Get ready to challenge everything you assume about AI's role in cybersecurity. Shannon Garcia, founder of Strategic Defense and a veteran red team leader with stops at Trustwave, SecureWorks, IBM, and Kudelski Security, joins the Cyber Smokehouse to break down why manual, human-led penetration testing still outperforms automated AI tools, and why that might not last forever.
You'll learn how shadow IT quietly drains company budgets, why remote work has changed both testing methodology and phishing success rates, and how translating technical findings into business language can protect million-dollar contracts. Plus, Shannon shares her unlikely path from 11 years as an AMD engineer to building two cybersecurity companies from scratch.
Takeaways:
- AI is reshaping conversations across cybersecurity, but Shannon's teams still rely on manual, human-led penetration testing. She notes that automated AI pen testing platforms can't yet handle certain test types, like wireless assessments, and that clients often value the real-time communication a human tester provides over an automated tool.
- Shadow IT remains a persistent and growing risk, not just from a security standpoint but from a business one. Shannon points out that when business units are given autonomy to buy and deploy their own tools, companies can end up bleeding money on redundant or unnecessary licensing without realizing it.
- Remote work has changed both how testing gets done and how social engineering performs. Without a traditional office network to test, engagements now lean heavily on VPN and SaaS-based access reviews, and Shannon has found that phishing and vishing success rates drop significantly when employees work from home and simply don't answer the phone.
- Shannon describes her leadership style as people-first and curiosity-driven. She asks her team detailed questions not to micromanage, but to genuinely understand their thought process and challenges, which she says helps her advocate for them with clients.
- Translating technical findings for non-technical executives has been one of Shannon's most valuable skills. She frames security findings in terms of business risk and cost avoidance rather than pure ROI, which has directly helped clients unblock stalled contracts tied to security requirements.
- Shannon transitioned into cybersecurity after being laid off from an 11-year engineering career at AMD in 2012. Her advice to newcomers is to recognize the transferable soft skills they already have, since communication and reliability matter as much as technical ability when building a career in the field.
- Looking ahead, Shannon is considering a potential acquisition to expand her pen testing company's capabilities, while continuing to grow her AppSec-focused company's response to AI-driven risk in the software development lifecycle. She also has a long-planned mentorship program for aspiring cybersecurity practice leads still in development.
Quote of the Show:
- “The thing that I love the most about running my own business is I don't have to ask for permission.” - Shannon Garcia
Links:
- LinkedIn: https://www.linkedin.com/in/shannongarcia/
- Website: strategicdefense.co
Ways to Tune In:
- Spotify: https://open.spotify.com/show/5LuXXqbK9k9rrVRFsdGzl0
- Apple Podcasts: https://podcasts.apple.com/podcast/cyber-smokehouse/id1872442297
- Amazon Music: https://music.amazon.com/podcasts/40a6c0da-242f-404b-8bd3-9f4997f19c47
- iHeart Radio: https://iheart.com/podcast/319629841/
- Podchaser: https://www.podchaser.com/podcasts/cyber-smokehouse-6356550