The Core Strength

In this episode of the Core Strength Podcast, we sit down with Stan Lee, Head of Security and Infrastructure at EarnIn, to explore how network security has evolved over the past three decades and why many of the industry's biggest challenges continue to repeat themselves in new forms. Drawing on a career that spans everything from frame relay networks and early internet infrastructure to cloud security, fintech, and AI, Stan explains how cybersecurity has continuously shifted its focus between networks, endpoints, data, and identity as technology evolved. We discuss why concepts like defense in depth, segmentation, visibility, and operational tradeoffs remain as relevant today as they were decades ago, despite the industry's constant pursuit of new technologies.

The conversation dives into the growing complexity created by cloud, Kubernetes, AI, and hybrid infrastructure. Stan explains why networks never disappeared, they simply became smaller, more distributed, and significantly harder to manage. We explore the economics behind security decisions, why organizations are constantly balancing operational efficiency against risk, and why perfect security remains unattainable in the real world. We also discuss how AI is reshaping both infrastructure and security operations, where it can realistically help security teams today, where human judgment remains critical, and why the future of cybersecurity will likely depend on AI augmenting experienced practitioners rather than replacing them. Finally, Stan shares his perspective on developing security talent, why curiosity matters more than years of experience, and how the industry can better prepare the next generation of defenders.

Creators and Guests

Host
Richie Hartnett
Community Director at The Core Strength Network
Host
Ross Haleliuk
Community Director at The Core Strength Network
Guest
Stan Lee
CISO at EarnIn

What is The Core Strength?

Welcome to The Core Strength Podcast, a place for network security professionals who care about getting the basics right. Each episode brings together experienced practitioners to share insights, stories, and practical lessons from the field.

Richie Hartnett:

Welcome to the Core Strength podcast. Every piece of data you create, every system you rely on, and now every AI agent you deploy, it all runs through one place, the network. The network is the foundation. On Core Strength, we bring together people who actually secure modern networks. Security engineers, network architects, leaders, and builders.

Richie Hartnett:

Together, we break down how it really works, the decisions, the trade offs, and the lessons learned from operating at scale in the real world. Let's get into it.

Ross Haleliuk:

Stan, let's start by briefly talking about your career in security. You've done some really incredible things from managing a frame relay network and supporting satellite networks to working at enterprises like Palo Alto and PayPal and now leading security and infrastructure at the fintech. Talk to me about your career. And as you zoom out across your career, what would you say were different eras in cybersecurity?

Stan Lee:

Let's start with Frame really may not be the most interesting thing for some folks these days. But I did have the benefit of time, meaning I have the chance to actually watch Internet grew up quite a bit over the many years in my career. I think in the early days, right, a lot of folks were much smaller network unless you're a hyperscale company. There were very few back then. Now, can take myself by naming some of those early very large companies.

Stan Lee:

But at the time, what happens is most companies have a data center. It's like if you're running some sort of technology, have a co location facility, so you have a data center on premise, probably with a handful of servers. And if you're a bigger company, you have frame relay networks that was the early onsets like corporate networks. And then of course with just avenue from a technology standpoint, have to increase bandwidth, lower driving, lower cost, Then you move everything over to VPN based, mesh based technology. So there's this pendulum of, hey, how do we think about protecting our assets?

Stan Lee:

What we cared about, how we protect the assets actually changed quite a bit over the years, right? I remember back in the early days, and especially in the time I was with the university where the internet was really born from, was to use for research. So most of the universities were really locked down on harming the host at the network level. At some point then people start figuring out, hey, have hundreds and thousands of hosts that I can't really effectively protect. So they start to protect the edge of the network.

Stan Lee:

Right? That's the perimeter defense. And that's the birth of some of the early stage firewalls and some of the network security. It's like, hey, if we protect the edge good enough, then we're fine. Then we start to discover things like, hackers could still penetrate the network.

Stan Lee:

You have issues with insider threats. And then you move things back into the internal network and you have to figure out how to protect from inside the network. And let's not forget about the days of the host IDS and the host firewalls. At some point, we start thinking about, hey, maybe the data is most important. So we start to get back into deeper into the stack and then we start to think about identity as being an attack vector.

Stan Lee:

So we saw just swing of everything from we go from networks down to host, back to hyperscale large networks, and then back down to the data. You would just have this back and forth of different things that we want to protect. Right? Of course, you know, you intermix that with big data. Of course, they'll also create some limitations from a compute scale standpoint, public cloud obviously, and now with with the age of AI, just this constant swing of, hey, do we protect the edge?

Stan Lee:

Do we protect a subset of the network? And then we go back to, hey, we need to protect where the data is. So we go back to the most basic fundamental part, what we hear about.

Ross Haleliuk:

But are those really the choices we have or do we have to do all of it at the same time? I mean, like, if you think about it, like, wouldn't do you agree that both the edge protection and the data protection are just, like, fundamental core functions of the security team?

Stan Lee:

I would love to meet the security team that tells me that they have unlimited budget and they got everything that they want. So as a practitioner, most of the time you make hard decisions, right? The economics of how you run your business of security has got to match what the company is doing. Essentially what happens is that with limited resources, and that's going be true with any security organizations, They have to make a choice. What's the most effective mean for them to defend against the latest set of attacks and threats?

Stan Lee:

So you're constantly making decisions like, hey, I'm gonna protect the perimeter defenses. I'm protect some part of my network. Maybe it's the hosting environment, maybe it's your EKS cluster, your cluster. It might be down to application level. In a perfect world, you want the layer in-depth.

Stan Lee:

Right? You want to protect that every single layer of it. There's very few companies in the world that will say, hey, have technologies that layer on everything perfectly. They could operationalize it, they implement in full, they can manage it effectively, and they are able to keep up and maintain all of those technologies. There's very few companies in the world that deal so well.

Stan Lee:

And that's a hard thing. So you end up making a decision like, what's the most economically efficient way of doing it? And then, you know, going back into some of the changes, for example, when new technology comes out, you know, when mobile device consumerization of mobile device, the technology isn't ready yet. So what happens is you have this effect of what's the best thing you could do. Right?

Stan Lee:

And then when public cloud came out, virtual firewalls say, hey, is that the most effective ways of actually managing the public cloud environment? And at some point, we decided, hey, there are better ways of doing this in different ways and that's some of the changes that happens over the years with our industry as a whole. So it's not perfect. You do definitely do it. You want to implement it in defense in-depth.

Stan Lee:

The challenge is the economy that you have to solve for. The economics you have to solve for.

Ross Haleliuk:

It does make sense. And you have this interesting concept of the pendulum moving between decentralization and decentralization when it comes to security. I remember we've talked recently about how even now, when in the context of AI, we are starting to sort of shift a bit, a bit away from where we were several years ago. Could you talk towards it? And could you also talk towards it from the perspective of just some historical look back as to where were we before, where are we now, what are we moving towards?

Stan Lee:

So if, you know, if we dial the clock back a little bit, right, a lot of times when we think about storage, the file systems, blob storage, and we think about relational databases, right, the OLTP type of transactional databases. Those are limited storage in the early days within the data center. So what happens is it becomes a little more effective and easier to manage, you know, specific file servers you may have back in the days. Right? Or if you were a big NetApp customer or EMC customer, were there specific places you could protect against.

Stan Lee:

And you look for file movement, you look for certain things there. And in the advent of public cloud, then everything moved into public cloud. Famously back then, there was someone else's infrastructure, how do you understand where things are? Storage also becomes very cheap to replicate and allows for a certain amount of hyperscales and horizontal scaling, which is what we wanted at a time. That allows for some very creative innovations of technologies and business models.

Stan Lee:

So you have this dispersion of just data and quality data as a result of it. And then at some point, we start looking at, hey, we need to evaluate this because data is really valuable. You know, comes the early stages of AI and ML. So when Hadoop came out, everyone was all of sudden collecting all of the data again back into this massive compute storage, except now you're talking about hundreds of nodes and thousands of nodes for that type of storage and compute. So you're the way that you design and protect against that is different.

Stan Lee:

And we become more effective, there's the birth of DLP, DSPM technologies that start to allow us to manage these more efficiently, so it's becoming a little more centralized. And again, now with AI, what's happening is that data is the most valuable thing and people are leveraging AI technologies and they want to be able to send that data everywhere else. So, we see this again, this dispersion of data in a lot of companies' ecosystem. Now we're looking at DLP is really the big thing on the same where the data is being sent, which AI providers has processing which data. And we see this birth of all these browser based security technologies that are looking to see where the data is being sent again.

Stan Lee:

So you have this interesting effect of, hey, we start small, we disperse, we centralize again in different orders of magnitude and then disperse again. It's there's this pattern that just with our economy, this is our with our industry, that's usually what happens.

Ross Haleliuk:

So nowadays, we start hearing about different gateways for AI and so on and so forth, like, where does that fit? Is it yet another way or yet another tool for centralizing security inspection?

Stan Lee:

It's interesting because the challenge we have right now is that with AI technologies, there's number of mobile applications, web applications are popping up. A lot of different companies trying to figure out the innovative use of AI. So, the channels where we could actually see where data is being sent, you could do it on the endpoint, on the mobile devices, on the laptop. And it becomes very difficult to understand where things are because the industry is changing so fast. Right?

Stan Lee:

There's new providers that start up. There's new applications. There's new use of it. Almost every single SaaS providers these days have some AI feature. Right?

Stan Lee:

So you have to start to figure that out. And what happens to a lot of companies, and this is not even including the Gentle world, by the way. So a lot of companies are trying to figure out where the data is going because they need to be able to speak to it. Especially if you're in a regulated space, have to be very cautious and be very mindful about where data is being sent and what candidate is being sent to whom and where. And how they're using it and how they're potentially processing it.

Stan Lee:

So, what happens is that in order to just kind of contain this, our industry has this tendency. Like, hey, if there's everything is going through, I'm gonna centralize it in one or two places. So, I could understand what's going on. I see everything. The visibility is always a big thing.

Stan Lee:

Right? It's like, hey, we want visibility, we need to build all that. We want people to control it. At some point, someone realizes like this is we need to solve for horizontal scaling problems. The industry started to move towards, hey, these are the effective means on how we manage this.

Stan Lee:

And then that's when we start to see the decentralized to support the scale of the operations. That's really the driving force of why you have this patterns of contractions and expansions and contraction expansion.

Ross Haleliuk:

Where does network security specifically fit in here? The reason I ask is because, like, look, the movement of data is largely like, it's only possible because of the network. Right? How do you secure the data? How do you secure the network?

Ross Haleliuk:

Like, where do those two tasks intersect? Where are they different?

Stan Lee:

It's you know, the the right way of thinking about it is always follow the data. Right? Where your critical data does those are typically your crown jewels. So, want to follow the data. But how we implement the controls for the data is really the challenge for network security.

Stan Lee:

Going back to early days, but when you have all the centralized data, what happens is network security is just going to be around Well, start with your host and then start with your perimeters. And as we move to public cloud, what happens is that we realized, okay, we got into this notion of zero trust. So, perimeter itself is not the defining solution for everything. So, what happens is that we get to the point where we want to layer on security across a different stack. And at that point, we see the industry start moving back towards like, hey, if you're running a Kubernetes cluster, if you're running a virtual environment, you want to protect those assets.

Stan Lee:

And we said that's not good enough. And we consigned down to back into, it's interesting, get back down to the host firewalls. The security groups in AWS for example is host firewall technologies, is what it really is. And of course, we can enter the virtualization with kubernetes clusters and what happens now, do you have multiple applications running inside a single node? So it's no longer running on a particular host.

Stan Lee:

You need to protect that so they can move that layer of defense deeper and deeper into the stack from a clustering network technology standpoint. And then new types of technology comes out because, for example, we go make the model around big data and machine learning. If you try to implement pot level protections for a known inside cluster, you're gonna have a bit of a hard time. You're gonna run into a complete deficiency problem. So now you're going back to protecting a cluster, protecting particular networks.

Stan Lee:

So again, network security also under this effect of, hey, I'm gonna protect at the perimeter, I'm gonna protect the host, I'm gonna protect at the node application level. And as the technology changed and evolved, then you go back to, hey, I need to protect at the network level. The reality is, like, hey. You need to do both, but the technology drives different implementation of technology.

Ross Haleliuk:

Yaron Levy, the CISO of Dolby, had a very good perspective that the network perimeter didn't disappear or doesn't disappear. Instead, it shrunk and it multiply, and and it shrunk around individual assets. So instead of before you had, like, a one perimeter that you had to worry about, now you have thousands of microperimeters and and assets sitting inside of each.

Stan Lee:

It's it's a logical way of thinking about it. The zero trust is in the perfect world, zero trust is how you implement it. Right? Do you want to bring the security down to the most elemental piece of your infrastructure, which is going be at the host of that data level? But if you have a large enough infrastructure, everyone knows that this can be a little difficult to manage hundreds, thousands, millions of holes.

Stan Lee:

If you're trying to manage it at that level, to do it perfectly is the thing that's going be difficult. Because everyone knows business changes. I hope your business is changing. Your business is evolving. Technology is going evolve underneath, so be able to maintain and operate that effectively and efficiently is the challenge.

Stan Lee:

And that's where some of the over permissioning that we typically see, both from an access level, from an ACL level, from a network network level, there's always the the same story. It's like this repeat pattern that we see in our industry. So there there is a bit of cyclical thing that goes on.

Ross Haleliuk:

It is. And it's also why micro segmentation historically has been such a big of a challenge. Right? Everybody likes to talk about micro segmentation, but how micro do you go in the real environment?

Stan Lee:

Right. It's it's fantastic technology with SD WAN. Just general SDN and SD WANs, I think, gives you that capability to do micro segmentations. Everything just gets smaller and smaller because we were looking for that compute efficiency, storage and compute efficiency. So at some point you have a single host that's running maybe hundreds of different applications on this at the same time.

Stan Lee:

And you do want to isolate that. But to isolate it at that level, then you start to lay on the very expensive security technologies on top of each layers. Then you start to diminish the amount of value you get from that type of virtualization. Right?

Ross Haleliuk:

I feel like a part of the challenge is that the number of people that understand the network layer is not exactly growing and hasn't been growing for a while. Like, everybody gets excited about the cloud. Everybody gets excited about the identity. But there is very few people that actually understand how different components interact with the network layer.

Stan Lee:

I think what network engineers have are responsible for and what they know and what they do have changed dramatically in my career. I've been doing it long enough that network engineers used to deal with cabling wiring. They look at the signals at the wire level. They look at packets and frames. I think if you were looking at, you know, data center engineers, they probably still understand that very very well.

Stan Lee:

But there are very few companies that actually have legitimate data centers now. So people that need to understand technologies at that level is very rare. So a lot of times they understand how to manage virtualization, they manage different software components that looks like network components. They do networking things, but they're not that classic piece of switch, piece of router. Right?

Stan Lee:

Not necessarily even a real firewall anymore. It's always security groups or some virtualized technologies that are somewhere else. Part of VMware stack, part of of OpenStack is just is very different than what it used to be.

Ross Haleliuk:

Well, and at the same time, I don't know if I fully agree with you in that. I think it's a bit of a wishful thinking to assume that the vast majority of the companies are now fully cloud and fully virtualized. Like, when I talk to the enterprises, the vast majority, like, probably well over 90% are all hybrid. So, yes, they are. They're they're on the journey of of the digital transformation and cloud migration and so on, but it's never as simple as just saying, okay.

Ross Haleliuk:

Starting in 2026, we're going to be fully cloud. The old infrastructure, the old firewalls, they're still sitting there in those environments. There's still all of that complexity that has been accumulated over several decades. Like, that doesn't really go away unless you are a small Bay Area startup and then you have the luxury of being able to start from the ground up and just be fully cloud native, be cloud only. The vast majority of the companies are not like that.

Stan Lee:

Fair point. And I'm guilty of exactly what you're describing. I think it's the what I'm trying to describe is I think the percentage of network engineers and network operators that need to work at the actual equipment and the wire level tends to be less. Data centers still exist. Think with especially now with AI, there's new data centers being built.

Stan Lee:

I think we're gonna start to swing back towards the pendulum. It's like, if you're getting into AI space, need to figure out power, need to figure out cooling, you need to figure I think the networking is a little different than what it used to be in the sense that I think a lot of technologies have advanced to the point where some of the things that we used to struggle with, it comes out of box by default a little easier to figure out. But so you tend to work at a higher level in the stack. Right? Back in the days, you had to figure out the IP routing these days.

Stan Lee:

Not so much because of the virtualization technology, so a lot of it is actually handled underneath the infrastructure stack. So a lot of the network engineers that supports applications teams, that supports the software engineering teams, for the most part, they're not at the equipment and the underlying infrastructure level. For folks who are working at infrastructure level, and there are plenty of them to your point. I think the old days still very much applies, but I think it's very different. It's still very different.

Ross Haleliuk:

So what is then the future of network security? Where are we going? If the number of people that understand the fundamentals and understand how things actually work on that, you know, on the infrastructure layer, if the number of those people isn't growing, the abstraction the lot more of the problems are being obstructed away, but not fully. Right? At larger at large scale, in large environments, there is still a need for that expertise.

Ross Haleliuk:

Like, how how are we navigating that?

Stan Lee:

Really interesting question. I mean, if you look at what's going on in the last year with AI and what's driving AI right now, meaning, I think a lot of companies now thinking about actually building out the ASMs that support their aspirations on AI. So whether it's their own data centers or they're using co location facilities or they're leasing a part of a co location facility specifically for training data, billing models and everything else. I think we're gonna see things kind of move back towards that direction. A lot of companies that gone cloud native, they're also thinking about, hey, what happens with a hyper cloud architecture?

Stan Lee:

Because there's some driving force that's gonna say, hey, it's very expensive to use someone else's model. It's very expensive to use someone else's infrastructure. If you have the capacity, you have the expertise, you have the capabilities, you could do this at a fraction of cost that's gonna provide you an edge against your competitors. So I think we're gonna see the pendulum swing back towards that direction a little bit. How far does this swing?

Stan Lee:

I don't have enough depth to say, hey, this is what the future AI looks like for our industry as a whole. It's possible that everyone's going start to move back to data center. I don't think it's going be everyone. I think it's going swing back to some directions, especially for large enterprises. I think a lot of startups, companies, probably still going to leverage companies like Anthropic, OpenAI, or Microsoft and Google.

Stan Lee:

Leverage infrastructure that they could consume and train the models there. I don't think this level of expertise is necessary to be ubiquitous across the entire tech industry. I don't think that's gonna be the case.

Ross Haleliuk:

So, basically, you're saying that we'll need more people who understand the network layer than the number of people who are currently working at hyperscalers. Is that the statement you're making?

Stan Lee:

I I think we're we're seeing more and more people get back into the networking stack because of the drive from AI. But some of the things that are going on for companies are for example, they have multiple products and multiple businesses. At least for now, what happens that they still need to be able to isolate the data that they're training, which means that they have to create back to the subnets and the networks. They have to create collections of the GPUs, processors, and data storage so that they could actually go and train against that particular set of data. And there are different ways to solve for it, but if you're looking for absolute efficiencies and that's be in the parallel processing world, you wanna solve at a wire level.

Stan Lee:

It makes a huge difference if you could solve at a wire level. So virtualization is great, but this can slow things down. If you're absolutely pressing for what's the fastest cost, lowest cost, can wanna do at the wider level is what it's gonna come down to. So we're bringing back some of the network calculations, the VLANs, and some well, it seems like older technologies as a result of it.

Ross Haleliuk:

Very interesting. What does it mean from the security standpoint?

Stan Lee:

I don't know if we necessarily understood how to best solve for it. I think there's what we're seeing at the Heal of RSA conference coming up in a couple of weeks here. I think a lot of companies are trying to figure out their story around how it's best to protect anything that's AI related right now. It's it is kind of a middle ground right now. I think a lot of folks have different perspective.

Stan Lee:

They solve it at the state of storage level. Some vendors, some innovators are really thinking about how do you solve it at the model level, at the application level. Everyone So has a different lens on it. Knowing how our industry typically evolves is gonna be a blend of the multilayer defense like we always talk about. I think the ones that are gonna win are the ones that have the best collection of the layered defenses in a way that's going to be both economical and also efficient for security teams to adopt.

Stan Lee:

So, I would expect some of the technologies that we're seeing to have some deeper consolidation once we understand, hey. These are effective means to protect against some of the threats and risks that we're seeing with AI technology.

Ross Haleliuk:

I'm also quite curious. What do you think the potential of AI is for solving some of the core network security problems in general? There's almost like the need to rethink network to support AI, but then there is the opportunity to use AI to rethink how we manage and secure our networks. Do you have a perspective on that as well?

Stan Lee:

I fundamentally, security is really fundamentally, it's two things. It starts with always the people problem first. The other thing is actually a data problem. You know, we touched upon, hey, security most of the time is trying to solve for the visibility issue. Because they need to understand what's going on so they can identify what's anomalous within the environment.

Stan Lee:

But by the time you actually get the visibility, the amount of data that we have to review to understand what's normal, what's not expected, is huge amount of data. And then understanding in those cases, the exceptions that were identified, hey, these could be potential threats, what's the context around it? And AS really good for two things, figuring out the patterns of things and also be able to automate the collection and providing context of it so that the actual security engineers can make the decisions behind it. Most of the time, how we think about things, I think there are everyone talks about playbooks, innocent response playbooks. So these are very well defined and the AI will probably eventually take over that process and start to make those decisions on our behalf.

Stan Lee:

So I think for a lot of security professionals, the future is gonna look like, hey, we have these autonomous agents that's gonna be running across the different stacks of technologies. These are decisions and making sure that they behave the way that we expect it. So anything that's not new that potentially gets flagged and we haven't seen before as AI goes and identify these, I think the human loop in the process is gonna confirm, hey, that's what's generally something that's novel and different and unique. Because I think AI is gonna help solve for the data problem, the scale problem, the context problem, then the next layer on top of it is actually the the sum of the lower level of decisioning.

Ross Haleliuk:

What problems are not going to be solved with AI?

Stan Lee:

In the context of the current generation AI or what the future AI potential looks like?

Ross Haleliuk:

Let's talk both.

Stan Lee:

I think that right now, I think with I'm not expert in this space, so this is limited to what my understanding of it and exposure of it. I think some of the AI right now has got really good at identifying patterns in things that we have seen. Things that we haven't seen that AI hasn't learned, it will probably be more difficult. I think the reasoning models is getting better and better but it's not quite there to replace the full human in the loop. So, it's more of the novel techniques that's going to stand out.

Stan Lee:

Unless there's basic patterns that's concerned to normal, and we can identify some of these things do not look like it's normal. AI, I think right now with the pattern matching, think, is still very good at detecting those. But you still need the person to be involved to understand, hey, what is the full context of it? The cost of the contact in the reasoning model the more context you provide it, the longer it takes to process while we get to more efficiency. In some of the models, I think we can solve for that scale and performance problem.

Stan Lee:

Right now, in some cases, humans are still better at some of these decisions for now. Now, when we get to AGI and ASI, I think that's a very different world. There's been some conversations with one of my former employers that talks about, hey, we can get to a world where AI or attacking AI, so AI has to defend against AI. It'll be interesting if and when we reach that stage in just technology advancement. Right?

Stan Lee:

At that point, I don't know what humans are gonna do about it because things are gonna move so fast that there's no way that people with all the human resources in the world will be able to solve for that particular problem.

Ross Haleliuk:

Stan, you worked in cybersecurity for a while. And as you're looking at how things are evolving today and the direction in which things are going, does it look like a natural evolution to you? Does it look like another step in the in the usual cycle that you've seen before, or is something different about this wave of innovation that we are looking at today?

Stan Lee:

In some degree, I think it looks a lot similar to some of the things I've seen around especially if think about the just general evolutions of big data. Right? Machine learning, this is a natural progression from that perspective. I think it's a step evolution from where we were with big data and machine learning. Is it a evolutionary change?

Stan Lee:

I reserve my opinion on what that future looks like. But they're from a cyber perspective. There's a new technologies. There's a lot of gravitation towards. There's very a lot of exciting things for it.

Stan Lee:

I think we as an industry have found some innovative use for it, but it's not the panacea where it's AGR, ASR where it's, hey, we don't have a job anymore. There's nothing that we need to do because machines are gonna take care of themselves. We're not quite at that stage. So from that perspective, I think some of the things that we're saying, hey, how do we defend against this? There's a lot of gravity towards AI on what it could do.

Stan Lee:

And as people figure out what you can do, there's new attack factors, there's new threats, there's new risks associated with it. Then the cyber industry is coming in, hey, let's talk about how we're defending against it. What I do like over the last couple of years, we are no longer lagging as much as we used to be. I remember back in the early days when we were talking about public cloud, security industry was like, no. No.

Stan Lee:

No. You don't wanna use public cloud. And the whole cybersecurity industry followed two or three years late behind it. Right? Big data was almost kinda the same thing.

Stan Lee:

So you have this repeated pattern of just as the cyber industry usually lags by some time behind it. What AI was promising for me to see that the cyber industry actually jumped on top of it as fast as the innovation use of AI. So I think we're we're reducing the lag time, and we're catching up with what everyone else is trying to do with it for once, which is nice.

Ross Haleliuk:

It does make sense. And I think a lot of the reasons why that's the case is because people can now see like, an average person can very easily see the value. They can test it themselves. With something like ML or even with the cloud, you needed to be a builder for you to understand the opportunities that unlocks. While here, you can just open, you know, you can open any of the providers on your laptop and you can see how that can help you in your day to day.

Ross Haleliuk:

So the imagination is much easier to support this way.

Stan Lee:

I I think so. I think it's also just a general innovation ideas around cyber is also very different. In my early career, do you people that get into cyber usually have a few years quite a few years of experience before you get in there. If you're a builder in the cyberspace, you know, you come from the likes of the networking world, you're deep in the kernel stack, in the software stack before you become a builder and practitioner in in cyber. I think in the last few years, that's no longer the case.

Stan Lee:

Think the ease of access to technologies, ease of access to information allows someone to get into the space, understand the complexity of the space much faster. Is it boosted by AI? Probably. So I think that there's a little bit of a circular pattern there where we get more people into industry because it's it's more well known. It's easier to figure out what matters.

Stan Lee:

And there's also a center of gravity around from a technology standpoint. Right? The people who are focused on building for cyber these days, there's a lot more folks than before. So there's more attraction to talents into the space. There's also a higher velocity as a result of it.

Ross Haleliuk:

Is that really the case for all of the roles we have in cybersecurity, or is that really is it only true for some? And the reason I ask is because in my, like, in my opinion, there is definitely a large number of people who have been trying to get into entry level roles around security operations, for example, and, like, maybe cloud, but to a lesser degree so, like, primarily SOC. While if you look at the areas of security that require a lot of deep domain knowledge, like network obviously being one of them, endpoint security being another of them, there isn't that many people who are getting excited and who are given an opportunity to actually go and and start from the ground up in those areas. Like, you don't become a a network security engineer out of school. It just doesn't happen for the most part.

Stan Lee:

So you're touching on a subject that's that I'm passionate about as well. Right? There's also a pet peeve of mine too. For me to hear folks like, hey, I'm looking for entry level position, but you need to have three to five years of experience. I I I don't know where you're gonna find that magic unicorn.

Stan Lee:

So there's very few people that are are gonna be like that. I do think that there's a lot of really, really great talent. And one thing that I know about industry is that it evolves very quickly. What we learned last year is gonna be quickly not relevant this year. Right?

Stan Lee:

Things that you learned last year is probably gonna expire. It's probably gonna be less and less relevant. But it is a set of knowledge you build over time that becomes unique and special because of the use case, because of whatever scenario you might find yourself into. But we do have to encourage folks to get into the space. We should expect that it will take them time to learn.

Stan Lee:

If you find someone who's passionate, you find someone who's curious, you find someone who's hungry, they will spend the time to invest. I've met some folks who come from very, very different backgrounds. Didn't come from an engineering background. I didn't come from the cyber background. They didn't get formal training around it.

Stan Lee:

And they're some of the best practitioners I know. So I don't know how our industry evolved into a space where, oh, yeah, you need three or five years, you have a master's degree in cybersecurity before you get a job in cyber. Because when the internet was founded and when the internet was used by research facilities, there was no such thing as cyber. We only found cybersecurity because of all the other things that were happening around it.

Ross Haleliuk:

I see where you're going. I think there is at least two factors that I would consider. One is that, to me, it's a it's a supply and demand challenge more than anything else where if you look at software engineering, for example, if you look at product management, if you look at design, there is simply the number of people who are trying to get into any of those roles greatly outweighs the number of companies willing to hire for entry level roles. Like, cybersecurity is not an exception in in in any way. You are a software engineer trying to find a job in 2026, you're gonna have a hard time.

Ross Haleliuk:

And that just has to do with the fact that companies are forced to move fast and the best way they see to move fast is to hire people who supposedly know what to do and who don't need much support for them to get up to speed and start moving quickly. In the same way, if you're a security leader, you probably have a limited budget. Right? You were talking at the beginning of the conversation about the need to prioritize. And in the same way, you need to prioritize the areas to invest in.

Ross Haleliuk:

You also need to prioritize and and decide, are you going to hire two junior people or one senior person? Like, you have if you have a limited budget or if maybe maybe you don't quite have enough money to hire two junior people and now you can only hire one person, Who is it going to be? And then when that person joins, do you have the time? Do you have the capacity to onboard them? Do you have enough time, and and can you allocate enough resources to get them up to speed with how the company operates?

Ross Haleliuk:

It's there is this, like, ideal world where we are able to give everybody an opportunity, and we should. We should absolutely strive towards it. But then there is also the day to day, sadly, very real challenges that prevent people and companies from being able to go that way. It's not all about gatekeeping. It's not all about somehow older generation not wanting to see the younger generation in the workforce.

Ross Haleliuk:

I think there is a lot of accusations that that's what's happening in security. But honestly, I think it's just the economics and supply and demand challenges.

Stan Lee:

I 100% agree with you. I think there's a pressure on a lot of security teams to be very effective in what they do. So they have limited resources. They have to this notion of having to get to everything right. You have to see everything.

Stan Lee:

You have to get everything right. You can't miss the details. I absolutely agree with that fundamental philosophy. But when you think about the practical means, how do you get arrive there? How do you achieve it?

Stan Lee:

First of all, you can't really get there to begin with. There's no absolute perfect security. Now, you think about organizations, hey, when I'm bringing new technologies, the technologies that are deployed today, next year is gonna be very different because our industry evolves so much because of threat and attack factors evolve so much. You have to evolve the technology. So at some point, how do you start to index for, I want someone with experience to manage this set of tools.

Stan Lee:

Is that really relevant for next year? Or do I bring in someone who's hungry, who's passionate about this? They will go and do things and figure out things because that's what they care about. Right? I think that's more important.

Stan Lee:

Does that mean that you have to have depth in a lot of technologies? I think a lot of times, like, hey, the trade off you wanna make is, hey, if I invest in someone for two or three months, what are they capable of doing is really the the better way of thinking about talent and building out your organization, building out strategy. I think most organizations index on, hey, I want heavy hitters. They want, they're able to contribute. I'd like to think of the organization, the more reasonable way of doing it is that you have a couple of folks who are or one folks one person that's very senior, and we have an opportunity to hire a couple of folks who more junior.

Stan Lee:

Due to industry, hire for the mindset, hire for for what they're capable of they will eventually be capable of doing. I think that's the best way to build on a secure organization.

Ross Haleliuk:

Agree. Definitely agree. And with the opportunities AI creates, they should also be more effective, more efficient, and they should be able to be much more successful at what they're doing.

Stan Lee:

Yeah. I think some of the newer entry into our industry are more likely to use some of the tools that are coming out. Right? So, of course, we're on top of AI tools. I think folks who have done this a little longer like myself, maybe a little bit more set in our ways of what we think things should be should be done.

Stan Lee:

We do need fresh ideas. We need innovation in what we do, not just the technology stack, but also how we think about solving for these particular problems. And solving for problems are relatable for a lot of companies, what whatever your business might be. Right? I think some of the younger folks early into industry could think more like the rest of the business anyway.

Stan Lee:

So you do want those people in your organization. I think most organizations have to find that balance between, hey, how the deep such amount of expertise to guide through tough challenges. And you want some set of folks who's gonna think like everyone else right now where the industry is going. And that's that's the balance that we have to get better at. I don't think we we as an industry, I don't think we have done so well in that particular space in the last few years.

Ross Haleliuk:

Stan, this has been a fantastic conversation. Thank you so much. Really, really great having you.

Stan Lee:

Well, thank you, Ross, for having me on.