all things cyber episode

1

Building the security tool we wished we had

A CISO and an engineer, years apart, now building what neither had when they needed it.

Tim Grieveson

Hi, I'm Tim Grieveson, Chief Security Officer at ThingsRecon.

Stephane Konarkowski

And I'm Stephane Konarkowski, Chief Product Officer at ThingsRecon.

Tim Grieveson

Steph, we've known each other for a long time, and this is the first time we've actually sat down to talk about supply chain security, cyber risk, and attack surface management. Thanks for joining me.

We've known each other for, what, 18 years?

Stephane Konarkowski

Something like that. A long time. You were actually my customer back then, although neither of us knew where that relationship would eventually lead.

I remember visiting your office to talk about vulnerability management. We arrived without many expectations, but instead of jumping straight into our presentation, we spent time listening to you.

You explained how your organization worked, the challenges you were facing, and what you were trying to achieve. Once we understood that, we completely changed the way we presented our solution.

That conversation shaped everything that followed.

Tim Grieveson

It certainly did. One thing that stood out was how different your approach was from every other vendor I met that day.

You were probably the sixth vendor through the door, and by that point I was exhausted. Most vendors spent hours talking about themselves, their products, and their features.

Your team did the opposite. You took the time to understand what I needed first, and only then explained how your technology could help solve those specific challenges. That customer-first approach really stayed with me.

One thing I've noticed throughout my career is how much the role of the CISO has evolved. It's no longer purely technical.

Today I often joke that I'm also the Chief Storytelling Officer, the Chief Marketing Officer, and sometimes even the Chief Finance Officer. The role now requires leadership across the entire organization.

From your perspective, how has the relationship between technology vendors and CISOs changed over that time?

Stephane Konarkowski

For us, everything starts with understanding how we can genuinely help the CISO.

A big part of your role is convincing the rest of the organization why security matters and why investment is needed. You're constantly making the business case for security.

That changes how we think about our own role.

Instead of asking how our technology helps only the security team, we ask how it helps the wider organization. How can we provide information that's valuable not only for security, but also for the people making business decisions?

Tim Grieveson

That's exactly the challenge.

Security leaders today are expected to deliver more, move faster, and do it all with fewer resources.

At the same time, regulations are evolving, threat actors are becoming more sophisticated, and organizations continue to grow more complex.

One of the biggest challenges throughout my career has been having enough context to build a convincing business case.

How do I gather the right information, with enough depth and breadth, to explain why security deserves investment?

Stephane Konarkowski

I think the key word there is depth. A few years ago, conversations focused on inventories and CMDBs. Today that isn't enough.

We're no longer talking about the surface. We're talking about understanding the depth of an organization's digital ecosystem, everything that's connected to it, and everything that exists beyond what traditional inventories can see.

Looking from the outside, it's clear that organizations have become far more interconnected than they realize.

So let me ask you: as a CISO, how do you deal with that level of complexity?

Tim Grieveson

One of the biggest challenges I see across large organizations is technical debt.

Companies acquire other businesses, inherit systems that never get fully integrated, and accumulate years of technology that nobody completely understands.

Then there's Shadow IT.

Interestingly, I don't see Shadow IT as purely a bad thing. In fact, I think it's often a sign that the business is innovating.

People are finding new ways to work, adopting new tools, experimenting with AI and automation, and trying to become more productive.

The challenge for security isn't to stop that innovation. It's understanding where those technologies are, how they've changed over time, and whether they've become business-critical without ever going through the normal governance process.

Anything a technology partner can do to improve that visibility is incredibly valuable.

Stephane Konarkowski

I don't even like calling them assets anymore.

I just call them things.

There are simply too many of them now, and each one serves a different purpose depending on how it's being used within the organization.

When you step back and look at everything that's connected, it's astonishing how much exists. The level of interconnection has become incredibly complex.

Sometimes I wonder whether organizations are simply overwhelmed by it all. Other times I think people avoid looking too closely because they're worried about what they'll discover.

Tim Grieveson

But isn't that a little dangerous?

Ignoring vulnerabilities or unknown technology doesn't make the risk disappear.

Whether we know about it or not, the exposure is still there.

So how do we change that mindset across the industry?

Stephane Konarkowski

It starts with helping people understand those things in context.

Finding an exposed asset isn't enough. You have to explain what it means for the organization.

That's why we think about different audiences.

A CISO needs information presented one way because they're communicating with executives and the board. An analyst needs a completely different level of detail because they're responsible for remediation.

The information may come from the same source, but the way it's communicated has to match the person using it.

Tim Grieveson

And then you have the growing list of regulations.

Whether it's the SEC, DORA, NIS2, or other compliance frameworks, organizations are trying to understand how all of these findings relate to regulatory requirements.

Is that something ThingsRecon is working towards?

Stephane Konarkowski

Definitely.

One of our goals is to map technical findings to regulatory frameworks so organizations can better understand their level of readiness.

Compliance is only becoming more important, so helping customers understand where they stand against those frameworks is a natural extension of what we're already doing.

But let me ask you something.

You've spent many years leading security organizations. How has the day-to-day life of a CISO changed compared to when you first started?

Tim Grieveson

It's changed dramatically.

When I started my career, the role was almost entirely about technology. The focus was on tools, infrastructure, and technical controls.

Today, technology is only part of the job.

Most of my time is spent collaborating with people across the business. I work closely with legal, finance, marketing, procurement, HR, and IT.

Where a CISO sits in the organizational structure isn't actually that important. Whether you report to the CIO or the CFO, your real responsibility is enabling conversations across the business.

That's something I genuinely enjoy about the role.

Security leaders often have one of the broadest perspectives in an organization. We see processes, suppliers, regulations, technology, people, and business operations all at once.

Because of that, we have to become much better communicators.

We need to understand finance. We need to understand vendor management. We need to speak the language of business.

One phrase I've never liked is "the business," as if security somehow exists outside of it.

Nobody talks about HR or Finance as being separate from the business, yet security is often treated that way.

In reality, security is part of the business.

Our role is to explain risk in terms the organization understands: business growth, profitability, operational impact, and strategic outcomes.

That's what makes an effective security leader today, not simply being the most technical person in the room.

Stephane Konarkowski

You mentioned suppliers earlier.

Organizations are becoming increasingly connected to their suppliers from a digital perspective, and we're seeing more supply chain attacks every year.

Is there a single solution to that problem? What should organizations actually be doing?

Tim Grieveson

I don't think there's a single solution that fits every organization.

For years, the standard approach was to send suppliers a questionnaire and ask whether they were secure. The problem is that those questionnaires are often completed by someone in sales or procurement rather than the people responsible for security.

Questionnaires still have value, but they need to be verified against what's actually happening in the real world.

More importantly, organizations don't always know who all of their suppliers are.

If there's a way to map suppliers, understand how they're connected, and see how close they are to the parts of the business that matter most, you've already made a huge step forward.

I also think we've spent too much time focusing purely on vulnerabilities.

Vendors often tell me they can show every vulnerability across my environment, but that alone isn't particularly useful.

Just because a vulnerability exists doesn't mean it's exploitable.

And even if it is exploitable, that doesn't automatically mean it's important to my business today.

What really matters is context.

I want to understand the relationships between systems, the data flowing through them, the geopolitical environment surrounding a supplier, and even their financial stability.

A supplier that's financially struggling may present a very different level of operational and cyber risk than one that's stable.

Security isn't just about technical vulnerabilities anymore. It's about understanding everything that could affect the resilience of your business.

Stephane Konarkowski

Exactly. Those factors don't just matter to the security team. They matter to procurement, legal, finance, and everyone else involved in managing supplier relationships.

That's why we need to provide information that supports decisions across the organization, not just within cybersecurity.

Tim Grieveson

That's one of the biggest opportunities for security leaders.

When I can bring that broader context into conversations with procurement, finance, or legal, security stops being seen as a cost center. It becomes something that helps the business make better decisions. I've experienced that many times.

Take COVID as an example. Overnight, organizations had to support remote working. That accelerated initiatives like multi-factor authentication, endpoint visibility, patch management, and understanding what assets employees were actually using.

Then we saw geopolitical events like the war in Ukraine, where organizations suddenly had to reconsider suppliers, regulations, and operations in certain regions. Those events helped accelerate security programs that were already needed. They also created opportunities to engage departments outside security and secure funding that otherwise wouldn't have been available.

Stephane Konarkowski

But why do we always wait for those events? Why does something bad have to happen before organizations invest?

Tim Grieveson

Exactly. We shouldn't. Those events are useful because they accelerate change, but resilience shouldn't depend on reacting to a crisis.

It should become part of everyday decision-making. Every time we assess a supplier or review part of our technology landscape, we should already be thinking about resilience, not waiting until an incident forces the conversation.

Stephane Konarkowski

It often feels like organizations only receive budget after something has gone wrong. Instead of preventing problems, we're constantly reacting to them.

Tim Grieveson

Historically, security has been very incident-driven. I think we need to shift towards what I call events of interest.

Organizations should continuously monitor the events happening around them and use those signals to reassess risk before they become incidents.

Take the large power outage in Spain and Portugal as an example. It wasn't a cyberattack, but it prompted organizations to ask important questions. How resilient are we? What does our cyber hygiene actually look like? Have we tested our recovery plans? Have we run realistic scenarios? Those questions often reveal gaps that would otherwise remain hidden.

Preparation isn't just about responding to incidents. It's about understanding the assets, the relationships between them, and the value they bring to the organization before something goes wrong.

Stephane Konarkowski

That's where proximity becomes important. The suppliers closest to your organization, the ones most deeply connected to your critical systems, will have the fastest and greatest impact if something happens.

The closer that relationship is, the smaller the distance between an incident affecting your supplier and an incident affecting your own organization.

Understanding those relationships allows you to prioritize the risks that truly matter.

Stephane Konarkowski

When we talk about all these events, the growing complexity of technology, and the rapid adoption of AI, how do you see organizations adapting?

As vendors, we have to evolve because attackers are already using AI. How do you think the industry should respond?

Tim Grieveson

Attackers have embraced AI remarkably quickly. They're using it to develop malware faster, automate attacks, create highly convincing phishing campaigns, and personalize social engineering at a scale we've never seen before.

As an industry, I don't think vendors should be adding AI simply because it's fashionable or because it's something they can market. The real opportunity is using AI to enrich information, improve visibility, and make data more useful for customers.

AI can also play a huge role internally. It can accelerate product training, help customers understand new capabilities, support onboarding, and automate many of the repetitive activities that previously required large teams.

As organizations grow, AI allows people to scale their expertise much more effectively.

Stephane Konarkowski

You mentioned something earlier that I found interesting: continuous monitoring. The more we talk about it, the more I think in terms of continuous events of interest rather than continuous scanning.

Is that really what continuous security should become? Watching for meaningful events, deciding what needs to be prioritized, and then responding based on the business context?

Tim Grieveson

Exactly. The environment is no longer static. Technology changes constantly, suppliers change, business priorities change, and threats evolve every day.

Continuous security isn't simply about collecting more data. It's about continuously identifying the events that matter, understanding their impact, and deciding where to focus your attention.

That's a very different mindset from periodically producing reports and hoping nothing has changed before the next assessment.

Stephane Konarkowski

Which brings us back to the role of the CISO. The environment has become much deeper and much more interconnected than when we first met. That means vendors like us also need to change. We have to spend more time listening.

We need to understand how the role of the CISO has evolved so we can build products that help communicate risk to the rest of the organization, rather than simply producing technical reports.

Tim Grieveson

That's exactly right. People sometimes joke that I'm more of a Chief Storytelling Officer than a Chief Security Officer. A huge part of my role is telling stories.

I have to explain cyber risk to executives, investors, auditors, customers, regulators, and boards, all in ways that are meaningful to each of them. Every audience needs a different conversation, but the objective is always the same: helping people understand business risk.

Choosing the right technology partner is just as important. A good partner doesn't simply sell software and disappear. They listen. They evolve alongside their customers. One of the things I've always valued most is co-creation.

I enjoy participating in customer advisory boards because they give me the opportunity to influence the direction of a product. When vendors genuinely listen to customers and incorporate that feedback into their roadmap, everybody benefits.

Customers receive products that solve real problems, and vendors build solutions that are far more relevant to the market. That's how lasting partnerships are created.

Stephane Konarkowski

Exactly. You can't bury your head in the sand. You have to stay engaged, understand what's happening around you, and keep learning. That's how both customers and vendors continue to improve.

Tim Grieveson

Steph, we could probably talk about this for hours. Thanks for joining me today.

This is the first episode in what we hope will become a series of conversations about cyber, supply chain security, and the challenges facing modern organizations. If you'd like to join us on a future episode, we'd love to hear from you. Reach out to the ThingsRecon marketing team.

Thanks for listening, and we'll see you next time.

Stephane Konarkowski

Thanks, Tim. Looking forward to the next one.

Thank you! You are now susbribed to The Recon Log
Oops! Something went wrong while submitting the form.