Categories
Artificial Intelligence Conferences Security

“Culture eats cyber strategy for breakfast”: Notes from 813 Tech Day’s Security Panel

I spent the morning and early afternoon of 813 Tech Day at Hotel Haya in Ybor. I’m still thinking about the Fortifying the Digital Frontier: Cybersecurity at the Forefront of Fintech Innovation session, largely because of the twist that host Michael Hall introduced, which made it different from every other “Cyber is important, yo!” panel I’ve sat through. About two-thirds of the way in, he stopped running the panel and turned it into a consulting engagement. On stage, for free, for a random attendee. And it worked!

Read on, and you’ll see.

A show of hands

Michael started by asking everyone who runs a company or product that touches money, customer data, or both to raise their hands.

Some hands went up, which wasn’t surprising.

Then he asked: “Keep them up if you have a single person whose actual job is nothing but security.”

All hands down.

And that moment was the panel in summary. A room full of people founding or working at companies (or hoping to found and work at them) handling money and PII, and essentially zero dedicated security headcount among them. To be fair, a number of them were solopreneurs. Still, Michael’s follow-up question was  an important one: “So what are you going to do about cyber warfare?”

Introducing the panel

The panel had unusually good coverage of the problem space: economic development, defense-grade compliance, offensive security, and someone who actually runs a bank.

They were, from left to right onstage:

The gap between passing the audit and actually defended

Michael’s next question was a good one: “What’s the widest gap between how secure fintechs think they are and how secure they actually are?”

Alexei’s answer was the cleanest formulation of the compliance trap: compliance does not equal security. You can check every box and still be wide open. His diagnosis of why startups get this wrong:

“We identify the target, then we fire, and then we aim.”

Speed first, aim later. But in banking, “later” can be expensive in ways founders don’t model. He mentioned that for an average-sized bank, a single day of downtime can put the bank’s license at risk.

Candace, coming from the defense side, made it concrete with the ATO, the Authorization to Operate. You bring in an assessor, they verify you’ve got your asset labeling and your SSO and your password policy, and you get the shiny gold star.

And then what?

“Are you updating your AV definitions after you have the ATO? Are you patching on a specific cadence? Are you continuously monitoring the controls you got a check box for?”

Compliance is a still-frame snapshot. Security is the whole movie. Everyone optimizes for the snapshot because that’s what gets audited, but forgets about the movie.

“Too small to matter” is not a security posture

Michael asked Aaron to scare the room, and to Aaron’s credit, he skipped the horror stories and reached for stats.

An attacker can get into essentially any internet-facing machine at almost any company inside an hour. Depending on whose telemetry you’re reading, that number is more like a few minutes. Someone in the audience called out CrowdStrike’s breakout-time figure, which is measured in seconds now.

Aaron’s framing:

“A breach is inevitable. Not if, but when. Your worst day is my every day. If it’s going to rain, you bring a raincoat, not an umbrella.”

That’s why “we’ll deal with it when it happens” isn’t a plan.

What AI did and didn’t change

Aaron summarized it well:

“AI lowered the skill floor for attackers and accelerated the execution timeline. It did not invent new attack classes.”

Phishing, smishing, and credential reuse: these are the same failure modes we’ve had for a couple of decades now. Attacks are just cheaper, faster, and automated now. All this means that your unpatched, password-shared, over-permissioned environment didn’t get more vulnerable; it just got found sooner.

He also had a nice riff on password policy whiplash. We spent years pushing everyone to 15–16 characters, guidance loosened again, and meanwhile the real-world state of the art is that password123 became password12345.

Alexei’s defensive take was the one that fintech founders in the room needed: his bank is doing “baby steps” on AI. Instead of a tool, the first step an AI policy and an AI strategy with actual guardrails. Because the failure mode isn’t anything as melodramatic as a rogue superintelligence, but something more mundane, such as an employee pasting client data into a public chatbot:

“Yes, you can get the answer. But now you’ve already lost that client data. It’s somewhere, and you don’t know who can get it.”

He also noted, matter-of-factly, that some of the adversaries in this space are state-funded. A small bank in Tampa versus a government-backed team is not a fair fight, which is precisely why the guardrails have process over motivation; policy and architecture over vigilance.

The compliance question founders actually care about: Which one pays?

When Michael asked which single compliance framework a founder should chase this year to unlock the most enterprise revenue, Aaron flagged it as a contentious opinion and we got the most useful ninety seconds of the panel:

  • SOC 2 Type II is the one. Depending on your market, it can move your ability to capture revenue by somewhere between 5% and 40%. Nearly everyone selling to enterprise ends up needing it anyway.
  • HIPAA is self-assessed. Draw your own conclusions about how rigorously that’s happening across the industry.
  • PCI DSS: If you’re doing payments and processing, you can largely offload it. Stripe already has it. Use their pipes; as a startup you can’t afford to build that infrastructure yourself.
  • Then there’s the practitioner’s trick: security people maintain crosswalks that map controls across frameworks. Do SOC 2 first and you’re roughly 70% of the way to ISO 27001. Do them in order and stop paying for the same control four times.

Candace added the necessary caveat: the right framework depends on your industry, and in defense you don’t get to choose; there are non-negotiable requirements.

Alexei pointed out that PCI DSS matters for finance the way HIPAA matters for healthcare, so “which framework” is downstream of “which industry.”

Candace’s advice for taking this to a board is deceptively simple: explain it in their language…

  • Bad: “We need to implement AC-2.”
  • Better: “We sell Cracker Jacks, here’s the system that keeps the Cracker Jack business running, here’s why this control protects it.”

The panel turned into a live advisory board

This is the part I’ve never seen at a conference.

An audience member who’s a consultant mentioned he’s got a client (transfer agents, handling bank relationships and a mountain of shareholder PII) who wants to point an agentic AI system at their overflowing email inbox.

The debate: should they be cloud-based, or reverse twenty years of industry momentum and go back to on-prem so they can hot-swap open-weight models without token costs and keep everything whitelisted?

Michael stopped the panel, brought the consultant to the front, declared the panelists a pop-up advisory board, and made them answer.

The responses split about how you’d expect from their backgrounds:

  • Alexei: Going on-prem relocates risk rather than eliminating it. It also means you’re now defending on two fronts: not just outsiders, but also insiders! You’re paying for infrastructure, security, and people. The “cheaper” assumption usually doesn’t survive contact with the invoice. When Microsoft ships patches every week, that’s a vendor doing work you’d otherwise be doing yourself, maybe badly.
  • Aaron: Go hybrid, on the grounds that nobody has a crystal ball about second- and third-order downstream constraints, and hybrid preserves optionality for next year.
  • Candace: Her world is mostly on-prem and air-gapped, so that’s where her instinct goes, insider threat and hiring burden included.
  • Paul: He’s a retired Rear Admiral, so he followed the Navy adage “A ship’s a fool to fight a fort” and declared the question outside his expertise and deferred to the other panelists. In my opinion, that earned him even more credibility.

Michael then asked for the consultant’s contact info so they can follow up in 60 days and report back to the room on what he actually decided. That’s the accountability loop conferences never close. I’ll keep tabs on this and let you know how it turned out.

After that, they did it again, this time with an attendee trying to break from defense-sector BDR work into commercial cybersecurity account management. They brought her to the front and gave her a live career consult.ation.

Candace’s advice was to stop being invisible on LinkedIn and start advertising the specific role she wants.

Aaron also had good cybersecurity-specific advice:

“Cybersecurity is one of the most arrogant professions on the planet. If you’re the one person they want to have a beer with afterward, you’ve already won.”

(I work in cyber. He’s right. In this field, being able to communicate humility is a cheat code.)

And finally, in a fit of audience participation, and after quickly consulting NetFoundry’s careers page (I work there and love it!), I stood up and asked her “How about starting with a Sales Development Rep role that works with Account Management? We have an opening at NetFoundry.”

She said “yes,” and Michael yelled “Joey’s got to get her the job!”

(She and I chatted afterward. Our conversation will be ongoing, and I guess I’ll have to follow up with Michael in 60 days…)

Tampa Bay resources you should know about

Paul’s whole reason for being there was to make people in the room aware of resources they might not have tapped:

  • The Florida High Tech Corridor spans 23 counties from Tampa Bay to the Space Coast, and deliberately plays Switzerland across all of them; there are no favorites among universities.
  • USF’s Bellini College of AI, Cybersecurity and Computing is teaching ethics at the beginning of the degree rather than bolting it on senior year, on the theory that security is fundamentally a judgment-call discipline, not a checklist one. Elizabeth Nelson is the Corridor’s point of contact at USF.
  • SBIR/STTR grants are available from eleven different federal agencies, it’s non-dilutive funding, and the Corridor can help you go after it and match on top of it.
  • Don’t forget places like Embarc Collective, Tampa Bay Wave, and spARK Labs!
  • Florida’s structural advantage is dual-use! The military and commercial sides are unusually well connected here, and the biggest buyer in the world is a short drive away.

Closing round: What’s the one thing you can’t get wrong?

Michael went down the line and asked each panelist for the single thing a founder walking out with one weekend and a small budget can’t afford to get wrong:

  • Paul: Take the first step. Just do something. Anything.
  • Candace: “Culture eats cyber strategy for breakfast.” If your people haven’t internalized cyber hygiene, none of the rest matters. Her running metaphor all afternoon was brushing your teeth: you don’t deliberate about it, you just do it. Security should feel like that.
  • Aaron: Get business insurance, make sure it has carve-outs for cybersecurity, and make sure those carve-outs cover AI-driven attacks. That’s the one I hadn’t heard before and the one I’d act on tomorrow.
  • Alexei: Hire the right people. (Michael made him clarify for the audio: right people.)

My four take-aways from this session

  1. Compliance is a snapshot, security is a movie. If your controls aren’t monitored continuously, your ATO or SOC 2 report describes a company that existed on one Tuesday.
  2. The framework question has an actual answer: SOC 2 Type 2 first, offload PCI to your payment processor, use a crosswalk so you’re not re-implementing the same control in four vocabularies.
  3. AI didn’t create new attacks; it created new attackers. The skill floor dropped. The people who couldn’t do this eighteen months ago can do it now, at scale, cheaply. Your threat model didn’t change; your threat volume did.

Take-away number four is so good that I wanted to separate it from the rest:

4. Turning a panel into a pop-up advisory board bit was brilliant! Michael took real attendee problems, put them in front of a panel of experts, made them answer in public, and asked them to follow up in 60 days. This moved what the panel said from the rhetorical to the practical.

Let’s see more of this, please, and nicely done, Michael!

Categories
Conferences Editorial Meetups Tampa Bay What I’m Up To

Tampa Bay’s “Scenius” and 813 Tech Day

813 Tech Day happens in Tampa this Thursday, and whether you plan to attend (I’ll be at the Hotel Haya and Sapphire events) or observe from afar, keep this word in mind: Scenius.

What is scenius?

Scenius is a portmanteau of the words scene and genius, and it was coined by musician, music producer, and visual artist Brian Eno to describe the extreme creativity that groups, places, or “scenes” can generate.

Eno came up with the term as a way of countering the pervasive myth of the Lone Genius: the idea that innovation comes from a small, select set of Chosen Ones:

Brian Eno. Creative Commons photo by Algemene Vereniging Radio Omroep (AVRO). Tap the image to see its source.

Just as genius is the creative intelligence of an individual,” he says in the video, “scenius is the creative intelligence of a community.

Here’s Eno’s expanded definition of scenius, courtesy of Eno:

“Scenius stands for the intelligence and the intuition of a whole cultural scene. It is the communal form of the concept of the genius.”

…I thought that originally those few individuals who’d survived in history – in the sort-of “Great Man” theory of history – they were called “geniuses”. But what I thought was interesting was the fact that they all came out of a scene that was very fertile and very intelligent.

So I came up with this word “scenius” – and scenius is the intelligence of a whole… operation or group of people. And I think that’s a more useful way to think about culture, actually. I think that – let’s forget the idea of “genius” for a little while, let’s think about the whole ecology of ideas that give rise to good new thoughts and good new work.”

Historical examples of scenius

Here are some examples of scenius, where the collective smarts, creativity, and passion of a group of people coming together to do great things is greater than the sum of its parts:

What conditions does scenius need?

Kevin Kelly

Kevin Kelly, founding editor of Wired and former editor and publisher of the Whole Earth Review, wrote that the geography of scenius is nurtured by several factors:

  • Mutual appreciation: Risky moves are applauded by the group, subtlety is appreciated, and friendly competition goads the shy. Scenius can be thought of as the best of peer pressure.
  • Rapid exchange of tools and techniques: As soon as something is invented, it is flaunted and then shared. Ideas flow quickly because they are flowing inside a common language and sensibility.
  • Network effects of success: When a record is broken, a hit happens, or breakthrough erupts, the success is claimed by the entire scene. This empowers the scene to further success.
  • Local tolerance for the novelties: The local “outside” does not push back too hard against the transgressions of the scene. The renegades and mavericks are protected by this buffer zone.
Austin Kleon
By Larry D. Moore, CC BY 4.0

Here’s what Austin Kleon, a writer and artist whose ideas have been adopted by the tech community, has to say about scenius:

Under this model, great ideas are often birthed by a group of creative individuals—artists, curators, thinkers, theorists, and other tastemakers—who make up an “ecology of talent.” If you look back closely at history, many of the people who we think of as lone geniuses were actually part of “a whole scene of people who were supporting each other, looking at each other’s work, copying from each other, stealing ideas, and contributing ideas.” Scenius doesn’t take away from the achievements of those great individuals: it just acknowledges that good work isn’t created in a vacuum, and that creativity is always, in some sense, a collaboration, the result of a mind connected to other minds.

What I love about the idea of scenius is that it makes room in the story of creativity for the rest of us: the people who don’t consider ourselves geniuses. Being a valuable part of a scenius is not necessarily about how smart or talented you are, but about what you have to contribute—the ideas you share, the quality of the connections you make, and the conversations you start. If we forget about genius and think more about how we can nurture and contribute to a scenius, we can adjust our own expectations and the expectations of the worlds we want to accept us. We can stop asking what others can do for us, and start asking what we can do for others.

How do we grow Tampa’s scenius?

The short answer is: By showing up and participating in events like 813 Tech Day!

While the elements of scenius are in place for Tampa Bay’s tech scene, there’s still some way to go before Tampa can match places like Nashville (whose tech scene is bigger than you might think) never mind places like Austin, Charlotte, Indianapolis, and Raleigh.

The success or failure of Tampa’s tech scenius depends on us, the Tampeños who work in tech, creative, and related industries.

I’m originally from Toronto. While it has one of the hottest tech scenes in North America today, it wasn’t always that way.

While the city did launch some initiatives to change this, what truly made the difference was Toronto’s own tech community stepping up and organizing. We held events of all sizes, from regular meetups and user group meetings at pubs and lecture halls to independent conferences like MeshRubyFringe and FutureRuby to tech “camp” events to big corporate gatherings put on by the likes of the Canadian subsidiaries of IBM and Microsoft. We built places to get together, from hackerspaces such as Hacklab.TO (where I met Chris Olah as a young teenager; he’d go on to co-found Anthropic)…

…and Site3 coLaboratory to the MaRS Centre. In my work as a developer evangelist for Microsoft, I’ve met many students at Toronto’s fine universities and colleges, and they’re eager to crank out the ‘wares, both hard and soft, and they’re bright as all get-out. We built a great community bound together by cooperation, a strong social media scene and good old-fashioned face-to-face meetings. We got stuff done, and the stuff we did traveled far and wide. We built Toronto’s tech scenius, and it put the city on the map.

Can Tampa do the same? I believe so; it’s just up to us.

And now, 813 Tech Day!

Thursday, August 13, or 8/13, is 813 Tech Day. Brought to you by the folks behind Tampa Bay Tech Week and 727 Tech Day, it’s one day of sessions, discussions, workshops, get-togethers, and networking for Tampa Bay’s tech community, held in Tampa.

There’ll be value in what the presenters show and what the panelists say, but the real gold will be in simply showing up and meeting other people you might not have otherwise met and gaining ideas and inspiration you might not have otherwise had.

Or, as the saying goes, 80% of success is showing up. (In fact, you might want to read this recent article of mine about how showing up paid off for me.)

So show up at 813 Tech Day!

Want to know more about 813 Tech Day?

Recommended reading/viewing

Here’s another video with Brian Eno talking about scenius:

Genius Vs Scenius: You Don’t Need To Be Extraordinary To Create Extraordinary Things:

Here’s Austin Kleon’s talk, Steal Like an Artist, which has some elements in it that would later lead to him writing about scenius:

Also by Austin Kleon:

 

Other writing: