Artwork for podcast The Industrial Talk Podcast Network
Sounil Yu with Cyber Defense Matrix
31st August 2026 • The Industrial Talk Podcast Network • The Industrial Talk Podcast with Scott MacKenzie
00:00:00 00:38:52

Share Episode

Shownotes

Industrial Talk/BCC is talking to Sounil Yu, Chief AI Officer at Knostic about "The DIE Triad - Distributed, Immutable and Ephemeral".
The conversation promotes the Barcelona Cybersecurity Congress, scheduled for November 3-5, 2023. Speaker 1 emphasizes the importance of cybersecurity and networking opportunities at the event. Sounil Yu, a seasoned cybersecurity professional, discusses the evolving landscape of cybersecurity, particularly the role of AI in making cybersecurity less relevant. He introduces the DIE triad (Distributed, Immutable, Ephemeral) and the Cyber Defense Matrix as frameworks for addressing cybersecurity challenges. Sounil also highlights the need for a cultural shift towards high-velocity engineering and continuous reengineering to stay secure. The discussion concludes with information on how to connect with Sounil and attend the Congress.

Outline

Barcelona Cybersecurity Congress Promotion

  • Scott introduces the Barcelona Cybersecurity Congress, emphasizing its importance and urging listeners to mark their calendars for November 3-5.
  • The event is described as a must-attend for networking with top cybersecurity professionals from around the world.
  • Scott mentions their own participation and broadcasting at the event, encouraging listeners to join.
  • Contact information and details about the event are available on Industrial Talk.

Introduction to Industrial Talk Podcast

  • Scott reiterates the importance of the Barcelona Cybersecurity Congress and its alignment with Industrial Talk's mission to celebrate industry professionals.
  • The podcast is described as a platform for celebrating bold, brave, and innovative industry professionals.
  • Scott emphasizes the collaboration with the Barcelona Cybersecurity Congress and the importance of cybersecurity solutions and professionals.

Introduction of Sounil Yu

  • Scott introduces Sounil Yu, highlighting his extensive experience and expertise in cybersecurity.
  • Sounil's background includes roles at Bank of America and his experience in penetration testing and red team activities.
  • Scott praises Sounil's ability to make complex cybersecurity concepts consumable and understandable.
  • The conversation is set to delve into topics like cybersecurity, AI, and network protection.

Sounil Yu's Background and Philosophy

  • Sounil shares his 30+ years of experience in cybersecurity, including his role as a chief scientist at Bank of America.
  • He describes his job as running experiments to learn through failures, emphasizing the importance of documenting and explaining what is learned.
  • Sounil discusses the rapid changes in technology and the need for organizations to adapt to new challenges.
  • He introduces the concept of the Cyber Defense Matrix and the DIE triad (Distributed, Immutable, Ephemeral) as tools for understanding and addressing cybersecurity issues.

The Role of AI in Cybersecurity

  • Sounil explains how AI is accelerating the evolution of cybersecurity, making traditional cybersecurity approaches less relevant.
  • He introduces the concept of high-velocity engineering organizations that constantly build, rebuild, and tear down systems to reduce attack surfaces.
  • Sounil provides examples of how AI tools are enabling organizations to pivot quickly and adapt to new challenges.
  • The discussion touches on the cultural shift needed for organizations to embrace high-velocity engineering and the role of AI in facilitating this change.

The DIE Triad and Cybersecurity

  • Sounil elaborates on the DIE triad, explaining how distributed, immutable, and ephemeral systems can reduce the burden of security.
  • He discusses the trade-offs between long-lived assets and the benefits of short-lived systems in terms of security.
  • Sounil provides examples of how AI is enabling the creation of ephemeral systems that are less vulnerable to attacks.
  • The conversation highlights the importance of adapting to new technologies and the role of AI in enhancing cybersecurity.

Training the Next Generation of Cybersecurity Professionals

  • Sounil emphasizes the importance of curiosity and experimentation in developing cybersecurity professionals.
  • He encourages young professionals to explore new technologies and understand their vulnerabilities.
  • The discussion touches on the need for continuous learning and adaptation in the cybersecurity field.
  • Sounil highlights the importance of addressing both long-lived and ephemeral systems in cybersecurity training.

The Future of Cybersecurity and AI

  • Sounil discusses the potential of AI to improve cybersecurity by proactively finding and addressing vulnerabilities.
  • He acknowledges the current advantage of attackers in using AI for attacks, but sees a future where defenders can leverage AI for better security.
  • The conversation explores the role of AI in accelerating high-velocity engineering and the benefits of reengineering systems quickly.
  • Sounil emphasizes the need for a mindset shift towards continuous building and reengineering to stay ahead of cybersecurity threats.

Cultural Shift and Organizational Adaptation

  • Sounil discusses the cultural shift needed for organizations to embrace high-velocity engineering and AI.
  • He provides examples of how organizations have adapted quickly during crises, such as the COVID-19 pandemic.
  • The conversation highlights the importance of a flexible and adaptive culture in cybersecurity.
  • Sounil encourages organizations to see themselves as developing countries, constantly building and reengineering to stay competitive.

Conclusion and Contact Information

  • Scott wraps up the conversation, emphasizing the importance of attending the Barcelona Cybersecurity Congress and networking with professionals like Sounil.
  • Sounil provides his contact information, including his website and LinkedIn profile, for listeners interested in learning more.
  • The conversation ends with a reminder of the discount code for the Barcelona Cybersecurity Congress and the importance of staying connected and informed.
  • Scott reiterates the value of the event and the opportunities it presents for professional growth and networking.
If interested in being on the Industrial Talk show, simply contact us and let's have a quick conversation. Finally, get your exclusive free access to the Industrial Academy and a series on “Why You Need To Podcast” for Greater Success in 2026. All links designed for keeping you current in this rapidly changing Industrial Market. Learn! Grow! Enjoy!

SOUNIL YU'S CONTACT INFORMATION:

Personal LinkedIn: https://www.linkedin.com/in/sounil/ Company LinkedIn: https://www.linkedin.com/company/cyber-defense-matrix/ Company Website: https://cyberdefensematrix.com/ The DIE Triade: https://dietriad.com/

PODCAST VIDEO:

https://youtu.be/l5gGbb-v3ao

THE STRATEGIC REASON "WHY YOU NEED TO PODCAST":

OTHER GREAT INDUSTRIAL RESOURCES:

NEOMhttps://www.neom.com/en-us Hexagon: https://hexagon.com/ Arduino: https://www.arduino.cc/ Fictiv: https://www.fictiv.com/ Hitachi Vantara: https://www.hitachivantara.com/en-us/home.html Industrial Marketing Solutions:  https://industrialtalk.com/industrial-marketing/ Industrial Academy: https://industrialtalk.com/industrial-academy/ Industrial Dojo: https://industrialtalk.com/industrial_dojo/ We the 15: https://www.wethe15.org/

YOUR INDUSTRIAL DIGITAL TOOLBOX:

LifterLMS: Get One Month Free for $1 – https://lifterlms.com/ Active Campaign: Active Campaign Link Social Jukebox: https://www.socialjukebox.com/  

Business Beatitude the Book

Do you desire a more joy-filled, deeply-enduring sense of accomplishment and success? Live your business the way you want to live with the BUSINESS BEATITUDES...The Bridge connecting sacrifice to success. YOU NEED THE BUSINESS BEATITUDES!

TAP INTO YOUR INDUSTRIAL SOUL, RESERVE YOUR COPY NOW! BE BOLD. BE BRAVE. DARE GREATLY AND CHANGE THE WORLD. GET THE BUSINESS BEATITUDES!

Reserve My Copy and My 25% Discount

Transcripts

SUMMARY KEYWORDS

Barcelona Cybersecurity Congress, cybersecurity, AI, high-velocity engineering, DIE triad, Cyber Defense Matrix, industrial professionals, network protection, data collection, penetration testing, vulnerabilities, distributed systems, immutable systems, ephemeral systems, cybersecurity solutions.

00:00

All right. Before we get into the conversation, I want you to be aware of a conference that you need to put on your calendar, and you have time. It is the Barcelona Cybersecurity Congress. It is necessary. You need to up your cybersecurity game. You're connected. You need to make sure that you're protected right here. This event, Barcelona Cybersecurity Congress. It is November 3 through the fifth. You have time, November 3 through the fifth this year in Barcelona. And I'm telling you right now, the team at Farah who put this particular Congress on the best. You will not be disappointed, and you know what else you get to do? You get to network with some of the best cybersecurity professionals from around the world. You need to do this. You need to put this one on your calendar. All of the contact, all of the information is out on Industrial Talk. I'm going to be there. I'm going to be broadcasting. I'm going to be talking cybersecurity with the best in the world. So be there. Put this one on your calendar. That is November 3 through the fifth. I'll see you there.

01:16

Welcome to the Industrial Talk podcast with Scott Mackenzie. Scott is a passionate industry professional dedicated to transferring cutting-edge, industry-focused innovations and trends while highlighting the men and women who keep the world moving. So put on your hard hat, grab your work boots, and let's. All

01:33

right, once again, welcome to Industrial Talk. Thank you very much for joining the number one industrial-related podcast in the universe that celebrates you, industry professionals all around the world. You're bold. You're brave. You dare greatly. You innovate. You collaborate. You're solving problems each and every day. That's why we celebrate you. That's why industrial talk is here for you. And that's why you are the heroes in this story. We are working, as you can tell. If you were out on the video, you could say Barcelona Cybersecurity Congress. It's right there. Yeah, right there. We're working with them. You know why we're working with them? They're great people. We have such, and I mean, they are doing the heavy lifting and highlighting all the wonderful cybersecurity solutions and professionals that exist out there today, and you need to put this one on your calendar and make it happen. We have a great conversation. I'm looking at his stat card right over here, Sounil. You and and you can tell he he knows cybersecurity. It's pretty exciting, man, and and I'm telling you, he he does take what is very challenging and unchallenging environment, and and makes it consumable. Let's get on with the conversation. So anyway, yeah, so no, you're just gonna have to get the paper and pencil. He's got so much going on. I mean, I'm again. I'm looking at his LinkedIn card, and it is just yes, he knows what he's talking about. He's one of those guys which I come across all the time that know a lot more than I do, which it's not too difficult. That's that's a low bar. A lot of people definitely know more than I do, but he's he's just he's got a book, and we talk about it. It's all in the conversation. I don't want to blow the conversation. I don't. You just have to listen to it because he it's it's really cool stuff. It really is, man. And and you're taking something that here's a world. The world is happening fast. It's just zipping and it's it's it's happening real fast. Industry and we're we're in the data. We need to collect that data. We need to do this with the data. We need to AI'S hammering at me upside the head. It's it's happening at a blistering pace. But fear not. You have people like Sounil to help to ensure that we and our networks and our our businesses are well protected because they they know what they're doing. It's really a good thing. All right, let's talk a little bit. You you heard the the promo of the Barcelona Cybersecurity Congress, and I want to let you know that I have Scott Mackenzie. Let's let's just check it out real quick. I have I I have it right here. You go out because this stuff's out on industrial talk. But if you go out and you saying to yourself, I want to participate. I want to go to Barcelona. I think our business, we need to be there, and I think that that's the right decision because you're going to be able to sort of run into people that have solutions that you need, or have conversations with people that know what they're talking about, and really because you have to protect your. Business, you need to have these conversations. You need to run into these people. You need to build up that network. It's imperative. You need to do it. So go out there. If if you're not on my my newsletter, I have it right there. But anyway, we have a code. First off, you go into Barcelona Cybersecurity Congress. That's a that's a keyboard, and you find it. You go there. You want to sign up. You put in BCC Podcast 26. That's your discount right there. You put that in there. Get a discount. You make it even better. You you're saying to yourself, Scott, how does it get any better? It doesn't because you're in Barcelona. That's one thing. Two, it doesn't get any better because you're going to be meeting with great people who are passionate about your success. Yes, and three, you have a code. You have a discount code that you can put in there and get the discount, and and and just you can come on and say hello to me. I'll be there. It's all good.

06:06

There's nothing to complain about. Really, nothing to complain about. All right. So that's one thing you need to do that, and you need to connect with Sounil. All the contact information definitely is out on Industrial Talk. I I recommend paper and pencil. I do. I recommend that. Anyway, great gentleman understands exactly what's going on. He is in the. He's leading the way. He looks at the market in a way that is makes you feel comfortable. You don't feel like a victim. He's him and his team. Yep, knocking it out the door, and with that said, here's Sounil. Sounil, welcome to Industrial Talk. Thank you very much for joining. I am looking forward to this conversation. All right, listeners, we're going to be talking a little bit about cybersecurity. We're going to be talking about AI. We're going to be talking about how we can work all that together and how to protect your networks and everything else, and not you know curl up in a ball and worry about your life. How you doing?

07:06

I'm doing well, thanks, Scott. Thanks for having me.

07:09

Oh, I am absolutely again. This is a podcast that is in conjunction with the Barcelona Cybersecurity Congress, and we're featuring incredible professional cybersecurity professionals such as Sounil, to talk about all of the stuff that's taking place, and it's happening fast, right, Sounil? It's happening fast. It's happening way too fast for me.

07:33

Yeah, you can say that AI has accelerated a few things for sure.

07:37

Come on, it's you're soft pedaling that one.

07:41

Yeah, I mean, I mean, like, I mean, just to make a statement, like Mythos is so April. Come on,

07:48

isn't that right? All right, for the listeners, so that we can establish your your gravitas, your credibility. Give us a little background on who Sounil is.

07:59

Yeah, so I've been in industry for about 30 some plus years in cybersecurity. Some of my background includes having been the chief scientist over at Bank of America, or rather call it being a mad scientist. My job was to try to get fired every day. So no, yeah, it was fun. So

08:19

like doing some penetration testing, sort of seeing weaknesses and things like that.

08:22

That was part of my role. I had the the what the what's called the red team underneath me at one point. But the way I would describe what a what what my role was was to run experiments, right? And I mean, like rather, what does an exper? What does a scientist do? They run experiments, and some of these experiments, or rather, I should say, many of these experiments will fail, but you want to try to learn through the process. And the the point of that is there's a whole range of technologies that we encounter on a regular basis, and unless you actually experiment with them and fail of them, you will never really learn what to do or properly control them.

08:58

Yeah, but culturally we don't like failing. We don't like. It's weird, you know. I agree with you 100% We just don't like. I don't like that feeling, but exactly.

09:09

Which is why I describe my job as trying to get fired every day because failure was a common, you know, what was really the the goal, right? We wanted to fail, but it truly would be a failure if we failed and didn't document and explain what we learned from it. If we didn't do that, then it truly would be a failure.

09:28

Yeah, but but because you've had what 35 years? Did you say you must have started at what five?

09:37

I've had a computer for a long, long time, but I've had a job doing this stuff well before I graduated from college. So I've been in this space for quite some time. Yeah, 35 years is

09:53

you've got to see a lot of changes. You've just must have seen tons of changes.

09:58

I see a lot of changes. To quote Mark Twain, history doesn't repeat itself, but it certainly rhymes, and the the rhymes that we see or hear with respect to some of the macro changes that are happening definitely point to what the where the future is going as well.

10:16

Okay, so listener, we have a form on Industrial Talk, and the form is filled out by the speaker because there are two things that I don't like to talk about. One, I hate talking about the schedule. Is you know they just get on my calendar. I'm fine. And two, the topic. This one is a little bit sort of eye opening. I like it. I I want to hear more about it. His topic that he put on here says making cybersecurity irrelevant in the AI age. Unpack that, Sanil. Well,

10:48

n five years, and so this was:

13:40

but you're going to have to expand upon that. When you say those, you know, die. Of course, you can't die.

13:48

Well, the acronym, and it's it's it's there's a the acronym is very intentional and meaningful in that regard. And the the assertion I would make is we need to either DIE build things to be distributed, immutable, and ephemeral, or they will DIE the verb because they will get hacked, they will get penetrated, they will get destroyed, they will get taken over in some way that they practically, for all intents and purposes, they have died. Right, so. so

14:23

yeah, we

14:24

have a choice. We can either DIE intentionally, or we can DIE because the attacker has done it for us.

14:29

Okay, here's here's a scenario, and this is what I've lived through for the past number of years. There was this big push. The big push was one. This was before the advent of AI, and we were we were just sort of talking about it, nothing nothing of real substance. But what we were doing is that we were all of a sudden saying, "Hey, we've got these devices. We're going to stick these devices, and we're going to collect data off of these assets, and we're going to put it in our network, and we're going to just sort of here they go. And everybody was like. Doling out the cash to be able to pull data. Okay, that's all fine and dandy. What the conversation then evolved to was like, are they secure, or are they just little points of, you know, exploitation of being able to sort of get into our network? Well, the latter was sort of the the Case, then what happened was I can't. I I get all this data. It's hard for me to process it. Then lo and behold, AI, and then AI happens, and now I can take that data and I can chew on it, and I could be more efficient. And then that AI says, "Hey, you got to watch this. You got to be careful of that. Whatever it might be, how how have we come? How have we evolved beyond that? That's where we're. That's where I'm finding that we're at Audible. Yeah, we're there. Like show on data, you know, show whatever results. Good, we're good. That that type of thing.

15:59

Well, so let me take just for the sake of the discussion. Let me take it to an extreme view, and so this is this is part of the assertion I'm making in terms of how AI will make cybersecurity irrelevant. So the data that you just talked about that you're collecting off the network or about some some entity or some asset is based on the belief that this asset is there for a long enough period of time that it matters to you, but the DIE triad. One of the the attributes of it is that is ephemeral or short lived. Okay, so in other words, I want things to be distributed, immutable, and or ephemeral, short lived, and by doing so, what happens is I actually lower my burden for security, or what we call the CIA triad: confidentiality, integrity, and availability. So the more DIE I make something, the less CIA I actually need. Okay.

16:56

Okay.

16:56

So this basic premise then of that your your incoming premise is that this whatever asset that you're talking about is long-lived enough that the data you collect on it means something. But what if that thing that you created or that asset you're referring to is gone by the time you actually even analyze it? In which case, the data that you collected is kind of not really that useful.

17:19

Does it work? Yeah.

17:20

Right. So now think about what AI is doing for a lot of things that we see in our ecosystem, whether it's vib coded software or a process that kicks off and then shuts down. There's a lot of things that are happening that are driving towards more what I would call high velocity engineering. Okay. If we think about so, one pattern, one macro pattern that I'm seeing is organizations that are adopting AI tools are becoming more and more high-velocity engineering organizations, and a high-velocity engineering organization is constantly building and rebuilding, tearing down and rebuilding. So the things that people find that may be insecure, or and if attacker finds something that's insecure, it may not be there tomorrow because the organization, if they're a high velocity engineering organization, has moved on.

18:17

Yeah, yeah, yeah. I I get it. Okay, give me an example of what that looks like. Because okay, I live in I live in the world of manufacturing or whatever it might be. We manufacture X Y Z day in day out. We're driven by the desire to be more efficient, more quality, better, whatever it might be. What does that look like in an organization when when I'm over here and I'm I'm in operations and I'm doing this? What does that look like?

18:49

Yeah. So okay. So let me let me start with the IT world and now go into the physical world for a moment. Okay. So in the IT world, what that looks like is things like Docker containers or serverless functions, or thing or or things that basically live for a very shorter period of time, perform its function, and then moves on. It gets it gets decommissioned. It gets torn down. Okay, so in the IT world, that's easy. In the IT world, the concept of one-time use plastics makes a lot of sense. There's there's no point in having something persist longer than it needs to. Obviously, one-time use plastics if they biodegrade really quickly are great. So in the same way, you know, in the IT world, something that lives for a moment and is removed as soon as the the function is performed reduces your attack surface and just makes it makes any vulnerabilities you might find in that space less less relevant. So now, how do you take this into the manufacturing space as you're talking about? So let me take us let me let me let me give you a slightly different view of that to give you a comparison. Okay, so during COVID. You could actually go find masks, PPE products that were that had BYD stamped on them. You could find Huawei masks. You could find Xiaomi masks. Okay, and none of these manufacturing entities are, of course, you know that none of that creating PPE. That's not their core competency. You know they're producing EVs and cell phones and networking equipment, and yet the manufacturing capabilities of this of this these companies, they were able to pivot and and become high velocity engineering organizations. Their ability to do that is remarkable, and I think that is something that unfortunately many of us in the West we we look at and say, how is that? How can they do that? Right? We it's exactly this what you just said, Scott, at the beginning, which is you we are running this manufacturing organization, and we want to increase, improve, you know, efficiencies and processes for the exact same product. Okay, which great, go for it, right? Reduce costs and so on and so forth. But pivot from doing that to making Patriot missiles.

21:15

Yeah, I'm not going to do that. That's a tough one. That's that's heavy lifting right there. Even though I might have the ability to be able to do it, but it's just that's a bridge too far. However,

21:26

if you're constantly in the mode of being a high-velocity engineering and re-engineering organization, then that is not such a difficult maneuver because you're already one already had the mindset. But moreover, people have this sort of perspective of how do I take the tools that I have and refactor, rebuild whatever it is that I'm I'm building today, and what I want to go back to the AI sort of mindset. That is essentially what AI tools are enabling us to do. We are held back in our own beliefs that we cannot refactor, change something because something might break. Well, yeah, something's gonna break, but you'll find a way to fix it and move on. Well, you know, the restructuring of the production lines for EVs to making PP. Did something break? Of course, I'm sure they did. But at the end of the day, they produce way more masks than that the U.S. could ever possibly produce, right?

22:21

So, and I hear what you're saying. This smacks of culture. There's you have these organizations all over the world. Just they they have a specific culture, and that culture has been nurtured, whatever it might be-good, bad, ugly. I don't, I don't know. You know, it just is. We got a culture. You were asking that organization to to change that culture to sort of rearrange that DNA and do it. How do we? How I'm still getting into the AI stuff, but all of this stuff is really interesting. That's a cultural change, and and and again, you're you're in a position where hey, I I'll break things all and then I learn from them. Just culturally, we just don't like that either. So how do we do that?

23:11

Well, I think that culture is shifting though, as people use these AI tools. Well, one, it's it is an imperative for us, especially in the Western world, to get to this point. Let me. I'll use an analogy that I read about, which is many of us in the many of the countries in the Western world are developed countries, right? And China, for a while, was considered a developing country, but developed is a past tensed word. We don't build anymore. We've stopped developing because we're a developed country, but we should always think of ourselves as a developing country. Even you know, we we should we should be constantly building and reengineering and and and because we are not a developing country or don't see ourselves as a developing country, we let our infrastructure stagnate, and you know we lower, reduce. You know, anyway, you get you get the basic premise here. So in the now, think about this about the same sort of mindset of AI, and what does AI enable us to do? It actually helps us recharge and reboot our thinking of, oh, I can build that, and if I once I build

24:18

it, I agree. It's like,

24:19

let's if if you have to remember that as you built this using AI, the that it required very little energy on your part to build it. So if you need to destroy it, no no I don't have that much. I didn't put that much skin into it, and so I can blow it away and restart. And I've done this actually many times where I may build something. I spent a lot of time, you know, giving it guidance and directions to build something, and at the end, I'm like, ah, you know what? Let me just start over. Okay, I'll take all the specifications and I will just start over from scratch. And usually, when I do that, it's better. And of course, I iterate on top of that. And but but the but the fear of starting over. Is vastly. I mean, it's just pretty pretty much gone, right? I don't. I'm not concerned that starting over is a is a headache.

25:06

See, I agree with that. I I love the the disruption that can take place, the innovation that is happening, the the the realization is, well, why not? Why can't we do that? That's right. Love that spirit of saying, "Oh, like, and and what comes to mind, of course, is SpaceX. Well, why not? Okay, give it a shot. You know, I love that spirit. Let me ask you this, and I'm going to transition just briefly to the next generation, the the professionals within the cybersecurity space. How do we, in this world, train? How do the how do we get the the right individuals in the places? So you're a seasoned professional. You've seen it all. You've got a track record. All of this this new stuff. How do how do we continue to sort of inspire that?

26:04

Well, so as we pointed out, I've been in the space for a long time, and that was well before there were formal classes or college curriculum or books or anything of that sort around this. But vast majority of us who started early in the space, got our start by being curious about the technologies that we see and experimenting with them, breaking them, but mostly just using them, using them and seeing how they're flawed, that where where they break, and saying, "Hey, someone needs to fix this. Now, there's some there's a group of people who go and exploit those for profit, and others who will find ways to actually do the do the good for the the common good and and try to address them at scale and so I think in the same way the evolution of technology is such that there's always some new interesting technology out there that can be exploited for gain in some way, and you can call it cybersecurity, but whether it's tied to IT machines, to AI, to quantum, to whatever, there's there's something new in the field out there. And so, what I would say is for all the folks who are trying to get into this field, let your curious like become be curious about the technologies that you're using, and as you direct your curiosity towards understanding how these things work, you'll also discover that these are these a lot of things are horribly broken in different ways. Now, again, what I going back to my earlier comment, I think that understanding how to fix some of these horrible, broken things? They may not be as relevant for things that are very ephemeral, but at the same time, as much as I'm promoting this thing around the DIE triad, there's also always going to be things that require security because they cannot be removed from our ecosystem. You know, think think hospitals, right? Think there are there are certain things that we're going to still have to secure and spend a lot of energy securing, and whether it's hospitals today or some new thing tomorrow, there's still going to be need for people who do cybersecurity, and it's just a matter of you know putting that time and energy towards those.

28:20

Can't do you see the possibility of, and I wrote this down as AI, the tool, the solution, whatever it might be, as a way of being able to improve that cybersecurity position and use it as a shield. Be a little bit more. Do you see it that way? Can of

28:42

course, yeah, of course. Although I think in the near term, the advantage is going to be on the attacker over the for the next I don't know 18 months or so. It's going to be pretty hard for for defenders because the attackers will be using it for attacking, and we as defenders are just getting wrapped up to using it for defending. But there is also a perspective that we'll always see vulnerabilities. There's always going to be vulnerabilities of some sort that are hard to anticipate a priori. So being able to proactively find them ourselves is always an opportunity that defenders have that will use AI for for sure. But I would say the best use of AI is like going back to the basic premise of the DIE triad and becoming a high velocity engineering organization. The best use of AI is to accelerate our ability to reengineer, to engineer and reengineer things, and get to a point where at least for in the digital world, where we can quickly replace the software that we are that we have today, such that even if a vulnerability were to be found, it's it becomes irrelevant because it's the software has changed tomorrow.

29:54

It's it's technology bobbing and weaving. It's it's like you're you're constantly. Changing and moving and just can continue to make it harder to to hit or sustain below. It just it's that's how I see it. I could be completely wrong, but I I can see some speed and some purpose in that.

30:12

Yeah, and there's also the other aspect of it is as people spend more time vibe coding and using consider for a moment what what's the purpose of open source? Open source was meant to save us time, because you don't want to have to go rewrite this yourself. But I can just as well tell AI, hey, use open source as a template, but don't actually use any of the open source packages because they may be vulnerable or they'll have some vulnerabilities, right? So now what you've done is you you get the features that you need, but you don't necessarily get the same vulnerabilities. So from an attacker standpoint, their ability to attack at scale becomes much much much harder.

30:52

Yeah, I get it. Yeah, that makes sense. So

30:58

yeah, there's so many things that we can do with AI now. A lot of the core assumptions that we have for as to why we do things today is based on the fact that we had this constraint. If that constraint goes away, we should really revisit them and see whether or not makes sense for us to. But again, there's always going to be open source. Okay, yeah, I was there. There's going to be

31:17

yeah, and I was going to say that that it doesn't. I mean, you still have to be diligent. You still, you still have to. You got your operation. You, you, you just still need to be diligent about it. And I think you still need to be that that organization that's constantly saying, "I got to protect. I got to, and be current. Right? It does. That doesn't change. I mean,

31:42

for certain. So I I also divide the world into pets and cattle. Cattle are things that are designed to be distributed, immutable, and ephemeral. Pets, you have to worry about the confidentiality, the integrity, and availability of them. Okay. So pets, you have the CIA. Cattle, you let DIE, and and my point is that you'll we will always have pets. We will always have pets. We will always have pets, and you'll have to secure those pets. We don't want them to get run over. But to the degree that we can build and deploy and and cull cattle on a regular basis, you know that's that's a preferred model. To put it a different way, using a biological analogy, you your brain cells are have several layers of security and segmentation and and protections, but your skin cells are highly vulnerable and exposed, and you don't care that they fall off and turn into dust-literal dust every day. Your brain cells are your pets. Your skin cells are your cattle. Today, it seems like many of us build more and more brain cells, but leave them exposed and susceptible to attack. We should really be be building more. We we we still will have brain cells. We still need pets. Okay, but we should be building more and more cattle-like systems. And if any of those cattle-like systems becomes important enough that we should treat them like a brain cell, then you put security around it. But for the vast majority of things, you don't care.

33:25

That is absolutely an interesting analogy. I I got it. I understand it, which is which is very cool. Good job on that one, because I I just and then but I always go to the point, Sounil, that I I I see the market out there. I just see things right, and it's massive, right? There's it's just massive, and and it's going to require a lot of. There's let's put it this way, there's a lot of opportunities to improve.

34:00

We have well. There's there's a lot of opportunities to improve what we have, but we have even more opportunities to restart. Yeah, and to build build from scratch, and I think that is something that we we collectively need to have that mindset of saying, let's go build, let's go reengineer. Let's become a developing country. Let's become a developing organization.

34:26

I agree with that 100. I I really do. I I enjoy that opportunity to learn and and grow and push the envelope. That's why it's great talking to people like you. It's always like, hey, I didn't know that. That's pretty cool. Yeah, die. Now I know die. That's cool.

34:42

Yeah. So it's called the D I E triad. Yeah. Obviously, die means a couple things. The the English word. The Germans don't quite understand what I'm saying, but that's okay.

34:56

Well, you are absolutely wonderful. How do people get a hold? Of you, so no. What if they're saying, "Hey, yeah, I like what he's saying. I want to know more. I got to find out more. I need to, I need to get my act together. What, whatever the reason is, how do they find you? What is the benefit?

35:13

Well, one of course is the Barcelona Cybersecurity Congress. I'll be there in November, meeting folks there. You can find me also by looking up the D I E Triad, so you can look up die triad.com, and I also have the another thing as I mentioned called the cyber defense matrix, defense spelled with the the proper American version, with a C sorry with a with an S instead of a C. We

35:38

always just go to say it's not a C. That's

35:41

right. Yes. So yeah, Cyber Defense Matrix or the DIE Triad. If you search for either one of those, people will find me pretty quickly.

35:49

And you're out on LinkedIn too because I'm going to put your LinkedIn stack card out there too.

35:53

That's correct. Yes.

35:54

All right. There you go. You're wonderful. I like this conversation, Sounil. Well, thanks for

36:01

having me. Yeah, absolutely.

36:03

Well, thank you, and all his contact information. It will be out on Industrial Talk, so you need to connect with this gent because he knows what he's talking about. All right, we're gonna wrap it up on the other side. Stay tuned. We will be.

36:17

You're listening to the Industrial Talk Podcast network.

36:28

Sounil, you, right there. Yeah, you need to put this one at a high priority. Defcon, no. Yeah, Defcon one. Defcon one's the highest. So Defcon one connection right there. All of his contact information definitely is out there on Industrial Talk. He's also going to be there at Barcelona Cybersecurity Congress. He's going to be chirping about what he knows best-that's cybersecurity. And I'm telling you, you will not be disappointed. Absolutely, we want you to succeed. That means you need to network with people who are passionate about your success. Sanil definitely is that, as well as all those wonderful people at Barcelona Cybersecurity Congress. Yeah, they're doing the work to get all these incredible voices, all these individuals, all these companies to come to Barcelona, and then be able to have those conversations. Yeah, they're doing it. They, they, and I deal with them all the time, and they're just wonderful people. And you need, you need to experience that wonderfulness. Is that a word? I don't know if that is. It is now, absolutely now. Yeah, you need it. You need to do it just because they're just absolutely a great, great organization brought to you by those wonderful people at Ferra Barcelona. Again, do not, do not just go out to the website and sign up. You need to put that code in. That's BCC Podcast 26. Put it in there. Get a discount. Sweeten the deal of going to this particular event, I will be there. You need to sort of wander on by. You'll see the lights and say, "Yeah, Scott, whatever you say. That didn't make any sense, but if you did that, I would sort of go, "Okay, need a little water. Anyway, Barcelona Cybersecurity Congress. All right, be bold, be brave. I say it all the time. You know, you dare greatly each and every day. You hang out with Sounil yeah, you will be changing the world. You need to have that conversation. Reach out to him. I'm telling you, he's a nice guy and he wants to talk to you. All right, we're gonna have another great conversation around cybersecurity around Barcelona Cybersecurity Congress because we have a lineup of incredible folks. So, as always, stay tuned.

Chapters

Video

More from YouTube