Run the Numbers

“Stop Trying To Quantify Risk”: Risk Management Wisdom (& Star Wars Analogies) From CISO Andy Ellis

34 snips
Aug 25, 2025
Andy Ellis, former CISO of Akamai and author of 1% Leadership, shares his vast expertise in cybersecurity and risk management. He critiques traditional risk measurement and introduces his 'Pyramid of Pain' framework. Andy discusses the critical dynamics between CFOs and CISOs, the impact of AI on security, and why the roles are converging. Using captivating Star Wars analogies, he illustrates complex risk management concepts and offers insights on strategic security procurement and the importance of evolving leadership skills in this fast-changing landscape.
Ask episode
AI Snips
Chapters
Books
Transcript
Episode notes
INSIGHT

Risk Is Both NPV And Fear

  • Risk is the net present value of future bad outcomes and also what you're actually afraid of.
  • Humans ignore technically measurable risks they don't emotionally fear, so focus on fears that move decisions.
INSIGHT

Actuarial Versus Human Risks

  • Actuarial risks are predictable by tables, human-driven risks change when people respond to incentives.
  • Treat human adversary risks as qualitative and non-statistical because attackers adapt to incentives.
ANECDOTE

Operation Aurora Breach Example

  • Andy recounts Operation Aurora where attackers accessed many tech companies and Google discovered it.
  • The attackers accessed a Hyperion upload used for quarterly reporting, which had limited impact for Andy's company.
Get the Snipd Podcast app to discover more snips from this episode
Get the app