Security Confidential S19 E9 David B. Cross

This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes David B. Cross. David is a veteran cybersecurity executive with more than 30 years of experience and currently serves as Chief Information Security Officer at Atlassian after previously leading Oracle’s SaaS Cloud Security organization. David has held leadership roles at Microsoft and Google Cloud, helping build and secure some of the world’s largest cloud platforms. He’s also a former U.S. Navy electronic warfare specialist, an inventor with more than 30 security patents, and now serves as both a Chief Information Security Officer and Venture Partner.

00:00 Intro

02:50 Our Guest

05:50 The Evolution of Technology and Coding

10:55 AI’s Role in Software Development and Security

16:07 DevSecOps and Cloud Security Architecture

18:35 The Future of Vulnerabilities and Human Factors in Cybersecurity

21:22 The Value of Veterans in Cybersecurity

22:21 Maturing Organizations in Cybersecurity

23:20 Understanding Risk and Maturity Models

24:51 Simplicity in Cybersecurity Practices

25:27 Challenges for Small and Medium Enterprises

27:05 Adopting AI in Organizations

29:58 Data Leakage Prevention Strategies

32:01 Third Party Risk Management

35:02 Concerns with Embedded Systems

37:50 Emerging Threats in Cybersecurity

39:58 The Future of Cyber Threats

43:27 Leveraging AI for Enhanced Capabilities

Transcript

Manoj Tandon: Hello everyone. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhiino Security Confidential. Please hit the like and subscribe button. It really helps us with the algorithms, improves our ratings, and allows us to continue bringing great content to you. Show us a little bit of love by hitting those like and subscribe buttons below. Today we’re honored to have a fantastic guest with us, Mr. David B. Cross. For many of you, he doesn’t need much of an introduction because he’s been in the cybersecurity industry for a very long time, but I’ll give a brief overview. David is a cybersecurity veteran with more than 30 years of experience. He most recently served as Chief Information Security Officer leading Oracle SaaS Cloud Security Architecture, has helped build and secure some of the world’s largest cloud platforms at Microsoft and Google Cloud, served as a U.S. Navy electronic warfare specialist, and holds more than 30 patents. That’s an incredible résumé. David, thank you for joining us.

David B. Cross: I’m excited to be here. I’ve really been looking forward to this conversation. Just to update the bio a little bit, I’m currently the Chief Information Security Officer for Atlassian. I’m also very active within the cybersecurity community as a venture partner with Rain Capital VC, an angel investor, and involved in a variety of other activities. I guess I just keep adding things to the list.

Manoj Tandon: That’s fantastic. We know Atlassian’s technology very well. We work with integrations involving Okta all the time.

David B. Cross: Absolutely. Jira, Confluence, and Bitbucket are used by organizations all over the world, across businesses of every size. And I’m sure we’re going to spend some time talking about AI today because that’s something everyone is focused on right now.

Manoj Tandon: Absolutely. Before we get into AI, though, I’d like our audience to learn more about your background because we have a lot of younger professionals listening who probably wonder, “How do I build a career like David’s?” Tell us how you got started and how you found your way into cybersecurity.

David B. Cross: That’s a great question. My philosophy has always been to work hard and play hard. Anyone who follows my travel blog knows that’s something I really believe in. My journey really started with the military. Serving in the military has been something of a family tradition. After college, I joined the Navy because serving your country gives you an incredible foundation for life. During my time in the Navy, I worked in electronic warfare aboard an EA-6B Prowler squadron during the first Gulf War. That experience sparked my interest in technology and security. On the way home from deployment, I stopped at the Navy Exchange in Naples, Italy, and bought a copy of Applied Cryptography by Bruce Schneier. Reading that book completely changed my perspective. I realized there was an entire world of cryptography and security that fascinated me, and that’s really where my cybersecurity journey began.

Manoj Tandon: Fantastic. How long were you in the Navy?

David B. Cross: I served five years on active duty. During the military drawdown afterward, I transitioned into the Army Reserve for another three years because it was a little easier to continue reserve service there than in the Navy. Altogether, I served eight years. After leaving the military, I went to graduate school and then joined Microsoft. That’s where I really began focusing on security, and I never looked back.

Manoj Tandon: When you joined Microsoft, were they still building DOS?

David B. Cross: Pretty much. I joined around the Windows 2000 timeframe and worked on the Windows 2000 Joint Development Program with one of Microsoft’s customers. I became heavily involved with Kerberos, public key infrastructure, certificates, and identity technologies. I wrote a number of Microsoft’s early white papers on certificate services, PKI, Exchange Key Management Server, and related technologies. Those documents are probably still floating around somewhere even though they were written more than twenty-five years ago.

Manoj Tandon: This would have been after the whole PGP controversy then.

David B. Cross: It was still happening around that time. I probably still have my old three-and-a-half-inch floppy disks with the original C source code somewhere.

Manoj Tandon: I actually found mine the other day while cleaning out some old boxes. For our audience that may not remember, PGP stood for Pretty Good Privacy. Back then, there was a major controversy because Phil Zimmermann developed advanced cryptography software, and the U.S. government argued that it represented a national security concern. I remember being in college, buying the book, scanning the source code into a computer, and compiling it ourselves.

David B. Cross: Those were definitely different times. I remember eventually moving everything from floppy disks onto CDs because I knew the floppies wouldn’t last forever. Now even those CDs are becoming obsolete, and eventually everything ends up on SSDs. Technology keeps moving forward.

Manoj Tandon: That’s exactly how technology works. I have a twelve-year-old son who found a box of cassette tapes in the basement and asked me what they were. I told him they were used to play music, and he just stared at me in complete confusion.

David B. Cross: It really makes you wonder. Even if someone had the original PGP source code today, how many young developers would actually know how to compile it from source? How many understand header files, libraries, build systems, and everything else that used to be common knowledge? I’m honestly not sure anymore.

Manoj Tandon: Thanks to Claude, ChatGPT, and the other large language models, someone can simply ask how to compile it and receive step-by-step instructions. But you’re absolutely right. Understanding the fundamentals—how operating systems work, how software is architected, how everything fits together—that only comes from experience. You can’t simply read about it and expect to truly understand it. You have to build things yourself.

David B. Cross: Exactly. I think back to my university operating systems classes where we studied concepts like the Dining Philosophers Problem, manipulated the stack with inline assembly, and really learned how operating systems worked underneath the hood. Those are concepts that very few people ever touch anymore. I even wonder whether today’s language models understand things like ASN.1 structures and ASN.1 compilers because those used to be fundamental concepts for people working with PKI and Kerberos.

Manoj Tandon: That’s actually a good question. I’ve never tried asking one. But I will say this: if you’re writing malware, understanding machine language is still incredibly valuable because it lets you accomplish certain things that higher-level languages simply don’t.

David B. Cross: Absolutely. That’s why today’s models have so many built-in guardrails. They don’t necessarily want to help you generate malicious code or duplicate certificates.

Manoj Tandon: They absolutely will if you know how to ask the question correctly, David.

David B. Cross: It’s all about the prompting.

Manoj Tandon: Exactly. If you simply ask an LLM to write malware, it’ll refuse. But that’s not how you ask. I always think back to Tom Clancy. I believe it was The Sum of All Fears. He explained that if someone wanted to understand nuclear weapons, they wouldn’t search for “How do I build a nuclear bomb?” Instead, they’d study papers on stellar physics and how stars work because that’s where fusion principles are explained. That same idea applies to large language models today. Sometimes you have to ask indirectly rather than directly.

David B. Cross: Absolutely. It really makes you wonder about what’s possible now. Suppose I gave an LLM a legitimate X.509 certificate and asked it to generate another certificate with the same hash so I could spoof an identity. I honestly wonder whether today’s models are capable of doing something like that. Now I’m probably getting myself into trouble just thinking about it.

Manoj Tandon: No, I don’t think you’ll get into trouble. In fact, I’d bet you a penny that it could do it. There are a couple of different ways you could approach it, but it all comes down to how you structure your prompts. It’ll do it.

David B. Cross: I suppose the next question would be how many tokens it would take to generate something like that. Is it going to require a trillion tokens?

Manoj Tandon: Tokens are cheap. It really depends on what you’re trying to accomplish. I think AI has democratized a lot of this technology because you no longer need to be an expert programmer or a deep technical specialist to build something fairly sophisticated. If you have the right mindset, you can accomplish things today that used to require an entire team of specialists, and you can do it at a fraction of the cost.

David B. Cross: I both agree and disagree with that. It’s absolutely amazing what these systems can do. Something that might have taken three months to prototype can now be built in three hours. But despite how much they’ve improved over the past year or two, they’re still imperfect. Hallucinations still exist. Errors still exist. I think expertise is still incredibly important for two reasons. First, you need enough knowledge to recognize when the AI is simply wrong. We’re never going to reach a point where hallucinations disappear completely or every answer is guaranteed to be factual. There will always be a long tail of mistakes. Second, even if the AI writes all of your code for you, what happens when there’s a bug? If you don’t actually understand software development, how are you going to debug it? I use Python extensively, and it’s incredible how quickly AI can generate code. But every so often I still encounter an SDK issue or a documentation problem that requires me to understand what’s actually happening. Sometimes the AI can’t solve it, and I have to step in myself. That’s why I believe people with real expertise become even more powerful when paired with AI. It’s an incredible force multiplier.

Manoj Tandon: I completely agree. It reminds me of engineering school. I’m an aerospace engineer by training, and during exams you really didn’t earn many points for getting the final answer. Most of the credit came from setting up the problem correctly. The professors always told us that in the real world there would be plenty of people checking your calculations, but if you knew how to frame the problem correctly and understood what the answer should roughly look like, you’d eventually solve it. I think large language models work the same way. If you know how to frame the problem, provide very specific instructions, and understand what a reasonable output looks like, you can even make the model validate its own work. I’ve had tremendous success doing that in financial analysis. If you simply tell the model, “Solve this,” the results aren’t very good. But if you explain exactly what the output should resemble, define the variables, specify the process, and tell it how to evaluate its own work, it will continue refining the answer until it gets there. That’s been my experience.

David B. Cross: That’s actually one of my favorite ways to use AI. Whenever I have it generate something—whether it’s code, financial analysis, recommendations, or anything else—I always follow up with another prompt asking questions like, “What’s inaccurate here? What has been exaggerated? Where are the bugs? What resources are being consumed unnecessarily?” It’s amazing how effective that approach is. The first prompt focuses on creating something. The second prompt focuses on finding everything that’s wrong with what was just created. It’s very similar to threat modeling. Your friend Adam Shostack talks about identifying everything that could go wrong rather than simply assuming things will work correctly. I think that’s one of the best ways to use AI today. Don’t just ask it to build something—also ask it to critique and improve what it built.

Manoj Tandon: Absolutely. Let me ask you something. Having worked at organizations like Microsoft, Google, and Oracle that built enormous SaaS platforms, what was the philosophy behind securing those cloud architectures? Did the original security foundation remain the same while the perimeter evolved, or has the entire architecture fundamentally changed over time? I’m asking more out of curiosity than anything else.

David B. Cross: I think one of the biggest transformations has really been DevSecOps. I know the term isn’t quite as fashionable as it once was, but it’s still incredibly important. The biggest change came when organizations shifted from delivering packaged software to delivering cloud services. Instead of developers owning individual features or isolated components, they began owning complete services from end to end. Historically, we’d build separate components, put all the pieces together, and rely on penetration testers, quality assurance teams, and security testing afterward. But SaaS really forced organizations to think differently. Developers became responsible not only for writing the code but also for deploying it, operating it, maintaining it, and securing it throughout its entire lifecycle. When you own everything from development through production, you naturally produce systems that are more secure, more reliable, and more performant because you can’t simply throw your code over the wall to someone else. I think we’ve made tremendous progress because of that. One challenge that still exists, though, is acquisitions. Large technology companies are constantly acquiring other products to expand their platforms. On paper everything becomes part of one suite, but underneath, those products often aren’t fully integrated. Whenever those gaps exist between systems, you introduce opportunities for security problems, performance issues, and poor user experiences. I think that’s still one of the industry’s biggest ongoing challenges.

Manoj Tandon: I think it always will be. Ever since software was first written, we’ve struggled with integrating systems that were built independently and then brought together later. That’s simply the nature of technology. But it does raise a bigger question. Is there ever going to be a purely technological solution to cybersecurity itself?

David B. Cross: That’s a great question. I know this is probably a little controversial, but I keep thinking back to a conference called Prompted that was organized by Gaby Evron. During one of the sessions, Heather Adkins from Google talked about the idea that within the next year or two, we may reach a point where software vulnerabilities become dramatically less common. Her point wasn’t that software would become perfect, but that AI will increasingly be used to remediate existing vulnerabilities across massive code bases. At the same time, if AI is writing 95% of software in the future, it will also be analyzing, scanning, and correcting vulnerabilities as that code is produced. We’ll never eliminate every bug or every vulnerability because that’s simply impossible, but I do think software will become more secure, more private, and more compliant because AI will continuously improve it. We’re still moving through that transition, but overall I’m optimistic about where we’re heading.

Manoj Tandon: I think my counterargument would be that even if software somehow became one hundred percent secure—which neither of us believes will ever happen—you still have the human being at the center of everything. You can build the strongest vault imaginable out of some fictional, indestructible material, but if I personally walk the bad guy into the vault, it doesn’t matter how secure the vault was. That’s the part of cybersecurity that, in my opinion, doesn’t receive nearly as much attention as the technology itself. The human element is still the largest variable.

David B. Cross: Absolutely. My friend Ira Winkler has written extensively about exactly that. Human beings are always going to make mistakes because we’re human. Today, phishing remains one of the primary ways attackers gain access to organizations. Social engineering still works because people make mistakes. That’s why we always talk about defense in depth. You can’t rely on any single control. You need layers of protection that work together with people because mistakes are inevitable.

Manoj Tandon: I think one of the biggest opportunities is helping people understand why security practices matter instead of simply telling them what they should or shouldn’t do. If people understand the reason behind a policy, they’re much more likely to develop good habits instead of simply following a checklist. Go ahead—I know you wanted to jump in.

David B. Cross: I couldn’t resist because it ties directly into something I care deeply about: veterans entering cybersecurity. One of the reasons I’m such a strong advocate for hiring veterans is that military service teaches discipline, honesty, integrity, ethics, teamwork, attention to detail, and loyalty. But perhaps even more importantly, it teaches you to train continuously. In the military we train exactly the way we expect to perform in real situations. We practice over and over until our responses become second nature. That’s one of the biggest advantages veterans bring into cybersecurity. They know how to execute a playbook under pressure. They know how to remain focused during an incident instead of becoming distracted. That kind of training benefits not only cybersecurity teams but operations teams across an entire organization.

Manoj Tandon: Absolutely. What you’re really describing is organizational maturity. Whether we’re talking about cybersecurity or any other discipline, organizations have to mature over time. When you look at companies like Microsoft or Google and compare them to organizations of similar size that haven’t reached the same level of maturity, what separates them? What advice would you give organizations that seem unable to develop those mature processes?

David B. Cross: That’s another great question. Historically, many organizations relied on extremely complicated maturity models. The problem was that understanding the maturity model often required more effort than actually becoming mature. Lately I’ve been encouraging organizations to start with something much simpler, like the NIST Cybersecurity Framework. The key isn’t simply measuring maturity. It’s understanding your organization’s risk appetite. Once leadership clearly defines what risks they’re willing to accept and what risks they’re not willing to accept, the path forward becomes much clearer. Personally, I’ve always been a huge believer in the KISS principle: Keep It Simple, Stupid. If your framework is so complicated that people can’t understand it, then you’re doing something wrong. If you can’t explain it clearly in a sentence or two, it’s probably too complex.

Manoj Tandon: That’s brilliant advice, and I’d encourage everyone listening to pay close attention to that because simplicity creates reliability.

David B. Cross: Exactly.

Manoj Tandon: If your processes remain simple, they’re much easier to execute consistently, which leads to predictable results. But at the same time, it feels like the regulatory environment keeps moving in the opposite direction. Whether it’s GDPR, the New York Privacy Act, AI legislation, or something else entirely, organizations are facing an ever-growing list of requirements that seems to change almost daily.

David B. Cross: That’s becoming one of the biggest challenges organizations face today. Large enterprises often have dedicated policy teams and specialists who understand regulations across different countries, but what about companies with one thousand or three thousand employees? They simply can’t hire experts for every jurisdiction. That’s why I’m seeing AI-powered policy solutions becoming increasingly valuable. Organizations can ask questions like, “How does this new regulation affect my business?” or “What do I need to do to comply?” and receive guidance tailored to their specific environment. If every country—and eventually every state—creates its own AI regulations, no organization can realistically keep up using only human experts. AI has become one of the few practical ways to scale that kind of compliance work.

Manoj Tandon: Otherwise companies eventually turn everything into another compliance checklist. They hire more lawyers, check the required boxes, and move on without necessarily improving security. That creates all kinds of unintended consequences.

David B. Cross: Exactly. That’s why I think organizations, especially small and medium-sized businesses, should seriously consider AI-powered policy services. Humans alone simply can’t scale fast enough anymore.

Manoj Tandon: Let me ask you something. When your organization encounters a brand-new regulation, do you immediately call the legal department, or do you ask AI to help you understand it first?

David B. Cross: That’s actually a great question.

Manoj Tandon: We definitely don’t go directly to the lawyers. If we already understand the general boundaries of what we’re trying to accomplish, why wouldn’t we let AI perform the initial research? Sure, it might occasionally hallucinate or provide a bad answer, but it’s still an incredibly effective research assistant. I’d argue that almost everyone with access to these models is already using them that way. That brings up another question. Some organizations are still resisting AI adoption or trying to prohibit employees from using large language models altogether. Personally, I think that’s probably a losing battle because employees naturally gravitate toward whatever makes them more productive. So how should organizations introduce AI responsibly?

David B. Cross: I think there are really three important steps. First, don’t throw someone into the deep end immediately. If someone has never been swimming before, you don’t throw them into the middle of the ocean—you let them put their feet in the pool first. AI adoption is very similar. Introduce people carefully and let them become comfortable with it. Second, leadership has to lead by example. Show employees practical examples within their own job functions. Whether someone works in finance, legal, cybersecurity, or incident response, demonstrate what AI can actually do to improve their work. Once people see real value, they begin thinking, “Maybe this can help me too.” Third, provide training. Years ago, when machine learning first became popular, there was a steep learning curve. Today, someone can spend forty hours learning prompting techniques, AI workflows, and basic skills, and they’ll become productive very quickly. Give people an opportunity to experiment safely. Let them put their feet in the water, show them successful examples, provide some training, and let them try it for themselves. In my experience, about ninety-five percent of people come away saying, “I had no idea this was so approachable. The water’s warm, there are no sharks, and I can actually swim.” That transition happens much faster than people expect.

Manoj Tandon: As a CISO, how do you deal with the growing risk of data leakage through AI?

David B. Cross: I think there are really two major areas CISOs are focused on today. The first is data loss prevention. We’ve had DLP technologies for years to prevent people from emailing sensitive information or uploading it to cloud storage, and organizations have become fairly good at that. But AI changes the landscape because employees naturally want to experiment with all sorts of AI tools. Some organizations have approved enterprise AI platforms, but employees also discover countless public tools and want to try them. The reality is you can’t block every AI website or every AI application anymore. That approach simply doesn’t scale. Instead, organizations need modern DLP solutions that help users avoid making mistakes. If someone attempts to send customer information, personally identifiable information, or other sensitive data into an AI platform, the system should recognize that and stop it before it happens. The second major trend is what I call Guardian Agents. Everyone is now building AI agents, using AI coding assistants, or creating automated workflows. Those AI agents themselves need supervision. Guardian Agents help ensure that AI doesn’t accidentally download malicious packages, leak confidential information, or perform unsafe actions. There are already several companies building solutions in this area. In my opinion, these capabilities are becoming just as essential as endpoint protection. Years ago you couldn’t imagine operating without antivirus or endpoint security. Today I don’t think organizations can safely operate without Guardian Agents and modern DLP.

Manoj Tandon: How does a medium-sized business realistically afford all of that? DLP alone requires constant policy updates and ongoing management. You typically need people dedicated to maintaining it.

David B. Cross: That’s a fair point. Larger enterprises often support multiple browsers, multiple development environments, and countless different tools. Small and medium-sized businesses usually have the advantage of being able to standardize. They can say, “We’re only going to use this browser,” or, “We’re only going to use this secure platform.” By reducing the number of supported environments, security becomes much simpler to manage. They don’t have employees experimenting with dozens of different browsers or hundreds of different AI tools. That simplification can significantly reduce both cost and complexity.

Manoj Tandon: As a large organization, what kinds of third-party security requirements do you place on smaller vendors that may fit into exactly the category we’ve been discussing?

David B. Cross: That’s another important area. Let me ask you a question in return. Would you accept a vendor today that didn’t have a SOC 2 audit?

Manoj Tandon: Probably not.

David B. Cross: Exactly. Years ago, many organizations would have accepted that. Today they wouldn’t even consider it. I think AI compliance will evolve the same way. Standards such as ISO 42001 will increasingly become baseline expectations for vendors. Alongside that, third-party risk management platforms become incredibly important because they continuously monitor vendors. Maybe a supplier fails a compliance audit, experiences a breach, or develops some other significant issue. Historically, organizations assigned program managers to track all of that manually. That simply doesn’t scale anymore. AI-powered third-party risk management platforms can continuously monitor those changes on your behalf.

Manoj Tandon: That’s an interesting thought—using AI itself to monitor third-party compliance.

David B. Cross: Absolutely. Everything changes so quickly now. Think about incidents like MOVEit. How many organizations even knew they were indirectly dependent on MOVEit until the breach occurred? How many knew which vendors were affected? No organization has enough people to manually monitor every software provider continuously. AI-based services are becoming one of the few practical ways to keep up.

Manoj Tandon: What about embedded systems? Suppose you’re purchasing hardware components that contain firmware or embedded software from third parties. What concerns you most as a CISO in that situation?

David B. Cross: That’s an interesting topic because I have mixed feelings about it. We all know firmware attacks are technically possible. We know UEFI can be compromised. We know hardware can theoretically be rooted before it ever reaches an organization. Those risks absolutely exist. But I also like to ask a practical question. Can someone point to a commercial company that has actually suffered one of those attacks within the past few years? Outside of intelligence disclosures and highly specialized nation-state operations, examples are surprisingly rare. Is it possible? Absolutely. Is it currently one of the highest priorities compared to something like prompt injection attacks against AI? Personally, I don’t think so.

Manoj Tandon: That’s actually a very pragmatic perspective. I think most people would agree that prompt injection is a much more immediate concern. Firmware attacks certainly matter in areas like medical devices or critical infrastructure, but your question is a good one. Can someone actually point to a real-world example?

David B. Cross: Exactly. In defense environments, absolutely. Those organizations have additional controls because of the risks they face. Even products like gaming consoles or commercial devices are manufactured all over the world, so supply chain concerns are legitimate. During my time at Microsoft, we had extensive controls governing hardware manufacturing and supply chains. But when people discuss compromised firmware today, I always ask for concrete examples. Beyond speculation and a few highly publicized reports, there simply haven’t been many confirmed commercial incidents.

Manoj Tandon: You’ve actually given me a new research project because I can’t immediately think of a concrete example either. But I do think about software supply chains. Nobody writes every line of code from scratch anymore. Everyone relies on open-source libraries and third-party components. You always hope those components are secure—but hope isn’t much of a security strategy.

David B. Cross: I completely agree. In fact, over the last several months we’ve seen software supply chain attacks become one of the fastest-growing threats in the industry. Open-source packages are being compromised, repositories are being poisoned, and malicious code is finding its way into development pipelines. Some of these incidents involve nation-state actors, while others are simply criminal groups. Regardless of who’s behind them, organizations need trusted repositories, threat intelligence, and continuous monitoring of things like GitHub Actions and software dependencies. That’s one of the biggest emerging risks I see today. Friends of mine working in that space are finding compromised packages almost every week. Compared to cryptocurrency mining malware or some of the other trends we’ve seen over the years, software supply chain attacks feel like one of the biggest cybersecurity challenges organizations will face moving forward.

Manoj Tandon: With that being one of the major threats, what other developments do you see emerging over the next few years?

David B. Cross: Looking ahead, I think there are a couple of major areas to watch. The first is phishing. We’re already seeing phishing attacks become dramatically more sophisticated because of AI. It’s not necessarily that the emails themselves are written better—although they are—but attackers are collecting enormous amounts of publicly available information and using it to make their messages incredibly convincing. They know your coworkers, your projects, your interests, and your communication style. Instead of sending generic phishing emails, they’re crafting highly personalized attacks that look completely legitimate. That’s one of the biggest changes we’re seeing today. The second area is something we all know is technically possible but haven’t really seen at scale yet: complex, chained AI attacks. We know models like Mythos, Glasswing, and others are capable of orchestrating increasingly sophisticated workflows. We know those capabilities exist, but we haven’t yet seen widespread evidence of attackers using them in real-world campaigns. Another concern people often bring up is AI-controlled drone swarms or autonomous attack platforms. Again, those scenarios are certainly possible, but we haven’t seen meaningful evidence that they’re happening yet. They’re things we need to monitor carefully, but I don’t think they’re today’s biggest threat.

Manoj Tandon: Every one of those scenarios is certainly possible, and eventually some of them will probably happen somewhere. That’s why vigilance is so important. What really encourages me is hearing people like you think creatively about these possibilities. Many major security failures throughout history have come from a failure of imagination. People convince themselves that something simply can’t happen, and then that’s exactly what happens. The Titanic wasn’t supposed to sink either. Organizations sometimes become too comfortable believing certain attack paths are impossible, and that’s often where the biggest surprises occur. It’s reassuring to know that security leaders are actively thinking several steps ahead instead of only preparing for yesterday’s attacks.

David B. Cross: I really like your Titanic analogy because I think one of the biggest differences today compared to ten or twenty years ago is how quickly information spreads. Back then, if one ship encountered an iceberg, only the nearby ships might hear about it. Today, whenever someone discovers a new attack technique, a new indicator of compromise, a malicious IP address, or new malware, that information spreads throughout the cybersecurity community almost immediately. Between threat intelligence feeds, industry collaboration, social media, and countless other channels, we all learn about emerging threats much faster than we used to. That allows organizations to respond much more quickly instead of discovering an attack weeks after everyone else already knew about it. I think that collaborative sharing has become one of the industry’s greatest strengths.

Manoj Tandon: David, we could easily continue this conversation for another hour, but unfortunately we’ve reached the end of our time. Before we wrap up, I’d like to give you an opportunity to share anything you’d like our audience to know. The floor is yours.

David B. Cross: One of the things I’m most excited about right now is what we’re building at Atlassian. Watching AI evolve over the last few years has been incredible, and seeing what organizations can accomplish when they connect information through capabilities like Teamwork Graph is genuinely impressive. When your Jira projects, Confluence documentation, Bitbucket repositories, and AI capabilities all work together, you can answer questions and solve problems at a speed that simply wasn’t possible a couple of years ago. As someone who’s worked in cybersecurity for decades, I genuinely believe AI is one of the most powerful force multipliers we’ve ever had. Yes, I happen to work for Atlassian, but even if I didn’t, I’d gladly pay for these capabilities myself because they make me dramatically more productive. My advice to everyone listening is simple: embrace AI. Learn how to use it effectively because it will significantly expand what you’re capable of accomplishing.

Manoj Tandon: That’s a fantastic message. David, it’s truly been an honor having you on the show. Thank you so much for spending time with us today.

David B. Cross: I really enjoyed it. As I mentioned before we started recording, I love doing podcasts. I can’t wait to download this episode and listen to it on my next run. And honestly, I can’t wait to schedule another conversation because we barely scratched the surface. There are so many additional topics we could dive into.

Manoj Tandon: We would absolutely love to have you back. We really only scratched the surface today. Every time you answered one question, I found myself thinking of three more I wanted to ask, and I realized we’d never finish if we kept going. David, thank you again. This has been a fantastic conversation.

David B. Cross: Absolutely. I look forward to the next one. And to everyone listening, join the community and be sure to download this podcast.

Manoj Tandon: Thank you. Take care, David.

Read more about David on his LinkedIn.

Check out the vCISO bot we created

Check out the other episodes in Season 19:

Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities

Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?

Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity

Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat

Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?

Ep. 5 Murphy John – The Future of Decentralized Data

Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now

Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern

Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis

Ep. 9 David B. Cross – The Future of Cyber Threats

Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft

David B. Cross' profile picture for Dark Rhiino Security's Security Confidential podcast

David B. Cross is a veteran cybersecurity executive with more than 30 years of experience leading security engineering and cloud security initiatives at some of the world’s largest technology companies.

He currently serves as Chief Information Security Officer at Atlassian after previously leading Oracle’s SaaS Cloud Security organization.

Before Oracle, David built Google Cloud’s Security Engineering organization and spent 18 years at Microsoft in leadership roles spanning cloud security, product engineering, authentication, encryption, and enterprise security.

A former U.S. Navy electronic warfare specialist, David is also a Venture Partner at Rain Capital and holds more than 30 patents in security technologies.

Throughout his career, he has built high-performing global security teams while helping shape the next generation of cloud security.

Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host Manoj Tandon talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, YouTube, LinkedIn, and more.

For inquiries, please email media@darkrhiinosecurity.com

Share and spread the word!

Leave a Comment

Your email address will not be published. Required fields are marked *

Chat Icon
Scroll to Top