Resilient Cyber

Building a System of Truth for the CISO

Chris Hughes

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 31:04

CISOs have a stack of tools but no system built to run the security program itself. Mike Armistead wants to fix that.

In this episode I sit down with Mike Armistead, co-founder and CEO of Pulse Security AI and a longtime security founder behind Fortify and Respond Software. We dig into why the security leader has never had a system of truth the way the CFO has an ERP and the CRO has a CRM, and how an agentic layer on top of the existing tools can finally close that gap. Mike is measured about where AI gets to decide and where the human stays in the seat, and he shares what surprised him most from research with more than 80 senior practitioners and corporate directors.

In this episode:
- Why two exits later Mike came back to build a third company around the AI wave
- The silos that left CISOs with an acronym soup of tools and no way to run the program
- What a system of truth for the CISO actually means and how it layers on top of existing structured and unstructured data
- Where agents do the heavy lifting on regulatory monitoring, vendor intelligence, and status reporting
- Governing the guardrails, not the keystrokes, and why closing the loop still involves people
- What corporate directors actually want to hear in the 15 to 20 minutes a CISO gets each quarter
- The findings that stood out, including that 55% of boards have never defined the cyber risk they are willing to accept, and only 12.5% of CISOs are very confident the board leaves with a true picture of the risk
- Institutionalizing the tribal knowledge every security program runs on

Chapters:
0:00 Intro
0:18 Mike's background and two prior exits
1:08 Why the AI wave pulled him back
2:21 Why the CISO has no system to run the program
4:09 Starting at the program level, not the SOC or AppSec
5:28 What a system of truth for the CISO means
8:19 Speaking the language of the business
9:09 Where AI does the heavy lifting on a typical Tuesday
11:57 Govern the guardrails, not the keystrokes
15:44 Bringing deputies into the conversation
16:46 What the research with senior practitioners found
20:37 Boards, risk tolerance, and the reporting gap
24:57 AI as a double-edged sword for security leaders
25:35 Joanna Burkey and institutionalizing tribal knowledge
27:31 A year from now for the security leader

Guest links:
Mike Armistead on LinkedIn

Pulse Security on AI

More Resilient Cyber:
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.

SPEAKER_01

What did you see that pulled you back into the fray here to build a third company?

SPEAKER_00

It was this really this AI wave that pulled me back. I really think that this is one of these areas that you could use it and have be a platform for a lot of great things to come in the future.

SPEAKER_01

You call it a system of truth for the CISO. I'm curious, like you know, break that down a little bit. What does it mean? What does it do? You know, does it replace and or augment what a security leader may already have access to?

SPEAKER_00

You can layer this on top of the existing tools, the existing, not not just like the structured data that you have, but the unstructured ones.

SPEAKER_01

55% of boards have never defined the level of cyber risk they're willing to accept. Cybersecurity storytelling problem on the CISO side? Is it structural? Is it both? What do you think of those numbers?

SPEAKER_00

I think it's both. I think there's both storytelling aspects, but really the CISO has long relied upon the storytelling. So I don't think it's like a delivery.

SPEAKER_01

Hey, I'm glad I could be here. Yeah, I'm excited to chat and learn more about you and the team. But for folks that don't know you and the Paul Security team, as well as some of your background, you know, kind of preceding that, tell us a bit about that.

SPEAKER_00

Yeah, sure. Uh you know, uh long time in high tech, uh, I'm I sadly counted my 40th uh kind of professional uh career or year in my professional career. But uh most recently I was the co-founder and CEO of a company called uh Response Software, um, which got bought by Mandiant, which got bought by Google. So we are uh me and my team uh actually stayed uh through all that. And uh prior to that it was in the AppSec space, uh a company called Fortify, uh which I was a co-founder of as well.

SPEAKER_01

Aaron Powell We were actually chatting about that. Like so this is not new to you. You've had two exits already, you know, Fortify to HP, respond to FireEye. A lot of people would take that and go invest in a few board seats, you know, kind of kick back and relax. You know, what did you see that pulled you back into the fray here to build a third company?

SPEAKER_00

Aaron Powell You know, uh, you know, since I've been through a couple of technology waves, it was this really this AI wave that pulled me back. I I really think that this is one of these areas that you you could use it and have be a platform for a lot of great things to come in the future. I'm not saying that it's gonna happen like tomorrow. I mean, uh it's actually part of the thing that motivated me was if you look at the the companies that were long-lasting through, say, Web 1.0, uh it wasn't the ones that were the leading in that stage. And I think, you know, it was the opportunity to build a company that could last through that, but really get to the value points that people want and the value that we can deliver to the customers and have a and grow a company like that.

SPEAKER_01

Yeah, that makes sense. So I'm curious too. Like, you know, I've been in security a long time. I've been a CISO, I've been an engineer, architect, all the different roles, and like, you know, I've I've been a CEO too, and like the CFO has ERP, you know, the CRO has CRM. Uh the CISO often has a stack of tools, none of which were built to run a security program. They don't really integrate well, communicate with one another, disparate formats, data types, et cetera. You know, why do you think that data, that that kind of gap has lasted as long as it has?

SPEAKER_00

Oh, I I I think it's because the way the market really grew, and the really the function inside of corporations grew as a very technical, practitioner level, like make sure we don't get uh breached or we correct from a breach really quickly or things like that. So it was just very level. And if you think about where the market started, I mean, it was network engineers looking at network packets to make sure that there wasn't something bad in there. And as the threats kind of evolved, we we sprung up a whole bunch of other technologies that could really detect and respond to those. And so it really created this uh world inside of security programs that are a bunch of different silos, all kind of you know, talking a little bit of different language and needing to have experts that could interpret what they're saying with the context that the business is operating in. Because ultimately that's what the business, you know, the the businesses and the security team within that business is about mitigating the cyber risk to that business. And so if you have a broad charter like that, you do need a lot of uh breadth in your program, but you're gonna have to make that translation from that technical area to more of the business side of things.

unknown

Yeah.

SPEAKER_01

Speaking about like translation from technical, when you look at um, you know, the the areas of uh innovation or startup focus, right, in AI in security, it's often been like the SOC, the AI SOC or AppSec or you know, uh a very kind of niche domain within cyber, right, where you all start at the program level instead with the security leader's office. You know, what made you start there? What made you pick this problem?

SPEAKER_00

Uh probably because the two things you just named were my previous two companies. It was this down at practitioner level of uh AppSec and then uh at the SOC uh automation level. Uh you know, Chris, it had a lot to do with when I was at HP, I also ran uh the old ArcSight business, which was very much uh you know SOC-oriented too, but it was a lot, you know, when you're when it's a sim, you see all the the signals that have to come through from all the different tools and that too. And it's just a a broader thing that gave me a big appreciation for both the communication challenges and you know, crafting a narrative from all these different signals that come together. And you know, I talked to a lot of CISOs through that journey, you know, which continued on through my other companies. And it was just clear that that there wasn't a lot of support for the actual leaders that have to actually put that narrative together for their board, for their executives, you know, maybe their business peers, um, and then even just run the that program because everyone was running around making sure they weren't going to get hacked. Uh this was a part that was ignored and and it and it just kind of, I don't know, kind of ate away at me for many years. And uh it was part of the reason why I came back to start Pulse Security.

SPEAKER_01

Yeah. And when I looked at uh some of the material you all have out there and how you're framing the problem, like you call it a system of truth for the CISO. I'm curious, like, you know, break that down a little bit. What does it mean? What does it do? You know, does it replace and or augment what a security leader may already have access to? I know we have all the tools, right? Like the we have our acronym soup of uh CNAP and CSPM and EDR and WAF and XYZ. Like, you know, how does this fit in? How does this system of truth kind of fit into that picture and what does it equip the CISO security leader with?

SPEAKER_00

Yeah, and it's it's in part um what I had said earlier about kind of the underlying technology being the AI or a genetic system. It's that um you can layer this on top of the existing tools, the existing uh not not just like the structured uh data that you have, but the unstructured ones. Uh you know, AI is really good at looking at a document and pulling the right things out of that document, for example, or and that goes for policies and you know other kinds of uh just things that are part of the security program. Yeah, and you know it it it kind of gets back to what you said earlier, too, about you know, uh CFO, you know, they're really in charge of managing the financial risk for the business. And they really they rely upon an ERP system that at its core has a general ledger. And that is the kind of system of truth for for the CFO. You know, probably similarly if you think about the the uh chief revenue officer, uh they've got Salesforce uh or another kind of CRM. And that's kind of their system of truth of like where are the deals happening and what's likely to happen or whatnot. And uh, you know, that's that's kind of that breakdown that we saw was missing for security programs. It's what what's the active current system uh that that leaders can rely upon to basically construct their narrative, know where their strategy is going, even just know where they are in their program status or their program health. And it it just uh it was just a scattering of spreadsheets or you know, assessment documents or audits that that they've been subject to or you know, those kinds of things. And and really they didn't have this system that they could just go back to. And you know, if you think about that those those other systems that the CISOS peers have, it's not like it's that's the system that only the leader stays in. It's like their function is within it and their function uses it. And same thing I think here. And what we're trying to do with Pulse is to provide that system that benefits really the whole function, um, but really up levels it into answering the questions that are asked about the program, not necessarily asked about a particular threat or a vulnerability or or something along those lines.

SPEAKER_01

Aaron Powell Yeah, when I listen to you say that, I kind of hear, you know, we we use these phrases in cyber. Like one of them is uh speak the language of the business, right, is one of them. And it's like not getting into the technical details with the board or executive leadership on a C V E or an exploit or something like that, speaking in languages that they understand. And you talked about that with like a narrative, like trying to bring things together from your disparate security tools to put together a picture of the security program and you know, kind of where you stand uh for executive leadership or the board or whomever, you know, how the reporting looks. You know, maybe stick with that example on like uh say a hypothetical scenario, uh a typical Tuesday, right? Uh for a CISO running a security program, like you've talked about, you know, in your Kai's content, like regulatory monitoring, vendor intelligence, contract exposure, stakeholder communication. You know, where does AI do some of the heavy lifting of these type of activities that historically has been kind of manual or cumbersome?

SPEAKER_00

I I think most in all those areas it's got some influence into because you can have an agent basically be scouring the landscape and uh picking up the right signals for that particular company. And I think there's a there's a point to be made there, is that everybody's security is a little different. Their situation is different. You know, they're a different kind of company, they they budget differently, they have different regulations uh thrown on top of them, they have different skill sets of their people, all those kinds of things. And and uh you know AI can help in getting the information that's needed for those individuals, wherever they may be. And so if you think about uh you know different disclosures that are happening across your vendor landscape or the you know different, you know, new vulnerabilities that are happening and stuff too, the the agents can basically be listening for those things and know what the stack is inside of your company so that they can actually put together what the impact might be. So it's not it's not a theory. It's you know, in theory, sometimes you have to answer too. You know, a board member is gonna show up at a board meeting and say, Hey, you know, I was just reading about that thing that happened at this company. Or are we susceptible? And and you have to answer that. But it's much more powerful to say here's what's going on with that particular situation. And given our tech stack, we're not affected. Or we were affected, we've already kind of identified those servers or those different things that that are uh susceptible to it. We've already applied the patch or put a compensating control there or something like that. And I think that's that's the kind of information that that we're trying to build for people uh kind of within that. And agents play a big role. They can also automate, you know. I think one of the surprising things, they can automate things that you may not have uh at first thought of as as that. Because we use these examples of them being super smart and going doing things. But you they can also just uh be a helper in collecting, say, the status or the the status re the metrics or the information that builds that status report for the for a manager. Um you know, we overlook automation like that a lot of times, and uh having something that's saying, hey, you know, the status hasn't come yet, should I go, you know, and ping them again and make sure that that comes in? And there's things like that that we've learned from our design partners uh, especially that these are really valuable and they save a lot of time. And mostly I think it keeps uh the leaders able to stay focused on some of their strategies, some of the things they're trying to get done, rather than having to run around and do logistical type things.

SPEAKER_01

Aaron Powell Yeah, it's actually exactly what I was thinking of as you were saying, is it lets a security leader be strategic rather than chasing down information from the latest, you know, compliance effort or the latest pen test or the latest, you know, XYZ. Like it lets them think about strategic activities within the security program and tied to, you know, business objectives or key results and so on. Um you used the word agent there, so you know that's kind of the buzzword de jour. Like everyone's talking about agentic AI. But I've been looking at some of the materials, some of the interviews you've done so far. You've been pretty measured about autonomous agents. You know, you said have I think you used the phrase govern the guardrails, not the keystrokes. Um, but you're also selling AI that reads across the whole program and turns it into judgment. You know, where's the honest line for you between what an AI gets to decide versus where a human stays in the seat, especially like from a security executive's you know kind of perspective?

SPEAKER_00

Yeah, I I I think it's a little bit of what we just talked about. If there are logistical things, maybe even just information gathering type items. Um but being able to go into all sorts of corners like uh an LLM can and and and that too, if it has the right skills uh for that, to be able to do that and bring it back. But you're gonna bring it back uh and really closing the loop, and this is something that even we had to discover, I think, when we first started the company was closing the loop involves people. And you know, even take something like a quarterly access review that you're trying to do. The agent's super great at going and getting information about what would feed into that. And that's a lot of systems. You know, you gotta check your cloud, you gotta check your identity system, you gotta check GitHub probably, you gotta you gotta check the HR system, and and that's very toilsome, um, not being very strategic, like you were saying. But then the judgment call is okay, how broad is this assessment gonna be? Um and then ultimately, do I make exceptions or do I not make exceptions? And those are the things that you lose typically. That's the tribal knowledge that almost every program runs on. And uh the what's great about these about an agetic system is it can capture even those decision points and the the things like those exceptions and remember them for the next time you either do the reviews or when you're doing some other assessment about the program to know what you've done in the past and what you may have to make sure you're you're closing the loop on to make sure you either close that out or re-grant the exception uh within that. And so I think there's a lot of stuff like that that happens, but it involves uh the security professionals and the agent doing it together. And so even our system, you know, we recognized long ago, I mean, the way we work as humans in those programs is a lot of times the leaders are asking questions of their trusted deputies and and other folks to get stuff done. And the system should be able, you should ask that question and then should invite maybe that deputy into a three-way conversation so you all can be uh describing or asking the question and and learning from it from each other. And and that's the way we built our system is so that it it had the right, you know, uh multi-user, you know, kind of capabilities that would allow that to happen. Um but to have it be have it be natural. Because there's going to be times where the leader is just gonna want to ask a question that they actually don't want to give to their deputy, because there know their deputy deputy is going to try to do a very high-quality uh um work on this and spend it maybe a couple days on something that they just wanted a quick blush on. And you can ask an AI, yeah, I know it's the context of the company or you know, of the of the company that Post would be in, uh, and could give a a really good first uh pass. And if they need to invite someone to get more depth, they can.

SPEAKER_01

Yeah, I think it it goes back to that system of truth uh framing that you gave where, you know, I've seen this in main security programs that I've worked in and supported where the CISO has to go ask the deputy CISO something, the cloud team something, the endpoint team, the SOC, you know, they're going to all these different teams, to your point tribal knowledge, and it's kind of just dispersed across the uh the entire program and it's inefficient. It uh doesn't really equip them to be able to know what they need to know right away and answer questions they may need to answer to their you know, C-suite peers or whomever. Um so I can see this being incredibly helpful bringing all that data together and like eliminating a lot of that manual activity. But like to your point, the critical decision making that may impact the business and so on, like that still resides with the security executive at the end of the day. And you talked about the the design partner phrase, you used that phrase earlier. I know you all had interviewed, I think it's uh over uh 80 senior practitioners, right, for research you did with Zscale, if I'm not mistaken. Uh when you looked at the gap between what CISO's report and what boards actually need, you know, what kind of surprised you the most versus what did you kind of expect going into it?

SPEAKER_00

Aaron Powell You know, uh it's funny because we kicked that off um and probably a whole nother set of other CISOs before we even started the company that we're you know just making sure what we were intending to do was something that was valuable. And uh, you know, there were plenty there's a plenty of material that was out there from CISOs giving advice about how what to say to the board. Maybe kind of lucky on my end is that I knew some really great corporate directors. And I thought it'd be super interesting to flip that a little bit and say, yeah, but what about what the corporate directors would want to hear from the CISO from their perspective? And that's where that translation of of it being very from very technical type stuff to uh the business. And in when you talk about corporate directors, I mean they may they may even not know what NIST is, you know, sort of thing. And you gotta remember those kinds of things. Uh that that's that that's there. And so um I think that was the one of the bigger surprises as we started to really investigate in there was first of all, how varied uh the different approaches are between different CISOs and directors and things. There really isn't any mu many standards here about how do you give the right narrative at the right level to directors so they can do their job, right? Their job is is is to monitor the risk themselves, but from the the whole business standpoint. I I I think one of the big surprising things though that I found was uh the CISO has 15-20 minutes every quarter. Telling me about your program in 15 minutes. You know, it's and and you know the the natural instinct of a CISO is to is to rely upon the stuff that makes them comfortable. So some of those metrics that they have, they built from the SOC, right? You know, you mentioned that. It's uh or or you know, how many investigations have we done and what is it to you know that's really not the language of that corporate director. That corporate director is is about what's changed in the landscape since last time. What would you say your posture is vis-a-vis that landscape change? You know, and and uh and by posture there I really mean the program health, its maturity, it's you know, it's like how is it what's its ability to kind of handle those kinds of risks? And then what kind of special topics do you have for me, this this thing? Now, they all want to hear that there was not a material uh in you know, uh incident or material breach that's happened. So you have to cover that ground. But then it's about you know making them feel confident that you and your program is on solid footing. And that's a very complex thing to do. And I think that's what was was the most surprised is like, how do you do that, right? Without spewing a bunch of the things that you know make you feel comfortable, but someone might not know what you're talking about. And you know, it's a fact of the matter that those directors do come in maybe biased from their last board meeting at some company that may have almost nothing to do with your situation. But they're still gonna come in and and have uh that that you know, they're gonna ask those questions, they're gonna have that a little bit of that bias uh to that. And so I I I think it was just fascinating from there. And I think there's there's a lot of room that can be that's there to add value to leaders in bubbling all that stuff up and to making it sound, you know, be part of that business conversation. You know, we've talked about that for a long time in security, but it is really a reality, and you and you have to really think hard about what you're saying and how you're saying it uh to get your point across. Aaron Powell Yeah.

SPEAKER_01

Yeah. Speaking about something we've said for a long time in security, uh there were some other uh findings that I found pretty pretty crazy, I guess you'd say, in the report. Um, it in the it talked about some of the numbers in there, and one of them was that 55 percent of boards have never defined the level of cyber risk they're willing to accept. So it's like you know, we always hear phrase about uh you know uh risk tolerance and like risk risk risk acceptance, et cetera. But like if if if less than half have ever really defined that, how do you make those decisions, right, as a security leader? And then also I think it said 12.5 percent of CISOs are very confident, uh only 12.5 percent of s of SISOs are very confident that the board walks away with the true picture of the risk. You know, is that a cyber security storytelling problem on the CISO side? Is it structural? Is it both? Like what did you get of what do you think of those numbers?

SPEAKER_00

Aaron Ross Powell Yeah, I think it's both. Uh I think there's there's both. Storytelling aspects, but really the CISO's long relied upon the storytelling. So I don't think it's like a delivery kind of storytelling. It's more of ground truth, what's in that story. You know, it's it's uh it is, you know, we often I think the trees are presented instead of the forest sort of idea. And and um so I do think it's a little of having ground truth, what's really going on, because so much of what the CSO has available to them is like snapshot type things. You know, the uh internal audit may have just done an audit, you know, internally, and but that's a snapshot of what's gone on. And and there might have been a p you know some penetration tests that have been happening or even an assessment that you've done. Uh so they have those kind of as as as bits of information, but then they have the day-to-day things that they know are going on as well. And and I think it's just hard to construct uh a storyline of that that's in that that has an impact on those directors uh within that. And again, you know, we we have as a couple of advisors to the company, it was one of the first things I did was to get some corporate directors as advisors to us because they're they're living this. And I, you know, happen to have one that's been a CISO and now is uh you know, her now in her second part of her career is a corporate director too. So she knows both sides and she talks about this. It's like uh um just using certain words um and not getting things make mixed up is is a part of it. So I do think, you know, while those statistics are are surprising and and maybe you know even a little scary uh within that, it just means that there's gotta be put more effort into that. And you think about security leaders' roles so often they're mired in the uh the firefighting mode. And they're they're you know, it's hard hard enough for them to think strategically about where they go, but then now to translate all that stuff um so that someone who is pretty far from the problem is gonna understand and and and then have confidence that you you know what you're doing and and you're going is is is is quite a step up. And I think those numbers didn't actually surprise me because I think that's probably where the CFO was, you know, maybe call it 30 years ago before Sarbains Oxley kind of came. And now and you know, I live through the CRM coming in and used to be the the that leader's problem too. You know, uh it's just these leaders have it and and and and having to work at it. You gotta work at it. And then you you do come to an understanding with your board uh at a time, but but you have you know, you you can't just come back, say some stats, hope it got through, and do that. And I also think it's uh it's on the corporate directors, which corporate directors these days, you know, I think are more and more because of AI, they're they're being more inquisitive about things. And I think that's putting more pressure actually on the security leaders, too, to to make sure they got good answers to those inquisitions that are happening uh on it. And uh it's a big big part of uh is it goes both sides.

SPEAKER_01

Trevor Burrus Yeah, that's actually a really great point. Is I was talking to someone else recently and they were saying that, you know, AI has kind of gotten security the attention we've always wanted it to get, right? But to your point, that's a double-legged sword because now there's there's pressure on security leaders to deliver on that that kind of uh you know that mandate that we have, right, from the board and executive leadership. I'm curious, real quick, uh you mentioned uh a CISO that you brought in, who now is a corporate director in the latter part of their career. Um, who is that? Because I think that's a really great move on your part to uh you know couple not only the CISO's perspective of how you build the product and what it delivers and what it can do for security leaders, but also what the corporate executives and board uh leaders, et cetera, want to see as well. Who is that individual?

SPEAKER_00

Aaron Powell Yeah, it's Joanna Berkey, and she was uh the CISO at uh HP and then at Siemens. Uh and you know, uh so two very large organizations, and you know, she's got great stories, by the way. Um and she's a great, great guide for us because she, you know, she remembers the stories of she's like, my team used to keep coming back to me about certain clauses of contracts that we should we accept these or not? And she's like, ah, I've given this position to you guys, you know, a number of times, you know, and and just you know, do that. And so there's there's you could tell that she really sees that the part that was missing were those memories that tribal knowledge. You talked about it before, Chris. The the tribal knowledge that's in there needs to be institutionalized in a way, and that's gonna save time and money and and headache and toil and and stuff everywhere. And and now that she sees it from the other side, she she admits she's like, I wasn't great my first year as a CISO talking to the board. Um, you know, and and she's like she felt like in this case too, the board was they were seeing all the things she was saying and just staying quiet. You know why? They didn't totally understand what she was saying. And until she started to get with her business peers, that's the first thing she always claims to do, is like she she saddled up to them and really thought about how can I help your business achieve its goals. Uh and then and then it was about then she could bring those stories, you know, to the board that she's helping the business make money and and do what it's going to do. Uh and now as a corporate director, she really helps, I think, the CISOs and her and the companies that she's a director of uh to to, hey, this is this is how you need to talk to us. And uh and I think it's uh it's really valuable for those companies. And she's a great asset for us.

SPEAKER_01

Yeah. You know what's funny is that I well, I asked for that exact reason. As you were describing this individual, I was like, I know someone like that. And it's her. I've had her on the show before. She is incredible. Um and she has made that transition so well, and she understands like, you know, moving from CISO to board member and both sides of the perspective, and like she has a wealth of knowledge in that. So I was like, I this sounds like a very familiar individual to me, so I wanted to double check on that. Um I was gonna ask you the last question, you know, rounding things out for us here. You know, play it forward a year. You you're you're setting out to build this system of truth, like this system that CISOs haven't haven't had. You know, in a year from now, like what should a security leader be able to do or answer that they can't do today? How do you, you know, what are your aspirations for that?

SPEAKER_00

Yeah, I I think you know, let's take it from the top level down. I mean, uh we actually have a part of our product that is about building the board deck. And but building it from all the signal and everything that they have as they're tracking their risks, their initiatives, the tasks and the work that's going on and those metrics that roll up from there. So to me, a year from now, they're they're hitting that button and it's it's getting 70, 80 percent of that deck done. And then they're putting the narrative on top of that that that speaks to maybe particulars of the business um uh of that too. And then this is very supportive for them. So this is the top level. Kind of to run their the the second level is they're running their org from something that's not a snapshot. You know, that's uh that's that's kind of a live thing that can that has working for them some agents that are bringing back information that's real time about maybe vulnerabilities or about disclosures that have happened or things like that. And then they can they can actually just have that as part of their their sense, uh, you know, their overall management of it. And it's helpful for their people because everyone in the org now is kind of um working off the same uh song sheet, you know, they're all singing the same tune, you know, that kind of thing. But they they know what risks are important to them today, which you know you know might not might not be the full list of risks that are that are out there, but they might have mitigated enough of of those for a while and they're gonna focus on these other ones. But they have a real picture of that, the real picture of the work that's going on, and that they're they're baselining against other people and um and against frameworks uh is can happen just on demand. And they don't have to, you know, they don't have to go and think of this big project I have to do and gather a bunch of evidence and things, but because the system has already kind of collected that stuff for them for a while. So I I guess I describe kind of a a bit of a well-oiled machine that's working.

SPEAKER_01

Yeah, no, it makes a lot of sense, and I'm excited to see it kind of come to fruition because we do see so much innovation with AI and agents for AppSec and loan management and offensive security, but the security leader is like still, to your point, living in the dark ages, like with spreadsheets and putting all this information together manually. Uh so I'm excited to see where it goes. And thank you uh so much for jumping on, Mike. I really appreciate the conversation.

SPEAKER_00

Yeah, Chris, thanks for the questions. Uh really uh it was a great, great conversation. Thank you. Absolutely. Take care.