how do we make sure that we know that they have the right permissions to be able to execute the work or that they don't change their permissions. And so what we're seeing organizations starting to have to do, and we're also seeing providers in the identity space think about, is how do you move from workforce identity management to workforce plus agent identity management?
Charlie Lewis:And you think about that from pure IAM standpoint, but you also have to think about what that means from an employee and the managers as they start having to apply additional controls and requirements around the agents that are helping them and supporting them with their job.
Dejan Kosutic:I mean, this is really a complex issue, right? I mean, first of all, non human identities will be probably much more numerous than human identities. And as you were saying, their, let's say, level of access will change. It will be probably some kind of dynamic access, and they will be probably also short lived. So, I mean, taking all of this into account, it's it's a really complex problem. So did or do you see that the security vendors are actually already solving this problem or the solution is not there yet?
Charlie Lewis:I mean, I think from our standpoint, we're seeing a little bit of both, right? I think the solution, it is a bit hard at this stage, folks are still trying to figure out their human identity access management programs, right? You and I have talked, I spend a lot more of my time on the foundational capabilities, right? And you still need those. When we talk to folks about Meetos, right?
Charlie Lewis:It is still great, you have your Meetos side and everything you need to do there, but let's talk about the foundational controls, IT asset management, identity and access management, your network segmentation, etcetera, etcetera. And so how do you take, how do you think about those foundations, but now like you said, you have to put it up on the agentic side. So you still have the legacy identity and access management across that entire workflow, those type of tools, and they are looking at building out, you know, Agentic identity and access management programs. If you think about the role of IGA tools and how do you accelerate and meet the governance at that stage. There's a funding component with this too, right?
Charlie Lewis:Maybe it's not a per identity cost, maybe there's something else that goes there. But then we're also seeing new startups, right? And I think that some of these new startups are really redefining the way that you allow agents to move through and control agentic movement and access to data. And they're learning a lot from the leading companies and the leading enterprises around who are using agents and their mapping. I saw it too, I saw a cloud security leader from a leading tech and I saw a startup agentic identity founder actually come together at RSA and we were talking and they both started drawing their approaches that they were thinking about and there were a ton of similarities there.
Charlie Lewis:And so we know that organizations are doing it, but many of the large enterprises are so complex, they're trying to do it in small pockets as they build out their agentic use cases.
Dejan Kosutic:When we speak about identity management, okay, there is obviously a technology part, but there is also, I would say, organizational part, so to say, I mean, how to define these privileges, how to authorize them and so on. What do you see as actually changes from this organizational point of view when it comes to identity management?
Charlie Lewis:That is a phenomenal question. And I think that if you were to raise that question with a lot of identity and access management leaders within organizations. That's why they have gray hair, right? And that's why they're losing their hair. Because when I think about security, many times security is, identity is the one place, both the workforce customer identity and machine identity now.
Charlie Lewis:That is one of the core places that the security team interacts with the business and the business interacts with them. That and probably some of the development side, right? And it's a lie and then they think about security in October for Cyber Awareness Month, and then when they click the fish button. Right? But every day they're logging in.
Charlie Lewis:They're using their various assets for MFA. They're whether it's me on my MacBook with my finger or using Windows Hello, the Duos, the Octas, etcetera, etcetera, as you're as you're logging in. That's the main interaction. You now actually have to take that struggles you had getting that up and running and you have to frame the specific requirements and the controls and probably be a bit more secure around your data requirements. And so how do we think about data classification?
Charlie Lewis:How do we think about structuring our folders and making sure that we don't have random pieces of say end user compute sitting on a laptop that, you know, your desktop with employee data or financial data or chin and comp data that is not controlled in the way that an agent is then able to see it. And so the change management I think is going to be fairly significant here. And the change management is not just about the identity, it's not just about the permissions, it's how do I manage the use of my identities? How am I making sure that my identities move with maybe the employee, right? If the employee leaves the organization, we turn off their agents.
Charlie Lewis:If the employee moves within their agents, either disappear or get different permissions. But then I also have to frame this into a broader data security and data governance and data privacy. And so identity with agents, just like identity and data otherwise, becomes much more cross functional, right? I'm talking to the business about what they need. I'm talking to legal about the privacy component, and then I'm talking to the data team about the governance, and then I get to security as I think about the broader security.
Charlie Lewis:And if you only think about identity as run by the identity and access management tower within the security or a CIO's org, you're probably falling too short and you're gonna run into potential hiccups, either security risks or just slowdowns in your operation because you don't have the right permissions.
Dejan Kosutic:Is than a solution to have, let's say, inventories of, let's say, data and systems and clear owners of these?
Charlie Lewis:Again, keep bringing me back to phenomenal questions, right? It's critical here. And this is why we can talk all we want about, and this is why we go back to our argument and what we say that it's not necessarily about new categories or entirely new categories. It is one, the reinvention of existing categories, and then the updating of certain categories to be able to account for what you need. And so I think about IT asset management.
Charlie Lewis:Everyone gets bothered by management. It is difficult. It takes a lot of time. It's boring. You run into data quality Hey, this is what I do all the time, right?
Charlie Lewis:So, you know, but it is. Right? But it like But that's fair, right? It is not the cool part about security. But no part of security can do their job effectively if you don't have, in my view, if you don't have a strong ITS management role.
Charlie Lewis:So if you think about what is it, know, there's sort of three core customers to an IT asset management program. Number one is procurement to make sure you're getting what you paid for. You've got the right number of licenses, etcetera, etcetera. Number two is your tech team, right? IT operations, infrastructure team making sure you know where everything is.
Charlie Lewis:Because we know that when a cyber crisis hits, it's the infra team that's getting everything back up and running, while the security team is cleaning it up, right? And so they have to know where everything is. So your customers, consumers are your IT asset management or are your IT team. And then finally, obviously security from a vulnerability management, from an incident response, You have to know who to call. You've got to get within there.
Charlie Lewis:You have to have that foundation now for what you had in the past. And then you have to be able to build a new way forward. One about what is my data? What are the controls and the requirements around that type of data? Do I have the right tagging?
Charlie Lewis:What is the data flow mapping? I was actually sad when they redid NIST because NIST CSF one point zero and one point one had ID. Am as the first sort of category and it was always my great story. Asset management, right? In the US government, the first thing you list is the number one priority and ID.
Charlie Lewis:Am was the And number one priority so you have to bring that in, but then you now have to think about your agentic registry And how am I classifying my agents? And you need to layer on all of that again. So that's why it comes back, it's not new categories, it's the reinvention of the old one. And the winners will improve and be able to integrate and accelerate and maybe make the boring and painful, still boring, but less painful.
Dejan Kosutic:Let's pitch a little bit to this other, I would say hot topic and this is obviously Mythos and vulnerability management. So how will tech vendors actually change their approach or their solutions because of these kinds of new threats and because of mythos and whatever will be in the future besides mythos?
Charlie Lewis:Yeah, I mean, look, it's going to be there. It's what everyone is working with. And I think the way I sort of think about it, right, the future of cyber is not simply about detecting bad behavior, right? It's governing autonomous behavior overall, and it's getting a bit of that structure. And so I think a little bit about this is right, the traditional security approach just doesn't necessarily work here.
Charlie Lewis:Whether you take the Mythos and sort of what we see from the core vendors now about rapid identification, attack path analysis. You know, I joke about like overly verbose endpoints are now the new thing I talk about because that's an easy way in, it's an easy way to identify. It's also just funny to me that a McKinsey consultant gets to talk about how bad something that's overly verbose is, right? And so I'm able to bring all of that in. But you have that.
Charlie Lewis:You then like typically have user authentication. You typically monitor endpoints with envoy detection and response in like, even think of the old days with antivirus software, very sort of malware signature based. You think about attack detection, the time for the trigger, your time to be able to respond, how long someone has been in your network, and then you get to investigate the alert and you spend that time. When you start thinking about agents in the mythos type approach, one, right, we said the attack path prioritization. So thinking about my broader business continuity program, how do I think, again, back to the ITS and management, I have to be able to understand where those sit.
Charlie Lewis:Right? But within here, as I shift from sort of this detection to runtime governance and always having it on, I have to continuously observe behavior. I can't just stop watching the agents. I need to make sure they're doing what they are supposed to do. I have to enforce policy.
Charlie Lewis:Policy becomes critical during execution, right? We need to be able to enforce that policy. We have to stop unsafe actions in real time. Right, it's like if you think about now, your credit card might think about you just once. If your credit card thought about you once and it got stolen, they may not stop it, right?
Charlie Lewis:But a credit card company now today, right, they're not just verifying you upon getting it, right? They are evaluating transactions and can decline in real time. If I'm making a purchase in Connecticut and then suddenly it sees it down the street from you in Croatia, right? They're likely going to stop that and you need to be able to have that sort of continuous view in the same way around agent security and really more specifically how you think about agents operating within your environment.
Dejan Kosutic:Okay, now, if most of these, let's say security operations are getting, let's say more or less automated, what does this really mean for a government, cybersecurity government? So, because you have something that is running at the computer speed, so how do you actually monitor and manage all of these things?
Charlie Lewis:Yeah. Look, I think, and this is actually, this actually typically is what draws a lot of interest in these conversations. I just think the humans move up the value chain, right? The human is still involved everywhere and when we're building out and thinking about the agentic CISO and some of these future moves broadly, the human is still there. We're actually not seeing that much of sort of a drawdown in terms of a lot of the jobs.
Charlie Lewis:We're actually seeing sort of an uplifting in the capability, especially as you think about the need to manage a lot of these agents, right? And so as the humans move up, right? So and I know our article cites, right, that we think that you expect 35% of the interviewed CISOs in here expect AI agents to replace a tier one SOC analyst, right? And that they do expect, 50% expect AI to be embedded across the cyber stack within three years. Look, actually think it's gonna be a bit faster, right?
Charlie Lewis:But that's typically how we run our surveys from a data standpoint. But folks are embedding them much faster, right? But again, like I said, the human is moving up the value chain within security, right? And they are becoming, and that allows the human to do more of I think the critical contextual driven work that has to happen. And so if you think about what today's analyst does, they're reviewing alerts, they're triaging tickets, they're collecting evidence, right?
Charlie Lewis:The future analyst is gonna supervise AI. They're going to review exceptions, which still needs a human and understands, right? They're gonna have to handle novel incidents, right? And now that we understand that a lot of the mythos are sort of standard attack types, but novel attack paths, you're probably gonna see there. And then they have to govern policies.
Charlie Lewis:So if you think about it, right, the future SOC is human supervised and it's machine operated, and so you still have a lot of those lines, folks on that sort of in the various lines throughout the organization. And I don't see in the orgs that we're building humans going away. I actually used it pretty well in consulting, right? You can talk about what we do from a consulting standpoint, but if I can take a set of agents and have machine operated analysis where I then have the human consultant do more of that and oversee that, again, they're moving up the value chain, they're moving up the line, and therefore they're able to do better, deeper work to help our clients achieve their outcomes.
Dejan Kosutic:What do you think, what kind of skills actually will be the most valuable in this new cyber world, I mean, for companies?
Charlie Lewis:Oh, that is a really good conversation. I think one of the most critical ones for me is around security architecture, just generally. I mean, let's actually take a step back. Number one, think that everyone should This is a great opportunity for security professionals, right? We all love to play, we all love to build, right?
Charlie Lewis:And we all love to learn. Like that's, in my mind, every successful security professional, that's what they wanna do. When we talk about retention, right? There's a lot of organizations where I mean, yes, they want more pay, right? But they also want good training, right?
Charlie Lewis:They wanna be able to attend training, they wanna be able to go. And so for me, number one, everyone should be understanding what they need to do. But I think security architects and security engineers still matters a ton as you think about this, right? So as we saw in the interview, like CISOs identify the challenge, right? But they also recognize that their existing architecture is not designed for human users, or it's designed just for human users, not for agentic ones, right?
Charlie Lewis:So how do you think about the governance of this in overseeing that? I think there'll be an increase in the ability, right? And then you're gonna think about the increase of the ability to actually build these agents and understand understand them and consume a lot of data. Think, and we see that there'll be skills around secure development will still matter and you need to think about not just secure development, but you gotta think about the threat modeling, etcetera, etcetera. And then finally, this may be a bit of an interesting one, but I actually really think that the ability to build knowledge graphs understand how to consume and use data in different ways matters, right?
Charlie Lewis:And the way I say this is we look at what we think a Meetos agent may do, right? Or a malicious agent, well it's not tied to those, a malicious agent and what they may do. They're gonna look for the node that where they can create the most disruption. And the only way that you can really fully understand that is in my mind thinking about mapping all of your core business processes, thinking about them as graphs. And then underneath there starting to map the data flow we talked about, the applications, right, and all of the infrastructure that they rely on, as well as the various agents that you need to have at play within there.
Charlie Lewis:And this might also include SBOMs and AI BOMs, and you'd be mapping your third parties. And so you're having all these views and you can most likely find some of the critical nodes in the same way a large manufacturing company will know where their critical nodes for an operation. And businesses that are digitally driven, that are becoming AI native, they will have to understand where those critical points are and really secure those. And to me that matters a lot. The others, and then if I could add one thing, because I just run.
Charlie Lewis:I am really interested to see what happens on the operational technology side. I think folks who operate there are very nervous around what can be done with mythos, right? End of life, end of support, Right? Still a lot of concerns about the difference in terms of identity and different splits within, you know, your IT network and across the DMZ into your OT network. How are you still moving the data in real time?
Charlie Lewis:How do you protect against your own agents? Right, but then knowing that there's probably likely vulnerabilities, how do you bring that conversation in and improve the compensating controls you have in place while still being able to operate? And if you think about it in many organizations, OT sits within the COO or the business side and not security always. No. That was long winded, but you got me on a bit of a a rant there.
Dejan Kosutic:Oh, thanks thanks for this insight. Now going back to this thing that you emphasized as as important of mapping actually and making these graphs of of where are the main, let's say, pain points, if I can use this word. Now do you think that Yeah. That's actually a skill of understanding the business processes and the business side of the company is important actually for making these mappings?
Charlie Lewis:100%, right? So I think, you know, again, this goes back to, it all goes back to ID. Am, the IT Asset Management Program, right, or your disaster recovery program, your business continuity program. You have to, it's no longer, right, and we know like the shift from individual vulnerability mapped to an individual asset now to a set of chain vulnerabilities and attack path prioritization. The only way you can prioritize the attack paths given what we think will happen, right, is one understanding sort of what matters most to the business, starting to do that mapping, and then really thinking about the exposure that you have.
Charlie Lewis:And so the Mythos is in our view, it's not just a cyber problem. It's not just a technology problem. It's actually a really, it is a business problem. And that's from an investment standpoint, it's from a patching standpoint, but it's also from a broader, how do I understand what to get up and running faster? And if we're going to live in a world where there could potentially be multiple simultaneous high severity events, then we have to think about how do we best prioritize our exposure and our risk and how do we think about continuously updating this and adapting from there.
Charlie Lewis:And so you have to anchor that in to the reason why you're working in the job you are and it's to protect the company that you're hired to. And you have to do that based off of the core value system. One of my colleagues says like, do you need to protect the menu as much as you have to protect your critical R and D and how do we think about that? I also think from a security professional standpoint, knowing what's going on, you have to understand the different cultures within your business, right? R and D has a different perspective often say than like finance or HR who are used to really protecting the data and serve other roles.
Charlie Lewis:And so how do you make sure the right controls and operating models are put in place? And then how do you monitor against that?
Dejan Kosutic:If I may ask you, how is the role of cybersecurity consultants going to change because of these technological changes?
Charlie Lewis:That's a really good one. Look, mean, I think the number one, I recognize the role that I play within the broader ecosystem, right? And that what I really try to do and what we try to do at McKinsey is first off understand and listen, right? Because every CISO in every organization has different issues that they're grasping with. And then, you know, it moves so much faster, right? Reading an IT asset management manual back in the day was pretty easy.
Charlie Lewis:Now we have to stay on top of it because we have to adapt for our clients, right? And we're talking for us, we're talking at the C suite, we're talking to the CISO, we're talking to architects, product security, whoever wants to, whoever has questions to reach out. It's been really busy. But I do think a couple of things for us is number one, we should go deeper, further, faster for our clients in terms of our analysis. That's number one.
Charlie Lewis:Number two is we have to recognize and build the same skill sets I talked about, right? I have to understand that from an OT side when I roll out a roadmap for someone that OT is probably owned elsewhere and I have to help the CISO build that relationship, right? Because we likely have that as well. And so a lot of it is just adapting with the CISO and making sure they bring what they have to have in the business. And then I have to have people who have the real skills.
Charlie Lewis:It's no longer just about PowerPoint, right? It's getting into Cursor, right? It's using Claude and Claude code and taking advantage of ChatGPT. At McKinsey, we have Lily that operates on Gemini, right? They're all up and running on our computers all the time, right?
Charlie Lewis:Just like yours, and we have to get better at all of that. And our world's just gonna move just as fast, and our job is to help hopefully make it slightly easier and less overwhelming for our clients.
Dejan Kosutic:Great, so there is a future, this is important. Many consultants are afraid of this.
Charlie Lewis:I mean, I hope there's a future. I have to pay for a birthday party in a couple of weeks, you know, so, and college more importantly.
Dejan Kosutic:Going back to your article, you actually in the article, you mentioned these five key recommendations for cybersecurity vendors, you know, on what they have to do and on how they actually have to kind of direct their development. So can you kind of summarize what are the most important conclusions there?
Charlie Lewis:As we generally think about, or really as sort of I think about what needs to happen, right? So number one, we know that agentic security spend is gonna increase from 4% today to 15% of your security budget within three years and probably faster, right? Organizations expect agentic adoption to roughly double, right? And that AI is going to be, needs to be deeply embedded across security stacks. And so what does that mean and what are some of the concerns, right?
Charlie Lewis:Like generally the word of like CISOs are worried about prompt manipulation, monitoring the models, how do they think about the security models, AI governance, model drift, data leakage protection, right? And so when we go through here, it really comes down to some of the core components that if you are a security vendor, you don't necessarily have to rethink or rebuild or do something new, but security organizations in my view, you need to build out the You need to understand the role of agents and machine speed in the future. And your customers are going to look to want to buy this. And it's important to be able to come with an end to end solution that meets the customer's workflow needs. And you have to be able to do this within your organization.
Charlie Lewis:And it is not, and what I see actually, because we wrote these five things, but actually what I'm seeing now is some of the key buying factors are shifting. They also don't want it just to be like hammered in or jammed down. Was funny when I was I served in the army and when we were in the rack the first time, we just started like We didn't have up armored Humvees, so we just started screwing more steel onto the Humvees, right? You can't do that in security. You can't better protect yourself with more steel, right?
Charlie Lewis:You actually have to rethink the equipment in the same way the US Army did and other armies have since then, right? You have to rethink the equipment that you're bringing. And so if you think about, well, how do I do faster response, right? Well, what does that look like? If you are thinking about an IT asset management and you build an IT asset management program, how do I think about making that, taking the data there and automatically making that knowledge graph we talked about?
Charlie Lewis:If it's about rethinking your network security, how do you anchor in agents that help you balance the load across your network over time to reduce your network resilient, your outages from a higher frequency to a lower, and then think about the prioritization. And then there's just generally how do you think about the machine operated security space, right? And I think a lot of folks are gonna do less building internally except the most talent, like the largest spenders, and they're gonna actually go out and look for these vendors. And the vendor who wins, right, comes and understands the client's problem and helps them build that agentic security organization of the future. And so that's really my view across there.
Charlie Lewis:And then obviously it's sort of some of the core stuff, right? Operated systems of record, think about mission critical workflows, how do you anchor into what the business knows, and it goes back to what we talked about, securing this specific business.
Dejan Kosutic:Okay, one of the things that I noticed in your article is that because of these, let's say, shifts in budgets, where actually there is a better proportion of budgets going towards AI and cybersecurity budgets are not growing as quickly. So, one of the things that you mentioned in the articles is that the cybersecurity vendors will actually have to look beyond CISOs to actually sell their products, right? So, from the CISOs point of view, what does this really mean? You know, if the CISO knows that actually these vendors are now, let's say, avoiding him. Yeah.
Charlie Lewis:So I will give you some inside baseball. We had a bit of a debate on this one, right? I slightly disagree with this, I understand what the purpose was here, right? And so the language really becomes, if you think about many organizations with product security or a large development organization, how does a seller of a security product go to the right buyer and find the right buyer? And so if I build an AI governance tool or I'm building something with agentic identity, is that a security problem or is it the head of AI problem?
Charlie Lewis:And so having and recognizing cross functional there. If we wanna create and move faster through our secure development process and we don't want to slow it down even though our data says it doesn't slow down getting products to market and I'm selling agentic threat modeling, DAS SaaS, right? And building all of that and working that whole workflow. I need to go to the development teams, the CTO, the enterprise architect. I have to go to those folks to help understand what that is and help them sell.
Charlie Lewis:So, right, the story is actually that the security budget is gonna grow. The CISO has their foundational central controls, but as organizations and we've seen this get more mature, some of these security capabilities can be pushed outward into the business because it's more effective, it meets business needs and allows you to deploy it better at scale without having massive security teams that are doing some of the sort of core work that maybe in the future an agent can do. And so that's what it becomes, you start pushing it out. Security budget remains the same, but the deployment of some of those tools and potentially the decision makers are outside of the CISO organization. And I think that that's a good thing, right?
Charlie Lewis:Because the closer the CISO is to the business, the closer security is to the business, the more likely your business is going to be better secured in my mind, because that's where we start seeing the controls applied to what really matters. So you're getting a risk based approach. Typically it's a more mature organization that's able to push, but you still have and you can productize what you wanna bring out. You can create security platforms that others can use, but you still have a lot of the components that are centralized as well as the requirements and you can't get additional exceptions. Right?
Charlie Lewis:And I also think it helps reduce sort of the shadow security component within there too, which is actually a massive risk as And that's a little bit about how I think I got comfortable with that comment. And I think it's actually a really good one in showing that if you are selling, you need to be in a room with people other than the CISO and people who will use your product and you'll be much more successful in the sales direction.
Dejan Kosutic:Okay. Now, what kind of questions actually do CISOs need to ask, let's say today towards their vendors and they didn't have to ask, let's say, year or two ago. So what are kind of the new things that CISOs need to take into account when buying these solutions?
Charlie Lewis:I mean, look, think a few things are thinking about how do you get down to, CISOs are still at times now they get a bit of a boost, right? Methos is really giving a boost, right? But number one, if I'm a CISO, I'm asking about the data insights that I can get. What can I learn more about anomalous behavior from agents? How can I take that and better remediate it?
Charlie Lewis:How can I look to collaborate across my different environments, right? And think about various internal and external sources, right? How do you as a vendor help me get my mission critical workflows more secure, right? So if you think about compliance work and we know that compliance services, we know that software providers who do this, right, they tend to have a lead in here. But if you're a network firewall provider, right, could you help provide AI enabled firewall capabilities that then inspect the traffic for compliance in real time, right?
Charlie Lewis:That's an example that came out of the article, right? And like, if you're looking at that, those are the kinds of questions, right? What are those next steps? If you come in and you're providing me help with my vulnerability management program and I now have access to Meetos or 5.5- Cyber, can you help me get my harness up and running so it runs more effectively? And then I think there's a little bit about the runtime controls.
Charlie Lewis:They should be asking about runtime controls. They should be asking about their SIEMs, right? The security information and management tools. Should be asking about the adaption of endpoint detection and response and how does that improve? IAM, right, Identity Detection and Response, how are you pulling all of these in, right?
Charlie Lewis:And again, it gets back to avoid the bolt on and embed. And CISOs should be asking about is this embedded, right? Or is it bolt on? And how does it help me make better decisions from a business context standpoint and learn from the data? And the best nerds are coming with the technical folks, right?
Charlie Lewis:A set of consultants and their sales folks who can do this conversation and then can engage at that level of technical depth and help really improve the CISO versus just trying to sell them a
Dejan Kosutic:product. Okay. Now, would say a big proponent of security as business enabler, right? But with all of these technological changes, is it really still true for security that you can actually enable business or security has to deal with something completely different now? I mean, catching up with the technology.
Charlie Lewis:So I think that security can, will, should enable and can enable and it's necessary, right? So if you think about what we talked about with who wins in security from a provider standpoint, right? It's the same thing. The winners of the future of regular companies are gonna be those who, right, build and improve AI and use AI to improve the outcomes for their customers, right? Improve value, improve better health delivery.
Charlie Lewis:Those are the folks that are going to win. Security has to do the same thing. So if you take what a security company who's gonna win in this space, right, they aren't the ones that create the standalone security or AI security tools. Again, the winning security will have a platform that embeds the AI governance, that embeds the policies, that embeds the types of controls that you need directly into the technology build, your AI builds, directly into your identity program, both your human and your agentic identity, right? Thinks about what do I need to do to better improve my data?
Charlie Lewis:And then on top of this, there is a core conversation that still happens around resilience, right? How do I think about resilience across the entire OSI stack? How do I build resilience in my network so the network doesn't go down, and then on top of that improve my data and my database security, and then keep my applications secure and running and doing the job? Security still has to do this. I actually think And then they have to do it while running with, right?
Charlie Lewis:Not towards, but running with the rest of the business and moving just as fast as the rest of the business. But they gotta be fixing in the background, right, and helping in the background. So the way you do that is you start to think about a security product platform. It gets back to what we talked about, about pushing security as far forward as you can, right, and making sure that the business when they go out, they're ready and they're prepared. That your Salesforce is able to talk about how secure and how resilient your organization is, right?
Charlie Lewis:That your core customers are potentially gonna start asking you questions about your resilience, that your business wants to make sure that you're up and running and that you prepared a business and you explain why they have to do it. And then one of the big shifts that has to happen is there's a lot of security shifts going on. The winners in the company change management process, right? Culture change and training. They're lumping these together and demonstrating why to the business.
Charlie Lewis:Those who are struggling are putting out a bunch of different changes all at once or over time, excuse me. And it feels a little bit like the ankle biters that are just there always and there's no justification of it and people think it's compliance. It's no longer about compliance. It actually is like you said, enabling the business.
Dejan Kosutic:Good. So let's wrap up the interview, even though I could speak with you quite a long...
Charlie Lewis:I could keep going, but I know you have to go to bed soon. It's late.
Dejan Kosutic:Anyway, last question. So what are your top recommendations for CISOs? You know, How should they actually prepare in this, I would say new technological environment, cybersecurity environment?
Charlie Lewis:Yeah, I think in my mind, I think there's three things that CISOs should do. I think that number one is to force their way into the business if they're not already there, right? The CISO has earned and will continue to earn the place at the table And they need to be seen as a core decision maker or a core decision advisor, not just to the CIO, not just to the chief risk officer in financial services, but broadly to the business as they think about what additional risk they are going to take on and how can they help that organization be secure and sustainable. That's number one. Number two that I think about is again, strengthen your foundations.
Charlie Lewis:We talked about it before, but I'm gonna add a little bit on there. If you think about agentic workflows and automation, that requires existing processes in place. You need to make sure that process works and it's good before you automate it because an automated process that's broken is still a process that's broken and you have to fix the automation. And so go through and make sure your processes are correct and adapt the ones that need to adapt given the new environment around chain vulnerabilities, around faster remediation requirements. How do you patch availability, regression testing, deploy commit, right?
Charlie Lewis:Like those components that you're bringing in, how do you get those a bit faster? And then I do think that there's the recognition of how do I secure what the business is building? And what I tell CISOs on this one, if they're already building this, how do you think about an agentic governance where as you think about agents, taking a risk based approach of the agentic registry through the agentic registry and you're requiring controls and approvals based off of right in the policy based, know, access your agentic controls, access controls you typically would have based off of the autonomy of the agents. And so you're not just saying everything needs to be locked down. You have to think about it in the same way you do your broader humans.
Charlie Lewis:But what I also say is like, if you don't have an agentic use case in your organization yet, you should push to have it in security because we know now that there's a demand, right? You're gonna secure it, you're gonna understand what works, what doesn't, and you can help the business get a bit better faster at defending itself while it builds out. So you're creating that security wall, you're being faster in your terms of your response because we know that threat is there. And so like my view is where are those agentic use cases you can build for yourself? Again, this goes back to then you work back, well, I've found these workflows, these will be great, And I'm sitting with the business, so let me ask and work with them.
Charlie Lewis:And so all of those come together. The best CISOs, the most effective CISOs in my mind are pushing it in that direction while they're doing everything else for the day job. Responding to incidents, right, making sure they're compliant, SOC one, SOC two, NIST assessments, audit, all of that stuff, right? They now have to do this bigger stuff.
Dejan Kosutic:Hopefully they'll have time to do all of that.
Charlie Lewis:Yeah, right, but that matters, right? It's such a busy time, right? And a lot of times I have a conversation with folks, right, and they feel a bit overwhelmed, or there's a lot going on, and how do they get a break? Like, we're helping folks figure that out, right? How do you prioritize what matters?
Charlie Lewis:How do you understand? Because it is a lot going on right now and you want the business to succeed, you need to succeed, but you still have to get to the family of the league game. You still wanna go out and see you know, your friends and it's important to still be there, right? I always say in a world full of robots, be a human, right? And it's important that we're able to do that.
Dejan Kosutic:Okay, great. So thanks for these insights. It was a real pleasure talking to you.
Charlie Lewis:No, thank you. No. This was great. Thank you. Great questions.
Dejan Kosutic:Okay. Thanks again. And, thank you all for listening or watching this, podcast and see you again in two weeks time in our new episode of Secure and Simple Podcast.
Creators and Guests
