
Microsoft for Startups: The benefits of the cyber startup ecosystem.
Dave Bittner: Welcome to this N2K CyberWire Special Edition, the "Microsoft Startup Spotlight," brought to you by N2K and Microsoft for Startups. I'm Dave Bittner and today we're shining a light on innovation, ambition and the tech trailblazers building the future right from the startup trenches. This episode is part of our exclusive RSAC series where we're diving into the real world impact of the Microsoft for Startups Founders Hub, a no cost, no funding required platform built to empower startups with everything they need to grow fast and build smart. We're talking free access to cutting edge AI tools like GPT-4, up to $150,000 in Azure credits, and one-on-one expert guidance to turn bold ideas into resilient scalable solutions. We'll be talking with founders from three incredible startups who are part of the Founders Hub, each tackling big problems with even bigger ideas. So, whether you're building your own startup or just love a good innovation story, stay tuned. This is "Microsoft Startup Spotlight," and the future starts here. [ Music ] Well, welcome everyone and this is the kickoff of our CyberWire N2K special edition showcasing Microsoft for Startup supported companies. We're talking about Survey, Reg Scale and Endor Labs. Before we get to that, I want to welcome to the show Kevin Magee from Microsoft, and FC, a very well-known and renowned hacker and also an entrepreneur in his own right. Let me start with you, Kevin. Welcome to the show.
Kevin Magee: Thanks Dave. Thanks for hosting us.
Dave Bittner: And FC, always great to catch up with you my friend. It's been a little while but I'm happy that we get this opportunity to chat.
FC: Yes, thank you. Thank you for having me on, Dave. I'm really -- really looking forward to this one. This is going to be an interesting conversation, I think.
Dave Bittner: Well Kevin, can you set the table for us here when we're talking about Microsoft for Startups, which is something that you run at Microsoft? What do you want folks to know about that endeavor?
Kevin Magee: Yes. I think we're really focused on is looking at using the ecosystem that Microsoft's creating. Not just the technology, but the access to enterprise customers, the trust we've built up in the brand over many years and then just our marketing machine, the -- the big microphone I like to call it, of Microsoft. How do we hand that to founders and startups and innovators, so that they can get the attention that they deserve, so we can drive innovation, so we can get innovation into the hands of the folks that most need it now? Because it's harder more than ever to get -- to get that attention. I founded my three companies, in the 90s. Two successful. One I don't like to talk about, using BizSpark, which was the predecessor to the Microsoft for Startups program. So, it's so cool to be involved after all these years. And -- and I have that connection. And I remember what having sort of that big ecosystem to plug into to be part of something to help accelerate my business did for me. And that's what I want to bring to our startup founders as well.
Dave Bittner: Well, FC, you have personally made the leap from hacker to entrepreneur. Can we talk about that journey a little bit? What -- what's your origin story and what led you to where you are today?
FC: So, my origin story was I was weirdly bitten by a radioactive spider. No, no, not really.
Dave Bittner: You too?
FC: Yes, yes. It happens. Didn't do any superpowers. No. So, I was working as a defense contractor. I was the head of offensive cyber security for Raytheon, for many years. And I was getting a little bit frustrated with all the red tape. And -- and there's a fantastic adage that says, "You'll never get rich working for someone else." And so, it was like, "Hang on, I need to get out -- get rid of the red tape. I also need to go and make some decent money for myself." So, my wife and I started the company Cygenta. We started that many years ago. And we -- we took the hard route. We went with self-funding. I think we put about $250 into it. I donated some computer systems and that was it. That was the start of it. And it's been a fantastic journey. It's been hard but incredibly rewarding.
Dave Bittner: What are some of the specific challenges you remember of -- of building a company?
FC: The biggest issues that we had, obviously being self-funded, was money, right? We -- we -- we struggled with money at the beginning. We had to make sure that we had enough payroll and mortgage and all of this stuff. And no one was going to come and save us. So, that was -- that was a challenge. That was a bit of stress. And then from there on, it's learning how to run a business. And -- and that is really hard. People just think, "Oh, I can just be an entrepreneur. I'll just start a company. I'll start making money and then we'll get clients." There's lots of administrative stuff that you have to learn, that you didn't realize when you were just an employee.
Dave Bittner: Kevin, I -- I think that is a message that echoes with probably anybody who's been an entrepreneur, who's listening that I think for most people, they get into running their own company because they want to do the work, not because they want to -- to tackle the day to day tasks of running a company which is its own thing.
Kevin Magee: I think that's the problem. When you make your -- your passion your job, it -- it can become a challenge. And -- and really, I think we look at sort of the exits or -- or you know, the -- the big IPOs or the big success stories, but we really forget the amount of work and challenge it -- it takes to find a unique solution, bring it to market, get the attention, get the funding you need, all while figuring out how to make payroll. I remember in the dot com boom running my first company, I was interviewed for a magazine article. And they said, "You're the president of a -- a dot com startup. What's the first thing you do when you come into the office?" And I said it was take out the garbage. Like, it's -- it's through these mundane things that really can distract from -- from building your business. But ultimately, I think what gets us through as -- and this is why I'm so excited about what we're building at Microsoft for Startups, and I think FC personifies this, is this hacker mindset is very much in tune with the entrepreneur mindset. It's experimental. It's adaptable, but it's also mission focused. And I think that's one thing our industry is so different than any other industry. We're all defenders. We're all trying to solve a problem. We're all trying to help people in organizations. So, I think that unites us in a way and lets us work together more collaboratively than potentially any other industry as well, too.
FC: Yes, I'd -- I'd like to echo that actually. I think that the hacker mindset is actually really quite helpful in the situation of starting your own company because you don't know all of the solutions that you need when you start. Right? So, when we started, we didn't have a CRM. We didn't know which CRM to use. We've changed CRM now three times. And you know, having the -- the team around you that understand that you're -- you're going to make mistakes and that you're going to change things and the way things work and the way that policies and procedures are done, they're fluid. Right? You -- you don't go in with this just set of things that you've got and you go, "Right, that's it. My business is now sorted out." You have to understand what you need to change and change it quickly. And I think that was one of the frustrating things when I was working for other people is you could see what needed to change, but they were so gigantic you could never change them. Whereas being a small, independent entrepreneurial company, we're able to like just make a decision. Like the other day, we just like, "Okay, we're not using Adobe anymore." That's it, we just killed it. And -- and we're going to find solutions as we need them for other work that we need.
Dave Bittner: You know, FC, I think you have the experience of being on both sides of things, having worked for a big organization and then taking that entrepreneurial journey yourself. I think one of the challenges that a lot of entrepreneurs have is getting the attention of those big companies and getting them to take you seriously. Was that something that you found yourself up against when -- when you're just starting out and knocking on doors? Or -- or did your experience from the other side serve you well?
FC: I have to say, we are incredibly fortunate. Right? So, I -- I founded the company with my wife who is incredibly good at her job, and she is very well known. So, we came into the industry, already very well-known as individuals. And because of that, a lot of people wanted to work with us straight away. So, we -- we made profit in like the first month, which is very unheard of for a lot of like sort of small startups. Because companies want to work with us, we don't spend a lot of time doing the general marketing stuff that a lot of people have to do. We have a backlog of people that want to work with us. We are very fortunate that we have enough clout, if that's the right word, to say no to certain people. Like I won't work with people that don't want to actually improve their cyber security, because it's a waste of their time. It's a waste of my time. So, having that freedom is massive, and -- and is very unlikely to happen for a lot of people straight away.
Dave Bittner: Kevin, can you touch on some of the advantages when an organization that's coming up when they partner with Microsoft for -- for Startups? I imagine having that subtitle, being a partner with Microsoft, helps open some doors.
Kevin Magee: I think that's the key. Having that sort of -- that brand recognition can really make a difference. But if you're two researchers that have spent time, you know, in the lab, building your solution or whatnot, you maybe don't have those public profiles. So, that's something that sort of we bring to the table. But also, just bridging that gap that FC talks about is -- and enterprise leaders have all this -- this challenge. You know, big enterprises are risk averse. There is a lot of bureaucracy and whatnot. But ultimately what they need to do is translate innovation into an outcome and they need the understanding of what that looks like and build the narrative for that business case to unlock that -- that budget or whatever it takes in terms of cultural change to adopt a new innovation strategy. So, one of the things I do in -- in my day-to-day role, which is what I really enjoy, and I did the reverse, I went from entrepreneurship to the large company, is -- is bridge that gap and be that translator. Innovators want to move fast. They -- they don't want to get -- have things get in the way. Enterprise leaders have the exact opposite problem. How do you find common ground and how do you translate that innovation into outcomes that can really, you know, build that story? I think you'll hear some stories from some of our startups as part of the series that have really focused on understanding that enterprise challenge, taking an innovative approach to solving it, but then being able to explain and articulate that solution well, that allows that CISO, that enterprise security leader, to build the business case or change the culture to adopt it. And that's really our mission is how do we get those best ideas, you know, into market and how do we help them scale securely responsibility and just, you know, sell more faster for the revenue -- for revenue for our startups, but also making our enterprise customers more secure faster as well, too. And getting sometimes these two cultural groups to come together and speak the same language is a bit of a challenge, but when it does happen, amazing things can -- can occur in terms of an innovation learning loop and whatnot with our startups.
Dave Bittner: Well, FC, we're going to hear from some startup founders here, some really interesting companies. What is your advice to folks who are in that situation? That person who is hungry to start their own business. They feel like they have something that -- that's going to solve some problems that aren't being solved out there, and they're ready to go. Any words of wisdom?
FC: Yes, I'd say go for it. Right? Just do it. You know, I'm sorry if I'm going to get sued by Nike for that, but no, just actually go away and actually start it. Right? So, I've -- I've had many, many people come up to me and be like, "Hey, thinking of doing this, thinking of doing that, like, when do I do it? How much -- how much savings do I need?" It's like, don't put your family at risk, right? Don't like mortgage the house in order to do it, but make sure you've got a little bit of money to -- saved up to -- as a like a slush fund, and then just go for it because there'll be unexpected costs along the way. And -- and you don't want to be out on the street with -- with nothing and saying, "Hey, I've got a company now." So, yes, plan it, but then just go and do it. Don't stop because you think you can't do it or that there's -- you have to have this perfect plan. Just start it. Just go and register the company. That -- that bit alone, it doesn't take any effort. Right? It's very cheap to start a company. You don't have to trade with that company for ages. You can just get it started. Buy the domains, build small, and then it will go. That -- that would be my advice. Just go off and do it.
Dave Bittner: All right, well, I'm looking forward to hearing the stories that our entrepreneurs have to tell. Kevin Magee and FC, thanks so much for joining us.
FC: Thank you.
Kevin Magee: Thanks, Dave. Thanks, FC. [ Music ]
Dave Bittner: Joining us is someone who's been at the forefront of cloud security long before it became buzzworthy. We're thrilled to welcome Matt Chiodi, Chief Trust Officer at Cerby, a Microsoft for Startups standout. Matt brings over two decades of deep security leadership experience, including his time as Chief Security Officer of Cloud at Palo Alto Networks. He's not just a security strategist, he's a voice in the industry. You've likely read his blogs, caught his podcasts, or seen him take the stage at major conferences like RSAC. And if you're an IANS research follower, you might also know him as a member of the faculty helping shape the next generation of cyber leaders. Today, Matt's here to talk about trust, innovation and how Cerby is rewriting the rules on securing what he calls, the "unmanageable applications" in the enterprise. [ Music ] So, let's start off with just some high-level stuff here. I mean, for folks who aren't familiar with Cerby and the -- the value proposition here, can you give us a little bit of the origin story and -- and the -- what you -- the -- the problems that you all are looking to address?
Matthew Chiodi: A hundred percent, yes. So, the origin story of Cerby, which I think is probably one of the most interesting, is that our founders were -- you know, had started some previous companies and after they left those companies, they were, you know, doing some work and they noticed that they started using these various different SaaS tools. And they would start to use them and then eventually the IT teams would come around and either shut them down or say to them, you know, "Hey, these tools don't support these standards. You can't use them." So, they would get blocked by IT. And it kept happening over and over again. Go to provision a tool, a SaaS tool, and then lose access to it. And so, that got them thinking, like, "Why are so many of these quote-unquote 'modern SaaS tools' -- why -- why don't they support these standards?" And they started to research it. And what they found was that at the time, it was easier for these tools to launch without support for standards like SAML, SCIM for provisioning and deprovisioning, than it was for these teams to build them out of the box. And what that created was, is that from a product perspective, when they actually spoke with these companies, they asked them like, "Hey, why aren't you building this?" they said, "It's because our users aren't asking for these standards to be supported. They don't care about them." And so, that got them thinking. And you know, the name of the company, Cerby, it comes from Greek mythology, so Cerberus the dog, and that dog, that three-headed dog, if you look at our logo, that three-headed dog in Greek mythology is what guards the gates of hell from breaking loose. And that's what we do for companies when it comes to all those applications that fall outside of the scope of their current identity stack.
Dave Bittner: Well, Kevin McGee, does this story resonate with you? I mean, I'm -- I'm thinking back to any experiences in your professional career of, you know, facing similar frustrations.
Kevin Magee: Well, first off Dave, you know I'm -- I'm a recovering historian, so I love the -- the tie into the Greek mythology. I think it was the twelve labors of Heracles he had to -- to steal -- to steal Cerberus. But it -- it certainly really speaks to sort of this challenge because the most innovative and smallest organizations are probably those early warning systems of -- because they're quick to adopt tools. You start to see identity sprawl in these early companies. And now as big companies, they're starting to act more innovative and more like startups, we're seeing these challenges as well too. But we've got CISOs that have to -- to figure it out and figure out how to protect these large organizations. So, I think there's real consequences to the large organizations when we don't have just sort of compliance across and hygiene across identities. So, it's a great opportunity to -- to look at new investment, new -- new innovation from both Microsoft's perspective and -- and our customers'.
Dave Bittner: Well Matt, help me understand here how widespread is this problem when we're looking across the enterprise landscape?
Matthew Chiodi: You know -- you know, a lot of us who are in tech, a lot of times we assume that every company is using, you know, something like a 365 or a very modern SaaS app. And while they might use some of those, that's not the only type of apps they're using. Like, we have found that even in some of the most progressive tech companies, they have these, what we would call disconnected apps that they can't manage with their entre or whatever they're using for their -- for their IDP. And you know, this creates all kinds of different challenges, right, with these different apps. There could be no multifactor authentication, no centralized logs, broken off-boarding, weak audit trails. And from a -- in terms of how widespread it is, we did research with the Ponemon Institute, and we found that the median -- the median number of these applications that exist in an organization, it's 176. That's the median. It's not the average. So, 176. That means you've got organizations, you know, if you've got a multinational corporation or, you know, a large financial services company, you could be talking about having thousands of these applications that exist again due to the diversity of the applications that exist in their businesses. So, the problem is it's very widespread.
Dave Bittner: Is this more of a legacy problem? Are -- are we finding that the new tools that are coming along, the new SaaS tools, are -- do they have these capabilities out of the box, or is this an ongoing situation?
Matthew Chiodi: You know, certainly some of them do support it out of the box. But we did other research. We looked at the top 10,000 SaaS applications and what we found was -- was surprising. We found that 47% don't support two-factor authentication, 54% don't support SAML, and 93% don't support the SCIM standard. And for those that aren't familiar with SCIM, the System for Cross Identity Management, that is the standard that was created years ago that was supposed to be available on every app, that would allow you to do automated onboarding, offboarding, you know, if someone moves roles, things like that, to automatically update it in those downstream apps. So, no, this is not a legacy problem. I mean, this is why companies like Auth0 were created on the market for the CIAM start of the house. And even other companies like DSCOPE followed on because the problem is so massive.
Dave Bittner: Well, I -- I know you and your colleagues there at Cerby are making good use of AI for identity security. Can you share with us, how are you applying it?
Matthew Chiodi: Yes, most of what people know about AI is typically generative AI. We specifically are leveraging agentic AI. And the best way to think about agentic AI is that it's -- it is a model that is trained on a very narrow problem set and then it can take actions autonomously, based on that training, right? So, if you, you know, you call, you know, a help desk number, you get an agent on the phone. We're talking about humans here, at least for now. Right? They are very good, or they should be very good at one thing. If you call, you know, help desk support and ask them how to change the oil in your car, they're probably not going to be able to help you with that, but they're good at one thing. So, the way that we leverage that is we train based upon the applications that we need to support. And these are, you know, typical integrations with, you know, thousands of different applications. So, we make use of things like computer vision, graph neural networks, reinforcement learning. And you know, the best way I would contrast this is when most people think about automation, they're typically thinking of like, script-based or RPA, Robotic Process Automation. And RPA is extremely brittle. It breaks anytime something changes. And in the use -- in the case of most of these, again these disconnected apps that we deal with, there's usually little offered in terms of -- of things in the way of standards. And so, it's super important that anything like this be multimodal. So, we look at the app and we look at, "Hey, Is there any APIs available? Is there partial protocol support?" And then based upon what's available in that app, we can leverage it with our agentic AI.
Dave Bittner: So, how do you make sure that the decisions that the agentic AI is making are -- are both safe and auditable?
Matthew Chiodi: That's one of the -- the -- the toughest challenges -- challenges to solve with AI right now. We've got a number of patents that are pending, and we certainly have not figured this out 100% yet. It's something that we are actively developing and working on. But there are a couple different things that we are working on and -- and even working with some of our partners. So, people might be familiar with RAG, which is Retrieval Augmented Generation. That is something that we are leveraging with our agents, and it grounds them in their responses so they're verifiable based upon our internal knowledge. But safety and auditability comes from how we wrap that AI with structured decision logging and policy enforcement. So, when we look at where we're going with the platform, every AI, every agent that's taking an action on behalf of a user or system, needs to be logged, the who, what, when, where and why, not just what the model said. You have to remember, AI is not -- is nondeterministic. When you're doing security things with AI, it's got to be deterministic. And so, there will, you know, at least for now, there's always going to be a human in the loop. So, for example, if confidence is low or risk is high, we escalate that to a human by design.
Dave Bittner: Kevin, what's your response to what Matt's describing here?
Kevin Magee: I think what CISOs are telling me they want is really just consistency. That's where the value is and allowing AI to ensure the policies are applied to -- to applications that humans would forget or ignore or not even know about, I think that's where the value that Cerby really brings to the conversation. And CISOs are -- are actively looking now for -- to solve these challenges and for solutions that can do that.
Dave Bittner: You know Matt, I know that Cerby integrates with Microsoft Entra. Can you describe that -- that combination and -- and why that makes sense for customers?
Matthew Chiodi: Well, what we overwhelmingly see across customers and prospects is that they do use Entra for their -- for their identity and access management. It's already integrated as part of 365 and for -- for us, it was a no brainer to have an integration there in terms of what we do. So, Cerby integrates with Entra to apply governance policies, again out to those disconnected apps. Now, normally, those apps would be outside the reach of Entra. And so, we help customers take their existing investment in Entra and then be able to extend those native capabilities of Entra to those disconnected apps. So, it could be enforcement of zero trust principles across all their apps, not just the ones that are integrated. There's use cases that are just as diverse as the applications are. It could be protecting social media platforms. It could be design tools. It could be a legacy application. And really with -- with a combination of Entra and Cerby, it allows us to combine Microsoft's platform with Cerby's provision -- precision for edge cases and those disconnected applications.
Dave Bittner: Well Kevin, what is Microsoft's view of this sort of integration?
Kevin Magee: Ultimately, we believe in building an open identity ecosystem and Cerby's innovation is really strengthening that approach. It -- it allows customers to look at the -- sort of the secure edge of their -- their identity attack surface and -- and solve for that. So, ultimately, you know, we're looking to -- to build that ecosystem platform for innovation and allow startups to build on that and find new ways to solve problems. And Cerby is a great example of that. That -- that really leads to -- to not lock in but fill in to our capabilities, but also just expand and empower organizations with choice. What do they really need to solve their challenges and -- and how do we provide sort of all of those opportunities to bring on innovation to address the -- the modern challenges that the CISO has.
Dave Bittner: Now, Matt, I-- I'm curious. You know, in your day-to-day, I suppose you probably come across CISOs who in talking to you about the products you offer, they -- they say, "Well, our identity program is already complete. We're -- we're good here." To what degree is that the actual case with -- the -- the folks that you interact with?
Matthew Chiodi: I would say that, you know, it -- it depends on the size of the company, but if I'm talking to, you know, a Fortune 100 CISO, that might be the case. And then I usually say, "Ask that same question to your head of identity and access management." And then they'll always come back and say, "Ah, yes." And so, it really depends on who you're speaking with. You know, did they come up, you know, with an identity background? Did they come from an audit background? But I have not spoken to a single organization in the last four years that I've been at Cerby that did not have this challenge of disconnected applications. And so, I just tell CISOs to ask the question in their identity program. Just ask the question, "Does our existing identity investments extend to all of our applications? All of our applications?" That's a great place to start.
Dave Bittner: Kevin, what's your take on that?
Kevin Magee: Well, I think the hardest place to really be successful in identity project is Layer Eight. It's really going around to each of the stakeholders and having that -- that discussion of federated identity or cross-functional discussions of how tools are working. I think the smart CISOs are starting to think in terms of ecosystem resilience, not just tool coverage, to address this -- this challenge.
Dave Bittner: What do you hope that the takeaway for CISOs is here, Matt? As -- as they're looking at their existing situation, what do you hope that when -- when they're considering their identity technology, any words of wisdom or tips for them?
Matthew Chiodi: I would say that they need to again think in terms of how far can they extend their existing investments across their identity stack? Is it -- is it really all of their apps? That's where I would challenge them. So, I would think about -- talk about your identity coverage, audit that, what apps sit outside our identity framework, and then think about it in terms of prioritizing coverage based upon risk, shared access and things like that. And then it's also thinking about -- a lot of times CISOs think, "Well, oh, does this mean I'm going to have to go out and replace my identity stack?" That's not the -- that's not the case. That shouldn't be the case, unless you're talking about a tool that's been, you know, sitting in your organization for 20-plus years. But look at -- think about tools and terms that can really help you extend your existing investments, not replace them. And certainly, this is a place where we believe AI can play a big place -- a -- a big part of it as well.
Dave Bittner: We'll be right back. [ Music ] Next up, we're joined by a founder who's taking on one of the most complex challenges in enterprise security, governance, risk and compliance, and making it actually usable. Say hello to Travis Howerton, co-founder and CEO of RegScale, another standout from the Microsoft for Startups Founders Hub. Under Travis's leadership, RegScale has built a powerful, continuous controls monitoring platform that bridges the gap between security risk and compliance, turning what used to be a static, slow moving GRC process into something real time, scalable and cloud native. Before launching RegScale, Travis had a remarkable run in public and private sectors alike. He served as Global Director for Strategic Programs at Bechtel, CTO of the National Nuclear Security Administration, and held leadership roles at Oak Ridge National Lab and the Department of Energy. When it comes to high stakes, high security environments, Travis knows the terrain. [ Music ] One of the things that we want to key off of today is this report that you all recently put out. This is your inaugural State of Continuous Controls Monitoring report. Can we start off with some high-level stuff here? What prompted the creation of the report?
Travis Howerton: Yes, so we kind of view ourselves as a next generation GRC tool, what's called a Continuous Controls Monitoring platform or CCM. We've been a leader in this space recognized by -- by Gartner, but what we're really looking for is sort of the pulse of the community on what are their expectations around CCM? What's the state of the market? And we were blessed to have, I think over 100 CISOs that were participants in this and gave us a lot of great feedback. But key things, you know, 90 -- over 90%, I think it's 94% believe that CCM can improve both their compliance and their security program. Only 6% say they're secure from code to cloud, meaning their CICD pipeline takes compliance and risk into account as it builds. And very few have that embedded. So, it seems like we're very early days in the art of the possible for what the industry's looking for here. But that there is a lot of hope and need expressed in this market by the CISO community.
Dave Bittner: Well, let me ask you this, I mean, was it surprising how few organizations are actually embedding compliance into their -- their CICD pipeline?
Travis Howerton: It -- it wasn't surprising to me in that, you know, compliance has always been an after the fact, check the box sort of activity. You know, when I talk to CISOs, I -- I always say, "There's no faster way to shut down a conversation in the bar than to bring up a compliance chat." Compliance doesn't equal security. It's sort of this checklist thing you've got to do. But it can be a roadmap to good security and sort of secure by design principles and embedding those and having sort of self-updating paperwork, is a win for everybody, not just the audit and compliance people, but also the -- the risk folks, because my -- my perspective on it is as people move more and more to the cloud, they take advantage of technologies, Azure offers and Microsoft offers, where things spin up, down, dynamically, risk can't be this after-the-fact manual checklist process. It's our view as an operational imperative for CISOs to have real time visibility into risk and compliance posture, as they accelerate adoption of cloud native technologies, AI technologies and other sort of forward-leaning technologies in their organizations.
Dave Bittner: Well, Kevin Magee from Microsoft is with us. Kevin, I -- I would love to -- to get your take on this. I know you have read the report here. What are your thoughts?
Kevin Magee: It was a great connection to the early cloud journeys, I think, where there's a cultural shift happening within organizations. We've always done it this way, so it's hard to -- to change. And -- and I get what you mean by compliance can sometimes shut down conversations. As a recovering CSO, compliance wasn't always my favorite topic. I'll -- I'll be completely honest with you at that point. But I started thinking when I saw some of the demos early on RegScale about, you know, what -- what we could look at compliance in a different way. How could we reframe it and how could it be a competitive advantage? If we could continuously understand what our compliance posture was, what could that do to the business? What could that become as a competitive advantage overall? And this is where this -- the space is really interesting for me from a startup perspective.
Dave Bittner: Well, Travis, I mean, what is the advantage of continuous controls monitoring here? What's the -- what's the game changer?
Travis Howerton: Yes, the way I've always viewed this is this is an industry that's run by consultants, advisory firm, internal staff who manually do this stuff to make sure all the paperwork's in place for audits and governance processes and regulatory reporting. And it's both expensive, manual and after the fact. So, what's in it for businesses is leveraging the telemetry you already have in cloud native systems in the modern API economy, then combining that with the things that AI does well, ingesting large amounts of data, summarizing it, synthesizing it for you to have a more real-time view of what's happening. We think that's the art of the possible. And the -- the cool part about it is I think it's one of the -- the last great computer science problems to solve in highly regulated industry and that everything else is fast. DevOps is fast, CICD is fast, AI is fast, Cloud is fast. Risk and compliance moves at snail speed. Right? And so, it's how do you get that to be at the same cadence, I think is the interesting intellectual challenge and -- and business challenge that we've been trying to wrap our arms around here at RegScale.
Dave Bittner: That's a really interesting perspective and insight. I mean I -- I think of -- when I talk to people about compliance, I think there's a lot of what I would label "aspirational talk." You know, people want to do more than comply. But then that aspiration kind of meets the real world. So, I'm intrigued by this notion of -- of it being the slow thing. I mean, is it -- is it an anchor that organizations are sometimes dragging behind them?
Travis Howerton: Oh, 100%. If you look at the organizations that lag behind sort of the cutting-edge commercial industry best practice, for example, government will always be, it seems like years if not a decade or more behind. Part of the reason is they have to go through these sort of complex risk and compliance, what they call authority to operate or ATO processes. Many cases, banks and other large entities that are multinational have some of the same struggles. It's sort of a function of scale and size. You get so big and you -- your operations are so dynamic that you've got to assure yourself you're not adding risk. And those risk processes take so long to execute that they just really hold back digital transformation goals for the company. So, it's sort of an interesting problem that by avoiding risk in -- in many ways in cyber, you're adding business risk of getting left behind and disrupted because of how far you end up behind others who are able to more rapidly adopt these technologies. And we think CCM is the best of both worlds where you don't have to reduce your posture. In fact, you're going to improve your posture, but you're going to move at the same speed as a commercial entity. And we think that's where the win is.
Dave Bittner: Well, help me understand what this looks like day to day for -- for an organization that's decided they want to jump in and do this. What does that shift look like for them?
Travis Howerton: Yes, so there's -- it -- it doesn't really matter which framework you're in. NIST puts out a lot of different ones that are popular. ISO 27000. There's CMMC, now. There's PCI. There's the Cyber Risk Institute, CRI and Financial Services, NERC CIP and Critical Infrastructure, HIPAA, HITRUST. All these different frameworks that evolve by industry. You need certain reps and certs to do business in markets. And whether it's helping you attest to controls, using our AI to author things in minutes that would have taken months to do by hand, automatic evidence collection, representing everything. Compliance is code, so you can do machine level assessments as well as AI-based assessments. Do smart, intelligent routing of things, for your issues management workflows. And then monitoring and accepting risk, all throughout the process, that whole life cycle is managed by the CCM platform. And so, what it looks like for a customer is sort of onboarding into the platform, getting their attestations done, connecting their tooling, wiring up the AI and then moving to a real-time posture versus a reactive, after the fact posture year.
Dave Bittner: Kevin, what are your insights here? I mean, what -- what are the advantages that you see when a company adopts real time compliance?
Kevin Magee: Yes, again I switched to my sort of board of director's hat and I've sat on a number of audit committees over my tenure as a board member. And I think there's real strategic value in knowing what your control posture is today. Not last quarter, not last year, but what -- what it is today. And it's also going to allow CISOs to have a different conversation with boards. Fewer surprises, more clarity, more understanding of what the role of the board is in mitigating risk, accepting risk and whatnot. Again, to be able to come to the board and say, you know, "Here's where we are today and here are some of the challenges we're seeing," and take action in real time as markets change or as geopolitical aspects change. This is a real competitive advantage. I think this is what compliance was always supposed to be but never has really gotten to. And we're finally reaching into the technology to -- to solve for that and make it -- make it that strategic enabler that it was always meant to be.
Dave Bittner: Travis, is -- is there a place for generative AI in all of this? I mean, it -- it's certainly the -- the topic we're all obligated to discuss these days.
Travis Howerton: Yes, 100%. And so, if you look at this market I mentioned is historically dominated by consultants. So, if you look at -- I think Gartner says GRC is a $50 billion a year market. But if you add up all the major GRC vendors, you're probably lucky to get to 5 billion, much less 50, which tells you 90% of this market is really driven by services, which makes sense to me. In my past lives, running large cyber teams, is a very heavy manual labor. And there was only so much you could automate. You could automate technical controls, but there's a whole bunch of controls that were very difficult historically to automate. And so, because of that, because there were huge unstructured data problems, there was just no other way other than sampling and throwing humans at it, issuing periodic audit reports. But today's nature of cloud, it's -- it's not acceptable to have, you know, some sort of object store with all your company's PI and it -- that's public. And maybe I'll find it if it's in the sample, once a year, once every three years we look at it. This stuff has to be more real time. It's -- it's -- it's an operational risk imperative to make it real time. The cool parts is that all those services things, our thesis is AI is largely going to eat it over the next three to five years. And so, if you look at what AI does well, synthesizing large amounts of data, writing about it, I -- I think many of these things we're doing by humans on a sampling basis can be done by AI on a real time basis at higher quality, lower cost, and it should at lower risk in the environments that adopt CCM platforms.
Dave Bittner: Can we talk about ROI? I mean what -- what are organizations experiencing from that direction?
Travis Howerton: Yes. So, if you look at jobs that you can do with generative AI using, let's say Microsoft OpenAI, behind RegScale, we have things that would literally take teams of people three to six months in a conference room to build out all the attestations, we can do in under an hour in AI. And so, you're talking about hundreds of thousands of dollars potentially saved on these. And for companies that have many, many of them to do and maintain, you can be talking significant ROI. And a core part of our CCM platform is that average you're leveraging, AI in the background or automation to do tasks, you get a running ROI calculator on the back end that tells you all the manual savings avoidance that you have. And so, now CISOs can take those dollars and put them towards operational excellence and hardening their environment and less towards the paperwork, check the box stuff which largely can become set and forget.
Dave Bittner: You know, Kevin, one of your responsibilities there at Microsoft is looking for these innovative cybersecurity startups. I'm curious, what about RegScale really caught your eye?
Kevin Magee: Well, I always kind of thought the GRC space was one of those kind of parts of the industry that -- that really wouldn't benefit from innovation. And I've completely flipped my -- my thinking on this. It is probably one of the areas that are most ripe for innovation and where I'm sort of looking for investment strategies as well too, because we can sort of approach it from a -- exactly the perspective that Travis was talking about. It's very manual. It's -- it's not only very manual, it's very inefficient and it's also -- it's just so cumbersome and so difficult for the employees. I can't imagine what it's like to get another spreadsheet to fill out or another form to fill out or whatnot constantly. So, maintaining staff morale, making sure that we're using resources wisely or whatnot. This is one of those areas that it's -- it's really I think ripe for innovation and has been largely ignored because it's sort of the boring end of the business. In fact, I would say the GRC space is probably where most of the innovation, some of the coolest stuff is happening right now. And it's not an exact analogy but I remember looking at the RegScale demo for the first time thinking, "Wow, this is soar," but for compliance this is something that you don't see very often, sort of a real innovation that has a true ROI story and I think it's going to be, you know, coming full circle, that CISO telling that ROI story to the board, to executive management, to the users, that's going to change the culture. But once they really start to see the tools in action, the automation and the benefits from that automation, I think that will shift the culture quickly and they'll see the -- they'll see the benefits, and -- and just immediate results which will change the market and -- and change the advantage for the company.
Dave Bittner: Well, Travis, wrapping up by getting back to the report here, I mean what are the take homes for you? What do you hope folks come away from having read the report?
Travis Howerton: Well, I always say I had a boss who was my mentor, always told me the best plans start with the truth. The truth is that this area in -- in the cyber domain is going to be eaten by automation and AI over the next five years. Like, we have really strong conviction around that, that we all stand on the shoulders of giants. You know, we're innovating on top of some world-class tooling provided by Microsoft and Azure and OpenAI, that allows us for the first time to have hope, because the first couple decades of my career, there was no hope. Like, this was boring, it was painful, it was terrible, everyone hated doing it, but it was the price of admission to certain markets that were very lucrative. So, you had to do it. Today, I -- I think that's changed. Now, this is stuff that should become commoditized over the next five years as AI sort of gives set and forget options of how you do these things. And now it's less about manually doing all this work and spending all this money on expensive consultants. It's how do I buy down risk in my organization and repurpose all those savings I generated? The things that help protect my organization, that I can talk to our board about risk reduction, and how we can get them into more markets. So, we think it's a really exciting time to be in the most -- most boring field on earth.
Dave Bittner: You know, I -- it strikes me too that -- that there must be a -- a satisfaction component to this for the employees where you're helping to remove some of these tasks that as you say are the boring ones, the drudgery ones. These are through automation, they're able to spend their time on the things that are a lot more gratifying and fulfilling.
Travis Howerton: Hundred percent and the things that add more value to the business. You hire some of the smartest people in the world to make risk based cyber decisions for your organization and then you waste 80% of their time chasing down evidence, doing data calls, waiting outside people's office to get something who's been ignoring them for two weeks. Like it's just an insanity problem that we've had as an industry. Now, instead, you've got a heads up display, you know where things are at and now it's sort of, "Where can we buy down the next level of risk? What decisions do we need to make?" So, you're getting more ROI out of those people. So, we don't talk about it as replacing people so much as it is how do we supercharge human beings to get more out of your risk professionals? Because as much as I love AI, I don't know anyone who wants AI making risk-based decisions for the strategy of their organization. Almost everybody I've talked to is willing to make the drudgery and the sort of mind-numbing paperwork go away.
Dave Bittner: So, Travis, when we're talking about things like FedRAMP and OSCAL and the -- these programs evolving, what are your insights there?
Travis Howerton: I think compliance as code as the foundation for this work is the future, because at some level of scale you can't handle these processes manually. And at the same time, what you need is a high amount of precision in -- in what you're trying to execute. And so, the best way to do that, that I know of, is to structure these things. And we've -- we've been building our platform on top of something called NIST OSCAL, the Open Security Controls Assessment Language run by Dr. Iorga's team, David Waltermire, who's now at FedRAMP, have been major innovators there. But they take all these huge thousand-page document spreadsheets we used to generate by hand, and now there are -- there are sort of tightly, formatted, XML, JSON, YAML representations of it that are machine readable. And so, that -- what that allows you to do is do automated assessments of these artifacts you used to have to do by hand. And so, I think of it like a compiler. And so, since we're with some Microsoft folks, they're one of the biggest software enablers in the ecosystem. When I write code, I'm in a development environment and I compile it at the end. And at the end, it may tell me an error, I screwed something up, I can't proceed. Right? That's kind of what OSCAL does. You can set your risk thresholds. What I'm expecting, am I inside or outside of that? Maybe it's not an error, it's a warning. I'll let you proceed, but you're still sort of out of the norm of what I expected. And so, now you can dial in your risk tolerance as code, apply it to the things you're building and have sort of a risk and compliance compiler that tells you, "Am I still in the safety zone of where I expected to be?" Because the -- the hard part of this industry for me for decades is getting invited to those meetings where you're asked to explain to them why you're not stupid, because something stupid happened and at one point it was in a good state, it changed and went to a bad state, and I didn't know it. Right? And so, this allows you to sort of compile that as often as you want, based off real-time speeds and feeds and make sure you're always inside this boundary that you want. So, we see it as this basis for dynamic operational control assurance, being able to know that the controls I have are in place, they're effective, they're operating the way I thought they were. And no more surprises from for CISOs and audits. [ Music ]
Dave Bittner: Our next guest is a name that resonates across the cybersecurity world. With more than 25 years of frontline experience, Karl Mattson has helped shape security strategy for some of the most complex sectors out there: finance, retail and tech. Today, he's the CISO at Endor Labs, a startup laser-focused on securing the software supply chain and a rising star in the Microsoft for Startups ecosystem. Before joining Endor Labs, Carl was CISO at No Name Security where he tackled API and application security head on. His resume reads like a roadmap through high-stakes cybersecurity leadership. He's held CISO roles at City National bank and PennyMac Financial, served on the FS ISAC Mortgage Risk Council, led the LA Cyber Lab, and even graduated from the FBI CISO Academy. When he's not leading security teams, he's been shaping minds as an adjunct faculty at the University of Minnesota for over a decade. [ Music ] Well, let's start out with a little bit of the origin story here. I mean, I -- I have to say, I'm enamored with the company name, but tell us about how the company started and -- and what your mission is.
Karl Mattson: Sure. The -- the company started just over three years ago. Varun Badhwar at -- at the time was leading the -- the Palo Alto PRISMA business unit. He had previously founded the company RedLock that was acquired by Palo Alto. And while he was there at Palo Alto, there was a -- a major open-source vulnerability event. And it was at that -- it was in the scanning of that environment where Varun sort of had the seed of an idea that scanning software is extremely noisy in Error Pro [phonetic]. And so, he started Endor Labs with -- with Dimitri Stiliadis who was a -- a counterpart at Palo Alto. So, Dimitri and Varun, about three years ago started the company with the mission essentially of reinventing software vulnerability analysis. We commonly have in the software industry noisy, antiquated, open-source scanners. And so, we've eventually reinvented the scanner and reinvented the way that we -- we -- we look at software vulnerabilities, starting with SCA, starting with Open Source, and now a much broader set of capabilities.
Dave Bittner: Well, I -- I think, you know, we have to talk about AI, which I know is a big part of your technology and your product here. How do you apply AI to this task?
Karl Mattson: Yes, great question. So, there's really a couple of ways to look at it. The -- the first is, as a company, we have a whole range of proprietary open-source research that -- that we've performed that I -- I would call it an enrichment layer on top of the national vulnerability database and -- and other vulnerability databases. That enrichment labor is -- is really our -- our data moat. And so, when we roll out capability that sort of -- if you're familiar with the concept of a RAG, a Retrieval Augmented Generation, that is essentially a local data set that can be utilized by our customers in an agentic AI, a sort of efficient operating model, that really accelerates an app sec team's, you know, capabilities but kind of leverages that -- that data set in -- in our -- our new agentic AI offering. And then the second area of that is then MCP, which is an anthropic protocol -- Model Context Protocol that came out about six -- six weeks or six months ago. That protocol really is for LLMs to talk with -- with each other. And so, we have also released an -- an MCP server that allows organizations that use Cursor or Copilot, this sort of code generation revolution. It's -- it's an integration pathway for those platforms that's really remarkably fast and efficient.
Dave Bittner: You know, when we're talking about boards of directors at organizations, some of the places that -- that you serve, are their expectations realistic when it comes to AI? Are -- are they prepared for -- for the types of things that -- that are the reality of this technology?
Karl Mattson: Oh, of course not. I think -- I think we learn that in each -- each technology revolution is that there is a -- is a trough of disillusionment. So, if you think back to like the mid-1990s and the -- the -- the sort of -- the dot com sort of explosion, it was many years later before turning that into revenue became a realistic possibility. E-commerce didn't blow up the moment the Internet occurred. It took a decade. So, I think that what we're -- we're going to do to certainly see is -- is board level expectations to -- to push the needle and -- and capitalize on AI. However, there are not yet a lot of examples of business models that have thrived with that kind of direction. I -- I think it's a matter of time, but right now, I think we're still in the very earliest stages of -- of sort of value capture in AI.
Dave Bittner: Kevin Magee, does that align with what you're seeing?
Kevin Magee: I spent a lot of time speaking to boards of directors, senior execs and it is exactly aligned. I mean, we've really shifted from this, "Are we secure?" discussion, this sort of negative security discussion, to "Hey, let's -- let's do everything with AI." Just the optimism is -- is really refreshing but it's challenging because how do we safely do things with AI really needs to be the conversation. So, I think, you know, startups like Endor Labs that are -- are empowering this vision of AI and building in -- in safety and security as part of the workflow are really something I'm interested in from an investment perspective, but also just a -- a capabilities perspective. How do we make these innovative leaps, but do it safely and not go back and repeat history where we've launched new technologies, run out with them to improve efficiencies, to build value, to -- to create opportunities which organizations should be doing and then figure out how to bolt on security afterwards. So, I think there's a unique opportunity right now.
Dave Bittner: Well Karl, let's talk about the security workforce themselves. You know, when it comes to hiring and training and -- and even retaining these people, with AI, is this requiring a new skill set? Are folks having to come into the job with new skills or are organizations finding themselves having to train people up?
Karl Mattson: Both are true. I think that -- that anybody who's a job seeker right now would best be served focusing on upskilling themselves in terms of basic generative AI, agentic AI technologies, but also internally for teams, for organizations to look at AI, as a -- and not just a -- a short-term fad, but -- but a long-term capability that -- that employees in the organization need to have really across the board and -- and supporting those trainees with -- or those -- those employees with -- with the training required to sort of upskill them to a baseline level of knowledge. I think we all need to look at this as a -- as an opportunity to upskill ourselves. And that's -- and that -- that is actually very good news in terms of like equalizing the -- the cybersecurity workforce. I think that the individual who really wrap their arms around AI capabilities and -- and begin to master them soon will -- will become very, very valuable to their organizations quickly.
Dave Bittner: Well, and let's flip the question around. I mean, in terms of the -- the people who are looking to take these jobs, what are they looking for in terms of security culture within an organization? What are the things that they value?
Karl Mattson: One of the interesting things that we see continuing to happen, finally -- let's go back to a couple years to the origin of the -- of the concept of shift left. And -- and there was a moment in time where shift left looked kind of like tossing things over the fence back to the developers or back to the DevOps teams. And that was oftentimes a recipe for failure. And so, there are certain -- certain successes but for the most part it was not a wild success. But here we are today in a -- in a really interesting place because now we can actually, with for example MCP integrations, we can put our security capabilities inside the developer's context or inside the DevOps team's context window. So, really quickly we now have security technologies that I would -- let's call them headless. The -- the UX isn't all that important, because the technology is running under the hood of the developers tools or under the hood of a -- of a DevOps team's tools and pipelines. That's a great move. That is an incredible upward trajectory of possibility for remediating vulnerabilities or getting attention on security is to have those security technologies inside of the developers' tools. So, I think culturally what that -- what that gives -- gives a security team, you know, the opportunity to be -- to be a -- a welcome asset at the table, not just the team that tosses vulnerabilities over the fence to you.
Dave Bittner: Kevin, I'm curious. You know, the startups that you work with, the ones who are having success both attracting talent and retaining them, what sort of commonalities are you seeing there?
Kevin Magee: I think startups are really becoming talent incubators. You know, what they really can offer are hands on AI security experience and capabilities development to employees. That's -- that's the real value. It -- it comes from working from a startup. Not only is it fun, it's really a chance to explore and learn very quickly how to -- to implement some of these -- these workflows or whatnot as well. But then startups also create value at scale for customers, and I think that's the key. So, it's not just learning those skills or whatnot, it's really often encapsulating some of this innovation into a product that customers can purchase to benefit from that, rather than having to source and -- and find all those employees and develop them on their own. I think it's a much more efficient way of -- of using talent more effectively. So, that's -- that's one of the things that has me most optimistic about startups and -- and their role in moving just workflows and cultures to this AI experience.
Dave Bittner: So Karl, you know, digging into open source software itself and -- and how organizations calibrate their risk when it comes to OSS, in your estimation, are organizations properly calibrated or -- or do they -- are they overconfident or are they underconfident? You know, where -- where do most organizations stand?
Karl Mattson: That's a great question. I think that organizations are -- are almost exhausted perhaps is the word I would use for you know, let's say open source scanning that's historically produced a lot of false positives or poor quality results, and incidents still occurring. And so, that endless cycle of chasing this enormous quantity of vulnerabilities and -- and particularly finding out that there are not -- they're not true positives, that's an -- that's an exercise in frustration and it's exhausting. And that's really where, like where we -- where we come in and where we come in and clean that noise up so that it's -- it -- it does not become exhaustive. And so, I think that what that does is it frees up an enormous amount of capacity and there's a sense of relief when we can get the -- the noise out of the -- of the open source scanner world.
Dave Bittner: You know, not all risks are created equal, and you know, they have different degrees of seriousness relative to any organization's risk posture. I mean is -- is that a big part of what you're helping folks with here as well, of prioritizing the things that are actually dangerous to the company itself?
Karl Mattson: Yes, absolutely. Because think of the -- the OWASP top 10. There's a lot of -- of risks that are not software vulnerabilities. So, in -- in our sort of open-source model, there's eight risk areas: legal risk, intellectual property risk, operational risk. So, for example, would be -- there are certain organizations whose -- whose ability to -- to be precise in their use of open source or third-party licensing makes a dramatic difference in the value of the company. That's a very important feature of -- of what we do, is to focus on all of these different aspects of risk, because it isn't just the software vulnerabilities. It's all these other operational viability issues to solve for. And that's really important for us to look at the -- the whole context of risk of software and be able to provide different organizations of different, you know, shapes and sizes, the -- the insight that they need for their risk profile.
Dave Bittner: Kevin, I'm curious for your insights here.
Kevin Magee: Well, the CISOs really described the -- the problem articulately. I think that makes most sense to me. Wouldn't it be great if we made sure there are no sharp edges on our products before we shipped it, kind of thing. And they were in the manufacturing industry. And -- and this -- this is -- makes sense to us in IT because we want to make sure that we're -- we're pushing production code that makes you know, that has no errors, that is error free. But it's not really embedded in a lot of organizational cultural approach to innovation. You know, build the application and they don't really know what's involved in it. It makes sense to leverage open source. It makes sense to leverage what's already been created and build on what others have already built to empower and move faster, but in moving fast, you know, we have to make sure we -- we look at all the associated risks. And -- and I think some of the ones we've, you know, discussed now are -- are good to articulate. It's not just a matter of is a code going to break or is it insecure? You know, what are the copyrights? What are some of the other challenges? What are the dependencies? And thinking through those challenges allows us to make sort of better decisions. The farther left we can shift that, the more secure we're going to be and the less challenges we're going to have in responding to some of these, either complaints legally or -- or actual software failures in -- in -- when code reaches production. So, this is an area that's really interesting to us and especially with our investment in GitHub and our capabilities in GitHub. How do we extend those capabilities? How do we provide more value to our customers in this space? And those are a lot of the conversations we have with Endor jointly with our customers.
Dave Bittner: Well Karl, how do you support that desire for velocity, to -- to make sure that, you know, security isn't the thing that's throwing sand in the gears or that the famous saying about being the department of no?
Karl Mattson: Well, I think it comes down to -- to two touch points that we focus on, that when you get them right, they become accelerators. The first is, the quality of the information about vulnerabilities. Reducing false positives may sound like a -- a punchline, but it really is -- is a very specific thing for us, which is to understand application context and -- and its nuance, because when we -- when we -- well, we call it program analysis but performing that analysis gives exceptionally detailed insight into vulnerabilities. Less noise, more actionable specific information. And then the second thing is giving the -- the opportunity to embed that -- that scanning activity, that program analysis inside developer workflows so that developers don't have to context switch, whether that's in their git [phonetic] repo, whether that's in their CISD pipeline. We need to give that -- that high-quality information, now put it in the -- in the place and time where it can be actionable, and with the sort of amplifying supporting information that allows the developer, the DevOps engineer, to make a great choice, in terms of how to remediate quickly. And so, both of those touch points give us opportunities to really move the needle and -- and allow those teams to -- to move forward, move faster, just ship -- ship better software faster.
Dave Bittner: Kevin, when you look at a startup like Endor Labs, what stands out to you? Why -- why is a company like this of interest to Microsoft?
Kevin Magee: It's velocity with visibility. I really think that's sort of the sweet spot. How do we make security a multiplier, a -- a value creator rather than a bottleneck? And how do we remove the challenges to a great experience for the developers or whatnot? So, they'll choose the right tools, they'll make security the easy thing to do, because we know when security is the easy thing to do, people will do the right thing. The more difficult we make it, security, the harder it is to -- to get them to comply. So, how do we really build it into the workflows right from the beginning of -- of software creation? I think that's what really interested me when I saw the first demos of Endor Labs is -- is that again, the -- the philosophy but with visibility was the key thing that stood out to me.
Dave Bittner: Karl, what's your message to the CISOs in our audience here? Words of wisdom based on your own experience?
Karl Mattson: Well, I think that we have to prepare everything in our organizations for the long haul right now. And I know that the world changes very quickly with AI, but -- but by the long haul I mean upskilling teams, rethinking our telemetry, rethinking that visibility, rethinking that -- that technology touch point. Because what's going to continue to happen is that there's this logarithmic increase in expectations and quantity of software and noise in the -- in the environment. And if we don't start preparing for that long haul right now with a sense of urgency, we're going to get behind very quickly. If we're not already behind, we're -- we're about to fall behind. And I think that's where we need to be looking at that future state right now and be -- be implementing that action plan without -- without meeting the -- the expectation of the board to be clear, we need to internalize that and know that it's coming sooner -- sooner or later. [ Music ]
Dave Bittner: And that's a wrap on this special edition, the "Microsoft Store Startup Spotlight." A huge thanks to all of our guests, Kevin Magee, FC, Matt Chiodi, Travis Howerton and Karl Mattson for sharing their insights, experiences and the incredible work they're doing to shape the future of cybersecurity. From tackling software supply chain risks and redefining GRC to hacking for good and building global startup ecosystems, these founders and leaders are proof that innovation thrives when community, trust and cutting-edge tech come together. We'd also like to thank Microsoft for Startups Founders Hub for making this episode possible. If you're a startup founder looking to level up your business with access to AI tools, Azure credits and expert guidance, this is your moment. And of course, thank you for tuning in. We'll be back with more stories, more innovators, and more reasons to believe in the power of the cyber startup community. Until next time, stay safe, stay curious and keep building. I'm Dave Bittner. We'll see you next time. [ Music ]

