Keynote, Fireside Chat, Interview
Stanford CS153 Frontier Systems | The Road Ahead: Resilience Required
Career Trajectory & Scope:
- Spent 8 years as a federal prosecutor with the US Department of Justice (starting 1995), becoming the first in their office to secure a direct internet connection.
- Moved to eBay in 2002, where they managed legal, safety, and security teams following the PayPal acquisition.
- Joined Facebook in 2008 (when it was smaller than MySpace), building the security team from 3 engineers to hundreds, and overseeing security during the acquisition of Instagram, WhatsApp, and Oculus.
- Served as the first Head of Security at Uber (2015–2018), scaling the team from 3 engineers to hundreds.
- Joined Cloudflare in 2018 as the first security executive, again scaling a 3-engineer team into a large operation.
- Currently runs a security consulting firm, serves as a Venture Partner at Costa Nova Ventures, and is the CEO of a nonprofit aiding Ukraine.
Uber Incident & Legal Challenges:
- In November 2016, a security vulnerability allowed two hackers to dump the database of 57 million users (12.5 million records) via compromised AWS credentials.
- Uber paid the hackers $100,000 as a bug bounty; legal counsel advised against mandatory government disclosure of the breach.
- In 2020, the speaker was charged by the FBI with obstruction of justice and misprision of a felony for allegedly concealing the incident from law enforcement.
- Trial in September 2022 resulted in a guilty verdict; the jury convicted the speaker despite evidence that the CEO and legal team approved the decision and that data was deleted by the hackers.
- The conviction hinged on a jury instruction that Uber could not legally grant retroactive authorization for the hackers' access under 18 USC 1030.
- Sentencing hearing in May 2023 saw the judge criticize the prosecution, noting no financial incentive for the defendant and that the CEO was fully aware of the actions.
- Sentence: Three years of probation and a small fine; probation completed in May 2024.
Post-Conviction Resilience & Community:
- Received over 200 letters of support from the cybersecurity community during the sentencing phase, which influenced the judge's leniency.
- Launched "Digital Wings," a nonprofit program distributing thousands of sanitized laptops to Ukrainian children and military families.
- Rebuilt reputation by speaking at major industry events (DEF CON, Black Hat) and securing keynote roles globally, including an AI conference in Tokyo.
Current Threat Landscape & Trends:
- Ransomware Evolution: Shifted from state-sponsored political attacks (e.g., Saudi Aramco, Sony) to a massive private-sector industry; 2026 best practice includes retaining ransomware negotiators on retainer.
- Operational Resilience: Focus expanded beyond data theft to operational continuity; cited Jaguar Land Rover's 3-month production shutdown in 2025 due to ransomware, costing the UK economy billions.
- AI & Generative Coding:
- Developers are using AI to generate code at unprecedented velocities (e.g., a bank moving from 250k to 1.25 million lines of code/month in two months).
- Non-technical staff are increasingly deploying AI agents, leading to unauthorized API connections and unsecured external servers.
- Security model must shift from static guardrails to real-time anomaly detection, treating AI agents like "toddlers in a house."
- Quantum Cryptography:
- Primary risk is "harvest now, decrypt later" where governments or adversaries store encrypted historical data to decrypt once quantum computers arrive (likely by 2030).
- Infrastructure providers (AWS, Google) are advancing quantum resistance faster than most enterprises.
- Anthropic's "Mythos" Model:
- Access to powerful AI models is tightly controlled; companies must build internal "harnesses" to prevent misuse.
- Release strategies involve selective transparency to avoid accusations of picking "winners and losers" among industries.
Regulatory & Government Relations:
- Support for "smart regulation" to protect users where commercial incentives fail (e.g., safety features for dissidents or children).
- Critique of government incompetence in technology regulation but praise for recent efforts to place private-sector experts (e.g., Emile Michael) in key policy roles.
- Advocacy for proactive government involvement in cyber prevention, including potential authorization for companies to "punch back" against active threat actors.
Executive Leadership Advice:
- Resilience: Leaders must anticipate crises ("getting punched in the face") and prioritize crisis management skills alongside technical expertise.
- Communication: Transparency during incidents builds long-term trust; opacity leads to long-term reputational damage.
- Stakeholder Management: Security leaders should dedicate 50% of their time to educating and building trust with non-technical executives rather than focusing solely on their own teams.
- Physical Security: Rising threats include executive kidnapping, coercion (e.g., family held hostage), and state-sponsored surveillance; companies must implement executive protection programs.
Future Outlook for 2026 and Beyond:
- Cybersecurity leadership is increasingly viewed as a core executive function rather than a support role.
- Demand for leaders with experience navigating high-profile crises is surging; companies are prioritizing candidates with proven "resilience."
- The industry expects a "steady state" in AI model development in a few years, but current dynamics remain volatile with rapid leaps in capability.