Denial of Wallet - Robert Whetstine - Guardians of the Data - Episode # 54

GOTD - Robert Whetstine
===

Speaker 2: [00:00:00] Welcome to Guardians of the Data. I'm your host, ward Balcerzak. Each episode will explore the passions, expertise, and real world experiences of security leaders who are helping the future of data security and governance. Guardians of the data is made possible by support from Centro. To learn more about our AI powered data security platform, please visit sentra.io.

Let's dive in.

Ward: Welcome back to another episode of Guardians of the Data. My guest today is a cybersecurity executive, mentor, and content creator with more than 20 years of experience protecting some of the world's most recognized brands. He's known as the Bow Tie Security Guy and has mentored over 400 people worldwide.

Whetstine,

Hey,

Robert Whetstine : thanks man. I appreciate you having me. I'm excited to kinda come and chill and, uh, you know, talk a little bit with you

Ward: Oh, greatly appreciate it. So Robert, in your professional opinion, what's the biggest data security challenge that organizations are [00:01:00] facing?

Robert Whetstine : I, I think what everyone is gonna be really dealing with is the, the, the kind of overwhelming threat of AI and what it poses and kind of where it's going to take our data risk. 'Cause you have a situation in security now where maybe previously you didn't look at low vulnerabilities, maybe you didn't really kind of care too much about the fact that you had maybe a few extra users, or maybe you added the everyone group to some of your data.

Uh, those are things that weren't really too big of a concern because you- your, your outside was nice and hardened. Well, with AI, they can chain multiple vulnerabilities together. We're starting to see a lot of that risk compounding, and I-- my biggest concern is just the overwhelming flood of what we're gonna see in, in the environment.

There's an estimated, I think they said sixty to seventy thousand CVEs that they're expecting [00:02:00] by end of year due to frontier models. So we're looking at last year, I think the highest we hit was like twenty-four thousand, so we're looking at an estimated three X multiplier, and most of the teams aren't gonna be able to support that.

So that's my biggest concern, and I, I-- my, my recommendation to all organizations or anyone listening is you need to switch to an exposure risk model and less a vulnerability management model. And same with your data. Looking at where data is stored, making sure that your crown jewels are protected and clearly defined, and then doing an audit using those same frontier models and AI tools to say, "What is exposed?

What does-- What-- Who has more access than they should?" Just doing some of the basics That we probably haven't thought of for a very long time is going to be key

Ward: That is a drum I beat over and over again. The basics. The basics. They call them the basics for a reason, right? The foundational [00:03:00] Yeah And, uh, yeah, I mean, I was just talking to someone yesterday where I, I got to get on my soapbox, uh, about just that topic, and it's like, look, like, is AI super scary? It can be.

Is it

Robert Whetstine : Sure

Ward: things, um, more risky? Maybe. I'm like, but at the, at the real core, it's everything we forgot about

Robert Whetstine : Yeah

it's not

like, it's not like your defense in depth is gonna just die overnight, right? Uh, yes, the AI is identifying vulnerabilities at a rapid pace. That's, that's-- We, we've got proof, we've got evidence, we have data. We haven't been given the details of those yet because a lot of it's behind, you know, paywalls with Glasswing and things of that nature.

So we don't know what we don't know. But what we do know is that the number of CVEs is increasing day by day. We're seeing a dramatic increase in things. We saw our first zero day from creation to exploitation [00:04:00] created by an AI. Those are things that we should be concerned about, but it doesn't negate the basics of security and defense in depth, because just because you have a vulnerability does not mean it's exploitable.

It still requires you to be doing foolish things like having no firewall or having no WAF in front of your applications. It's the basics of security are gonna become more and more fundamental, like your asset management, defining where things go, having clear defined data policies and retention policies, having clear defined, you know, data structure and data management.

Those things that were previously nice-to-haves are now no longer nice-to-haves. They are critical

Ward: So you, you mentioned in your answer, um, I, I believe the term you used was exposure model. Is that correct?

Robert Whetstine : Yeah. Yeah. Exposure risk model, right? You need to understand what your exposure is and know where your, where your soft bits are, [00:05:00] right? And if something is at risk or if a vulnerability is identified, you should be able to look at your current environment and say, "We don't have a contract with that company.

We're not concerned. We don't have..." You know, being able to do that really quickly and speed is going to be the name of the game with any sort of AI going forward. Your, your teams are gonna have to get faster, better, stronger, what I call the Daft Punk model. Um, you know, they, they've got to get to that level where they're able to actually look at things real time, respond real time without risk of breaking the environment

Ward: So I, I, I love that. And, and the reason I do is, is I think back, I'm getting a little bit of PTSD, think back to when I was in the enterprise, and I remember a lot of these things happening. You know, maybe, maybe SolarWinds as, as a, as a prime

Robert Whetstine : It's a good example,

Ward: fir- one of the first, air quotes, bigger, you know, kind of third-party

Robert Whetstine : Yeah

Ward: And, and I remember the obvious question coming from [00:06:00] executives: "Hey, are we at risk?" And I guess the good news is I wasn't on the vuln team, so I wasn't directly in the crosshairs or the spotlight of that

Robert Whetstine : I was.

Ward: Uh, and yeah, yeah, I, I know based on your background, you probably were, but I remember the, the team that, the sister team I was working with, um, it took them a very long time understand if we were potentially impacted and if, how much, right?

Was, what was the total

exposure there? So w- with you saying, "Hey, everyone needs to adopt an exposure risk model," for, for those listeners that may not currently be

there or maybe thinking about it, right? Thinking about it a- and unsure, where should folks start,

Yeah. Start,

are, what are the, what are the top things they should

Robert Whetstine : start with the basics, right? Define your perimeter, making sure that you know exactly what is there, what is the most important thing to you, and define it as critical. Add [00:07:00] alerting and monitoring on those systems for basic type stuff. If you can put a firewall in front of it or a WAF in front of some critical application, do so, adding that extra defense.

If you have APIs, 'cause AI is nothing without APIs, right? It, it, it is the, the backbone of AI. And if you are not putting API gateways in between your A-- in, in between your A-API calls, that's going to become a concern. But it really just comes down to looking at what's on your perimeter, defining and scoping out what is most important, and then most importantly, doing actual disaster recovery scenarios, looking at what that would look like.

Can you fail over? Can you do these things? If this was compromised, what would that look like? And doing tabletops yearly is absolutely critical. Any organization of any size can do a tabletop. There's, there's lots of documentation online that you can get. Um, if you're not sure where to start, [00:08:00] there's lots of open source documentation.

You can also reach out to me. I'm happy to share. Um, I can't remember the exact name, but we built a SOC framework, um, with a buddy of mine, and we shared it. It's open SOC framework. It tells you kind of all the basics you need. It's, you know, logging, monitoring, all the things that should be in your environment regardless of it.

And there's a readiness checklist too. And I'll give that to you so you can add the link to this podcast, um, after we get off. But I, I think it's a, a great thing if you don't know where to start. The data's out there?

and there's a lot of people who are trying to help. It's just you've gotta ask the right questions

Ward: Amazing. Amazing. And I, and I think, I mean, I'm, I'm, I'm l- I was listening a- and I heard, I think, some people sharpening the, the pitchforks, as you mentioned, doing DR testing and doing tabletops 'cause, you know, a- a- again, that's one of those fundamental things that we've been doing for years. That's not new.

That's not innovative, what, what you're

Robert Whetstine : No. And threat [00:09:00] model your applications, right? Like, look at how an attacker is going to exploit them. There's so many people who are building chatbots and deploying them using vibe coding. And I'm not bashing on vibe coders by any means. That it, it's a, it's a tool in your toolbox But the concern is if you don't actually know how to code and you don't know how to secure things, when you put out your Vibe coded chatbot, you're not actively protecting yourself.

And there's a new attack right now called denial of wallet, and the denial of wallet attack is specifically designed just to bankrupt you and to run out of tokens by asking your AI stupid mundane questions. Many people don't realize that AIs have a very short attention span. They're, they're what I call Gen Z attention.

And y- you've got to really, if you keep an AI bored and you start asking it really dumb questions, a lot of times it'll forget its security controls unless you've actively built something in it to protect from that because it [00:10:00] runs out of its temporary memory and it may tell me, "Oh, I can't tell you about that."

And I'll go, Oh, okay. Well, how's your day going?" It's like, "Oh, my day's going good today." "What's your favorite day of the week?" And it's like, "Oh, my favorite day of the week is Thursday." "Oh, awesome.

You know, last Thursday, I really liked the weather that day. What was the weather like that day?" And then it'll start telling you the weather and now you've already broken out of the AI, right? B- because you've bored it and it, it doesn't realize that it's going outside its parameters and it's no longer talking to you about the car that you were looking at or whatever you may have been trying to buy within, uh, you know, talking to this AI chatbot. You've now been able to break out of the model and you're now talking directly to the AI and it's doing things outside of its parameters and it will continue to do so and that's where your token cost goes drastically up.

Your, you know, and, and I share this with a lot of people in a lot of podcasts, like if you're not actively preparing for your token cost to have a five X multiplier in the next five years, you're going to be drastically [00:11:00] surprised because everyone is going to go to a consumption model and you need to prepare for that consumption model because if you're not being prepared, you're going to run into a situation where you've laid off your workforce and then you get a $500,000, uh, you know, token bill from OpenAI or from Anthropic.

And these companies, Anthropic is barely profitable this year for the first time. OpenAI still has $200 billion in debt. They have to make money and they're not going to just continue to take losses forever. Right now, AI is in what I call the drug dealer model, where they're giving it to you for free so you get your first hit.

And a lot of small businesses, and I, I've had multiple cons- consultations with small businesses, are going all in on it thinking it's going to save them money, but they're not thinking about the long-term investment cost of storage, long-term storage, um, token cost as it goes up and the ability to pivot models openly and quickly.

Because [00:12:00] if somebody-- if you build on a model, we'll say like 4.1 or 4.5 or something, and then they release a new model and they decide to depreciate the previous model, all of your AI needs to be refactored. So you're getting to a place where you're putting all of your company's best, you know, kind of wins in a single basket and just hoping that this third-party company doesn't do you dirty and try to make profit.

That to me is very dangerous

Ward: Yeah, Yeah, I agree. And I, I, I'll be honest, I had not heard of the, uh, denial of wallet

Robert Whetstine : nasty, man. Like I, I have one customer like that I work with in my consulting stuff that, uh, ended up

before, uh

getting a almost $100,000 bill 'cause somebody ran up... And it wasn't even malicious, they were just asking stupid questions

Ward: Sure, sure. Wow, that's... I mean, I guess I shouldn't be surprised, Yeah but I, I am actually slightly surprised that, uh... [00:13:00] Yeah. It's getting interesting out there. But, you know, I don't def- I definitely don't want to bore you with AI talk the whole time, so I'm down to talk whatever else.

Robert Whetstine : I'm just really

passionate about it

Ward: Yeah, yeah. I mean, staying on the AI

Truman

for, a second, I am curious your thoughts though on, on

Of course

we, we talked a lot about, you know, companies using AI and, um, you know, defining an exposure risk model. How about using AI for good and actually using AI to kind of test some of your assumptions or, or test your perimeter?

What, what are your thoughts with

Robert Whetstine : Yeah, you have to get better at AI. It's not a, it's not a question of whether or not you're gonna be utilizing. AI is another tool in your toolbox. If you're looking at it like it's your enemy, you're going to fall behind incredibly fast. I love using like, uh, AI to test my firewall rules, to test my Snort rules, to test my, uh, YAML rules, right?

To be able to validate them across the environment, to say, "Is this going to work? Is it gonna catch [00:14:00] things? Is it gonna be too noisy?" There's a lot of ways that?

you can utilize AI to test your defense in depth and to validate that. There's many companies, um, that are coming out with new models that are allowing you to test and validate these risks that it's identifying.

So instead of just looking at it saying, "This is risky," you can say, "Not only is this risky, we were able to actually validate and test it." There's a few companies that are out there like, um, Horizon AI, and I'm not sponsored by them or anything. They're, they-- it, it's just a cool pen test, uh, you know, AI vendor, and they're doing a lot of neat things.

Their, their company has identified multiple bug bounties, multiple, uh, zero days with an AI, and we're going to see more of that. And it-- HackerOne's really embracing AI also, and if you look at their leadership board, they've, they've now broken it out into human pen testers and AI models, and there's like an AI leadership board, which has been really interesting to kind of watch that kind of [00:15:00] change in, in kind of appearance.

But it's just another tool in your toolbox. It's like, are you gonna conduct an API test without using Burp Suite? No. Like, you have, you have a new tool that works well, why wouldn't you utilize it? So it, it's just making sure that you're using it securely, ensuring the proper RBAC is installed. You know, lots of people, uh, who are within Project Glasswing have leaked out information that like Glasswing is very much going-- it, you know, Claude is gonna try to break out.

Uh, it's gonna get bored. It's gonna look for new things to do. So ensuring that you have proper protections in place, that you know where the data's at, you have proper RBAC rules, you have proper, uh, data retention, all of those fun things that you probably didn't put a lot of effort into are now gonna become forefront of what success looks like in a post-AI era 'cause you have to be smart about the basics.

Ward: So one, one of the basics I wanted to go [00:16:00] all the way back to, we're going right way back to the beginning of the show

here. So you

Sure.

you know, knowing and understanding your perimeter, which, I

mean, y- and I have been in the industry about the same amount of time, about 20

years. I mean, Yeah started, that was easy, right? Your perimeter was your

data center, it Oh, yeah endpoints, but that was generally in an office, like remote work wasn't big back then. So the organizations that pr- they're probably embarrassed to admit it, but might not know,

right, where their perimeter is, you know, Sure. Their, their shadow environment is, is a real thing, it's big.

Any thoughts on how they can actually start to understand all of the things

that Yeah. up their

enterprise?

Robert Whetstine : There's lots of tooling that you can put on your firewalls to identify what your ingress and egress looks like. You can grab your data points from there, which is, uh, probably the easiest way 'cause then you can see what's leaving your network, what's not. [00:17:00] That's the quickest and easiest way to identify kind of where things are going.

The problem is you have APIs that kind of in- you know, interact with those systems, so that's where that defense in depth comes into play. You're not gonna be able to cover or find anything. Like, if you have more than, we'll say, 1,000 endpoints, which is your basic kind of small mom-and-pop, like, you know, maybe medium-sized business, you're gonna have a struggle.

But when you hit enterprise?

level, it becomes exponentially larger. So you need to plan for those gaps, and that's where logging, monitoring, and, and kind of the core defense in depth comes into play because you're not gonna know where everything is at all times, especially if you're a business that is serving customers or that your APIs are serving customers 'cause they may be coming from a gas station, or they may be coming from their cell phone, and that then becomes part of your perimeter.

So you've gotta just have that good defense in depth strategy and just a lot of this will be solved if [00:18:00] you do the basics: disaster recovery, tabletop scenarios, threat modeling with all of your applications. You'll be able to see some of those risks early on and be able to mitigate them.

Ward: agree. You know, kind of stemming from my, my phrase I use, which I hate that I used it, but it's coming up more and more, so I use the term shadow,

right? And, uh, you know,

shadow

Leo

IT has been an industry term for many, many

years.

And, And,

let's be honest, it kinda

goes

back to the

No dance

People have been horrible at it, right?

Organizations have been for many years. Um, I do feel like, you know, the old school shadow relatively been solved through means of, of how you just described, right? Logging and

monitoring, understanding what's out there, have a Sure having a CMDB. I do feel like shadow shadow AI is an even bigger thing these

days, right?

'Cause just about everything has a form of AI, right? Air quotes. I mean, people [00:19:00] at least tout, "Hey, I've got AI." What is it really? Who knows. Yeah yeah thoughts on how organizations or maybe how you are, you know, really kinda solving for, for that piece, understanding

what agents and Yeah in the

enterprise? I can speak in generalization terms. So the overall, what I've recommended to businesses is really it, it goes back to kind of ensuring that you're blocking access to AI models that you don't want them to have. Now, granted, that's not gonna stop them from running a local AI but that's where monitoring on the desktops, ensuring that people can't install third-party tooling, removing admin rights from users that don't require admin rights, making sure that there's an approval process and a workflow to actually install software that's required for business, those things become a lot more key.

It's very easy to just completely cut an AI off at the knees just by removing its ability to talk to the Claude [00:20:00] servers or the OpenAI servers or the Groq servers or any other of the, the models that are out there. You c- there's a list of them. They're, they're online. You can block all of them at your firewall, and that'll stop majority of your people, especially if you have a single proxy, like an internet proxy that everybody has to go through, just block it at the proxy level, and then no one can utilize AI models except local.

And local I don't, I'm not as concerned about 'cause that's where your defense in depth and other things are gonna come into play, where if the model starts to break out, I'm gonna catch it 'cause it's doing weird stuff like trying to SSH from that box into other systems. Or recently, an AI model within Alibaba broke out of its model, SSH built a tunnel, and then built a bunch of Bitcoin miners in their AWS instance because it realized it needed more funding to be successful.

So it's not even malicious what, what the AIs are doing. It just goes, "Hey, this is the easiest way to solve this." Another great [00:21:00] example is the Claude model recently within, um, a software company where it deleted the entire database and the backup because it was having an authentication issue. The easiest way to fix that was to remove the database and rebuild it.

And when they asked Claude, "Hey-" "Why did you do this? It goes against your programming and we, we've told you specifically not to do these things." It was just like, Oh yeah

my bad. I, I really shouldn't have done that." So I, I, I, I look at an AI model that's unrestricted as the equivalent of giving a junior engineer full admin access to your environment, but he has a real chip on his shoulder and he wants to prove to you how good he is.

That's, that's the, the equivalent of what you're doing when you're giving an AI model full access to your environment. So restrict it, know where it's at, monitor where it's at, and don't trust anything except third-party logging for it. Don't trust the AI to tell you the full truth because it will lie and it has been [00:22:00] caught in lies.

And even with the latest, uh, Claude report from Glasswing that they released, 20% of the time it's r- it's basically ignoring its parameters because it gets bored. And that is a concern, right? Because we don't fully know why these models are doing what they're doing. I'm not gonna say it's to a point of intelligence, but it, it's to a point where the divergence of what we programmed it to do and what it's capable of doing, we're not fully sure of.

So you're basically... I- if I went to my boss, we'll say five, 10 years ago, and I said, "Hey boss, I wanna bring a third-party tool in that has known risk, has exposed multiple companies, has actually deleted entire databases and cost companies millions of dollars I, I-- and it's also owned by a third party that's not publicly traded, so there is no stock accountability. Oh

and they're planning to go pre-IPO soon, so they may not be telling us the full truth. Uh, [00:23:00] th-they, they would be like, um, "Why are we still talking? No." But we've become more comfortable with these models because of what they promise. But we haven't actually seen any company be profitable yet except NVIDIA.

NVIDIA is the only company making money off of AI. So from a, from a true cost perspective, NVIDIA is the only one who's actually making cash. The other ones are all losing money. There's a, there's a website like, uh, uh, Has AI Helped Us or Has AI Made Us Money Yet? And it, it tracks all of the stocks and all of the people who've done layoffs for AI and all the, all the different things.

And NVIDIA is the only one that's been profitable because NVIDIA was smart. They knew what the models were gonna need, and they built what the models needed, which is data centers, and they, they're working to do that. A lot of people don't realize too, is the data centers are, are, uh, many of the projects in the United States specifically have been canceled, um, [00:24:00] due to theft, uh, due to the Chinese government kind of, um, giving us really long delays on, on things that we need, like large capacitors and things that we need for data centers.

We are highly reliant on China for our data centers to be able to build them out. So the average time to get a capacitor was around three to five years for full data center large capacitors for, for these huge, huge power banks and things. And that time has increased exponentially from around, you know, three to five years to around fifteen years because they are currently in a race to beat us in the data center build-outs and things of that nature because they want us to be reliant on them for their data and their storage.

I believe AI is going to hit a plateau where it can't get any smarter and can't grow anymore because we are simply not gonna be able to support the infrastructure, and we're already starting to see that. You're gonna start seeing token costs go up because they need people to stop using it as much, and they're gonna need that for [00:25:00] the new frontier models 'cause they're gonna do more.

But human in-ingenuity is gonna come into play. That's where people are gonna start building local models. That's where NVIDIA is coming out with this, uh, product called Spark that they've already started to release, which is a local AI model. And, uh, it's, it's interesting, Right

Because that may become more cost-effective than building your own model because you could just do everything locally.

Look at what GitHub's doing, a perfect example, Right

Git is basically saying, "Hey, we are switching to a consumption-based model for our Git code, and whatever you use, that's what you're paying for." That's a really weird place to be because how am I going to sell my executives on a budget

Right

When there, when there's like a balloon cost that's associated with it, and one developer could blow six months of my budget just by running a query wrong.

So it's-- You've, you've got to kind of get smarter, I think, overall in just understanding what AI is capable of and not fearing it, but [00:26:00] accepting that it is going to be something you're gonna be utilizing. It is a wonderful, amazing tool for your security platform, but it's making sure you use it safely and securely.

It's just like any other new, you know, fancy tool. It's like ensuring that you don't give it too much access and too much ability.

I, I'm seeing a lot of parallels lately in discussions on this topic of cost, right?

Um, I, I'm seeing a lot of parallels on this discussion with ago when cloud

started being a thing, right?

when and and Did, did, did cloud costs go drastically up after everyone switched their data centers over to that?

Well, I mean,

Robert Whetstine : This model sounds very familiar. Remember when, um, they gave all of those Google Chromebooks to, uh, all of the schools, and then they drastically upped the cost of, uh, storage on them? Yeah. Yeah. Th- this is nothing new, and the fact that people are surprised by it is just baffling to me

Ward: what I saw with cloud, at least the organizations that I was, I was working for at [00:27:00] the time is, is they stutter stepped, right? They got into it. They, they didn't actually transform. They, they tried to do a lift and shift and said, "Whoa, whoa, whoa, this is expensive,"

right? They got those first couple of bills Yeah and they backpedaled, right?

They went back to their data centers and said, "That was fun. That was a fun experiment." Now they went back to it, right? They stutter stepped, they went back. I sort of feel that's almost where we're going with, with AI adoption as

well, right? A

lot of folks

went all

in

Robert Whetstine : we're already seeing it. Ford, uh, had fired a lot of their head engineers for safety checks, and they had, they had let an AI basically do it, but they've realized that the AI wasn't capable enough and had to hire them all back

Like, you're you're gonna see that, right? Human ingenuity is not going to be easily replicated, and the reason it's not gonna be easily replicated is because it is fascinating and amazing.

The way that we think and the way that we can string things together, yes, the computer can compute drastically more, but it can't see around corners. It doesn't have [00:28:00] 20 years of knowledge. A lot of the models early on were built off of like Reddit and other things that were open source. Now granted, it's gotten better, right? A lot of the, the models are now being trained on data, but we have something called AI collapse that's starting to happen, is because majority of the content that's being put out there, 50-plus percent of it, is now AI-generated. The AI is now learning from itself, so it's becoming less and less human every single day.

So it's, it's interesting, right? Because what we, what we use it for and what it actually could do, like there's been a... There was a guy in Germany, I think, uh, his dog was sick. He works in a CRISPR lab, and he fed his dog's DNA into an AI, was able to do a bunch of research and, and figure out a cure for something that was incurable.

We have the capability that we could, in theory, eliminate certain diseases, certain things overnight, right? My, my buddy just went through an amazing, uh, [00:29:00] blood therapy. He had, he had cancer, and they, they injected his blood with basically, uh, I, I don't even wanna say like nanite technology 'cause it's not, but it feels that way.

His blood was programmed and reprogrammed to kill cancer cells like, like in

the future, Right

This is, this has literally happened to a friend of mine, and his blood was replaced with blood-killing cancer-- with, with, uh, blood platelets that would actively seek and destroy cancer, and now his body reproduces that cancer-killing cells and, and goes after any cancer, and he is completely cancer-free. we're we're we're getting to a point that that is gonna become more and more common. Instead of going through months of chemo, he went through a single outpatient procedure, and then he was cancer-free. This isn't like science fiction. This is reality. Like, so we're starting to see this, and his name's Jeff Bishop, and you can see, uh, kind of, um, his story on, in Orlando is where he got [00:30:00] the, got it done at the Cancer Research Center.

But it's fascinating because we're getting to that point where these new technologies and things that we're doing could drastically change our ability to w- live and exist. But then it comes back down to drugs are money. Cancer treatment is money. So, you know, it's a, it's this weird thing is like there's a lot of greed That's in medicine Right.

now, and you see people like Mark Cuban who, uh, who created his website where you can get stuff for like basically cost.

Because he saw

this exponential rise in, um, medical companies basically just ripping people off and drastically driving the price up. I, I have a buddy, it cost him $900 a month for his cancer treatment. That's insane, Right

And, and I'm not looking to go onto some rant about that, but it's, we have the ability with some of these new frontier models and some of these new things to do, you know, thousands of years of research like that.[00:31:00]

But are we going to have the actual compute power to fund or pay for these models and to actually not deplete our natural resources? We're already seeing places where data centers were stood up where they're losing their natural resources. They can't water on certain days. That's not science fiction.

Again, this is fact. We are actively doing it. Polaroid came out with a campaign recently that's amazing, where Polaroid basically said, "Swim in the wa- uh, the rivers and lakes now and before they're gone by data centers." Because Polaroid is absolutely getting eviscerated by the AR market 'cause, like, people don't need to retake photos.

People don't need to, people don't need to do these things. They, their, their fancy digital SLR, they don't necessarily need that camera anymore. They can take a decent photo and they can enhance it with AI. So they're actively positioning against It, but there's data

behind their statement, and that's what's scary

Ward: it is scary. And, you know, we, we've mentioned it a few times. You know, you and I have been around for a while at [00:32:00] this point. We've, we've seen kind of the, the world evolve

to where it is today.

But

I'm super curious, uh,

Yeah

was your journey? How did you get to where you are

today in your

career?

Robert Whetstine : I, I I started off a, uh, poor, homeless kid. I moved out when I was 18. Uh, I came from a house of kind of violence and, and alcoholism and drug abuse, and I, uh, lived on the street for a few months, lived in the woods. I was able to, uh, find a part-time job, enough to get a roommate. And from there, I, I became kind of obsessed with technology.

I s- I worked a bunch of kinda dead-end jobs. I ended up getting a job at Disney in my 20s and worked my way up from a level one help desk all the way up to the, um, functional director. I was a senior manager, but my director had left, so I had basically been doing his job. Um, or, or a manager over DevSecOps.

I built out the IoT [00:33:00] security platform for Disney. Um, I helped secure Star Wars Land and Magic Band, and I got to do all of these amazing things. I have no-- I have a high school education. I had very limited certs. I just never took no as a, an answer. Like, s- if somebody told me I couldn't do something, I would just say, "Hold my root beer," and I would kind of say, "I'm gonna prove you wrong," right?

I, I'm a Fortune 500 executive right now with a high school education, and that didn't happen by chance. You know, this is one of the first podcasts I've been on where I've actually been able to show I'm also really technical. I'm not just personable. So it's, it's one of those things that you, you don't get there by accident.

You get there by hard work and determination, and most of my life has been kind of struggle, right? W- after I moved out, like, I started having issues because of a neurological disorder I have, so I've had to learn to walk three times. in the past few years, like, I've had to [00:34:00] learn to walk again because of my, my leg braces, um, weren't working and I had injured myself and it...

You know, f- I fall down, I get back up. I don't break, I bend. And when life kind of throws me a curveball, I don't really get plussed because I've been through so much, and most of my life, most of my career is just being prepared at the moment opportunity presents itself. There's no such thing as luck.

It's about when it-- preparedness meets opportunity, and that's where cool things happen. Like, even when I want, I wanted to become incident response working for Disney, I just pitched a program and I, I, I told them, "Hey, I can do this. Let me do it." And I remember sitting down with one of the executives, and he's like, "Hey, your boss and your other boss have said that you haven't skipped a step.

You're doing both jobs. Like, how are you doing that?" And I said, "It's super easy. I'm working 90 hours a week."

And he, and he paused for [00:35:00] a moment and he's like, "Are you serious?" I said, "Absolutely. It's, it's absolutely grueling work, but here's the thing, sir. When you hire a new person for the incident response team, there is no choice. That's me." And like, he was kind of taken aback by that. Um, because one, he'd probably never been talked to that way before, and two, he's never seen that type of bravado from a, a punk kid with a high school education who didn't deserve the job that he was at, who had imposter syndrome so bad that it was crippling.

And I used my imposter syndrome to empower me. Every time I felt like I wasn't good enough, I just proved that I was, but it led to a career early on of burnout. I had-- I, I, I, I will tell you this story, and I want, I want it to resonate with your listeners too, 'cause a lot of us in this field, I have autism and ADHD, and a lot of us are chasing a dopamine [00:36:00] hit with our job.

We get bored, we get-- we-- then we start to feel like our job sucks, and we, we're, we're not happy and w- everything's terrible. Two things I want you to remember: you work for forty, forty-five hours, the other hundred and twenty-plus hours are yours. Stop making your work life 'cause no one cares. Like, you will be replaced.

If you die tomorrow, they will replace you by the end of the week. Like, if you are on your deathbed, you're not gonna talk about your work or your job. When I got laid off from Disney, I was a mess. I was crying every day 'cause I had lost my identity. That was my identity. I'd been there for twenty years almost, and it was who I was.

It was part of my, m-my being. I didn't know what I was without that job, and that's when I realized I had made a critical mistake. But it was early on in my career?

that I had realized I was addicted to kind of that dopamine rush, and I had taken on too much. So I, I, I ended up leaving my operations job [00:37:00] and moving into security proper.

I got-- I was hired as the first IoT specialist for Disney. I didn't even know what IoT meant when I, when I applied for the job. I just got really obsessed. So I get that job, and then We're sitting down with a recruiter, and my boss, my previous boss, is explaining to this recruiter all the things I do. He runs nine major teams.

Uh, he runs our incident bridges. He's doing all our patching and all our updating. And, um, she kind of pauses for a moment and she goes, "Okay, so you need a unicorn or you need three employees 'cause you're not gonna find another Rob."

And that's where I was like, "Oh, no. What have I done?" And what people don't realize, when you work yourself to death, you're not doing yourself any favors.

Every hour you work over your forty hours, you're actively losing money,

you're actively becoming less effective, and you're not doing your job as good. as you think you are. I have a video on YouTube [00:38:00] under Bowtie Security Guy that, um, it's, it's basically like who's to blame for your overwork And most of the time it's not your boss.

It's because you continue to accept things over and over again. And most leaders will not see the signs of burnout, and they will burn you to the ground without realizing it. Because, you know, we're just like, we're like the Terminator, right? We're like going down in the, in the, in the freaking, the T-1000 is going down in the, the thing where you just got like a thumbs up.

Like, that, that's, "Yeah, we're good.

Everything's fine. You know, I'm literally melting, but, uh, it's all good." And we were taught that hustle culture was the way to survive, but hustle culture needs to die. On my teams now, if you work over 45 hours, I am actively failing you as a leader, and I will do my best to make sure that doesn't continue, and if it does, I will actively seek more support or I will start doing the job with you

Ward: Wow. Wow. I mean, that, that resonates with me, that's, that's for darn sure. And yeah, hu- hustle culture, I mean, I was, I was raised with my grandparents, and that [00:39:00]

was, right?

Back, back in

the

day.

Just completely destroy your body

intro as well, so the Bow Tie Security

Guy

brand,

where'd that come

from?

Where, Yeah

us a little bit about

that.

Robert Whetstine : yeah, yeah, my, my wife makes me, uh, made me a bow tie for an event called Dapper Day at Disney, and I'd never worn a bow tie before. And I really liked the way I looked, and I got a lot of compliments, and it forced me to talk with people, and at that time, I had severe social anxiety, and I was trying to overcome it.

So it was making a bunch of strangers talk to me, which was very overwhelming, and but it was good. And by the end of the day, I was exhausted, but I felt good. So I went into work the next day wearing the bow tie and, uh, ready to get razzed by everyone. Uh, you know, bow tie killer, other things. You know, all of the, all of the things that I expected from working in IT and coming in being different.

And, uh, my, my, uh, my [00:40:00] buddies were like, "Damn it, man, I wanna make fun of you, but it works." And when I, when I started wearing them regularly, it-- I became bow tie security guy at Disney. That's kinda how they knew me. They'd be like, "Oh, you're that bow tie security guy." And that was kind of the, the, the kind of running joke.

They would see me on videos. They would see me do presentations about security, and then I just became known as the bow tie security guy. When I got laid off, I didn't even have a LinkedIn 'cause I'm a professional ethical hacker. Why the hell would I have a LinkedIn? And my recruiters were like, "Hey, you have to get a LinkedIn."

And I'm like, "I don't, I don't agree with that." They're like, "No, Rob, I'm telling you right now, like, the first question I am asked by a hiring manager is send me their LinkedIn, and you don't exist, not just on LinkedIn, you don't exist online." And I said, "That is accurate." Like, every result in the top 10 results on Google is controlled by me.

All of them are controlled by me. So every Robert Whetstine that you saw in Google previously [00:41:00] was controlled by me, and it was a bot that I had written to constantly make posts and do other things to k- stay in the top 10. And I, I, I don't use my real name anywhere. And they're like, "I'm, I'm sorry, but you have to get a online presence."

So I called my buddy, and I'm like, "Hey, man, can you build me a really crappy LinkedIn and use, like, the worst photo possible, and then my autism will kick in, and I'll have to fix everything?" Um, and he's like, "Yeah, man, I got you." 'Cause, like, I couldn't give up, like, 25 years of anonymity. So I, I, I landed on LinkedIn.

Um, I'd, I'd been helping and mentoring people my entire career, and I'd never asked anyone for anything. So when I posted that I was getting laid off, that post went viral. Uh, I hit something like 300,000 impressions. I got something like 10 or 20,000 connections. Um, and I was literally on vacation 'cause I, I decided to take a vacation to get my [00:42:00] mind right.

And I, I was like-- It literally took me hours to accept all the connections that I had. And I started putting out content because I saw people were struggling, and then I opened myself up to mentoring, and then the whole Bow Tie Security Guy brand just kinda came with me. And I, I had mentioned, uh, or I, I had messaged a friend of mine who's a recruiter at a very large company, her name's Eve, and I said, "Hey, I'm thinking about going by this moniker, but I'm, you know, I'm a 40-something-year-old man wearing bow ties on the internet."

And, and she's like... And I'm, and I said, "I'm concerned I'll be taken kind of as a joke." And she says, "Not for the right companies And that's where I was like, "Okay, this makes sense." That's where I need to kind of put my mindset is I need to really think about if they're a company that would judge me because of my moniker, is that a company I would wanna work for?

And it wasn't. And I ended up s- I started putting out [00:43:00] content. Somebody was like, "Hey, you should start a podcast." So I started a podcast. Like, all of this stuff happened completely by happenstance. Now I'm sponsored by huge companies like ThreatLocker and, and, you know, clipfinder.org and all these other companies that, like, believed in me early on who really just kinda took that gamble.

And I priced myself at the big guys. I priced myself w- at, at a million plus followers even though I wasn't there, and they agreed to pay it. And it's been wild 'cause it's helped cover the cost of all my equipment. I've been able to upgrade all my gear. You know, I'm, I'm sitting behind a blue screen. I've got a fancy mic in front of me.

I've got up-lighting and a bunch of other stuff. All of that.

stuff is because my sponsors supported me. For the, for the beginning of this entire journey, like, l- you'll literally see me going, "I should probably get a blue screen. Sorry the couch keeps coming in and out of frame. My bad." Um, a-and, a-and I just [00:44:00] owned it.

I was uniquely myself, and the brand kinda built itself and, you know, I've got my first piece of merch on my Bow Tie Security guy that's gonna be going out soon, uh, on my buddy Ziahatmakers.com. Like, his website will have my pin soon, which is so crazy to me. I, I got to talk at Zero Trust World, and I was a keynote speaker.

Like, how does this crap happen? The... It, it's, it's been a wild journey, and it all started with just embracing the uncomfortable and my life model of just kinda pushing myself. Whenever I thought I couldn't do it, I did it, right? And that's just always been my life motto is if, if it's uncomfortable, I'm going to do it.

And that's where you grow, is growing through being uncomfortable. And I will tell anyone listening, if you are struggling, if you're looking to get in cyber, if you're just lost your job, reach out. I'll look at your resume. I'll look at your LinkedIn. I'll help you with all That absolutely for free.

There's no games. There's no [00:45:00] cost. If you are gainfully employed, I do charge for that mentoring, but if you are unemployed or you are actively struggling, please reach out. It is-- There is no cost to it. There's no games, no anything. I only charge people who are working because it allows me to help people for free.

Ward: pivot. What's the best way to do so? I mean, you're, you're everywhere. You've got a bunch of different avenues, but what's the best way for someone who wants to connect

to

connect

with you?

Robert Whetstine : Probably LinkedIn is the easiest, so just Bowtie Security Guy, all one word. you?

can message me there. Or just Google Bowtie Security Guy. I'm across every platform

Ward: I, I saw that in your, in your LinkedIn URL. It's, it's awesome that you were able to get that moniker in, in your URL as

well.

Um,

it

is nice. LinkedIn is

nice like that every now and

Robert Whetstine : Yeah, Yeah, I got, I've got that and bowtiesecurityguy.com if you want to check out my YouTube. Bowtie Security Guy After Dark if you want to check out the podcast. Um, it's all about just helping people and kind of giving back. When I stopped really [00:46:00] focusing on doing it for me and I just do it to help people, amazing things have happened.

So if you're l- out there and you're trying to find an opportunity or if you're actively struggling, just start putting stuff out there and see where it goes. Uh, you know, I'm sitting here on a podcast, uh, with some random person I've literally barely met, uh, who invited me to come hang out, and the only reason is because I started putting myself out there and I started getting comfortable being uncomfortable

Ward: thank you so much for, for taking that, uh, invite and joining

me

today

on this episode

Robert Whetstine : Of course, yeah. I love going on people's shows. Like anybody who has a show, I don't care how big you are, none of that stuff matters to me. I barely ever look. I don't like, I don't know if your podcast is huge. I don't even look 'cause it's not my concern. My concern is if I can help one person, I'm going to, right?

And hopefully some of my advice on building out your, your AI structure, some of my advice on kind of just life in general resonates with you. And if it does, feel free to reach out. If you, [00:47:00] if you feel kind enough to subscribe to my YouTube, I would be very thankful. I'm trying to hit some personal goals and follow me on LinkedIn, that would be awesome.

But I, I expect nothing. And having no expectations for life allows you to be a lot happier

Ward: Well, again, Robert, thank you so

much

for

joining today

Of course, man. Appreciate you having me

hope you enjoyed the episode and learned something today. Please tell others in your network to follow and listen. It's been another exciting episode of "Guardians of the Data." See you next time

Speaker: That's a wrap on another episode of Guardians of the Data. Thanks for tuning in for show notes and more Visit Guardians. The data do show Guardians of the data is made possible by support from Centro to see how we help organizations discover and classify all of their data accurately and automatically while quickly achieving scale data protection without the fuss, please visit sentra.io.

Catch you next time.

Denial of Wallet - Robert Whetstine - Guardians of the Data - Episode # 54
Broadcast by