State of Cybersecurity 2025 | December 2024 | Nils Puhlman & Mark Carney

Fireside Chat: State of Cybersecurity 2025

Join us for this fireside chat hosted from Las Vegas to talk about Mega Trends for 2025.

Speakers Nils Puhlman, CEO of Endari (7x CISO) and Mark Carney, President of Evolve Security.

Conversation Agenda:

  1. Megatrends in Cybersecurity
  2. Innovation & Investment: Where Cybersecurity is Headed
  3. AI Innovation: Transforming Cybersecurity
  4. Strategic Priorities for the Year Ahead
  5. People + Platform
  6. Evolve Security's View on Pen Testing
  7. Endari's View on Security Maturity

Transcript

Mark Carney:

Welcome to the Fireside Chat. I'm Mark Carney, and I'm here with Nils Puhlmann. We decided to come together here in Vegas to talk about what's next in the cybersecurity industry. We're going to talk about mega-trends — venture capital and private equity, and how they're spending money in the cyber space and its sectors. We'll also cover some topical areas: AI, automation, and LLMs; industry-specific concerns; the size of businesses and what their threats are, and how they're going to overcome those; and a variety of other things. So, welcome — we're excited to get started.

Let's start with some macro trends in the industry. Nils, what are your thoughts?

Nils Puhlmann:

The macro trends in our industry have always been a reaction to bigger macro trends — economic, geopolitical. What we're seeing is that the complexity of the issues, or threats as some people might call them, is going up, simply because on a macro level things are getting really complex and complicated. What this means for the industry is that it has to cope with so much more complexity, and there's only so much money that can address all the problems. Suddenly, companies large and small no longer just have to worry about a smaller set of technological cybersecurity issues, but all sorts of things we couldn't even imagine years ago. People who follow the news have seen it — now we need to worry about whether the people we hire are actually real. Three, four, five years ago, nobody saw that coming. We have more international interference in business and politics, countries using economics as a form of play, and that affects any company — especially technology-minded companies that operate globally. And this is perhaps just the tip of the iceberg.

Mark Carney:

Certainly. On a global scale, things are not getting better — they're getting worse — and it's almost overwhelming for a CISO, or the kinds of personas we deal with every day, our friends in the industry. They're really struggling. How do you combat all of these different threats and dynamics when everything is compounding, and with limited spend? How do you appropriate capex and opex into the right areas? It's a risk-management mindset, but you've got all of these dynamics on the macro scale, and you have to manage them day to day while protecting your intellectual property and everything else. It's a very unique time for CISOs, more than ever before.

Nils Puhlmann:

Years ago we talked about cybersecurity viewing itself more from a business-risk angle. Now is definitely the time, because a lot of the risks we're seeing are not pure technology risks. They might affect technology, but they pop up in all sorts of other areas. We talked for years about security teams being very close to other parts of the business — HR, finance, you name it — and these new risk factors are really popping up in exactly those areas. People wiring money because of a fake video or fraudulent instructions — that's finance. Hiring folks who are actually sitting in a country that's not so friendly to the rest of the world — that's HR. So if you have a security team at a Fortune 500 that's already inundated with pure technology-risk questions, they now have to branch out and proactively sit down with all sorts of other functions of the company. And that's a Fortune 500. Take it down to a company that might have one or two security people — how do they do that? They're already oversaturated with what I'd call old problems, problems we still have to address, whether it's phishing or infrastructure security. And now you add these on top. That's quite overwhelming.

Mark Carney:

The world has gone digital, and it's such a vast array of use cases. If you look at the CISO role, security blends into IT — cyber leaders are now taking CIO roles. And look at some of the breaches, like the unfortunate CrowdStrike event, where managed services that used CrowdStrike had impacting effects on the people who used that technology. IT and security are blending together, along with the convergence of physical and technology, and you've seen emerging technologies come out of this. There's more of a need to figure out how to balance both of those worlds together.

Nils Puhlmann:

And then there's the trend we've talked about for years — the shortage of cyber talent. Now I question whether we actually need more specialization in roles, simply because the world of cybersecurity has become so complex. Can one generalist really cover all these areas — and, as we just discussed, these areas keep multiplying? Or are we foreseeing that the talent shortage will get worse because the complexity of the issues is increasing? And what does this mean for different sizes of companies? Larger ones might compensate by hiring more people, but what do smaller companies do — the ones that increasingly rely on technology, because everything is tech now? That's a good evergreen topic: what does it mean for the industry? Can we continue doing things as we have been, or do we have to adapt, adjust, and overcome, because the world around us is changing so quickly?

Mark Carney:

The workforce is a very interesting topic. There's always been a talent debt — it's been widely publicized. Now you go through this macroeconomic period, and in fact I think it's harder to get a cyber role now than ever. At the same time, you still need these specialists who are in demand. So the workforce is pretty stable, and it's not as easy as it used to be — it's a very different dynamic than in the prime time of cyber. I have friends looking for roles, and I get asked a lot, "Mark, let me know if you know somebody who's looking." Back in the day it was employee-demand; now it's more about employers being able to find talent that's actually waiting for its next role, and that's not moving as fast for people as far as what's coming next for them individually.

Nils Puhlmann:

Going back to the macro view — you made me think that perhaps we missed the boat in cybersecurity when it comes to thinking globally. What I mean is: if you go back ten or fifteen years, we had a lot of good, expensive developers concentrated in certain parts of the world. They cost a certain amount of money. Then IT and development people popped up in other areas that were cheaper, and we started outsourcing. There was this layering: do I need somebody highly specialized and really good at a more expensive level, or could I send certain work somewhere else? We never did this in cybersecurity. In fact, there are certain parts of the world where there's zero cybersecurity talent — but those are exactly the areas where we could potentially send some of these jobs today.

If you look at how a lot of companies work now, they'll tell you they have people all over the world — they don't care where they are anymore. Unfortunately, in cybersecurity we can't do that yet, because we didn't develop those roles and we didn't transfer the knowledge. As an industry and a profession, we probably could have done better. That doesn't help the folks looking for a job right now, but looking at it macro-economically, we made a mistake. We should have trained and placed more knowledgeable people in other places, so we'd have this layering opportunity that we now don't have — which is why cybersecurity is still very expensive on companies' balance sheets. If you look at how much they have to spend just to combat the common risk scenarios, it's still very expensive.

Mark Carney:

Even in non-cyber labor across the enterprise, companies are looking to build business efficiencies. So you're seeing pressure on the cyber industry to outsource, and you're seeing more talent on the global scale — though it's a fraction of what the cyber market is. But certainly over the last 18 months, I've seen more of our clients looking to build international teams in certain parts of the world. And consulting firms too — some of the large systems integrators and consulting firms are delivering a lot of cyber work, whether that's managed-services-oriented businesses, all from overseas — again, trying to build business efficiency into their margins, but also passing that lower cost on to their customers. The last 20 to 24 months have been very different than before.

Nils Puhlmann:

Mark, you and I have had many conversations over the months, but there's an area we've talked about often that I wanted to dive into deeper. I'd categorize it as looking at innovation — what's happening with investments in our industry, the trends you're seeing, what that does to the industry overall, and where you think this is headed.

Mark Carney:

We've seen tons of innovation over the years. It's a very unique industry, with so many products and services — and combinations of those — coming out over the years, and it hasn't stopped; it continues to flow. There's a lot of VC activity that slowed down over the last 24 months, but it's picking up over the last couple of quarters. This creates an immense amount of marketing to weed through: what are they truly trying to accomplish, and what are the outcomes of these innovative products? It's great to have them, and a lot of times it creates opportunity, but it also creates challenges for the end user — the CISOs and the folks using and managing the products — because a product might fix or solve a very niche problem. So then how do you take all of these disparate, isolated products and put them into a single pane of glass? How do you make sense of the data, aggregate it, and make something meaningful out of it to manage your cyber program? Innovation and investment are a luxury, because we have so much, but they also create a back-end challenge for CISOs. That's my opening take — what are you seeing?

Nils Puhlmann:

I think you're right. We've seen concentration and consolidation. The term "platform" — "security platform" — has been overused in the last 12 months. Sometimes I wonder whether the exit strategy for a lot of these companies is to be acquired by a platform. Does that really foster innovation, or does it change the approach to the market? We know the companies — we've seen some build massive amounts of revenue in record time. But everyone who couldn't will have to be acquired or become a target of acquisition. That leads to a shrinking of the market, because they go away — they go under an umbrella. And a lot of existing customers don't like that umbrella, so they move somewhere else.

But where in all of this is the innovation? Is it really more that a big part of the industry focuses on just building a better widget? It's a replacement game, which is a very expensive game for all involved. So the question — and I'd love to hear your take — is how can we actually help ensure that real core innovation is happening? A lot of our products address very old problems. Has anyone really come up with something completely new that we hadn't even thought about? Or is it like with AI, where suddenly AI security companies are popping up — not because we as an industry thought "there's something new we need to innovate," but because we saw other innovation happening and decided we had to jump on the bandwagon and piggyback? I'd love to hear how you look at innovation, and the money that supports all of that.

Mark Carney:

There's so much attention on the pursuit of being the next darling in the industry — name a company that's been really successful, and you can fill in the blank. But then you go to RSA and see all the vendors, and 90% of them are under $10 million in revenue. They're very small. They've got a persona that they're much bigger, because they're spending a lot on sales and marketing, but truly it's a very niche solution and they haven't figured out scale and growth. Meanwhile, all this attention is on the darlings that do make it — but you forget that, having been in the industry long enough, a lot of companies get eaten by the Ciscos and Palo Altos and other bigger players. There are a lot of acquisitions, but a lot of companies just disappear — they're gone; they don't even exist anymore. With startups, cyber or non-cyber, most fail. That's an interesting dynamic in itself.

One thing I've always found interesting is the buying behavior of the CISO. Think of personal finances — most people aren't great at personal finance; they're in debt. Take that into the business world, and I see that CISOs, generally speaking, don't spend their money very wisely. They've got six technologies to one staff member managing them, and it's not even fair to the staff to manage so many. You get this buying behavior because there's so much attention on the newest technology, the replacement technology that's supposedly better, and people buy what's tangible — and they forget about doing the things that are just proper cyber hygiene. I'm sure you've seen that behavior in the industry over time.

Nils Puhlmann:

That makes me want to play devil's advocate a little. As a CISO, you have different pressures on you. On the one hand, you don't want something terrible to happen on your watch — that's bad for many reasons, not least your career. But there's also the cost pressure. You could go to one extreme and just buy platform products — you won't get best-of-breed, but integration will mostly be better, and so will trainability with staff. Or you go the other route: "I need best-of-breed, because I just can't sleep at night, there's too much flying at me," or "we just had an incident and the board is breathing down my neck, saying we can't have this happen again." Either approach alone won't work. You can come up with a mix, but then the question is where you draw the line — and that's really, really hard, saying this from my own experience. You could have a bunch of platforms and then layer best-of-breed solutions on top, which still leaves you with enormous complexity for your staff.

That leads back to my question: have we done enough around innovation? Because innovation could also mean somebody found a better, easier way to solve a problem. It doesn't always have to be the latest and greatest technological revolution. And I'm not sure absorbing something into a platform is necessarily innovation in terms of making things easier — if you use some of these platforms, they're not always easy, by the way. Going back to all these different players: if you have so many players all hovering at a certain level, the market forces might not be working well, because normally there's a self-cleaning mechanism that weeds out a lot of the early ones to leave room for others to grow bigger. But they're all around the same size. That's actually detrimental to innovation, and financially it's not great for the VCs either.

Mark Carney:

If you look at buyer behavior again — CISOs have to present to the board, so you've got this pressure around people, technology, capabilities, and processes. I've met hundreds and hundreds of CISOs throughout my career, and I put them into a couple of different buckets. One I'd call very enlightened — they really understand how to blend the whole program. And then some that struggle with it, honestly — and it's not necessarily their doing; it's just a lot to manage. So how do you know where to be a platform player and buy platforms, versus buying niche technologies? An element of that is the size of the organization. If you've got a large team with lots of capabilities, it's much easier to consume technologies, integrate them, and get insights to manage your program. If you're down-market — a small or medium-sized company — you've got to have somebody who does that for you; you need an outsourced model. We're seeing the emergence of purpose-built managed services with a specific outcome, and from the middle market downward, that's a very attractive way to go, simply because you don't have enough staff. Staff ends up being the majority of your cost on the P&L, whether it's a consulting firm or your own cyber staff and budget. So having a different approach to outsourcing — one that gives you the freedom to get that outcome and that purpose-built managed service without having to maintain an army on your cyber team — is compelling. What do you think about the approach for different sizes of companies?

Nils Puhlmann:

Larger companies face the typical complexity problem. Cybersecurity doesn't live in a vacuum — you have engineering teams, IT teams, different parts of a company you have to integrate with. So even if you pick a certain product or technology, it's most likely not just your decision; there are a lot of other people at the table. That's unique for cybersecurity inside a company, because it's this octopus function with tentacles in all these other areas. The downside is you have a lot of stakeholders, which often takes forever and might even push you into a corner you wouldn't have chosen if it had been solely your decision.

When you go mid-market or smaller, it's the opposite problem: not enough talent, not enough knowledge. Things are moving fast, but there's not a lot of complexity — so you could move fast if you had the right people and the right technology. Unfortunately, a lot of the technology built for enterprises is way too complicated for a company that operates differently — it's not purpose-built for them. So I can see that managed services are better in those cases, because they prepare everything and make it easy to put in, and they bring the experience, talent, and knowledge. But we definitely see a huge difference in how larger companies make these decisions versus how mid-market and smaller companies do — they're polar opposites. Which leads me back to innovation: a vendor basically has to pick which segment they're building for.

Mark Carney:

Certainly — and that's probably why we see so many vendors hovering at that level, because you can't please everyone. A lot of vendors claim they can, but I'll let others be the judge. You can't really build for enterprise and for the mid-market at the same time; it would be a completely different product. You've got to understand your ideal customer profile — your ICP. Trying to serve everybody is a very tough thing to do; very few can do it.

What are you seeing specifically in products? Obviously there's a lot of emerging AI-based technology and startups. What else are you seeing in the market outside of AI — or what are you seeing within AI that's intriguing to you?

Nils Puhlmann:

Certainly there's a wave now of AI security — or security AI, however you want to call it — companies, and that's great. We've had this at every major innovation cycle. It was cloud security; suddenly cloud security companies came. There was an explosion of mobile devices, and suddenly mobile security was what everyone at every conference talked about. That will normalize itself out. The question is what other innovation will spawn out of that AI wave. Will it have effects — say, on the workplace — that we're not thinking about, and not building security for right now? It often feels — and I say this intentionally — that in security we build tech after a trend has already been established and the tech is already in flight. It's a typical catch-up syndrome.

Should we instead think about what could happen next that would be real innovation? Should somebody build something in anticipation? That means a high degree of risk, but that's what innovators do — anticipate what the next thing will be and build for it, because otherwise we spend years of trial and error catching up. I don't think we've done a good job of that in the industry. It obviously takes more risk capital. But to me, that would be real innovation, because then we could also shape the thinking of security teams differently and get everyone a seat at the table. If they can say, "We already work on this, we know what will happen next" — and there are a couple of products that are early-stage — that changes the conversation from "here's the security team once again wanting to bolt on something that's already in flight" to "welcome to the innovators' table; let's talk about how this could affect us." I don't see enough of that.

Mark Carney:

I was talking to a VC — a trusted friend of mine — a few weeks ago, and I asked his perspective on all of these AI products coming out. His response was really interesting. He said that most of these AI products have a very small total addressable market, or solve such a niche problem, that he had no interest in them. What I also found interesting: you'd think phishing, phishing simulation, and security awareness would be one of the most common ways to use LLMs and this new technology — and that was actually where his interest was highest, because you've got legacy technology, you're building a better mousetrap, and the TAM is very large. So it was interesting to get his perspective: you could have hundreds of AI products come out, but where is the VC money going to come from, and what's their interest to do a Series A or Series B, if the TAM is so small and the problem so niche — versus this broader technology that's been around for 20 years, the legacy stuff, where you're building a new mousetrap by leveraging this new technology? I thought that was an interesting perspective.

Nils Puhlmann:

That confirms it. So, in terms of wrapping up on innovation — my takeaway and advice, for what people should watch out for or lean into over the next 12 months from an innovation and investment perspective:

From a buyer's or user's point of view, really ask the question: what does this solve? What problem does it solve, and how long do I think that will be my biggest concern? Because if it's only a 12-month problem, you're just buying something for 12 months.

On the investor and innovator side, I'd like to see more mission-driven things — where people really say, "I strongly believe this is the next big leap, and we need to start building for it now." It's possible — we see it in military technology, where there are amazing things being innovated that people couldn't even dream about years prior. That's what we need. I think we've escaped too much into a world that talks too early about total addressable market — "can I find email spam better than the next guy?" That's not enough. If we really internalize what we just talked about — that the boundaries are shifting and the complexity of the problems is growing — then we need to really innovate. And that means taking a lot of risk, potentially failing, but thinking ahead. I'd love to see more of that.

Mark Carney:

Nils, we've covered a lot — it's been an incredible conversation. One thing we wanted to talk a little more about is that, no matter the size of the organization or the vertical you operate in as a CISO or cyber leader, there's this concept of people plus platform: the blend of taking advantage of the new automation and technology we have available today, combined with surging human intelligence when we need it the most. That applies to a variety of use cases. What do you think about that — how do you see it being applied through your lens?

Nils Puhlmann:

On the enterprise level, there's definitely much more technology integration happening between the tools. A lot of larger companies have valid security engineers — they write code, they create beautiful integrations, and some have even created wonderful open source for others to use. But as you move into the mid-market, because of what we discussed — the limited resources — I think more automation is key. That doesn't have to be a platform; you can have automation at any level of solution. But more automation, more visibility, more hygiene — I can't stress it enough — because then you can use the people you mentioned more specifically, where you need them. You can't use them for everything, so you have to pick and choose. We see a trend overall in the industry that automation, at every level of company and in every area of tech, is increasingly used on the security side too. And more automation makes all sorts of other things possible. I'm sure you see this a lot with what you do as well.

Mark Carney:

Yeah. I'd call it an obsolete approach where you have project-oriented work happening — whether that's a task done internally, or by an advisor or consultant — when the demands today, given the dynamic nature of our threats, call for a more continuous approach. We need an always-on, real-time view and visibility, and that can be applied to numerous capabilities we need to have, whether you outsource them, in-source them, or use a co-managed service.

At the company I'm at, Evolve Security, take pen testing. You've got this archaic approach that's lasted for 25 years, surprisingly — a one-time pen test that lasts for two or three weeks, and then there's no visibility for the rest of the time. We live in a completely different world now, with new pressures, demands, and threats, where that's no longer enough, and we shouldn't feel comfortable with it. So we see an opportunity to provide better value to customers who want more value out of it, who want more visibility, and who want to care for and maintain their environment — so they don't have this surge of a massive vulnerability list they don't know what to do with, from the two or three weeks a year they perform a pen test. That's driven, unfortunately, by compliance and regulation, versus what's right and what you should be doing as a cyber leader. That's a use case we're seeing at Evolve.

What are you seeing at Endari?

Nils Puhlmann:

What we definitely see is a trend toward companies paying more attention to where they are on the maturity curve. We help companies not just understand where they are, but — more importantly — how to build out their cyber maturity to be in line with customer expectations. That's really what it comes down to: moving away from one-time checks, old audits, or even self-assessments, to a real, impartial, independent view of how cyber-mature they are — so that their customers and their ecosystem can continue to trust them, and, more importantly, support them from a business point of view.