Category: AI and Cybersecurity

  • How AI Will Disrupt Entry-Level Jobs and Create More Snake Oil Influencers: The AI/Human Apprenticeship Shakeup

    How AI Will Disrupt Entry-Level Jobs and Create More Snake Oil Influencers: The AI/Human Apprenticeship Shakeup

    Overview

    Much of the opinion on how AI will change human work is polarizing: AI will either create a paradise where we’re all relaxing with our newfound time and wealth or it will cause the rapid downfall of civilization and kill us all. To me, the result of changing in the division of human/AI labor will be much more gradual, but will cause monumental shifts in education, work, recreation, and how we meatbags spend our time. In this article, I want to explore a few obvious shifts, the second and third-level effects, and finally a prediction that we’ll see the TikTok-style “Snakeoilification” of entry-level work.

    Part One: Obvious Predictions on What AI Will Change in Human Jobs

    Displacement of Blue-Collar Workers in Construction, Manufacturing, and Agriculture

    One of the most common predictions is that AI will replace construction, manufacturing, and agriculture jobs. I think that the combination of semi-manual labor and how much technology has changed these industries make these sectors an easy target. Some examples:

    • Mining and Construction: AI-powered robots and machinery can take over dangerous tasks in mining, construction, and oil drilling, significantly reducing the risk of human injury. This displacement benefits workers by removing them from hazardous environments.
    • Manufacturing: In sectors where repetitive tasks dominate, like automotive or electronics manufacturing, AI can perform tasks with greater precision and consistency. This can free human workers to focus on more complex, creative, or supervisory roles.
    • Precision Farming: AI can help optimize the use of resources in farming, reducing the need for manual labor while increasing crop yields. Automated machines can plant seeds, monitor crops, and apply fertilizers or pesticides in precise amounts, reducing waste and environmental damage.
    • Farm Management: AI systems can monitor soil health, weather conditions, and pest activity to help farmers make data-driven decisions, improving efficiency and sustainability in agriculture.

    Let’s then look at the 2nd and 3rd level effects that could result from AI taking over these jobs,

    Second-Level Effects:

    • Disruption of Unions and Worker Protections: As AI takes over dangerous and repetitive jobs in these industries, unions that traditionally protect blue-collar workers could lose influence. This could result in fewer collective bargaining opportunities, wage stagnation, or less job security in remaining roles.
    • Impact on Trade Schools and Vocational Training: Institutions that train people for trades like welding, carpentry, and machinery operation may see decreased enrollment, forcing these schools to pivot toward emerging industries like robotics maintenance, AI system operation, or renewable energy technologies.
    • Shift in Supporting Industries: Companies like Home Depot, Lowe’s, and others that rely on DIY construction, repair, and renovation may experience downturns in sales as demand for construction tools and materials declines. The retail economy could see fewer in-person customers, forcing adaptation through new business models, such as focusing on automation maintenance tools or smart home devices.

    Third-Level Effects:

    • Migration to New Sectors: Blue-collar workers displaced by AI in mining and manufacturing may seek opportunities in sectors like healthcare, renewable energy, or logistics. These sectors will need to adapt by offering reskilling programs for workers with a different skill set and expanding job openings in roles like technician and maintenance.
    • Economic Shifts in Regions Dependent on Traditional Industries: Regions whose economies are heavily reliant on mining, construction, or manufacturing might suffer economically. This could lead to regional economic depressions, a shrinking tax base, and a shift toward service-based or gig economies.

    AI in Retail

    Right after manual labor is retail, and the lowest paid, lowest margin industries are always looking to cut costs and have lower turnover.

    Second-Level Effects:

    • Decline of Traditional Retail Jobs: As AI takes over customer service (via chatbots) and in-store operations (via automated checkout), traditional retail jobs will diminish. This will impact roles like cashiers, stock clerks, and even customer service representatives.
    • Shift in Retail Skills: Retail workers will need to shift from customer-facing roles to more technical ones, such as robotic maintenance, supply chain optimization, or AI system management. Retail training programs may need to focus on technical literacy rather than interpersonal skills.

    Third-Level Effects:

    • Increase in E-commerce Jobs: While traditional retail jobs may shrink, e-commerce platforms and digital services could see growth in positions related to logistics, warehousing, and customer experience design. New job opportunities will emerge in areas like managing AI-driven supply chains and optimizing last-mile delivery.
    • Impact on Local Economies: Local economies reliant on brick-and-mortar retail could see a decline, which might prompt cities to rethink urban planning. Commercial spaces may transition to co-working hubs or experience-driven retail (e.g., pop-up stores, interactive events) that provide something AI cannot replace.

    Displacement of Support Staff by AI in Administrative Work

    Moving down the “perception of humanness” continuum of work, we can then look at support staff in the professions. Administrative roles. Again, these are roles that perform similar, repeated tasks that are often entirely computer-based.

    Some examples:

    • Document Review and Contract Analysis: AI can handle routine legal tasks like reviewing contracts, analyzing case law, or preparing documentation. Lawyers and legal professionals can then focus on more complex tasks like litigation, negotiations, and client advisory roles, where human judgment and creativity are indispensable.
    • Tax Preparation: AI can streamline tax filing processes, reducing errors and speeding up the work that accountants do for routine tax returns. This allows accountants to focus on more strategic financial planning services.
    • Customer Support: AI-driven chatbots can handle routine customer service queries, such as FAQs or simple troubleshooting, reducing the workload for human support agents. Displacement here allows human workers to focus on more complex, personalized, or higher-level customer issues, which can improve overall service quality.

    Second-Level Effects:

    • Decline in Paralegal and Administrative Roles: As AI takes over document review, case analysis, and administrative tasks, there will be fewer entry- to mid-level jobs for paralegals, legal assistants, and administrative professionals. Law firms may become leaner, focusing on higher-tier roles like attorneys or legal strategists.
    • Changes in Legal Education: With fewer entry-level legal roles, the appeal of law school may decrease, leading to a reduction in law school enrollments. This could shift the focus of legal education from routine work to strategic, AI-supported roles like legal technology experts or cyber law specialists.
    • Mid-Level White-Collar Job Scarcity: Young professionals seeking stable, mid-level white-collar jobs like paralegals or office managers may find themselves struggling to find employment in fields traditionally reliant on administrative work. This could drive them toward sectors like data analysis, project management, or customer experience management, which may experience a surge in demand for human oversight of AI systems.

    Third-Level Effects:

    • Widening Gap in Legal Representation: As fewer people enter the legal profession, there may be a gap in representation for lower-income individuals or small businesses. While AI may help automate some legal services, it could increase the divide between those who can afford human legal expertise and those who must rely on AI-driven legal advice.
    • Higher Education Shift: Universities may need to rethink curricula to accommodate fewer students entering traditional mid-level professions like law, accounting, or office management. There could be a rise in new academic disciplines, such as AI governance, ethics, or data rights law, to prepare students for a legal field shaped by AI.

    AI and the Impact on Creative Industries

    This is where it gets into the argument about whether AI can create art, and whether the “creative” industries will really only be dominated by us humans. I think there’s something uniquely human about saying “only people can do this”, but let’s put that aside and look at a few potential effects.

    • Content Creation Support: In fields like design, music, and art, AI can assist creators by handling repetitive tasks such as generating design templates or background music. This doesn’t displace the creative process but augments it, enabling artists to focus on higher-level work.
    • Elimination of “Low-Level” Creative Work – Things like stock photography, royalty-free music, and low-cost video work are already being eliminated as viable income-generators due to AI tools.

    Second-Level Effects:

    • Reduction in Entry-Level Creative Jobs: AI-driven tools in design, writing, and content creation could reduce the need for entry-level positions in advertising, publishing, and media. For example, companies might use AI-generated copy or design elements, leaving fewer opportunities for junior writers, graphic designers, or video editors.
    • Evolving Creative Education: Creative arts programs may need to shift their focus from traditional skills (like drawing or writing) to AI-augmented creativity, teaching students how to collaborate with AI systems to enhance their output. This could also lead to the emergence of new roles such as AI-curators or content integrity managers who manage AI output to maintain brand and creative standards.

    Third-Level Effects:

    • Rise of AI-Driven “Gig” Economy in Creative Work: Many displaced creative workers might turn to freelance or contract-based work, creating a larger gig economy in the creative sectors. Platforms like Upwork or Fiverr could see a rise in professionals using AI tools to enhance their service offerings, further driving down prices in competitive creative fields.
    • Shift Toward Experience-Driven Marketing: As AI takes over content generation, human creativity may become more valued in experiential fields like event marketing, experiential design, or storytelling-based marketing, where emotional intelligence, human connection, and originality are essential.

    Part Two: The Decline of “Apprenticeship”

    That might be the longest preamble I’ve ever written to get to my main point. Sorry. I actually cut some fluff…really…there was even more before! Here’s the main point:

    For hundreds of years, we humans have accepted an apprentice system whereby the “expert” is willing to exchange mentorship and guidance for cheap labor. The entry-level worker is willing to dedicate time and effort above and beyond what they’re getting paid in order to get experience and learn from the professional. From unpaid internships to “individual contributor” roles, this exchange is seen as normal and sometimes necessary – especially in highly competitive, highly-compensated roles.

    But what happens when the expert can replace cheap labor with free, AI-based assistants?

    What Happens When Entry-Level Jobs Evaporate?

    This will be a topic for an entire post, but here’s a teaser:

    We’re already seeing a large shift where people sell “fast track” techniques to success, like courses on drop shipping, increasing followers to become influencers, affiliate marketing, and so on. These creators capitalize on people’s wish to bypass traditional pathways by promoting “passive income” strategies that avoid climbing a corporate ladder or gaining gradual experience.

    This shows a type of meta-market where knowledge about how to hack or game the system becomes the product itself. These “inside secrets” essentially offer a promise of bypassing traditional expertise in favor of quick success. This shift also contributes to the gig economy and creator economy, where many people attempt to leverage platforms for short-term gains, often without building long-term skills or relationships, which might have historically come from working under an experienced mentor or within a structured organization.

    In this way, the “apprentice effect” is not just hypothetical—it’s already happening, and we’re seeing people try to capitalize on this trend by selling courses on shortcuts to success. These new pathways raise concerns about sustainability and depth of expertise, but they reflect how individuals are adjusting to the changing landscape of work. 

    In other words, if you roll your eyes every time you see an ad touting a new “proven method” to gaining followers, creating a YouTube channel that pays $50k per month, or teaching you to sell a course, get ready…..your eyes are going to be bleeding soon.

  • The Human Role in Cybersecurity: Adapting to AI’s Evolution

    The Human Role in Cybersecurity: Adapting to AI’s Evolution

    As artificial intelligence (AI) and machine learning (ML) continue to revolutionize the field of cybersecurity, it’s crucial to understand the evolving roles of humans and machines in this domain. While AI can handle many tasks with unprecedented speed and accuracy, there remains a vital space for human expertise. This article explores the division of responsibilities between humans and AI, highlighting what each is best suited for and how cybersecurity professionals can adapt to this changing landscape. It’s the first in a sort of “thinking out loud” articles looking at what I think is an inevitable future.

    AI’s Strengths in Cybersecurity

    AI and ML excel in tasks that require the rapid processing of large amounts of data, identifying patterns, and reacting in real-time to threats. These technologies are particularly effective in:

    1. Threat Detection and Response: AI systems can monitor network traffic, analyze vast amounts of data, and recognize patterns that may indicate a cyber threat far faster than any human could. For example, AI can identify anomalies in behavior or detect new types of malware by recognizing subtle patterns that would be invisible to the human eye.

    2. Automated Incident Response: In situations where speed is crucial, like when containing a ransomware attack, AI can automate responses to mitigate damage. Automated systems can isolate infected devices or block malicious traffic almost instantaneously, actions that might take a human operator minutes or even hours to execute.

    3. Predictive Analytics: By analyzing historical data, AI can predict potential future attacks and help organizations to preemptively strengthen their defenses. This predictive capability is essential in a landscape where new threats emerge constantly, and staying ahead of adversaries is key.

    The Speed of Adversaries and the Challenge for Humans

    One of the most significant challenges in modern cybersecurity is the speed at which adversaries, often empowered by AI themselves, operate. Cybercriminals are leveraging AI to launch sophisticated attacks at a pace that is simply incompatible with human response times. For instance, AI-driven phishing campaigns can target millions of users simultaneously, adapting their strategies based on real-time data, making it nearly impossible for humans to keep up without assistance. A few resources:

    As these threats become more advanced, the role of AI in defense becomes not just beneficial but necessary. While AI can manage and respond to these threats quickly, it still requires human oversight to make sure that responses are appropriate and ethical.

    Human Strengths: What AI Can’t Replace

    Despite AI’s capabilities, there are areas where human skills are (at least currently) irreplaceable:

    1. Strategic Decision-Making: AI can provide data and even suggest actions, but humans are better at making complex decisions that consider context, ethics, and long-term consequences. For example, deciding how to respond to a sophisticated attack might require an understanding of the geopolitical implications that AI lacks.

    2. Creativity and Problem-Solving: While AI excels at pattern recognition, it struggles with out-of-the-box thinking. Humans can devise creative solutions to new problems, such as developing innovative cybersecurity strategies or creating novel defenses that an AI might not be programmed to consider.

    3. Understanding Human Behavior: Cybersecurity is not just about technology but also about people. Humans are better at understanding and anticipating how other humans behave, which is crucial in areas like social engineering defense and insider threat detection.

    Note: The notion that there are things that AI can’t replace is an interesting topic, and something worthy of an entire article challenging whether these three examples are truly impossible for AI to dominate.

    Shifting Focus: What Humans Can Do with Freed-Up Time

    As AI takes over routine and time-consuming tasks, cybersecurity professionals have the opportunity to focus on more strategic and creative work. This shift is not unlike what has happened in other industries over time. For example:

    • Manufacturing: Automation and machinery took over repetitive tasks on the production line, allowing workers to move into roles that required more oversight, quality control, and innovation.

    • Agriculture: The introduction of industrial equipment reduced the need for manual labor, enabling farmers to focus on crop management, sustainability practices, and business expansion.

    In cybersecurity, professionals can now dedicate more time to:

    • Developing Security Policies and Frameworks: With AI handling real-time threats, humans can focus on creating and refining security policies that address broader organizational goals and compliance requirements.

    • Conducting Advanced Threat Research: Freed from routine monitoring, security experts can delve into researching emerging threats, studying the latest attack vectors, and developing new defense techniques.

    • Training and Awareness: Human experts can invest more time in educating employees and users about security best practices, an area where human interaction is essential.


    Adapting Training and Education for Entry-Level Cybersecurity Professionals

    As AI takes on a more significant role in cybersecurity, it’s crucial to rethink how we train and educate entry-level cybersecurity professionals. The traditional curriculum, which often focuses on manual processes and basic technical tasks, must evolve to prepare new professionals for a world where AI is a critical component of the cybersecurity toolkit. While it’s still important to train cybersecurity professionals on the fundamentals, it’s worth revisiting the reality of the new co-pilot or AI collaboration model of day-to-day cyber work.

    Traditional Curriculum vs. AI-Enhanced Curriculum

    A typical entry-level cybersecurity curriculum includes courses on network security, incident response, ethical hacking, and cybersecurity fundamentals. For example, a program like the Certified Information Systems Security Professional (CISSP) or CompTIA Security+ certification includes topics like:

    • Network and Host-Based Security: Configuring and managing firewalls, intrusion detection systems, and antivirus software.

    • Incident Response: Identifying, analyzing, and mitigating cybersecurity incidents manually.

    • Ethical Hacking: Learning to use manual penetration testing tools to identify vulnerabilities.

    While these skills are foundational, many of the tasks involved can now be performed more efficiently by AI. Therefore, the curriculum needs to pivot to ensure that entry-level professionals are not just equipped to work alongside AI but can leverage it effectively as a “cybersecurity co-pilot.” Again, this isn’t to suggest we ditch the basics and let people simply rely on AI without understanding the core concepts. Instead, there must be a balance.

    Potential Curriculum Changes

    Here’s how we can adapt the existing curriculum to incorporate AI:

    1. AI-Driven Security Tools:

    • Current Curriculum: Manual use of firewalls, IDS, and antivirus software.

    • Updated Curriculum: Training on AI-driven security platforms like those from Palo Alto Networks, CrowdStrike’s Charlotte AI, or IBM’s AI-driven threat detection tools. Students should learn how to configure, monitor, and interpret the outputs of these AI tools, understanding how AI makes decisions and how to intervene when necessary.

    2. AI-Augmented Incident Response:

    • Current Curriculum: Manual identification and response to security incidents.

    • Updated Curriculum: Focus on AI-based incident response automation. Students should be trained to work with AI systems that automatically detect, analyze, and respond to incidents. They should understand how to use these systems, how to review AI-driven decisions, and how to escalate or modify responses when human judgment is required.

    3. AI in Ethical Hacking:

    • Current Curriculum: Learning manual penetration testing techniques.

    • Updated Curriculum: Introduction to AI-powered penetration testing tools that can automate the discovery of vulnerabilities. Students should be trained on how to interpret the results from these tools, validate findings, and understand where AI can fall short, requiring human intuition and creativity.

    4. Understanding AI Ethics and Governance:

    • New Addition: Introduce courses that cover the ethics and governance of AI in cybersecurity. As AI systems make decisions that affect security, understanding the ethical implications of AI deployment and the biases that may be present in AI algorithms becomes critical.

    5. Collaborative Problem Solving:

    • New Addition: Develop courses that emphasize collaboration between human and AI teams. This includes case studies where students must determine when to trust AI, when to intervene, and how to work in tandem with AI to solve complex security challenges.

    Emphasizing Soft Skills and Strategic Thinking

    As AI handles more routine and technical tasks, entry-level cybersecurity professionals should be encouraged to develop soft skills and strategic thinking. This includes:

    • Communication Skills: Explaining complex AI-driven decisions to non-technical stakeholders.

    • Strategic Planning: Understanding the broader implications of AI in security and how to align AI strategies with business objectives.

    • Continuous Learning: As AI evolves, professionals must stay updated on the latest technologies, tools, and ethical standards.


    The pivot to a collaborative model between humans and AI in cybersecurity necessitates a corresponding shift in how we train the next generation of professionals. By updating curricula to emphasize AI tools, strategic thinking, and ethical considerations, we can ensure that entry-level professionals are well-prepared to thrive in a landscape where AI is a central player in cybersecurity defense. This approach not only equips them with the necessary technical skills but also empowers them to take on more strategic roles, driving innovation and enhancing the overall security posture of organizations.

    Conclusion

    In a world where AI is increasingly capable of handling many cybersecurity tasks, the role of the human evolves rather than diminishes. While AI excels at speed, pattern recognition, and automation, humans remain essential for strategic decision-making, creativity, and understanding human behavior. As AI takes over more routine tasks, cybersecurity professionals can focus on higher-level responsibilities that require human insight, ensuring that they continue to play a crucial role in protecting organizations from evolving cyber threats.

    Note: This article was written in collaboration with ChatGPT and WordPress. I used ChatGPT to create the initial outline based on the prompt:

    
    
    What is the role of the human in a world where AI can handle many of the tasks needed in cybersecurity? Help me write an outline for an article about what people should do vs. what AI should be responsible for and include the following:
    1. What cybersecurity tasks are obviously better suited for AI/ML based on things like speed and pattern recognition
    2. The idea that adversaries are taking advantage of AI/ML and will continue operating at a speed incompatible with human capacity
    3. What humans will be better at than AI/ML
    4. What people can do if they're not spending time on the types of tasks that will be taken over by AI - here please give examples of work that humans did in the past, but innovation in automation, machinery, industrial equipment etc. meant that people could instead do more strategic work
    5. How we should adapt our approach to training and educating entry-level cybersecurity professionals given this pivot to a collaborative model between humans and AI. 

    Additionally, every image in the post was generated using the default “create image with AI” feature within WordPress.

  • Building a Startup Cybersecurity Strategy from Scratch: A Step-by-Step Guide

    Building a Startup Cybersecurity Strategy from Scratch: A Step-by-Step Guide


    Introduction

    Cybersecurity is often an afterthought for startups focused on growth, product development, and securing funding. However, the cost of ignoring cybersecurity can be catastrophic, especially in a world where data breaches and cyberattacks can take down even the largest companies. As a startup founder or executive, you don’t need an army of security professionals to protect your business—you just need the right strategy.

    This guide provides a clear, step-by-step approach to building a robust cybersecurity strategy from scratch that grows with your company.


    Step 1: Understand Your Startup’s Risk Profile

    Before diving into specific tools or policies, it’s crucial to first understand the risks specific to your startup. Different industries and business models have varying security concerns. A SaaS platform handling sensitive customer data will have different risks than an e-commerce company, for example.

    Key Questions to Ask:

    • What kind of data do we collect, process, or store? Is it sensitive (e.g., financial or health information)?
    • What would happen if we lost access to critical systems?
    • Who would want to attack our business, and why?

    By answering these questions, you can assess the potential impact and likelihood of a cyber incident, allowing you to prioritize which areas of cybersecurity to focus on first.


    Step 2: Build a Security Culture from Day One

    Security is not just an IT issue—it should be embedded into your startup’s culture from day one. Building this culture early on will ensure that all employees, regardless of their role, are aligned with the company’s security goals.

    Actionable Tips:

    • Training and Awareness: Make cybersecurity training part of onboarding for all new employees. Teach them about common threats like phishing, social engineering, and password hygiene.
    • Foster Accountability: Encourage a mindset where every team member takes responsibility for security, whether they’re in engineering, marketing, or sales.
    • Regular Communication: Have open lines of communication about security incidents and vulnerabilities. Transparency is key to creating a proactive security culture.

    Step 3: Implement Basic Security Measures First

    You don’t need to hire a full-time CISO or invest in expensive security tools right away. Start by implementing basic cybersecurity best practices that can drastically reduce your risk.

    Security Basics for Startups:

    • Strong Passwords and Multi-Factor Authentication (MFA): Implement MFA wherever possible—especially for critical systems such as email, CRM platforms, and development environments.
    • Data Encryption: Ensure that data at rest and in transit is encrypted using industry-standard protocols (e.g., TLS for data in transit, AES-256 for data at rest).
    • Backup and Recovery Plan: Regularly back up your data and have a disaster recovery plan in place. Automate backups for critical data and systems, and ensure that backups are stored securely.

    Suggested Tools:

    • 1Password or LastPass for password management.
    • Google Workspace or Microsoft 365 for built-in security and data encryption.
    • CrashPlan or Backblaze for automated backups.

    Step 4: Identify and Secure Critical Assets

    Your startup might not have many resources to secure everything equally, so you need to prioritize protecting the assets that matter most. These could include customer data, proprietary code, intellectual property, or key infrastructure.

    Steps to Secure Critical Assets:

    1. Map Your Data: Identify where your most sensitive data is stored and how it flows between systems.
    2. Segment Networks: Separate critical systems and data from less important systems. For example, development environments should be segmented from production environments.
    3. Apply Principle of Least Privilege: Limit access to critical systems and data to only those who absolutely need it. Implement role-based access controls (RBAC).

    Suggested Tools:

    • AWS IAM or Azure AD for access management.
    • Datadog or Elastic Security for monitoring infrastructure and assets.

    Step 5: Protect Against Common Attack Vectors

    Startups are often targeted by cybercriminals looking to exploit weak points. Understanding the most common attack vectors will help you defend against them.

    Top Threats to Startups:

    • Phishing Attacks: Employees may receive fake emails designed to trick them into sharing sensitive information or credentials.
    • Ransomware: Hackers encrypt your data and demand a ransom for its release.
    • Insider Threats: Both malicious and accidental insider actions can expose your business to security risks.

    Key Defenses:

    • Email Filtering and Anti-Phishing: Use email filtering solutions that block suspicious emails and train employees to recognize phishing attacks.
    • Endpoint Protection: Ensure all company devices are protected with antivirus software and endpoint detection and response (EDR) tools.
    • Access Controls: Implement strict access controls for sensitive data and systems.

    Suggested Tools:

    • Proofpoint or Mimecast for email security.
    • CrowdStrike or SentinelOne for endpoint protection.

    Step 6: Establish an Incident Response Plan

    No matter how well-prepared your startup is, incidents can still happen. Having an incident response plan ensures that your team can act swiftly and minimize the damage.

    Key Elements of an Incident Response Plan:

    • Incident Detection: Set up monitoring to detect potential threats early. This could involve alerts for unusual login attempts, unexpected data transfers, or system changes.
    • Response Team: Assign roles and responsibilities to a response team, including who will handle internal communication, who will investigate the issue, and who will communicate with external stakeholders.
    • Post-Incident Review: After an incident is resolved, conduct a thorough post-mortem to understand what went wrong and how to prevent future incidents.

    Suggested Tools:

    • Splunk or Datadog for real-time monitoring.
    • Trello or Jira for managing response steps.

    Step 7: Plan for Growth with Scalable Security Solutions

    As your startup grows, so will your attack surface. Security should scale alongside your business, so it’s important to invest in tools and processes that can grow with you.

    Scalable Security Practices:

    • Cloud Security Posture Management (CSPM): As you adopt cloud services, CSPM tools will help you continuously monitor and improve your cloud security.
    • DevSecOps: Integrate security into your development pipeline early (shift-left security) to catch vulnerabilities before they go to production.
    • Third-Party Risk Management: As your ecosystem expands, ensure that your vendors and partners also have robust security practices.

    Suggested Tools:

    • Palo Alto Prisma Cloud or Lacework for CSPM.
    • Snyk or Veracode for DevSecOps.

    Conclusion: Start Small, Scale Big

    Building a cybersecurity strategy for your startup doesn’t need to be overwhelming. By focusing on the basics and implementing scalable security practices, you can create a strong foundation that grows with your company. Cybersecurity should be viewed as an ongoing process—not a one-time project. With the right mindset, tools, and a proactive approach, your startup can stay secure and resilient in today’s dynamic threat landscape.


  • AI and Cybersecurity: Sharing Insights from AI Revenue Summit Thought Leader Award

    AI and Cybersecurity: Sharing Insights from AI Revenue Summit Thought Leader Award

    I’m incredibly honored to have been recognized as an AI Thought Leader at the AI Revenue Summit, an event that brings together the brightest minds in the AI and tech industries. This award signifies a pivotal moment for me, marking the beginning of a new chapter where I’ll be sharing my thoughts on the future of AI—particularly its impact on the field of cybersecurity.

    What is the AI Thought Leader Award?

    The AI Thought Leader Award is designed to recognize individuals who are making significant strides in advancing AI technologies and solutions. At the AI Revenue Summit, leaders across industries were selected for their contributions to AI innovation and thought leadership. The judging panel considered not only technical expertise but also the ability to communicate complex AI concepts in ways that help companies understand their real-world impact.

    It’s not just about being an expert in AI but about creating a vision for how AI can transform industries, improve workflows, and solve previously insurmountable challenges. Winners are chosen based on their impact in the AI community, their influence on industry peers, and their potential to drive change in how AI is used in business and technology.

    Why This Matters to Me

    This recognition is both exciting and humbling. I’ve always believed that AI has the potential to reshape cybersecurity, offering us new tools to automate repetitive tasks, detect threats faster, and reduce human error. However, like many emerging technologies, the real challenge lies in integrating AI in ways that don’t diminish the human element but rather enhance it.

    Cybersecurity, in particular, stands at the intersection of AI and human expertise. As I start to dive deeper into the subject, I’ll be sharing insights on how AI can play a pivotal role in incident response, anomaly detection, and workflow automation—areas where speed and precision are critical. But more importantly, I’ll explore how these technologies can free up our talented security professionals to focus on strategic thinking and creative problem-solving, areas where humans still reign supreme.

    What’s Next?

    Over the coming months, I’ll be posting more regularly on NathanWBurke.com about AI’s role in cybersecurity, what organizations can do to adopt these technologies effectively, and how we can maintain a strong partnership between AI and human-driven work. This award has given me the encouragement to share my vision more openly and foster discussions around how we can build a future where AI is a trusted ally in securing our organizations.

    Note: This post was written entirely by ChatGPT.

  • Dig This Event – Black Hat 2024

    Dig This Event – Black Hat 2024

    This year at Black Hat, the great Anna Suslova and Ryan Morasco came up with an amazing idea: instead of the boring, usual events…why not rent excavators and crush cars?

  • I’m Not a Security Practitioner But I Play One on LinkedIn: Investigating LinkedIn’s “Possible malicious content” Flagging

    I’m Not a Security Practitioner But I Play One on LinkedIn: Investigating LinkedIn’s “Possible malicious content” Flagging

    TLDR; When Nagomi emerged from stealth in April, we noticed that any time we linked to nagomi.security on LinkedIn, it would be flagged as “Possible Malicious Content.” Here’s why and how the issue was resolved. And some interesting findings…..

    Disclaimer: The Author Isn’t a Security Practitioner.

    I’ve worked at several cybersecurity companies, but I’m not a researcher, engineer, or any flavor of legitimate security practitioner. I was a developer back in the stone age (early 2000s), but I don’t claim any expertise whatsoever. There’s a high probability that I’ll get some stuff wrong, so I figure I should start with that.

    Possible Malicious Content: A Not-So-Great Look for a Cybersecurity Company

    If you’ve ever launched a company and its website from stealth, you’d know that it’s a lot like a duck swimming. On the surface it looks calm and natural. Underneath it’s web-footed chaos.

    Gif of a website launch.

    But this one was actually pretty straightforward with very few hiccups. In fact, I remarked that this was one of the easiest site launches I’ve ever done. Which is why the next part happened. The universe loves a gloater.

    Right after launching the site, I launched our LinkedIn page. And immediately I noticed something weird: as soon as I put in nagomi.security as our site URL and URL for a CTA button, I saw that the URL was overwritten and went to:

    And after playing around a bit, I noticed that ANY .security TLD was getting overwritten. But that didn’t make sense…there are plenty of companies that have .security domains….

    I then saw that any time we posted from the Nagomi Security LinkedIn page, if we linked to, say:

    https://nagomi.security/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/

    Clicking that link would result in:

    Why Is LinkedIn Marking Our Domain as Possibly Malicious?

    I reached out to LinkedIn support about the issue and got the following reply (and quickly):

    Going to VirusTotal, we saw:

    Two security tools listed in VirusTotal dinged us for having a “newly registered domain name”. Although the domain was registered in January….

    …I guess “newly registered” is subjective.

    We then reached out (via form fills) to the 2 vendors to get out of domain jail. Meanwhile….

    Hey! Look!! I Found A Workaround!!

    Filling out forms isn’t exactly the most urgent path to getting a problem solved, so in the meantime we needed to share our content and build a following for our LinkedIn page. I found a couple of workarounds – each with quirks.

    Workaround 1: A .com Domain Forwarding to the .security Domain

    A few days before registering nagomi.security, we registered nagomisecurity.com

    That domain just forwards to nagomi.security, so if we want to promote the blog post that’s at:

    https://nagomi.security/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/

    we could just use:

    https://nagomisecurity.com/what-is-credential-stuffing-and-how-can-cybersecurity-teams-use-existing-tools-to-minimize-the-threat/

    It works, but it’s kind of long. LinkedIn uses its own URL shortener, so the long URL above would end up being: https://lnkd.in/eJUbqRtt Problem solved, but that’s odd. LinkedIn is okay with a URL that forwards to a domain flagged in VirusTotal. So wait…..what about…

    Workaround 2: A Bitly URL

    If LinkedIn is cool with a redirect, then would they allow a URL shortener like bit.ly?

    Yep! When you buy a bit.ly subscription, you get a new domain registration

    On April 23rd, while still serving our sentence in new URL jail, I registered nagomi.ws and then started creating shortlinks to nagomi.security. It works every time. Here: https://nagomi.ws/youre-so-vain That goes to my LinkedIn profile. This one goes to our super popular credential stuffing blog post https://nagomi.ws/4bjnnga

    The Resolution

    On April 29th, I got the following message:

    24 hours after being cleared by VirusTotal, LinkedIn should drop the warning. Then, on May 20th, I checked VT and we were clear! But we were still being flagged as malicious. I reached out to LinkedIn and let them know that although we were clear in VirusTotal, our links were still getting marked as possible malicious content.

    Then, the next day I got a message:

    I looped in our Trust and Safety and they let me know website link was caught by one of our security vendors but has been cleared since.

    Fixed!

    A highly specific Monopoly card.

    What Did We Learn?

    First, LinkedIn uses VirusTotal to check links and if any vendor on VT says you’re a potential problem, you get flagged. So if you’re emerging from stealth and plan to use LinkedIn, check VirusTotal before launch. It might take a while to get cleared.

    Second, register your domain months before you plan on launching. You can get dinged for a “new domain” even when your domain is hundreds of days old…..

    ….unless

    Unless you want to use a brand new forwarding domain like bit.ly. Not only does that skip the “newly registered domain” issue, it allows you to forward to any domain you want! Which begs the question: does LinkedIn have a suppression list for domains so that if they’re known to be owned by a URL shortening service they skip the VirusTotal check?

    Thirdly, LinkedIn support was very helpful, super responsive, and without their escalation path I don’t think the issue would have resolved itself. It’s not their fault that VT marked us as potentially malicious, and as soon as they saw we were in the clear, they let us out of jail immediately. Kudos to them!

    Fourthly and finalthly – This security research stuff is fun! I’m not going to quit my day job, but I see why people love going down the rabbit hole. And if you’ve made it this far, thanks for reading…and please let me know what I got wrong. I’m sure there are errors. Just not the word “finalthly”. That’s correct.

  • Making the Most of What You Already Have. Why I Joined Nagomi.

    Making the Most of What You Already Have. Why I Joined Nagomi.

    Today we’ve announced that Nagomi Security has emerged from Stealth with $30 million in funding. The company operated in stealth mode with Seed funding from Team8, and the recent round was led by TCV, with participation from CrowdStrike Falcon Fund and Okta Ventures. Nagomi is also backed by leading angel investors, including Shlomo Kramer, co-founder and CEO of Cato Networks, Nir Polak, co-founder and CEO of Exabeam, and Guy Podjarny, Founder of Snyk.

    How I Got Here

    After 6+ years of career-defining work at Axonius, I knew I had to get back to early stage. I am incredibly proud of what we were able to accomplish, the team we built, the product, and I have nothing but great things to say….I mean….I have a tattoo on my arm to prove it. Going from zero to $100 million in ARR is a massive accomplishment, and I can’t say enough about the team that made it happen.

    But it was time. I was always conscious of the fact that – at some point – there would be someone better to run marketing at a certain level of size and scale. Knowing that I love the early, chaotic stage from stealth to $100 million, balanced with knowing that there is someone out there that loves the $100+ million stage, it became clear to me that it was time to move on.

    Start or Join?

    When I made the decision to do something new, I had to choose whether to start something myself or join an existing startup. And I had an idea that was bothering me. Despite all of the tools we have in cybersecurity, how do we know whether they’re actually providing value and working effectively? Other than the binary “did I get breached?” how can we tell whether what we buy is both working and providing value? And in both cases, how do we measure progress?

    I had incredible guidance from investors that thought the problem space was interesting enough to explore. And when I spoke to one investor specifically, he said something like “not only do I love the problem space, I invested in a company a year ago that’s working on exactly that problem. You should talk to them.” So I did. And they were. So I am, too.

    I Buy All This Stuff…….But Is It Working?

    Cybersecurity is hard. You buy a bunch of tools, configure them on day one, and then move on to something else. But threats change, cyber criminals pivot, and tools add functionality over time. But with cybersecurity teams constantly stretched thin, and practitioners underwater with too many threats to possibly investigate it becomes incredibly difficult to ensure that the tools we have at our organizations are configured properly against the real-world threats targeting us.

    What if there were a way to connect all of your security tools to a brain that:

    1. Creates a unique threat profile for your organization – taking industry, geography, size, etc. into account.
    2. Constantly monitors threats, campaigns, and TTPs that are being used in the wild.
    3. Understands that a law firm in the UK is being targeted by different threat groups than a manufacturing plant in Australia, and using different attack vectors.
    4. Looks at your security tools and defenses, and then maps to MITRE ATT&CK to understand where there are gaps, where there are opportunities for improvement, and then gives prescriptive remediation plans to move the needle.

    That’s what Nagomi does. By connecting to the security tools an organization already uses, it then compares that to threats like ransomware and phishing, then gets more granular looking at the specific threat actors and campaigns, analyzing the configuration of the stack, and providing evidence-based suggestions on how to decrease threat exposure.

    How Big Is The Problem?

    Big.

    Much like it was in the early days at Axonius, every person I talk with has the problem. At Axonius I’d ask “how many devices do you have?” and would get either “I don’t know” or “between 10 and 30,000.” Here, when I ask “how do you know whether your security tools are effective against Black Cat ransomware, and do you have any exceptions? What about compensating controls?” I hear “It’s incredibly manual, and we’re trying to figure out how to solve it.”

    One of our customers put it best: “You buy a bunch of tools and have them configured perfectly on day one. But then you move on to other things, a year goes by, and you know that there are either new features or changes that could make your defenses more effective against changing threats. I want to know where my controls are degraded, where I am exposed, and what I can do to close that gap and move the needle.”

    Give It To Me Straight, Doc

    I like an analogy, so here goes:

    So How Do I See It?

    Great question. We just emerged from stealth today, and our awesome new site is nagomi.security – huge thanks to the team at CNP who put up with my aggressive timeline and dumb questions. They really do great work (I’ve worked with them at 3 different companies).

    And if you’ll be at RSA, come see us! You can schedule a time here, or send a message and we’ll find a time to talk!

  • Controlling Complexity: Growth – Featuring Simone Biles and Amy Bream

    Controlling Complexity: Growth – Featuring Simone Biles and Amy Bream

    Today we released the final installment of the Axonius film series with Simone Biles, Controlling Complexity: Growth. This post looks at why we did it, how we evaluated whether it was successful, and what we learned from a 2 year adventure.

    Starting at the End: Today’s Launch

    Today we’re launching the final chapter in our 3 part series with Simone Biles. You can see Controlling Complexity: Growth here.

    No alt text provided for this image
    Click on the thumbnail to watch the video on Axonius.com. Couldn’t get the embed to size right….

    What Were We Trying to Accomplish with the Controlling Complexity Campaign?

    In a word: awareness. When we first started Axonius, we knew that the larger the organization, the more acute the pain they felt around knowing what assets they had, uncovering risk, and automating action. But a few years after launching the first cybersecurity asset management solution, we noticed that smaller organizations were feeling the exact same pain.

    But as a young company, we didn’t have the brand awareness for the masses. In fact, when we did our first aided recall survey only 9% knew who we were. In other words, 91% of our target audience didn’t know Axonius existed.

    Which led us to do two things:

    1 Creating a simple theme to describe our value.

    We could talk about cybersecurity asset management, becoming the system of record for digital infrastructure, and all of the amazing product features we have. But we needed a big theme to hang those from. We needed that big, lofty idea to concisely tease the aspirational value.

    Q: What is the thing that Axonius customers get when they buy our product(s)?

    A: They are able to control complexity.

    Complexity is inevitable. It’s the 2nd law of thermodynamics, and it’s true in our everyday lives. Over time, things get more complex. And that’s what we see at organizations we work with. They add more people, more devices, SaaS applications, cloud instances, and tools to manage and secure them all.

    This fragmentation is what leads to many of the IT and security challenges organizations face today. But if they were able to collect, aggregate, and correlate data from all of the sources that know about assets, they would be able to know what they have, uncover risk, and decide what to do when any asset deviates from their expectations.

    In short: we help organizations control the inevitable complexity they will face as they grow.

    2. Figuring out how to tell the story

    Great. We have a theme that fits. Now what? Well now we needed to figure out how to tell that story.

    Cybersecurity vendors (and tech in general) tend to rely on talking about military-grade features, real-time detection, and lead with FUD. They rarely focus on the people behind the software and hardware. The hacker behind the hoodie.

    We wanted to focus on the human beings that know working in cybersecurity isn’t a fair fight, but they show up every day anyway.

    We wanted to find a public figure that represented the idea behind the campaign. Someone that faced adversity and came out stronger on the other side. Someone that could adapt. Someone that is constantly striving for growth.

    I kept coming back to one name: Simone Biles. Arguably the greatest American athlete of all time, she grew up as a foster kid, and the entire world watched her at the Tokyo Olympics. Imagine competing at the highest level under a worldwide microscope. But Simone is one of the most marketable athletes on earth. Why would she choose to work with a cybersecurity company?

    You don’t get what you don’t ask for. So we asked.

    Meantime, we saw that a video of Amy Bream, a Crossfit athlete born with one leg was going viral. In the video, she’s seen trying to lift a very heavy weight, and fails. She tries again, fails. Tears stream down her face. But she does it again and this time, she nails it. In that video, without any words whatsoever, it encapsulated the spirit of the campaign.

    So we reached out to Amy, too.

    What happened next is truly unbelievable. They both said yes. And in what I will refer to as the “dog that caught the car” scenario, we had to figure out what to do next. What happens to the Marketing team that got what they wished for?

    What Do These Two Athletes Have to Do with Cybersecurity?

    As Chris Cochran and Ron Eddings so perfectly say:

    Cybersecurity professionals are mental athletes with no off-season.

    From an Inc. article covering the initial campaign launch:

    Still, it invites the question, what does a cybersecurity asset management firm aiming to humanize the field have in common with a gymnastics star, even if that star has been hacked?

    Despite the unusual pairing, the answer’s pretty simple: resilience.

    “Throughout our lives, we’ll all share adversity and complexity over the course,” Biles tells Inc. “And the ability to persevere through that is what really makes a strong system.”

    “We both share complexity,” Biles adds. “Even if it’s in our own different worlds, we both go through it.”

    and:

    Biles isn’t the only athlete to connect to Axonius’s campaign. The CrossFit champion Amy Bream, who was born without a right leg, is also involved. Along with Biles, the two will discuss how they each take on complexity in their lives in a video series that’s housed on an Axonius video platform. They will also make appearances on podcasts and in-person events.

    Chapter One: How Amy and Simone Control Complexity

    Our first video with Amy Bream looked at how she focuses on what she can control to overcome adversity.

    Followed by the first commercial with Simone Biles

    Chapter Two: Adaptation

    In the second installment, we wanted to highlight how in the face of enormous complexity, the best not only find ways to adapt to the challenge, they also find ways to give back.

    Giving back is core to what we do at Axonius. In this chapter, we were fortunate enough to be able to give to Friends of the Children – an organization that provides professional mentors to kids in foster care – and the Morgan family. I don’t want to spoil it. You’ll have to watch:

    Chapter Three: Growth

    And now, back to today. We started with the fundamentals of dealing with complexity. We then looked at adapting to challenges. In the final chapter, we finish with the idea that complexity is inevitable, but growth is optional.

    To do this, we wanted to bring in people that work in and adjacent to cybersecurity to tell their stories through the vehicle of a letter written to their younger selves. We then had an informal conversation to explore the common threads between a champion athlete and cybersecurity professionals:

    No alt text provided for this image
    Again, please click the thumbnail to go to the landing page. Sorry. Issues with embedding.

    Oritse Justin Uku, CISSP is an author, veteran, and Business Information Security Officer. I met him years ago at an event in NYC and stayed in touch. His journey from business school to Afghanistan, finance to cybersecurity is fascinating, and I’ve always thought him to be one of the most inspiring people I know.

    Tiffanie Joseph, PSM1 took the leap to put herself through a yearlong cybersecurity program to improve her and her daughter’s life. Her story is evidence that cybersecurity can transform people’s lives.

    John Seaman helped us convince Simone to work with us in the first place. John and his family have been involved in orphan care (adopting & fostering), he’s a long-distance runner, and his motto is to leave people, places, and things better than you found them. A truly great human being.

    Promoting the Growth Chapter: Letter Writing Campaign

    As part of today’s launch, Dean Sysman wrote his own letter to his younger self:

    We’re encouraging people to write their own letters to themselves about a time when you overcame complexities of your own.

    Use hashtag hashtag#DearYoungerMe and please tag Nathan Burke, Dean Sysman and Axonius in your post so we can read your stories!

    Was It Successful? How Do We Know?

    People often say that measuring brand is impossible. You just know the absence of it. I disagree.

    Though not perfect, I evaluate brand investment in two ways:

    1. Aided Recall – If you made it this far, you may remember that at the outset of the campaign we were at 9% aided. 18 months later (before today’s launch) we are now at 27% aided recall. That is a historic leap in such a short time.
    2. Customer and Employee Stories – We are constantly hearing from customers and Axonius employees that they only found out about us because they saw the Simone and Amy content.

    I won’t give any numbers here, but I can confidently say that the investment has been well worth it by any measure.

    Time to Thank People

    Working with Simone, Amy, and everyone involved with this campaign was truly a career highlight for me. I need to thank many people, and I apologize for anyone I’ve missed.

    Kaite Rosa, Karen Dorfzaun, Elizabeth Hartel, Madeleine King, Jeffrey Schleicher, Allen K. and Sky Pak – You transformed a high-level idea into something amazing that you should all be proud of. You accomplished something that is beyond all expectation.

    Dean Sysman – You let us run with a crazy idea that no one has ever done before. Thank you.

    Stephanie Fox, Micheal B., Jennifer Lynch, Austin Holcomb for all the work behind the scenes on the website and social channels to get this out the door.

    Tracey Workman for convincing journalists that this wasn’t a run-of-the-mill vendor stunt, but a story worth telling.

    To our great agency partners Stept Studios for producing and editing the final chapter in the series, and to Ruckus for the first two chapters.

    To Janey Miller, Drew Johnson and the Octagon team for taking a chance on a cybersecurity company who wanted to do something ambitious.

    To Genevieve Jewell Thompson and the Amy Bream team – thank you so much for being a joy to work with.

    To Oritse Justin Uku, CISSP, Tiffanie Joseph, PSM1, John Seaman – thank you for letting us tell your stories.

    To the entire Axonius team, thank you for supporting this project. I am so proud of the work we’ve done and can’t wait to hear what people think.

  • I Am A CMO. I Don’t Buy Anything. A Renewed Case for outreach.txt

    I Am A CMO. I Don’t Buy Anything. A Renewed Case for outreach.txt

    If I get the tone wrong, I’ll sound like an old man yelling at kids to stay off his lawn (hence the photo). If I get it right, it’ll be an examination of “always target the top” when selling. You be the judge.

    I Don’t Buy Anything.

    In November, I’ll hit my 6 year anniversary at Axonius. That’s a long time.

    In the early days, I was CMO, demo-giver, writer, presenter, speaker, mailer of backpacks (Joseph Hoban will remember that), requester of API access, and generally chief pest. And in those days I still bought stuff.

    Fast-forward to today, and we’re a global team with leaders and specialists in nearly every Marketing function. Yet every day I get calls, emails, and LinkedIn messages from people saying some version of:

    “I see you’re the CMO, which means you would be responsible for buying click fraud detection solutions / spam attendee lists from events that haven’t happened yet / marketing automation software / explainer videos / partner portals / branded swag. Can we set up 45 minutes to talk and I’ll send you a pair of AirPods / a bluetooth speaker / an UberEats gift card ?”

    And every time someone gets through by spoofing a local number or creating a well-crafted subject line that makes me think I know them, I respectfully reply with a version of:

    I appreciate the hustle. As someone that runs Marketing at a tech company, I get the game….you have to get meetings in order to generate pipeline. Same. But I have to tell you: I’m not your guy. If you’re selling meetings or events, I have a team for that. Tech to help us automate? MOPS team. Other stuff? Channel, Content, PR, Field/Experiential, Brand…..Am I the guy that approves and says yes at the end? A lot of times, yes. Am I the guy to have a first meeting with? Nope.

    Because to me, two things are incredibly important:

    1. Time – I promise not to waste yours. Even if I agree to get on a demo call, the best case scenario is for me to say “Hmm. Interesting. Go talk to Anna. If she likes it, maybe we’ll do it.” What will NEVER happen is “You’ve convinced me. I’ll buy it and make my team use it. I’ve been down that road before. The best way to piss off your team and guarantee something won’t be adopted is to make them use something because the CMO said so. Even if it’s good. Because…
    2. You must let your leads evaluate what they want to buy. Why bother hiring great people if you’re just going to tell them what to do, how to do it, and what to buy to get them there? We’ve all been micromanaged. It stinks. But there’s a fine line between dictating what your team buys and just letting everyone buy anything they want without being involved. It has to be a balance.

    Being overbearing and making yourself the only person who evaluates and procures vendor solutions? Terrible idea.

    Being totally hands off and telling your team to go buy anything they want? Terrible idea.

    There’s a lot of nuance, integration, and understanding how everything fits together if you want to be both efficient and high performing.

    Does It Make Sense to Always Target The Top?

    I’m not sure it makes sense to always do anything.

    But I think in this case, it sort of depends. And this is where I’d like to hear your thoughts.

    • Are there industries/situations where the CXO always needs to be involved in the initial demo? Maybe. Could be that at smaller companies, that’s the right move. Maybe if you are selling something that the CXO themselves will be using, that’s the only way.
    • Should the person that signs the check be involved at the outset? Sometimes. I know that there are many deals in graveyards because the sales process didn’t include the decision maker. So is there something to be said for including the CXO at the beginning? Probably. But in my case, including me before my team wants to do something isn’t at all useful.

    So Isn’t This Just Personal Preference?

    Fair question. It might be. I’m sure there are CMOs out there that love attending vendor webinars, demos, and want to be involved at the outset. I am not one of them, and can’t understand why anyone would operate like that. I also don’t understand people that like:

    • Pop country
    • Pickles
    • Eating outdoors in the summer
    • 90 Day Fiancee
    • The movie “Death Becomes Her”
    • Clothes shopping
    • White cars
    • Flying from Boston to NYC rather than taking a train

    And about a million other things.

    A long time ago (February 2021) I wrote a similar LinkedIn post: Like robots.txt but for LinkedIn. The idea was to create a way to quickly demonstrate what I’m not at all interested in, what I’m not responsible for, and it would save me AND vendors a lot of wasted time and effort.

    More than two years later, I want to resurrect that idea and update it..this time not just for LinkedIn. Now it’s outreach.txt:

    //Tell Explainer Video Vendors We're Not Interested
    User-agent: Explainer-Video-Vendor
    Disallow: /
    
    //Tell Event Vendors Which Team to Contact
    User-agent: Event-Vendor
    Allow: Connections
    Disallow: /
    Refer: Axonius-Experiential-Team
    
    //Tell Lead List Vendors We Don't Buy Spam Lists
    User-agent: List-Vendor
    Disallow: /
    
    //Tell Martech Vendors Who to Contact
    User-agent: Marketing-Tech-Vendor
    Disallow: /
    Refer: Axonius-Marketing-Ops-Team
    
    //Tell PR/Content Vendors Who to Contact
    User-agent: PR-Content-Vendor
    Allow: Non-Pay-to-Play-Podcast-Requests, Earned-Media
    Disallow: Pay-to-Play-Infomercials
    Refer: Axonius-Content-and-PR-Team
    
    //Tell Webinar Vendors Who to Contact
    User-agent: Webinar-Vendors
    Disallow: /
    Refer: Axonius-Programs-Team
    
    //Tell Meeting Setting Vendors Who to Contact
    User-agent: Meeting-Setting-Vendors
    Disallow: /
    Refer: Axonius-Programs-Team
    
    //Tell Consulting Services Who to Contact
    User-agent: Consulting-Services
    Allow: Connections
    Refer: Kind-of-Depends
    
    //Tell Data Enrichment Vendors Who to Contact
    User-agent: Data-Enrichment-Vendors
    Disallow: /
    Refer: Axonius-Marketing-Ops-Team
    
    //Tell Outsourcing Agencies Who to Contact
    User-agent: Outsourcing-Agencies
    Disallow: /
    
    //Tell Sports Team Patch Sponsorship Vendors Who to Contact
    User-agent: Sports-Team-Patch-Sponsorship-Vendors
    Disallow: /
    
    //Tell OOH Brand Agencies Who to Contact
    User-agent: OOH-Brand-Agencies
    Disallow: /
    Refer: Axonius-Brand-Team
    
    //Tell ABM Vendors Who to Contact
    User-agent: ABM-Vendor
    Disallow: /
    Refer: Axonius-Digital-Team
    
    //Tell Analyst Firm Vendors Who to Contact
    User-agent: Analyst-Firm-Vendor
    Allow: Connections
    Refer: Axonius-Product-Marketing-Team

    If you’ve made it this far, enjoy another AI-generated photo like the header:

    No alt text provided for this image
    A 40+ year old white male yelling at a door-to-door salesman. Salesman looks dejected and embarrassed.

    What do you think? Am I just venting at what’s inevitable? Outreach is always going to be the same despite it – situationally – being a total waste of time. Or is there a case for understanding context and when it makes sense to have a leader of a function involved on the first engagement?

    Or even better….how do we get this outreach.txt thing to become real?

  • Behind the Scenes of a Cybersecurity Unicorn Announcement

    Behind the Scenes of a Cybersecurity Unicorn Announcement

    People tell us that they see Axonius everywhere – and we love hearing that. But a lot has to happen behind the scenes. Here’s a backstage look at what went into our recent news along with some massive thank yous to those that make everything look easy. 

    Plans and Punches to the Face

    There’s a quote I love from Mike Tyson:

     “Everybody has a plan until they get punched in the mouth.”

    Originally, we planned to announce our funding round on March 3rd, but with so many huge funding announcements in the news, we wanted to give ourselves until March 9th. The great and powerful Megan Berry decided we should do a Times Square takeover, so we planned to have the press coverage coincide with billboards on the NASDAQ and Thomson Reuters buildings. We wanted to go big. 

    No alt text provided for this image

    PR strategy is simple: with news like our funding announcement, there are two options:

    1. Exclusive – You pitch one major outlet and let them break the story.
    2. Embargo – You pitch everyone and tell them what time they’re okay to publish the news.

    Going exclusive lets you shoot for a higher-tier publication, but you sacrifice breadth. The embargo route gets you more coverage, but when you’re a young company, that usually means the top-tier publications won’t cover the news. 

    No alt text provided for this image

    Sin Embargo

    None of that matters in this case. Instead, someone leaked our news to a publication that refused to hold the story. On a Sunday. So we had to improvise.

    Great PR is like chess: you have to be strategic and think 3 moves ahead, BUT you also have to react to what’s thrown at you. That Sunday morning, LookLeft (our PR firm) pulled off what should be taught as a case study in rapid response PR. They were able to get a top-tier publication to interview our CEO and Co-founder and the story got massive coverage everywhere. Outstanding work. 

    Let the Professionals Do It

    To share the news with our customers, we wanted to shoot a short video of Dean Sysman. I’m a big fan of DIY video, but there are times when you should call in the pros. TestimonialHero shoots all of our customer videos, and this is what they were able to create for Dean’s announcement

    I simply cannot recommend TestimonialHero enough. Everything they produce is amazing looking, and getting people to feel comfortable while doing something inherently uncomfortable is their superpower. 

    Times Square Takeover

    Although the news of our unicorn status was already out, we decided to move forward with the Times Square billboards anyway. I had some truly terrible ideas for a design. Like, embarrassingly bad. So I consulted with the mighty Kaite Rosa, and like always, the result was something we loved. And then, superstar designer Maddie King created something that was jaw-dropping:

    If we were living in a normal world, we would have invited everyone in the company to be there to see it. My only regret is that we couldn’t have all Axonians together in Times Square to be part of that moment, but that would have been irresponsible. It takes a massive effort from everyone in the company to go from nothing to a $1.2 billion valuation in such a short time, and although only a handful of people could be there to witness it, I hope they feel the same sense of awe. I need to thank Eileen Ann, Linor Shust, and Jacklyn Goldstein for making this all happen safely.

    No alt text provided for this image

    Back to Work – Now What?  

    Instead of our billboards coinciding with our unicorn status, that day we announced that YL Ventures sold its stake in Axonius for $270 million to make room for IPO-focused investors.

    No alt text provided for this image

    The fact that our earliest investor sold its stake in Axonius makes sense all around. YL Ventures is able to focus on what they do best while making room for later-stage investors that have expertise in scaling companies to IPO and beyond. 

    No alt text provided for this image

    So that’s the plan. We want to push ourselves to solve a huge, nagging problem that’s been around for decades and do it with a simple product that our customers love. We want to do that with exceptional employees that aren’t afraid to do really hard things while maintaining standards that are just shy of impossible. 

    So far, so good.