← All transcripts
EP. 20

The Economics of Cyber Offense & Defense

September 22, 2026 · 57 min ·Fernando Montenegro
Watch episode on YouTube
~56 min read · 163 exchanges
Mehul 00:01.336

Fernando Montenegro, it's so great to have you on the Noise 2 Signal podcast. Welcome.

Fernando Montenegro 00:07.282

Thank you so much. This this I'm look really looking forward to this.

Mehul 00:11.448

Fernando, when I reached out to you to come on the pod, you said I will only come on the pod if we raise the level of debate. So let's let's le re let's raise the level of debate on this on this podcast.

Fernando Montenegro 00:25.796

Okay. Well little a a little presumptuous of me, but let's see let's see where we take this. Yeah, absolutely. Yeah.

Mehul 00:32.936

Fernando, I want to start I I want to start this journey into your early days into the career. You started as a sales engineer, you were in different sales roles, and now you're the VP of cybersecurity practice at Future and Group, right? That's a that's a big change from what you've been doing. You've been selling software for a long period of time, and now you're you're an industry analyst in cybersecurity. How did that transition happen?

Fernando Montenegro 00:58.11

So even even before that, so hi everyone, Fernando Montenegro, like I I I I lead cybersecurity at at at Futurum. And my career I've been in in cybersecurity for give or take thirty years. The the the white hair that that you're seeing comes from yeah, yeah, pretty much. Right. And my c I've always been a technologist, right? So my background's computer science and and whatnot. And I've

had roles in as as customer support, as as security operations, right? And then as professional services, right, consulting, et cetera. Right. The at the time this was back in the days of of SOX, right, and and and and governance and and and whatnot. But anyway, it's been a long it's been a long journey. Along the way I moved from professional services into sales engineering, right?

And the rationale for that had a lot to do with what my what I felt my personal strengths were. Right. And I I always liked communicating and and and and and and right. And then I I spent a f ten years, give or take, a little bit more, maybe fifteen, as a sales engineer in in different roles, always in enterprise security, right? And then back in twenty seventeen, an opportunity came around to do something different.

Right. And my good friend Adrian Sanabria, he was an analyst at four five one research, and he he was looking for his replacement because he was moving on to something else. And he knew this weird guy on Twitter, me, who was arguing about all sorts of different things about the cybersecurity industry. And he told me, Look, what you're doing is pretty much what an analyst does. Why don't you why don't you come interview for this role?

And the role was so that the team at 451 was run by Scott Crawford, who I know that that that that that you you have as well. And so it turns out that Scott became my mentor as of as an analyst, right? And and he knew me on Twitter before I became an analyst, like like so he knew me already. So it was just so I spent a a a very nice time at at 451 learning the the ropes on many different things.

Mehul 03:02.391

He's coming out of here.

Fernando Montenegro 03:23.771

Then I moved on to a to a very interesting role with Omdia, who was another analyst firm, where I got a little bit more of the of the the quantitative side of things, market sizes, forecasts, those kinds of things. And then now for the past little while, I've been here at Futurum where I lead research overall, right? So quantitative, qualitative, etc. If you ask me, the the I've people once asked me, what's the origin story, right? And and and I say that.

Do you remember Highlander, the movie? Like the original Highlander. Did you ever

Mehul 03:57.6

I've I've seen it but I don't remember it as as deeply pr as probably you do.

Fernando Montenegro 04:01.569

okay, yes. It's it's like you watch it again, it's it didn't age that well. And by the way, there's a new remake, there's a remake coming soon, so I'm I'm curious to see that. But on Highlander, there was the prize, right? And the prize was like the what did you get after you if you got and the prize was you knew what people were thinking, right? And he said something along the lines of I know if if I know what people are thinking all over the world.

diplomats and and and presidents and whatever and I can help them understand each other, right? That's what I want for my role as an analyst, right? I want to be able to understand what buyers are saying, what sellers are saying, what investors are saying, and help them understand each other. Right. So

Mehul 04:42.219

Hmm. And that's like you know, your role is the perfect place to do that because you by by nature of your job, you get to talk to the people who are building the products, the people who are buying the products, the po people who are investing in products. So you get to be at the you know the center of all the things. so you're in the and you know, and you are also very active. You're also very active in terms of your writing. You write a lot, you write a lot, you have a lot of opinions about a lot of things on the state of

Fernando Montenegro 05:09.309

Sometimes sometimes too many. Yeah.

Mehul 05:12.461

you one thing I want to the one thing I want to get to is the state of the union of cybersecurity and AI. And you write about AI a lot in terms of what is happening. But given you know, given your intro, I also want to ask you, like you probably seen these you know, AI is all the hype right now, but you probably have seen a lot of AI winters way back in the early days of nineties, right?

Fernando Montenegro 05:33.307

I yeah, the the we we talked

We talked up we talked about this, yes, and and the the the the running joke is I I make references to movies all the time. So for the Lord of the Rings fans, when Elrond was talking to Gandalf about the foraging of the ring, I was there, Gandalf. I was there three thousand years ago. That's kind of how I feel about AI, right? In the sense that my my degree from nineteen ninety-four, like I'm old, and and back then it was already the beginning of the the the

the second AI winter. Like if you and what I mean by AI winter for for AI as a discipline has been around since the nineteen nineteen fifty seven, I think it was. and we've seen multiple phases where there is real excitement about the shield and then it dies, right? Because it collapses. Right. So there was excitement in the in the late 60s and whatnot and that collapsed. Right.

And then in the eighties and nineties, there was excitement about it as well because we were doing expert systems. We were using symbolic logic to to encode domain knowledge, right? And but that collapsed because that model didn't really account for all the variances in the world.

Mehul 06:50.581

And the funny the funny thing is, in every of these eras, artificial intelligence was like two years away. If you ask the scientist in nineteen fifties, it is like two years away. If you ask somebody in nineteen eighties, it's two years away. If you ask somebody in nineteen nineties, it's like next year we'll have artificial intelligence. So

Fernando Montenegro 07:07.293

Something like that. Yeah. But the thing was, and and so what happened was the the the the the interest in in AI diminished and and and people shifted their interest to you know what, if we can't really do the kind of stuff, can we use math differently? And that's where we had more statistical methods and and and and machine learning, and that's where things like support vector mechanisms came along and and

but then at the same time, we already knew about neural networks, right? So this was something we knew from from the 70s, I believe, even before maybe. And but we never had the compute power for that, right? Along comes this little company called NVIDIA, right? With a set of of of GPUs that were really used to playing games. And then the the the researcher behind AlexNat said, you what?

Mehul 08:04.373

Yeah. Let me try it.

Fernando Montenegro 08:05.415

We can we could yeah, we we we can use these to to to to to train much better. And that was 2012, I think. And and and that and and then things picked up from there, right? So it's fascinating to see where we are. as we record this. I mean here we are in in July of 26. We are about one year away from the attention paper for Google, being 10 years old, right? The attention paper for came in 2017.

Mehul 08:12.375

twenty twelve. Yeah, the Alex note.

Mehul 08:30.667

Yeah. I thought I thought you were going to say we are one I one year away from AGI.

Fernando Montenegro 08:35.639

no, no, no, no, no, no, no, no. So I'm so I'm of the the the the I say I live through interest because you asked me about the current state. I think that the state of the union is that we have found that generative AI and everything that surrounds it is extremely useful in many, many, many, many, many, many cases, right? But it's not AGI, right? And and it's when we overestimate the capabilities of those models,

that we get into trouble. Right. And where I where I'm I'm I'm hoping that the industry is going and and we seem to be going down that path is okay, we can do a lot with generative AI right now, but it's very expensive, whether it's tokens or or overall compute. Can we make it more efficient? Right? Can and one of the areas that I I'm I'm curious about where we're going to see things is this

Going back to the basics of not the basic, going back to the beginnings of like symbolic logic. There's a field called neurosymbolic AI, which is basically taking symbolic logic and and where do where can you take the best of both worlds? And we start to see that. If you know how Claude Code, the the the the the source code for Claude Code leaked a few months ago, right? And people went to look into that and look, there's 3,000 lines of Python here.

Mehul 09:50.731

Yeah, yeah. Yeah.

Fernando Montenegro 09:55.634

That is basically symbolic logic, right? So we're starting to see that. We're starting to LLMs as we think about them are not the be-all end-all. There is also really interesting work being done around world models, right? Can we encode that that knowledge of the world that some people refer to sometimes as digital twins, as a close proximity, right? That is really interesting, right? And and I urge people to pay attention to those developments where

what's going to happen what is the the the basis through which agents are going to reason through things. Right. So the the anyway, that's the the the

Mehul 10:36.555

When well so when you when you saw the f you know you say as if you know two thousand twelve happened and then we're we are right here, but that was a long journey from two thousand twelve all the way till twenty twenty two. It took ten years for Chat GPT to come along. When you saw the first Chat GPD moment, did you anticipate how it's going to change cybersecurity? Did you have that thought that it is going to completely transform or was it like, it can write lyrics in Taylor Swift's voice?

Fernando Montenegro 10:47.195

Yeah, yeah, yeah, of course, of course.

Fernando Montenegro 11:03.013

No, no, no, no. So funny funny story. I I hope I'm not embarrassing my my mom when I say this. But my mom, who is a brilliant medical researcher, she's in her eighties and she's still very active. And she's one of the smartest people I know. And and I remember vividly, November twenty twenty two, she was visiting me back.

Mehul 11:24.759

By the way, now that you have commented on your mom, you have to also comment on your wife because your wife is gonna get upset after she listens to this podcast. So I'm just warning you.

Fernando Montenegro 11:31.55

No, no, no, that's totally fine. My my my wife is brilliant. She she she's been my my my partner for many years. And and and but but the thing about the that has to do with GPT. because my mom was visiting us. we live in Canada. We're from Brazil originally. My mom was visiting and I came across Chat GPT and I showed her, Mom, look how cool this is and and and I typed a a

Mehul 11:39.381

Now we can go to the next. Yes. Go ahead. That's it.

Fernando Montenegro 12:00.837

a a prompt, right? And got back the answer I wanted. Of course it was generating the content. And then she was very impressed and she said, can you ask something in Portuguese? Right? And sure enough, I asked something in Portuguese and it came up in Portuguese and her eyes went, whoa. Then then in she asked something about her area of research, which is which is biology and and medicine and and genetics.

Right. And then she asked the question and the answer came back and she said, you know what? That answer is actually correct. Right. Okay. she goes back home to Brazil, and I kid you not, the very first thing that the the the next few days later, I c she calls me, like we we we we talk regularly, right? The pretty much the very first thing she asked was, okay, how do I get that on my computer? Right. and and and goes from there.

Since then, she now understands much better, of course, the issues with hallucinations and and and everything. But it but I was really it was really impressive for me to see an end user who is a very, very knowledgeable in their particular field take to this technology so quickly. And I think that this is something that to bring back to our industry and cyber and and whatnot, this is an area that they say that the four most dangerous words in investing are this time, it's different.

Mehul 13:14.754

Mm.

Mehul 13:29.322

It's different.

Fernando Montenegro 13:29.937

Right. this time is different in a sense because the the the level of autonomy that we are giving these things and the class of problems that they are working with is different. People people often compare the the rise of AI with the rise of cloud. I was there for the rise of cloud phenomenal technology. I I I it's it's it's it's marvelous.

Mehul 13:46.698

Mm.

Fernando Montenegro 13:59.954

But even cloud at its at its highest, it's always been very IT centric, right? It benefits IT. Hey, can I spin up if I can spin up VMs faster than I can buy hardware, if I can use serverless functions, if I can use databases, if I can use API gateway, whatever.

Mehul 14:22.572

Yeah, it was very tech centric. You have to be tech enabled to use these technologies. but with with you know something like cloud code. Yeah, it in cloud code you don't have to be technol technology be technology abled to be able to use these technologies and go from there.

Fernando Montenegro 14:28.217

AI is different.

Fernando Montenegro 14:36.135

But but not only that, the kinds of problems that AI as it stands right now is trying to solve or positions itself as being able to solve are different. You now have AI creating strategy plans. You have AI writing code. And and I want to bring yeah.

Mehul 14:57.706

Well, you have AI writing vulnerabilities and finding vulnerabilities as well.

Fernando Montenegro 15:01.533

Yes, and but but this is a very important point because what happens is

Why did why is coding, right? Coding specifically, why is coding so successful as an AI field? Right? I think that part of the reason, and and this is not just me saying it, like one of the most important things in AI for for practitioners to understand is the cost of verifiability, right? How how

Quickly an AI can learn has a lot to do with understanding how well it did in the previous run, right? the reinforcement learning. It's not exactly, but but so the point is when you write code, right, it either compiles or it doesn't, right? And then you write test suites and either it fails a test or it doesn't, right? and that

Because of that, it can learn how to do it better that much faster. We're starting to see that with security, right? You can why does vulnerability, why does AI created vulnerability disclosure appears to move so quickly? Because it is relatively easy from a computing perspective to verify: was this a vulnerability? Yes or no.

the the the the the asymmetry is that for the defender can i use ai to defend it's much more expensive right did we did we actually close the gap right so there's the there the there's a there's an economic imbalance between it's easier I'm not saying it's cheap, right? one of the things when Mythos came about, people were saying, God, this is gonna cost fifty dollars or or or whatever.

Fernando Montenegro 16:56.949

No, it's not that. I mean, even complex vulnerabilities are are are are are still expensive from a compute time perspective and everything, but it's still cheaper, right? And and and and it's cheap and but the defense it's more difficult. So anyway, I talk too much. The point the the point I I I wanted to make is that the the the current state of play is that yes, AI is able to do these things. It

Mehul 17:09.29

Yeah.

Fernando Montenegro 17:25.231

It seems to favor more the attacker in the perspective of creating vulnerabilities. The question that we have to ask ourselves though, and that's the point that that that I don't want to make this alarmist, is that is the existence of the vulnerability the constraint for an attack to happen? Right? And that's a and I would argue that it's not, right? There's a lot that has to happen for an attack to happen, right? I I

I know that people love the expression the defenders have to be right every time, the attacker only has to be right once. I respectfully disagree because what happens is the you have to have the right conditions for an attack to happen, right? You have to have the the the vulnerability, you have to have the the the reachability, right? And and and and the vulnerability has to yield the kind of failure.

Mehul 18:16.094

Reachability and you have to have it.

Fernando Montenegro 18:23.409

That allows you to exploit it for more things. It's not just enough to to crash a to crash a process, right? You have to be able to okay. And I

Mehul 18:29.952

get a foothold. You have to get a foothold into the system and then you can do lateral movement from there. All those things.

Fernando Montenegro 18:35.151

And in in all of those things, right, the attacker has to get right. Sure. so in all of those things, the attacker has to get right, risking capture by the defense, if the defense is doing the right things. So anyway, I think that it is a a a very vibrant environment that we're in right now, but it's the kind of thing where

People need to understand what are the A what are the capabilities of AI and where it benefits attackers and defenders.

Mehul 19:13.26

There are two things, there are two things I want to comment on. one is you said one you one is you said the the exploitation is expensive, but it tri from a trajectory point of view, it will start to get cheaper over a period of time. So attackers will continue to have that benefit. And then risking capture, it's not like physical capture, right? So they could I mean that doesn't you know, they can r they could run an exploit, get compromised, but then there is no

Fernando Montenegro 19:16.21

Sure.

Mehul 19:39.166

negative consequence in the sense they don't get jailed, they don't get put into jail or something on those lines.

Fernando Montenegro 19:44.37

Hundred percent, right? And and that changes the nature of conflict, right? Not to not to go off on a complete tangent, but we are seeing that in the evolution of drone warfare, right? Why are drones so effective, right? You don't particularly care if you lose one, right? So

Mehul 19:55.116

So

Mehul 20:00.95

Exactly. And and and that is my point too. That i the the because of AI, a and correct me if I'm wrong, my sense is the complete architecture of cyber defence will have to change to account for this cheap AI where, you know, going back to your inner wage, it's like a hundred dollar drone taking out a hundred thousand dollar tank. Right? Your defense is like still a moving at the speed of a tank, you know, it is taking its own sweet time, but the attackers can now move quickly and cheaply.

Fernando Montenegro 20:17.724

Yeah.

Fernando Montenegro 20:26.543

It doesn't mean that they immediately will, right? And it doesn't mean that just because attackers can move quickly, and they can, it doesn't mean that your organization, as it stands, is the immediate next victim, right? But as a prudent defender, you have to acknowledge that your adversaries now have more capabilities. Now they can move faster. Now they can

they're lowering the cost of of of that attack and that has consequences again it doesn't mean that that the sky's falling but you have to prepare for it and you have to you kudos in this case to to what Hugging Face did in relation to the open AI incident of a few days ago because they detected it and and it it it was a phenomenally interesting

Mehul 21:18.124

They stopped it, they repor and they stopped it, they reported it, and it was and they probably use the open models to stop it too. You know, the fascinating comment I remember from my my previous season is Ed Belis. Ed Belis said something to the effect and he is the founder of Empirical Security. He said, Just because I have the tools, I don't become a criminal. So just because you have the tools doesn't mean it it you can become a criminal, right? So so the tools will always be there. the attackers who are

Fernando Montenegro 21:34.759

Yeah, I know red.

Mehul 21:47.693

who are malicious they will go and attack these use these to s compromise these systems but people like you and i just because these tools exist don't become criminals to go and explore the exploit the systems a question for you is do you think you know trajectory wise if this is this continues if this continues do you see do you see a trajectory where these systems get banned these these these models get outlawed

Fernando Montenegro 21:57.286

Exactly.

Mehul 22:15.542

I mean, we are already seeing some debate around hey, these Chinese models are too t they're they are dangerous. my sense is this is mostly a regulatory capture play where from the leading models in the in the US, hey, we don't want all this competition. They're way too cheap and we have taken way too much money from all these investors. Help us, God. I'm curious what do think of those those things that are happening.

Fernando Montenegro 22:40.131

I'm listen, I'm I'm from a time like the the the original hacker ethos ethos, right? Information wants to be free, right? I think it's really difficult to to contain these things like this, particularly as you said, as you well said, like the the the consequences for an attacker are are not the same, right? So are we we're going to ban we're going to ban models.

Mehul 23:02.508

Yeah.

Fernando Montenegro 23:09.051

Great. We're in the context of what? Okay, maybe in a particular jurisdiction, the United States, Canada, Europe, et cetera. If an attacker is based somewhere where they can use this, they're gonna use it, right? so yeah, I'm I'm I'm much more I am much more open to the idea that defenders should acknowledge that.

the capabilities for the attackers have improved, right? And will continue to improve, and they have to respond in kind. Again, it doesn't have to, it doesn't mean that they have to do this right away or or or they have to do it on a timeline that makes sense for them. It's not that the sky is falling, but the world is changing. There's a there's a really interesting concept from I believe it's evolutionary biology.

Right. It's like they they call it the the Red Queen hypothesis, right? That in Alice in the Wonderland, I believe it is, right? You have the the the the Alice meets the the Red Queen that's always running, right? And and Alice asks her why are you running? I'm running to stay in place, right? That is the way that this industry works in a sense, right? We have to keep evolving to maintain our capabilities to to fulfill mission objectives.

Mehul 24:28.524

Yeah.

Fernando Montenegro 24:34.575

Mission objectives keep changing. We have to keep changing with them.

Mehul 24:40.076

Fernando, let's get to the meat of this debate. you know, when I as I said in the intro, as when I reached out to you, you said the only reason I would come on the pod is to raise the level of debate. And let's live raise the level of debate. Why well, first of all, where did this come from?

Fernando Montenegro 24:44.325

Yeah.

Mehul 25:01.932

You know, because you know, the more I talk to you, the more I realize you're a movie buff. You watch a lot of movies or at least have a very strong memory. You have a lot of you have a very strong memory. You really remember all these plot lines because your opening was to the Lord of the Rings, you're coming back to all these you know and then the Highlander and like, you know, so there is there is something going on.

Fernando Montenegro 25:07.091

god, yeah.

Fernando Montenegro 25:15.975

Hi Wonder.

I I I resisted I resisted yeah, I resisted an example using The Rock. If you've ever seen The Rock with Nicolas Cage and I I I I did not use it, I could have. Yeah. No, but but the the debate, the the the that line about the level of debate comes from my absolute favorite TV show of all times, which was The West Wing, right? And in The West Wing, there is an episode, I believe it was Let Bartlett be Bartlett.

Mehul 25:26.388

Yeah again, there's another movie reference. So

Mehul 25:40.832

Mm.

Fernando Montenegro 25:47.642

where Leo McGarry, played by John Spencer, who was the chief of staff to the president, is is trying to rally the troops. Like they've they've they they they were in a number of political fights about different things and and they were getting they they were getting beat left and right. Right. And Leo McGarry talks to the president and and they they they decide what they're going to do and so on. And

And then he takes that message to his troops, right? And along the lines, he says, we're going to try this, we're going to try that, we're going to try that, and we're going to win some of these, we're going to lose some of these battles, right? We may even lose the White House, right? But we're going to raise the level of public debate in this country and let that be our legacy.

Sorry, I tear up like even now. I want that for us. I want us to raise the level of understanding of what this industry is. And because of that, we are better at achieving our objectives. Right. That's what I'm trying to do.

Mehul 26:54.454

So maybe pause the slack because it is coming up. The Slack

Fernando Montenegro 26:58.541

I'm sorry. I okay, let me just give me a sec. I'm sorry about that.

Mehul 27:04.936

It's the the the the knocking sound is coming up.

Fernando Montenegro 27:08.445

Okay, I'm sorry. Okay, I'm quitting my Slack. Okay, sorry about that. But yes.

Mehul 27:15.992

so let's let's really you know let's raise the level of debate. if you look at our cybersecurity industry, if you look at our cybersecurity industry, it is predominantly focused on FUD. Fear, uncertainty, and doubt. It's just to scare people, bad things, buy our product, buy things, bad bad things are happening. Even when Mythos came out, the entire thing was focused around FUD because hey, bad things are happening. we can't share anything with you, but it is bad.

Right? Like we we can't give you anything, but it is really bad. It's so deadly, it's bad. Right. So what in your humble opinion is are the underlying economic forces that is driving the cybersecurity industry, or maybe even the vulnerabilities and all those things that we are listening to or hearing.

Fernando Montenegro 28:10.119

So I I we bring up economics because in my in my view, the one of the best ways to understand what is going on is through economics, right? And I'm I'm sorry to bring up another movie reference, right? for those that that have have watched it, Moneyball, right? seen it, right? So yeah, it's it's the the the the scene about the

Mehul 28:31.872

Yeah. I've seen that.

Fernando Montenegro 28:38.735

We are managing this industry thinking it works one way when it it if you look down a little bit deeper, it actually works a little different, right? And I think that you you brought up I I love the expression you brought up earlier, you brought up regulatory capture, right? that's what

Mehul 28:55.188

Yeah. I believe in it is I see the the the fingerprints of it everywhere I listen. So it's very difficult to shake that feeling off. Everything I look now the lens my lens is regularly captured.

Fernando Montenegro 29:06.821

Yeah, but but b I I think you are right in a sense because a lot of what's driving so I think that one of the the fundamental things that drives this industry is that security is a latent construct that it is an emergence. Security is an emerging emergent concept, right? You can't actually measure security. You can measure proxies for it, right? Security is an emergent property, as they say, right?

And everything that you do, every activity that you're doing about man measuring that security has a cost, right? So the the name of the game is how do you deal with the opportunity cost of what's going of all that you have to do? How do you choose? They say that economics is the study of scarcity, right? How how do you make choices?

When you don't have enough resources for everything that you want. The joke is the first rule of economics is there is always scarcity. And then the joke is that the first rule of politics is ignore the first rule of economics and promise everybody everything. Right. But but I think that the fundamental issue is economics, right? On on one hand, you have the you have people looking to optimize the marginal cost of finding vulnerabilities.

Right. or reduce the marginal cost of finding vulnerabilities. on the other hand, you have people who are dealing with how do I prioritize between what I need, when I need to fix something, where what do I actually need to fix? Right. Those are those are choices that that essentially result in am I choosing this because of the impact? How well do I know what the impact to my organization is of doing something? Right.

do I you had Ed Ed Bellis and and and the work that he and the others are doing at at Empire is really interesting, right? How do you find out what really matters to you, right? it's it's a it's essentially an economics problem.

Mehul 31:23.795

And in you know, in i in some sense, you know, security is not an is not a ROI discussion. You don't get more money because you did more secure software. Right. So if you're like an if you're in an early stage startup you just you're focused on shipping the product rather than fixing the world with this.

Fernando Montenegro 31:38.352

And and and the and the thing is, and the thing is, you know what? It is actually economically rational for you as a startup founder to do this, right? because since the buyer can't really tell the quality of of of of what you are buying, yeah, then then you then then you ship what's good enough. Now, of course that the and and and

Mehul 31:58.688

Perceived perceived or real. Perceived or if it's good enough.

Fernando Montenegro 32:08.477

I I keep saying to economics, and there is a phenomenal concept in economics called information asymmetry, right? And I think it explains this a lot of this industry, which is how do in a in a ideal economic transaction, the buyer understands the quality of what they are selling. The sorry, the buyer understands the quality of what they're buying, the seller understands the quality of what they are selling, they agree on a price and the price is the signal, perfect, right?

The real world is not like that. Like the buyer may know less about the product than the seller. In some cases, the seller may know less about the buyer, about what the buyer is going to do. so this was you've you've heard the term market for lemons, right? This was so it's it's again economics. So this was the work that George

Mehul 33:00.991

By the way, I have to ask you, I I have to ask you, are you a student of Austrian economics or are you a student of the Keysi Keysian economics? Like if you were to choose, if I had to put a gun to your head, which which line of economics are you more it looks like you're more closer to the Austrian school of economics.

Fernando Montenegro 33:18.929

I think that I I I I wouldn't pick a particular school. I would say that they all contribute different things. And I would say that the the if there is one school, like if there's one thing that I would like to say that I'm I'm particularly curious about, it's behavioral economics, right? Which is how do real humans, real non perfectly rational humans make decisions, make economic decisions under

Uncertainty right

Mehul 33:50.092

Yeah, but the isn't that I I th I mean this is going on a completely different tangent, but but isn't that essentially what Hayek and those said? You know, it's the echo economics is the is the study of scarcity, right? I mean you give you i i in some in some respects.

Fernando Montenegro 34:04.239

In in some way, yeah, but but but but then by the same by the by the same token, Keynes was has one of my the favorite lines that I that I that I I refer to all the time is that when the facts change, I change my opinion. What do you do, sir? Right? So the but but I think that they argue I'm I'm trying to argue more for us understanding, not so much picking a school. I'm arguing us more for understanding what is driving things.

the the the animal spirits that that we refer to as and and i i and i think that it's important for us to understand that and now so sorry going back for for for this from from a behavioral economics perspective what imp what biases do you have when you are making decisions that influence what's going to happen and and

Mehul 34:37.887

That are at least amount. Yeah.

Fernando Montenegro 35:02.341

Shout out here to I've I followed their I they they worked on this on cybersecurity for for like when I started reading more about this. Shout out to Alison Miller, I think she's now at at Google, and Kelly Shortridge, she's now at at Fastly, right? As as two people who have done a lot of interesting work on this on behavioral economics as it relates to cybersecurity, right? I read their work, I I

Love it. And the the the thing that sorry, I'm lost my train of thought. The thing that I find interesting is if we look deeply enough, we understand that we understand why things happen. And then it's about you see once you understand why it's happening, you understand what levers you can and you can't pull, right? Ultimately, if there is one thing that that that I believe in.

Mehul 35:55.083

Mm.

Fernando Montenegro 36:01.529

Is that security no, I'm I'm I'm sorry, but security is not a moral imperative, right? people are going to choose how much security they'll deploy based on their own incentives. And if you don't understand what those incentives are, if you don't play those incentives, it it it's foolish to try to get them to change their mind.

Mehul 36:23.795

No, that is true because you know I have also personally experienced this. You know, I I I have always been a product builder and I always thought the best products will win. But then when I when you go into the market, sometimes it could just be a compliance requirement. Especially vulnerability management products. They they buy vulnerability management products not to secure themselves, but to satisfy a compliance requirement which is required to gain new business or maintain their existing business.

Fernando Montenegro 36:47.229

And that is information asymmetry in a nutshell, right? And in in in the sense, right? Because I I was talking about information asymmetry. So in the work of of I was gonna say George Akerloff and the market for lemons. Now I remember. It's the notion of in a given market, if you don't know the quality of something rightly, imagine a market of used cars. Every used car is the same, right? Same model, same same year, but

Hypothetically, they have different quality. There are better cars and there are worse cars, right? The cars that have been better maintained or not, right? There is a very specific failure condition in the market where if you don't, if you as a buyer, you don't know the price, you don't know whether a car is good or not. You are not going to pay as much as the person who has a good car wants, but you are going to pay more than the person who has a

a bad car once. So what happens? The good the person with a good car leaves the market. So the overall quality of the market decreases. I'm I'm I'm probably trans simplifying the the the research wrong but the point I'm trying to make is that in the market if there is if there is an imbalance in what do we know about quality, right? It's a market failure, there were two mechanisms

That's that that came up came across. This is economics. This is not cybersecurity. There are two mechanisms to explain it. One is called signaling, and the other one's called screening. So the three so George Akerloff won the Nobel Prize in Economics for this. He shared it with Steglitz and Spence, who were the author who are the authors of these mechanisms, right? The signaling mechanism is if you are the party that knows more about the quality, right? If you're the seller,

And you know about the quality, you signal that, right? So, for example, you say, I am certified here, I I certified, and here's my my certification for this, as an example. The screening mechanism is that if you are the party that doesn't know as much, you develop a selection process where the quality is going to emerge through the selection process. You're going to screen.

Mehul 38:48.531

Mm.

Fernando Montenegro 39:14.279

You're going to put enough gates that only people who, by virtue of how you designed it, have the quality that you want are going to be the ones out of this. This is why RFPs are such a big deal for a vendor, right? Because the RFP is a selection process where, look, if you don't have a 5 million, 10 million, $50 million bond, you don't even comp you don't even compete, right? Or this is why.

Mehul 39:40.469

Mm.

Fernando Montenegro 39:42.33

yes your product has to be has to be certified you show me your sock to type two right that's a that's a quality gate on the screening process right and once anyway so you once you understand these it the industry becomes very interesting

Mehul 39:55.047

And no.

Mehul 40:02.955

You know, you you bring up an interesting point in the sense that when I was talking to you earlier, you said something to the effect that there is this there is a theory of inferior goods. There is this theory of inferior goods and security where good enough you know good enough is good enough. You know, you don't need the best.

Fernando Montenegro 40:21.251

of yes and and and i'll i'll i'll i'll i'll clarify i it first of all in the the the the the the name is horrible it's called inferior goods it's not necessarily a quality it's not a quality assessment it's not that the good is bad right an inferior good in economics is a good that you consume less once you have more income that's that's pretty much and the the the prototypical example we we like to talk about is look

Back when we were all in in school, we all ate crappy food because it was cheap, because there's a right you stop theoretically buying when when you get better. there are such a thing as inferior goods in cybersecurity as well. I mean, the there are the the the cheap products that you buy because that's what you can get now, right? But once you know better, once you have the resources, you can get others that are better, right?

Mehul 41:14.058

Yeah.

Fernando Montenegro 41:21.361

The thing that is interesting is that where we were talking earlier is that there is a balance because you don't need you don't need theoretically the best of everything at all times. And the example I like to I like to use is depending on your threat model, right, you may choose different things. Here I am sitting at home in just outside Toronto, Canada, and yes, my doors are locked.

But if if if a hit assassin team wants to get to me right now, they'll get to me. I'm vulnerable to that, right? How do I evaluate the risk the the of of that happening? Well, in my risk assessment, that's a very low risk, right? So I don't need to have armed armed guards myself or have

Mehul 41:58.538

Yeah.

Fernando Montenegro 42:18.279

Bulletproof glass or or or or or right? So choosing something that is good enough is good enough. And the problem is too often in the industry we we argue that my God, you need to buy this because it's the best product for this. Do you really need that? in some cases you do, in some cases you don't, right? And and trying to get trying to buy that for everything.

It's not practical.

Mehul 42:50.611

Yeah. the next topic I had for you was that that you mentioned the principal and agent problem. the principal and agent problem, especially, you know, the AI agent that is in play. And you had a lot of opinions on that too.

Fernando Montenegro 43:10.307

i it it it it it's funny because the the I really apologize to the economists and the statisticians and on on in the audience because I'm probably butchering a lot of things. My background's computer science, not economics. But

Mehul 43:23.689

I'm I'm trying I'm starting to wonder if this is an economist podcast or a cybersecurity podcast.

Fernando Montenegro 43:27.901

But but but the point is in economics there's something called the principal agent problem. And agents here are not the agents you're thinking about. They are they are economic agents, right? So when you are a a principal, so a principal is someone who is hiring somebody and they hire an agent, right? So the agent is going to do something for you as the print, right? The principal agent problem is

Simplifying when it if you design the the the contract between agent and principal in a way that doesn't have enough verifiability between them, there is a there is an issue where the agent might maximize their own utility, their own benefit, and not yours as the principal, right? So they they they

They they are going to do what's best for them. And the the examples might be that, you you hire someone to do a scan of your network, right? whatever, and they I I'm gonna date myself here, they run Nmap against your network and they present you a report, right? And that's it, right? Done.

Wait, that's not like if you don't understand what and what a scan should be like, right, that person, it's economically rational for them to spend as little time as possible to get it done and move on, right? So if you don't understand what your agent is doing, if you don't understand what your agent, if you don't specify to your agent what you want done, and you don't understand what your agent is doing, right, you risk.

Mehul 45:21.397

Hmm.

Fernando Montenegro 45:27.057

this kind of problem. Well, it's it we see in a sense, the a similar thing now with AI agents. If you don't understand

Mehul 45:36.019

And that's precisely the reason I wanted to bring up this discussion is because y you can have a very well defined contract between you and the and the claude or the AI agent where you can actually see what work is getting done and you can see the work getting done at a far much lower cost than a agent, like a human agent that you would hire to do that do that job. And the question I had for you is do you see then do you buy into this narrative of job losses because of it?

that you know you the the the principal agent or the AI agent problem, like the principal, somebody who's hiring these AI tools to do the job, they can actually see what work is getting done. They can approve, you know, they're using cloud code or something on those lines, get the job done at a far cheaper cost than a human agent. And as a result of it, they don't need as many humans to do the job.

Fernando Montenegro 46:27.121

That part, I mostly think it holds, right? Hear me out. I think that the the there are two problems here. One problem is how do you as a principal understand what your what your agent, your human agent, does, right? Are you able to accurately replace

Mehul 46:47.474

Mm.

Fernando Montenegro 46:54.191

your human agent with an AI agent, I don't think you are, right? I yeah. And and and and honestly, this is the AGI conversation. Maybe in a few years, right? Yeah I don't I I think that we are at the point where we have AI is extremely beneficial to accelerate, sometimes replace entire tasks and workflows.

Mehul 46:58.472

Right now, right now, currently.

Mehul 47:22.73

Mm.

Fernando Montenegro 47:23.109

It does not replace the role, right? So if you imagine somebody right and and I say this as a my industry, like industry analyst, we are being disrupted by AI in a sense. We all are, right? But if you don't, if you expect an AI agent to replace the entirety of what an analyst does, you are going to miss out on the on the non-tangibles, if you will.

Mehul 47:25.898

Yeah.

Fernando Montenegro 47:52.508

The intangibles of of of what that analyst is doing, how they are connecting things, how they're bringing different areas together, for example. Right. But the same thing happens in other professions as well. Now, that doesn't mean that you, as a principal, can't give an a human agent AI tools to do the job better, right? and and to use a a non-AI analogy.

I had we had some some remodeling work done in our house a few years ago, right? And one of the things that fascinated me was seeing the contractors with very efficient nail guns, right? I'm I'm I I I'm still of the age of, you know, like but no, they had they had very efficient ways of of it's not and it's not just a nail gun that fired one, it's like they they had whole strings of nails and blah blah blah.

Mehul 48:31.305

Yeah.

Fernando Montenegro 48:46.641

was really impressive.

Mehul 48:46.972

And yeah, I I don't know if they had the the top of the line measuring equipment as well. Like they have the lasers, they can just point it to a direction and they just measure the length and everything. So yeah, so the

Fernando Montenegro 48:56.345

Exactly. But but but but that's the thing, right? But you still hire a contractor to to to to to to do some things for you. I think the same thing happens with AI, at least for the foreseeable future. The smart organization is going to look at their look at at their workforce, their human workforce, is going to see, okay, what is that workforce doing? What parts of their work could ai help with? Sorry, right.

Mehul 49:00.712

Yeah. Yeah. Yeah.

Mehul 49:24.714

I don't know

Fernando Montenegro 49:25.531

What parts of their work could AI help with? Let's give them AI to solve that. Now, as you do that, is there going to be job loss? Probably, because if it if it took five people to handle the workload that you have as a business, right? And now you've you've made those five people twice as effective, you st you didn't double your business.

Mehul 49:45.353

Yeah.

Fernando Montenegro 49:54.278

Right. You still only have to handle so many requests. Two things. That gives you the opportunity to go pursue more requests. Right. You can grow your business. Or it gives you the opportunity to pare down the costs that you have. The cost of running the business. Again, we go back to to economics and accounting. Right.

Mehul 50:03.497

Yeah.

Mehul 50:10.28

Cost of running the business.

Mehul 50:15.752

The last the last topics I had on the economics section for this interview is the theory of theory of theory of constraints. I need to pitch this to some economists. Hey, I just had the fascinating economics interview. So the last economics topic I wanted to discuss with you is the theory of constraints because I pitched to you a new research that my my team did.

Fernando Montenegro 50:23.718

my God, we we

We had fun with this one.

Fernando Montenegro 50:38.148

And and hardly

Mehul 50:41.694

where we were able to exploit vulnerabilities for three dollars in eleven minutes. And you said, that is not the point. You said or you argued in the sense that exploit generation is not the is not the constraint. maybe maybe you can dive deeper on that.

Fernando Montenegro 50:54.225

Potentially.

So I will and and I I'll argue one thing, so just to be clear. Theory of constraints is not so much economics as it is operations management, right? So if I if I to go back to the raise the level of debate for for for a little pretentious on my side, I apologize. But the the two disciplines that I think would would help practitioners learn more would be operations management and economics, right?

Mehul 51:05.386

Yeah.

Fernando Montenegro 51:25.285

operations management for the the the efficiency of running things and and so theory of constraints my understanding comes more from the operations management side of the house and and the theory of constraints is that so I first read about this in the Phoenix project. if people haven't read it it's an an an older book about DevOps phenomenal book. But so David so Goldbratt the theory of constraints the the book he wrote was called The Goal I think.

Mehul 51:42.666

Amazing. It's an important yeah.

Fernando Montenegro 51:53.07

And the theory of constraints simply is that every system has constraints, period. Right? The only thing, and what's the constraint, right? That's the bottleneck, right? And you have to find the bottleneck and you have to fix the bottleneck. Because if you fix something that happens before the bottleneck, guess what? You just made the bottleneck worse, right? if the bottleneck could only process 50 things a minute.

And and you and you made the process go from 100 to 200 things a minute, guess what? You just made it worse, right? And you can't fix things after the bottleneck because things are constrained by the bottleneck. If they if you can only output 50 things a minute, you build a system that takes each of those things and does something else at a thousand a minute, you're just wasting it because you can only get 50 things a minute, right?

So I think about that in the context of of vulnerabilities because I don't know and that we should automatically say that.

Creating a vulnerability was the constraint, right? I think that they in some cases it may have been, but the way that attackers work, they they will pick whatever works for them. Like if they can find instead of of hey, I can't create a vulnerability, but I can social engineer some help tech, some some help desk person to reset the credentials that I'm after, I'm gonna do that.

So but anyway, but the the the theory of constraints, I think it's an interesting concept for people to learn.

Mehul 53:36.959

But my qu my question is, isn't one of the constraint, especially in the in the space of vulnerability management, is that the attackers didn't have the time to create all these exploits and create a cre not just the creating the vulnerabilities, but creating the exploit because it takes a lot of time, testing and so on and so forth. And now you can prompt your way to an exploit. So instead of focusing on maybe the two or five percent of vulnerabilities, you can go to thirty percent of the vulnerabilities are out there so that because you know just cheaper, faster and better, so that that

Constraint from an attacker's point of view has been removed. Yes, that constraint has shifted.

Fernando Montenegro 54:08.507

That constraint has shifted, right? So now the so let's look at the attacker point of view. Maybe for their model, the constraint was, I can't create exploits fast enough. now I can create exploits fast enough. What is my next constraint? My next constraint is, maybe I don't have now that I can create the exploits fast enough, maybe now my constraint becomes I can't.

operate the campaign at at at at the cost that I want to. because that's the thing about the theory of constraints. Every system has constraints and if the moment you fix one, the constraint moves elsewhere, right? And the moment that the constraint moves elsewhere, at some point you don't care because that's not a constraint for you anymore. I'm exaggerating to make a point. Okay. But please don't take this as as gospel. But

Mehul 54:40.935

At the scale at at the scale, yeah.

Mm.

Fernando Montenegro 55:06.553

If the attacker changes their process so that look, I've I've optimized my system in a way that I can now generate a million dollars in yeah.

Mehul 55:18.098

Thousands of exploits, yeah. Thousands of exploits and run thousands of exploit campaigns.

Fernando Montenegro 55:22.139

Yeah, I can generate a million dollars, but you know what? I'm gonna stop here because if I gener if if I keep going to 10 million dollars, then I'm going to be much higher on the Interpol watch list. And and so you know what? The the fact that I have a million dollar constraint is enough. It's not a problem, right, for me. Right. So I think that's the the that's where I would apply this in the in in the in a sense.

Mehul 55:50.741

So the last last topic for today, Fernando, what does this mean for enterprises? Like you know, the h enterprises were very focused on, you know, investing in the tools and technologies for cyber defense, but now cyber offense is getting cheaper, faster, better, those things are going to, you know, in the get better n for the attackers, not necessarily for the defenders. When this massive technology shift is happening in AI.

From all the offensive tools to defensive tools, how should enterprises think about securing their enterprise from your point of view, in the age of AI?

Fernando Montenegro 56:27.877

In the age of a age of AI. So one one joke I like to say is that so I'm originally Brazilian. And in Brazilian Portuguese, the letters A and I spell I. Right? I is the sound you make when something hurts. Right. So if I point if I punch you in the shoulder, you're gonna say I, right? And and that and that sets the stage for for for me covering this entire space, right? I right.

Mehul 56:39.389

Okay.

Mehul 56:51.922

So are you saying I for the defenders? Are you saying defenders in this way?

Fernando Montenegro 56:55.309

Aye for it. Aye yay aye. Right. It's a it's the the I actually got that once as a as a as a report title. I said, Ay ay ay, right? In the but

Based on everything we spoke about, I think that you bring up the very real scenario that things are accelerating. Right. You bring up the very real scenario that there are that there are adversaries who can now do things cheaper. plug for you, like I you showed me, and I was like, This is really cool. The the the the the work that you guys are doing on the economics of yeah.

Mehul 57:30.056

Yeah, on the vulnerability yeah, vulnerability research labs. Yeah.

Fernando Montenegro 57:33.679

I really like I think that's a phenomenal education tool, right? for for for a security team to say, look, yes, these things can cost. Here's how much this can cost.

Mehul 57:44.682

No, the re and the re and the reason we did the reason we did the research on vulnerability research labs is because nobody was able to quantify how how how cheap is it or how fast is it. Like people told us random numbers, AI models are getting easier and faster, but then no one told us how fast or how cheap.

Fernando Montenegro 57:59.706

And and and and and here's the thing, right? I I maybe you may be right, you may be wrong, right? but you're but but it's the directionality, right? It's that something is going to cost maybe something's going to cost fifty dollars as opposed to fifteen, right? But it's still but but it's the scale of things. It's not gonna it's not something that's gonna be fifty thousand dollars, right? I think so I I

Mehul 58:27.626

Yeah.

Fernando Montenegro 58:29.627

The thing I would say for enterprises is that

Try to understand and and and I I to bring back to movies, right? The the the look how Billy Bean in in Moneyball, how he thought about the game of baseball different, right? Inspired by the character play Peter Brandt was Jonah Hill, right? Because he had that scene where he said, Look, there is this game the

people think in terms of buying buying players when you shouldn't be buying players, you should be buying runs. And right and and so think about different like understand the economics and the systems thinking that goes into

Mehul 59:08.446

Hey yeah.

Mehul 59:16.084

So what's the equivalent of runs in cybersecurity?

Fernando Montenegro 59:20.069

That's a really good question. I think that the equivalent it it's security outcomes. I think that the the the the equivalent of rent is outcomes, right? Because you want it doesn't matter that you're using a vulnerability tool A, code security tool B, a or that you because you understand economics, because you understand incentives, you sat down.

with the with the CTO and between the two of you you decided that you know what instead of of coding this system I'm I'm completely making it up of course instead of doing this as a as a VM running the database whatever we're going to make this as a serverless function that that only runs a couple of times an hour or a minute or a second or whatever.

Mehul (01:00:15.29) Yeah.

Fernando Montenegro (01:00:16.037) And you completely avoid the problem to begin with. You bought the outcome of not having the vulnerability because you were able to understand that the best defense is not to is to not be there, like I used to do martial arts. The best defense is to not be there in the first place. Right.

Mehul (01:00:33.349) And you know, this is that that brings up a very interesting point because in in vulnerabilities we have the situation where the you have all these old applications that are never used, but they are vulnerable as hell, but they're still there on these old systems. So why not just delete them? Just delete them, take it out of the equation so that that attack vector no longer exists. Like if you're you're not using Firefox, just get rid of it.

Fernando Montenegro (01:00:52.615) But hey, I I I I love Firefox, I use it all the time. So let's let's there's no trauma. But but but the point is that's a good example. Why do you why are those applications there? Right? Maybe they are there because there is this very old process that requires them. Why hasn't this process been updated? Well, this process hasn't been updated because the it only

Mehul (01:00:56.925) How about Chrome? How about we settle with Chrome?

Fernando Montenegro (01:01:20.751) generates X amount of money for the organization. But then it's on you as a security team to say, look, this process only generates X amount of money for the security organization. But we can show or or we we can point to the fact that look, it it it contributes to our overall risk profile that increases the likelihood that we're going to lose X amount of money as on a security incident.

And it it's understanding those trade-offs. So I think that my my mission, or not my mission, but my my guidance to organizations is try to understand how these things are related and how underneath it all, right, what are the incentives at play that you need to understand? Maybe you can change things, maybe you can't, but at least you understand where they are.

Mehul (01:02:09.971) Yeah.

Mehul (01:02:15.333) Awesome advice. Fernando, last question of the day. You are a very active you're a very active writer. What's the next big report or blog that you're writing? What keeps you excited?

Fernando Montenegro (01:02:27.887) I hate to join the crowd in the sense, but a lot that's going on around Agentic is super interesting. We just wrote I just wrote a a note, it's it's available online. we argue that from an economics perspective, people should really be paying more attention to agentic authorization and runtime over the identity conversation. So that that that was one piece.

Mehul (01:02:49.769) I see.

Fernando Montenegro (01:02:53.521) the my my next piece of writing, I'm trying to see if I can get my hand my heads around we mentioned it at the beginning, some of the stuff around verifiability, right? Help people understand why why does why does attacking progress more than defending, right? I'm I'm still thinking it through, but it's fascinating. Like I I

I have a joke that I say like they've never a dull day in this industry, right? So I'm I'm let's let's let's let's see what this murderer does. Yeah.

Mehul (01:03:26.553) Let's let's let's end on that. There is never a dull day in this industry. That's a good good that's a good note to end this interview. Fernando, thank you for coming on the podcast. This was awesome. I can't tell if this was an economist podcast or a cybersecurity podcast, but I think people who have interest in economics or cybersecurity, they'll both get some value out of this conversation with you.

Fernando Montenegro (01:03:43.995) I hope it was close.

Fernando Montenegro (01:03:50.735) I I I I had a wonderful time. Thank you for doing these and and and I've seen some of the other episodes. You have great insights from other people and then you have me. I don't know why, but that's okay. Anyway, thank you very much, Mahoul. This this this this was wonderful. I hope I hope we we cross paths again very soon.

Mehul (01:04:02.515) Thank you.

Mehul (01:04:09.674) Thank you.