newsfilter.io
Interview

a16z Podcast | Getting Security Right Isn’t as Hard as You Think (But the Effort Never Ends)

  • Detected attack volumes are projected to rise as organizations deploy detective mechanisms that previously failed to surface incidents, while attack sophistication will increase alongside the growing data exposure resulting from business reliance on internet accessibility.
  • Despite board-level recognition of cybersecurity as an existential threat driving spending to levels ten times higher than five years prior, most organizations will continue failing to execute basic hygiene practices like patching, disk encryption, and multi-factor authentication for years due to a resigned mindset regarding the feasibility of full device coverage.
  • The market for advanced security solutions remains focused on Global 2000 companies, as smaller entities lack the personnel capacity to handle complex threats, with only 1% to 2% of companies visited ready to discuss insider threats while the vast majority struggle with fundamental operational issues.
  • A persistent tension will exist between security teams prioritizing urgent vulnerabilities and operations teams fearing disruptions to business functions, often leading to a scenario where organizations ignore hygiene issues until suffering breaches, after which they engage in reactive "hair-on-fire behavior" rather than strategic planning.
  • The industry will continue to face a "never-ending process" of security optimization driven by the flux of environments, cloud computing, and mobility, characterized by "two steps forward and one step back" dynamics where business unit changes undo prior security work.
  • Nation-state attacks are expected to remain a "bloody conflict" where total prevention is nearly impossible, and all of the 10 biggest attacks this year will be traced back to mundane, known hygiene issues that organizations were aware they should have addressed.
  • While organizations with proper tools and coordination may address critical flaws globally in minutes rather than weeks, many will continue carrying vulnerabilities detected years ago due to a lack of urgency, and few companies will successfully build lasting world-class security organizations post-breach.
  • Security trends will shift away from fear-mongering and reliance on "silver bullet" vendor solutions, moving instead toward the realization that continuous daily effort is the only path to security, requiring organizations to first acquire visibility and basic knowledge of their infrastructure to enable change management.
  • Organizations that have not been hacked are expected to rationalize low risk, whereas those post-breach often exhibit "neurotic behavior" that hinders decision-making, with the industry eventually progressing through improved tools and discipline despite the current prevalence of ignorance regarding basic inventory counts.