newsfilter.io
Interview, Fireside Chat

a16z Podcast | Making Security More Useable

  • The security perimeter will undergo constant evolution as environments shift from data centers to the full cloud and from personal devices to those handling all business functions, creating a mobile, cloud-based landscape that expands the attack surface while offering more security tools.
  • Attackers will increase in sophistication, collaborate more frequently, and exploit diverse channels including networks and call centers, evolving the dynamic from a "cat and mouse" game to a "cat and dog" scenario where the prey matches the predator's aggression.
  • New technologies lacking established security paradigms will fail immediately under fraud attempts, while fraud functions will globalize as organizations grow, resulting in centralized power over tool decisions across different lines of business.
  • C-level executives and board members will maintain heightened security awareness due to high-profile media vulnerabilities, increasingly involving security vendors like Okta because they are perceived to enhance organizational security rather than just usability.
  • Enterprise-wide security licensing will typically occur within six months of one line business adopting a solution, driven by the need to move from isolated implementations to holistic, cross-channel collaboration against attackers leveraging data from multiple breaches.
  • Security strategies must balance risk with functionality to avoid losing competitive opportunities to excessive risk aversion, as winning is defined by moving the organization forward rather than achieving zero breaches or reverting to legacy server environments.
  • The security paradigm will increasingly anchor on the "person" as the central identity, requiring context-based policy enforcement across people, applications, devices, and organizations, even for physical assets like IoT devices and steam shovels.
  • IT departments attempting to make security inconvenient or out-of-band will likely fail, whereas secure services must offer better user experiences than consumer alternatives, granting full access only to those adhering to security hygiene and protocols.
  • CISOs will operate under the assumption that breaches have already occurred, focusing on monitoring and limiting access to critical assets, while creating a communication gap with CEOs and boards who may still believe they have never been breached.
  • Organizations will need to implement frameworks similar to government classified levels to lock down super-sensitive information while providing flexibility for less sensitive data, alongside defining identity to account for evolving social norms and millennial data sharing.
  • Voice-based interfaces such as smart watches, rings, and Google Glass will replace keyboards as primary interaction methods, presenting an opportunity to define security from the ground up with platforms capable of detecting emotion, duress, and urgency to verify identity without impacting the customer experience.
  • As new voice interfaces emerge from major technology companies, security partners aim to set paradigms to change the battlefield, utilizing clever authentication to verify if compiled social and data information truly represents the person.
  • Security is a necessary component of function similar to breathing, as it is impossible to stop using technology to stay secure, and the definition of a breach will continue to change as society's norms regarding data sharing evolve.