Episode #
10

Security, AI Adoption, and Human Judgment with Patrick McKinney

Episode Description

Patrick McKinney, VP of Security at Invisible Technologies, has spent his career building security and compliance functions from the ground up, from Coinbase to Dropbox to Salesforce. He shares the playbook lessons that carried across each stop, why phase two never adds security, and how he's applying an AI native approach to security at Invisible while still keeping judgment and accountability firmly in human hands.

Main Topics Covered:

  • Building compliance functions from scratch at Coinbase, Dropbox, and Salesforce, and the lesson that phase two never adds security
  • Standing up SOX and GDPR compliance ahead of Dropbox's 2018 IPO
  • Early FedRAMP work at Salesforce, including a dedicated authorized colo built entirely from scratch
  • Investing in an agentic SOC platform and running quality bake offs before adopting new AI security tools
  • Knowing when to shift security ownership from a CTO or head of IT to a dedicated security professional
  • How AI is reshaping entry level talent, and why judgment and accountability still belong to humans

Links & Resources

Transcript

00:00:08 - 00:00:31 Stephen Koza
A crypto exchange, a file sharing giant, a big enterprise software company that was trying to figure out FedRAMP. My guest today has stood up the first version of a security or compliance program at all three. And then he went somewhere to work where the product itself is AI automation. His playbook was not the same. It didn't survive all the stops.

00:00:31 - 00:00:55 Stephen Koza
But what he kept is probably not what you would expect. Welcome to TechPod talks. This is Stephen Koza. We do candid conversations with the leaders who are building what's next. Every episode we bring in a practitioner, somebody who's actually in the arena to share what's happening behind the scenes, and platform engineering, DevOps, cloud leadership, security. And my guest today is just that kind of person.

00:00:55 - 00:01:30 Stephen Koza
Today I've got Patrick McKinney. He's the vice president of security at Invisible Technologies. Patrick spent pretty much his whole career building security and compliance functions from the ground up. He built the first line of defense compliance engineering team at Coinbase. He was a founding member of Dropbox's risk and governance team. He stood up the first Socks and GDPR programs there, and he was also the first technical program manager at Salesforce, worked in San Francisco and Dublin, where he helped them earn FedRAMP.

00:01:30 - 00:01:54 Stephen Koza
It invisible today, he's built a security program that leans pretty hard on AI native tooling and SoC platforms, encrypted AI analytics. And he ties security spend directly back to revenue and retention and sales enablement, which is pretty cool. Outside of work, you'll find him in the backyard cooking and barbecuing, and I definitely want to talk about that. So hey Patrick, welcome to TechPod Talks.

00:01:54 - 00:01:57 Patrick McKinney
Hey, Stephen. Great to be here.

00:01:57 - 00:02:02 Stephen Koza
Before we get into it, what's what's your favorite thing to barbecue on?

00:02:02 - 00:02:12 Patrick McKinney
Man I'm a big beef ribs guy. I think you know, big dino beef ribs. Everybody likes the presentation. The big bone, the soft, you know, juicy, smoky meat. Nobody ever complains about those.

00:02:12 - 00:02:20 Stephen Koza
Nice. And what do you like to cook them on? You. You charcoal guy, a Traeger guy. You got your own set up?

00:02:20 - 00:02:38 Patrick McKinney
I actually did buy a custom smoker. It's an offset wood smoker by a local guy out here in Vegas. He makes them as a hobby. And then I bought a quart of of Hickory from from Oklahoma that got shipped it out here. So I take my barbecue seriously and I feed usually between 15 and 20 people. And I when I fire that guy up.

00:02:38 - 00:02:46 Stephen Koza
Yeah, I can tell. Yeah. Anybody that's serious about it usually graduates to something like that. I have not yet, but maybe you can give me some tips later.

00:02:46 - 00:02:47 Patrick McKinney
We'll get you out here.

00:02:47 - 00:03:11 Stephen Koza
Yeah, I love it, man. Well, let's get into it, man. You've got a really cool background. Bunch of brand name companies. And, you know, I seems like you joined some of those, you know, in the earlier days when you had to build stuff that didn't doesn't exist. Let's start with Coinbase. So I know there you you helped build their first line of defense compliance engineering team.

00:03:11 - 00:03:19 Stephen Koza
What the heck is that. What did that mean? What did what did it look like on on day one where nothing was established?

00:03:19 - 00:03:37 Patrick McKinney
Yeah. So that is a mouthful. You kind of call it I think people call compliance engineering now, but it's essentially when I came into Coinbase, a person we both know, Alex Brown, basically called me and hired me and said, hey, listen, I'm leading it over here and I just want somebody to handle the security and compliance for it.

00:03:37 - 00:03:59 Patrick McKinney
And I said, I got you. And as soon as I came over there, it was it was pretty blatant that everybody was moving fast and building things. And when you're moving fast, you're building things. You don't tend to bake compliance controls into the systems you're building, the processes you're building. Everything was changing. They were maturing rapidly. And so myself and a small well, it was just me to start.

00:03:59 - 00:04:17 Patrick McKinney
And then it became me. And two others essentially made it to where every time something new was being built, we took the compliance controls into place. We either consulted on the on the applications or platforms being built and we would say, hey, you should do this, this and this to make sure we abide by all the controls we're doing.

00:04:17 - 00:04:34 Patrick McKinney
Then anything that couldn't be built in or just was too clunky and it wasn't working. We would handle some manual processes and work their way towards automation. So it was it was a very step by step process to get this going. And we eventually turned into a into a program that encompassed all of security, all of it, and all of engineering at Coinbase.

00:04:34 - 00:04:41 Stephen Koza
Oh nice. Nice. I imagine given the nature of the business, your your role and function was pretty important.

00:04:41 - 00:04:56 Patrick McKinney
It was it was yeah. We we spent about I spent about four and a half years there and had a lot of successes, a lot of wins. But you could see it as it organically spread out across the company from people just saying, hey, you know, Patrick's team is doing a great job here. Patrick team's doing a great job here.

00:04:56 - 00:05:08 Patrick McKinney
Eventually we would get asked for help and that would just, you know, mature the program. So it became a rather large team before before my exit there. But yeah, it was it was very, very helpful for the business and still talk about those times today with some of the Coinbase alumnus.

00:05:08 - 00:05:27 Stephen Koza
Yeah I but yeah, I know they're appropriately pretty security conscious. Was there anything unique about working there at a fintech that's different when it comes to security versus, you know, CRM company, file sharing company, AI enablement company?

00:05:27 - 00:05:47 Patrick McKinney
Yeah, I mean, off the bat, I mean, as expected, like the regulations are different. You're dealing with different regulatory bodies. You're dealing with the NYSE, you're dealing with, you know, high trust and all these different compliance regulations. And you don't have to have at a file sharing company or CRM company. And so with that just comes extra scrutiny, extra controls that you want to bake in and scale across the business.

00:05:47 - 00:06:16 Patrick McKinney
So that was kind of the major difference. But then the other not on the surface level that you see is just coming into that company. Even when I came in in 2018, just the maturity of that security program that Philip Martin led was incredible. And he expected that security maturity across the entire company. So it was it was a breath of fresh air coming into a place that took it seriously across the board, which made my job easier, but also at the same time, made it, made it something we had to live up to.

00:06:16 - 00:06:23 Stephen Koza
Yeah, sure. Any any lessons learned or things that you got out of that experience that you you took forward to other roles?

00:06:23 - 00:06:42 Patrick McKinney
I think, yeah. Focusing on security and compliance as part of the as part of the design process before you start building does make things a lot easier as you move forward. You know, you don't have to sit there and and retrofit security because a good buddy of mine made a made a very famous quote that I've kept with me.

00:06:42 - 00:06:46 Patrick McKinney
It's like phase two, never add security. So always do it in phase one.

00:06:46 - 00:07:14 Stephen Koza
Oh yeah, that makes a ton of sense. Intuitive, but maybe. Maybe not. Not always practiced. Let's let's keep going through the LinkedIn. I love hearing about the variety. So I know you spent some time at Dropbox and you kicked off the risk and governance team. I threw out some fancy acronyms earlier Sox compliance, GDPR, stuff that people are probably familiar with.

00:07:14 - 00:07:24 Stephen Koza
Or maybe give them a little PTSD. Like, tell me about that. What? Like what was it like building that function? What do you guys tackle? What were you focused on?

00:07:24 - 00:07:50 Patrick McKinney
Yeah. So this is another example where, I mean, I came in as the first security TPM at Dropbox, where I focus on the traditional functions infra production, security, detection, response and helping those teams kind of get organized, talk to the engineering teams better. And then when it came time for Dropbox to go public, which was early 2018, there was another kind of I don't call it disconnect, but there was just a bridge that needed to be built between engineering and compliance.

00:07:50 - 00:08:10 Patrick McKinney
And so similar to my time at Coinbase spinning that are already knowing the playbook, that point. This is what I learned the playbook. And it was spinning up a very small team that reported actually into the IT team and rather than the security team, but it took those compliance principles that needed to be engineered into the product or, you know, automation processes built between teams.

00:08:10 - 00:08:27 Patrick McKinney
And we basically identified those and worked on automating those. And through that, it incorporated, you know, that was when GDPR was becoming very, very big. That was when obviously first year SoCs for any company that goes IPO is going to need some help. And addressing those new controls they hadn't focused on before. So that's what the program really focused on.

00:08:27 - 00:08:39 Patrick McKinney
And it was it was great to be able to see kind of a head into when compliance during wasn't a thing at that point, but kind of building those first processes that would eventually become that for the company. And the function is still going on there today.

00:08:39 - 00:09:05 Stephen Koza
I know when you're if you're a company and you're gearing up for an IPO, things have to be tight. Your financial controls have to be tight. Security has got to be tight. You know, you're all of a sudden invite a lot of scrutiny that you didn't have before. Like how do you approach that? And then given the scale of the company at the time, how do you get all the stakeholders on the same page, the auditing team, partners, engineering teams?

00:09:05 - 00:09:07 Stephen Koza
What? How do you approach that kind of stuff?

00:09:07 - 00:09:26 Patrick McKinney
Well, luckily, I think I think most teams at that point new like Sox is going to be absolutely important. I think. I don't think people really understood the gravity of GDPR yet. So we took a couple avenues. One, I mean, as as most companies do, we did bring in an outside consulting firm to help us get ready for Sox compliance.

00:09:26 - 00:09:44 Patrick McKinney
We also run a separate outside company to help us get GDPR ready. And they both came with, hey. These are the risks. These are the trade offs. You have to do these. These are potential fines. You know, all that sort of stuff. So getting everybody aligned and informed first on what could possibly happen if we don't do this.

00:09:44 - 00:10:01 Patrick McKinney
And then it made it very clear that we have to do this and we have to do it the right way, because if you don't do it the right way, it doesn't scale. And if it doesn't scale, obviously things can break or go haywire. So it was it was more of an informed inform the teams, get them on the same baseline level of understanding of what we have to do, and then move forward and do it.

00:10:01 - 00:10:09 Patrick McKinney
And if anybody was it really aligned, then you obviously escalated to the exact. But luckily everybody that worked there was pretty intelligent. So as soon as you told them why we need to do it, they were like, okay, let's go.

00:10:09 - 00:10:31 Stephen Koza
Yeah. I for for people who aren't familiar with this, when you file for IPO, you file this thing called an S-1 and basically like, say everything about everything there is to say at the company, including all the risks and the gaps and the deficiencies. So I imagine, you know, you had a spotlight on you probably like, what was that pressure like?

00:10:31 - 00:10:37 Stephen Koza
And what was the was the timeline for making sure you guys were going to be in a good spot for that?

00:10:37 - 00:10:55 Patrick McKinney
Yeah. With Sox compliance, you the the way it works is. Yeah. You do file your S-1 and then when you officially list you have or when you officially go public, you know, your stock launches that day, you basically get a year from your launch until your first Sox audit. So you do have a year post long post IPO to actually become Sox compliant.

00:10:55 - 00:11:14 Patrick McKinney
And we knew going up into the IPO that we had to do this. So we had a year plus to get ready. But there's a lot to do. I mean, there's a reason they give you that much time to get ready. There's a lot to do. And so it definitely took a team, a pretty large team, including those outside consulting firms, to help us out and get ready for it.

00:11:14 - 00:11:33 Patrick McKinney
I mean, it was my first time pre-IPO going IPO. I had worked at Salesforce prior, which is already public. So Sox compliance with something that I'd already worked on. But once you go through it and once you get through the first year, it does become a little bit easier. You kind of follow the same playbook. You learn from the mistakes, any little small things.

00:11:33 - 00:11:44 Patrick McKinney
The auditors mentioned that you could could use improvement on, you just improve upon. So the pressure was there, but it luckily, like I said, everybody Dropbox is really talented. So we got we got through it pretty easily.

00:11:44 - 00:11:52 Stephen Koza
Yeah. Nice. Nice. You mentioned Salesforce. Tell us about that. What did you do for Salesforce. And you spent some time out of the country as well right.

00:11:52 - 00:12:12 Patrick McKinney
Yeah. So I did a I actually did a variety of things for the security security org over there at Salesforce. I worked there for almost four years going back to 2012. And when I was first hired, I was I was doing actually working on their R&D side, which is very interesting. That didn't last too long before I moved into the security side.

00:12:12 - 00:12:32 Patrick McKinney
And the first thing that I did was was like you mentioned earlier, is the FedRAMP program. This is back in. You know, 20, 2013 getting fed ramp ready. This is before any of the really great MSPs that are out there now, any of the acceleration programs. So this was flying from San Francisco to meet with their sponsors, the Health and Human Services organization.

00:12:32 - 00:12:53 Patrick McKinney
We flew monthly from San Francisco to Washington, D.C. they weren't big on video conferencing. They weren't big on all that. So it was it was a hassle. And with and with the way Salesforce did is they actually had a physical colo. That was what they called a super pod back then. That was actually FedRAMP authorized. So they built everything the edge network, the servers, everything.

00:12:53 - 00:13:09 Patrick McKinney
Like it wasn't one of those where you could just go deploy your application in a hosted MSP and get get certified. Now it was we have to do everything from scratch. And we had a really great leader back then who she was running the program. Her name was Laura and had a good team of people that are now.

00:13:09 - 00:13:27 Patrick McKinney
I mean, I actually look at that team. It's very interesting because three of those people are now CISOs at other companies. You know, Laura's got her own company. I'm over here running security, other companies. So you have you had these future heads of security and future heads of compliance that were all in one team making this work back then when everything was a little more hazy.

00:13:27 - 00:13:37 Patrick McKinney
But that was a really fun program. I learned a lot. There were some definitely some battle scars. I mean, it was it was a year and a half program of traveling every month. But it was it was really, really great.

00:13:37 - 00:13:53 Stephen Koza
So if you think about the experiences at the companies and roles, we've talked about any common threads, like what were the lessons learned? What did you take away? What what what worked at one place didn't work at another? Connect the dots for us a little bit.

00:13:53 - 00:14:12 Patrick McKinney
I mean, definitely the dot that followed me everywhere is is think security early. And obviously, you know, my career spanned almost 20 years at this point. And there are definitely areas of my career where it it felt like we were thinking about security early on, and there were definitely areas where we're not thinking about security and it was necessary, a linear progression.

00:14:12 - 00:14:36 Patrick McKinney
It could, you know, I started my career in the public sector. I worked for the CIA, I worked for Disa. Obviously they think about security very, very heavily. And then after that, going into the private sector, you had companies that may or may not have invested as much they as they should or as they wanted to due to various reasons and continuous thought of think of security early is definitely something that stuck with me the entire way, and some other things that I learned.

00:14:36 - 00:14:55 Patrick McKinney
Lessons learned is bad news doesn't get better with time, so make sure that if something isn't going to work or if something is going to be a problem, you you escalate that early. And obviously, you know, with all the supporting metrics and all the supporting details. So you're not just kind of crying wolf, but make sure that you do surface these risks early.

00:14:55 - 00:15:08 Patrick McKinney
I mean, I still practice that today at invisible. I, you know, we have monthly risk meetings within the security team with my CTO all the way up to the chief legal officer. And we and we surface these risks well before they become actual issues.

00:15:08 - 00:15:34 Stephen Koza
Yeah, I feel like that's pretty good leadership advice. Regardless, regardless of your domain, you don't want to sit on stuff and hide it. There's there's not a lot of value in that. Well, let's jump into AI because it's obviously a fun topic these days. And yeah, I know you guys are doing a ton here, and people probably love to learn about how you're thinking of it and the types of investments you're you're making.

00:15:34 - 00:15:56 Stephen Koza
I know one of those is an agent SOC platform. So tell us a little bit about that. I think you told me the problem with the problem with people's adoption of AI today is because it's new. You know, companies are chasing a lot of different things, and sometimes there's disorganization and sometimes they're not picking the right use cases.

00:15:56 - 00:16:12 Stephen Koza
And so the general narrative is, you know, enterprises are not getting positive ROI. It's a lot of token spend without any value to match. And I think you would disagree with where you guys have invested. So so tell us about that. Maybe start with the SOC platform.

00:16:12 - 00:16:30 Patrick McKinney
Yeah, absolutely. You're exactly right. We've calculated where we want to invest AI, and not just from a cost perspective, but also I think if you talk to most security professionals, they're they're naturally kind of risk averse. And so a lot of people are looking at quality control. How do you how do you ensure you're getting the returns on the data, the information that you're getting?

00:16:30 - 00:16:51 Patrick McKinney
How are we sure that. That's right. You know, but yeah, the SOC was actually one of the first things we adopted at invisible. I'm actually giving a talk with my vendor ex-offenders at Blackhat. So if any folks are there, they can attend that talk. But really what we were looking at is what what benefits do we get from an agent SOC?

00:16:51 - 00:17:07 Patrick McKinney
What are the quality controls? What are the what are the risks? How do we avoid them? And so I actually took a two pronged approach to the agenda. SOC is not just bringing in a platform that we could send all of our logs to, and actually use AI to parse them faster than what a traditional detection and response team would do.

00:17:07 - 00:17:31 Patrick McKinney
But I also invested in the part the human element of of force. They do have a human detection, managed detection and response area so that they can monitor the platform even while AI is doing its thing. And really what it came down to was cost. You're exactly right. And it start with cost. What it cost for us to bring that in was about one fifth of what it would cost to stand up our own 20 473 65 SOC team.

00:17:31 - 00:17:50 Patrick McKinney
I think you're getting a lot of the tools and the people elements kind of built in together, similar to when people bring EverOps on and you get a pot of people, you're getting that shared services kind of mentality. You are getting experts in their domain and they're working in a smarter, not harder sense to serve the customer.

00:17:50 - 00:18:07 Patrick McKinney
So that's that was the reason that I brought excellence into invisible was really like there was the human side, there was the AI side. They were both showing results. We did do quality control test. We still performed quality control test quarterly to make sure that whatever the AI is returning is the same thing we're seeing in the primary system, in the logs and that sort of stuff.

00:18:07 - 00:18:25 Stephen Koza
Yeah, that makes a ton of sense because AI is obviously good at a lot of things, but it's not right 100% of the time. And we all know that. And unfortunately, it was security. You kind of got to be right 100% of the time. So there's the judgment layer that you still need. And you know, there's a role for humans.

00:18:25 - 00:18:48 Stephen Koza
And because of that. And so I didn't ask you, but you know, to me that's kind of like the perfect example of that, of that point. Tell me about how like when you're when you're making AI investments and you've got these great tools that are now available, how how do you think about mapping them to how your teams actually work today?

00:18:48 - 00:19:11 Stephen Koza
What needs to change? What's the difference between the old model and the new model, and how do you adapt to that? Because we see that as a failure point and we're you know, we're not we're not geniuses. You know, that's kind of commonly understood now that you can't just bolt AI on and keep every single one of your business processes the same people need to start working differently and you reorganize and, you know, maybe you don't need all the process.

00:19:11 - 00:19:14 Stephen Koza
So tell us about that. What's what showed up in your org?

00:19:14 - 00:19:32 Patrick McKinney
Yeah. So some of the things that we've we, we went with early on were like we wanted to build the team lean organically. I wasn't I wasn't able to hire, you know, 15 people at once or 20 people at once. So as people would come in for different functions, you know, infosec apps, cloud sac, all that sort of stuff, detection, response fraud.

00:19:32 - 00:19:58 Patrick McKinney
I would have those people work with me and we would we would basically build the what, what the function should look like. Where are the processes that are repeatable? What are the ones that we could trust to AI if the AI was quality and which ones would always need human oversight? And where does that human oversight look? A quick example is, you know, you got a lot of these tools out now that will for apps side that will the they'll find the vulnerability and they'll cut a PR to fix the vulnerability.

00:19:58 - 00:20:18 Patrick McKinney
Well we still want human oversight of that PR to make sure it doesn't break something just outside of fixing the vulnerability. So and I believe that AI should be supercharging humans, not necessarily just replacing jobs 1 to 1. So as I would hire out the team, lean organically, you know, meeting, meeting the needs of the business while also not over hiring.

00:20:18 - 00:20:37 Patrick McKinney
We would look to some of this tooling that's coming out now, a lot of the newer stuff, series A, series B, companies that are building really impressive things, we would absolutely, you know, look for competitors, do a proper bake off and find out during that bake off which AI is bringing back quality results. You know, if you ask, you know, ChatGPT the same question ten times, you're not going to get ten of the same answer.

00:20:37 - 00:20:53 Patrick McKinney
And that's a big, you know, multibillion dollar company. So what makes a series A, series B company implementing AI any better. So we would just do the quality checks and and we would just know to make sure that, you know, if there were any weaknesses to take into account and didn't necessarily rule the tool out, it just means that you'd have taken into account.

00:20:53 - 00:21:17 Patrick McKinney
So that's kind of the way that I look at AI being bringing into security right now is let's supercharge the people we have. Let's let's automate and use AI to enhance routine processes or repeatable processes. AI allows you to kind of automate more complicated and complex processes than what we used to just be able to automate and move forward from there and find out there's always something new in, something extra to take on when it comes to security.

00:21:17 - 00:21:22 Patrick McKinney
So let's let's try and knock out the stuff that's known and solvable fast via AI and automation.

00:21:22 - 00:21:49 Stephen Koza
Yeah. You know, we've all heard the job loss narrative around AI. And, you know, I've told people six months ago I wasn't so sure, you know, because there's smart people on either side of that argument. And both arguments were pretty compelling. Now I'm way more convinced what you're saying is accurate. Like, I heard a figure the other day that, you know, maybe AI can tackle 60% of work just to put a number on it.

00:21:49 - 00:22:12 Stephen Koza
And that's like maybe 60% of somebody's job or 60% of certain kinds of tasks. And so the question is like, what do you do with that other 40%? It's like, well, the other 40, like the other 40% is still the human, but now they've got 60% more in their day to do a better job of that, or do higher value stuff, or be more productive or deliver more value.

00:22:12 - 00:22:28 Stephen Koza
And to me, that's pretty cool. And I think that point of view is probably correct. I think the job loss stuff was probably a little overblown, and even the some of the AI luminaries have started to kind of soften their tone on that. So I like the way you said it. I agree with that point of view for sure.

00:22:29 - 00:22:54 Patrick McKinney
Well, I think too, when you combine a lot of I mean, I'm sure people have seen the articles that now with with token costs, AI is becoming more expensive than humans. So it's like now we got to hire some humans back because it's cost effective and I get that side of it. But I also, you know, AI can't future I mean it can model but it can't really see the future can't predict the same way the human brains do because it's being trained on data that's here and before.

00:22:54 - 00:23:16 Patrick McKinney
So it can't accurately forecast. And I think humans can't accurately forecast for the most part. I mean, look at most weather channels. But at the same time, I think, you know, the human the human element that needs to be in security teams, engineering teams is, you know, because with with security, it's definitely obviously with engineering teams, its resiliency, it's making sure that things are up and running.

00:23:16 - 00:23:28 Patrick McKinney
Is that forecasting that foresight if something that humans are still doing better than AI for the most part. And I think that's where that extra 40% really, really goes. Like what's the next thing? What's the next thing? What's the next thing?

00:23:28 - 00:23:42 Stephen Koza
Yeah, I always, always, you know, refer to the judgment layer, which is, you know, AI is going to give you an answer or several different and conflicting answers depending on what you give it and how you ask the question and what model you're using.

00:23:42 - 00:23:46 Patrick McKinney
The answer. It's always going to be a zero EQ high IQ answer. Yeah.

00:23:46 - 00:24:10 Stephen Koza
Yeah, totally. So so there's that. And then there's also this, this like relationship element where, you know, if you're in a leadership role, you know, you have kind of natural intuition around how the company works and what your customers are telling you. And you know, your X number of years of experience and like being able to connect the dots on that, like AI is just never going to be able to do it.

00:24:10 - 00:24:38 Stephen Koza
Well, never say never, but AI doesn't quite do it in the same way. And then on top of all that, like somebody has to make a decision eventually, like there's a vulnerability. You know, are we going to address it or not? Or there's a trade off here, or are we going to pick A or B? And I don't think Wall Street is going to let AI start making those, you know, judgment based decision calls anytime soon because then there's nobody to hold accountable.

00:24:38 - 00:24:49 Stephen Koza
And so like there's just so much to it. Once you start peeling back the onion that you realize, well, you know, it's an amazing set of tools to solve a lot of problems and automate things and drive efficiency.

00:24:49 - 00:25:05 Patrick McKinney
And it. Yeah, Europe. Europe is is not allowing AI right now across the board. EU is not allowing AI to make the decision on whether to hire or fire anybody. It's illegal. And so I think I think you're exactly right. The judgment, the accountability, the judgment, the decision making has to be a human.

00:25:06 - 00:25:25 Stephen Koza
Yeah. Yeah, totally. You mentioned, you know, doing Bake Off supplier. Walk us through maybe some examples of stuff you've evaluated or how you've gone about that. How do you find the right tech or the right solutions for the right use cases, and get to an answer that is ultimately actionable or investable?

00:25:25 - 00:25:46 Patrick McKinney
That's a great question. I think. I think everybody kind of has a similar playbook. You get a scorecard, you make it weighted based on what's more important, what's less important, and you start doing the basic things. Does it work with my technology stack? Obviously, if I'm a GCP customer, I'm not buying Azure tools like things like that. And then for us it comes down to and what I've always kind of thought is where am I going to get the most value?

00:25:46 - 00:25:57 Patrick McKinney
And that's where you start weighting the things, you know, what's weighted like at a scale of 1 to 5, what are your fives? What are your heavy hitters? What's going to save me time? What's going to save me money? What is going to save me head count? And I don't mean that in the way that I want to lay people off.

00:25:57 - 00:26:24 Patrick McKinney
But if I can grow slower, more organically, still maintain operations and all that sort of stuff, then that's going to be a value to me, because I can convince my finance team and my CEO to sign off on it. And so some of the things that we've been looking at is, and I tell this to every company I'm an advisor to or anybody that I've consulted for, is like, if you save people time and money and that is also headcount as part of that, you will get their attention as long as you can give them value and show those things.

00:26:24 - 00:26:45 Patrick McKinney
That's how you land a sale. That's how you convince not just a CSO, because you're not just selling to season, where you're selling the CISOs and you're selling to CTOs and finance people all in the same package. So I look for I look for ways that I'm gaining efficiencies in multitudes. You know, if you tell me you're going to enhance my workflow throughput by five x, that does nothing for me.

00:26:45 - 00:27:05 Patrick McKinney
And that's stuff on a that's marketing spiel. I don't know what that means, but if you tell me, hey, you're your two senior, IT engineers can now do the work of six. Great. Show it to prove it to me. And if you prove it to me, then I'll believe you in that. And that's a huge thing for me, because now I can probably let those people do their jobs, give them the confidence to do those jobs.

00:27:05 - 00:27:20 Patrick McKinney
But I don't have to hire four more people in the next year or so as we grow. I have superpowers for those two. So that's kind of some of the stuff we looked at. We also look at how serious do you take your own company? Are you quality checking your your AI? Are you are you taking security and compliance seriously?

00:27:20 - 00:27:41 Patrick McKinney
I know, you know, people always joke that SOC two is the biggest check mark in all of and all of business at this point, because a series A company with five people can have a sock two or a Salesforce can have a sock two, and they're the same sock two, that's obviously not the case. You know, you look at who the auditor is, you look at, you know, the control scape, you look at what systems are in place, but at the same time.

00:27:41 - 00:27:57 Patrick McKinney
Have you gone beyond a sock two. Are you thinking about that? Are you are you are your controls that you're describing better than a checkbox sock to? Are they, you know, that sort of thing? Or you said of doing a yearly attestation of your access, are you doing it quarterly or are you making or at least for the elevated access going into those things?

00:27:57 - 00:28:13 Patrick McKinney
So we actually do look beyond just, oh, you have a sock two great. We actually go through the sock two we don't let AI parse it. We do, for the most part, to do the basic check. And it's going to call out any like blatant vulnerabilities. But we'll go back through and we'll look at things like that. So I think third party risk is a big part of Bake offs and everything.

00:28:13 - 00:28:32 Patrick McKinney
So backups are important and you shouldn't you shouldn't be. I mean, companies are going to be out there. They're going to be wowing you with marketing and wowing you with demos. Everybody knows that demos are built to wow, they're not built for real life. So definitely do your due diligence and check out these companies. There's a really cool tech out there, but there's obviously some people that are that are doing a little pageantry.

00:28:32 - 00:28:53 Stephen Koza
I like the way you you think about that because like SOC two is not going to tell you how a company thinks or what their culture is around security or quality or innovation. And like at the end of the day, that's kind of what you're buying. Like get a product and set of features. And what you really want to know is are they going to continue to innovate?

00:28:53 - 00:29:10 Stephen Koza
Are they actually going to be secure beyond this compliance checkbox? You know, that they went and paid Vanna for whoever it is or and like how do you how do you vet that. I'm curious. Like what are the things you do to like kind of get underneath and read between the lines. What shows up in a report?

00:29:10 - 00:29:34 Patrick McKinney
So, I mean, you can never be 100% certain because a lot of a lot of times I'll ask, you know, the report is the report and especially if it's drawn up by, you know, auditors that are less scrupulous about their job, they're just kind of, you know, selling them over, like if they're at overseas vendor or it just wants to collect money and, and they're doing it for 10-K, a checkbox, whatever, I ask to see procedural and guideline documentation.

00:29:34 - 00:29:56 Patrick McKinney
Now just policies obviously very high level policy will tell you yes, we do these things but tell you how they do these things. So when I see guideline documentation or process documentation and I see that they've taken the time to actually draw on a process, I look to see when they created the process, because if I asked for it on August 1st and they wrote it up on July 31st, obviously they're doing their writing up something just to appease me.

00:29:56 - 00:30:10 Patrick McKinney
But if you look at it and say, oh, it was it was approved a year ago by the legal team and by the security team, and it's got the it's got what they're doing in place. I want to give them the benefit of the doubt without going into their, their tools that actually seeing reports. I'm not going to go through and do that.

00:30:10 - 00:30:29 Patrick McKinney
But I think the enhanced due diligence beyond the basic reporting, the basic policy checks is the place to do that and to try and get a good handle on that, obviously, to reputation. I mean, if you talk to people that have either worked at the company, you know, recommendations in this industry go a long way. You know, I didn't even know about EverOps till I came into Coinbase.

00:30:29 - 00:30:42 Patrick McKinney
And then when I heard about, you know, when I worked with the EverOps folks at Coinbase and saw how incredibly talented they were and how, you know, thoughtful they were and what they were doing, I don't have to go back and look for a sock to another company. When I go see them, I'm like, I know they're good.

00:30:42 - 00:30:57 Patrick McKinney
I'll go in. Yes, we'll still do the property diligence, but I know from experience or friends of mine that have worked with EverOps before and say, hey, you know, these guys are fantastic. We'll bring them in. That's why we brought them in to invisible as well, to, to help out with things, because that that goes a long way to.

00:30:57 - 00:31:04 Patrick McKinney
So there are a few channels you can go that aren't just looking at stock through reports to get comfort with who you're going to be working with.

00:31:04 - 00:31:19 Stephen Koza
Yeah, makes sense of sense. Thanks for the commercial, by the way. I, I always tell people, you know, the podcast isn't self-serving, but sometimes, sometimes this kind of thing comes up. And so I truly appreciate the kind words.

00:31:19 - 00:31:21 Patrick McKinney
When you do good work, you do good work.

00:31:21 - 00:31:45 Stephen Koza
So yeah, that's right. We definitely try to let's jump into leadership a little bit since we're we're starting to touch on it. You know, you've led a bunch of different teams across different companies. And one of the things I you've talked about is the stage or the moment when a company needs to shift from CTO, CTO, own security to a security professional owning security.

00:31:45 - 00:31:53 Stephen Koza
Like how do you know you're there? What does that look like? And what happens if a company, you know, waits too long to realize that?

00:31:53 - 00:32:13 Patrick McKinney
Yeah, I think there are a couple of indicators on the on the CTOs side or the head of it side that, you know, some companies will punt security to the from the beginning to, to the IT folks to handle before they bring the security professional. And I think a CTOs job is is the technology organization overall it is the engineering teams.

00:32:13 - 00:32:40 Patrick McKinney
It's the DevOps teams, the SRE, the QAS. And I think once their percentage of time spent on security becomes greater than 10% of their time. As a CTO, you need to start thinking about who you're bringing and doesn't mean have to hire a CSO. You could hire just a dedicated security generalist to come in and start, you know, doing compliance, engineering, privacy, all kind of, you know, get to that base 1.0 level.

00:32:40 - 00:33:02 Patrick McKinney
Same with like ahead of it. Head of its job is to is to operate and run an efficient IT team. The minute that security percentage goes greater than what they're comfortable with, it's time to start thinking about it. And I've worked with some phenomenal CTOs, I mean, world class leaders. And even they will tell me it just got too much for me to handle.

00:33:02 - 00:33:17 Patrick McKinney
So that's why we brought a consultant on it. So we brought in our first engineer. So we brought in a CSO. You know, when I came to invisible Adam Haney shout out to him, he's a phenomenal leader. Now over Infinity told me, hey, you know, it just got too much for the existing team to manage without a subject matter expert.

00:33:17 - 00:33:31 Patrick McKinney
And he was right. I mean, when I came in, there was a lot of work to do, and it gave me a full time job right away. Day one, which that means, you know, like, yeah, you probably waited a little too long, but even still like it, you got you got a person in, they started focusing on it.

00:33:31 - 00:33:39 Patrick McKinney
And we built out a lot of stuff very quickly. That was that was kind of at the 1.0 level, if you will. And then we progressively got to like the 2.0, 3.0.

00:33:39 - 00:34:00 Stephen Koza
Going back to our AI conversation for a minute, minute not not to not not to make everything about AI. But, you know, one of the one of the things I've been thinking about, and it's not just me, companies are able to leverage AI more and more. What does that mean for the people coming out of school today and the entry level folks?

00:34:00 - 00:34:30 Stephen Koza
I mean, you know, some of the stuff I did earlier in my career, AI can do all that and it can do it way better. And that's especially true in legal and, you know, maybe like accounting and the other like software development. So I think you spoke on a panel about this, if I'm not mistaken, about how AI is kind of changing the craft and what that means for building talent.

00:34:30 - 00:34:49 Patrick McKinney
Yeah, I was raised a little, little quick personal. I was raised by by a dad who basically told me not to rely on technology, which is ironic now that I work in technology. But my dad, my dad, I mean, he's a woodworker by hobby. He he gets, you know, he and he does things with his hands. He also has machines because he's like, what if the power goes out?

00:34:49 - 00:35:09 Patrick McKinney
You can't use the machines. You have to know how to do it by hand. And I think that's something I've always kind of taken with me as well, is like, learn the fundamentals, learn how to do the basics and understand the areas better. Yes, there are tools that are out there like that are going, you don't have to write a Hello World application anymore as a starter to learn coding.

00:35:09 - 00:35:27 Patrick McKinney
You can use AI to in the start, but you should know the fundamental underpinnings of why we program, why things are built that way, how to do them better. Because let's say something happens and like the AI pushes its own kill switch and now you still you still have power. You can still write your own things, but you don't have AI to do it.

00:35:27 - 00:35:49 Patrick McKinney
You need to be able to still continue these businesses. You need to be able to have those fail safes. So I do strongly. I mean, education is a fundamental underpinning of what we do in the world, whether it's, you know, cooking, whether it's programing, whether it's, you know, building anything, mechanical engineering, stuff like that. So understanding why things are the way they are is always going to be valuable.

00:35:49 - 00:36:11 Patrick McKinney
So I'm not suggesting people just go to college or spend their money on that. But but learn always educate yourself. I'm always educating myself. And I'm going to be 41 years old this year. With that being said, I do think that you need to also educate yourself about the AI that's out there and learn how to use it in a way that maximizes your productivity, while also not taking away from that fundamental education.

00:36:11 - 00:36:29 Patrick McKinney
So learn how to program, learn different languages, learn why different languages exist. Why aren't we doing everything in Java? Why does go exist? Why does rust exist? You know, there's there's more than one front end language. Understand the why and then move forward and build with the why. Because I do think that really gives you a better way to make decisions.

00:36:29 - 00:36:36 Patrick McKinney
Like you said, the human element is making decisions, and we need that to make the decisions and then use the AI to help get you there.

00:36:36 - 00:36:55 Stephen Koza
Yeah, if I think about my own experience. So, you know, I'm a business guy and, you know, my whole career has been on the business side, except for my first job, which was an engineering job because I studied engineering. But then I, you know, I kind of took the, you know, took the exit ramp or went down a different path pretty early in my career.

00:36:55 - 00:37:18 Stephen Koza
But because I have that technical foundation and it's it's very dusty. Now, just to be clear, you know, now what I'm, you know, I'm vibe coding something. I realize, oh my gosh, it's like really helpful that I actually have a base level understanding of what code does. And, you know, things are architected. And what is this list of files mean.

00:37:18 - 00:37:42 Stephen Koza
That's in my in my IDE. And you know, like, you know, it wants an environment variable. Oh, I actually know what a variable is because, you know, I had a code in like C++, you know, two decades ago. And so and so like that's my personal experience of what you're saying, which is it's really useful to understand, at least at a high level, what's happening under the hood.

00:37:42 - 00:38:02 Stephen Koza
Because otherwise, like, you know, if you're talking about software development, you know, just about any anybody you can go vibe code something. But it's also really easy to create something that you know is just a big pile. You know what? It doesn't work well and you don't know what's going on. And you let the AI do its thing and you have no idea what it's doing behind the scenes.

00:38:02 - 00:38:05 Stephen Koza
And like, that's been that's been really useful.

00:38:05 - 00:38:23 Patrick McKinney
I'd say vibe coding creates vulnerabilities. It creates quality issues like II is not right quality code. And if anybody says that it does, then they're 100% wrong. And I've seen I've seen the benchmarks. So understand like being able to make your code quality make your code secure because obviously oh I can just point a vulnerability tool at it.

00:38:23 - 00:38:31 Patrick McKinney
But we just said like they're not necessarily doing everything 100% correct. So you can't just keep pointing AI to solve problems.

00:38:31 - 00:38:52 Stephen Koza
Although it is it is it is kind of cool how that works because, you know, one one use case is, you know, somebody will code something with opus and then they point, you know, one of the GPT models at it and say, you know, give me a quality. And like the models don't always agree. And one model, like, finds a bunch of stuff that the other one didn't.

00:38:52 - 00:38:57 Patrick McKinney
And oh, look, we just we just engineered an office. We engineered people disagreeing.

00:38:58 - 00:39:21 Stephen Koza
Yeah. Yeah. Totally. So, you know, back to the leadership thing is, you know, as AI kind of changes people's day to day on your team instead of like, you know, some of the stuff they don't have to do, some of it becomes more important. How does that actually change people's work? And then how do you keep them? How do you keep them growing and engaged and productive?

00:39:21 - 00:39:28 Stephen Koza
When you know a big part of their day, they don't have to do it anymore. It's not their job anymore.

00:39:28 - 00:39:44 Patrick McKinney
I'm going to answer this a two ways. So one of the things that I believe companies are doing, whether they want to admit it or not, and this is not a bad thing, is we are starting we as the world and as companies are starting to grow leaner. You're not starting out with, okay, I have to build an engineering team.

00:39:44 - 00:40:03 Patrick McKinney
Let me go hire 30 engineers. Even if you're trying to get cheaper ones in different geo regions, you're not doing that anymore. You're saying, hey, let me go get a team of five, because a team of five, they can align faster, they can write code now faster, and they're doing that stuff faster. So I think with that it's you're you're having more people handle more things.

00:40:03 - 00:40:26 Patrick McKinney
Whereas you used to have an IT engineer just answer tickets. Now that engineers also learning systems, they're learning how to do the automation. They're going to build these things. And then with that comes the second part is like what's the next thing. I'll bring that back up. The foresight that that what's the next thing on the list. There's nobody especially I mean, dude, Salesforce has been around since I think 98.

00:40:26 - 00:40:43 Patrick McKinney
Like they've been around for a long time, and they still have ways to mature and grow programs and areas of their companies. Coinbase, same. Every company I've been to still has areas to mature. So the fact that companies have been around for 20, 30 years and they still have areas to mature in, that means that the job is never done.

00:40:43 - 00:41:02 Patrick McKinney
And so it's always what's the next thing? How do we think about this? And when the when the easy to find things that are that new mature need to be upgraded are, are getting smaller and smaller, it's like now let's bring in that complex thinking, you know, let's where are let's start looking at ways that we can test what we've built so far.

00:41:02 - 00:41:26 Patrick McKinney
Let's look at ways that we can challenge it in pen, test it if you will, or red team it the our privacy program, our our compliance program, our reliability program. Let's introduce chaos engineering. Let's do all these different things that we're not doing to become the best that we can. And I think the people that will thrive the most in an AI centric world are going to be those people that look to the next thing they look to.

00:41:26 - 00:41:40 Patrick McKinney
How do we make it the best of the best? Not ever achieving perfection because we never will. There will always be something else that comes along. But but striving for that and trying to find the next thing to improve your area that you oversee will. There will always be something there.

00:41:40 - 00:41:59 Stephen Koza
Yeah, that's I mean that's great career advice on top of everything else. Speaking of, to kind of wrap things up here as a security leader, what do you think one of the most underrated skills is? What's what's served you really well? If you were given advice to people who are earlier in their career.

00:42:00 - 00:42:12 Patrick McKinney
The one that I give everybody is is soft skills and networking. Like those those go that's not a security gets everybody you need. You need to be able to talk to humans. People need to want to work with you. They want to have I mean, they don't have to like you, but they want to work with you because they respect you.

00:42:12 - 00:42:33 Patrick McKinney
So, so have those build those soft skills, understand all that. And from a security world, I would say as much as people complain and say the CIS certification is useless because it's a breadth of knowledge, not a depth of knowledge. Learn the breadth of knowledge, understand data center security. Even if you're not working in data centers like you should still understand these things.

00:42:34 - 00:42:56 Patrick McKinney
Physical security. But if you're not a physical security expert cloud, learn everything because some of this stuff will tie together camera systems. Now they're being controlled by AI. They will tie together back into your cloud infrastructure. That's securing the data that's going in there. So these things will all tie together at some point in your career. So it never hurts to learn the breadth of knowledge before you go into the depth of knowledge.

00:42:56 - 00:43:21 Stephen Koza
Yeah, that's a good one. And then I'll I'll second your soft skills comment. My answer is usually sales. And I don't mean like, you know, you got to know how to close a deal. I mean the skills behind sales, like hopefully everybody, you know had a lemonade stand at some point or, you know, they did a door to door sales job and they're in college or something.

00:43:21 - 00:43:41 Stephen Koza
And if you're in college and you haven't, you should go do that because sales fundamentally teaches you the soft stuff. How do you communicate? Well, how can you clearly explain something in a way that the person across the table understands and gets it? And, you know, how can you connect with somebody and you know, it helps you with interpersonal stuff.

00:43:41 - 00:43:52 Stephen Koza
And I think that's probably underrated and maybe not known or valued enough by, you know, generally speaking, by a lot of people who are coming into the technical fields.

00:43:52 - 00:43:54 Patrick McKinney
Yeah, I agree with you 100%.

00:43:54 - 00:44:00 Stephen Koza
Yeah. You're I don't know if you had sales jobs or not, but you you picked us. Yeah. You picked up those skills somewhere. I can tell.

00:44:00 - 00:44:17 Patrick McKinney
I did. I had a I had a couple sales job. I worked retail actually as my first high school job. I worked at like GameStop and Best Buy and and all those. And over summer breaks in college, I would go get jobs, came and speak jobs in malls and working like malls and just see people interact with people.

00:44:17 - 00:44:33 Patrick McKinney
And I think, you know, I say it all the time to people. It's kind of like it's a joke, one liner. But like in an age of AI, humans still matter the most. So humanity is a thing. We have to take care of each other. We have to work with each other. We have to, you know, we have to be humans.

00:44:33 - 00:44:34 Patrick McKinney
So.

00:44:34 - 00:44:47 Stephen Koza
Yeah. Well, and and all that, all of a sudden that stuff is now even more important because that's, that's the that's the differentiator. That's the thing that sets you apart. You know, being able to write a lot of code is unfortunately not that thing anymore.

00:44:47 - 00:44:49 Patrick McKinney
Right, exactly. Yeah.

00:44:49 - 00:45:19 Stephen Koza
Well, cool. Patrick, man, it's been fun. Yeah. Appreciate you coming on. I learned a ton and appreciate you sharing everything. I think our listeners will probably appreciate it. So for everybody listening, if you enjoyed it, if you got something out of it, please subscribe, review, follow whatever the button is and it helps us with our reach. We're on Spotify and YouTube and Apple and probably a bunch of other spots that I don't know about, but maybe my mom found me on.

00:45:19 - 00:45:26 Stephen Koza
I'm. I'm Stephen Koza, I'm the CEO of ops, and this has been Tech Pod talks. And we'll see you next time.

00:00:08 - 00:00:31 Stephen Koza
A crypto exchange, a file sharing giant, a big enterprise software company that was trying to figure out FedRAMP. My guest today has stood up the first version of a security or compliance program at all three. And then he went somewhere to work where the product itself is AI automation. His playbook was not the same. It didn't survive all the stops.

00:00:31 - 00:00:55 Stephen Koza
But what he kept is probably not what you would expect. Welcome to TechPod talks. This is Stephen Koza. We do candid conversations with the leaders who are building what's next. Every episode we bring in a practitioner, somebody who's actually in the arena to share what's happening behind the scenes, and platform engineering, DevOps, cloud leadership, security. And my guest today is just that kind of person.

00:00:55 - 00:01:30 Stephen Koza
Today I've got Patrick McKinney. He's the vice president of security at Invisible Technologies. Patrick spent pretty much his whole career building security and compliance functions from the ground up. He built the first line of defense compliance engineering team at Coinbase. He was a founding member of Dropbox's risk and governance team. He stood up the first Socks and GDPR programs there, and he was also the first technical program manager at Salesforce, worked in San Francisco and Dublin, where he helped them earn FedRAMP.

00:01:30 - 00:01:54 Stephen Koza
It invisible today, he's built a security program that leans pretty hard on AI native tooling and SoC platforms, encrypted AI analytics. And he ties security spend directly back to revenue and retention and sales enablement, which is pretty cool. Outside of work, you'll find him in the backyard cooking and barbecuing, and I definitely want to talk about that. So hey Patrick, welcome to TechPod Talks.

00:01:54 - 00:01:57 Patrick McKinney
Hey, Stephen. Great to be here.

00:01:57 - 00:02:02 Stephen Koza
Before we get into it, what's what's your favorite thing to barbecue on?

00:02:02 - 00:02:12 Patrick McKinney
Man I'm a big beef ribs guy. I think you know, big dino beef ribs. Everybody likes the presentation. The big bone, the soft, you know, juicy, smoky meat. Nobody ever complains about those.

00:02:12 - 00:02:20 Stephen Koza
Nice. And what do you like to cook them on? You. You charcoal guy, a Traeger guy. You got your own set up?

00:02:20 - 00:02:38 Patrick McKinney
I actually did buy a custom smoker. It's an offset wood smoker by a local guy out here in Vegas. He makes them as a hobby. And then I bought a quart of of Hickory from from Oklahoma that got shipped it out here. So I take my barbecue seriously and I feed usually between 15 and 20 people. And I when I fire that guy up.

00:02:38 - 00:02:46 Stephen Koza
Yeah, I can tell. Yeah. Anybody that's serious about it usually graduates to something like that. I have not yet, but maybe you can give me some tips later.

00:02:46 - 00:02:47 Patrick McKinney
We'll get you out here.

00:02:47 - 00:03:11 Stephen Koza
Yeah, I love it, man. Well, let's get into it, man. You've got a really cool background. Bunch of brand name companies. And, you know, I seems like you joined some of those, you know, in the earlier days when you had to build stuff that didn't doesn't exist. Let's start with Coinbase. So I know there you you helped build their first line of defense compliance engineering team.

00:03:11 - 00:03:19 Stephen Koza
What the heck is that. What did that mean? What did what did it look like on on day one where nothing was established?

00:03:19 - 00:03:37 Patrick McKinney
Yeah. So that is a mouthful. You kind of call it I think people call compliance engineering now, but it's essentially when I came into Coinbase, a person we both know, Alex Brown, basically called me and hired me and said, hey, listen, I'm leading it over here and I just want somebody to handle the security and compliance for it.

00:03:37 - 00:03:59 Patrick McKinney
And I said, I got you. And as soon as I came over there, it was it was pretty blatant that everybody was moving fast and building things. And when you're moving fast, you're building things. You don't tend to bake compliance controls into the systems you're building, the processes you're building. Everything was changing. They were maturing rapidly. And so myself and a small well, it was just me to start.

00:03:59 - 00:04:17 Patrick McKinney
And then it became me. And two others essentially made it to where every time something new was being built, we took the compliance controls into place. We either consulted on the on the applications or platforms being built and we would say, hey, you should do this, this and this to make sure we abide by all the controls we're doing.

00:04:17 - 00:04:34 Patrick McKinney
Then anything that couldn't be built in or just was too clunky and it wasn't working. We would handle some manual processes and work their way towards automation. So it was it was a very step by step process to get this going. And we eventually turned into a into a program that encompassed all of security, all of it, and all of engineering at Coinbase.

00:04:34 - 00:04:41 Stephen Koza
Oh nice. Nice. I imagine given the nature of the business, your your role and function was pretty important.

00:04:41 - 00:04:56 Patrick McKinney
It was it was yeah. We we spent about I spent about four and a half years there and had a lot of successes, a lot of wins. But you could see it as it organically spread out across the company from people just saying, hey, you know, Patrick's team is doing a great job here. Patrick team's doing a great job here.

00:04:56 - 00:05:08 Patrick McKinney
Eventually we would get asked for help and that would just, you know, mature the program. So it became a rather large team before before my exit there. But yeah, it was it was very, very helpful for the business and still talk about those times today with some of the Coinbase alumnus.

00:05:08 - 00:05:27 Stephen Koza
Yeah I but yeah, I know they're appropriately pretty security conscious. Was there anything unique about working there at a fintech that's different when it comes to security versus, you know, CRM company, file sharing company, AI enablement company?

00:05:27 - 00:05:47 Patrick McKinney
Yeah, I mean, off the bat, I mean, as expected, like the regulations are different. You're dealing with different regulatory bodies. You're dealing with the NYSE, you're dealing with, you know, high trust and all these different compliance regulations. And you don't have to have at a file sharing company or CRM company. And so with that just comes extra scrutiny, extra controls that you want to bake in and scale across the business.

00:05:47 - 00:06:16 Patrick McKinney
So that was kind of the major difference. But then the other not on the surface level that you see is just coming into that company. Even when I came in in 2018, just the maturity of that security program that Philip Martin led was incredible. And he expected that security maturity across the entire company. So it was it was a breath of fresh air coming into a place that took it seriously across the board, which made my job easier, but also at the same time, made it, made it something we had to live up to.

00:06:16 - 00:06:23 Stephen Koza
Yeah, sure. Any any lessons learned or things that you got out of that experience that you you took forward to other roles?

00:06:23 - 00:06:42 Patrick McKinney
I think, yeah. Focusing on security and compliance as part of the as part of the design process before you start building does make things a lot easier as you move forward. You know, you don't have to sit there and and retrofit security because a good buddy of mine made a made a very famous quote that I've kept with me.

00:06:42 - 00:06:46 Patrick McKinney
It's like phase two, never add security. So always do it in phase one.

00:06:46 - 00:07:14 Stephen Koza
Oh yeah, that makes a ton of sense. Intuitive, but maybe. Maybe not. Not always practiced. Let's let's keep going through the LinkedIn. I love hearing about the variety. So I know you spent some time at Dropbox and you kicked off the risk and governance team. I threw out some fancy acronyms earlier Sox compliance, GDPR, stuff that people are probably familiar with.

00:07:14 - 00:07:24 Stephen Koza
Or maybe give them a little PTSD. Like, tell me about that. What? Like what was it like building that function? What do you guys tackle? What were you focused on?

00:07:24 - 00:07:50 Patrick McKinney
Yeah. So this is another example where, I mean, I came in as the first security TPM at Dropbox, where I focus on the traditional functions infra production, security, detection, response and helping those teams kind of get organized, talk to the engineering teams better. And then when it came time for Dropbox to go public, which was early 2018, there was another kind of I don't call it disconnect, but there was just a bridge that needed to be built between engineering and compliance.

00:07:50 - 00:08:10 Patrick McKinney
And so similar to my time at Coinbase spinning that are already knowing the playbook, that point. This is what I learned the playbook. And it was spinning up a very small team that reported actually into the IT team and rather than the security team, but it took those compliance principles that needed to be engineered into the product or, you know, automation processes built between teams.

00:08:10 - 00:08:27 Patrick McKinney
And we basically identified those and worked on automating those. And through that, it incorporated, you know, that was when GDPR was becoming very, very big. That was when obviously first year SoCs for any company that goes IPO is going to need some help. And addressing those new controls they hadn't focused on before. So that's what the program really focused on.

00:08:27 - 00:08:39 Patrick McKinney
And it was it was great to be able to see kind of a head into when compliance during wasn't a thing at that point, but kind of building those first processes that would eventually become that for the company. And the function is still going on there today.

00:08:39 - 00:09:05 Stephen Koza
I know when you're if you're a company and you're gearing up for an IPO, things have to be tight. Your financial controls have to be tight. Security has got to be tight. You know, you're all of a sudden invite a lot of scrutiny that you didn't have before. Like how do you approach that? And then given the scale of the company at the time, how do you get all the stakeholders on the same page, the auditing team, partners, engineering teams?

00:09:05 - 00:09:07 Stephen Koza
What? How do you approach that kind of stuff?

00:09:07 - 00:09:26 Patrick McKinney
Well, luckily, I think I think most teams at that point new like Sox is going to be absolutely important. I think. I don't think people really understood the gravity of GDPR yet. So we took a couple avenues. One, I mean, as as most companies do, we did bring in an outside consulting firm to help us get ready for Sox compliance.

00:09:26 - 00:09:44 Patrick McKinney
We also run a separate outside company to help us get GDPR ready. And they both came with, hey. These are the risks. These are the trade offs. You have to do these. These are potential fines. You know, all that sort of stuff. So getting everybody aligned and informed first on what could possibly happen if we don't do this.

00:09:44 - 00:10:01 Patrick McKinney
And then it made it very clear that we have to do this and we have to do it the right way, because if you don't do it the right way, it doesn't scale. And if it doesn't scale, obviously things can break or go haywire. So it was it was more of an informed inform the teams, get them on the same baseline level of understanding of what we have to do, and then move forward and do it.

00:10:01 - 00:10:09 Patrick McKinney
And if anybody was it really aligned, then you obviously escalated to the exact. But luckily everybody that worked there was pretty intelligent. So as soon as you told them why we need to do it, they were like, okay, let's go.

00:10:09 - 00:10:31 Stephen Koza
Yeah. I for for people who aren't familiar with this, when you file for IPO, you file this thing called an S-1 and basically like, say everything about everything there is to say at the company, including all the risks and the gaps and the deficiencies. So I imagine, you know, you had a spotlight on you probably like, what was that pressure like?

00:10:31 - 00:10:37 Stephen Koza
And what was the was the timeline for making sure you guys were going to be in a good spot for that?

00:10:37 - 00:10:55 Patrick McKinney
Yeah. With Sox compliance, you the the way it works is. Yeah. You do file your S-1 and then when you officially list you have or when you officially go public, you know, your stock launches that day, you basically get a year from your launch until your first Sox audit. So you do have a year post long post IPO to actually become Sox compliant.

00:10:55 - 00:11:14 Patrick McKinney
And we knew going up into the IPO that we had to do this. So we had a year plus to get ready. But there's a lot to do. I mean, there's a reason they give you that much time to get ready. There's a lot to do. And so it definitely took a team, a pretty large team, including those outside consulting firms, to help us out and get ready for it.

00:11:14 - 00:11:33 Patrick McKinney
I mean, it was my first time pre-IPO going IPO. I had worked at Salesforce prior, which is already public. So Sox compliance with something that I'd already worked on. But once you go through it and once you get through the first year, it does become a little bit easier. You kind of follow the same playbook. You learn from the mistakes, any little small things.

00:11:33 - 00:11:44 Patrick McKinney
The auditors mentioned that you could could use improvement on, you just improve upon. So the pressure was there, but it luckily, like I said, everybody Dropbox is really talented. So we got we got through it pretty easily.

00:11:44 - 00:11:52 Stephen Koza
Yeah. Nice. Nice. You mentioned Salesforce. Tell us about that. What did you do for Salesforce. And you spent some time out of the country as well right.

00:11:52 - 00:12:12 Patrick McKinney
Yeah. So I did a I actually did a variety of things for the security security org over there at Salesforce. I worked there for almost four years going back to 2012. And when I was first hired, I was I was doing actually working on their R&D side, which is very interesting. That didn't last too long before I moved into the security side.

00:12:12 - 00:12:32 Patrick McKinney
And the first thing that I did was was like you mentioned earlier, is the FedRAMP program. This is back in. You know, 20, 2013 getting fed ramp ready. This is before any of the really great MSPs that are out there now, any of the acceleration programs. So this was flying from San Francisco to meet with their sponsors, the Health and Human Services organization.

00:12:32 - 00:12:53 Patrick McKinney
We flew monthly from San Francisco to Washington, D.C. they weren't big on video conferencing. They weren't big on all that. So it was it was a hassle. And with and with the way Salesforce did is they actually had a physical colo. That was what they called a super pod back then. That was actually FedRAMP authorized. So they built everything the edge network, the servers, everything.

00:12:53 - 00:13:09 Patrick McKinney
Like it wasn't one of those where you could just go deploy your application in a hosted MSP and get get certified. Now it was we have to do everything from scratch. And we had a really great leader back then who she was running the program. Her name was Laura and had a good team of people that are now.

00:13:09 - 00:13:27 Patrick McKinney
I mean, I actually look at that team. It's very interesting because three of those people are now CISOs at other companies. You know, Laura's got her own company. I'm over here running security, other companies. So you have you had these future heads of security and future heads of compliance that were all in one team making this work back then when everything was a little more hazy.

00:13:27 - 00:13:37 Patrick McKinney
But that was a really fun program. I learned a lot. There were some definitely some battle scars. I mean, it was it was a year and a half program of traveling every month. But it was it was really, really great.

00:13:37 - 00:13:53 Stephen Koza
So if you think about the experiences at the companies and roles, we've talked about any common threads, like what were the lessons learned? What did you take away? What what what worked at one place didn't work at another? Connect the dots for us a little bit.

00:13:53 - 00:14:12 Patrick McKinney
I mean, definitely the dot that followed me everywhere is is think security early. And obviously, you know, my career spanned almost 20 years at this point. And there are definitely areas of my career where it it felt like we were thinking about security early on, and there were definitely areas where we're not thinking about security and it was necessary, a linear progression.

00:14:12 - 00:14:36 Patrick McKinney
It could, you know, I started my career in the public sector. I worked for the CIA, I worked for Disa. Obviously they think about security very, very heavily. And then after that, going into the private sector, you had companies that may or may not have invested as much they as they should or as they wanted to due to various reasons and continuous thought of think of security early is definitely something that stuck with me the entire way, and some other things that I learned.

00:14:36 - 00:14:55 Patrick McKinney
Lessons learned is bad news doesn't get better with time, so make sure that if something isn't going to work or if something is going to be a problem, you you escalate that early. And obviously, you know, with all the supporting metrics and all the supporting details. So you're not just kind of crying wolf, but make sure that you do surface these risks early.

00:14:55 - 00:15:08 Patrick McKinney
I mean, I still practice that today at invisible. I, you know, we have monthly risk meetings within the security team with my CTO all the way up to the chief legal officer. And we and we surface these risks well before they become actual issues.

00:15:08 - 00:15:34 Stephen Koza
Yeah, I feel like that's pretty good leadership advice. Regardless, regardless of your domain, you don't want to sit on stuff and hide it. There's there's not a lot of value in that. Well, let's jump into AI because it's obviously a fun topic these days. And yeah, I know you guys are doing a ton here, and people probably love to learn about how you're thinking of it and the types of investments you're you're making.

00:15:34 - 00:15:56 Stephen Koza
I know one of those is an agent SOC platform. So tell us a little bit about that. I think you told me the problem with the problem with people's adoption of AI today is because it's new. You know, companies are chasing a lot of different things, and sometimes there's disorganization and sometimes they're not picking the right use cases.

00:15:56 - 00:16:12 Stephen Koza
And so the general narrative is, you know, enterprises are not getting positive ROI. It's a lot of token spend without any value to match. And I think you would disagree with where you guys have invested. So so tell us about that. Maybe start with the SOC platform.

00:16:12 - 00:16:30 Patrick McKinney
Yeah, absolutely. You're exactly right. We've calculated where we want to invest AI, and not just from a cost perspective, but also I think if you talk to most security professionals, they're they're naturally kind of risk averse. And so a lot of people are looking at quality control. How do you how do you ensure you're getting the returns on the data, the information that you're getting?

00:16:30 - 00:16:51 Patrick McKinney
How are we sure that. That's right. You know, but yeah, the SOC was actually one of the first things we adopted at invisible. I'm actually giving a talk with my vendor ex-offenders at Blackhat. So if any folks are there, they can attend that talk. But really what we were looking at is what what benefits do we get from an agent SOC?

00:16:51 - 00:17:07 Patrick McKinney
What are the quality controls? What are the what are the risks? How do we avoid them? And so I actually took a two pronged approach to the agenda. SOC is not just bringing in a platform that we could send all of our logs to, and actually use AI to parse them faster than what a traditional detection and response team would do.

00:17:07 - 00:17:31 Patrick McKinney
But I also invested in the part the human element of of force. They do have a human detection, managed detection and response area so that they can monitor the platform even while AI is doing its thing. And really what it came down to was cost. You're exactly right. And it start with cost. What it cost for us to bring that in was about one fifth of what it would cost to stand up our own 20 473 65 SOC team.

00:17:31 - 00:17:50 Patrick McKinney
I think you're getting a lot of the tools and the people elements kind of built in together, similar to when people bring EverOps on and you get a pot of people, you're getting that shared services kind of mentality. You are getting experts in their domain and they're working in a smarter, not harder sense to serve the customer.

00:17:50 - 00:18:07 Patrick McKinney
So that's that was the reason that I brought excellence into invisible was really like there was the human side, there was the AI side. They were both showing results. We did do quality control test. We still performed quality control test quarterly to make sure that whatever the AI is returning is the same thing we're seeing in the primary system, in the logs and that sort of stuff.

00:18:07 - 00:18:25 Stephen Koza
Yeah, that makes a ton of sense because AI is obviously good at a lot of things, but it's not right 100% of the time. And we all know that. And unfortunately, it was security. You kind of got to be right 100% of the time. So there's the judgment layer that you still need. And you know, there's a role for humans.

00:18:25 - 00:18:48 Stephen Koza
And because of that. And so I didn't ask you, but you know, to me that's kind of like the perfect example of that, of that point. Tell me about how like when you're when you're making AI investments and you've got these great tools that are now available, how how do you think about mapping them to how your teams actually work today?

00:18:48 - 00:19:11 Stephen Koza
What needs to change? What's the difference between the old model and the new model, and how do you adapt to that? Because we see that as a failure point and we're you know, we're not we're not geniuses. You know, that's kind of commonly understood now that you can't just bolt AI on and keep every single one of your business processes the same people need to start working differently and you reorganize and, you know, maybe you don't need all the process.

00:19:11 - 00:19:14 Stephen Koza
So tell us about that. What's what showed up in your org?

00:19:14 - 00:19:32 Patrick McKinney
Yeah. So some of the things that we've we, we went with early on were like we wanted to build the team lean organically. I wasn't I wasn't able to hire, you know, 15 people at once or 20 people at once. So as people would come in for different functions, you know, infosec apps, cloud sac, all that sort of stuff, detection, response fraud.

00:19:32 - 00:19:58 Patrick McKinney
I would have those people work with me and we would we would basically build the what, what the function should look like. Where are the processes that are repeatable? What are the ones that we could trust to AI if the AI was quality and which ones would always need human oversight? And where does that human oversight look? A quick example is, you know, you got a lot of these tools out now that will for apps side that will the they'll find the vulnerability and they'll cut a PR to fix the vulnerability.

00:19:58 - 00:20:18 Patrick McKinney
Well we still want human oversight of that PR to make sure it doesn't break something just outside of fixing the vulnerability. So and I believe that AI should be supercharging humans, not necessarily just replacing jobs 1 to 1. So as I would hire out the team, lean organically, you know, meeting, meeting the needs of the business while also not over hiring.

00:20:18 - 00:20:37 Patrick McKinney
We would look to some of this tooling that's coming out now, a lot of the newer stuff, series A, series B, companies that are building really impressive things, we would absolutely, you know, look for competitors, do a proper bake off and find out during that bake off which AI is bringing back quality results. You know, if you ask, you know, ChatGPT the same question ten times, you're not going to get ten of the same answer.

00:20:37 - 00:20:53 Patrick McKinney
And that's a big, you know, multibillion dollar company. So what makes a series A, series B company implementing AI any better. So we would just do the quality checks and and we would just know to make sure that, you know, if there were any weaknesses to take into account and didn't necessarily rule the tool out, it just means that you'd have taken into account.

00:20:53 - 00:21:17 Patrick McKinney
So that's kind of the way that I look at AI being bringing into security right now is let's supercharge the people we have. Let's let's automate and use AI to enhance routine processes or repeatable processes. AI allows you to kind of automate more complicated and complex processes than what we used to just be able to automate and move forward from there and find out there's always something new in, something extra to take on when it comes to security.

00:21:17 - 00:21:22 Patrick McKinney
So let's let's try and knock out the stuff that's known and solvable fast via AI and automation.

00:21:22 - 00:21:49 Stephen Koza
Yeah. You know, we've all heard the job loss narrative around AI. And, you know, I've told people six months ago I wasn't so sure, you know, because there's smart people on either side of that argument. And both arguments were pretty compelling. Now I'm way more convinced what you're saying is accurate. Like, I heard a figure the other day that, you know, maybe AI can tackle 60% of work just to put a number on it.

00:21:49 - 00:22:12 Stephen Koza
And that's like maybe 60% of somebody's job or 60% of certain kinds of tasks. And so the question is like, what do you do with that other 40%? It's like, well, the other 40, like the other 40% is still the human, but now they've got 60% more in their day to do a better job of that, or do higher value stuff, or be more productive or deliver more value.

00:22:12 - 00:22:28 Stephen Koza
And to me, that's pretty cool. And I think that point of view is probably correct. I think the job loss stuff was probably a little overblown, and even the some of the AI luminaries have started to kind of soften their tone on that. So I like the way you said it. I agree with that point of view for sure.

00:22:29 - 00:22:54 Patrick McKinney
Well, I think too, when you combine a lot of I mean, I'm sure people have seen the articles that now with with token costs, AI is becoming more expensive than humans. So it's like now we got to hire some humans back because it's cost effective and I get that side of it. But I also, you know, AI can't future I mean it can model but it can't really see the future can't predict the same way the human brains do because it's being trained on data that's here and before.

00:22:54 - 00:23:16 Patrick McKinney
So it can't accurately forecast. And I think humans can't accurately forecast for the most part. I mean, look at most weather channels. But at the same time, I think, you know, the human the human element that needs to be in security teams, engineering teams is, you know, because with with security, it's definitely obviously with engineering teams, its resiliency, it's making sure that things are up and running.

00:23:16 - 00:23:28 Patrick McKinney
Is that forecasting that foresight if something that humans are still doing better than AI for the most part. And I think that's where that extra 40% really, really goes. Like what's the next thing? What's the next thing? What's the next thing?

00:23:28 - 00:23:42 Stephen Koza
Yeah, I always, always, you know, refer to the judgment layer, which is, you know, AI is going to give you an answer or several different and conflicting answers depending on what you give it and how you ask the question and what model you're using.

00:23:42 - 00:23:46 Patrick McKinney
The answer. It's always going to be a zero EQ high IQ answer. Yeah.

00:23:46 - 00:24:10 Stephen Koza
Yeah, totally. So so there's that. And then there's also this, this like relationship element where, you know, if you're in a leadership role, you know, you have kind of natural intuition around how the company works and what your customers are telling you. And you know, your X number of years of experience and like being able to connect the dots on that, like AI is just never going to be able to do it.

00:24:10 - 00:24:38 Stephen Koza
Well, never say never, but AI doesn't quite do it in the same way. And then on top of all that, like somebody has to make a decision eventually, like there's a vulnerability. You know, are we going to address it or not? Or there's a trade off here, or are we going to pick A or B? And I don't think Wall Street is going to let AI start making those, you know, judgment based decision calls anytime soon because then there's nobody to hold accountable.

00:24:38 - 00:24:49 Stephen Koza
And so like there's just so much to it. Once you start peeling back the onion that you realize, well, you know, it's an amazing set of tools to solve a lot of problems and automate things and drive efficiency.

00:24:49 - 00:25:05 Patrick McKinney
And it. Yeah, Europe. Europe is is not allowing AI right now across the board. EU is not allowing AI to make the decision on whether to hire or fire anybody. It's illegal. And so I think I think you're exactly right. The judgment, the accountability, the judgment, the decision making has to be a human.

00:25:06 - 00:25:25 Stephen Koza
Yeah. Yeah, totally. You mentioned, you know, doing Bake Off supplier. Walk us through maybe some examples of stuff you've evaluated or how you've gone about that. How do you find the right tech or the right solutions for the right use cases, and get to an answer that is ultimately actionable or investable?

00:25:25 - 00:25:46 Patrick McKinney
That's a great question. I think. I think everybody kind of has a similar playbook. You get a scorecard, you make it weighted based on what's more important, what's less important, and you start doing the basic things. Does it work with my technology stack? Obviously, if I'm a GCP customer, I'm not buying Azure tools like things like that. And then for us it comes down to and what I've always kind of thought is where am I going to get the most value?

00:25:46 - 00:25:57 Patrick McKinney
And that's where you start weighting the things, you know, what's weighted like at a scale of 1 to 5, what are your fives? What are your heavy hitters? What's going to save me time? What's going to save me money? What is going to save me head count? And I don't mean that in the way that I want to lay people off.

00:25:57 - 00:26:24 Patrick McKinney
But if I can grow slower, more organically, still maintain operations and all that sort of stuff, then that's going to be a value to me, because I can convince my finance team and my CEO to sign off on it. And so some of the things that we've been looking at is, and I tell this to every company I'm an advisor to or anybody that I've consulted for, is like, if you save people time and money and that is also headcount as part of that, you will get their attention as long as you can give them value and show those things.

00:26:24 - 00:26:45 Patrick McKinney
That's how you land a sale. That's how you convince not just a CSO, because you're not just selling to season, where you're selling the CISOs and you're selling to CTOs and finance people all in the same package. So I look for I look for ways that I'm gaining efficiencies in multitudes. You know, if you tell me you're going to enhance my workflow throughput by five x, that does nothing for me.

00:26:45 - 00:27:05 Patrick McKinney
And that's stuff on a that's marketing spiel. I don't know what that means, but if you tell me, hey, you're your two senior, IT engineers can now do the work of six. Great. Show it to prove it to me. And if you prove it to me, then I'll believe you in that. And that's a huge thing for me, because now I can probably let those people do their jobs, give them the confidence to do those jobs.

00:27:05 - 00:27:20 Patrick McKinney
But I don't have to hire four more people in the next year or so as we grow. I have superpowers for those two. So that's kind of some of the stuff we looked at. We also look at how serious do you take your own company? Are you quality checking your your AI? Are you are you taking security and compliance seriously?

00:27:20 - 00:27:41 Patrick McKinney
I know, you know, people always joke that SOC two is the biggest check mark in all of and all of business at this point, because a series A company with five people can have a sock two or a Salesforce can have a sock two, and they're the same sock two, that's obviously not the case. You know, you look at who the auditor is, you look at, you know, the control scape, you look at what systems are in place, but at the same time.

00:27:41 - 00:27:57 Patrick McKinney
Have you gone beyond a sock two. Are you thinking about that? Are you are you are your controls that you're describing better than a checkbox sock to? Are they, you know, that sort of thing? Or you said of doing a yearly attestation of your access, are you doing it quarterly or are you making or at least for the elevated access going into those things?

00:27:57 - 00:28:13 Patrick McKinney
So we actually do look beyond just, oh, you have a sock two great. We actually go through the sock two we don't let AI parse it. We do, for the most part, to do the basic check. And it's going to call out any like blatant vulnerabilities. But we'll go back through and we'll look at things like that. So I think third party risk is a big part of Bake offs and everything.

00:28:13 - 00:28:32 Patrick McKinney
So backups are important and you shouldn't you shouldn't be. I mean, companies are going to be out there. They're going to be wowing you with marketing and wowing you with demos. Everybody knows that demos are built to wow, they're not built for real life. So definitely do your due diligence and check out these companies. There's a really cool tech out there, but there's obviously some people that are that are doing a little pageantry.

00:28:32 - 00:28:53 Stephen Koza
I like the way you you think about that because like SOC two is not going to tell you how a company thinks or what their culture is around security or quality or innovation. And like at the end of the day, that's kind of what you're buying. Like get a product and set of features. And what you really want to know is are they going to continue to innovate?

00:28:53 - 00:29:10 Stephen Koza
Are they actually going to be secure beyond this compliance checkbox? You know, that they went and paid Vanna for whoever it is or and like how do you how do you vet that. I'm curious. Like what are the things you do to like kind of get underneath and read between the lines. What shows up in a report?

00:29:10 - 00:29:34 Patrick McKinney
So, I mean, you can never be 100% certain because a lot of a lot of times I'll ask, you know, the report is the report and especially if it's drawn up by, you know, auditors that are less scrupulous about their job, they're just kind of, you know, selling them over, like if they're at overseas vendor or it just wants to collect money and, and they're doing it for 10-K, a checkbox, whatever, I ask to see procedural and guideline documentation.

00:29:34 - 00:29:56 Patrick McKinney
Now just policies obviously very high level policy will tell you yes, we do these things but tell you how they do these things. So when I see guideline documentation or process documentation and I see that they've taken the time to actually draw on a process, I look to see when they created the process, because if I asked for it on August 1st and they wrote it up on July 31st, obviously they're doing their writing up something just to appease me.

00:29:56 - 00:30:10 Patrick McKinney
But if you look at it and say, oh, it was it was approved a year ago by the legal team and by the security team, and it's got the it's got what they're doing in place. I want to give them the benefit of the doubt without going into their, their tools that actually seeing reports. I'm not going to go through and do that.

00:30:10 - 00:30:29 Patrick McKinney
But I think the enhanced due diligence beyond the basic reporting, the basic policy checks is the place to do that and to try and get a good handle on that, obviously, to reputation. I mean, if you talk to people that have either worked at the company, you know, recommendations in this industry go a long way. You know, I didn't even know about EverOps till I came into Coinbase.

00:30:29 - 00:30:42 Patrick McKinney
And then when I heard about, you know, when I worked with the EverOps folks at Coinbase and saw how incredibly talented they were and how, you know, thoughtful they were and what they were doing, I don't have to go back and look for a sock to another company. When I go see them, I'm like, I know they're good.

00:30:42 - 00:30:57 Patrick McKinney
I'll go in. Yes, we'll still do the property diligence, but I know from experience or friends of mine that have worked with EverOps before and say, hey, you know, these guys are fantastic. We'll bring them in. That's why we brought them in to invisible as well, to, to help out with things, because that that goes a long way to.

00:30:57 - 00:31:04 Patrick McKinney
So there are a few channels you can go that aren't just looking at stock through reports to get comfort with who you're going to be working with.

00:31:04 - 00:31:19 Stephen Koza
Yeah, makes sense of sense. Thanks for the commercial, by the way. I, I always tell people, you know, the podcast isn't self-serving, but sometimes, sometimes this kind of thing comes up. And so I truly appreciate the kind words.

00:31:19 - 00:31:21 Patrick McKinney
When you do good work, you do good work.

00:31:21 - 00:31:45 Stephen Koza
So yeah, that's right. We definitely try to let's jump into leadership a little bit since we're we're starting to touch on it. You know, you've led a bunch of different teams across different companies. And one of the things I you've talked about is the stage or the moment when a company needs to shift from CTO, CTO, own security to a security professional owning security.

00:31:45 - 00:31:53 Stephen Koza
Like how do you know you're there? What does that look like? And what happens if a company, you know, waits too long to realize that?

00:31:53 - 00:32:13 Patrick McKinney
Yeah, I think there are a couple of indicators on the on the CTOs side or the head of it side that, you know, some companies will punt security to the from the beginning to, to the IT folks to handle before they bring the security professional. And I think a CTOs job is is the technology organization overall it is the engineering teams.

00:32:13 - 00:32:40 Patrick McKinney
It's the DevOps teams, the SRE, the QAS. And I think once their percentage of time spent on security becomes greater than 10% of their time. As a CTO, you need to start thinking about who you're bringing and doesn't mean have to hire a CSO. You could hire just a dedicated security generalist to come in and start, you know, doing compliance, engineering, privacy, all kind of, you know, get to that base 1.0 level.

00:32:40 - 00:33:02 Patrick McKinney
Same with like ahead of it. Head of its job is to is to operate and run an efficient IT team. The minute that security percentage goes greater than what they're comfortable with, it's time to start thinking about it. And I've worked with some phenomenal CTOs, I mean, world class leaders. And even they will tell me it just got too much for me to handle.

00:33:02 - 00:33:17 Patrick McKinney
So that's why we brought a consultant on it. So we brought in our first engineer. So we brought in a CSO. You know, when I came to invisible Adam Haney shout out to him, he's a phenomenal leader. Now over Infinity told me, hey, you know, it just got too much for the existing team to manage without a subject matter expert.

00:33:17 - 00:33:31 Patrick McKinney
And he was right. I mean, when I came in, there was a lot of work to do, and it gave me a full time job right away. Day one, which that means, you know, like, yeah, you probably waited a little too long, but even still like it, you got you got a person in, they started focusing on it.

00:33:31 - 00:33:39 Patrick McKinney
And we built out a lot of stuff very quickly. That was that was kind of at the 1.0 level, if you will. And then we progressively got to like the 2.0, 3.0.

00:33:39 - 00:34:00 Stephen Koza
Going back to our AI conversation for a minute, minute not not to not not to make everything about AI. But, you know, one of the one of the things I've been thinking about, and it's not just me, companies are able to leverage AI more and more. What does that mean for the people coming out of school today and the entry level folks?

00:34:00 - 00:34:30 Stephen Koza
I mean, you know, some of the stuff I did earlier in my career, AI can do all that and it can do it way better. And that's especially true in legal and, you know, maybe like accounting and the other like software development. So I think you spoke on a panel about this, if I'm not mistaken, about how AI is kind of changing the craft and what that means for building talent.

00:34:30 - 00:34:49 Patrick McKinney
Yeah, I was raised a little, little quick personal. I was raised by by a dad who basically told me not to rely on technology, which is ironic now that I work in technology. But my dad, my dad, I mean, he's a woodworker by hobby. He he gets, you know, he and he does things with his hands. He also has machines because he's like, what if the power goes out?

00:34:49 - 00:35:09 Patrick McKinney
You can't use the machines. You have to know how to do it by hand. And I think that's something I've always kind of taken with me as well, is like, learn the fundamentals, learn how to do the basics and understand the areas better. Yes, there are tools that are out there like that are going, you don't have to write a Hello World application anymore as a starter to learn coding.

00:35:09 - 00:35:27 Patrick McKinney
You can use AI to in the start, but you should know the fundamental underpinnings of why we program, why things are built that way, how to do them better. Because let's say something happens and like the AI pushes its own kill switch and now you still you still have power. You can still write your own things, but you don't have AI to do it.

00:35:27 - 00:35:49 Patrick McKinney
You need to be able to still continue these businesses. You need to be able to have those fail safes. So I do strongly. I mean, education is a fundamental underpinning of what we do in the world, whether it's, you know, cooking, whether it's programing, whether it's, you know, building anything, mechanical engineering, stuff like that. So understanding why things are the way they are is always going to be valuable.

00:35:49 - 00:36:11 Patrick McKinney
So I'm not suggesting people just go to college or spend their money on that. But but learn always educate yourself. I'm always educating myself. And I'm going to be 41 years old this year. With that being said, I do think that you need to also educate yourself about the AI that's out there and learn how to use it in a way that maximizes your productivity, while also not taking away from that fundamental education.

00:36:11 - 00:36:29 Patrick McKinney
So learn how to program, learn different languages, learn why different languages exist. Why aren't we doing everything in Java? Why does go exist? Why does rust exist? You know, there's there's more than one front end language. Understand the why and then move forward and build with the why. Because I do think that really gives you a better way to make decisions.

00:36:29 - 00:36:36 Patrick McKinney
Like you said, the human element is making decisions, and we need that to make the decisions and then use the AI to help get you there.

00:36:36 - 00:36:55 Stephen Koza
Yeah, if I think about my own experience. So, you know, I'm a business guy and, you know, my whole career has been on the business side, except for my first job, which was an engineering job because I studied engineering. But then I, you know, I kind of took the, you know, took the exit ramp or went down a different path pretty early in my career.

00:36:55 - 00:37:18 Stephen Koza
But because I have that technical foundation and it's it's very dusty. Now, just to be clear, you know, now what I'm, you know, I'm vibe coding something. I realize, oh my gosh, it's like really helpful that I actually have a base level understanding of what code does. And, you know, things are architected. And what is this list of files mean.

00:37:18 - 00:37:42 Stephen Koza
That's in my in my IDE. And you know, like, you know, it wants an environment variable. Oh, I actually know what a variable is because, you know, I had a code in like C++, you know, two decades ago. And so and so like that's my personal experience of what you're saying, which is it's really useful to understand, at least at a high level, what's happening under the hood.

00:37:42 - 00:38:02 Stephen Koza
Because otherwise, like, you know, if you're talking about software development, you know, just about any anybody you can go vibe code something. But it's also really easy to create something that you know is just a big pile. You know what? It doesn't work well and you don't know what's going on. And you let the AI do its thing and you have no idea what it's doing behind the scenes.

00:38:02 - 00:38:05 Stephen Koza
And like, that's been that's been really useful.

00:38:05 - 00:38:23 Patrick McKinney
I'd say vibe coding creates vulnerabilities. It creates quality issues like II is not right quality code. And if anybody says that it does, then they're 100% wrong. And I've seen I've seen the benchmarks. So understand like being able to make your code quality make your code secure because obviously oh I can just point a vulnerability tool at it.

00:38:23 - 00:38:31 Patrick McKinney
But we just said like they're not necessarily doing everything 100% correct. So you can't just keep pointing AI to solve problems.

00:38:31 - 00:38:52 Stephen Koza
Although it is it is it is kind of cool how that works because, you know, one one use case is, you know, somebody will code something with opus and then they point, you know, one of the GPT models at it and say, you know, give me a quality. And like the models don't always agree. And one model, like, finds a bunch of stuff that the other one didn't.

00:38:52 - 00:38:57 Patrick McKinney
And oh, look, we just we just engineered an office. We engineered people disagreeing.

00:38:58 - 00:39:21 Stephen Koza
Yeah. Yeah. Totally. So, you know, back to the leadership thing is, you know, as AI kind of changes people's day to day on your team instead of like, you know, some of the stuff they don't have to do, some of it becomes more important. How does that actually change people's work? And then how do you keep them? How do you keep them growing and engaged and productive?

00:39:21 - 00:39:28 Stephen Koza
When you know a big part of their day, they don't have to do it anymore. It's not their job anymore.

00:39:28 - 00:39:44 Patrick McKinney
I'm going to answer this a two ways. So one of the things that I believe companies are doing, whether they want to admit it or not, and this is not a bad thing, is we are starting we as the world and as companies are starting to grow leaner. You're not starting out with, okay, I have to build an engineering team.

00:39:44 - 00:40:03 Patrick McKinney
Let me go hire 30 engineers. Even if you're trying to get cheaper ones in different geo regions, you're not doing that anymore. You're saying, hey, let me go get a team of five, because a team of five, they can align faster, they can write code now faster, and they're doing that stuff faster. So I think with that it's you're you're having more people handle more things.

00:40:03 - 00:40:26 Patrick McKinney
Whereas you used to have an IT engineer just answer tickets. Now that engineers also learning systems, they're learning how to do the automation. They're going to build these things. And then with that comes the second part is like what's the next thing. I'll bring that back up. The foresight that that what's the next thing on the list. There's nobody especially I mean, dude, Salesforce has been around since I think 98.

00:40:26 - 00:40:43 Patrick McKinney
Like they've been around for a long time, and they still have ways to mature and grow programs and areas of their companies. Coinbase, same. Every company I've been to still has areas to mature. So the fact that companies have been around for 20, 30 years and they still have areas to mature in, that means that the job is never done.

00:40:43 - 00:41:02 Patrick McKinney
And so it's always what's the next thing? How do we think about this? And when the when the easy to find things that are that new mature need to be upgraded are, are getting smaller and smaller, it's like now let's bring in that complex thinking, you know, let's where are let's start looking at ways that we can test what we've built so far.

00:41:02 - 00:41:26 Patrick McKinney
Let's look at ways that we can challenge it in pen, test it if you will, or red team it the our privacy program, our our compliance program, our reliability program. Let's introduce chaos engineering. Let's do all these different things that we're not doing to become the best that we can. And I think the people that will thrive the most in an AI centric world are going to be those people that look to the next thing they look to.

00:41:26 - 00:41:40 Patrick McKinney
How do we make it the best of the best? Not ever achieving perfection because we never will. There will always be something else that comes along. But but striving for that and trying to find the next thing to improve your area that you oversee will. There will always be something there.

00:41:40 - 00:41:59 Stephen Koza
Yeah, that's I mean that's great career advice on top of everything else. Speaking of, to kind of wrap things up here as a security leader, what do you think one of the most underrated skills is? What's what's served you really well? If you were given advice to people who are earlier in their career.

00:42:00 - 00:42:12 Patrick McKinney
The one that I give everybody is is soft skills and networking. Like those those go that's not a security gets everybody you need. You need to be able to talk to humans. People need to want to work with you. They want to have I mean, they don't have to like you, but they want to work with you because they respect you.

00:42:12 - 00:42:33 Patrick McKinney
So, so have those build those soft skills, understand all that. And from a security world, I would say as much as people complain and say the CIS certification is useless because it's a breadth of knowledge, not a depth of knowledge. Learn the breadth of knowledge, understand data center security. Even if you're not working in data centers like you should still understand these things.

00:42:34 - 00:42:56 Patrick McKinney
Physical security. But if you're not a physical security expert cloud, learn everything because some of this stuff will tie together camera systems. Now they're being controlled by AI. They will tie together back into your cloud infrastructure. That's securing the data that's going in there. So these things will all tie together at some point in your career. So it never hurts to learn the breadth of knowledge before you go into the depth of knowledge.

00:42:56 - 00:43:21 Stephen Koza
Yeah, that's a good one. And then I'll I'll second your soft skills comment. My answer is usually sales. And I don't mean like, you know, you got to know how to close a deal. I mean the skills behind sales, like hopefully everybody, you know had a lemonade stand at some point or, you know, they did a door to door sales job and they're in college or something.

00:43:21 - 00:43:41 Stephen Koza
And if you're in college and you haven't, you should go do that because sales fundamentally teaches you the soft stuff. How do you communicate? Well, how can you clearly explain something in a way that the person across the table understands and gets it? And, you know, how can you connect with somebody and you know, it helps you with interpersonal stuff.

00:43:41 - 00:43:52 Stephen Koza
And I think that's probably underrated and maybe not known or valued enough by, you know, generally speaking, by a lot of people who are coming into the technical fields.

00:43:52 - 00:43:54 Patrick McKinney
Yeah, I agree with you 100%.

00:43:54 - 00:44:00 Stephen Koza
Yeah. You're I don't know if you had sales jobs or not, but you you picked us. Yeah. You picked up those skills somewhere. I can tell.

00:44:00 - 00:44:17 Patrick McKinney
I did. I had a I had a couple sales job. I worked retail actually as my first high school job. I worked at like GameStop and Best Buy and and all those. And over summer breaks in college, I would go get jobs, came and speak jobs in malls and working like malls and just see people interact with people.

00:44:17 - 00:44:33 Patrick McKinney
And I think, you know, I say it all the time to people. It's kind of like it's a joke, one liner. But like in an age of AI, humans still matter the most. So humanity is a thing. We have to take care of each other. We have to work with each other. We have to, you know, we have to be humans.

00:44:33 - 00:44:34 Patrick McKinney
So.

00:44:34 - 00:44:47 Stephen Koza
Yeah. Well, and and all that, all of a sudden that stuff is now even more important because that's, that's the that's the differentiator. That's the thing that sets you apart. You know, being able to write a lot of code is unfortunately not that thing anymore.

00:44:47 - 00:44:49 Patrick McKinney
Right, exactly. Yeah.

00:44:49 - 00:45:19 Stephen Koza
Well, cool. Patrick, man, it's been fun. Yeah. Appreciate you coming on. I learned a ton and appreciate you sharing everything. I think our listeners will probably appreciate it. So for everybody listening, if you enjoyed it, if you got something out of it, please subscribe, review, follow whatever the button is and it helps us with our reach. We're on Spotify and YouTube and Apple and probably a bunch of other spots that I don't know about, but maybe my mom found me on.

00:45:19 - 00:45:26 Stephen Koza
I'm. I'm Stephen Koza, I'm the CEO of ops, and this has been Tech Pod talks. And we'll see you next time.

Become a Guest
ABOUT THE PODCAST
Honest Conversations. Hard-Won Lessons.

TechPod Talks is a podcast from EverOps featuring candid conversations with the leaders behind the platforms. Each episode dives into topics like leadership, AI, cost efficiency, and what it actually takes to build and scale in tech. No scripts. No fluff. Just real conversations with people who've been in the trenches.

Have a story worth sharing? We're always looking for tech leaders, founders, and operators with real-world experience to join the show. Tell us about yourself and we'll be in touch.