Welcome to Cybersecurity Unplugged, the CyberTheory podcast where we explore issues that matter in the world of cybersecurity. Good day, everyone. This is Steve King, the Managing Director at CyberTheory. Today's podcast episode is going to feature Patricia Moyle, who is a partner at SignWave Ventures in New York City.
That's an early stage venture capital firm that's dedicated to helping new technology companies grow across the commercial and public sectors. Pat's been a partner at SignWave for eight years and spent 13 years running R&D for the Department of Defense with a big team of 100 researchers and a lot of different interdisciplinary efforts that hopefully enable national security customers to operate safely in compromised environments. So she's an expert and has been providing strategic direction for secure wireless and resilient systems and trustworthy computing and security science and cryptography. So in addition to earning her undergraduate degree from Fordham, she went on and got a PhD from Yale.
So welcome, Pat. I'm glad you were able to join us today. Great. Thanks for having me.
Yeah, so let's jump right in here. And before we do anything, can you give our listeners a little background on SignWave and, you know, the work that you guys have been doing and what this year has looked like so far for you guys? Sure. So as you had mentioned, SignWave is an early stage venture firm dealing with helping companies get into the commercial and government sector.
And what we concentrate on are computing, analytic and cybersecurity companies that, you know, really help agencies and industries that haven't been traditionally information driven, use information safely and effectively to influence business and policy decisions. So we have a small size, but I think mighty impact portfolio of companies in those three general areas. In terms of cybersecurity, we've always had an attack agnostic kind of approach. So we don't really invest in companies that aim to, you know, address this particular attack vector or this particular way of getting into your system, but rather to look for sort of broad-based technologies that enable you to face a variety of threats and remain resilient in the face of known and unknown challenges.
Our investment size is three to five million typically, and we always invest with the consortium of others trying to build a set of investors that really can help the company survive. In the later rounds or early rounds? Early rounds. A is our favorite.
We do do some seeds and we do do some Bs. And in the companies that we invest in, we will do follow on if we like where the company is going, but we don't commit to following on, you know, each round we assess them anew. Yeah, no particular market emphasis within cybersecurity? No, I have a particular interest in some of the new zero trust stuff that's emerging.
I think the new challenges are at the application layer and at the identification and authentication part of the system. So we try to be strategic in the parts of the system that we're looking to to find technologies to fit because we're attack agnostic. Obviously, we're not big into threat identification systems or stuff like that. Yeah, right.
I mean, that makes sense to me anyway. I think that companies that approach it from an attack point of view, it seems very tempered. It's just like, OK, that's great for the first the next six, 10, 12 months or something. But what happens when the next attack vector occurs?
That's right. And you get just caught up in this game of whack-a-mole you can't win. And so there's no reason to keep trying to win that way when there are other better ways. Yeah.
You have a sort of philosophy about getting companies to think more about cyber resilience than cybersecurity. What do you mean by that? So traditionally, particularly with people who have a sort of attack based approaches to cybersecurity, there's always been this tension that you invest in security at the expense of business objectives. Right.
You may have to limit what people can do. They may need complicated login procedures. There's always this war between security capabilities and what needs to get done with the notion of cyber resilience. The idea is that the cybersecurity technologies actually help your company survive in normal operating conditions, but in conditions where things go wrong, whether that be attack or a power outage or a hurricane.
The idea is to continue to know enough about your system and to put controls in place so that you can continue operating at least your critical functions and have the wherewithal to quickly build back any of the functions that had to be sort of downgraded because of the problematic period you were in. Yeah. And, you know, so we approached cybersecurity in different ways. But if you look across the spectrum, I think there's a mindset around, you know, what we do when we fight a war.
You know, our experience is, you know, we we military up, we head off into, you know, country A and we, you know, conquer them and then we come back and the war is over. That's never been true, nor will it ever be true with cybersecurity. So it's really more like a like a police action around crime. Right.
I mean, you know, so the assumption should be that there will always be criminals. There are like four or five main things that we worry about, you know, homicide and armed robbery and burglary and et cetera. You know, we're going to focus on trying to manage those into a, you know, into a resilient model, I guess. Is that kind of, is that kind of what the mindset is?
Yeah. And I think your point on the war metaphor is extremely well taken. And I personally think the war metaphor has held back the cybersecurity industry for years. The contrasting metaphor that I like to use is health.
And it'll be, you know, there's always going to be a disease. And particularly in the time of COVID, I guess this has become a less clear metaphor than it used to be. But, you know, there's always going to be disease, but you wash your hands and you take your vitamins and you eat good food. And when you do get sick, you have drugs that help you get better quickly.
But you don't expect that germs are going to be eradicated from the face of the earth, just like you don't expect cyber threats are going to completely disappear. What you want to do is make sure you are not impacted by any of those germs in a way that you can survive. And similarly, you want to make sure you're not impacted by any cyber action in a way that you can't recover from. I agree.
Good analogy. And speaking of sort of the eternal fight here, I wrote a book that is in the process of being published this week. And my publisher insisted on calling it Losing the Cyber War. It's focused on five different theaters of war.
And, you know, my thesis is that we're losing in each one of those. But I offer recommendations for how we can avoid avoid that and get out of it. You know, so we spent, what, 150 billion, I think, in 21. And we're probably gonna spend about 150 ish in 22 on cybersecurity.
And yet the only correlation between what we spend and the attacks or the number of breaches is that they both go up. If you dropped in from Mars, you'd conclude that our funding is actually increasing the number of cyber attacks that we have to deal with. Are we doomed or what? We are not doomed.
And I think we are doomed when we invest in things that solve the wrong problem. Right. And so we do a lot of investments. So, for example, there are many, many, many threat tracking technologies.
And it's important that security companies understand how the threats are evolving, where they are, what they are. It's important that governments understand that and so on. So in both cases, you can build defenses, you can do research, you can figure out new and innovative ways to address attacks in general. But here I am, you know, small and medium business like threat tracking thing.
I have not a single knob in my system that I can turn if I know a particular threat is in my area to make my system safer. All it does is tell me, oh, you can worry now, which in general, you'd be worried anyhow. If you had a capability, you would have already deployed it in all cases. You're not going to just turn it on when threat X is in the environment.
So there's this whole lot of investment in protecting, you know, as I said before, the individual attack or an understanding a threat environment that you then have no capability to do anything about. There's a lot of tools that analyze your system and alert a gazillion times and tell you you have this vulnerability and that vulnerability, but not in a way that enables you to do something about it in real time or to do something about it even in longtime. And so that whole mode of chasing after the attacker gives the attack an advantage and the attacker will ultimately win if that's the mode of defense we do. There's a different kind of defense, though, that I think is way more effective and involves basically shaping the game board.
Right. If the attacker is coming into an environment that you have set up for you to win and for them to lose, the likelihood of the attacker succeeding becomes significantly smaller. So to give an example of that, there's a whole lot of technology emerging now in the area of micro segmentation, which says, all right, we are going to carefully control who in what system can talk to, you know, what other assets in the system and, you know, how logically lay out the network according to the business rules so that only legitimate types of interactions can happen. So if an attacker comes in as, you know, they do a phishing and they come in as me, average person, they'll only be able to get to those parts of the system, which me, average person could get to.
And that would not include the privileged spots that they would need to really execute their payloads. And so if Unfortunately, it's difficult to afford right now, but I do think the paradigms do change over time to get to better places. Right. Okay, let me ask you, from my view, so I was a CISO six years ago, and my world six years ago was very, very simple compared to the technology map, if you will, of today's world.
And I'm pretty sure that I was working 12 hours a day six years ago. So I look at the current complexity of the environment from a CISO point of view, and I'm pretty convinced that none of the folks I know who run these things for a living have a, let me be generous, a safe understanding of or an effective understanding of the technology that they're overseeing, or how to implement it properly, or what the standards should look like, or anything about the adjacent impacts of rolling out another layer or a new cloud, hybrid cloud instance that's going to be built around Kubernetes containers, which I think if I asked, you know, 10 folks that I know to, you know, who understands and can explain Kubernetes, I'm not going to see a show of hands, period. So from my point of view, the complexity is kind of killing us, but also there's this unwillingness to say, to raise your hand and say, Hey, you know what? You want me to do this stuff, but I don't understand anything that we're doing, but digital transformation keeps pushing me because you keep saying, you know, serve the business units, you know, what does the CISO do?
Well, I think there was, is a recognition of the importance of the role of the CISO that over time moved the CISO role up to a, you know, a C-suite kind of role, removed the CISO from the groups that were actually writing the software, implementing the network, managing the IT system and put them in charge of their security fiefdom, which was divorced from the executing parts of the company. I understand, you know, that this was done in a well-meant intention of giving security the consideration it deserves, but I think the unwanted side effect was it is that it really reduced the effectiveness of security solutions. The decisions were made by people who were not the people who were implementing the IT system, and there was, you know, back and forth about, you know, what security is doing to me now, rather than how can security help me implement this network in a way that's going to work for the company in a safer way. Similarly, developers, often they were code audits at the end of a process that only slowed them down.
And so the security guys weren't seen as people who help them build better code, but as guys who got in the way of their delivery dates. And I think that that separation of the security function from the software and hardware development and execution function is truly problematic and does need to change. Or the decisions will be made without a full understanding, as you said, of the concerns of the business of what needs to be done, of what these technologies really do, how they interact and so on. So I think it really is worth rethinking the structure of the CISO role and perhaps embedding more of it in the places where the system is implemented.
The other thing about complexity, I do think that there's not enough understanding of security architecture as opposed to security solutions and security orchestration. And I don't know how to make that a more central part of the CISO's toolbox, but it's really, really important to pick your solutions in an architected way, to know how they interact, to know whether they're helping each other or hurting each other, to understand their performance impact when used together and all sorts of things like that. I actually haven't looked at too many school curricula or anything like that these days, but I would think that there needs to be an increased emphasis as people are being educated and trained in the importance of architecting solutions rather than just deploying them. Yeah, everything you said is spot on.
One of the things that I do for ISMG is I run the thing called the CyberEd.io initiative, which is an online education platform. There's no paucity of those, and there must be 70 competitors in that space, but we're different and we're different because we've looked at it from a learning path point of view and built coursework within multiple learning paths that relate to the specific roles that are in the real world. And from a point of view of a practical way, if you will, to allocate responsibility, you know, tied loosely to the NIST framework. And we have a pretty strong emphasis on zero trust because we're, you know, I think one of the original proponents of zero trust in the market.
And you had described in the answer to our last question, I think, basically a zero trust approach when you're talking about micro segmentation and so forth. And so the answer to the question, you know, you just suggested is from my point of view, since I couldn't find you a CISO who could tell me or you what the topology of his network is or her network is today, why don't we just rip it all out and start over, right? Why don't we start over with a zero trust strategy and a zero trust reference architecture and then build to the business requirement from that point forward? Yeah, I mean, if we could pause time to get things right and then start over, that would be a fabulous idea.
I think, I mean, this is a company where we're considering for investment now at Sinwave. That is a zero trust micro segmentation company. And their approach to this, which I happen to love, is that the system is what it is. So the zero trust technology has to bear the burden of learning what the system is, not by asking people, but by querying the system and then can lay out the policies given this understanding of what the system is and what the business rules are that do come from people.
And I think there's something to be said. And again, this goes with the theme of resilience a little bit. And technology's understanding that they're not delivering into a blank slate world and figuring out how they can accommodate the existing mess and still add their value to provide a reasonable solution. It does, you know, it does make the development of the technology harder.
But I think that's a very, very responsible way to do your design of novel tech is to recognize the world you're delivering into it and not assume that it has the characteristics you need for your solution to be viable. Yeah, absolutely. And I'm conscious of the time, Pat. So maybe our final question here might deal with the connection between your current business, the VC investment model, cybersecurity as a market, and then the government's role, if you will, having spent, you know, 13 years with the Department of Defense.
You have, I'm sure, a rich appreciation for the realities of government. And what do you think? Yeah, so I think the government has some important roles to play in the cybersecurity marketplace. I think the government should be the source of guidance.
And, you know, you mentioned this framework earlier. I think that's probably the most recent source of guidance. The executive order on that goal is zero trust is another important one. Where I think the government has fallen a little short is that guidance is not as accessible and implementable as many enterprises need it to be.
And it's good reason for that. You know, the government has these fairness requirements. They can't pick a technology. They can't pick a company as a winner.
And so necessarily that makes the descriptions of this guidance be so high level. That's hard for people to get their heads around. And so I think trying to figure out a way that you can actually make this advice more actionable while still maintaining the need for fairness and not to stifle innovation by picking a solution when a new one might be better later or down the road. So I think that that has got to be thought through by the government making the advice more actionable or perhaps some other organizations like your own providing interpretations that people can get their heads around.
There is another big role that the government plays forensically. There's a big role the government plays in understanding the attack space, particularly for advanced persistent threats. And all of these roles are important to inform what I think is the commercial space is going to solve this problem for American companies and for all companies and and agencies. I don't think this is something where the government can invent particular solutions and deploy them out.
We actually, when I was at the agency doing research, we needed to work through commercial partners to get solutions into the mainstream without, you know, mandating solutions. So I think the government is in some ways hampered by its own rules. I think the government people are extremely smart, though. And if we can figure out a way to get their idea space translated into the implementation space of the commercial world, I think that's important.
That's part of, you know, what we're trying to do in sine wave, too, is build these bridges between the government thinking and the commercial implementation that helps companies be successful. Yeah, sure. Second part of that question before we close in the last 20 years, what job or what role gave you the most satisfaction? So my last job at the government was heading up the trusted systems research group, which was the cybersecurity or information assurance research group.
And I am convinced that is the best job in the government. The problem space is fabulous. The people are brilliant and hardworking. The creativity level is high.
And I just loved it. You know, it was the kind of job where as an executive, you could actually execute by brainstorming, right? It wasn't one of these things, you know, very rule-based, being counting kind of a job. So that was by far my favorite job.
And, yeah, I mean, not counting sine wave, it's just a completely different beast. I was assuming you meant of my government jobs. Yeah, yeah. Well, of any of those jobs.
I mean