Blog

banner-asset-med

Profile: Kyle Bubp, CISO, Avid

Kyle Bubp Header

 

Kyle Bubp’s interest in technology started early. Growing up in the 1990s, he was introduced to computers by his father, who built and repaired them as a side business. By seven or eight years old, Kyle was already exploring MS DOS, bulletin board systems, and the early internet.

Kyle’s first significant exposure to cybersecurity came while supporting a Department of Defense contractor. At the time, security was not a separate function. IT administrators were responsible for maintaining systems while also conducting vulnerability scans, patching, and hardening configurations to meet strict government requirements.

“Even though I didn’t have security in my title, that first job contracting with the Department of Defense taught me so much about good hygiene and good security,” Kyle recalls. 

Those fundamentals would remain important as his career expanded from hands-on technical work into consulting, entrepreneurship, security architecture, and eventually executive leadership.

Seeing Security Differently

One of the most influential periods in Kyle’s career came while leading a security practice for a technology reseller. Working directly with customers gave him visibility into security programs across many different organizations, and he began noticing a common problem.

Companies were continually investing in new security technologies, but another product was rarely what they actually needed. “They’re not one tool away from becoming more secure,” Kyle explains. “They lacked a strategy and they lacked the ability to measure their program. They had shelfware, meaning they had bought products that they never implemented or didn’t fully implement.” 

The experience eventually led Kyle and a colleague to launch Savage Security, where they helped organizations assess their programs and improve security without simply defaulting to adding more technology. The company was eventually acquired, continuing a career path that would take Kyle to work at AWS and later JLL. 

At JLL, Kyle became Executive Director of Attack Surface Management, with responsibility across security architecture, vulnerability management, cloud security, and application security within a global organization of more than 100,000 employees.
By then, he knew that the natural progression of his career path would lead to CISO. 

Finding the Right Opportunity

When Kyle saw that Avid was looking for a CISO, the opportunity immediately stood out for both professional and personal reasons. A longtime musician, Kyle had played guitar since his teenage years and was already familiar with Avid through Pro Tools, which he had used for recording and editing audio.

“I thought it would be really cool to work for a company where, on the side of my personal life, I use their software,” he recalls.
Today as CISO, his responsibilities extend beyond a traditional security organization. In addition to overseeing the breadth of Avid’s cybersecurity program, Kyle is responsible for enterprise IT, including systems and network administration. He believes that combination provides an important advantage.

“Security teams struggle because they actually can’t make the changes to make the company more secure,” Kyle explains. “They’re simply advising on the risk and recommending the remediation, but they’re wholly reliant on other teams to execute.” Having both teams aligned under one structure, he believes, can accelerate risk reduction. 

Getting Back to the Fundamentals

That ability to execute is particularly important given Kyle’s priorities for the next several years. Rather than looking for another security product to add to his portfolio, he is focused on maximizing the technologies Avid already owns and addressing more systemic issues within the environment.

“We’re not one tool away from making Avid more secure,” he says. “I’ve largely applied all the bandaids we can apply. Now I want to go after the systemic issues.”

For Kyle, that means improving configuration management, strengthening processes, and hardening environments against known configuration standards. It is work that may not generate the same excitement as buying a new technology, but he believes it can have a greater impact on security.

He compares the approach to personal health. Much like jumping on the latest fad diet, purchasing another security product can be relatively easy. Consistently maintaining strong configurations and processes requires considerably more discipline, much like consistently maintaining a healthy diet and exercise program. “There are a lot of things that don’t require a tool,” Kyle explains. “It’s just human work that has to be done.” 

Finding Practical Value in AI

Kyle brings a similar perspective to artificial intelligence. He sees significant opportunities for AI to augment his team, particularly when it can eliminate repetitive work and give employees more time to focus on improving the security program.

One example is customer security questionnaires. Rather than purchase another SaaS platform, Kyle challenged a team member to explore whether they could build something themselves. Within roughly a day, they developed an internal AI powered tool that can process questionnaires and produce responses for human review in minutes. 

Avid is also using AI within email security, where automation has replaced a previously manual review process and is saving the security team significant time each week.

Those use cases have made Kyle optimistic about AI as an efficiency tool, but he remains measured about some of the broader predictions surrounding its impact on cybersecurity. “I don’t know that we really understand what the actual ROI of AI is quite yet,” he says. 

Security Fundamentals in an AI World

Kyle has heard predictions that AI will dramatically increase the scale and sophistication of cyberattacks. While he expects AI to make certain capabilities more accessible to attackers, he does not believe it changes the fundamental problem defenders need to solve.

 “At the end of the day, they still have to exploit vulnerabilities, the same misconfigurations, trick the same humans” Kyle explains. “If we maintain some of the base principles of security, like principle of least privilege, good configuration management, understanding our asset inventory, and controlling what happens on those assets, I think we’ll be okay.”

His greater concern is making sure organizations do not become distracted by AI hype at the expense of those fundamentals. “I’m not afraid of the machine,” he says. “I’m afraid of how much money we’re spending with AI in hopes that we see an ROI one day.” 

Changing the Culture of Security

Kyle expects his team to identify problems and take initiative rather than wait for direction. He also does not want to be the only person identifying risk or developing solutions. “If I am the smartest person on the team, that’s a problem, because I can’t be the one solutioning for everything,” he explains.  

The role of the security team, he believes, should be that of a risk advisor. If someone wants to purchase a technology or pursue building a new feature or solution, Kyle’s team evaluates it and explains the potential risk. The appropriate business leader then decides whether that risk is acceptable.

“We’re not gatekeepers,” Kyle comments. “If you want to go put your hand on a hot stovetop, we’ll tell you all the reasons why you shouldn’t do it, but at the end of the day, if you accept the risk, it’s on you.” 

Building Trust Through Transparency

The same philosophy shapes Kyle’s relationship with executive leadership and the board. He believes CISOs need to be willing to present the organization’s risk as it actually exists, even when the picture is uncomfortable. Trying to make a security program appear stronger than it is ultimately undermines a CISO’s responsibility as a risk advisor.

“If I’m hiding that risk to make myself look better, that’s a really bad place to be in,” Kyle says. 

“Everyone has things in their organization that they need to address. Every program has gaps,” he explains. “If we’re just honest with each other and we’re a little vulnerable with each other, I think that helps establish trust.” 

It is an approach that connects back to the lessons Kyle learned early in his career. Security does not always require another product or a more complicated solution. Often, meaningful progress comes from understanding the risk, addressing the fundamentals, and being willing to do the difficult work required to make the organization stronger.

 

    Subscribe

    Stay up to date with cyber security trends and more