← All episodes

Andres Andreu: Why Cybersecurity Is Still 100% Reactive

Andres Andreu · Chief Executive Officer · Constella Intelligence
· Hosted by
Come on the show →

Starts with a 20 minute pre-interview call. I handle everything else.

About this episode

Andres Andreu is Chief Executive Officer at Constella Intelligence, and he went from CISO to COO to CEO in about two and a half years. What you lose on the way up, he says, is determinism. A technologist gets discrete outcomes. A chief executive makes uncomfortable calls on very few data points, then lives with them.

He argues that the security industry is 100% reactive and keeps choosing to stay that way, and that AI governance is being tucked under the wrong function exactly as InfoSec once was. He holds an international patent for a machine learning engine, which is part of why the current use of the word AI irritates him.

In this conversation

Watch the full episode on YouTube →

Full transcript

Welcome to another Agentee Digital podcast. Today I'm pleased to have Andres Andreu, the CEO at Constella Intelligence. Andreu, it's great to have you here today.

>> Thanks for having me. It's good to be here. >> So for folks that don't know Andres, who is he and what does he do?

He is a technology executive that's been given a chance to play the CEO role and I'm wholeheartedly embracing it and giving it my best shot. >> Okay. And that's interesting because you went through from a CISO to COO and then now to a CEO.

So what has changed throughout these career changes because it's it's been like 2 and a half years right? >> Yeah. Yeah.

>> So the biggest change is perspective. You know, when you're a CTO, when you're a CISO, there's a certain level of determinism that you can live with that when you're running a company disappears. What the I find one of the biggest challenges running a company is having to make decisions with very few data points to inform that decision.

And so you have to just learn how to make uncomfortable choices, live with them. You know, if it's a bad choice, fail fast, and adjust, adapt, and then keep things moving. And when you're building technology or running security programs, there are more discrete outcomes that you can rely on that when you're running a company, it's a little more gray.

It's a little more nebulous. H can you think about some kind of call that you made that you might have been a bit I don't want to say scared but you know and that actually turned out well. >> Yeah.

I can tell you on the previous company, not this company, but my previous company, we realized that doing direct sales was just not working out the way we needed it to. You know, boards usually hold you accountable for certain things like margins, right, and growth trajectory. And if the sales teams that you have, the sales operations don't achieve those numbers, you have to adapt.

You have to change. And for years when we had that company, we were trying to do direct sales. We swapped out entire teams a couple of times over a few years and it just didn't change much.

And it was when we decided to pursue a different model to go down a channel reseller type model that things started to change and we realized what we had been doing wrong for a number of years. You know, as a technologist, the sales world just wasn't something that came natural to me. So, I had to learn all of that.

>> And how do how do you approach sales at Constella? >> So, sales here is a little different than what's normal because we don't do direct sales to end users, right, to customers. This is not a BTOC type model.

We're an really an OEM company. And so we are we sell to cyber security product companies and ID theft and ID fraud companies. So we're a background player.

The predominant model of business for us is API based. And so that OEM model is very different. You know the first thing you have to realize is that your ICP and your target markets are totally different than a direct sales model.

And so, you know, again, making that adjustment when I got here was one of the first steps because I realized that for a number of years, the company was trying to build products to sell directly to customers and it really wasn't working out the way they thought it would. So, we had to backtrack and stick to what made sense, what the core competence is of this company. And so, you know, we're an OEM company.

>> Yeah. And what do you think most like security enterprise teams do wrong? [laughter] >> Oh man, we don't have enough time to cover that.

But I will say this. I think that as an industry, and I' I've been in this industry a long time. I think in this industry, you know, we have had to grow up figuring things out.

So anything I say, it's not being judgmental. I'm just making observations because I've made all the mistakes myself. I'm not accusing anybody else.

I've made them. I think first of all when leaders build security programs, I think they listen to the wrong sources of information. We've been trained as an industry to go listen to analysts, right, from the big analyst companies.

And when you when you do that long enough, you start realizing, wow, they don't know any much more than I do. So why am I listening to them? And so informing your program with the right sources of information I think is one of the areas where the industry still has not figured it out properly.

And the you know the other big thing that I always have had a problem with is that very similar to law enforcement this industry is 100% reactive because to shift anything into the proactive is so difficult that they won't try. They just won't try. It is resource intensive.

I acknowledge that. But it is the right approach. And the problem is it's a lot of work.

So a lot of entities just shy away from that. And they'd rather invest resources into dealing with a problem after the fact, right? Incident response, you know, remediation after the fact.

And so I always find you know people talk about shifting left and being more proactive and all that but doing it is very difficult. >> Yeah. And I feel like most organizations still treat AI governance as almost like a security or a legal problem.

>> And it's not. >> Why do you think that's the wrong frame? Because very similar to so information security if you grew up in this industry infosc what became cyber security over the years infosc was treated as an IT problem for a long time and what you know the reason for that if you if you look back in retrospect executive leaders not technical leaders executive leaders just didn't know what to do with infosc so they said okay put it under let them deal with it.

That was their attitude. It's the same thing that's happening now with AI governance. They're basically trying to tuck it away under something else when it is not their problem.

It is an executive leadership problem. And until executive leaders own that, we're going to have challenges in this industry. And I'll tell you one of the reasons why they have a hard time owning it because they don't understand it.

And that creates a challenging ecosystem. You're asking someone who has the resources to be responsible to be responsible for something they don't understand. And it's a bad cycle.

And so I think until we get past that point, I think executive leaders just have to open up to the fact that they have to embrace this and understand it as much as they can. And I'm not saying you have to be an expert, but understand it as much as you can so that you can build governance around it in the right way. I mean look at risk.

I think you know the entire industry of risk follows the same trajectory. Who's accountable for risk in any given organization? There's no one answer.

You'll hear a myriad of answers. And ultimately it comes down to the fact that person X doesn't want to be held accountable. So they pass it off to person Y and person Y passes it off to person Z right and you know we have this cycle of not me you right and I think AI governance is happening something very similar is happening within AI governance because they don't understand it and they don't want to be held accountable >> But you can't stop it though you can't stop AI at this point and that's the funny part you cannot stop it somebody's got to live with the governance and the accountability of risk around the use of AI.

>> How do you look at AI and kind of what it's been shaping into? >> So, I look at it very differently than most people I talk to. Let me start with that because I've been doing this a long time.

You know, I authored an international patent that was granted many years ago for a machine learning engine. So, I've actually been involved with AI technologies for many years. What drives me nuts is that when people talk about AI now, they mean generative AI.

They don't mean AI. They mean Gen AI. >> Because AI is a family of technologies that goes way beyond Gen AI.

It's only one of that family. That drives me nuts as a technologist because accuracy matters, right? And so you know generally speaking when you talk about generative AI you a number of challenges come in guard rails right governance data leakage that's obviously a huge problem right and the technology you know basically came into enterprises so quickly they didn't know h what to do with it they didn't know how to handle it they and they still don't to a large extent and so I think that we're in a we're at point that everybody sees the tremendous potential that this brings to the table, but nobody really knows what to do with it.

I mean, look at how many fiascos have shown up about somebody taking something directly generated out of a Genai engine, copying, pasting, not checking, not verifying anything and putting it out into the wild. That is irresponsible at worst, right? Very sloppy.

On top of that, I mean, there was a lawyer who did it who ended up get losing his certification as a lawyer because he did not check and verify the information that came out of that engine. And I think that's irresponsible. And people, come on, let's face it, people are lazy.

They want the quickest way out and they want to look like superstars. And Gen AI gives them that ability. And as someone who has written three books without AI, because when I wrote my first one, none of this existed, it I find it almost offensive that people with no knowledge can turn around and do something very similar and they can't back it up.

If they get on stage and get and start getting questions about what they quote unquote wrote about, they can't back it up because they didn't actually write it. They're not experts in their field. But anyway, those are some of my thoughts.

>> So, what do you think how do you actually use AI in maybe Constella for example to not get data leakage and hallucinations and all these issues that happen when you're using heavily AI? >> So, we use AI very different. So, we don't we don't use AI so strongly on the front end.

In other words, our employees, you know, generating documents or whatever, we use a ton of AI technology on the back end. So, for example, when our breach hunting engine, which is partially largely AIdriven, when our breach hunting engine discovers a new breach, it gets put through this pipeline of normalization and curation. There's AI built into all of those steps.

For example, categorizing the breach cuz there are different categories for breaches. That's now done via an AI engine. You can teach a model how to categorize that type of data.

And so rather than have a human do it, that's an area where it makes sense. And so normalizing the data after that, for example, saying, "Oh, this email address already exists in our data lake. Let's unionize these new attributes that we have discovered that's automated via an AI engine.

So you see what I'm saying? We use AI a little differently because it's all backend processing for well not let me not say all. It is mostly backend processing for us as a company.

Hm. If a company reaches out to Constella, what's kind of the common mistake that you see or that you fix first? >> You mean a problem that we're trying to solve for the customer?

>> Yes. So you know our the challenges for us are understanding the space they're in and then for instance taking them to the right API cuz we have a lot of APIs taking them to the right API that makes sense based on their business challenge right because for example a customer may say I want to search your data lake but when you talk to them you realize that they don't want to search they want to monitor the data lake continuously and get notified of something. That is the typical mistake that we run into, right?

They come to say, "I want to search your data lake." Okay, here's the API. And they go, "Oh, but I want it to happen all the time." you don't want you don't want search, you want monitoring, and we can do that for you. Yes.

Right. That's the very classic not mistake but whatever erroneous attitude that we deal with in the company. >>.

And go going from AI to leadership because I think probably being the CEO now it you manage a lot of people and so do you have any best practices around managing people and leadership in general? >> Yeah I've learned quite a bit or I like to think I've learned quite a bit. You know, one of the things I genuinely believe in and I've been in leadership for a long time before, you know, especially before this, you have to give people the latitude to succeed or fail, but grow.

And if you fail, that's part of growth. That's okay. So long as you learn from it, okay?

So long as you learn from it because if you keep make the same mistakes over and over, it's like, "Okay, dude. Like something's not right here." But if you give your people the latitude, the space to succeed, fail, but definitely grow, I think that's one of the most important leadership lessons that I've learned. And I and I've practiced it for many years.

I feel that I've given my people plenty of space to grow. And you know, when they fail, we whatever take that postmortem approach. Hey, let's let's discuss what failed here, why it failed, what we could have done differently.

And then you watch people grow in their career. It's actually quite rewarding on a personal level. You know, the other thing that I think I've learned and been able to implement in my in my leadership strategy is to shut the hell up and listen.

Most of the time leaders want to dictate. So they talk. That's to me that's the wrong approach.

I'd rather ask you a question and then let you go and let just listen. Because you what you find is that your people generally have really good ideas, really good, you know, concepts about the business, really good vision in some cases, vision in terms of how to grow, what the trajectory should look like. And if you don't let them talk, you'll never realize that.

So I believe that, you know, it should be 10% talk, 90% listening. >> Interesting. And if you could replay the beayshore exit with what you know now is there anything that you would do differently?

I guess that's that's a bad question, right? So what >> What would you do differently? >> I think that's a great question because we made so many mistakes and I own them.

I own them. We made a ton of mistakes. And first of all, what we did not realize early on is that when we did make mistakes and failed, we should have just tried to catch them early.

Fail fast, right? Catch those early and adjust. In the beginning, we just didn't we didn't have that agility.

We developed it over time. We were able to fail fast very quickly, you know, towards the tail end of that journey. One of the things I would have done radically different, I going back to the sales conversation earlier, I would have swapped the sales model out like 5 years before we did.

I think we wasted cuz I'm not a sales guy. I ran technology. The people that ran sales for us just did not want to accept that the models were not working and we just kept trying over and over and it was like, "All right, listen.

Let's come to terms. Change." When we changed, it had a big impact. The other big mistake that we made which I would have loved to have changed early is that this the product vision at Beayshore was driven by the original founder who is an absolute genius.

The guy is one of the most brilliant people I've ever met. But that doesn't mean that you know your product is going to sell. We didn't have customer or potential customer feedback loops early enough in the cycle to take that valuable input and make product changes based on those feedback loops.

The original the first let's say half of the journey was driven based on the founders's intelligence and vision. And as it turned out some of some of the smaller areas in that vision did not resonate with potential customers. So, we had to make changes.

We should have done that 4 years before we did. >> What's in the future for Constella? Where do you want to take it?

>> Growth. I mean, look, we're, you know, we're constantly the feedback loops I talked about, we live by that. So, we're constantly taking feedback from our customers.

Like for instance, we're in the pro we're in the tail end process of a brand new API that we just created that I think is going to be a massive differentiator for us and that entirely came through multiple customers telling us, hey, what would really take me to the next level is this and we're building that. And so I'm very happy that we're doing it based on their feedback, not us saying, hey, we're smarter than everybody. We know what's right.

We know what you need. That's the wrong approach. Tell me what you need.

We'll go build it. And I think we're just going to see more of that at Constella. That trajectory of growth trajectory here is based on customer satisfaction and that's what we're allowing to drive the product.

>> All right. And wrapping this up, Andres, where can people find you or Constella? >> Conella.ai is our website.

You can find me on LinkedIn. I'm pretty I pretty active. I write on my personal blog pretty much on a weekly basis unless I'm traveling.

And then I usually post some stuff about those writings on LinkedIn. So, you can find me on either one of those. >> Okay.

Well, thank you for joining. >> My pleasure. Thanks for having me.

Come on the show →

Grab a slot and we will record.