Jeremy Snyder sits down with industry analyst Richard Stiennon, founder of IT-Harvest and author of the annual Security Yearbook, for a tour of the cybersecurity industry from the inside.

Jeremy Snyder sits down with industry analyst Richard Stiennon, founder of IT-Harvest and author of the annual Security Yearbook, for a tour of the cybersecurity industry from the inside. Richard has been tracking this space for more than twenty-five years, and he takes us from the days when a firewall and antivirus were the whole security stack, through the Windows NT and VMware era, and into a present he describes bluntly: the most important new threat actor is not a human, it is "an alien of our own making." Along the way the two get into why Microsoft built the security industry by accident, why nobody actually pays for more security, why network segmentation is still undone after three decades, and why Richard is 99% excited and 1% ready to move to the country and trap rabbits.
Key Discussion Points
About Richard Stiennon
Richard has tracked the cybersecurity industry for over two decades — as VP of Research at Gartner, CMO at Fortinet, and the author of 14+ books, including the annual Security Yearbook. IT-Harvest puts that career of research into a platform anyone can use.
Episode Links
https://it-harvest.com/https://stiennon.substack.com/richard’s
https://www.amazon.com/stores/author/B003L5VNJ8?ccs_id=3d5ab76e-1f39-4401-a94a-ccf703da9d07and
https://www.amazon.com/Guardians-Machine-Age-Security-Digital-ebook
Jeremy Snyder: All right. Welcome back to another episode of Modern Cyber. I've got a real treat lined up today for both myself and for our audience, because we are going to get a chance to talk to somebody who's been watching the cyber industry longer than probably a lot of people that you will meet in your regular day to day lives. I'm delighted to be joined today by Richard Stiennon, and if that name sounds familiar, it should. Richard has been analyzing the cybersecurity industry for a long, long time. Richard and I, you know, I don't mean to age you, but you, you know, you've spent time as a VP of research at Gartner, CMO at Fortinet. You've written fourteen plus books, including the annual Security Yearbook. How many years have you been putting the Security Yearbook out now?
Richard Stiennon: Uh, six years.
Jeremy Snyder: Six years. So I think that viewpoint that you have over at IT-Harvest really puts you in a unique position to comment not only on where we've been, not only on where we are today, but on where we're going. And for all of that, I'm really excited to get in today's conversation. Thank you so much for taking the time to join us today on Modern Cyber.
Richard Stiennon: I appreciate that. Thank you, Jeremy.
Jeremy Snyder: Awesome. I want to start actually at the beginning. How did you get into this, both into the industry and then kind of, I guess, transitioning out of, let's say, a role like Fortinet and then into an analyst role. What was that journey like?
Richard Stiennon: Yeah. So it started with, um, my kind of transition out of automotive industry. So as aerospace engineer, I went to school in Ann Arbor and was a structural analyst. Uh, so designing car seats and crashworthiness testing, all that stuff. Um, and I had my own firm called virtual engineering, and along came the internet. So, which I'm proud to say I discovered, uh, I think, uh, a year and a half before Bill Gates even heard the word internet. Um, and the internet was just mind blowing to me. I recognized it immediately for the powerful thing it was, kind of dropped everything and started an ISP here in Michigan called RustNet. Okay. And that was probably the fastest and steepest learning curve I ever went up. Right. Because I had to learn all of networking in a very short time. About twelve months, it felt like. And luckily I had, you know, people tutoring me kind of from the networking world. Um, and, but then my company RustNet was stolen from me and I found myself in need of a job. So I went to one of the other ISPs in Michigan called Netrexx that was specialized in security. They were like a Check Point and Cisco reseller that had started an ISP based on my business plan. So they welcomed me with open arms. And that was the first time I got really exposed to security and selling. And I sold firewalls to Tank Automotive Command, Ford Motor, you know, all the automotive suppliers. Um, and then, but I was a horrible salesperson and I don't like cold calling. Never have. And so I look for something else to do. And I joined PwC as a pen tester, essentially, back in the day when they, and typical engagement, they charged ninety thousand dollars for. Wow. And it'd be a bunch of us with just, you know, like a team would descend on them, and we'd have outside hackers and inside hackers, um, doing, you know, essentially audits on the inside. And that gave me the exposure to security at large enterprise. Right. Because it's, you know, I hacked into BNSF railroad, um, hacked into Dell computer. Uh, so great, great exposure. And I ran the firewall lab for PwC. And so when all of a sudden I got this call from a headhunter to interview at Gartner. That I remember that I only knew about Gartner because they had something called Dataquest that they had acquired in ninety five. Um, Dataquest was this awesome marketing information feed that would be streamed to every PwC Lotus Notes desktop app. So it was, you know, um, anyways, super addicting. And so I get to Gartner, and that was two thousand, so twenty six years I've really been an industry analyst. Um, and that transition was fast. I mean, it took only a few weeks for me to be as busy as only other analysts covering security was John Pescatore. Yep. And, uh, it was just a whirlwind four years of, uh, you know, working with enterprises and answering questions about security during that critical time from two thousand to two thousand and four, when the industry kind of came into its own. Yeah. Um, but I got bored. And you have to know, like, you know, that I've started an ISP, I started an engineering company, but I've actually started twenty six companies. So I get bored very easily. And yeah. And convinced myself that it'd be more fun to do this stupid startup. Um, not good for marital relationships, I can tell you that. And hard on the family on top of that. Um, so, so I left and I joined, uh, Webroot software. And, oh, yeah, uh, you know, Webroot had the potential to be a great thing. Um, after about a year and a half of missing the mark, I realized they weren't going to go public anytime soon. And, uh, of course, I went off to start my own thing again, which was IT-Harvest. And IT-Harvest was meant to, uh, you know, recreate what Gartner had with Dataquest, but for cybersecurity. And that's what I've been working on ever since.
Jeremy Snyder: Fantastic. It's really interesting. I mean, I think back to some of the beginning of that journey. I started my own career in kind of IT and cybersecurity. And I always tell people back then they were one and the same. There was no real separation of duties between, you know, IT infrastructure, networking, etc., and cybersecurity. You had to do it all. You know, there was no specialization in this function. But, you know, when I started in ninety eight and I started again, really kind of core practitioner, build out data centers, office networks, file servers, all of that. All we really had from a security perspective was kind of two threats that most organizations were looking at. One was, you know, got to keep bad guys out of your network. So you need a firewall. And the other was viruses, and viruses you primarily worried about from the email perspective and, you know, malicious attachments. And that's how it was for a number of years there, it seemed like. And it was really kind of in that, I'd say, early two thousand time frame that we started to get a little bit more hip to web applications. And some of the work you would have been doing at PwC doing, you know, early pen testing, because there was probably a very small percentage of companies that realized that if you were putting out a kind of customer facing web application, whether it's for order processing or customer support or whatever the case may be, you've got some sensitive data behind it. And, you know, you'll probably also remember it took a while for it to be really a popular trend. You know, even in the early internet, customer support, the thing that you had on your website was very often an email address and a phone number for your customers to get in touch with you. Right. And it was a whole evolution. So I'm really curious from that early threat time period. And let's say like, again, email, firewall, early web applications. What was the next thing that you saw where you were like, oh, this is actually going to be the next big security problem?
Richard Stiennon: Yeah. You know, so I always look at the threats as they develop, right? So cyber crime was the next one, right? Okay. Uh, it was when the Russian Business Network, who were apparently holdover from KGB days, you know, going into business for themselves. Um, but when they, uh, automated and created a multi-tiered system to allow people to create Trojan horses and spread them and capture, uh, credentials from them, and people were using that for, you know, stealing banking information, etc. So that was the next big thing. And that, you know, we, of course, in the industry, the existing vendors evolve to meet the new threats. And credential stealers were something that the antivirus vendors took on, you know, that was their, you know, it was injected new blood into them. And you were right, in that time frame, all the antivirus vendors started in the nineties, as did all the firewall vendors. And they all started as PC tools, right? So they would have a disk cleanup utility. They'd have McAfee, or Network Associates as it was called back then. I think they own, act, you know, so a CRM solution. Yeah. And a bunch of other stuff. And it took that, the mid two thousand, for them to realize that security is where it's happening. And, yeah, get rid of the rest of their stuff. And McAfee actually, or Network Associates actually asked for my input on what to get rid of, and then what to acquire afterwards to fill out their security portfolio. Yeah. So, uh, so we went from, you know, we went to cybercrime fairly quickly. But at the same time, the other threat happening was worms spreading. The authors of the worms were, uh, you know, like today's hackers, they're doing things kind of just for fun. Let's see what happens if we do this, right. And obviously, William Tappan Morris, the creator of the Morris Worm earlier than the two thousand, um, was just curious. Right. And just wanted to see what happened. Wouldn't this be cool if I took down all the Linux servers on the, you know, pre-internet. But the worm creators of SQL Slammer, uh, ILOVEYOU, you know, all these things that spread like wildfire, uh, led to the next evolution of network security, right? Because you got, now we got to stop these things from getting into our corporate network over the network. That led to needing more powerful network devices. Firewalls, you know, were pretty much just iptables running on a fast server. They had to be updated with the ability to, you know, see what's going on. SYN floods for DDoS and, yeah, worms. Yeah, yeah.
Jeremy Snyder: I want to ask one more question about this era before we get into kind of where we are today. So you mentioned that you heard of the internet before Bill Gates. And Microsoft was kind of famously at the time a little bit behind on the internet. You know, they were not one of the first companies to realize its potential. And, you know, there was a series of memos around that time that finally got out there. And I always thought it was kind of interesting from two perspectives. Number one was that, you know, the Windows desktop market share back then was so much higher than it is today. And I know Windows is still kind of the dominant operating system. But I think, you know, we were at a point where Mac was down to single digit percentage. Oh yeah. Um, you know, desktop penetration for average office workers, and Linux was zero on the desktop side, right? It was early Linux servers even at that point in time. Right. But with all that, you know, when I think about these worms, and I think about the early malware and viruses and so on, so many of them were primarily enabled by Windows and flaws within the Windows operating system. And there's a part of me that feels like not much has changed between then and today on the Windows operating system. What's your view on that?
Richard Stiennon: Yeah, I view, and I used to have this feeling all the time, I'd walk around the RSA Conference, I'd see all these vendors and this huge space that had been created solely to solve a problem that Microsoft created. So Microsoft created the entire security industry. That's why it pisses me off when I see Microsoft reporting that they have twenty billion in security sales. They have no right to sell into a market that they cause. They didn't create it. They caused it to happen. Um, yeah. So, but luckily, you know, markets tend to cure themselves. And the biggest problem to me was, and of course, you know, I was swayed by being a Sun Microsystems, you know, reseller. Yeah. So I literally was there in the room when I quote, you know, a Sun Netra to run somebody's web server, and they go, six thousand dollars for a server, I can buy three Windows NT boxes and hire a high school graduate to manage it because it's all Windows, right? Yeah. The widgets. Yeah. Um, which is a little offensive to anybody who's a system administrator, right. As you know, and it's easy to offend Unix system administrators. Um, they, it was the CIO's fault. And back then, as you remember, uh, MIS departments, management information system, actually reported to the CFO.
Jeremy Snyder: The CFO. Yeah, for some reason I had that at two of my jobs along the way where I ran IT, I rolled up into finance.
Richard Stiennon: Yep. Exactly. Because finance was the buyer of computers, you know, and we were just a cost center. We were not a strategic asset to the business that enabled, you know, operations.
Jeremy Snyder: We were just an infrastructure cost, like facilities.
Richard Stiennon: Exactly. So, um, and they decided, hey, you know what? Uh, it's stupid to have all these different operating systems. At one point, you know, my favorite one was IRIX from Silicon Graphics. But every, you know, there were a dozen flavors of Unix for, you know, CAD workstations, for business workstations, for whatever. Um, the idea was that you should standardize your OS, and that will save you all this money because you buy it all from one place. And of course, that gave rise to the—
Jeremy Snyder: Yes. It's one throat to choke, gives you control, you know, a better voice with the seller, but it's also vendor lock in completely.
Richard Stiennon: And it took a decade to break Windows NT's stranglehold on the server market, because that's, you know, one of the things easy to see in retrospect, it's completely insane to have a single user system act as a server. That's why you ended up with, yes, it was cheaper to buy Windows NT machine, but you needed a single Windows NT machine to run network time protocol because no Windows machine could do two things at once. Unlike Unix, which is a multi-user system based on mainframes. So, so we ended up with huge data centers with huge racks in them of Dell or HP equipment, all running Windows, Windows, Windows, Windows, and as a reagent cost to do that. And the thing that cured that problem was VMware. And that's why VMware, like, overnight became an eighty billion dollars company, is because it allowed you to run multiple versions of Windows on a single server.
Jeremy Snyder: Yeah. So yeah, yeah, yeah. It's funny. I mean, it's a little bit of nostalgia and memory lane as you're talking there. I mean, I built, I had this conversation earlier this week with somebody about the difference in the way that I built data centers. And then one of the data centers I was in, Google moved in while I was there. And it was just this complete, like, mind changing experience watching what their build out looked like versus ours, because we built like everybody else, you know, seven height unit, in our case, Compaq servers, by the way, who was later acquired by HP. But, you know, we were very hardcore about our love for Compaq hardware. But, you know, these seven height unit, for nineteen inch rack mounted servers that typically ran at five percent utilization. And, you know, the other ninety five percent of their CPU capacity was sitting there wasted, you know, just causing heat that's being offset by air conditioning. And meanwhile, in the, you know, Northern Virginia summers where it's eighty plus degrees and eighty plus percent humidity out, I'm driving around with a sweatshirt in my car if I have to go into the data center, and it's just like bonkers. And then Google rolled in, and, you know, they were one hundred percent Linux based, and they really had a fleet mentality. And they didn't care that five percent of the machines on a rack didn't, you know, didn't light up green. You know, it didn't matter as long as the fleet was healthy and it could keep serving. Now, mind you, at the time, Google was really only serving Google.com. So they had a single application that had to run. But it was a real mind shift, to your point, like all the everything around the ecosystem at that time was, as Werner Vogels from AWS likes to say, it was very much pets, not cattle. And, you know, you name your pets, you love them, you take care of them, you nurture them. Whereas your cattle, you number them and you just make sure that you have enough and that they're giving you what you need out of it. So yeah. Yeah, a lot of change in the IT infrastructure and the way that we operate and so on. So love hearing your perspective on that. Fast forward to where we are today. I mean, from those early days, from those early threats of, you know, worms and viruses in email and break into your network, etc., to where we are today. I mean, it seems like the constant threads are, okay, people still try to break into networks. We don't see much in the way of, you know, email based worms anymore. I know they're not nonexistent. I know there are still people who send, you know, infected files around at volume using spam servers and things like that. But that's not typically, you know, the main kind of cyber incidents that we hear about anymore today. And now we have this quote unquote era of AI that we're in. What do you think about as being the most prominent and real threats today?
Richard Stiennon: Yeah. So, um, first of all, we still have nation state actors that are the prominent threat actors that we have to worry about, most of us. Uh, well, I don't know if I can say most of us, but look at, um, if you're a victim of ransomware, it's because you've under-invested in cybersecurity. You know, I don't like to victim blame, but I am victim blaming, right? It's, you are identifying yourself to the world that you did security poorly, right? Everybody who's not in the newspapers for ransomware, they're doing an okay job. So, um, that's great. Except that, um, APTs from, you know, Russia, China, etc. can do damage. Even Iran lately has been doing damage here in Michigan to our water systems. So those threats are there. And I always try and look ahead, because I've discovered, you know, years ago, that if you create a hierarchy of threats, there's always one above where you're at today. And if today, you know, the threat is nation states engaging in cyber war, what could possibly be worse than that? And I remember the first time I posed that question to myself, I said, well, it has to be aliens, right? So aliens are going to send us transmission signals, we're going to get infected, and they'll do something. Facetiously, obviously. Um, right. But when you think about it, post Hugging Face, the new threat actor is not a human. It's an alien of our own making, mind you. Um, and it doesn't have to be, you know, the like OpenAI and the rest of them, you know, indicating that they have AIs that have broken out of their sandboxes and, and, you know, gone after their goals in such a way that they had to hack. Um, it could also be threat actors, China, targeting infrastructure and government agencies in Taiwan, which also happened in July, using AI to assist them. Right. It's just a Claude agent set up. And, you know, they're not Claude, they're Kimi or one of the other ones. And they're executing these attacks. And it goes so far beyond persistence, right? Because it's, they, as anybody who knows, if you've asked AI to create, you know, help me understand this space. Yeah, it gives you a complete essay, right? Doesn't leave anything out. And, yeah, you know, that's one thing. That's where it's different from me, right? I just, I want to get to the point, and I miss half the points I should make in the interest of getting to the point that I initially had when I'm writing. An AI just covers it all. And, yeah, same with its attack methodologies. It just keeps going until it gets what it needs. And then it drops everything, moves on to the next thing. So if you can harness that power as an attacker, uh, that is the future of attack. It's gotten me, I've picked up on this at Black Hat. So Black Hat was only about a month ago, right? And I came away from it thinking, wow, there's such a buzz this year. And last year there was a buzz because everybody was talking about AI last year. This year there's a buzz. Yes, AI is part of it, but the thing that had changed was Hugging Face. And, yeah, and the reason that the industry is buzzing over it is that there's a new kid on the block. Every time there's a new threat actor, the industry has a surge in buying of their products. Yeah, yeah. You don't have to have anti-AI products, you, because in order to counter Hugging Face and or the attacks on Hugging Face and, uh, anything that AI does, you just have to do security really, really well, much better than we've ever done it before, right? If there's a way to chain vulnerabilities together to get in and get the target, it will be there. Go find it. Right? Yeah. So that's, so obviously, you know, we can't harden ourselves perfectly, so we have to do detection and response perfectly in order to avoid this. And that means network segmentation, you know, all the things, you know, strong authentication and all the things that you should have been buying already. Yeah.
Jeremy Snyder: So to that point, if I kind of take your previous analogy or your previous comment around organizations that are victims of ransomware, it's because they didn't do cybersecurity well. But if I think about, like, how we've typically done cybersecurity as a broader technology, and kind of as an economy, really, it's never been complete cybersecurity, or for very few organizations. It's always a kind of a balance of risk management. You kind of look at the organization, you do your kind of, let's say, your high level threat model of like, what are the things that could affect us? And then you do, I don't know if eighty twenty is the right way to think about it, but you eliminate the biggest threats at a cost effective way, or at least you try to mitigate them. Most organizations don't chase down everything.
Richard Stiennon: Yeah. Most organizations actually say, uh, will we end up on the front page if we succumb to this type of attack, or will we face prosecution from the SEC if we succumb to this kind of attack? So if you go to them and say, hey, look, we're going to deploy a virtual network of honeypots within your network, and it's going to give you this really good signal of attackers, uh, and then you'll be able to respond quickly, they'll go, nah, not buy that. Nobody else is doing it. It's not best practices. Gartner doesn't say I should do it. None of my competitors do it. I'm not doing it, right? So they, yeah, they turn away from better security. And I advise startups all the time. If you come to me and tell me you're more secure than CrowdStrike, you're going to fail. That nobody pays for more security. They don't want that. They want ease of use. They want cost savings, etc.
Jeremy Snyder: Yeah, yeah. Okay. So but if we take that as kind of accepted for where most organizations are, they want ease of use, they want cost savings, and they do look at, like, okay, what are my peers buying? What are the analysts telling me I need to buy, etc. Even that list is never complete, right? So like nobody has, let's say, complete security. But now you bring that into the current era where, to your point, our attacker is an alien, or maybe an alien plus an APT, right? Which is kind of a little bit of a scary combo to think about, you know, a little bit of human creativity and direction to something that is, uh, inexhaustible and will be, you know, one hundred percent thorough looking at everything. How should an organization today think about defense? Because part of what you're saying is, no, you never have been complete on security, but now you absolutely have to be complete on security. And that's really, really hard.
Richard Stiennon: Yeah, yeah. Um, so it does take some, uh, critical thinking, because you have to, instead of putting yourself in the mind of the attacker, which is kind of what we do when we're thinking about insider threats. We say, you know, somebody disgruntled, they're going to pull the plug on this. Um, and, you know, when we think of cybercrime and ransomware, oh, you know, gosh, we'll just back up all of our stuff and not have it connected to the network, and we'll back up from there and problem solved. Um, now you have to think about something that won't give up, as you do if you're battling APTs every day. So the ones, you know, the people in the defense industry and serve the defense industry, uh, are completely experienced with this, and they figured out how to counter teams of professionals who work nine to five and come to the office every day and just execute to get to their target. So they're best prepared for that, because that thinking is exactly what you need to counter an attack augmented by AI now. And that means, you know, yes, going to basics, um, break down what you're doing on the network. And, you know what, I don't have any numbers, but, um, there are so many vendors that have to push network segmentation over and over and over again. That kind of lets you know that nobody does it. Right? To calculate. Yeah. Oh my God. And it is, if you use Cisco to do it, it's extremely complicated, but it's getting better. Um, yeah. So you have to do network segmentation. You have to compartmentalize and realize that, you know, what, that AI is going to get to our HR system today. Yeah, but it's not going to get to our financial system, because the two are connected only by sneakernet. And now, yeah, AI will solve the sneakernet problem too, right? Because they get in your head and they can get you to do what they ask. But you have to think about those two. You need two people to, you know, authenticate, putting a thumb drive in, for instance. And you have to take the same approach for your desktop laptops, etc. It's like minimize the attack surface. We're no longer talking about increasing the cost for the attacker, uh, like we used to. Right. That was very, very effective. Attacker wouldn't want to spend one thousand dollars to get in. Um, but a threat actor and an AI, you know, might not have any cost to keep going. And even, you know, ridiculously, you know, made up exploit that nobody's ever thought of, that's worth millions of dollars, we might just do that on the fly and then throw it away. Yeah. You know, so, yeah, cost is not an issue anymore. So we can't fight back with that. Yeah. Yeah. Risk modeling is not going to help. It has to be threat modeling all the way. You have to consider that. Uh, so yeah, so you can see I'm excited by the world where everybody starts to think that way, right? Because it just makes our industry more valuable.
Jeremy Snyder: But it's funny, there's a couple of things in what you said that I want to dive into a little bit, because to your point about network segmentation, that concept has been around as long as I've been running networks, you know, and I did a TCP/IP course, the first switch, right? Yeah, exactly. You know, back in ninety eight when I started doing IT admin work and, you know, and then we rolled out probably the very first kind of lightweight version of network segmentation when we got our first set of Cisco firewalls and switches. And we did, you know, a public facing network, a DMZ, and an internal network. And even that, you know, we ran, the DMZ was the first network on the topology map where we had internal IP addressing and network address translation and port address translation and everything. And, you know, that was very much around the risk map, the more the risk map than anything else. And I won't say the threat map, because I don't think we had a solid understanding of the threats at that point. Right. Um, but, uh, but to your point, like, that's twenty eight years ago that I started working on IT. And to your point, like, it's still a thing that new companies get launched around and get funded around. And VCs see that there is a big addressable market on, because people don't do it, right? So there's still lots of organizations that need to. And it's crazy. You know, we started earlier this year, we started running a number of internal agents for various processes. We've actually, and I've spoken about this publicly, we replaced a couple of our SaaS vendors with homegrown tools because we just didn't feel like the price to value ratio was right. And we felt like, in particular one on that I've talked about is expense reporting. And we broke up with the vendor that we used over there. And I, you know, I happen to think they're a great victim of what Cory Doctorow has called enshittification, a formerly great service that has just gone tragically downhill as they went public. And, you know, it hasn't been successful. But, you know, we built our own in a day and a half, and it saves us a lot of money. And by the way, it's one hundred times faster. I did my expense report this morning, and something that used to take me an hour and a half a month now takes me five minutes, and it's better, you know. And so, like, there's all kinds of things. But my point is, we put all of our agents into an internal subnetwork. And by the way, we also sleep them when they're not actively being used. And you can wake them up via Slack application, a Slack channel that you say, like, hey, I need to run an expense report, spin up the expense reporting app, etc. But we're a cyber company and we have a mindset around this. And we kind of knew, like, well, okay, if we're going to unleash these agents, we don't know what all they might do. And that was already well before the Hugging Face incident. You know, we, months before that, we decided, no, we're going to put them on a dedicated network. In our case, we actually spun up a dedicated AWS account. Um, and, you know, put another IAM trust boundary around it and a couple of other safety controls. And you have to be on our VPN in order to access it, and so on and so on and so on. And, like, but, you know, it's one of those things that is a good practice, has been a good practice for decades, is under-invested today. Similarly, two other things that you said I think are good practices. One is figuring out what your threat model is. And two is actually, like, kind of assessing the security of your source code. These are things that have been good practices for a long time. And the interesting thing that I want to get your take on is, those are things that I don't think, if you were standing in front of a very well educated board of directors who know cybersecurity in and out, they could say to you, Richard, there's no excuse for you not to be able to give me a threat model today. There's no excuse for you to not know the security of the source code of all your applications, because those are, you know, a couple of prompts and pennies spent, right? Right. So those are things that I think we're going to get better at, but I'd love to hear from your analyst perspective what you're hearing from people. Are they actually doing more of this?
Richard Stiennon: Uh, I haven't heard that they're doing more of it. Okay. But, uh, when you think of it, like, one of the biggest hold backs on doing network segmentation is the complexity, right? You got to sit down with everybody in the room, figure out what that architecture is. People fight over it and all the rest. But that's one thing I've learned, you know. We are all IT support for our families, right? And, yes, um, anything, right. And now you just, a single prompt does the task for you. And I would have no problem going into a huge network and figuring out an unconflicted, minimally available, uh, optimally available network segmentation plan and deploying it. Right. I would give access to the switches to my agents and have it deploy it. Now, maybe not full time all the time, but I would get it up and running. Nobody would notice anything other than probably performance improvements on a bunch of segments. You would identify, uh, networks that were needed to be beefed up and, uh, you know, switches changed out, and stuff. So yeah, I think that even though I'm not hearing it, I bet you it's happening. And if it's not happening yet, it will happen, that people start, okay, deploying with the help of AI. Okay.
Jeremy Snyder: Okay. Yeah. I'm hopeful that we get a little bit better at this. Yeah. And I'm also curious. So you mentioned Black Hat, obviously I was there as well. And we showed off some of our new stuff. It's always a great opportunity to, to kind of, one, to show off, but two, I use it internally as a tool for our team to do a mix of like, okay, let's, you know, solidify a few things, but then let's come up with some big ideas, because it's always just this, like, great showcase. You're going to get in front of a few hundred people over a very short period, and you can get a lot of very fast live feedback. So when you're thinking about, like, new strategic direction for something, you could build, something you could solve with your product or your platform or whatever, I find it's a great test bed for that. Mhm. But for you as an analyst, I got to think it's just, like, madness trying to gather information, assess new tools, products, vendors, companies, teams, etc. How do you keep up with things from the analyst's perspective? Because it feels like this is the craziest time I've worked in cyber.
Richard Stiennon: Yeah, for sure it is. Well, it's interesting. Um, a couple of things have conspired to change how I treat RSA and Black Hat. One, okay, I've got issues with my feet that make it extremely painful to spend a lot of time on my feet. Okay. And it goes beyond, you know, get comfortable shoes, right. Um, so now I can't just constantly be running from one meeting and briefing to the other, right? Because everybody, you know, one person will be in the top of the hotel, and the other person will be on the show floor, and the other person will be off site somewhere. And just, you know, I know seventeen thousand steps isn't a lot for some people, but it is for me. That's what my Fitbit was telling me. Um, but at the same time, uh, I have solved my own problem about keeping up with the industry, because I have executed on that Dataquest for cybersecurity. And that's what my platform now does. It automatically keeps up on the entire industry. And I can query it. I can take notes in it. Yeah. All the information I need is right there. So that part's taken care of. So now when I go to Black Hat, I'm not gathering information. I'm selling information. So I'm only taking meetings with cybersecurity consultants, resellers who do security assessments, and user CISOs that need decision support software for cybersecurity. Okay. So that's how I solved it.
Jeremy Snyder: Gotcha, gotcha. I'm curious, and I'll just step out of picture for a second here. As somebody with a security yearbook, what do you do about the yearbook? Because, like, it almost feels like you send it to press, it gets printed, it gets distributed. How long before it's out of date already? I mean, it almost feels like that might be, you know, a question of weeks.
Richard Stiennon: Yeah. Yeah. I send it to the final design about the third week in January, and it's already out of date. Yeah. So, but it's a point in time, and thus yearbook. Um, you know, and I keep track of failures, um, people who passed on, um, and then developments in the industry every year. And it was a twenty twenty four edition, um, it was the first time that I mentioned AI. There were eighty four vendors that qualified as AI security. Um, today there are five hundred and thirty eight that we tracked. Jeez. Yeah. Um, and, you know, so you can see, and it's great to have a history book, right? You can go back and contemporaneously see what, yeah, I was observing, and, yeah, and people I interviewed were observing. Yeah. Um, so that part of it was great. But then, uh, last year I realized that, you know, there was a chain of events that happened. We have all of the, you know, websites, URLs of all the vendors, four thousand three hundred and two this morning. If you have that and pass that off to an AI with a whole bunch of harnessing for doing web scraping, uh, you can gather all of the products from all of the vendors. And, and there, you know, I'm not saying that we have more cybersecurity companies than PitchBook does, because if you ask PitchBook, they'll say there are twenty five thousand. And that's because PitchBook doesn't have any domain expertise in anything. So they co-mingle resellers, consultants, law firms, insurance companies with product companies. They just can't tell the difference. So, um, so they do have the same companies that we have, but they don't have any product data at all. And we have all product data. We're right now, we're getting into the next phase where we're capturing versioning data for all the products. So it's going to explode how much data we have to cover. Um, and I realized that I can no longer release the Security Yearbook with the directory in it. So I made that decision last summer. Um, the copy you've got in your hand there, there are PDF versions of it floating around on the internet that people have sent me that are physically scanned. Somehow somebody put them on a scanner, and, yeah, yeah, um, grab them. You can see the curvature of the page. Um, and all you have to do is grab that, OCR it, and you can become a competitor of us, or, you know, your team could say, we don't want to pay IT-Harvest for their API access, you just build your own, you know, with a couple million tokens. Um, yeah. So, so I had to stop the directory. And then the publisher, Wiley, decided that they had printed too many of the twenty twenty five editions. So they canceled the twenty twenty six edition. So, and it's still up in the air whether there'll be a twenty twenty seven edition.
Jeremy Snyder: Do you think there might be a twenty twenty seven digital edition?
Richard Stiennon: Um, yeah, I could easily do that. Yeah. Yeah. But Wiley owns all the copyright, so.
Jeremy Snyder: Gotcha. How do you change that? Yeah. Yeah, fair enough. Well, I'll be very curious to see how that plays out, because it just feels right now like things are changing so fast that a yearbook is not nearly frequent enough.
Richard Stiennon: That's why, instead of the yearbook this past year, I wrote Guardians of the Machine Age, which is a complete coverage of all the vendors at the time, three hundred and seven in this, um, obviously. And then I've been updating it on my Substack, because that's very cool, because next year there won't be a standalone AI security category. Every company will be AI security. There'll be four thousand three hundred and two AI security companies.
Jeremy Snyder: Yeah, I think the interesting thing about it, to your point, is that, you know, every company is going to be some flavor of an AI security company. It's just what part of the stack you defend and what part of the problem you're trying to solve. And, you know, obviously we have ours that we focus on. But I know very much that, for instance, like, you know, the automated SOC or the AI SOC analyst, etc., like, that's totally not us, but that's a valid use case. I get it. I understand, like, why somebody would be interested in that, etc. And there's just too many problems for any one company to solve, even if they are. Yeah.
Richard Stiennon: Um, you know, even if they are, there's a handful, at least a handful of new vendors addressing every old security technology, right? So no matter what it is, email, operational technology, there's an AI type solution for it. And some might be valuable, I don't know. You know, it's, yeah, it takes an industry analyst. First of all, we, of course, we have our opinions right away. But, yeah, um, we need a couple of years, because we need to see one, that you got customers, and two, that the customers renewed. Yes. Because in this day and age, no customer, you know, doesn't, no customer renews if they're not getting value out of a product. Right.
Jeremy Snyder: Yeah, yeah, yeah, yeah. Awesome. We've only got a couple minutes left, but I want to get one closing question in, and we will share, by the way, for all of our audience, we'll share the links to IT-Harvest and to Richard's Substack, where he's talking about the evolutions since even the publishing of that book earlier this year. Where do you think we're going? You know, from your vantage point as an analyst, great, every company is going to be some flavor of an AI security company. But what are, let's say, like, the meta elements that you're worried about? Is it APT plus alien? Is it alien on its own? Is it swarms of aliens? What are the things that you're thinking about for the next couple of years?
Richard Stiennon: So I can't think two years ahead anymore. Um, it used to be easy to do that. Yeah. Um, but now you can't, because, you know, we don't know what the, uh, the foundational models are going to do in the next two months. And that's going to determine everything, right? Because we are, we're entering a phase where AI is going to significantly impact our lives, from medicine, material science, geopolitics. Um, it won't be long before governments start, you know, the intelligent governments start using AI in order to do their job better. All that is going to be so much change that, as usual, security is just going to be a small segment of it. Um, but we have to be there ready to support, uh, all the organizations, everybody that is using AI, support them by protecting them. And we're going to harness AI to do that, right? So we are, no question that we're going to have, you know, William Gibson's vision of, you know, battling, AI as the attacker and the defensive ICE, uh, going on. And, you know, how that scales is a little mind boggling, right? We know that attacks and defenses scale really fast into, you know, now it's millions of whatever. And if there are millions of swarms of AI agents battling it out, there is going to be costs associated with that that we have to deal with. So, yeah, uh, it's a super exciting time to think about these things. The best I think I can do, uh, is observe as quickly as I can and, you know, kind of get the word out about where it's going.
Jeremy Snyder: How do you allocate your own internal excitement versus your internal fear versus your internal uncertainty? If you had to put percentages on those three, uh—
Richard Stiennon: Uh, excitement, ninety nine percent.
Jeremy Snyder: Okay. Yeah. Okay. That only leaves one percent for fear.
Richard Stiennon: Yeah. And fear is relegated to, yeah, I'm not going to put that in my house, you know? Okay, I'm not going to buy a humanoid robot, right? Yes. I grew up in automotive industry. Robots can kill you so fast accidentally that I'm not going to have one in the house. And I frankly, I don't think anybody is. But, um, the, uh, you know, I'm not, you know, I don't have Alexa. I don't have anything like that. I'm a survivalist at heart, and I'm ready to move to the country and trap rabbits to eat. And that's the one percent.
Jeremy Snyder: Fair enough. Last, last question. What's with the Antarctica map? As a geography buff myself, I'm just curious about the map behind you.
Richard Stiennon: Yeah. Um, yes, I'm a, uh, Antarctica, I have been since being a young man. Um, and I, you know, read, uh, polar explorers, etc. Uh, maps are very disappointing, right? Because they're, yeah, no details on them. It's just all almost none.
Jeremy Snyder: That's a white blob basically on behind you. No fun at all.
Richard Stiennon: They might get better. There's a young woman, twenty year old, former Palantir, uh, Hannah Wong, I think her name is, um, and, uh, she's twenty years old and an accomplished pilot. She's flown on every continent already. She plans on flying, having an expedition to fly across all the continents and then Antarctica, and take LiDAR with her and map underneath the ice as she goes to the South Pole. So she's repeating, you know, uh, going way beyond what Richard Byrd did when he first flew across the poles.
Jeremy Snyder: Yeah, yeah, yeah. Fascinating. We'll have to keep an eye out for that. Well, Richard, thank you so much for taking the time to join us on Modern Cyber today, to talk cyber kind of past, present, and future, and see where we go. And for your work as an analyst, thanks for all that you do for the industry. We will have links, like I said, to IT-Harvest, to your Substack. Anything else we think of, we'll put in today's show notes for all of our listeners. Thanks so much, and we'll talk to you next time. Bye bye.
Richard Stiennon: Awesome.