This website uses cookies

Read our Privacy policy and Terms of use for more information.

What you'll learn

  • Why the best security teams get fast by industrializing — automation, shared tooling, security embedded in the platform — instead of relying on what Phil calls "artisanal craftsmen" with their own unique tools and tribal knowledge.

  • The three attributes of Phil's CISO 2.0: being a business executive who happens to run security, technical empathy with engineering teams, and long tenure — plus why AI is quietly turning CISOs into chief digital risk officers.

  • Attackers are industrializing too: agentic threat actors went from nonexistent to 3% of attacks observed by the Sysdig threat research team in roughly six months, multi-incident tabletops are failing at big companies, and yet Phil argues large segments of infrastructure could reach near-zero software vulnerabilities within two years.

Description

Phil Venables has run security at the highest-stakes levels of two industries — as CISO of Goldman Sachs and, most recently, as CISO at Google. He's now a venture partner at Ballistic Ventures and the author of one of the most-read and most-respected blogs in the security community. He joined us to unpack an idea that runs through most of his recent writing: security teams need to retool for speed, and speed comes from moving from artisanal to industrial.

The argument is simple to state and hard to execute. If your OODA loop runs faster than the attacker's, you win — and you get fast by scaling, not by hiring more brilliant individuals with their own bespoke ways of working. Phil walks the whole staircase of that idea: control reliability engineering, controls that emit enough "digital exhaust" to be continuously validated, security teams that show up with engineering solutions instead of one-page policies, and the uncomfortable fact that attackers — who have "bosses and budgets just like the rest of us" — are industrializing on the same timeline. He also puts numbers on the optimism: a Chrome update that fixed 1,000 vulnerabilities, and a two-year path to near-zero software vulnerabilities for major segments of infrastructure. This one is for CISOs building or rebuilding programs, deputies who want the seat next, and founders trying to sell to either.

What we cover

  • "You get fast by scaling what you do" — the artisanal-to-industrial frame: why great people with unique tools are both a strength and a key-person risk, and what industrial scale actually looks like.

  • "I've often described the very best organizations as like CISO factories" — the small set of companies (Salesforce, JPMorgan, Goldman Sachs, Google) that produce a disproportionate share of Fortune 500 CISOs, and why leadership development is the undersold ingredient.

  • "They just sat down at the table and said, 'I'm here, and this is what we're going to do.'" — nobody grants the seat at the table; the CISO 2.0 attributes of business execution, technical empathy, and tenure.

  • "We really can retool the environment to give us security, but give us so many other things as well" — moving past "security is an enabler" clichés to concrete adjacent benefits: lower fraud and lower customer friction, better SDLC and faster time to market.

  • "Didn't emit enough kind of digital exhaust to let us validate what they were doing" — why continuous assurance forces you to replace effective-but-opaque controls, and how to win that argument with IT and business leaders.

  • "The dirty secret of security is there's always been more vulnerabilities that have gone unexploited than exploited because attackers have been resource-constrained" — agentic threat actors remove that constraint, and every target of opportunity becomes a target.

  • "Two incidents at once, and it failed" — why concurrent incidents break most IR programs, what disclosure regulations do to incident volume, and the case for real incident management platforms.

  • "We could potentially have almost zero software vulnerabilities inside the next two years" — Big Sleep, Naptime, CodeMender, $50 million bug bounties, and a possible renaissance for deception technology.

→ Thank you to our Sponsors:

RISC Point is security & compliance consulting tailored to your business. Talk to RISC Point.

Hampton North is the premier US based cybersecurity search firm. Start building your security team with Hampton North.

Sysdig is the leader in AI-powered real-time cloud defense; stop watching and start defending.

The conversation

"You get fast by scaling what you do"

Phil's opening frame sets up everything else in the episode. Defenders win when their OODA loop — observe, orient, decide, act — runs faster than the attacker's. But declaring "we should be fast" changes nothing. Speed is a byproduct of scale, and most security teams aren't built for it.

"A lot of security teams today are fantastic people, fantastic teams, but they're like artisanal craftsmen."

— Phil Venables

Stuart pushed on the business risk hiding inside that observation: artisanal brilliance walks out the door. In smaller companies, "it's just the security guy," and when that person leaves, the institutional knowledge leaves with them. Phil's answer is to engineer scale into the environment itself — build security into the foundation platforms (shift left becoming shift down), and borrow from how Google runs infrastructure:

"Control reliability engineering is thinking about how do we systematize, industrialize the management and embedding of controls?"

— Phil Venables

The point isn't to replace expert practitioners. It's to amplify them — their skill contributes to a system that keeps working when they're on vacation, or gone. That's true at Google scale and it's true at a two-person security team, which is arguably where it matters more.

CISO 2.0: business executive, technical empathy, and the tenure paradox

Phil has written about CISO 2.0 as three attributes. The first is the business executive angle — the best CISOs are peer executives whose particular focus happens to be security, "just like the CFO is an executive of the company advancing the company whose particular focus happens to be finance and capital allocation and accounting." Nobody grants that status. As Phil put it, the CISOs who've reached it "just sat down at the table and said, 'I'm here, and this is what we're going to do.'"

The second is technical empathy: showing up to engineering teams — who are drowning in transformation work and legacy debt — with your own engineers and combined solutions, not a wagging finger. A principle that predates Phil at Google: "you have to come with solutions, to come with product, to come with engineering solutions." Security didn't leave a one-page policy behind and check back in three months.

The third is the one that cuts against industry folklore: long tenure. Phil has sympathy for CISOs in genuinely hostile organizations, but he's blunt about the pattern of leaving at the first sign of impediment.

"So you push through that and you have another go, and you reframe it, and then you ask and then you persevere, then all of a sudden, things start to click into place, and you get more resources, you're more trusted in the organization."

— Phil Venables

By years five to ten, the most successful CISOs can get almost anything done — not because the organization changed, but because they stayed long enough to become part of it. Stuart added the hiring-market view: commercially minded security engineers in their late twenties are cutting the line into head-of-security seats precisely because they operate this way from day one. There's also a new branch on the journey — CISOs becoming CTOs after successfully championing infrastructure reinvestment, which Phil thinks is mostly temporary, and Stuart thinks is a burnout risk worth watching.

The adjacent-benefits play that gets CEOs to fund security

"Security is an enabler" is a throwaway line. Phil's version has teeth: go one level below the cliché and find where doing security differently produces commercial outcomes. Retool customer authentication to cut fraud and account takeover, and if you do it with good design you also get fewer lockouts, fewer abandoned transactions, and a better customer experience. Retool the SDLC so software can be rebuilt at will, and you get security plus agility, time to market, reduced cost, and reliability. Stuart's example: when FanDuel had a login problem, DraftKings — with a smoother flow — absorbed a rush of customers, because nobody places a bet for next month.

"We really can retool the environment to give us security, but give us so many other things as well."

— Phil Venables

The psychological kicker is that the search itself pays off even when the adjacent benefits don't materialize:

"Even if they don't get the results, they're seen in a positive, engaging way that causes them to get more support."

— Phil Venables

And that accumulated trust is what makes the rare "no" land. Phil's honest about it: security should never be the department of no, but a few times a year you genuinely have to throw the flag on the field — and people only sit up when your no is surprising.

Continuous assurance dies without controls that emit digital exhaust

Conor floated a thesis — that the true output of a security program is a currency of trust, built from security, safety, and reliability — and Phil agreed with one addition: constant testing and validation. Most organizations ground their testing in change events. AI breaks that model, because model drift and similar failure modes require validating continuously, not just when something new ships.

The trap in moving to continuous anything is automating processes that were never efficient in the first place. Organizations that do it well go back to first principles — and usually discover the controls themselves are the problem. Phil described effective, well-loved controls that

"didn't emit enough kind of digital exhaust to let us validate what they were doing."

— Phil Venables

Telling an IT leader that a working control needs replacing because it can't be continuously monitored is a painful conversation, and Phil's advice is to bring every tool of influence: it'll be cheaper, there'll be less central recharge, you'll gain agility. Conor shared the war story from the other side — a legacy AV system that "never emits a false positive" because the engineers had tuned it out of existence, and the technical empathy required to walk that team, not run them, to something better.

Attackers have bosses and budgets — and now they have agents

The most sobering stretch of the conversation starts with a line worth keeping:

"The dirty secret of security is there's always been more vulnerabilities that have gone unexploited than exploited because attackers have been resource-constrained."

— Phil Venables

Agentic tooling removes the constraint. Conor cited the Sysdig threat research team's numbers: agentic threat actors didn't exist six months ago, and now account for 3% of observed attacks — a climbing rate, with JadePuffer as the marquee example. Phil's conclusion isn't "buy AI to fight AI." It's that a relentlessly enforced high baseline — MFA, segmentation, patching — becomes table stakes, because "you're not going to be able to hide in the sea of other targets."

The downstream effect lands on incident management. Phil has seen three big companies recently run tabletops simulating just two simultaneous incidents — and fail, sometimes because a single outside counsel can only run one disclosure decision cycle at a time. Meanwhile regulations worldwide are lowering disclosure thresholds:

"There'll be more incidents, more types of incidents, and more things that will be disclosable."

— Phil Venables

Five incidents a week instead of one every two weeks means documents and spreadsheets stop working — which is the thesis behind Ballistic portfolio companies like BreachRx, and more broadly Phil's democratization play: Armadin (Kevin Mandia's AI red-teaming company) and Above Security (insider risk) sell world-class capabilities that almost no one could previously afford to staff. Practical homework from this section: run a two-incident tabletop and see how it lands.

Near-zero software vulnerabilities inside two years

Phil describes himself as a near-term pessimist and long-term optimist, and the optimism is specific. Defenders have a structural, home-field advantage with AI — the context and the data to use models in ways attackers can't match.

"We could potentially have almost zero software vulnerabilities inside the next two years. Not for the whole world, but for big segments of infrastructure."

— Phil Venables

The evidence: Google Chrome shipped an update fixing 1,000 vulnerabilities, with tools like Big Sleep, Naptime, and CodeMender running a relentless find-and-fix cycle. Pair continuous AI red teaming with AI-augmented remediation — a fast-detect loop and a fast-fix loop — and vulnerability counts trend toward zero. Phil even wonders aloud whether we'll see the first $50 million bug bounty once exploitable flaws become scarce enough.

Attackers won't retire — "They're not going to go, 'Oh, shucks, I should go get a regular job now.'" Expect more scams and more coercion of insiders to induce vulnerabilities from within. But there's a curveball for defenders too: early post-mortem evidence suggests AI agents are more susceptible to deception technology — honeytokens, honeytraps — than human attackers ever were. A category that arrived too early a decade ago may get its renaissance, especially now that agentic operations can run a deception infrastructure without consuming your engineers. The advantage goes to the defender — but only if defenders do the work to adopt it.

One more thing worth pulling out of this stretch: Phil's advice to vendor CEOs. You're not selling a technology, "you're selling a technology to solve a real problem" — and don't fixate on the CISO. His deputies had correct opinions about the tools they needed, and "99 times out of 100, I would go, 'Fine.'" His standing rule for buyers: "you should never buy a product that you then have to buy another security product to make it safe." Don't buy the car and then the seat belts.

Show notes

Guests — Phil Venables, venture partner at Ballistic Ventures; former CISO of Google and CISO of Goldman Sachs; author of one of the most-read blogs in the cybersecurity community.

Books mentioned — None named in the conversation.

Frameworks / models / tools named — OODA loop; artisanal-to-industrial; CISO 2.0; control reliability engineering; site reliability engineering (SRE); shift left / shift down; Intent-Based Leadership (David Marquet); continuous assurance / continuous controls validation; deception technology (honeytokens, honeytraps); Big Sleep; Naptime; CodeMender; Google Chrome; Armadin; Above Security; BreachRx; Sysdig threat research.

Other people / shows / resources referenced — Kevin Mandia; David Marquet; Matt Stamper (LinkedIn Live on agentic threat actors); InfraGard; Black Hat; RSAC; JadePuffer; Salesforce, JPMorgan, Goldman Sachs, and Google as CISO factories; Anduril; Fox; FanDuel; DraftKings; Apollo Global Management; Google Cloud; Ballistic Ventures portfolio.

Hosted by Conor Sherman and Stuart Mitchell.