Building Cyber Resilience with Fortinet’s Glenn Maiden
Host Paul Spain is joined by Glenn Maiden, Chief Security Officer at Fortinet and Director of Threat Intelligence Operations at FortiGuard Labs, Australia and New Zealand. Glenn brings invaluable insights into today’s rapidly evolving digital threat landscape with practical advice for organisations of all sizes on how to bolster cyber defences against current and future threats.
Paul and Glenn also dive into the latest tech news including:
Special thanks to our show partners: Fortinet, Workday, Spark New Zealand, One New Zealand, 2degrees, PwC New Zealand, and Gorilla Technology.
Read the full transcript
Transcript is computer-generated and may contain errors.
Glenn Maiden:
The problem is we always think that we can just have one silver bullet that’s going to make us secure. It’s not, but there’s a few things that we can do that can make us considerably harder. So I don’t want everyone just to sort of, you know, throw in the towel and go home. There is absolutely a way to face this threat even in 2026.
Paul Spain:
Hey folks, greetings and welcome along to the New Zealand Tech Podcast. I’m your host, Paul Spain. Joining us today is Glenn Maiden. He’s Chief Security Officer and Director of Threat Intelligence at Fortinet Australia and New Zealand. Glenn brings with him more than 20 years experience across defence, intelligence and enterprise cyber security and now leads efforts to help organizations better understand and defend against today’s evolving cyber threats. In addition, Glenn is also the Chief Security Officer for Crimestoppers International. So there’s a lot going on there.
Paul Spain:
Great to have you on the show, Glenn. How are you?
Glenn Maiden:
Very well. Thank you for having me Paul. It’s great to be here.
Paul Spain:
Thanks for joining us. Looking forward to delving in and really hearing some of your insights on cyber security currently what that looks like with the landscape of war in Iran and other things going on. Although you know, we hear that something’s been signed off. But I know there have been things going on in that part of the world and you know, data centres at risk and undersea cables, all sorts there. So looking forward to your insights and of course we’ll be delving into some of the tech news of the week as well. So looking forward to that. Before we jump in, of course a big thank you to our show partners to Spark, One New Zealand, 2degrees, Workday, Fortinet, PwC and Gorilla Technology. So yeah, thank you for the support of the show from Fortinet and of course appreciation to our other show partners as well, not only for supporting the New Zealand Tech Podcast but you know, for what all our partners do for the broader tech and innovation ecosystems in New Zealand.
Paul Spain:
Well, first up on the New Zealand front we’ve heard from TUANZ, the Technology Users association of New Zealand today and, and they’re urging for cross party agreement on a long term national cybersecurity strategy in order to help unlock New Zealand’s digital potential. Now they warn that the short political cycles that we have in New Zealand so we’re, you know, rolling over a new government every three years and then you know, a chunk of that is election cycle. So in reality there’s not that much time, you know, in between. So they’re saying, look, these short political cycles, risk under investment, despite some good infrastructure skills and renewable energy foundations, we need to do better to be able to compete globally and to drive growth. And of course cyber security is a part of that picture as well. What are your thoughts coming from? You obviously are across both New Zealand and Australia, but you’re based very close to Canberra. So I’m sure you’re probably following what happens on the Australian government side a bit closer and you’ve got the four year election cycle over there. What do you think around this approach of kind of a unified guidance? Because what TUANZ are suggesting here, they’re basically working on recommendations that I guess the hope is that, you know, become adopted, you know, nationally from both sides, depending on, you know, where the government goes, so that we don’t have that kind of flip flopping, you know, change.
Glenn Maiden:
I think I listened to a podcast and it wasn’t as good as yours, Paul. It was an inferior podcast, but the guest on it was AI expert and they just said, well, we had the Industrial Revolution and we had 100 years to get from point A to point B and be able to get our society to be able to understand what it means, embrace the technology, then adapt. What this particular gentleman was saying was with AI, it’s going to be 10 times the impact of the Industrial Revolution in about a tenth of the time. So we’ve really got about ten years now for our entire world to change absolutely exponentially. So I think this advice is probably very, very, it has a lot of merit, it’s very, very insightful. So I think given the rate of change, I mean there would need to be a level of flexibility to be able to adapt as the technology changes so quick with Moore’s Law and stuff. But I do really, really like the idea of a country like New Zealand and Australia of course as well, but looking at where some of our competitive advantages and investing in some really long term infrastructure. So whether that’s making sure we’ve got, you know, additional undersea cables or additional fibre connecting up the main technology parts of New Zealand or whether it’s data centres as we were talking about before, but I think building some of those foundational national assets is a fantastic idea.
Glenn Maiden:
And some of these things, if we get started now and we’ve got a few years work ahead of us, it should be very, very valuable for
Paul Spain:
a
Glenn Maiden:
future and maybe only a couple of years in the future as things change so quickly.
Paul Spain:
Yeah, well, you Know, I think if we were to, say, compare New Zealand to Australia, and us Kiwis do this from time to time, and let’s just pick the broadband, for instance, here in New Zealand. And that was something where one government kicked it off. We’re gonna roll out fibre to initially 75% of homes. But that was something that the, you know, successive governments sort of stayed the course and invested in. And, you know, I would argue we got a pretty good, you know, result on that front. You know, with 87% of the population, you know, now able to get fibre, we probably don’t need to talk about the Australian one and how much was spent on that. But, you know, you guys caught up in the end, right?
Glenn Maiden:
I still think. I mean, and again, I’m happy to. I’m happy to be honest about it. I think that was massive lost opportunity for Australia in some of the ways that a huge asset like that could have been politicised and not. Not realized the way that it should have been. So you’re right, we’re getting there. Now, I live on a farm about half an hour from Canberra. I’m using Starlink.
Glenn Maiden:
I shouldn’t be. I’m half a half, half an hour away from a capital city. So, again, goes back. Goes back to your point, let’s have a look and see what’s really, really important for the nation, not for the political party of the day.
Paul Spain:
Yeah, but these things are hard, I guess, is the reality. And, yeah, it’ll be really interesting to see what, you know, what Tuan’s come out with. You know, I think even an independent organisation like this, coming up with something, you know, very hard to maybe get agreement, you know, right across the board on everything. But I think it’s a great initiative. But, yeah, the lesson I would pick would be the Ultra Fast Broadband Initiative in New Zealand versus the National Broadband Network in Australia. Because in New Zealand, we really, you know, did have that consistent support from both sides and it was, you know, ultimately an excellent outcome.
Glenn Maiden:
Yes. And I think, you know, countries like ours, we, even though you’re a bit smaller than Australia, but we do have a very geographically dispersed population. So, you know, having some of that connecting tissue, even if it’s digital tissue these days, is absolutely critical for the health and wellbeing of a bunch of people that are very, very far away from potentially health services or education services and things like that. So, yeah, this is an investment in the country, not in the nothing else.
Paul Spain:
Yeah. Now, onto things on a global front. Anthropic has suspended its new Claude Fable 5 and Mythos 5 models following a US government directive over potential security risks linked to jailbreaking. The move highlights escalating concerns around AI models, cyber capabilities, geopolitical control, and the real world risks of increasingly powerful models. I’m picking this as something you’re probably watching reasonably closely because it’s so deeply connected to the world of cyber, isn’t it?
Glenn Maiden:
It is. So I think when Mythos came out, I think that surprised a lot of people in terms of just how capable it is. I think a lot of people still don’t have the full picture in terms of what it can and can’t do and what’s, you know, what’s real and what’s not. But my view is the way that that’s panned out has panned out the best way possible that that could have panned out. So Fortinet, we’re part of Project Class Wing. Mythos has been shared with us for quite some time now. So we’re using it to make sure that all of our products are as secure as possible and resistant to potentially AI vulnerability assessment and exploitation. So to me, I think that was really, really optimal outcome for something that could have maybe been a lot worse than that.
Glenn Maiden:
I think with the, with the new banning of some of these technologies overseas. I mean, I look back many, many years ago, and there was a whole bunch of encryption protocols and encryption algorithms that were not allowed to be exported from the US because they had export controls on them. So I think that this is probably similar and, you know, you could argue it’s probably not ideal for us, but probably trying to keep a little bit of a handle on some of those technologies until we can understand just how capable they are and some of the implications. I know, certainly from a cyber perspective, I should say we’ve seen even just gen AI models where I can’t talk a Gen AI model into doing something illegal. But what the bad guys have done is said, well, I’m just going to create my own Gen AI model. So whether that’s worm GPT or fraud GPT or some of these other models that have those guardrails. So, you know, maybe if there is some really, really critical technology like that, this is, this is not a bad thing necessarily for the world.
Paul Spain:
Yeah. And I think the concerns around jailbreaking that, you know, bad actors, you know, can manipulate the models to do things that in theory they’re not supposed to do. But because, you know, we haven’t, you know, seen all of the risks with, you know, prompt injection and so on, you know, addressed. There is that risk sitting in the background. You know, actually Anthropic can’t completely, you know, control their own models and that’s probably the same for all of the companies. Right. So it is a absolutely fascinating time to be alive. I did like you, I thought that, you know, project Glasswing this, you know, the, you know, making available of the new models to some, you know, specific partners by Anthropic to be able to address cybersecurity issues before the models were, were released more broadly.
Paul Spain:
Yeah, that sounded either really good or good PR spin, but I think, I think, you know, to me it was more than, you know, more than some sort of publicity trick. You know, it seems like genuinely, you know, the, the new models are, are a step up and you know, they were able to find a whole lot of vulnerabilities. So yeah, you know, this is going to be quite a challenging one to probably solve over the next little while because as a new model comes out it tends to get mimicked and kind of copied and then you’ll see sort of open source models from varying places and so on effectively match what the most cutting edge models do within a period of months. Right. So it is I think a significant challenge and I’m not quite sure where to from here. Obviously Anthropic have really sort of pushed back on the US Government and you know, saying this doesn’t make sense but yeah, I’m not, I’m not sure we have the perfect answer. And you know, from, from what we’ve been hearing from the leaders, you know, across the, the key gen AI platforms, you know, they all hold some, some significant, you know, concerns around the future of AI and significant risks. So you know, in some ways it’s actually pleasing that there is at least some, you know, government intervention that isn’t just saying, hey, go for gold, do whatever you like, we’re never going to, we’re never going to say no to anything.
Glenn Maiden:
I mean, maybe I’m a little bit getting a bit more conservative in my older days, but I think, you know, the old principle that information wants to be free holds true. So I think until we can actually understand and actually, even if I step back a bit, one of the things that I’ve seen over the last couple of years is, you know, obviously there’s been some really clever AI models, some absolutely mind bending AI models, but one thing that stood out to me is just the innovative use of some of these models by normal people, but also by cybercriminals as well, so I think just until we actually understand what that capability is and what risk that’s bringing to businesses here in New Zealand and broader. I think just maybe keeping it a little bit close to the chest is not necessarily a bad thing, at least temporarily.
Paul Spain:
Yeah, I mean, but it creates a whole new situation we haven’t seen before when governments are able to shut down an AI model. And effectively this is what’s happened on a global basis. I think it also highlights the concerns around AI being used by bad actors as a cybersecurity weapon. And, you know, I think we’ll definitely stir up some tensions around, you know, tech sovereignty. You know, we’ve talked about data sovereignty, you know, often in years gone by, but we haven’t thought of the sovereignty from an AI perspective to the same degree in terms of, you know, who has control over the AI models. Which takes us into our next story, which is around SpaceX. They’ve had their initial public offering on the NASDAQ over the weekend. And you know, part of what they’re doing, you know, I get their big sell, is about data centers in space.
Paul Spain:
Now you kind of cross these two things, these two things over what sort of control would there be if the data centers that were housing these AI models were sitting in space? You know, you could potentially have companies that are pushing back on their local governments and going, well, that’s outside of your jurisdiction. It’s sitting in space and we will do what we like. Do you think that’s a possibility?
Glenn Maiden:
This sounds like a Pandora’s box, Paul. I mean, I think the interesting part, and going back to your previous question about the anthropic and banning, the, banning the export of that technology to certain countries, if you think about what that could mean from a realistic perspective, it’s only a couple of their models that they’re banned, that are sort of very, very high end models. But I think, you know, as countries like Australia and New Zealand and we’re a long way away from everywhere else, so as we start to become more and more dependent on whether it’s even not even just AI, but certainly with software as a service and you know, the big hyperscalers and those sort of things, what would it actually mean if we did have. So whether it was a political or a physical event that had that cable cut, or in the case, as in your example now, whether it was a data center in space, if we had that beam interrupted, what would that mean? Would that mean that we can no longer operate on someone in hospital? If you think in a Couple of years the surgeon’s going to be sitting in Auckland, you know, operating on someone down in Dunedin or something like that. All of a sudden that whole business model and all the efficiencies we’ve gained from technology over many, many years have been undermined. So it’s absolutely something that we need to think about not just in terms of, I guess that one model, but if we think of everything as one massive big mesh of interconnected systems, you know, what is the effect? If I cut one link here, what does it actually mean for, you know, my 80 year old mother that’s getting operated on tomorrow in Dunedin or something bad happens.
Paul Spain:
This is part of the flip side, isn’t it, is when these things get blocked or banned it’s hard to necessarily know what the flow on effect might be. I mean I, I was impacted. I was using, you know, one of these models over the, over the weekend and you know, I was wondering why, why I had some errors on the screen and the weekend. It wasn’t nothing too critical. But yeah, somehow it’s later and I pick up the news and, and realized, oh, here’s what’s going on.
Glenn Maiden:
It’s not just, at least it wasn’t user error.
Paul Spain:
Yeah, yeah. At least it’s not just me. Everyone else around the world was in exactly the same boat. But yeah, certainly if it was something, you know, critical in terms of somebody’s health and yeah, the models have been relied on and I think this is one of the aspects of AI is the models keep changing quite quickly and things need to be designed in such a way that they can fail gracefully and that there are alternatives to be able to lean on if, if issues arise and, and even just the, the reality that yeah, a model won’t be around for, yeah, it’s not going to stick around for five years. It’s just not. That sort of thing’s not happening anymore. Whereas we, we’ve got quite used to, you know, bit of software. Yep.
Paul Spain:
You installed that on, you know, might be, might be 20 year old software. You might still be able to run it on a, on a current machine in some cases. Right. But that isn’t going to be the case probably anytime soon.
Glenn Maiden:
I was just going to say if you’ve got any listeners here that are in configuration management, your life is about to get a whole lot more painful and my apologies in advance. And change control as well. Change control is the other part of it. There’s big implications from cyber security. But yeah, how can you maintain a really, really solid change control system when essentially these models you’re consuming as a service are changing all the time.
Paul Spain:
Yeah, there’s a lot to delve into here. So when it comes to the SpaceX initial public offering, this has been the largest ever IPO in history. It’s landed at a time when we’ve got this huge AI fueled market boom and really intense investor demand. So I guess what we saw at the IPO where they put US$75 billion worth of shares on the market is that’s turned upward and anyone that was able to jump in right at the get go has ended up with a positive lift just having even a quick look. So as the share market’s been operating today, another 20 looks like, including sort of after hours trading, 23% increase in that stock. So, you know, we’re now looking at a market cap for SpaceX of US$2.5 trillion trillionaire, which is nuts, right? That’s north of, you know. Yeah, Elon’s the first trillionaire and yeah, north of 4 trillion if you put that in New Zealand dollar terms. So, yeah, biggest IPO in history.
Paul Spain:
A lot of people that have jumped in behind this and I guess it’s that sort of combination of their AI data center offerings, AI and space alongside the existing business that’s got people excited. But I think there’s probably some significant tension here in terms of if they don’t pull off what they’re aiming to, then that valuation is potentially way too high. If they do pull it off, then who knows, is it too low, the
Glenn Maiden:
sky’s the limit, or maybe even the skies aren’t. The sky’s not the limit when SpaceX.
Paul Spain:
Yeah, it certainly wasn’t something I was jumping into to invest in myself, but I can understand why so many people have been attracted to it. But I think it’s one of those stocks that, you know, potentially carries a significant amount of risk. And on the flip side, if it goes well. Well, yeah, maybe, as some people are suggesting, they end up as a, as a $10 trillion business.
Glenn Maiden:
Yeah. For anyone listening, do not take any investment advice from me. That’s the last thing you want to do. But I do think that in the case of SpaceX. Paul, I actually agree with all your points there. There’s definitely, there’s just definitely some risk there. But they seem to be a very innovative, iterative, fast moving company. Like there’s a lot, there’s a, there’s a lot that they’re doing which is really, really exciting.
Glenn Maiden:
So, yeah, I guess from a financial perspective then that’s not for me to comment. I’ve got no idea.
Paul Spain:
That’s not the purpose of the show. So. Yeah, and I guess also, you know, we should, we should mention there’s a bit of a story here with Rocket Lab as well. You know, incredible and innovative New Zealand slash American space business. And at the same time as SpaceX were doing their IPO, we heard that Rocket Lab have entered the NASDAQ 100 index. And of course, SpaceX will land on that as well. And what that means is for, you know, those that are, you know, got Kiwisavers and varying other sort of investments, you know, then they may well end up with a slice of SpaceX and now a slice of, of Rocket Lab in their portfolios because of the way that these indexes work and how investments go against those top companies. So, yeah, I think that certainly got a few people kind of excited on the Rocket Lab side.
Paul Spain:
And of course, a lot of Kiwis are following with interest. I think we’ve seen stats suggesting something like 32,000 New Zealanders have Rocket Lab shares. So. And I think there’s, you know, there’s a lot of interest in seeing Rocket Lab’s continued success.
Glenn Maiden:
It’s good to see the Kiwis keeping the fight alive with the Americans. Yeah.
Paul Spain:
Yeah, well, definitely, because we’re not getting too much competition on the Australian front at the moment. No, you’re not. So, you know, we’re pretty happy on that front. Now, another story that crossed my path that I thought we should, we should touch on, and this is one that could become a deep rabbit hole, which probably today we won’t do that. But new scientists have published a story and their report claims that fully autonomous AI drones killed soldiers during a Ukrainian battlefield test two years ago. The drones apparently independently targeted and destroyed enemies without human oversight, marking a controversial milestone and raising some very significant ethical, legal and accountability concerns about autonomous warfare. And yeah, I guess when you think about that, you know, having no human oversight or visibility with the drones apparently operated without, you know, communication, without there being a video feed with somebody external making or having that opportunity for, for any sort of intervention, we have a, you know, a big challenge. And that also, as well as those sort of ethical, you know, concerns about that, you end up with, well, who’s legally liable? Is it the manufacturer of the equipment? Is it the country that sort of, you know, initiated the attack? Is it individual that programmed it? That’s pretty challenging.
Paul Spain:
Now, you know, they have said that, look, the evidence is limited and, you know, we don’t have any sort of verification from Ukraine’s Ministry of Defence or any kind of official parties. But this is the sort of thing that’s been talked about for decades, isn’t it? And now we’re hearing that, you know, maybe at least in a test scenario that, you know, there have been folks that have been, you know, killed in this manner.
Glenn Maiden:
Am I going to be the first person on this podcast to mention Skynet? Maybe, maybe, maybe not. But I mean, it’s absolutely terrifying again, like with a lot of these AI instances where we don’t fully know exactly what’s going on underneath, even the, even the developers that are actually building these systems. So yeah, there’s a million ways that it could go wrong. The flip side of that though also is if we’re going to be honest with ourselves, this is probably the future of warfare. So, you know, a whole bunch of tactical, operational and strategic level drone platforms is where the world’s heading, whether we like it or not. All with some level of AI embedded capability to at least some degree. So I guess we’re going to have to start to come to terms with it.
Paul Spain:
Yeah, I mean, I guess, you know, my feeling is, well, we’ve got the technology like we’ve got, you know, somewhat autonomous cars, we’ve got, you know, autonomous tools from a cyber security perspective and so on. But you know, when we’re talking about taking people’s lives, is this an area that, you know, should be sacrosanct and you know, then there, you know, needs to be, you know, some sort of global agreement and you know, it’s not unique to have, you know, legal restraints around certain things in a, I guess in a war type context. So yeah, this to me seems like, like something that needs, probably needs some serious thought. But, but yeah, I mean, I agree. I think if, if there is, if there is no agreement or laws in place otherwise then you know, we will move to, you know, very much to a world where I mean, this is just the natural progression of things. So, you know, I’m kind of hopeful that that doesn’t happen. Right.
Glenn Maiden:
It could be a good thing. I mean, going back to my defence days, you know, you’ve got international laws of arms conflict and unfortunately they’re not always adhered to. But most countries, and certainly Australia was one of them, you know, you would be doing battle damage assessments before any particular campaign. So you didn’t hit a school or you didn’t hit a mosque or didn’t hit a church or whatever it is. So if you think from an AI perspective, there is the opportunity to introduce some very, very, very hard guardrails where that may eliminate human error and I guess hopefully have less innocent, innocent bystanders be killed. And I know if you take it back to, you mentioned the autonomous cars, I know I heard Elon say once, you know, I don’t have to have the best, you know, I don’t have to have it perfect. I don’t have to have it so it never has a crash, but I just need to get it to the point where it’s better than the best driver in the world. So maybe there is a glass half full element to this as well.
Glenn Maiden:
As long as we can trust countries to use technology like this responsibly.
Paul Spain:
It’s a good point actually, and definitely an area that I think would be called quite controversial. And you know, when we don’t understand how, you know, a particular type of technology works, it can be pretty hard to, to have, you know, confidence, you know, particularly in an area like this. So. Yep. But you know, no doubt there are lots of people, you know, thinking and working on, on how to, how to leverage artificial intelligence within these sort of contexts in a manner that yields, you know, the most positive results and minimizes the downsides.
Glenn Maiden:
I know you didn’t want to go down this rabbit hole, but I did a presentation yesterday and I had a video in it of the, you know, the MIT robot dog.
Paul Spain:
Oh yeah.
Glenn Maiden:
So there was a country now has developed a version of that, but with a machine gun mounted to the top. And I was just thinking, you know, if I was a soldier running around like, that’d be pretty hard to get away from. So yeah, there’s some of the, some of these innovative AI enabled capabilities is going absolutely change the nature of war.
Paul Spain:
Yeah, well, I mean, you, you get into a, into an environment where, you know, you do have, you know, you’ve got those sort of robots out in, in the field as obviously in the, in the sky already. You know, whether, whether it be, you know, parts of the Middle east or whether it be, you know, Ukraine war and, and so, you know, we expect that these sorts of progressions that we’ve seen examples of will, you know, we’ll, we’ll continue sort of for better or for worse. But you know, I hope that we can, we can get the, the balance right. And I don’t know there is a perfect balance ever when it comes to war, to be fair. But you know, that there will be, you know, good, good debate on these things. And you know, of course the ultimate is that we don’t ever have war. But you know, I think while there’s, while there’s humans on this earth, we, you know, we will see conflict in one form or another.
Glenn Maiden:
I think the interesting thing for me is if you look back, I mean, it’s not new for us to be using drones. So whether it’s, you know, Reaper or something like that. We’ve been using drones for 10, 15 years, but they’ve always been really big platforms. What is happening now, I guess in, and what Ukraine has shown us is just, and I mentioned that word before, innovative use of some of these systems. So, you know, you get a, you know, thousand dollar DJI Mavic Pro or something like that and strap a, strap a bomb to it and that then becomes a extremely effective weapon. So I think, you know, this, this innovation side is going to change a lot of things very, very quickly.
Paul Spain:
Yeah, and I think, you know, we’ve, we’ve seen that, you know, with some of these drones where in the past they’ve been able to, you know, block their signals and you know, now they’re, they’re attaching a, you know, fiber optic to, to a drone and you know, sending that, you know, across into, into a territory that might be trying to interfere with comms, but you can’t interfere with a fiber optic, you know, cable. So, you know, the, I guess the, the reality is, and you know, we’ve seen this, you know, over a period of years that, you know, where lives are at stake. You know, there will be, you know, significant, significant work done and an investment, you know, made to, to find new approaches to, to doing things. All right, that’s probably our news topics over for the episode. Very keen to sort of delve into a bit of your story and what you’re seeing out there in the cybersecurity world. Glenn, so maybe you can tell us a little bit about what was your path into the world of cyber and how you’ve ended up in your current role at Fortinet across Australia and New Zealand.
Glenn Maiden:
Yeah, it’s funny, like people as old as me didn’t really have a path into cyber because it wasn’t even a thing back then. So I sort of started out working for the Department of Defense in Australia, obviously in the mid-90s. I then sort of fell into cyber security in some of our national security organizations. So I sort of fell into cyber security and some of our defense intelligence and security organizations and then grew up there for several years. I then left, left Defence and went to our tax office and I was the IT security advisor for our tax office for about four years. So. And as you can imagine, that was sort of quite unique, trying to defend such an incredible database of the PII of every. Of every Australian at that scale.
Glenn Maiden:
So, you know, so the looking back now, it’s actually, I’m quite proud that we were able to keep the integrity of such critical systems like that. But all my background in, I guess, sort of in cyber and intelligence sort of led me through to now Fortiguard Labs, which is the threat intelligence component of Fortinet. For anyone that doesn’t know, we’re one of the biggest pure cybersecurity companies in the world. We’ve got about. Actually, we’ve got heaps and heaps of firewalls all throughout New Zealand. You don’t have to look too far to find one. But we’ve actually got about 59 other products from. And if it’s cybersecurity, we probably do it.
Glenn Maiden:
But my organization, Fortiguard Labs, is the threat intelligence component that sits behind all the capabilities of these products. So we go through the threat environment, we work with partners, we work with people like CERT New Zealand, pulling in as much information as we can and then turning that into some form of protection profile and then pushing that back out to the fleet of Fortinet devices and also partner devices. Obviously we share a lot with partners as well. So. Yeah, so I sort of fell into it a little bit. But it’s sad. Maybe it’s. I don’t even know what the right word is, but it’s a little bit sad.
Glenn Maiden:
But unfortunately, in all my years, it’s still. The cyber threat has only grown. We haven’t been able to squash it down as much as I would have liked.
Paul Spain:
And tell us about this role you’ve taken on with Crime Stoppers International, because there’s a partnership between Fortinet and Crime Stoppers on a global basis. But you’re also taking on a. Wearing a pretty important hat for Crime Stoppers too.
Glenn Maiden:
No, it’s a role I’m absolutely proud of, Paul. So we started out about six months ago. My boss, his name’s Derek Menke, so he’s our global head of threat intelligence and he’s done some great work with partnerships. So he set up partnerships with Interpol, with World Economic Forum. Anyway, he sort of was sitting back probably about 12 months ago and he just said, well, you know, there’s bug bounties, there’s bounties for real criminals, real world criminals. But at the moment, most Cyber criminals are getting away with it. So, you know, we’ll learn from the attacks and then build our defenses better. But in terms of actually catching the bad guys, we still need to do much more.
Glenn Maiden:
So Crime Stoppers was a natural partner there. They’ve got about Crime Stoppers International is the international component of Crime Stoppers and then there’s Crime Stoppers in 800, I think it is jurisdictions around the world. Anyway, so they, they were a natural spot for us to sort of set up what we thought would be a cybercrime bounty program. And luckily for, luckily for me is when I got handed this, handed this challenge by the boss. The CEO of Crimestoppers International is actually, she’s an Australian, Hayley Van Loon, based out of Melbourne. So anyway, so we’ve been working closely with, with the CEO and with the rest of Crimestoppers now for about six months to come up with this bounty program, its initial operating capability. So if you know a cyber criminal that’s operating outside of, in your street or something like that, you can actually put in a tip and we’ll be starting to accept paid bounties from people soon. So if you know who one of our bounty targets is, you can go in, put the tip in and then potentially get, get a juicy reward.
Glenn Maiden:
So that’s where it all started. But then the thing that I’m most excited about in terms of my Crimestoppers International role is the way the law enforcement sort of look at cyber crime. They call it cyber dependent crime and cyber enabled crime. So cyber dependent is your typical ransomware, your typical data breaches, those sort of things. And that’s what I’ve been doing my whole career. But the cyber enabled crime is the stuff that is the more horrible side of it. So this is human trafficking, this is a lot of smuggling people, smuggling, child sexual exploitation, all that horrible stuff. But a lot of these criminals now are run by global organised crime gangs and counting that, they’re using some of that same infrastructure for the cyber crime dependent crime and cyber enabled crime.
Glenn Maiden:
So by joining up with Crime Stoppers, I’m hoping we can join the few dots and make some very, very horrible people’s days. Very, very, very bad. That’s, that’s my plan anyway.
Paul Spain:
Yeah. Oh, that, that’s, that’s great. You know, I think it’s, it’s a big challenge and we’ve got to pull out all the stops to, to address these, these challenges.
Glenn Maiden:
Well, the good thing is like there’s companies like Fortinet and you know, we work with the other big companies, but you know, not for profits like, like Crime Stoppers. There’s so many, you hear all these horrible stories, but there’s so many people doing the best trying to, you know, bring a little bit of, a little bit of good to the world. So yeah, I think with any luck we’ll start to see a few, a few wins on the, on the scorecard over the next few months.
Paul Spain:
Yeah. Yeah, good. Well, definitely keep us appraised on, on that front. Now you see things that, that, you know, probably would, would, would shock people and you know, you, you get access to, to information that, you know, isn’t necessarily getting talked about every day. Now some of that will tend to, you know, float through in the, the varying reports that, that, you know, that are released. We have the 2026 Threat Landscape Report that has, has come through from, from Fortinet. What can you, what can you share with us around the key cyber threats? You know, right now? And you know, what are maybe those that people may be not quite so familiar with but, you know, really starting to come onto the, onto the radar?
Glenn Maiden:
I think I’m not going to answer this the way maybe you expected, but I think there’s a lot of hype and there’s a lot of fear, uncertainty and doubt in the, certainly in the market at the moment. There was a survey done by one of the big consulting companies and it was about what the CISOs across the, they surveyed so many CISOs, like, you know, probably thousands of them and you know, what was their greatest concerns and what was. Where were they planning on spending their money in the next 12 months? Yeah, and I looked at what their greatest concerns were and I looked at what the, where they were going to spend their money and both those things didn’t add up for me. So while, you know, we’ll, we’ll say as in Fortinet, we’ll say that the speed of these attacks is getting, is getting quicker. For sure it is. The attackers are getting better at what they do for sure they are in some components. But I think the biggest, I guess concern for me is not 100% turnaround in the threat. I mean, the threat has been getting incrementally, I guess, more severe every year and that’s getting quicker and quicker.
Glenn Maiden:
But the most important thing for me is having good decision for defenders blue side and making sure that they’re proactive in their defensive architectures. And I think that’s the way that we win. We need to make sure that we’re understanding what the threat is Becoming, I guess, a little bit more comfortable with getting a breach. So I think we’re at the stage now where it’s inevitable that we’re going to get a breach of our organisation somewhere. But we need, as you know, as board members, as C suite, as anyone in cyber security to say, well, I need to do everything in my power to make sure that when I get that breach that as rapidly as possible, I’ve identified it, I’ve contained it, I’ve remediated it and I’ve made sure that the impact of that breach is absolutely minimised. And there’s some, you know, I’ve got 60 products that we can sell you today that will help you do that. It’s just a matter of getting in front of that threat and getting some of those layered defence systems installed and deployed quickly.
Paul Spain:
Yeah, yeah, it’s, I guess that old adage of, you know, it’s not, you know, if you’re going to be impacted by a, you know, cyber incident, it’s, it’s when. Yes, and being prepared, as you say, so you, you really, you know, can, can minimise that. And I think that’s something I’m concerned about for, for New Zealand, especially because of the reality that, you know, from the government, you know, down, we probably still don’t fully have our heads around the cyber risks that exist today and the fact that they are fast moving and are not reducing things are on the increase and we have so many sort of mid size and smaller organizations in New Zealand where cyber isn’t necessarily something that’s, you know, the, the first thing that people think about. And then, yeah, you’ve got a government situation where there’s not enough money to go around the, the different areas. And you know, cyber certainly gets attention and there’s great work going on from the government front. But are we where we should be as a country? Are we investing enough? Yeah, probably not. And I think getting, getting, you know, the awareness front and center of mind, you know, this has been a journey over a long period. I think, you know, the first interview I did sort of, you know, on TV is probably, you know, 15 years ago talking about the, you know, the very early sort of ransomware that was coming through.
Paul Spain:
And yet, you know, I was talking to producer with our main public radio broadcaster today and I realized that some of the absolute basics from a cybersecurity point of view are still not deeply embedded in how we operate as a New Zealand population. And I’ve had multiple discussions around the basics of things like multi factor Authentication. And that was part of the discussion that, that we had about a future segment today. And you realise, well, even though there’s, you know, companies like Fortinet, there’s folks like me, there’s lots of people that are trying to, you know, nudge us forward, we’re still kind of a long way off where we should be.
Glenn Maiden:
It is tough. I mean, I think Australia is probably similar to New Zealand, maybe, maybe a little bit, little bit of difference. But in terms of the 90% of the economy being a small business of, of 20 or 20 people or less, like, it definitely creates some challenges. And I was actually just reading up today, so in Australia we just introduced some mandatory reporting for ransomware. The trouble with that is there’s a threshold of you’ve got to be making $3 million or more or you have to be a critical infrastructure owner and then you have to report. But if you think of us like those people that you’re talking about, the people that I’m talking about, a lot of those companies are not making $3 million or more. And even if they’re not critical infrastructure, maybe they are actually providing essential, maybe they’re building the bolts that go into some critical infrastructure. So either way it’s still going to hurt.
Glenn Maiden:
So I think, you know, to start off with, there’s a massive gap in terms of our visibility and in Australia, where we’ve actually made it law to try and get better visibility, there’s a massive gap in US seeing how impacted some of these segments are. We’re not reporting it, we don’t know. So that, that gives us almost zero clarity on how to address the problem. And then as you say, like some of these smaller organizations, it’s hard to be critical and just say, well, you know, you haven’t got MFA or you know, your password was password1,2,3. It’s hard to be critical when, you know, it might be a hairdresser or it might be a builder or it might be a bricklayer, you know, that has not touched cybersecurity in their life. So, you know, so how do we, how do we solve that? And here’s where I think I’ll get a little bit, a little bit optimistic because, because I do sort of get around New Zealand a little bit. There is some absolutely brilliant world leading cyber security talent in this country, like, of almost everyone I meet is, you know, is good or above. So I think if we can.
Glenn Maiden:
And there’s also some really, really good managed services providers, including Fortinet. So you know, if people need to need some cyber security advice. You know, go and knock on your nearest Fortinet door and you’ll get that. Good advice. But I think what’s happened up until now, the challenge at least to my mind has always been how can you have really good bleeding edge cybersecurity technology like something that we would be able to sell, but then how do we make sure that it’s viable for a business then to be able to scale that out to maybe 100 of these small 20 people or less companies. And I think that’s where AI is going to be our friend. So you know, we can actually start to deliver really good quality visibility, incident management, incidents response type services to a much broader swath of the, of, of the New Zealand business community.
Paul Spain:
Yeah, yeah, I think that that AI element is something that people are really interested in. Do you see that AI shifts the balance more in the direction of, you know, protecting organizations or more in the protection of the cyber criminals? Or is that something that’s going to vary the vary over time?
Glenn Maiden:
It might be like this, might be like this FIFA World cup at the moment Paul but where I’ve seen the true, I guess where the cybercriminals have grown absolutely incredibly in the last couple of years is in the pre exploitation phase of a breach. So this is just before they manage to get that first toehold into our networks. And that’s all about really, really authentic social engineering, really bait, deep fakes. So what we’re at the stage now where any one bait, whether it’s an email, whether it’s, you know, a teams call or something like that, whatever, whatever the bait happens to be, it is going to be so compelling that 99% of us can’t tell the difference between what’s legitimate and what’s fake. So that changes the game. But again, to put the glass half full perspective on that, we still have a lot of ability to minimize damage with all the other defence in depth controls we can have. If we assume that this most brilliant attack is going to be successful against someone in our one employee in our organisation, they’re going to click or they’re going to fill in a form or they’re going to do something. If we make sure that that initial component of the breach is about as far as they can go and that’s where we’ve got really good technology.
Glenn Maiden:
It’s not a technology problem. There’s technology that can limit that all the way through. Then we can get to the point where we make it really, really difficult for the most part. Cybercriminals to make any money.
Paul Spain:
Now, before we wrap up, I think folks would be interested in hearing what have we seen when it comes to warfare recently, particularly what’s been going on in the Middle East. What really stands out in terms of how, for instance, you know, cyber, cyber things being attacked that, you know, maybe not everyone is as aware of in this sort of current wartime type situation.
Glenn Maiden:
So I can give you three learnings. I started watching this really, really carefully when Russia invaded Ukraine a few years ago now. But there’s three things that really stand out to me. One is just how, just how embedded cyber security attacks or cyber attacks have become in what we would call the order of battle. So a cyber weapon now just as indiscriminately as kinetic weapon. So and again, we’ve seen that. I’ve watched the campaigns that’s happened in Ukraine. I’ve seen the cyber attacks line up incredibly well with the movement of troops and other infrastructure on the ground.
Glenn Maiden:
So cyber is now, besides being a tool for cyber criminals to use to make money, is absolutely in the toolbox, the war toolbox of nation states. So it will be used, it will be easy. And when you think about the context of Australia and New Zealand, it’s not limited by geography like a missile or a bullet is. So, you know, we are absolutely exposed with our critical infrastructure sectors. So that was sort of part one. Part two is, if you look at just more recently in the Iranian invasion, the data center, the Amazon data center just across the border, I think it was in Kuwait. You probably know better than I do
Paul Spain:
drone and missile strikes targeting AWS data centers in both UAE and Bahrain.
Glenn Maiden:
So this was one of the first targets that the Iranians retaliated against. Retaliated against was this data centre. So, you know, it wasn’t an area where there was troops, it wasn’t a hangar where there was jet planes, there wasn’t a port where there was either Israeli or American ships. You know, it was a data centre. So that when we go back to our earlier discussion, what does that actually mean if that data centre was providing critical infrastructure services for that country? So that was absolutely a legitimate target.
Paul Spain:
This is, you know, not something that we think about, you know, every day. And it’s probably not something that most Kiwis are thinking about either. But if there was, you know, a war situation that was directly impacting New Zealand, then, hey, what would that mean for infrastructure? Whether it’s in Auckland, whether it ends up in Invercargill, what would it mean for our fibre Optic, you know, connectivity to the rest of the world.
Glenn Maiden:
Well, that comes back to my third point so that, so when we saw the conflict break out in Gaza, almost every hacktivist or issue motivated group activity that we, that we’ve been tracking in Fortiguard for the last 12 months is somehow related to that conflict. And I’ve seen instances here in New Zealand, also in Australia where major, major organizations have been targeted as a result of the perception of which side they sit on in this conflict that’s on the other side of the world. So you know, for us to sit down in our little corner of the world and just say, well you know, that’s a long way from me, it’s got nothing to do with me. There’s other people, whether they’re criminals, whether they’re issue motivated individuals or whether they’re a hostile nation state that don’t see it the same way we do. So we are absolutely a target.
Paul Spain:
And yeah, and we’ve seen, you know, real world impacts on the subsea cables as well, haven’t we? So these things are not just, you know, a fictitious idea, it’s reality that these assets considered significant when it comes to war or anything else that you wanted to add. Glenn, before we, before we wrap up,
Glenn Maiden:
I would like to try and at least not leave it quite as negative as I guess my last comment, but I do think if we can understand where our business is, where our risks are placed and who maybe might be interested in making my life a little bit miserable. So whether that’s a ransomware person trying to cure my availability or, or whether that’s, you know, someone else trying to steal some sensitive data. It’s not necessarily the, there’s not necessarily the requirement to go and invest huge amounts of money to buy the latest security capability. There is some really good ways that we can lift our resilience very, very quickly. Just understanding, you know, having an incident response plan that works, understanding that we’ve got a backup that we can restore from how long we can afford to be offline. So some of that stuff people are already doing, but our evidence shows that they’re doing it bad. So just getting that sort of dusted off, updated for 2026 and exercised importantly is one. But from a technology perspective, as I said before, there’s some really good MSPs that certainly Fortinet work with in this country, some of the best in the world they’re able to help.
Glenn Maiden:
And from a technology perspective there’s some really good bang for the buck technologies you mentioned MFA before that will make it, it’s not, not perfect like everything. There’s no, I think that’s one of
Paul Spain:
the problems part of the picture, isn’t it?
Glenn Maiden:
Yeah.
Paul Spain:
Elements like.
Glenn Maiden:
I think that’s when you mentioned before, we’re still not getting it right. I think the, the problem is we, we always think that we can just have one silver bullet that’s going to make us secure. It’s not but there’s a few things that we can do that can make us considerably harder. So don’t, I don’t want everyone just to sort of, you know, throw in the towel and go home. There is absolutely a way to face this threat even in, you know, even in 2026.
Paul Spain:
Yeah. Good. Oh well, thank, thank you so much for joining us on the show. Glenn Maiden, thanks for having me. Much appreciated. And you know we’re, we’re certainly very grateful for, for the support and of course across all our partners. So yeah, big thank you to PwC, Fortinet, Workday, One New Zealand, 2degrees Spark and Gorilla Technology. And of course if you’ve been listening into the audio for the show, make sure you’re also following us on, on the like of YouTube for the video and of course if you’ve been watching the video, make sure you follow us on your favourite audio platform as well.
Paul Spain:
That’s us for this week and we’ll look forward to catching up with everyone again next week. And if you’ve got any feedback or any ideas for the show, we would love to hear from you. We are going through a few quiet changes in the background that you may notice as we work to iterate on the New Zealand Tech podcast. Thanks again Glenn and thanks everyone for listening in.