Episode 28

full
Published on:

14th Apr 2026

The Analyst's Role in Cybersecurity: Bridging Gaps and Shaping Trends with Fernando

In this episode, Fernando Montenegro shares his journey into the cybersecurity industry, insights on industry analysis, and the evolving trends shaping cybersecurity today. Discover how analysts bridge the gap between vendors, buyers, investors, and academia, and learn practical tips for engaging effectively with industry experts.

key Takeaways

  • Role of industry analysts in cybersecurity
  • Emerging trends in cybersecurity including AI and attack surface expansion
  • Effective engagement with analysts for decision support
  • Strategic cybersecurity budgeting and investment
  • Influence of economics and incentives on security decisions

sound bites

"Understanding what's going on in the world"

"Good enough security can be effective"

"Workload AI versus workforce AI"

Chapters

00:00 Introduction to Security by Default Podcast

00:53 Fernando Montenegro's Origin Story

05:16 The Role of an Industry Analyst

08:55 Maximizing Value from Analyst Interactions

13:16 Understanding AI in Conversations

15:44 Choosing the Right Solutions

16:40 Decision-Making in Technology and Business

17:13 Trends in Cybersecurity and AI

18:26 Understanding Workload vs. Workforce AI

19:40 The Evolving Role of Security Professionals

21:43 The Strategic Importance of Cybersecurity

23:58 Incentives and Decision-Making in Security

25:53 The Shift Left Approach in Development

27:16 Budgeting for Cybersecurity Investments

30:47 Navigating Cybersecurity Budgets

32:26 Engaging with Analysts and Staying Informed

34:33 Curating Information in a Data-Driven World

36:55 Balancing Operational and Strategic Insights

37:51 Connecting with Analysts and Final Thoughts

Resources

LinkedIn Profile of Fernando Montenegro - https://www.linkedin.com/in/fsmontenegro/

Futurum Group - https://futurumgroup.com/

Obsidian Knowledge Management System - https://obsidian.md/

Book: Why Most Security Budgets Go to Waste by Ross Young - https://a.co/d/02BZPwdO

Show artwork for Security by Default

About the Podcast

Security by Default
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends.
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

About your host

Profile picture for Joseph Carson

Joseph Carson

I am a distinguished cybersecurity professional with over 30 years of experience in enterprise security and infrastructure.

Throughout my career, I have been an active contributor to the cybersecurity community, serving as an educator, ethical hacker, and speaker at global conferences. I hold both the Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP) certifications as well as advise various governments, critical infrastructure organizations, and industries such as finance and transportation on cybersecurity matters.
I am the author of "Cybersecurity for Dummies," a book that has gained global recognition for helping companies integrate people, processes, and technology to strengthen their defense against cyberattacks. The book has over 50,000 readers worldwide and provides a straightforward approach to understanding cybersecurity.

In addition to my writing, I have authored numerous articles and research papers, contributing to publications such as The Wall Street Journal, USA Today, Dark Reading, and CSO Magazine. I also host the bi-weekly podcast "Security by Default" which offers insights from leading cybersecurity experts and discusses best practices for navigating security challenges.
I am dedicated to educating the next generation of cybersecurity leaders and his commitment to building a safer internet have made him a respected figure in the cybersecurity community.