#81 Daniel Schiappa, Chief Product Officer at Arctic Wolf: Cybersecurity Unlocked

10 Oct 2023 · 46 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Tech Leaders Podcast Episode Summary: #81 Daniel Schiappa, Chief Product Officer at Arctic Wolf: Cybersecurity Unlocked

Episode Overview In this episode, Gareth interviews Daniel Schiappa, the Chief Product Officer at Arctic Wolf, focusing on the critical subject of cybersecurity in today's hyperconnected world. Daniel shares his insights on tech leadership, the current state of cybersecurity, the implications of AI on security practices, and his extensive career path through major tech companies.

Key Themes and Discussion Points

  1. The Importance of Cybersecurity
  2. Hyperconnectivity and Security: In today's digital landscape, cybersecurity remains paramount for protecting businesses from breaches and threats.
  3. AI Arms Race Warning: Daniel warns that the rise of AI has escalated into a "nuclear arms race," emphasizing the need for regulations and defenses against potential misuse.
  1. Daniel's Leadership Philosophy
  2. Humility in Leadership: Daniel believes effective leaders are humble, aware of their strengths and weaknesses, and focused on building a supportive team.
  3. Duality of Leadership: He uses the analogy of being both "Yoda" (mentor) and "Darth Vader" (enforcer), suggesting that leaders must adapt their approach based on circumstances.
  1. Career Milestones and Experiences
  2. Early Influences: Daniel’s fascination with technology began in high school, leading to a successful career in various roles at Oracle, Microsoft, and Sophos.
  3. Working with Bill Gates: He shares anecdotes about his experiences at Microsoft, particularly in leading security initiatives and collaborating with Gates.
  1. Current Role at Arctic Wolf
  2. Innovative Security Solutions: Arctic Wolf is focused on creating a security operations cloud that aggregates signals from various security products, aiming to reduce noise and improve threat detection.
  3. Concierge Security Team: The team provides personalized support to clients, significantly reducing alert noise and enhancing security posture.
  1. Cyber Threat Landscape
  2. State-Sponsored Cybercrime: Daniel highlights the increasing sophistication of ransomware and how it has become a business, enabling less skilled hackers.
  3. AI in Cyber Attacks: He discusses the potential for AI to empower attackers, leading to an exponential increase in threats.
  1. Future of Technology and Innovation
  2. Excitement for AI: Daniel sees both challenges and opportunities with AI in cybersecurity, emphasizing its role in continuous innovation.
  3. Quantum Computing: He predicts significant advancements in quantum computing within the next decade, which could revolutionize various sectors, including cybersecurity.
  1. Advice for Aspiring Tech Leaders
  2. Be Humble and Work Hard: Daniel stresses the importance of humility and diligence in achieving success in tech.
  3. Continuous Learning: He encourages young professionals to stay updated and engaged in their fields, especially in fast-evolving areas like cybersecurity.
  1. Recommended Reading
  2. "The Leadership Pill" by Ken Blanchard: Daniel recommends this book for its insights on leadership characteristics and development.

Conclusion This episode of the Tech Leaders Podcast features a wealth of insights from Daniel Schiappa, emphasizing the critical role of cybersecurity and the dynamic challenges technology leaders face today. His experiences and philosophies offer valuable lessons for current and aspiring leaders in the tech industry.

Listen to the Episode For more in-depth discussions and insights, listen to the full episode on [The Tech Leaders Podcast](https://www.bedigitaluk.com/).

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00To use the war analogy in the past, you know, they have tanks, we have tanks, they have planes, we have planes, and now it's a nuclear arms race race, right? It's the amount of catastrophic damage could be much higher when you have this type of power.

0:18We've been lucky enough to get some amazing guests on with cyber security expertise, thought leaders in the space. Quentin Taylor being the most recent example of that. Following the interview with Quentin, which was received really well, we had amazing feedback from that interview. I wanted to get somebody else on to talk about cyber, maybe from a slightly different angle. Arctic Wolf, one of the most progressive thought leaders in the cyberspace, we were lucky enough to get the chief product officer on. His name is Dan Sciapa. Dan, his credentials in this space are extremely impressive. He's worked for the likes of Oracle, Sophos, and notably Microsoft, when he first got into the space back when they were developing one of their original modern security products.

1:02Bill Gates was heavily involved in that project. It was fascinating to talk about that. They received a letter from the British government commending them on their work and just reiterating the importance of excellent cybersecurity. It was a very profound and proud moment for Dan and his team. So we talk about that. We talk about the other companies he's worked for, and discussing the ever-evolving landscape of cybersecurity, the latest trends. And notably, we talk about technology innovation and the impact it's going to have on cybersecurity. Things like blockchain technology, AI, of course, and quantum computing too, which I thought was fascinating.

1:38And Dan's take on quantum was very, very interesting. There was so much to cram in, but I really enjoyed the interview with Dan. Fantastic guy. I think you will too. It's Dan Schiappa.

1:56Dan, lovely to meet you. How are you today? I'm doing wonderful. Thanks for having me. Thank you so much for coming on. I've been really excited about this one. We've had a couple of guests on talking about the subject of cybersecurity. Let's start with this one. What does good leadership mean to you, Dan? Yeah, so I've had the luxury in my career to work for many great leaders and also work for a few bad ones. And so you get an opportunity to kind of really compare the two. And, you know, for me, kind of the style that I've adopted is I think first and foremost, a good leader is a humble leader.

2:29Somebody who understands where their strengths and weaknesses are and how they can build a team around their personal weaknesses. So you have a collection of leaders that work with you to help really build an outstanding team. So I grew up playing a lot of team sports, and I understand that you can't have a team full of goalies and expect to win a football match. So you got to really kind of have the right collection of talent to be able to do that. And so I think building that team is really important. I think leading by example is very important. And I'm a big fan of the structure of, you know, if there's any credit given, it goes to the team.

3:06If there's any blame, it comes to me. And that's kind of my job. And, you know, I look at my organization as I work for them, not they work for me. Like, what can I do to help make them more successful and, you know, remove barriers, provide clarity, whatever that is. And so a leader also makes the team around them feel that they can do more than maybe they actually can. You know, just really kind of build that confidence, build them up, educate them. I talk about with a lot of my young managers who I try and mentor on occasion that there's a time to be Yoda and there's a time to be Darth Vader.

3:44And the Yoda is the default, right? It's the coaching. It's the encouragement. It's the tough love. And there's sometimes in your career you do have to, you know, break out the red lightsaber, but that should be the rare occasion. And I think that's what people look for in leaders, someone who's going to inspire a coach, you know, help grow. And I've had the luxury of people doing that for me so much in my career that I think it's a great thing to pass on to others. Yeah, fantastic answer, by the way. And I love it how you switched into British mode there, talking about goalkeepers and football, not soccer.

4:16I was really impressed with that. So yeah, no, that's fantastic. Thank you so much. I think that I completely agree. There's so much logic in amongst that. So you're obviously in a leadership position now, Dan. I want to delve back into the archives. You obviously grew up in the New York area. You've worked for some of the most influential companies in the world. Can you maybe give the listeners a little bit of an overview of your career and crucially the key milestones which set you on the path that you ended up pursuing? Yeah, I think it probably started back when I was in high school. My father worked for IBM and we bought an IBM PC when they first came out.

4:53It dates me. This is back in the early 80s, right? But I just was enamored just immediately. It was magical to me that I could write code and it could do something. It was a combination of science and artistry. And it was just, I was hooked. And so throughout my career, I've always focused on computer science. So from high school, I went to university, studied computer science there. I took a weekend class, believe it or not, on Oracle when I was at the University of Central Florida in Orlando. And, you know, nobody had really heard of Oracle. And it was really a class about relational databases, but they were using Oracle technology.

5:35And so I thought that was pretty interesting. That was the first time I really did anything of that nature. And it was pretty exciting. And it just resonated with me mentally, kind of the relational aspect of data. And so when I graduated and moved on, I had jobs focused on Oracle databases and Oracle technology and building tools and interfaces and designing databases. And I eventually got the chance to work for Oracle. And it was it was a bunch of fun. We were focused on a category that preceded the Internet called interactive television. And it was extraordinarily innovative stuff. I mean, there's still things that we built in the early 90s that don't exist yet today.

6:13It was engineering candy land because as we went in there, there was set-top boxes with no operating systems. We had the right operating systems and publishing platforms and all sorts of stuff. So that was a lot of fun. I moved on from there. My first role in my career where it wasn't technical, I moved into more of a strategic business development type of role. And I had a ton of fun doing it. It was great. It was an opportunity for me to flex a business muscle in addition to my experience with flexing a technical muscle. startup was very successful. I think lasted, you know, three years and we sold it.

6:48And then I did my own startup. After that, I had a startup that a bunch of different divisions of Sony funded. I was a 27 year old CEO and started that company out. We had that for about four years. I sold that. And I look back now at that as who on earth would have given me, given me money. Like I was 27 years old. I mean, I was probably a relatively smart person, but I've never run a sales team before. I look back at some of the decisions I made and embarrassment, how naive I was in the day. But that's some of the ways you learn is by doing. And so I learned in some cases what worked well, but I think you often learn more from what doesn't work well.

7:33And so there's a bunch there. When I started the company, the dot-com craze was still going, and then the bubble burst in the middle. And my company wasn't a dot-com. It was more of a technology infrastructure company. But nonetheless, it impacted the entire investment community, and it was tough. And so you did have to learn to kind of eat what you killed. And there wasn't a lot of investment money falling from the sky anymore, and you had to make a living and make payroll off of the business itself. So that was a great learning experience. So after we sold that company, I went to work for Microsoft.

8:07And this was a great activity for me. My prior company was in digital media. And they initially recruited me to come run the Windows Media division. I just was not interested in doing digital media anymore after the scars and burn marks I had from doing it in the dot-com era. And so they routed me towards cybersecurity. And as an engineer, I thought, well, that's a really exciting place. And so I jumped in and spent eight years at Microsoft, most of that leading cybersecurity there in the Windows security division. I got back to my engineering roots. Towards the end, Microsoft liked to move their executives around and give you different experiences.

8:46So I spent almost two years as the head of corporate development and strategy for one of the, at the time, three P &Ls at Microsoft. It's called the Entertainment and Devices Group. I killed the Zune. So I think a lot of people should thank me for that, but really kind of focusing on that stuff. And that was a lot of fun, but I to get back to being an operator. So I jumped back into an operator role leading mobile applications and advertising group. But at the end of the day, I'm a cyber guy like that got in my bloodstream. And I really, really wanted to go back to cyber. The Windows security group that I led before didn't even exist anymore.

9:24They kind of naively thought they solved that problem. And so I left Microsoft. Yeah, right. That's funny. Windows security, I used to say was an oxymoron when I when I took on that team. But I went to RSA, you know, they're, you know, they're great kind of blue blood security company and spent three years there. And then I made the jump to go to Sophos. And I did this for a variety of reasons. One, just the breadth of the portfolio. Two, it was, you know, known as a very solid security company, but more so it was known as what I would call a spectacularly average security company. Like it was, it was good.

10:01It wasn't great. It was not innovative, but not behind. It was just like right comfortably in the middle. And for me, as somebody who likes to innovate, I thought, well, there's a great opportunity that I can get there and like unleash some innovation and help transform that company into something special. Then I had an opportunity to join Arctic Wolf. And I knew from my time at Sophos how Arctic Wolf was really taking the market by storm because of their unique approach. And so I had an opportunity to join, I would say, relatively early, 1 ,000-ish employees at the time, and help bring them to the next level of where they needed to be, both technically and from a product strategy perspective.

10:43I mean, who's going to turn down that opportunity to latch onto a rocket ship like Arctic Wolf? When I joined, actually, when I was interviewing with people, one of the things that I loved and admired is, you know, I grew up playing team sports all the way through university and the pack, we call it the pack. The atmosphere of the pack is real. The way people rally around each other, support, help each other, just the collegial way we go about things. We do challenge each other, obviously, but we're always there for each other in the end. And just the humility that the CEO and the leadership team has was really impressive.

11:18And it just really resonated with me. So I could be more excited to be here now. Wow. There's a lot to unpick there, Dan. You've had an amazing career quite clearly, but what's he like to work with Bill Gates? Bill's obviously a brilliant guy. He was in this role as chief architect at the time and security was one of his key projects. So I had a project that we launched called Project Zeno after Zeno's paradox, which states you cannot get to your final destination in one iteration. You can only get halfway. And of course, that paradox means you'll never get there. Right. And, and I named it that because Bill would always ask me, when am I going to have an impenetrable windows?

11:55And my answer was always never, you know, we'll always make it harder and harder and harder, but you know, in cybersecurity, nothing is impossible. And it used to frustrate him, but that was the reality. Is that because he was a perfectionist then? Yeah. He just, you know, he was such a purveyor of Microsoft property. He just, he hated that it could be besmirched by some hacker, you know, and, and Microsoft could be infiltrated and have things exfiltrated through their operating system. So it just really kind of ate at him. And that's a great quality to have, right? You don't sleep if you think there's a problem with your marquee product.

12:30And of course, Windows and Office were at that time, the two kind of franchises in the company. So I was able to put together a collection of the biggest security brains in all of Microsoft, including some legends, frankly, people like Butler Lamson, who was an MIT professor and a Microsoft researcher who literally wrote the book of cybersecurity. There's a book called The Orange Book that was written by a bunch of early computer scientists at Digital. And that's like literally the first Bible of cybersecurity. And Butler is one of those authors. And just a bunch of brilliant people. And we went around kind of predicting the future.

13:06So 10 years, which would have been circa 2015. So that tells you how old we are now, but what was the work going to look like in 10 years and how do we protect it? And it was a great project. And I think almost everything that came out of that project has since shipped in Windows. So I do still look at a lot of the progress that Windows made around security with some pride. And it was great. Bill was a strong critic. He was great to work with. What I learned to help get Bill engaged was to hand him the pen every once in a while, Like ask him to tell us what he thought. A lot of people would just present to him and treat him like he was a movie critic.

13:43Like, here's my movie. What do you think? I wanted to treat him like a movie producer and get him involved. And he did. And I think, you know, we formed a good relationship as a result of that. Yeah, for sure. So looking back now, what's the biggest sort of engineering challenge you overcome? What are you most proud of in all this innovation you've been involved with? What's from an engineering standpoint? What's your highlight, Dan? Wow. It's hard to pick just one. It really is. I'll kind of do a top five maybe. I would say, you know, doing the interactive television stuff at Oracle was mind-blowing for me because, you know, Larry Ellison sold this vision to a bunch of telecos and we had no technology.

14:23And so I was like, okay, guys, now you got to go build this like really otherly world thing I pitched to everybody. It was amazing. Like we built operating systems, we built publishing platforms, we built application layers, we built video pumps, we it was, it was a it was a ton of fun. And we did stuff, as I mentioned that, you know, even by today's standards, I don't see people doing it. I think at Microsoft, obviously, working on helping to improve the security of Windows was a challenge. It was a kernel that was developed before the internet existed. And now, you know, the attack factors were so different and building out, you know, and improving the protections for what was really the flagship of what everybody in the world used.

15:06You know, I got a letter from the UK government, actually, that said Western civilization depends on your team. And I thought, oh, boy, what a bunch of kooks. And I thought, wait a second, the right, right. Hospitals, universities, militaries, financial companies, you know, trading companies, like everybody used Windows. And if we did not protect it, it would it would be problematic. And then, you know, at Sophos, it was great to build a brand new endpoint with super modern technology, leveraging AI very early. I built a new firewall operating system there. And then at Arctic Wolf, you know, we just innovate like constantly.

15:39It's just a big aspect of what we're doing. To operate at the scale we operate is really, really hard. There's not many companies. There's probably two or three in the world that operate at the scale we operate. And so continuing to do innovation there. I want to maybe ask you about that then because I want to move on to sort of the stuff you're doing now. Talk us through Arctic Wolf. Where did that opportunity come from? What's the purpose of your role? What are you trying to achieve? What problem are you trying to solve, Dan? Yeah, so it's a great question. So if you think about security, it's been primarily focused on single points of observation.

16:14So I either have endpoint security or I have email security or I have network security. And so big ecosystems were built around each of those. And they've advanced. So, you know, you went into Palo Alto, came up with the next generation firewall and Carbon Black and CrowdStrike really pioneered the endpoint detect and respond business. And so each one of them had their own wave of innovation. The one product that was supposed to be the panacea of the security operations center was the SIM, the Security Incident Event Management. And it was supposed to correlate all your logs and be able to tell you if something's going wrong in your system.

16:52And the way I describe it is a lot of people say security is like looking for a needle in a haystack. No, it's not. Finding a needle in a haystack is easy. I can write an ML algorithm to look at the needle, look at the hay, and separate them. Right. It's security is really about finding a needle in a pile of needles, which needle in this pile really matters. And that's where SIMS didn't do a good job. Like they were constantly under attack or they were missing everything. It was like one or the other. There was no kind of common ground. So it was either incredibly noisy or it wasn't noisy enough.

17:23Arctic Wolf decided, hey, we got to we got to fix that problem. And so they fix it in a variety of ways. And that mission from day one carries on to today, which is we're going to build a security platform, a security operations cloud, we call it. We are going to collect signal from whatever the customers have. We're not going to go in and say, you must use our product, our technology. We collect that signal in through a massive, massive platform. So we do about four and a half trillion security observations a week, well over 600 billion every single day. And we have to take that signal and we have to reduce that signal and eliminate the noise.

18:01Then once we eliminate the noise, we have to look across that ecosystem and find things that other people can't find. And then we have to deliver that experience back to customers who range from, I don't know anything about security, just help me, to I'm super sophisticated, I just don't have the scale, help me. We have to handle that whole spectrum of customers. And so we have something we call our concierge security team. And they interface directly with our customer. They help them on board through what we call a security journey. They're understanding the environments of their customers. They're helping set up good security posture from the get go.

18:35And then when we do discover something and it's, it's, it's, you know, it's not super common. So to be honest with you, if you look at a SIM, according to a Forrester report recently, get about 11 ,000 alerts a week on average through a SIM. Our customers get 10. So we're really reducing it down to the things that matter. So, you know, between one and two a day and our concierge will come out as a ticket and technology will be reported to the customer. But our concierge will also be there like, here's what we recommend. Here's how we can help. Here's what you should do. And so they're there to help those customers who need that help through it.

19:07And then technology helps the customers that that don't necessarily need that human being. And so we have the ability to take a very sophisticated, one of the largest security operations in the world and bring it to very small customers who don't understand security to very large customers who just don't want to have a SOC or don't have the bandwidth of security talent to operate their SOC. I know you guys host the Cybersecurity Awareness Summit. What can attendees expect to gain from that event then? And what else do you do on the education piece? Yeah, there's multiple different steps to it.

19:40Like the first one is making sure that your training is relevant and time sensitive. So what that means is like, for example, just a week ago, there was these big attacks on two casinos in Las Vegas, MGM and Caesars, where they actually ransomed some of the operating aspects of the casino. And, you know, if you think about it, it's like an Ocean's 14 movie, right? Where the hackers want to go. When was that? When was that done? That was just a week or so ago. And within two days, we had training out about that and the techniques they used to circumvent the human aspect of it. And so you have to have timely training that's really on top of what's happening in real time in the security landscape.

20:23The other piece that we do is we make it short, educational, and entertaining. Nobody wants to drone through a 30-minute security training session when they got work to do. So we really focus on real quick entertaining. You know, we have, you know, Hollywood quality productions, you know, many of the people work for many of the famous Hollywood studios produce our work. So it's really high quality. And it's, it's, it's very educational. And some, some of them finish with a quiz that helps the companies audit, you know, how successful that campaign was, and some are just informational. That's it.

20:55It's timely, you know, it's got to be relevant, it's got to be short, and it's got to be entertaining. Yeah, yeah, sure. Are you seeing anything on a global level that you're quite concerned about now? This is going to be really difficult to defend against. What keeps you up at night? I think what keeps me up at night is the state sponsor people enabling the people who are hacking in their bedroom. That's what keeps me up at night, right? And so what we're seeing today is ransomware is still the king of the hacking world because it's become a business, right? It used to be, you know, back when I took on Windows security, it was, you know, the Melissa Sasser blaster worms that someone created just to be disruptive, right?

21:34And now you've got multi-billion dollar businesses that are run like businesses that are around commercial hacking. And what worries me is we've already seen things like malware as a service and ransomware as a service where you have hackers basically building technology platforms for other hackers to take that technology and go perpetrate attacks. So they pay a license fee to these platforms and then they go perpetrate the attacks. And so you're enabling less sophisticated people to go be malicious actors. That's just going to really expand further when you bring AI into it. Right now, you know, the attackers are starting to use AI aggressively, gen AI aggressively to attack.

22:16And it's not just computers. It's over the phone. It's through video. Like there's been some, you read about some of these amazing vishing attacks where it's either, you know, coming over voice on your phone. We see attacks on text. We see attacks on Slack and Teams and communication like that. And so the thing that worries me about AI is you can create now a, you know, back in the day, you had to have some command and control. I get a footprint inside an organization. I create a communication path to my kind of hacking center. and then I can bring other payloads down. I can exfiltrate things.

22:53I could have a human being help me recon and traverse across the network. I'll be able to do that with AI and not need command and control, not need another human being. I could launch the AI and all of a sudden, money is where I need it to be. That's pretty terrifying. And not terrifying from a defense perspective. I think we've always, as an industry, successfully kind of kept pace to some degree with the attackers, that they can enable an army of people who don't have technical expertise to go be bad actors. That's the part that frightens me. So the scale of defending against attackers, just the multitude of people who can do it, it's going to go up exponentially.

23:34That's the part that worries me. Yeah, I suppose. I mean, if AI can be used by the belligerents, it can also be used by the sort of defenders as well, can't it? So I think it's going to become an arms race essentially eventually, isn't it? I mean. It is. And my kind of analogy is it's always been an arms race. I think, you know, we were using conventional arms to use the war analogy in the past. You know, they have tanks, we have tanks, they have planes, we have planes. And now it's a nuclear arms race, right? It's the amount of catastrophic damage could be much higher when you have this type of power.

Read the full transcript

24:07And in this industry, we've been using AI for a long time. AI is not new to cyber. It's been a key, key part of how we defend for a long time. I think what's happening now is the processing power has caught up with the potential of AI. And so it can be used more broadly in attacks. And that's the scary part. Yeah, sure. What are you most optimistic about, Dan, in terms of technology innovation? Is there anything that you're working on from a product standpoint or anything you're seeing in the market in terms of more general innovation right now? Yeah, I do think AI is going to be a big driver for innovation.

24:45As I mentioned, we've in this industry been using it. We at Arctic Wolf have been using it for a long time. But it is, you know, it's picking up pace because the processing power is keeping up. So we're able to do some, you know, really exciting things with AI that probably maybe weren't possible five years or so ago. Plus just the multitude of people now who are experts in AI, you know, a number of data scientists out continues to grow. Universities are pumping out PhDs with data science backgrounds now where that was, you uncommon. So I feel good that that's going to be one of the key generators for our industry.

25:21At Arctic Wolf, what we're really focused on is continuing that mission of finding things that others can't find because of the breadth and depth of signal that we have. Getting signal from 15, 20 different data sources in an organization, really granular information, then building AI models on top of it. And then from a business perspective, the important aspect is to be able to do it cost effectively. And so, you know, for us, you know, we want to continue to operate a business that's heading towards profitability, that has great margins, that still has that security operator in mind. Like we don't think you're going to be able to fully automate the SOC.

26:00I think there's a lot of value to having human intelligence along with artificial intelligence. But for us is how do we make it as efficient as possible so those humans are focusing on the things that really only humans can do and they're not toiling around doing things that a machine can do. And so it's a combination of all those things that I'm going to think are going to be pretty innovative for us. Yeah, sure. What sort of general advice do you give to business owners, business leaders who want to protect their company from or protect their customers' data, their own data from cybersecurity threats?

26:31Yeah, I think the biggest advice would be don't assume that you're not a target. I think a lot of companies, particularly smaller companies will go, why would anybody want to hack me? Well, you know, you may be the lowest hanging fruit in a supply chain attack. You may be a company that while you don't think is important, could be ransomed at a decent amount of money. So I think that is an important aspect. And what's also important is to recognize that you may not have the security expertise necessary to protect yourself in this environment. And that means, you know, making sure you have the right tooling, making sure you have the right eyes on your environment.

27:09As I mentioned before, I don't think there's a world where a human being doesn't add security value to your security operations. So making sure that you have that. And a lot of companies can't afford to build security operation centers. They can't afford to hire top tier security operators. And so companies like Arctic Wolf, and I think kind of the whole MDR industry is growing because of that need. And so my recommendation is understand what you're good at, what your core business is, and make sure that you're leveraging the right tooling and expertise to provide the security coverage when that's not your core competence.

27:46Let's talk about product development then. So obviously, you're the chief product officer. How do you go about creating, researching, and then creating new products? Do you have a methodology that you follow? How does that process work for Arctic Wolf? Yeah. So I know there's a A lot of teams, a lot of companies that have innovation teams or a separate group that's off experimenting and trying new things. My perspective there is the entire organization's an innovation team. We really need to innovate. And so one of the things I ask my teams to do is we do planning for what we're going to deliver.

28:22So I have something I call the feature pyramid. And if you could envision in your mind a pyramid that's broken into three pieces, the bottom of that pyramid is what I call foundation. These are all the basic things you need to build into a product that drives a high quality product. And it's also kind of the basic features to be competitive in the market. Quality and security is incredibly important because if you fail, you either fail open and the bad guys get in or you fail close and it impacts business operations. And so security really has to operate almost like utility quality. It just has to be there.

28:56So foundation is very, very important. That's why it's the biggest part of the pyramid. The middle part of the pyramid is what I call differentiation. And this is where we do something different. Someone may do something similar or we do it better, cheaper, faster. We do it different. And it's innovative. It's driving maybe an advantage where we can operate at scale at better cost structures and others, which means we can invest more in creating better security outcomes for our customers. And that's the middle of the pyramid. So that's the next biggest piece. And the top of the pyramid is what I call a game changer.

29:28This is something that Arctic Wolf would do that nobody else in the industry would do. People would look at us and go, oh my God, I don't do that. And so I make my teams kind of really focus on filling out that pyramid as we go through our planning exercise, because you don't want to be a company that's focused so much on the bottom of the pyramid that you're not innovating, you're not pushing innovation forward, because you have to innovate in security, because I'm just not out competing with other security companies. I'm competing with adversaries and professional hackers. That's who I'm competing with, and they're very innovative.

29:58Now, at the same time, you don't want to be so focused on innovation that you're not doing the basics right. You're not building quality products, reporting, auditing, the core features. You're just focused on the shiny object. There's a lot of security companies, particularly startups, that do that. They focus on the shiny object, and as a result, they can't scale. They can't serve an enterprise customer. And you really have to kind of balance those things out. Just out of curiosity, Dan, you know, obviously you've worked for some of the world's most influential companies in the technology space.

30:29I'm talking about Microsoft, obviously, Sophos being another one. Is there anything you took from those companies, lessons you learned in those companies that you've actually implemented in Arctic Wolf since you've been there? Whether it's from a cultural standpoint, technology engineering standpoint, is there anything you've transferred over to your new role? Yeah, I think there's quite a bit. I think we talked in the beginning about leadership. I think that's probably the most important thing I bring over. I think every company is a little bit different. Every company I've been to, I bring some commonalities, but I always have to adapt it to the culture of the company, to the skill sets of the company.

31:05One of the things that I always brought forth is a little more of a planful environment. I think a lot of people think agile development means you don't know what you're doing next. You're just focused on rapid innovation and we'll get to what's next when we get there. And security and an IT in particular, that's a hard path to follow. If I'm a consumer web-facing service maybe, but when I have IT staffs that need to deploy stuff and know when something's coming, a certain integration or whatever, you have to be a little more planful. So I have brought a planning process with me that still allows for agile development, agile execution, but a little more planful.

31:46So we know what's coming over the next 12 months. We know what the priorities are. We know what the human capital cost of delivering that is. And as priorities change, which they always do, that's the agile part, you can adapt. But you know if something new is coming in and it costs a certain amount of human capital, something's got to go out because you're not minting human capital unless you're adding more and more employees. And so it just it's a great structure to help us move fast, but also be planful and predictive about what we're delivering. What do you think about blockchain technology to enhance supply chain security?

32:19This is something I kind of wanted to ask you just to get your thoughts on it. I mean, it's something I've read quite a lot about recently using distributed computer systems to protect supply chain data. Yeah, so I think blockchain is something that when it first obviously came through cryptocurrency into the mainstream, people fantasized quite a bit about the impact it could have on security in a broad way. I don't think it quite lived up to that just yet. I think it's still, it hasn't lived up to the hype. On the hype cycle, it's still climbing. What it has brought is there is a large focus on distributed computing.

32:58That's a combination of mesh computing from a processing perspective. It's a combination of data mesh where my data is in different locations. So I do think those areas are definitely advancing. I do think as processing power continues to advance, things like blockchain can finally meet its potential. We know that crypto mining is just gutting the CPU processors to operate the GPUs as well. And so we're not quite there yet where we have broad scale computing to possibly reach its full potential. But we're not far away. You think about science fiction-y things that are around the corner. Quantum computing is around the corner.

33:37It will happen in my work lifetime, not just in my lifetime. And that's going to be a total game changer. That's, again, why I think AI is where it's at today. It's the GPU revolution. It's companies like NVIDIA and others who build GPUs now used at mass scale. And it's just brought AI to a different level. Quantum computing will just be a force multiplier for many things. And I do think that's on the horizon. I mean, we know it already exists today, but at the speed that things go from laboratory to production, I would expect to see that sometime in the next 10 years. So that will be a game changer.

34:13And that could make blockchain a lot more relevant. Tell us what you know about quantum computing, Dan. Sounds like you're quite well-versed on this topic. So you think quantum computing being rolled out on a global sort of level, we're 10 years away from that then? Yeah, I think it'll start with the infrastructure providers who can run quantum workloads in the cloud. It'll start small where people will be able to use it for certain activities and certain workloads. And I think it is everything in computing as it becomes cost efficient, it'll just expand further. But, you know, quantum computing in a nutshell is, you know, computing is still driven by binary, right?

34:54It's ones and zeros. And quantum computing throws that on its ear. And it's not just ones and zeros anymore. It's many factors. And so the ability to jam processing power into small footprints from a CPU perspective go up exponentially. And the ability to drive instructions through that is going to be a game changer. So it's going to be the biggest step function change to Moore's law that we've ever seen. We've talked how Moore's law has kind of not been fulfilled recently as technology gets harder and harder to make smaller and smaller fabs on the microchips. Quantum is going to throw that on its ear.

35:30And so a lot of companies are doing some great experimentation with it. And we definitely know there's quantum computers that exist in laboratories today. And yeah, I think it's a matter of time before we see, you know, all the major infrastructure providers have some capability of offering quantum based workloads. Yeah, sure. So can you tell me, Dan, why is cybersecurity a good career path for a young person in 2023? For one, it's it's it's job security because you can't solve the problem. So back back to the story where I got that letter from the UK government saying Western civilization depended on my team.

36:07I actually realized they were right. And if my team, the Windows security team, all just walked out of Microsoft, the world would fall into chaos. And I joke, no offense to anyone who worked on the office team or still works in the office team, but if the Microsoft office team walked out of the building, people would be like, okay, you're not going to cram 10 more features in Word that I don't use. Yeah, I know Office has been a great place for innovation, so I don't mean to knock it. But cybersecurity is necessary. It's a necessary innovation. It's not optional for companies to focus on that.

36:46And so as an engineer, as a technical person, you always have to be up on the latest technology. You're never done. You can never go, oh, problem solved. I'm out. And that's really exciting. And, you know, as a competitive person, too, you have an adversary. And my adversary isn't, can I have a better office solution than somebody else? My adversary is somebody who's actually trying to violate what I am building. That has just a different level of excitement from an engineer's perspective and a different level of competitive nature. So to me, it is the most exciting part of technology simply because we are going to leverage all these AI and quantum and, you know, you name it.

37:27Like whatever cool innovations going on around us, we're going to leverage it. And also our customers are. So you have to learn how to protect it. So it's just it's one of those things. I remember as a kid, I had, you know, friends. His father was a doctor. I thought, man, you know, they got to just constantly, continuously educate themselves. Like, you know, you can't ever be behind the times in medical. And I was like, you know, that stinks. Like, I was glad to be done with school when I was done. But no, cyber, you're never done. You're always educating yourself. Absolutely. It's even worse.

37:57The innovation's even quicker, isn't it? Exactly. And so that's kind of like a drug it's hard to get off of once you get on it. And, you know, once I think you get into cyber, you just you can't find the same excitement anywhere else. Yeah, absolutely. Good answer. What are you most excited about from a technology standpoint? What technology innovation are you most excited about outside of the world of cyber? I do think it's AI. I'm both excited and terrified by it. I think, again, in cyber, we've been using it for a long time, so it's nothing new. But when you see things like generative AI and chat GPT and Dolly and things like falling into the hands of the everyday people, they finally go, oh, my God, this is crazy.

38:37crazy. And then you see, you know, strikes in Hollywood over it because they're worried it's going to come take their job. Right. And so it's going to be one of those human transformative technologies that as we continue to gain expertise in it, we gain more and more processing power. It is going to be, it's like the industrial revolution all over again. It's going to have that much of an impact on us. I completely agree. Yeah. Industrial revolution, microwave oven, internet, AI, those are like four things that, you know, drastically changed the world. And, and I think we don't even know, I mean, you see, you know, the Stephen Hawking's and Bill Gates, even like, you know, Skynet's coming, you know, machines are going to take over the earth.

39:20Like, well, well, a lot of people can roll their eyes at that. We don't know, like, you know, I mean, it's, it's, it's, it's quite possible. So at the same time is it's going to be very exciting to see how it can positively transform the world. It's certainly going to negatively transform the world as well. So that is something that both excites and terrifies me. Yeah. But look, looking back on your career now, Dan, we need to cast your mind back to that guy who left university pre-Oracle days, maybe 21 year old self. What advice would you give to that guy knowing what you know now? Wow. So I had people gave me good advice that I think I listened to back then.

40:01I would just say something I learned too late in my career is be humble. Just be humble. I think in my early career, I was a very arrogant, frankly, engineer. I was talented and I just thought I could do anything I was asked of. And I was a little arrogant. It wasn't until I was running a company and I ran into bad things. I ran into a tough economy, uh, no more investor money. You know, I had to lay people off and I had to lay off my mother-in-law and I love my mother-in-law. It was, it was, it was, and it wasn't really until then that I learned humility to be frank. And I would have, I think I would have been even, I think I would have been better prepared for that scenario if I would have started off with humility.

40:49Uh, and then the other advice I give everybody that I, someone did give me and I, I, I did live this is you cannot control if somebody is more talented than you, but you can control if you will outwork them, right? So you can control how hard you work. And I think in a world like cyber, where you're constantly learning and like that, that matters. And I do think that's the world's changed a little bit in that regard. I think as a society, we're a little more focused on, you know, how, you know, what, what, when the next holiday is, or, you know, what I'm going to do on the weekend. We've lost a little bit of that hard edge of just working really, really hard.

41:27It doesn't mean you have to work 70 hours a week. That's not what it means. It just means you got to put your nose to the grindstone. You got to do that extra research to educate yourself on what's changing in your job. I did do that throughout my career. I think that's helped me become who I am today. Yeah, sure. Great answer. Final question then, what book or story or anecdote or documentary have you seen recently, which inspired you? That's a great, great question. So it's not as recent a book, but there's a book called The Leadership Pill. It's a small book, Ken Blanchard wrote. I'm not ahead of that one.

42:06Very famous. Yeah, very famous kind of business author. He likes to tell his stories, his business lessons in the form of a story. And this story is about two employees who are moving into managerial roles and one was given the leadership pill and one wasn't. And, and, and basically it's a story about our leaders born or are they made? And it was a, it was a great book and you can read it probably in an hour. It's very thin, but I, I, many places handed that book out to every one of my, my leaders, because I think it, it really kind of tells a story of what it means to be a leader, how you can become a leader, even if you don't have that natural instinct in you.

42:47And it's one of the books when I read it, it just felt like a light bulb went off over the top of me. And it was really enlightening. It was probably the only book I've ever read in my life that changed my life. Oh, wow. That's strong words. So that's The Leadership Pill by Ken Blanchard. Yeah, we will put that on the show notes. Dan, thank you so much. This has been great. I really enjoyed chatting to you. I feel like I could talk to you for a lot longer, but we've covered a lot of ground. So I think it's a great place to finish. So thank you so much for coming on the Tech Leaders Podcast. Where can people find you, reach out to you and find out about Arctic Wolf?

43:23So you can find out about Arctic Wolf at arcticwolf.com. I think that tells the whole story there. You can find me somewhere buried in the company leadership area. You can find me on LinkedIn and Twitter. Just search Dan Sciapa. I'm there. And I do spend quite a bit of time sharing information and my thoughts and everything on both those platforms. Thank you so much, Dan. Thank you for having me. It's been fun.

43:53Brilliant interview, Dan. Wow, so knowledgeable. A fountain of knowledge, actually, when it comes to cyber. It was brilliant to talk about his perception, his take on the evolution of the space. Some of the stuff they were doing in the early days with Microsoft was obviously very interesting and working with Bill Gates and stuff. Fascinating insights there. I really want to draw attention to Dan's take on leadership. I want to quote him directly, actually. I work for them. They don't work for me. That was brilliant. I think that literally sums up my view on leadership. Actually, I really empathized and related to that.

44:26You've got to see it as, you know, if it's to be any sort of level of leader, you really have to see yourself as having an obligation to the people you're leading. I thought that was really good. But the thing that really stood out for me was Dan's take on creating his own startup and the journey he went on there. He made a really salient point about that. He had to lay off his own mothering law, for goodness sake. That must have been awful. But he basically said, the point was, he said he was very arrogant going into that experience, but he went through this cathartic lesson, this process of having his backside handed to him by the marketplace.

45:03And it was at that point he became a better operator. He learned a lesson which benefited him for the rest of his career and I thought that was really interesting which I certainly felt was quite profound. Please download the Tech Leaders podcast.

45:22If you found this episode valuable and thought-provoking we would really appreciate it if you could quite simply click the subscribe button and possibly even leave a review. This helps us to spread the word and reach a wider audience so that we can make a bigger impact and bring you the best guest possible. Thank you so much for downloading.

From the publisher

In this digital age of hyperconnectivity, ensuring your business is cyber-secure is crucial. That’s where this week’s guest comes in. Daniel Schiappa, Chief Product Officer at Arctic Wolf, joins Gareth to discuss his top tips for tech leadership and what’s happening right now in the cybersecurity space.  

Warning that the AI arms race has turned into a nuclear arms race, Daniel gives advice on what we all should be concerned about regarding AI regulations and how smaller companies can defend themselves against security breaches. 

Daniel has experience working in some of the largest tech companies across the globe, including Oracle, Microsoft, and Sophos before ultimately joining the team at Arctic Wolf. With a passion for cybersecurity guiding his journey to CPO, Daniel tells us of his highlights; from working with tech geniuses like Bill Gates, to receiving a life-changing letter from the UK government stating that the western civilisation is dependent on the work of himself and his team. 

Daniel is an influential tech leader with an unusual leadership mantra originating from a galaxy far, far away. He believes that ‘“there’s a time to be Yoda and there’s a time to be Darth Vader”’, and this duality of encouragement and ruthless determination is what keeps him and his leadership team ahead of the game. 


  • What does good leadership mean to Daniel? (02:12) 
  • Daniel’s key career milestones (04:33) 
  • Working with Bill Gates (11:28) 
  • The greatest engineering highlight of his career (14:00) 
  • Daniel’s role at Arctic Wolf (16:00) 
  • The cyberthreats that keep Daniel up at night (21:10) 
  • How to avoid cyberthreats as a smaller company (26:21) 
  • What is quantum computing? (34:16) 
  • Why cybersecurity is the perfect career path in 2023 (35:50) 
  • Daniel’s advice to his 21-year-old self (39:50)

 *Book recommendation – The Leadership Pill: The Missing Ingredient in Motivating People Today, Ken Blanchard The Leadership Pill: The Missing Ingredient in Motivating People Today eBook : Blanchard, Kenneth, Muchnick, Marc: Amazon.co.uk: Books 

https://www.bedigitaluk.com/

More from The Tech Leaders Podcast

All 66 episodes
#81 Daniel Schiappa, Chief Product Officer at Arctic Wolf: Cybersecurity Unlocked The Tech Leaders Podcast · 46 min
Listen in VO