Business Security Weekly (Audio) Being Exploitable While Your Risk Tolerance Changes and You Unblock Innovation - Myke Lyons - BSW #438
12 snips
Mar 11, 2026 Myke Lyons, CISO at Cribl and 20+ year security leader, explains why AI is changing exploitability and how defenders must respond. He covers attackers using AI to craft exploits, shifting from IoCs to TTPs for prevention, trusting AI for smarter patching workflows, and leadership changes needed to unblock innovation and manage evolving risk tolerance.
AI Snips
Chapters
Transcript
Episode notes
Cribl's Telemetry Reach Informs CISO Perspective
- Cribl now partners with over half of the Fortune 100 to solve IT security data challenges according to Myke Lyons.
- Lyons referenced clients like Aflac and Nestle while noting Cribl's telemetry focus informs his CISO view.
Prioritize TTPs Over IoCs
- Shift focus from chasing Indicators of Compromise to modeling attacker Tactics, Techniques, and Procedures to enable preventative controls.
- Use TTP-based detection plus compensating controls so you can block behavior without immediate patching.
Telemetry And Schemas Unlock Behavior Detection
- Rich, structured telemetry is essential to detect agent and behavior patterns that indicate attacks beyond signature lookups.
- Myke Lyons recommends open schemas like OCSF to standardize data and enable cross-system detection.
