In short
Cybersecurity risk and leadership in the AI era, with a shift from “assume breach and detect/respond” toward containment-focused defenses in cloud environments.
Guest
Doug Merritt, chairman/CEO/president of Aviatrix; former CEO of Splunk (led transformation to cloud subscription, growing annual recurring revenue from ~$220M to $3B+). Longtime technology/cybersecurity leader focused on making cyber risk understandable for CEOs and boards.
Key claims
AI accelerates both offense and defense, lowering the bar for finding/exploiting vulnerabilities. Cloud has removed “castle walls/moat,” expanding attack surface and increasing both likelihood and impact. Compliance/governance isn’t enough; containment and runtime controls are essential. Boards should elevate the CISO and consider D&O and cyber insurance exposure, with insurers baking in containment.
Notable examples
Anthropic’s “Mythos” (coding/vulnerability discovery); LightLLM middleware malware that exfiltrated credentials via unfiltered internet egress; “submarine breach locks” and “egress whitelisting” analogies.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VODoug Merritt's Journey in Technology
0:45 to 5:10
Doug shares his background and the evolution of his career in tech.
“Doug is a longtime technology and cybersecurity leader focused on making cyber risk understandable for CEOs and boards.”
Lessons from Leading Splunk and Aviatrix
5:10 to 6:43
Insights on key lessons learned from his leadership roles in cybersecurity.
“So it's just tied into a bunch of different life philosophies that I had and felt that it was a noble profession and a noble career.”
The Importance of People and Culture in Organizations
6:43 to 11:03
Discussion on how culture and people impact organizational success.
“And you may want to just describe what those businesses do at a high level for those who are not familiar.”
Evolution of Technology and Cybersecurity
11:03 to 14:03
Doug discusses the future of technology, AI, and cybersecurity.
“are a byproduct of the daily habits and the culture.”
The Future of Automation and AI
14:03 to 18:46
Explore the optimistic outlook on human roles in an increasingly automated world.
“But I absolutely see daily progression on the end-end processes that are able to be conducted by machines with human oversight or some degree of human review.”
Understanding Cybercrime
18:47 to 21:44
Gain insights into the simplicity and complexities of cybercrime today.
“So let's zoom in into cybercrime for a moment.”
Evolving Cybersecurity Strategies
21:45 to 27:02
Learn about the shift in cybersecurity from prevention to containment.
“And there were a whole set of principles that applied to the physical world.”
The Vulnerability of the Digital Age
27:03 to 28:00
Discuss the vulnerabilities faced by companies in the modern digital landscape.
“There's the initial entry path, and then there tends to be lateral movement.”
The Evolution of Cybersecurity in the Internet Era
28:00 to 29:10
Learn about the origins of cybersecurity and how the internet's design influences security challenges.
“Given that cyber activity is really bad, how do you get in?”
The Dual Nature of AI in Cybersecurity
29:10 to 31:00
Explore how advancements in AI, like Anthropics Mythos, both enhance coding and expose vulnerabilities.
“You knew exactly who was in the other end and you trusted them.”
Show all 23 chapters
The Growing Threat Landscape
31:00 to 34:10
Understand how the rise of powerful AI models is democratizing hacking capabilities and increasing risks.
“I'm sure that most of your listeners will have heard of Anthropics Mythos, the latest offering that they've held for a couple of weeks.”
Strategies for Cyber Resilience
34:10 to 38:20
Learn about the importance of containment strategies and how compliance isn't enough for security.
“and we've liberalized who has access these engines just through the open source arena, then we have to have a remediative strategy.”
Understanding Cyber Attacks and Prevention
38:20 to 41:20
Get insights on the main types of cyber attacks and the foundational controls needed for effective prevention.
“but they need to both have a feeling that their voice matters.”
Personal Cybersecurity Practices
41:20 to 42:00
Discover essential practices individuals can adopt to protect against identity theft and enhance online security.
“And for individuals, how should people think about identity theft differently than they do today?”
Importance of Multi-Factor Authentication
42:00 to 43:30
Learn why multi-factor authentication is crucial for online security.
“Everyone talks about complex passwords, but you have to have multiple different ways before, which is friction and a pain in the butt to try and protect the activities that you have.”
The Asymmetry in Cyber Defense
43:30 to 45:00
Understand the challenges defenders face against attackers in cybersecurity.
“Don't go around opening all the doors and leaving them open.”
Practical Cybersecurity Changes for Executives
45:00 to 46:50
Get practical advice for executives to reduce cyber risk immediately.
“to meaningfully reduce cyber risk, what would it be?”
Case Study: Middleware Malware Attack
46:50 to 48:35
Learn about a real-world malware attack and its implications for security.
“It's kind of the connectivity layer between everyone in your company that is querying AI and the AI that it has accessed.”
Leadership Principles for Cybersecurity
48:35 to 51:40
Discover five core leadership principles to enhance cybersecurity culture.
“I'd like to ask you a few questions about your leadership philosophy, which I found very insightful.”
The Balance of Purpose and Action in Leadership
51:40 to 55:50
Explore the importance of purpose before action in effective leadership.
“And I'll give an example that I'm concerned about right now.”
Learning from Failures in Leadership
55:50 to 56:06
Understand how to cultivate a learning mindset without compromising standards.
“Even my failures, if I'm really honest, though, like they were the best learnings.”
Embracing Failure as a Learning Tool
56:06 to 58:22
Learn how embracing failure can lead to growth and innovation.
“That benefited me way more than continuously doing something with success, which is the other element I'm trying to capture is if life is all about learning and growth, it's a full contact sport.”
Wrapping Up a Fascinating Discussion
58:22 to 58:36
A summary of the engaging conversation and reflections on its value.
“It was a lot of fun for me and I hope our listeners enjoyed it as much as I did.”
Transcript
Automatic transcript. May contain errors.0:05Doug Merritt:Welcome to the Insightful Investor Podcast, a weekly series that seeks to share industry, investment, and market insights. We define insights as concepts that are counterintuitive, widely misunderstood, or underappreciated. In other words, unique ideas that you probably won't hear elsewhere. I'm Alex Shahidi, the host of the podcast and co-CIO of Evoke Advisors, a leading investment advisory firm. Learn more about our show at insightfulinvestor.org.
0:38Doug Merritt:Today, I'm joined by Doug Merritt, chairman, CEO, and president of Aviatrix and former CEO of Splunk, where he led a major transformation in how the company built and delivered its products, shifting to a cloud-based subscription model and growing annual recurring revenue from roughly 220 million to over 3 billion during his tenure. Doug is a longtime technology and cybersecurity leader focused on making cyber risk understandable for CEOs and boards. Today, we'll stay high level and discuss the evolution of cybersecurity, how companies should think about their cyber posture, what AI changes for both attackers and defenders, and Doug's leadership philosophy.
1:20Doug Merritt:Doug, thank you so much for joining us. Alex, thank you very much for having me. Let's go back a few years. What do you feel originally pulled you into technology and enterprise software and has kept you there as the industry has evolved? Going through college, I did not have in mind that I wanted to be in the high-tech industry. It was the 80s and it wasn't nearly as in vogue as it has become over the past couple of decades. But when I got out and started interviewing, I wound up interviewing with a company that became Accenture. Back then it was Anderson Consulting. And I dove into what they did and realized in my mind that when I go back to what makes humanity, when are there enlightened ages of humanity and when do we progress as an overall organism, as an overall species?
2:16For me, everything ties back to liberal access to information and educational capability. And as weird as it sounds, as a 22-year-old kid interviewing, when I had taken a couple of coding classes and I had one of the early, early renditions of what became the PCs and I did some basic coding, but I hadn't really thought about the impact that technology could have on the world around us. But my tie as I was going through those interviews was back to technology at its core is liberalization of information for good and for bad. It has no borders. And I just became grounded kind of moralistically or in the orientation that this was a general force for good as far as helping educate people, ensuring that you had ample information to make decisions and research.
3:21And I kind of got, I guess, stuck in enterprise because Accenture helped create systems for enterprises. But what fascinated me about addressing enterprises needs versus, and back then consumer wasn't nearly as much of a thing with technology as it is today, but the consumer orientation is that the domain set is understandable. It's hard for me to visualize what makes a hit and not a hit with a consumer. There's a whole body of psychology around that and people that are really good to study it deeply and are tapped into the psyche of the average consumer. But for me, spending time with a company or a function within a company, I could really get a beat on how does it operate and what are the key elements to make a marketing function or an engineering function or a manufacturing function or a sales function more productive and more effective.
4:20And I just I love that constrained set. And ultimately, for the other posh that I have is an increasing economic capability for the world is the grounding of safer societies versus less safe societies. and the revenue flows come from these companies and organizations. The impact that they have on communities and the world around them is just, we sometimes overlook it when we have these anti-business waves that we go through. But I mean, that is the foundation of companies is serve the population they're serving and do that by galvanizing teams of people. And as you galvanize the teams of people, they get economic remuneration and the community winds up doing better.
5:15So it's just tied into a bunch of different life philosophies that I had and felt that it was a noble profession and a noble career. And I could do something that I actually cared about that might be helping others along the way.
5:29Doug Merritt:It's interesting. I always think it's fascinating to imagine a world without whatever you're considering. rink. So imagine a world where we couldn't easily share information. Like think about how much slower humanity would progress if we couldn't share that data. And you think about companies, like if companies didn't exist, you know, what would the world look like? It is really interesting when you view it through that perspective. And as you go back to how do you control a population and go back to the millennia and the centuries, you dramatically curtail the information that they can, that that population receives, and you try and pull education from folks.
6:13Historically, I can see why so many things have happened in the world on how to contain the power of people if that's your motivation. So yeah, free flow of information and spreading economic capability across population both seem to be very good things.
6:32Doug Merritt:So looking back over the last decade, what do you feel were the most important lessons you learned from your time as CEO of Splunk and now at Aviatrix? And you may want to just describe what those businesses do at a high level for those who are not familiar. So Aviatrix, our focus is on how do you provide more and more effective cyber resiliency and cyber capability to the cloud environments that organizations will be or so depend upon for their daily interactions today. Splunk served that purpose also, but through a different lens. We're focused on Aviatrix, on how do we make it more difficult for attackers to be successful by leveraging something as foundational as the network and information flows across the cloud.
7:27At Splunk, we were focused on how do you help all organizations, but principally we focused on the cybersecurity division, do their job through the accumulation of massive amounts of data and finding the signal from that very, very, very noise data. And the whole angle that we had at Splunk is cyber, most industries are becoming data industries at their core. And the cyber industry, if they want to be successful, had to get far better at detecting anomalies, understanding aberrant patterns and capabilities, and remediating those as quickly as possible to try and stay a step ahead of the attackers, people that were trying to do harm.
8:18But both companies are very focused on cyber resiliency and the ability for organizations to continue to operate and serve their constituencies effectively.
8:29Doug Merritt:And obviously, as a CEO, you get to run those organizations. Are there any key lessons that you learned through that experience? So many lessons. The core of what I've learned over and over, which is that trite thing that so many leaders say is everything is about the people. It's trying to determine what is the right market and how to serve that market. And do you have a defensible moat? I mean, they're all critical. The job of any leader is so, so multifaceted. but you're really bounded by the capability and the culture of the people that you draw in and how they operate. And it's hard, like it's non-trivial to create a culture that is gelled and that has learning growth and development as the core mindset and has an abundance frame as the core mindset for the organization.
9:30There's so much in our genetic development that really emphasizes fear and scarcity for good reasons, for self-preservation reasons. But the teams that I found that are super successful are incredibly curious. They're learning organizations that truly have a growth mindset, right? There's no way that you can learn and grow without consistent learnings, which we dub failures. Like there's so many dead ends and so many ideas that you have that as you test them out, because the business is just one continuous experiment, wind up to not be the answer to the thought that they're going to be. And with a fixed mindset and a fear-oriented or scarcity mindset, I think it's really difficult to have a long-term successful organization.
10:25So who you draw in, what attributes and skills you're looking for from those people, and how do you create a culture that really, really orients toward incremental discipline, incremental daily progress and learning as the core reason for the organization, which often means like so much of guiding teams is helping to drive the outcomes of the team. And my orientation is the outcomes are a byproduct of the daily habits and the culture. That if you're doing the right things day in and day out, and you've got a learning-oriented organization that's okay with lots of iterations and experimentations, you will eventually get great outcomes.
11:18But if you're focused on, I have to achieve this thing, and that's the guiding, that is the mark that everyone is striving toward, it actually, I think, is more of a lazy orientation because there's insane numbers of excuses that you can manifest on why you didn't achieve the outcome. There are very few excuses that you can manifest on why weren't you able to incrementally learn today and incrementally improve your craft. Half a percent, a percent, a quarter of a percent day in, day out.
11:51Doug Merritt:So we're going to get into your leadership philosophy near the end of this podcast. So I'm looking forward to that. But I wanted to talk about technology and computers and cybersecurity, if I may. And I want to start very high level. So long ago, it was humans interacting with humans. Then humans started interacting with computers. Then computers were connected to each other. Then everything moved from physical to the cloud. Now systems increasingly think and act like humans. But what do you see as the next stage in that evolution? It is evolving day by day. And anybody that says that they have the answer to where this is going to land, it's hard to believe that answer because it is such a non-deterministic system that we're building right now.
12:46The foundations of this generative AI wave are non-deterministic in their origination, in the way that they are actually architected. But it's assuming that something completely cataclysmic doesn't happen, where our technological world and online world just disappears, the trajectory is pretty clear. And we've seen that from the industrial era all the way through to today, that machines or third parties are increasing the amount of output and involvement that they have in every day-to-day operation. I think what's so unique about what's happening right now with this generative AI wave is it's the first time that knowledge work is now being included in full stack, full end-to-end capability of the systems that we're using.
13:40And we're in a very weird in-between spot right now, which is this mix of agents and humans. And the rate at which each operates and the capabilities of each is very, very different. And I think that's part of the haphazardness of how much benefit you're getting from AI right now. But I absolutely see daily progression on the end-end processes that are able to be conducted by machines with human oversight or some degree of human review. But the actual process is largely autonomous with humans being involved, but not in the middle of every process. And I can see us getting there in the next, you know, for many processes in the next 18 to 48 months.
14:36And that then opens up a whole bunch of questions of like, what are the roles of humans and what jobs do humans have? And that, again, I'm an optimist. I'm an abundance thinker. And I do believe that long-term, all of the work that we're doing winds up dramatically increasing the overall economic capability of the world. And dramatically, and through that, dramatically increasing the resources available to every human. Again, barring a cataclysmic outcome, like where we'll be five years and 20 years and 50 years from now, I think is hard for people to imagine. like it would be difficult for a farmer that was operating their couple-acre plot in 1800s to imagine what the world would look like when we had gone through this industrial revolution.
15:24But the economic output over the past 200 years has just been mind-boggling. And I see an exponential curve of exponential output through everything that we're doing right now. I think that there is a singularity that's coming at some point in time, and I don't know exactly what that looks like. But it's the path that we're on for sure.
15:44Doug Merritt:Do you feel long-term, are computers here to serve humans, partner with humans, or eventually set their own rules? Hopefully it's not the latter. There's so much debate with someone like Jeffrey Hinton on, who's been incredibly influential in all the developments around AI for the past many, many decades, taking one extreme position, which is who knows what the rule is going to be. We don't know what a rule looks like when there is a species that's significantly more intelligent than us. And there's not a lot of incidents of the more intelligent species doing a super effective job of caretaking the less intelligent species.
16:30All the way through to at least the philosophy that I had decided to adopt three and a half years ago, as you really could start to see what the trajectory looked like. The most enlightened humans that I've studied through history become incredibly believing in a power greater than ourselves and very thoughtful about the intelligence that they have. But increasingly, it's hard to imagine that humans are less involved in the daily activities of a lot of the operations and activities that are happening around us.
17:19Doug Merritt:What do you think are the implications of where we are today that most people aren't really grappling with yet? One of the interesting observations I've had is that through a whole series of environmental elements, got increasing attention deficit disorder, we're distracted all the time, everything is quick twitch, that humans are becoming more binary, gravitating one in the spectrum of the other, because it's easy to occupy those ends. and it requires a lot of thought and a lot of nuance and a lot of attention to understand the gray in the middle. At the exact same time that the systems we're creating are becoming much more thoughtful, much more first principle driven, much more nuanced.
18:10So ultimately, I think we have a lot that we can learn. Like when I interact with the multiple engines I interact with every single day, the curiosity, the empathy, the thoughtfulness, the groundedness of my interactions is often higher than it is with many humans. So yeah, again, on the positive side, I think there's a lot of beneficial influence that the continued evolution of AI and all the correlate artifacts can have to help guide humanity a little bit more.
18:47Doug Merritt:So let's zoom in into cybercrime for a moment. So you often describe cybercrime as simple at its core. Find something valuable and get it out, just like in the physical world. What are the valuable assets today that companies tend to underestimate? I don't think that companies underestimate valuable assets that often. I I think most companies understand either the physical items that they're trying to secure in the physical world or the critical data elements that they have. They both have the obligation to protect their customers' data, et cetera, as well as the elements that make their business so successful.
19:26The intellectual property that they have, the contracts they have, et cetera. And I think I have not met a company that doesn't understand any importance of protecting that. I think what I'm seeing with that groundedness of, so what are the attackers? There are two broad categories of attackers. There are attackers that just are interested in disruption, and they're not as interested in monetary extraction. Those are super dangerous. Those are much harder to defend against. But the bulk of the attackers are business people. They're business people with different ethics and a different business they're trying to run.
20:05But they actually count on not crippling the system and not crippling the company entirely because they've got to extract ransom or some type of payment from that organization. And if I go with that primary headset of, you know, what are most cyber teams really, really focused on trying to work against, then those folks are just they're just trying to get into it's much harder to get into most physical environments. The cyber environments are a little bit easier to get in because they're so complex and there are so many entry and exit paths. They're just trying to get establish any foothold anywhere within that environment.
20:43And then, you know, most of the reusable actors are very patient and they're very sophisticated. Once they gain access, whether they co-opt an employee to begin to work for them, which is actually still the predominant, like human engineering is still, the human weakness is one of the biggest weaknesses in cybersecurity. Or whether they get in through other means, they're super patient and sitting within those environments so that they can take their time, like they'll land in the entryway of your house. There's usually not a lot of valuables lying around the floor right by your entryway. So they have got to take their time to understand the layout of the house and what are all different rooms and which rooms might have the highest valuables and how do I get to those rooms?
21:24And if I get there, where do the easy access pass out? Because I don't want to get caught moving through that house, getting to those rooms and then with the valuables that I'm trying to extract. The complication I see for many companies is the world that we grew up defending was a physical world. I owned a data center or I had a closet in my building, on a floor of the building, that had very restricted access in and out. And there were a whole set of principles that applied to the physical world. Castle Emote, as an example, as I try and make sure that there's only one location for these assets and they're hardened walls and only one way in and one way out and lots of systems to gate who can come in and out.
22:12As we move to the cloud, that world changed really, really, really dramatically. And I think the biggest challenge that most technical teams and cyber teams are grappling with is really understanding at a fundamental level, what is that architecture look like as I move to the cloud? What is every entry and exit point? What are all the corridors between these things? And how do I get some degree of comfort that I've got motion sensors, cameras, and guards sitting at every entry point, every exit point, and every hallway, every connection between those. The attack surface has changed a lot, and it's changed actually to the adversary's advantage versus the defender's advantage.
23:02Doug Merritt:So based on that, are we more vulnerable today than we were even 10 years ago? Not just in the likelihood of an attack, but in the impact when something goes wrong? Yes, I think we are much more vulnerable today and the impact is at a very different scale than it was before. And again, just on kind of the foundational thinking, the principle with Splunk was given the complexity of the landscape, you have to assume that portions of your state probably are already at bad guys inside of them, that the predominant cyber thinking was perimeter defense and prevention of allowing people to get in. And given the complexities of that cloud environment that I described and the advancements that the attackers have in the tooling that they use and the natural vulnerabilities that exist across code that's been written through the many decades of code that's being run inside companies, there are so many spots for an attacker to potentially get in and begin that reconnaissance and extraction.
24:11So if you assume they're inside, then the whole splump about your proposition was you've got to get really, really, really good at detection and response, right? Assume breach and make sure that you can, when they start to do something, you've got as many signals as humanly possible that something is beginning to go in a direction that you didn't understand. And you've got really effective spot teams that can flood the area that you're seeing anomalous behavior and try and stop something before it actually spreads very detrimental or detrimentally or they're able to get something out. With what's been happening, you know, over the past few months that has been years in building, the, you know, what we're advocating here is the predominant approach has got to move from detection and response, still important, right, just like perimeter defense and prevention is important, like these don't go away, But what is the strongest hand you have?
25:10The strongest hand you have at this point is containment, is ensure that if they land somewhere, where they can operate is as bounded as possible. An analogy I've been using the past few weeks is, if you think of every company's cloud environment as a submarine, and that submarine is the depth, meaning if anything happens to the hull and it spreads, everyone dies. Like, the entire sub will implode, and it's a cataclysmic event. Any critical physical technology, a submarine, hydraulic systems on airplanes, nuclear reactors is built assuming failure with containment philosophies built in. If a portion, if one small hole occurs within your submarine, you happen to hit something or they've got breech locks so that that portion had suffered a bad thing, but it doesn't infect the entire sub.
26:12That is what I'm advocating as one of the key champions and building one of the largest companies in the detection remediation era is we have entered a new era. And it's got to be a containment-focused set of activities that are at least as well-funded and at least as aggressively implemented and paid attention to as a detection and response element. We've got to implement breach locks. We've got to implement as many containment modules as we possibly can within our technology stack and make sure that they're sound, make sure that they're effective. So if an attacker does get into an area of your state, they're very limited in the damage that they can do.
27:00You'll see the signal over time, and they're not able to spread very quickly. in the cyber world. There's the initial entry path, and then there tends to be lateral movement. I'd begin to move a cry out through the house, and then there's the eventual either nefarious activity. I'd detonate a bunch of stuff or exfiltration. And you want to contain lateral movement as much as possible so the damage has been lost.
27:29Doug Merritt:One way to think about it is you used to have a castle with a massive moat. The moat is gone. The castle doesn't have walls. It's sort of open. So the mindset shift is, and the new mental model is, there's going to be probably be a breach. There may already be one. And just think about how you contain it should that occur. At each, we used to rely on that moat and the castle walls and guards around those walls. And therefore, you could have lots of valuable stuff lying around inside without a lot of guards. but in this world that we're occupying now like all the valuable things have got to have their own little box around them um with like a camera and a motion sensor and a guard and if you're willing to adopt that philosophy then you know they may get you know actually breach the walls of that one viable thing that you could probably keep them inside that viable thing or at the very worst not allow them to move to every other valuable thing i mean if we're if we're super fundamental, right?
28:31Given that cyber activity is really bad, how do you get in? How do you find the valuables? How do you get back out? You need access paths to make that happen. The internet, the only reason the cyber industry really exists as an investable category, I believe, is because we invented the internet. The internet is a series of very well-paved roads that anyone on the planet that has access to the internet can travel. As soon as the internet got invented. It wasn't invented to be secure. It was invented on purpose to be a collaboration technology. It was invented out of a series of trusted sources, governmental agencies that needed to cooperate.
29:10You knew exactly who was in the other end and you trusted them. They're employed by the same organization and universities that were collaborating. So security was not the overriding principle of the internet. They didn't initially think that the internet would become the commercial pathway for the world to operate on. But as the internet both evolved and we began to plug it into our devices. We began to plug it into our data centers. That was really the beginning of the cyber industry. You know, the first company that really capitalized on that was a company called Checkpoint. They built the first industrialized firewalls.
29:39Like given that you're plugging the internet in, put the guard there. You know, look, everything that's coming in, everything that's going out of the internet, make sure that hopefully no bad guys get in, but if they do, they're trapped inside.
Read the full transcript
29:54And with what we've done with cloud, Like, the internet is woven through cloud. Every critical service that you use for an Amazon, Google, or AWS is directly internet addressable. You know, when we go out to open AI and back, we're going across the internet. And all those systems are woven together to serve a corporation. So that is your, like, the walls are gone. And the walls are gone and good guys and good humans and bad humans can wander through that castle at any point. So you've got to really change your thinking.
30:32Doug Merritt:We talked earlier about the good side of the liberalization of information and data and the advancement of humans. But now we've shifted into the bad side of it where that same opportunity and openness can create significant issues. Yes. And you can't have – when you invent something, it's the good and the bad are two sides of the same coin. What is it? I'm sure that most of your listeners will have heard of Anthropics Mythos, the latest offering that they've held for a couple of weeks. And there's so much discussion right now about, like, how do we contain this? So, Mythos, it's just the latest model, and it's a huge step forward in capability versus their last model, which was just released in January, which is incredibly powerful.
31:29Opus 4.6 is amazing, and it has released Opus 4.7. But Mythos is way, way, way more powerful in many different dimensions, and one of those is its coding capability, its ability to understand the language of software development and coding. And there are two sides of that. What do we generally use it for? We use it to produce more code of higher quality, hopefully with less security vulnerabilities way more quickly. But the flip side of that, that's an inherent property of these engines, is it can find vulnerabilities within that code. It can find ways to abuse that code in one way or another.
32:08And it's extraordinarily difficult to put guardrails around that, like trying to understand what is a good coding behavior and a bad coding behavior. They try. The commercial engines try. There are some patterns that you can detect that would indicate that it's a bad set of activities. but it's an inherent property of these models. And Anthropic and OpenAI and others already have their next two or three models being queued up that are way more powerful than these current models. And the open source community, which is where the entire transformer paper was birthed, it was an open paper for the world to operate against.
32:45The open source community is progressing very rapidly. And just the gap between what Anthropic or OpenAI are doing with their models and what the open source models are doing continues to close because you've got thousands of people globally working on those open models as well. So we have this capability. It is here amongst us. And the negative side of all the incredible coding and software productivity that unleashes is it also unleashes the ability for less sophisticated people to find weaknesses and vulnerabilities in code. So we're taking an attacker base that once was a couple thousand. You had to be very sophisticated to do some of these difficult attacks.
33:30And we're expanding it very quickly. Like some of the vulnerabilities that Mythos found had zero human assistance. And they were found in hours. It costs compute cycles. So there's a cost. Like you got to pay tokens for that. But the sophistication on the attacker side to do really interesting things, we're lowering that bar pretty quickly so that non-sophisticated attackers can look like very sophisticated attackers now, which we'll go back to my earlier statement of if that's the case, if most of the software ever written, we're going to be able to find vulnerabilities that no one's even thought of across that code.
34:15and we've liberalized who has access these engines just through the open source arena, then we have to have a remediative strategy. And I've tried to attack this every way I can for a year and a half on what are, you know, there's many. But I think the most powerful and immediately impactful is you've got to contain the blast radius. Like the more that you can put guardrails around every workload, every piece of software, so you can limit the progression of these attackers, then that's how you can make your environment the safest.
34:52Doug Merritt:So most organizations tend to approach cybersecurity through compliance and governance. What does that approach get right and where does it fall short? It is a really important element of cyber. You've got to be able to, one, humans are the greatest weakness, a lot of compliance and governance is, are you doing the right things within your team? So you reduce the incidences of bad code or attacks being successful within your world. Governance and compliance is different than the actual act itself, though. So I've been a big governance and compliance person through my career. Many of the software products that my teams have written or that we roll out are very strong on compliance and governance, because you have to be able to see the landscape.
35:40You've got to understand, you know, what is the equation of my landscape? Where does it rate on a scale of zero to 10 as far as healthy or not healthy? And am I getting healthier or am I getting less healthy? And all that is really, really important to give teams and boards of directors and CEOs and customers confidence that I should be doing business with this entity or not. But you don't get to be cyber resilient through compliance and governance alone. You could be compliant with every standard out there and still have a breach, have a pretty cataclysmic breach.
36:15Doug Merritt:And given that, how should boards think about cyber insurance, personal exposure, D &O considerations without becoming overly reactive? For most organizations, I think it's now mandatory, which has been a boon to the cyber insurance industry, that one, you've got cyber insurance and that you've got health ineffective D &O insurance. Given what we're seeing in the cyber landscape, I think that the cyber insurers really, really, really need to take a hard look at the products they're offering and how much exposure they actually have. Because the attack surface is growing both by the amount of code that's being added, but by the progression of the light of the LLMs and the amount of attack surface that's out there.
36:59And I would advocate super strongly to cyber insurance companies that they really start to understand containment as a philosophy and start to bake containment into part of the policies that they adopt. The number one thing that I advocate to boards and CEOs is I believe strongly that the chief information security officer should be elevated in the org, not because I serve that group, but because understanding, it's got to be the right CISO, it's called CISO, chief information security officer. You have to have the right to understand business and business risk and is able to translate the deep technical understanding they have into what does it mean for the company.
37:40Nothing is risk-free. But the closer that is to the CEO, I think the more impact they can have across the organization. And again, you can't be secure at the cost of business. You've got to drive your business, but you've got to have business that is secure as you drive it. and the D &O insurance has to extend to the CISO. The personal liability, some of these lawsuits have come out in the past four, five, six years that tags the CISO with both personal financial liability and personal criminal liability. I get the orientation around that. There's a healthy balance. They don't control everything, but they need to both have a feeling that their voice matters.
38:26There's obligation on them to be able to translate their voice into business terms, and they need to feel that they're protected as they're moving forward to try and protect the organization.
38:36Doug Merritt:At a high level, what are the main categories of cyber attacks today, and how should non-technical leaders think about them? Yes, another complexity in this landscape is there are a lot, there's so much technology, and there are many different avenues for attackers to utilize. The way that I think about it to advise cybersecurity teams and executives is, if you assume breach, then the most important element is, how do I stop a breach? And there are three, and it's called a runtime control in this weird tech speak, which is what can I invoke that actually kills the progression? And at the 10 ,000-foot level, our tech industry is really simple.
39:29You have actors. I would have said humans. But now you've got humans, agents. You've got entities that are consuming compute talking to entities consuming compute. So the three runtime controls, like every CISO that really wants to try and have a foundational level of cyber effectiveness are make sure you've got a strong and pervasive identity, both authorization but control capability. I've got to be everything that is acting has to have an identity and I have to have a way to kill that identity if I see something weird happening. That's one control. The second is everyone's not as pervasive of what's called endpoint, of an endpoint strategy as possible.
40:18Those are agents that sit around the compute. There are agents I can put onto my laptop or there are agents I can insert into what's called stateful workloads in a data center. Because if I see my iPhone, if someone sees my iPhone behaving weird, I can shut down my iPhone. The third that tends to be underplayed right now is network. Our entire world is connected and communicating. That's a critical runtime control. If I fail on the identity, someone is doing something aberrant that I have not caught, then my final element is cut off the channel, which goes back to that containment. Like if I can get into my entryway of my house, if I've got a way of keeping them in the entryway of my house, that's another runtime or remediative control.
41:08And I think going back to kind of first principles and foundational elements, like you have to have visibility, monitoring, controls, and confidence around those three core capabilities to then be able to build other elements of your cyber strategy.
41:26Doug Merritt:And for individuals, how should people think about identity theft differently than they do today? Hopefully. So one, be really thoughtful before you accept a network connection from anything. That is the number one path in or out to cause any type of harm. And people just blindly click it. I'm okay to accept this message or the network is actually pretty foundational to each of us as individuals. always have multi-factor. Everyone talks about complex passwords, but you have to have multiple different ways before, which is friction and a pain in the butt to try and protect the activities that you have.
42:13And everywhere that I possibly can, not every service allows this, but rather than use something like your cell phone as a multi-factor element, you try and use a third-party authenticator app. It is not that difficult for cyber criminals. All of our cell phones are on the dark web. All of our identity is on the dark web, sadly. And it is not as difficult as people think to spoof and pretend like you, like a third party, actually controls your cell. So when you get a text code sent over your cell, bad guy can intercept that, and it goes to them instead of you. So, you know, difficult passwords for sure.
42:57Get a password managers that can be as complex and crazy as possible. Use authenticator apps as your multi-factor wherever possible. Those are very difficult for bad guys to commandeer. And then just be aware of like, how many websites are you on? How many apps do you have? Do you actually need those apps? And it's very hard for most of us to see what are all those things linked to? going back to containment. But I think if you really treat your interactions with difficult passwords and true multi-factor, I think that we are in much better shape. Yeah. Don't go around opening all the doors and leaving them open.
43:33Doug Merritt:Yeah, exactly. So AI is empowering both attackers and defenders. Over the next few years, who do you think has the edge? Ultimately, I mean, the difficulty with defense is all you need is one failure for an attacker to be successful, where the attackers just need one opening. So there's an asymmetry between the attackers and the defenders. I think that defenders can be successful long-term as long as, one, we aggressively adopt AI on the offensive side or the defender side, I guess. But we really, really have to understand our landscapes and how do you put as many gates as possible in to make it much more difficult for the attackers to do their work.
44:29And I'm a broken record on this that I've said too many times in this podcast already, but I think the network is the most important channel that people have overlooked. And it is one of the strongest tools that people have to try and remediate and contain the bad activities that the attackers have.
44:50Doug Merritt:If listeners could make one or two practical changes this week, either as executives or individuals, if there's any practical changes they can make to meaningfully reduce cyber risk, what would it be? I will go with the executive, just to count the business people. I think that the questions that all executives need to be asking their cyber teams is, do you have a concrete list that you have high confidence in of one of all the workloads that you're trying to manage across our technology estate? and which workloads have internet access? And are you clear and are you confident in what internet access those workloads have?
45:45If you can just get a confidence meter on, I know all the workloads in my estate. I know exactly which ones have direct access or indirect access to the internet. And for every workload that is talking to the internet, I've got high degree of confidence on exactly what sites they're allowed to talk to. And I know those sites are verifiable, certifiable, and necessary sites. I think you're way ahead. The easiest way to be secure is nothing talks to the internet. That doesn't work. Like our system, our way of life does not work. So then the pivot is, does it need to talk to the internet? And do you have a whitelist of the few sites that it really, really needs that it can reliably communicate with?
46:39I'll give you all an example of an attack that happened about three weeks ago. So there's a really important middleware, AI middleware capability that put out by this vendor called LightLLM. It's kind of the connectivity layer between everyone in your company that is querying AI and the AI that it has accessed. A group called Team PCP found a way to insert malware within the public version of that middleware. What was the point of that malware? it took all the credentials that this middleware had, which were very, very valuable credentials, and it encrypted them, and it put them out over an internet channel.
47:24Very normal. I got a detection capability would not have seen that as weird. But the channel I went out to was a bad guy site. That middleware should only be able to communicate with a handful of certified critical sites that that needs to do its job. Most people did not have that internet filtering, that whitelisting, that way it's called egress controls in our industry in place. And so their credentials were exfiltrated to bad guys. Those attacks do not have to be successful. That is a very basic hygiene, not as difficult to do. And you have to think from the start when you're creating these things, like what could ever happen?
48:09but the appropriate posture for any workload is denial. Like it shouldn't communicate to anyone and then add the things it should communicate to one at a time and you'll largely be safe. I mean, if they don't ever rode in, they don't ever rode out, it's hard to do a lot of damage.
48:29Doug Merritt:Yeah, rather than having all the doors open, they're closed and somebody knocks and then you check to make sure you want to let them in, right? Right, right. I'd like to ask you a few questions about your leadership philosophy, which I found very insightful. I know you've distilled it down to five core principles. Would you walk us through those? Yes. And it's taken a long time. I had a really long list that I think I got down to seven at Splunk and I got them down to five at Aviatrix. And they're prioritized in order because it's the way that I tend to go through them. The first is relentless curiosity.
49:06If going back to the beginning of our conversation, if you are not just innately curious, and you can screen for that, for people you bring into your company, I think it's very difficult to have that learning culture I talked about. The second is lead with empathy. If you're curious, but you're not willing to kind of step back and listen, and really try and digest the curiosity, then you're kind of failed on the curiosity piece. And the third is purpose before action, right?
49:35Doug Merritt:If you've been very curious and you're leading with empathy and you're really trying to put yourself in the shoes of the people that you're acting with, then you've got to take a few moments to really understand what is it that I'm trying to get done? Like, what are the first principles in the thing that I'm trying to attack? You know, what is the scale of the thing? And the fourth is radical accountability. Now, if you get those first three and you're convicted you want to do something, then hold yourself and others accountable to make sure that you, you know, are marching forward with incremental progress every day towards that goal.
50:06The last is celebrate success. And I've said it over and over, that's more for me than everybody else. I am horrible at ever patting myself on the back or taking a moment and reflecting on anything positive I've done. I'm always on to the next thing. But I feel like that's fuel that's necessary to keep that flywheel going of you're making incremental progress.
50:30Doug Merritt:And every incremental win is something to be celebrated. Which of those principles do you think is least common among senior leaders today? My guess is there's probably more celebration than maybe you're personally used to, but I'm curious about the other four. What I have struggled with the most with people in teams is purpose before action. And I think, again, I think it goes back to all the conditioning we've had over the past 15 or 20 years. there's a premium on action and we're there's so much benefit that we get from from clicking and from doing it feels good and motion is really important in life like life is all about motion and purpose for action advocates stop for a second like before you just respond to something before you do the default really ask like five more questions on what is the driving force behind the thing that I'm advocating and go as far down the first principles as you can before you just jump in and take action.
51:41And I'll give an example that I'm concerned about right now. With Mythos coming out from Anthropic, the immediate recommendations and responses was the tried and true path that we've been on, which is use mythos to find as many vulnerabilities as you possibly can as quickly as you can and remediate those vulnerabilities as quickly as you can. And that's not a bad thing, but that shouldn't be the first thing to do. The first thing to do, if you think about the situation should be, let me analyze my containment architecture. Like how big is the blast radius on my estate right now? And assuming that someone gets in and then not gonna be able to find every vulnerability and close every vulnerability, there's physics involved in organizational dynamics and remediating a vulnerability.
52:32What else can I be doing? But like we've been taught for 15, 20 years, vulnerability detection, vulnerability remediation is the most important thing. And that's where everybody immediately gravitated to. It's like, slow down, slow down. And we've got new information. We've expanded the attack audience from thousands to millions. Like, really? Do you think you're going to outrun them? Do you think you're going to catch every vulnerability? Do you think you're going to be able to remediate in time before they exploit those vulnerabilities? Like, what else could you be doing? And that one seems to be something we've gravitated away from the past 10 to 15 years.
53:08Doug Merritt:Yeah, what you said there was, I think, really insightful. And one observation that I've had is there are certain leaders who have the unbelievable ability to zoom out and see the direction that everybody's working towards. Whereas most people tend to be zoomed in because they're busy doing whatever job they're tasked with. And you can feel like you're making a lot of progress because you're working hard. But if you were to zoom out, you may realize you're working hard, heading in the wrong direction. So you're actually not making progress. You may feel like you are when you're zoomed in, but if you zoom out, you realize you need to shift, you know, five degrees to the right, and now you're heading in the right direction and you'll actually realize progress.
53:50Doug Merritt:So I think having that purpose is another way of describing what I just said. Does that make sense? You said that in a far more engaging way than I did, Alex. Yes, 100%. That's why I was trying to kick. Yeah, I appreciate that. Well, one other aspect of this that I think is related to what you said earlier is, and I've heard you say this before, there's no failure, only learning. How do leaders create that mindset without lowering the bar? The two most controversial statements I have is that and release the objective, like the objective, stop focusing on the objective. And both of those are so counter to, again, the prevailing approach.
54:32I'll gate both of those. Like ultimately, do I have outcomes that I want? Do I have objectives I want? Yes. And if I don't achieve those objectives for long enough, should I be fired 100 %? It's like what it's a sequencing, like what do you put first? What's the most important element? And if you're over rotate on the outcome, I think you're going to be disappointed more often than not versus over rotated on the finding the right path. Now going back to your discussion and then understand, am I making incremental progress on that path? So the way that I try and drive that internally is if what you're doing is something that is super standard and we've done it a hundred times and you don't do it properly, that's a legitimate failure.
55:22Like you did something, you weren't paying attention, you were lazy, you were cutting corners. Like those are not failures I want. Where that, where I'm trying to apply, there is no failure. There's only learning is we're trying to build something that hasn't been built yet. And, and we don't know what the answer is. Like we all got, we've, hopefully we've studied it. We've done purpose for action and we're going hard in a direction, but we've got to be willing to pivot continuously because it's an experiment. And that is where, you know, there is no failure. Even my failures, if I'm really honest, though, like they were the best learnings.
55:58They were when I tried to accomplish something and I wound up not getting, not being successful. That benefited me way more than continuously doing something with success, which is the other element I'm trying to capture is if life is all about learning and growth, it's a full contact sport. Get in. You're going to fall on your face a ton of times. that's the glory of life. Like if you don't enjoy that, then again, you probably won't be super curious. Like there you're going back to the whole piece of, of, uh, it's just, it's life is fun. If, if you're super learning and growth oriented. Yeah.
56:40Doug Merritt:I think the way you describe that is to me is very clear. There are certain destinations that have been reached a million times and there's a clearly defined path to get there. You do A and then you do B and you do C. Whereas if you're trying to achieve a destination where there is no clearly defined path, I don't think it's correct to assume you know what that path is going to be. So recognize that you may be going down the wrong path and failure may be just realizing it's the wrong path. And then you learn from that and then you adjust and you keep adjusting and you're focused on what the destination is and recognize that you may take many detours to get there.
57:20Doug Merritt:And that may, and as you're learning the right path, and then now you've created that right path for others. And now you move on to the next thing. Yep. And the detours are part of it. They're part of it. That's,
57:34I personally, and I know so many CEOs that have tried to recreate something they have from scratch, because it's ugly. Like it's got tech debt and it's got so many things that you learn along the way. And I've never actually seen one of those go well because the, as ugly as the thing is, it's beautiful because of all the detours that are in the product. It's, if you do something fresh, do something new, right? Recreating the old thing in a more perfect state is a hard path for most people.
58:12Doug Merritt:Yeah, and it's probably less beneficial for society as a whole than discovering a new destination and finding a good path to get there. Yep. Well, Doug, this has been a fascinating conversation. It was a lot of fun for me and I hope our listeners enjoyed it as much as I did. Thank you for joining us. Thank you for having me on, Alex. I had a lot of fun too. I really appreciate the opportunity to talk. Thanks for listening. We hope you enjoyed this episode. Please visit our website at insightfulinvestor.org to access past shows and learn more about our podcast. If you have questions, feel free to email us at info at insightfulinvestor.org.
58:52Doug Merritt:And if you enjoyed the discussion, please subscribe to this podcast to ensure you don't miss future episodes. And don't forget to forward today's conversation to others you think would enjoy listening. Important information. This podcast is provided for informational purposes only and should not be considered legal, tax, investment, or business advice. It is not a solicitation, recommendation, or endorsement. All opinions expressed by participants are their own and do not necessarily reflect the views of the Evoque Advisors Division of MAI Capital Management, LLC, or Evoque, its affiliates, or any companies mentioned.
59:26Doug Merritt:Information shared has not been independently verified by MAI or its affiliates. MAI Capital Management LLC, or MAI, is registered with the U.S. Securities and Exchange Commission, SEC, which does not imply any particular level of skill or training. Certain information contained herein has been obtained from third-party sources, and such information has not been independently verified. No representation, warranty, or undertaking expressed or implied is given to the accuracy or completeness of such information by any person. While such resources are believed to be reliable, Evoke does not assume any responsibility for the accuracy or completeness of such information.
1:00:02Doug Merritt:Evoke does not undertake any obligation to update the information contained herein as of any future date. The content is intended for a general audience and does not constitute a recommendation to buy or sell securities or adopt any investment strategy. Any examples or scenarios discussed are illustrative only, involve risks and uncertainties, and do not guarantee future results. Non-traditional assets carry significant risks and may not be suitable for all investors. Decisions should be based on individual objectives, risk tolerance, and circumstances. Statements herein are general and may not reflect an individual's or entity's specific circumstances or applicable laws, which vary by jurisdiction.
1:00:41Doug Merritt:Further, speakers' views are personal and may differ from evoke and MAI recommendations and are not specific investment advice, and do not consider client objectives, risk tolerance, and diversification. Guests may have current or past relationships with Evoke and MAI, its affiliates, or the host, including as clients, service providers, or business partners. Participation does not constitute an endorsement or testimonial. No compensation has been paid or received for guest participation unless disclosed. MAI and its affiliates may have business relationships with entities mentioned in this podcast, which could create potential conflicts of interest.
1:01:15Doug Merritt:These relationships may include advisory services, investment management, or other arrangements. MAI seeks to manage such conflicts consistent with its fiduciary obligations and policies.
From the publisher
Doug is Chairman, CEO, and President of Aviatrix, which helps companies safely connect and manage their cloud systems, and former CEO of Splunk, which helps organizations understand what is happening across their technology and security environments. We discuss how AI is changing cybersecurity risk, why cyber is a leadership and business issue, and Doug’s leadership philosophy for navigating complexity and change.
-
This podcast/webcast is provided for informational purposes only and should not be considered legal, tax, investment, or business advice. It is not a solicitation, recommendation, or endorsement. All opinions expressed by participants are their own and do not necessarily reflect the views of the Evoke Advisors Division of MAI Capital Management, LLC ("Evoke”), its affiliates, or any companies mentioned. Information shared has not been independently verified by MAI or its affiliates. MAI Capital Management, LLC (“MAI”) is registered with the U.S. Securities and Exchange Commission ("SEC"), which does not imply any particular level of skill or training.
Certain information contained herein has been obtained from third party sources and such information has not been independently verified. No representation, warranty, or undertaking, expressed or implied, is given to the accuracy or completeness of such information by any person.
While such sources are believed to be reliable, Evoke does not assume any responsibility for the accuracy or completeness of such information. Evoke does not undertake any obligation to update the information contained herein as of any future date.
The content is intended for a general audience and does not constitute a recommendation to buy or sell securities or adopt any investment strategy. Any examples or scenarios discussed are illustrative only, involve risks and uncertainties, and do not guarantee future results. Non-traditional assets carry significant risks and may not be suitable for all investors. Decisions should be based on individual objectives, risk tolerance, and circumstances.
Statements herein are general and may not reflect an individual’s or entity’s specific circumstances or applicable laws, which vary by jurisdiction. Further, speakers’ views are personal and may differ from Evoke and MAI recommendations and are not specific investment advice; and do not consider client objectives, risk tolerance, and diversification. Guests may have current or past relationships with Evoke and MAI, its affiliates, or the host, including as clients, service providers, or business partners. Participation does not constitute an endorsement or testimonial. No compensation has been paid or received for guest participation unless disclosed. MAI and its affiliates may have business relationships with entities mentioned in this podcast, which could create potential conflicts of interest. These relationships may include advisory services, investment management, or other arrangements. MAI seeks to manage such conflicts consistent with its fiduciary obligations and policies.
(As of December 22, 2025)




