Episode Details
Back to Episodes
102. CISO does not spell CEO (with Chris Kirschke)
Description
Chris Kirschke spent 27 years in security operations before a venture studio's general partner asked him to run a company. His first answer was that CISO does not spell CEO. He took the job anyway, and Kyberis AI now runs a threat graph that pulls in any OpenCTI-compliant feed, commercial or OSINT, and exposes it to security agents through MCP.
Jon and Chris start with what has to be true before any of that works. Chris borrows the thesis Jason Clinton laid out at Anthropic. If you can't trust the inputs, you'll never trust the output, and that holds whether the thing consuming the input is an L1 analyst, a 2003 IDS, or a threat-hunting agent.
Then the good part. Chris has enabled write access on a production system exactly once in his career. Cisco NetRanger, shunning turned on, signature matched, ACL written to the downstream router. He watched a production system go from hero to zero in 7 minutes, and finding a way to power cycle a router that size took him longer than the outage. Sean Gray was in the data center with him, still in college. That's the story sitting under the question Chris now puts to anyone selling autonomous remediation. Are you actually going to give an agent write access?
Also in this one. The engineer at Gartner who wired an anti-CISO agent to his own Gartner login, his tech stack, and his team's engineering bandwidth, so he can ask Claude to explain to his boss why they're not doing the shiny thing yet. Why Chris thinks the case for AppSec being dead is horseshit, and why the SIEM isn't going anywhere either. The hoodie-or-suit question he'd hand his younger self. And the product he'd write an angel check for tomorrow, which has nothing to do with security and everything to do with understanding what his teenage daughters just said to him.
Chris's ask is simple. Go to developer.kyberis.ai and start building.
Brought to you by YSecurity, the security team that works next to yours. Your first 8 hours with 40+ security engineers are free at ysecurity.io/startups.
Chris Kirschke: https://www.linkedin.com/in/kirschke/
Kyberis AI: developer.kyberis.ai
Jon McLachlan: https://www.linkedin.com/in/jon-mclachlan/
YSecurity: https://ysecurity.io