Curiouser & Curiouser
Curiouser & Curiouser is a podcast for leaders, builders, and curious minds navigating AI, GenAI safety, and governance in a rapidly changing world.
Produced by Alice, the enterprise trust, safety, and security platform for the AI era, the show draws on frontline adversarial intelligence to explore how AI systems are stress-tested, red-teamed, governed, and protected across their lifecycle.
Each episode looks at how AI is actually showing up in the real world, how organizations evaluate it, where it breaks, and what it takes to build systems people can trust.
We cut through hype and fear to explore how AI shapes trust, decision-making, and real-world work, one rabbit hole at a time.
Explore more from Alice:
Website: https://alice.io
YouTube: https://www.youtube.com/@Alice.io.advance.unafraid
LinkedIn: https://linkedin.com/company/alice-io
X: https://x.com/alice_dot_io
Curiouser & Curiouser
Why Your CISO Shouldn't Be the Department of No
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What if the person whose entire job is risk was the most excited one in the room about AI?
That's Mea Clift. While most CISOs are bracing for what could go wrong, she's leaning in, she calls it being "risk excited," and it flips the whole conversation. She and Mo get into saying yes to AI without letting risk run away from you, how she handles shadow AI without punishing people for being curious, and how she somehow ends up teaching all of this through Marvel and Monsters Inc.
🔗 Podcast: https://alice.io/podcast
Follow the show so you don’t miss the next episode.
New episodes every two weeks. Stay curious.
I've never been a fan of cybersecurity or InfoSec or however you want to call it being the department of no and oh. I need to give them the information to make those informed decisions. So I want to be the department of KNOW. No. So I want to say, hey, this system needs access to our systems that's going to put us at expensive risk. And here's the risk. This is all the informing that I can do to say, hey, I'm cool with us doing these things. I just want to make sure that we're making the right decision from a risk perspective and from a security perspective. And that we don't get caught in a situation where we can't come back from it or can't be resilient.
SPEAKER_01If AI has ever made you stop and think, wait, what's happening? You're not alone. I'm Mo, and I'm a security researcher asking the same questions. On Curiouser and Curiouser, we're having open conversations with experts, researchers, and leaders working at the edge of this space, talking through how AI is taking shape, what's shifting, and how people inside the work are thinking about it as it happens. So join us and listen in as the conversation takes shape. Hello and welcome back to Curious and Curiouser. I'm Mo. You are stuck with me for another week, unfortunately. Um, but this week is made a little bit better, or much better. We are joined by um what I was told not to say, I'm gonna say anyway, the LeBron James of Report, the Lionel Messi of Cybersecurity, one of the top 25 women uh of all time. I will say of all time, but it's 2026. Mia Clift, the CISO of Sengage.
SPEAKER_00Yes. Hi, hello.
SPEAKER_01Mia, welcome to the show. Tell us more about yourself so I don't skewer your intro any more than I already have.
SPEAKER_00Well, thank you. Uh so uh again, I'm CISO of Sengage. I've been here uh a few months. I'm new to my role. It's the second time being CISO of his once CISO of a water and wastewater consultancy firm. I've been in cybersecurity for 28 years. Um, I worked my way up from desktop support all the way through learning all the ropes and server and everything. Uh, I'm in GRC. Uh it that was where I kind of really got my my sea legs under me, as it were, and security proper. Um, I teach the only hands-on cybersecurity GRC course in the world as of right now. Um, and uh I teach it for Oesys, Women in Cybersecurity. And I'm I mentor for Cybersity. Um, and I live in the Twin Cities of Minnesota, where I uh collect antique quilts and I'm a quilt appraiser for fun and teach quilt history, and then I have three dogs as well. So uh really excited to be here and on the podcast.
SPEAKER_01Awesome. Yeah, no, we're super excited to have you. Um, and again, just like such a cool history, but before we go into any of that, Send Gage um want to hear a little bit more about like what Send Gage is because I've never heard of the company. And honestly, at first I was like, it sounds like the EndGage, which was a definitely failure of a device, but a very good attempt at mobile gaming before mobile gaming was mobile gaming.
SPEAKER_00It's so funny you say about the gaming system. Every time I think about it, I think of um I think of uh Picard saying engage on Star Trek the Next Generation. But there you go. Um so Syngage is an educational technology platform. So we handle um several different verticals, workforce education, higher education, textbooks and the like, and uh K through 12 education. So we have a lot of different verticals and support that we do. We even do English as a single language, and we support um different initiatives with National Geographic and with library systems around the country. So we started as a textbook printing company and I've worked into the digital space. We handle uh textbooks for many universities, so a lot of people have that. We also have products like Visible Bodies, which is a mobile app that you can download and do uh dissections or do anatomy work on. So doctors, med students, veterinary students, even biology classes. If you don't want to do the little frog dissection in your biology class, you can do it on the app. So you too can just, if you have a passion for anatomy, can purchase the app and use it. So we have a lot of different flavors of education.
SPEAKER_01Okay, cool. And did you specifically, were you like specifically interested in joining SendGate because you too have been an 18th century surgeon, or is that just like a coincidence?
SPEAKER_00Totally a coincidence. I I had the passion for coming to education because being a teacher and being a student, you know, learning is so important. And I've seen where other organizations have had had breaches and compromises, and I wanted to help protect student identities. I wanted to help protect student data and the property around it. So it was a really interesting opportunity, and and thankfully they they allowed me to come on in BC so and help to protect all of those environments.
SPEAKER_01No, that's pretty cool. Um, and you know, you talk about like uh like education data, and you know, on the show we've had folks from like all different sorts of background from financial, uh, we've had uh medical. Uh, I think you are one of the few people that have come on the show that is coming from an ed tech place. And specifically, you know, it sounds like you have a lot of student data to deal with. So, one of the things that I like to ask when you're in any of these kind of spaces is like, how's like AI just initially when it first started being adopted by orgs, what did that look like? Um, a lot of uh orgs would take a governance-heavy approach at the beginning because of the types of data that they had. A lot of them are more innovative approach. So, like, how do we like innovate first and then figure out the problems later? So, how did it kind of happen for
Adopting AI in Education Tech
SPEAKER_01you?
SPEAKER_00So, our organization is very innovative. We're we're very much into how can we use AI to shape the future of our organization. So it's it's been very much a journey of what are we doing with it? How can we do it? How can we leverage it to make our environment better, to make the customer experience better with engaging with support or even engaging with our education components? So we've we've taken that very like, I want to say, I said this at a different presentation, a very risk-excited posture when it comes to AI. Like we're willing to see where it's gonna go and how well it can work in our environment. So it's very interesting to be in this organization and understand how we're moving forward with AI in a secure manner.
SPEAKER_01Yeah, okay. So makes sense. And risk excited is like kind of one way to like is one way to say it, uh, I will say. Um, most people that are outside of GRC, I've never actually heard them say risk excited.
SPEAKER_00Um, I literally I was I was on a panel and I was uh exhausted. I was super tired, and I had only had like half a cup of coffee, and then it was the first panel of the day, and I just dropped it and everybody went with it. They were like, oh, that's a really good term. And I'm like, okay, we're doing this.
SPEAKER_01Yeah, I mean, it makes sense though, right? For a lot of organizations, it's like, okay, we are going to build, we're gonna do it fast, and we are excited to build, and there's like a lot of risk associated with the both the excitement and the technology. So makes sense. I guess how do you like help your organization make the right decisions uh around risk so that you can kind of maybe minimize the risk part and maximize the excitement?
SPEAKER_00So it's really the the the understanding around it. What is the actual risk of whatever we're looking to do? So is it the risk of how uh the tool is going to work? How are we going to use the tool? What data is going to be provided to the tool? All of those components go into storytelling and understanding what the true risk is. I've never been a fan of cybersecurity or or InfoSec or however you want to call it, being the department of no and oh. You know, I need to give them the information to make those informed decisions. So I want to be the department of KNOW, no. Um, so I want to say, hey, this system is going to pull data out of systems that have intellectual property. Or, hey, this system needs access to our systems that's going to put us at extensive risk. And here's the risk. Here's the impact if that gets compromised. Here's where we're thinking we need to look at securing. This is all the informing that I can do to say, hey, I'm cool with us doing these things. I just want to make sure that we're making the right decision from a risk perspective and from a security perspective, and that we don't get caught in a situation where we can't come back from it or can't be resilient. And I think that's that's the challenge that a lot of organizations are facing. They want the guardrails and they've started to create those governance guardrails, but now it's like how what do we need to actually think about? We
Balancing Risk and Innovation
SPEAKER_00just we we've gotten to the point where we're buying all these tools or we're playing with all these tools. Now it goes, but what is the actual impact of these tools? What are we getting in return from them? And is the juice even worth the squeeze on what we're getting out of it for what we're sacrificing in risk or in cost, even. So it's it's a continuing discussion. And I think it changes continuously. I think where I was six months ago on how I felt about AI and everything was, you know, the questions I was asking was how do you get the data out if you can't remove the data from the model? Well, now the AI companies have started to get smarter where they're creating individualized model environments for each of their customers so they don't have to delete their main model to get the data out. There's they're looking to answer the questions that we've been starting to ask as security professionals and as data professionals and and meeting us where we are so that they can continue to advance the cost. So I really appreciate that that's happening. And I think what what what I'm talking about today may be irrelevant tomorrow because they're going to come up with a different way to protect it.
SPEAKER_01Yeah. I I remember when it was basically like, I think it was like every 30 days in some environments, they basically reset the model and you'd have to make sure, like, oh, well, we've got all the learnings uh like already stored. So like we can just like kind of do this uh this rag tag rag system um where you can go back, load it up, and basically say, okay, well, like here's all the learnings that we've had from the last 30 days, let's stack it on top of this. Just the context gets huge and it's very, it was very not not helpful. I think now, at least from the foundation model companies, we're seeing a lot of better ways to manage it. And then even some of the startups and um smaller organizations that are building um like memory and all these new functions, uh, it's really, really cool. And um, I guess that kind of brings up another another question or at least another realm of thought. So you you know, it sounds like there are a lot of different verticals that SendGauge is involved in, and you've probably seen it as a CISO. Um, I guess how do you help the organization um work or how do you work cross-functionally with teams whenever a new thing comes up that you don't want to like necessarily build, right? You'd rather buy it. How do you like make sure that they're able to like test, iterate, bring new things into the environment, and then get the most value out of that? You know, that's like a lot of product work, it's a lot of IT work. Uh yeah, tell me more about that.
SPEAKER_00You have to work on collaboration. Nobody can work on a silo. And I think in a lot of organizations, there's been siloing. Like security just hangs off in the corner and just comes in and goes, no, you can't do all these things because it's horrible. That's like I said, it's the same with AI. You know, it's the same with any tool or any project that we want to undertake. You know, we have to make sure that we're collaborative and we're understanding what the true problem is and what the true concern is. And sometimes it's not even a big concern. And we have to look at it in the grander scheme of things. If my team wants to be able to uh impersonate another user, cool. How do we do that securely? I don't just want to say no because it's an access control concern. We still have a valid use case for it. And while I could just go, no, you can't do it, how can we do it securely? How can we add additional monitoring? How can we do um, you know, how can we make sure that we're allowing these innovations or allowing these changes or allowing these projects to happen while making sure that we're minimizing the exposure to any sort of data loss or risk or any kind of you know compromise that could happen. I feel like a lot of times CISOs come into the room and people are automatically like, oh, the CISOs there, they're gonna be like, no, you can't do this because it's a security issue. Again, I wanna be like, how can we do it? And and how can we prioritize it? So for example, we have a large international presence, right, for our business. And we have some of our people who want to use international messaging systems that may be insecure. I'm super concerned about that. I wouldn't want them to use it, but I also understand that in the international construct, we have to allow them to use it. How can I allow them to do it safely? Well, I can add additional monitoring, I can add additional controls, and I can limit the exposure to just these systems of these people that have to use it, and they have the permission to use that messaging app,
Managing International Data and Compliance
SPEAKER_00and no one else does. And they can only use it on this device. If we see it being used in other devices that are being managed on our network, then we have to curtail that and and come to a different discussion. So it's not just saying no for the sake of no and no for the sake of, oh my gosh, the sky is falling. It's here's how we can do it safely. And that's really the story that we have to do and we have to manage. And what I've found is that if you do that that way, you earn a lot of trust in the organization. I think, again, security is sometimes that place that nobody trusts because they're just gonna come in and block everything. I never want to be a blocker unless there's something really fundamentally broken. Um I want to be that collaborative person. I want to earn the trust of the organization. And so far in the first few months, I've actually seen where that is happening, where I have some of my project teams, some of my uh business leads are coming and asking me questions or coming and engaging me in opportunities now because I haven't come in and just said no. Because if I come in and just say no, then they don't trust me there because they're not going to be able to meet their goals and their objectives. And I have to be there to empower their goals and objectives.
SPEAKER_01And that makes a lot of sense. It's, I think uh, especially the problem that you were talking about with international, I think that's where things are very, very difficult, right? It really does require everyone to be on the same board or at least uh the same page. Um, when you start looking at users in different uh jurisdictions, right? Now you trigger different compliance requirements. This means you also like something that you can accidentally overlook. Um, it may require you to have different infrastructure completely managed in different ways in different places. It also will require you to have very strict policies around role-based access control, how you're storing data, who can access it, when can they access it, right? So you have all of this regulation that's around it. And I think as soon as like you think GRC or security, the e the reason why people think no a lot of times is because it's like so easy to say no when there are so many rules and people are so bound by like accidentally tripping a requirement somewhere, right? And it's just like, okay, well, like if we don't tell anybody about it, I guess we can't really trigger a rule, right? Um so building trust within the organization is probably one of the biggest things that you have to do. The other part that's really hard to manage is that the the compliance requirements, especially as they just keep continuously mounting with AI. And it feels like over the last four years, it's just continued. Like every time something happens, we then add more requirements and we learn. And the pace of the technology is moving so fast. That's like one minute you have access to a model, the next, it's too dangerous to use, the next, we get it back. And then the next, it's like, whoa, whoa, we actually need to do a security review. Definitely not uh pointing at the US government by any means. Um, but like, how does that work like within an organization? The no versus no, how do you streamline the knowledge in a way where it's like as we're building, we don't feel like we're being slowed down. We feel like we're being empowered by the security team. And like, how do you provide that knowledge to them in in that way?
SPEAKER_00It's it's meeting them where they are, it's getting on the meetings, it's talking to them, it's listening. A lot of what I do is listening. And it's
The Role of GRC in a Fast-Moving World
SPEAKER_00also not just looking at the regulation. You know, I'm reading uh a book now called Stupid Rules. And it talks about that it's not rules don't solve problems. Rules actually cause more problems and they cause red tape and they cause complexity and challenge. What we're actually missing is authority. So what I'm doing is I'm coming in and I'm saying, you have the authority to make this decision. I'm just giving you the information to say, hey, here's where we need to set a hard line and here's where we need to kind of find a way to flex and work together. And that's that's very challenging to a lot of people, especially people coming from a GRC kind of background where they're like, or or a regulatory controlled background. You know, I find it fascinating sometimes when you think about like FinTech, because they have so many regulations now on them, and there's so many competing regulations. Like you have to meet NYDFS if you're doing New York work and you have to meet your national rules and your international rules. And sometimes they conflict with each other. So which one is right? And then you're like scoping down to the point that you're only talking about this one little part of the controls, whereas the whole environment could be on fire behind it. It's like, no, this is secure. No, don't look behind the curtain. And it's like, no, all of it plays together and ties together. You just have to be able to flex it and acknowledge where your gaps are and be honest about it, and then compensate for those gaps. And that's to me, that's what GRC should be doing. GRC shouldn't just be like, hey, check this box and you're not compliant and you should be fined. It's you're not compliant here, but here's how you're compensating for that, or here's how you're resilient for that. Here's here's a thing that we need to work on and improve. Um it kind of like looks at audit too, where you know, people think audit is, oh my gosh, we have a deficiency, it's the end of the world. It's not. A deficiency is a place to grow from, and we have to start looking at it that way. You know, I I took up running about a year ago, and you know, I go for a run three days a week, and there are days that I can run really far and I get a distance that I haven't gotten before, and I'm super excited. And then there are mornings that I wake up and I'm like barely able to do the distance that I that I normally do. You know, there are days that I run three miles and there are days that I run four and a half. It's it it depends on what's going on, but I don't stop running because I did a three mile that day. I go, okay, today is today is that day. I want to get to this point. Like I want to get to a 10K. I still need to keep running. Every day helps me get stronger. Everything that I do helps me to move towards that goal. So a deficiency is is something that I need to work on to improve the security posture, not just a black spot on my record.
SPEAKER_01No, I unfortunately relate to that a little too much. I'm training for a high rocks right now, and it is like the worst thing in the world. It's like a lot of running and then just insane requirements for all the obstacles, right? So like every day I'm like trying to do like a percentage of like the amount of squats and burpee long jumps that I actually have to do, right? Like there's a lot of conditioning and resilience that you really have to build. But um going back to like kind of building the conditioning around a security program and how you kind of do that. I've and again, I don't I don't remember the name of the book, but I do remember my football coach who used to say, keep it simple, stupid, right? The KISS philosophy, um, where you make things easy enough to implement so that you don't have to continuously think about like what type of routes you need to run, right? Or um how you how you're gonna make this lock. You have simple rules that are easy to follow. Um, now I've heard, and some of the people that we work with and some of my friends have all made mention building their own frameworks to work within their organization and kind of get the low least common denominator across everything to try and make it really simple to enable security by default. Now, you you kind of giggle, and I want to know why, because this is this is kind of interesting. I really want to know why, because that either means um this is ridiculous, everybody tries to do it and it doesn't work, or we are actually doing the same thing. So, where where are you at with this?
SPEAKER_00So I I applaud anybody who tries to build their own framework, but why would you reinvent the wheel? Because everybody reinvents the wheel, right? This is why I'm a big fan and proponent of NIST 853. And everybody goes, oh, it's 1400 controls, it's so much work, it's all these processes. But it allows you to build that tailored system. So, you know, it's something that I want to implement here in my organization currently, where, you know, we have all of the policies that are controlled at the organizational level. So all of the main controls are something that the executives agree to that everybody has to follow. Then you tailor down to the things that are important to your data center or the things that are important to your cloud environment, or the things that are important to your office. And then you even tailor down to the individual information system. So in reality, you're not answering 1400 controls. Answering depending on the criticality of the system, 100 controls, 200 controls, 500 controls. It's a lot easier. And then you can automate most of that now. So it's really like giving yourself the ability to have better visibility and control over what is required, but also not asking a cloud environment to answer to physical security questions because you're not, that's a shared responsibility model. You know, the cloud provider is going to have to handle that, not you. But it also allows you to see the full breadth and gap of your organization. It allows you to categorize each individual information system and do that business impact analysis that we are all craving to understand our critical systems. So you build this comprehensive program that allows you to really understand the full risk posture. So while it's great, everybody's like, oh, I created my own framework with 29 controls. Cool. Does that meet the need for everything across the org? And it the answer is it doesn't, because each each operating system is different. Each information system that you're bringing in, each SaaS product is different. Each AI that you're bringing in is going to be different. Each contract is going to be different. You have to meet that difference with that framework. And sometimes it just isn't a one-to-one.
SPEAKER_01Yeah, it's you're you're right. I mean, it's very hard. I think the reason why people like kind of go for like the custom thing is because they just like sometimes don't know that a resource that's all-encompassing exists, right? Or they decide that they want to um, you know, like I've seen people go through different mists and different ISOs, and they say, Oh, we want to use MITRE, and then we're gonna throw something else on top of that. It almost feels like a hodgepodge. And I'm gonna throw a little bit of shade at AI, but I think AI makes it so much easier for people to just like copy and paste documents into a folder and then say, Hey, can you summarize all these and tell me like what we've got to do here? So I'm wondering, um, since you come from a GRC background, right? And GRC engineering has been like this amazing new field or that has like kind of been, I would say, taking a lot of uh career page space recently.
SPEAKER_00Yes.
SPEAKER_01Um I guess how do you see the role of a GRC person changing? Um, whereas like maybe before it was more of like this kind of consulting role. So now like GRC professionals are enabled to kind of do more faster. And again, uh, at least in the situations I've seen with GRC teams, they tend to be smaller, um, but now really be able to force multiply.
SPEAKER_00So I think GRC engineering is that force multiplier, but it's really just APIs going into your GRC, and you still have to understand what good looks like. So if you're getting the data from whatever integration you're doing, you still have to understand what good looks like in your environment. So it's not this binary. And I think that the GRC professional in that situation becomes even more important as the risk advisor to say, yeah, this is the information we're getting. It looks okay, but it's not comprehensive, or here's the gap that we're seeing. So I think in some ways it's really great because it allows them to be a little bit more technical because they're learning APIs and they're they're pulling in the integrations and they're understanding the software that that gives us the information or the the software that we're testing. But I also think that that then derides the fact that we still have to document how we're using these tools and why we're using these tools and provide the understanding of why it's important that we meet the control needs. Like that's the thing is the engineering doesn't tell us why we need to do this. And the why is so important. You know, there's a whole book on start with the why. Why do I need to, why do I need to lock this system down? You get that question all the time. GRC gives you the answer. Well, one, because it's part of this framework, but also here's the thing this builds on this, builds on this. And if you don't have this part, you leaving yourself open to exposure, which opens up this risk, which leads to this data, which means your all your stuff is out on the internet and it's really, really bad. So it becomes even more imperative for that GRC professional to be able to talk in terms of risk and to be able to see the interplay between all these things and not just go, okay, I have this integration and it says that I'm compliant. Well, what does compliant mean? It's also a matter of again, thinking about like audit. Audit is very binary. It's checking the box, it's saying you have this or you don't. And GRC, you can't be that way, or you shouldn't be that way. Let me let me be prescriptive. You shouldn't be that way. Um, I tell this story to my students and uh and uh and in other things. Um, years ago, I had my lawn guys looking at the trees in my backyard. I have a a birch forest behind my house, and I had a couple of trees that needed to come down. I knew one because I had already had one fall. And he was looking at the sky, and I was like, What are you doing? And he said, I'm looking at the tops of the trees. He said, Look at that one. He said, That tree's not moving in the wind. All the other trees around it are moving in the wind. That tree is dead and it needs to come down. You want to be able to flex in the wind. If your tree is flexing, it's alive and it's not gonna take anything out. If it's not moving when the wind is going, it's gonna be the one to fall and it's gonna take other trees with it. You don't want to be that dead tree. You want to be able to flex in the wind because if you're that dead tree, you're gonna take things out and things are gonna go with it. And that's gonna be the residual risk that's gonna take out an organization. So when we talk about GRC and when we talk about security, we can't be that rigid. Now we have roots, we have very strong roots and that ethical and moral and and that understanding of why security is important to us and that passion that keeps us going. But it also means that we have to be able to weave and go, okay, this isn't the biggest risk in my environment today. The biggest risk in my environment's over here, and I need to be a little bit firmer on here, but I need to weave in the wind over here. And I think that that's where GRC professionals are really going to excel.
SPEAKER_01I like the I like the tree in the wind example. Uh, it's also a similar example to why we stretch before we run, right? Um, you do not want those muscles to be tired. And if you can't tell, I'm very sore, which is why all I can now think about are is how sore I am. Um, but you do you do want to stretch because then you're able to run, right? Versus encountering knee pain in the middle of your run or otherwise.
SPEAKER_00Or ankle pain or side pain. I had a pain in my side the other day, and I was like, oh, because I didn't stretch my upper arm. And you're like, you don't think that your upper arm is gonna play into it, but I can assure you it does.
SPEAKER_01Gotta move your arms while you're running. So um you kind of went into it a little bit, I think, with the kind of summary of what you said about GRC teams and how they're evolving. Um, but I want to go back to something you said at the beginning where you're actually you actually teach GRC professionals as well. So when I first started in security, I was really focused in AppSec and I did that for a number of years. And a lot of the things that you described with like understanding the foundations and how something is built and what are the important components, was a lot about how like we do threat modeling and how we actually build systems, right? This is not something that GRC professionals were taught at first. But it seems like now this is becoming much more of like a necessity almost. So I guess uh in the way you teach GRC now to folks, how do you how have you seen that education evolve?
SPEAKER_00Really good question. I think because of the way that I teach and because I teach foundationally, and I
Evolving Education for GRC Professionals
SPEAKER_00don't teach to the technology, I teach the the the foundations of governance, risk, and compliance. And I actually encourage my students to use pop culture as their example. So I don't I don't make them find a business or use a use case and say, oh, well, it's because they they had this, they had this technology and this is how it was built and this is how it worked. They're talking about something that they can humanize and familiarize themselves with. And that allows them to see the risk in a bigger light. It I I appreciate that, you know, we're teaching systems and that what they do get some of that IT knowledge and that you should have some of that IT knowledge. But I don't, I'm not of the school that you have to be super technical to do GRC. I think one of the advantages of GRC is that you can learn how to speak security, you know how to speak normal person, and you can learn how to speak technology, or you can get the technology information from the people who you're asking these questions of. It's about asking good questions, it's about helping asking to understand. And so if you can understand it in a pop culture reference. So, for me, for example, the example presentation that I give is about uh Shield from Marvel and how they are an organization that's protecting secrets and protecting superheroes who are protecting the world. So they're a very high-risk organization that you have to keep very secure. Yet they had an insider risk. If you look at the movie Avengers, they have a guy playing Galaga, you know? That's an insider risk problem because he can, and it's an unapproved software problem because he was able to install Galaga on a workstation on a helicarrier that is protecting the world. And and just thinking about that and how it opens up a new world for these people to go, oh, that's why security is important. That's the thing, and that's the connection. It doesn't matter if it was running Windows, it doesn't matter if it was running Sentinel One, it doesn't matter who it was, what it was doing or or when it was doing it. This person did this thing that exposed the risk that could have caused an incident. That's the education that I'm weaving in. And then if they want to go learn technology, I mean, there's tons of schools for that. There's there's tons of opportunity. You know, you can play around with hack the box. And I advise I advise my students to do that. When they're like, hey, how can I get more technical? I'm like, go take a CCNA course, go take a Microsoft course, go play with, you know, go play with Hack the Box or any of the CTFs that happen at different events. Find what gets you excited and and fall down that rabbit hole. But here's what you need to understand to do GRC.
SPEAKER_01I actually like the uh the example with like agents of Shield. Kind of reminds me of Secret Wars when you know enough information was leaking outside of the organization. And you could kind of uh like these alien this alien race was like fainning to be other people in the organization, right? It also like kind of when you we talk about the Galaga example, it reminds me of like change management where someone's introducing new pieces of software. Oh, like I just wanted to play this, I wanted to try this out, you know? And all these different things they come in and it's like, okay, well, we're expanding the threat surface yet again, and we're introducing shadow AI in the environment. And again, we like don't have proper change management, we just didn't communicate it. I guess like that, all that shifting behavior, it's not like it's a bad thing intentionally, right? It's just happening. And it's very hard to keep keep up with. Do you think that this is something that um I don't I don't know like really how to describe like the partnership piece of this because this could really just be a curious engineer versus uh you know someone who's like really acting with malicious intent?
SPEAKER_00I think you know, you have to think and assume positive intent as much as possible. Um as much as we want to think everybody's out to get us. And you know, we all I I I personally believe I think like a super villain. So uh because of the things that I worry about from a risk perspective and all the things that could go wrong, I do still have to assume positive intent. They're just trying to do this thing, or they're just trying to do this thing. And even threat actors, like they're trying to make money. Is that really a bad thing? Yes, because they're hacking our systems, blah, blah, blah. But I digress. Um when it comes to people wanting to play with new things, people wanting to innovate, doing the shadow AI thing, they're just wanting to do better work. They're wanting to show that they can do their best work, they can do better things, and they can come up with these great solutions. So then it's the combination of how do we put controls in place to ensure that they can do those things safely, but also make sure that they're not going to put us at greater risk. Yes, it's gonna expand our attack surface, but everything we do expands our attack surface. And even the things that we know about are going to expand our attack surface because how many tools do we have in our environment that are magically turning an AI tool on the next day and then tripling our attack surface because they didn't talk to us about it, or they're like, hey, everybody now has access to this AI and you can put anything in it. And then it's like, oh, but that AI, like the was it the Chipotle one that you could get it to write code for you? I think.
SPEAKER_01Yeah, the burrito bot. Yeah. The burrito bot.
SPEAKER_00Um so you know, thinking through that, but also being like prepared to say, okay, we have to put these guardrails. Um, someone mentioned in another presentation that I was at, like, you know, it's kind of the teenager. You still need to teach them how to drive the car. You don't just give them the Ferrari and tell them to go because they're gonna go super fast and they're gonna wreck it and everybody's gonna get hurt. You know, you say, okay, let's go to driver's ed, and then we have guardrails on the roads. And you I remember teaching one of my nieces how to drive, and she was a baker, and she kept trying to weave into the the right side of the road. I was like, no, picture a line of cupcakes in the center of the road that you cannot run over and keep your wheels on either side of the cupcakes. It's the same kind of thing. How do we teach them to keep the wheels on either side of the cupcake? And that's an education component and that human risk component. We want to empower people to make the right decisions and do the right things. And that's part of why we do training. And that's why we come to them and say, help me understand what you're trying to do and how we can do it securely. And again, building that trust relationship with the organization and then building the trust relationship with the business, and then exam it making that example so that our customers then have trust in us. That's really what it's all about. And then Marvel's great in general, going back to the Marvel comment, because you can actually see cyber maturity throughout the entire MCU, and I love it.
SPEAKER_01Yeah, I I for some reason, like I immediately just like when it when you said like maturity, I just imagined that
Teaching Security Through Marvel
SPEAKER_01like scene in, I forget which movie it was, but it was basically after the whole thing happened in um Age of Alt Fond. And they were just like, no, we need a way to like understand every superhero. We need to log all of you, and there's like a group that's like, no, exactly.
SPEAKER_00The courts that goes back to stupid rules, right? There was too many rules for these people. But you think about it. So you think about Avengers, you think about the insider wrist, but you also think about Tony Sark walked on and basically plugged in a USB drive and was able to hack all of SHIELD in 30 seconds by Captain America the Winter Soldier. They're using facial recognition. You have separation of duties because Nick can't get up to that, he can't get into Project Insight because he it's locked by himself, except it wasn't locked by himself. It was hacked, you know. Then they use facial recognition and retinal scans to give the elevated privileges to um for Natasha to release all of the shield data out to the internet. Like that is cool maturity over time on how they protect it. But then you're right, you go to Civil War and they're like, hey, we need more regulation around this.
SPEAKER_01Yeah.
SPEAKER_00And that ends up being a challenge. And then you also then have like, you know, Black Panther and all of the Wakandan stuff, and then you have all, you know, and then you have even secret wars where again the deep figs are coming in. I actually just re-watched Winter Soldier on um on a flight this weekend, and I was like, uh, Project Insight has hit really close to home with how it's like this AI is taking all this information about all of these people and making determinations on their success or failure and if they're a threat or not. And I'm like, hmm, that's uh that's scary now.
SPEAKER_01It's it's it's really good. It's actually cool. I've never um I'm gonna have to re-watch some of these movies because I'm just like, oh, interesting. Like I didn't really think of it from a cyber lens, but there's like so many parallels that can be can be made.
SPEAKER_00Yeah. I actually um years and years ago, I did an AI or not an AI, an IG. So I was working for the government, so I was you doing the Office of Inspector General audit on the Death Star from episode four of Star Wars as well. And there's that was great because I ended up in a like a one-hour discussion with a colleague at the time. Now, this was like 2015, 2016, um, on whether or not R2D2 was a mobile device or removable media.
SPEAKER_01I mean, you know, to interact with most of the systems he had to plug in. Like, I don't remember him like ever doing anything wirelessly. Like, I don't like he always had to be plugged into something, and that was the only way he got context on a system or was able to make any changes.
SPEAKER_00So think about this though, but Princess Leia had to plug a thing into him to to give her the give him the like he filmed that video of her and then just gave that out without having to do it. Oh, it's a transfer thing. Yeah, it was a transfer. So it could have been a mobile device, but I think he was a mobile device because he was transmitting a movie. But you know, now he would just be considered an AI. But yeah, yeah, at the time, what was it? And it was a it was a very intense discussion. It was super fun. But cybersecurity is everywhere. Like, you know, my students are even doing like they did somebody did the cybersecurity they turned the wire into a business. Uh, somebody did a cybersecurity presentation on Monsters Inc., somebody did one on uh Bridgerton this year. I was really impressed by the Bridgerton ones. So cybersecurity is everywhere if you look for it.
SPEAKER_01Okay, I'm I'm very interested in the Monsters Inc. ones uh personally. So I will have to ask you to share that one with me. Yeah.
SPEAKER_00So uh his so they have to give the controls that are in place, they have to give the policies in place, they have to talk about the the
Cybersecurity Lessons from Monsters Inc.
SPEAKER_00categorization, so the risk impacts to CIA triad, but then they have to identify the risk. And the risk was that all the doors were in one facility. It was a single point of failure risk. So you didn't have a second, you didn't have redundancy, you didn't have business continuity. So if something had happened to that one facility where all the doors were, you couldn't get to the other world. You were done. So his proposal was to create a second offsite facility to replicate the book, replicate the doors or at least split the doors up so that you would have success and business continuity.
SPEAKER_01Yeah, there's a lot more places I want to go with the monsters inc one, but I don't even think we have it. Like I'm really I really love Monsters Inc.
SPEAKER_00Um I love it too, yeah.
SPEAKER_01And I've thought about this as well because I'm like, okay, well, like there's almost no access control over the doors. Anybody can get to a door. Exactly, right? Yeah, it's it's um I I forget what it what it is in AppSec, but it's basically uh, you know, you you pick an ID and like you can go to it. Um it's yeah, there's no there's no real controls there. Like I don't ever remember them having to swipe a badge to get to a door or like have to authenticate.
SPEAKER_00They had to get through ROS.
SPEAKER_01You had to get through ROS.
SPEAKER_00So Roz was physical security, but yeah, they didn't have any swiping. You didn't have access control.
SPEAKER_01Yeah, I was gonna say she walks really slow too. Um I remember her speed. Um, but anyway, I think that's about the time we've got for today, which I'm a little sad because I wanted to ask more about your quilting. I wanted to ask more about your antiquing um and how you repair antique sewing machines. But um, I think I will just have to leave that for another day. Where can people find you? Uh, what are you working on? What's next?
SPEAKER_00Yeah, so um I post to LinkedIn uh a lot. Every Friday I post Human Fridays, which is just a human aspect thing. So you can learn a little bit more about me and what I do. Um, it's completely unrelated to security 99% of the time. And then I post about security the rest of the week. Um, if you want to follow my quilting adventures and my antique stuff, uh, you can find me on Facebook at Patches of Time. Not that that really matters. Um, and then my GRC courses through Resus, and our next cohort will be sometime next year. So I think I will be I'll be speaking at uh uh this uh CISA Society's anti-summit in LA in September. That'll be my next gig.
SPEAKER_01Okay, cool. So then we'll have to look out for you there. But until then, thank you so much for joining us today. It was really a pleasure. Um, yeah, very fun conversation.
SPEAKER_00Absolutely. Thank you so much.
SPEAKER_01Cool. And I guess that's it. Um, anyway, stay curious, everybody. Have a great and safe day. Enjoy your drive or wherever you're listening to us from. Thanks for spending time with us. Until next time, stay curious.