Episode Details

Back to Episodes
Episode 69: Built Wrong: Why Cybersecurity Is Failing and What We Must Do About It with Richard Bird

Episode 69: Built Wrong: Why Cybersecurity Is Failing and What We Must Do About It with Richard Bird

Episode 69 Published 14 hours ago
Description

Richard Bird, a 25-year cybersecurity veteran and former Global Head of Identity at JP Morgan Chase, joins Den Jones to deliver a frank, data-driven indictment of how cybersecurity has been measuring the wrong things for decades. They explore why increased spending hasn't made organizations safer, what three metrics actually matter, and how to rebuild on outcomes over activity.


EPISODE HIGHLIGHTS:

  • Richard Bird's Career JourneyRichard describes his accidental entry into identity at JP Morgan Chase, managing a global function before moving to startups and VC.Key quote: "I'm in the third stage of my career. I'm learning something new every day... none of which were things that I was ever exposed to prior to about 2018, 2019."
  • Announcing the Book: Built WrongRichard introduces Built Wrong: Why Cybersecurity is Failing and How We Can Rebuild It, a systemic diagnosis backed by over 110 citations.Key quote: "The most important thing that I'm trying to answer with this book is are we getting safer today versus where we were yesterday?"
  • The Hacker in a Hoodie IndexA presentation sparked the metaphor comparing adversary ROI against defender spending.Key quote: "The bad guys are doing six times better on the invested dollars that they're using to attack things than we're doing on the dollars that we're spending to protect things."
  • Measuring Activity Instead of OutcomesCybersecurity fails to measure performance in financial terms. FBI IC3 data shows losses grew from $800M to over $21B in ten years alongside rising security spend.Key quote: "We're spending more money and losing more money. This is not a business that anybody would invest in."
  • The Myth of the Sophisticated AdversaryMost breaches are not novel or sophisticated; the same problems recur yearly.Key quote: "We can't even fix the problems that we know about... hundreds of thousands of breaches and exploits every single year, and we haven't improved on a single one."
  • Stop Using the Word "Risk"Risk is a financial term. Allowing excessive standing privileges that lead to a breach is a bad decision, not risk.Key quote: "Risk is what is left over when you have done what you are able to... none of that was risk. That was all self-chosen."
  • Self-Perpetuating Mythology30 years of wrong metrics reinforce bad behavior and defeatist narratives.Key quote: "We are literally the only profession in the corporate world that gets up in the morning and goes, I'm going to go to work and get my ass kicked."
  • The Three Metrics That MatterCurrent practice lacks three vital measures: Exposure (attack surface), Interdiction (stopping exploitation), and Consequence (containing blast radius).Key quote: "There are only three things that need to be measured in security, and these manifest virtually nowhere on the planet currently today."
  • Compliance Frameworks & Outdated ControlsNIST, CMMC, and ISO frameworks create a self-sustaining revenue machine without reducing risk.
  • The IT Operations Origin StorySecurity metrics originated from 1980s IT ops, treating security like uptime rather than safety.
  • How to Fix It: Aviation & Safety EngineeringRemediation requires safety engineering, day-over-day safety tracking, and NTSB-style forensic disclosure.
  • Business Economics & CybersecurityApplying unit costing and performance compensation to integrate security into business operations.
  • Stewardship & Digital TrustOrganizations have a core obligation to protect customer data to restore broader digital trust.



Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us