Transcript
Manoj Tandon:
Hello everyone, and welcome to another episode of Dark Rhiino Security: Security Confidential. I’m your host, Manoj Tandon. Before we get started, please remember to hit the like and subscribe button. The algorithms rule, and every click helps us continue bringing you this content. We truly appreciate it.
Today we have an exceptional guest joining us. Grant Asplund brings over 25 years of experience helping organizations defend against sophisticated cyber threats. He has traveled and spoken globally, including at RSA, and has worked closely with analysts, partners, and executive leadership across the industry. Grant has held senior roles at companies such as Dome9, Blue Coat, Neustar, and Alto Networks, and he led MetaInfo through its acquisition by Neustar. He’s also a podcast host, leading Sizzle Secrets and Talking Cloud, where he explores cloud security trends and leadership insights. Grant, we’re honored to have you. Thank you for joining us.
Grant Asplund:
Manoj, the honor is mine. Thank you very much. I’m thrilled to be here.
Manoj Tandon:
Let’s start with your background. I’m not talking about Lake Louise—though there’s a story there—but how did you actually get into cybersecurity?
Grant Asplund:
Honestly, I kind of fell into it. A guy bought a computer, and a few months later said, “Hey, we should be selling these.” That’s how I got into the business. Then in February of 1998, I went to work for MetaInfo, and two months later Shlomo Kramer came in and said, “We just acquired you.” That’s how I specifically landed in cybersecurity.
Manoj Tandon:
That’s quite a start. Were you formally trained as a computer scientist?
Grant Asplund:
By training, I have a high school diploma. I like to joke that my PhD is perseverance, hard work, and determination—earned at the School of Hard Knocks. I moved out of my mom’s house when I was 16, finished high school, did a little college, and was eager to get into the world and make my mark. I’ve been incredibly fortunate in my career—blessed, really—and I’ve managed to stay relevant for over four decades. A lot of that comes from my upbringing and the gray matter my parents gave me.
Manoj Tandon:
That’s a powerful story, and it’s inspiring for younger listeners or people thinking about transitioning into cybersecurity. What advice would you give someone looking to break into the industry today?
Grant Asplund:
Everyone’s path is different, but there are some fundamentals. First, you have to put yourself out there. You need self-belief, courage, and the willingness to knock on doors, attend meetups, and engage with people. There’s an old saying that it’s not what you know, it’s who you know. I actually disagree—it’s not who you know, it’s who knows you. You need to be visible and create waves.
As for cybersecurity specifically, the exciting thing is that no matter when you enter, you’re still getting in at the beginning. This industry keeps evolving and accelerating. That can feel overwhelming, but there’s a wealth of free and paid training available online. Still, nothing replaces hands-on experience. You have to get in the saddle.
One of the best starting points is a help desk role, especially at an MSP. You become a catcher of all problems. You’re exposed to networking, systems, security, applications, and business operations. It’s an incredible foundation and helps you discover what truly interests you.
Manoj Tandon:
That’s some of the most practical advice we’ve heard. Most people want to jump straight into being a SOC analyst or red teamer, but the help desk really does give you a broad foundation.
Grant Asplund:
Exactly. You’ll constantly encounter situations where you don’t know the answer and have to figure it out. That learning loop is invaluable. And even with AI coming into play, I still don’t think there’s a replacement for that foundational exposure.
Manoj Tandon:
Since you mentioned AI, we have to go there. Entry-level roles seem like they may be impacted first. Do you think cybersecurity is becoming harder to enter, or is the path simply changing?
Grant Asplund:
You’re not going to lose your job to AI. You’re going to lose your job to someone who uses AI and you don’t. That’s the real risk. I’m a firm believer in an AI-first mindset, similar to how companies once adopted a cloud-first approach. Understanding AI, learning how to use it effectively, and mastering prompting is critical.
AI is incredibly powerful, but it’s only as good as the prompts you give it. Think of it as an assistant that knows everything on the internet but is useless without direction. You don’t get sniper precision—you get a volley, and you refine it iteratively. That’s a skill people need to learn.
Manoj Tandon:
We’ve seen that firsthand. People complain about AI output quality, but the real issue is often poor prompting and lack of verification. Hallucinations are real.
Grant Asplund:
Absolutely. In fact, hallucination actually saved us in one recent agentic AI attack that was 80–90% autonomous. The system falsely claimed it had valid credentials, which didn’t work, and that failure helped prevent further damage. That won’t last forever, though. These models are improving rapidly.
Manoj Tandon:
That’s sobering. Where does this leave organizations that view cybersecurity as a shopping cart of tools rather than a strategy?
Grant Asplund:
That’s where many go wrong. Some of the most basic blocking and tackling still isn’t done—patching, MFA, access control. Organizations need to assume they will be breached and focus on limiting impact through segmentation, minimizing blast radius, and preventing lateral movement.
Most security programs are still infrastructure-centric and perimeter-focused. We need to shift to being data-centric. Data is what attackers want, whether it’s ransomware or nation-state espionage.
Manoj Tandon:
That’s nuanced. Can you expand on what being data-centric really means?
Grant Asplund:
It means starting with the data—inventorying it, classifying it, governing access, and controlling how it moves. With AI agents accessing data, the agent shouldn’t have free rein. Access should be inherited from the user’s identity and permissions. If a vice president queries an agent, the response should reflect their access level. If someone else asks the same question, the response should be different or denied.
Security that’s built around data access scales better than perimeter-based models, especially in an AI-driven world.
Manoj Tandon:
That aligns with the idea that nobody is breaking in anymore—they’re logging in.
Grant Asplund:
Exactly. And the explosion of non-human identities—especially in cloud environments—has made this even more complex. Managing, deprecating, and securing those identities is a massive challenge.
Manoj Tandon:
So what would you tell a new CISO stepping into this environment?
Grant Asplund:
Today’s CISO has to be a translator—someone who explains cyber risk in business terms to executives and boards. Technical depth matters, but judgment, communication, and prioritization matter more. Zero trust principles are critical, but they require work and discipline.
And CISOs need independence. Reporting into IT creates conflicts. Cybersecurity is about risk, and it should align with whoever owns enterprise risk—often the COO or CEO.
Manoj Tandon:
That’s a debate we’ve had often, and I agree with you. Before we wrap, what would you like to leave our audience with?
Grant Asplund:
Check out the Talking Cloud podcast—we cover topics like this all the time. And remember, security done right doesn’t slow the business down. It enables trust, speed, and confident decision-making. Security isn’t about the perimeter anymore—it’s about the data. When governance and security align with how business operates, everyone wins.
Manoj Tandon:
Sage advice, Grant. It’s been a pleasure having you on the show. Please don’t be a stranger.
Grant Asplund:
Thank you very much, Manoj. I really appreciate it. Great being here.