“Everything that was wrong last week is still wrong this week. The difference is now you get to see it.”
Who They Brought In
Nathan Case is the CTO of TPO Group, a security and policy firm whose partners include some of the most credentialed names in the industry: a former CSO of Azure, a chief lawyer from Cisco, and the person who wrote the cybersecurity policy for the United States. Nate’s own path started in the mid-90s writing C-sharp and experimenting with early internet protocols, moved into facial recognition software in 1998 and 1999, then shifted toward encryption work for the Department of Energy and hardware pentesting on firewalls. He helped build the data centers that became AWS US West and US East, spent years doing incident response and security architecture across government and private sector clients, and still codes today. He is also faculty at an AI institution and brings a rare combination of builder, breaker, and responder to every conversation he enters.
What Got Loud
- The cybersecurity apocalypse people are afraid of already happened. It happened 35 years ago when basic hygiene got abandoned. AI just turned the lights on
- Why nation states are no longer targeting just governments and enterprises. Small companies are now in the blast radius and AI is what made that scale possible
- A defense contractor was using Social Security numbers as the primary ID in a grill ordering app at a facility near the Pentagon. Nate found it during a database migration
- Why AI for incident response is a trap: your attacker’s AI is going to talk to your AI, and cheaper is not a strategy
- The logistics company that did not know its crown jewels were the shipping routes for dangerous chemicals that could be weaponized. That is what attackers actually want
The Rundown
Nate’s framing for where AI sits in the security conversation right now is the sharpest in the series so far. His argument is not that AI creates new threats. It is that AI illuminates the threats that were already there. The map was always that big. You just could not see the edges. “There were bad things that were coming to get you last week,” he says, “but now you can see them.” For a lot of organizations that means the news is bad. The work ahead is significant. But at least now you know what the number is. The FUD era of security selling, where fear was the product because nobody could quantify the actual exposure, is over. AI makes the negative space visible for the first time.
The nation state conversation is where the episode gets uncomfortable fast. Nate is working on a paper about unrestricted warfare, specifically what it looks like when nation states target civilian entities with no rules of engagement. What he is seeing in incident response right now is that scale has removed the friction. AI and cloud infrastructure make it trivially easy for attackers to go after everybody at once. The small logistics company, the water treatment facility, the five-person critical infrastructure team. “If you’re the unlucky deer and you stumble in the forest and everybody else is running a little faster than you, you’re the one that gets jumped on.” The answer is not panic. It is the basics: MFA, endpoint protection, zero trust. Not because they solve everything but because they remove the easy targets from the herd.
The crown jewels story is one of the most instructive moments in the episode. A logistics company brought Nate in for incident response and did not think of themselves as a high-value target. They moved chemicals. What they did not fully reckon with was that they held the logistics data for those chemicals across the entire planet, including chemicals that could be used in weapons development. The attackers were not after money. They were after the map of where those materials move and who controls the routes. Nate’s point is that most companies have no idea what their actual crown jewels are, and the attacker has usually already figured it out before the company has.
The AI and human labor debate comes up toward the end and Nate does not hedge. AI is exceptional at synthesizing vast amounts of data. It is not good at understanding second and third order impacts, at creative problem-solving inside a unique business context, or at knowing when to turn over the next rock in an incident investigation. “I’ve done a couple incidents over my lifetime,” he says, where the key insight came from thinking like the attacker, asking a question nobody had asked yet, and following a thread that no automated tool would have surfaced. A bank that laid off 20,000 people and then discovered its AI token costs were lower than those salaries is the cautionary tale he drops at the end. The humans are still the answer. The question is what you are giving them to work with.
Real Talk
If you do not know where your sensitive data lives, how it moves, and who would want it, you cannot protect it. Ask the stupid questions now. The attacker already has.
Catch It
Listen to the full episode on Apple Podcasts, Spotify, or wherever you get your podcasts. If this conversation made you think twice about your own security posture, let’s talk. Visit socsoter.com
