POPULARITY
In this episode of The New CISO, host Steve Moore welcomes Sherri Douville for a conversation that sits outside the show's usual lane — less war story, more blueprint. Sherri works alongside CISOs rather than inside the role, and arrives with a pointed argument about what the job is becoming.She starts with why TTIC exists. IEEE UL 2933 gave healthcare a full-stack standard for clinical IoT device and data interoperability, but a standard on paper does nothing until it is adopted, implemented, and maintained. Getting there in a high-reliability industry means pulling in CIOs, CISOs, physicians, and engineers — and, Sherri admits, negotiating turf wars with bodies who assume you have come for their territory.Then the headline: how to make security cool. Sherri's answer starts with visibility — getting CISOs onto stages, onto podcasts, and into print in front of clinical leadership. Underneath it is a claim about trust. In healthcare, trust is the core of the business rather than an adjacent concern, which makes the CISO its natural steward. With AI pushing trust to the center of every industry, she argues that is the opening to become the rock star of the C-suite.Steve raises a banking CISO's framing of AI as a curious seven-year-old with a gun. Sherri pushes back on the spot: her analogy is the gifted teenager — capable, resource-hungry, and badly in need of direction. That leads to her real thesis. Scarce expertise used to carry economic value, and AI is rapidly compressing the worth of expert analysis. What appreciates instead is judgment, authority, execution, verification, organizational integration, and ownership of the outcome. Executives do not want more reports; they want the security problem to go away without adding coordination burden.The last stretch turns practical. Sherri walks through running Exabeam's open-source Praxen against Medigram's own code — painless to run, with remediation effort scaling to whatever standard you are chasing — and pairs it with Observra for continuous runtime telemetry. She closes on why it matters: when systems go down in a hospital, the real damage is not the outage hour but the fortnight of delays, miscommunications, and pile-up that follows for clinicians and patients.Key TopicsWhy standards bodies stall at adoption, not authorshipMaking security “cool”: visibility, stages, and executive presenceTrust as the core of the business in high-reliability industriesThe gifted teenager vs. the curious seven-year-old with a gunJudgment, authority, execution, verification, integration, ownershipSelective depth and the player-coach executiveRunning Praxen pre-deployment; Observra for runtime telemetryWhat a healthcare outage really costs, 14 to 20 days outGuest BioSherri Douville is CEO and Architect of Medigram and Founder and Chair of the Trustworthy Technology & Innovation Consortium (TTIC). She co-chairs the Trust subgroup of IEEE UL 2933 (TIPPSS), the standard for trust in clinical IoT. Medigram builds and operates Darwin, a governed AI decision platform whose agentic fleet runs in production and writes a sealed governance record at the moment of every agent action — an auditable trail for counsel, courts, insurers, and credit rating agencies. Sherri spent over a decade at Johnson & Johnson across a dozen disease states before physician leaders pulled her into healthcare IT and AI. She calls herself an accidental technologist: a domain expert who got into the code, logging 200 GitHub commits across June and July.GET A DEMO:
Today’s headline news for Canadian IT solution providers: Expel MDR for AI attack surface: Expel has launched what it says is the first managed detection and response service covering the full AI attack surface, extending its SOC capabilities to threats launched with AI, employee AI misuse, and exposure inside AI systems themselves. The company announced the expansion at Black Hat 2026, adding an Anthropic Claude integration that pulls enterprise compliance signals and prompt content into Expel’s detection pipeline. Expel’s operators work the prompt content itself to surface intent, not just activity, and the company has mapped its detection library to 13 of 16 MITRE ATLAS tactics. Expel Huntress CEO on autonomous adversary: Huntress CEO Kyle Hanslovan is warning that autonomous, AI-powered attacks have moved from theoretical concern to active reality. In an interview with CRN, Hanslovan cited OpenAI’s disclosure that its AI agents compromised the Hugging Face platform during testing, as well as subsequent Anthropic disclosures about its Claude Mythos 5 model, as evidence that autonomous hacking is already happening. Huntress, which recently crossed $250 million in annual recurring revenue, has built its business around protecting smaller organizations that lack enterprise-scale security teams. CRN Myriad360 acquires F3 Technology Partners: Myriad360 has acquired the assets of F3 Technology Partners, a Connecticut-based healthcare IT solution provider, pushing the combined organization past $1 billion in estimated annual revenue. While Myriad360 is U.S.-based, the firm services the Canadian market through its global logistics and international business operations. F3 brings deep healthcare vertical expertise to Myriad360’s portfolio, reinforcing a trend of mid-market consolidation that is creating a new class of “Super-VARs” with the scale to compete for multinational enterprise business. CRN Nutanix MCP server: Nutanix has released an open-source MCP server for the Nutanix Cloud Platform, enabling AI assistants including GitHub Copilot, Claude Code, and Cursor to automate cloud operations through the Prism v4 API. The move follows Ingram Micro’s MCP server launch for its Xvantage marketplace and reflects growing channel investment in the Model Context Protocol as a standard for AI-tool integration. Nutanix Halo AI Studio and MCP push: PSA vendor Halo unveiled AI Studio and MCP integrations at XChange August, giving MSPs tools to build AI agents for service desk, sales, customer success, reporting, and quarterly business reviews. The company also launched an MCP server to act as a central interface across MSP tools. Halo partner John Douglass of Pileus Technologies said the AI Studio capabilities are “a game changer” for automating service delivery. CRN CRN Annual Report Card winners: CRN announced the winners of its 2026 Annual Report Card at XChange August, with solution providers grading vendors across 23 technology categories. Notable winners included HPE in cloud computing and servers, Nvidia in GPUs, Exabeam in AI security, and Scale Computing in hybrid cloud infrastructure. Complete scores will be published on CRN.com on October 5. CRN Liquidware CommandCTRL 1.5: Liquidware launched CommandCTRL 1.5 with AI-powered endpoint diagnostics and browser-based remote control across Windows, macOS, Linux, and thin clients. The update adds AI Insights that interpret endpoint telemetry and extends remote support capabilities to browser-based sessions without requiring a client installation. Liquidware Read Full Transcript TRANSCRIPT TO COME
Today’s headline news for Canadian IT solution providers: [Schneider Electric]: The company yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what it says is the first multi-chemistry battery technology for distributed and edge environments. The platform accepts both VRLA lead-acid and lithium-ion batteries, allowing customers to start with lower-cost lead-acid and upgrade later without replacing the chassis. Read more on CRN. [Ingram Micro]: The distributor says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year, while IT Design Consulting says it cut quoting from hours or days to seconds. Read the announcement on Ingram Micro. [D&H Distributing]: The distributor is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option after Dell ended its relationship with Arrow Enterprise Computing Solutions. D&H says its Advanced Solutions+ business unit now accounts for more than 25 percent of its overall business. Read more on CRN. [Acronis]: The company unveiled an autonomous IT platform update with an AI-driven console, service desk, and migration tools designed to help MSPs automate operations and expand services. Read more on msp-channel.com. [NCC Group and SailPoint]: The two companies have partnered to strengthen identity security services for both human and non-human identities. Read the announcement on NCC Group. [Lexful]: The company announced general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Read more on Yahoo Finance. [Circana]: Research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term, with MSP executives noting persistent talent gaps despite automation advances. Read more on CRN. Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Tuesday, August 11, 2026, and here’s what’s happening in the channel today. Schneider Electric yesterday unveiled its next-generation APC Smart-UPS at XChange August 2026, introducing what the company says is the first multi-chemistry battery technology for distributed and edge environments. The new platform accepts both traditional VRLA lead-acid batteries and lithium-ion batteries, allowing customers to start with lower-cost lead-acid technology and upgrade to longer-lasting lithium-ion later without replacing the chassis. Adam Compton, offer management leader at Schneider Electric, told CRN that the chassis is engineered to recognize different battery chemistries through firmware and battery management systems, which then alert EcoStruxure IT monitoring software about the specific battery type and replacement timeline. The company says future battery chemistries will also be supported as they become viable. For channel partners, the flexibility creates new service opportunities around battery lifecycle management, assessment, and the Rip-Replace-Recycle refresh program. Gordon Lord, vice president of channels, said Schneider Electric is doubling down on its Gateway program to give partners visibility into distributed power infrastructure across customer sites. The online versions of the new Smart-UPS are slated to be available starting September 1, with line-interactive versions following next year. Partners will not require new certifications. Canadian partners working with regulated and industrial customers should note the air-gapped deployment potential and the EcoStruxure monitoring layer as a recurring services hook. Ingram Micro says hundreds of channel partners are now using its Xvantage Integration Hub and secure Model Context Protocol Server to connect AI assistants directly to their business systems. The distributor announced the expanded adoption last Wednesday, positioning the platform as a way to reduce integration friction and automate workflows across quoting, ordering, and customer management. Executive Vice President Sanjib Sahoo described the MCP Server as a way to bring AI directly into the flow of business, giving partners a secure, real-time connection to Ingram Micro’s data mesh without building custom integrations. Trust X Alliance member Matrix Integration estimates the platform will save its team between 1,000 and 1,500 hours this year. IT Design Consulting CEO Ryan Evans said his team cut quoting processes from hours or days to seconds using the XI Hub integration. Ingram Micro is offering on-demand training sessions to help partners build AI-powered solutions through the platform. The company is positioning the offering as part of its broader strategy to make Xvantage an intelligent operating layer for the global channel. Canadian partners should watch how quickly small MSPs adopt the plug-and-play connectivity, since Ingram Micro reports that smaller providers are the fastest adopters so far. D&H Distributing is now authorized to carry Dell Technologies’ full enterprise storage portfolio in the United States and Canada, adding a new sourcing option for partners after Dell ended its distribution relationship with Arrow Enterprise Computing Solutions last month. The Harrisburg, Pa.-based distributor is bringing Dell’s advanced infrastructure, including Dell Apex as-a-service and subscription technologies, to its Advanced Solutions+ business unit. Chief Commercial and Consumer Officer Marty Bauerlein told CRN that Dell’s decision followed an RFP process and was influenced by D&H’s execution capabilities and growth mindset. Partners including Precision Computer Services and CompuCom have praised D&H’s responsiveness and collaborative approach. D&H says its Advanced Solutions+ unit now accounts for more than 25 percent of its overall business. For Canadian partners, the move adds another distributor option for Dell storage and server infrastructure at a time when Dell is also rolling out program changes focused on AI outcomes and faster rewards. The timing means partners can evaluate sourcing alongside the new rebate and registration structures Dell is expected to introduce this month. In Brief – Acronis unveils autonomous IT platform update with AI-driven console, service desk, and migration tools for MSPs. NCC Group partners with SailPoint to strengthen identity security services for human and non-human identities. Lexful announces general availability of its AI-native IT documentation platform for MSPs, with plans to join the Pax8 and Sherweb marketplaces before the end of 2026. Circana research presented at XChange August says AI’s workforce shock is unlikely to ease in the near term. Full details and links in the show notes or the blog post. Later today on In The Channel, my conversation with Exabeam about rebuilding the MSSP commercial model to fix the economics of managed SIEM. And if you haven‘t heard it yet, check out my conversation with Chris Fabes from TD SYNNEX Canada about his three-sided view of the channel. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Craig Patterson, global channel chief at Exabeam For years, SIEM has been one of those technologies that looked good in theory but was genuinely hard to build a profitable managed service around. Deal-by-deal discount negotiations, licensing structures built for enterprise resale rather than recurring managed services revenue, and no predictable floor on margin. For many MSPs, the math just never worked. Exabeam – the combined company formed from the merger of the original Exabeam and LogRhythm – is making a direct play to change that. Global channel chief Craig Patterson and senior director of service provider alliances Peter Stratis join In The Channel to walk through the new MSSP commercial framework inside the recently launched APEX Partner Program. Two new licensing pathways: a single-pool capacity model for high-volume, multi-tenant environments serving SMB and mid-market clients, and a federated subscription model that isolates customer environments for compliance and data sovereignty requirements. For Canadian MSSPs navigating PIPEDA, OSFI E-21, or Protected B, that second model is the one to pay close attention to. Peter Stratis, senior directof of server provider alliances at Exabeam The conversation also covers Sherpa, Exabeam’s new AI-powered partner enablement platform – a move away from the traditional LMS toward an always-on coaching tool that can join partner sales calls in real time – and Agent Behavior Analytics, Exabeam’s new capability for detecting malfunctioning, misaligned, and subverted AI agents inside customer environments, included at no additional cost. The standout line from Peter Stratis – who called this his first-ever podcast appearance – is the one worth writing down: “We treated our service providers like resellers, unfortunately.” The new framework is a direct acknowledgment of that history, and an attempt to rebuild the commercial relationship from the ground up. Read Full Transcript Robert Dutt: Hello and welcome to In The Channel from ChannelBuzz.ca, bringing news and information to the Canadian IT channel community for the last 16 years. I’m Robert Dutt, editor of ChannelBuzz.ca and your host for the show. If you’ve been in the channel for any length of time, you know that SIEM has always been one of those technologies that seems great in theory but has been genuinely hard to build a profitable managed service around. Licensing models that weren’t built for multi-tenancy, unpredictable costs, discount structures that made margin planning more of a guessing game than a business model. A lot of MSPs have looked at the security operations space and quietly backed away for exactly those reasons. Exabeam, the combined company that emerged out of the merger of Exabeam and LogRhythm, is making a direct play to change that. They have overhauled their channel program into what they’re calling the APEX Partner Program and at the centre of it is a new commercial framework built specifically for managed security service providers. Two distinct pathways: one for high-volume multi-tenant environments and one built with compliance and data sovereignty in mind. For Canadian MSPs navigating PIPEDA, OSFI E-21 and Protected B requirements, that second lane is worth paying close attention to. I’ve got two Exabeam executives here to walk us through it. Craig Patterson is Exabeam’s global channel chief and Peter Stratis is the senior director of service provider alliances, the person who’s been working directly with MSSPs to build this out from the ground up. Let’s get right into it. My chat with Craig Patterson and Peter Stratis. Gentlemen, thank you for taking the time. Craig Patterson: Thank you, Robert. Super excited to be on here with you today, my friend. Peter Stratis: Thank you. Robert Dutt: Craig, can you just kick us off with a quick version of where Exabeam sits right now? You know, you guys went through a significant merger with LogRhythm not that long ago. Now you’re pushing an updated partner program. For solution providers who maybe haven’t been following closely, what does the combined company look like from a channel perspective? Craig Patterson: The short answer, my friend, is that we’re sitting in an amazing place. We’re absolutely in a good place positioning to really drive value to our partner community. And so to give you a little more context around that, like you asked, we’ve spent the last 12 months really kind of rethinking, reimagining the whole partner ecosystem in a way to create value for all of our partners globally. And so there was a number of things we went through over the last 12 months. We spent a lot of time really going to this assessment loop, understanding everybody’s perspective. So we did that by having very strategic conversations with our top-tier partners. We did some survey work. We looked at the broad landscape in terms of the trends that the partners are really looking for in these modern channel programs. So all of that really became this assessment loop. The output of that is that really became the foundation for what we built here with APEX. And so with APEX, the Exabeam APEX Partner Program, what you have here is you have a program that’s really centered on value that’s really focused on solving a problem that exists in our market today around enablement. And so when you think about enablement today, I’ve written a lot of articles on this. Most enablement programs really don’t drive to the level of outcome that companies are looking to have. Outcomes like conversion rates, outcomes like time to first deal, outcome rates like retention rates, all these things. And so what we’ve done is we’ve really focused on enablement as the key catalyst to really drive value to our partners. And so with that, we’ve launched new enablement programs really with a focus on increasing their competency level so we can align to those outcomes we’re looking to have with our company’s operating plan. And so there’s a lot of thought that’s got into this. The short answer is we have a program that’s built on value. It aligns to where the market is going and what partners are really asking for. Robert Dutt: Peter, your title as senior director of service provider alliances is a pretty specific role. Can you tell us a little bit about what that looks like sort of on a day-to-day basis and the big problems that you’re focused on? Peter Stratis: Sure thing. Thanks, Robert. Well, I’ve been with Exabeam for about eight years now and service providers have always been a key component of not only our channel strategy, but our go-to-market and just from our net new revenue perspective. After our merger with LogRhythm, that actually continues and if anything, it’s only been more emphasized because both from an on-prem and from a cloud perspective, we see the MSSPs being a strong driver of that strategy of our go-to-market. So over the last eight years, we’ve seen that trend of not only on net new revenue, net new logos being a major part of our business, but then how do, to Craig’s point, how do we support them? To be quite honest, in the past, it was quite difficult. We really didn’t have any kind of structured pricing for these partners. It was, to say the least, it was more of a resale program that had some discounts tied to it. So through Craig’s efforts, through our whole surveys and our intent to really go after this market and treat them the way they should be treated, he mentioned that we did these surveys. We asked internally, what do you look for in a service provider partner? We asked externally what these partners were looking for from us. And that’s when in building the APEX Partner Program here at Exabeam, we also took into account what service providers would look for in a new partner program. So that’s everything from pricing to support. Craig mentioned enablement. Enablement is a huge part of that, where they felt in the past they were just lumped up as just a regular partner. Now we have supported APIs, documented APIs that most, if not all, of our partners are using as part of their foundation for their services. So we’ve really come a long way and continue actually to build upon that, as you’ll see throughout 2026 and beyond. Robert Dutt: Okay, let’s get into the framework itself. You guys positioned it at launch as solving commercial and operational friction for MSSPs. Curious, what did you hear that friction looked like in practice? What were MSSPs telling you was broken or was a big challenge? Craig Patterson: Yeah, so I’ll take a stab at this and I’ll let Peter give more context. So a lot of this came out during that assessment phase. Robert, we’re talking to the MSSPs globally. I’m like, what’s working? What’s not working? What would they like to see incorporated into the MSSP program 2.0? So a lot of the feedback we heard was really around the flexibility. Being able to have a license that is catering to all the customer demand they have beneath. So it’s really giving them the flexibility to buy that one license and carve it up as they see fit. And giving them more flexibility on the commercial terms. That was a lot of the commentary we heard. The other thing we heard was really they wanted more value as it leads to the enablement side. So obviously getting them enabled on the pre-sales side, but more importantly on the post-sales side. So they could actually drive those implementations, drive the management and really help those customers create a lot of value. And so I think those were kind of the big levers that I heard from those assessments. And then in practice, Peter can give you some more context in terms of how we’re putting all this together. Peter Stratis: Yeah, thanks Craig. A lot of what we heard from the service provider community in the past was friction. So when they’re trying to price out their services and our product and etc., they were seeing friction at onboarding. They were seeing friction in trying to predict their margin on deals. As mentioned, not airing any dirty laundry here. It was more like a resale program. So we gave discounts and there were very opportunistic discounts on a deal-by-deal basis. So they didn’t build predictable service models around it in the past. And then you always hear the buzzword, multi-tenancy. We kept on getting asked about our multi-tenant roadmaps, etc. We’re looking at this framework as a way of solving for that. We continue to make feature enhancements into the platform that will strive for that multi-tenancy. But the way we’re solving for it is by these two pathways. One is that single license, pooled capacity, data segregation model. And the other is that federated workflow that we announced where it’s more for, whether you’re within data sovereignty, if in different regions or just different use cases from a compliance perspective, whether it’s healthcare or finance, and you have to keep these environments isolated. We have a plan and we worked with our MSSPs specifically to have these kind of pathways. So we heard from our MSSPs and we actually developed these two pathways with them in mind. So they were in the design phase and in the rollout phase for both federated and the single pool capacity. Robert Dutt: The federated model is such an interesting one, I think, for the Canadian market, specifically data sovereignty, huge topic. And there are specific compliance requirements, PIPEDA, OSFI E-21, Protected B status. It means that a lot of Canadian MSSPs can’t just kind of throw everything into one pool. Was that the sort of thing that was explicitly on the radar when you built this out or a happy coincidence of the architecture and the feedback that you heard along the way? Peter Stratis: It’s actually a little of both, right? So it just so happened to be the maturity of our platform. Even from our Exabeam New Scale platform, we went from an on-prem hardware appliance way back in 2012, to our version 1.0 was a SaaS product, to our native cloud. It was always a single-tenant solution. So it worked well for certain service providers that had the capacity. They had their APIs and their own platforms that could manage this solution. As you heard more and more about multi-tenancy and the need for data sovereignty and all that, we still had a big part of our MSSPs were asking for this single license pooled capacity. So we structured it in a way where for midsize organizations or even some small, medium business, you still have that single pool capacity using data segregation. You lose some of the customization, but you could actually solve for a lot of those customers in that model. And then you have another plan with the federated. So the more mature MSSPs are running both models in some capacity. They could still run that single license for their SMB play. And then for either large enterprise or very compliance-driven customers that want those isolated environments, they have that flexibility. And that’s what we built a framework around. Obviously, that’s one point of feedback that sort of directly informed the framework. Robert Dutt: You guys have said that this whole thing was built, as you said, with direct collaboration with your MSSP partners rather than kind of coming down on high. I’m curious along with what you’ve touched on already, what actually changed as a result of going through that process? What did you go in thinking you’d build and how did it come out differently because of what partners told you along the way to building it? Craig Patterson: Yeah. So I think there’s a lot of things that have been addressed. Obviously, the packaging and the commercial aspects as Peter was describing, but think about some of the fundamental problems in terms of partners want this path to profitability, right? Really understanding how they can create margin. That was one thing. Another path is like, how do I become enabled with Exabeam? And how do I stay informed in terms of where you’re going? Another problem we wanted to solve. So I think it’s a lot around the financial aspects of doing business with us. A lot of it’s around becoming enabled, becoming more knowledgeable on all the new features and releases that we’re dropping. And so those were some of the big fundamentals that we wanted to solve in the APEX framework. And then beneath that, obviously, is the whole MSSP play. And that’s what Peter’s been talking about. So you can probably give a little more context on that. Peter Stratis: Yeah. As mentioned, there is no one-size-fits-all. So the feedback we were getting was obviously their security platform was important to them. Some of them had an in-house platform they built on their own. And there’s ways of differentiating. So basic SIEMs are just going after alert monitoring. So how can I differentiate my service if I’m a service provider? Well, there’s ways of going to market, but also there were things we needed to do in the back office from a platform perspective to make those possible. So making our behavioral analytics available in these models so they can actually differentiate their services. As I said, we have a history of actually adding features quarter-over-quarter, month-over-month. So that’s not stopping. We didn’t announce necessarily multi-tenancy to the world. We announced a commercial framework for that. So you’ll continue to see on a month-to-month, quarter-over-quarter basis, features added to support not only the commercial framework, but the underlying platform to make it easier for service providers to add that operational efficiency, to add those differentiators from a product portfolio as well. Robert Dutt: Let’s talk about the economics underneath there. You use the term predictable margins as a phrase that shows up in the messaging. SIEM has historically been a tough service to make money on. Licensing models that didn’t fit the managed services motion, unpredictable costs on data ingestion, those sorts of things. What specifically changes for an MSSP’s P&L under the framework? Craig Patterson: Yeah. So I think there’s really two components here. The first is the whole financial package associated to the MSSP partners. And the second is the discounting framework. And so let’s maybe start with the discounting framework. One of the observations that we made during this whole assessment phase was the vast majority, Robert, of all of our deals were flowing through this non-standard process, which means the discounts that were aligned to the traditional framework were not putting the MSSP partners in a position to actually transact. And so what we did is we went through and we re-looked at the discounting framework and sort of realigned it based upon our actual data points. We looked at the last 12, 24 months, the discounts that were being derived to actually transact. And we sort of rebuilt the entire discounting framework for our company in a way that really empowers the MSSP partners now to have enough discount to actually transact without going to this non-standard queue. So what does it mean? Well, we really kind of flipped the script. Instead of 80% being non-standard, we believe 80% will flow through the standard process now because we’ve built the discounts in a way to align with what the market is looking for. That’s kind of the key component number one. And then as it relates to the discounting side, we reimagined how those discounts are calculated. And so now you kind of have your standard program discount. So that’s based upon your tier. So top-tier MSSP partners get the highest level discount. The second is deal registration. Obviously, they put the deal reg in that ties to a discount. Those are both standard common things. But what’s new, which is what you care about. What is new? Well, we’ve aligned the third discount based to their competency level. And so we measure that based upon certifications. And so if you think back to those choose-your-own-adventure books as a kid, we’re really giving the partners their own choose-your-own-adventure. And if they want to drive to the highest level discount, well, simply, MSSP partners got to go take all of our certifications, pre-sales and post-sales, so they have the highest level of competency to drive our services in the market. And our thesis around that is partners that have higher certifications, they’re going to be more active, they’re going to be more interested, they’re going to drive more pipeline. And if we do this the right way, Robert, they’re actually going to convert at a higher percentage, we’re going to see shortened sales cycles, all of which align to the operating plan of our company. So it’s kind of those two fundamental things that were addressed through that process. And then I’m sure Peter can fill in the detail for you. Peter Stratis: Yeah, if I can actually elaborate on that. Thanks for that, Craig. And just some historical context, Robert, as mentioned in the past, we treated our service providers like resellers, unfortunately, so it was very deal-specific in terms of what they were getting on a deal-by-deal basis from a discount. So the economics of it was they really couldn’t rationalize their margin predictability on an overall services basis. And you know, different regions go to market different ways. In Europe, Asia, Latin America, predominantly, it’s all SIEM as a service and MSSP owns the license. In the Americas, both US and Canada, we saw a lot of proliferation in the past of customer-owned licenses. So the MSSP would resell the license, and consequently, just provide managed services wrap on top of that. Not only do we see more of that MSSP-owned model now where it’s SIEM as a service in the US and Canada. So it’s proliferated itself throughout all the regions. Now with these frameworks, we actually are able to build these economics, the margin predictability, as Craig mentioned, because now they know as a standard, what they’re going to be selling for. So especially as we do this federated model, and even the single license, you know what your price is across the board, you know what license you’re buying, you know what price you’re buying it for, you know, the more customers you add to these models, the more your profitability will increase as well. So it continues to grow from a pure profit play. Partners want to know what their margin would be as their customer licenses grow. And this is exactly what the framework did. Robert Dutt: This is sort of a broader question around MSP/MSSP distinctions as opposed to directly about the framework. But there’s a distinction worth drawing between an MSP trying to bolt a security practice onto the existing managed services business and the established MSSP who’s been at this for a year or who has built it up. Are those two different conversations for you? And if so, what are the different entry points and care-abouts? Peter Stratis: So it’s interesting, not only because of this announcement, even prior to it, the announcement of the APEX Partner Program here at Exabeam caused a lot of interest from partners and different kinds of partners. The traditional MSP, when inquiring, it was kind of hard when we were vetting them that they had no security practice of their own. So oftentimes they would actually outsource that security to an MSSP, to a classic MSSP, or maybe just resell services from those other organizations. We see that, we see a lot of interest from MSPs with that. And we see VARs or resellers come to us that want to build managed service practices as well. So we look at both of these in two different ways. One, how can we take care of these partner inquiries now, and then how can we grow with these organizations? So both MSPs and resellers that are interested in managed services now, our first inkling is to try to introduce them to our current managed service base. These people have the experience, they have the certifications, they have the technical knowledge. We’ve seen that move from a lot of MSP partners actually having channels of their own. So they actually sell their MDR or MSSP services through a channel of resellers or MSPs. But then if that’s our first step with these type of partnerships, then it’s like, how can we grow within your organization? How can we help you get the technical skills required? Because for a true MSP to have success, not only in SIEM, but just security as a service, you can’t just train one or two people, you need the 24-by-7 support, you need the tier one and tier two level of support services as well. So you have to grow your organization or outsource it to people that are already prepared to handle that. So that MSP play, we actually see it more and more going towards our current managed security service providers and getting that as a resource. Craig Patterson: Just to add a little more context to that too. So this actually becomes a very interesting point for the distributors worldwide as well. Because a lot of what they provide in terms of value is helping those MSPs in terms of deployment and management of the services. And so we’ve gone through the vetting process globally, looking at all of our distributors and we’ve handpicked our strategic distributors around the world. So if we have MSPs that want to come into the program, but they’re not ready on that post-sale side, well, guess what? That can become the role of the distributor. And secondarily, this is where the enablement really comes into play as well. And so that’s why we’ve built very specific paths on enablement, pre-sales and post-sales, where partners can choose their own adventure. “Hey, if I want to get going on the pre-sale side, well, guess what? I can simply resell.” Or, “Hey, I want to really start focusing on the post-sales services implementation.” I can start to take the enablement around those courses to become more of an expert to really give me those new capabilities. And so there’s a whole conversation around what we’re doing on enablement with our brand new Sherpa that’s really given a lot of these partners those capabilities. Robert Dutt: On the note of Sherpa, an AI-powered tool for partners, it’s essentially a virtual channel account manager in terms of enablement, onboarding, that sort of thing, especially for an MSSP who’s new to SIEM. How does it change the friction of getting started with Exabeam as their platform? Craig Patterson: You’re going to love this. You’re going to love this. So we’ve sort of reimagined all of the enablement. Again, when you look at traditional enablement, it’s like most enablement is built in these LMS platforms. Like, “Hey, partner, go log on to this LMS platform, get your certification, and then we expect you to actually know what the hell you’re doing.” Reality is that’s not what happens. They log on to the LMS platforms. They fast-forward as quickly as they can to the end. They turn the volume down. And then when the quiz comes, they use AI to answer the questions. And so they just find a way to get the certification. The reality is none of that helps them be better in life or actually raise their competency. And so that’s a problem we took on head-on with Sherpa. And so Sherpa was built in a way to really change the way partners learn with the whole goal of raising their competency level so they can be better on the market. And there was really like three use cases we were trying to solve with the emergence of Sherpa. The first is like you think about this global ecosystem that Peter and I have. We have 3000 partners. The partner ecosystem looks different. We have VARs. We have MSPs. We have MSSPs. We have distributors. We have the trusted advisor market as well. All of them have different needs in terms of where they are from a learning perspective. And so the first use case, Robert, is simply like a tool to be able to ask questions. What are the use cases? How do I position this? Why is SIEM or UEBA better than the competition? Just an always-on tool for partners to ask questions. And so that was kind of use case one. And then the cool thing around that is you think about the ecosystem being very global in nature. The other problem with LMS platforms is I’ve got partners in Japan. Well, that means the LMS platform they log on to needs to be able to talk to them in Japanese. And so the beauty with Sherpa, it does all the translation for us. And we’ve got 15 plus languages that are now live in Sherpa. Partners in Japan are talking to it. We got partners in India and all over the world really asking questions in terms of how we position our services. And that integration can be done by just logging on to our portal. You’ll see a bot pop up. They can just simply ask a question. It integrates in Teams, integrates in Slack. So that was use case number one. Use case number two was we reimagined the whole enablement certification platform. And so it’s a very dynamic learning experience. And so the way it happens is you log on, there’s a topic that you like, you click on that, you start learning, it asks you questions, it asks you to position services, and then you record your answer to how you’re actually positioning those services or the features. And it gives you feedback like, “Robert, you did really good on this aspect, but next time you should use this and this.” Or, “Robert, if you’re talking to a customer that’s in this vertical, you should talk about this use case because that’ll help resonate.” And so the whole certification process has been rebuilt and that’s the second use case. The third use case, this is a game changer. And this really goes to your question. And it’s an always-on coach. And so partners are now able to invite Sherpa to calls. And so as they’re having those conversations with customers, and the customer may say something or give them an objection, well, in the background, Sherpa will give them the answer to that objection and say, “Customer said this, talk to them about this.” Or, “Have you shared this new feature that was just released in the quarterly launch?” So it’s like this always-on coach, always-on assistant to really give them what they need. And then we’re putting it on this innovation roadmap. And so every single quarter, we’re launching new innovation in Sherpa. As an example, we’re now launching our LinkedIn integration. So if you’re an MSSP partner, you log on to Sherpa, you’re connected to LinkedIn, it’s going to ask you, if Sherpa can look through your network to find customers that may be a good fit for our services. And then it’ll say, “Okay, great. We found these contacts. Should we go ahead and write the campaign? Should we write a campaign that you can use to send to those customers in your ecosystem on LinkedIn?” And so quite honestly, I think we’re bleeding edge in terms of really being able to use AI and adopt AI in a way to drive good outcomes, well beyond where most companies are with their simple ChatGPT things like that. We’re actually driving outcomes. Robert Dutt: The rise of AI baked into the partner program and partner tools is a fascinating space for me to watch. And that certainly, you make a compelling case for the role of Sherpa there. That sounds really interesting. A quick one on the product side, not directly related here, but just out of curiosity, Exabeam just dropped Agent Behavior Analytics in your April release, sort of extending behavioral detection to AI agents, ChatGPT usage, Copilot activity, those kinds of things. For an MSSP looking to take this to market as a service, is it a new revenue line? Is it an upsell? Or is this sort of becoming table stakes that clients expect to see bundled into what you’re doing for them? Craig Patterson: I’m glad you asked. It was just recently at RSA, the conference, obviously AI is the buzzword, but what do you do with that? When we presented the agentic behavior analytics to a lot of our partners or potential new customers, the question that was often asked was, “Well, how much is this extra?” And that’s not how we license our product. So the behavior analytics has been part of our solution since our inception from our analytics model. So specific to AI, this is going to be, you could differentiate your service from other service providers by using this behavior analytics, but by no means is it an extra cost on the MSSP’s behalf. So they’re going into an organization that has a thousand users, human entities, and overnight they now have 10,000 non-human entities. We look at and model all of them using our analytics. So now you actually have at least a basis of what’s normal from a behavior standpoint for both non-human and human entities. So we really change the game, but haven’t changed the pricing along with it. So it comes naturally within our platform. So no change for me as a partner, but if I can find a way to upsell based on it, all the better. If not, I add additional features. Hopefully my customer is more happy. Peter Stratis: I was just going to say, if you look at the macro trends we’re seeing, this is the number one conversation that’s being had right now, especially like you look at the financial sector. Every single company is facing this problem. And so this really, not only does it give them a new use case to go after, I think it just makes the overall security services of Exabeam more relevant based upon what’s happening in the overall market, which all that makes the revenue stickier, makes those conversations more impactful that those MSSP partners are having. Craig Patterson: Yeah. Well, what I’m going to mention is operational efficiency and service differentiation is what’s key to our MSSPs and their success. So the license is foundational. And now that we’ve actually solved for being predictable from a margin perspective, how can they differentiate themselves, making them operationally efficient using automation, using our threat detection, and then also the service differentiation. And the other thing too, just thinking through this a little bit, I mean, there’s different AI agents that exist out there that are doing different things. You think about the malfunctioning agent, the one that’s just off base and it’s doing things that are just incorrect based upon the fundamentals or foundation of the AI agent. That’s one thing that gets addressed by looking at the abnormal behavior. The second is the misaligned agent, the ones that are pursuing goals in a way that could negatively impact the company. And that gets a little bit more scary. But really what gets scary is those subverted agents, the ones that have been hijacked that are actually causing harm. And so you think about all those different use cases that are happening, and that’s the beauty of what we just released is our new ABA, sort of creating this new category in the market. That’s really what our ABA is looking for, is all those different things that are happening, whether it’s misused, misaligned, or subverted. All that can be detected through this new agent behavior. Robert Dutt: Okay, last question for me. If I’m an MSP who’s been sitting on the sidelines, I’ve been thinking about them or are upgrading my security operations practice. What’s one thing that you wish I understood about the opportunity and the economics, but I probably don’t at this point? Peter Stratis: It’s all about how they actually start off. They’re interested in selling managed security, but they don’t know that they have to standardize their delivery model. They can’t make it where every customer is custom, because that’s when that price predictability goes away. So everything from onboarding to customizing your offering has to go away. You might be able to do it for a certain amount of customers, but you have to build a model that’s repeatable. Automation is going to be very important to that. And then finally, you could add optional add-ons, but you have to resist the temptation to over-customize everything. The great thing about what Craig has done with the APEX Partner Program and the way we built it out here at Exabeam is it supports all of this through all the enablement efforts. So Craig mentioned all the enablement built into the program, but then we have certification tracks. So we’ll help you along in that process. And we have everything from APIs and the use case and the scripts to help you automate that track for you to make it easier, but just don’t jump in and try to do a custom solution for each customer. Robert Dutt: Gentlemen, I thank you very much for your time. Once again, I appreciate your walking us through the commercial framework. Craig Patterson: Thank you, Robert. Appreciate it. Peter Stratis: Thank you, Robert. Robert Dutt: There you have it. Craig Patterson and Peter Stratis from Exabeam. I’d like to thank Craig and Peter for their time today. And a special note, this was Peter’s first podcast appearance. You never would have known it. A few things I’ll leave you with. First, if Peter’s candid admission landed for you — that Exabeam used to treat service providers like resellers with opportunistic deal-by-deal discounts that made it impossible to build a predictable margin — sit with that for a moment. Not unique to Exabeam. That was the industry. And it goes a long way to explaining why so many MSPs have struggled to make managed SIEM work as a business. The new framework is a direct attempt to fix that math. Two pathways: a single-pool capacity model that works well for SMB and mid-market clients, and a federated model that isolates environments for compliance-heavy customers. The discounting structure has been rebuilt from the data up with the goal of moving 80% of deals through a standard process. Up from what Craig described as the opposite of that. The Sherpa AI tool is worth watching closely, not just as a training platform replacement, but as an always-on coach that can actually sit in on partner sales calls and surface real-time objection handling. The LinkedIn integration is coming next, and it starts looking less like an LMS and more like a business development tool. And the closing advice I’ll leave you with is Peter’s. If you’re an MSP thinking about entering the security space, standardize your delivery model before you take on your first customer. Resist the urge to customize every environment. That’s exactly where price predictability and profitability goes away. Thanks as always for listening. In The Channel is available on Apple Podcasts, Spotify, YouTube, and all the major podcast directories. If you’re finding value in the show, leave a rating or review. It goes a long way to helping other folks in the channel find us. Until next time, I’m Robert Dutt for ChannelBuzz.ca, and I’ll see you in the channel.
Ravi Soin has clear advice for anyone starting a security career today: don't be a risk manager, be a trust architect. In this episode, Steve Moore sits down with Ravi—CIO and CISO at Smartsheet—for a builder's-eye conversation on the modern CISO role, AI as an accelerant on old sins, and why the CISO who still says “no” is already obsolete.Ravi traces his path through Sun Microsystems, RealNetworks, a decade at Microsoft, and 15 years at healthcare software leader Edifecs to his eight months at Smartsheet. He explains what it means to think about security the way builders do—understanding where corners get cut under sprint pressure—and why that inside-out perspective changes how you defend.Steve and Ravi dig into how Smartsheet is deploying agentic AI across the enterprise: a centralized knowledge graph tied to every corporate system, Claude-powered threat models, DAST and SAST scans, SOC triage on the 80% phishing baseline, and MCP-connected asset and license management.They name the old culture directly. It was an era of risk registers where lows and mediums were quietly punted, tens of thousands of known vulnerabilities were accepted as compensating- control fiction, and time-to-exploit was assumed to be forgiving. Both push back on the panicked reaction to the Mythos disclosures, arguing AI has simply closed the exploit window on the trash environments were already ignoring.Ravi's core advice: build trust into the system, think about security through the customer's lens, and treat AI agents as first-class identities under the same IAM principles you apply to humans. He and Steve close on how incident response must be re-fit for the agentic era, why auditability is the non-negotiable foundation of AI governance, and why community remains the sharpest source of learning.Key Topics• Thinking about security like a builder, from the inside out• Why the CISO who still says “no” is already obsolete• Deploying agentic AI across engineering, SOC, and corporate systems• MCP-connected asset and license management• The old risk-register culture and how the industry was gambling• Why the Mythos reaction missed the bigger story• Advice to your 21-year-old self: be a trust architect• Building security through the customer's lensGuest BioRavi Soin is the CIO and CISO at Smartsheet, where he leads global IT and security strategy for the AI-enhanced enterprise work management platform. He brings more than two decades of security and IT leadership, including 15 years as CIO and CISO at healthcare software leader Edifecs and product roles at Microsoft, RealNetworks, and Sun Microsystems. Ravi serves on the SeattleCIO advisory board and was named Seattle CIO of the Year.GET A DEMO:
What if your next breach came down to a token budget? In this episode, Steve Moore is joined by Lou Rabon, Founder and CEO of Cyber Defense Group, for a conversation on the modern CISO's world—from how to interview for the seat, to why AI agents are the next insider threat, to research that reframes breach cost as a token calculation.Lou and Steve open on breach response, why making introductions during a crisis is a losing game, and the questions every CISO candidate should ask before accepting an offer. Lou lays out how many rounds of interviews a serious CISO role should include, why the CEO must be involved by the final round, and why he believes Legal—not the CIO or CTO—is the ideal reporting line for security.The conversation pivots to AI. Lou argues we are watching a dot-com-speed shift, only compressed. They dig into the emerging insider-threat framing for autonomous agents, the recent incident where an AI slipped its sandbox to contact a researcher, and why attackers face none of the ethical guardrails defenders must respect.Steve shares recent Cornell research showing that agentic tooling can already automate 22 of 32 steps in a corporate intrusion, compressing hours of expert work into seconds—with token spend as the only real limiter. If a breach can be priced in tokens, they argue, defenders must think in tokens too, and machine-to-machine defense becomes a necessity rather than a novelty.The episode closes on what Lou calls “the dirty secret” of cybersecurity: the unglamorous hygiene work—asset lists, data maps, MSA notification clocks—that no one wants to fund. He and Steve explore how agentic AI could finally deliver the always-on trash collection defenders have wanted for decades, from dynamic breach-notification tracking to a security agent that flags every new device.Key Topics• Why making introductions during a crisis is a losing strategy• The interview questions every CISO candidate should ask• Why Legal is the ideal reporting line for the CISO• The inverse curve between convenience and security• AI agents as the next form of insider threat• Cornell research: 22 of 32 intrusion steps automated• Tokens as the new unit of breach cost• Machine-to-machine defense in financial services• The “trash collection” hygiene work at the heart of InfoSec• Agentic AI for asset lists and breach-notification analysisLou Rabon is the Founder and CEO of Cyber Defense Group (CDG), a cybersecurity strategic advisory firm he launched in 2016 to help fast-growing organizations manage modern risk and threats. With more than two decades in security, privacy, and incident response, Lou has led response engagements against nation-state attackers and previously served as CISO at Spokeo. Connect with Lou on LinkedIn or learn more at cdg.io.GET A DEMO:
Today’s headline news for Canadian IT solution providers: OpenAI Partner Network: OpenAI‘s inaugural Partner Network is officially live as of July 15, with vice president of strategic global partnerships Colleen Kapase confirming the three-tier program is backed by $150 million in channel investment. Partners can progress through Select, Advanced, and Elite tiers while earning specializations in areas like Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by year-end and is recruiting solution providers of all sizes that can put AI systems into production. OpenAI Carbon60 MSP 501: Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, ranking among the world’s top managed services firms by revenue and operational discipline. The company has built a differentiated practice around Canada-first sovereign cloud and Azure expertise, and the ranking follows a broader push by Canadian MSPs to demonstrate global competitiveness in compliance-heavy verticals. Carbon60 RecordPoint channel-first: RecordPoint has launched a global partner program that CRN describes as a channel-first move, enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. Partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. Channel Insider Blackpoint Cyber 2026 threat report: Blackpoint Cyber has released its 2026 Annual Threat Report, finding that attackers are increasingly exploiting trusted IT tools rather than using perimeter breaches. The report highlights abuse of remote monitoring and management platforms, VPNs, and identity credentials as primary vectors. ChannelPro Network Managed security market growth: Acronis and Omdia project the global managed security market will grow from $93 billion in 2025 to $106 billion in 2026, a 14.4 percent increase. The growth reflects sustained demand for outsourced security operations among mid-market organizations that lack internal SOC capacity. RAMageddon pressures PC refresh: Industry analysts and OEMs continue to signal significant PC RAM price increases through 2026 due to the ongoing memory supply shortage. Channel partners should advise clients on refresh timing and alternative configurations to manage budget impact. CNET Exabeam MSSP licensing: Exabeam has expanded its APEX partner program with pooled and federated licensing options designed specifically for MSSPs. The new framework is intended to reduce onboarding friction and simplify compliance across multi-tenant security operations centers. Security Brief Read Full Transcript Welcome to The Buzz from ChannelBuzz.ca, I’m Robert Dutt, today is Thursday, July 16, and here’s what’s happening in the channel today. OpenAI’s inaugural Partner Network is officially live as of yesterday, July 15, with the company backing the three-tier program with $150 million in channel investment. Vice president of strategic global partnerships Colleen Kapase confirmed the program is open to solution providers of all sizes, not just global systems integrators. Partners can progress through Select, Advanced, and Elite tiers based on sales performance, technical capability, and deployment experience. The program includes specializations in Codex, cybersecurity, and AI agents. OpenAI says it aims to train 300,000 certified consultants by the end of 2026, and is actively recruiting solution providers that can put AI systems into production. Philip Larson, senior director of the OpenAI Partner Network and a former Google Cloud channel leader, said the program is designed to reward partners for the value they create with customers. Canadian VARs and MSPs with existing AI practices should evaluate the program alongside their current AWS, Google, and Microsoft partnerships, as the specializations in Codex and AI agents may create differentiation in automation-heavy verticals. Carbon60, a Toronto-based managed cloud services provider, has been named to the 2026 MSP 501 at position 206, marking the company as one of the world’s top managed services firms by revenue and operational discipline. The ranking, published by Channel Futures, evaluates financial health, operational maturity, and recurring revenue growth. Carbon60’s inclusion follows a broader trend of Canadian MSPs demonstrating global competitiveness in specialized infrastructure and compliance-heavy verticals. The company has built a differentiated practice around Canada-first sovereign cloud and deep Azure expertise. As Canadian public sector and healthcare clients face stricter data residency requirements, sovereign cloud capabilities are becoming a key differentiator for domestic MSPs seeking to compete with larger global firms on government and enterprise contracts. RecordPoint has gone channel-first with the launch of a global partner program enabling resellers, consultancies, and systems integrators to resell, co-sell, and refer its data and AI governance platform. The program arrives as AI adoption drives a surge in demand for data governance across regulated industries. RecordPoint says partners will receive enablement, joint sales support, and platform access to build practices around data retention, compliance, and AI-ready data classification. CRN reports that the move represents a strategic shift for the company. Canadian partners serving regulated industries like finance, government, and healthcare may find particular opportunity as clients confront unstructured data sprawl ahead of AI deployments. In Brief – OpenAI commits $150 million to launch its inaugural Partner Network with tiered AI specializations. Acronis and Omdia project the managed security market will reach $106 billion in 2026. Blackpoint Cyber’s 2026 Annual Threat Report highlights attackers hiding inside trusted IT tools and RMM platforms. RAMageddon memory shortages continue to pressure PC pricing and enterprise refresh cycles. Exabeam adds pooled and federated licensing options to its APEX partner program for MSSPs. Full details and links in the show notes or the blog post. Later today on In The Channel, we’re talking specialist distribution in Canada with Carrie Hopkins of Exclusive Networks. We get into the Ignition program, what broadliners can’t deliver, and why the model might feel familiar to channel veterans. And if you haven’t heard it yet, yesterday we wrapped our HPE Discover 2026 arc with HPE vice president of North America channels Jeremiah Jenson. He talks about the quote-cycle win, the Canadian angle on data sovereignty, and what partners should stop doing. That’s how we’re seeing the headlines today. I’m Robert Dutt for ChannelBuzz.ca, thanks for listening. Have a great day.
Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »
Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »
Take a Network Break! We start with a critical vulnerability in Adobe Coldfusion. On the news front, Infoblox acquires Kentik to add network observability to its portfolio, data center electricity consumption jumps worldwide, and Exabeam rolls out AI-agent focused detection in its Agent Behavior Analytics platform. DriveNets and WhiteFiber connect two AI data centers over... Read more »
Sales Game Changers | Tip-Filled Conversations with Sales Leaders About Their Successful Careers
This is episode 856. Read the complete transcription on the Sales Game Changers Podcast website. Watch the video of this podcast on YouTube here. The Sales Game Changers Podcast was recognized by YesWare as the top sales podcast. Read the announcement here. FeedSpot named the Sales Game Changers Podcast at a top 20 Sales Podcast and top 8 Sales Leadership Podcast! Subscribe to the Sales Game Changers Podcast now on Apple Podcasts! Purchase Fred Diamond's best-sellers Love, Hope, Lyme: What Family Members, Partners, and Friends Who Love a Chronic Lyme Survivor Need to Know and Insights for Sales Game Changers now! Today's show featured an interview with Craig Patterson, Global Channel and Ecosystem Chief at Exabeam. Find Craig on LinkedIn. CRAIG'S TIP: "Stop measuring activity and start driving outcomes. It's easy to become focused on how much you're doing, but the real question is: what are you actually trying to achieve? The best sales professionals measure success by the business outcomes they create."
What separates a CISO who survives from one who shapes the boardroom? In this episode, Steve Moore sits down with Walt Powell, Lead Field CISO at CDW and author of The CISO 3.0, to unpack the modern CISO playbook—why technical credentials alone no longer cut it, how to build personal eminence, and why most security leaders are still treated as second-class C-suite citizens.Walt traces his path from teaching networking before stateful firewalls existed, to writing CISSP exam questions for ISC2, to running CDW's Global Security Strategy Office. He explains what a field CISO does, why the role is harder than ex-CISOs realize, and how one bad meeting can tarnish a brand built over decades.He and Steve break down the four pillars Walt uses to measure his team—embedded advisory, eminence building, sales enablement, and voice of the customer—and how a karate-style “belt system” maps each consultant's competency. Walt explains why the same skills matrix from The CISO 3.0 works for any CISO trying to spot their own gaps.Walt argues a CISO who is not liked cannot succeed: you are the talent magnet, the culture builder, and the person proving in every board meeting that you belong in the seat. He shares the questions every candidate should ask before accepting the role—from D&O coverage to 10-K disclosure access—and why the 30-60-90 plan should be written before the second interview, not after the offer.The conversation closes with what Walt calls “strategic debt”—the identity and data governance work organizations skipped a decade ago that is now blocking AI adoption. Walt shares lessons from running OpenClaw on a Mac mini, why non-human identity tops every 2026 CISO worry list, and how Deep Research is reshaping senior architects.Key Topics• The modern field CISO role and the four pillars of impact• Why CISOs are still treated as second-class C-suite citizens• Building personal eminence through books, speaking, and writing• The CISO 3.0 skills matrix and self-assessment spider wheel• Two paths to the CISO seat: technical vs. MBA, and the gaps each leaves• Why likability is not optional for a successful CISO• Board readiness and proving you belong in the seat• Interview questions every CISO candidate must ask• Strategic debt: identity and data governance blocking AI adoption• OpenClaw, non-human identity, and the future of senior architectsGuest Bio:Walt Powell is the Lead Field CISO at CDW and a founding member of CDW's Global Security Strategy Office, where he leads a team of former CISOs advising security leaders in the field. A longtime executive coach and ISC2 exam development committee member, Walt is the author of The CISO 3.0: A Guide to Next-Generation Cybersecurity Leadership and Quantum Ready, his book on post-quantum cryptography. Connect with Walt on LinkedIn or at ciso30.com.GET A DEMO:
What happens when an AI agent inside your company starts behaving like an insider threat? In part two, Steve Moore picks the thread back up with former FBI operative Eric O'Neill to explore how agentic AI is rewriting cybersecurity, the legal traps that follow a breach, and why the modern CISO must think like a spy hunter.Eric opens with a sobering reality: ransomware victims who decline to pay are re-attacked at staggering rates. He explains why criminals treat cybercrime as a business, invest weeks in reconnaissance—mapping SharePoint, harvesting file trees, and studying access patterns—and why a botched recovery hands them the same door twice.The conversation turns to the new insider threat hiding in plain sight: rogue AI agents. Eric shares a real case in which one executive's casual query exposed the next round of layoffs and triggered coordinated lawsuits. They unpack how agents inherit excessive access, how attackers hijack them once inside, and why organizations are now building insider-threat programs to monitor AI behavior.Eric argues AI is an accelerant on every unresolved problem—weak identity management, entitlement drift, missing asset inventories, and absent data classification. They debate whether IT and security should be unified under the CISO, why the CISO needs a direct line to the board, and the legal landmines that follow a breach, from cyber insurance to the “reasonable steps” standard.The episode closes with Eric's advice for any new CISO: put “spy hunter” on your resume. Counterintelligence, not perimeter defense, is the discipline that wins today. Tune in for part two of a story-driven conversation on why preparation, mindset, and threat hunting beat any single technology.Key Topics• Why ransomware victims who decline to pay get re-attacked• How attackers map SharePoint, file trees, and access patterns• The new insider threat: rogue and hijacked AI agents• A real case of an AI agent exposing an HR layoff list• Shadow IT and the cost of banning AI outright• Permission structures and second-level reviews for agent actions• Why AI exposes gaps in identity, asset, and data classification• Unifying IT and security under the CISO• Why the CISO needs a direct line to the board• Legal traps: cyber insurance, reasonable steps, and missed alerts• The CISO as counterintelligence officer and spy hunterGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:
What does it feel like to stand in the smoking ruin of a ransomware attack? In this episode, Steve Moore is joined by former FBI undercover operative Eric O'Neill—the man who helped capture Robert Hanssen—to explain why modern cybercrime is just traditional espionage repackaged, and why the dark web has quietly become the world's third-largest economy.Eric traces his path from the FBI's counterintelligence trenches to founding NeXasure AI and writing cybersecurity books that read like spy thrillers. He and Steve unpack the staggering scale of cybercrime, which Eric predicts could reach $20 trillion in global GDP within years—a marketplace selling everything from ransomware kits to stolen credentials.They dismantle the “it won't happen to me” mindset that still lingers in boardrooms. Eric describes how attackers use AI agents to scan for vulnerable systems, walks through how Scattered Spider socially engineered MGM in a ten-minute phone call, and explains why disabled MFA remains the leading point of failure for small and mid-size businesses.Eric then unpacks the painful calculus of paying a ransom. He explains why the FBI says never pay, when OFAC sanctions make payment a federal crime, and why—even after paying—an organization must still do the same forensic, legal, and architectural work. Steve and Eric also detail how attackers resell access and treat victims as repeat customers. The episode closes with a candid look at recovery. Eric and Steve explore why most companies fail at restoration, why rolling back to “before the attack” leaves the original flaw wide open, and why preparation always beats panic. Tune in for a part-one masterclass for any leader who thinks their organization is too small to be a target.Key Topics• How traditional espionage evolved into modern cybercrime• The dark web as the world's third-largest economy• Why every organization is a target, regardless of size• The MGM ransomware attack and Scattered Spider's playbook• Disabled MFA as the leading cause of SMB compromise• Vulnerability assessments versus fire-time remediation costs• The pay-versus-don't-pay ransomware calculus• OFAC sanctions and the legal risks of paying• Why restoring backups is not the same as recovery• The how, where, why, what, and when of breach forensicsGuest BioEric O'Neill is a former FBI counterintelligence operative, attorney, and bestselling author who helped bring down Robert Hanssen—the most damaging spy in FBI history. He is the founder of NeXasure AI and co-founder of The Georgetown Group, and his undercover work was dramatized in the film Breach. Eric is the author of Gray Day and Spies, Lies, and Cybercrime.Connect with Eric on LinkedIn or at ericoneill.net.GET A DEMO:
Cybersecurity debates tend to center on tools, frameworks, and threats. But Rob Knoblauch has built a 25-year career in global security leadership by focusing on the soft skills that determine whether a CISO survives, thrives, or burns out. In this episode of The New CISO, Rob joins Steve Moore to trace the through-line from running a multi-node BBS as a kid to serving as Deputy CISO of one of the world's largest banks — and the career lessons he's carried through every chapter.Rob's path wasn't engineered. It began with a VIC-20, a love of video games, and a side passion for DJing that eventually clinched his first big bank interview. Running a BBS taught him identity management, patching, and infrastructure long before those were industry terms, and responding to the Melissa and “I Love You” outbreaks as a twenty-something Toronto Stock Exchange analyst launched his pivot into information security.The conversation turns to leading at scale. Rob walks through the three mentors who shaped him — “the teacher” who grounded him in fundamentals at Bank of Montreal, “the coach” who taught him the collaborative nature of global operations at Scotiabank, and “the general” who sharpened his leadership edge. He frames these not as phases but as lenses he still applies situationally today.Rob and Steve dig into incident response — from taking down Canada's first phishing site with no playbook to running tabletop exercises at the board, C-suite, and technical levels. Rob argues every organization needs a breach coach and that communications is the biggest make-or-break factor in a breach. He also offers a candid take on CISO politics — short tenures, CIO friction, and why trust with your boss matters more than being right.The episode closes with Rob's take on why this may be the best time in history to be a new CISO. AI is stripping away the commodity work that defined earlier generations of the role, leaving more room for strategy, leadership, and real influence. For anyone stepping into the seat, Rob's message is simple: the most valuable skills aren't technical at all.Key Topics• Rob's path from a VIC-20 and a grade-school BBS to the CISO seat• How DJing as “Robbie Knobs” clinched his first big bank interview — and why “notables” matter on a resume• Taking down the first phishing website in Canada with no playbook and a lot of cold calls• The three mentors who shaped his leadership: the teacher, the coach, and the general• Why tabletop exercises at the board, C-suite, and technical levels each matter — and how they differ• The case for engaging a breach coach before a breach happens, not during one• Why communications is the single biggest make-or-break factor in incident response• How AI is reshaping the CISO role by stripping away commodity workGuestRob Knoblauch — Chief Information Security OfficerRob Knoblauch is a seasoned CISO with 25+ years of global information security leadership. He began his career at the Toronto Stock Exchange during the Y2K era and later held increasingly senior roles at Bank of Montreal and Scotiabank, where he spent years as Deputy CISO and VP of Global Security Services. Rob is also a startup advisor and longtime house music DJ performing as “Robbie Knobs.” Connect with Rob on LinkedIn.GET A DEMO:
In this episode of the Application Security Podcast, Chris Romeo and Robert Hurlbut welcome back Steve Wilson, a global leader in AI security and Chief AI and Product Officer at Exabeam, as well as founder of the OWASP Gen AI Security Project.Steve shares how his AI assistant was “hacked” using a simple phishing attack, highlighting a major shift in security—AI agents behave more like humans than traditional software. The conversation explores how this changes the threat model, why AppSec is struggling to keep up, and how organizations should approach the practical security of AI systems.They also cover the risks of autonomous agents, the expanding blast radius of failures, and what AppSec professionals can do now to adapt.FOLLOW OUR SOCIAL MEDIA:➜Twitter: @AppSecPodcast➜LinkedIn: The Application Security Podcast➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcastThanks for Listening!~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
What does sharpening a knife over a case of onions have to do with incident response? For Myke Lyons, CISO at Cribl, the answer is everything. Myke trained at the Culinary Institute of America — learning speed and accuracy under the clock of a professional kitchen — before a summer IT job in Manhattan set him on an entirely different path. In this episode of The New CISO, host Steve Moore traces that journey and the surprising parallels between culinary craft and security leadership.The conversation moves through a career that evolved organically: a summer job moving refrigerator-sized printers in a Manhattan ad agency, a crash course in executive white-glove IT support, a breakthrough moment finally cracking subnetting, and a slow expansion from NOC operator to global security leader. Myke credits the kitchen — its insistence on precision and calm under fire — for instilling an operator's mindset that still defines how he leads through incidents today.Mentorship, both formal and accidental, threads through Myke's story. A curmudgeonly colleague who threatened to "replace him with a script" taught him the value of continuous improvement. A trusted mentor reframed the CISO's role with a single line about house fires and lock changes. And years in executive IT support gave Myke an early education in empathy and knowing when not to fix what wasn't asked.Myke and Steve examine a vendor incident where a product leader's dismissive response to a forensics question destroyed credibility with hundreds of customers. The lesson: saying "I don't know, but we'll find out" is not a weakness — it is the most powerful tool a leader has. The same insight applies to M&A due diligence, where reframing technical conversations as expectation-setting exercises turns adversarial interviews into collaborative ones.For Myke, the new CISO is defined by empathy and culture. Know your audience. Think like your customers. Communicate policy changes as explanations, not mandates. Find your internal advocates and invest in them before you need them. The recipe for great security leadership is less about technology than it is about people — and that lesson translates perfectly from the kitchen to the boardroom.Key Topics• Career pivots: from culinary school to IT and cybersecurity• Speed, accuracy, and craft — what kitchen discipline teaches security professionals• Building an operator's mindset and staying calm during security incidents• White-glove executive IT support and the patience, precision, and empathy it develops• Mentorship — formal and accidental — and the lessons that only land in retrospect• The dangers of filling silence with false confidence vs. the power of saying "I don't know"• Crisis communication best practices and what not to do during a vendor incident call• Managing M&A security due diligence with low-emotion, expectation-setting conversations• Building security culture through empathy, clear communication, and internal advocates• Telemetry, log management, and Cribl's role as the data engine for IT and security Guest BioMyke Lyons is the Chief Information Security Officer at Cribl, the AI platform for telemetry trusted by organizations worldwide — including half of the Fortune 100 — to manage IT and security data at any scale.He trained at the Culinary Institute of America with aspirations of becoming a food critic — until a summer IT job in Manhattan set him on an entirely different course. Myke went on to build expertise across networking, NOC operations, and log management, holding CISO positions at Snyk and Collibra before joining Cribl in 2024.Connect with Myke on LinkedIn and learn more about Cribl at cribl.io.GET A DEMO:
Today is Monday, March 23, 2026. Welcome to In Case You Missed It, our weekly five-minute rundown of important channel news stories that might have flown under the radar last week. This episode of In Case You Missed It is brought to you by ESET Canada. ESET's Women in Cybersecurity Scholarship is now open for 2026, with three $5,000 awards available to women pursuing careers in cybersecurity. Applications close April 8. Learn more and apply. On this episode: Bell Canada bets big on AI in Saskatchewan. Bell Canada and the Government of Saskatchewan announced a 300-megawatt AI data center outside Regina — Canada’s largest purpose-built facility, projected to generate up to $12 billion in economic value for the province. Cerebras Systems and CoreWeave are signed on as anchor tenants. For the Canadian channel, the downstream opportunities in connectivity, edge infrastructure, and AI professional services are worth watching, as is the data sovereignty angle of keeping AI compute on Canadian soil. The Globe and Mail’s take on what this signals about Bell’s broader AI strategy. WBM Technologies says buy your RAM now. WBM’s March IT Procurement Update is the most useful thing a Canadian partner has published this month. Every vendor category is listed as constrained. HPE has seen a 24-30% list price increase in March alone. Fortinet is implementing monthly 10% price increases. HP is coming with another 10%+ increase April 1. WBM’s recommendation: buy the RAM and storage you need for the lifetime of the system. Nature magazine is calling it “RAMmageddon.” AWS brings AI agents to partner selling. At its Global Partner Summit, AWS announced AI-powered sales agents in Partner Central, built on Amazon Bedrock AgentCore. Partners can upload meeting notes, auto-update opportunity records, check funding eligibility, and generate draft MAP funding requests. AWS reports 15% higher win rates and 44% faster close times from its solution matching engine. Another signal that vendors are using AI to fix the administrivia of partner selling. Exabeam launches new MSSP commercial framework. Exabeam expanded its APEX Partner Program with two new licensing models for MSSPs: a single pooled multi-tenant option and a federated subscription model. For partners building or scaling MSSP practices, it’s designed to offer more flexibility in packaging and pricing Exabeam’s SIEM and analytics platform. This week on In The Channel: Canadian MSPs plan the lowest pay increases of any region, and that might not be a bad thing (Tuesday) Most MSP contracts wouldn’t survive a courtroom — here’s where to start fixing that (Wednesday) Cisco Canada sees a “perfect storm” driving multi-year infrastructure refresh (Thursday) From NetSuite President’s Club to grain-to-bottle whisky in the Eastern Townships — our first Life After the Channel episode (Friday) Read Full Transcript Welcome to In Case You Missed It from ChannelBuzz.ca. I’m Robert Dutt, editor of ChannelBuzz.ca. Today is Monday, March 23rd, 2026. Let’s get your week started right. This week’s In Case You Missed It is brought to you by ESET Canada. ESET’s Women in Cybersecurity Scholarship is now open for 2026, with three $5,000 awards available to women pursuing careers in cybersecurity. Applications close April 8th. Learn more and apply at eset.com/ca. ESET – protecting progress. The biggest Canadian tech infrastructure story in a while landed last week, and it didn’t come from Toronto or Montreal or Vancouver. Bell Canada announced a partnership with SaskTel and SaskPower to build a 300-megawatt AI data center outside Regina, Saskatchewan. The facility is projected to generate up to $12 billion in economic value for the province, and it’s being positioned as Canada’s largest purpose-built data center. The anchor tenants tell you where this is headed: Cerebras Systems and CoreWeave, two of the biggest names in AI compute infrastructure, are signed on. This isn’t a general-purpose facility — it’s built for the kind of GPU-dense, power-hungry workloads that AI training and inference demand. For the Canadian channel, there are a few things to watch. Local IT providers in Saskatchewan and Western Canada could see downstream opportunities in connectivity, edge infrastructure, and professional services around AI deployments. The data sovereignty angle is real — keeping AI compute on Canadian soil is increasingly a selling point with public sector and regulated-industry customers. And the scale of this investment signals that Canada is becoming a serious destination for AI infrastructure, not just a market that consumes AI services built somewhere else. If you’re quoting hardware right now, you need to see WBM Technologies’ March procurement update. It’s the most useful thing a Canadian partner has published this month, and the message is blunt: They're telling customers to buy the RAM and storage you need to support your systems for the lifetime of that system. Every single vendor category WBM tracks is now listed as constrained. HPE has seen a 24 to 30 percent list price increase in March alone, with quote validity down to just 14 days. Fortinet is implementing monthly 10 percent price increases. Dell expects further adjustments on March 30th. And HP is coming with another minimum 10 percent increase on April 1st. WBM is linking to Nature magazine, which is calling this “RAMmageddon.” If you’ve been following our coverage of the component shortage over the past few weeks, this is the same story, but it’s accelerating. We’ll have a link to the full WBM update in the show notes. It’s worth bookmarking. Two weeks ago on this podcast, we talked about Ingram Micro’s AgenTeq platform and the push to bring agentic AI into the distribution workflow. Now AWS is doing something similar inside Partner Central. At its Global Partner Summit, AWS announced AI-powered sales agents built on Amazon Bedrock AgentCore. Partners can upload meeting notes and have opportunity records auto-updated. The agent flags whether a deal qualifies for AWS funding programs like MAP and can generate draft funding requests pre-filled with deal details. AWS says partners using its solution matching engine are seeing 15 percent higher win rates and 44 percent faster close times. The pattern is becoming clear: vendors are using AI to fix the messy middle of partner selling — the admin, the quoting, the funding applications, the administrivia. Worth watching how quickly this becomes table stakes. And finally, Exabeam launched a new commercial framework for MSSPs last week, offering two licensing models: a single pooled multi-tenant option and a federated subscription model. The idea is to give managed security service providers more flexibility in how they package and price Exabeam’s SIEM and analytics platform for their customers. For partners building or scaling MSSP practices, it’s worth a look. We’ll have a link in the show notes. Those are some of the things we were paying attention to last week. Big week ahead on In The Channel. Peter Kujawa from ConnectWise’s Service Leadership practice on why Canadian MSPs are planning the lowest pay increases of any region — and why that might not be a bad thing. Rob Scott from Monjur on why most MSP contracts wouldn’t survive a courtroom. Cisco Canada on the perfect storm driving a multi-year infrastructure refresh. And our very first Life After the Channel episode, with Martin McNicoll, who went from NetSuite President’s Club to making grain-to-bottle whisky in the Eastern Townships. For ChannelBuzz.ca, I’m Robert Dutt. Have a great week, and I’ll see you in the channel.
Alan Lucas always wanted to be an architect or a firefighter — as CISO of Worldstream and Greenhouse Datacenters, he has become both. In this episode, he joins host Steve Moore to explore leading cybersecurity at the intersection of design and crisis response.Alan traces his path from Fox-IT through a Dutch cryptocurrency exchange where he arrived post-breach to an organization under near-constant attack from nation-state threat actors. Leading a technically sophisticated but security-anxious leadership team, he learned the lasting power of transparency and directness — and his most memorable measure of success was not a technical control, but a CTO who finally slept through the night.The conversation goes deep into crisis communication. Alan and Steve discuss how the industry has matured from reflexive silence around breaches to embracing transparency as a trust-building tool, the danger of well-meaning legal edits that send customers chasing the wrong narrative, and why the CISO should hold final review over all public incident communications. He also shares his Security Champions Program, tabletop exercise design, and why knowing who to call in a crisis must be mapped out before that crisis arrives.Alan also covers his volunteer work with the DIVD, coaching ethical hackers and supporting responsible disclosure worldwide — an extension of his belief that security, done well, creates trust and enables growth for everyone.The episode closes on "bouncing forward" — the idea that true resilience means using every incident as a forcing function for improvement, not just a return to baseline. Alan frames lessons learned as the most important resilience KPI a security team can own. A masterclass in leading through both calm and chaos. Key Topics• The architect-and-firefighter mindset: building security programs while fighting live fires• Alan's career path from Fox-IT (MSSP) to post-breach CISO at a cryptocurrency exchange• Leading security post-breach — and what "sleeping well again" actually means• The unique threat landscape facing cryptocurrency companies, including nation-state adversaries• The Dutch Institute for Vulnerability Disclosure (DIVD): coordinated, ethical vulnerability disclosure worldwide• Mentoring young ethical hackers: communication, confidence, and responsible disclosure process• Crisis communication: balancing transparency with operational security during active incidents• Why legal edits to breach notifications can mislead customers and create dangerous distractions• The CISO's role as final reviewer of all incident communications• Security Champions Programs: bridging the gap between security and non-technical departments• Tabletop exercise design: running effective simulations in under an hour with non-technical staff• Writing the breach notification letter before the breach happens• Bouncing forward, not bouncing back: using lessons learned as a resilience KPI• Security as a business enabler: positioning the CISO role for organizational growth and confidenceGuest BioAlan Lucas is CISO at Worldstream and Greenhouse Datacenters, two of the Netherlands' leading cloud and data center infrastructure providers. With over a decade of cybersecurity experience, he leads security strategy for mission-critical IT and cloud environments. Prior roles include Fox-IT (MSSP) and LiteBit, a Dutch cryptocurrency exchange where he served as CISO post-breach. Alan also volunteers as a coach at the Dutch Institute for Vulnerability Disclosure (DIVD), mentoring ethical hackers and supporting responsible disclosure globally. He is passionate about security as a catalyst for innovation — and about building a safer digital society, one step at a time.LEARN MORE:
Steve Wilson, Chief AI and Product Officer at Exabeam and lead of the OWASP GenAI Security Project, discusses the practical realities of securing Large Language Models and agentic workflows. Subscribe to the Gradient Flow Newsletter
This podcast is brought to you by Outcomes Rocket, your exclusive healthcare marketing agency. Learn how to accelerate your growth by going to outcomesrocket.com AI security is no longer optional; it's the foundation that determines whether innovation in healthcare will thrive or fail. In this episode, Steve Wilson, Chief AI & Product Officer for Exabeam and author, discusses the hidden vulnerabilities inside modern AI systems, why traditional software assumptions break down, and how healthcare must rethink safety, trust, and security from the ground up. He explains the risks of prompt injection and indirect prompt injection, highlights the fragile nature of AI “intuition,” and compares securing AI to training unpredictable employees rather than testing deterministic code. Steve also explores issues such as supply chain integrity, output filtering, trust boundaries, and the growing need for continuous evaluation rather than one-time testing. Finally, he shares stories from his early career at Sun Microsystems, Java's early days, startup lessons from the 90s, and how modern AI agents are reshaping cybersecurity operations. Tune in and learn how today's most advanced AI systems can be both powerful and dangerously gullible, and what it takes to secure them! Resources Connect with and follow Steve Wilson on LinkedIn. Follow Exabeam on LinkedIn and visit their website! Buy Steve Wilson's book The Developer's Playbook for Large Language Model Security here.
In a world where employees can now include autonomous identities with operational access and decision-making power, traditional security models are being pushed to the limit. AI agents have become embedded across enterprise operations and they’re unlocking new frontiers of productivity which is exposing unseen vulnerabilities. On Industry Insight, Lynlee Foo speaks to Kevin Kirkwood, Chief Information Security Officer at Exabeam to find out why conventional defences are falling short, and what best practices global companies are adopting to safeguard enterprise environments against a new class of AI-powered insider threats.See omnystudio.com/listener for privacy information.
Most security professionals know what a CISO does. But what about a BISO? And why are Fortune 500 companies increasingly creating this executive role?In this episode of The New CISO Podcast, host Steve Moore sits down with Evan Ferree, Staff Vice President and Business Information Security Officer at a Fortune 50 company, to decode one of cybersecurity's most misunderstood leadership positions.What You'll Learn:Understanding the BISO Role:What a Business Information Security Officer actually does (and how it differs from a Deputy CISO)When organizations need a BISO - the size, industry, and complexity indicatorsWhy the BISO serves as a "force multiplier" for the security organizationHow to measure and defend BISO value during organizational changeThe Career Journey:Evan's unconventional path from IT infrastructure to executive security leadershipHow a major cybersecurity breach became his "MBA in cybersecurity" in six monthsWhy volunteering for uncomfortable work during crisis creates career opportunitiesThe progression from vulnerability analyst to SOC leadership to Staff VPThe 90% Influence Principle:Why the BISO role is about influence, not authorityHow to navigate multiple business units with different security needsMastering the "why" behind security initiatives for non-technical audiencesBuilding relationships and organizational awareness over timeExecutive Skills That Matter:The "log lines" storytelling framework from Deloitte CISO AcademyDeveloping executive presence through failure and self-awarenessWhen to end a meeting and start over (and why that's okay)Speaking plain English vs. technical jargon with business leadersPractical Career Advice:Transitioning from tactical security operations to strategic leadership rolesWhy getting uncomfortable is essential for growthBuilding business acumen alongside technical expertiseWhy Evan's best security hires came from outside cybersecurityKey Insight: "You are 90% an influencer in this role. Unlike tactical security work where authority and urgency create credibility, the BISO must master explaining why security matters to the business - in terms the business understands."Whether you're a security professional planning your path to executive leadership, a CISO considering adding a BISO function, or a business leader trying to understand how security enables business outcomes, this episode delivers actionable insights from someone who's lived the journey.Guest: Evan Ferree, Staff Vice President & Business Information Security Officer at a Fortune 50 company, with 11 years of progressive security leadership experience spanning Security Operations, threat management, vulnerability management, and business information security.Hosted by: Steve Moore | Produced in partnership with: Exabeam
This week Marc sits down with James Anderson, Channel Director (International) at Abnormal AI. From starting out as a biochemistry graduate and aspiring rugby pro, James has built a career shaping channel strategies across Trend, Quest, Ivanti, Exabeam – and now Abnormal.
In this episode, we delve into the transformative role of AI in product management through conversations with some of the best Product leaders. You'll hear from Anthony Maggio (VP Product Management at Airtable), Jessica Hall (CPO at Just Eat Takeaway), Karthik Suri (CPO at Cornerston OnDemand), Mario Rodriguez (CPO at Github), Steve Wilson (CPO at Exabeam), Darren Wilson (CPO at Soul Machines), and Tamar Yehoshua (Former Glean President of Product and Technology).We explore how AI tools are reshaping strategy and efficiency, while personalizing customer experiences. Join us as we discuss the impact of AI, and the future of product strategy. Are you curious about how AI can revolutionize your product management approach? Tune in to discover insights and practical applications that could redefine your strategies and customer interactions.You'll hear us talk about:10:05 - AI's Role in Product StrategyExplore how product leaders are integrating AI into their strategic planning, focusing on addressing significant business and customer problems. The discussion highlights the experimental applications of AI in enhancing customer journeys and optimizing backend processes.18:45 - Enhancing Customer Interaction with Digital AvatarsWe dive into the world of digital avatars and their role in creating empathetic and personalized customer interactions. This section covers how avatars can be used for language learning and practicing difficult conversations in a non-judgmental setting.27:30 - Cybersecurity in the Age of AIUnderstand the evolving landscape of cybersecurity with AI's influence. Learn about the dual nature of AI in enhancing defenses and creating new threat vectors, emphasizing the importance of rapid AI adoption to stay competitive in the cybersecurity arena.Episode Resources:Anthony Maggio (VP Product Management at Airtable): https://www.linkedin.com/in/anthonymaggio/Jessica Hall (CPO at Just Eat Takeaway): https://www.linkedin.com/in/jessicalrhall/Karthik Suri (CPO at Cornerston OnDemand): http://linkedin.com/in/surikarthik/Mario Rodriguez (CPO at Github): https://www.linkedin.com/in/mariorodriguez3/Steve Wilson (CPO at Exabeam): https://www.linkedin.com/in/wilsonsd/Darren Wilson (CPO at Soul Machines): https://www.linkedin.com/in/dpjwilson/Tamar Yehoshua (Former President of Product): https://www.linkedin.com/in/tamar-yehoshua-886217/Check our new course: https://productinstitute.com/p/mastering-product-strategy-overviewTimestamps:00:00 Coming Up01:37 Intro02:57 AI raising the bar for PMs06:57 Using AI to improve personalization10:52 Reimagining products with emerging AI14:55 AI behind GitHub Copilot20:21 AI's risks and impact on cybersecurity24:22 AI avatars and emotional interaction30:42 How PMs can stay relevant in the AI age
Some scams are so convincing, they're almost impossible to spot. With phishing emails that look like they're from your bank, deep fake videos that mimic real people, and AI-generated messages that feel personal, it's getting harder to know what's real and what's a trap. In this episode, I sit down with Gabrielle Hempel, a security operations specialist at Exabeam and a current law student at Purdue University. Gabrielle brings a sharp perspective shaped by years in cybersecurity, a master's in cybersecurity and global affairs from NYU, and hands-on experience navigating everything from vulnerability management to executive risk consulting. She even wrote her graduate thesis on critical infrastructure security. We talk about the new era of digital deception, why younger people are actually falling for scams more often, and how criminals are using AI and current events to build trust and bypass defenses. Gabrielle shares practical advice, personal stories, and a fresh way to think about digital safety that could help you spot the next scam before it costs you. Show Notes: [01:09] Gabrielle has held quite a few jobs in cybersecurity. She's currently the Security Operations Strategist at Exabeam. [01:40] She's involved with anything to do with the internal security operation. [02:04] She majored in psychology and neuroscience. Working in Pharma and with medical devices led her to the path of cybersecurity. [04:34] We learn about an incident that she was involved in. Her parents were attempting to file their taxes with TurboTax, but they were flagged as already filing. This led to a lot of shenanigans with the IRS. [06:29] Most everyone has been a victim to some type of fraud or scam. [07:20] Our information is out there. It's more about staying vigilant and keeping an eye on things. [08:05] A lot of the current scams are blending with the cybercrime ecosystem. [09:17] AI has made it easier for people to craft more convincing phishing emails. [12:51] Are modern phishing emails getting through the spam filters more often? [15:48] How it's not retirees being the people most frequently caught in scams. [16:42] Why 20 to 29 year-olds frequently fall for scams. It could be because of their comfort with technology. [21:12] Better education surrounding threats might be a good idea for young people. [22:47] As scammers get more information about us, targeting will be easier. [24:32] Big trends are voice cloning and deep fakes. [27:51] Scams around shipping fees and tariffs are skyrocketing. [29:15] Advice includes adopting zero trust with communication. [33:10] If you're not expecting it. It's potentially suspect. [34:45] Best practices include doing your due diligence, and if you feel like something may not be legitimate go around and check. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review. Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Gabrielle Hempel - LinkedIn Exabeam @gabsmashh on X
Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead, OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinView This Show's Sponsors___________________________Episode NotesIn this episode of Redefining CyberSecurity, host Sean Martin sat down with Steve Wilson, chief product officer at Exabeam, to discuss the critical topic of secure AI development. The conversation revolved around the nuances of developing and deploying large language models (LLMs) in the field of cybersecurity.Steve Wilson's expertise lies at the intersection of AI and cybersecurity, a point he emphasized while sharing his journey from founding the Top 10 group for large language models to authoring his new book, "The Developer's Playbook for Large Language Model Security." In this insightful discussion, Wilson and Martin explore the roles of developers and product managers in ensuring the safety and security of AI systems.One of the key themes in the conversation is the categorization of AI applications into chatbots, co-pilots, and autonomous agents. Wilson explains that while chatbots are open-ended, interacting with users on various topics, co-pilots focus on enhancing productivity within specific domains by interacting with user data. Autonomous agents are more independent, executing tasks with minimal human intervention.Wilson brings attention to the concept of overreliance on AI models and the associated risks. Highlighting that large language models can hallucinate or produce unreliable outputs, he stresses the importance of designing systems that account for these limitations. Product managers play a crucial role here, ensuring that AI applications are built to mitigate risks and communicate their reliability to users effectively.The discussion also touches on the importance of security guardrails and continuous monitoring. Wilson introduces the idea of using tools akin to web app firewalls (WAF) or runtime application self-protection (RASP) to keep AI models within safe operational parameters. He mentions frameworks like Nvidia's open-source project, Nemo Guardrails, which aid developers in implementing these defenses.Moreover, the conversation highlights the significance of testing and evaluation in AI development. Wilson parallels the education and evaluation of LLMs to training and testing a human-like system, underscoring that traditional unit tests may not suffice. Instead, flexible test cases and advanced evaluation tools are necessary. Another critical aspect Wilson discusses is the need for red teaming in AI security. By rigorously testing AI systems and exploring their vulnerabilities, organizations can better prepare for real-world threats. This proactive approach is essential for maintaining robust AI applications.Finally, Wilson shares insights from his book, including the Responsible AI Software Engineering (RAISE) framework. This comprehensive guide offers developers and product managers practical steps to integrate secure AI practices into their workflows. With an emphasis on continuous improvement and risk management, the RAISE framework serves as a valuable resource for anyone involved in AI development.About the BookLarge language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models.Complete with collective wisdom gained from the creation of the OWASP Top 10 for LLMs list—a feat accomplished by more than 400 industry experts—this guide delivers real-world guidance and practical strategies to help developers and security teams grapple with the realities of LLM applications. Whether you're architecting a new application or adding AI features to an existing one, this book is your go-to resource for mastering the security landscape of the next frontier in AI.___________________________SponsorsImperva: https://itspm.ag/imperva277117988LevelBlue: https://itspm.ag/attcybersecurity-3jdk3___________________________Watch this and other videos on ITSPmagazine's YouTube ChannelRedefining CyberSecurity Podcast with Sean Martin, CISSP playlist:
Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead, OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Host: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinView This Show's Sponsors___________________________Episode NotesIn this episode of Redefining CyberSecurity, host Sean Martin sat down with Steve Wilson, chief product officer at Exabeam, to discuss the critical topic of secure AI development. The conversation revolved around the nuances of developing and deploying large language models (LLMs) in the field of cybersecurity.Steve Wilson's expertise lies at the intersection of AI and cybersecurity, a point he emphasized while sharing his journey from founding the Top 10 group for large language models to authoring his new book, "The Developer's Playbook for Large Language Model Security." In this insightful discussion, Wilson and Martin explore the roles of developers and product managers in ensuring the safety and security of AI systems.One of the key themes in the conversation is the categorization of AI applications into chatbots, co-pilots, and autonomous agents. Wilson explains that while chatbots are open-ended, interacting with users on various topics, co-pilots focus on enhancing productivity within specific domains by interacting with user data. Autonomous agents are more independent, executing tasks with minimal human intervention.Wilson brings attention to the concept of overreliance on AI models and the associated risks. Highlighting that large language models can hallucinate or produce unreliable outputs, he stresses the importance of designing systems that account for these limitations. Product managers play a crucial role here, ensuring that AI applications are built to mitigate risks and communicate their reliability to users effectively.The discussion also touches on the importance of security guardrails and continuous monitoring. Wilson introduces the idea of using tools akin to web app firewalls (WAF) or runtime application self-protection (RASP) to keep AI models within safe operational parameters. He mentions frameworks like Nvidia's open-source project, Nemo Guardrails, which aid developers in implementing these defenses.Moreover, the conversation highlights the significance of testing and evaluation in AI development. Wilson parallels the education and evaluation of LLMs to training and testing a human-like system, underscoring that traditional unit tests may not suffice. Instead, flexible test cases and advanced evaluation tools are necessary. Another critical aspect Wilson discusses is the need for red teaming in AI security. By rigorously testing AI systems and exploring their vulnerabilities, organizations can better prepare for real-world threats. This proactive approach is essential for maintaining robust AI applications.Finally, Wilson shares insights from his book, including the Responsible AI Software Engineering (RAISE) framework. This comprehensive guide offers developers and product managers practical steps to integrate secure AI practices into their workflows. With an emphasis on continuous improvement and risk management, the RAISE framework serves as a valuable resource for anyone involved in AI development.About the BookLarge language models (LLMs) are not just shaping the trajectory of AI, they're also unveiling a new era of security challenges. This practical book takes you straight to the heart of these threats. Author Steve Wilson, chief product officer at Exabeam, focuses exclusively on LLMs, eschewing generalized AI security to delve into the unique characteristics and vulnerabilities inherent in these models.Complete with collective wisdom gained from the creation of the OWASP Top 10 for LLMs list—a feat accomplished by more than 400 industry experts—this guide delivers real-world guidance and practical strategies to help developers and security teams grapple with the realities of LLM applications. Whether you're architecting a new application or adding AI features to an existing one, this book is your go-to resource for mastering the security landscape of the next frontier in AI.___________________________SponsorsImperva: https://itspm.ag/imperva277117988LevelBlue: https://itspm.ag/attcybersecurity-3jdk3___________________________Watch this and other videos on ITSPmagazine's YouTube ChannelRedefining CyberSecurity Podcast with Sean Martin, CISSP playlist:
Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead, OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this episode of the Chat on the Road On Location series for OWASP AppSec Global in San Francisco, Sean Martin hosts a compelling conversation with Steve Wilson, Project Lead for the OWASP Top 10 for Large Language Model AI Applications. The discussion, as you might guess, centers on the OWASP Top 10 list for Large Language Models (LLMs) and the security challenges associated with these technologies. Wilson highlights the growing relevance of AppSec, particularly with the surge in interest in AI and LLMs.The conversation kicks off with an exploration of the LLM project that Wilson has been working on at OWASP, aimed at presenting an update on the OWASP Top 10 for LLMs. Wilson emphasizes the significance of prompt injection attacks, one of the key concerns on the OWASP list. He explains how attackers can craft prompts to manipulate LLMs into performing unintended actions, a tactic reminiscent of the SQL injection attacks that have plagued traditional software for years. This serves as a stark reminder of the need for vigilance in the development and deployment of LLMs.Supply chain risks are another critical issue discussed. Wilson draws parallels to the Log4j incident, stressing that the AI software supply chain is currently a weak link. With the rapid growth of platforms like Hugging Face, the provenance of AI models and training datasets becomes a significant concern. Ensuring the integrity and security of these components is paramount to building robust AI-driven systems.The notion of excessive agency is also explored—a concept that relates to the permissions and responsibilities assigned to LLMs. Wilson underscores the importance of limiting the scope of LLMs to prevent misuse or unauthorized actions. This point resonates with traditional security principles like least privilege but is recontextualized for the AI age. Overreliance on LLMs is another topic Martin and Wilson discuss.The conversation touches on how people can place undue trust in AI outputs, leading to potentially hazardous outcomes. Ensuring users understand the limitations and potential inaccuracies of LLM-generated content is essential for safe and effective AI utilization.Wilson also provides a preview of his upcoming session at the OWASP AppSec Global event, where he plans to share insights from the ongoing work on the 2.0 version of the OWASP Top 10 for LLMs. This next iteration will address how the field has matured and new security considerations that have emerged since the initial list.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________This Episode's SponsorsAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More
Guest: Steve Wilson, Chief Product Officer, Exabeam [@exabeam] & Project Lead, OWASP Top 10 for Larage Language Model Applications [@owasp]On LinkedIn | https://www.linkedin.com/in/wilsonsd/On Twitter | https://x.com/virtualsteve____________________________Hosts: Sean Martin, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining CyberSecurity Podcast [@RedefiningCyber]On ITSPmagazine | https://www.itspmagazine.com/sean-martinMarco Ciappelli, Co-Founder at ITSPmagazine [@ITSPmagazine] and Host of Redefining Society PodcastOn ITSPmagazine | https://www.itspmagazine.com/itspmagazine-podcast-radio-hosts/marco-ciappelli____________________________Episode NotesIn this episode of the Chat on the Road On Location series for OWASP AppSec Global in San Francisco, Sean Martin hosts a compelling conversation with Steve Wilson, Project Lead for the OWASP Top 10 for Large Language Model AI Applications. The discussion, as you might guess, centers on the OWASP Top 10 list for Large Language Models (LLMs) and the security challenges associated with these technologies. Wilson highlights the growing relevance of AppSec, particularly with the surge in interest in AI and LLMs.The conversation kicks off with an exploration of the LLM project that Wilson has been working on at OWASP, aimed at presenting an update on the OWASP Top 10 for LLMs. Wilson emphasizes the significance of prompt injection attacks, one of the key concerns on the OWASP list. He explains how attackers can craft prompts to manipulate LLMs into performing unintended actions, a tactic reminiscent of the SQL injection attacks that have plagued traditional software for years. This serves as a stark reminder of the need for vigilance in the development and deployment of LLMs.Supply chain risks are another critical issue discussed. Wilson draws parallels to the Log4j incident, stressing that the AI software supply chain is currently a weak link. With the rapid growth of platforms like Hugging Face, the provenance of AI models and training datasets becomes a significant concern. Ensuring the integrity and security of these components is paramount to building robust AI-driven systems.The notion of excessive agency is also explored—a concept that relates to the permissions and responsibilities assigned to LLMs. Wilson underscores the importance of limiting the scope of LLMs to prevent misuse or unauthorized actions. This point resonates with traditional security principles like least privilege but is recontextualized for the AI age. Overreliance on LLMs is another topic Martin and Wilson discuss.The conversation touches on how people can place undue trust in AI outputs, leading to potentially hazardous outcomes. Ensuring users understand the limitations and potential inaccuracies of LLM-generated content is essential for safe and effective AI utilization.Wilson also provides a preview of his upcoming session at the OWASP AppSec Global event, where he plans to share insights from the ongoing work on the 2.0 version of the OWASP Top 10 for LLMs. This next iteration will address how the field has matured and new security considerations that have emerged since the initial list.Be sure to follow our Coverage Journey and subscribe to our podcasts!____________________________This Episode's SponsorsAre you interested in sponsoring our event coverage with an ad placement in the podcast?Learn More
Pat Moorhead and Daniel Newman sat down with Sam Burd to discuss AI PCs at Dell Tech World. These new PCs include significant new AI integrations, and Dell expects these to initiate a "super cycle" of PC upgrades. We discussed the importance of Qualcomm Snapdragon X Elite earlier in the program, but what should we make of the market for AI PCs? This and more announcements from Dell Tech World on The Rundown. Time Stamps: 0:00 - Welcome to The Rundown 1:00 - Dell Writes a HYCU in their PowerProtect DataDomain 3:36 - GitHub Patches Massive Security Hole in Enterprise Servers 6:45 - Palo Alto Networks Acquires IBM QRadar 10:35 - Exabeam and LogRhythm to Merge to Strengthen AI-Driven Security Future 14:00 - PC Makers Debut AI PCs with Microsoft CoPilot+ 19:36 - CoPilot+ Totally Recalls Everything 23:09 - Announcements from Dell Tech World 23:55 - Dell AI Factory Using NVIDIA for AI Adoption 26:55 - Dell collaborates with NVIDIA, Microsoft, and ServiceNow on Dell NativeEdge 32:50 - Dell PowerStore using APEX AI innovations to Improve Storage Performance, Efficiency, and Resiliency 36:08 - Dell's AI PCs using Copilot+ 47:22 - The Weeks Ahead Hosts: Tom Hollingsworth: https://www.twitter.com/NetworkingNerd Stephen Foskett: https://www.twitter.com/SFoskett Follow Gestalt IT Website: https://www.GestaltIT.com/ Twitter: https://www.twitter.com/GestaltIT LinkedIn: https://www.linkedin.com/company/Gestalt-IT Tags: #Rundown, #DellTechWorld, #Copilot, #AI, @TheSixFiveMedia, @TheFuturumGroup, @TechFieldDay, @GestaltIT, @SFoskett, @NetworkingNerd, @DellTech, @DanielNewmanUV, @Krista_Lee, @PatrickMoorhead, @HYCU_Inc, @GitHub, @IBM, @PaloAltoNtwks, @LogRhythm, @Exabeam, @Qualcomm, @DellTech, @Lenovo, @HP, @Microsoft, @NVIDIA, @ServiceNow,
Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »
Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »
Take a Network Break! This week we discuss what IBM and Palo Alto Networks get out of a deal for Palo Alto Networks to buy the SaaS version of the QRadar SIEM from IBM, why LogRhythm is merging with Exabeam, and how Google is positioning its latest AI chip to take on the Nvidia juggernaut.... Read more »
Private equity giant Thoma Bravo has announced that its security information and event management (SIEM) company LogRhythm will be merging with Exabeam, a rival cybersecurity company backed by the likes of Cisco and Lightspeed Venture Partners. Learn more about your ad choices. Visit podcastchoices.com/adchoices
Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Visit the show notes for full descriptions on each RSAC executive interview! Show Notes: https://securityweekly.com/esw-362
During the earnings call, Cisco Systems acknowledged the competitive landscape in cybersecurity and observability, as evidenced by Palo Alto Networks' acquisition of Exabeam. However, Cisco highlighted its strategic strengths in these areas, emphasizing the value of an integrated, unified platform for end-to-end security and insightful solutions.The company stated its focus on the immediate integration of its XDR (Extended Detection and Response) solution with Splunk Enterprise Security, showcasing its commitment to harnessing the combined strengths of Cisco and Splunk. This integration represents progress in developing seamless product alliances, innovative solutions, and robust go-to-market strategies.Furthermore, Cisco has integrated AI capabilities into its cybersecurity offerings, such as Cisco Hypershield, to differentiate itself from competitors relying on standalone products. The company asserted that embedding security within the network fabric provides a unique and significant market differentiation.Cisco's strategic emphasis on integration, AI capabilities, and unified platforms in cybersecurity and observability positions the company to leverage market opportunities and address evolving industry challenges effectively.Navigating Macroeconomic Challenges and Sector-Specific DynamicsWhile Cisco experienced revenue declines in its core networking business due to inventory implementations, its security and observability segments saw growth driven by innovations and the integration of Splunk. The company acknowledged the ongoing macroeconomic challenges, particularly in the telco and cable segments, although some stabilization was noted in the Webscale sector.Cisco's CEO, Chuck Robbins, stated, "So from a macro perspective, what I would say is that ironically, we saw the quarter actually slow -- showed slight improvement as we move through the quarter." The company's strong cash flow and strategic investments in AI, security, and the Splunk integration position it well for future growth, despite these headwinds.Balancing Growth Opportunities and Competitive PressuresCisco Systems reported mixed financial results, with revenues for Q3 down 13% year-over-year at $12.7 billion, primarily due to reduced product revenue. However, service revenue saw a 6% uptick, and the recent acquisition of Splunk added $413 million post-close, boosting annualized recurring revenue to $29.2 billion. Gross margins remained strong at 68.3%, and operating margins stayed steady.While the company faced declines in its core networking business, key customer sectors like data center and campus switching, security, and collaboration witnessed order increases. Capital returns to shareholders amounted to a robust $2.9 billion in Q3.Moving forward, Cisco Systems must navigate the competitive waters while capitalizing on growth opportunities in cybersecurity and observability. The company's strategic focus on integration, AI capabilities, and unified platforms positions it to address evolving industry challenges and leverage market opportunities effectively. This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit theearningscall.substack.com
Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Visit the show notes for full descriptions on each RSAC executive interview! Show Notes: https://securityweekly.com/esw-362
Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Show Notes: https://securityweekly.com/esw-362
Suddenly SIEMs are all over the news! In a keynote presentation, Crowdstrike CEO George Kurtz talked about the company's "next-gen" SIEM. Meanwhile, Palo Alto, who was taken to task by some for not having an active presence on the RSAC expo floor, hits the headlines for acquiring IBM's SIEM product, just to shut it down! Meanwhile, LogRhythm and Exabeam merge, likely with the hopes of weathering the coming storm. The situation seems clear - there's no such thing as "best of breed" SIEM anymore. It's a commodity to be attached to the existing dominant security platforms. Are the days numbered for the older pure-play SIEM/SOAR vendors out there? Crowdstrike and Palo Alto alone could displace a lot of incumbents, even with a less than stellar product. Show Notes: https://securityweekly.com/esw-362
Gianna Driver, CHRO at Exabeam, joined us on The Modern People Leader. We talked about how Exabeam's HR team built their AI roadmap and which AI for HR use cases have been the most successful for them. ---- [02:00] - Good news stories [06:00] - Gianna's career journey and her unexpected path into HR [10:00] - Discussion on pivotal career moments and the importance of supportive leadership [13:00] - Learning from failures [17:00] - Gianna talks about the integration and challenges of implementing AI within HR at Exabeam [21:00] - Initial failures and subsequent successes in adopting AI for HR at Exabeam [25:00] - Practical applications of AI in writing job descriptions and updating employee handbooks [30:00] - The potential and limitations of AI in handling complex HR tasks and strategic decision-making [34:00] - Gianna offers her perspectives on the future roles of AI in enhancing employee experience and development [40:00] - Discussing the ethical considerations and policy frameworks necessary for AI deployment in HR [45:00] - Closing thoughts on the importance of courage and innovation in HR ----
In this podcast episode, Angelique Cuevas, the Director of Talent Acquisition at Exabeam, shares insights about her journey from an individual contributor role to a leadership position. Discussing her initial struggle with the shifting dynamics of peer relationships, Cuevas presents various strategic approaches and methods implemented to ensure smooth transitions within the company. She highlights the need to learn and unlearn in this ever-evolving professional landscape. She also emphasizes the role of communication, delegation, and understanding individual career growth paths in successful people management. Highlights: 01:19 Transitioning from Individual Contributor to Leader 02:22 Angelique's Journey to Leadership 04:39 Challenges of Becoming a People Leader 07:03 The Importance of Talent Acquisition 08:33 Navigating Relationship Dynamics as a New Manager 12:39 Learning from Mistakes and Adapting Strategy 18:36 Empowering Team Members and Facilitating Growth Guest: Angelique Cuevas began her career in social work, volunteering as the Outreach Counselor. In this role, she attended county events to promote the services of the group home, a period during which she discovered a passion for connecting with and assisting people. This realization prompted a career transition into the tech startup sector, where she worked closely with the HR department. Eventually, Angelique took on full responsibility for managing all aspects of Recruiting, including training, system implementation, interview best practices, and the hiring and onboarding processes. https://www.linkedin.com/in/angelique-cuevas-918864a3/ ------ Thank you so much for checking out this episode of The Talent Tango, and we would appreciate it if you would take a minute to rate and review us on your favorite podcast player. Want to learn more about us? Head over at https://www.elevano.com Have questions or want to cover specific topics with our future guests? Please message me at https://www.linkedin.com/in/amirbormand (Amir Bormand)
In this episode we wanted to put together for our listeners some of the best of our innovations in talent and culture chats. Shauna Geraghty, SVP & Global Head of People & Talent at Talkdesk, will share invaluable insights on optimizing the quality of hire. Debbie Shotwell, CPO at Stack Overflow, will delve into the secrets of developing a strong and vibrant company culture. Gianna Driver, CHRO at Exabeam, will challenge traditional notions of 'culture fit' and explore how embracing 'culture add' can ignite innovation within your organization. 1:15 Shauna Geraghty, SVP & Global Head of People & Talent at Talkdesk - Optimizing the quality of hire9:18 Debbie Shotwell, CPO at Stack Overflow - Employee well-being and onboarding process15:03 Gianna Driver, CHRO at Exabeam - Shifting culture fit to culture add Thank you to our sponsor, SecureVision, for making this show possible! Our host James Mackey Follow us:https://www.linkedin.com/company/82436841/#1 Rated Embedded Recruitment Firm on G2!https://www.g2.com/products/securevision/reviewsThanks for listening!
Ready to revolutionize your hiring process and build high-performing teams that add value to your organization? Join our host James Mackey and Gianna Driver, Chief Human Resources Officer at Exabeam, and discover how to redefine 'culture fit' as 'culture add,' and boost innovation. They share insights on measuring diversity impact, addressing performance issues, and handling workplace toxicity in the tech sector. 0:34 Gianna Driver's background 1:43 Effective hiring for high-performing teams11:38 Building diverse and inclusive workplaces16:52 Handling workplace toxicity in the tech sector.21:35 Importance of employee sentiment and feedback Thank you to our sponsor, SecureVision, for making this show possible! Our host James Mackey Follow us:https://www.linkedin.com/company/82436841/#1 Rated Embedded Recruitment Firm on G2!https://www.g2.com/products/securevision/reviewsThanks for listening!
In this episode of The Stream Life Podcast, Cribl's Desi Gavis-Hughson and Exabeam's Chris Stewart join the show to talk about the big news out of Black Hat 2023: Cribl and Exabeam's strategic partnership! Resources Press Release Blog Cribl's solutions with Exabeam If you want to automatically get every episode of the Stream Life podcast, you can subscribe on your favorite podcast app.
Aarna's News | Inspiring and Uplifting Stories of Women In STEM
Join industry experts, trailblazers, and advocates, including Ronit Polak, VP of Engineering at Exabeam and President of Women in Cybersecurity Silicon Valley Affiliate, as we explore strategies for overcoming gender bias in the workplace. Gain insights into personal stories, challenges faced by women, and practical solutions to foster equality and create inclusive work environments. Let's shatter the glass ceiling and empower everyone to thrive. Don't miss this thought-provoking episode! Ronit's Information Resources Mentioned: Lean In by Sheryl Sandberg --- Support this podcast: https://podcasters.spotify.com/pod/show/aarna-sahu/support
This week, host Sagi Eliyahu is joined by Gianna Driver, Chief Human Resources Officer at Exabeam. The focus of the conversation is on empathy and transparency with the people in an organization.Topics discussed include:- The amount of change and destabilization humans have gone through in the past few years.- The role of empathy in attracting and retaining talent in the workplace.- The importance of being empathic while still holding people accountable.- Tools and technology that allow people to anonymously express their opinions or feelings.- Transparency and openness in an organization.Gianna Driver - https://www.linkedin.com/in/gianna-driver-6183391/Exabeam - https://www.linkedin.com/company/exabeam/This episode is brought to you by Tonkean. Tonkean is the operating system for business operations and is the enterprise standard for process orchestration. It provides businesses with the building blocks to orchestrate any process, with no code or change management required. Contact us at tonkean.com to learn how you can build complex business processes. Fast.#Operations #BusinessOperations
When we talk about diversity, equity, and inclusion, or DEI, some leaders still roll their eyes or assume they have bigger fish to fry. But, happily, the trendline shows that companies that can move beyond diversity into true inclusivity experience sustained growth, higher performance, and more revenue. They are the ones harnessing more innovation, attracting top talent, getting more ideas and innovation from their people, and frankly, making smarter business decisions.Today, I talk to Gianna Driver about how DEI efforts support organizational goals and the link between DEI efforts and bottom-line performance. She shares how a company can make the leap from a diverse culture to a truly inclusive one in order to better enjoy those benefits. Gianna shares the ground rules you need to set to make DEI work, and how to be empathetic to - yet manage executive resistance to change. And we talk about her personal story growing up Filipino-American and how it shaped her passion for empowering people. Key Takeaways:People are at the heart and center of everything you do. If you are trying to make a change in your organization, you need to remember that. Healthy relationships have conflict. What matters is not the existence of conflict, but how individuals resolve conflict; the same is true of organizations.We do not leave our humanity at the door when we come to work. Employees need to be treated as humans with respect and multiple facets of their lives. When employees thrive, they bring their best selves to work and have higher performance as a result. "Conflict is necessary for high performance and innovation. What differentiates are those organizations who have found ways to create spaces where people can respectfully and healthfully disagree and come up with better solutions together." — Gianna Driver About Gianna Driver, CHRO, ExabeamGianna Driver is Chief Human Resources Officer (CHRO) at Exabeam, a global cybersecurity leader that adds intelligence to every IT and security stack. As CHRO, Driver manages the strategy and processes related to building, investing in, and retaining top talent at Exabeam, enabling employees to do their best work. She is responsible for architecting the company's talent strategy, driving corporate culture and diversity, equity and inclusion (DEI) initiatives, and leading the global human resources function. Prior to Exabeam, Driver was the Chief People Officer at BlueVine, a private fin-tech company based in Redwood City, CA. Driver has also led HR and People functions in high-growth technology, gaming, consumer, and SaaS organizations including Playstudios, Aristocrat, Actian Corporation, Talend, and Balsam Brands. She is passionate about building high-performance cultures, establishing operational excellence, and creating joy at work. Driver is a graduate of The Wharton School of the University of Pennsylvania.References MentionedThe Empathy Edge podcast: M.E. Hart: How to Have Honest Conversations at WorkConnect with Gianna DriverWebsite: https://exabeam.comLinkedIn: https://www.linkedin.com/in/gianna-driver-6183391/ Don't forget to download your free guide! Discover The 5 Business Benefits of Empathy: http://red-slice.com/business-benefits-empathy Connect with Maria: Get the podcast and book: TheEmpathyEdge.comLearn more about Maria and her work: Red-Slice.comHire Maria to speak at your next event: Red-Slice.com/Speaker-Maria-RossTake my LinkedIn Learning Course! Leading with EmpathyLinkedIn: Maria RossInstagram: @redslicemariaTwitter: @redsliceFacebook: Red Slice
Companies don't scale fast without the right people on the team. Leaders must focus on a strategy to develop people and create a place where culture is everything. Building the right team is essential if you want your company to scale fast. So slow down and make a sustainable plan to scale fast. Today's guest is Michael DeCesare, President, and CEO at Exabeam. Inc Magazine ranked his company #2945 on the 2022 Inc 5000 list. Exabeam is a global cybersecurity leader that created New-Scale SIEM™ for advancing security operations. Built for security people by security people, they reduce business risk and elevate human performance. In this episode, Michael talks about how to lead a company to scale fast and what it takes to build a strong team. He also talks about how the leadership team should be responsible for developing people. Discover how to take your business to the next level and continue to scale fast the way you want it. Get the show notes for Leading a Company to Scale Fast with Michael DeCesare at Exabeam Click to Tweet: Listening to a fantastic episode on Growth Think Tank featuring #MichaelDeCesare with your host @GeneHammett https://bit.ly/gttMichaelDeCesare #ScaleFast #GeneHammettPodcast #GHepisode945 #Inc2022 #globalcybersecurity #SIEM Give Growth Think Tank a review on iTunes!