Behind the Shield

Rob Hughes Returns: What AI Means for Identity, Security, and FedRAMP 20x

Season 1 Episode 40

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 58:23

Rob Hughes returns to Behind the Shield for his second appearance, making him the show’s first returning guest. This episode picks up in the middle of a year defined by rapid change, especially across AI, cybersecurity, identity, and federal compliance. Rob joins the InfusionPoints team for a wide-ranging conversation about how security leaders are thinking through the speed, scale, and uncertainty being introduced by AI, and what that means for organizations trying to keep pace without losing control.

The discussion explores how AI is reshaping vulnerability management, identity security, social engineering, data governance, and security culture. Rob shares perspective on how security teams are evaluating AI’s impact in real environments, including how AI can help prioritize vulnerabilities, assess risk faster, and surface issues that may have previously taken much longer to identify. At the same time, the group digs into the challenges AI introduces, including AI agents, non-human identities, permission creep, unclear data retention, model transparency, and the rise of shadow AI.

A major theme throughout the episode is that AI may be new, but many of the security fundamentals still matter more than ever. Strong identity controls, clean data, least privilege, layered defense, human accountability, and clear governance all become even more important when AI can move quickly, access large amounts of information, and operate across systems. Rob also discusses what good security culture looks like inside a company built around security, and why organizations need to educate employees on responsible AI use without stifling innovation.

The conversation also turns toward FedRAMP 20x and the broader federal authorization landscape. Rob and the team discuss how trust, automation, 3PAO expectations, agency adoption, and ATO challenges are evolving as the federal market looks for faster, more scalable ways to evaluate cloud security. From AI risk to FedRAMP 20x, this episode looks at what is changing, what still needs to be solved, and how security leaders can prepare for what comes next.
What You’ll Learn:

• Why AI is accelerating the pace of change across cybersecurity
• How AI is changing vulnerability discovery, analysis, and prioritization
• What security teams should consider when evaluating AI agents in the enterprise
• Why identity, permissions, and non-human identities are becoming even more critical
• How shadow AI creates new risks around data visibility, retention, and control
• Why security culture still depends on people, not just tools
• How organizations can encourage AI adoption without ignoring risk
• What good security culture looks like inside a company built around security
• Why FedRAMP 20x is forcing new conversations about trust, automation, and accountability
• Where agencies, vendors, and 3PAOs may still be struggling with authorization expectations
• What needs to improve to make ATOs more accessible, repeatable, and scalable

Chapters:
0:09 - AI Overview
1:55 - Rapid Change
10:14 - Identity Management
12:54 - Social Engineering
20:45 - Government Security
28:17 - Data Transparency
32:19 - AI Ethics
36:56 - Robotics
41:57 - Human Trust
49:49 - Authorization Process
55:41 - Shadow AI

Guest Links:
https://www.linkedin.com/in/robert-hughes-816067a4/
https://www.linkedin.com/company/rsasecurity/
https://www.rsa.com/


Learn more about InfusionPoints:
https://www.linkedin.com/company/infusionpoints/
Jason Shropshire: https://www.linkedin.com/in/shrop/
Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/
Request a Demo: https://xbu40.com/
FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment

InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.

About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

SPEAKER_02

Hey Rob. Thanks for coming back on behind the shield. That felt awkward already.

SPEAKER_00

Oh, I'm doing it. Okay. But hey, he is, isn't he our first comeback?

SPEAKER_02

I think so. Yeah. I was just thinking about that right before we got in here. And yeah, I think I think Rob, you are the first return uh guest. Welcome.

SPEAKER_00

We appreciate having you back.

SPEAKER_03

I'm honored for that. You know, I've known you guys a long time, so you know, I think it makes some sense too.

SPEAKER_02

Um absolutely. And you know we're in the halfway through 2026, and oh my gosh, what a year. Um, I feel like the beginning of the year it felt different than even the the second quarter, and now you know the third quarter is right, right, uh breathing down our necks. Um, and it just feels like the pace of change is is so you know rapid right now, and and it's it's hard to keep up.

SPEAKER_03

Yeah, totally totally agree. And I think you know, really AI is just pushing on lots of boundaries where it's like from the security perspective, like you want to make sure your um your fundamentals are good. And it's like could highlight all the things where you know you're having some trouble with that. It's like, all right, how do we how do we deal with that? And the acceleration, like maybe we could talk about the vulnerability space for for a little bit.

SPEAKER_01

Uh, yeah.

SPEAKER_03

Yeah, definitely. Um, right like there's all this uh, you know, there's some differing views and controversy around like, hey, is this the thing that is actually as dangerous or amazing as anthropics as it is? And it's like whether you agree or not with that, um, I think it's sort of like this thing that's out there, like uh, you know, when quantum computing can actually break through our modern encryption algorithms, like that might not happen for a while or it might happen a year from now, like, but hopefully it's more like aligned with like the NIST timeline and like 2030, 2035, you know, we we get prepared for that, but you just you know that something's coming, and even if it's not coming now, like, and I think mythos is a bit more real than um than that, in the sense that even though it itself might not have like you know, it has good capability, like I don't know if it has all the capabilities that they were worried about, but what it's highlighted is that any use of AI to scan code, even local models, can come up with some pretty good things. And I don't know that everyone was really doing that effectively before like the alarm got sounded, and now we're seeing lots of new vulnerabilities getting patched, like I think Microsoft's last uh patch when patch grouping was like over 200, which I don't think we've ever seen that before.

SPEAKER_00

Well, we're seeing it in Linux too, right? They they they seem to be dropping a lot more um just across all the different things.

SPEAKER_02

Yeah, I saw the announcement from ChainGuard that you know they're they're investing $50 million to saving open source, and and it and it it all hinges around the Vuln counts that are coming out of um all of these open source projects, right? Um so I mean you see announcements like that that are happening, and uh you know, oh yeah, you know what, there's hype in all of it, um, but there's I think there's an underlying reality that underpins the whole thing that things are have fundamentally shifted. I mean, there's been like the Overton window has like been been shoved uh more than we've we've seen in a long time, I think.

SPEAKER_03

Yeah, that definitely. And it's you know, it's it's like once you open a door, you can't close it sometimes. Like we opened the door, it went through. Like we're here, you know, there's all this money and resource being invested towards AI. And you know, you can hear you know daily about different uh communities you know not being happy with how much water is used for AI data centers. You know, you see the impact of like how much the size of this thing is, like water, power, all the compute that's that's being uh you know consumed here. So like it's harder for us to get, you know, for me to get for my home PC, like get a new GPU or CPU or memory or hard drive. And so it has like this impact that like all that's going there. So it's like, and you think like, hey, what comes after mythos? Is it gonna be more powerful? Like, how could it not be with like these massive data centers being constructed with all this power going towards it? It's like using a lot of the earth's resources to just like put it into the thing.

SPEAKER_02

So yeah, and you know, I think that that's that's sort of leading to the talk of AI data centers and and stuff like that, right? Because probably the the the the earth itself, you know, down here in the atmosphere, can't uh probably can't sustain it all indefinitely if if things keep moving in that direction. Part of me to wonders too, like, you know, are there going to be breakthroughs? I mean, we saw this a little bit with Deep Seek uh when it first came out, but it was like, oh gosh, they they can we can do the same um you know the same things with an LLM that we that we could do with with um you know one of the US labs LLMs, but we could do it much more efficiently, right? So you wonder like, are there gonna be other 10x breakthroughs and efficiency that's gonna um allow them to continue to to have you know more and more intelligent models that are more efficient? I mean, I I don't I don't think so. I don't think that's gonna happen indefinitely. I think I think to make fun fundamentally make these things work, it takes a uh a ton of compute, and it's always gonna take a lot of compute. I think it'll be incremental breakthroughs and efficiency, but but um I don't know. That's just my thinking.

SPEAKER_00

No, I I agree. Um and you know, just kind of going back to the the vulnerability aspect briefly. Maybe Rob, this is something I see working with your team is AI has the impact that I've seen is the ability to help, hey, what does this really mean for my environment? Like, you know, having that input and having that that ability to run that analysis, and yeah, there there is still some some human intervention there, but you know, it's identifying it and it's also like what is what is the real impact here on on my environment, on my infrastructure. I would imagine you as a CISO having that kind of insight is invaluable.

SPEAKER_03

Yeah, I I think so. So there's like a few things I'm thinking about when you mentioned that. Like one is like sort of this like what's you know, what's in my environment. So it's like we don't just have FedRAMP environment, we have all these spaces, we have manufacturing, we have you know a website that's that's hosted, we have all these different pieces to our um to our threat space and uh or to our surface area, I should say. And with all those pieces, it's like seeing like, hey, does this headline, does this concern, this vulnerability apply to us? And if it does, where which pieces? And you know, based on where that is, you know, what's what's the the risk? And so like we you know, we have tools that do some of that analysis, but sometimes you have to go and look, and it's like, well, I thought of like, can we have an AI agent to just go and like do that review if you feed it in a bunch of like the rough data and like just get that kind of you know alarm against the headlines sometimes? Uh, you know, how quickly do you react? Um, it might be some some use in there.

SPEAKER_00

Um yeah, yeah. I mean, if you can prompt that AI agent to have that that historical knowledge that say one of your one of your team members would have as they're doing their analysis, then it can just s really speed up that process to really know what impact this has on RSA holistically, right? Yeah, yeah.

SPEAKER_02

No, it's it's it's really having the data foundation, right? And then then I mean as long as the data's good and and the context is there, right? Then you can surface these things with agents um to make to make our lives easier, right? Yeah, yeah. I mean, that's the that's the goal.

SPEAKER_03

Yeah, yeah, no, I I think so. And and it's like, you know, how do we you know leverage this in in the best way? And like having an agent like that that just like scans the headlines, like I tend to do that anyway, like I enjoy it because you know, sometimes uh there's interesting headlines and get into that, but sometimes there's just sort of this uh you know kind of repetitiveness about vulnerability, vulnerability, and it's like, okay, well, and uh you know, it's it's like I don't necessarily know off the top of my head like which WordPress plugin you know got owned and how many we have on on the website because it's like you know, we have a subset and like a hundred thousand you know, WordPress WordPress plugins out there, and it's like this big one today, it's like okay. So it's like there's there's some you know checking that we do when those things happen. You know, we certainly have the list, but can we make that faster and easier for the teams and maybe like let us spend more time on more valuable things? Um absolutely. Absolutely.

SPEAKER_00

Yeah, the I I guess the other thing, and I know we started talking about this um you know, kind of leading up to when we started our pre-talk chatting, yeah, all of our pre-talk Rob. Um, just kind of talking about, you know, we we've discussed the vulnerability aspect of it. What about, you know the the identity management piece? Because you know, RSA is is really known for you know securing identity, right? And and and validating that. So like what kind of impacts has that had on on that side of the business?

SPEAKER_03

Well, it it you know, I've been sort of asked for the past few years, you guys can imagine about like, hey, what you know, what new threats is AI bringing to to us, to, you know, to our company, to our customers, to, you know, in the identity space. And it's like at first it was it was kind of quiet. It was like there were a lot of people trying different things, and it's like, okay, well, you you have the idea of vibe coding so that you can get into spaces maybe faster or chain, you know, a bunch of tools together and like maybe someone that couldn't code before. But I think a lot of the attackers could do some coding already, so it wasn't necessarily like you had all these attackers that couldn't code waiting for AI to like let them code, right? So it's like it's that risk was already there, and it's like, okay, well, improving social engineering.

SPEAKER_02

Yes, that's a big one.

SPEAKER_03

That's true. Where we started getting more interesting, and I still don't think we've fully seen like this thing because this concept of like spear phishing at scale. Like if I was uh you know advanced persistent threat group, uh, I might say, All right, well, I want to get into company X. All right, go to their website, you hear AI, go to their website, check out their leadership page, you know, find the personal email addresses of all of them. You know, you have open access to the internet and start, you know, it really gives you that ability to chain those tools together.

SPEAKER_02

Yeah.

SPEAKER_03

Yeah, and like I don't think we've fully seen where that's gonna go. Um, like I feel like there's just still like enough restriction in the the big bottles that most people are using. Um, but then I think you could get to private models that um you know maybe have less restriction or less guardrails, and you can start doing. I mean, I there's there's definitely ones out there, and and they may be doing things like that already. I just, you know, I haven't seen it as much. Um, you know, it's like we we get these types of threats already, we get impersonation, we get this just um, you know, is you know when you know, so it definitely improved the social engineering aspect, but I don't think we've seen it like at the scale level it could do. Because I think at scale, it could be that like you start to like not trust a lot more of the emails that you're getting. Exactly. A lot more of the contacts.

SPEAKER_02

Like, is that really honestly email's like a dumpster fire these days? If we were just talking about this, that that email in general just feels almost dead because um it's and it's felt that way for a while, but it's just intensified, I think.

SPEAKER_00

No, I I agree completely. Like, you know, even like even when you email me, like I'll be like, you know, hitting you up on a on a Slack channel or something. If it's really from you, like even joining this this podcast, it's like uh do I really want to click this link, right? Like I really do think it has changed that that landscape completely.

SPEAKER_03

So in a sense, like I think we've already adapted a little bit to like knowing that hey, if if I see this like shuddery video or this video of like our my CEO asking me to approve like a million dollar you know wire transfer that normally would make no sense, like, okay, I think most people are aware that that's probably uh not something you should do. So I think you know it's it's coming down now to like you know the big thing if you lead back, like oh, how is it impacting the threat landscapes, like maybe down to the vulnerability space and getting some of these zero days faster or sooner, or you know, the big thing is chaining, you know, chaining a bunch of mediums and lows together to end up with one where you can get access. Um so that's that's kind of the interesting thing. And then you just uh excuse me.

SPEAKER_02

I mean, a big part of what I've seen going to I've I've gone to a lot of um government-related uh tech industry tech shows this year, uh and and and toward the end of last year. One trend that I've seen a lot is AI pen testing. Um as far as companies that are out there that are a lot of them are are you know, this feels like a theme uh for for venture capital um to be like building this as well. Um, but there's just a ton of companies out there that are that are trying to build this, right? And at some point I'm sure there'll be consolidation and all, but it just seems like you can't throw a rock and not hit somebody trying to build this.

SPEAKER_00

A pen test agent, right? Well, yeah, yeah.

SPEAKER_02

And it well, it different approaches sometimes, but but they're all working toward a common theme.

SPEAKER_00

Absolutely.

SPEAKER_02

Um the um but yeah, I mean, getting back to identity, um you know, it's it's it's a different game than it used to be. I mean, uh I I really did a lot of identity management work years ago, um, and it's always been an aspect of what we've done here at Infusion Points, but you know, now it's it's um it's agents, right? That like we're not talking it and we've been dealing with with um machine identities for a while, but it feels like this is like a whole different um level, right? Um and the implic and the and the implications are are uh very different as well of of you know because I think there's just so much opportunity for permission creep.

SPEAKER_00

Um those service accounts, right? Oh yeah, yeah. Anyway, I've set up the service account now. Uh generally you're okay, it's a service account. You have to have certain permissions to get to it. But when AI can pivot and do things, yeah, I think that that's opening up a whole new landscape.

SPEAKER_03

Yeah, yeah. Like I think of the kind of the AI agent on someone's machine. Um, I mean, a lot of cases the default is to inherit the permissions of the person that's on the machine. It's like, okay, kind of natural. But then the thing you miss is like if the agent misbehaves, like who's accountable for that? So I think that's like some of the governance comes in to say, like, hey, look, if if you're having your agent do something that you have access to, you know, you're accountable for that. Like, you know, we need to kind of reinforce that. There's some user learning there, and like, is that appropriate in all instances? Like, you know, you want people to be fast and innovative and embrace the new technology, but at the same time, um, you know, if your identity structure isn't in a good spot to um allow for that, then there's a lot of risk there. You know, do you have that segmentation? Do you have you know approaching the zero trust? Like some again, old tried and true terms, but AI like pushes on a lot of those capabilities, push on a lot of those barriers of like, hey, if you don't have a good uh landscape, a good um set of controls, good data controls, AI will really quickly um you know make make you aware.

SPEAKER_02

Um it'll let you do it supercharges uh you know bad ideas.

SPEAKER_03

Yeah. I mean, we we need this to be, you know, give it an example. Like we had uh we were putting a chatbot on our website, like a lot of companies do, um, you know, and in the testing of it, we're like asking it about one of our products was like, oh, it's giving like kind of old information. So what's you know, is it hallucinating? And it's like, no, we we tracked it back like we had an older document on the website that we needed to update. And that's like so we got to cleanse our data really quickly. So there's a positive benefit in that. Like, you know, we might not have noticed that as quickly without the AI kind of you know giving that kind of real-time response. Um, but uh it it can highlight your data and permissions issues, your vulnerability, attack surface issues, like it's all like faster. And it's like, well, how do we deal with that now? You know, and it's like, well, the layered defenses are still a good idea, you know, defensing that like you know, if your one layer gets penetrated like really fast, then it might take some time to figure out how do I even approach the next layer. Like it that still might not be um easy for even super AI enabled uh attacker to do.

SPEAKER_02

Yeah. And it the interesting thing to me too is you like you talked about attribution or that human in the loop. You know, we have a desire always to to know that there's trust, you know, there's there's there's a human-to-human aspect of trust, right, that that really is in play here. Um and it and it goes all the way to something as fundamental as like like like the agent driving your your workstation reminds me a lot of like uh a self-driving car, right? Like, yeah, you can have a self-driving car, but if the if that causes an accident, the human sitting there is supposed to be responsible, right? But the human sitting there, I mean, we've seen all the YouTube videos of people defeating the guardrails. Yeah, um, and you know, the same thing, obviously, the the same thing is happening on on the workstations, I'm sure, as well, um, where there's agents involved and and um and automation. But um, you know, I I just think that that um it's playing out right now with FedRAMP 20X and um, you know, that the the three PAOs' heads are exploding because they're not being asked to make a uh a recommendation anymore based on, you know, and and formerly, I mean that was a big deal because their recommendation, you know, this is my firm's recommendation, and it's it's a reputational thing, right? Uh and if you get that wrong, you're gonna have a reputational hit um that matters. So a lot to put into making sure that that recommendation is a good one. Uh, and it when you take that away, it's like, well, what are we basing this on? You know, and and I see the industry, I see especially three PAOs really struggling with that, with understanding like the like the role here. Yeah, I wonder what even the agencies think about that, right? But in the in this AI age, it's like you're you're you're trying to keep the human in the most, it's like you're elevating the the most important trust aspect of a transaction, and you're trying to get the human where they're just involved in that, right? And everything else is automated and and and reasoned by you know the the the stack, um then, and you know, hopefully explainable and and all of those things.

SPEAKER_03

But you know, hopefully you get this little thing called uh non-determinism or probabilism, where it's like you know, you ask a large language model something a hundred times, and one of the times maybe you get something crazy. Um, so it's like there's an element of unpredictability in there just in these in these models. Um and so how do you account for that? So it's like Jason, I was thinking as you're talking, like would put you know the trust in the human, but like humans can't uh be in the loop at scale, right? Not scale that AI speed. So it's like, all right, well, how are you appropriately in that loop? And it's going to depend on your risk decision. Like, are you deciding to turn off a power plant uh at a certain time? And and then like oh launch a missile. Yeah, launch a missile. missile and like percussions of that might be big. And so like, and and you know, but hopefully you're not having to make a million of those decisions every minute, you know. Uh so then if like you are in these high transaction profile type systems, it's like you kind of have at least the control like the human in the loop might be like the human confirmed that all those controls were there. And then that there were checks against those controls even internally by other AI aspects or just structural controls around it. And that the human approved like hey that was sufficient for this use case for that to go forward into production and be used. So that could be a human in the loop even though you know you're not in the loop of each outcome or each transaction, but there was a human governance there. So I think we have to think about just the volume and where it's appropriate. Like you know human driving decision like you know when you're when you go into one of those robotaxis if you ever have I did you know a few times and it was kind of fun and and weird and actually kind of did a decent job but it's like all right well I'm not determining if it turns right or when it goes or when it hits the brakes like I'm not in the loop but I can hit the button to say pull over and get me out of here you know that's yeah but uh and and or I could push the button to get help I think if like hey we got stuck somewhere and then someone out there in the ether be like oh okay I can see you're here let me take over the controls you know so that might be sufficient and that's like a life or death thing. You know it's not you know driving is can be a scary thing.

SPEAKER_00

Absolutely um so I and I know kind of prior to to starting you had spoken about how you were at a CISO conference recently and you know we've done a lot of talk about AI. I believe you mentioned that there was some talk about AI there.

SPEAKER_03

Uh are these some common themes that other CISOs are are are trying to solve for oh yeah I mean like I think everybody's challenge with like you you know you asked about identity earlier and of course we have a big interest in identity over our day um and just the idea of all the non-human identities and how you manage them and sort of having you know how do you like think of like at one point an agent started but it might talk to the next agent and get the next thing and the next agent and you might have a chain of these things and then like what's the permissions that you expected here if it went to all these other pieces and they can all see more data then does this one agent have really access to all this stuff so you need to you know take that into account and I think people are even struggling with just like the base inventory of agents and the ownership of the agents and you know and then you get into the permissions and there's a great statistic and I don't know I don't remember who to attribute it to but someone mentioned that there are 96% of um of permissions are not utilized in the enterprise. So if you think of that the idea of security like least privilege um it's just that's an indictment yeah no it's it really is and it's like you know we do our best and it's like you know you go into a system like pick your favorite CRM tool or whatever in the cloud and it's like oh yeah they define you know 27 roles and then we needed to define another 20 and like you get to the point where you're going through these quarterly access reviews or whatever access reviews you do and it's like all right how does that you know how does that actually line up to this access so I think generally things people are over provisioned but there's this pain when you're right at the line that you try something different and you you hit a wall and then it's like that's where security gets a bad name or IT gets a bad name or whoever's the system manager and so people are a little afraid to like restrict it too tightly. So then you get into ideas of like just in time type of access and how does that work with agents there's a lot in there. We could have a few days worth of podcasts on that problem.

SPEAKER_00

No I'm right there with you because one of the things that you had mentioned that that sparked a little thought in my brain was inventorying these agents right like what does that even look like I mean I know historically from a a security compliance perspective it's you know we're looking for rogue assets in an environment well is there a rogue AI agent in your environment like how do you inventory all your agents?

SPEAKER_02

Yeah it's really interesting right now like like the it depending on if you're using SAS, you know, you don't know the underlying LLMs that they're using you don't know the frontier models that your data is being swept off to um you know there's there's such opaqueness right now and and lack of transparency in in some of that some of it's intentional some of it's just everyone's trying to ship as fast as they can so they're figure it out. They're not building it in right um but yeah I mean I I I'm seeing quite a bit of that and and even you know in the way that we want to lean into AI here um I'm constantly considering like are we losing are we losing track of where our data is going like like like it was you know we were looking at Kiro for example which is it's Amazon's IDE you know port of VS Code or a fork of VS Code rather um and it it it's not clear what models that we're using and right now dod doesn't like anthropic and we do some dod work so um you know it just it really matters um and it and right now it's just difficult.

SPEAKER_03

It it really is and it's like I think that's like there's an inherent lack of definition around these things. So it's like first if you think like hey I'm gonna go do a prompt okay so I'm interacting with this LLM. By the way Mike you mentioned that like conference I was at and there were a couple people that were from bigger companies are like yeah we have our our own LLM like we created this thing just for our company but then it's like okay well it interacts with something you know it might and they might be able to shift that out over time but they have some control over that um but not everybody does. And if you're interacting with it like so you know if if we have the personal one on the phone or whatever, you don't know how big your space is you don't know what memory it has you don't know how long it's going to retain the data especially if like you you're going between a few different ones and they might change their terms of service regularly or leave it open so that you're not going to be able to define that. So you don't even know like the capabilities of the thing you're interacting with when you interact with and that's like the first thing where it's just like as a user it's like just just difficult. And then from there it's like okay then you get into some of the things like the non-human access like okay well you don't know the capabilities of it the access isn't clear the data retention isn't clear and I think that that was a that was a huge topic like data security how do you know how long not just the prompt but any file that you upload for it to process and the response you know how do you know how long any of that stuff is sticking around and where it it's going to be sticking around is it where it's living exactly like do they put it off to like a giant storage center somewhere it just sits there for indefinitely or you know or not and it's and it's like there's all these things to understand. It's like we I think as a as a universe I guess or or space it's like we I don't think most I'd say that most enterprises are not great at data enterprise data security and understanding where all their data isn't having great controls around it. So then you introduce AI that comes in and it can touch all that data at the same time like almost instantaneously and it's like I was just thinking that yeah made that challenge even you know harder or scarier.

SPEAKER_00

Yeah we went from shadow IT right to shadow ai you know that's a real term like you know too it's like you know I think uh yeah yeah and I mean in that that reach is is really almost scary sometimes to use AI because I don't know about about you Rob or or Jason but it's like I you know I used to use this the that search bar at the top of SharePoint when I'm trying to find something and trying to find that right word but now it's like I just ask Copilot it scrapes it oh were you talking about this maybe this this looks like this and it's it's like holy cow it can access everything that I can access yeah in SharePoint.

SPEAKER_02

Well and you know what what I find interesting like just think about that you know now fundamentally the LLMs are learning about everything we do and the way that we've done it for you know years um and you know are the AI companies the especially the um the frontier labs are are they gonna end up with all of the expertise across all these industries intellectual property um yeah I mean it it's it's really interesting and then you know what are the ethics around them using that or or you know how are they gonna um how's that gonna go?

SPEAKER_03

Yeah I I think that that's a huge uh that's a huge area of concern because I mean look I think one of the worries out there I'm sure you guys have heard talked about is like AI replacing humans uh in certain jobs certain roles and you see things out there like I think it's it's no secret that Meta is putting you know training onto all their all their employees PCs to like train on like hey what are you doing? So it's like you think of the Bobs coming and like what would you say you do here? Exactly on your workstation you know it's exactly what I do here and it's and it's like a little sort of uh you know concerning like dystopian future there and like we're we're in that space now it's like you and and it's like I can't even remember now like I've seen these things with like you know people in uh you know putting together garments in these uh sweatshops and it's like they're they're you know doing this and they have like things on their hands to track the movement so that a robot can potentially do that in the future. Wow. And it's like well look I mean I think it might be good if people didn't have to work in in like tough conditions and with your hands like all all day long you know and have a better life but it's like well what are the you know is is that a promise up there like all this the work gets taken over that hey we're all actually uh uh everyone it's gonna improve like general human life like it's kind of the it's it's the scary topic like all right where what gets replaced but like you know I like to look at it as like hey ai should be able to enhance what we're doing and like that's the kind of you know the it's a tool.

SPEAKER_02

I I I tend to fall down on that side of things as well. Um because you know to me this is a continuum right and these same conversations were were had when you know agriculture was mechanized, right? The same conversations were had when uh you know probably when the wheel was invented I don't know. But um you know more recently um the age of computing the age of cloud computing I remember the angst uh uh when cloud computing came out of of people who literally didn't want to even get anywhere near it because they were scared of it they felt like it was going to take their jobs because they had been racking and stacking hardware for the last 20 years or they knew right right yeah so you know but is it really a continuum is is the other the flip side of that right because this feels like it might be different. It feels like we might be at some kind of um what do you call it like a like a like a quantum leap kind of event where you know this this one is going to be fundamentally uh more um and I've seen people fall in both camps and people who are leaning into AI fall into both camps like the uh the the guy that founded um asked age like he's he's got a book called replacement um out and he uh he's drilling it all the time like there's gonna be an apocalypse of jobs um you know Elon Musk like he did I have to say musk uh he he's come come down on the side of yeah there's gonna be like a mass apocalypse of jobs lost and replaced by machines and AI but at the same time he's like actually life's gonna be better because work's gonna be optional like we're gonna figure this out um like that like that's his thing and then you've got like the scale the guy that founded scale AI like I was watching a podcast uh that he was on um a while this was a while back a few months ago but he was um you know his thinking is is yeah look at all look at all this the things that I can do now that I couldn't do a year ago uh because of you know he he's figured out um you know using AI for coding is a big part of what he what he does and and they're transforming industries right by leveraging AI in different verticals but um but he's fallen down on this side of you know this is gonna make um this is just gonna open so many more new markets right and there's gonna be so many more products and services available uh in the future which is kind of what happened with computing you know like like there wasn't such a thing as a software developer before computing came around but everyone thought that well computing is gonna we're not gonna need the secretaries and the accountants uh because of spreadsheets and you know all that kind of stuff so it's just I I I I tend to lead into the more hopeful um that this is gonna improve life yeah I mean I I think it's uh you know I I think it's tough because it's like you see the you know the the change is and change is scary and like I think you said sort of this this convergence of things like I see that it's sort of the intelligence converging with like you know what robots could do now.

SPEAKER_03

You know that you know if you go back 50 years we didn't have the same type of lightweight materials and batteries and things like that and that stuff is getting better and you see robots that you know they're instead of one increment this is like this is like two increments right at the same time. Yeah and if you're scared of two increments just throw quantum in there and then you can be more concerned or less like there might be nothing there but I don't know I always said this theory if you put all three things together that that's that's gonna be something interesting.

SPEAKER_00

So it's like quickly right yeah change to the third power yeah so I know a lot of our conversation and rightfully so has been really been focused on AI and the impact to to RSA and you know what we've seen across the industry as a whole. But I guess kind of specific to RSA and I don't know if I even asked you this last time but like you know um you're a company that is known for security right so like what does good security culture look like in a company that basically sells security right like you guys are you know what is it your slogan is securing the most secure right um so what is that you know what does that culture look like is there more pressure or does does it come naturally yeah I I think it's a bit of both I mean what what's really helpful is you have that backdrop.

SPEAKER_03

I mean we've we've been a cybersecurity company for 44 years like the oldest cybersecurity company out there and um you know with that lineage and that and that backdrop you know there's an expectation and I think that you know a lot of people stick around here you know because because of that because it's like hey you know these guys take security seriously but we also bring in new people that don't have you know that backdrop but I think it's sort of like getting them integrated into the culture and kind of keeping that like keeping that expectation so you know like a lot of places we do an annual security awareness training I'm aware training ramp program we have and you know they check on things like that. But also you know I think it's important to just you know make it part of just the daily life and the expectation that like hey look you're you know you are part of our security program as an employee you know you can actually take actions if you're not being responsible that can harm our security and like we we're depending on you. It's not just like hey as a security department all right you're 10% of this this employee base. So you guys have all that responsibility it's like no the responsibility is really with everyone um and that's I think the culture that that helps drive that. So we have this excellent backdrop so we have an advantage there but you still have to do that care and feeding of like okay let's make sure we cover it in the training the onboarding processes the um you know that I'm sending something out regularly to the company that you know we have um the right types of meetings like we had a water cooler on AI not too long ago to just kind of get people's thoughts going is pretty well attended one um so it's it's things like that and you know I I do travel to our global offices on a somewhat regular basis and I try to talk to the people on there just like hey look we're available you know reach out to us like it we don't have to be I think some people think of security like some things like sometimes it's a a blocker and sometimes people think of it as something scary like if I talk to these people I'll get in trouble and it's we don't want to be really of those things. You know we want the right guardrails so you can you know want to be the control so you can drive the car faster. We'll help like be the anti-lop brakes you know so you can drive faster comfortably you know we also want to be the um you know the you know not something scary but like like you can bring uh even a a minor concern to us be like hey I need guidance on this thing because I'm not sure this looks right and we're like okay well we might you know let us kind of take a look at that and see what we think of it. You know I had a couple of them after our training a couple of those came out uh the week after like hey I just went through the training I had this in mind and like I wanted your guidance on this and I think that you know they the two things I'm thinking weren't huge things but it was good that they kind of you know folks in the team like just brought stuff up and said hey like let's make sure that this is okay uh that we're seeing this and how we're doing this you know are we following the right approach so um it helps to have a nice security backdrop but I think everybody's got to do work on that culture like it's not like we don't have to do work on it I'll say that like it is something that we have to think about.

SPEAKER_00

One of the things and Rob if you if if I'm saying something that you want us to cut out of the podcast let me know. But if uh like you guys had integrated an AI module in your security awareness training and to me that was you know I haven't seen that a lot in a lot of other companies security awareness training yet I'm sure it's coming but just like the appropriate use. So I mean that just I mean to me showed how much you were leaning into realizing and and teaching people what an appropriate use of AI is. And I mean it impacted me to a point I I said hey Jason this is a module that uh that RSA is doing um I I I think I should be encouraging others to be doing the the the same thing.

SPEAKER_03

I I'd agree like it's really important to like stay ahead of those trends if you can because look I mean it depending on your source of training material um you know that may get refreshed faster or more slowly based on your vendor is if you make it internally but I mean that's something to go push back on that vendor or that group and be like hey we need we need some guidance around AI and like look even if it's me doing a five minute you know little video and they have to hit play on it fine but to get that guidance I think is really important. Like if it's like one of the things also I think our customers would expect and asked about just like they would ask about hey do you have a training not just on security awareness but on data and privacy they want to know that we're following all those regulations we're thinking about those things like AI would be another one and as we've talked about in most of the segments like yeah it's hard to control some aspects of AI like it's a huge uh let's see uh like a huge um uh risk surface a a a huge you know shadow AI is is a real thing and you know a can a technology that most of your employees They're using, uh, and we're expecting them to get all those contacts correct, you know, because we might, as a whole, might not have every control in place properly to deal with all these new contacts right away.

SPEAKER_00

Um how you could, it's always evolving and changing, right? So right, right.

SPEAKER_03

And that's the fun and and challenge of like being in a security team. But also it's like, you know, it's especially challenging now with AI and like you know how ubiquitous it's become on everyone's devices and expectations of use of it and how right everyone can use it to innovate because hey, if you know if there are statistics out there, if people are companies are using AI well, they are um you know uh making it better news faster and you know, scaling better.

SPEAKER_02

Um ultimately, yeah, everyone's worried about being out competed and based on the advantages of use, right? That that was a real big tension for us, Rob, like in our thinking through like how do we need to communicate to our employees about appropriate use of AI. You know, we don't number one, we the way that it ended up, we almost came down more on championing the use of AI and less about the um the um I guess what more of a negative view of it or more of a here's all the don'ts. We were like, well, here's all the do's is sort of the way that we came down. Um just just due to the same concern, right? But the last thing that we wanted to do was stifle um our yeah, yeah, because uh there's already a stifling effect over you know some people within the organization, right? They're already um have opinions on it, maybe they're they're afraid of it, they're afraid of you know what it means to their job, all those things. And we've been trying to tell people that like like look, you know, I I don't think that we're not looking to to lose anybody. We're looking to up productivity so we remain competitive.

SPEAKER_03

And and I think that that's the key thing to keep in mind, and like, you know, I think you know, you do have to consider what people's worries are and that. Like I know that like in our internal Slack, just you know, I posted something about some headline, and someone was like, hey, you know, uh, you might be worrying developers that like, you know, this headline's talking about maybe you know more code and you know taking over jobs. And it's like, hmm, yeah, and you know, I should probably like think about that when I'm messaging uh and be careful with that type of thing so that you know I didn't think I don't know it was necessarily like a huge, you know, it wasn't so uh extreme in that case, but like there is a little nuance there, like hey, you know, I got some feedback and I was like, oh I'll I'll think about that. You know, I'll take that into my messaging because people are sensitive about AI and jobs, and like I think we try to push ahead of like making it a uh you know, force multiplier is something I hear a lot. And it's like, but you know, might be cliche, but it's like, yeah, if if you're doing it right, it can be. And I think that there's there'll always be a debate about like, hey, is it the right thing in a particular use case? Just like there was a debate with cloud, like, we put all that stuff in the cloud, but we we have a whole data center team and they're really good and efficient, and it's like we do heavy compute and the cloud's gonna be this much more expensive. Like, okay, maybe it does make sense to keep that workload in your data center if if that's part of your core business function. But if it's not, and you're just like, we're struggling to keep you know these uh you know data center folks employed, and like they just you know, it's hard that these is too much volume, and like that's not our core business. It's like, okay, maybe that does make sense to be in that cloud. So I think we're going through a lot of the same thing with with AI now, and some people are gonna have great experiences, and some people are gonna have terrible experiences. Like it just try to take care as you're doing it, you know. And go.

SPEAKER_01

Yep.

SPEAKER_02

Yeah, I think um it's funny that you mentioned the uh the data center um example because I remember it was just only a few years ago. This was really common. There was all these stories about uh, you know, hey, we we migrated everything to cloud, but then we migrated everything back. Um and you know, there was story after story about that, like kind of down on cloud, and cloud is more expensive than we thought. I haven't heard of about anything like that in the past two almost two years. I haven't seen an article like that because now it's like everyone's scrambling to get their data back in the cloud so that it's close to the frontier model.

SPEAKER_00

Well, because nobody can buy servers because the AI data's like and servers are like you can't even find chips anymore.

SPEAKER_03

Or I mean I I could have a take on that. Like I think of a shrinking sine wave where it's like you know, you go extreme one way and then the other way, and like you end up towards like here's where things like people now found like most of the time the right spot for that workload, that function, whether it's spiritual cloud, and we've been like, all right, we see both, and now we have the right decision process around which one it should be. So the new things we pick where it should go, you know.

SPEAKER_02

It's it's it's almost like the hype cycle just playing out, you know, and and dying down to a steady state. But yeah, yeah.

SPEAKER_00

I do have one more question. We have three minutes left. All right. And this question is if you could rewrite if I can speak.

SPEAKER_02

Are you like perfectly timing this, Mike?

SPEAKER_00

I'm not perfectly timing this. I'm sorry. If you could rewrite or change one thing about how the federal government uh approaches vendor security authorizations, what would that be?

SPEAKER_01

Vender security authorizations.

SPEAKER_03

Um ATO type of thing.

SPEAKER_02

Are you talking about the FedRAM?

SPEAKER_03

Yeah. Okay. Yeah, yeah. Um look, I I think well look, I I think I think it's an easy one. I I'd say in the FedRAMP base, like, what would I change? Like, I I want to make sure that the agencies that are working with um all the FedRamp enabled services have the time and and the capability to you know be an easy, like easily deliver an ATO, and that they have confidence to do that. Um, and that I think that there's definitely a feel like with some of them where it's like they might not have the capability as well, might not be familiar with it, and they might feel like, if I sign this thing, like what am I signing, right? What am I gonna be held responsible for here? And it's like I think that's where like, hey, if if you're using FedRamp services, like I think you need that comp that comfort, that discipline. So if like if I can kind of rewrite that, I'd try to do it in a way that gives some space for that. That's you know, maybe just make that easier, easier.

SPEAKER_02

Yeah. I think so, in other words, where's my ATO letters?

unknown

Exactly.

SPEAKER_03

It's it's it's like for a lot of agencies, you know, and I get it, like not everyone's gonna be an expert or be comfortable with like um measuring an entire security program going through a con mod, but maybe that's where like to kind of have a little reciprocity, or they, you know, where you can all right, we're gonna align with maybe this bigger agency to do these in more volume and and you know, get it more uh down to a simple science.

SPEAKER_02

Yeah. And I think that that's where the you know earlier I was talking about the trust thing with with three PAOs, you know, that they were supposed to be the ones that made the recommendation. But that never I mean, to your point, that really never worked, right? Because nobody accepted the recommendation at face value. If they would have, then it wouldn't be hard to sign the ATO letter, right? But I think that there's this idea of Physma jail that's still out there. Like if I sign that and something happens, I'm gonna go to Physma jail. Um, and you know, I guess it's debatable. I think, I think, you know, some things have happened, but I I just don't I don't think that that's been a common occurrence. If anything, you might end end up in a um a GAO a GAO report or something like that. Um but those things, I don't know. They could be corrected, it feels like. But I've seen this so many times, Rob, and and it's not just yeah, it's not just uh something that's impacted y'all. It's been impacted the whole industry. I think I do think that 20x is kind of I'm sorry.

SPEAKER_03

I was gonna say there's not really any enforcement if you don't do an aggrantio while you're using something in a certain period of time. Um and I don't think that should be a GAO fine. Great. I don't need I don't think it needs to be a harsh enforcement, but just like the expectation that like if you're using this, you have to do it within a time and and develop your program so that that's possible, even if you are relying on maybe a larger org that you're part of that is more experienced at that type of review.

SPEAKER_01

Yeah, yeah.

SPEAKER_02

And the cool thing that's going on right now is I I think that 20x 20x hasn't exactly solved this, but I think that it's uh it's set the stage for a showdown to force the issue to be dealt with, right? Because, you know, now you're gonna be able to get into the marketplace at class A, B, or C um and basically be able to be there for two years, be able to sell. Um, and you know, what's gonna happen if if these products are used either by federal agencies or or used by third parties, even like we've got customers that that now have a pathway to to get into the FedRAMP marketplace as certified, right? Um, that may never get a FSMA authorization from that or a FSMA ATO off of that, right? Um and it's because they they don't really sell to federal, but they need to be they need to be authorized because they service the the Dib uh for on the CMMC side and and or uh you know other other FedRAMP um CSPs. So, you know, it what's gonna happen two years and you've sold a lot into you know the DIB and into and what they're gonna remove you, they're gonna they're gonna bunt your certification. You know, it's it's gonna there's gonna be a showdown, yeah. And I have a feeling that it's gonna set the stage for a solution uh to the issue. Otherwise, I think there's gonna be a reckoning or a a wrecking.

SPEAKER_03

Yeah, yeah, and look, uh, you know, it I think it makes it harder for new technologies to come into the space and new vendors. And if you want it to be a competitive space, which I think like most people, you know, in the US, like, hey, competition is good, it's like, you know, how do we encourage that and and keep that you know level playing field? And it's like if it's that hard to get one and only the bigger players can come in and like get it early, and and then they don't have to worry about it, and then the smaller players trying to come in, like, I can't get it. Like, what how does it really take a long time and it's hard? You know, it's a huge barrier to entry for new folks going into FedRamp spaces.

SPEAKER_02

It is. There's this new thing that that's been happening for a few years. These these um, it's basically they're platform companies a lot like us, uh, but they they're managing to get an authorization directly with an agency or with DOD. And now they're just taking that authorization and they're just absorbing new customers, new software kind of into that ATO and then repeating that, right? And yeah, it has, I don't know, I've seen uh several do this. I think some are doing it the right way, maybe others are are uh being a bit more of a rubber stamp or they're kind of skirting the rules a little bit, it feels like I'm I don't I don't know all the detail. It just feels like it. I'm not saying anything. Um, but you know, I think we're I think the government's just fooling themselves by doing that, by by letting that go on. It's like, okay, you got 10 products under one label now. Like how much risk are you grouping together, you know? Yeah, anyway. Well, talked about shadow AI. Is this shadow FedRamp?

SPEAKER_03

Shadow FedRamp, love it. And it's like what you're saying, it's like it's actually easier to buy a company than it is to get FedRamp certified. Like, is uh you know, like, okay, uh this company is like all right, I just that's the business model of some of these companies that are doing this. My company and and now I'll be certified. Like wow, or the intent of the certification. Like, that's that's a little much.

SPEAKER_02

Right. Yeah, and it's it's a workaround, it's cute, but I don't know if I would want my my business model propped up against that. Um anyway.

SPEAKER_03

Yeah, and and does that bring us the best security, you know?

SPEAKER_02

That's the well it's it's definitely not doesn't bring the best transparency. I mean, they might be doing the right things behind the scenes, but no, that's fair.

SPEAKER_00

All right. Well, Rob, I appreciate you joining us again for round two of Behind the Shield.

SPEAKER_02

You're being formal. I'm being formal.

SPEAKER_00

Well, we're just supposed to end.

SPEAKER_02

Caitlin just wants us to end.

SPEAKER_00

Caitlin just wants us to end. I like that.

SPEAKER_02

I like just ending.

SPEAKER_00

Bye, Rob.

SPEAKER_02

Trying to be funny.

SPEAKER_00

You make it sound like I just want it to end. Like, please stop talking.

SPEAKER_02

Oh, I didn't mean it like that. I mean that was not what I meant. No, I did it. And it's over. Like, yeah.

SPEAKER_00

Yeah, we are a little bit over, so I appreciate you joining us and being willing to stay a little bit over. So um all right. Great time. Hopefully, we'll have you back again soon. Yeah, look forward to it.

SPEAKER_02

Yeah, this this was a great one.

SPEAKER_01

Yep, love it. Really enjoyed it. Thanks, Rob. Same here. See you guys.