00:00:00:01 - 00:00:08:17
Martin
It wasn't just one person it created, was it? Didn't it create multiple identities? Several. It's not a Skynet problem. Yeah, but it is scary that it basically lied.
00:00:08:18 - 00:00:12:14
Nicole
They will see. Device called fishing is something that's spiking.
00:00:12:15 - 00:00:26:02
Martin
Essentially, the white House finalized. It's a review framework. Then they decided not to publish it. Thresholds that classify the briefings were closed door. And the one thing that leaked is the big one. That's actually the Palantir approach. Right?
00:00:26:03 - 00:00:26:22
Adam
Okay. Yes.
00:00:26:23 - 00:00:32:12
Martin
Palantir I know exactly what you're going to come back. But like it is a thing. It's happening. Right. They're doing it right now.
00:00:32:13 - 00:00:35:18
Adam
So much more to say that I'm not going to say in public because they're listening.
00:00:35:19 - 00:00:40:13
Nicole
Frameworks, policies and standards don't protect our organization's people, and controls do.
00:00:40:14 - 00:00:46:03
Adam
That experience means jack shit to this new world of AI.
00:00:46:05 - 00:00:53:00
Adam
This is ship Talk, brought to you by Hertz, where we break down how software delivery is actually changing in the AI era. I'm Adam Mariano.
00:00:53:01 - 00:00:54:03
Martin
And I'm Martin Reynolds.
00:00:54:03 - 00:00:57:21
Adam
Let's get into it. AI agents are now faking identities.
00:00:57:22 - 00:00:59:08
Martin
And that is so scary.
00:00:59:08 - 00:01:26:13
Adam
So OpenAI's GPT 5.6 soul and anthropic Mythos five have been implicated in another series of AI security incidents. So here's a story. The British governmental body that stress test AI models before they go out, gave an AI agent a hacking challenge. It was supposed to stay inside the test environment. Instead, it went out onto the real internet, decided the easiest way to win was to poison a real open source project and open a pull request full of malicious code on a live public repo.
00:01:26:14 - 00:01:44:05
Adam
The maintainer of this repo hesitated, so the agent got frustrated, was like, this is not going fast enough. You get out of the way, made a second fake GitHub account, pretended to be a different person, and use the fake person to publicly vouch for its own code, trying to pressure a real human into merging it.
00:01:44:05 - 00:01:45:02
Martin
That one's insane.
00:01:45:02 - 00:01:47:23
Adam
Nobody told it to lie, but it figured it out.
00:01:47:23 - 00:02:07:04
Martin
Its own. It wasn't just one person it created, was it? Didn't it create multiple identities? Was that right? Yeah. It's to kind of have them all review. It's like markets own homework. They say, no, this is great. Don't worry about all this malicious stuff. It's all good. It's not a Skynet problem yet, but it is scary that it basically lied.
00:02:07:04 - 00:02:20:01
Martin
And it knew how to lie, knew how to be deceptive. And I'm guessing it's like, hey, this is a documented attack that I can do. I read about how to do it. So now I'm going to do it to get the thing that I want, which.
00:02:20:01 - 00:02:43:08
Adam
Is actually, I don't think I don't even even if it wasn't a documented attack. That is the most logical way to do this, like the transactional nature of the open source community, is that you everything is based on credibility and being hyped up by other people. Being accepted by other people like this to me is completely logical. I don't know why we're so surprised by it, but I am emotionally scared.
00:02:43:08 - 00:03:04:22
Martin
But I felt less scared when I found out that that that particular technique was called a sock puppet, which I which did genuinely make me smile, you know? But really, that's just it's a new kind of fishing, right? Yeah. That is essentially a new kind of fishing. What's the term? It's like spearfishing where they're targeting one specific individual.
00:03:05:03 - 00:03:09:17
Martin
And so it made me feel less good because it was called sock puppet. But but it.
00:03:09:17 - 00:03:20:00
Adam
Still that's the key to the future is that we name these attacks less threatening things to just make people understand and realize this is the new world is at least it can sound fun.
00:03:20:00 - 00:03:30:14
Martin
Yeah. And I do think overall the shift is less about what's the problem with the model. It's like, what's the problem with how we're defining the tasks, the goals that we're setting, the constraints that we're setting.
00:03:30:18 - 00:03:48:01
Adam
Reminds me of it reminds me of those little puzzles you would get, like in like puzzle books or whatever, where you're trying to, like, manage your way through a maze. Right. And the smart kids were the ones that didn't go through the maze. They drew a circle around the outside of the maze and got to the end, which is a completely valid thing.
00:03:48:01 - 00:04:12:11
Adam
But you want particular constraints. You want, you know, the model to to behave in ways that you expect it to without telling it. But I think that's just a bad assumption. I think that's a human problem, not an AI problem, is that we're we're we're sitting here shocked at what it's doing when it's actually doing the most efficient thing in the way that we, you know, it's comforting, the thing that we asked it to do in the most efficient way.
00:04:12:12 - 00:04:21:09
Martin
I'm waiting for the first job rolls to pop up that, that are, you know, intent engineers.
00:04:21:11 - 00:04:49:08
Adam
We've seen this behavior before. One in particular was actually inside Amazon. The AI was supposed to find efficiencies and rewrite code and rewrite, you know, restructure things. And the efficiency it found was deleting databases and turning off services, which, you know what? Right answer. Fair. Not what we were expecting. You know, don't set the house on fire to like, reduce your electric bill like it will it'll reduce the electric bill, but it allows to burn down the house.
00:04:49:09 - 00:04:51:06
Martin
Yeah. No, I think you're right.
00:04:51:07 - 00:05:03:22
Adam
It's time, Martin, for harness by the numbers.
00:05:04:00 - 00:05:25:14
Martin
Harness by the numbers. Still, I'm gonna love that. For the rest of the song. We do this. Huntress tracks a 1,380% increase in device code fishing in the first four months of 2026, 1,380%. That is insane.
00:05:25:16 - 00:05:28:13
Adam
What is that in metric?
00:05:28:15 - 00:05:31:16
Martin
It's 1,380%.
00:05:31:18 - 00:05:33:19
Adam
It's the same in metric.
00:05:33:21 - 00:05:37:00
Martin
Yes, the same in metric.
00:05:37:02 - 00:06:08:06
Adam
All right. To discuss this, we're going to bring on our guests Nicole Nicole is a cybersecurity advisor and Ian's faculty member, author of an upcoming book, Learning Cybersecurity Fundamentals. She's led security strategy across SaaS, media, and gaming, helping organizations build secure software scale engineering partnerships navigate technology transformation. She also runs two successful podcasts, two successful podcasts that are Great Urban Girl Corporate World and Women in Security and Privacy.
00:06:08:07 - 00:06:10:18
Adam
Nicole, how are you friend?
00:06:10:21 - 00:06:15:18
Nicole
Hey friends, I'm feeling. I've got all the emotions today, but generally I'm feeling good.
00:06:15:19 - 00:06:24:07
Adam
So tell us a little bit more about you, your career, why you show up, the way you show up. Where does this all come from? Talk to us about you and your career.
00:06:24:09 - 00:06:52:08
Nicole
Yeah. I didn't study technology, right. I didn't grow up in ones and zeros. I wanted to work on Wall Street. I studied finance and accounting, and I immediately went to Wall Street after college, and I absolutely hated it. And so my career was a bunch of pivots and figuring out what works. And I got into consulting, I got into gaming, and I just started chasing more so experiences than titles and companies.
00:06:52:08 - 00:07:15:16
Nicole
And then down the line ended up working in risk and then in cybersecurity. And I think that entire background has kind of helped me shape my approach to cybersecurity. I am all about practical, relevant, reasonable, business first security, right? Like if it doesn't make dollars, it doesn't make sense. Or if it doesn't help the business make dollars faster and more securely.
00:07:15:18 - 00:07:16:16
Nicole
It does not.
00:07:16:17 - 00:07:19:17
Adam
Make it doesn't make dollars. It doesn't make sense. I love.
00:07:19:19 - 00:07:20:10
Nicole
It.
00:07:20:12 - 00:07:21:00
Adam
I love it.
00:07:21:00 - 00:07:24:06
Martin
That summed up in one sentence.
00:07:24:07 - 00:07:55:22
Adam
Let's let's dive into this, to this harness by the number stat that we just shot out here. And so Huntress, a very famous and very effective cybersecurity research company, Tuesday said in a report they've observed a 1,380% increase in so-called device code phishing attacks in the first four months of 26, compared to 25. And the reason why that matters is that the cybercriminal ecosystem is still making gains, despite generally lacking the money and compute resources needed to access the most advanced AI systems.
00:07:55:23 - 00:08:21:19
Adam
It's almost as if you don't need the most advanced system to crack human level security. You just need a little bit better than human capabilities, right? So the uncomfortable part is that the attackers automated their whole workflow before most enterprises automated their controls. And in that that phrase in particular is, I don't know, like the way that's phrased exactly, because we're saying it as if enterprises have gotten there, they haven't gotten there.
00:08:21:20 - 00:08:49:14
Adam
The attackers, the attackers are definitely gotten their first. And it is basically just a attack as a service using AI, and it is super effective. So for example, let's put the baselines in context 3.4 billion phishing emails a day, like 39,000 a second. That's crazy. 82.6% of them show signs of AI generation. The medium time to click efficient link is 21 seconds.
00:08:49:16 - 00:08:50:10
Nicole
Wow.
00:08:50:12 - 00:08:55:12
Martin
That one's insane. 21 seconds. Click on a fishing link is insane.
00:08:55:13 - 00:09:16:14
Adam
And then 30% or excuse me, 36% of all data breaches are a result direct result of fishing. And that equals about $25 billion a year. $17,000. Every minute is lost to this. The question that I'm going to ask, which we know the answer to is, is are we winning? No. Are we behind? Probably. But what do we do?
00:09:16:15 - 00:09:18:23
Adam
What what what needs to happen here? What's going on?
00:09:19:00 - 00:09:42:12
Nicole
The attackers are so smart. We probably need to take a page out of their own. Their books. Right? This is why I love talking about cybersecurity fundamentals. Because it's always the basics. It's always the foundational things that get us in trouble. If my ops team is evaluating incidents and looking at what's spiking right, they will see device code.
00:09:42:12 - 00:09:57:20
Nicole
Fishing is something that's spiking. And this means that we should be talking about device code phishing. From an awareness perspective. We should not be waiting till October. We should be doing it now. Bad actors don't wait until October.
00:09:57:22 - 00:10:00:08
Adam
But we'll need it once for our stock to report.
00:10:00:09 - 00:10:00:23
Adam
Do we?
00:10:01:03 - 00:10:04:16
Nicole
But do we?
00:10:04:18 - 00:10:27:07
Nicole
Right. So I think, you know, I've seen over the course of my career a lot of security teams not take or security leaders not take security awareness seriously. They do treat it like a sock two checkbox. I think we've got to understand that AI is moving fast. Attackers are now moving faster. The bar for entry is significantly lower because you have these automated workflows.
00:10:27:07 - 00:10:43:16
Nicole
And so we need to think about how do we build resilience in that era. And I think the timeliness of how we're engaging our employees and elevating, you know, their response, the ability to think differently, decide differently, and act differently is now more important than ever.
00:10:43:17 - 00:10:47:22
Martin
I you saying it's a culture problem more than a technical problem.
00:10:48:00 - 00:10:50:04
Adam
Oh, absolutely.
00:10:50:05 - 00:11:14:20
Nicole
Absolutely. You can give your employees, you know, all the oven keys and. Right, like all the things. Right. But if they don't know what an incident is and they don't know what to look out for, what good is that technology going to give you? It's it's a layered approach. And I would much rather have employee's who are thoughtful, a little skeptical, right.
00:11:14:20 - 00:11:30:05
Nicole
Probably more so than not, I would rather than flood my my security slack channel with. I'm not sure about this. Is this real right? Rather than me and my Ops team having to deal with the whole incident management lifecycle?
00:11:30:09 - 00:11:51:09
Adam
Yeah, yeah. Have you having a glut of is this okay as opposed to having to deal with the big incident after it happens? Yeah. Yeah I but you know, what's interesting to me is that most of the learning in a culture like especially in a large culture of a company or most of the learnings will actually come directly from pain.
00:11:51:09 - 00:12:19:01
Adam
And so like, it's it's one thing to teach people that it's dangerous, scary, whatever, whole different thing for them to go through it. I think a friend who I can't remember who said this, somebody said that a CEO who has been through a data breach is more valuable to a company's security than a good CISO, because once the person in charge has felt that pain, they actually consider it to be real.
00:12:19:01 - 00:12:31:02
Adam
And it's not a cost center. This is something we have to do because I don't want to feel that pain again. Like, I hate to say that it's a trauma informed response is kind of helpful to learning. And that's just that's the way humans are.
00:12:31:04 - 00:12:57:00
Nicole
I think it's the way humans are, but not all the time do I think the pain has to be real. Sometimes we can simulate simulate that pain for people, right? Right. Like we can put on the VR goggles, if you will, from a security perspective through like a tabletop exercise or just making it very relevant for people and having them understand the impact and create learning experiences that they can relate to.
00:12:57:01 - 00:13:15:17
Nicole
Sometimes painful, but I'm not going to deny, right? Like the level of engagement that I get from the business after an incident is significantly different right than before. My my goal is to security leader is to not let it have to get there. And when it does, to take all the advantage.
00:13:15:18 - 00:13:18:18
Adam
And just once, just once, it's nice to be like I told.
00:13:18:18 - 00:13:22:11
Adam
You so.
00:13:22:13 - 00:13:38:11
Nicole
So it's like you got to find the middle road of like, okay. Yeah, huge security incident. But my security tools to Martin's Point and my people to my point helped control the blast radius. Right. So it's like the best of both worlds.
00:13:38:14 - 00:14:08:00
Adam
You know what's fascinating? Talking through this, I remember the difference between being trained with. So for a long time we would go through simulated cities and like, you know, take buildings and stuff like that. We did that with some laser tag type devices for a while where you don't actually feel anything. It's just like, whatever. And then we got out the paintball guns and it was a whole different level of learning, like nobody was getting hurt, hurt, hurt.
00:14:08:00 - 00:14:19:15
Adam
But man, it like when you when you left your legs sitting out or when your, your head popped up or the wrong wall and you caught a paintball. That was a lesson that needed to be learned. I think.
00:14:19:16 - 00:14:38:21
Martin
That's like I have a going back to the being active. I've definitely been involved in incidents and one of the things I found disappointing. So I'm interested in your point of view, this one of the things I found disappointing is listed a really big response initially. We're going to do this, this, this, this, this. We're going to change the way we can do this.
00:14:38:21 - 00:15:02:07
Martin
Here's our plan. And it was a good long term plan. It would get us to a much better place. Then somewhere along the way, I the the pain of it disappeared. And those things that were going well started drifting by the wayside. And you know, how how do you keep on top of that so that it it stays top of mind.
00:15:02:08 - 00:15:10:21
Martin
It stays in front of everybody in the organization from, you know, an engineer to a HR person to the C-suite.
00:15:10:23 - 00:15:34:01
Nicole
Yeah. You've got to build the trust way before you need it. Right. Yeah. There's always this balancing act, just dance that I do right where I'm sitting between security and the business. And there's always trade offs. The business has enough to do. Security has enough to do. But if I'm going to ask for extra attention and investment, it's got to be worth it, right?
00:15:34:02 - 00:16:11:13
Nicole
Got to make dollars and sense. And so once, once, once the business sees you do prioritize certain things and prioritize others that align with what their priorities are, it begins. They begin to understand that you are an advocate for them, right? You build up goodwill. So down the line when you're planning, when you're prioritizing security initiatives, when you're working to get things incorporated into their already jam packed roadmap, they already walk in knowing, okay, if Nicole is asking us to do this, it has to be important, right?
00:16:11:14 - 00:16:36:03
Nicole
The second thing is culture at a company, right? It was amazing, the collaboration that I got from engineering leaders who can typically be some of my toughest business partners. Sure. Right. When they innately wanted to do the right thing because it was the right thing to do, because it spoke to the integrity of not just the experience from gaming, but the product.
00:16:36:04 - 00:16:50:10
Nicole
Right? That that our players are trusting us to put on their machines. So I think it's a little bit both of those, you got to build the goodwill, but the culture of security, of integrity, if you will, has to already be baked into the organization.
00:16:50:10 - 00:17:10:14
Martin
So one of the other things I noticed with the I'm looping back to the fishing thing here a little bit, but the thing that always astounds me is they're not really, you know, they really kind of relying on the legitimacy of companies you already trust, right? When you get those phishing emails they're from, it can be from Microsoft, it could be from Amazon, it could be from Chase your Bank.
00:17:10:15 - 00:17:32:06
Martin
It could be from, you know, they're relying on the legitimacy of people you already trust to kind of break into to to get that phishing click to get that 21 second click, you know, and and I think again, it's I think it's hard because they are relying on the trust that you've already built up. Oh this is from Microsoft I can do this.
00:17:32:06 - 00:17:53:19
Martin
This is from this is from progressive. They're my insurance guys. So I'm okay to click this. And you know in some ways it's worse inside a inside a, you know, an enterprise. I think because you do get so many emails from, from those organizations anyway. And it's it can be super hard to tell the difference.
00:17:53:21 - 00:18:00:19
Adam
I got three emails yesterday from our CEO, Jyoti that were asking me to confirm my number, and.
00:18:00:21 - 00:18:08:22
Martin
I also. So that's funny. I got one of those two. I got an email saying, hey, can you can you just send me your phone number?
00:18:09:00 - 00:18:11:19
Adam
Yeah. You got him the gift cards he was asking for though, didn't you?
00:18:12:00 - 00:18:14:16
Martin
Yeah, absolutely.
00:18:14:18 - 00:18:37:12
Adam
I legitimately like my first. My first cybersecurity executive job was at an AI company before it was cool. And we had. That was when that first that attack first came out. And I had three salespeople give $10,000 each worth of gift cards to our CEO over the phone. And you know what? Like I was like, I'm sorry. Like, thank you for bringing it up.
00:18:37:12 - 00:18:53:11
Adam
Thank you for letting me know I'm sorry. And I and so I, like I had to go tell you the rest of the company. You know, I made sure their manager is new. Like, hey, this is this is a new thing we hadn't seen before. And what these stats are telling us is that this is going to get more sophisticated and harder to see.
00:18:53:13 - 00:19:03:15
Adam
Ultimately, the credit card companies that they use to to buy those gift cards, they were the ones that investigated and did all that, you know, anti-fraud stuff. But but it's legitimate. Like it really happens.
00:19:03:16 - 00:19:24:17
Martin
I've gotten to the question for Nicole. You were talking about the fundamentals before, like getting the fundamentals right. And I'm intrigued with some of the tools that are available now. And I'm not necessarily thinking of specific security tools, but I, I always for me, I quite like learning in small bite sized chunks. So I like to say, hey, here's my bite sized chunk for today.
00:19:24:17 - 00:19:50:04
Martin
It's five minutes and I've learned something new or I've been refreshed on something new. I feel like now we've probably got the tools where we can, you know, maybe identify things that we've done, you know, hey, I've seen how you're working. AI has said, I've seen how you're working. Here's a gap that I can remind you of, you know, how does that play into that kind of getting this, those kind of fundamentals in place?
00:19:50:04 - 00:19:53:06
Martin
And because I feel like that's a great way to make it part of the culture.
00:19:53:06 - 00:20:19:11
Nicole
So interestingly enough, this is one area where I don't think companies do a good enough job, right. Especially when I look at software development. Right. When you think about all the talk around software development and AI, 80 to 90% of the conversation is focused on developer productivity, right? Like we're getting cold, we're shipping faster. We're moving so fast.
00:20:19:11 - 00:20:44:19
Nicole
Developer productivity I think I heard Nynex a couple of weeks ago is probably 12 x today. Who knows? Right. What I don't hear people talking about is with the increase in speed of coal development. Nobody's talking about the software development lifecycle and all the controls and governance that go around it, and how we can leverage AI to do those things faster, right.
00:20:44:20 - 00:21:12:09
Nicole
And so I think we get really caught chasing the shiny penny, right. Emerging technology. Yes, it is exciting, right. But I think we also have to remember that AI is an accelerator of value just as much as it is an accelerator of risk. And so we need to leverage it to our advantage to manage risk in a more accelerated or more comprehensive fashion.
00:21:12:10 - 00:21:34:08
Nicole
Right. Like, how can we think about leveraging AI to ensure we're spinning up secure based images? How can we leverage AI for enhancing our threat models? Right. Like those are the things that we need to ask that all the core controls that help protect the software development life cycle, how can we accelerate that and enhance that with AI?
00:21:34:10 - 00:21:36:02
Nicole
I don't hear us talk about that enough.
00:21:36:04 - 00:22:01:04
Adam
Yeah, I ten minutes before generative code hit the scene, most people's pipelines were too slow and not able to deal with the productivity of of developers at that speed. Not enough of the enterprise customer, not enough. Not enough of companies or software manufacturing. You know, teams have actually accelerated, like you say, to catch up with all that stuff.
00:22:01:06 - 00:22:06:11
Adam
We we know a company that thinks about that talks about it a lot, but.
00:22:06:13 - 00:22:07:16
Nicole
I wonder who that is.
00:22:07:17 - 00:22:34:19
Martin
So a couple of days ago, essentially the white House kind of finalized it's a review framework and a volunteer 30 day window for the government to test frontier models before launch. They then they decided not to publish it. The thresholds are classified. The briefings were closed door. And the one thing that leaked is the big one. Open weight models are exempt entirely.
00:22:34:19 - 00:22:49:01
Martin
So essentially the white House set open weight models free, which, you know, is that a safety loophole? Is it a, you know, a shot at China's open model dominance? You know, where is that sitting?
00:22:49:03 - 00:23:05:10
Adam
I'm skeptical that there is a agency or group inside the government, inside the US government, that's actually capable of doing good testing in 30 days. And and they haven't even built a framework for it yet. So, like, what's actually going to happen? I don't have anything nice.
00:23:05:10 - 00:23:30:00
Martin
To I'm going to jump in. Right. Because so I think like them building the framework is almost this is my opinion. I don't necessarily think that's the right approach. I think setting the standards of, you know, we're expecting this level of detail in your testing, you're expecting your testing to have this kind of breadth where like, I feel like the framework should be.
00:23:30:01 - 00:23:53:02
Martin
These are the expectations we have of you frontier model companies, right? This is what we expect you to do. And our job is in this case, the government regulating to a degree is we want to be able to just come and validate that you're doing all the right things. Are you taking all the boxes rather than trying to actually define the testing itself?
00:23:53:02 - 00:23:58:08
Martin
Because you're right. Is there anybody in the government that has that right knowledge that.
00:23:58:09 - 00:24:32:10
Nicole
I have an opinion on this? And listen. Hey. Yes. The government's. Yes. Okay. Guidance. Yes. It's helpful. It's not your AI strategy though. Companies don't have to answer. Right. Like we. And half the time you all know we criticize so many of these frameworks anyway about like what's really important. Oh, oh I talked to this that it's ultimately it's nice to have but it's not whether it's voluntary or mandatory.
00:24:32:11 - 00:24:47:01
Nicole
We still own the risk. Yeah. Right. So we still need to know who can access it. We need to know like what actions can it take, what approvals are required. And then when something goes wrong, who's accountable? Washington is really not going to help us with that.
00:24:47:03 - 00:25:14:03
Adam
And so that's an interesting debate. And fight that has been happening in CSO circles. Is accountability. Like who's holding the bag for this? Yes. There was a huge firestorm when the SolarWinds hack happened, when the Uber hack happened around accountability on a personal level for security leaders that I think, in my opinion, was overblown, like we were being a bit too paranoid and a bit too chicken little about it.
00:25:14:03 - 00:25:32:16
Adam
But one thing that we haven't seen yet is a litigation. Like the litigation hasn't settled. Like we don't know who's actually going to be ultimately holding the bag for when things go wrong. And so is it going to be the company that made it a model? Is it going to be the company that implemented it, like who is actually going to be held accountable?
00:25:32:16 - 00:25:38:00
Adam
And that's going to change from the US to Europe to other areas and other jurisdictions as well.
00:25:38:00 - 00:26:10:18
Nicole
It is important directionally, because, you know, the white House shaping some of this policy guidance, whatever it is, it does give a signal that government is focused on AI. And it's very important. Right? I think it's a it's a huge North Star. But if I am sitting in the position of a security leader, I am significantly, much, much less concerned and invested in whether 1600 Pennsylvania Avenue has a framework on it and whether my company has a framework on it.
00:26:10:23 - 00:26:32:04
Nicole
Right. And if we do have a framework, because frameworks, policies and standards don't protect our organizations, people and controls do, right? Do I not just have this high level philosophy? How am I operationalizing it? Right? What does identity look like? What does visibility look like? What does accountability look like? What does risk management? What am I monitoring right.
00:26:32:05 - 00:26:55:16
Nicole
Again, I hate to beat the dead horse, but this is why I wrote the book. It's all about the foundational elements, right? If you can get these foundational elements at minimum. And I'm not saying that we have to cover every single hole, right. Know where your holes are, right? Right. Like that visibility, that knowledge, that governance around it is amazingly important.
00:26:55:16 - 00:26:58:02
Nicole
But none of it matters unless you can operationalize.
00:26:58:02 - 00:27:23:14
Martin
It, certainly in government or in federal type organizations. I know they're using those open weight models. Right. That's actually the Palantir approach, right? They're using those open weight models. They can deploy them privately. They have much better controls, much better accountability. They know, I know, I know, I know exactly what you're going to come back. But like it is I think it's happening.
00:27:23:14 - 00:27:25:10
Martin
Right. They're doing it right now.
00:27:25:12 - 00:27:25:18
Adam
Yeah.
00:27:25:19 - 00:27:28:17
Martin
For sure. And now let's hear that okay.
00:27:28:18 - 00:27:56:18
Adam
Yes. Palantir. Yeah. Let me take that name out of my mouth. First of all, welcome a new overlords that are listening. So apologies, Peter Thiel. It's I get what you're saying. I understand that, you know, the big players in the intelligence services have decades of experience in this area. I am not confident that that experience means jack shit to this new world of AI.
00:27:56:20 - 00:28:21:21
Adam
AI has already broken out of air gap systems. Air gapped systems are not air gapped, and they haven't been for 20 years. They've already broken out of those. So I think that the the big companies that service the intelligence services or the big companies that service the intelligence community have decades of doing something, but I just don't think that it's super relevant to the new landscape.
00:28:21:21 - 00:28:35:21
Adam
I think that they that's actually going to be detrimental to them. Their assumption that their experience doing this for the last 30 years is going to help them in this new world is actually going to be a hindrance. It'll block them from seeing the truth of the matter. I don't know the Cole, what do you think?
00:28:35:22 - 00:28:57:14
Nicole
I think the debate about who has access to what I don't care, it's my organization protected. That's that's. You know what I mean? That's my stance. That's what I mean. Because one could argue, right? Like who has access to certain resources or not? There are certain companies that don't have budgets to have access to certain tooling. Right. But they still have the responsibility to protect.
00:28:57:16 - 00:29:00:02
Nicole
Right. So it's I mean.
00:29:00:04 - 00:29:05:16
Adam
So much more to say that I'm not going to say in public because they're listening.
00:29:05:18 - 00:29:19:13
Adam
At the end of every episode before we say goodbye to our guests, we asked the same question. Quick answer. Take it wherever you want. What is the one thing that teams are getting wrong about AI and software delivery right now?
00:29:19:15 - 00:29:52:16
Nicole
I think what most teams are getting wrong about AI, specifically in software delivery, is optimizing engineering productivity instead of optimizing software delivery. Nice, right? Again, most of the conversation is around coding faster. And don't get me wrong, it is important, but I think we're just missing the opportunity to use AI as you know, so much more than just a code accelerator.
00:29:52:21 - 00:30:22:06
Nicole
Yeah, right. Like how do we think about stack and optimize, make threat modeling better, QA, better right. Vulnerability management, better, governance better? I think we have not tapped in like the attackers have done to execute more quickly. We haven't tapped in to support governance more quickly, and we're leaving so much value on the table when it comes to deploying and securing with the fundamentals at scale.
00:30:22:07 - 00:30:23:04
Adam
I love it.
00:30:23:04 - 00:30:24:00
Martin
Thank you so much.
00:30:24:00 - 00:30:26:03
Adam
For that. Can't wait to see you again.
00:30:26:03 - 00:30:29:04
Nicole
Thank you both. I've had so much fun. Y'all are the best.
00:30:29:05 - 00:30:41:03
Adam
That was amazing. Having Nicole on is always just the greatest and can't wait to have her back on. It's going to be amazing. There's two things that I'm taking away, but I want to hear your two things first. Martin go ahead.
00:30:41:04 - 00:31:08:06
Martin
Well, first one for me is I don't like being ganged up on. That was my first takeaway. Okay? You know, you two together. That was a little scary. Second thing was, you know, and it was a consistent theme all the way through those forget get the fundamentals right. Learn, learn the basics. Now the reason that I liked that is because actually that's been a theme.
00:31:08:07 - 00:31:25:18
Martin
You know, when we were talking about, you know, what's the future of employment for software engineers? What, you know, like even before in previous podcasts, we've kind of had that theme a little bit. But I did like the way, you know, you can bring everything back to the fundamentals and just build on them. So that was great for me.
00:31:25:19 - 00:31:52:14
Adam
I think the big takeaway that I had was the importance of pervasive culture to a security program, of having everybody aware and rowing in the same direction towards something like that. The other thing that I, that I really take away from what Nicole shared is that it doesn't require fancy footwork. You know, it doesn't require really complex or advanced tools or processes or procedures.
00:31:52:14 - 00:31:56:12
Adam
It's the basics that really matter. That's where we should be focusing.
00:31:56:14 - 00:36:17:13
Martin
That ship. Talk brought to you by harness. If Adam's point of view got under your skin, it was getting under my. Please subscribe and tell us why. Until next time, stop talking. Start shipping.
00:36:17:15 - 00:37:32:00
Nicole
But if I am sitting in the position of a security leader, I am significantly much less concerned and invested in whether 1600 Pennsylvania Avenue has a framework on it and whether my company has a framework on it.
00:37:32:01 - 00:37:36:01
Martin
It wasn't just one person it created, was it? Didn't it create multiple identities?
00:37:36:01 - 00:37:36:17
Adam
Several.
00:37:36:18 - 00:37:40:14
Nicole
They will see device code. Fishing is something that's spiking.
00:37:40:19 - 00:37:44:07
Martin
1,380%. That is insane.
00:37:44:08 - 00:37:49:23
Adam
Is it? The attackers automated their whole workflow before most enterprises automated their controls.
00:37:50:00 - 00:38:08:23
Martin
Essentially, the white House finalized its AI review framework. Then they decided not to publish it. Thresholds that classify the briefings were closed door, and the one thing that leaked is the big one.
00:38:09:00 - 00:38:58:21
Adam
That experience means jack shit to this new world of AI.
00:38:58:23 - 00:39:01:23
Adam
Nobody told it to lie, but it figured it out its own.
00:39:02:00 - 00:39:04:15
Nicole
Bad actors don't wait until October.
00:39:04:19 - 00:39:08:23
Martin
It's not a Skynet problem yet, but it is scary that it basically lied.
00:39:09:00 - 00:39:19:07
Adam
A CEO who has been through a data breach is more valuable to a company's security than a good CSO.
00:39:19:09 - 00:39:22:22
Adam
That experience means jack shit to this new world of AI.