Signed

Your security tool says you're protected. Most of the time nothing is lying to you on purpose. It's just reporting what it was configured to report, whether or not anyone ever checked if that setup was correct in the first place. 

Zach Stewart, CISO and Director of IT at Steno, spends this conversation walking through exactly where that gap hides, and it's not only the tool. There's the BAA that only protects you if you configured it correctly, and most companies never click the button. The SOC 2 stamp that tells you someone ran a pen test, not that you're secure. An MDR service marketed as round the clock remediation that turns out to only detect, and a maturity score that gets handed to a board and answers a question nobody in the room actually asked. 

It also covers the buying side of all of this: what it actually looks like to evaluate a vendor without falling for the slide deck, why nobody wants to buy secure web gateway until it's already saved them, and the exact moment a customer contract forces corporate owned devices with no plan in place. 

Go find out right now if your tool, and everything else you're trusting, is actually telling you the truth. 

Where to Start
  • You're evaluating a new vendor and you're tired of getting a slide deck instead of the actual tool. → Jump to [49:20]
  • A vendor passed every checkbox on paper, but something still feels off. → Jump to [1:17:36]
  • You just got a SOC 2 report from a new vendor and you're not sure what it actually tells you. → Jump to [1:05:18]
  • Your BAA says you're HIPAA compliant, and you've never checked whether the tool is actually configured for it. → Jump to [1:08:35]
  • You're being sold on an MDR service, and you don't know if there's a real person on the other end at 2am. → Jump to [1:33:14]
  • You need the rest of leadership to take a risk seriously before it becomes an incident, not after. → Jump to [1:56:38]
  • Your security budget looks fine on the spreadsheet, but nobody's checked if it's enough for what it's supposed to protect. → Jump to [2:03:09]
  • Your continuity plan treats an outage and a breach as the same problem. They're not, and that's costing you. → Jump to [2:06:30]
  • A customer just told you their contract requires corporate owned devices, and you don't have a plan for that yet. → Jump to [2:22:28]
  • You're bringing a maturity score into your next board meeting, and you already know it's not going to land. → Jump to [2:28:39]
  • You're about to consolidate onto one security platform, and you haven't worked out what you'd be giving up to do it. → Jump to [2:39:50]
  • You rolled out passkeys, and you're still not sure if you actually replaced your passwords or just added a step. → Jump to [2:48:24]
  • Nobody at your company can tell you what percentage of your applications actually sit behind single sign on. → Jump to [2:57:47]
  • You've read a breach postmortem and thought, any one thing on this list would have stopped it. You don't know if that's true for you too. → Jump to [3:07:02]

Chapters
  •  49:20 Show me the tool, not the slide deck
  • 1:05:18 A new vendor says they're secure because of SOC 2. What else to check
  • 1:08:35 The HIPAA BAA loophole nobody reads closely enough
  • 1:23:29 SSO can cost more than the product it's attached to
  • 1:33:14 The real math behind running your own SOC, and where MDR falls short
  • 1:40:07 Test your backups. Actually test them
  • 1:56:14 Sponsor break
  • 2:03:09 The company running its entire security budget at under a dollar per employee
  • 2:06:30 Outage risk and breach risk need two different plans
  • 2:22:28 When a customer contract forces corporate owned devices
  • 2:28:39 Why a one to ten maturity score means nothing to your board
  • 2:48:24 Passkeys are useful. Most companies deployed them wrong
  • 2:57:47 The SSO coverage gap nobody's counting
  • 3:07:02 The breach where almost anything would have stopped it

What We Mentioned
  • NIST CSF
  • SOC 2 and HIPAA
  • PCI, CMMC, and ISO 27001
  • Google Workspace OAuth ("Sign in with Google")
  • Microsoft Entra, E5/E7 security bundling
  • Apple Business Manager and zero touch MDM enrollment

About Zach Stewart 
Zach Stewart is CISO and Director of IT at Steno, where he spends his days doing exactly what this show is about: buying technology in a market built for the people selling it, then fighting to get it funded and adopted inside his own company. Max discloses in the episode that Zach is someone ITBroker.com works with directly, which is part of why he was on the show, no product to pitch, no reason to give a polished answer.
LinkedIn: https://www.linkedin.com/in/zacharykstewart/
Company: https://steno.com

About Signed
Signed is the podcast for buyers in a market built for sellers. Host Max Clark, CEO of ITBroker.com, sits down with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals. New episodes weekly at itbroker.com/podcast. If you're in the middle of a real tech decision and want someone in your corner, book an intro call at itbroker.com. Buy tech without regret. Follow: @itbrokerdotcom

Full Transcript

Creators and Guests

Host
Max Clark
Founder & CEO of ITBroker.com

What is Signed?

The IT market is built for sellers, not buyers.

That's why 80% of tech buyers regret their last major purchase. Deals take longer than they should. Teams get locked into platforms that don't fit, contracts they can't escape, and vendors they wouldn't choose again. The pitches, demos, and analyst reports are built to close deals, not help buyers make the right one.

Signed is the podcast for the buyers. Host Max Clark, CEO of ITBroker.com, talks with CIOs, CFOs, operators, and founders who've lived inside real enterprise tech deals — the ones who can explain what actually determined whether the deal worked.

Plus weekly Playbooks breaking down the moments that matter most: renewals, M&A, compliance mandates, office moves, budget cuts, and the specific plays that separate buyers who get it right from those who regret it.

If you're responsible for choosing, negotiating, or living with the consequences of enterprise technology, this show is for you.

New episodes weekly. An ITBroker.com podcast.

Zach (00:00)
I'll be honest with

you, I don't think I've ever heard anybody tell me what XDR really means in a way that makes any sense. So we'll start there.

I think you have to get the EDR in place first. And

If they do all the things,

they hit all

the layers of Swiss cheese to get through all the holes to get to the endpoint, that's

where you want to have the most defense. And I do think as much as there's ways to encode payloads to bypass EDRs and there's reports every year of here's all the things that the EDRs miss,

Max Clark (00:28)
Welcome back to Signed. I'm Max Clark, CEO of ITbroker.com. My guest today is Zach Stewart, a hands-on CISO who spends his days doing the exact thing the show is about. Buying technology and a market built for the people selling it, then fighting to get it funded and adopted inside his own company. Full transparency, Zach is someone we work with, which is exactly why I wanted him here. He doesn't have product to pitch you and no reason to give me a polished answer. We went long and we went deep. Where you even start, how you sell security to a business that sees it as a tax?

Where to find budget nobody knew they had, and the technical traps to catch even the people who should know better. Let's get into it.

Max Clark (01:11)
internal

alignment and like I want to say consensus, but but you know, like how do you actually get I'll just say alignment. How do you get like allies and alignment inside, right? And so from a from a risk management standpoint, we talk, you know, risk management is like like the word of the day, right? You know, Mr. Rogers, word of the day, risk management. So shared risk and risk management obviously kind of goes in right into general counsel, right? Because general counsel usually thinks in the terms of risk. But

Zach (01:38)
Mm-hmm. Yeah.

Max Clark (01:41)
But in addition to the G C who become non obvious allies inside of a company when you get into a risk conversation?

Zach (01:50)
Yeah, I I think the the general guidance or what's worked for me here is you have to meet people where you're where they're at. You need to understand what's important to them and then you have to bridge the gap, right? Because like you said, unless you're a G C or you're a security person or maybe you're a high level ops person who's seen a big enough system where they have to start to manage risk within their system, otherwise they can't deliver on whatever they're trying to deliver on. You know, those types of people are gonna have a higher

grasp around the thinking and risk perspective. But for the people who that is not their focus and that's not what they're doing on a day-to-day, the biggest way I've found to find

alignment with them and get them on the same page about why we do these things is instead of coming to them and decreeing this is what we're gonna do, it's because I said so because risk, you really have to figure out what does their perspective look like. Try to shift yourself into what they care about and what the business cares about by extension through what they're providing and link that to what you're trying to do and say, hey, the reason we're doing this is because we need to mitigate this risk, which if this risk were to happen, because right now it's intangible to them, this is the touching the hot stove example

example again, right? It's intangible to them. You say if this risk were to happen, this is this is the negative impact of this and this is how it would affect you. And then having that conversation I find a lot of times can open the door. And then that's something as a leader you have to cultivate over time with these people. You have to build up these relationships so that they know when you come to them you're coming from another perspective which they have to do some work, right? So you have to show them why they need to do the work to meet you halfway.

Max Clark (03:22)
Let me give you an example and then we can I want to dig into this more. I I think the easiest example that pops up to me is in manufacturing. We have a lot of experience with manufacturing. So when you when you look at manufacturing, you've got you know, the the first thought always goes to your production line. Like, you know, what are you actually doing to produce a product, you know, through your through your factory, through your through your process.

And and so that becomes the idea of of risk instantaneously of what happens if this line gets shut down and and and how does that back us up. But then there becomes what happens when that behind the line, right? Which is product comes off the line, it has to get into inventory, it goes, you know, through whatever process that looks like. Then you have an ordering and and fulfillment process, you know, like, hey, we need to ship stuff out. And where I've seen conversations

Get

really interesting with with companies is, you know, the focus becomes the manufacturing line, like, we can't produce product if we have a shutdown of this plant. But that's not the biggest point of pain in a lot of cases. The bigger point of pain is we can't ship stuff. Or if we have a delay in our shipping process, then that backs everything up beforehand. And and that that has become the bigger point of like learned, you know, I want to say like learned pain almost of like, we couldn't ship out for a day. And so that

like really crushed us. How how do you get into a risk conversation with somebody, especially if you're starting talking about like the obvious isn't the real pain point? Or or

Zach (04:56)
Mm-hmm.

Max Clark (04:57)
I'm I'm more interested, I think, in the how does this become not a learned experience? Like I I don't want to, you know, being in a situation where you have an outage that then drives pain that then becomes like, we don't want to have that, that that's a horrible place to be in a risk management conversation versus trying to alleviate it in the first place, right?

Zach (05:14)
Yeah. I mean I think that you're correct in that and that that that there's a lot of a lot more sensitivity around supply chain, right? And whether that's hard good or soft good, whatever you're talking about, supply chain is a really big point of focus right now, and it hasn't been in the past. and so I think that there's a little bit more appetite to have these conversations. But as far as what I found to be effective, I think the first thing is just scenario based learning, right? Scenario based learning. So do tabletops.

Don't just in in depending on your s situation, if you have more education to do around getting people up to speed on risk within the leadership, you know, you might have to do more than one tabletop a year. You might have to do, you know, micro tabletops where you just walk through a specific scenario with them and say, Hey, we're doing this as part of our risk management program. We're doing business continuity exercise. Here's a scenario. Maybe it's only a couple of paragraphs, walk them through it. And if you get on the line with somebody and that's their part of the business and you start putting out a scenario, even if you've made some assumptions which are wrong.

they're gonna immediately jump in and correct you and then you're both in this learning phase of exchanging ideas and hopefully that's where you can then make that connection to make your point about maybe the risk that they're not seeing directly in front of them.

Max Clark (06:24)
Getting an an executive team together for an hour to two hours to sit down and do a risk management tabletop exercise is not an easy task. Like how I mean,

Zach (06:29)
Mm-hmm.

Max Clark (06:31)
where do you how how so it's like it's like that almost becomes the first problem and point of like, can you even get people in a room together, then do the tabletop exercise then so how do you even start this and get get that piece started?

Zach (06:45)
Well, I think part of it's the culture of the organization. Right. So it's the culture of the organization that has to be motivated to want to do these things with you. and there's only so far that you can bridge a gap, right? You can't go a hundred percent of the way on your own.

But you have to have that prerequisite there, which is something that as a security executive, you always want to be thinking about is is that is that there for you to branch off of. But then also if you can't get everybody together all at once, or maybe you can only do that once a year, I think the next best thing is you have to have those touch points with those leaders separately and meet with them to get time on their calendar where you can, or you know, deliver some sort of reporting artifact or even Slack message or an email if you have to, just to try and get this stuff in front of them. And it's really exposure.

It's time and exposure I find is is the the best way to approach this.

Max Clark (07:35)
Okay.

I have to be careful. My NDA has long expired on this one, but I still

Zach (07:42)
Mm.

Max Clark (07:42)
gotta not step on any toes here. I had a conversation with a security leader years ago, and it was a vertically integrated manufacturer, including distribution and retail. Right. So they had everything souped to nuts. More o north of a billion annualized revenue, global footprint, brand you would know. And this and the security leadership,

their entire budget for people and tooling was like non n was like nonsensical for the entire organization. Right. Like on a on a on a revenue basis, you know, it wasn't even a pr it was less than a percentage point. excuse me, on a on a revenue basis, it was less than a tenth of a percentage point. And on a, you know, employee headcount basis, you know, I don't even think it was it wasn't I don't even think it was a dollar.

Per employee, right, is basically what their entire IT budget, you know, security budget was. And and what was fascinating about listening to the this conversation, really like reflecting on it afterwards, was almost a sense of like resignment. Like, like his view of it was, I need to identify, like I have to I have to find risk, and then I have to identify an ins incident.

And and the only thing I can really do here is try to identify an incident and then figure out maybe, you know, can I contain it, you know, or wall it off.

This company had peers with massive security incidents that caused significant damage to the business. It's not like they didn't know what was going on in a bigger world outside of them, but they're but you talk about like culture, like there didn't seem to be any appetite culturally to make any shift or or adjust this. And you know, like

It's just just like come like table sta like this is just the what it is internally and you just deal with it and you're like y you know, or how do you how do you not get jaded in that situation to the point where like, what I'm I'm doing here doesn't matter and like this isn't a security first culture and you know.

Zach (09:45)
Yeah. I I

think there's two pieces to that. There is the piece that we talked about earlier, which is that's something that you need to interview the organization as much as the organization interviews you to see if that appetite is there and how much of it is there. And and that's one piece of it. But I think the other side of it too is, you know, there's always at least some little headway or progress that that you can try and make. And I think that's what keeps your

your motivation up is just try to you have to keep trying to find an avenue that resonates with them, right? So if presenting the risks in a green, yellow, red, you know, spreadsheet is not working for them, then you need to figure out

how do they perceive risk? Because as humans we all perceive risk in different ways and we have different focuses in which we perceive risk. So what you might need to do is just just keep talking to them. Just keep talking to them. Talk to them about the business. Talk to them about revenue. Talk find out what they're concerned about. Right? This is why you need to be in the room when they're talking about the business and you need to know what's going on because you need to be speaking the same language that they are. And to me this problem to an extent, and again, caveat there needs to be some motivation from the rest of the team to address things.

There's going to be some perception of risk, you need to align with how that perception is being delivered to get your information into that conversation.

Max Clark (11:02)
So we you we talk about supply chain for like manufacturing, right? And like a lot of there's a lot of attention on that. But you know, supply chain in ever there's a supply chain in every business. you know, if you're a if you're a tech company, a software company, you know, you're you're producing software, you're producing an application, and you have a supply chain, you have external dependencies, vendors, infrastructure, whatever it is, you still have this supply chain. And

You

know, lately there's been so much activity on different dependency trees, you know, and and you know, we're seeing all sorts of crazy stuff going on. people are the conversations, I think, picking up a little bit of like how vulnerable the average business really is to a supply chain software. But you know, it's it's also I I don't I don't feel like this this conversation has shifted into really like what is the actual risk and what's the impact of the business.

For the business to be able to execute, because it's almost like a learned response again for me. You know, until until you have these out, you until you have a massive outage. The outages are also weird. It's like an event happens, it's really painful, it resolves, and then like 48 to 72 hours after that, everybody's like, it's not gonna happen again. You know, like like how do you manage that

Zach (12:12)
Mm-hmm. Mm-hmm.

Max Clark (12:13)
like human psychology of just like, it was in the past, we don't have to deal with it now.

Zach (12:19)
Yeah. I think that that is another thing we're always working towards a culture where that's not their first reactive response, right? And that's that's challenging because people wanna be they wanna handle something, wanna jump on it, and they wanna be done with it, right? And that again, I think that's just human nature. You want to move on to the next thing. But I think part of this is changing the culture to understand that security is this continuous thing or this management is this continuous thing that we're always doing, because we don't know

What's coming? We can't predict it. We can't say with any certainty whether something is going to happen or or not.

future generally speaking we try to predict as best we can but we don't have certainty and I think that's an important thing that you have to inject into the culture is we don't have certainty. That's a dangerous thing to think. We need to understand what the probability of things is going to be and how we need to make decisions based on that. So I think that's the first part of it. I think the the second part of that too is just structurally I like to try and draw a a somewhat fine line between is it an outage-based thing? Is this an availability risk or is

Is

this a a risk of compromise? Because those are two very different situations with two very different sets of variables and and two very different sets of risks. Potentially there's overlap, but the the amount of

potential long term pain from both can be very different. And so I think that that's also worth understanding and and being able to communicate the magnitude of a breach versus an an availability outage issue. And one maybe get the other, and that's where I think people get a little confused. But I do think it's important to draw a distinction between the two things.

Max Clark (13:56)
Well tell me more. Go go go go into more detail there.

Zach (14:00)
So I think on the availability side, right, you wanna try to

address that with your business continuity and you want you need to similar to risk management, you need to make business continuity an organizational priority, right? And so you have to work with the business leaders, you need to help build the business continuity plans, you need to have playbooks for specific things, you need to work with engineering to understand what their RPO, RTO, and all that good stuff is in terms of delivering the application and the service. And that's kind of one side of it. And then on the other side you have kind of the more classic security engineering and CICD and STLC stuff.

Around how do we make sure this this application we're delivering is not, you know, is to the best of our ability is not going to be breached. And that I think is something you want to spend even more focus on because that's where the security expertise can have a more dramatic impact. Whereas you can kind of try to lean on the organization a little bit for the other stuff because business continuity is something that they have a lot more control over, whereas you need that security engineering lens a little bit more on the breach prevention side of things. And a lot of those

functions that feed into fighting that are going to be a higher contribution from security in terms of an expertise perspective.

Max Clark (15:13)
RPO

RTO is an interesting conversation for me because when you ask a question like what is your RTO, RPO RTO, you know, the answer is like immediate. We like want one minute, right? And what ends up happening very quickly is you find that it's really, you know, if you ask the question, the response is going to be instant. And then if you equate it to like how much it costs, right, you end up in this thing where like eventually you figure, you know, you the organization decides like,

This is an acceptable RTO RPO for us in theory, based on the actual cost that we perceive to have it. And then you have this this this this thing of like until it's actually tested in practice, you don't really know, you know, was that an acceptable RTO RPO?

Zach (15:53)
Yeah. Mm-hmm.

Max Clark (15:57)
and and I feel like that's very similar, you know, there's like a similar parallel for me in in code quality and you know, you say CI C D pipelines, what this actually looks like and different techniques out there and

you know, like container registry scanning. Like what what is your supply chain and modules inside of a thing and what does that look like? And how do you do that automated at scale and and and flag stuff? And, you know, there was this, you know, are you doing static static analysis? Are you doing dynamic analysis? Are you trying to do API based security? Are you, you know, all these other things that come into it that

You know, again, becomes it's it is it is interesting because then it's like do we have a culture of trying to actually go through a code base and look for vulnerabilities or do we not? And you know, how do we how do we scale on that? on the allies allies com you know topic here. I'm gonna use the words Trojan horse. It's so like appropriate, I just can't help myself. One of my favorite things I I've I've found

Is when you can solve a problem for another side of the business and then at the same time solve a problem for yourself. Right. So like in the world of security, I'll use Treasure Hillers, right? Like HR. HR wants to deploy an HRS platform. HR wants to be able to onboard and offboard themselves instantaneously without interacting with other departments. I mean, you know, like if you have to involve IT in order to go through some event, whether it's hiring, you know.

like on on either side, it's not ideal, right? So, you know, what does that lead into? That leads into single sign on, the life cycle life's you know, the life to life device lifecycle management, MDM, you know, those package really nicely on top of an HRS platform and integration where it's like, hey HR, you get what you want, but like we also get what we want, which is SSO, MDM and device lifecycle. So that way we can actually do this stuff at scale in a better way.

What

did

I don't wanna say like what's your reaction to that. I wanna say more along the lines of like, in addition to that, at a live like a very high level, you know, obvious cycle, where else do you see these kind of things serving both both sides? Where it's like business actually wants this and by the way, we get what we want at the same time along the way.

Zach (18:29)
Yeah, I mean I think that a lot of this comes through

Security is primarily, you know, what we were talking about before, you know, the observe, orient, detect act, right? And and you can't you can't observe if you have no visibility, right? And so I think from the security lens, the way I start to look at this is you need visibility. That's that's priority number one. Because if you don't have visibility, you don't have information, then you can't orient, you can't figure out what the risks are, you you can't figure out what technical controls are appropriate, how to prioritize all these things.

So I think way that you you get a lot of that is through what could traditionally be considered IT tooling, you're talking about, right? The the MDM, IDP, all that stuff, but the security lens can kind of ride on top of that. And so that's I think the direction that you enter those conversations from to your point with HR, you talk about the life cycle and you talk about onboarding and offboarding and automation and the MDM and what you're really talking about is building a zero trust security environment. Right. So you're kind of getting your cake and eating it too in that case, which I think is the is the ideal approach.

Because that goes back to also something we talked about earlier about what's the difference between someone in a in a security executive role who's been hands-on and who's built everything and who hasn't is like, you know, to use the house analogy again, you know where the pipes should go, you know where all the wires

should go. That comes in here heavily where you know what synergy makes sense there and what things you can offer to people and pitch and actually follow through on so that you can get that organizational trust that you what you're presenting and what your plan is is actually going to make everyone else's lives a little bit easier in the long run and a little bit safer and and you're not just here to stop them from doing things that would make them more productive.

Max Clark (20:10)
So from your experience, I mean, are there other opportunities for you know, other tooling and other infrastructure that solves other department priorities?

Zach (20:20)
Yeah, I think a big one that I've personally seen that people don't think about is as we have all of more

hybrid and remote and so I mean some maybe super big organizations you see them moving away from this a little bit, but I think in kind of the general middle there's a lot more hybrid and remote than there used to be. Thinking about what networking tools you have in your stack and how you're managing the the endpoints and how they're networking with each other because there's a lot that you can do there that's highly technical in terms of, you know, are you letting people go to certain sites? Are you letting them not go to certain sites? And you can kind of reinforce your policies, which everyone has probably already agreed on what

What

people should and shouldn't do in theory, and you can go, hey, I guarantee you, if we put visibility in place, there's probably some folks that just never either never saw the policy or maybe they're just not following the policy, because sometimes that happens for whatever reason. And you can reinforce that with technical controls, right? And you can say, well, I can use this network tool if you let me implement it, right? Where I can make sure that that policy is being followed by following it up with the technical control. And I think that's where you start to bridge the gap with people. You point to

what everyone's already agreed should be, and then you say, look, I can have a tool that can do this, and it can also help you do the things you need to do.

Max Clark (21:34)
I

I just listening to say that, like the the first obvious one that goes to my mind is security awareness training. Like mandatory top one requirement for every cyber insurance policy, foundational thing. I I you know, love hate security awareness training.

You know, is it effective or is it not? But then it's, you know, HR. HR has annual training that everybody has to go through. It's like w why haven't we seen anybody merge an HR training module with a security awareness training module and shove them into one tool and say, Hey, HR, here's your mandatory annual training that we have to go through. And by the way, we also get this other thing as well that we need at the same time.

Zach (22:15)
Yeah, I don't know. I think security training is a bit of a divisive topic amongst security leaders 'cause I think that you know it's it's hard to say what the what the direct value is, but I will say that, you know, it is important for you're saying for for cybersecur security insurance and it's becoming a big consideration and I think that makes sense and for a lot of regulatory frameworks and and audits, third party audits, it's a requirement. So

I don't necessarily know why nobody is taking the swing on trying to get that together, but what I can say from my personal experience is anytime I have to interact with a security awareness platform or a general LMS, I'm always just like, this should not be this hard. There should be a better way to do this. So maybe somebody'll figure it out.

Max Clark (22:59)
I I

I

My problem with SAT is this idea that comes of like, we can't the the problem that we have is because users are doing bad things. And if we give them training with the SAT tool, that then they'll stop doing this bad thing and we won't have this bad thing happen to us. Right. And you're like, that doesn't really exist in today's world, right? Like, you know, the the old idea of like

I wanna say like red teaming, but like, you know, are we leaving USB drives in the parking lot and people are plugging them to their computers? Like, why are you allowing people to plug USB drives into your computer in the first place? Like, do we really solve this by teaching people not to plug in USB drives? Or do we just take away the ability for people to plug in USB in the first place? And

Zach (23:50)
Yeah, and I think that was what I was saying earlier. You're linking that to a a concrete example of you have the policy, but then you also need to have the technical control. You need to have both. But you're also highlighting the challenge there is you might want to say, okay, our policy is that you shouldn't plug in a USB drive into your machine, and then our technical control is we're going to shut off USB. The nuance and the value of the security leader there is to figure out can we just do that? Is that going to be an outsized impact to the

organization. Does there need to be more nuance in who can do it and who can't do it? Because there there's shades of gray in terms of who needs to be able to do that for business purposes. And that is where the whole ball game is, so to speak, right? The rest of it is table stakes.

Max Clark (24:37)
I'm reading this morning and it's specific to autopilot and in tune for MDM with Microsoft. And the and the point that was being made is there's a default, you know, time delay between you push an instruction and w when a payload gets deployed onto a computer. When I say payload, I that that comes across as like a a an exploit, but you know, like a application update, right?

And what we're seeing in supply chain, of course, the first reaction is like, you know, if you have a node module takeover, the best thing that you could have is have a seven day delay or whatever in your in your package management tool. So you don't get the the current stuff, right? But then everybody immediately goes, Well, I want the fastest stuff. And this whole post was about like, here's how you break the in tune configuration to push stuff instantly. And you're like, you're like, this control exists for a good reason, but now, you know, the natural thing is is like, I don't like that.

Because I don't get what I perceive as valuable, which is instant response or instant gratification. And so, like, you know, that becomes this like constant push-pull inside the organization as well, which is like veloc velocity, right? Talk about velocity a lot, velocity

Zach (25:37)
Mm-hmm. Mm-hmm.

Max Clark (25:39)
and speed of things happening. Like, you know, I need those USB drive to work because I know, you know, so it gets really messy. You know, like this stuff gets so messy. Corporate policy. Are you giving somebody a handbook with 500 pages they're never gonna read? Or are you like,

exclude

the entire thing about USB drives and just say it's not functional on our equipment, right?

Zach (25:58)
Yeah, and I think that's where, you know, the culture and the alignment come in heavily, right? Is because if you a lot of the stuff that we're talking about, if you only do one part of it, the other part is going to become that much harder, right? It's almost like a a magnetic push pull or a a seesaw that you need to the to balance out. And so I think anytime you push too hard in one direction and you start to feel resistance, that for me and my experience what's been helpful is to think about what what what am I not doing maybe that's that's not supporting this, right? From that

Other angle. but yeah, it's definitely not easy. It's definitely not easy. And there's a lot that goes into the nuance around that. And it's something that's evolving rapidly, right? I mean, it depending on the organization, what's your mix of on premise tools that maybe need to be supported, or legacy software that needs to be supported, or are you all SAS? Do you have very little? All of these things require completely different approaches from the technical side.

to address what you're talking about in terms of when things get updated and how they get updated.

Max Clark (27:00)
Okay,

so a point on that, right? companies, especially on the smaller side or the faster side, you know, go into a BYOD and and we s and you know it's super fast to onboard a person, a developer, if they just bring their own. They already have a laptop, they already have a device, like okay, you can just start working. I see that shift from BYOD computers and desktops to corporate owned happen faster, but then we have cell phones. And cell phones become this like trailing animal.

in every organization of like at what point did we tip over into corporate owned cell phones. And and we can talk about NIST COPE and or not or all these different things, but I'm I'm I'm more interested and curious from your take on this of, you know, the real triggers of like, you know, this idea of like speed and time and ease of use, right? You're like, you have local admin privileges. You can do anything on your device. To then all of a sudden this like changing environment where we're gonna go to now corporate owned and corporate policy and corporate control, which

For a lot of people is a drag, you know, like, I can't install anything I want on my computer anymore. but like what becomes those big tip overs of the company? Because again, it's usually reactive to something happening that pushes companies into changing behaviors.

Zach (28:13)
Yeah, I I think the big thing with this is you need to present really strong cases for these kinds of things, but you also have to be aware of does it make sense for your particular business, right? And so I've been in scenarios where it makes a lot of sense and there's a very clear need because of how the business operates for those phones to be corporate owned phones because of what how people are using them or what data might have to pass through them. And so I think that is a is a case by case thing. But if you don't have a strong case for it, then

maybe that's not the right angle in terms of taking that risk management approach and maybe there's something else you can do, right? And maybe there's somewhere else you can put those controls. There's one thing I will say is we know we have a lot of different avenues in terms of the modern security stack for where you can intervene or where you can inject visibility and then take action. It might be that you're just

trying to you know be the hammer where everything is looks like a nail and it might just not be the right place for that. But I will say that if you have a really strong driver for something like that, then you need to build that case and present it to the business in terms of lead with the thing that affects the business the most. And then explain the general security and risk management approach of this is the data classification and this is how the data's flowing and all that stuff that they're gonna, you know, glaze over if you start there. Start with

business scenario of hey here's why this is a problem for us specifically.

Max Clark (29:37)
I guess

what I'm looking for

is more like what's a common that I see? okay. Companies moving up stack in terms of their customer, right? And their customer comes to them or they have a a big enterprise that's really on the ball with with supply chain and they say something like, as a requirement for us doing business with you, you have to ensure promise contractually to us.

That our data can only be accessed by corporate owned equipment. Right. And so that I've seen that all of a sudden trigger this like response of like, okay, we've got to go corporate owned cell phones, corporate owned devices. You know, that's like the first part of it. But then it becomes, okay, how do we actually now enforce this control against I mean, and the you know, and then we get into a conversation of what controls they want and what techniques then you're like, okay, great, we have the entire the entire ocean available to us in terms of techniques and technology and

Zach (30:26)
Mm-hmm.

Max Clark (30:27)
And and what are we going to do? And let's talk about what makes the most sense now for you where you currently are in your evolutionary cycle. But you know, that example of that customer going inside of the company and saying, Hey, here's a risk management issue or here's a future state issue that we have to approach, they weren't talking like the same language to each other.

And I I do believe that conversation was occurring, but like they never, you know, like people weren't on the same page until all of a sudden it was like this is a hard revenue requirement. And then all of a sudden everything scrambles. And that translation I think about a lot because I don't I don't feel like IT in general and definitely security does a really good job of talking to the business and exp and and like finding like, and it's not like teaching the business how to talk IT, it's more like how does IT talk.

finance, you know, or like marketing to other people in ways that they get it.

Zach (31:17)
Mm-hmm. Yeah.

I think you just have to you have to be in a position where you can invest the time and you have to build a strong team that can handle the technical and the security op stuff on a day to day basis so that it enables you to be able to spend that time with the business.

And I maybe that's a cop out answer, but that's honestly the first thing that I went to and I'm sticking with it is I think that's really where you have to go. But I do want to address your point about sometimes those kinds of things just happen, right? Sometimes there's an opportunity in the market that shows up and you know you're not

The one necessarily staring at the market data day to day, or you might not know about some prospective customer that's this huge thing coming out of nowhere and all of a sudden they want to do a huge amount of business with you. And so you just you have to be good at presenting these things slow and practicing the implementation and working with the business so that when you have that opportunity or that scenario come up where all of a sudden it comes out of nowhere, you're doing the same playbook.

You just are doing it quicker. And you might have to deprioritize other things. You might have to shift things around. But fundamentally, your approach shouldn't really change that much. You're just accelerating the speed at which it's happening and you're communicating that to the business. You say, Well, okay, look, just as you want to onboard this client quickly, I'm gonna tell you that these things that we're gonna have to do to do it is going to be a a huge lift. We're going to have to do it somewhat quickly. Here's how much it's gonna cost. Here's the consequences and the things we're not gonna be able to do anymore. And then you put that decision back in their lap and say,

If you want to go forward and and do business with this customer, then you're ign agreeing to this, right? And I'm this is what we're gonna have to do. And they're already thinking about that customer relationship in terms of how much is the cost to acquire that customer and how much are we going to make off that customer. So you're just contributing to that discussion at that point. But you have to have that full picture of what that looks like from start to finish.

Max Clark (33:11)
Well, I mean, do you

though? Because let me back up. Let me let me let me come up with this a a slightly different direction. Every I I I hate this so much about the cybersecurity industry. Every framework in terms of qu of of like

Explaining like the maturity, the cyber maturity model, cyber defense matrix, you know, explaining what SOAR is, like all these different things. Every single model makes absolutely zero sense to somebody who's not in cybersecurity. Like, it's like if you talk to an executive who has no basis in ex in cybersecurity that actually has like, like, I can make a decision, put a stamp on it, force things to change, and they're like,

10 being the NSA and zero being like a bunch of people in a garage. Like, like, what's where do we need to be? Like, like, like where what's your perception of where we need to be? Right. And if they're like, you know, and they'll like, well, where are we currently at? And you'd be like, we're like at a two, right? And they're like, okay, I think we should be like at a four. You know, like, what what the heck does that mean? Nobody understands. There's like no scaling of these things of what it means. Now

There are some frameworks, and we can talk about NIST CSF and you know, like different things, but you know, you use the example of like risk of like, you know, green, yellow, red risks. But at some point, like, isn't there a simpler way of explaining, like, look, look down the road two, three years? We are going to have to be ISO 27001, and this is what that means. And and this is how we start down this path and like steps and

And kinda like paint that picture in a better way of like, we're here and this is what coming next and at some point we can accelerate or we can decel or what you know. How do how do how does the security industry do a better job of explaining like the future to people that haven't been through this before?

Zach (35:12)
Well

For me, from my perspective, I'll start there and then I promise

Max Clark (35:16)
Yeah.

Zach (35:16)
I will address it from that perspective too. but from my perspective, I think what you need to do there is, you know, I'm gonna use another analogy. If if you go to the mechanic and you're and you're mechanically inclined, they have to fix something on your car and they're like, your differential is out. They can say your differential is out and you have some concept of, they gotta take the wheels off and and maybe the axles in the way depending where it is. Is it front wheel drive, is it rear wheel drive, where's the differential in the car? is there a transfer case, all these things.

And so you have all of this understanding. And I I think the the zero to ten anal or you know framework is the same of if someone comes in, they have no idea how a car works, and the mechanic just starts talking to them and in technical, it's never gonna you're never gonna bridge the gap. So that's not the right conversation in my perspective to have with those executives. And I think you need to find the parts that are relevant to them, and it's your job to see the zero to ten at a macro scale, and it's your job to try and plot from A to B, but I don't know if

that there's necessary value in constantly communicating that to the rest of the executive team. I think what you're communicating to them is the shorter term. Here's the impacts of stuff that you're seeing. Here's the problem that you're having. Your engine's making a weird noise. We're going to spend a bunch of money and time and manpower and then we're going to make the engine stop making a funny noise and that's good because then it's going to keep working. Right. And that's how you explain that to them. Rather than trying to say here's where we are on this macro scale of security sophistication or enterprise maturity because I don't think there's as much value there as people tend to think.

But as humans, naturally, we want to simplify the problem down into this easy bite-size-to-understand framework. And I think the fact of the matter is, is it's a complex system of systems. And if you try to start there, you can do that reduction. And maybe there's some executives that do just want that number because they they feel they can track progress to some degree. And that's okay too. But I think you need to communicate to them as an understanding as part of that of hey, there's a ton of nuance involved here, and this is just an estimate of where we're at.

Max Clark (37:11)
Yeah. I mean it depends on the pens for sure. Like I s I use that for for decades now. But the you know, the the I guess the point that I'm making, the question I'm asking is at some point there is there is like we we need to understand like what's the what's the journey, what's the finish line, what's the you know, there was no finish line, right? But you know, like like like what's the appropriate scale? You know, with with startups.

You know, nowadays, like what's what's seed versus A, you know, like seed rounds have gotten so big it doesn't but you know, but if you look at if you look at the you know milestones for a startup that usually goes funding acquisition IPO, right? Like it's

Zach (37:51)
Mm-hmm.

Max Clark (37:52)
you know, like what you need seed to A to B to C to D plus into acquisition or or IPO.

Zach (37:59)
Yeah. To the end of the alphabet these

days. Yeah. Yeah.

Max Clark (38:02)
Yeah, yeah, yeah. I mean, it of course it depends on your velocity and everything else that's

going on. But, you know, at some point there is this basic assumption you could probably end around D, you know, in terms of like, you know, I I can you can you can put D on a line and then say from D to acquisition or IPO, you know, whatever rounds behind that are gonna be more of the same to some degree in terms of what the organization's gonna look like internally. You know, when we look at companies, you know, in that like B to C round size, that company's going through scale up.

Like, you know, they have product market fit, they have a process, they have sales, they understand what's going on, and they're taking that investment to 10x in size, right? And that usually involves a significant growth of headcount. So now, you know, you can you can go through, you know, series A, series B, you know, B under 200 headcount.

You can kind of figure it out just by giving everybody a laptop and local admin control, but then all of a sudden you say like all this IT stuff has to mature, you know, and then MDM shows up and corporate owned devices show up and like all these things show up. But but you know, so I come from that like thought process more around, okay, everybody understands if we're on this journey of A, B, C, D, E, you know, and maybe it's revenue for a non venture, you know, comp like at these points, like we kind of have to be at

at this like, you wanna go public, all of a sudden your S1's gonna ask you all these questions about risk. Y you know, like how do you wanna answer them? You know, probably you have to a have a good answer for them.

Zach (39:24)
Mm-hmm. Mm-hmm. Yeah.

Yeah, and I think we're getting at the same thing there. And I think what we're converging on is in terms of how you're communicating the maturity of your IT security program is how is it protecting the value of the organization?

And and how is it how is it addressing things that threaten the value of the organization? And again, I mean what we're really doing is we're all bringing this back to the risk management program, which d I d I don't disagree is probably the right place for it to go. And that's where all of your reporting needs to be scaffolded by is is how are we doing risk? What's our risk appetite? What's our approach? And the part of your question before for that I didn't answer is how does the cybersecurity industry do this better?

I don't have a great answer for that because I don't know that they've even figured out a way to do it. I think they just kinda

Max Clark (40:15)
No

Zach (40:16)
throw stuff at the wall and see what sticks, and as far as I'm concerned, none of it sticks. and that I think that's you know, but

Max Clark (40:20)
It's it's awful. It's absolutely awful.

Zach (40:23)
and that's the that's the the where the security leader comes in to to translate, right, and to bridge that gap. Because obviously there are value in these tools and they do solve very real problems, but there's that huge translation from what they think the pitch is to

what the tool actually does to what's the value to your specific organization. And so you're kind of mixing those three things together to find the right the right match.

Max Clark (40:49)
Yeah, I mean this is and this is also big misalignment in terms of how these companies function, right? Because you know, sick s tr traditional companies use outbound cold outbound as a primary sales mechanism. What's the one thing that every security buyer hates is cold in you know, cold inbound and outreach to them. Yeah, and and you're like and so then you're in the situation where where you you look at actual like sales cycles and deal cycles with these things. It's like, event happens, ransomware takes place, let's go out and buy some tooling afterwards. You know, it's like this very reactive thing. And

I don't know if there's a solve. I just I think about this a lot. A lot of a lot of what you're you're getting into is there's a lot of there's a lot of this conversation. I I hate this term convergence, but I'm gonna use it here. What was traditionally IT and what was traditionally security are mashing together, right? And a lot of what you're talking about advocates in a way for the combination of the IT and security org, where

It's not necessarily a CISO and a CIO, but one hat wears both functions, right? Or one person wears both hats.

Zach (41:54)
Yeah. Mm-hmm.

Max Clark (41:58)
Where does that make things easier and where does that bite you?

Max Clark (42:03)
This show exists because of what we do at ITBroker.com. If you're in middle of a real tech decision right now, new technology, vendor selection, a contract that doesn't feel right, an &A event that just landed on your lap, and so on, we help buyers like you get it right. Independent strategy, sourcing and contract negotiation, no kickbacks, no sales quotas, just someone in your corner. Schedule a call at ITBroker.com. Back to the episode.

Zach (42:29)
Yeah, I think there's validity in in both approaches, right? I think there's validity in having those be two different individuals and I think there's validity in in combining them. And I think it's gonna just depend on how is the rest of your organization structured and how does it operate. But I think that the benefit to start there is that you have a holistic view of how all the IT tools integrate with security. And I think what you've seen previously, and again this is just anecdotal, but I I think you can find a lot of evidence of it out there, is security ha

To then joust with IT over what the tool stack's gonna look like and with a lot of tools now being platform tools, which is a whole nother conversation we can get into in platform platform versus point solution, but with a lot of the tools being platform tools, if IT locks you into one environment

you know, of of the big players, then your security stack is almost being defined for you. And then so you're taking that agency away from the security professionals to say, well, what's the right security approach here? And so when you have that as one individual who's been on both sides of it and is not just only a security person or only an IT person, 'cause I think that's kind of a bad framework and doesn't really exist i in the first place.

you can figure out well what's the right balance, right? W there's always going to be trade-offs and what platform gives us the IT operational functionality that we need, but that also gives us the security visibility and the security action ability that we need. And you can try to put those two together. Or you can also make the right budget optimization calls around here's the right place for a platform tool that meets all of our IT and security needs. And here's where actually we need to use this tool for the IT operations piece of it. And then we need to get a different security tool that either talks to it or rides

on top of it or how you want to look at it because this platform's security tooling does not meet the requirements that we have. And the only way you're going to have that true flexibility is either you have

those two people that work incredibly well together and are willing to make that compromise, or you have it as that one individual who can then make that call and move forward faster and be able to make sure that everything's staying in sync with each other while also trying to optimize for cost, which we you're just talking about startups and A, B, C, D rounds. And of course the huge part of that is is optimizing cost versus what you're what you're bringing in, right? And continuing to do that aggressive growth.

Max Clark (44:48)
So

platform versus point solutions, this is a this is a great segue, and we can talk about tooling here a little bit. every point solution tries to become a platform, and it's just TAM expansion, right? So like take an EDR tool. An EDR tool becomes a SEM-like tool, then becomes a full SIM tool, and then tries to say they're an XDR tool and then wants to do this tool next. You know, and then we've got the undisputed champion of the universe for bundling, Microsoft, right? And platforms with with

you know, E5 security now, E7, where they're just like basically we're just gonna s shove everything in and we have one license. And we could talk about whether that's actually efficient from a licensing cost standpoint or not. But you know, finance loves when you have one bill. Like and and also in

Zach (45:30)
Yeah. Mm-hmm.

Max Clark (45:31)
theory, if you're doing it right, like one one bill means less cost, but but there's some trade-offs. Now I've been on Microsoft since the DOS days because I started with a computer before I was born. But the

You know, like the secret is that what Microsoft has done with E5 security and defender and Sentinel, it's a good product. I just have like like like a moral religious objection to using Microsoft to secure Microsoft, right? And that just becomes, you know, experience over the decades with Microsoft, right?

Zach (46:05)
Yeah. I mean I

mean, any way you look at it, good product or not, you're putting all your eggs in one basket. Right. And so from a risk management, you know, academic perspective, that's just not a good idea in general, right? That's a risk that you need to then consider.

Max Clark (46:18)
So how

how do you so I mean, but so but this goes into the other part of it, which is deployment manageability becomes inf sign I mean, it's not like like having two tools make it twice as hard. It's like three times or four times as hard. And you know, each tool you have more more graph points. And how do you balance that decision process between, hey, we're gonna go on the point solution basis, right? We're gonna have a different s you know, sim data platform data lake, we're gonna have a different EDR, we're gonna have a different this, we're have a different that. But now we've got best and breed for everything.

But now we have like make it all work together and operate it versus just saying, Hey, we're gonna put all of our b eggs in one basket and like you know, nobody got fired for buying Microsoft, like whatever.

Zach (46:58)
Yeah, I think it I think it's a it's a personal risk determination, that you have to make is the as leadership of

what can your team handle and what can you support? Because I do think that there's a lot of value that is not necessarily immediately perceived when you go to the best of breed of everything and integrate it together. But then as you sit with that stack over time and as you see other people and the pain points that they run into having put all their eggs in one basket or maybe you move to another environment where that decision's already been made and you go, this thing doesn't make sense or this part of their product doesn't actually work.

very well and then you find out actually you're stuck with it because it's part of this massive investment that has been made.

That's where you really see and again,

Max Clark (47:42)
Some cost policy, sure. Yeah.

Zach (47:44)
this is the touching the hot stove from one of the from the experience things of and until you see that it can be really hard to communicate that. But that's part of the nuance I think of being hands on and having done it before is you can go look, we can go with the one player and we can consolidate everything, but when we have a problem with them, we have a lot less leverage. And when we have a problem with them, we can't just go get something else to fix it. So that problem might not go away for a long time, depending on how

you know, quickly they respond to you. and so there's some very real business implication to that. And I think that's the angle you have to come at it from when you are explaining why you want to do that versus just buying everything from a Microsoft or someone else.

Max Clark (48:25)
Okay. We we you you opened the door to this one. So I'm gonna make you I'm gonna make you not give me no it not it depends answers, but actual like like hard answers here. And this is, you know, we're gonna we're gonna create some we're gonna we're gonna give you some trolls here. brand new fresh environment, you're picking a desktop. Windows, Mac, VDI, Chrome OS, what are you deploying why?

Right, yeah, I gotcha.

Zach (48:52)
How many how many yeah,

uh-huh. I'm I'm not gonna ask you I'm not gonna make you answer this question, but I for my own sanity I have to at least vocalize it. This is incredibly dependent on what kind of organization this is and what they do, right? But we'll move past that.

Max Clark (49:09)
Mm-hmm.

Zach (49:11)
Personally, I think that the most effective thing you can do is Windows and Mac, right? I think that the most effective thing you can do in a modern enterprise is give people the flexibility. as long as there's not a Windows-dependent piece of software, obviously, and there's ways to deal with that. But I think that hybrid approach is the most effective. It offers a good amount of flexibility. Well, most of the tooling is now good enough to realistically support both at the same level of enterprise, you know, capacity in terms of controls. And I think that's another way where you as the

IT and security department partner with the business, right? And you're actually trying to give them some flexibility back and have a little bit of a compromise because the tooling will allow you to do that. And that's part of where you need to understand the differences. You need to be able to understand both operating systems and how they function. And you need to align the rest of the tooling to work with both. Assuming you can do that and having done it from experience, that's a much better place, I think, to be and having that flexibility versus trying to consolidate down onto one thing.

Especially something like VDI, where talk about putting all your eggs in one basket, right? that's that's a scary one, especially if we've seen cloud cloud compute go out of control in terms of pricing for VDI. So

Max Clark (50:22)
Well, I

you know, okay, so let's let's let's let me let me cut off a couple things here. right. No legacy Windows environment or or Windows software. now almost all modern software, as you pointed out, like the cr the the browser is the operating system for most most cases. We're really talking about specifically Chrome being the operating system for most applications, or Electron, JavaScript on the desktop, right? So it's not like outside of like

you know, a finance team saying we absolutely have to have X you know, Excel on Windows, which which does happen, but you know, Chrome OS gives you a lot of controls built in, you know, smaller security fra you know, f you know, surface area, you know, cheaper equipment, MDM baked into it, right? Like there's you know, if you're on workspace, like it's pretty nice. Mac, similar thing. You can go to any Apple store on the planet and go buy a laptop.

And if you have a if you have a support issue, any any Apple store on the planet, you can go get support, right? now you have to have an organization that is either comfortable with using Mac or not, right? Versus Windows.

Zach (51:27)
Mm-hmm. Yeah.

Max Clark (51:29)
But but they're they're, you know, this is why this is a be this becomes like the, you know, you're gonna be a team of one for the next however much time, or this is your company that you're starting and you get to make the decision and it's like

Zach (51:41)
Mm-hmm.

Mm-hmm.

Max Clark (51:42)
it's my decision. You know,

like this is what we're doing. Then what are you picking?

Zach (51:47)
I'm probably going Mac. And the reason why I would do that is

mostly rooted in pragmatism. So we're assuming in this example I have the skill set that I have right in terms of how to like set this up. Okay. So

Max Clark (52:00)
Sure. You you've got a decent letter, right?

Zach (52:02)
yeah, so in that case what I'm doing is I'm going Mac and I'm doing that for a couple of reasons. One, the hardware is a little bit more expensive up front, but you tend to get a longer life cycle out of it than a standard Windows device in in some cases. And two, Apple has, I think, a little bit more of a

don't break the user experience approach than Microsoft currently does in terms of how they're choosing to roll updates. So I think in terms of a business risk perspective, it's it's not substantially lower, but it's definitely a factor. And then I think maybe something that Apple doesn't necessarily get as much credit for, but is a huge thing, is you can set up your Apple business account and you can order through the Apple business portal and you can have every single one of those devices do zero touch MDM enrollment. And almost every MDM supports it because that's the s the standard that they put out there. And that's a huge win.

that you don't have to deal with a lot of the you know, you don't have to buy an intro subscription to to, you know, and in tune your Microsoft laptops for five people, right?

Max Clark (53:01)
I don't I don't think I don't think look, I have a lot of beefs with Apple. and I have a lot of beefs with with cell phone carriers and ABM enrollment. Like initial setup, right? I mean and and the ABM setup sucks the first time you go through it. Like I'm I'm just I like listen let's not let we w I won't

Zach (53:20)
I won't fight you on that.

Max Clark (53:22)
pull punches. It is horrible. But the experience of opening up a device and being like, look, it's just boom.

Zero touch configuration from that point forward is so it's just magical. I you know, I I there's th th it's just it just is. Okay. Non controversial topic. Pass keys, yay or nay.

Zach (53:43)
I've had this conversation a couple times with various people. I think generally

Max Clark (53:45)
Yeah, I would imagine so.

Zach (53:47)
where I fall on this is I I think it's I think it's useful. I think it's a useful technology. I think it has its place. I think like every other additional factor, every other MFA tool, whether you're talking about TOTP, whether you're talking about hardware-based keys, there's a time and a place for it. And I don't think that it is the kind of panacea that it was originally presented as is you're gonna roll this out and no one's ever gonna use a password again.

Max Clark (54:12)
Well, I I think that's

Zach (54:13)
That doesn't make sense.

Max Clark (54:15)
my number one complaint with pass keys right now is most implementations are using pass keys as two FA and not actually the you don't have a password anymore to authenticate. Like you go to the website and you get your password management pop pop up if you want to sign it. You know, like it's so the both from a password management side or like a password password manager, password vault, and from a deployment of the pass key in practice.

It's like it's like why am I why am I authenticating with a username and password and an email magic link and then you're asking me for my passkey? Like the the whoever implemented that flow, like take them out back and beat them with a stick, you know? Like it's sort of those like what was the plan

Zach (54:53)
Yeah.

Max Clark (54:53)
here?

Zach (54:54)
I think there's a lot of issues with implementation 'cause I think a lot of vendors just bolted it on, right? And that's why I think

Max Clark (54:59)
Yeah.

Zach (54:59)
you see it more effective as an MFA tool than a replacement for password as a primary factor.

in a lot of places is because of that. It was more of a bolt-on thing. But I do think it is useful as an additional factor. I just don't ever think I bought the the promise of it being a replacement for passwords because there's a chicken and the egg problem there. just like any other password replacement. I mean we want to go go old school with it. You can look at SSH keys, right? We've had those forever. Those haven't replaced passwords. And there are similarities, you know, between how passkeys work and how SSH keys work. I think it's a similar thing of it's it's a really great MFA device. You could use it in places

of certain a password in certain scenarios where it makes sense, but it's not going to become the thing that gets rid of passwords forever, especially when the implementation kind of obscures what's happening from the user, the end user, in a way where they don't really, I don't think I've seen understand what's happening, right? I think that's one of the other flaws of passkeys is it's not clear to a non-technical user what's actually happening. I think that's a huge challenge in terms of adopting it as a password replacement.

Max Clark (56:03)
I you know, I I I

I c I kinda look at this and go back to

this idea of like

We can't educate our users to defend themselves against professionals that are trying to do nefarious things. Right. Like like this idea of like, we can do SAT and educate people into not being fished is like, let's let's be real. Like the amount of of like really savvy crypto people that have had their wallets stolen from them from successful atta I mean, like it's this isn't like a user education issue. It becomes like, can we create guardrails just that are just generally better?

And

in the sense of like fishing an account compromise, I you know, I view PASCIS as a really good thing because you know, it d that does solve a lot of problems there. But from from like at the it's like everything in tech, the deployment sucks. I mean, this is like I mean, what's another one? Like antivirus versus antivirus next generation versus EDR versus XDR. It's like y you know, you live this every day. Can you define what the differences are between those four act you know, four terms are at this point?

Zach (57:12)
I'll be honest with

you, I don't think I've ever heard anybody tell me what XDR really means in a way that makes any sense. So we'll start there.

Max Clark (57:20)
'Cause it's a marketing term.

Zach (57:21)
Mm-hmm. Yep.

Max Clark (57:26)
But this this is like I I do this as a thought exercise with lot of people. It's, you know, is it better to be investing in in EDR or is it better to be investing in secure web gateway, a SWIG and with RBI? Like from a practical deployment standpoint inside of your company and actually protecting things, you know,

EDRs give you observability and and reactivity, so I mean that that's a really good thing. But but it's like, well, if you prevent it from happening in the first place, isn't that a better thing? You know, like

Zach (57:58)
I think generally speaking, in my personal opinion from from what I've seen, I think you have to get the EDR in place first. And why I say that is because at the end of the day, your end user, regardless of what other controls you have in place, like your end user is typically their identity is emanating from that endpoint, right? And so I'm really taking the the zero trust framework here as the guiding principles, but that is where everything is coming from out from. And so

You need to protect that at all costs. That's like kind of your first layer, right? That you need to have that visibility and you need to have that defense there. Because yes, there's tons of other layers as we start to go out further of what they might be interacting with that you can also secure with those other tools. And you should, and you should have defense in depth. But if you have to say what's the two between the two, what we're doing, I think you have to start with EDR as a core because it's just that last bastion of defense against. If they do all the things, if they hit all

the layers of Swiss cheese to get through all the holes to get to the endpoint, that's

Max Clark (59:01)
Yep. Yep.

Zach (59:02)
where you want to have the most defense. And I do think as much as there's ways to encode payloads to bypass EDRs and there's reports every year of here's all the things that the EDRs miss, it's about the lowest common denominator, right? It's about putting the fence up in the front yard.

Max Clark (59:18)
I mean what's popular right now? people there there's been there's been reports of payloads adding nuclear and other other, you know, keywords into their payload to try to get the LLM to trigger safety mech you know, to trigger trigger its safety key, you know, and and not actually inspect the payload because it's like, I can't touch that topic. What what do you what do you think is the most overrated? Actually let's let's let's do let's underrated. What think is the most underrated security category?

or

you know, tooling technique right now.

Zach (59:51)
Well, something that surprised me a little bit lately, and and again, this could just be out of sheer coincidence, but I feel like there's not as many folks that are focused on the network piece of it. And I think that that's something that with cloud maybe and this is just me conjecturing a hypothesis here, but like I think cloud has kind of obscured networking for a lot of people. And I think that

Max Clark (1:00:12)
Yeah.

Zach (1:00:13)
there's been a pull away from looking at the network traffic and the network layer is something important. And to me, there's so much you can do there.

from a security perspective that that's something I think people r should really think about, especially again as we have hybrid organizations, remote organizations, you're talking to all these different cloud platforms potentially of traffic going in between them. And you know, the more complicated your your setup is too, the more you can do with with networking and and that visibility can really show you some things that otherwise you wouldn't have visibility necessarily from the EDR or visibility from a swig of other things that are happening on the network.

Because now the network, right, isn't just a network, it's networks.

Max Clark (1:00:55)
As an old network engineer talking about language right now, the actually interesting trend I'm seeing right now is, you know, everything. I mean, everything in tech is just cyclic, right? You know, you go like I, you know, mainframe terminal to like distributed computing, back to centralized computing with cloud and like all this different stuff. Are they in the office? Are they not in the office? But a lot of work that a lot of what we're doing, a lot of work that

I see in the future is more about using, you know, network overlays and tooling to actually recreate the private network experience for people, like recreate this idea of a perimeter, you know, whether it's

Zach (1:01:30)
Mm-hmm. Mm-hmm.

Max Clark (1:01:34)
to, you know, cloud computing resources that the company controls, or if it's to, you know, SaaS applications, like, you can have private connectivity to your CRM that doesn't touch the public internet and take the CRM off the public internet and or ERP and and that stuff is really interesting. we

Zach (1:01:50)
Yeah, and

I think that's part of one of the things like the first time I really dug into how is zero trust supposed to work back when like, you know, Google was pioneering it and

Max Clark (1:01:59)
Yeah.

Zach (1:01:59)
I went

Okay. And I was talking to someone that I know that works at Google, not on that team, but just a general team. And I was like, so how does this work? And they're like, Well, I mean, vaguely this is kind of how it works. And I was like, well, they can do zero trust because they control everything, right? So they control, they have all their own things. But I think that's what we're not necessarily regressing back to a perimeter based model completely, but the perimeter being this important piece of the puzzle in terms of where can you exert influence and where can you route traffic and where can you see traffic and where's

the boundary between where you have the that that extra layer of control and you're still involved in the loop versus then when does it go out to, you know, the the greater web, so to speak, and then you don't have necessarily nearly as much control over what happens at that point.

Max Clark (1:02:44)
So perimeter, right? And and you touched on identity. We talked about identity in the pa earlier. A lot of people identity is the is the new perimeter, right? Like it's it's everything's coming back down to identity. In zero trust, everything comes back to identity. And then and then, you know, there's the whole SSO tax, dirty secret, right? So you've got SSO, SAML, Skim, you know, depending on deployments, it works, it doesn't work. But

I I think the bearer conversation becomes like coverage, right? This is like the dirty secret of identity and SSO becomes the actual coverage of of it. And, you know, we see reporting of like what percentage actually gets deployed in an organization behind SSO. And I'm I'm not asking for specifics for you, but like how how big is this gap now, you know, for companies of trying to deploy and manage identity.

And

just not having SSO coverage across the and like and and what do you do about it? You know, like how do you actually look at this from a security standpoint and say, great, we've got, you know, sixty percent coverage from applications from SSO and like what do you do with the other forty percent of that?

Zach (1:03:51)
Well, I think if you're in a situation where you can't get full coverage on on SSO, which I think a lot of people probably find themselves in that situation, then I think you have to start looking at compensating controls, which is why I had mentioned, you know, I think networking is somewhere that people need to look at more because if you're controlling the network traffic, you may not have that SSO piece, but there are other things you can do to try and exert zero trust principles over what's happening. I think the other thing though is

You're seeing in in in the industry now there's there's dedicated roles, right? Everybody is getting I shouldn't say everybody. It's a little bit hyperbole, but there's a lot of IAM roles out there. There's a lot of IAM architect roles out there, you know,

Max Clark (1:04:28)
Cheese. Yeah.

Zach (1:04:29)
right? And so I think what that's doing is it it's showing that there's a need for dedicated roles for this because the amount of time and effort and organization it takes to get all this stuff under control... you know, you might have a hundred, two hundred, five hundred applications depending on how much SaaS is in.

Max Clark (1:04:51)
People have more applications they have any idea how many applications they have. It's it's wild.

Zach (1:04:55)
Yeah.

Max Clark (1:04:55)
Yeah.

Zach (1:04:55)
Yeah.

I mean and you're and you're seeing companies, smaller companies try to figure that out too and be the application, you know, inventory and discovery and shadow IT and all these things. But I think that all just again feeds into SSO is going to be a core part of zero trust, kinda no matter how you look at it. And so it's more about I think acknowledging that that is one of your probably largest priorities in a lot of cases. And so you need to try and do a lot of the soft stuff, right, that we were talking about earlier in terms of getting buy in and

in getting people on the same page of why this is important to kind of shepherd them into that world of man, isn't it really cool when everything comes from one single identity and you log in one time and then you click on the icon for the thing you need and everything just magically works. And if

Max Clark (1:05:40)
By the way, users love

that stuff 'cause they don't have to remember anything at that point. This is the thing. It's like here's a security

Zach (1:05:43)
And yeah, and and I

Max Clark (1:05:44)
You know? Yeah. Yeah.

Zach (1:05:45)
I've seen it happen and and they do. But it when you're

on the other side of it and you don't have that yet, you know, that's part of h getting to where you wanna be is having those discussions and showing how good it could be and how seamless you can make it while also saying, Hey, look at behind the curtain, all this extra security we can do and I'm not gonna use any specific examples, but you know, there are things you can probably think about in your organization where if there's some behavior that that is that users are doing that you don't like, then there's probably

a way to tie in with an IDP to be able to control whether or not they're doing those things, right? And so that's another really powerful thing that I think people generally tend to look at SSO as as a tax, right? And as a a kind of a thing that just makes one click login possible, but it but it's not. It's also a ton of logging, which can make audits easier. And it's also a ton of extra control around

exhibiting having users that are exhibiting risky tendencies not be able to do things that you wouldn't want them to do.

Max Clark (1:06:47)
Okay, this is gonna be specific to Google Workspace. I wouldn't call Google Workspace like an IDP in the sense that like what you know, Microsoft's pushing everybody into Entra, and Entra is gonna be more like IDP ish, you know, the traditional sense of the term. but you know, Google Workspace specifically, you get the option of signing signing with Google, like their OAuth flow, which for applications that don't that that push you into an enterprise seat for an IDP, you know, OAuth is usually included for free. but you know, recently we've seen two

Two big things with Google auth signing with Google and Google Auth, right? We've seen tokens and credentials being stolen and used to access infrastructure and do like real damage. and there was a theoretical like example that that was you know working as intended that's been proven to be a problem, which is, you know, defunct domains, you know, within you know being purchased and reactivated and used to log into resources, right? So so

Google

o you know, sign in isn't necessarily like like this isn't s it's like nothing's safe, right? So like if you're looking at this from a from a from a you know, balancing like lesser of two evils, you know, OAuth, you like like shove everybody into Google OAuth and just say, Hey, we're gonna try to manage this, or is it like untenable and you just skip it completely and try to go, you know, something into a root into a quote real IDP?

Zach (1:08:14)
I think I think the login with Google buttons have their place and I do think in a lot of senses, like you were saying, typically it's not an extra charge and I do think it's it's better if you are already aligned with Google workspace. I think it's better than managing a whole bunch of applications with usernames and passwords, because at least with the OAuth tokens, you have some control in terms of revocation from the Google admin side, and so you can use that to your advantage and you can also use some of the newer tools that Google's rolled out around

being able to limit what applications that users can can use that with that, what data they have access to, again becomes a little bit of a management burden.

especially and I think that's where you start to run into that decision point even more of okay, well now we're doing all this extra management and what we should kind of really be doing is just getting this to an IDP where we can set the applications up ahead of time and do it in that more controlled way. And I do think that's something where Google doesn't provide a strong path for you to make that transition. And then that's where you get into the situation of trying to evaluate what the next tool is going to be to do that better.

Max Clark (1:09:18)
This this

is my I don't wanna be a broken record for like you should have a strong MSP or CSP involved, but like this is one of my examples with it. Platforms default to ease of use, right? The number one thing is is adoption and ease of use. They're optimizing for it. And so if you're if you're listening to this in the future and you haven't done it in in your Google Workspace admin, you can go in and you can change third-party API access for authentication. And it's a button that you check, and that button gives you two options at that point.

First option is who can actually use you know, sign in with Google at that point to authenticate. And and what's actually what to Google's credit, what they do is when users try to use it, it'll actually trigger an event to the admin team that then can go and review it and say yes or no. But you can also limit the scope of what they can get out of the Google environment at that point through that OA. But you have to configure it. And if you don't know it's there and you haven't had something happen that makes you go look for it, like you you just don't even know this thing exists, right? And

but th this is like also for me, I'm curious what you think about this. you know, you find a l I find a lot of people where it's like, we have Macs and we're running Google Gmail and so we're secure. We don't have to do anything else. We've got it handled, right? Yep,

yep. That's the reaction I was looking for. You know, what do you what

Zach (1:10:35)
It's interesting perspective. Yep.

Max Clark (1:10:38)
do you say to that? What do you say to that person? Like, you know, again, you talk about culture and like interviewing the company before you come in, but you know, maybe, maybe you

You know, you're at a company and the company hires a new fill in the blank executive that's got, you know, real and control and that's their viewpoint. Like how do you counter that that that conversation?

Zach (1:10:57)
Well, I think that a lot of that is gonna come down to your soft skills and ability to interact with that individual and figure out how do you

How do you get them to consider alternative opinions? Right. And that that's more of a people thing than a security thing, right? I think it's just generally where you have to start. But assuming that works, I think the next piece is you just provide examples, right? And and I there's

Max Clark (1:11:23)
Yeah.

Zach (1:11:24)
no shortage of examples where that is just demonstrably not the case. And I think you try to overwhelm them with evidence in a polite way of, hey, that's that's just not right. And you know, there's there's a version of that maybe that you can show them that.

that's better and that would counteract the evidence and and help with risk but I think that's somewhere where you just have to acknowledge that someone's on a fundamentally different 180 degree opinion from where you know they that we would like them to be and then you need to figure out how do we swing them to the other side.

Max Clark (1:11:59)
I'm I'm gonna reference an example here. I'm I'm gonna give enough breadcrumbs so you can find it you know if you want to. But there was a a a very well known piece of infrastructure, you know, company. When I say infrastructure, not like like compute, but like, you know, tooling. And they had a a fairly significant breach that was had had had wide supply chain reaching issues into a lot of other companies.

Zach (1:12:21)
Mm-hmm. Yep.

Max Clark (1:12:24)
First issue with this breach

In this story, was they didn't detect it. One of their customers detected the breach and noticed it and then told them an inform. Then so they start the reaction, they go through the they go through the process. And and then they identify it and they resolve, we resolve it, they remediate it, and then they implement new controls and they move on. And then and and to their credit, they post they they posted a, you know, they posted a lot of information on it. Now a lot of it got coded, you know. We're running industry leading antivirus, and you're like, okay.

I already know that you don't have anything running if you're calling your your platform antivirus. What was crazy about reading this thing, you know, the other part of it, part of the hack was when people got credentials, they were doing they they were able to steal and hijack sessions and then you know, we're logging in via VPNs in different countries. You know, and you read through this list and you're like, and it reads like a horror story where like every step along the way, you're like, you're like, if you had this or this or this or this or this or this or like any any anything.

Anything you would have prevented this entire thing from happening, you know? And and it's

It's just so fr I don't want to say frustrating. It's just it's so like deflating, you know. Like if you're if you if you're in this business and you read these things, you're like, you guys had no infrastructure to protect yourself whatsoever, and now you're like on the apology tour of like it wasn't our fault we were breached. And you're like All right, anyways, I wanna I don't have to rant about this too much. I'm not gonna make you say that SOC2 and HIPAA is garbage. but

The I I'm curious what your thoughts are in terms of actual frameworks that give value and real security into a company, right? So like, you know, if you were processing credit cards, you had PCI, right? Then you healthcare has HIPAA and we see SOC two becoming the standard for every B2B and manufacturing

Zach (1:14:13)
Mm-hmm.

Max Clark (1:14:14)
and and is is is coalescing around CMMC because

Zach (1:14:18)
Mm-hmm.

Max Clark (1:14:18)
of government influence and supply chain down. I think CMMC will get pushed out to everybody.

For a company that is actually interested in deploying a real framework that is going to help them measurably improve their security. And probably also, by the way, the good news about a lot of these things is it becomes foundational for every other framework that you want to do. Like

like

Zach (1:14:40)
Mm-hmm.

Max Clark (1:14:42)
what would you tell them to start with? Like what's what's your view? What's what's your position of like start here and focus on this?

Zach (1:14:50)
Yeah. well I think there's good news and bad news here, right? Like the good news is the things those things that you mentioned are probably more useful than you might think. And it might not be that you're looking at them in the way that they're more useful, right? And so I think a lot of the things you talked about is how do you get people on your side, how do you get alignment, how do you get a wedge in a lot of these things. Those are great wedges. Those are great wedges 'cause a lot of times they're non negotiable.

And the business has already basically implicitly agreed that they're going to do those things. And so where you come in is you bridge the gap between what you're trying to propose and the nitty-gritty technical of it and here's how it relates to our organization. And then sometimes you to to add that next layer onto it, you could say also these regulatory compliance frameworks or these security frameworks that we're already obligated to for either cybersecurity insurance, customer obligations, whatever it may be, government regulatory.

That is all just extra oomph to your argument. And I think that's where those things become important. And I think that they're also relatively good starting points. and they're probably how a lot of security programs get created slash, you know, investment be put into. So I do think those are decent places to start. But I will say from

a day to day practitioner perspective or if you really want to latch onto it from from the technical side of things, I do think that NIST has a ton of value. I'm not saying it's easy to understand. I'm not saying it's definitely the most organized thing in the world. There's a s there's a structure of organization, but you know, it's it's very you have to look at it one way and this is the only way it makes sense. But I think there's a ton of value there in terms of good practice. And I think NIST CSF is is a is a decent place to start, especially if you if you have nothing, right? So

in in the event that you also don't have those other compliance obligations already, I do think N NISCSF is a decent place to start. And I think one of the biggest advantages for that is it's relatively straightforward and most people or other security practitioners or customers that you might talk to, like there is a a common ground there that I think is valuable. Whereas ISO twenty seven thousand one can be useful, but it's also not something that people are going to have as much immediacy with outside of certain specific industries.

Max Clark (1:17:03)
Right.

Very I think my my my beef with SOC two is it actually predates SOC two. I mean this goes back to ITAR, you know.

Zach (1:17:17)
I think everybody's got beef in sock too though.

Max Clark (1:17:19)
Where it's like, okay, you have a s you have a standard that you have to adhere to, right? And then it's like, but the interpretation of that standard is so broad that it doesn't actually you know, like like the stamp doesn't end up meaning what people

think it means. It's like, a pen, we had a pen test. We're secure, right? Like, what does that actually tell you? It doesn't tell you that you're secure. It just tells you you had a pen test. and I I guess maybe backing up our earlier question, right? It's like, you know, if you're talking to somebody you're like, you know, we need to be SOC two compliant in two years based on our our plan, you know, corporate planning. Well, before we're going to be SOC two and go through the SOC two audit process and and and you know

create evidence and be able to controls and validate and do all this other stuff that we have to do. Let's go out and get NIST CSF because almost everything that we're doing here for NIST CSF will apply to this next thing that we're gonna have to Yeah, you don't have to pay an auditor. Yeah, NIST 800, you don't have to do anything.

Zach (1:18:12)
Mm-hmm. Yeah. And it's not gonna cost you anything, right? Because it's all there. It's all on the internet. Yeah. Mm-hmm.

Max Clark (1:18:19)
You just have to go like, do we have MFA deployed everywhere? You know, like yes, like, okay, great check, you know. and actually I've used NIST CFS in a lot with

Different CNAP and CSPM tooling where it's like, you can pick your framework, you say, NIST CSF, and it'll just

give you the checklist. It's like you've got this, you don't have this, and you start working through it.

Zach (1:18:32)
Mm-hmm. Yeah. Mm-hmm. Yeah.

Max Clark (1:18:38)
I I've got so much other rambling notes here. I'm gonna, I'm just gonna I'm I'm gonna I'm gonna I'm gonna skip a bunch of stuff here because I think we've already we've already beat a lot of this to death. here's here's one which

I mean tell me about s tell me about something that genuinely genuinely surprised you. And this this is an intentionally broad question, right? This could be

Zach (1:19:06)
Sure.

Max Clark (1:19:07)
a provider, a tool, a platform, person, a process, dialogue. Like like were you just like had this like wow, that just happened moment. And it could be positive or negative. A lot of lot of interpretation here on this.

Zach (1:19:24)
Yeah. I mean I think as someone who

has seen a couple environments now and has had the privilege of kind of being able to build from the ground up before. One of the things that I think was both the most satisfying and the bulls most surprising goes back to something we were just talking about a little bit ago around SSO and and finally getting an enterprise level IDP in and spending the time and energy 'cause it's not a fast process, even even for a smaller organization. This it's a huge commitment. But once you get to the point where everybody can sign in once and you know they do

their little MFA and then they get to a dashboard and they can just click on a thing and get into it. I it seems like a small thing, but to get to that point from zero to that level in an organization and have it work and have people just use it.

I was like, wow. I don't think that y that's not an experience you typically get with security tooling, right? That's not an experience you typically have because either a lot of times the security team's the only one that's looking at it and you're just kind of reporting back the the end state or or the metadata, so to speak. You know, I think email security is a great example of this, right? Like it's really hard. A lot of times a user doesn't really notice what's going on and you're just kind of like we blocked X million emails.

Right? A versus the IDP is so fundamental, it changes the way people work. And I think for me that was really surprising to be like, this was worth all the effort and like it really does work. And that's not something you really get a lot in security I find.

Max Clark (1:20:55)
Me that that I I so good. I'll I'll wrap with this. So so so finish this line for me. the difference between knowing the technology and being protected when you buy it is blank.

Zach (1:21:14)
The difference between knowing the technology and being protected when you buy it.

Max Clark (1:21:19)
Let's let's let's you you can we can invert this a l you know, not invert it, you can change it a little bit. The difference between being protected and not being protected is you know.

Zach (1:21:29)
Yeah, well I I I like your I like your first point there about understanding and knowing knowing the technology, right? And I so I think that's fundamental, right? I think the way I would phrase it is you need to understand the technology and then when you buy it, you need to follow through on the implementation. I think that's the biggest

Max Clark (1:21:47)
huh.

Zach (1:21:47)
thing, right? And I I'm not saying that's simple. I'm not saying that's straightforward in a lot of cases, but I think that is where

a lot of times things can fall apart or, you know, if if expectations are misaligned or if it if it's taking too long perceptively from the rest of the organization, whatever the case may be, I think that's the most important part is you're not across the finish line when you sign the invoice, right? And when the invoice gets paid, it's you you what's the implementation plan? When's this thing actually producing value? And and how are you communicating that it's producing value?

Max Clark (1:22:21)
Zach, I I promised you I wouldn't turn this into a Joe Rogan like that. So so I appreciate it. Thank you very much. This

Zach (1:22:29)
Mm-hmm. Absolutely.

Max Clark (1:22:30)
is fantastic. I can I can, you know, I I could turn turn this into a Joe Rogan thing. We can talk for another three hours if we have the time, but

Zach (1:22:35)
Yeah. Absolutely.

Max Clark (1:22:37)
we'll we'll we'll we'll stop here. Appreciate it. Thank you very much for joining. this is so fantastic.

Zach (1:22:40)
Yeah.

Awesome. Thank you.

Max Clark (1:22:44)
That's my conversation with Zach Stewart, and we covered a lot of ground. If there's one thing to carry out of it, security is the thing everybody wants and nobody wants to pay for, and the person stuck in the middle is buying against a market and selling to a business that are both stacked against them. Nobody should have to do that alone. More at itbroker.com slash podcast. And if you're in the middle of a real decision and want someone in your corner, book an intro call at itbroker.com and buy tech without regret. I'm Max Clark. See you on the next one.