This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Rob Oden for a two-part series. This is part 2, and he discusses his personal journey from humble beginnings to a great cybersecurity architect. Rob provides insights into the many issues prevalent in cybersecurity and relevant to anyone serious about making their cyber environment safer.
Chapter Titles:
00:00 Introduction
01:50 Why does being compliant not equate to great cybersecurity?
13:53 No good deed goes unpunished
16:50 Technology vs Process in cybersecurity
21:45 The Prevention Paradox
28:54 Gov’t Policies addressing cybersecurity
34:41 Cybersecurity business problem or an IT Problem?
37:37 Should the office of the CISO be separate from IT?
40:26 How to quantify cybersecurity risk?
44:08 The insider threat and the executive order governing it?
54:10 How to leverage the most underutilized cybersecurity asset?
01:00:20 Vulnerability management
01:07:18 Rob’s favorite cybersecurity organizations
Audio:
Important Links:
Transcript
Manoj Tandon:
Hello everyone, welcome to another episode of Dark Rhino Security Confidential. We are back here with Rob Oden. For those of you that might have missed part one, please go back and listen to it. We’ll put a link in the show notes. Rob had some great advice on transitioning into cybersecurity, but now we’re actually going to talk about cybersecurity itself.
For those of you that may not remember, Rob is an Air Force veteran and a cybersecurity architect with over 16 years of experience. He’s a very talented individual with extensive experience evaluating, defining, advocating, and driving adoption of policies, programs, strategies, and technologies that advance cybersecurity.
Welcome back to the show, Rob. Thank you for coming back.
Rob Oden:
Thank you for having me. I appreciate it.
Manoj Tandon:
The last show is going to be great for anyone looking to transition into cybersecurity. You had some great advice. Now perhaps you can give us some advice as a practitioner in the field. There are so many questions I have for someone like you, and if I ask something you can’t answer because it presents a security issue, you can just say, “I can’t talk about that,” and I’m good with that.
One question that comes to mind is this: why does compliance not correlate to being good at cybersecurity? You see firms that have been penetrated or breached, whether that was Yahoo with three billion records stolen, or Equifax, or JPMorgan Chase. These firms, if you look at the checkbox of compliances, would have checked every box, whether it was SOC 2 Type II, PCI, or HITRUST. Yet it didn’t necessarily equate to the best cyber defense. What are your thoughts on that?
Rob Oden:
A couple of things. One, I think it comes down to incentive models. When you are building a purely Governance, Risk, and Compliance program that says you have to meet this requirement, you’re not doing it to address risk. You’re not modifying it to fit your environment. You’re looking at how to meet this requirement to do business in a certain space at the lowest cost possible.
When I used to run assessments for cybersecurity programs for the U.S. government, I remember an executive telling me, “What is the minimum acceptable level of non-compliance I can meet?” He was basically saying, “Look, I’m not going to do all of this, so where’s the line where I don’t have to do the rest?” It wasn’t that they wanted to expose information. It was that if the program is driven strictly by compliance, then it’s really about passing a test. It’s like studying for an exam versus actually learning the material. You are focused on passing the test, not understanding or applying the knowledge.
The second thing is that for a long time, the people practicing cybersecurity and the people leading compliance efforts were very different. I want to be clear: I don’t think GRC professionals don’t bring value. They absolutely do. But if your focus is on policies, regulations, collecting artifacts, and presenting those to an auditor, that is not the same skill set as someone building a vulnerability management program, or someone doing incident response, or someone investigating events. If your program is checkbox-based, then you’re focused on collection, not on trends, not on patterns, not on where you are actually exposed and getting attacked, and not on looking for things you weren’t explicitly told to look for.
I think those are some of the primary reasons compliance gets a bad rap from cybersecurity professionals and from the industry as a whole.
But I can add some hope to that.
Manoj Tandon:
Okay.
Rob Oden:
If we look at the Cybersecurity Framework that NIST created and that has been widely adopted, and if we look at something like CMMC for the Department of Defense, those are not supposed to be simple pass-or-fail checklists. With the CSF, you can decide how mature you want your program to be. Not everyone needs to be level five. If the confidentiality of your information is sensitive but not extreme, then maybe there is an acceptable level of risk you can tolerate. If the integrity of that information is temporary in nature, maybe you don’t need a massive control structure around it. If you’re not Amazon, where every minute of downtime costs a fortune, then maybe you don’t need five nines of availability.
That’s where a framework like CSF can really help. It allows an organization to say, “How do I want to build my program?” or “What kind of program do I already have, and where do I want to go?” If CMMC is done right, then it could deliver on the promise of compliance, which is that it raises the baseline for everyone. It makes good cyber hygiene part of the cost of doing business, and then everybody benefits.
But if compliance is just a checkmark exercise that cannibalizes funding from real cybersecurity work because a regulator says, “This is what the rule says,” then yes, it can hurt cybersecurity. It can even create a false sense of confidence.
Manoj Tandon:
A couple of comments on that. We had James Azar on the show, and he actually said the same thing. We were in complete agreement. We’ve talked about that ourselves before too.
What you’re saying makes sense. There are going to be some learning curves and some growing pains, but I honestly believe if we had a standard that could be applied and everyone could agree upon, that would be a huge step forward.
ISO 27001 is a good start in the sense that it asks whether you have a program, but 27002 is more prescriptive about how to implement it. What you’re describing gives more flexibility. A mom-and-pop shop building thumbnails doesn’t need the same cybersecurity program as an aerospace and defense contractor building missiles.
Even internally, the CSF really shines because different parts of an organization can operate at different maturity levels. The company as a whole may want to be level three, but certain environments, like payment processing, may need to be level five. That gives you a risk-based way to apply cybersecurity.
As a supply chain standard, it also gives a level of confidence to business partners. They can look at you and say, “This is what I meet, and this is how I meet it.” It creates a common lexicon around security.
Let me go to my second comment. Do you think the accounting firms are actually going to allow this to happen? Auditing is a huge business. We went through our SOC 2 audit, and I can tell you it is not cheap. SOC 2 Type I, SOC 2 Type II, those are accounting standards and you pay for them. The approach you’re advocating for seems like it would hurt the revenue channel a little bit for those folks. Will our laws really go along with this? I see that as a big hurdle.
Rob Oden:
One, which of the Big Four doesn’t have a major investment in cybersecurity consulting or advisory services? They all do. I would be shocked if they didn’t already have plans around CMMC audits or advisory services.
Also, we have to remember that different standards exist for different purposes. There is general cyber hygiene, and then there are industry-specific requirements. My own specialty is primarily data protection and insider threat. From a hygiene standpoint, how we identify, segment, and protect regulated and sensitive data is a serious conversation every organization has to have.
We’ve had vendors say things like, “Just encrypt it, it doesn’t matter.” That’s fine until quantum computing changes the equation, but even before that, encryption alone is not enough. What do you encrypt? Everything? Do you isolate? Do you segment? Those are real architectural questions.
Manoj Tandon:
You’re getting to something I do know something about because I’ve spent a lot of time with mathematics. By training I’m an aerospace guy. I don’t know if people understand how the RSA algorithm works and how encryption is really set up, but if you go by certain approaches, you may already be giving away some of the keys to certain parties in order to unlock that information.
So much of cybersecurity relies on encryption. Confidentiality has been first among equals in the CIA triad. But the Office of Personnel Management let all the forms on our people end up in China. How did that happen? You’d think those guys would have had this figured out.
Rob Oden:
What’s sad is that encryption is fine until people get the keys. If I compromise your network and you’re encrypting everything, but I create an account that has access to your key management structure, then you’ve effectively packaged the meal for me. I just walk out with it.
With ransomware, the attacker just brings their own keys. You can have your data encrypted already and they’ll just encrypt it again.
The OPM situation was actually interesting. Looking at the after-action reports, they found the compromise because they were starting to implement better cybersecurity practices. They were looking into their environment and trying to improve things. I actually think the CIO and CISO got unfairly railroaded in that case because they were the ones trying to investigate and address the issues.
The same thing happened with FireEye. FireEye came out and said, “We were compromised,” and they were transparent. If they had not done that, we probably wouldn’t have known about SolarWinds when we did.
Manoj Tandon:
You’re absolutely right. Which brings me to another question. Are we too focused on technologies in cybersecurity? SolarWinds wasn’t the domain of a tool. There was no technology vendor or product that would have simply prevented that. The only reason we even found out about it was human consciousness. Real people had a hunch.
An intern gave away a password, or someone reused a weak password, then got an MFA reset request they never asked for. That tipped off red teams who realized something was wrong.
Rob Oden:
The intern issue was a symptom, not the cause. That whole narrative disappointed me from a leadership perspective. This is my personal opinion, not that of any employer, but I thought that was a failure in leadership.
The fact that an intern was able to do that points to systemic process failures and a lack of cyber hygiene. If it hadn’t been that intern, it would have been somebody else. They just happened to be one avenue into the environment. Technology wasn’t the root issue there.
I’m a technologist. I love technology. I think it’s going to do a tremendous amount for us, and we’re still barely scratching the surface. But technology is just a set of processes for things we were already doing in the real world. Most of the time, when I come to a problem, it’s not really a technology problem. It’s people, process, and scope.
We talk about people, process, and technology, but we rarely focus enough on scope. Technology augments our processes. It doesn’t eliminate the need to define them. Even when we talk about automation, we’re still talking about process. The best technology can only help us move faster or at greater scale. It doesn’t replace the need for people making judgments.
In insider threat, for example, there is this desire for tools that “spy.” But the best those tools can do is help your analysts work more efficiently. They can highlight suspicious activity, but they can’t remove the need for humans to evaluate context and make decisions.
So yes, I completely agree. If we start the conversation with technology, we’ve already broken it.
Manoj Tandon:
It’s prevalent in our industry. Everybody wants to just write a check to mitigate risk.
After the SolarWinds breach, look at how many vendors used that as a part of their marketing engine.
Rob Oden:
And if any vendors are watching this, please stop using FUD. For the love of God, if you are dealing with people who actually do this work, we know. We’ve looked into the abyss and it has looked back at us. We know the fear, uncertainty, and doubt.
Please stop using it. Your product did not cure cancer yesterday because this thing happened. I understand it gets attention, but as a security practitioner, I’m begging you: stop using FUD. It worked when you had executives who didn’t understand technology, but for most of us now, it just makes us want to put you in the spam box.
Manoj Tandon:
Thanks for saying that. I literally just did a webinar with PMI Montreal this past week for project managers and that was the second slide. I said FUD is bad, this is why it has become what it is. I’m glad that a real security architect agreed with me.
Rob Oden:
Yes, we know. But tell me what business doesn’t have risk. Tell me what industry isn’t globally interconnected and changing. Cybersecurity’s pace might be a little faster, and some of the technologies are different, but fundamentally, people are still people. Spear phishing, social engineering, exposed doors, unpatched systems, known vulnerabilities. The flavor changes, but the fundamentals are the same.
Help me. Don’t just come in and say, “You’re vulnerable. If you don’t buy this, how are you going to explain it to your board?” Unless you have done a real assessment of my environment, you don’t know. So FUD is useless.
Manoj Tandon:
The U.S. Air Force did a study a while back and came up with this term called the Prevention Paradox. It isn’t talked about much, but fundamentally they were saying the more you concentrate on prevention, the more insecure you become.
If you look at the NIST framework, it is prescriptive for prevention, detection, and response. You have to do all of those and they need to be separated.
One thing I’d like to put out there is this: your endpoint prevention shouldn’t be the same as your EDR. If I know how you’re preventing things, then I know how to compromise your defenses. It’s the old moat-and-castle problem. If all I have to do is get around the moat and the castle, and that’s all you’ve got, then you’re in trouble.
Rob Oden:
I would completely agree with that. I’m an architect, and in my organization we have a directorate of architecture and engineering that handles the security tools, hardening, and prevention side. Then we have a threat mitigation team. They are the ones monitoring traffic, responding to malware, and handling the incident response mission. Those are different teams with different skill sets and different focuses.
Even the technologies are different. I like defense in depth as much as the next person. I want as many good preventive controls as possible. But eventually somebody is going to get in. That’s just reality.
As an architect and engineer, my focus should absolutely be prevention as much as possible, but I still have to support the business. I have to let things go out. I have to accept a certain amount of risk because there are risky behaviors that are still beneficial to the organization. If not, I could just shut off the internet and the power and declare everything secure. But I’ve also just killed availability.
So yes, you need someone focused on detection and response. Anything I do on the prevention side should be reviewed by people who are thinking about how we detect and respond when prevention fails.
There is definitely a false sense of security when organizations say, “We have these huge walls, no one will get through them.” That is exactly when you need the paranoid person on the team. The person who says, “I don’t know where they are, but I know they’re in.” That person is going to save you.
And that ties back to policy and procedures too. You need prevention, detection, response, and governance all working together. They should not be one focus. Prevention is a focus, not the focus.
Manoj Tandon:
Exactly, and they should be segregated. You need a peer challenging you.
I know I’m probably going to upset some vendors, but there are vendors saying, “You should engage in vendor consolidation. We can do this from soup to nuts.” But then I think you create the Prevention Paradox. You create a blind spot you don’t even know you’ve created.
There is always this desire to have one throat to choke. If things are broken, I want to go to one vendor and say, “Make this right.”
Rob Oden:
That desire makes sense. And there are definitely times where having one vendor across multiple parts of the information flow is useful, because integration matters. But I will say something that may annoy some vendors: there is almost always an over-promise around how integrated those products really are.
If you have a tool trying to do everything, then more often than not it does everything at a mediocre level, rather than doing one thing exceptionally well. For some organizations, that may be acceptable. If they just need a 70 percent solution across several areas, fine. But for an organization that says, “This particular kind of data or this specific business process is critical,” that last 20 percent may be absolutely essential.
So yes, there is value in simplification and scale. But if it’s interacting with users or critical business processes, I might want the tool specifically built for that mission instead of the Swiss Army knife of IT. It really depends on the use case.
Manoj Tandon:
Let’s upset some politicians too. After SolarWinds, I saw a lot of congressmen and senators talking about laws we should have. No one said anything that, as a cybersecurity professional, made me say, “Yes, that’s a great idea.”
From a policy perspective, do you have thoughts on anything we as a nation should implement that addresses the very tip of that Pyramid of Pain? Because SolarWinds wasn’t the domain of a vendor. That was something much higher-level.
Rob Oden:
I touched on this a little with CMMC. I’d be concerned if we said, “Everyone shall meet a cybersecurity standard,” because not every business needs the same thing. A mom-and-pop bait shop does not need an MSSP running their environment like a defense contractor does.
That said, I’m more of a Federalist in this regard. I think there are things we can do at the federal level that would provide real support to states and local municipalities. Specifically, creating an environment where those organizations could move certain applications or services to a shared, more secure infrastructure. In effect, a federal-state partnership model where you consolidate some cybersecurity resources.
My local municipality is not going to be able to hire someone like me. Most states have talent shortages as it is. If we created environments that smaller organizations could opt into, where we could centralize stronger security capabilities, then we would move the needle in a meaningful way.
That comes with risk too, because you’re putting more eggs in one basket, so you need to think about how to minimize blast radius. But I do think there’s promise there.
I also think the adoption of CMMC over the next few years is going to have a huge impact because it is focused on the supply chain, not just individual organizations. If done well, it will push better baseline hygiene into many industries.
Then there’s privacy. Right now we’re moving toward 50 different solutions with each state creating its own rules. That is going to be hard on organizations and confusing for citizens. I think we need something closer to a national baseline, almost a Bill of Rights for internet identity and privacy.
The only thing I would strongly caution against is knee-jerk reactions. If we do things through executive order or rushed lawmaking without thinking through implementation and funding, we may do more harm than good.
Manoj Tandon:
Do you think companies are understanding now that cybersecurity is a business problem and not an IT problem?
Rob Oden:
It depends on the organization and the industry.
I think banking understands it. Banking sees fraud directly. They have analytics and monetary exposure and the consequences are immediate. But when you ask how many real CISOs exist across organizations, or whether those people truly sit at the leadership table, the answer still isn’t where it should be.
There are companies where if you tried to implement a comprehensive cybersecurity program overnight, you’d sink them financially or operationally. So yes, people understand that cyber matters, but I don’t think business and cyber are aligned yet the way business and IT eventually became aligned.
Twenty years ago, many C-suite leaders hated computers. Now no one can run a business without IT. Cybersecurity is becoming that important, but we as professionals still have to do a better job of communicating why.
If we can’t communicate to the business why this matters, then we are part of the reason it’s failing. We are supposed to be the experts. There is no education like screwing up, and many companies only really “find religion” on cybersecurity after they get hit. But even then, unless cyber becomes inherent to the organization and tied to operations and business outcomes, they’ll be in the same place again in three to five years.
Manoj Tandon:
One of the things we’ve advocated for is the Office of the CISO itself, because we think the CISO should be taken out of IT. They’re being asked to critique the very people they work for, and that isn’t healthy.
Rob Oden:
There are absolutely some inherent conflicts of interest there.
As a CIO, I have to deliver uptime, features, and capability at the lowest possible cost. Security is part of IT, but it may not be the top priority from that perspective. For a CISO organization, I need to preserve confidentiality, integrity, and availability. Those priorities are not always in perfect alignment with the CIO’s incentives.
There’s a reason I think the peer relationship model is where we’re headed. Whether that becomes a distinct office or something closer to legal, I’m not sure. But I do think the CISO needs either a direct line or at least a dotted line to the CEO. Because if your boss is the same person whose work you have to critique, you may not be able to have the honest conversation.
Sometimes you have to say, “Your baby’s ugly.” And if you can’t say that at the leadership level, then the program is going to suffer.
Manoj Tandon:
I know our CEO is going to love that statement because he uses it all the time. I always tell him not to do it. You can’t tell people their baby is ugly.
Rob Oden:
It’s about how you frame it. It’s not, “You suck at public speaking.” It’s, “Public speaking is a growth opportunity for you.” Engineering is the same way. It’s all about framing it as an opportunity to improve.
Manoj Tandon:
How do you evaluate risk? I know there are a lot of frameworks out there. We’re familiar with FAIR. It has its pluses because it gives you a continuum of risk and magnitude of loss. How should a company think about quantifying risk?
Rob Oden:
My first question is: how does the company already quantify risk? What is the business already doing to compare investments or exposures? What language does the business already use when it talks about consequences, opportunity cost, and tradeoffs?
If I’m in a bank or a heavily regulated industry, the conversation is likely going to be far more quantitative. If the CFO runs the show, I need to be able to say, “If we do this, here’s what we get, within these bounds.”
I like the CSF as a framework for conversation because it uses plain language. We in cyber are guilty of drowning people in acronyms. If there is no business, then there is no need for us. Security exists to serve the mission of the business.
If I can’t explain how technology or exposure to technology helps or hurts the business, then I’m wasting everyone’s time.
Manoj Tandon:
Which brings up a question: why is availability not at the forefront of the CIA triad? Security professionals get excited about confidentiality and maybe a little about integrity, but availability often feels like an afterthought.
Rob Oden:
I completely agree. If I implement a process, procedure, or technology that stops people from doing the things that make the company money, then I am performing a self-inflicted denial of service. That is a failure of availability.
This is where understanding the business is essential. We as cybersecurity professionals need to understand what business our organization is in, and what its real operational drivers are. If we don’t, then the framework we’re using doesn’t matter.
Manoj Tandon:
Let me ask you about insider threats. How big a risk is that? Does every organization have an Edward Snowden?
Rob Oden:
Every organization has the potential for insider issues. Whether that’s malicious behavior, unintentional mistakes, or compromise through coercion, it exists everywhere.
I previously supported the National Insider Threat Task Force, which was a presidential task force focused on insider threat programs for executive branch organizations handling classified material. From that work, I can tell you that every organization has some version of this risk.
It may be an employee making a mistake, clicking something they shouldn’t, or taking sensitive data home. It may be a malicious insider. It may be someone who has been compromised personally and is now being pressured. All of those are people problems first, even though technology can augment the response.
The bigger the organization, the more likely it is that statistically you’re going to see some representation of those risks. In some cases, a compromised IT administrator is a far bigger risk than a thousand blocked phishing attempts.
The key is not just technology. It’s communication between traditionally siloed groups like HR, legal, and IT. It’s creating an environment where employees feel safe saying, “This doesn’t feel right,” without turning everything into a witch hunt. That gives you the opportunity to investigate responsibly, protect the organization, and also protect the employee from unfair assumptions.
It’s not really a Big Brother program if it’s done correctly. It can be more like Big Mother: watching for signs that someone may be in trouble or may pose a risk, and then intervening appropriately.
Manoj Tandon:
How does the government or military deal with that? They’re handling very critical information. People have to be able to do their jobs, but at the same time, blind trust is dangerous. What’s the mindset there?
Rob Oden:
There is always a balance between need to know and need to share.
Executive Order 13587 established insider threat programs for organizations handling classified information. There are minimum standards around that. But the philosophy is not radically different from good practice in industry: collect relevant information, protect privacy and civil liberties, communicate between the right departments, and create a process that allows you to identify and investigate legitimate concerns.
Technology comes in at the end. First you define the people, the process, the policy, and the scope. Then technology can help you monitor, enforce, or accelerate those things.
Manoj Tandon:
Why is the “why” behind the scope and policy not explained to the general user population? Most people are reasonable. If they understand why something is being asked of them, they’re more likely to follow it. If you just issue a mandate, it becomes another rule.
Rob Oden:
I completely agree. Communicating with employees is one of your strongest cybersecurity controls.
Yes, people are also your greatest risk, but they are your greatest asset too. Most people want to do the right thing. Give them a path to do it. Explain why something matters.
If the first time your employees hear from your security department is when they failed a phishing simulation, then you failed, not them.
And as security professionals, we are very susceptible to the curse of knowledge. We think something is obvious because it is obvious to us. Then we get frustrated when others don’t get it. But maybe the issue is that we haven’t communicated it well, or maybe we’ve designed a process that actually breaks a business workflow.
This is why partnering with communications teams matters. If you can’t say it in a way your employees can understand, implement, and own, then you are undermining yourself.
Manoj Tandon:
If we took a poll today, I don’t know how many employees would say they’ve even had communication from their cybersecurity department other than maybe a phishing simulation.
Rob Oden:
Exactly. If the first time they hear from security is because they did something wrong, that’s a failure on our part.
Manoj Tandon:
I know I’m being conscious of our time, but I have to ask: why haven’t we gotten IT hygiene right? WannaCry was preventable if systems had been patched. Why is IT hygiene still such an arduous task?
Rob Oden:
Legacy systems are a big part of it. There’s complexity there, especially in large organizations. Add mergers and acquisitions and you get more inconsistency. It takes a lot of money to standardize, even though it often costs more in the long run not to.
But more than that, the problem is all the exceptions. It’s not that most organizations have no hygiene. It’s that they have general hygiene plus countless exceptions. Temporary exceptions become permanent. You end up managing exceptions instead of managing systems.
Patch management is another example. Maybe you pushed the patch, but did you verify it was actually applied? Did you have enough testing and rollback in place? Did you skip a business unit because they were tied to an old application? If you don’t follow all the way through, then the patching process doesn’t really protect you.
Then there’s shadow IT. People do what they need to do to get work done. Add legacy equipment, legacy applications, dependencies, exceptions, and a bunch of teams who all believe they are special, and you get what we have now.
That’s why prevention alone is never enough. There will always be some unpatched system or misconfiguration. The goal is to reduce the probability and then detect and respond quickly enough to shrink the damage.
The worst case is when your MSSP, your internal IT team, and your security team are not communicating. Then you have gaps no one owns. That’s why the CISO needs visibility and communication paths into the business and ideally to the CEO.
Sometimes you have to be able to say, “Your baby’s ugly.” If security can’t say that honestly, then some of the hygiene issues are never going to get fixed.
Manoj Tandon:
We’re at the hour and you’ve been very generous with your time. Is there anything you want to plug? Any books, shows, appearances, conferences, or talks?
Rob Oden:
Unfortunately, with COVID limiting travel and conference activity, I’ve mainly been focused on completing my MBA. That has been about 20 hours a week. My wife and I also welcomed our son last year, so it’s been the great dad life.
Probably around mid-2021 I’ll start getting a little more active again. I am very active in working groups, though. I’d recommend people look at those.
I’m active in the Carnegie Mellon Open Source Insider Threat Working Group. It’s a phenomenal resource for organizations. Because of the sensitivity of the topics, vendors and government organizations don’t have full open access, but commercial entities with insider threat programs, whether nascent or mature, are welcome.
I also lead a couple of working groups in the Defense Industrial Base, so if you’re part of that community, come join us at ndisac.org.
And finally, people can find me on LinkedIn. I love interacting with people: sales team members, cybersecurity professionals, and people entering the field. It’s Robert Oden on LinkedIn.
I will warn vendor folks: if I accept a connection and your next message is a pitch, that’s probably going to stop the conversation. I know you love your product and I’m happy for you, but we just don’t have bandwidth for every cold pitch. Have a real interaction first. Comment on a post, engage in a discussion, build a connection.
Manoj Tandon:
We’re going to have you back. In fact, maybe we’ll get a panel together.
Back in the old days, we would fly our guests to Dublin, Ohio, put them in a real studio, and pour a glass of very nice select bourbon.
Rob Oden:
I’m Southern, so bourbon definitely works for me.
Manoj Tandon:
We used to do this marketing thing called Whiskey and Whiteboards. It was basically a way to get our customers into the office and have them talk to each other. We’d provide a glass or two of bourbons they couldn’t easily get on the open market. Now COVID killed all of that, so we’ve got a bunch of booze in the office with nothing to do with it.
Rob Oden:
Customer advisory boards are extremely impactful. Not prospective customers, but actual users of your product. If I’m using your product, I’m going to have pain points, no matter how good it is. Bringing users together and hearing, “Oh, you have that issue too?” creates your strongest advocates.
If I feel like my vendor took my feedback, changed the roadmap, or helped me better meet my objectives, that’s incredibly valuable.
Manoj Tandon:
Rob, thank you so much for your time. We’re looking forward to having you back again.
Rob Oden:
Thank you so much for having me. I look forward to hearing some of the other podcasts you mentioned, especially the one coming up next week from Google.
Manoj Tandon:
Yeah, we’ll absolutely have it posted on Monday.
Rob can be found on LinkedIn
Check out the other episodes in Season 4:
Ep. 0 Dark Rhino Security – Cyber Basics: The Rundown on Ransomware
Ep. 1 Rob Duhart Jr – In Cybersecurity There are Builders and Breakers, You Need Both!
Ep. 2 Rob Oden – Is a Traditional Computer Science path necessary for Cybersecurity?
Ep. 3 Chad Weinman – Compliance does not correlate to Cybersecurity
Ep. 4 Rob Oden (part 2) – Should the office of the CISO be separate from IT?
Ep. 5 Ross Young – Foreign Cyber Espionage Capabilities
Ep. 6 Ilya Bodner – How to land your first customer
Ep. 7 Samara Williams – Why is there a lack of people going into STEM?
Ep. 8 Amelia Jarboe – A passion for protecting people with Cybersecurity
Ep. 9 Hans Vargas-Silva – Compliance is a low bar for Cybersecurity
Ep. 10 Fredrik Oedegaardstuen – Cautionary advice on Automation
About Rob Oden

Rob is a cybersecurity professional with over two decades of experience. He currently works at Roblox, focused on data security. He’s passionate about developing data classification and handling programs, integrating the latest data protection tools, and managing diverse cybersecurity teams.
Rob holds an MBA from the University of Florida and a Master of Science in Management of Information Technology from the University of Virginia. He has also earned multiple certifications, including CISSP, ISSAP, ISSMP, CGRC, and ITPM.
He is an active member in the cybersecurity community, where he focuses on evolving and strengthening security and privacy practices in the tech industry.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host, Manoj Tandon, talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, Youtube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
Share and spread the word!
