AJ Grotto

229 posts

AJ Grotto

AJ Grotto

@GrottoAndrew

Cyber/tech nerd @FSIStanford, former NSC Senior Director for Cyber Policy

Stanford, CA Katılım Aralık 2017
125 Takip Edilen1K Takipçiler
Vivek Ramaswamy
Vivek Ramaswamy@VivekGRamaswamy·
The federal government is the world’s largest IT customer, spending ~$2TN since 1994. In theory, this *should* give us great buying power to negotiate good deals for taxpayers, but of course that’s not what happens: in 2021, the US Department of Agriculture agreed to pay $170 million for one enterprise software, instead of $58 million for a competing one, due to perceived switching costs. In other cases, vendors have required agencies to repurchase licenses in order to migrate to the cloud. If the federal government were serious about reducing costs, it would procure government-wide licenses, just like many state governments do, which would save $750mm+ per year (likely much more). The to-do list for @DOGE continues to grow.
English
1.2K
4.1K
23.4K
965.7K
AJ Grotto
AJ Grotto@GrottoAndrew·
@Microsoft promised to tie executive pay to cybersecurity performance. Months later @satyanadella’s salary is up 63%, Brad Smith’s 29%, while exploited vulns are already higher now than in 2023, a year after launching its “Secure Future Initiative.” bloomberg.com/news/articles/…
English
1
1
0
66
AJ Grotto
AJ Grotto@GrottoAndrew·
@BradSmi testified that @MSFT would “treat security as the most important attribute of product quality.” Yet its security business - which involves upselling security features to customers - surpasses $20 billion annually. What will become of this revenue cash cow?
English
0
0
0
24
AJ Grotto
AJ Grotto@GrottoAndrew·
Bill Gates in 2002: when @MSFT “face[s] a choice between adding features and resolving security issues, we need to choose security.” @BradSmi at @HomelandGOP just made the same pledge in 2024. Why should we believe this time will be different?
English
0
1
3
762
AJ Grotto
AJ Grotto@GrottoAndrew·
@BradSmi’s written testimony talks about “empowering and rewarding every employee to find security issues, report them, help fix them, and encourage broader learning from the process and the results.” So…this wasn’t happening before? @Microsoft
English
0
0
1
31
AJ Grotto
AJ Grotto@GrottoAndrew·
Lots to like in Charlie Ball's memo microsoft.com/en-us/security… about security by default, but if you're still upselling security, by definition, security is not the default.
English
0
0
1
384
AJ Grotto retweetledi
Stanford DigiChina Project
The Cyberspace Administration of China today published a draft decision to amend the Cybersecurity Law five years after it took effect in 2017. We are working on a simple comparison now. cac.gov.cn/2022-09/14/c_1…
English
2
14
37
0
Victor Cha
Victor Cha@VictorDCha·
Great @CSISKoreaChair episode on supply chain security and “silicon allies” with @GrottoAndrew @mwlippert #newfrontiers even if it was 3am HDT!
CSIS Korea Chair@CSISKoreaChair

In case you just missed our tour de force episode with @StanfordCyber @GrottoAndrew, @mwlippert, @VictorDCha & @SueMiTerry on all things economic security & tech cooperation related in the US-ROK alliance, rewatch the @CSIS #CapitalCable below ⬇️ youtube.com/watch?v=nCRNdU…

English
1
2
3
0
AJ Grotto retweetledi
The Reasoning Show
The Reasoning Show@ReasoningShow·
The Cloudcast - CyberSecurity, Economics and Policy in 2022 bit.ly/cloudcast-eps6… Andy Grotto (@grottoandrew, Researcher @StanfordCyber) & Steve Weber (Prof. Cal Berkeley I-School) talk about the big picture intersection of Cybersecurity, Global Economy and Government policy.
The Reasoning Show tweet media
English
0
3
2
0
AJ Grotto retweetledi
Stanford HAI
Stanford HAI@StanfordHAI·
🚨Just released: HAI policy white paper outlining a roadmap for a multilateral AI research institute (MAIRI) bringing international stakeholders together to promote AI R&D collaboration, multidisciplinary AI research, and democracy-affirming AI with human-centric norms & values.
Stanford HAI tweet media
English
2
14
43
0
AJ Grotto retweetledi
Stanford Tech Impact and Policy Center
Join us tomorrow at noon, as @GrottoAndrew moderates a discussion on recent developments in cybersecurity law, including pragmatic advice on compliance and litigation strategy & big picture insights on the direction of U.S. cybersecurity policy. Register: stanford.io/3NS0zce
Stanford Tech Impact and Policy Center tweet media
English
0
6
8
0