YouSaid · the spoken record

Katie Moussouris

lines on the record
48
first
2017-06-18
most recent
2017-06-18
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. Maybe returning to your first question is why is cybersecurity the wrong term? Because security is not just about what we consider cyber. It's not about your laptop. It's not about your mobile phone. It's about increasing your patient health records. It's about everything you use every day. It's about things that you touch that you want for convenience. And suddenly that all becomes a security threat. So it's not this narrow thing. It's everything we're doing. And that's why we should be worried about that we're not doing enough.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  2. We're all insecurity, basically. This is interesting because it's following the. Arc of evolution of tech. You know, we always say you can't silo the internet division back in the day when there was an internet. Like you can't silo the chief technology offer. You can't silo technology. And now you're saying you just can't silo security. It has to have a seat at the table.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  3. And you have all these other companies now coming to the arena that were in technology companies, manufacturing refrigerators or toys or cars. And now they have to now be responsible for security. So it's completely new for them, right? And in many cases, a lot of these companies don't even have security visions. You can't outsource it. You would never joke and say, I'm not a numbers guy, so I don't really know sort of like what our debt load is.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  4. That's right. And so it may be that in the future, and I think we're actually there now, we're sort of at a tipping point, that we need to find a way of having a disciplined conversation about whether the security risks are too much to say, no, we're not going to go down that path. And we're not going to ask them to do the functionality that we're asking them and we're going to scale back our expectations. The security people have to be in the room when they're trying to think of a new offering and so on. They have to be involved from the start. They can't be given the security as a, here's what we want to do. Now go make it secure. That can't be the way it goes.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  5. There's one other aspect of this which I want to raise. It's not necessarily a board issue. It could be a senior executive leadership issue. But the problem is the following, that we are asking collectively in our computers to do more and more. We want more and more functionality. The only way to do that is to have your systems become more and more complex. Complexity, as everyone knows in the security business, is the enemy of security. And so what we're really trying to do is we're trying to make information technology do things and we don't know whether or not we can do them securely.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  6. Yeah. So the other thing I would add to reporting to board members is there's two things that are important. One is the metric should communicate risk. A lot of the metrics I see are things like the number of attacks. AI don't know what that means. And two is I don't know what the risk of that is, right? What is an attack? What is an event? The other component is can I measure that over time? Board members don't want to pick up a packet and then see a metric that is different from quarter to quarter and cancel you in financial? Exactly. So we want to see trends so that we can ask questions on odd trends. We want to see are we improving or are we not improving and then be able to ask questions in those areas. So I think that's incredibly important and something I don't see a lot of.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  7. Would actually argue something slightly different though because there's something intangible and dangerous and more subtle and pervasive involving cyber trust is a shaky thing. When you have like a specific actor, a person you can pinpoint and see that guy's the asshole who gave our secrets away, you feel okay that you have a scapegoat. When your scapegoat is distributed, nebulous, faceless attacker, that makes reputation management very difficult, I would argue.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  8. Should be, and the challenge is right now, there's no standardized way to report information to the board. So if you look at when I report financial information at my 10K or 10Q, I'm reporting financial metrics in a similar way so that if I'm a board member on multiple boards, I can interpret that data and make sense of it. Each board is getting a different set of data, and it's not always complete. And so one of the things that probably needs to happen in the near future is define on a set standard that ensures that boards are first educated on what cybersecurity is. So they have to be knowledgeable about it, just like they have to know about financials, right? You wouldn't expect the board member to join and have no understanding of financial information. So I think that's incredibly important. You have to link it back to the impact in the organization to make it relevant to the board members so they actually understand there's a risk, but what's my impact? What's the cost?

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  9. I mean, part of the attribution is how do you deter other states from acting against us? How do you respond to them when they've done it? And how do you talk to the American people about what's happened? These are like the sexy high-level cyber issues. The ones that you read about in the newspaper. The boardroom issues are very different. The boardroom issues are how do you have the basic hygiene to stop yourself from being attacked? The equivalent basic advice from a doctor would be, you know, eat less, sleep more, drink less and don't smoke. The cyber conversations that often happen in the situation were more of the fad diet. They're dealing with the most advanced threats to companies right now. And those, frankly, aren't the major threats that most companies need to deal with.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  10. Just this tremendous gulf between what's happening in the situation room and what's happening needs to happen in the boardrooms. Now, if you're in a situation room, the members of the President's National Security Cabinet look around the table and look at each other and wonder who is attacking us? Is it Russia? Is it Iran? Is it North Korea? How do we find that out? And how do we make sure that we're knowing where it's coming from?

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  11. Yeah, when I was at Park, we had a special group dedicated to what was called Usable Security for that very reason because the fundamental breakpoint in any system will always be the human, the error, you know, the psychology of a person and the details related to that.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  12. The other thing I do is they know human behavior. Systems are very different, systems are very complex, but humans are pretty similar. Humans get frustrated. They get impatient. They take shortcuts. They get annoyed.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  13. You ask, how is it that the attackers know the system better than the defenders? The attackers know it because they have to get the details right. That's a must for them to succeed. And you never see the attackers who don't get the details right because they're never in your system. It's only the guys who are in your system that have gotten the details right.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  14. Well, I think it goes back to how distracted a lot of security leadership is. So I'll give you a great example. I was talking to a chief security officer the other day, and they were talking to me about how to protect mobile phones. Meanwhile, when I asked them how many systems they had in their organization, how many endpoints they had, computers and servers and things like that, they had no idea. So that's pretty common.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  15. No, I think actually they're not unpredictable. A lot of them are following the same trend. An attack isn't made up of one action. It's usually made up of multiple actions. And so what you may see is one different action in that attack. And probably 10 or 12 of the steps that you've seen in previous attacks. So in most cases, you're looking to detect those things that are not new in the organization or not new during the attack. And I think that's a reasonable approach. Understand your network better than anyone. Few people realize it's kind of like, you know, know thyself first.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  16. Isn't the very point that we can't always predict they're basically getting the operational machinery in place to be able to know how to respond. But you don't actually know a lot of these threats are completely.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  17. There's a lot of companies that are now doing advanced threat modeling and they're doing something called red teaming where they're bringing individuals in and simulating attacks and practicing their response. And they're actually running through a real attack. They're constantly running simulated attacks and the defenders are practicing their response and they're looking at the results to see how they're improving over time.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  18. You know, I want to pause for a moment because it's actually really interesting what you said about the last war because we're so oriented as human beings on what we already know. We're very bad at seeing the consequences of things that we built that are complex systems that evolve with behaviors that we cannot predict. And I'm even thinking of things like Facebook where you think you're just friendling people and it's social and you're seeing cats. And then actually that becomes a whole new paradigm for all this data that's powering deep learning. So in a way, the very thing you're describing begs the question of what the appropriate response is like do you just only know the appropriate response based on your current toolkit? Like what happens?

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  19. It means that you look back and like, let's prevent the next Pearl Harbor. Well, the next Pearl Harbor doesn't look like what happened. It's a new set of threats. It's coming from an enemy you're not expecting, some kind of direction you don't even think about. And so rather than trying to win what calls yesterday's war, let's think about the new threats.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  20. Can be dead. I think the theme here, too, is we're very reactionary. So it takes certain types of breaches to wake us up to a possibility we all knew about. If you walk through the timeline You go back and start with Google in 2010 when they're the first company to come out and actually talk about Chinese state sponsored actors. This is something the government and a lot of people knew about at the time. And it's the first commercial organization that actually came out and said it and made people aware And we need to take note of that. I mean, there's a phrase historians always use it says we're always fighting the last war.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  21. You go to a physician, your medical records are in a computer. Would it be more concerning to you to have your records published on the internet or to have somebody screw around with the data inside to change your blood type?

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  22. That's right. There are hacks of information. And since information can be duplicated perfectly without your ever knowing it, I can have the information and you can have the information and you won't know it until I use this for somehow in some way that's bad for you. And attacks on compromises of integrity are changing the data or the program or deleting it or somehow affecting the actual bits that are there. Attacks on integrity mean that you've actually changed the data or zeroed it out or something like that. Malware can be used to do any one of those things, or all of them. It's the generic tool that it's a computer program, loosely speaking, that will create compromises in any of those attributes.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  23. Specialists usually differentiate between three different attributes that you want to defend. Ironically, the acronym is CIA, right? Confidentiality, integrity, and availability. A DDoS attack is an attack on availability. That is, it means that your system is no longer available to do the things it's supposed to do for the people who are supposed to be able to use them. Violation of confidentiality means I steal your credit card numbers. You still have a credit card in your hand. It's not like a dollar bill. I take a dollar bill from you. You don't have it anymore.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  24. And lately, we've been seeing more of the DDoS attacks in the news earlier point about the smaller gradations and the annoyance cases. You see a ton of DDoS attacks when they're like personal vendettas against like a gruntled employee leaving a company or something. It could be anything.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  25. It did have physical consequences. It was certainly not by any means the first time. I'll tell you a very embarrassing story. The first time I was interviewed about Beth Stuxnet, the person said, and what do you think the impact of Stuxnet is going to be? And my answer was nothing. There was going to be no impact out of it at all because every computer person knew that it was possible and this was nothing new. I was totally wrong about that because what it did was it woke states up policymakers up to the possibility that this was a possible feasible thing to do. It may have been the first documented instance of a large-scale attack on something physical that people noticed. But certainly there have been people who have caused physical damage by computers before.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  26. My friend Kim Zetter wrote the definitive book on Stuxnet. And that was, by the way, the first case ever that we know of where, at least the way I heard it, where computer malware had a physical consequence because it took down a nuclear facility.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  27. Isn't certainly not surprising to any technical person. There had been other smaller IoT based attacks on stuff, but yet it got all this attention. And people said, hey, it woke people up. Seven years ago, when Stuxnet hit the news, Stuxnet was the alleged American and Israeli cyber attack against the nuclear facilities, enrichment facilities in Iran.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  28. But no, it's the party that's responsible for the botnet and may not even be a single individual. But anyway, what was newsworthy about it was that it caused a bunch of consumer-facing websites that relied on this infrastructure to be inaccessible to you and me. And what's interesting about it is that we've been predicting this, we've known that this was possible for a very long time.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  29. And you just ignore it recently, and we heard about an attack on the domain name system infrastructure against a company called Dyne. What was newsworthy about it was that it was a large distributed denial of service attack that was largely caused by compromised Internet of Things devices.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  30. So, if something's really hard to use and people aren't going to use it, this is how it is. Most people look at the cyber training video, like they do the airline safety video when you board your flight. And you're like, well, I fly 1,000 miles a year. I know there's an airbath. I know there are window seat, and you just ignore it.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  31. And for most organizations, the attribution doesn't matter for the government, it absolutely matters. But as a corporation, what will you be able to do? You're not going to be able to hack back that country. The reason why attribution matters in the situation room is Russia trying to influence United States elections. Is this an act of war? Like the questions that happen in this situation room need to be these big questions about how cyber relates to our entire national security. When you're in the boardroom, maybe the first question you'd be asking is, have you trained your employees about how to address the most common cyber threats?

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  32. It's interesting you say that because attribution is hard. At a certain point, like you can have all these people claim one thing or another and then other people actually have theories about what happens. But at the end of the day, there's politics in the attribution, active attribution itself. It almost matters to focus to your point on like trying to prevent and solve and address.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  33. Right. And so we did all these break ins, right? And I realized how easy it was. And we switched over eventually about six years ago when I started doing investigations because it was much more difficult to actually find an attacker and trace it back than it was to actually break it. And so I went sort of the opposite side since I had that knowledge and methodology. And what I found over time is not much has really changed. And it's because we continue to focus on the things that are sexy, right? It's these things like hygiene that are the issue. The basic solutions are things like better security for a IoT devices, network segmentation, preventing things being accessible from the internet. These are not complex topics. And that's what I've tended to see over time. You get into these boardrooms and the topics are overly complex. Like security is a very complex topic. Board members are very high level. They're simply really interested in things that are in the news. So if you look at things like China and Russia that don't impact most organizations, they want to know who's attacking and where they're from, what they're doing. And to be honest with you, that's not something that's typically helpful.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  34. Not to minimize the seriousness of that, but one of my absolute favorite movies of all time is Sneakers. Their job is to be like the penetration testers and they actually get enlisted by the NSA to break into someone and it actually turned out not to be the NSA. But anyway.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  35. I'll be honest with you, I was not very good, but within about a week or less, I think my best was about two hours we were able to break into some of the most secure locations in the world physically and based on information technology. Not

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  36. The other thing that strikes me is a big difference between, for example, nuclear and cyber, which is a big deal, is that you need the materials, you need enriched uranium and plutonium to build a nuclear weapon. Cyber weapons are basically knowledge.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  37. Ransomware or even something like a lot of the bank heist that we've seen. One of the first cases I ever worked on back in 2010 was a bank that lost about $10 million overnight. It's a gang of criminals who were loosely affiliated with each other, who had a reasonable set of skills from their computer science degrees, from their experience in education in college, who had combined with some individuals with banking knowledge. And overnight were able to steal $10 million in a very sophisticated way. And again, not associated with the nation state, not associated with tremendous amount of resources.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  38. An opportunity. And isn't this part of the reason why some of the best and worst attacks come out of Russia? Because you have a lot of code savvy kids who are very competent but who don't have a lot of economic options like to be in jobs.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  39. There's no legitimate use for private citizens to have nuclear weapons. This is a type of weapon which is held by states who have the monopoly over the use of force. Cyber weapons are totally different. We want for growing economy people within our country to be great hackers, to come up with technological innovations, to have that power in their hands and the same power that they have to create the innovation we want can be enormously destructive. And as the government worries about that, it's really hard because you think about cyber as a threat on the one hand, but the other economic.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  40. Exactly. And so the tendency here is that cyber weapons are weapons that are eminently usable for a variety of purposes. And one of the most interesting things in the past 10 years is that nations are starting to wake up to this. They're starting to see that these weapons are enormously usable.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  41. Yeah, you're right. I mean, these different gradations, I'm even seeing people use them as a form of expression, even doing something like doxing or denial of service attacks, just single company because they're annoyed or even like a form of protest. Some people consider this like the modern equivalent of just spray painting on a wall, but it has enormous financial and other consequences. So it's kind of interesting actually to think about that because you would never have done that with a nuclear weapon, obviously. Exactly.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  42. Yes, there has been a trend away from weapons that have a very large boom to weapons that have a much smaller boom. And there's a sense in which cyber weapons can do something, just do an annoyance to somebody, to something that might destroy the entire system or systems to which this computer is connected. And I can do anything in between.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  43. Historically, with the development of weapons technology, there was a period where we were trying to make more and more powerful weapons. So we got bigger and bigger bombs and so on. But nobody uses nuclear weapons.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  44. Cyberspace security. But I think conceptualizing it to me of cybersecurity in the same sense, that's the cyber plays the same role that the word national plays in national security, that puts a whole different spin on it for me.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  45. Cybersecurity are those things that are taken to defend and protect the computer system or the information inside it. Notice that it's a completely defensive orientation. If you put the space in between cyber and security, cyber space security, you start thinking about it's now it's the security of the cyberspace, of the cyber domain, which is a very different thing. If you think about the term national security, nobody leaves the space out. Two words, not one word. And if you start thinking about the security of the nation, that gives you a whole different perspective on it. It's all of the things that you might want to think about in terms of what would make a nation more secure. And so depending on the context, I'll use a space or not the space. But of course, in giving talks, you can't make that distinction. You could actually do the air quality.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  46. Start with the word cybersecurity as one word cybersecurity, no space in between them. It matters because the Oxford English Dictionary has, which I regard as the authoritative source on the English language, has taken over the term.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  47. You prefer? That's a good question, actually. What is the alternative? This is like that word synergy where it's like a really useful word, but everyone hates it, and there's no better alternative. I guess just security.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source

  48. Hi, everyone. Welcome to the A6 and Z podcast. I am Sonal. Today we're continuing our taking the cyber out of cybersecurity series with Herb Lynn, who's senior research scholar for cyber policy and security at the Center for International Security and Cooperation, and is also at the Hoover Institution, which are both at Stanford University. We have David D'Amato, Chief Security Officer at Tenium, and ASICSNZ Policy Team Partner Matt Spence, who among other things previously spent time at the White House working with the National Security Council. The hallway style discussion ends up focusing on practical advice for changing the conversation about security in the boardroom as opposed to the situation room. And we begin with considering the term cybersecurity and the very first voice you'll hear really briefly is David, followed by herblin. By the way, for a quick second, can I just say how annoying a term cyber security is? I feel like only policy people actually say cyber and people trying to get research.

    2017-06-18 · a16z Podcast · a16z Podcast: Cybersecurity in the Boardroom vs. the Situation Room · IDENTIFIED FROM THE TRANSCRIPT · source