
Sign up to save your podcasts
Or


In this OODAcast we provide insights into Zero Trust architectures from an experienced practitioner, Junaid Islam.
Junaid is a senior partner at OODA. He has over 30 years of experience in secure communications and the design and operations of highly functional enterprise architectures. He founded Bivio Networks, maker of the first gigabyte speed general purpose networking device in history, and Vidder, a pioneer in the concept of Software Defined Networking. Vidder was acquired by Verizon to provide Zero Trust capability for their 5G network. Junaid has supported many US national security missions from Operation Desert Shield to investigating state-sponsored cyberattacks. He has also led the development of many network protocols including Multi-Level Precedence and Preemption (MLPP), MPLS priority queuing, Mobile IPv6 for Network Centric Warfare and Software Defined Perimeter for Zero Trust. Recently Junaid developed the first interference-aware routing algorithm for NASA's upcoming Lunar mission. He writes frequently on national security topics for OODAloop.com.
We discuss Junaid's approaches to zero trust networking. His approach is to always start with the needs of the business. From there he works with organizations to ensure a comprehensive assessment of the existing architecture is done, since every organization already has some elements of a zero trust approach in play. Junaid highlights that one of the biggest mistakes he sees organizations make is skipping this gap analysis and moving right to purchase of products or services. This frequently ends up being a negative to the project.
Today's global businesses operate with many partners, providers and suppliers and zero trust designs must be established with this unique mix in mind to optimize the use of technology in support of core business needs.
Junaid provides insights into many of the products he encounters in zero trust architecture work.
Related Reading: Cybersecurity Sensemaking: Strategic intelligence to inform your decisionmaking
The OODA leadership and analysts have decades of experience in understanding and mitigating cybersecurity threats and apply this real world practitioner knowledge in our research and reporting. This page on the site is a repository of the best of our actionable research as well as a news stream of our daily reporting on cybersecurity threats and mitigation measures. See: OODA Cybersecurity Sensemaking
From Solar Sunrise to Solar Winds: The Questionable Value of Two Decades of Cybersecurity AdviceWhile the Ware Report of 1970 codified the foundations of the computer security discipline, it was the President's Commission on Critical Infrastructure Protection report of 1997 that expanded those requirements into recommendations for both discrete entities as well as the nascent communities that were growing in and around the Internet. Subsequent events that were the result of ignoring that advice in turn led to the creation of more reports, assessments, and studies that reiterate what was said before. If everyone agrees on what we should do, why do we seem incapable of doing it? Alternately, if we are doing what we have been told to do, and have not reduced the risks we face, are we asking people to do the wrong things? See: From Solar Sunrise to Solar Winds: The Questionable Value of Two Decades of Cybersecurity Advice
If SolarWinds Is a Wake-Up Call, Who's Really Listening?As the U.S. government parses through the Solar Winds software supply chain breach, many questions still remain as to the motive, the entities targeted, and length of time suspected nation state attackers remained intrenched unseen by the victims. The attack stands at the apex of similar breaches in not only the breadth of organizations compromised (~18,000), but how the attack was executed. See: If SolarWinds Is a Wake-Up Call, Who's Really Listening?
Executive Level Action In Response to Ongoing Massive Attacks Leveraging Microsoft VulnerabilitiesThis post provides executive level context and some recommendations regarding a large attack exploiting Microsoft Exchange, a system many enterprises use for mail, contact management, calendar/scheduling and some basic identity management functions. This attack is so large and damaging it is almost pushing the recent Solar Winds attacks off the headlines. Keep in mind that till this point, the Solar Winds attack was being called the biggest hack in history. So this is a signal that the damage from this one will also be huge. See: Executive Level Action In Response to Ongoing Massive Attacks Leveraging Microsoft Vulnerabilities
Bryson Bort is the Founder of SCYTHE, a start-up building a next generation attack emulation platform, and GRIMM, a boutique cybersecurity consultancy. He is widely known in the cybersecurity community for helping advance concepts of defense across multiple critical domains. He is the co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security. Bryson is also a Senior Fellow for Cybersecurity and National Security at R Street and the National Security Institute and an Advisor to the Army Cyber Institute.
In this OODAcast we examine approaches Bryson has seen make positive differences in evaluating and mitigating risks to enterprises, specifically in the domain of adversary emulation.
The discussion covers:
More on cybersecurity: Ransomware: An update on the nature of the threat
The technology of ransomware has evolved in sophistication and the business models of the criminal groups behind it have as well. The result: The threat from ransomware has reached pandemic proportions.
This post provides an executive level overview of the nature of this threat. It is designed to be read as an introduction to our accompanying post on how to mitigate the threat of ransomware to your organization. See: Ransomware, an update on the nature of the threat
China's Plan for Countering Weaponized InterdependenceIn an article entitled "The international environment and countermeasures of network governance during the "14th Five-Year Plan" period" by Xu Xiujun (徐秀军) in the February 27, 2021 edition of China Information Security, we see the continuation of China's concerns over Weaponized Interdependence and China's desire to shape a global technology and economic environment that is less influenced by Western power. Xiujun identifies concerns in several interconnected areas including cybersecurity, economic centralization, and advancement in technologies like AI, Quantum, and 5G. See: China's Plan for Countering Weaponized Interdependence
If SolarWinds Is a Wake-Up Call, Who's Really Listening?As the U.S. government parses through the Solar Winds software supply chain breach, many questions still remain as to the motive, the entities targeted, and length of time suspected nation state attackers remained intrenched unseen by the victims. The attack stands at the apex of similar breaches in not only the breadth of organizations compromised (~18,000), but how the attack was executed.
See: If SolarWinds Is a Wake-Up Call, Who's Really Listening?
Russian Espionage Campaign: SolarWindsThe SolarWinds hacks have been described in every media outlet and new source, making this incident perhaps the most widely reported cyber incident to date. This report provides context on this incident, including the "so-what" of the incident and actionable insights into what likely comes next.
Russian Espionage Campaign: SolarWinds
The Cyber Threat to NASA Artemis Program:NASA is enabling another giant leap for humanity. With the Artemis program, humans will return to the Moon in a way that will enable establishment of gateways to further exploration of not just the Moon but eventually the entire solar system. The initial expenses of the program will return significant advances for scientific understanding and tangible economic returns. As Artemis continues, the project will eventually deliver improvements for humanity that as of yet have only been dreamed of. But there are huge threats. For more see: The Cyber Threat To Artemis
Security In Space and Security of Space:The last decade has seen an incredible increase in the commercial use of space. Businesses and individual consumers now leverage space solutions that are so integrated into our systems that they seem invisible. Some of these services include: Communications, including very high-speed low latency communications to distant and mobile users. Learn more at: OODA Research Report: What Business Needs To Know About Security In Space Also see: Is Space Critical Infrastructure, and the special report on Cyber Threats to Project Artemis, and Mitigating Threats To Commercial Space Satellites
Trond Undheim is a futurist, investor, consultant, executive, speaker, entrepreneur and podcaster.
He produces widely impactful podcasts: Futurized, which tracks the underlying forces of disruption in tech, policy, business models, social dynamics and the environment, and Augmented, which reveals stories behind the new era of industrial operations.
Trond is trained as a social scientist with a career in technology and innovation, and is the author of a string of books helping make sense of the dynamics at the nexus of multiple technology and societal trends, his most recent book, Future Tech, was just released.
Future Tech provides a framework designed to help all of us understand and capture value from disruptive industry trends. The book explains how four sources of technology, policy, business models and social dynamics work together and how they are shaped by complex interactive environments. More importantly, the book provides recommendations and concepts for how to apply understanding of these disruptive forces to analysis.
In the discussion we gain insights on how to apply Trond's framework to inform decisions being made today.
Additional Resources
Futurized
Augmented
Future Tech
Jeremy King is a trusted advisor to corporate boards and some of the nation's most elite business leaders. He is also a serial connector helping move business information on opportunities at the intersection of talent, capital, entrepreneurs and business development. Jeremy is an entrepreneur himself, creating successful executive search firms and also a game-changing non-profit we will talk a bit about later called MissionLink.
Today Jeremy is the founder and President of Benchmark Executive Search. For more than 20 years, Jeremy has played a strategic role in building the leadership organizations for more than 400 growth companies, including noteworthy publicly-traded success stories. Jeremy has helped transition and guide hundreds of top federal executives and flag-officers into private sector, consulting, and board roles.
In this OODAcast we discuss:
Related Resources:
Benchmark Executive Search
Ben Ford is the founder of Commando Development, a firm which leverages his deep background and experience in enterprise IT as well as his years in service as a Royal Marine to the benefit of technology teams in startups and large enterprises.
In this OODAcast we discuss Ben's views on the history of Commando's, from the experiences that inspired Winston Churchill prior to his forming then in World War II up to today, capturing a surprising number of lessons for business and IT leaders today.
Some discussion topics:
How can Winston Churchill's decisions regarding Commando Unit reporting structure inform your decision on how your enterprise AI initiatives or cybersecurity actions are organized and led?
How can the metrics of legendary Commando (and trainer of OSS) William Fairbairn inform the metrics of enterprise cybersecurity?
We also examine Ben's use of the OODA Loop approach in his methodologies. He calls the OODA Loop the Algorithm of Adaptation, considering it the best mental model for thinking about how we shape and are shaped by our environments.
Additional Resources:Commando Dev
Algorithms of Leadership
OODA CEO Matt Devost has a track record of executing on innovation via entrepreneurship. He has extensive past performance in cybersecurity, counterterrorism, critical infrastructure protection, intelligence, and risk management issues, and deep experience in delivering value in those domains via entrepreneurship.
In this OODAcast, Jen Hoar extracts lessons and insights from Matt's journey that will be relevant to creators, innovators and entrepreneurs at any stage of their journey.
Some topic covered:
- How will you know when it is the right time to start your business? - How should you evaluate risks of the new business endeavor? - How do you establish credibility with potential investors? What about potential clients? - How do you sell? - What is the best way to listen to potential clients? - What is your story and how do you articulate it? - What doesn't work? What common mistakes have you seen or experienced yourself?
Currently, Matt is the CEO & Co-Founder of OODA LLC. Prior to OODA, Matt was the EVP for Strategy and Operations at Tulco Holdings. Previously, Mr. Devost was a Managing Director at Accenture where he led the Global Cyber Defense practice responsible for Accenture's cloud, mobile, infrastructure, network, endpoint, incident response, threat intelligence, threat hunting, vulnerability management, IOT/IIOT, and red teaming offerings. Mr. Devost joined Accenture following their 2015 acquisition of the global cybersecurity consultancy FusionX LLC where he had served as President & CEO since 2010. As a Founder of FusionX, Mr. Devost helped an international clientele identify and manage dynamic threats in complex operational environments.
Additional Links:
Matt's writing at OODA Loop
Follow Matt on Twitter
Connect with Matt on LinkedIn
Subscribe to Matt's Global Frequency List
Matt's Book Recommendations
Max de Groen is a managing director at Bain Capital Private Equity (one of the world's leading PE firms with over $130 billion of assets under management), where he focuses on investments in infrastructure, cybersecurity, and application software as well as internet and digital media. This means is is well positioned to help us understand more about the future of technology enabled businesses.
Max joined Bain Capital Private Equity in 2010. Prior to joining Bain Capital Private Equity, Max was at The Boston Consulting Group, where he consulted in the technology, financial services, and healthcare practice areas. He also serves on the board of directors of Nutanix, and Rocket Software and has also previously been involved in Bain Capital's investments in BMC Software, Symantec, and NortonLifeLock among others.
Our discussion dives into Max's views on:
Related Resources:
Bain Capital PE
A CTO's Perspective on Technology Debt in M&A
Security, Risk Management and Intelligence professionals all know of Jim Clapper. He had a long and distinguished career in the US Air Force, which included leadership spanning the Vietnam era all the way to the end of the Cold War. By the time he retired he was a three star General, leading the Director of the Defense Intelligence Agency. After retirement he would later return to government service as head of the National Imagery and Mapping Agency just three days after 9/11. In 2007 he was named the Pentagon's top intelligence official (USDI), serving as an appointee in both the Bush and Obama administrations before President Obama appointed him DNI. He is author of the book "Facts and Fears: Hard truths from a life in intelligence."
In this OODAcast we sought to extract lessons from General Clapper's career relevant to intelligence professionals in and out of government. We get behind the scenes looks at the sometimes frustrating situations he was placed in early in his career and lessons that flowed from frustrations, including anecdotes that drive home the reality of what intelligence is supposed to be. Intelligence professionals in and out of government will hear first hand the dangerous temptations put on intelligence professionals to do what is easy and why the easy path can lead to irrelevance. Ever heard of a "self-licking ice cream cone?" We explore the caution of that phrase, which is a warning to not just produce intelligence for intelligence sake. Intelligence must be produced for a purpose and disseminated to those who need it. We also examine the tendency of some in the intelligence community to want to be historians, focused on exploring what happened instead of what will happen next. Reputation of military intelligence cultures are also examined.
We examine cyber intelligence, and the perception of some that the intelligence community is falling into the trap of just being historians there. But we also dive into what can be done to change this situation including changes in legislation and funding and prioritization.
Whether you are in commercial business intelligence or the government intelligence community there are lessons for you from the successful Osama Bin Laden raid of 2 May 2011 and we examine some of them in this OODAcast. If you are in the commercial sector and do not run your own operational military units you may be wondering what these lessons are. As you will find in the video, the success was based on being proactive about intelligence. Making assessments, seeking information, validating or refuting hypotheses, making new assessments and continually hunting for the right data. This success focused approach is required in any successful intelligence effort.
We ask for insights and tips on how to provide intelligence to incredibly busy decision makers. Cut away the fluff, he says, know what two or three points to make, make them, and stop. This can be hard, it is almost always easiest to drone on. But investing in making points succinctly and clearly are key.
General Clapper's management and leadership style reflects a belief that people should be treated with respect, and in most professional situations you should assume you are interacting with people that are competent and are set on doing the right thing, unless you get information that indicates otherwise. This approach comes with some risks but has helped bring out the best in teams he has led. We talk about this and many other leadership lessons including an example where his mother demonstrated to him an enduring lesson about bravery and an ability to take action at the moment needed to do the right thing. This happened in 1952 at Chitose Air Force base in Japan, and young Jim Clapper was at the Officer's club with his parents. Watching how his mother proactively worked to demonstrate that all races are welcome at her table left a mark on him he explains well in this discussion. This story is the kind of thing they make movies about, and is well worth hearing and reflecting on today.
We also talk about operational intelligence, and get an excellent briefing from General Clapper on the dynamics in the geopolitical situation with China and Russia.
Additional Resources in and references on Intelligence:
R "Ray" Wang is the Founder, Chairman and Principal Analyst of Silicon Valley based Constellation Research Inc., a research and advisory firm which studies disruptive business and exponential technology trends.
You very likely have heard of Ray before. He is active on social media (follow him here). He is also frequently interviewed in media outlets such as the Wall Street Journal, Fox Business News, CNBC, Yahoo Finance, Cheddar, CGTN, Tech Crunch, ZDNet, Forbes, and Fortune.
Ray is the co-host and co-founder of the widely watched DisrupTV, a weekly enterprise tech and leadership webcast that averages 50,000 views per episode. He's also the author of the popular business strategy and technology blog "A Software Insider's Point of View". Since 2005, Ray has delivered hundreds of live and virtual keynotes around the world that are inspiring and legendary. Wang has spoken at almost every major tech related conference, including Salesforce's Dreamforce, Adobe Summit, IBM Think, HR Tech Conference, Microsoft's Conferences, Google Next, and the sessions at Davos for various clients.
Ray is a great leader, evidenced by the people he has attracted to his firm. I know many of his team and can say for a fact that they are people who can do just about anything they want (which means they are in a position to pick their boss). Ray is also an entrepreneur, and in this OODAcast provides context anyone thinking of starting out on their own should consider. One of many anecdotes he provided was an insightful recap of a conversation he had with his then boss at Forrester Research, George Forrester Colony, which made it clear to Ray that he faced a choice. He could work at a place that wanted to motivate him to be as average as possible or he could go out on his own and create his future himself.
Ray is one of the most prolific writers and thinkers in this space, which includes bestselling books. His 2015 "Disrupting Digital Business" provided insights into ways businesses could create authentic, trustable experiences for clients and optimal experiences for employees in an age where the economy focuses less on products and services and more on experiences and outcomes. We also ask Ray for early context on his latest book, "Everybody Wants to Rule The World", which brings new lessons on surviving and thriving in a world of digital giants like Amazon, Google and Facebook. The book may help you steer your business to success in an age where many will be crushed by the powerful forces unleashed by large firms like these.
Why read this book? Because if you don't, you may well be crushed. Imagine the incredibly tech savvy Dominos Pizza, who really should be lauded for their embracing new technologies and disrupting the pizza business through technology. But now are in total danger of being crushed by an amazing, but previously unforseen model, which enables firms by companies that don't have stores, that don't sell pizzas, and don't have their own drivers, but that can deliver. The food aggregators, like postmates , Doordash etc, don't have to invest the capital to make pizza in order to make money from the transaction. This is just one of many examples, Ray also tells us how to crush LG and Samsung, for example, using the new approaches to platform based dynamics.
We ask Ray for his insights on many other tech topics, including quantum computing, quantum security (he says it is like running a bulldozer over a thatch hut), Bitcoin and Cryptocurrencies.
Additional Resources:
Constellation Research
Ray Wang on LinkedIn
Everybody Wants to Rule The World
Disrupting Digital Business
Lisa J. Porter has successfully lead some of the world's largest and most critical technology efforts. Her career started with a focus on academic rigor in pursuit of some of the toughest degrees, a B.S. in Nuclear Engineering from MIT and a PhD in Applied Physics from Stanford. She would later lecture at MIT and then became a researcher for DARPA related projects, eventually becoming a DARPA program manager. Dr. Porter would later lead NASA's Aeronautics Portfolio, would become the first Director of the Intelligence Community's IARPA, became President at Teledyne Scientific and an EVP at In-Q-Tel, and then was named to be the Deputy Under Secretary of Defense for Research and Engineering, an office which is essentially the CTO for the entire Department of Defense. She now co-leads a consultancy she formed with Michael Griffin (LogiQ).
In this OODAcast we explore Lisa's approach to leadership in the technology domain. Some themes from the discussion:
Heilmeier's Rules:
Lisa discussed the courage she saw in leaders like George Heilmeier, including the courage to stand up to large interests that will try to push there parochial interests through decision-makers, at times trying to do so by throwing their weight around or bully or seek to claim some ultimate wisdom. One of the way Heilmeier dealt with that was to force all who came to DARPA with a new idea or request to answer a set of very simple to understand questions which are still in use today. These simple questions, now called Heilmeier's catechism or Heilmeier's rules, were not always simple to answer, especially if an idea was not firmly rooted. They are:
From the publisher's feed