This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon talks to John Carse is the Field CISO at SquareX and a seasoned cybersecurity leader with over 20 years of experience spanning the U.S. Navy, JPMorgan, Expedia, Dyson, and Rakuten. With a background in securing critical naval systems during his 14 years in the Navy, John has since built and led global security programs across finance, tech, and e-commerce. He holds multiple cloud security patents and is currently helping develop the industry’s first Browser Detection and Response (BDR) solution. With hands-on expertise and a global perspective from roles in the U.S., Japan, Singapore, Bahrain, and Europe, John is passionate about tackling emerging threats and sharing real-world insights that blend innovation with practical defense.
Chapter Titles
00:00 Introduction
03:00 Protecting Intellectual Property
10:37 Understand the business, then look at the controls
14:18 How different is cybersecurity across the country
22:16 Browser Detection Response
32:19 Does BDR replace other tools?
36:10 What about virtual environments?
39:30 More from John
Audio
Important Links
Transcript
Manoj Tandon: Hello everyone! Welcome to another episode of Dark Rhiino Security—Security Confidential. This is your host, Manoj Tandon. We’ve got a fantastic guest today, but first, please hit like and subscribe so we can keep bringing you great content and guests. Without further ado, joining us from Texas is John Carse. You may remember Vivek from SquareX a few episodes back—John is with SquareX too. He’s a field CISO with 20 years in cyber, having worked with names like the U.S. Navy, JPMorgan, Expedia, and Dyson. He’s built global security programs and is now developing the industry’s first browser detection and response solution. John, thanks for joining us.
John Carse: Thanks, Manoj—great to be here. Quick intro: I actually started in IT before moving into cyber. I spent a lot of time with the U.S. Navy securing systems, which gave me a strong foundation before industry roles at JPMorgan Chase, Rakuten Mobile and Rakuten Symphony as CISO, and most recently Dyson, before joining SquareX.
Manoj Tandon: I have to ask a side question: is Dyson really that good, or is it great marketing?
John Carse: Dyson makes some excellent products. One of my favorites was the “Big+Quiet” purifier fan I had in Singapore. It pulled air from the room, cleaned it, and pushed it back, with telemetry that was catnip for a data nerd. Their small turbine design shows up across products—vacuums, fans, hair dryers—and it’s impressively engineered. Like any company, there are tradeoffs; for example, the robot vacuum had strong suction but battery-life challenges. My wife wasn’t thrilled about that, but loved the hair dryer, vacuums, and fans.
Manoj Tandon: My “brand my wife cared about” client was Godiva—walking into the plant in the morning smelled amazing. Back to Dyson: given your CISO role, I assume protecting intellectual property was paramount, especially with contract manufacturing in the Far East?
John Carse: Absolutely. My cybersecurity strategy’s top objective was “keep Dyson’s secrets secret.” That meant protecting IP from insider risk and third parties like contract manufacturers. Dyson often innovates in overlooked categories; the Supersonic hair dryer is a great example. Keeping that under wraps until launch mattered. Controls spanned cyber and physical security, with strong identity practices (SSO/MFA/IDP), digital rights management to control documents outside our perimeter (no print, no screenshots, etc.), and hardening and monitoring of engineering environments. In labs, you’ll see Arduinos, Raspberry Pis, and assorted hardware—so you need clear policies, OS-level controls (e.g., USB/Bluetooth restrictions), and visibility into what enters and leaves those networks. We modeled ~144 distinct threat/use cases and tuned protections to real engineering workflows. The key is letting engineers work while ensuring you can investigate anomalies quickly.
Manoj Tandon: What stands out is how grounded your controls are in the business. Many practitioners skip that step.
John Carse: The business sets strategy and a go-to-market plan; technology delivers it; cybersecurity then protects it. You can call yourself “security first,” but in reality you need to understand how value is created before you can secure it. I’ll say “no” when needed, but I prefer “no, and here’s an alternative.” I’m a technical, threat-driven CISO. If I can influence choices—languages, OS, platforms—for better security, I will. But large organizations get complex fast: hundreds of business units and stacks. Start with the business, understand the value chain and tech approach, then apply a cyber strategy that fits.
Manoj Tandon: Do you see cultural differences between Eastern and Western companies in how they view cyber—impediment vs. enabler?
John Carse: Generally, yes. In Western tech firms, teams will debate every control to be sure it’s necessary. In Japan and Singapore, we’d align on a checklist through consensus before going to the ultimate decision-maker; once agreed, execution was disciplined. That consensus model means people understand the risks and tradeoffs earlier. Regardless of region, if a security step demonstrably slows delivery, expect pushback. That’s where the Theory of Constraints (from The Goal) is useful: security should increase throughput and quality, including security quality. If a control doesn’t measurably help, adjust it. Also, cyber teams should implement controls that are easy to adopt and explain. We often cite raw vulnerability counts, but likelihood and context matter—compensating controls, platform applicability, exposure paths—so we should bring facts into risk discussions.
Manoj Tandon: In your current role you’re focused on BDR. What is it, and why prioritize it?
John Carse: BDR—Browser Detection and Response—is about instrumenting the browser so you can see activity inside it and take action, similar to how EDR works at the OS level. As more of work moves to SaaS, a huge amount of risk and loss sits in the browser: phishing, credential misuse, copy/paste of sensitive data, uploading to AI tools, personal drives, and more. Traditional stacks—CASB, SWG, DLP, EDR—help, but they have gaps: limited browser/OS coverage; weak context (personal vs. enterprise accounts); coarse “block/allow” steering instead of granular, in-flow controls. With BDR, the same visibility that detects threats can enforce data controls in-browser. Example: allow ChatGPT but only via your enterprise account, and block pasting sensitive data into personal sessions. Or distinguish between corporate and personal OneDrive/Google Drive in real time. Postman, Pastebin, PDF converters—wherever data can leak—BDR sees and can act at the point of use.
Manoj Tandon: Some will argue existing tools already cover this.
John Carse: They cover parts. We used leading DLP/CASB/EDR stacks. Reality: support varied by browser/OS, and context was often missing. Policies like “block ChatGPT” are blunt. The business wants safe enablement: allow AI tools, but enforce enterprise accounts and prevent data leakage. BDR gives that fine-grained, in-flow control where users actually work—inside the browser—complementing EDR (which won’t stop someone pasting customer data into WhatsApp Web). You should keep your EDR, CASB, SWG/SASE—defense-in-depth matters—but augment with BDR because ~80% of user time is now in the browser. Preventing at the source is cheaper and more effective than cleaning up after disk writes or network egress.
Manoj Tandon: What about virtualized or fully isolated environments?
John Carse: In some high-trust or classified environments, VDI and isolation are warranted and effective—but they’re costly and still not foolproof. People still move data in unexpected ways. Even in closed environments, visibility and anomaly detection help you catch the “this should never happen” moments before they become incidents. And remember: you still had to open some path into that environment—understanding and monitoring user actions there is valuable.
Manoj Tandon: We’re at time. Anything you’d like to plug?
John Carse: Take a fresh look at what’s happening in your browsers. Work has changed since 2006; users live in SaaS, and data moves in ways legacy tools can’t fully see. If you need deeper visibility and in-flow controls—especially around IP and AI tool usage—we’d love to help.
Manoj Tandon: Best way to reach you?
John Carse: Email founder@sqrx.com. You can also visit browser.security to test your browser and contact us there, or go to sqrx.com.
Manoj Tandon: John, this was excellent—way too short! Thanks for being so generous with your time.
John Carse: Thanks, Manoj—appreciate it.
Manoj Tandon: Hope to have you back soon. Bye-bye.
John Carse: Bye.
Read more about John on his LinkedIn
Check out the vCISO bot we created
Check out the other episodes in Season 17:
Ep. 0 Jon DiMaggio – Tracking Cyber Criminals
Ep. 1 John Carse – Why Your Browser Is Your Biggest Risk
Ep. 2 Alex Sharpe – Is Your Job Safe From AI?
Ep. 3 Chuck Brooks – Thinking Beyond the Checkbox
Ep. 4 Henrik Parkkinen – Adapting to AI & Rethinking What We Protect
Ep. 5 Alex Sharpe – Are AI Models Being Trained with Lies?
Ep. 6 Santosh Kaveti – Disaster Recovery Isn’t Optional
Ep. 7 Bob Burke – Think MFA is Enough? Think Again.
Ep. 8 Ed Gaudet – The Biggest Mistakes in Healthcare Security
Ep. 9 Husam Shbib – The Hacker’s Playbook
Ep. 10 Shayla Treadwell – The Psychology Behind Cyber Resilience
About John Carse

John Carse is the Field CISO at SquareX and a seasoned cybersecurity leader with over 20 years of experience spanning the U.S. Navy, JPMorgan, Expedia, Dyson, and Rakuten.
With a background in securing critical naval systems during his 14 years in the Navy, John has since built and led global security programs across finance, tech, and e-commerce.
He holds multiple cloud security patents and is currently helping develop the industry’s first Browser Detection and Response (BDR) solution.
With hands-on expertise and a global perspective from roles in the U.S., Japan, Singapore, Bahrain, and Europe, John is passionate about tackling emerging threats and sharing real-world insights that blend innovation with practical defense.
About Us
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
